Bridge Groups, are they required?

Hi All
I'm currently a tad confused about Bridge Groups and ASA/FWSM in transparent more. Are they really required or not?
Here one sample: http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/interface_complete_transparent.html
It's written:
At least one bridge group is required per context or in single mode.
So that really sounds like yes you need one.
Where as this config sample here: http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008089f467.shtml or many others I found online, never have a bridge group configured.
Could somebody please enlighten me about what is correct?
And does it matter if it's an active/standby configuration?
Thanks a lot
pato

Pato,
It depends.  On the newer ASA and FWSM you need the BVI. It is just to configure the management IP. This is required.
The old link (the second one that you listed) has the management IP (not under the int BVI) but on the newer ASA code you can see it is configured under the int BVI as you can see here:
http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/interface_complete_transparent.html#wp1382356
-Kureli

Similar Messages

  • Tips for Using Containment Relationships (When Are They Required?)

    Hello again,
    Our team was recently discussing when to use containment relationships, and we realized that there is room for improvement in our understanding. Having read many of the help topics, the primary use for containment relationships seems to be the ability to determine whether or not an entity is complete. However, as far as we can tell, in our work we have not yet encountered a need for the entity-completeness concept (if we have, it was unbeknownst). Instead, using a containment structure within a data model often seems to complicate matters by distancing entities from the Global (thus making it seem more challenging to reason across instances).
    My best guess, aside from completeness, is that containment relationships are required when mapping from a database structure (e.g. Siebel). For example, a model such as:
    Global
    - the invoice
    - - the invoice line item
    ...might interface more correctly with external data structures compared to a "flatter" structure such as:
    Global
    - the invoice
    - the invoice line item
    ...where a "regular" (non-inferred, non-containment) relationship would be needed to connect invoices to their line items. In the latter scenario, perhaps the relationship would be more difficult to define when the data were mapped over?
    I have a feeling we might be missing something obvious, but I'm curious to know what this community thinks about this question. Can anyone help, perhaps by providing a list of advantages / disadvantages to containment, or maybe the situations in which containment is always required?
    Thanks!
    - Patrick

    I've built numerous demo rulebases for integration, usually with Siebel so I'll use that as my example. What I have learnt through doing this is that integration will be easier if the logical structure of the OPA entities/containment relationships matches the logical structure of the Siebel business components.
    For example, if in Siebel you have something representing Global (which I'll call a Case for this example), and you also have several business components logically below Case, e.g.
    A Case can have multiple Contacts
    Each Contact can have multiple Incomes
    Each Contact can have multiple Resources
    Each Contact can have multiple Expenses
    I would set up the following entities/containment relationships in OPA:
    Global --> one-to-many --> the household member
    the household member --> one-to-many --> the household member's income
    the household member --> one-to-many --> the household member's resource
    the household member --> one-to-many --> the household member's expense
    Note that Contact (Siebel) = the household member (OPA). I could use "the contact" in OPA, but I prefer to use a more business-user friendly name such as "the household member" -- if they are indeed household members, it could also be the person, the taxpayer, etc. or whatever is appropriate for the source material.
    I assume this general principle still applies if the integration is with something other than Siebel.
    Cheers,
    Jasmine

  • App-specific passwords: are they required for the iOS versions of iMessage and Facetime?

    I was recently prompted to generate app-specific passwords for iMessage and FaceTime on my Mac. The process went reasonably smoothly, but after doing this I wondered whether I'll need to do the same on my iOS devices.
    The Apple Support page Using app-specific passwords - Apple Support offers no clues about which Apple apps require them and on which devices.
    As a test, I tried signing out of iMessage on my iPhone, and signing back in with my regular Apple ID password, not an app-specific one. This worked fine, therefore I assume the iOS versions of iMessage and Facetime do not need app-specific passwords.
    On the other hand, I've read some of the articles which state that the iOS versions of iMessage and Facetime will require app-specific passwords:
      http://arstechnica.com/apple/2015/02/apple-extends-two-factor-authentication-to- facetime-and-imessage/
    Does this mean that app-specific passwords have simply not been "rolled out" to my devices yet, and we'll be prompted to generate app-specific passwords on iOS at some random time in the future?
    If so, that's a problem for non-technical users in my household on whose behalf I look do setup and security. It will effectively mean iMessage will stop working for them, until I can take a look at the issue. This is not always something that can be done quickly if we're in different locations.
    If I pre-empt the roll-out by visiting https://appleid.apple.com/account/manage/security and generate and install an app-specific passwords for them anyway, before the prompt appears, will this work?

    So far the app specific passwords were only required for 3rd party apps, not for "Apple apps". Not sure why you cannot use trusted device verification for iMessage and FT like on the App store or iTunes. or on Apple TV.
    Having to generate a different  app specific password for every device that uses iMessage or FT is a pain, but I guess the powers that be at Apple feel it is more secure.

