<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA traffic redirection to Sourcefile in Multiple Contexts in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-traffic-redirection-to-sourcefile-in-multiple-contexts/m-p/3214162#M926719</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Can you verify that this is not happening?&lt;BR /&gt;You cannot configure both inline tap monitor-only mode and normal inline mode at the same time on the&lt;BR /&gt;ASA. Only one type of security policy is allowed. In multiple context mode, you cannot configure inline&lt;BR /&gt;tap monitor-only mode for some contexts, and regular inline mode for others.&lt;BR /&gt;&lt;BR /&gt;On page 3:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa92/asdm72/firewall/asa-firewall-asdm/modules-sfr.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa92/asdm72/firewall/asa-firewall-asdm/modules-sfr.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;br, Micke&lt;BR /&gt;</description>
    <pubDate>Thu, 09 Nov 2017 20:04:50 GMT</pubDate>
    <dc:creator>mikael.lahtela</dc:creator>
    <dc:date>2017-11-09T20:04:50Z</dc:date>
    <item>
      <title>ASA traffic redirection to Sourcefile in Multiple Contexts</title>
      <link>https://community.cisco.com/t5/network-security/asa-traffic-redirection-to-sourcefile-in-multiple-contexts/m-p/3213762#M926718</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had issues configuring traffic redirection on ASA's configured with multiple contexts.&lt;/P&gt;
&lt;P&gt;I can create a new class-map within each context and enable monitor mode. However when I want I want to disable monitor mode and configure inline via ASDM I receive an error:&lt;/P&gt;
&lt;P&gt;[Error] sfr fail-open command failed.&lt;/P&gt;
&lt;P&gt;I am able to configure without errors via the admin context.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA Ver 9.6.3(1)&lt;/P&gt;
&lt;P&gt;ASDM Ver 7.7.1(151)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Documentation suggests that the redirection should be configured within each context.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any suggestions or clarification would be appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ian&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:41:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-traffic-redirection-to-sourcefile-in-multiple-contexts/m-p/3213762#M926718</guid>
      <dc:creator>iwearing</dc:creator>
      <dc:date>2020-02-21T14:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA traffic redirection to Sourcefile in Multiple Contexts</title>
      <link>https://community.cisco.com/t5/network-security/asa-traffic-redirection-to-sourcefile-in-multiple-contexts/m-p/3214162#M926719</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Can you verify that this is not happening?&lt;BR /&gt;You cannot configure both inline tap monitor-only mode and normal inline mode at the same time on the&lt;BR /&gt;ASA. Only one type of security policy is allowed. In multiple context mode, you cannot configure inline&lt;BR /&gt;tap monitor-only mode for some contexts, and regular inline mode for others.&lt;BR /&gt;&lt;BR /&gt;On page 3:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa92/asdm72/firewall/asa-firewall-asdm/modules-sfr.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa92/asdm72/firewall/asa-firewall-asdm/modules-sfr.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;br, Micke&lt;BR /&gt;</description>
      <pubDate>Thu, 09 Nov 2017 20:04:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-traffic-redirection-to-sourcefile-in-multiple-contexts/m-p/3214162#M926719</guid>
      <dc:creator>mikael.lahtela</dc:creator>
      <dc:date>2017-11-09T20:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA traffic redirection to Sourcefile in Multiple Contexts</title>
      <link>https://community.cisco.com/t5/network-security/asa-traffic-redirection-to-sourcefile-in-multiple-contexts/m-p/3216324#M926720</link>
      <description>Hi Micke,&lt;BR /&gt;&lt;BR /&gt;I deleted the redirection class map from both contexts.&lt;BR /&gt;&lt;BR /&gt;I created a new class map on one context only and the policy still fails when trying to apply online.  I can still configure in monitor mode only..&lt;BR /&gt;&lt;BR /&gt;Br&lt;BR /&gt;&lt;BR /&gt;Ian&lt;BR /&gt;</description>
      <pubDate>Tue, 14 Nov 2017 14:24:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-traffic-redirection-to-sourcefile-in-multiple-contexts/m-p/3216324#M926720</guid>
      <dc:creator>iwearing</dc:creator>
      <dc:date>2017-11-14T14:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA traffic redirection to Sourcefile in Multiple Contexts</title>
      <link>https://community.cisco.com/t5/network-security/asa-traffic-redirection-to-sourcefile-in-multiple-contexts/m-p/3216522#M926721</link>
      <description>&lt;P&gt;This has been working for me:&lt;/P&gt;
&lt;P&gt;admin context:&lt;BR /&gt;Nothing&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;contextA:&lt;/P&gt;
&lt;PRE&gt;access-list contextA-inside_mpc extended permit ip any any
!
class-map contextA-inside-class-sfr
match access-list contextA-inside_mpc
!
policy-map contextA-inside-policy
class contextA-inside-class-sfr
sfr fail-open
!&lt;/PRE&gt;
&lt;P&gt;contextB:&lt;/P&gt;
&lt;PRE&gt;access-list contextB-inside_mpc extended permit ip any any
!
class-map contextB-inside-class-sfr
match access-list contextB-inside_mpc
!
policy-map contextB-inside-policy
class contextB-inside-class-sfr
sfr fail-open&lt;/PRE&gt;</description>
      <pubDate>Tue, 14 Nov 2017 19:27:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-traffic-redirection-to-sourcefile-in-multiple-contexts/m-p/3216522#M926721</guid>
      <dc:creator>mikael.lahtela</dc:creator>
      <dc:date>2017-11-14T19:27:31Z</dc:date>
    </item>
  </channel>
</rss>

