<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can I use sub-interfaces for (Failover lan interface and link st in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-i-use-sub-interfaces-for-failover-lan-interface-and-link/m-p/2348097#M311401</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have not mentioned all the interfaces that the ASA has.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the original ASA5500 Series I tend to use the Management0/0 port for the Failover purpose. I use the Management0/0 for both of the purposes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or are you perhaps using the Management0/0 interface at the moment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is one example configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover lan unit primary&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover lan interface failover Management0/0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover key &lt;KEY&gt;&lt;/KEY&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover replication http&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover link failover Management0/0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover interface ip failover 10.10.10.1 255.255.255.0 standby 10.10.10.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont know if there is a command called &lt;STRONG&gt;"failover link state"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll have to say that I have never configured or tried to configure a Sub Interface as an actual Failover interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Oct 2013 17:50:40 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-10-07T17:50:40Z</dc:date>
    <item>
      <title>Can I use sub-interfaces for (Failover lan interface and link state)</title>
      <link>https://community.cisco.com/t5/network-security/can-i-use-sub-interfaces-for-failover-lan-interface-and-link/m-p/2348096#M311399</link>
      <description>&lt;P&gt;Hi All, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I have two ASA 5510(8.2). I am planing to make Active/standby. I have only 4 interfaces on each ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Ethernet0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside&lt;/P&gt;&lt;P&gt;Ethernet0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside&lt;/P&gt;&lt;P&gt;Ethernet0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ&amp;nbsp; &lt;/P&gt;&lt;P&gt;Ethernet0/3.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (failover)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;As I checked cisco config and found that I need two physical interfaces (Lan failover and link state). My plan is to make subinterfaces of Ethernet0/3 and assign it to Lan failover and Link state. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;failover lan unit primary&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;failover lan interface failover &lt;SPAN style="font-size: 10pt;"&gt;Ethernet0/3.1&amp;nbsp;&amp;nbsp; &amp;lt;=========== Subinterface &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;failover lan interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;failover replication http&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;failover link state &lt;SPAN style="font-size: 10pt;"&gt;Ethernet0/3.2&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;========= &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;Subinterface Link state &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Ethernet0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside&lt;/P&gt;&lt;P&gt;Ethernet0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside&lt;/P&gt;&lt;P&gt;Ethernet0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ&amp;nbsp; &lt;/P&gt;&lt;P&gt;Ethernet0/3.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (failover Lan interface)&lt;/P&gt;&lt;P&gt;Ethernet0/3.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (Failover Link state)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Can you please confirm if it is possible that I can use subinterface for failover config instead of physical interface. Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:48:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-use-sub-interfaces-for-failover-lan-interface-and-link/m-p/2348096#M311399</guid>
      <dc:creator>Tarjeet Singh</dc:creator>
      <dc:date>2019-03-12T02:48:19Z</dc:date>
    </item>
    <item>
      <title>Can I use sub-interfaces for (Failover lan interface and link st</title>
      <link>https://community.cisco.com/t5/network-security/can-i-use-sub-interfaces-for-failover-lan-interface-and-link/m-p/2348097#M311401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have not mentioned all the interfaces that the ASA has.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the original ASA5500 Series I tend to use the Management0/0 port for the Failover purpose. I use the Management0/0 for both of the purposes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or are you perhaps using the Management0/0 interface at the moment?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is one example configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover lan unit primary&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover lan interface failover Management0/0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover key &lt;KEY&gt;&lt;/KEY&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover replication http&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover link failover Management0/0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;failover interface ip failover 10.10.10.1 255.255.255.0 standby 10.10.10.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont know if there is a command called &lt;STRONG&gt;"failover link state"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll have to say that I have never configured or tried to configure a Sub Interface as an actual Failover interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 17:50:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-use-sub-interfaces-for-failover-lan-interface-and-link/m-p/2348097#M311401</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-07T17:50:40Z</dc:date>
    </item>
    <item>
      <title>Can I use sub-interfaces for (Failover lan interface and link st</title>
      <link>https://community.cisco.com/t5/network-security/can-i-use-sub-interfaces-for-failover-lan-interface-and-link/m-p/2348098#M311404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks for your reply. I am not using mamangment interface.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Ethernet0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Ethernet0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Ethernet0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ &lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Ethernet0/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (failover)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Management0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Word "State" used as interface name for Ethernet3.2. It is to exchange the failover link state information. Configuring the stateful failover link.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I didnt know that I can use Managment0/0 interface. Can I use same interface for LAN Failover and Failover Link? In Cisco document, they have shown to use separate interfaces or subinterface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;============================================&lt;/P&gt;&lt;P style="margin: 0em; color: #000000; font-family: 'Courier New', Courier, mono; font-size: 11px; background-color: #ffffff;"&gt;failover link &lt;EM&gt;if_name&lt;/EM&gt; &lt;EM&gt;phy_if&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1107388" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="margin: 10px 0em 0em; color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 11px; font-weight: bold; background-color: #ffffff;"&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;A name="wp1107392" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="margin: 0em; color: #000000; font-family: 'Courier New', Courier, mono; font-size: 11px; background-color: #ffffff;"&gt;hostname(config)# failover link statelink GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;EM style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;if_name &lt;/EM&gt; argument assigns a logical name to the interface specified by the &lt;EM style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;phy_if &lt;/EM&gt;argument. The &lt;EM style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;phy_if&lt;/EM&gt; argument can be the physical port name, such as Ethernet1, or a previously created subinterface, such as Ethernet0/2.3. This interface should not be used for any other purpose (except, optionally, the failover link).&lt;/P&gt;&lt;P&gt;===============================================&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 19:27:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-use-sub-interfaces-for-failover-lan-interface-and-link/m-p/2348098#M311404</guid>
      <dc:creator>Tarjeet Singh</dc:creator>
      <dc:date>2013-10-07T19:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: Can I use sub-interfaces for (Failover lan interface and lin</title>
      <link>https://community.cisco.com/t5/network-security/can-i-use-sub-interfaces-for-failover-lan-interface-and-link/m-p/2348099#M311405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I managed to read wrong the command you had mentioned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above &lt;STRONG&gt;"failover"&lt;/STRONG&gt; configuration I mentioned is from one of our actual Failover devices so there should not be a problem with it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It has the same interface acting as the Failover interface and the Statefull Failover interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using the Management interface in the Failover is possible on the original ASA5500 Series firewalls. I think the situation would be different if you had a newer ASA5500-X Series model. Though then again those models do have higher amount of ports by default than the original ASA series. The original ASA firewalls usually had 4 ports + management while the new ones have 6 ports + management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 19:50:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-use-sub-interfaces-for-failover-lan-interface-and-link/m-p/2348099#M311405</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-07T19:50:43Z</dc:date>
    </item>
    <item>
      <title>Can I use sub-interfaces for (Failover lan interface and link st</title>
      <link>https://community.cisco.com/t5/network-security/can-i-use-sub-interfaces-for-failover-lan-interface-and-link/m-p/2348100#M311408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jouni...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;BR /&gt;I have old series ASA 5510, so I will be good to use managment interface. it is 8.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 8.3(2)&lt;/P&gt;&lt;P&gt;Device Manager Version 6.4(3)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 21:39:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-i-use-sub-interfaces-for-failover-lan-interface-and-link/m-p/2348100#M311408</guid>
      <dc:creator>Tarjeet Singh</dc:creator>
      <dc:date>2013-10-07T21:39:03Z</dc:date>
    </item>
  </channel>
</rss>

