cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
993
Views
0
Helpful
3
Replies

MultiContext - Vlan Subinterface Deletion

Hi Experts,

 

We're running Multi-context Active/standby firewalls on the version 9.8.4.35. We have been asked to delete the VLAN sub-interfaces, it's access-lists and access-groups.

Not sure if the sub-interface should be removed first from the specific context or from the system space.

Please assist with the order to be followed or the best practice?

 

System Context:-

show run int Port-channel10.101
interface Port-channel10.101
vlan 101

 

Specific Context:-

show run int Port-channel10.101
interface Port-channel10.101
nameif DMZ_1
security-level 50
ip address X.X.X.X 255.255.255.128 standby X.X.X.X

 

1 Accepted Solution

Accepted Solutions

Get in to context :

 

1- clean up associated ACL and policies

2. from context remove related config for the sub-interface.and shutdown

3. system context where you remove the sub-interface ( no interface Port-channel10.101)

 

changes to be done always active one.

 

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

Clear up the access list and access group any assiciated and shutdown the sub-interface and  remove sub-interface is best approach (in maintenance window always).

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi Balaji, Thanks for the reply. Can you please assist on the below?

Not sure if the sub-interface should be removed first from the specific context or from the system space.

 

System Context:-

show run int Port-channel10.101
interface Port-channel10.101
vlan 101

 

Specific Context:-

show run int Port-channel10.101
interface Port-channel10.101
nameif DMZ_1
security-level 50
ip address X.X.X.X 255.255.255.128 standby X.X.X.X

Get in to context :

 

1- clean up associated ACL and policies

2. from context remove related config for the sub-interface.and shutdown

3. system context where you remove the sub-interface ( no interface Port-channel10.101)

 

changes to be done always active one.

 

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card