<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic good information - thanks for in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/managing-security-contexts-asa-multimode/m-p/2446390#M267357</link>
    <description>&lt;P&gt;good information - thanks for sharing your resolution. +5&lt;/P&gt;&lt;P&gt;FYI I tested SNMP by snmpwalking a multi-context firewall. Admin context has only management interface allocated and thus only gives me an ifIndex for that single interface. I had to walk the production context to get an ifIndex (and associated counters) from one of their interfaces.&lt;/P&gt;</description>
    <pubDate>Wed, 23 Apr 2014 13:27:14 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2014-04-23T13:27:14Z</dc:date>
    <item>
      <title>Managing security contexts ASA multimode</title>
      <link>https://community.cisco.com/t5/network-security/managing-security-contexts-asa-multimode/m-p/2446388#M267353</link>
      <description>&lt;P&gt;We use a pair of ASA 5585's in a multimode active/active setup. I'm able to set up and access the management interface for the admin context easily, but I'm having trouble setting up management interfaces for the other contexts.&amp;nbsp;I'm sure I'm missing a fundamental config or understanding...&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Here is my summariezed admin context mgmt config&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;_______________________&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;BR /&gt;&amp;nbsp;management-only&lt;BR /&gt;&amp;nbsp;nameif management&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.199.0.220 255.255.255.0 standby 10.199.0.221&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;route management 0.0.0.0 0.0.0.0 10.199.0.1 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Here is the summarized context1 mgmt config&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;_______________________&lt;/P&gt;&lt;P&gt;interface Management0/0.1&lt;BR /&gt;&amp;nbsp;management-only&lt;BR /&gt;&amp;nbsp;nameif management&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.199.0.170 255.255.255.0&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;route management 0.0.0.0 0.0.0.0 10.199.0.1 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Here is the summarized system config:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;_______________________&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Management0/0.1&lt;BR /&gt;&amp;nbsp;description&amp;nbsp;Context1 Management&lt;BR /&gt;&amp;nbsp;vlan 7&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;context&amp;nbsp;Context1&lt;BR /&gt;&amp;nbsp; description Context1_VLAN177&lt;BR /&gt;&amp;nbsp; allocate-interface GigabitEthernet0/5.1&lt;BR /&gt;&amp;nbsp; allocate-interface Management0/0.1&lt;BR /&gt;&amp;nbsp; allocate-interface TenGigabitEthernet0/8.1&lt;BR /&gt;&amp;nbsp; config-url disk0:/dmzmt.cfg&lt;BR /&gt;&amp;nbsp; join-failover-group 1&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am unable to ping the context1 management interface, whereas I can ping (and ssh) to the admin context. One thing that I think might be preventing ping is that Management0/0.1 is assigned to Vlan7. This is an arbitrary VLAN and is not actually running across any links, but the ASA won't let me assign the Management0/0.1&amp;nbsp;interface to Context1 unless it's configured&amp;nbsp;with a VLAN not already in use (which is by the way frustrating). Then again, in Context1 the Management0.0.1 interface is assigned to the default VLAN, just like in the Admin context, so does that even matter?&lt;/P&gt;&lt;P&gt;I'm sure I'm missing something easy or maybe have a misunderstanding on how to configure management access to the other contexts. This is my first multimode setup.&amp;nbsp;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Logan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:06:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/managing-security-contexts-asa-multimode/m-p/2446388#M267353</guid>
      <dc:creator>Logan Kampsnider</dc:creator>
      <dc:date>2019-03-12T04:06:43Z</dc:date>
    </item>
    <item>
      <title>FYI - I spoke with someone at</title>
      <link>https://community.cisco.com/t5/network-security/managing-security-contexts-asa-multimode/m-p/2446389#M267356</link>
      <description>&lt;P&gt;FYI - I spoke with someone at Cisco and you have to put each management port that you configure for contexts into a separate VLAN. So, if you have 5 contexts with each having a management port, that's 5 VLANs. Fairly annoying as I'd hoped to keep all management traffic under the same VLAN.&lt;/P&gt;&lt;P&gt;That that said, I think we'll end up just managing the admin context with the management port and manage all the other contexts via the inside IP gig port address.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2014 17:09:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/managing-security-contexts-asa-multimode/m-p/2446389#M267356</guid>
