cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
988
Views
10
Helpful
2
Replies

Context FW 'mac-address auto'

johnlloyd_13
Level 9
Level 9

hi,

i'm going to configure a multiple context FW on a new ASA5525-X.

i saw previous setup with and without the 'mac-address auto' command under the system context.

my question is, is the command required or optional?

if not enabled, will this cause 'asymmetric' routing issue towards a specific context?

2 Replies 2

It can work with and without this command.

By default, contexts sharing same interface will have the same mac address
for the interface in each context which is the mac of the physical
interface. When the packets forwarded from the upstream device to the
multi-context firewall, the firewall will use the destination IP address to
identify the right context because all contexts share the same destination
mac (For the shared interface). To get destination IP used, you need to
configure NAT rules for that destination address (unity NAT or identity
NAT). This method has other limitations.

With this command, each presence of the share interface per context will
have a uniquely generated MAC address started with A2.

In you don't share any interface between contexts then you don't have
problems and this command isn't needed. However, if you have shared
interfaces the best practice is to enable this command.

From version 9.3 this command is enable auto so you don’t have to config this.

 If you using nat on the box it will use the nat sequence number to create a sessions 

please do not forget to rate.
Review Cisco Networking products for a $25 gift card