<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic management iP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/management-ip/m-p/2151658#M360699</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am currently migrating a netscreen firewall to a cisco asa 5515 ver. 8.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is setting up the management connectivity. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;basically the management IP of the cisco asa is not advertised. But, we want to route a management IP through the management interface to interface Gi0/2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so IP of management interface is say - 216.10.100.10. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the IP of the inside interface is say - 198.1.1.10/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on our router we have a static route sending 198.1.1.0/24 to next hop of 216.10.100.10 (management interface of cisco asa). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Cisco ASA can I send the traffic to the inside interface and manage the firewall via ssh that way? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appriciated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:10:37 GMT</pubDate>
    <dc:creator>cstpierre4</dc:creator>
    <dc:date>2019-03-12T01:10:37Z</dc:date>
    <item>
      <title>management iP</title>
      <link>https://community.cisco.com/t5/network-security/management-ip/m-p/2151658#M360699</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am currently migrating a netscreen firewall to a cisco asa 5515 ver. 8.6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is setting up the management connectivity. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;basically the management IP of the cisco asa is not advertised. But, we want to route a management IP through the management interface to interface Gi0/2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so IP of management interface is say - 216.10.100.10. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the IP of the inside interface is say - 198.1.1.10/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on our router we have a static route sending 198.1.1.0/24 to next hop of 216.10.100.10 (management interface of cisco asa). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Cisco ASA can I send the traffic to the inside interface and manage the firewall via ssh that way? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appriciated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:10:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-ip/m-p/2151658#M360699</guid>
      <dc:creator>cstpierre4</dc:creator>
      <dc:date>2019-03-12T01:10:37Z</dc:date>
    </item>
    <item>
      <title>management iP</title>
      <link>https://community.cisco.com/t5/network-security/management-ip/m-p/2151659#M360701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Basically you want to use one interface to pass traffic and also to manage the ASA via SSH.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you can do that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Commands in case you need'em:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;crypto key generate rsa modulus 1024 noconfirm&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ssh 0 0&amp;nbsp; inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authentication ssh console LOCAL&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Mar 2013 19:31:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-ip/m-p/2151659#M360701</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-06T19:31:40Z</dc:date>
    </item>
    <item>
      <title>management iP</title>
      <link>https://community.cisco.com/t5/network-security/management-ip/m-p/2151660#M360702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cool thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im just having an issue with an ACL. Im not that versed with the cisco asa's. I generally support netscreen firewalls. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so basically my management traffic is supposed to come into the management interface and be routed to the inside interface as the IP of the inside interface is what we have DNS configured for our firewalls hostname. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but im seeing this - &lt;/P&gt;&lt;P&gt;TCP access denied by ACL from ipaddress/50816 to inside:ipaddress/22&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I created an acl but its not working. what would be the acl to allow this? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Mar 2013 04:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-ip/m-p/2151660#M360702</guid>
      <dc:creator>cstpierre4</dc:creator>
      <dc:date>2013-03-08T04:10:40Z</dc:date>
    </item>
    <item>
      <title>management iP</title>
      <link>https://community.cisco.com/t5/network-security/management-ip/m-p/2151661#M360703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are comming into the managment interface and that my friend means that only managment traffic from the same subnet will be allowed,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No routed traffic going to another interface or from another subnet than the Managment IP address will be allowed, on other hardware plataffoms than the ASA 5500 X series you could remove that function by taking the managment-only command but this on your hardware device is not allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That being said you will need to use a different interface, no matter if you create an ACL traffic will still get denied&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio Carvajal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Mar 2013 05:18:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-ip/m-p/2151661#M360703</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-03-08T05:18:11Z</dc:date>
    </item>
    <item>
      <title>management iP</title>
      <link>https://community.cisco.com/t5/network-security/management-ip/m-p/2151662#M360704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my case, if I want to manage a remote firewall by ssh I connect to its outside interface, not its inside.&amp;nbsp; That works fine, as long as I have an ssh statement allowing the network I'm coming from.&amp;nbsp; E.g.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssh network1 netmask1 outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssh network2 netmask2 outside&lt;/P&gt;&lt;P&gt;The ACL's for transit traffic mentioned in &lt;EM&gt;access-group&lt;/EM&gt;&amp;nbsp; statements don't come into this; we are terminating the ssh connection at the firewall interface itself.&amp;nbsp; jocamare's &lt;EM&gt;crypto key generate ...&lt;/EM&gt;and &lt;EM&gt;aaa authentication ssh ...&lt;/EM&gt; are critical; you have to do those too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For those of us still feeling some 55**-X confusion, what's the role of &lt;EM&gt;management-access&lt;/EM&gt; in this sort of situation?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I upgrade from 5520's to 5525-X's Real Soon Now I'm apparently going to have to use the management interface to manage IPS stuff.&amp;nbsp; In my topology the firewall is routing all the local vlans, so remote access to a firewall cannot be via a host on the management vlan itself; there can't be any because the management vlan can't pass remote traffic to them.&amp;nbsp; That is, the toplogy would look like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; (managment PC) -- [firewall 1] --IPSEC tunnel-- [firewall 2]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The goal is to manage IPS on firewall2 from the far side of the IPSEC tunnel.&amp;nbsp;&amp;nbsp; I haven't had a chance to play with this scenario in a test lab yet, and am a complete IPS neophyte.&amp;nbsp;&amp;nbsp; The combination of the warning against static nat and VPN with management-access is a bit scary.&amp;nbsp; I'd prefer not to have to put a dual-NIC host on two vlan's just to be able to come back into the management-only 5525-x interface on firewall2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-- Jim Leinweber, WI State Lab of Hygiene&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Mar 2013 15:54:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-ip/m-p/2151662#M360704</guid>
      <dc:creator>James Leinweber</dc:creator>
      <dc:date>2013-03-08T15:54:12Z</dc:date>
    </item>
  </channel>
</rss>

