07-01-2013 09:16 AM - edited 03-11-2019 07:05 PM
Hi Everyone,
Need to confirm below
If we have ASA in multi context mode and it has only single interface say gi2 that is shared between 2 contexts and its subinterfaces have different
IP address then we can confirm that this is the outside interface of the ASA as a whole?
Regards
Mahesh
Solved! Go to Solution.
07-01-2013 09:27 AM
Hi,
If the ASA only is connected through the physical interface Gi0/2 to the next device and its divided into subinterfaces then it would seem that one of those interfaces is used for outside connectivity.
Judging by what you say the ASA has a single Trunk link to some neighbor device and subinterfaces are used to handle "inside" , "dmz" , "outside" and all other kinds of interfaces for the actual Security Contexts.
Without seeing any configurations I dont know if there is anything else that can be said of the setup.
- Jouni
07-01-2013 11:37 AM
Hi,
Well it depends.
I think by default the ASA is set to have same MAC address for each subinterface of a single physical interface.
To my understanding this is changed by setting the "mac-address auto" in the System Context configuration after which the ASA generates MAC addresses for the interfaces. The default setting is, as I said, "no mac-address auto".
Or you can even set the interfaces MAC address under the interface configuration mode.
Here is a link to a command reference which explains the command use
http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/m.html#wp2043127
- Jouni
07-01-2013 09:27 AM
Hi,
If the ASA only is connected through the physical interface Gi0/2 to the next device and its divided into subinterfaces then it would seem that one of those interfaces is used for outside connectivity.
Judging by what you say the ASA has a single Trunk link to some neighbor device and subinterfaces are used to handle "inside" , "dmz" , "outside" and all other kinds of interfaces for the actual Security Contexts.
Without seeing any configurations I dont know if there is anything else that can be said of the setup.
- Jouni
07-01-2013 10:03 AM
Hi Jouni,
For current setup seems gi0/2 is outside int of ASA.
Also the shared interface which is Gi0/2 has different mac address for each context i mean to say
context admin
int gi0/2.3 has say mac of 1234
context x
int gi0/2.5 has say mac of 6789
So this is default behaviour?
Regards
MAhesh
07-01-2013 11:37 AM
Hi,
Well it depends.
I think by default the ASA is set to have same MAC address for each subinterface of a single physical interface.
To my understanding this is changed by setting the "mac-address auto" in the System Context configuration after which the ASA generates MAC addresses for the interfaces. The default setting is, as I said, "no mac-address auto".
Or you can even set the interfaces MAC address under the interface configuration mode.
Here is a link to a command reference which explains the command use
http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/m.html#wp2043127
- Jouni
07-01-2013 11:40 AM
Hi Jouni,
Many thanks
Best reagrds
Mahesh
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: