ASA Management VLAN

Hello Irfan

Creating a management VLAN simply means that you are creating one more VLAN on your topology. There’s nothing special about a management VLAN, so you simply configure it the same way as the rest of the VLANs. You simply designate the particular interfaces (SVI on the switch and subinterface on the ASA) through which you will access their CLIs. You can also block any SSH or Telnet access on other SVIs and subinterfaces for security.

Now in order to actually use it as a management VLAN, you must create an interface on each device that will through which you will access the CLI. For the L2 switch, that would be an SVI on the management VLAN itself. For the ASA, that would be the subinterface that corresponds to the management VLAN. Additionally, you will have to also place the PC from which you want to access the management VLAN on the same VLAN as well, so you would create an access port on the switch assigned to the management VLAN from which that PC can be connected.

Now by the sound of it, it seems that you’ve done this already. However, I’m not clear as to where your problem is. You say:

Make sure the PC you are connecting from is on the management VLAN. If you can’t reach other subinterfaces then there may be some problem with routing or access lists or security levels on the ASA. In any case, if your PC is on the management VLAN you don’t need to have access to the other subineterfaces.

Although I’m not completely clear as to what you want to achieve in the end, I hope this has been helpful…

Laz