Since upgrading to the ASA5585-X firewall running in multi-context mode we have had a number of questions around functionality. We raised a case with Cisco TAC to find out why EIGRP peering is not supported between contexts. This was their response:-
Thank you for your patience on this case; the behavior you
are seeing on the ASA is expected since inter-context exchange of multicast is
not supported
“Context Guidelines
EIGRP instances cannot
form adjacencies with each other across shared interfaces because inter-context
exchange of multicast traffic is not supported.”
As a workaround, you can configure static neighbors but it
is supported only on point-to-point links.
So due to inter-context exchange of multicast traffic not being supported, EIGRP cannot work either. When they say static neighbours, they mean statically configured unicast neighbours for both EIGRP and OSPF. This however only works for a single configured neighbour on a point to point interface.
The workaround I guess is to apply static routes between the contexts. I would hazard a guess that this works best when you have auto-mac turned on so that every interface is assigned a unique MAC. Otherwise the classifier engine would get very confused.
Comments
Post a Comment