<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-ha-pair-broadcasting-duplicate-mac/m-p/2898424#M154000</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;What MAC address does the primary and the secondary firewall have?&lt;/P&gt;</description>
    <pubDate>Tue, 10 May 2016 17:57:34 GMT</pubDate>
    <dc:creator>Henrik Grankvist</dc:creator>
    <dc:date>2016-05-10T17:57:34Z</dc:date>
    <item>
      <title>ASA HA pair broadcasting duplicate MAC</title>
      <link>https://community.cisco.com/t5/network-security/asa-ha-pair-broadcasting-duplicate-mac/m-p/2898423#M153998</link>
      <description>&lt;P&gt;We are using 2 ASA 5512 firewalls as HA pair. Both are uplinked to a switch owned and configured by the ISP in a datacenter. Some time ago one of the uplink ports went to err-disabled on the switch. The messages show that a duplicate MAC address is seen. Further investigation shows that the MAC address concerned is the MAC of the outside interface for the standby ASA. This MAC is sent both by itself as by the primary ASA.&lt;/P&gt;
&lt;P&gt;Can this have something to do with the fact that proxy ARP is enabled on the outside?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:44:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ha-pair-broadcasting-duplicate-mac/m-p/2898423#M153998</guid>
      <dc:creator>pbarendse</dc:creator>
      <dc:date>2019-03-12T07:44:06Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/asa-ha-pair-broadcasting-duplicate-mac/m-p/2898424#M154000</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;What MAC address does the primary and the secondary firewall have?&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2016 17:57:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ha-pair-broadcasting-duplicate-mac/m-p/2898424#M154000</guid>
      <dc:creator>Henrik Grankvist</dc:creator>
      <dc:date>2016-05-10T17:57:34Z</dc:date>
    </item>
    <item>
      <title>With an ASA in Active/Standby</title>
      <link>https://community.cisco.com/t5/network-security/asa-ha-pair-broadcasting-duplicate-mac/m-p/2898425#M154003</link>
      <description>&lt;P&gt;With an ASA in Active/Standby mode the ip and the interface mac address moves from one ASA to another when a failover event occurs, this could be what you are seeing. The ISP should probably disable whatever protections they have in place in that vlan, as this is common ASA behaviour.&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2016 18:23:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ha-pair-broadcasting-duplicate-mac/m-p/2898425#M154003</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-05-10T18:23:07Z</dc:date>
    </item>
    <item>
      <title>Hello Jan,</title>
      <link>https://community.cisco.com/t5/network-security/asa-ha-pair-broadcasting-duplicate-mac/m-p/2898426#M154005</link>
      <description>&lt;P&gt;Hello Jan,&lt;/P&gt;
&lt;P&gt;I know about the behaviour you are mentioning. That is actually not what is happening. The primary, active firewall is also broadcasting the MAC address of the secondary, passive firewall. Disabling the protection on the switch has been discussed with the provider but they are not allowing that unfortunately...&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 07:53:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ha-pair-broadcasting-duplicate-mac/m-p/2898426#M154005</guid>
      <dc:creator>pbarendse</dc:creator>
      <dc:date>2016-05-11T07:53:59Z</dc:date>
    </item>
    <item>
      <title>MAC address outside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-ha-pair-broadcasting-duplicate-mac/m-p/2898427#M154007</link>
      <description>&lt;P&gt;MAC address outside interface primary ASA: bc16.65b4.93c3&lt;BR /&gt;MAC address outside interface secondary ASA: 78da.6e99.384d&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2016 11:11:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-ha-pair-broadcasting-duplicate-mac/m-p/2898427#M154007</guid>
      <dc:creator>pbarendse</dc:creator>
      <dc:date>2016-05-19T11:11:53Z</dc:date>
    </item>
  </channel>
</rss>

