<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Transparent ASA BPDU issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/transparent-asa-bpdu-issue/m-p/2635282#M196999</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;Hopefully someone will be able to help, I have an ASA running 8.4 in Multi-context transparent mode.&lt;/P&gt;&lt;P&gt;The problem I am seeing this is passing BPDU (I see this is expect in this mode)&amp;nbsp;which is making the network converge.&lt;/P&gt;&lt;P&gt;Which is the best way to stop this, I had thought an ACL&amp;nbsp;on the ASA but I think you can have only 1 type.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks MJ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:30:56 GMT</pubDate>
    <dc:creator>mj11</dc:creator>
    <dc:date>2019-03-12T05:30:56Z</dc:date>
    <item>
      <title>Transparent ASA BPDU issue</title>
      <link>https://community.cisco.com/t5/network-security/transparent-asa-bpdu-issue/m-p/2635282#M196999</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;Hopefully someone will be able to help, I have an ASA running 8.4 in Multi-context transparent mode.&lt;/P&gt;&lt;P&gt;The problem I am seeing this is passing BPDU (I see this is expect in this mode)&amp;nbsp;which is making the network converge.&lt;/P&gt;&lt;P&gt;Which is the best way to stop this, I had thought an ACL&amp;nbsp;on the ASA but I think you can have only 1 type.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks MJ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:30:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-asa-bpdu-issue/m-p/2635282#M196999</guid>
      <dc:creator>mj11</dc:creator>
      <dc:date>2019-03-12T05:30:56Z</dc:date>
    </item>
    <item>
      <title>You are right, you cannot mix</title>
      <link>https://community.cisco.com/t5/network-security/transparent-asa-bpdu-issue/m-p/2635283#M197000</link>
      <description>&lt;P&gt;You are right, you cannot mix different types of access lists.&lt;/P&gt;&lt;P&gt;Here is what I&amp;nbsp;can think as a workaround to achieve your requirement.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;Try creating a different access-list to block BPDU and apply it on different interface.&lt;/P&gt;&lt;P&gt;For eg:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Say you have two acl:&lt;/P&gt;&lt;P&gt;access-list 1 ethertype deny bpdu&lt;/P&gt;&lt;P&gt;access-list 1 ethertype permit any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list 2 extended permit ip any any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;you can apply acl 1 at one interface to block bpdu&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;and acl 2 on the other interface to filter other traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, by doing this you will&amp;nbsp;inspecting same&amp;nbsp;traffic flow at two different interfaces by different type of ACLs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2015 07:17:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-asa-bpdu-issue/m-p/2635283#M197000</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-02-18T07:17:08Z</dc:date>
    </item>
    <item>
      <title>Hi Thanks for the response, I</title>
      <link>https://community.cisco.com/t5/network-security/transparent-asa-bpdu-issue/m-p/2635284#M197001</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the response, I will let you know how I get on.&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Feb 2015 11:19:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/transparent-asa-bpdu-issue/m-p/2635284#M197001</guid>
      <dc:creator>mj11</dc:creator>
      <dc:date>2015-02-19T11:19:52Z</dc:date>
    </item>
  </channel>
</rss>

