<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Active-Standby 'monitor-interface' in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-active-standby-monitor-interface/m-p/2909051#M154429</link>
    <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;i'm configuring 2x ASA for active/standby and just want to confirm the 'monitor-interface' command&lt;/P&gt;
&lt;P&gt;we have context with an 'outside' (with a different public IP) and 'inside' with different allocated sub-interface.&lt;/P&gt;
&lt;P&gt;i was thinking of configuring these lines for each context just to be sure:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;monitor-interface inside&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;monitor-interface outside&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;my question, since we're creating sub-interface (different VLAN) for the 'inside' interface for each context, do we always have to configure the 'monitor-interface inside' for each new context?&lt;/P&gt;
&lt;P&gt;is 'outside' interface enabled by default for the 'monitor-interface' command since the allocated outside interface is always the main interface g0/0?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA01/pri/act(config-pmap)# monitor-interface ?&lt;BR /&gt;&lt;BR /&gt;configure mode commands/options:&lt;BR /&gt;&amp;nbsp; service-module&amp;nbsp; Enable service-card monitoring&lt;BR /&gt;Current available interface(s):&lt;BR /&gt;&amp;nbsp; inside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name of interface GigabitEthernet0/1.&lt;SPAN style="color: #ff0000;"&gt;400&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; THIS IS FOR CONTEXT A; WHAT IF CONTEXT B HAS G0/1.401 FOR 'inside'?&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; outside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name of interface GigabitEthernet0/0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;lastly, is it good practice to enable the 'failover replication http' command? will it cause heavy traffic on the failover links?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 07:40:15 GMT</pubDate>
    <dc:creator>johnlloyd_13</dc:creator>
    <dc:date>2019-03-12T07:40:15Z</dc:date>
    <item>
      <title>ASA Active-Standby 'monitor-interface'</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-monitor-interface/m-p/2909051#M154429</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;i'm configuring 2x ASA for active/standby and just want to confirm the 'monitor-interface' command&lt;/P&gt;
&lt;P&gt;we have context with an 'outside' (with a different public IP) and 'inside' with different allocated sub-interface.&lt;/P&gt;
&lt;P&gt;i was thinking of configuring these lines for each context just to be sure:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;monitor-interface inside&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;monitor-interface outside&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;my question, since we're creating sub-interface (different VLAN) for the 'inside' interface for each context, do we always have to configure the 'monitor-interface inside' for each new context?&lt;/P&gt;
&lt;P&gt;is 'outside' interface enabled by default for the 'monitor-interface' command since the allocated outside interface is always the main interface g0/0?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA01/pri/act(config-pmap)# monitor-interface ?&lt;BR /&gt;&lt;BR /&gt;configure mode commands/options:&lt;BR /&gt;&amp;nbsp; service-module&amp;nbsp; Enable service-card monitoring&lt;BR /&gt;Current available interface(s):&lt;BR /&gt;&amp;nbsp; inside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name of interface GigabitEthernet0/1.&lt;SPAN style="color: #ff0000;"&gt;400&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; THIS IS FOR CONTEXT A; WHAT IF CONTEXT B HAS G0/1.401 FOR 'inside'?&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; outside&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name of interface GigabitEthernet0/0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;lastly, is it good practice to enable the 'failover replication http' command? will it cause heavy traffic on the failover links?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:40:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-monitor-interface/m-p/2909051#M154429</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2019-03-12T07:40:15Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-monitor-interface/m-p/2909052#M154431</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I don't understand what you mean with:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;is 'outside' interface enabled by default for the 'monitor-interface' command since the allocated outside interface is always the main interface g0/0?&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;By default only the failover interface is monitored if I remember correctly.&lt;/P&gt;
&lt;P&gt;The monitor-interface is done inside each context, so if you have interface "outside" on three different context you have to enable monitor-interface on all three contexts for interface "outside".&lt;/P&gt;
&lt;P&gt;Whether it's good practice or not depends on your need at your company/customer. Is it critical that not even the http session has to reestablish? Well then HTTP replication is necessary. For most companies it is not necessary.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2016 19:57:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-monitor-interface/m-p/2909052#M154431</guid>
      <dc:creator>Henrik Grankvist</dc:creator>
      <dc:date>2016-04-26T19:57:05Z</dc:date>
    </item>
    <item>
      <title>hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-monitor-interface/m-p/2909053#M154432</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;i saw this link and it mentioned about the said command.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/ha_failover.html"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/ha_failover.html&lt;/A&gt;&lt;/P&gt;
&lt;SECTION&gt;
&lt;H3 class="p_H_Head2"&gt;Configuring Interface Monitoring&lt;/H3&gt;
&lt;P class="pB1_Body1"&gt;&lt;A name="pgfId-1348727"&gt;&lt;/A&gt;&lt;SPAN style="color: #ff0000;"&gt;By default, monitoring is enabled on all physical interfaces&lt;/SPAN&gt;, or for the ASA 5505 and ASASM, all VLAN interfaces. You might want to exclude interfaces attached to less critical networks from affecting your failover policy.&lt;/P&gt;
&lt;/SECTION&gt;
&lt;SECTION&gt;
&lt;H3 class="p_H_Head4"&gt;&lt;A name="pgfId-1343205"&gt;&lt;/A&gt;&lt;A name="Guidelines"&gt;&lt;/A&gt;Guidelines&lt;/H3&gt;
&lt;UL&gt;
&lt;LI class="pBu1_Bullet1"&gt;&lt;A name="pgfId-1345796"&gt;&lt;/A&gt;You can monitor up to 250 interfaces on a unit (across all contexts in multiple context mode).&lt;/LI&gt;
&lt;LI class="pBu1_Bullet1"&gt;&lt;A name="pgfId-1343203"&gt;&lt;/A&gt;&lt;SPAN style="color: #ff0000;"&gt;In multiple context mode, configure interfaces within each context.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/SECTION&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;do you 'hardcode' these commands in your environment? same goes for the http replication, do you configure this in your ASA?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2016 06:21:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-monitor-interface/m-p/2909053#M154432</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2016-04-27T06:21:12Z</dc:date>
    </item>
    <item>
      <title>Normally I only use</title>
      <link>https://community.cisco.com/t5/network-security/asa-active-standby-monitor-interface/m-p/2909054#M154433</link>
      <description>&lt;P&gt;Normally I only use subinterfaces because it scales a lot better and yes I will configure http replication, it doesn't impact that much on the bandwidth.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Apr 2016 07:38:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-active-standby-monitor-interface/m-p/2909054#M154433</guid>
      <dc:creator>Henrik Grankvist</dc:creator>
      <dc:date>2016-04-30T07:38:28Z</dc:date>
    </item>
  </channel>
</rss>

