<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA virtual mac best practice in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446163#M652063</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what exactly do you mean by virtual mac address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when in failover the mac-address of primary is used when primary comes up first and when secondary becomes active it gets this mac address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when in failover pair secondary comes up first since the failover cluster does not detect a primary it will use the mac of secondary to pass traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;hope this is what you need&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can read more her&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1091288"&gt;https://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1091288&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Aug 2010 15:14:49 GMT</pubDate>
    <dc:creator>Jitendriya Athavale</dc:creator>
    <dc:date>2010-08-20T15:14:49Z</dc:date>
    <item>
      <title>ASA virtual mac best practice</title>
      <link>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446162#M652048</link>
      <description>&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;Will it cause issues if the burned in mac addresses are used as the virtual mac addresses when configuring failover on an ASA? Or will the cause issues in the case where the secondary comes up first and assumes the active state using the mac addresses off the primary? Some delay in applying the virtual mac addresses or something on the primary?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is it a better idea to define your own random mac addresses and use those instead as the virtual mac addresses?&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:28:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446162#M652048</guid>
      <dc:creator>ben.wiechman</dc:creator>
      <dc:date>2019-03-11T18:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA virtual mac best practice</title>
      <link>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446163#M652063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what exactly do you mean by virtual mac address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when in failover the mac-address of primary is used when primary comes up first and when secondary becomes active it gets this mac address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when in failover pair secondary comes up first since the failover cluster does not detect a primary it will use the mac of secondary to pass traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;hope this is what you need&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can read more her&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1091288"&gt;https://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1091288&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 15:14:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446163#M652063</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-20T15:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA virtual mac best practice</title>
      <link>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446164#M652073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;When the secondary comes up first and the primary is not available it will use its own mac address and not that of the primary. When the primary comes up the mac address will be updated to be that of the primary causing a short interruption. The recommendation is to configure a virtual mac address (&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1073913"&gt;https://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/failover.html#wp1073913&lt;/A&gt;&lt;SPAN&gt;) so that this does not happen.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Instead of inventing a set of mac addresses to use (and hoping that at some point there won't be duplication, etc) if it would cause issues to just use the actual physical mac addresses and configure those as the virtual mac addresses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 15:25:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446164#M652073</guid>
      <dc:creator>ben.wiechman</dc:creator>
      <dc:date>2010-08-20T15:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA virtual mac best practice</title>
      <link>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446165#M652083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Ben,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would think this will not cause problems. Since the virtual MACs will take precedence over the actual MAC addresses, even if we have the actual MAC addresses aas the virtual MACs, there shouldn't be a problem. But i must tell you that I have not really tried this before and also, the probabilities of duplication if you use invented virtual MAC addresses are really low &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 15:36:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446165#M652083</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-08-20T15:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA virtual mac best practice</title>
      <link>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446166#M652088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I couldn't think of any reason why it wouldn't work, just wondered if anyone had tried it and ran into something goofy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 15:48:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446166#M652088</guid>
      <dc:creator>ben.wiechman</dc:creator>
      <dc:date>2010-08-20T15:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA virtual mac best practice</title>
      <link>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446167#M652092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think i will leave it for someone who has tried this to answer it if there can be any glitches. But my thought too is that it should work just fine. If you manage to try it out, let us know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Aug 2010 15:50:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446167#M652092</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-08-20T15:50:57Z</dc:date>
    </item>
    <item>
      <title>ASA virtual mac best practice</title>
      <link>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446168#M652096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would like to do the same and set the virtual MAC address as the real MAC address of the current active unit.&amp;nbsp; My reason is the ISP is very unresponsive (&amp;gt;4 hours) to clear their arp table which makes it difficult to plan sme future upgrades.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone set the virtual to be the same as the real MAC address?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2012 19:57:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446168#M652096</guid>
      <dc:creator>NeverOutofTune</dc:creator>
      <dc:date>2012-09-21T19:57:45Z</dc:date>
    </item>
    <item>
      <title>You can't do it, the ASA</title>
      <link>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446169#M652099</link>
      <description>&lt;P&gt;You can't do it, the ASA rejects this and gives an error:&lt;/P&gt;
&lt;P&gt;DC-FW/unit1/master(config)# int po 23&lt;BR /&gt;DC-FW/unit1/master(config-if)#&amp;nbsp; mac-address 8d64.2406.1cb7&lt;BR /&gt;ERROR: active address equals to burn-in address&lt;BR /&gt;DC-FW/unit1/master(config-if)# int po 24&lt;BR /&gt;DC-FW/unit1/master(config-if)#&amp;nbsp; mac-address 8d64.2406.1cbd&lt;BR /&gt;ERROR: active address equals to burn-in address&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2016 17:49:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446169#M652099</guid>
      <dc:creator>grant.maynard</dc:creator>
      <dc:date>2016-03-08T17:49:00Z</dc:date>
    </item>
    <item>
      <title>Wanted to clarify this answer</title>
      <link>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446170#M652102</link>
      <description>&lt;P&gt;Wanted to clarify this answer - the syntax for defining the failover mac addresses is 'failover mac address &amp;lt;&lt;EM&gt;interface&amp;gt; &amp;lt;active mac&amp;gt; &amp;lt;standby mac&amp;gt;'&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;And yes you can use the interface physical MAC addresses when using the failover syntax.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 21:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-virtual-mac-best-practice/m-p/1446170#M652102</guid>
      <dc:creator>JViveiros</dc:creator>
      <dc:date>2017-06-06T21:15:18Z</dc:date>
    </item>
  </channel>
</rss>

