<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic management interface in cluster Asa in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097263#M393363</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You already did that with this command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;interface Management0/0&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;management-only&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;nameif management&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;security-level 100&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="text-decoration: underline; "&gt;&lt;STRONG&gt;ip address 172.16.100.92 255.255.255.0 standby 172.16.100.91&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;You can now access the secondary unit attempting to ssh,telnet or ASDM to 100.91 and the active one at 100.92&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is that normal that I need to make a route map to exclude management network in ospf to avoid that the routing service publish the management network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The managment-only command is really picky so you got to be really carefull when you use this interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H2 style="background-color: #ffffff; border-collapse: collapse; font-size: 14.166666030883789px; list-style: none; margin: 14px 0em 7px -0.1in; color: #336666; font-family: Arial, Helvetica, sans-serif;"&gt;Management 0/0 Interface on the ASA 5500-X Series&lt;/H2&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;A name="wp1068467" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;#&lt;/A&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12.499999046325684px; list-style: none; margin: 1px 0em 6px; color: #000000; font-family: Arial, Helvetica, sans-serif;"&gt;You manage the ASA through the Management 0/0 interface on the ASA 5512-X through ASA 5555-X models. The Management 0/0 interface has the following characteristics:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;A name="wp1068469" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;#&lt;/A&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12.499999046325684px; list-style: none; margin: 0px 0em 7px 0.25in; color: #000000; font-family: Arial, Helvetica, sans-serif; text-indent: -0.25in;"&gt;•&lt;A href="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none;" width="19" /&gt;&lt;/A&gt;No through traffic support&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;A name="wp1068470" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;#&lt;/A&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12.499999046325684px; list-style: none; margin: 0px 0em 7px 0.25in; color: #000000; font-family: Arial, Helvetica, sans-serif; text-indent: -0.25in;"&gt;•&lt;A href="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none;" width="19" /&gt;&lt;/A&gt;No subinterface support&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;A name="wp1068471" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;#&lt;/A&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12.499999046325684px; list-style: none; margin: 0px 0em 7px 0.25in; color: #000000; font-family: Arial, Helvetica, sans-serif; text-indent: -0.25in;"&gt;•&lt;A href="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none;" width="19" /&gt;&lt;/A&gt;No priority queue support&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;A name="wp1069159" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;#&lt;/A&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12.499999046325684px; list-style: none; margin: 0px 0em 7px 0.25in; color: #000000; font-family: Arial, Helvetica, sans-serif; text-indent: -0.25in;"&gt;•&lt;A href="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none;" width="19" /&gt;&lt;/A&gt;No multicast MAC support&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;A name="wp1069160" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;#&lt;/A&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12.499999046325684px; list-style: none; margin: 0px 0em 7px 0.25in; color: #000000; font-family: Arial, Helvetica, sans-serif; text-indent: -0.25in;"&gt;•&lt;A href="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none;" width="19" /&gt;&lt;/A&gt;The IPS SSP software module and the ASA share the Management 0/0 interface; however, each has its own separate MAC addresses and IP addresses. You must configure the IPS IP address within the IPS operating system. However, you configure physical characteristics (such as enabling the interface) on the ASA.&lt;/P&gt;&lt;P&gt; So as you can see there is no restriction for that so yes it is normal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Jan 2013 04:12:46 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-01-09T04:12:46Z</dc:date>
    <item>
      <title>management interface in cluster Asa</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097259#M393358</link>
      <description>&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a misanderstand about management interface configuration in cluster. So I have a cluster asa 5515X with management interface. i Would like to be able to connect to any of the member of my cluster on management interface, so i would like to fix a different ip on management interface on each of my node ip 92 and 91. I think it is the only way to make asa firmware update to access local flash on each node.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; channel-group 1 mode active&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; channel-group 1 mode active&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/5&lt;/P&gt;&lt;P&gt; description LAN/STATE Failover Interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.16.100.92 255.255.255.0 standby 172.16.100.91&lt;/P&gt;&lt;P&gt; ospf cost 300&lt;/P&gt;&lt;P&gt; ospf priority 30&lt;/P&gt;&lt;P&gt; ospf network point-to-point non-broadcast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface asa GigabitEthernet0/5&lt;/P&gt;&lt;P&gt;failover key *****&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;failover link asa GigabitEthernet0/5&lt;/P&gt;&lt;P&gt;failover interface ip asa 172.16.255.254 255.255.255.0 standby 172.16.255.253&lt;/P&gt;&lt;P&gt;no monitor-interface management&lt;/P&gt;&lt;P&gt;no monitor-interface Etherchannel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---------&lt;/P&gt;&lt;P&gt;As