Any ideas on how to assign Azure public ip and subnet mast to cisco asav

Garth Taylor 20 Reputation points
2024-01-28T10:52:25.46+00:00

I have been asked to setup and Cisco asav on azure, so I can assign the public interface on the cisco firewall but it does not like /32 for a single public ip. Anyone know what subnet to configure on my external inferface so it keeps the firewall happy. Thanks

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,520 questions
{count} votes

Accepted answer
  1. Silvia Wibowo 3,991 Reputation points Microsoft Employee
    2024-02-01T00:22:48.54+00:00

    Hi @Garth Taylor, there are 2 sets of routing:

    • Azure Virtual Network routing -> this is applied as Route Table on the subnets. Once you've created vnet peering, there will by system-injected routes that complement the Route Table to inform about routes to the other vnet. Since you've created vnet peering, I think your setup is already good for this.
    • Routing in Cisco ASAv -> you need to set default route to Outside interface.
    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. GitaraniSharma-MSFT 49,591 Reputation points Microsoft Employee
    2024-01-30T13:02:59.2566667+00:00

    Hello @Garth Taylor ,

    Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.

    I understand that you would like to know how to assign an Azure public IP and subnet to cisco asav firewall during its deployment.

    You can find more information about the Prerequisites and deployment options for the Cisco ASAv in the below docs:

    https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/asav/quick-start-book/asav-98-qsg/asav-azure.html

    https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/asav/quick-start-book/asav-98-qsg/asav-azure.html#id_48477

    You can also refer this blog for detailed instructions with screenshots:

    Anyone knows what subnet to configure on my external interface, so it keeps the firewall happy.

    The smallest supported IPv4 subnet in Azure is /29, and the largest is /2 (using CIDR subnet definitions).

    Refer: https://learn.microsoft.com/en-us/azure/virtual-network/virtual-networks-faq#how-small-and-how-large-can-virtual-networks-and-subnets-be

    So, you need to make sure that the subnet you define is either /29 or larger such as /28, /27 and so on.

    enter image description here

    Kindly let us know if the above helps or you need further assistance on this issue.


    Please don’t forget to "Accept the answer" wherever the information provided helps you, this can be beneficial to other community members.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.