<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA-5520 Multiple-context - Mgmt Inteface problem... in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-multiple-context-mgmt-inteface-problem/m-p/926125#M937880</link>
    <description>&lt;P&gt;I have the following issue with the management interface of an ASA5520 running version 7.0(7).&lt;/P&gt;&lt;P&gt;I'm currently using two contexts in transparent mode.&lt;/P&gt;&lt;P&gt;The management interface is currently assigned to the admin-context and is physically connected to a cat4500 switch in a management Vlan.&lt;/P&gt;&lt;P&gt;The issue is that I have intermitent communication with this IP address from the 4500 and I just can't explain what's going on, the IP address configured in the management port is not repeated in the vlan and the interface vlan in the 4500 is always UP.&lt;/P&gt;&lt;P&gt;This is the configuration I am using in ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*****system space*****&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall transparent&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;admin-context admin&lt;/P&gt;&lt;P&gt;context admin&lt;/P&gt;&lt;P&gt;  allocate-interface GigabitEthernet0/0 &lt;/P&gt;&lt;P&gt;  allocate-interface GigabitEthernet0/1 &lt;/P&gt;&lt;P&gt;  allocate-interface Management0/0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;context VPN&lt;/P&gt;&lt;P&gt;  allocate-interface GigabitEthernet0/2 &lt;/P&gt;&lt;P&gt;  allocate-interface GigabitEthernet0/3 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;****CONTEXT ADMIN******&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif gestion&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list 199 extended permit ip any any &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;mtu gestion 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;ip address 10.8.129.254 255.255.255.0&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;access-group 199 in interface gestion&lt;/P&gt;&lt;P&gt;access-group 100 in interface inside&lt;/P&gt;&lt;P&gt;access-group 101 in interface outside&lt;/P&gt;&lt;P&gt;route gestion 0.0.0.0 0.0.0.0 10.8.129.1 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 10.0.0.0 255.0.0.0 gestion&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;ssh version 1&lt;/P&gt;&lt;P&gt;dhcpd lease 3600      &lt;/P&gt;&lt;P&gt;dhcpd ping_timeout 50&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I explained it is possible to log into the ASA using SSH but the connection is dropped at some point.  I also need to upgrade the software version but the tftp session is dropped due to lack of conectivity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody have a clue regarding the possible solution?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:43:39 GMT</pubDate>
    <dc:creator>javiercastro</dc:creator>
    <dc:date>2019-03-11T12:43:39Z</dc:date>
    <item>
      <title>ASA-5520 Multiple-context - Mgmt Inteface problem...</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-multiple-context-mgmt-inteface-problem/m-p/926125#M937880</link>
      <description>&lt;P&gt;I have the following issue with the management interface of an ASA5520 running version 7.0(7).&lt;/P&gt;&lt;P&gt;I'm currently using two contexts in transparent mode.&lt;/P&gt;&lt;P&gt;The management interface is currently assigned to the admin-context and is physically connected to a cat4500 switch in a management Vlan.&lt;/P&gt;&lt;P&gt;The issue is that I have intermitent communication with this IP address from the 4500 and I just can't explain what's going on, the IP address configured in the management port is not repeated in the vlan and the interface vlan in the 4500 is always UP.&lt;/P&gt;&lt;P&gt;This is the configuration I am using in ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*****system space*****&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall transparent&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;admin-context admin&lt;/P&gt;&lt;P&gt;context admin&lt;/P&gt;&lt;P&gt;  allocate-interface GigabitEthernet0/0 &lt;/P&gt;&lt;P&gt;  allocate-interface GigabitEthernet0/1 &lt;/P&gt;&lt;P&gt;  allocate-interface Management0/0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;context VPN&lt;/P&gt;&lt;P&gt;  allocate-interface GigabitEthernet0/2 &lt;/P&gt;&lt;P&gt;  allocate-interface GigabitEthernet0/3 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;****CONTEXT ADMIN******&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif gestion&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list 199 extended permit ip any any &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;mtu gestion 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;ip address 10.8.129.254 255.255.255.0&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;access-group 199 in interface gestion&lt;/P&gt;&lt;P&gt;access-group 100 in interface inside&lt;/P&gt;&lt;P&gt;access-group 101 in interface outside&lt;/P&gt;&lt;P&gt;route gestion 0.0.0.0 0.0.0.0 10.8.129.1 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 10.0.0.0 255.0.0.0 gestion&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;ssh version 1&lt;/P&gt;&lt;P&gt;dhcpd lease 3600      &lt;/P&gt;&lt;P&gt;dhcpd ping_timeout 50&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I explained it is possible to log into the ASA using SSH but the connection is dropped at some point.  I also need to upgrade the software version but the tftp session is dropped due to lack of conectivity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody have a clue regarding the possible solution?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:43:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-multiple-context-mgmt-inteface-problem/m-p/926125#M937880</guid>
      <dc:creator>javiercastro</dc:creator>
      <dc:date>2019-03-11T12:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA-5520 Multiple-context - Mgmt Inteface problem...</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-multiple-context-mgmt-inteface-problem/m-p/926126#M937882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The adaptive security appliance has a dedicated interface for device management that is referred to as the Management0/0 port. The Management0/0 port is a Fast Ethernet interface. This port is similar to the Console port, but the Management0/0 port only accepts incoming traffic to the adaptive security appliance.You can configure any interface to be a management-only interface using the management-only command. You can also disable management-only mode on the management interface. For more information about this command, see the management-only command in the Cisco Security Appliance Command Reference prsent in the link below:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/intparam.html#wp1051819" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/intparam.html#wp1051819&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;refer the link below for troubleshooting guide:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/trouble.html#wp1042019" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/trouble.html#wp1042019&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 May 2008 20:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-multiple-context-mgmt-inteface-problem/m-p/926126#M937882</guid>
      <dc:creator>smahbub</dc:creator>
      <dc:date>2008-05-16T20:41:18Z</dc:date>
    </item>
  </channel>
</rss>

