<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA routing issues between interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-routing-issues-between-interfaces/m-p/4116058#M1071885</link>
    <description>Is that the full output of the packet-tracer command?&lt;BR /&gt;What was the exact syntax of the packet-tracer command you ran?&lt;BR /&gt;</description>
    <pubDate>Thu, 09 Jul 2020 15:08:55 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2020-07-09T15:08:55Z</dc:date>
    <item>
      <title>Cisco ASA routing issues between interfaces</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-routing-issues-between-interfaces/m-p/4115789#M1071876</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have defined our main network as inside on our Cisco ASA. Then we defined vlan (sub interfaces) &amp;nbsp;within this interface and add groups that allow access to each vlan (departments).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So far all works as expected. We also allow inter and intra communications between interfaces (all have same level of security 100).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So from outside to inside or other sub interfaces (vlan) each one within a group with proper NAT and rules work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem comes when we want to access from inside network (10.11.x.x) to a vlan with ip 172.21.x.x.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course I cannot add a route to this network since it is known by the device on a vlan.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I need to move the inside to be also a vlan and no IP address on the interface itself but use a vlan like the others under inside to be able to reach the other sub interfaces right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what we have is something like:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Ethernet1/14&lt;BR /&gt;description untagged / native VLAN to inner networks&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.11.x.x 255.255.252.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Ethernet1/14.30&lt;BR /&gt;vlan 30&lt;BR /&gt;nameif WEB_dev&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 172.21.x.x &amp;nbsp;255.255.0.0&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Carmelo Lopez&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 07:23:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-routing-issues-between-interfaces/m-p/4115789#M1071876</guid>
      <dc:creator>lopezportilla</dc:creator>
      <dc:date>2020-07-09T07:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA routing issues between interfaces</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-routing-issues-between-interfaces/m-p/4115938#M1071877</link>
      <description>Hi,&lt;BR /&gt;Please run packet-tracer from the CLI and provide the output for review. E.g:- "packet-tracer input inside icmp 10.11.x.x 8 0 172.21.x.x"&lt;BR /&gt;&lt;BR /&gt;Do you have NAT configured that could unintentially NATTING the traffic? Provide the output of "show nat detail"&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Thu, 09 Jul 2020 12:22:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-routing-issues-between-interfaces/m-p/4115938#M1071877</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-07-09T12:22:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA routing issues between interfaces</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-routing-issues-between-interfaces/m-p/4116024#M1071882</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes we do NAT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is the packet trace&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;MAC Access list&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: Resolve Egress Interface&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;found next-hop 172.21.xx.xx using egress ifc&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;Web-dev&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: SUBOPTIMAL-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: suboptimal next-hop&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;ifc selected is not same as preferred ifc&lt;/P&gt;&lt;P&gt;Doing route lookup again on ifc&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: Resolve Egress Interface&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;found next-hop 10.11.xx.xx using egress ifc&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: Web-dev&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (rpf-violated) Reverse-path verify failed, Drop-location: frame 0x000000aab04e9034 flow (NA)/NA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The NAT (only the part involved)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;6 (outside) to (inside) source static Net-XXX-VPN-network Net-XXX-VPN-network&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static Net-XXX-VPN-network Net-XXX-VPN-network no-proxy-arp route-lookup description no NAT for VPN Clients going to their own net&lt;/P&gt;&lt;P&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 1348838, untranslate_hits = 1351597&lt;/P&gt;&lt;P&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Source - Origin: 10.11.xx.0 Translated: 10.11.xx.0&lt;/P&gt;&lt;P&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Destination - Origin: 10.11.xx.0 Translated: 10.11.xx.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;10 (outside) to (Web-dev) source static Net_Web-Dev_NEtwork Net_Web-dev_NEtwork&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static Net_Web-dev_NEtwork Net_Web-dev_NEtwork no-proxy-arp route-lookup description no NAT for packets going in same network&lt;/P&gt;&lt;P&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 1489143, untranslate_hits = 45535&lt;/P&gt;&lt;P&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Source - Origin: 172.21.0.0, Translated: 172.21.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This one I was thinking about using to NAT from inside to the Web-DEV. Not enable (I did and nothing happened).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11 (inside) to (web-dev) source static Net-XXX-VPN-network Web-dev-PAT-inside&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;destination static Net_web-dev_NEtwork Net_web-dev_NEtwork no-proxy-arp inactive&lt;/P&gt;&lt;P&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Source - Origin: 10.11.xx.0/22, Translated: 172.21.xx.xx/32&lt;/P&gt;&lt;P&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Destination - Origin: 172.21.0.0/16, Translated: 172.21.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2020 14:31:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-routing-issues-between-interfaces/m-p/4116024#M1071882</guid>
      <dc:creator>lopezportilla</dc:creator>
      <dc:date>2020-07-09T14:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA routing issues between interfaces</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-routing-issues-between-interfaces/m-p/4116058#M1071885</link>
      <description>Is that the full output of the packet-tracer command?&lt;BR /&gt;What was the exact syntax of the packet-tracer command you ran?&lt;BR /&gt;</description>
      <pubDate>Thu, 09 Jul 2020 15:08:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-routing-issues-between-interfaces/m-p/4116058#M1071885</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-07-09T15:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA routing issues between interfaces</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-routing-issues-between-interfaces/m-p/4116576#M1071943</link>
      <description>&lt;P&gt;Hi Rob,&lt;/P&gt;&lt;P&gt;yes that’s all from the trace&lt;/P&gt;&lt;P&gt;i did like you said replacing the IP with 2 working IP within the 2 networks&lt;/P&gt;&lt;P&gt;best&lt;/P&gt;&lt;P&gt;carmelo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 13:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-routing-issues-between-interfaces/m-p/4116576#M1071943</guid>
      <dc:creator>lopezportilla</dc:creator>
      <dc:date>2020-07-10T13:01:38Z</dc:date>
    </item>
  </channel>
</rss>

