<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA External Interface Lease renewal ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-external-interface-lease-renewal/m-p/5359877#M1124044</link>
    <description>&lt;P&gt;Hi Again,&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) We loose internet access. The interface goes down, then returns to up as connection is regained to the ONT.&amp;nbsp;&lt;BR /&gt;(The ONT is not on a UPS, so if there is a power interruption, it has to re-initialise. Hence the interface going DOWN-UP. The ASA is on a UPS.)&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) The IP number remains the same.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;3) yes, we still have an IP number on the interface, and default route.&amp;nbsp;&lt;BR /&gt;sh route as above&lt;BR /&gt;sh ip int bri as above.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jan 2026 09:56:39 GMT</pubDate>
    <dc:creator>HumptyD-UK</dc:creator>
    <dc:date>2026-01-08T09:56:39Z</dc:date>
    <item>
      <title>ASA External Interface Lease renewal ?</title>
      <link>https://community.cisco.com/t5/network-security/asa-external-interface-lease-renewal/m-p/5359576#M1124035</link>
      <description>&lt;P&gt;Hi folks,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a ASA on 9.12(4)67.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is an&amp;nbsp; ONT that is connected on the external interface and we use DHCP to retrieve our IP and gateway etc. for out internet connection.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If this interface drops and then recovers (ONT is in a different room which is not UPS maintained.) I can see we still have an IP number and gateway, but routing stops.. and thus, so dose any remote access.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I've found that if we then renew the lease via ADSM, routing is then refreshed? and passes traffic.&amp;nbsp;&lt;BR /&gt;(this is a pain because I normally work remotely as the ASA is a 30 min drive away.)&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If this is known feature, can it be mitigated in any way to force a complete lease renewal,&amp;nbsp; perhaps with a script responding to loss of ping to the remote gateway?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;With Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2026 12:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-external-interface-lease-renewal/m-p/5359576#M1124035</guid>
      <dc:creator>HumptyD-UK</dc:creator>
      <dc:date>2026-01-07T12:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA External Interface Lease renewal ?</title>
      <link>https://community.cisco.com/t5/network-security/asa-external-interface-lease-renewal/m-p/5359581#M1124037</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;I'd first need to understand the exact conditions. When the event happens, the ASA interface goes DOWN or remains in UP state? When you renew the lease after the event to fix it, do you get a different IP address than you previously had before the event happened, or is it the same? When the event happens, from ASA CLI, what is the output of &lt;FONT color="#FF0000"&gt;show interface ip brief&lt;/FONT&gt; and &lt;FONT color="#FF0000"&gt;show route&lt;/FONT&gt;, do you still have an IP address on the interface and the default route installed in RIB?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2026 12:19:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-external-interface-lease-renewal/m-p/5359581#M1124037</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-07T12:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA External Interface Lease renewal ?</title>
      <link>https://community.cisco.com/t5/network-security/asa-external-interface-lease-renewal/m-p/5359621#M1124038</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's some example syslogs.&lt;/P&gt;&lt;P&gt;2025-11-19 03:40:12 Gig-0/5-External &amp;lt;IP&amp;gt; ifAdminStatus: down -&amp;gt; up System&lt;BR /&gt;2025-11-19 03:40:12 Gig-0/5-External &amp;lt;IP&amp;gt; ifOperStatus: down -&amp;gt; up System&lt;BR /&gt;2025-11-19 03:35:10 Gig-0/5-External &amp;lt;IP&amp;gt; ifAdminStatus: up -&amp;gt; down System&lt;BR /&gt;2025-11-19 03:35:10 Gig-0/5-External &amp;lt;IP&amp;gt; ifOperStatus: up -&amp;gt; down&lt;/P&gt;&lt;P&gt;2025-11-19 03:39:07 warning &amp;lt;IP&amp;gt; Nov 19 03:39:34 GMT/BST: %ASA--4-411001: Line protocol on Interface GigabitEthernet0/5, changed state to up warning&lt;BR /&gt;2025-11-19 03:39:03 warning &amp;lt;IP&amp;gt; Nov 19 03:39:30 GMT/BST: %ASA--4-411002: Line protocol on Interface GigabitEthernet0/5, changed state to down warning&lt;BR /&gt;2025-11-19 03:38:55 warning &amp;lt;IP&amp;gt; Nov 19 03:39:22 GMT/BST: %ASA--4-411001: Line protocol on Interface GigabitEthernet0/5, changed state to up warning&lt;BR /&gt;2025-11-19 03:38:51 warning &amp;lt;IP&amp;gt; Nov 19 2025 03:39:18: %ASA--4-411002: Line protocol on Interface GigabitEthernet0/5, changed state to down warning&lt;BR /&gt;2025-11-19 03:38:49 warning &amp;lt;IP&amp;gt; Nov 19 03:39:16 GMT/BST: %ASA--4-411001: Line protocol on Interface GigabitEthernet0/5, changed state to up warning&lt;BR /&gt;2025-11-19 03:34:51 warning &amp;lt;IP&amp;gt; Nov 19 03:35:18 GMT/BST: %ASA--4-411002: Line protocol on Interface GigabitEthernet0/5, changed state to down warning.&lt;BR /&gt;&lt;BR /&gt;the sh ip bri, shows our external IP number on the external if but don't have a full output on record atm.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;S* 0.0.0.0 0.0.0.0 [1/0] via &amp;lt;extenral gw ip&amp;gt;, Gig-0/5-External&lt;BR /&gt;C &amp;lt;internal&amp;gt; .0 255.255.255.0 is directly connected, Gig-0/0-Internal-0&lt;BR /&gt;L &amp;lt;internal&amp;gt; .2 255.255.255.255 is directly connected, Gig-0/0-Internal-0&lt;BR /&gt;C &amp;lt;internal&amp;gt; .4.0 255.255.255.0 is directly connected, Gig-0/4-Wifi&lt;BR /&gt;L &amp;lt;internal&amp;gt; .4.1 255.255.255.255 is directly connected, Gig-0/4-Wifi&lt;BR /&gt;C &amp;lt;external subnet&amp;gt;.0 255.255.255.0 is directly connected, Gig-0/5-External&lt;BR /&gt;L &amp;lt;external ip&amp;gt; 255.255.255.255&lt;BR /&gt;is directly connected, Gig-0/5-External&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/5&lt;BR /&gt;nameif Gig-0/5-External&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address dhcp setroute&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2026 14:48:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-external-interface-lease-renewal/m-p/5359621#M1124038</guid>
