<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thank You Erik in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-9-3-multiple-context-ipv6-between-contexts/m-p/2579354#M205373</link>
    <description>&lt;P&gt;Thank You Erik&lt;/P&gt;</description>
    <pubDate>Sun, 30 Nov 2014 12:10:11 GMT</pubDate>
    <dc:creator>ol_th0001</dc:creator>
    <dc:date>2014-11-30T12:10:11Z</dc:date>
    <item>
      <title>ASA 9.3 - Multiple Context - IPv6 between contexts</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-3-multiple-context-ipv6-between-contexts/m-p/2579349#M205368</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We have a ASA 5525 with &lt;STRONG&gt;multiple contexts&amp;nbsp;&lt;/STRONG&gt;running &lt;STRONG&gt;9.3(1)&lt;/STRONG&gt;.&amp;nbsp;We are having troubles routing &lt;STRONG&gt;IPv6 &lt;/STRONG&gt;traffic &lt;STRONG&gt;between contexts&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Assume: Internet ---- &amp;lt;ASA "Internet" Context&amp;gt; --- &amp;lt;ASA "Customer A" Context&amp;gt; ---- End Host&lt;/P&gt;&lt;P&gt;We have configured&amp;nbsp;static to route from internet to end host and the other way around.&lt;BR /&gt;We do not see IPv6 neighbors getting established between the two ASA contexts. IPv4 is working just fine.&lt;/P&gt;&lt;P&gt;Does anyone have an idea what I missed in the configuration? All interfaces (in all contexts) are using unique mac addresses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik Tamminga&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Customer ASA&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;interface CustomerAInside&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 172.29.10.10 255.255.255.0 standby 172.29.10.11&lt;BR /&gt;&amp;nbsp;ipv6 address 2001:abcd:0:a::a/64 standby 2001:abcd:0:a::b&lt;BR /&gt;&amp;nbsp;ipv6 enable&lt;BR /&gt;&amp;nbsp;ipv6 nd suppress-ra&lt;BR /&gt;!&lt;BR /&gt;interface PublicDMZ&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 1.2.3.10 255.255.255.0&lt;BR /&gt;&amp;nbsp;ipv6 address 2001:abcd:0:ff01::a/64 standby 2001:abcd:0:ff01::b&lt;BR /&gt;&amp;nbsp;ipv6 enable&lt;BR /&gt;&amp;nbsp;ipv6 nd suppress-ra&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;ipv6 route outside ::/0 2001:abcd:0:ff01::1&lt;BR /&gt;ipv6 route inside 2001:abcd::/48 2001:abcd:0:a::1&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Internet ASA:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Outside&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 7.8.9.10 255.255.255.0&lt;BR /&gt;&amp;nbsp;ipv6 address 2001:7890:1400:18::2/64&lt;BR /&gt;&amp;nbsp;ipv6 enable&lt;BR /&gt;&amp;nbsp;ipv6 nd suppress-ra&lt;BR /&gt;!&lt;BR /&gt;interface PublicDMZ&lt;BR /&gt;&amp;nbsp;nameif public-dmz&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 1.2.3.10 255.255.255.0&lt;BR /&gt;&amp;nbsp;ipv6 address 2001:abcd:0:ff01::1/64&lt;BR /&gt;&amp;nbsp;ipv6 enable&lt;BR /&gt;&amp;nbsp;ipv6 nd suppress-ra&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ipv6 route outside ::/0 2001:7890:1400:18::1&lt;BR /&gt;ipv6 route public-dmz&amp;nbsp;2001:abcd::/48 2001:abcd:0:ff01::a&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:03:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-3-multiple-context-ipv6-between-contexts/m-p/2579349#M205368</guid>
      <dc:creator>etamminga</dc:creator>
      <dc:date>2019-03-12T05:03:04Z</dc:date>
    </item>
    <item>
      <title>Hmm this is a bit of</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-3-multiple-context-ipv6-between-contexts/m-p/2579350#M205369</link>
      <description>&lt;P&gt;Hmm this is a bit of speculation but IPv6 relies heavily on multicast. I know that when we tried to do OSPF routing (IPv4) between contexts it would not work since multicast is not supported between either shared or unshared interfaces in multiple context mode.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2014 13:08:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-3-multiple-context-ipv6-between-contexts/m-p/2579350#M205369</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-11-10T13:08:22Z</dc:date>
    </item>
    <item>
      <title>Hi,Thanks. I suspected</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-3-multiple-context-ipv6-between-contexts/m-p/2579351#M205370</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks. I suspected something like this. All IPv6 manual pages say it is supported in multi-context but do not specifically mention shared interfaces.&lt;/P&gt;&lt;P&gt;I've created a TAC case to be sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;</description>
      <pubDate>Wed, 12 Nov 2014 14:31:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-3-multiple-context-ipv6-between-contexts/m-p/2579351#M205370</guid>
      <dc:creator>etamminga</dc:creator>
      <dc:date>2014-11-12T14:31:50Z</dc:date>
    </item>
    <item>
      <title>HiI have exactly the same</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-3-multiple-context-ipv6-between-contexts/m-p/2579352#M205371</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I have exactly the same problem.&lt;/P&gt;&lt;P&gt;Did you get it sorted and if what was the solution.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 30 Nov 2014 11:00:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-3-multiple-context-ipv6-between-contexts/m-p/2579352#M205371</guid>
      <dc:creator>ol_th0001</dc:creator>
      <dc:date>2014-11-30T11:00:41Z</dc:date>
    </item>
    <item>
      <title>Hi,It turns out to be not</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-3-multiple-context-ipv6-between-contexts/m-p/2579353#M205372</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It turns out to be not supported on ASA 9.3. The IPv6 neighbor mechanism relies on multicasting and multicasting (ipv4 &amp;amp; ipv6) is not supported on shared interfaces.&lt;/P&gt;&lt;P&gt;Two ways to work around it:&lt;/P&gt;&lt;P&gt;- Define static neighbors. Works fine if you only have 2-3 contexts. Too much work if you need more contexts. You need to setup a full mesh of routes and static neighbors.&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Have some other device in the shared network do routing (router on a stick) for IPv6.&lt;/P&gt;&lt;P&gt;I did the last. I use one context for Internet-&amp;gt;DMZ traffic and multiple other contexts (one per customer) to handle DMZ-&amp;gt;Customer X traffic. The switch in the DMZ VLAN was able to do IPv6 routing and I now have all my routes from all contexts pointed to the L3 interface on the DMZ VLAN of the switch. And on the switch routes pointing to all Customers/contexts&amp;nbsp;and a default.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;</description>
      <pubDate>Sun, 30 Nov 2014 11:18:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-3-multiple-context-ipv6-between-contexts/m-p/2579353#M205372</guid>
      <dc:creator>etamminga</dc:creator>
      <dc:date>2014-11-30T11:18:50Z</dc:date>
    </item>
    <item>
      <title>Thank You Erik</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-3-multiple-context-ipv6-between-contexts/m-p/2579354#M205373</link>
      <description>&lt;P&gt;Thank You Erik&lt;/P&gt;</description>
      <pubDate>Sun, 30 Nov 2014 12:10:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-3-multiple-context-ipv6-between-contexts/m-p/2579354#M205373</guid>
      <dc:creator>ol_th0001</dc:creator>
      <dc:date>2014-11-30T12:10:11Z</dc:date>
    </item>
  </channel>
</rss>

