10-14-2021 07:49 AM
Hi Experts,
We're running Multi-context Active/standby firewalls on the version 9.8.4.35. We have been asked to delete the VLAN sub-interfaces, it's access-lists and access-groups.
Not sure if the sub-interface should be removed first from the specific context or from the system space.
Please assist with the order to be followed or the best practice?
System Context:-
show run int Port-channel10.101
interface Port-channel10.101
vlan 101
Specific Context:-
show run int Port-channel10.101
interface Port-channel10.101
nameif DMZ_1
security-level 50
ip address X.X.X.X 255.255.255.128 standby X.X.X.X
Solved! Go to Solution.
10-14-2021 08:15 AM - edited 10-14-2021 08:15 AM
Get in to context :
1- clean up associated ACL and policies
2. from context remove related config for the sub-interface.and shutdown
3. system context where you remove the sub-interface ( no interface Port-channel10.101)
changes to be done always active one.
10-14-2021 07:53 AM
Clear up the access list and access group any assiciated and shutdown the sub-interface and remove sub-interface is best approach (in maintenance window always).
10-14-2021 08:05 AM
Hi Balaji, Thanks for the reply. Can you please assist on the below?
Not sure if the sub-interface should be removed first from the specific context or from the system space.
System Context:-
show run int Port-channel10.101
interface Port-channel10.101
vlan 101
Specific Context:-
show run int Port-channel10.101
interface Port-channel10.101
nameif DMZ_1
security-level 50
ip address X.X.X.X 255.255.255.128 standby X.X.X.X
10-14-2021 08:15 AM - edited 10-14-2021 08:15 AM
Get in to context :
1- clean up associated ACL and policies
2. from context remove related config for the sub-interface.and shutdown
3. system context where you remove the sub-interface ( no interface Port-channel10.101)
changes to be done always active one.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide