<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5510, routing issue. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085965#M1070222</link>
    <description>&lt;P&gt;if you issue the command &lt;STRONG&gt;show run | in same-security-traffic&lt;/STRONG&gt; on the ASA do you see entries for both &lt;STRONG&gt;inter-interface&lt;/STRONG&gt; as well as &lt;STRONG&gt;intra-interface&lt;/STRONG&gt;?&lt;/P&gt;
&lt;P&gt;in the initial configuration you posted for the ASA I only saw an entry for &lt;STRONG&gt;inter-interface&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;I suggest adding the command &lt;STRONG&gt;same-security-traffic permit intra-interface&lt;/STRONG&gt; and then check connectivity.&amp;nbsp; If it still doesn't work please post a fresh configuration of the ASA as well as the core switch (remember to remove any public IPs, usernames and passwords).&amp;nbsp; Also please indicate which interface is connected to the ASA.&lt;/P&gt;
&lt;P&gt;Screenshot from the configuration file you posted.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="inter-interface.JPG" style="width: 370px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/74595iB13C47BA4A8A43A5/image-size/large?v=v2&amp;amp;px=999" role="button" title="inter-interface.JPG" alt="inter-interface.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 14 May 2020 16:24:10 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2020-05-14T16:24:10Z</dc:date>
    <item>
      <title>ASA 5510, routing issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4084594#M1070152</link>
      <description>&lt;P&gt;Hello Folks,&amp;nbsp;&lt;/P&gt;&lt;P&gt;reaching out to you for some help,&lt;/P&gt;&lt;P&gt;I have a simple setup in my 5510 , 2 interfaces: first one for OUTSIDE and second one for Inside with multiple sub-interfaces (vlans) :&lt;/P&gt;&lt;P&gt;- all subinterface on the same security level,&amp;nbsp;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;same-security-traffic permit inter-interface&amp;nbsp; &amp;nbsp;"enabled",&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the issue that i'm facing, is a host in a new subinterface (vlan333 / host ip 172.16.210.19) can't reach another host in another subinterface (vlan30 / host ip 10.10.30.10)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;see configuration attached the running config and below a screenshot from ASDM logging&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-05-13_032606.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/74429i52F8F03004769EE5/image-size/large?v=v2&amp;amp;px=999" role="button" title="2020-05-13_032606.png" alt="2020-05-13_032606.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Those things make me confused:&amp;nbsp;&lt;/P&gt;&lt;P&gt;- i can ping 10.10.30.10 from other hosts in another subinterface&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- if I disable ICMP inspection (from service policy rule) then I can see successful ping but TCP / UDP failed,&amp;nbsp;&lt;/P&gt;&lt;P&gt;- in the capture above, I can't understand why "via-subnet2:172.16.210.19" however 172.16.210.19 belong to via-subnet1 interface (see running-config)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Waiting for your valuable ideas!!!&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 03:42:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4084594#M1070152</guid>
      <dc:creator>AyoubC</dc:creator>
      <dc:date>2020-05-13T03:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, routing issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4084899#M1070170</link>
      <description>&lt;P&gt;Is there any routing on the switch connected to the ASA? Looks like there is asynchronous routing possibly.&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 13:01:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4084899#M1070170</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-05-13T13:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, routing issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085101#M1070182</link>
      <description>&lt;P&gt;Thanks for your reply,&amp;nbsp;&lt;/P&gt;&lt;P&gt;there is no routing in the core switch where ASA is plugged.&amp;nbsp;&lt;/P&gt;&lt;P&gt;the network is very small and simple, multiple access switches are connected to the core switch, and uplink with different VLAN to the ASA inside (ASA is playing the role of the router on a stick)&amp;nbsp; and ASA natting traffic to internet via the OUTSIDE interface,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any other ideas based on what i shared?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 16:37:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085101#M1070182</guid>
      <dc:creator>AyoubC</dc:creator>
      <dc:date>2020-05-13T16:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, routing issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085145#M1070183</link>
      <description>&lt;P&gt;Which other subinterface works?&amp;nbsp; I am a little uncertain how another subinterface will work.&amp;nbsp; You need to configure hairpining by using the command &lt;U&gt;&lt;STRONG&gt;same-security-traffic permit intra-interface&lt;/STRONG&gt;&lt;/U&gt; to allow ingress and egress of the same traffic flow on the same interface (traffic entering and exiting on the same interface).&amp;nbsp; I suggest adding this command and then test again.&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 17:26:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085145#M1070183</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-05-13T17:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, routing issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085148#M1070184</link>
      <description>&lt;P&gt;Also, just an observation, if this is a production network I suggest removing or at the very least specify more specific addresses for your http and ssh configuration on the outside interface.&lt;/P&gt;
&lt;P&gt;ssh 0.0.0.0 0.0.0.0 OUTSIDE&lt;/P&gt;
&lt;P&gt;http 0.0.0.0 0.0.0.0 OUTSIDE&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 17:31:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085148#M1070184</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-05-13T17:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, routing issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085152#M1070185</link>
      <description>&lt;P&gt;It looks a lot like asymmetric routing - traffic goes out one way and tries to go back another.&lt;/P&gt;
&lt;P&gt;Does the core switch where the multiple VLANs are configured have any SVIs in those VLANs at all? Even without ip routing configured, a connected interface will affect traffic flow.&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 17:41:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085152#M1070185</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-05-13T17:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, routing issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085176#M1070190</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;U&gt;&lt;STRONG&gt;security-traffic permit intra-interface&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/U&gt; is enabled,&lt;/P&gt;&lt;P&gt;I enabled ssh and https from anywhere just to troubleshoot this issue, i'll ABSOLUTELLY restrict access shortly&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 18:12:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085176#M1070190</guid>
      <dc:creator>AyoubC</dc:creator>
      <dc:date>2020-05-13T18:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, routing issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085190#M1070194</link>
      <description>&lt;P&gt;in the configuration you posted the same-security-traffic permit intra-interface command is missing.&amp;nbsp; I only see the same-security-traffic permit &lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;&lt;U&gt;inter&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;-interface command.&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 18:21:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085190#M1070194</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-05-13T18:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, routing issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085429#M1070199</link>
      <description>&lt;P&gt;Hello Marvin,&amp;nbsp;&lt;/P&gt;&lt;P&gt;your approach looks good, yes I have SVIs in core switch I tried&amp;nbsp; to verify one more time everything, run Wireshark in all ends but results are weird,&amp;nbsp;&lt;/P&gt;&lt;P&gt;for instance look at this capture from ASA,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logs2.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/74529i4E61D536B2C5328D/image-size/large?v=v2&amp;amp;px=999" role="button" title="logs2.png" alt="logs2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;the crazy thing here is, "Routing failed to locate next hop for TCP fromvms:10.10.30.10 to Aruba-MCs:172.16.210.20"&amp;nbsp;&lt;/P&gt;&lt;P&gt;one thing i can't understand, &lt;EM&gt;&lt;STRONG&gt;Aruba-MCs:172.16.210.20, &lt;/STRONG&gt;&lt;/EM&gt;Aruba-MCs is the subinterface for 10.10.62.0/24 (refer to run config). how can we explain that?&amp;nbsp; any idea?&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 00:04:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085429#M1070199</guid>
      <dc:creator>AyoubC</dc:creator>
      <dc:date>2020-05-14T00:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, routing issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085622#M1070206</link>
      <description>&lt;P&gt;I specifically asked if there was routing on the switch and you said "no", and now you are saying there is?&amp;nbsp; Adding IP to SVIs on a layer 3 switch enables routing between the SVIs unless they are placed in their own VRF (routing instance).&amp;nbsp; If you set the default gateway on the end devices to the ASA instead of the switch you will get asynchronous routing which you are now seeing.&amp;nbsp; This is where the end device in VLAN 333 sends traffic destined for VLAN 30 to the ASA, the ASA sends this traffic to VLAN 30, but the endpoint in VLAN 30 sends the traffic directly to the end point in VLAN 333.&amp;nbsp; And then the process continues.&amp;nbsp; The ASA drops the next traffic flow indicating "no connection" as it did not see the return traffic from VLAN 30.&lt;/P&gt;