      <dc:creator>Logan Kampsnider</dc:creator>
      <dc:date>2014-04-22T17:09:43Z</dc:date>
    </item>
    <item>
      <title>good information - thanks for</title>
      <link>https://community.cisco.com/t5/network-security/managing-security-contexts-asa-multimode/m-p/2446390#M267357</link>
      <description>&lt;P&gt;good information - thanks for sharing your resolution. +5&lt;/P&gt;&lt;P&gt;FYI I tested SNMP by snmpwalking a multi-context firewall. Admin context has only management interface allocated and thus only gives me an ifIndex for that single interface. I had to walk the production context to get an ifIndex (and associated counters) from one of their interfaces.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2014 13:27:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/managing-security-contexts-asa-multimode/m-p/2446390#M267357</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-04-23T13:27:14Z</dc:date>
    </item>
    <item>
      <title>Well after some more</title>
      <link>https://community.cisco.com/t5/network-security/managing-security-contexts-asa-multimode/m-p/2446391#M267358</link>
      <description>&lt;P&gt;Well after some more searching I found a guy who had put the same VLAN on all the context management interfaces, so to me it sounds like what I originally want to do is possible. Here's the link to that post: &lt;A href="https://www.google.com/url?sa=t&amp;amp;rct=j&amp;amp;q=&amp;amp;esrc=s&amp;amp;source=web&amp;amp;cd=2&amp;amp;cad=rja&amp;amp;uact=8&amp;amp;ved=0CDIQFjAB&amp;amp;url=https%3A%2F%2Fsupportforums.cisco.com%2Fdiscussion%2F11112171%2Fsame-vlan-interfaces-different-ip-address-two-or-more-multiple-context&amp;amp;ei=cMNXU7e6BuLC2QX-lYDQCg&amp;amp;usg=AFQjCNHNug1HabWdH6qDt431nTd9rLHLmQ&amp;amp;sig2=7XXc6iNOZi8CDIJZCBMBdg"&gt;https://www.google.com/url?sa=t&amp;amp;rct=j&amp;amp;q=&amp;amp;esrc=s&amp;amp;source=web&amp;amp;cd=2&amp;amp;cad=rja&amp;amp;uact=8&amp;amp;ved=0CDIQFjAB&amp;amp;url=https%3A%2F%2Fsupportforums.cisco.com%2Fdiscussion%2F11112171%2Fsame-vlan-interfaces-different-ip-address-two-or-more-multiple-context&amp;amp;ei=cMNXU7e6BuLC2QX-lYDQCg&amp;amp;usg=AFQjCNHNug1HabWdH6qDt431nTd9rLHLmQ&amp;amp;sig2=7XXc6iNOZi8CDIJZCBMBdg&lt;/A&gt;&lt;/P&gt;&lt;P&gt;So I guess I'd like to ask the Cisco community again if they know if there is anyway to assign&amp;nbsp;the Management interfaces on multiple contexts to the same VLAN, and therefore an IP on the same subnet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Logan&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2014 13:57:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/managing-security-contexts-asa-multimode/m-p/2446391#M267358</guid>
      <dc:creator>Logan Kampsnider</dc:creator>
      <dc:date>2014-04-23T13:57:04Z</dc:date>
    </item>
    <item>
      <title>So, to continue my one-sided</title>
      <link>https://community.cisco.com/t5/network-security/managing-security-contexts-asa-multimode/m-p/2446392#M267359</link>
      <description>&lt;P&gt;So, to continue my one-sided conversation I finally figured out how to do this. It IS possible to share the management interface across multiple-contexts on the SAME vlan, despite what the rest of the Internet (or Cisco) says.&lt;/P&gt;&lt;P&gt;You simply need to allococate the main interface, Management0/0, and not the sub-interfaces, to whatever contexts you want to assign a management IP to. You'll notice however that you cannot assign a VLAN to a main interface, but you can with the sub-interfaces,&amp;nbsp;within system.&lt;/P&gt;&lt;P&gt;So with this in mind we can assume&amp;nbsp;the main interface, Management0/0, will operate on VLAN 1 since we can't assign it to a different vlan. In my case we needed management traffic to traverse VLAN 199. All I did to remedy this is make sure the switch port Management0/0 connected to was configured as an Access Port on VLAN 199. Viola, everything works.&lt;/P&gt;&lt;P&gt;Hope this information is useful to others. I know many people just use the inside interface of each context to manage it, but I think using the management interface (and subnet) for management purposes across all contexts is cleaner.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2014 15:59:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/managing-security-contexts-asa-multimode/m-p/2446392#M267359</guid>
      <dc:creator>Logan Kampsnider</dc:creator>
      <dc:date>2014-04-23T15:59:06Z</dc:date>
    </item>
  </channel>
</rss>

