Cisco ASA 5505:交换端口VLAN分配

一种思科Luddite,但我想分配物理switchports 0/1和0/2到Vlan2和物理switchports 0/3和0/4到Vlan3。 我假设这是可能的基本安全许可证,即:

! interface Vlan1 nameif outside security-level 0 ip address 100.200.100.200 255.255.255. no shutdown ! interface Vlan2 nameif inside security-level 100 ip address 10.0.0.1 255.255.255.0 ! interface Vlan3 nameif dmz security-level 50 ip address 10.0.1.1 255.255.255.0 ! interface Ethernet0/0 switchport access vlan 1 ! interface Ethernet0/1 switchport access vlan 2 ! interface Ethernet0/2 switchport access vlan 2 ! interface Ethernet0/3 switchport access vlan 3 ! interface Ethernet0/4 switchport access vlan 3 ! 

是的,这将工作得很好,虽然基本许可证将迫使您限制其中一个接口:

 interface Vlan3 no forward interface Vlan2