  • Bridge-group

    Anyone know why bridge-group are not available in Nexus switch ?
    I need to migrate a customer network that has bridge-group for SNA connectivity within the DC.
    Thanks

    Anyone know why bridge-group are not available in Nexus switch ?
    I need to migrate a customer network that has bridge-group for SNA connectivity within the DC.
    Thanks

  • I deleted some JPG files in Bridge CS5. They are not in the trash. Where could I find them?

    I deleted some JPG files in Bridge CS5. They are not in the trash. Where could I find them?

    From the Finder menu select 'Secure Empty Trash'. If this or the suggestion above doesn't resolve the problem take a look at the various suggestions in this link:
    http://www.thexlab.com/faqs/trash.html

  • Overnight my contact list went from 1492 contacts to 52.. With help from Apple support I retrieved all of my contacts.  Here is the problem, I lost the groups.  None of my contacts are sorted into groups as they used to be which is very important for me.

    Overnight my contact list went from 1492 to 52.  With help from Apple I retrieved the missing contacts using Time Machine.  The problems is that the contacts are not in groups as they used to be.  Any suggestions?  I really need them grouped for business reasons.
    Also, there are no longer pictures associated with each contact.
    thanks for any help anyone can give me getting contacts back into the groups that I had established.  By the way, the group names are still there, but they are all empty.
    thanks,
    Sparky

    What Mac do you have, with what version of OS X?

  • HT204150 My contacts and groups are not duplicated in iCloud but my groups are duplicated on iPhone and iPad. Any ideas on how to remove duplicate groups or why they are duplicating?

    My contacts and groups are not duplicated in iCloud but my groups are duplicated on iPhone and iPad. Any ideas on how to remove duplicate groups or why they are duplicating?

    Welcome to the Apple Community.
    Check that you don't have more than one account in your contacts, such as 'iCloud' and 'On My Phone'.

  • I cannot get on to my Apple TV.  I know that they are now requiring a one time security code?  What is it How do I find it?

    I know that they are now requiring a one time security code.  How do I find it?  Does anyone know what it is?

    There is no such code required to use the Apple TV. A user can setup a passcode to be required for airplay, and Apple ID is required for use of the iTunes store (or any other subscriptions associated with it).

  • Sales office and sales group are not copied from quotation to sales order

    Hi All,
    I have maintained sales office and sales group in quotation maually at header level.while  coping to sales order sales office and sales group are missing.
    Please let me know what would be reason for missing those twoand whether i should check anything in copy controls.
    Regards
    Mohan

    As its a standard functionality to have the Sales Group & Sales Office from Quotation to Order. But in your case, check the Copy Control settings at Header Level .
    DataT 051 General header data       Copying requirements 001 Header-same customer
    DataT 101 Header business data
    DataT 001 Partner header
    In case , they are also same, then check if any Logic is added in the Existing Routine.
    Best Regards,
    Ankur

  • Leopard and CS3 - Are they ready for prime time?

    Trying to revive this thread, I manage 130 Macs at an art school and I am starting to research what I am going to do this summer as far as OS and CS versions. Currently we are on 10.4.9 and CS2 and about 15% of our Macs are Intels. I am concerned as I am not hearing good things about Leopard and I am wondering if CS3 is ready for prime time. I should note that stability is my first priority NOT the latest OS and App versions. So the question is are they ready for prime time or should I stay with CS2 and Tiger or should I go CS3 and Tiger.

    Summer is a long way off, so hard to guess. I would say that if they don't have the kinks out by then, they probably never will, but still a gamble at this point IMO. I have one of the new Mac Pros (early 2008) w/CS3 Apps installed. I have been using all the below listed apps for the past two weeks without any major problems so far, but I also know that I may be living on the edge right now. I don't feel confident enough to switch to Leopard on my other two computers yet. My restarts on the new machine take about 30-seconds between selecting Restart and ready to start work again (vs about 1.5-2 minutes on my Dual G5). Apps like Photoshop CS3 launch in about 1/3 the time. But all of this speed means absolutely nothing when you slam into an incompatibility - that is the real time trap - I spent the last 8 hours doing nothing but tracking down a Permissions problem in Leopard that none of the utilities will currently fix.
    These appear to be working for me so far...
    Photoshop CS3
    Illustrator CS3
    InDesign CS3
    Flash CS3
    Dreamweaver CS3
    Bridge CS3
    Lightroom
    After Effects CS3
    Contribute CS3
    What doesn't work yet...
    Acrobat Pro & Acrobat Reader (fix was expected from Adobe last month)
    Other issues encountered so far...
    Most Photoshop and After Effects Plugins required paid upgrades to function in Leopard/CS3 (over $1500 for me the past week)
    Monitor calibrator software (such as Artisan) dead with no fixes, but to buy all new hardware calibrators/software - again! - another $1000 bucks
    I purchased the Silverfast Leopard upgrade ($105) to get the Epson 4870 scanner plugin to work with Photoshop CS3, but having problems - I think it is a Leopard problem
    Adobe UPDATES menu item is dimmed out in all CS3 apps.
    Having lots of Leopard User Permissions problems - hopefully 10.5.2 will help?

