<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA - Packets in and accepted but not forwarded in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-packets-in-and-accepted-but-not-forwarded/m-p/3208058#M1065561</link>
    <description>&lt;P&gt;I have the same issue, i am attempting to traceroute. Packet tracer says the packet is allowed, a packet capture shows the packet arriving but not being forwarded to the outside.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone have an ideas?&lt;/P&gt;</description>
    <pubDate>Tue, 31 Oct 2017 11:14:58 GMT</pubDate>
    <dc:creator>jayohaitchenn</dc:creator>
    <dc:date>2017-10-31T11:14:58Z</dc:date>
    <item>
      <title>ASA - Packets in and accepted but not forwarded</title>
      <link>https://community.cisco.com/t5/network-security/asa-packets-in-and-accepted-but-not-forwarded/m-p/3197479#M1065560</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Strange issue here, I have a fairly simple setup, client trying to connect to a server via the ASA, there is an ACL on the input interface and nothing on the egress interface. When they establish connection I see the traffic hit the ingress interface but never leave the egress interface (there is another ASA on the outsid einterface of this ASA which never recieves the packet). Packet tracer is also showing the same thing, I see the packet on the ingress but not the egress. However everything shows it shoudl be allowed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any thought osn what this could be? I know packet tracer is not always trust worthy but I have done this same testing with real traffic with the same captures and get the same results.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;packet-tracer input INSIDE tcp 172.16.150.5 1025 10.10.10.5 445&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: CAPTURE&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;
&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in 10.10.10.0 255.255.255.0 OUTSIDE&lt;/P&gt;
&lt;P&gt;Phase: 4&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group INSIDE in interface INSIDE&lt;BR /&gt;access-list INSIDE extended permit tcp 172.16.150.0 255.255.255.0 host 10.10.10.5 eq 445&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 5&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (INSIDE,OUTSIDE) source dynamic any interface&lt;BR /&gt;Additional Information:&lt;BR /&gt;Dynamic translate 172.16.150.5/1025 to 10.10.20.1/1025&lt;/P&gt;
&lt;P&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 7&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 8&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 9&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (INSIDE,OUTSIDE) source dynamic any interface&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 10&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 11&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 12&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 3147485250, packet dispatched to next module&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;input-interface: INSIDE&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: OUTSIDE&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-list CAP extended permit tcp any4 any4 eq 445&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;capture IN type raw-data access-list CAP interface INSIDE [Capturing - 74 bytes]&lt;BR /&gt;capture OUT type raw-data access-list CAP interface OUTSIDE [Capturing - 0 bytes]&lt;/P&gt;
&lt;P&gt;show cap IN&lt;/P&gt;
&lt;P&gt;1 packet captured&lt;BR /&gt;1: 17:51:04.962047 802.1Q vlan#123 P0 172.16.150.5.1025 &amp;gt; 10.10.10.5.445: S 638249094:638249094(0) win 8192&lt;BR /&gt;1 packet shown&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;show cap OUT&lt;BR /&gt;0 packet captured&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any ideas what could be the cause?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:28:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packets-in-and-accepted-but-not-forwarded/m-p/3197479#M1065560</guid>
      <dc:creator>ryancisco01</dc:creator>
      <dc:date>2020-02-21T14:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - Packets in and accepted but not forwarded</title>
      <link>https://community.cisco.com/t5/network-security/asa-packets-in-and-accepted-but-not-forwarded/m-p/3208058#M1065561</link>
      <description>&lt;P&gt;I have the same issue, i am attempting to traceroute. Packet tracer says the packet is allowed, a packet capture shows the packet arriving but not being forwarded to the outside.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone have an ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2017 11:14:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-packets-in-and-accepted-but-not-forwarded/m-p/3208058#M1065561</guid>
      <dc:creator>jayohaitchenn</dc:creator>
      <dc:date>2017-10-31T11:14:58Z</dc:date>
    </item>
  </channel>
</rss>

