<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple context - EIGRP between shared interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3296845#M1010513</link>
    <description>&lt;P&gt;Sorry, but "&lt;SPAN&gt;EIGRP instances cannot form adjacencies with each other across shared interfaces because inter-context exchange of multicast traffic is not supported.&lt;/SPAN&gt;"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The configuration guide mentions it here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/general/asa-98-general-config/route-eigrp.html#ID-2179-0000001b" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/general/asa-98-general-config/route-eigrp.html#ID-2179-0000001b&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 15 Dec 2017 13:28:16 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-12-15T13:28:16Z</dc:date>
    <item>
      <title>Multiple context - EIGRP between shared interfaces</title>
      <link>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3230447#M1010505</link>
      <description>&lt;P&gt;Not sure if I should be posting on the firewall or routing section, but here it goes.&lt;/P&gt;
&lt;P&gt;I have multiple routers and &lt;STRONG&gt;one &lt;/STRONG&gt;firewalls with &lt;STRONG&gt;two &lt;/STRONG&gt;context ruining on the same subnet with EIGRP enabled, everything is working between routers and firewalls, the problem is between the firewall itself, one context cannot see the other and I dont have idea of how to troubleshooting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;######## CONTEXT 1

interface Port-channel13.101
 nameif transit
 security-level 0
 ip address 10.10.101.36 255.255.255.0 standby 10.10.101.37
!
router eigrp 100
 eigrp router-id 10.10.101.36
 network 10.10.101.36 255.255.255.255
 passive-interface default
 no passive-interface transit
 redistribute connected