  • What are phantom materials and assembly... how are they taken care during M

    Hello Gurus
    what are phantom materials and phantom assembly... how are they taken care during MRP run

    Hi
    Phantom assembly is the logical assemble. You have to define special procurement type in mateiral master as 50 to make the item as phantom.
    When you make the item as phantom when running mrp BOM will explode for the phantom <b>ONLY child materials requirements will be generated</b>.For phantom assembly planned order will not be generated.
    A phantom assembly is a logical grouping of materials. A phantom assembly is usually created within engineering, in order to describe a number of components easily and manage them as a whole. The components in a phantom assembly are placed immediately into the superior assembly. As opposed to this, components in an assembly are first assembled to produce the header material. After this the header material is placed into the superior assembly.
    Example: The phantom assembly "set of wheels" contains the components "front wheel" and "rear wheel". The front and rear wheels are placed immediately into the "bicycle" assembly. The "light" assembly contains the materials "bulb" and "reflector". The light components are first assembled and then the light is attached to the bicycle.
    Regards
    Ranga
    null

  • Request.getParameter("") values: Are they null or ""?

    Hello:
    I have a web page that links up to a MYSQL database. I use JSP files to process the database queries from an HTML form. However, I am having an issue after moving the code from MYSQL 5.0 and JDK 1.5 to a machine with MYSQL 4.X and JDK 1.4.X
    I am enabling user to enter several pieces of search criteria that I, in turn, use to build the SQL syntax statement. And I test to see which HTML fields the user has entered something into so that the SQL only includes those where statements.
    I first had the following to process the individual search criteria into SQL where statements:
    String tester1 = request.getParameter("tester");
    String tester = "";
    if (tester1 != "") {
         tester += " tester like \"" + tester1 + "%\"" + " and ";
         } else {
    tester += "";
    so if the user enter "Tommy in the tester field as a search criterion this part of the SQL would be
    tester like Tommy%
    Then I build the select statment with only the where statements that the user is interested in (and provided search criteria on):
    String syntax = "Select * from database where ";
    String array[] = { tester, call_from, call_to, r_no, rec_no, date };
    for (int counter=0;counter<array.length;counter++){
              if (array[counter] != "") {
              syntax += array[counter];
    int a = 0;
    int b = (syntax.length() - 4);
    String syntax1 = syntax.substring(a, b);
    so the above would create
    Select * from database where tester like Tommy%
    This worked on the previous machine. However, it no longer works on the machine with the older apis. So I have tried everything to weed out the blank database fields so they are not factored in the query (if they are they return nothing as these fields are required to be entered into the database). I tried this:
    String tester1 = request.getParameter("tester");
    String tester = "";
    if ((tester1 != "") || (tester1 != null)){
         tester += " tester like \"" + tester1 + "%\"" + " and ";
         } else {
    tester += "#";
    . . . and then . . .
    String syntax = "Select * from database where ";
    String array[] = { tester, call_from, call_to, r_no, rec_no, date };
    for (int counter=0;counter<array.length;counter++){
              if (array[counter] != "#") {
              syntax += array[counter];
    int a = 0;
    int b = (syntax.length() - 4);
    String syntax1 = syntax.substring(a, b);
    But no matter what I try the query that gets sent to the database is as follows:
    Select * from qa_data where tester like "%" and called_from_1 = "" and call_to = "" and r_no = "" and rec_no = "" and (date >= "" and date <= "")
    So I am at a loss. It appears that I am not testing for the correct value that the browser is sending to my JSP file when a user does not enter a value in the field. What other than "" and null are there? I have tested for one or the other and both. I am at a loss now as to what to do. I am only concerned with IE6/7 and Firefox 1.5
    I output what the value being sent to the JSP file was and it was something like "The tester value is:". So, basically it isn't anything ("").
    Can anyone help me here?

