<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: mutliple context sharing interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/mutliple-context-sharing-interfaces/m-p/1667848#M557631</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi experts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any ideas on this question and document ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Apr 2011 11:17:10 GMT</pubDate>
    <dc:creator>techkamleshs</dc:creator>
    <dc:date>2011-04-22T11:17:10Z</dc:date>
    <item>
      <title>mutliple context sharing interfaces</title>
      <link>https://community.cisco.com/t5/network-security/mutliple-context-sharing-interfaces/m-p/1667845#M557621</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;is it possible to assign same IP to shared interface in multiple context ? i have gone through below cisco document but this explain example in which logical interfaces are given different VLAN ID and assigned a unique MAC . so how is the interface considered to be shared in this eg ?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;in the link &lt;A href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808d2b63.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808d2b63.shtml&lt;/A&gt; the heading "Assign the Same IP Address to the Shared Interfaces in the Multiple Context Mode" has following eg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if interface is shared the example should be something like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;context1 configuration&amp;gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0.1&lt;BR /&gt;mac-address 0000.0707.0000&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&amp;lt;context2 configuration&amp;gt;&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0.1 ----------------------&amp;gt; currently this is Ethernet0.2 in example &lt;BR /&gt;mac-address 0000.0808.0000&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:22:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mutliple-context-sharing-interfaces/m-p/1667845#M557621</guid>
      <dc:creator>techkamleshs</dc:creator>
      <dc:date>2019-03-11T20:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: mutliple context sharing interfaces</title>
      <link>https://community.cisco.com/t5/network-security/mutliple-context-sharing-interfaces/m-p/1667846#M557625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kamlesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Physical interface Ethernet 0, is being split into two logical interfaces 0.1 and 0.2, and these are shared amongst the multiple contexts.&lt;/P&gt;&lt;P&gt;The physical interface, is thus being shared by both contexts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this clears things up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shrikant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: Please mark this question as answered if it has been resolved. Do rate helpful posts. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Apr 2011 11:59:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mutliple-context-sharing-interfaces/m-p/1667846#M557625</guid>
      <dc:creator>Shrikant Sundaresh</dc:creator>
      <dc:date>2011-04-18T11:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: mutliple context sharing interfaces</title>
      <link>https://community.cisco.com/t5/network-security/mutliple-context-sharing-interfaces/m-p/1667847#M557628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shrikant ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the example given is not really of a shared interface . A shared interface would not be separated by a different VLAN tag and that interface should be part of both context (whether logical or physical)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Apr 2011 09:06:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mutliple-context-sharing-interfaces/m-p/1667847#M557628</guid>
      <dc:creator>techkamleshs</dc:creator>
      <dc:date>2011-04-19T09:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: mutliple context sharing interfaces</title>
      <link>https://community.cisco.com/t5/network-security/mutliple-context-sharing-interfaces/m-p/1667848#M557631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi experts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any ideas on this question and document ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Apr 2011 11:17:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mutliple-context-sharing-interfaces/m-p/1667848#M557631</guid>
      <dc:creator>techkamleshs</dc:creator>
      <dc:date>2011-04-22T11:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: mutliple context sharing interfaces</title>
      <link>https://community.cisco.com/t5/network-security/mutliple-context-sharing-interfaces/m-p/1667849#M557633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kamlesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First, a shared interface is either a physical interface or sub-interface on the same subnet/vlan. Because each context has an interface in the same subnet, the IP addresses should be different. So...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q. Is it possible to assign same IP to shared interface in multiple&amp;nbsp; context?&lt;/P&gt;&lt;P&gt;A. Yes this is possible, but strongly discouraged. The subnet will be the same, but the IPs should be different because it behaves like any other duplicate IP in your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q. I have gone through below cisco document but this explain&amp;nbsp; example in which logical interfaces are given different VLAN ID and&amp;nbsp; assigned a unique MAC. So how is the interface considered to be shared&amp;nbsp; in this example?&lt;/P&gt;&lt;P&gt;A. In your example, the sub-interface Ethernet0.1 in context1 would have to be configured with the same subnet and vlan as Ethernet0.1 in context2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding the link, I think it is just saying that it is possible to assign the same IP to interfaces in 2 contexts so long as their mac-addresses are different. Keep in mind that I would NOT suggest doing this. If you do, you would have to manually configure the arp entries for all other hosts in that subnet. Otherwise, when a host sends an arp for your duplicate IP, it's a race to see which interface replies first. (this is very bad)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bottom line, you should not configure duplicate IPs on your shared interface if it can be avoided.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps. If this answers your question, please mark it as resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brendan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Apr 2011 14:31:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mutliple-context-sharing-interfaces/m-p/1667849#M557633</guid>
      <dc:creator>brquinn</dc:creator>
      <dc:date>2011-04-22T14:31:19Z</dc:date>
    </item>
    <item>
      <title>Re: mutliple context sharing interfaces</title>
      <link>https://community.cisco.com/t5/network-security/mutliple-context-sharing-interfaces/m-p/1667850#M557635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi brendan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your explanation was helpful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.If it is possible to hav 2 shared i/f (whether logical or physical ) assigned to same context [ with the shared i/f having same IP and VLAN ID ]is it possible that we can differentiate them by assigning virtual mac to each of them [ in their individual contexts ] so that firewall can distinguish among them ? I dont know if this is possible .&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2. If the link is providing explantion to assign the same IP to diffrent interfaces in 2 contexts , then the document heading should be changed as it is no longer a shared interface example then .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Apr 2011 10:34:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mutliple-context-sharing-interfaces/m-p/1667850#M557635</guid>
      <dc:creator>techkamleshs</dc:creator>
      <dc:date>2011-04-26T10:34:30Z</dc:date>
    </item>
  </channel>
</rss>

