ASA 5520 Mgt. Interface Traffic/Routes

Unanswered Question
Apr 23rd, 2009
User Badges:

Do the management interface routes tie in with the other routes on the ASA or are they separated? I'm trying to figure if say network is granted management access would that that route conflict with site-to-site VPN traffic from the same source network?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
smalkeric Wed, 04/29/2009 - 12:54
User Badges:
  • Silver, 250 points or more

The ASA 5510 and higher adaptive security appliance includes a dedicated management interface called Management 0/0, which is meant to support traffic to the security appliance. However, you can configure any interface to be a management-only interface using the management-only command. Also, for Management 0/0, you can disable management-only mode so the interface can pass through traffic just like any other interface.

Transparent firewall mode allows only two interfaces to pass through traffic; however, on the ASA 5510 and higher adaptive security appliance, you can use the Management 0/0 interface (either the physical interface or a subinterface) as a third interface for management traffic. The mode is not configurable in this case and must always be management-only. You can also set the IP address of this interface in transparent mode if you want this interface to be on a different subnet from the management IP address, which is assigned to the security appliance or context, and not to individual interfaces.

myounger Wed, 04/29/2009 - 14:12
User Badges:

Thanks for your info. Let me clarify. Is the routing table on the 5520 shared between the management and other interfaces?


This Discussion