you can see and this is my second request I use OSpf for routing and with management-only on manangement0/0&amp;nbsp; the ip adress is redistribute on OSPF or with command "management-only" you can make routing, but the network is steal redistribute on ospf routing. I make route-map to exclude this interface but I think it should not be the normal way to do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route-map RM-select permit 10&lt;/P&gt;&lt;P&gt; match interface Classe1 Backbone97 Backbone98&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route-map RM-select deny 20&lt;/P&gt;&lt;P&gt; match interface management DMZ&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;router ospf 1&lt;/P&gt;&lt;P&gt; router-id 172.16.97.92&lt;/P&gt;&lt;P&gt; network 172.16.97.0 255.255.255.0 area 0&lt;/P&gt;&lt;P&gt; network 172.16.98.0 255.255.255.0 area 0&lt;/P&gt;&lt;P&gt; area 0&lt;/P&gt;&lt;P&gt; log-adj-changes detail&lt;/P&gt;&lt;P&gt; redistribute connected route-map RM-select&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Port-channel1.10&lt;/P&gt;&lt;P&gt; vlan 10&lt;/P&gt;&lt;P&gt; nameif Classe1&lt;/P&gt;&lt;P&gt; security-level 10&lt;/P&gt;&lt;P&gt; ip address 192.168.10.254 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Port-channel1.97&lt;/P&gt;&lt;P&gt; vlan 97&lt;/P&gt;&lt;P&gt; nameif Backbone97&lt;/P&gt;&lt;P&gt; security-level 10&lt;/P&gt;&lt;P&gt; ip address 172.16.97.92 255.255.255.0&lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt; ospf retransmit-interval 3&lt;/P&gt;&lt;P&gt; ospf priority 2&lt;/P&gt;&lt;P&gt; ospf hello-interval 1&lt;/P&gt;&lt;P&gt; ospf message-digest-key 1 md5 *****&lt;/P&gt;&lt;P&gt; ospf authentication message-digest&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Port-channel1.98&lt;/P&gt;&lt;P&gt; vlan 98&lt;/P&gt;&lt;P&gt; nameif Backbone98&lt;/P&gt;&lt;P&gt; security-level 10&lt;/P&gt;&lt;P&gt; ip address 172.16.98.92 255.255.255.0&lt;/P&gt;&lt;P&gt; ospf cost 20&lt;/P&gt;&lt;P&gt; ospf retransmit-interval 3&lt;/P&gt;&lt;P&gt; ospf priority 2&lt;/P&gt;&lt;P&gt; ospf hello-interval 1&lt;/P&gt;&lt;P&gt; ospf message-digest-key 1 md5 *****&lt;/P&gt;&lt;P&gt; ospf authentication message-digest&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;------------------------&lt;/P&gt;&lt;P&gt;Sorry for my english and thank's for your help.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:43:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097259#M393358</guid>
      <dc:creator>fcorfdir</dc:creator>
      <dc:date>2019-03-12T00:43:54Z</dc:date>
    </item>
    <item>
      <title>management interface in cluster Asa</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097260#M393360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no one have an idea ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Jan 2013 23:09:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097260#M393360</guid>
      <dc:creator>fcorfdir</dc:creator>
      <dc:date>2013-01-08T23:09:37Z</dc:date>
    </item>
    <item>
      <title>management interface in cluster Asa</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097261#M393361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure I understand your query,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the problem that an OSPF neighorship is being created over the managment interface, is the problem that you cannot create an OSPF neigborship over this interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you supposed to filter this Subnet and is not being the case??? Let us know &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2013 00:58:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097261#M393361</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-09T00:58:00Z</dc:date>
    </item>
    <item>
      <title>management interface in cluster Asa</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097262#M393362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have 2 query :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I configure a diferent management ip on each member of my cluster node in a cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is that normal that I need to make a route map to exclude management network in ospf to avoid that the routing service publish the management network&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2013 02:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097262#M393362</guid>
      <dc:creator>fcorfdir</dc:creator>
      <dc:date>2013-01-09T02:55:19Z</dc:date>
    </item>
    <item>
      <title>management interface in cluster Asa</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097263#M393363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You already did that with this command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;interface Management0/0&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;management-only&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;nameif management&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;security-level 100&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="text-decoration: underline; "&gt;&lt;STRONG&gt;ip address 172.16.100.92 255.255.255.0 standby 172.16.100.91&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;You can now access the secondary unit attempting to ssh,telnet or ASDM to 100.91 and the active one at 100.92&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is that normal that I need to make a route map to exclude management network in ospf to avoid that the routing service publish the management network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The managment-only command is really picky so you got to be really carefull when you use this interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H2 style="background-color: #ffffff; border-collapse: collapse; font-size: 14.166666030883789px; list-style: none; margin: 14px 0em 7px -0.1in; color: #336666; font-family: Arial, Helvetica, sans-serif;"&gt;Management 0/0 Interface on the ASA 5500-X Series&lt;/H2&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;A name="wp1068467" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;#&lt;/A&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12.499999046325684px; list-style: none; margin: 1px 0em 6px; color: #000000; font-family: Arial, Helvetica, sans-serif;"&gt;You manage the ASA through the Management 0/0 interface on the ASA 