<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: monitor-interface in ASA Context in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/monitor-interface-in-asa-context/m-p/4956446#M1105706</link>
    <description>&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;my question is do i need to apply this config on all context sub-interfaces?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;This depends on if you want a failover to occur if there is a protocol failure on any of the sub-interfaces.&amp;nbsp; Otherwise you would only need the command on the interfaces you want to monitor and trigger in a failure situation, (your most important interfaces).&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;will it cause failover flapping issue when one or two sub-interfaces in a specific context had a problem?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Not entirely sure what you mean by this, but once a failover occurs, the previously active device will not become active again unless you manually failover or there is another failure situation on the current active device.&lt;/P&gt;
&lt;P&gt;Also, if you have not done so already, it is a good practice to configure standby IPs on the interfaces for situations where it is the failover link that has failed.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Nov 2023 14:27:01 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2023-11-09T14:27:01Z</dc:date>
    <item>
      <title>monitor-interface in ASA Context</title>
      <link>https://community.cisco.com/t5/network-security/monitor-interface-in-asa-context/m-p/4956307#M1105700</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;i'm configuring a new FPR 3100 with ASA OS.&lt;/P&gt;&lt;P&gt;it's an ASA in multiple context mode and was doing some failover test and ping to the internet.&lt;/P&gt;&lt;P&gt;it didn't failover to secondary after shutdown trunk switch port facing the ASA FW LAN and WAN. it only worked after configuring the 'monitor-interface' on the LAN and WAN.&lt;/P&gt;&lt;P&gt;my question is do i need to apply this config on all context sub-interfaces?&lt;/P&gt;&lt;P&gt;will it cause failover flapping issue when one or two sub-interfaces in a specific context had a problem?&lt;/P&gt;&lt;P&gt;asa/pri/act/TEST# show interface ip brief&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;Port-channel2.199 172.16.4.5 YES manual up up&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; LAN/inside: PORT-CHANNEL TO TRUNK SWITCH PORT&lt;BR /&gt;Port-channel2.999 178.2.10.1 YES manual up up&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; WAN/outside: PORT-CHANNEL TO TRUNK SWITCH PORT&lt;/P&gt;&lt;P&gt;asa/pri/act/TEST# sh run | i monitor&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; INTERNET EDGE FW&lt;BR /&gt;no monitor-interface TEST_VRF&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt;&amp;lt; LAN/inside&lt;BR /&gt;no monitor-interface INTERNET&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; WAN/outside&lt;/P&gt;&lt;P&gt;Router#ping vrf TEST_VRF 8.8.8.8 source 172.16.4.1 repeat 1000&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; PING FROM DOWNSTREAM ROUTER, NO FAILOVER&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 1000, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:&lt;BR /&gt;Packet sent with a source address of 172.16.41&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!................................&lt;BR /&gt;................&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;asa/pri/act/TEST(config)# monitor-interface TEST_VRF&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;asa/pri/act/TEST(config)# monitor-interface INTERNET&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Router#ping vrf TEST_VRF 8.8.8.8 source 172.16.4.1 repeat 1000&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; FAILOVER TO SECONDARY FW WORKED&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 1000, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:&lt;BR /&gt;Packet sent with a source address of 172.16.4.1&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!.!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;!!!!!!!!!!!!!!!!!!!!&lt;BR /&gt;Success rate is 99 percent (999/1000), round-trip min/avg/max = 15/15/21 ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 09:11:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitor-interface-in-asa-context/m-p/4956307#M1105700</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2023-11-09T09:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: monitor-interface in ASA Context</title>
      <link>https://community.cisco.com/t5/network-security/monitor-interface-in-asa-context/m-p/4956446#M1105706</link>
      <description>&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;my question is do i need to apply this config on all context sub-interfaces?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;This depends on if you want a failover to occur if there is a protocol failure on any of the sub-interfaces.&amp;nbsp; Otherwise you would only need the command on the interfaces you want to monitor and trigger in a failure situation, (your most important interfaces).&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;will it cause failover flapping issue when one or two sub-interfaces in a specific context had a problem?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Not entirely sure what you mean by this, but once a failover occurs, the previously active device will not become active again unless you manually failover or there is another failure situation on the current active device.&lt;/P&gt;
&lt;P&gt;Also, if you have not done so already, it is a good practice to configure standby IPs on the interfaces for situations where it is the failover link that has failed.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 14:27:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitor-interface-in-asa-context/m-p/4956446#M1105706</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-11-09T14:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: monitor-interface in ASA Context</title>
      <link>https://community.cisco.com/t5/network-security/monitor-interface-in-asa-context/m-p/4956804#M1105717</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;i'll probably just configure monitor on the "INTERNET" sub-interface/nameif since there's a lot of "inside" subif.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 05:42:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/monitor-interface-in-asa-context/m-p/4956804#M1105717</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2023-11-10T05:42:53Z</dc:date>
    </item>
  </channel>
</rss>

