<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic pix 8.0 security context in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-8-0-security-context/m-p/1257947#M824105</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;i want to have two security context for active/active failover. but I have a problem with the admin context&lt;/P&gt;&lt;P&gt;I want the context 1 to be empty and the context 2 to contient one gateway(on outside interface) and several vlans.&lt;/P&gt;&lt;P&gt;The context2 will be part of the failover group2 wich willbe active on security appliance2.&lt;/P&gt;&lt;P&gt;the context 1 will be part of the failover group1 wich will be active on security appliance1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But wath do I do with the admin context? wath do I put or remove from this context? does it have to contains all the interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I have 802.1Q trunks for&amp;nbsp; both, outside &amp;amp; inside interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want&amp;nbsp; vlan2, vlan3, vlan4,vlan5 in the inside &amp;amp; vlan 10, vlan 11 in the outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security appliance1 would have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context context1&lt;BR /&gt;&amp;nbsp; allocate-interface GigabitEthernet0.10 outside_context1&lt;BR /&gt;&amp;nbsp; allocate-interface GigabitEthernet1.2 vlan2&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.3 vlan3&lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url flash:/context1.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context context2&lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url flash:/context2.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security appliance2 would have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context context1&lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url flash:/context1.cfg&lt;/P&gt;&lt;P&gt;context context2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; allocate-interface GigabitEthernet0.11 outside_context1&lt;BR /&gt;&amp;nbsp;&amp;nbsp; allocate-interface GigabitEthernet1.4 vlan4&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.5 vlan5&lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url flash:/context2.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wath about context admin wath do I out or wath doit remove?&lt;/P&gt;&lt;P&gt;Actually it has everithing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context admin&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet0.10&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet0.11&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.2&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.3&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.4 &lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.5&lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url flash:/admin.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks you very much&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 16:41:59 GMT</pubDate>
    <dc:creator>roussillon</dc:creator>
    <dc:date>2019-03-11T16:41:59Z</dc:date>
    <item>
      <title>pix 8.0 security context</title>
      <link>https://community.cisco.com/t5/network-security/pix-8-0-security-context/m-p/1257947#M824105</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;i want to have two security context for active/active failover. but I have a problem with the admin context&lt;/P&gt;&lt;P&gt;I want the context 1 to be empty and the context 2 to contient one gateway(on outside interface) and several vlans.&lt;/P&gt;&lt;P&gt;The context2 will be part of the failover group2 wich willbe active on security appliance2.&lt;/P&gt;&lt;P&gt;the context 1 will be part of the failover group1 wich will be active on security appliance1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But wath do I do with the admin context? wath do I put or remove from this context? does it have to contains all the interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I have 802.1Q trunks for&amp;nbsp; both, outside &amp;amp; inside interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want&amp;nbsp; vlan2, vlan3, vlan4,vlan5 in the inside &amp;amp; vlan 10, vlan 11 in the outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security appliance1 would have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context context1&lt;BR /&gt;&amp;nbsp; allocate-interface GigabitEthernet0.10 outside_context1&lt;BR /&gt;&amp;nbsp; allocate-interface GigabitEthernet1.2 vlan2&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.3 vlan3&lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url flash:/context1.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context context2&lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url flash:/context2.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security appliance2 would have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context context1&lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url flash:/context1.cfg&lt;/P&gt;&lt;P&gt;context context2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; allocate-interface GigabitEthernet0.11 outside_context1&lt;BR /&gt;&amp;nbsp;&amp;nbsp; allocate-interface GigabitEthernet1.4 vlan4&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.5 vlan5&lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url flash:/context2.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wath about context admin wath do I out or wath doit remove?&lt;/P&gt;&lt;P&gt;Actually it has everithing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context admin&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet0.10&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet0.11&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.2&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.3&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.4 &lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.5&lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url flash:/admin.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks you very much&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:41:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-8-0-security-context/m-p/1257947#M824105</guid>
      <dc:creator>roussillon</dc:creator>
      <dc:date>2019-03-11T16:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: pix 8.0 security context</title>
      <link>https://community.cisco.com/t5/network-security/pix-8-0-security-context/m-p/1257948#M824135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;roussillon wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;i want to have two security context for active/active failover. but I have a problem with the admin context&lt;/P&gt;&lt;P&gt;I want the context 1 to be empty and the context 2 to contient one gateway(on outside interface) and several vlans.&lt;/P&gt;&lt;P&gt;The context2 will be part of the failover group2 wich willbe active on security appliance2.&lt;/P&gt;&lt;P&gt;the context 1 will be part of the failover group1 wich will be active on security appliance1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But wath do I do with the admin context? wath do I put or remove from this context? does it have to contains all the interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I have 802.1Q trunks for&amp;nbsp; both, outside &amp;amp; inside interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want&amp;nbsp; vlan2, vlan3, vlan4,vlan5 in the inside &amp;amp; vlan 10, vlan 11 in the outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security appliance1 would have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context context1&lt;BR /&gt;&amp;nbsp; allocate-interface GigabitEthernet0.10 outside_context1&lt;BR /&gt;&amp;nbsp; allocate-interface GigabitEthernet1.2 vlan2&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.3 vlan3&lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url flash:/context1.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context context2&lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url flash:/context2.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security appliance2 would have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context context1&lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url flash:/context1.cfg&lt;/P&gt;&lt;P&gt;context context2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; allocate-interface GigabitEthernet0.11 outside_context1&lt;BR /&gt;&amp;nbsp;&amp;nbsp; allocate-interface GigabitEthernet1.4 vlan4&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.5 vlan5&lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url flash:/context2.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wath about context admin wath do I out or wath doit remove?&lt;/P&gt;&lt;P&gt;Actually it has everithing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context admin&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet0.10&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet0.11&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.2&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.3&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.4 &lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface GigabitEthernet1.5&lt;/P&gt;&lt;P&gt;&amp;nbsp; config-url flash:/admin.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks you very much&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The admin context is used purely for administering the ASA so it doesn't need to have all the interfaces in it. It should have it's own interfaces that ar used purely to remotely logon to the ASA and also for remotely accessing config files etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Nov 2009 11:24:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-8-0-security-context/m-p/1257948#M824135</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-11-24T11:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: pix 8.0 security context</title>
      <link>https://community.cisco.com/t5/network-security/pix-8-0-security-context/m-p/1257949#M824154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes it worked, Thank.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but&amp;nbsp; I can not make ping &amp;amp; traceroute work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I added&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;access-list outside_access_in extended permit icmp any any time-exceeded log disable &lt;BR /&gt;access-list outside_access_in extended permit icmp any any echo-reply log disable&lt;BR /&gt;&lt;BR /&gt;access-group outside_access_in in interface outside&lt;BR /&gt;&lt;BR /&gt;It works fine in single mode but it seems to have no effect in context mode&lt;BR /&gt;&lt;BR /&gt;is there something missing?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Nov 2009 17:09:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-8-0-security-context/m-p/1257949#M824154</guid>
      <dc:creator>roussillon</dc:creator>
      <dc:date>2009-11-24T17:09:48Z</dc:date>
    </item>
  </channel>
</rss>