5512-X through ASA 5555-X models. The Management 0/0 interface has the following characteristics:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;A name="wp1068469" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;#&lt;/A&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12.499999046325684px; list-style: none; margin: 0px 0em 7px 0.25in; color: #000000; font-family: Arial, Helvetica, sans-serif; text-indent: -0.25in;"&gt;•&lt;A href="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none;" width="19" /&gt;&lt;/A&gt;No through traffic support&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;A name="wp1068470" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;#&lt;/A&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12.499999046325684px; list-style: none; margin: 0px 0em 7px 0.25in; color: #000000; font-family: Arial, Helvetica, sans-serif; text-indent: -0.25in;"&gt;•&lt;A href="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none;" width="19" /&gt;&lt;/A&gt;No subinterface support&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;A name="wp1068471" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;#&lt;/A&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12.499999046325684px; list-style: none; margin: 0px 0em 7px 0.25in; color: #000000; font-family: Arial, Helvetica, sans-serif; text-indent: -0.25in;"&gt;•&lt;A href="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none;" width="19" /&gt;&lt;/A&gt;No priority queue support&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;A name="wp1069159" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;#&lt;/A&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12.499999046325684px; list-style: none; margin: 0px 0em 7px 0.25in; color: #000000; font-family: Arial, Helvetica, sans-serif; text-indent: -0.25in;"&gt;•&lt;A href="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none;" width="19" /&gt;&lt;/A&gt;No multicast MAC support&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;A name="wp1069160" rel="nofollow" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;#&lt;/A&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12.499999046325684px; list-style: none; margin: 0px 0em 7px 0.25in; color: #000000; font-family: Arial, Helvetica, sans-serif; text-indent: -0.25in;"&gt;•&lt;A href="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none; outline: none; color: #2f6681;"&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" style="border-collapse: collapse; list-style: none;" width="19" /&gt;&lt;/A&gt;The IPS SSP software module and the ASA share the Management 0/0 interface; however, each has its own separate MAC addresses and IP addresses. You must configure the IPS IP address within the IPS operating system. However, you configure physical characteristics (such as enabling the interface) on the ASA.&lt;/P&gt;&lt;P&gt; So as you can see there is no restriction for that so yes it is normal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate all of the helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2013 04:12:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097263#M393363</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-09T04:12:46Z</dc:date>
    </item>
    <item>
      <title>management interface in cluster Asa</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097264#M393364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok, thanks for the information about management-only. I hope that it could be less picky in next asa release.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can connect in SSH on both management ip but I can't with ASDM. before I always test only with ASDM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 172.16.100.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 172.16.100.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;ssh version 2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2013 06:22:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097264#M393364</guid>
      <dc:creator>fcorfdir</dc:creator>
      <dc:date>2013-01-09T06:22:36Z</dc:date>
    </item>
    <item>
      <title>management interface in cluster Asa</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097265#M393365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you get any specific errors while connecting via ASDM??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Add the following&lt;/P&gt;&lt;P&gt;aaa authentication http console LOCAL &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And give it a try&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2013 14:17:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097265#M393365</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-09T14:17:19Z</dc:date>
    </item>
    <item>
      <title>management interface in cluster Asa</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097266#M393368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have add aaa authtication http consol local but same error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i connect to 172.16.100.91 (standby ip on management) i have the error "could not open device 172.16.100.91"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2013 21:13:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097266#M393368</guid>
      <dc:creator>fcorfdir</dc:creator>
      <dc:date>2013-01-09T21:13:03Z</dc:date>
    </item>
    <item>
      <title>management interface in cluster Asa</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097267#M393372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From witch Ip add are you trying to connect??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2013 21:28:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097267#M393372</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-09T21:28:49Z</dc:date>
    </item>
    <item>
      <title>management interface in cluster Asa</title>
      <link>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097268#M393374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I update ASDM on both node and I can connet to both management ip with the new asdm. thank for your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jan 2013 21:52:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/management-interface-in-cluster-asa/m-p/2097268#M393374</guid>
      <dc:creator>fcorfdir</dc:creator>
      <dc:date>2013-01-09T21:52:15Z</dc:date>
    </item>
  </channel>
</rss>

