<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5512-x CX module configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205263#M358181</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem was the native VLAN on the switch that connects to the inside interface of the ASA. The handle does not understand native VLAN. Change in the Uplink Native Vlan Trunk and I could manage the ASA from the inside network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it works for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Jul 2013 21:17:48 GMT</pubDate>
    <dc:creator>cesarsoto</dc:creator>
    <dc:date>2013-07-22T21:17:48Z</dc:date>
    <item>
      <title>ASA 5512-x CX module configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205260#M358173</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm currently in the process of setting up a new 5512-x to get it running with the context-aware module. I have read the documentation at:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/quick_start/cx/cx_qsg.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/quick_start/cx/cx_qsg.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But still have some questions about how exactly how to appropriately set up a management IP for the service. Currently the only way I can access the CX module is if I use the management interface as the default gateway and put the cx module on an IP in the same subnet (192.168.1.x) and use the management interface IP 192.168.1.1 as the default gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem with this (I'm guessing) is that when I log into the module via PRSM and look at events, the first thing I notice is that it's failing to go out to the internet and pick updates (update failed). I suspect this is because the Management interface is set to for management-only traffic and thus won't let the ASA cx connect out to the internet for updates, or web reputation, etc. So I tried to remote the management-only option and get an error message that this isn't possible on this platform.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my question is, how is the ASA cx module supposed to be configured from a routing standpoint? I read the document about whether or not you have a router on the LAN or not. I do have a layer-3 switch behind it, so I would like to be able to reach it from the LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My inside interface is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.254.254.17/29&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried using 10.254.254.19/29 as the module's ip and using 10.254.254.17 as the default gateway but am unable to reach it from the inside LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas what I'm doing wrong here? Basically, I can't get the module to go out to the internet when the IP is on the Mangement subnet (192.168.1.x) and can't even reach it at all when I place it on the internal LAN subnet 10.254.254.16/29.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help or an example is greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:28:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205260#M358173</guid>
      <dc:creator>ropeadope</dc:creator>
      <dc:date>2019-03-12T01:28:30Z</dc:date>
    </item>
    <item>
      <title>ASA 5512-x CX module configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205261#M358176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Brian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could solve this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same thing happening to me you mentioned, I have the scenario where I have not the ASA router is directly connected to the Internet. And I am using the ASA CX module in the same subnet as my LAN, and I have connected to the LAN connectivity to the module, but since I can not reach the ASA CX module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea why this happens?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jul 2013 22:19:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205261#M358176</guid>
      <dc:creator>cesarsoto</dc:creator>
      <dc:date>2013-07-01T22:19:39Z</dc:date>
    </item>
    <item>
      <title>ASA 5512-x CX module configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205262#M358179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm looking for this information as well.&amp;nbsp; Can the 5512 be managed from an IP on the inside interface instead of the management interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have my inside IP set at 192.168.254.1/29&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the CX interface set as 192.168.254.6/29&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but I can't get to it from that network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 20:40:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205262#M358179</guid>
      <dc:creator>benbollinger</dc:creator>
      <dc:date>2013-07-22T20:40:33Z</dc:date>
    </item>
    <item>
      <title>ASA 5512-x CX module configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205263#M358181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem was the native VLAN on the switch that connects to the inside interface of the ASA. The handle does not understand native VLAN. Change in the Uplink Native Vlan Trunk and I could manage the ASA from the inside network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it works for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 21:17:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205263#M358181</guid>
      <dc:creator>cesarsoto</dc:creator>
      <dc:date>2013-07-22T21:17:48Z</dc:date>
    </item>
    <item>
      <title>ASA 5512-x CX module configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205264#M358182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure I know what you mean.&amp;nbsp; I can already manage the asa from the inside,&amp;nbsp;&amp;nbsp; just not the software CX module.&amp;nbsp; Can you clarify?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 22:01:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205264#M358182</guid>
      <dc:creator>benbollinger</dc:creator>
      <dc:date>2013-07-22T22:01:37Z</dc:date>
    </item>
    <item>
