<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Management Routing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-management-routing/m-p/4140791#M1073305</link>
    <description>Hi&lt;BR /&gt;&lt;BR /&gt;I know there were bugs in previous versions of management-access was set or other little things but in your 9.8.2, i don't recall if any issues.&lt;BR /&gt;Do you have the same config like no nat with any statements and route-lookup on both sides?&lt;BR /&gt;Do you have other services configured to use management like radius, tacacs? If yes, are these features working?</description>
    <pubDate>Tue, 25 Aug 2020 03:10:29 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2020-08-25T03:10:29Z</dc:date>
    <item>
      <title>ASA Management Routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-management-routing/m-p/4140419#M1073283</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have 2 DCs both with HA pair of ASA5516-X firewalls. I use the management interfaces for management purposes. I was trying to configure logging to a syslog server. Syslog server IP is 10.10.10.1&lt;/P&gt;&lt;P&gt;My logging config is:&lt;/P&gt;&lt;P&gt;logging host management 10.10.10.1 udp/1514&lt;/P&gt;&lt;P&gt;logging trap informational&lt;/P&gt;&lt;P&gt;route management 10.10.10.1 255.255.255.255 10.190.11.1&lt;/P&gt;&lt;P&gt;All traffic is allowed outbound on the interfaces&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In one DC this works fine and syslog is sent out via the management interface. In the other DC however the traffic gets routed via the inside interface. Now both ASAs have a route to the inside interface for network 10.10.0.0/16 also but i expected the management route for the more specific ip to take precedence&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What im trying to figure is how come on one ASA this works fine, whereas on the other is is still trying to route it via the inside interface. There is a software version difference, the one that routes correctly out the management interface is on 9.12(2) however the other one is 9.8(2).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking into this I seen there was a new feature of a separate management routing table from version 9.5 onwards. Is it possible I need to upgrade the firewall from version 9.8 to the latest?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2020 13:11:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-management-routing/m-p/4140419#M1073283</guid>
      <dc:creator>Mokhalil82</dc:creator>
      <dc:date>2020-08-24T13:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Management Routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-management-routing/m-p/4140791#M1073305</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;I know there were bugs in previous versions of management-access was set or other little things but in your 9.8.2, i don't recall if any issues.&lt;BR /&gt;Do you have the same config like no nat with any statements and route-lookup on both sides?&lt;BR /&gt;Do you have other services configured to use management like radius, tacacs? If yes, are these features working?</description>
      <pubDate>Tue, 25 Aug 2020 03:10:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-management-routing/m-p/4140791#M1073305</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2020-08-25T03:10:29Z</dc:date>
    </item>
  </channel>
</rss>

