<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cascading Contexts on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cascading-contexts-on-asa/m-p/2371320#M308747</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have two options when wanting to send traffic between the contexts.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;allocate a physical interface to each context and then connect those interface to a switch in a dedicated transport VLAN.&lt;/LI&gt;&lt;LI&gt;Assign sub interfaces of the same interface to each context and assign an IP in different subnet to them&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; context 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; int ten0/1.101&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; security-level 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nameif Context1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address 10.10.10.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; context 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; int ten0/1.102&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; security-level 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nameif Contex2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address 10.10.11.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the second option the traffic will hit the interface and then do a U-turn and come back in the same interface.&amp;nbsp; The ASA will act as a router between the contexts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/fwmode.html#wp1220886" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/fwmode.html#wp1220886&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please rate all helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Nov 2013 19:26:50 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2013-11-20T19:26:50Z</dc:date>
    <item>
      <title>Cascading Contexts on ASA</title>
      <link>https://community.cisco.com/t5/network-security/cascading-contexts-on-asa/m-p/2371319#M308745</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to set up a new pair of ASA's in active-standby configuration, on the ASA I need to configure 2 contexts.&lt;/P&gt;&lt;P&gt;Each of these contexts will have about 5 interfaces that connect to the network, now comes the part that I don't seem to grasp, I also need to interconnect the 2 contexts because there will be some flows that need to go from networks that are connected on Context A to networks that are connected on Context B and vice versa.&lt;/P&gt;&lt;P&gt;This 'transit network' in between the 2 contexts doesn't really leave the ASA, but I think I still need to assign an interface to it and connect it on a switch ?&lt;/P&gt;&lt;P&gt;Do I really need to do that ? Do I need to assign 1 interface to the context A and another one to the context B and have both of them connected to switchports in the same Vlan then ? And what about the failover configuration of this segment between the 2 contexts ?&lt;/P&gt;&lt;P&gt;Also in the documentation I saw something about using unique mac addresses in case of cascading contexts, do I need to do this ? And how exactly do I do this ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be much appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:06:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cascading-contexts-on-asa/m-p/2371319#M308745</guid>
      <dc:creator>Cisco Ham</dc:creator>
      <dc:date>2019-03-12T03:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cascading Contexts on ASA</title>
      <link>https://community.cisco.com/t5/network-security/cascading-contexts-on-asa/m-p/2371320#M308747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have two options when wanting to send traffic between the contexts.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;allocate a physical interface to each context and then connect those interface to a switch in a dedicated transport VLAN.&lt;/LI&gt;&lt;LI&gt;Assign sub interfaces of the same interface to each context and assign an IP in different subnet to them&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; context 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; int ten0/1.101&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; security-level 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nameif Context1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address 10.10.10.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; context 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; int ten0/1.102&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; security-level 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nameif Contex2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address 10.10.11.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the second option the traffic will hit the interface and then do a U-turn and come back in the same interface.&amp;nbsp; The ASA will act as a router between the contexts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/fwmode.html#wp1220886" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/fwmode.html#wp1220886&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please rate all helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Nov 2013 19:26:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cascading-contexts-on-asa/m-p/2371320#M308747</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2013-11-20T19:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cascading Contexts on ASA</title>
      <link>https://community.cisco.com/t5/network-security/cascading-contexts-on-asa/m-p/2371321#M308749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marius,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your answer but I'm afraid I'm even more confused than before. My ASA's will be in routing mode, I don't see how these 2 contexts will be able to communicate with eachother over this transport vlan if the IP addresses on both ends are in different IP subnets.&lt;/P&gt;&lt;P&gt;Maybe I didn't make myself clear enough, I made a few simplified draw pictures of what I want to do, this is the locical setup :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/0/8/166803-Logical%20setup.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The physical setup would be something like this :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/0/8/166804-Physical%20setup.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this make sense ? Do I really need to waste 2 Interfaces on each ASA for this transit Vlan between the 2 Contexts ?&lt;/P&gt;&lt;P&gt;I was planning to assign a /29 network to this transit vlan because I need at least 4 IP's in this range.&lt;/P&gt;&lt;P&gt;Do I need to use this "unique mac addresses" feature in this setup ?&lt;/P&gt;&lt;P&gt;Or am I seeing this completely wrong and is there a better way to achieve this ?&lt;/P&gt;&lt;P&gt;The documentation around cascading contexts seems to be very limited, I really need some guidance here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 11:01:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cascading-contexts-on-asa/m-p/2371321#M308749</guid>
      <dc:creator>Cisco Ham</dc:creator>
      <dc:date>2013-11-21T11:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cascading Contexts on ASA</title>
      <link>https://community.cisco.com/t5/network-security/cascading-contexts-on-asa/m-p/2371322#M308750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I meant to say that the shared interface needs to be on the same network. (must have been thinking about something else when I was writing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you do not need to waste 2 interfaces on the ASA to get this working, however, if your security policy dictates that you need to have the two contexts physically seperate then you must use two interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;context1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface outside&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 10.1.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface inside&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.0.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 10.0.10.0 255.255.255.0 10.1.0.2 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;context2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface outside&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 10.1.0.2 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface inside&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.0.10.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 10.0.0.0 255.255.255.0 10.1.0.1 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 14:30:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cascading-contexts-on-asa/m-p/2371322#M308750</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2013-11-21T14:30:12Z</dc:date>
    </item>
  </channel>
</rss>