    Rule #1 when comparing strings: use the equals() method, rather than == or !=
    You only use == when checking for null, or checking to see if it is the same object.
    if (tester1 == null || tester1.trim().equals("")){
      // value is null/empty/spaces only
    else {
      // a value is present
    }

  • T/F: iPhone users are not required to pay $15/month extra for Good Technology

    I have a personal Droid RAZR M.  You may wonder why I am posting in the iPhone forum but you are about to find out.
    I have access to corporate e-mail via Good Technology.  When I got this service set up at the same time I acquired the phone, I was required to upgrade from a $30/month 2GB plan to a $45/month 2GB plan just to have this access ("needed for access to company servers").  That was a surprise but I got over it.  However, since then, I have come to learn the following:
    1.  It appears that other than VZW, no other carriers are charging users extra for access to Good Technology.
    2.  Based on a colleague's information from a Good Technology support engineer and a office mate who is using a VZW iPhone, VZW iPhone users are *not* *required* to move to an Enterprise plan aren't paying an extra $15/month.  If one searches the Internet, I am not the only one asking about this.
    If you are using a Verizon Wireless iPhone and have Good Technology on your phone, would you let me know if were *required* to upgrade your data plan and pay extra just for using Good Technology?
    Thanks,
    Techvet

    I need to check some information at work about this, since they have some guidance on how their employees can connect to their corporate email with android and iphone devices.

  • Cisco 1702i WAP: how to get an interface in a non-native bridge group/ VLAN to be recognized by the internal DHCP server

    Does anyone know how the internal DHCP server in these access points connects to virtual interfaces and bridges in the unit?
    Is there some sort of default connection that connects the DHCP server to the native bridge group or VLAN?
    In a test case, with an SSID in the native VLAN and bridge group, the 1702i serves an IP address to a wireless client no problem. But with a second SSID in a non native VLAN and bridge group, no IP gets served. My only guess is that since the bvi1 defaults to the native bridge group and VLAN, sub-interfaces also in this group are assumed to be in the same subnet as bvi1, or in this case:
    interface bvi1
      ip address 192.168.1.205 255.255.255.0
      no ip route-cache
      exit
    It would be the ..1. subnet.
    Since the dhcp pool is set as:
    ip dhcp pool GeneralWiFi
      network 192.168.1.0 255.255.255.0
      lease 1
      default-router 192.168.1.1
      dns-server 8.8.8.8
      exit
    There may be an assumption that anything bvi1 can talk to is in the ..1. subnet, so the above pool gets activated on a request coming through bvi1.
    Is the DHCP server just hanging out waiting for a request from an "area" that is assumed to be on the same subnet as the given pool?
    Do I need to somehow show the device what subnet the 2nd SSID/ subinterfaces are in so the internal DHCP server can decide it needs to go to work, or is there some sort of bridging between the DHCP server and the interfaces that needs to be done? I am trying to use the same DHCP pool for the second subnet at this point, since I assume I will need another router to service an additional subnet and DHCP pool.

    Keep in mind that DHCP is a broadcast packet to start. So the AP can only listen in the subnet that it has an IP address for.
    Now, for any other subnet you can use the AP for DHCP but you have to have an IP helper address on your L3 pointing back to the AP.
    That being said, I wouldn't use the DHCP server on the AP as it is limited. You'd be better off using a Microsoft server or some other device that is designed for DHCP.
    HTH,
    Steve

  • Happy Holidays.  I have Adobe Actobat 7.0 Standard for quite a while, and I'm happy with it. I use it for mainly filings at the federal court.  They require PDF.  I use two computers in two different states for work.  I realize my Adobe 7.1 is a few years

    .  I have Adobe Actobat 7.0 Standard for quite a while, and I'm happy with it. I use it for mainly filings at the federal court.  They require PDF.  I use two computers in two different states for work.  I realize my Adobe 7.1 is a few years old, but sometimes I have difficulty using it with the other days downloading a boarding pass, and e filing at the USDC. .  There's a problem with Adobe Flash, media, etc.  and other Adobe programs, (which I use for downloading boarding passes for airlines, etc.) so basically I have to delete these other Adobe programs, besides the Adobe Acrobat 7.0 Standard if I want to 7.0 Standard to work.  I periodically download the updates, but there's still a problem. My question is:  Can or should I purchase another program to update the present Adobe Acrobat 7.0 standard, or just buy a new program such as the Adobe 11?  Am I mistakenly doing something wrong, such as when I download?  I'm an old valued customer so I don't want to spend a lot of money since I am replacing my Dell XP for a new computer now, and my other computer is a Dell Vista.
    I'd appreciate your valued advice.

    If you are getting a new computer (for a PC it would have Win 7 or 8), then you will need to purchase XI if you wish to continue using Acrobat. Acrobat 7 is not compatible with these systems (and probably the same for MAC systems), though sometimes workarounds are possible, though not easy to use. I guess the answer is to buy the new version. Try http://www.adobe.com/products/catalog/software._sl_id-contentfilter_sl_catalog_sl_software _sl_mostpopular.html, click on the Buy for Acrobat, and then select the version you want.

Maybe you are looking for