cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
596
Views
0
Helpful
1
Replies

ASA admin context cluster IP not reachable

MARK BAKER
Level 4
Level 4

I have a multi-context firewall configured and have recently lost the ability to log into the admin context cluster IP. I can still log into the physical interface IP of each firewall. I receive the below log message. I have two clusters and one of them is doing this. The other is working properly. Has anyone else had this issue?

NOTE: I used to be able to change the cluster master and it would start working again. Now it works for a short time after changing the cluster master, and then starts producing this log and no connectivity. Actually, if I change the cluster master and log into the cluster IP before it stops working again, that session will stay up as long as I don't log out. Any new connections will produce the below message. 

 %ASA-4-418001: Through-the-device packet to/from management-only network is denied: tcp src Management:10.2.2.142/51264 dst Management:10.1.1.110/22

1 Reply 1
Review Cisco Networking for a $25 gift card