cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
994
Views
0
Helpful
3
Replies

MultiContext - Vlan Subinterface Deletion

Hi Experts,

 

We're running Multi-context Active/standby firewalls on the version 9.8.4.35. We have been asked to delete the VLAN sub-interfaces, it's access-lists and access-groups.

Not sure if the sub-interface should be removed first from the specific context or from the system space.

Please assist with the order to be followed or the best practice?

 

System Context:-

show run int Port-channel10.101
interface Port-channel10.101
vlan 101

 

Specific Context:-

show run int Port-channel10.101
interface Port-channel10.101
nameif DMZ_1
security-level 50
ip address X.X.X.X 255.255.255.128 standby X.X.X.X

 

1 Accepted Solution

Accepted Solutions

Get in to context :

 

1- clean up associated ACL and policies

2. from context remove related config for the sub-interface.and shutdown

3. system context where you remove the sub-interface ( no interface Port-channel10.101)

 

changes to be done always active one.

 

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

Clear up the access list and access group any assiciated and shutdown the sub-interface and  remove sub-interface is best approach (in maintenance window always).

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi Balaji, Thanks for the reply. Can you please assist on the below?

Not sure if the sub-interface should be removed first from the specific context or from the system space.

 

System Context:-

show run int Port-channel10.101
interface Port-channel10.101
vlan 101

 

Specific Context:-

show run int Port-channel10.101
interface Port-channel10.101
nameif DMZ_1
security-level 50
ip address X.X.X.X 255.255.255.128 standby X.X.X.X

Get in to context :

 

1- clean up associated ACL and policies

2. from context remove related config for the sub-interface.and shutdown

3. system context where you remove the sub-interface ( no interface Port-channel10.101)

 

changes to be done always active one.

 

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking products for a $25 gift card