<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot add route entry, conflict with existing routes in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3230184#M1011566</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/449200"&gt;@WillCai&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I´ll do this on my lab and I will let you know about the results.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Gio&lt;/P&gt;</description>
    <pubDate>Mon, 11 Dec 2017 14:40:32 GMT</pubDate>
    <dc:creator>GioGonza</dc:creator>
    <dc:date>2017-12-11T14:40:32Z</dc:date>
    <item>
      <title>Cannot add route entry, conflict with existing routes</title>
      <link>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3229443#M1011530</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Why the route will show up he error message "Cannot add route entry, conflict with existing routes". Even the outside and backup route can switch automatically. However, the backup line still no internet. I try to connect the backup line without the ASA route, and the Internet work just fine.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:55:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3229443#M1011530</guid>
      <dc:creator>WillCai</dc:creator>
      <dc:date>2020-02-21T14:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot add route entry, conflict with existing routes</title>
      <link>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3225772#M1011548</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/449200"&gt;@WillCai&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You are having problems with the track route since it is not adding the outside route just the backup, you have to check what is happening with the track itself and verify if you can reach 8.8.8.8.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The configuration is OK and probably you need to issue this commands in order to know what is going on with the routes:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;show sla monitor operational-state&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;show track&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also you can enable the logs for this connection and verify if the ASA is doing that change:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;logging list SLA-LIST message 622001&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;logging trap SLA-LIST&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;logging history SLA-LIST&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;snmp-server enable traps syslog&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We need this information in order to verify the connection.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Gio&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 22:24:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3225772#M1011548</guid>
      <dc:creator>GioGonza</dc:creator>
      <dc:date>2017-12-01T22:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot add route entry, conflict with existing routes</title>
      <link>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3227416#M1011552</link>
      <description>&lt;P&gt;Hi GioGonza,&lt;/P&gt;
&lt;P&gt;Thanks for you response, I do check my&amp;nbsp;ASA can reach 8.8.8.8, and the show command you can check in the attachment. However, one more question is my backup route can not browsing any website. I do set up the firewall as the same as the outside, but it just&amp;nbsp;not working.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sincerely,&lt;/P&gt;
&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 21:17:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3227416#M1011552</guid>
      <dc:creator>WillCai</dc:creator>
      <dc:date>2017-12-05T21:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot add route entry, conflict with existing routes</title>
      <link>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3227448#M1011556</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/449200"&gt;@WillCai&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on the output you pasted before the SLA should be working fine and it should have the route to the outside instead of the backup. But there was a change 5 hours before you collected the information so probably you experienced a problem with the routing.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you do show route, the default route should be on the outside interface instead of the backup as it was before.&amp;nbsp;The way I see it everything is normal and the connection is stable as per thee outputs you shared.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now according to the other question, the ASA is receiving the IPs for the outside and backup interface from another device in front of the ASA (and those devices are doing the NAT for Internet access), if you don´t have access through the backup interface you need to verify with the device in front of the ASA and verify if the NAT is taking place and also verify if the traffic is not being dropped.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Other than that, I don´t recall any other reason for this behavior.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;Gio&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 22:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3227448#M1011556</guid>
      <dc:creator>GioGonza</dc:creator>
      <dc:date>2017-12-05T22:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot add route entry, conflict with existing routes</title>
      <link>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3228213#M1011558</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Gio,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Now the Dual ISP switch come back to normal. However, the backup line still can not go to the internet. I do use my computer to connect to backup line, and it is work. The means the device before the ASA in backup line is OK. The attachment are my check commands.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Sincerely,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Will&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 22:03:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3228213#M1011558</guid>
      <dc:creator>WillCai</dc:creator>
      <dc:date>2017-12-06T22:03:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot add route entry, conflict with existing routes</title>
      <link>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3228656#M1011562</link>
      <description>&lt;P&gt;Hi Gio,&lt;/P&gt;
&lt;P&gt;I just hit the wrong&amp;nbsp;key to solved. I still have no idea Why the route will show up he error message "Cannot add route entry, conflict with existing routes". Even the outside and backup route can switch automatically. However, the backup line still no internet pass by. I try to connect the backup line without the ASA route, and it is no any problem with the backup line.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sincerely,&lt;/P&gt;
&lt;P&gt;Will Cai&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2017 14:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3228656#M1011562</guid>
      <dc:creator>WillCai</dc:creator>
      <dc:date>2017-12-07T14:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot add route entry, conflict with existing routes</title>
      <link>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3229551#M1011534</link>
      <description>&lt;P&gt;(Moved thread to firewall forum for more accurate classification.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since both your outside and backup interfaces are DHCP, I believe you need to modify backup to override the default administrative distance of 1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a thread here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/firewalling/sla-monitor-on-dual-dynamic-isp-asa5505/td-p/2385667" target="_blank"&gt;https://supportforums.cisco.com/t5/firewalling/sla-monitor-on-dual-dynamic-isp-asa5505/td-p/2385667&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;...with a very similar situation.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The setting is explained in more detail here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/A-H/cmdref1/d1.html#pgfId-2254460" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/A-H/cmdref1/d1.html#pgfId-2254460&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As noted in that command reference link,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN&gt;If DHCP is configured on multiple interfaces, you must use the&amp;nbsp;&lt;STRONG class="cCN_CmdName"&gt;dhcp client route distance&lt;/STRONG&gt;&amp;nbsp;command on each of the interfaces to indicate the priority of the installed routes. &lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Dec 2017 11:23:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3229551#M1011534</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-12-09T11:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot add route entry, conflict with existing routes</title>
      <link>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3230184#M1011566</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/449200"&gt;@WillCai&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I´ll do this on my lab and I will let you know about the results.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Gio&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2017 14:40:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3230184#M1011566</guid>
      <dc:creator>GioGonza</dc:creator>
      <dc:date>2017-12-11T14:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot add route entry, conflict with existing routes</title>
      <link>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3230425#M1011540</link>
      <description>&lt;P&gt;Dear Marvin,&lt;/P&gt;
&lt;P&gt;Thanks for you information. I just follow it and fix the problem. However, I just have one more question about the DNS. Now my backup internet it can go though the ASA route, but without the DNS server can be reached. I just setup the the DNS address again, because the backup line default DNS address is 8.8.8.8, and 8.8.4.4.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sincerely,&lt;/P&gt;
&lt;P&gt;Will Cai&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2017 22:12:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3230425#M1011540</guid>
      <dc:creator>WillCai</dc:creator>
      <dc:date>2017-12-11T22:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot add route entry, conflict with existing routes</title>
      <link>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3230499#M1011545</link>
      <description>&lt;P&gt;You're welcome. Please rate the earlier reply if it answered the original question.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Re your follow up, you have "dhcpd dns 75.75.75.75 75.75.76.76 interface inside" for your dhcp server. Try adding the Google DNS servers there and release / renew a client's ipconfig to test it.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2017 02:30:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-add-route-entry-conflict-with-existing-routes/m-p/3230499#M1011545</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-12-12T02:30:45Z</dc:date>
    </item>
  </channel>
</rss>