      <title>ASA 5512-x CX module configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205265#M358185</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The CX needs to use (one of) the ASA's physical management interface(s). You may or may not also use that interface for ASA management. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is explained in some detail &lt;A href="http://www.cisco.com/en/US/docs/security/asa/quick_start/cx/cx_qsg.html#wp49866"&gt;here&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 03:27:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205265#M358185</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-07-23T03:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5512-x CX module configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205266#M358188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was facing a similar problem. I was only using the man0/0 interface to give the CX module network connectivity, but as soon as I enabled another firewall interface on the same subnet, I had connectivity problems with this interface sharing the same subnet as the CX module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To make myself clear:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA CX Interface mgmt0/0: Vlan 12 - Access to the mgmt interface of CX module working OK&lt;/P&gt;&lt;P&gt;ASA Interface G0/2: Vlan 12 - 1 Ping worked OK to hosts on same subnet, after that, no connectivity in this interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I tried is, instead of having interface g0/2 configured in access mode, to create a port-channel interface between the ASA and the Access switch, and in this port-channel, I enabled a subinterface mapped to vlan 12.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CX Interface (mgmt 0/0) was left with the same configuration, in access mode in vlan 12. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Doing this, I was able to have connectivity in both interfaces with IP addressing of the same subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this is helpful to others having this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's my interface config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; description Outside&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address dhcp setroute&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; channel-group 1 mode on&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; channel-group 1 mode on&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Port-channel1&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Port-channel1.12&lt;/P&gt;&lt;P&gt; vlan 12&lt;/P&gt;&lt;P&gt; nameif services&lt;/P&gt;&lt;P&gt; security-level 60&lt;/P&gt;&lt;P&gt; ip address 192.168.12.8 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Port-channel1.222&lt;/P&gt;&lt;P&gt; vlan 222&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.222.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Oct 2013 17:23:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205266#M358188</guid>
      <dc:creator>jorge-mora</dc:creator>
      <dc:date>2013-10-21T17:23:16Z</dc:date>
    </item>
    <item>
      <title>ASA 5512-x CX module configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205267#M358190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I also have the same issue as &lt;A _jive_internal="true" href="https://community.cisco.com/people/ropeadope" id="jive-6124852695219848732480" style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; outline: none; color: #000000; font-weight: bold; font-family: Arial, verdana, sans-serif;"&gt;Brian Larter&lt;/A&gt;; i m not able to figure out how to correctly perform the configuration displayed at: &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/quick_start/cx/cx_qsg.html"&gt;http://www.cisco.com/en/US/docs/security/asa/quick_start/cx/cx_qsg.html&lt;/A&gt;&lt;SPAN&gt; (ASA 5512-X with router inside).&lt;/SPAN&gt;&lt;BR /&gt;If someone already did it, it would be nice to hear some tips.&lt;BR /&gt;Best Regards&lt;BR /&gt;Pisco &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 22:41:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205267#M358190</guid>
      <dc:creator>tiago_pisco</dc:creator>
      <dc:date>2014-01-23T22:41:39Z</dc:date>
    </item>
    <item>
      <title>ASA 5512-x CX module configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205268#M358193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; After 30 min. i find out that to transfer file from your PC to ASA-CX. you need to transfer via ASA's M0/0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/cx/cx_qsg.html#wp51248"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/quick_start/cx/cx_qsg.html#wp51248&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Feb 2014 11:49:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205268#M358193</guid>
      <dc:creator>Tanamed Sidthawonsri</dc:creator>
      <dc:date>2014-02-16T11:49:51Z</dc:date>
    </item>
    <item>
      <title>ASA 5512-x CX module configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205269#M358194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Few days ago i had configure ASA CX and its working fine. Please share your exprience and what you want actually.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Parosh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Feb 2014 13:07:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205269#M358194</guid>
      <dc:creator>Mizanul Islam</dc:creator>
      <dc:date>2014-02-16T13:07:40Z</dc:date>
    </item>
    <item>
      <title>benbollinger@ho.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205270#M358196</link>
      <description>&lt;P&gt;&lt;A href="https://supportforums.cisco.com/users/benbollingerhomecom" title="View user profile." class="username" lang="" about="/users/benbollingerhomecom" typeof="sioc:UserAccount" property="foaf:name" datatype=""&gt;benbollinger@ho.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;actually this is exactly my problem now&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have my inside IP set at 192.168.X.X/24&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;and the CX interface set as 192.168.X.X/24&lt;/P&gt;
&lt;P&gt;but the CX module cannot reach any network,,, did you manage to solve this problem?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 11:38:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-x-cx-module-configuration/m-p/2205270#M358196</guid>
      <dc:creator>Garbosh</dc:creator>
      <dc:date>2017-02-21T11:38:29Z</dc:date>
    </item>
  </channel>
</rss>

