cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1205
Views
0
Helpful
3
Replies

if we enable IP audit feature in physical interface, will it apply to sub-interface too ?

Senthil Murugan
Level 1
Level 1

Hi - I have a query regarding the ip audit option in Cisco ASA, We have enabled IP audit features in outside physical interface and that interface is split into 2 sub-interface. Will it be effect in both sub-interfaces ? Pls clarify.

2 Accepted Solutions

Accepted Solutions

I do not believe that it will affect the subinterfaces.  When assigning the audit policy to an interface you need to specify the interface name and the policy only affects that specific interface even if there are subinterfaces associated with that physical interface.

You can easily check this by issuing the command show ip audit count interface for each interface.  You will see that only the physical interface will have any signatures associated with it while the subinterfaces have none.

--
Please remember to rate and select a correct answer

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

That is correct.  There is no inheritence of policy based commands from the physical interface to sub-interfaces.

Sincerely,

David.

View solution in original post

3 Replies 3

I do not believe that it will affect the subinterfaces.  When assigning the audit policy to an interface you need to specify the interface name and the policy only affects that specific interface even if there are subinterfaces associated with that physical interface.

You can easily check this by issuing the command show ip audit count interface for each interface.  You will see that only the physical interface will have any signatures associated with it while the subinterfaces have none.

--
Please remember to rate and select a correct answer

--
Please remember to select a correct answer and rate helpful posts

That is correct.  There is no inheritence of policy based commands from the physical interface to sub-interfaces.

Sincerely,

David.

Thanks. I have verified it. Now i understood.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card