A single Cisco ASA appliance can be partitioned into multiple virtual firewalls known also as
“Security Contexts”.
Each security context acts as a separate firewall with its own security policy,
interfaces and configuration.
However, some features are not available for virtual firewalls,
such as IPSEC and SSL VPN, Dynamic Routing Protocols,
Multicast and Threat Detection.

Each security context that you create on the appliance includes its own configuration file
(filename.cfg) stored on local
flash memory. This configuration file contains the security policy,
the included interfaces and the virtual firewall configuration
of the specific security context.

By default, an admin context is always created having a configuration file “admin.cfg“.
This is just like any other security context except that when a user logs in the admin context
then he has full administrator
access to all other security contexts.

When you convert the appliance from single context mode to multiple context mode
(using the command “mode multiple“)
the firewall converts the current running configuration
into two files: a new startup configuration that comprises the
system configuration, and “admin.cfg”
that comprises the admin context (stored in the root directory of the internal Flash memory).

The original running configuration is saved as “old_running.cfg” (in the root directory of the
internal Flash memory).


Configuring Security Contexts

! Enable multiple context mode
ASA(config)# mode multiple

! Then reboot the appliance.

! Configure the administrator context
ASA(config)# admin-context administrator
ASA(config)# context administrator
ASA(config-ctx)# allocate-interface gigabitethernet0/1.10
ASA(config-ctx)# allocate-interface gigabitethernet0/1.11
ASA(config-ctx)# config-url flash:/admin.cfg

 

! Configure other contexts as required
ASA(config)# context customerA
ASA(config-ctx)# allocate-interface gigabitethernet0/2.100
ASA(config-ctx)# allocate-interface gigabitethernet0/2.200
ASA(config-ctx)# config-url flash:/customerA.cfg

! Configure other contexts as required
ASA(config)# context customerB
ASA(config-ctx)# allocate-interface gigabitethernet0/2.111
ASA(config-ctx)# allocate-interface gigabitethernet0/2.222
ASA(config-ctx)# config-url flash:/customerB.cfg

 

To change between the system execution space and a context, or between contexts, see the following commands:

! To change to a context named CustomerA, enter the following command:
ASA# changeto context CustomerA

! The prompt changes to the following:
ASA/CustomerA#

! To change back to the system execution space, enter the following command:
ASA/CustomerA# changeto system

! The prompt changes to the following:
ASA#

 

Summary adding a Context :

System context 5580:

changeto context system

context CONTEXT1
allocate-interface GigabitEthernet7/1

changeto context CONTEXT1

interface GigabitEthernet7/1
description Voice Hosting
nameif Voice
security-level 10
ip address #.#.#.# 255.255.255.252

access-list Voice_access_in extended permit ip any any
!
mtu Staging_Voice_Hosting 1500
!
access-group Voice_access_in in interface Voice
!
route inside #.#.#.# 255.255.255.0 #.#.#.# 1