<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configuring ASA Management on a sub-interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/configuring-asa-management-on-a-sub-interface/m-p/1451013#M660734</link>
    <description>&lt;P&gt;Dear All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two ASA 5520 with 4 Giga interfaces and 1 management interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to use 4 interfaces four data traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- Inside&lt;/P&gt;&lt;P&gt;2- Outside&lt;/P&gt;&lt;P&gt;3- dmz-1&lt;/P&gt;&lt;P&gt;4- dmz-2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The remaining will be the management interface only.How can I configure the Statefull failover and Management?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I did?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- I used the management0/0 for The stateful failover. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2- I used gig 0 for outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3- I used gig 1 for inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4- I used gig 2 for dmz-1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5- I divided the gig 3 to two sub interfaces&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; a- gig0/3.1 for dmz-2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; b- gig0/3.2 for Management and I defined it as a management-only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone has comments or recommendatiosn on this design? Please advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks on advance,&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 18:17:36 GMT</pubDate>
    <dc:creator>Ahmad Samir</dc:creator>
    <dc:date>2019-03-11T18:17:36Z</dc:date>
    <item>
      <title>Configuring ASA Management on a sub-interface</title>
      <link>https://community.cisco.com/t5/network-security/configuring-asa-management-on-a-sub-interface/m-p/1451013#M660734</link>
      <description>&lt;P&gt;Dear All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two ASA 5520 with 4 Giga interfaces and 1 management interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to use 4 interfaces four data traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- Inside&lt;/P&gt;&lt;P&gt;2- Outside&lt;/P&gt;&lt;P&gt;3- dmz-1&lt;/P&gt;&lt;P&gt;4- dmz-2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The remaining will be the management interface only.How can I configure the Statefull failover and Management?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I did?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- I used the management0/0 for The stateful failover. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2- I used gig 0 for outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3- I used gig 1 for inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4- I used gig 2 for dmz-1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5- I divided the gig 3 to two sub interfaces&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; a- gig0/3.1 for dmz-2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; b- gig0/3.2 for Management and I defined it as a management-only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone has comments or recommendatiosn on this design? Please advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks on advance,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:17:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-asa-management-on-a-sub-interface/m-p/1451013#M660734</guid>
      <dc:creator>Ahmad Samir</dc:creator>
      <dc:date>2019-03-11T18:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring ASA Management on a sub-interface</title>
      <link>https://community.cisco.com/t5/network-security/configuring-asa-management-on-a-sub-interface/m-p/1451014#M660735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The way that you propose is fine, but what is the reason for needing a management-only interface? If it is more convenient you can manage from any interface that you are behind.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jul 2010 21:07:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-asa-management-on-a-sub-interface/m-p/1451014#M660735</guid>
      <dc:creator>August Ritchie</dc:creator>
      <dc:date>2010-07-28T21:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring ASA Management on a sub-interface</title>
      <link>https://community.cisco.com/t5/network-security/configuring-asa-management-on-a-sub-interface/m-p/1451015#M660736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear August&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just put it to follow the security standard of having a didicated management interface for the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any concern about configuring the management 0/0 with stateful and lan faiover?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Aug 2010 07:14:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-asa-management-on-a-sub-interface/m-p/1451015#M660736</guid>
      <dc:creator>Ahmad Samir</dc:creator>
      <dc:date>2010-08-01T07:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring ASA Management on a sub-interface</title>
      <link>https://community.cisco.com/t5/network-security/configuring-asa-management-on-a-sub-interface/m-p/1451016#M660737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahmad, it is recomended to have a stateful failover interface that is as fast as the fastest traffic passing interface. With your design that would have to be one if the Gig ports. This is to ensure that failover stateful info is not going to overload the failover link. I do not have the document infront of me, but im sure it is documented somewhere.&amp;nbsp;&amp;nbsp; - Magnus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Aug 2010 00:24:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-asa-management-on-a-sub-interface/m-p/1451016#M660737</guid>
      <dc:creator>Magnus Mortensen</dc:creator>
      <dc:date>2010-08-02T00:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring ASA Management on a sub-interface</title>
      <link>https://community.cisco.com/t5/network-security/configuring-asa-management-on-a-sub-interface/m-p/1451017#M660738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;as magnus suggested, it is not recommended to use management interface for state&lt;/P&gt;&lt;P&gt;ful failover&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is the link which has cisco recommendations&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml#intro"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00807dac5f.shtml#intro&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Aug 2010 05:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-asa-management-on-a-sub-interface/m-p/1451017#M660738</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-08-02T05:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring ASA Management on a sub-interface</title>
      <link>https://community.cisco.com/t5/network-security/configuring-asa-management-on-a-sub-interface/m-p/1451018#M660739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="name"&gt;Jitendriya,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks for the link. Ahmad, the key lines in that document are as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN class="name"&gt;&lt;/SPAN&gt;&lt;SPAN class="content"&gt;Cisco recommends that you do not use the management interface for &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; failover, especially for stateful failover in which the security appliance &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; constantly sends the connection information from one security appliance to the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; other. &lt;SPAN style="color: #ff0000;"&gt;The interface for failover must be at least of the same capacity as the &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interfaces that pass regular traffic&lt;/SPAN&gt;, and while the interfaces on the ASA 5540 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; are gigabit, the management interface is FastEthernet only. The management &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interface is designed for management traffic only and is specified as &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; management0/0."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Magnus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Aug 2010 05:16:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-asa-management-on-a-sub-interface/m-p/1451018#M660739</guid>
      <dc:creator>Magnus Mortensen</dc:creator>
      <dc:date>2010-08-02T05:16:13Z</dc:date>
    </item>
    <item>
      <title>Configuring ASA Management on a sub-interface</title>
      <link>https://community.cisco.com/t5/network-security/configuring-asa-management-on-a-sub-interface/m-p/1451019#M660740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm in the same situation with a pair of 5520s.&amp;nbsp; For clarification I found the following excerpt from Cisco Docs stating different requirements for various ASA models. Link at the bottom.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt; Failover Interface Speed for Stateful Links &lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1077628"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; If you use the failover link as the Stateful Failover link, you should&amp;nbsp; use the fastest Ethernet interface available. If you experience&amp;nbsp; performance problems on that interface, consider dedicating a separate&amp;nbsp; interface for the Stateful Failover interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1077629"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; Use the following failover interface speed guidelines for the adaptive security appliances: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1077630"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Cisco ASA 5510 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1077631"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; –&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="17" /&gt;Stateful link speed can be 100 Mbps, even though the data interface can operate at 1 Gigabit due to the CPU speed limitation. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1077632"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Cisco ASA 5520/5540/5550 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1077633"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; –&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="17" /&gt;Stateful link speed should match the fastest data link. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1077634"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; •&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="19" /&gt;Cisco ASA 5580/5585 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1077635"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt; –&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="17" /&gt;Use&amp;nbsp; only non-management 1 Gigabit ports for the stateful link because&amp;nbsp; management ports have lower performance and cannot meet the performance&amp;nbsp; requirement for stateful failover. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ha_overview.html#wp1078922"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/ha_overview.html#wp1078922&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Nov 2011 18:15:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/configuring-asa-management-on-a-sub-interface/m-p/1451019#M660740</guid>
      <dc:creator>Ben Quinata</dc:creator>
      <dc:date>2011-11-02T18:15:09Z</dc:date>
    </item>
  </channel>
</rss>