&lt;P&gt;You need to set the default gateway to the switch SVI IP or remove the SVI IP for one or both of the VLANs and make sure that the correct default gateway is set on the endpoints.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The error you are getting for routing and the drop error is because you do not have the same-security-traffic permit intra-interface command (or at least it was not present in the configuration you posted earlier).&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 08:30:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085622#M1070206</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-05-14T08:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, routing issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085859#M1070213</link>
      <description>Hello Marius,&lt;BR /&gt;totally missed that routing may happen in Core switch with SVIs. when you asked I was only thinking about static routes,&lt;BR /&gt;any way, i deleted all necessary vlan sub-interfaces from core switch, i have now only vlan to trunk traffic to ASA inside uplink, and I'm still getting same errors, I don't know what's wrong even the network is so simple,&lt;BR /&gt;but do you think my previous question&lt;BR /&gt;Aruba-MCs:172.16.210.20, Aruba-MCs is the subinterface for 10.10.62.0/24 (refer to run config). how can we explain that? any idea?</description>
      <pubDate>Thu, 14 May 2020 14:30:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085859#M1070213</guid>
      <dc:creator>AyoubC</dc:creator>
      <dc:date>2020-05-14T14:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, routing issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085965#M1070222</link>
      <description>&lt;P&gt;if you issue the command &lt;STRONG&gt;show run | in same-security-traffic&lt;/STRONG&gt; on the ASA do you see entries for both &lt;STRONG&gt;inter-interface&lt;/STRONG&gt; as well as &lt;STRONG&gt;intra-interface&lt;/STRONG&gt;?&lt;/P&gt;
&lt;P&gt;in the initial configuration you posted for the ASA I only saw an entry for &lt;STRONG&gt;inter-interface&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;I suggest adding the command &lt;STRONG&gt;same-security-traffic permit intra-interface&lt;/STRONG&gt; and then check connectivity.&amp;nbsp; If it still doesn't work please post a fresh configuration of the ASA as well as the core switch (remember to remove any public IPs, usernames and passwords).&amp;nbsp; Also please indicate which interface is connected to the ASA.&lt;/P&gt;
&lt;P&gt;Screenshot from the configuration file you posted.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="inter-interface.JPG" style="width: 370px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/74595iB13C47BA4A8A43A5/image-size/large?v=v2&amp;amp;px=999" role="button" title="inter-interface.JPG" alt="inter-interface.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 16:24:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085965#M1070222</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-05-14T16:24:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, routing issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085984#M1070225</link>
      <description>&lt;P&gt;I can see both inter/intra see attached run config&amp;nbsp;&lt;/P&gt;&lt;P&gt;I added also run config of core switch (it's an Aruba s1500) looks similar to cisco switch,&amp;nbsp;&lt;/P&gt;&lt;P&gt;coreswitch (port ge/0/0/11) --&amp;gt; connect to --&amp;gt; ASA (port 0/1)&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2020 02:01:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4085984#M1070225</guid>
      <dc:creator>AyoubC</dc:creator>
      <dc:date>2020-05-15T02:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510, routing issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4086303#M1070240</link>
      <description>Hello Marius/marvin,&lt;BR /&gt;I was able to sort out the issue,&lt;BR /&gt;the issue was on vlan 333 it self, I found that the host in vlan 333 is using aruba WLC as a default gateway and thus when traffic is getting forwarded to ASA for routing to vlan 30 we see: Routing failed to locate next hop for TCP from vms:10.10.30.10 to Aruba-MCs:172.16.210.20, while Aruba-MCs is sub-interface for 10.10.62.0/24 and 172.16.210.20 belongs to VLAN network30&lt;BR /&gt;&lt;BR /&gt;any way, thank you for your recomendations (SVIs, and Intra-interfaces routing) Appriciate,</description>
      <pubDate>Fri, 15 May 2020 02:09:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-routing-issue/m-p/4086303#M1070240</guid>
      <dc:creator>AyoubC</dc:creator>
      <dc:date>2020-05-15T02:09:02Z</dc:date>
    </item>
  </channel>
</rss>

