<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: switch ASA outside interface connection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/switch-asa-outside-interface-connection/m-p/1656021#M560302</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&amp;nbsp; NG,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct about the 2 Gig capable ports e0/0 and e0/1&amp;nbsp; after license&amp;nbsp; upgrade,&amp;nbsp; most likely&amp;nbsp; the far end port can only do&amp;nbsp; handle&amp;nbsp; up to 100mb.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you and teh ISP upgrade to Gig cable switches&amp;nbsp; I suggest&amp;nbsp; to use auto&amp;nbsp; for the speed and duplex&amp;nbsp;&amp;nbsp; at both ends, this way you can see the actual bandwidth/speed&amp;nbsp; when issuing show interfaces on the firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;What best practice should we be aware of to do this?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;There is no realy a best practice when doing these chnages other than using common sense ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; The usual stuff ,&amp;nbsp; never do these chnages during production hours. Coordinate with your ISP&amp;nbsp; and have a resource&amp;nbsp; handy from their end&amp;nbsp; when making chnages on&amp;nbsp; the port settings ISP side .&amp;nbsp; There will always be a quick hiccup&amp;nbsp; when changing speed duplex&amp;nbsp;&amp;nbsp; but if you and the ISP make the changes right away at the same time&amp;nbsp; you probably will not even feel the network disconnects&amp;nbsp; 3 to 4 seconds&amp;nbsp; at the most.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on your side&amp;nbsp; you can simply go to the interface and issue those commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What commands should we be familar ourself with?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;speed auto&lt;/P&gt;&lt;P&gt;duplex auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;speed auto&lt;/P&gt;&lt;P&gt;duplex auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Mar 2011 23:00:57 GMT</pubDate>
    <dc:creator>JORGE RODRIGUEZ</dc:creator>
    <dc:date>2011-03-11T23:00:57Z</dc:date>
    <item>
      <title>switch ASA outside interface connection</title>
      <link>https://community.cisco.com/t5/network-security/switch-asa-outside-interface-connection/m-p/1656020#M560229</link>
      <description>&lt;P&gt;Our ASA 5510 is running 8.0(5). We recently upgraded the license from base to security plus. By doing so the capacity of the the external port Ethernet0/0 and Ethernet0/1 should increase from the original FE to GE. But, we were still seeing 100 Mbps on our Ethernet0/0 interface. We figured that out that the provider switch is only supporting 100 Mbps which is a bottleneck for us.The provider will be upgrading there switches to 1 Gb switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We will have to swap the switch connections now from 100 Mbps to 1 Gb switch.&lt;/P&gt;&lt;P&gt;What best practice should we be aware of to do this?&lt;/P&gt;&lt;P&gt;What commands should we be familar ourself with?&lt;/P&gt;&lt;P&gt;Though this will be doine in our maintenace window.&lt;/P&gt;&lt;P&gt;All the transaltions/connections will be dropped in our production environment so we are kind of scared.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate if someone has some suggestions as how we can do this with minimum downtime.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-NG&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/switch-asa-outside-interface-connection/m-p/1656020#M560229</guid>
      <dc:creator>gnaveen</dc:creator>
      <dc:date>2019-03-11T20:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: switch ASA outside interface connection</title>
      <link>https://community.cisco.com/t5/network-security/switch-asa-outside-interface-connection/m-p/1656021#M560302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&amp;nbsp; NG,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct about the 2 Gig capable ports e0/0 and e0/1&amp;nbsp; after license&amp;nbsp; upgrade,&amp;nbsp; most likely&amp;nbsp; the far end port can only do&amp;nbsp; handle&amp;nbsp; up to 100mb.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you and teh ISP upgrade to Gig cable switches&amp;nbsp; I suggest&amp;nbsp; to use auto&amp;nbsp; for the speed and duplex&amp;nbsp;&amp;nbsp; at both ends, this way you can see the actual bandwidth/speed&amp;nbsp; when issuing show interfaces on the firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;What best practice should we be aware of to do this?&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;There is no realy a best practice when doing these chnages other than using common sense ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; The usual stuff ,&amp;nbsp; never do these chnages during production hours. Coordinate with your ISP&amp;nbsp; and have a resource&amp;nbsp; handy from their end&amp;nbsp; when making chnages on&amp;nbsp; the port settings ISP side .&amp;nbsp; There will always be a quick hiccup&amp;nbsp; when changing speed duplex&amp;nbsp;&amp;nbsp; but if you and the ISP make the changes right away at the same time&amp;nbsp; you probably will not even feel the network disconnects&amp;nbsp; 3 to 4 seconds&amp;nbsp; at the most.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on your side&amp;nbsp; you can simply go to the interface and issue those commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What commands should we be familar ourself with?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;speed auto&lt;/P&gt;&lt;P&gt;duplex auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;speed auto&lt;/P&gt;&lt;P&gt;duplex auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 23:00:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/switch-asa-outside-interface-connection/m-p/1656021#M560302</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2011-03-11T23:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: switch ASA outside interface connection</title>
      <link>https://community.cisco.com/t5/network-security/switch-asa-outside-interface-connection/m-p/1656022#M560303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jorge! My real concern is if there any way to avoid this hicchup. As what I understand during the network disconnect all the "Connections" will essentially disconect. Only the "translations" still might be able to stand the hicchups.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Mar 2011 00:51:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/switch-asa-outside-interface-connection/m-p/1656022#M560303</guid>
      <dc:creator>gnaveen</dc:creator>
      <dc:date>2011-03-12T00:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: switch ASA outside interface connection</title>
      <link>https://community.cisco.com/t5/network-security/switch-asa-outside-interface-connection/m-p/1656023#M560304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Assuming, that it takes 10 minutes for this ordeal where the ISP brings down our ASA outside Ethernet0/0 connection.&lt;/P&gt;&lt;P&gt;Do you think changing the UDP connection timeout from the default 2 min to 10 min can avoid this hiccup?&lt;/P&gt;&lt;P&gt;This is what is configured right now on the ASA&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510#show conn detail&lt;BR /&gt;UDP outside:74.210.112.106/1061 WEB:10.39.128.10/1191,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags -, idle 0s, uptime 17h5m, timeout 2m0s, bytes 618455&lt;BR /&gt;TCP outside:10.41.1.123/1203 inside:10.39.1.91/1151,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags UIO, idle 23s, uptime 17h7m, timeout 1h0m, bytes 137721&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Mar 2011 17:03:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/switch-asa-outside-interface-connection/m-p/1656023#M560304</guid>
      <dc:creator>gnaveen</dc:creator>
      <dc:date>2011-03-13T17:03:34Z</dc:date>
    </item>
  </channel>
</rss>

