10-14-2021 07:49 AM
Hi Experts,
We're running Multi-context Active/standby firewalls on the version 9.8.4.35. We have been asked to delete the VLAN sub-interfaces, it's access-lists and access-groups.
Not sure if the sub-interface should be removed first from the specific context or from the system space.
Please assist with the order to be followed or the best practice?
System Context:-
show run int Port-channel10.101
interface Port-channel10.101
vlan 101
Specific Context:-
show run int Port-channel10.101
interface Port-channel10.101
nameif DMZ_1
security-level 50
ip address X.X.X.X 255.255.255.128 standby X.X.X.X
Solved! Go to Solution.
10-14-2021 08:15 AM - edited 10-14-2021 08:15 AM
Get in to context :
1- clean up associated ACL and policies
2. from context remove related config for the sub-interface.and shutdown
3. system context where you remove the sub-interface ( no interface Port-channel10.101)
changes to be done always active one.
10-14-2021 07:53 AM
Clear up the access list and access group any assiciated and shutdown the sub-interface and remove sub-interface is best approach (in maintenance window always).
10-14-2021 08:05 AM
Hi Balaji, Thanks for the reply. Can you please assist on the below?
Not sure if the sub-interface should be removed first from the specific context or from the system space.
System Context:-
show run int Port-channel10.101
interface Port-channel10.101
vlan 101
Specific Context:-
show run int Port-channel10.101
interface Port-channel10.101
nameif DMZ_1
security-level 50
ip address X.X.X.X 255.255.255.128 standby X.X.X.X
10-14-2021 08:15 AM - edited 10-14-2021 08:15 AM
Get in to context :
1- clean up associated ACL and policies
2. from context remove related config for the sub-interface.and shutdown
3. system context where you remove the sub-interface ( no interface Port-channel10.101)
changes to be done always active one.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: