<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/directaccess-possible-with-multiple-context-mode/m-p/2795426#M175248</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Unfortunately, security context on multiple context mode (or Act/Act pair) is not real virtual machine such as virtual machine on ESXi or VMware Workstation. Security context will be behaving a virtual firewall, but it is not perfect one. So it has some limitations (e.g. VPN, Routing, QoS, etc)&lt;/P&gt;
&lt;P&gt;Multiple context mode started to support Site-to-site VPN from 9.0. Therefore, RemoteVPN might be supported in the future.., but latest ASA version 9.5 does not support Remote VPN. So the future of the support is unclear.&lt;/P&gt;
&lt;P&gt;ASA9.5:&lt;BR /&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa95/configuration/general/asa-95-general-config/ha-contexts.html#ID-2171-0000015b"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa95/configuration/general/asa-95-general-config/ha-contexts.html#ID-2171-0000015b&lt;/A&gt;&lt;BR /&gt;--------------------------------------------------------&lt;BR /&gt;Guidelines for Multiple Context Mode&lt;BR /&gt; -- snip --&lt;BR /&gt;Unsupported Features&lt;BR /&gt;Multiple context mode does not support the following features:&lt;BR /&gt; RIP&lt;BR /&gt; OSPFv3. (OSPFv2 is supported.)&lt;BR /&gt; Multicast routing&lt;BR /&gt; Threat Detection&lt;BR /&gt; Unified Communications&lt;BR /&gt; QoS&lt;BR /&gt; &lt;SPAN style="color: #3366ff;"&gt;Remote access VPN. (Site-to-site VPN is supported.) &amp;lt;--- THIS&lt;/SPAN&gt;&lt;BR /&gt;--------------------------------------------------------&lt;/P&gt;
&lt;P&gt;I think if you will migrates your ASAs to multiple context mode for Act/Act support, as your mentioned, putting another ASA for accepting Remote VPN would be prefered solution.&lt;/P&gt;</description>
    <pubDate>Sat, 07 Nov 2015 17:03:31 GMT</pubDate>
    <dc:creator>Akira Muranaka</dc:creator>
    <dc:date>2015-11-07T17:03:31Z</dc:date>
    <item>
      <title>DirectAccess possible with Multiple Context Mode?</title>
      <link>https://community.cisco.com/t5/network-security/directaccess-possible-with-multiple-context-mode/m-p/2795425#M175246</link>
      <description>&lt;P&gt;We have to Cisco ASA's at a customer site. At the moment they are in single context mode (active/passive) and thus used for failover.&lt;/P&gt;
&lt;P&gt;We want to change this to an active/active configuration but the problem is that we use remote access VPN. We need to find a solution for the VPN limitation&amp;nbsp;before we can implement the active/active configuration. 1 solution is put another firewall in the topology dedicated for the VPN connections.&lt;/P&gt;
&lt;P&gt;The other possible solution is using DirectAccess within Windows.&lt;/P&gt;
&lt;P&gt;I would like to know if this&amp;nbsp;is supported&amp;nbsp;when both ASA's are&amp;nbsp;multiple context mode. I cannot find&amp;nbsp;an answer to this&amp;nbsp;anywhere. Also if someone knows this in depth, why is VPN not working in a active/active configuration? I understand the 2 ASA's will behave as one single virtual machine, but what exactly is the reason it doesn't work in multiple context mode? Also &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1761"&gt;@cisco&lt;/a&gt; when will remote access VPN be supported in multiple context mode?&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:50:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/directaccess-possible-with-multiple-context-mode/m-p/2795425#M175246</guid>
      <dc:creator>a.agoudi1</dc:creator>
      <dc:date>2019-03-12T06:50:20Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/directaccess-possible-with-multiple-context-mode/m-p/2795426#M175248</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Unfortunately, security context on multiple context mode (or Act/Act pair) is not real virtual machine such as virtual machine on ESXi or VMware Workstation. Security context will be behaving a virtual firewall, but it is not perfect one. So it has some limitations (e.g. VPN, Routing, QoS, etc)&lt;/P&gt;
&lt;P&gt;Multiple context mode started to support Site-to-site VPN from 9.0. Therefore, RemoteVPN might be supported in the future.., but latest ASA version 9.5 does not support Remote VPN. So the future of the support is unclear.&lt;/P&gt;
&lt;P&gt;ASA9.5:&lt;BR /&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa95/configuration/general/asa-95-general-config/ha-contexts.html#ID-2171-0000015b"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa95/configuration/general/asa-95-general-config/ha-contexts.html#ID-2171-0000015b&lt;/A&gt;&lt;BR /&gt;--------------------------------------------------------&lt;BR /&gt;Guidelines for Multiple Context Mode&lt;BR /&gt; -- snip --&lt;BR /&gt;Unsupported Features&lt;BR /&gt;Multiple context mode does not support the following features:&lt;BR /&gt; RIP&lt;BR /&gt; OSPFv3. (OSPFv2 is supported.)&lt;BR /&gt; Multicast routing&lt;BR /&gt; Threat Detection&lt;BR /&gt; Unified Communications&lt;BR /&gt; QoS&lt;BR /&gt; &lt;SPAN style="color: #3366ff;"&gt;Remote access VPN. (Site-to-site VPN is supported.) &amp;lt;--- THIS&lt;/SPAN&gt;&lt;BR /&gt;--------------------------------------------------------&lt;/P&gt;
&lt;P&gt;I think if you will migrates your ASAs to multiple context mode for Act/Act support, as your mentioned, putting another ASA for accepting Remote VPN would be prefered solution.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Nov 2015 17:03:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/directaccess-possible-with-multiple-context-mode/m-p/2795426#M175248</guid>
      <dc:creator>Akira Muranaka</dc:creator>
      <dc:date>2015-11-07T17:03:31Z</dc:date>
    </item>
    <item>
      <title>Remote access support in 9.5</title>
      <link>https://community.cisco.com/t5/network-security/directaccess-possible-with-multiple-context-mode/m-p/2795427#M175250</link>
      <description>&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-firewalls/200353-ASA-Multi-Context-Mode-Remote-Access-A.html"&gt;Remote access support in 9.5(2)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/discussion/12980056/multi-context-asa-ssl-vpn-question"&gt;https://supportforums.cisco.com/discussion/12980056/multi-context-asa-ssl-vpn-question&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Mar 2017 13:04:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/directaccess-possible-with-multiple-context-mode/m-p/2795427#M175250</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2017-03-18T13:04:18Z</dc:date>
    </item>
  </channel>
</rss>

