<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA management Interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-management-interface/m-p/2446965#M921996</link>
    <description>&lt;P&gt;Two ASA-5510 in failover.&lt;/P&gt;&lt;P&gt;I have configured the Management Interfaces, connected to a separate VLAN, thinking that the IP address of this Interface is tied to the "physical unity.&lt;/P&gt;&lt;P&gt;That is: Primary has allways 192.168.0.1 and Secondary has allways 192.168.0.2&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;interface Management0/0&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; nameif MANAGEMENT&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; security-level 100&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; ip address 192.168.0.1 255.255.255.0&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; management-only&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Differently from the failover Interfaces, where the IP address is tied to the "role": the active unity has always 172.27.252.1 and the stand-by unity has alway 172.27.252.2&lt;/P&gt;&lt;P&gt;Or at least it was so, up to some version ago ...&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;interface Ethernet0/1&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; nameif INSIDE&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; security-level 100&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; ip address 172.27.252.1 255.255.255.240 standby 172.27.252.2&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now (9.1.4) I see that ALSO the management IP "move" together with the role.&lt;/P&gt;&lt;P&gt;And I can not set two IP address separately.&lt;/P&gt;&lt;P&gt;And this complicate the management of the two units...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this an issue of my config or and there some way to fix this problem ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Claudio&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 13:07:10 GMT</pubDate>
    <dc:creator>battanc</dc:creator>
    <dc:date>2020-02-21T13:07:10Z</dc:date>
    <item>
      <title>ASA management Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-management-interface/m-p/2446965#M921996</link>
      <description>&lt;P&gt;Two ASA-5510 in failover.&lt;/P&gt;&lt;P&gt;I have configured the Management Interfaces, connected to a separate VLAN, thinking that the IP address of this Interface is tied to the "physical unity.&lt;/P&gt;&lt;P&gt;That is: Primary has allways 192.168.0.1 and Secondary has allways 192.168.0.2&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;interface Management0/0&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; nameif MANAGEMENT&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; security-level 100&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; ip address 192.168.0.1 255.255.255.0&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; management-only&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Differently from the failover Interfaces, where the IP address is tied to the "role": the active unity has always 172.27.252.1 and the stand-by unity has alway 172.27.252.2&lt;/P&gt;&lt;P&gt;Or at least it was so, up to some version ago ...&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;interface Ethernet0/1&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; nameif INSIDE&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; security-level 100&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt; ip address 172.27.252.1 255.255.255.240 standby 172.27.252.2&lt;/EM&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now (9.1.4) I see that ALSO the management IP "move" together with the role.&lt;/P&gt;&lt;P&gt;And I can not set two IP address separately.&lt;/P&gt;&lt;P&gt;And this complicate the management of the two units...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this an issue of my config or and there some way to fix this problem ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Claudio&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-management-interface/m-p/2446965#M921996</guid>
      <dc:creator>battanc</dc:creator>
      <dc:date>2020-02-21T13:07:10Z</dc:date>
    </item>
    <item>
      <title>ASA management Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-management-interface/m-p/2446966#M921997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In your example above the first section showing a management interface configuration will result in the standby unit of an HA pair having no address on its management interface. The configuration synchronization includes the management interface configuration. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need separate direct IP reachability of the management interface, you should set it up just like your inside interface address is setup - with a standby address designated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Mar 2014 14:01:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-management-interface/m-p/2446966#M921997</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-03-04T14:01:26Z</dc:date>
    </item>
  </channel>
</rss>

