紧急:如何在asa 5506中使用相同的ip子网配置不同的接口?

网络工程 VLAN 思科 防火墙 IP地址 界面
2021-07-30 02:35:36

场景是旧的 asa 防火墙 5505 我在不同的接口中有 switch port access vlan 命令。就像下面一样:

interface Ethernet0/0
!
interface Ethernet0/1
 switchport access vlan 2
!
interface Ethernet0/2
 switchport access vlan 2
!
interface Ethernet0/3
 switchport access vlan 2
!
interface Ethernet0/4
 switchport access vlan 2
!
interface Ethernet0/5
 switchport access vlan 2
!
interface Ethernet0/6
 switchport access vlan 2
!
interface Ethernet0/7
 switchport access vlan 2
!
interface Vlan1
 nameif Outside
 security-level 0
 ip address x.x.x.x 255.255.255.224 
!
interface Vlan2
 nameif Inside
 security-level 100
 ip address 172.16.0.1 255.255.0.0 

从上面我可以使用不同的接口作为 172.16.0.1 的同一网络。

但在 5506 命令中不受支持。对于我可以在 5506 asa 中运行的相同场景,我可以做些什么吗?

参考:

GigabitEthernet1/1         unassigned      YES manual administratively down down
GigabitEthernet1/2         unassigned      YES unset  administratively down down
GigabitEthernet1/3         unassigned      YES unset  administratively down down
GigabitEthernet1/4         unassigned      YES unset  administratively down down
GigabitEthernet1/5         unassigned      YES unset  administratively down down
GigabitEthernet1/6         unassigned      YES unset  administratively down down
GigabitEthernet1/7         unassigned      YES unset  administratively down down
GigabitEthernet1/8         unassigned      YES unset  administratively down down
Internal-Control1/1        127.0.1.1       YES unset  up                    up
Internal-Data1/1           unassigned      YES unset  down                  down
Internal-Data1/2           unassigned      YES unset  up                    up
Internal-Data1/3           unassigned      YES unset  up                    up
Internal-Data1/4           169.254.1.1     YES unset  up                    up
Management1/1              unassigned      YES unset  administratively down down

请帮忙。迫在眉睫。谢谢你。

1个回答

ASA 5506 没有像 5505 那样的 switchport 命令。在路由模式下,每个接口都在一个单独的子网上,就像一个路由器。