cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
11484
Views
5
Helpful
4
Replies

ASA Management Interface default gateway

Hi,

 

We are using 5506x version 9.8.x with firepower. We wanted to manage SFR and ASA with IPs(192.168.1.x) from subnet behind the ASA indside interface. This subnet is terminated in L3 switch behind ASA. 

We have a route for this subnet (192.168.1.x) in ASA towards L3 switch. ASA management interface is connected in the switch and SFR is configured with IP 192.168.1.10 and working properly.

can we use the same mgmt interface to mange ASA ?

If i assign an IP on  Management1/1 from 192.168.1.x, we will be able to manage firewall via this IP ? Which default gateway do mgmt interface routing table prefer ? if mgmt routing table is maintained separately, how do i define default gateway for Mgmt interface ?

Subnet 192.168.1.x will be considered as directly connected subnet in ASA ? 

 

 

 

2 Accepted Solutions

Accepted Solutions

Dennis Mink
VIP Alumni
VIP Alumni

add: route management 0.0.0.0 0.0.0.0 10.10.10.1  for instance

 

that should do it (this is off an asa running 9.8)

Please remember to rate useful posts, by clicking on the stars below.

View solution in original post

Yes. I tried to add the IP and route. ASA is treating MGMT routing table as different than the global routing table. I am able to manage ASA as well as the SFR with the same interface on different IP from the same subnet.

 

Thank you all

View solution in original post

4 Replies 4

Florin Barhala
Level 6
Level 6
I don't think you can have a SEPARATE default gw for the mgmt "routing table" - unless Cisco has released this feature recently and I' not aware of it.
What you can do instead is to configure routing information for the mgmt hosts you use to manage the ASA. You can do this through static routes - but this might alter some production traffic or you can do PBR aka for you mgmt. station traffic on ASA will use mgmt interface rather than what's on the routing table already.

Dennis Mink
VIP Alumni
VIP Alumni

add: route management 0.0.0.0 0.0.0.0 10.10.10.1  for instance

 

that should do it (this is off an asa running 9.8)

Please remember to rate useful posts, by clicking on the stars below.

So will this basically "create two routing tables" on that ASA?

Yes. I tried to add the IP and route. ASA is treating MGMT routing table as different than the global routing table. I am able to manage ASA as well as the SFR with the same interface on different IP from the same subnet.

 

Thank you all

Review Cisco Networking for a $25 gift card