<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5580 Failover Using Sub-Interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5580-failover-using-sub-interface/m-p/1259515#M791546</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the ASA5580-20 I have:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - 2 * 10Gig LC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - 2 * 1gig Mgmt port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how can I configure FO without using one of these interafces? what are your recommendations?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 25 Nov 2009 08:33:13 GMT</pubDate>
    <dc:creator>netsec</dc:creator>
    <dc:date>2009-11-25T08:33:13Z</dc:date>
    <item>
      <title>ASA 5580 Failover Using Sub-Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-failover-using-sub-interface/m-p/1259512#M791543</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an ASA5580-20 with 2 port of 10Gig. I have configured the A/S failover usiasang suinterface in "interface TenGigabitEthernet7/1" interface. it work fine. but the problem I have is I can't assign any subinterface to any context. is that a bug?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface TenGigabitEthernet7/1&lt;BR /&gt;!&lt;BR /&gt;interface TenGigabitEthernet7/1.94&lt;BR /&gt; description LAN Failover Interface&lt;BR /&gt; vlan 94&lt;BR /&gt;!&lt;BR /&gt;interface TenGigabitEthernet7/1.95&lt;BR /&gt; description STATE Failover Interface&lt;BR /&gt; vlan 95&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;interface TenGigabitEthernet7/1.100&lt;BR /&gt; vlan 100&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;interface TenGigabitEthernet7/1.200&lt;BR /&gt; vlan 200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw(config)# context admin&lt;BR /&gt;fw(config-ctx)# allocate-interface TenGigabitEthernet7/1.100&lt;BR /&gt;ERROR: Interface TenGigabitEthernet7/1.100 cannot be allocated to context. Interface is being used by failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so according to this ERROR, I can use any sub interface for my traffic data, Am I wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Reda&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:42:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-failover-using-sub-interface/m-p/1259512#M791543</guid>
      <dc:creator>netsec</dc:creator>
      <dc:date>2019-03-11T16:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5580 Failover Using Sub-Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-failover-using-sub-interface/m-p/1259513#M791544</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I find the answer: &lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa81/config/guide/failover.html#wp1061397" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa81/config/guide/failover.html#wp1061397&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;============================================&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pSN_StepNext"&gt;&lt;STRONG&gt;Step 5 &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="5" /&gt;(Optional) To enable Stateful Failover, configure the Stateful Failover link.&lt;/P&gt;&lt;A name="wp1066369"&gt;&lt;/A&gt;&lt;P class="pSsF_StepsubFirst"&gt;&lt;STRONG&gt; a. &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="10" /&gt;Specify the interface to be used as Stateful Failover link.&lt;/P&gt;&lt;A name="wp1066373"&gt;&lt;/A&gt;&lt;DIV class="pEx2_Example2"&gt;&lt;PRE&gt;hostname(config)# &lt;SPAN class="cExBold"&gt;failover link&lt;/SPAN&gt; &lt;EM class="cExItalic"&gt;if_name&lt;/EM&gt; &lt;EM class="cExItalic"&gt;phy_if&lt;BR /&gt;&lt;/EM&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;DIV class="pPreformatted"&gt;&lt;PRE class="pPreformatted"&gt;&lt;A name="wp1066374"&gt;&lt;/A&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;DIV class="Note3"&gt;&lt;IMG src="http://www.cisco.com/en/US/i/templates/note.gif" /&gt;&lt;/DIV&gt;&lt;HR class="Note3" /&gt;&lt;A name="wp1066375"&gt;&lt;/A&gt;&lt;P class="pN3_Note3"&gt;&lt;STRONG&gt;Note &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="6" /&gt;If the Stateful Failover link uses the failover link or a data interface, then you only need to supply the &lt;EM class="cEmphasis"&gt;if_name&lt;/EM&gt; argument.&lt;/P&gt;&lt;HR class="Note3" /&gt;&lt;A name="wp1069248"&gt;&lt;/A&gt;&lt;P class="pB2_Body2"&gt;The &lt;EM class="cEmphasis"&gt;if_name&lt;/EM&gt; argument assigns a logical name to the interface specified by the &lt;EM class="cEmphasis"&gt;phy_if&lt;/EM&gt; argument. The &lt;EM class="cArgument"&gt;phy_if&lt;/EM&gt; argument can be the physical port name, such as Ethernet1, or a previously created subinterface, such as Ethernet0/2.3. This interface should not be used for any other purpose (except, optionally, the failover link).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;============================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is it a Cisco Bug?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So we're obliged to use Management port if we plan to order the ASA5580 with only 1 TenGig module &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your feedback Cisco guys.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Nov 2009 12:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-failover-using-sub-interface/m-p/1259513#M791544</guid>
      <dc:creator>netsec</dc:creator>
      <dc:date>2009-11-24T12:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5580 Failover Using Sub-Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-failover-using-sub-interface/m-p/1259514#M791545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would not suggest you to use a management interface as the failover link. The reason is that it is not optimized for traffic so if you have high connection rates it might not be able to pass the failover updates of state information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason you see the problem there, as you probably figured, is that the failover is dedicated link, it cannot be used to pass failover info and real traffic at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest at lest 2 oprimized interfaces, one for traffic and subinterfaces and one for failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Nov 2009 14:19:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-failover-using-sub-interface/m-p/1259514#M791545</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2009-11-24T14:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5580 Failover Using Sub-Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-failover-using-sub-interface/m-p/1259515#M791546</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the ASA5580-20 I have:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - 2 * 10Gig LC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - 2 * 1gig Mgmt port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how can I configure FO without using one of these interafces? what are your recommendations?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Nov 2009 08:33:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-failover-using-sub-interface/m-p/1259515#M791546</guid>
      <dc:creator>netsec</dc:creator>
      <dc:date>2009-11-25T08:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5580 Failover Using Sub-Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5580-failover-using-sub-interface/m-p/1259516#M791547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a good rule of thumb. The failover link should be as fast as the fastest interface in the box. You can use this same&lt;/P&gt;&lt;P&gt;interface for state as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Think about this. You have 4 Gig interfaces and one management 100 mb interface.&amp;nbsp; It is not a good idea to use the mgmt inteface for failover link and state to pump all the state updates for all Gig interfaces over this 100 MB link.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Nov 2009 13:57:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5580-failover-using-sub-interface/m-p/1259516#M791547</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-11-25T13:57:51Z</dc:date>
    </item>
  </channel>
</rss>

