<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ahh, the span idea sounds in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/multiple-inside-interfaces-active-standby/m-p/3013388#M145087</link>
    <description>&lt;P&gt;Ahh, the span idea sounds much easier. &amp;nbsp;I will try to persuade in going that route if allowed. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see my error now with the ether channel after your explanation. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;I created separate port channels for each ASA, one port channel for the primary and a separate port channel for the secondary unit. &amp;nbsp;Now the monitoring is working fine. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the quick response.&lt;/P&gt;</description>
    <pubDate>Mon, 10 Apr 2017 15:45:37 GMT</pubDate>
    <dc:creator>tsiemers1</dc:creator>
    <dc:date>2017-04-10T15:45:37Z</dc:date>
    <item>
      <title>Multiple inside interfaces active/standby</title>
      <link>https://community.cisco.com/t5/network-security/multiple-inside-interfaces-active-standby/m-p/3013386#M145085</link>
      <description>&lt;P&gt;We are in a situation where they would like to demo a new content filter inline and in live production. &amp;nbsp;I have been tasked with setting up a sceniaro where our current content filter is running side by side with the new one. &amp;nbsp;They would like to grab buildings one at a time and transition from the old filter to the new filter on the fly. &amp;nbsp;Attached is a diagram of what the network will need. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Current setup:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;6 5545-x ASA's, setup in 3 different pairs of active/standby. &amp;nbsp;One pair is for the High Schools, One pair for Middle Schools, and the last pair for Elementary schools.&lt;/P&gt;
&lt;P&gt;Content filter is Firepower modules all pointing to a virtual FMC.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;New Setup:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;iBoss content filter inline with an additional aggregation switch between the iBoss and ASA pairs. &amp;nbsp;This is only because the iBoss only has a single 10gb link outbound.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Where I am getting stuck is how do I have two inside interfaces that use the same routes. &amp;nbsp;Currently I am using PBR's to send traffic to its appropriate&amp;nbsp;ASA pair. &amp;nbsp;What we would like to do is start changing the next-hop on certain buildings to point to the iBoss server, then to a aggregation switch that uses another PBR to go to its assigned ASA. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When I try to create interfaces from the swi-aggregation that go to both the active and standby unit for the new iBoss-Inside interface the failover monitoring on the secondary fails.&lt;/P&gt;
&lt;P&gt;Is this the right way to approach this setup? &amp;nbsp;Can you monitor two inside interfaces? &amp;nbsp;Every time I set the scenario up I can get the ether-channels to work but the failover monitoring says "failed" on the standby unit.&lt;/P&gt;
&lt;P&gt;Is it better to use layer 2 ether-channels with an SVI or layer 3 ether-channels?&lt;/P&gt;
&lt;P&gt;Please see attachment for diagram.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And yes I have suggested multiple times to run this in a test environment, and to slim down to one ASA instead of 3 pairs.&lt;/P&gt;
&lt;P&gt;All ASA's have a static route pointed towards the inside of:&lt;/P&gt;
&lt;P&gt;10.0.0.0 255.0.0.0 10.10.10.x &amp;lt;----interface on the nexus&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:12:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-inside-interfaces-active-standby/m-p/3013386#M145085</guid>
      <dc:creator>tsiemers1</dc:creator>
      <dc:date>2019-03-12T09:12:11Z</dc:date>
    </item>
    <item>
      <title>Etherchannels must go from</title>
      <link>https://community.cisco.com/t5/network-security/multiple-inside-interfaces-active-standby/m-p/3013387#M145086</link>
      <description>&lt;P&gt;Etherchannels must go from the same device (or virtual device in the case of VPC, VSS or switch stacks) to the same device. An ASA HA pair is not considered a single device for Etherchannel purposes.&lt;/P&gt;
&lt;P&gt;When we are doing demos of a new IPS or content filter we would typically span the interesting traffic and let the content filter do "what-if" analysis.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 15:23:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-inside-interfaces-active-standby/m-p/3013387#M145086</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-10T15:23:16Z</dc:date>
    </item>
    <item>
      <title>Ahh, the span idea sounds</title>
      <link>https://community.cisco.com/t5/network-security/multiple-inside-interfaces-active-standby/m-p/3013388#M145087</link>
      <description>&lt;P&gt;Ahh, the span idea sounds much easier. &amp;nbsp;I will try to persuade in going that route if allowed. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see my error now with the ether channel after your explanation. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;I created separate port channels for each ASA, one port channel for the primary and a separate port channel for the secondary unit. &amp;nbsp;Now the monitoring is working fine. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the quick response.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 15:45:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/multiple-inside-interfaces-active-standby/m-p/3013388#M145087</guid>
      <dc:creator>tsiemers1</dc:creator>
      <dc:date>2017-04-10T15:45:37Z</dc:date>
    </item>
  </channel>
</rss>