      <dc:creator>HumptyD-UK</dc:creator>
      <dc:date>2026-01-07T14:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA External Interface Lease renewal ?</title>
      <link>https://community.cisco.com/t5/network-security/asa-external-interface-lease-renewal/m-p/5359715#M1124041</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; Unfortunately, you didn't answer my questions. You provided some log, however I don't want to assume what it might mean, I need to tie the logs to the sequence of events.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. When the event happens, the ASA interface goes DOWN or remains in UP state? The event means, you loose Internet access, not you disabling and enabling the interface.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. When you renew the lease after the event to fix it, do you get a different IP address than you previously had before the event happened, or is it the same? &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3. When the event happens, from ASA CLI, what is the output of &lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;show interface ip brief&lt;/FONT&gt;&lt;SPAN&gt; and &lt;/SPAN&gt;&lt;FONT color="#FF0000"&gt;show route&lt;/FONT&gt;&lt;SPAN&gt;, do you still have an IP address on the interface and the default route installed in RIB?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cristian.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jan 2026 21:26:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-external-interface-lease-renewal/m-p/5359715#M1124041</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-07T21:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA External Interface Lease renewal ?</title>
      <link>https://community.cisco.com/t5/network-security/asa-external-interface-lease-renewal/m-p/5359877#M1124044</link>
      <description>&lt;P&gt;Hi Again,&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) We loose internet access. The interface goes down, then returns to up as connection is regained to the ONT.&amp;nbsp;&lt;BR /&gt;(The ONT is not on a UPS, so if there is a power interruption, it has to re-initialise. Hence the interface going DOWN-UP. The ASA is on a UPS.)&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) The IP number remains the same.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;3) yes, we still have an IP number on the interface, and default route.&amp;nbsp;&lt;BR /&gt;sh route as above&lt;BR /&gt;sh ip int bri as above.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2026 09:56:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-external-interface-lease-renewal/m-p/5359877#M1124044</guid>
      <dc:creator>HumptyD-UK</dc:creator>
      <dc:date>2026-01-08T09:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA External Interface Lease renewal ?</title>
      <link>https://community.cisco.com/t5/network-security/asa-external-interface-lease-renewal/m-p/5359894#M1124045</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;That's weird, as far as if the interface goes down, upon interface coming back UP, it initiates the DHCP DORA process gain, thus it communicates with remote side, you're saying the IP is preserved, so it should work. I suggest to perform the following actions:&lt;/P&gt;
&lt;P&gt;1. Upgrade to&amp;nbsp;&lt;SPAN&gt;9.14(4)24, to maybe fix a bug on the ASA.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. If above doesn't fix it or for whatever reason you can't perform an upgrade, use an EEM script to automatically renew the lease on the interface upon interface flap:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;event manager applet DHCP_RENEW_LEASE
 event syslog id 411001 occurs 1 period 1
 action 0 cli command "interface GigabitEthernet0/5"
 action 1 cli command "no ip address dhcp setroute"
 action 2 cli command "ip address dhcp setroute"
 output console&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If you're going ahead with second proposed option, test it, create a link down event and see if it works.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jan 2026 11:20:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-external-interface-lease-renewal/m-p/5359894#M1124045</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2026-01-08T11:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA External Interface Lease renewal ?</title>
      <link>https://community.cisco.com/t5/network-security/asa-external-interface-lease-renewal/m-p/5360529#M1124069</link>
      <description>&lt;P&gt;Good Morning, Thank you for the follow up, and can confirm the script worked nicely.&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes, we could do&amp;nbsp;9.14(4)24, but that's for another day when I have more £ in the budget later this year.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Mark&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2026 07:17:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-external-interface-lease-renewal/m-p/5360529#M1124069</guid>
      <dc:creator>HumptyD-UK</dc:creator>
      <dc:date>2026-01-12T07:17:07Z</dc:date>
    </item>
  </channel>
</rss>

