<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA -- mac address &amp; FT groups in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-mac-address-ft-groups/m-p/1103819#M895567</link>
    <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question regarding "mac address" command under "failover group"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I am using 4 contexts (Context-A, Context-B, Context-C, Context-D)&lt;/P&gt;&lt;P&gt;and each context has 4 subinterfaces assigned out of which "outside interface is shared by all contexts"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What will be impact of the following commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover group 1&lt;/P&gt;&lt;P&gt;    mac address Ethernet0 0000.1111.2222 0000.1111.2223  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover group 2&lt;/P&gt;&lt;P&gt;    mac address Ethernet0 0000.2222.3333 0000.2222.3334&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Context-A &amp;amp; context-B are in FT Group 1 &amp;amp; remaining contexts are in FT Group 2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that "mac address auto" command will take care of the shared outside interface by automatically&lt;/P&gt;&lt;P&gt;assigning unique MAC addresses to the shared interfaces in the contexts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is about the non-shared interface. What Mac addresses will get assigned to these interfaces&lt;/P&gt;&lt;P&gt;with the commands I mentioned above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q1. Will the MAC address "0000.1111.2222" configured under "FT group 1"  will get assigned to "all the &lt;/P&gt;&lt;P&gt;interfaces" allocated to all the contexts assigned to "FT group 1". ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q2. What is the significance of standby mac address in this command? Will these addresses be switched &lt;/P&gt;&lt;P&gt;    during a failover&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would appreciate if someone can show me the "CLI outputs" on ASAs to make things clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in Advance&lt;/P&gt;&lt;P&gt;A.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 13:52:20 GMT</pubDate>
    <dc:creator>AnthonyGZ</dc:creator>
    <dc:date>2019-03-11T13:52:20Z</dc:date>
    <item>
      <title>ASA -- mac address &amp; FT groups</title>
      <link>https://community.cisco.com/t5/network-security/asa-mac-address-ft-groups/m-p/1103819#M895567</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a question regarding "mac address" command under "failover group"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I am using 4 contexts (Context-A, Context-B, Context-C, Context-D)&lt;/P&gt;&lt;P&gt;and each context has 4 subinterfaces assigned out of which "outside interface is shared by all contexts"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What will be impact of the following commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover group 1&lt;/P&gt;&lt;P&gt;    mac address Ethernet0 0000.1111.2222 0000.1111.2223  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;failover group 2&lt;/P&gt;&lt;P&gt;    mac address Ethernet0 0000.2222.3333 0000.2222.3334&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Context-A &amp;amp; context-B are in FT Group 1 &amp;amp; remaining contexts are in FT Group 2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that "mac address auto" command will take care of the shared outside interface by automatically&lt;/P&gt;&lt;P&gt;assigning unique MAC addresses to the shared interfaces in the contexts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is about the non-shared interface. What Mac addresses will get assigned to these interfaces&lt;/P&gt;&lt;P&gt;with the commands I mentioned above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q1. Will the MAC address "0000.1111.2222" configured under "FT group 1"  will get assigned to "all the &lt;/P&gt;&lt;P&gt;interfaces" allocated to all the contexts assigned to "FT group 1". ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q2. What is the significance of standby mac address in this command? Will these addresses be switched &lt;/P&gt;&lt;P&gt;    during a failover&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would appreciate if someone can show me the "CLI outputs" on ASAs to make things clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in Advance&lt;/P&gt;&lt;P&gt;A.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:52:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-mac-address-ft-groups/m-p/1103819#M895567</guid>
      <dc:creator>AnthonyGZ</dc:creator>
      <dc:date>2019-03-11T13:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA -- mac address &amp; FT groups</title>
      <link>https://community.cisco.com/t5/network-security/asa-mac-address-ft-groups/m-p/1103820#M895570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The standby Mac address is used to avoid having duplicate MAC addresses in the network, by assigning each physical interface a virtual active and standby MAC address.When Failover occurs the Active MAC address gets swithced form the device which was active before failover to the device which is active after failover.Similarly the static MAC address gets switched from the standby device before faiover to the standby device after faiover.thus the Active Mac address is always present with the active device and the Static MAC Address is present with the standyby device always.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2008 14:37:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-mac-address-ft-groups/m-p/1103820#M895570</guid>
      <dc:creator>sadbulali</dc:creator>
      <dc:date>2008-10-08T14:37:56Z</dc:date>
    </item>
  </channel>
</rss>

