<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5506-X redundant subinterfaces not communicate with each other in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609622#M1090044</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/605219"&gt;@riccardodem&lt;/a&gt; that's because you can only ping the local ASA interface, not ping through the ASA to a far interface IP address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI, you test connectivity be sending traffic through the ASA....you obviously need the NAT rules configured correctly to ensure you aren't unintentially translating.&lt;/P&gt;</description>
    <pubDate>Fri, 13 May 2022 08:48:14 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2022-05-13T08:48:14Z</dc:date>
    <item>
      <title>ASA 5506-X redundant subinterfaces not communicate with each other</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609125#M1089995</link>
      <description>&lt;P&gt;Hi all, as per the attached configuration the subinterfaces (e.g vlan101 and vlan105) are not communicating with each other, But they regularly go on Internet. What is wrong in the attached configuration?&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 15:14:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609125#M1089995</guid>
      <dc:creator>riccardodem</dc:creator>
      <dc:date>2022-05-12T15:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506-X redundant subinterfaces not communicate with each other</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609133#M1089997</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/605219"&gt;@riccardodem&lt;/a&gt; configure some NAT exemption rules, your traffic between the VLANS is probably being unintentially translated.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 15:26:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609133#M1089997</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-05-12T15:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506-X redundant subinterfaces not communicate with each other</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609154#M1089998</link>
      <description>&lt;P&gt;thanks Rob...any documentation about&amp;nbsp;&lt;SPAN&gt;NAT exemption rules cofiguration?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 15:43:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609154#M1089998</guid>
      <dc:creator>riccardodem</dc:creator>
      <dc:date>2022-05-12T15:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506-X redundant subinterfaces not communicate with each other</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609162#M1089999</link>
      <description>&lt;P&gt;From this post and your previous post, You have two Internet and you want to use it for Anyconnect if I am right ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/misc/anyconnect-faq/anyconnect-faq.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/misc/anyconnect-faq/anyconnect-faq.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;check this doc. it help you in your design.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 15:50:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609162#M1089999</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-05-12T15:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506-X redundant subinterfaces not communicate with each other</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609168#M1090001</link>
      <description>&lt;P&gt;Only one WAN internet connection on port&amp;nbsp;GigabitEthernet0/0. Multiple vlans (subinterfaces) on redundant interfaces, must be natted to WAN and comunicate with each other.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 15:55:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609168#M1090001</guid>
      <dc:creator>riccardodem</dc:creator>
      <dc:date>2022-05-12T15:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506-X redundant subinterfaces not communicate with each other</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609180#M1090003</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/605219"&gt;@riccardodem&lt;/a&gt; example&lt;/P&gt;
&lt;P&gt;&lt;A href="https://integratingit.wordpress.com/2022/01/16/asa-nat-exemption/" target="_blank"&gt;https://integratingit.wordpress.com/2022/01/16/asa-nat-exemption/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 16:11:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609180#M1090003</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-05-12T16:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506-X redundant subinterfaces not communicate with each other</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609181#M1090004</link>
      <description>&lt;P&gt;Sub interface INSIDE ?&amp;nbsp;&lt;BR /&gt;you config bridge group and then assign IP to VLAN ??&amp;nbsp;&lt;BR /&gt;the FW either work as Brdige or as router.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 16:12:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609181#M1090004</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-05-12T16:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506-X redundant subinterfaces not communicate with each other</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609588#M1090038</link>
