<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FIPS enable ASA 5515  - Port-Channel Break in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fips-enable-asa-5515-port-channel-break/m-p/3342738#M968043</link>
    <description>&lt;P&gt;Current Setup: ASA 5515 - Active/Standby pair&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Situation: Need to make currently running ASA 5515 FIPS complaint - cisco support said at least one port needs to be single port&amp;nbsp;by itself before "fips enable" is implemented and not in port-channel.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are thinking to break port channel interface that has outside and management sub-interfaces to it and assign these two sub-interfaces to single gig&amp;nbsp; interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Question: would we lose any config related to outside and management interface?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Question: what is the best way to approach this re-config of the ASA? Example: break port channel or remove the single interface from port channel and configure that?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Question: do you have any experience with FIPS upgrade on currently working devices?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:28:31 GMT</pubDate>
    <dc:creator>aamsq11</dc:creator>
    <dc:date>2020-02-21T15:28:31Z</dc:date>
    <item>
      <title>FIPS enable ASA 5515  - Port-Channel Break</title>
      <link>https://community.cisco.com/t5/network-security/fips-enable-asa-5515-port-channel-break/m-p/3342738#M968043</link>
      <description>&lt;P&gt;Current Setup: ASA 5515 - Active/Standby pair&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Situation: Need to make currently running ASA 5515 FIPS complaint - cisco support said at least one port needs to be single port&amp;nbsp;by itself before "fips enable" is implemented and not in port-channel.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are thinking to break port channel interface that has outside and management sub-interfaces to it and assign these two sub-interfaces to single gig&amp;nbsp; interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Question: would we lose any config related to outside and management interface?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Question: what is the best way to approach this re-config of the ASA? Example: break port channel or remove the single interface from port channel and configure that?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Question: do you have any experience with FIPS upgrade on currently working devices?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:28:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fips-enable-asa-5515-port-channel-break/m-p/3342738#M968043</guid>
      <dc:creator>aamsq11</dc:creator>
      <dc:date>2020-02-21T15:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS enable ASA 5515  - Port-Channel Break</title>
      <link>https://community.cisco.com/t5/network-security/fips-enable-asa-5515-port-channel-break/m-p/3343087#M968044</link>
      <description>&lt;P&gt;Anytime you need to reassign an interface you have to use "no nameif ___". that command will remove any associated ACLs and NAT commands that reference that nameif. As long as you know that in advance and take it into account you should be fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've not done a FIPS conversion but I know there are several other requirements for compliance - the hardware anti-tamper kit as well as some operational procedures - that are required for full compliance.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 11:04:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fips-enable-asa-5515-port-channel-break/m-p/3343087#M968044</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-03-06T11:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS enable ASA 5515  - Port-Channel Break</title>
      <link>https://community.cisco.com/t5/network-security/fips-enable-asa-5515-port-channel-break/m-p/3343347#M968088</link>
      <description>&lt;P&gt;Thanks for the response Marvin. Since running the command "no nameif" will remove configuration then:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;can we have a port-channel with only single interface being part of it? or will the port-channel break once we remove one interface out of the two it currently has?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also, will the "no nameif" command remove any configs related to the interface like (VPN tunnels, digital certs, etc...) or just ACL and NATs?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 16:10:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fips-enable-asa-5515-port-channel-break/m-p/3343347#M968088</guid>
      <dc:creator>aamsq11</dc:creator>
      <dc:date>2018-03-06T16:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: FIPS enable ASA 5515  - Port-Channel Break</title>
      <link>https://community.cisco.com/t5/network-security/fips-enable-asa-5515-port-channel-break/m-p/3343369#M968091</link>
      <description>&lt;P&gt;You can have a portchannel with a single member.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you "no nameif" an interface, the lines anywhere the nameif appears in the rest of the configuration will be removed. I mentioned the most common ones but the ones you mentioned and a few others would also be affected.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 16:32:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fips-enable-asa-5515-port-channel-break/m-p/3343369#M968091</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-03-06T16:32:22Z</dc:date>
    </item>
  </channel>
</rss>

