<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Replacing PIX with ASA issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/replacing-pix-with-asa-issue/m-p/1941317#M437920</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Phil, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I know why. The ASA firewall uses the same mac-address for both Vlans, so that can mess the hell up with that router (if it is using switchports). If it is using interfaces it shouldnt cause a problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do a show interface and look for the mac-addresses of both vlans, you will see what I am talking about. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on your diagram, I think that is the problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Solution, Assign the physical mac-address of the port that is connected to the outside to the respective vlan ID. You can see the physical mac-address using the show version command. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 May 2012 03:31:31 GMT</pubDate>
    <dc:creator>Maykol Rojas</dc:creator>
    <dc:date>2012-05-03T03:31:31Z</dc:date>
    <item>
      <title>Replacing PIX with ASA issue</title>
      <link>https://community.cisco.com/t5/network-security/replacing-pix-with-asa-issue/m-p/1941316#M437919</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am experiencing issues at a site where I need to replace an ageing PIX 506e with an ASA 5505.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The current setup looks like this:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/6/6/4/88466-pby.jpg" alt="pby.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PIX is used for site-to-site VPN connection via the WAN 2 link.&amp;nbsp; The WAN 1 link is used for general Internet connectivity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't have access to the Draytek Router as it is supported by a 3rd party, but I believe it uses static routing to direct the relevant traffic to/from the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I replace the PIX with the ASA, the inside i/f connection experiences dropouts - but no errors show in the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only significant difference I can see in the config is that the ASA utilises VLans for the inside &amp;amp; outside interface configs - I used the PIX-to-ASA Migration tool to make the initial configuration on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In tests, if I only connect the inside i/f of the ASA, pings from the LAN are stable.&amp;nbsp; Once I connect the outside i/f, pings timeout approx 80% of the time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could anyone offer any advice please?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:59:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replacing-pix-with-asa-issue/m-p/1941316#M437919</guid>
      <dc:creator>Phil Smith</dc:creator>
      <dc:date>2019-03-11T22:59:47Z</dc:date>
    </item>
    <item>
      <title>Replacing PIX with ASA issue</title>
      <link>https://community.cisco.com/t5/network-security/replacing-pix-with-asa-issue/m-p/1941317#M437920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Phil, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I know why. The ASA firewall uses the same mac-address for both Vlans, so that can mess the hell up with that router (if it is using switchports). If it is using interfaces it shouldnt cause a problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do a show interface and look for the mac-addresses of both vlans, you will see what I am talking about. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on your diagram, I think that is the problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Solution, Assign the physical mac-address of the port that is connected to the outside to the respective vlan ID. You can see the physical mac-address using the show version command. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 May 2012 03:31:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replacing-pix-with-asa-issue/m-p/1941317#M437920</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2012-05-03T03:31:31Z</dc:date>
    </item>
    <item>
      <title>Replacing PIX with ASA issue</title>
      <link>https://community.cisco.com/t5/network-security/replacing-pix-with-asa-issue/m-p/1941318#M437921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Mike, many thanks for this info - I will mark it as correct answer when I get the chance to test (I am out of the country at the moment), but feel very confident that it will solve the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again, thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 May 2012 07:45:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replacing-pix-with-asa-issue/m-p/1941318#M437921</guid>
      <dc:creator>Phil Smith</dc:creator>
      <dc:date>2012-05-03T07:45:28Z</dc:date>
    </item>
  </channel>
</rss>

