cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
919
Views
0
Helpful
2
Replies

Problem with MAC learning on ASA, MAC moving between two bridge-groups

silemire
Level 1
Level 1

Hi,

I'm running an ASA 5585 pair in transparent mode with two bridge-groups inside one context. The ASA is connected to a 6500 switch in VSS.

In the logs, I'm seeing the MAC of the VSS cluster moving between between the two outside interfaces of my two bridge-groups (same context). So, my traffic is getting dropped intermittently, as the ASA doesn't flood traffic on an unknown MAC.

For this particular problem, I've assigned MACs manually to the SVIs of the 6500.

However, I still have the same problem with routed multicast traffic going to a firewalled VLAN. The 6500 PFC always uses the VSS MAC when it rewrites the L2 packet header so it's not using the MAC I've specified on the SVI.

Is there any way to fix this? Should I be only using one bridge-group per context?

-Simon

2 Replies 2

mirober2
Cisco Employee
Cisco Employee

Hi Simon,

This issue is caused by the following bug:

CSCti13482 - BG: Same MAC-address not allowed in two different bridge groups

You should upgrade to 8.4(2) to get the fix for the bug and everything should work fine.

-Mike

Thanks Mike,

I will upgrade my ASA as soon as possible.

-Simon

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card