######## CONTEXT 2

interface Port-channel13.101
 nameif transit
 security-level 0
 ip address 10.10.101.38 255.255.255.0 standby 10.10.101.39
!
router eigrp 100
 eigrp router-id 10.10.101.38
 network 10.10.101.38 255.255.255.255
 passive-interface default
 no passive-interface transit
 redistribute connected
!&lt;/PRE&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:56:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3230447#M1010505</guid>
      <dc:creator>Rolando Valenzuela</dc:creator>
      <dc:date>2020-02-21T14:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple context - EIGRP between shared interfaces</title>
      <link>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3230699#M1010506</link>
      <description>&lt;P&gt;It gather form your description that&amp;nbsp;EIGRP&amp;nbsp;neighborship between the contexts is not forming.&lt;/P&gt;
&lt;P&gt;Following commands would be useful to further troubleshoot:&lt;/P&gt;
&lt;PRE&gt;&lt;STRONG&gt;show eigrp neighbors&lt;BR /&gt;debug eigrp neighbors&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P&gt;You could also capture the EIGRP packets:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&lt;STRONG&gt;capture CAP match eigrp&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 11:05:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3230699#M1010506</guid>
      <dc:creator>Bogdan Nita</dc:creator>
      <dc:date>2017-12-12T11:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple context - EIGRP between shared interfaces</title>
      <link>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3230929#M1010507</link>
      <description>&lt;P&gt;You are correct Bogdan,&lt;/P&gt;
&lt;P&gt;The problem is between the contexts, in fact I tried all those commands before starting this thread, and I dont get anything on the debug.&lt;/P&gt;
&lt;P&gt;The capture shows traffic going to the multicast address 224.0.0.10, but the source is never the other context &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 15:55:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3230929#M1010507</guid>
      <dc:creator>Rolando Valenzuela</dc:creator>
      <dc:date>2017-12-12T15:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple context - EIGRP between shared interfaces</title>
      <link>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3231234#M1010508</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Don't have any physical boxes right now to do some tests only vm...&lt;/P&gt;
&lt;P&gt;Have you tried using the neighbor command to force unicast messages instead of multicast?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 02:21:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3231234#M1010508</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-12-13T02:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple context - EIGRP between shared interfaces</title>
      <link>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3231445#M1010509</link>
      <description>&lt;P&gt;It seems that the&amp;nbsp;&lt;SPAN&gt;eigrp hello messages from one context&amp;nbsp;are not reaching the other.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Are you able to see the messages going out ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;According to your config I would expect to see on the first context&amp;nbsp;eigrp hello messages sent&amp;nbsp;form&amp;nbsp;10.10.101.36 to 224.0.0.10 and on the second context from 10.10.101.38 to 224.0.0.10.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 10:26:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3231445#M1010509</guid>
      <dc:creator>Bogdan Nita</dc:creator>
      <dc:date>2017-12-13T10:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple context - EIGRP between shared interfaces</title>
      <link>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3231700#M1010510</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/321306"&gt;@Francesco Molino&lt;/a&gt; I haven't fully tested it. because when I tried that all the dynamic neighbors when down so I decided to play with that during non-businnes hours and I havent schedule the window. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/316948"&gt;@Bogdan Nita&lt;/a&gt; I do see the traffic going out form the context itself, I do not see the traffic of the other context tho.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;kcinf-fw5585x/brazil# show capture CAP&lt;BR /&gt;&lt;BR /&gt;5469 packets captured&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 1: 09:54:06.475622&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#101 P0 10.10.101.19 &amp;gt; 224.0.0.10:&amp;nbsp; ip-proto-88, length 40&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&amp;nbsp;&amp;nbsp; 2: 09:54:06.527804&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#101 P0 10.10.101.38 &amp;gt; 224.0.0.10:&amp;nbsp; ip-proto-88, length 40&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 3: 09:54:06.648510&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#101 P0 10.10.101.4 &amp;gt; 224.0.0.10:&amp;nbsp; ip-proto-88, length 40&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 4: 09:54:06.811206&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#101 P0 10.10.101.17 &amp;gt; 224.0.0.10:&amp;nbsp; ip-proto-88, length 40&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 5: 09:54:07.253206&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#101 P0 10.10.101.5 &amp;gt; 224.0.0.10:&amp;nbsp; ip-proto-88, length 40&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 6: 09:54:07.711221&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#101 P0 10.10.101.30 &amp;gt; 224.0.0.10:&amp;nbsp; ip-proto-88, length 40&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 7: 09:54:09.157874&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#101 P0 10.10.101.15 &amp;gt; 224.0.0.10:&amp;nbsp; ip-proto-88, length 40&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 8: 09:54:10.186239&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#101 P0 10.10.101.8 &amp;gt; 224.0.0.10:&amp;nbsp; ip-proto-88, length 40&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 9: 09:54:11.093424&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#101 P0 10.10.101.19 &amp;gt; 224.0.0.10:&amp;nbsp; ip-proto-88, length 40&lt;BR /&gt;&amp;nbsp; 10: 09:54:11.153342&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#101 P0 10.10.101.4 &amp;gt; 224.0.0.10:&amp;nbsp; ip-proto-88, length 40&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&amp;nbsp; 11: 09:54:11.427986&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#101 P0 10.10.101.38 &amp;gt; 224.0.0.10:&amp;nbsp; ip-proto-88, length 40&lt;/FONT&gt;&lt;BR /&gt;&amp;nbsp; 12: 09:54:11.439384&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#101 P0 10.10.101.17 &amp;gt; 224.0.0.10:&amp;nbsp; ip-proto-88, length 40&lt;/P&gt;</description>
      <pubDate>Wed, 13 Dec 2017 15:40:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3231700#M1010510</guid>
      <dc:creator>Rolando Valenzuela</dc:creator>
      <dc:date>2017-12-13T15:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple context - EIGRP between shared interfaces</title>
      <link>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3296727#M1010511</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looks like you can't form&amp;nbsp;&lt;SPAN&gt;adjacencies&amp;nbsp;between contexts:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI class="pBu1_Bullet1"&gt;EIGRP instances cannot form adjacencies with each other across shared interfaces because inter-context exchange of multicast traffic is not supported.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/route_eigrp.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/route_eigrp.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Specifying the neighbors , as &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/321306"&gt;@Francesco Molino&lt;/a&gt;&amp;nbsp;suggested will establish EIGRP neighbors using unicast and therefore should work.&lt;/P&gt;
&lt;P&gt;I presume you are using&amp;nbsp;Port-channel13.101 to connect to the routers as well, in which case you will need to specify all the neighbors.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 11:10:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3296727#M1010511</guid>
      <dc:creator>Bogdan Nita</dc:creator>
      <dc:date>2017-12-15T11:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple context - EIGRP between shared interfaces</title>
      <link>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3296845#M1010513</link>
      <description>&lt;P&gt;Sorry, but "&lt;SPAN&gt;EIGRP instances cannot form adjacencies with each other across shared interfaces because inter-context exchange of multicast traffic is not supported.&lt;/SPAN&gt;"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The configuration guide mentions it here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/general/asa-98-general-config/route-eigrp.html#ID-2179-0000001b" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/configuration/general/asa-98-general-config/route-eigrp.html#ID-2179-0000001b&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2017 13:28:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3296845#M1010513</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-12-15T13:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple context - EIGRP between shared interfaces</title>
      <link>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3298678#M1010515</link>
      <description>&lt;P&gt;Very unfortunate &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thanks for the information Marvin!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;
&lt;P&gt;Rolando A. Valenzuela&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2017 15:08:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3298678#M1010515</guid>
      <dc:creator>Rolando Valenzuela</dc:creator>
      <dc:date>2017-12-19T15:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple context - EIGRP between shared interfaces</title>
      <link>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3298686#M1010517</link>
      <description>&lt;P&gt;Did you try to use neighbor command ?&lt;/P&gt;
&lt;P&gt;I think it should work, but I do not have a physical box to play with.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2017 15:16:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3298686#M1010517</guid>
      <dc:creator>Bogdan Nita</dc:creator>
      <dc:date>2017-12-19T15:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple context - EIGRP between shared interfaces</title>
      <link>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3299668#M1010520</link>
      <description>&lt;P&gt;They forced a freeze at work and I haven't been able to test, we are going to retire an old 5585 in a couple of days and lab it with it, but it will take time, what I'm doing is advertising a summary route from the router that is in the middle and that way both context can talk.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rolando A. Valenzuela&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 19:57:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-context-eigrp-between-shared-interfaces/m-p/3299668#M1010520</guid>
      <dc:creator>Rolando Valenzuela</dc:creator>
      <dc:date>2017-12-20T19:57:43Z</dc:date>
    </item>
  </channel>
</rss>

