05-31-2022 03:17 AM
Hi All,
We have a Cisco ASA that is connected to the network using a singe port-channel interface. We then use sub-interfaces for each ASA logical interface such as inside, outside and DMZ. When it comes to monitoring the logical interfaces for failover, as they are all associated to the same physical port-channel interface, does it make a difference if only one logical interface was set to monitor (such as monitor-interface inside) or if all logical interfaces are monitored?
Solved! Go to Solution.
05-31-2022 04:21 AM
Yes, you can monitor the sub-interface this work as per the logic.
Thanks,
Jitendra
05-31-2022 03:25 AM
You are correct they are Logical sub interfaces using same Physical ports-
some time it may have some reason other side go down, so monitoring sub-interface is valid here - if you looking Failover.
05-31-2022 03:52 AM
I would suggest please read the below article your query surely will resolve.. hope you will found helpfull.
Thanks,
Jitendra
05-31-2022 04:14 AM
Thanks for this. So if I read this correctly either the physical interface needs to be monitored or one of the sub-interfaces that uses this physical interface.
In my scenario I am using multi-context mode with only the port-channel sub-interfaces presented to the context. Based on the above, I should only need to monitor one sub-interface such as inside (Port-Channel1.100 - monitor-interface inside) for failover to work in the event that the port-channel interface goes down?
05-31-2022 04:21 AM
Yes, you can monitor the sub-interface this work as per the logic.
Thanks,
Jitendra
05-31-2022 11:50 AM
Yes, you can use one monitor like inside BUT what if the Queue of INSIDE sub interface in SW connect two ASA drop message because congestion??
so it better to make three logical sub interface monitor for failover.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide