Contents [hide]
Description
Today I am going to talk about VLAN Mapping for Cisco ASA Firewall in Transparent mode. It gives you a fair idea and describes a solution to be able to insert an ASA in transparent mode between two switches to screen multiple VLANs without changing the VLAN numbering scheme on either switch.
In Transparent Mode even though there is only one Layer 3 network for example 192.168.20.0/24 there MUST be two different Layer 2 Vlans (Vlan2 for inside zone and Vlan20 for outside zone). All hosts must reside in network range 192.168.20.0/24
This configuration example explains how to map or translate the VLAN numbers on RouteXP_SW2 for scenarios where the VLANs IDs cannot be renumbered easily after inserting the ASA in transparent mode to an existing topology.
Layout network diagram

Configuration on Switches and Cisco ASA Firewall
RouteXP_SW1
Cisco ASA Firewall
RouteXP_SW2
On the allowed vlan list we need to permit the translated vlans 2, 3 and 4 because the VLAN ID in the IEEE 802.1Q tag are mapped (or translated) just before a packet is transmitted and just after a packet is received.
Verify
show vlan mapping
Good luck
Source : https://www.routexp.com/2019/11/vlan-mapping-for-cisco-asa-firewall-in.html