Solving Shared Context Interface Issues with Unique MAC Addresses
By default, every physical ASA interface uses its burned-in address (BIA) as its Media Access Control (MAC) address. Also, every subinterface of a physical interface uses the physical interface's MAC address. After the ASA is configured for multiple context mode, system context interfaces (both physical and subinterfaces) are allocated to other contexts. This means that the MAC address of a system context interface is reused on each of its associated context interfaces.
For example, consider an ASA that has the following system context configuration. Physical interface EthernetO is shared across all contexts as the single link to the outside world. Each context has a unique subinterface of Ethernetl to use as its inside interface, as shown in the following system context configuration:
admin-context admin context admin allocate-interface EthernetO allocate-interface Ethernetl config-url flash:/admin.cfg
context ContextA
allocate-interface EthernetO allocate-interface Ethernetl.l config-url flash:/ContextA.cfg
context ContextB
allocate-interface EthernetO allocate-interface Ethernetl.2 config-url flash:/ContextB.cfg
Next, it is useful to see how the ASA allocates its MAC addresses. In the following example, the system context interface MAC addresses are displayed with the show interface command. Notice that each physical interface (EthernetO, Ethernetl, and so on) has a unique address. The MAC addresses for subinterfaces (Ethernetl.l and Ethernetl.2) are not shown; they simply inherit the address of their parent physical interfaces.
asa-a# changeto system asa-a# show interface | include (Interface | MAC) Interface EthernetO "", is up, line protocol is up
MAC address 000e.d7e6.af77, MTU not set Interface Ethernetl "", is up, line protocol is up
MAC address 0 0 0e.d7e6.af78, MTU not set Interface Ethernetl.l "", is up, line protocol is up Interface Ethernetl.2 "", is up, line protocol is up Interface Ethernet2 "Failover", is up, line protocol is up
MAC address 0005.5d19.019c, MTU 1500 Interface Ethernet3 "", is administratively down, line protocol is down
MAC address 0005.5d19.019d, MTU not set Interface Ethernet4 "", is administratively down, line protocol is down
MAC address 0005.5d19.019e, MTU not set Interface Ethernet5 "", is administratively down, line protocol is down MAC address 0005.5d19.019f, MTU not set asa-a#
Finally, each context is visited to display the MAC addresses of its own interfaces. Because system context interface Ethernet0 is allocated to each of the other contexts as a shared outside interface (also called Ethernet0), notice that the highlighted MAC addresses are identical:
asa-a# changeto context admin asa-a/admin# show interface | include (Interface | MAC) Interface Ethernet0 "outside", is up, line protocol is up
MAC address 000e.d7e6.af77, MTU 1500 Interface Ethernet1 "inside", is up, line protocol is up
MAC address 0 0 0e.d7e6.af78, MTU 1500 asa-a/admin#
asa-a/admin# changeto context ContextA
asa-a/ContextA# show interface | include (Interface | MAC) Interface Ethernet0 "outside", is up, line protocol is up
MAC address 000e.d7e6.af77, MTU 1500 Interface Ethernet1.1 "inside", is up, line protocol is up
MAC address 0 0 0e.d7e6.af78, MTU 1500 asa-a/ContextA#
asa-a/ContextA# changeto context ContextB
asa-a/ContextB# sh interface | include (Interface | MAC) Interface Ethernet0 "outside", is up, line protocol is up
MAC address 000e.d7e6.af77, MTU 1500 Interface Ethernet1.2 "inside", is up, line protocol is up
MAC address 0 0 0e.d7e6.af78, MTU 1500 asa-a/ContextB#
Reusing the MAC addresses does not usually pose a problem because neighboring devices can still see a correspondence between a context interface's IP address and its MAC address. But what about the example case where the same physical or subinterface is allocated to several different firewall contexts? Each of the allocated context interfaces would have a unique IP address from the same shared subnet, but would reuse the same MAC address.
Neighboring devices might not be able to distinguish one context from another because of the shared MAC address. However, the ASA can usually accept traffic destined to the shared MAC address and figure out which context interface is the real recipient. The ASA uses a classifier function to examine incoming packets and pass them along to the correct context. The classifier works through the following sequence of conditions to map a packet's destination address to a context:
1. A unique interface— When one interface is allocated to only one context, the destination context is obvious.
2. A unique MAC address— The destination MAC address is found on only one context interface.
3. A unique NAT entry— A unique destination Internet Protocol (IP) address is needed, either through a global address configured in a static NAT entry or found in the xlate table.
Beginning with ASA 7.2(1), you can configure the ASA to use unique MAC addresses on every subinterface and context interface. Physical (system context) interfaces continue to use their burned-in addresses, whereas context interfaces receive MAC addresses that are automatically generated. You can use the following global configuration command to assign unique MAC addresses:
asa(config)# mac-address auto
This command can be used only in the system execution space because that is the source of all interface allocation. As soon as you enter the command, the interface MAC addresses is changed. You can revert back to the original interface MAC addresses by using the no mac-address auto command.
The MAC addresses are automatically generated according to the format spelled out in Table 41.
|
Failover Unit |
Example |
|
|
Active |
12_slot . port_subid . contextid |
Continue reading here: Initiating Multiple Context Mode
Was this article helpful?