<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can&amp;quot;t ping sub interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-quot-t-ping-sub-interface/m-p/3936821#M26747</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/321949"&gt;@Jean Paul Enerst&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When you configure subinterfaces, the physical interface should not have addressing. Maybe, that's why only that interface answers you. I suggest you remove the address from the physical interface and assign that address to another subinterface, enabling the corresponding vlan on the switch.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.networkstraining.com/how-to-configure-vlan-subinterfaces-cisco-asa-5500-firewall/" target="_blank"&gt;https://www.networkstraining.com/how-to-configure-vlan-subinterfaces-cisco-asa-5500-firewall/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Oct 2019 23:49:37 GMT</pubDate>
    <dc:creator>luis_cordova</dc:creator>
    <dc:date>2019-10-07T23:49:37Z</dc:date>
    <item>
      <title>Can"t ping sub interface</title>
      <link>https://community.cisco.com/t5/network-security/can-quot-t-ping-sub-interface/m-p/3936811#M26727</link>
      <description>&lt;P&gt;Hi Gents,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is an easy one, but i can"t seem to figure it out. I have a pair of 5515X in failover with three interfaces(inside, outside, DMZ) and a sub-interface(uses the DMZ as main). So i use the DMZ interface to create a sub-interface, i had noticed that the Sub-interface did not have a standby IP when i added that standby IP... Failover status of the FW failed, i have to remove the standby IP, perform a no interface-monitoring , and reset the failover.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have double-checked everything connected to the secondary devices, but still no luck!&amp;nbsp; Everything works as expected when the primary device is running, but if a failover occurs, devices connected to the sub-interface subnet can"t pass traffic! Below is the configuration...&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;BR /&gt;speed 1000&lt;BR /&gt;duplex full&lt;BR /&gt;nameif dmz&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 192.168.xxx.1 255.255.255.0 standby 192.168.xxx.2&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2.xx&lt;BR /&gt;vlan xx&lt;BR /&gt;nameif coop&lt;BR /&gt;security-level 25&lt;BR /&gt;ip address 172.16.x.x 255.255.255.0&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2019 23:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-quot-t-ping-sub-interface/m-p/3936811#M26727</guid>
      <dc:creator>Jean Paul Enerst</dc:creator>
      <dc:date>2019-10-07T23:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Can"t ping sub interface</title>
      <link>https://community.cisco.com/t5/network-security/can-quot-t-ping-sub-interface/m-p/3936821#M26747</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/321949"&gt;@Jean Paul Enerst&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When you configure subinterfaces, the physical interface should not have addressing. Maybe, that's why only that interface answers you. I suggest you remove the address from the physical interface and assign that address to another subinterface, enabling the corresponding vlan on the switch.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.networkstraining.com/how-to-configure-vlan-subinterfaces-cisco-asa-5500-firewall/" target="_blank"&gt;https://www.networkstraining.com/how-to-configure-vlan-subinterfaces-cisco-asa-5500-firewall/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2019 23:49:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-quot-t-ping-sub-interface/m-p/3936821#M26747</guid>
      <dc:creator>luis_cordova</dc:creator>
      <dc:date>2019-10-07T23:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Can"t ping sub interface</title>
      <link>https://community.cisco.com/t5/network-security/can-quot-t-ping-sub-interface/m-p/3936955#M26768</link>
      <description>&lt;P&gt;instead, you can try below : (make sure other switch port config trunk to allow the vlans for the subinterface)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;interface GigabitEthernet0/2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;no nameif&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;no ip address&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;no shutdown&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;interface GigabitEthernet0/2.xx&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;speed 1000&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;duplex full&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nameif dmz&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;security-level 50&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;interface GigabitEthernet0/2.xx&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;vlan xx&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nameif coop&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;security-level 25&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ip address 172.16.x.x 255.255.255.0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Other note I do not believe failover is recommended to configure using subinterfaces.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Look for some recommendation document.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/ha_overview.html#wp1077627" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/ha_overview.html#wp1077627&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 07:59:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-quot-t-ping-sub-interface/m-p/3936955#M26768</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-10-08T07:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can"t ping sub interface</title>
      <link>https://community.cisco.com/t5/network-security/can-quot-t-ping-sub-interface/m-p/3937451#M26786</link>
      <description>&lt;P&gt;Although it is not common, using an IP on the physical interface while also having a subinterface should still work.&amp;nbsp; I would suggest trying to add a standby IP to the sub interface.&amp;nbsp; I think the issue might be that MAC address is still hung up on the primary which has "failed".&amp;nbsp; Adding a standby IP will ensure that the primary MAC will follow to the secondary in the case of failover.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;interface GigabitEthernet0/2.xx&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;vlan xx&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nameif coop&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;security-level 25&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ip address 172.16.x.x 255.255.255.0 &lt;U&gt;&lt;STRONG&gt;standby 172.16.x.2&lt;/STRONG&gt;&lt;/U&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2019 21:09:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-quot-t-ping-sub-interface/m-p/3937451#M26786</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2019-10-08T21:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Can"t ping sub interface</title>
      <link>https://community.cisco.com/t5/network-security/can-quot-t-ping-sub-interface/m-p/3937951#M26805</link>
      <description>&lt;P&gt;Thanks Marius. But i have tried that, and i think that iève mentioned that ebove.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i added the standby IP,&amp;nbsp; failover status changes for a few sec then failed. The secondaray device aka standby device can ping that IP but i can"t ping the active IP for that interface. I have double check the trunk ports and stuff it seems all good to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will try the above suggestion because they have not tried them yet, but i think the issue might be something else.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you all, will update soon.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 14:33:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-quot-t-ping-sub-interface/m-p/3937951#M26805</guid>
      <dc:creator>Jean Paul Enerst</dc:creator>
      <dc:date>2019-10-09T14:33:07Z</dc:date>
    </item>
  </channel>
</rss>

