cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1909
Views
0
Helpful
4
Replies

Traffic cannot send out through Management Interface of ASA

chanda_eng
Level 1
Level 1

Dear Team,

 

Currently i have ASA 5525 that configured SNMP information sent out through management interface of ASA, but it is not work. And i try to use another gigabit port instead, it works fine. So what was the problem on management of ASA. Thanks!

4 Replies 4

AFROJ AHMAD
Cisco Employee
Cisco Employee

Kindly explain more on the issue , may be with the help of output or error.

 

SNMP traps \SNMP polling does not works  with MGMT interface ?

 

Thanks-

Afroz
 

Thanks- Afroz [Do rate the useful post] ****Ratings Encourages Contributors ****

I don't have any error output, I just noticed that when i configure snmp traps \snmp to send information through management interface of ASA, it was not work that we could not collect snmp information from my ASA device "snmp-server host management 172.16.5.201 community secret".

 

But when i use the same configuration on interface inside of my ASA, The monitor software can collect snmp information well. "snmp-server host Inside 172.16.5.201 community secret".

It is correct that any traffic cannot send out through MGMT interface of ASA?

The ASA can originate traffic from the management interface. Whether or not it can establish two way communications usually depends on the routing setup. (Note the ASA will not forward traffic through the management interface to or from other interfaces.)

A major limitation is that the ASA only has a single routing table. So when your command is set to send traffic to a host via the management interface but the ASA believes due to its routing table that the inside interface has the most specific route to that host, it will fail.

Most people decide to forgo the management interface of the ASA due to this fact, unless they have a dedicated out of band management network. One work around to make it work is to but a /32 host route on the ASA for the specific host you desire to communicate with via the management interface.

i just get the logs from ASDM

"2015|12:37:07|106014|10.1.1.111||172.16.5.201||Deny inbound icmp src PCCS:10.1.1.111 dst management:172.16.5.201 (type 0, code 0) 4|Jun 20 "