<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Multi-Context + sub-Interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-multi-context-sub-interfaces/m-p/2373979#M306485</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can't run Active/Passive failover with multiple contexts. You must run Active/Active. You can set one firewall to be Primary Active for all contexts if you want it to operate a little more like Active/Passive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 01 Jan 2014 00:22:30 GMT</pubDate>
    <dc:creator>Collin Clark</dc:creator>
    <dc:date>2014-01-01T00:22:30Z</dc:date>
    <item>
      <title>ASA Multi-Context + sub-Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa-multi-context-sub-interfaces/m-p/2373978#M306481</link>
      <description>&lt;P&gt;I am trying to configure two ASA 5525 in Active/Standby mode using multiple contexts and is in transparent mode. We are using trunk ports which are ether-channeled. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem we are having is the the ASA's alternate betwen active/standby with the following messages being seen&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Switching to Active&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Dec 31 2013 10:23:48: %ASA-1-104001: (Secondary) Switching to ACTIVE - Other unit wants me Active. Primary unit switch reason: Interface check.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Dec 31 2013 10:23:58: %ASA-1-105003: (Secondary) Monitoring on interface management waiting&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Dec 31 2013 10:24:08: %ASA-1-105004: (Secondary) Monitoring on interface management normal&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Switching to Standby&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Dec 31 2013 10:24:16: %ASA-1-104002: (Secondary) Switching to STANDBY - Interface check&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Dec 31 2013 10:24:38: %ASA-1-104004: (Secondary) Switching to OK.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the configuration from the ASA's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Active ASA&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Ethernet0/0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; speed 100&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; duplex full&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; channel-group 1 mode on&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Ethernet0/1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; speed 100&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; duplex full&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; channel-group 1 mode on&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Ethernet0/2&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; speed 100&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; duplex full&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; channel-group 2 mode on&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Ethernet0/3&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; speed 100&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; duplex full&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; channel-group 2 mode on&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Management0/0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Port-channel1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; speed 100&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; duplex full&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Port-channel1.105&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; vlan 105&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Port-channel1.106&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; vlan 106&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Port-channel1.107&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; vlan 107&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Port-channel1.108&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; vlan 108&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Port-channel1.155&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; vlan 155&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Port-channel1.156&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; vlan 156&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Port-channel1.157&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; vlan 157&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Port-channel1.158&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; vlan 158&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Port-channel2&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; speed 100&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; duplex full&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Port-channel2.801&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; description LAN Failover Interface&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; vlan 801&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Port-channel2.802&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; description STATE Failover Interface&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; vlan 802&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;failover&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;failover lan unit primary&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;failover lan interface LAN-Failover Port-channel2.801&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;failover link State-Failover Port-channel2.802&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;failover interface ip LAN-Failover 10.xx.xx.12 255.255.255.248 standby 10.xx.xx.13&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;failover interface ip State-Failover 10.xx.xx.20 255.255.255.248 standby 10.xx.xx.21&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;admin-context admin&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;context admin&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; allocate-interface Management0/0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; config-url disk0:/admin.cfg&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;context Context-1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; allocate-interface Port-channel1.105-Port-channel1.106&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; allocate-interface Port-channel1.155-Port-channel1.156&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; config-url disk0:/Context-1.cfg&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;context Context-2&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; allocate-interface Port-channel1.107-Port-channel1.108&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; allocate-interface Port-channel1.157-Port-channel1.158&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp; config-url disk0:/Context-2.cfg&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Standby ASA&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The same configuration except apart from the failover commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;failover&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;failover lan unit secondary&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;failover lan interface LAN-Failover Port-channel2.801&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;failover link State-Failover Port-channel2.802&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;failover interface ip LAN-Failover 10.xx.xx.12 255.255.255.248 standby 10.xx.xx.13&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;failover interface ip State-Failover 10.xx.xx.20 255.255.255.248 standby 10.xx.xx.21&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Can anyone see any issues with this configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-multi-context-sub-interfaces/m-p/2373978#M306481</guid>
      <dc:creator>John Quick</dc:creator>
      <dc:date>2019-03-12T03:23:44Z</dc:date>
    </item>
    <item>
      <title>ASA Multi-Context + sub-Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa-multi-context-sub-interfaces/m-p/2373979#M306485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can't run Active/Passive failover with multiple contexts. You must run Active/Active. You can set one firewall to be Primary Active for all contexts if you want it to operate a little more like Active/Passive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jan 2014 00:22:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-multi-context-sub-interfaces/m-p/2373979#M306485</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2014-01-01T00:22:30Z</dc:date>
    </item>
    <item>
      <title>ASA Multi-Context + sub-Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa-multi-context-sub-interfaces/m-p/2373980#M306489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;or use version 9.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;Posted by WebUser &lt;A href="http://www.facebook.com/profile.php?id=100002677647017"&gt;Erik Boss &lt;/A&gt; from &lt;A href="http://apps.facebook.com/ciscosupport/"&gt;Cisco Support Community App &lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jan 2014 14:53:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-multi-context-sub-interfaces/m-p/2373980#M306489</guid>
      <dc:creator>fb_webuser</dc:creator>
      <dc:date>2014-01-01T14:53:57Z</dc:date>
    </item>
    <item>
      <title>ASA Multi-Context + sub-Interfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa-multi-context-sub-interfaces/m-p/2373981#M306494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I am running version 9.1(1) and it works fine until I failover to the standby firewall where it then flips between being active or standby every 30-60 seconds.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jan 2014 08:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-multi-context-sub-interfaces/m-p/2373981#M306494</guid>
      <dc:creator>John Quick</dc:creator>
      <dc:date>2014-01-02T08:16:41Z</dc:date>
    </item>
  </channel>
</rss>

