<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Management Interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-management-interface/m-p/3050236#M134767</link>
    <description>&lt;P&gt;I have configured the management interface on an ASA 5525 as follows:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;interface Management0/0&lt;BR /&gt; description MGMT link to GOLABC012SW - F1/0/17 - VLAN 701&lt;BR /&gt; management-only&lt;BR /&gt; nameif management&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 143.16.191.45 255.255.255.0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The ASA is directly connected to the switch with the following switchport config:&lt;/P&gt;
&lt;P&gt;interface FastEthernet1/0/17&lt;BR /&gt;description ASA MGT port 00&lt;BR /&gt;switchport access vlan 701&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;interface Vlan701&lt;BR /&gt;description Network lab management VLAN&lt;BR /&gt;ip address 143.16.191.15 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The management interface on the ASA and switch is up/up. From the switch I can ping the ASA. But from the ASA I can't ping the switch and I can't even ping my own IP address at 143.16.191.45 on the ASA let alone anything on the 143.16.191.x subnet.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;GOLABASA1/sec/actNoFailover# ping 143.16.191.45&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 143.16.191.45, timeout is 2 seconds:&lt;BR /&gt;?????&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here's my ARP table from the ASA. So I am seeing IP hosts from the 143.16.191.x in the ARP table.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GOLABASA1/sec/actNoFailover# sh arp&lt;BR /&gt; outside 193.17.99.65 7081.057c.9501 0&lt;BR /&gt; serverlan 143.16.80.53 6c20.5665.5ec0 5246&lt;BR /&gt; serverlan 143.16.80.49 1cdf.0f83.3240 10814&lt;BR /&gt; management 143.16.191.1 7c95.f35b.4ef3 10184&lt;BR /&gt; management 143.16.191.26 b4a4.e3ee.96c1 12505&lt;BR /&gt; management 143.16.191.29 8cb6.4ff4.51c1 12512&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Anyway, I'm a bit of a novice on ASA firewalls. I think I may missing something very basic. Any suggestions on what else to look for would be much appreciated.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 09:29:36 GMT</pubDate>
    <dc:creator>tomyip</dc:creator>
    <dc:date>2019-03-12T09:29:36Z</dc:date>
    <item>
      <title>ASA Management Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-management-interface/m-p/3050236#M134767</link>
      <description>&lt;P&gt;I have configured the management interface on an ASA 5525 as follows:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;interface Management0/0&lt;BR /&gt; description MGMT link to GOLABC012SW - F1/0/17 - VLAN 701&lt;BR /&gt; management-only&lt;BR /&gt; nameif management&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 143.16.191.45 255.255.255.0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The ASA is directly connected to the switch with the following switchport config:&lt;/P&gt;
&lt;P&gt;interface FastEthernet1/0/17&lt;BR /&gt;description ASA MGT port 00&lt;BR /&gt;switchport access vlan 701&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;interface Vlan701&lt;BR /&gt;description Network lab management VLAN&lt;BR /&gt;ip address 143.16.191.15 255.255.255.0&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The management interface on the ASA and switch is up/up. From the switch I can ping the ASA. But from the ASA I can't ping the switch and I can't even ping my own IP address at 143.16.191.45 on the ASA let alone anything on the 143.16.191.x subnet.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;GOLABASA1/sec/actNoFailover# ping 143.16.191.45&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 143.16.191.45, timeout is 2 seconds:&lt;BR /&gt;?????&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here's my ARP table from the ASA. So I am seeing IP hosts from the 143.16.191.x in the ARP table.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GOLABASA1/sec/actNoFailover# sh arp&lt;BR /&gt; outside 193.17.99.65 7081.057c.9501 0&lt;BR /&gt; serverlan 143.16.80.53 6c20.5665.5ec0 5246&lt;BR /&gt; serverlan 143.16.80.49 1cdf.0f83.3240 10814&lt;BR /&gt; management 143.16.191.1 7c95.f35b.4ef3 10184&lt;BR /&gt; management 143.16.191.26 b4a4.e3ee.96c1 12505&lt;BR /&gt; management 143.16.191.29 8cb6.4ff4.51c1 12512&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Anyway, I'm a bit of a novice on ASA firewalls. I think I may missing something very basic. Any suggestions on what else to look for would be much appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:29:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-management-interface/m-p/3050236#M134767</guid>
      <dc:creator>tomyip</dc:creator>
      <dc:date>2019-03-12T09:29:36Z</dc:date>
    </item>
    <item>
      <title>Can you try "ping management</title>
      <link>https://community.cisco.com/t5/network-security/asa-management-interface/m-p/3050237#M134768</link>
      <description>&lt;P&gt;Can you try "ping management&amp;nbsp;&lt;SPAN&gt;143.16.191.45"? The newer ASA software versions (9.5 and above) have a separate&amp;nbsp;routing table for management which may be why your ping might be failing.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jun 2017 19:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-management-interface/m-p/3050237#M134768</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-06-12T19:49:45Z</dc:date>
    </item>
    <item>
      <title>That worked! </title>
      <link>https://community.cisco.com/t5/network-security/asa-management-interface/m-p/3050238#M134770</link>
      <description>&lt;P&gt;That worked!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GOLABASA1/sec/actNoFailover# ping management 143.16.191.45&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 143.16.191.45, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;BR /&gt;GOLABASA1/sec/actNoFailover# ping management 143.16.191.15&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 143.16.191.15, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;BR /&gt;GOLABASA1/sec/actNoFailover# ping management 143.16.191.1&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 143.16.191.1, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/4/10 ms&lt;/P&gt;
&lt;P&gt;I can see the separate routing table.&lt;/P&gt;
&lt;P&gt;GOLABASA1/sec/actNoFailover# show route management-only&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Routing Table: mgmt-only&lt;BR /&gt;Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;BR /&gt; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;BR /&gt; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;BR /&gt; E1 - OSPF external type 1, E2 - OSPF external type 2, V - VPN&lt;BR /&gt; i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;BR /&gt; ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;BR /&gt; o - ODR, P - periodic downloaded static route, + - replicated route&lt;BR /&gt;Gateway of last resort is not set&lt;/P&gt;
&lt;P&gt;S 143.0.0.0 255.0.0.0 [1/0] via 143.16.191.15, management&lt;BR /&gt;C 143.16.191.0 255.255.255.0 is directly connected, management&lt;BR /&gt;L 143.16.191.45 255.255.255.255 is directly connected, management&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is there a way to integrate/combine the management routing table with the global routing table? Or at least make the two routing tables learn about each other?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2017 15:25:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-management-interface/m-p/3050238#M134770</guid>
      <dc:creator>tomyip</dc:creator>
      <dc:date>2017-06-13T15:25:29Z</dc:date>
    </item>
  </channel>
</rss>

