<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5520 Sub Interface problems in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737193#M1022672</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm.. Once you have enabled the same security intra interface, do you have dynamic nat statements already present in the config? You need to do a no nat configuration to allow access between these hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Hoogen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Mar 2007 11:10:21 GMT</pubDate>
    <dc:creator>hoogen_82</dc:creator>
    <dc:date>2007-03-28T11:10:21Z</dc:date>
    <item>
      <title>ASA 5520 Sub Interface problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737184#M1022656</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another question &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On an ASA 5520 I am trying to configure sub interfaces. However was created I am unable to ping that sub interfaces address from anywhere outside of its subnet. The setup is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GIG0/0	 	Inside, 10.177.8.41, 255.255.255.248, Native, Security level 100&lt;/P&gt;&lt;P&gt;GIG0/0.27	Test, 10.177.27.240, 255.255.255.0, Vlan 27, Security level 100&lt;/P&gt;&lt;P&gt;GIG0/1		Outside, 1.1.1.1, 255.255.255.248, Native, Security level 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configured routes are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.177.0.0, 255.255.128.0 &amp;gt; 10.177.8.46&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I ping from a device within the 10.177.27.x subnet I can reach the Test subinterface. If I ping from outside of that subnet (ie from my machine of 10.177.29.251) I get no response. The logs on the ASA show the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;110003	Routing failed to locate next hop for icmp from Test:10.177.27.240/0 to Test:10.177.29.251/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On my switch which connects the ASA to the network I have the uplink configured as untagged for the 10.177.8.40 network and tagged for vlan 27 (10.177.27.0/24).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've looked through the Cisco Press book and the online docs and followed everything mentioned. The behaviour of the failed pings is typical of devices configured without any default gateway. I would imagine the routing on the box should take care of that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also tried enabling communication between interfaces with the same security level or between multiple hosts on the same interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:52:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737184#M1022656</guid>
      <dc:creator>jason.scott</dc:creator>
      <dc:date>2019-03-11T09:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 Sub Interface problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737185#M1022659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to setup a trunk between the ASA and a router.  Remember, the ASA is not a router and cannot route between vlans.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2007 13:34:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737185#M1022659</guid>
      <dc:creator>DfyAnt</dc:creator>
      <dc:date>2007-03-27T13:34:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 Sub Interface problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737186#M1022661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;dont scratch your head on this anymore...its not ya fault&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check this  bug CSCsd85281&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/Support/Bugtool/home.pl" target="_blank"&gt;http://www.cisco.com/cgi-bin/Support/Bugtool/home.pl&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 01:15:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737186#M1022661</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2007-03-28T01:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 Sub Interface problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737187#M1022664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that issue is neither with the trunking, nor with the bug as mentioned previously on this post. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA is behaving as it is expected to. Let me explain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test interface connects directly to 10.177.27.0/24 network only. Then you have the route-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.177.0.0 255.255.128.0 --&amp;gt; 10.177.8.46&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now you are initiating PING from 10.177.29.251, which as per the configuration of ASA is on the Native interface, because the above route points to 10.177.8.46, which is part of the Native interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So logically, your host which is on the Native interface, is trying to ping altogether a different interface of ASA. This is simply not possible. ASA does not allow to ping the other side interface from a host on a different interface. Please refer to following link for the same-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#pingsown" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#pingsown&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if you requirement is that 10.177.29.251 should be in vlan27, then we need to make configuration changes on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this explains the bhaviour of ASA. Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 01:43:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737187#M1022664</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-28T01:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 Sub Interface problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737188#M1022667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can ping from one interface to another on my firewall.  I have icmp enable of course.&lt;/P&gt;&lt;P&gt;By the way, your link is for PIX Software Versions 4.1(6) to 4.2(2).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont agree with you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 04:37:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737188#M1022667</guid>
      <dc:creator>DfyAnt</dc:creator>
      <dc:date>2007-03-28T04:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 Sub Interface problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737189#M1022668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Vibhor. I started to think along these lines yesterday and come to the same conclusion. Presumably however if some ACLs were configured I should be able to permit some traffic between hosts on these interfaces (ie inside &amp;gt; dmz sub interface or reverse)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It makes sense that by default the networks on the sub interfaces are seperate - just as they would be in a physical port configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 07:01:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737189#M1022668</guid>
      <dc:creator>jason.scott</dc:creator>
      <dc:date>2007-03-28T07:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 Sub Interface problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737190#M1022669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hrm, that sounds like it should be the cause, however we're running 7.2(10) which I believe includes the fix for this particular bug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having said that I would've thought the ASA would return a message stating the packet was denied because of internal policies rather than complaining of a routing issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 07:04:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737190#M1022669</guid>
      <dc:creator>jason.scott</dc:creator>
      <dc:date>2007-03-28T07:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 Sub Interface problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737191#M1022670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems that you have not at all understood what I explained and gave your opinion. First off, we were not talking about pinging the firewalls interfaces from firewall itself. We were talking about pinging firewalls interface from a host on different interface. I hope you understand this now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next, it seems that you didnt carefully read the link posted also. Here is a line from the link-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Components Used&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The information in this document is based on PIX Software versions 4.1(6) and later."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This looks very contradictory to your statement- "By the way, your link is for PIX Software Versions 4.1(6) to 4.2(2)." &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you are clear on this now. Let me know if you need further clarifications.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 07:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737191#M1022670</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-28T07:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 Sub Interface problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737192#M1022671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Absolutely. If you need to allow hosts on Native interface to be able to ping hosts on the vlan27 interface, we can do so using static/access-lists etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the same link I mentioned earlier, it explains how to permit ICMP traffic through (through because traffic is supposed to pass 2 interfaces and traverse logically through PIX) PIX-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#topic0" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#topic0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 07:55:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737192#M1022671</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-28T07:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 Sub Interface problems</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737193#M1022672</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm.. Once you have enabled the same security intra interface, do you have dynamic nat statements already present in the config? You need to do a no nat configuration to allow access between these hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Hoogen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2007 11:10:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-sub-interface-problems/m-p/737193#M1022672</guid>
      <dc:creator>hoogen_82</dc:creator>
      <dc:date>2007-03-28T11:10:21Z</dc:date>
    </item>
  </channel>
</rss>