      <description>&lt;P&gt;I tried without solving to put eg. network vlan104 and vlan105 in communication with these commands:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;nat (vlan105,vlan104) source static vlan105 vlan105 destination static vlan104 vlan104&lt;/P&gt;&lt;P&gt;nat (vlan104,vlan105) source static vlan104 vlan104 destination static vlan105 vlan105&lt;BR /&gt;&lt;BR /&gt;Trying to ping from vlan105 to vlan104:&lt;BR /&gt;&lt;BR /&gt;5 (vlan105) to (vlan104) source static vlan105 vlan105 destination static vlan104 vlan104&lt;BR /&gt;&lt;STRONG&gt;translate_hits = 4, untranslate_hits = 4&lt;/STRONG&gt;&lt;BR /&gt;6 (vlan104) to (vlan105) source static vlan104 vlan104 destination static vlan105 vlan105&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;&lt;BR /&gt;this is the output of sh nat detail:&lt;BR /&gt;&lt;BR /&gt;Manual NAT Policies (Section 1)&lt;BR /&gt;1 (vlan101) to (outside) source dynamic any interface&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 0.0.0.0/0, Translated: 192.168.178.2/24&lt;BR /&gt;2 (vlan102) to (outside) source dynamic any interface&lt;BR /&gt;translate_hits = 10451, untranslate_hits = 8647&lt;BR /&gt;Source - Origin: 0.0.0.0/0, Translated: 192.168.178.2/24&lt;BR /&gt;3 (vlan103) to (outside) source dynamic any interface&lt;BR /&gt;translate_hits = 41, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 0.0.0.0/0, Translated: 192.168.178.2/24&lt;BR /&gt;&lt;STRONG&gt;4 (vlan104) to (outside)&lt;/STRONG&gt; source dynamic any interface&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 0.0.0.0/0, Translated: 192.168.178.2/24&lt;BR /&gt;&lt;STRONG&gt;5 (vlan105) to (vlan104)&lt;/STRONG&gt; source static vlan105 vlan105 destination static vlan104 vlan104&lt;BR /&gt;translate_hits = 5, untranslate_hits = 5&lt;BR /&gt;Source - Origin: 192.168.10.0/24, Translated: 192.168.10.0/24&lt;BR /&gt;Destination - Origin: 192.168.6.192/27, Translated: 192.168.6.192/27&lt;BR /&gt;&lt;STRONG&gt;6 (vlan104) to (vlan105)&lt;/STRONG&gt; source static vlan104 vlan104 destination static vlan105 vlan105&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 192.168.6.192/27, Translated: 192.168.6.192/27&lt;BR /&gt;Destination - Origin: 192.168.10.0/24, Translated: 192.168.10.0/24&lt;BR /&gt;&lt;STRONG&gt;7 (vlan105) to (outside)&lt;/STRONG&gt; source dynamic any interface&lt;BR /&gt;translate_hits = 12, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 0.0.0.0/0, Translated: 192.168.178.2/24&lt;BR /&gt;&lt;BR /&gt;thanks in advance for the help&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2022 07:36:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609588#M1090038</guid>
      <dc:creator>riccardodem</dc:creator>
      <dc:date>2022-05-13T07:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506-X redundant subinterfaces not communicate with each other</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609589#M1090039</link>
      <description>&lt;P&gt;yes, Asa act also as a router (nat-dhcp-routing):&lt;BR /&gt;on gi1/1 WAN to ISP router&lt;BR /&gt;on gi1/7 and 1/8 reduntant interface to 2 Cisco switch with 5 vlans (subintefaces)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2022 07:41:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609589#M1090039</guid>
      <dc:creator>riccardodem</dc:creator>
      <dc:date>2022-05-13T07:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506-X redundant subinterfaces not communicate with each other</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609602#M1090040</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/605219"&gt;@riccardodem&lt;/a&gt; how are you testing exactly?&lt;/P&gt;
&lt;P&gt;Run packet-tracer from the CLI and provide the full output for review&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;packet-tracert input vlan105 tcp 192.168.10.5 3000 192.168.6.224 80 detail&lt;/PRE&gt;
&lt;P&gt;You should also remove the other dynamic nat rules to section 2 (auto nat).&lt;/P&gt;
&lt;P&gt;FYI, You only need one NAT rule to add, not 2. The NAT is bi-directional.&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2022 08:20:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609602#M1090040</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-05-13T08:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506-X redundant subinterfaces not communicate with each other</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609620#M1090043</link>
      <description>&lt;P&gt;I was mistakenly trying to ping from a host on the vlan105 network the gateway of vlan104 with this result&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;ASA-HLSDN# packet-tracer input vlan105 tcp 192.168.10.50 3000 192.168.6.222 80&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: vlan105&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (no-route) No route to host&lt;BR /&gt;&lt;BR /&gt;it works instead pinging from host of vlan105 to host of vlan104, I will do more tests by removing nat exception to see if the situation changes&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;packet-tracer&amp;nbsp;command is very usefull!&lt;BR /&gt;&lt;/SPAN&gt;thanks&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2022 08:43:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609620#M1090043</guid>
      <dc:creator>riccardodem</dc:creator>
      <dc:date>2022-05-13T08:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506-X redundant subinterfaces not communicate with each other</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609622#M1090044</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/605219"&gt;@riccardodem&lt;/a&gt; that's because you can only ping the local ASA interface, not ping through the ASA to a far interface IP address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI, you test connectivity be sending traffic through the ASA....you obviously need the NAT rules configured correctly to ensure you aren't unintentially translating.&lt;/P&gt;</description>
      <pubDate>Fri, 13 May 2022 08:48:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-x-redundant-subinterfaces-not-communicate-with-each/m-p/4609622#M1090044</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-05-13T08:48:14Z</dc:date>
    </item>
  </channel>
</rss>

