<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding new subnet in the ASA. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/adding-new-subnet-in-the-asa/m-p/4787860#M1098390</link>
    <description>&lt;P&gt;Can you post the ASA&amp;nbsp; model,&amp;nbsp; ASA&amp;nbsp; code,&lt;/P&gt;
&lt;P&gt;Also how are you adding from CLI and GUI ?&lt;/P&gt;
&lt;P&gt;can you post the command you used ?&lt;/P&gt;
&lt;P&gt;do you have any subnet in the same range ?&amp;nbsp;&lt;SPAN&gt;10.3.20.0/22&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Mar 2023 11:56:52 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2023-03-06T11:56:52Z</dc:date>
    <item>
      <title>Adding new subnet in the ASA.</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-in-the-asa/m-p/4787847#M1098389</link>
      <description>&lt;P&gt;Hello Cisco Community,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have VTI setup from Cisco ASA(on prem) to Azure. Recently in azure side they add this new network 10.3.20.0/22. So now try to add this network on ASA for accessing this resource, but I couldn’t add this network? I got an error saying ip address/mask doesn’t pair. How can I add this network? Do I need to change network details on Azure side?&amp;nbsp;&lt;BR /&gt;Help on this would be appreciated &lt;span class="lia-unicode-emoji" title=":folded_hands:"&gt;🙏🏽&lt;/span&gt;.&lt;/P&gt;&lt;P&gt;Veera.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 11:53:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-in-the-asa/m-p/4787847#M1098389</guid>
      <dc:creator>veerapandiyanrengasamy</dc:creator>
      <dc:date>2023-03-06T11:53:27Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet in the ASA.</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-in-the-asa/m-p/4787860#M1098390</link>
      <description>&lt;P&gt;Can you post the ASA&amp;nbsp; model,&amp;nbsp; ASA&amp;nbsp; code,&lt;/P&gt;
&lt;P&gt;Also how are you adding from CLI and GUI ?&lt;/P&gt;
&lt;P&gt;can you post the command you used ?&lt;/P&gt;
&lt;P&gt;do you have any subnet in the same range ?&amp;nbsp;&lt;SPAN&gt;10.3.20.0/22&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 11:56:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-in-the-asa/m-p/4787860#M1098390</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-03-06T11:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet in the ASA.</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-in-the-asa/m-p/4787953#M1098398</link>
      <description>&lt;P&gt;VTI or route-based site-to-site VPNs depend on getting routes from the distant end to know what traffic to encrypt.&lt;/P&gt;
&lt;P&gt;You don't need to add the remote networks into a crypto map ACL like the old policy-based site-to-site VPN setup.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 13:15:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-in-the-asa/m-p/4787953#M1098398</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-03-06T13:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet in the ASA.</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-in-the-asa/m-p/4787970#M1098402</link>
      <description>&lt;P&gt;you add new subnet in Azure&amp;nbsp;&lt;BR /&gt;in ASA side&amp;nbsp;&lt;BR /&gt;you need static route toward VTI for this new route&amp;nbsp;&lt;BR /&gt;you need to include this new route in no-NAT (if there)&lt;BR /&gt;&lt;BR /&gt;that it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 13:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-in-the-asa/m-p/4787970#M1098402</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-03-06T13:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet in the ASA.</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-in-the-asa/m-p/4787978#M1098404</link>
      <description>&lt;P&gt;Thanks for your reply i have add this network 10.3.20.0/22(this network in Azure), But i could nt access the resorce on the Azure side. Here is packet-tracer output, Packet is allowing but web link is timeout.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;LAUS-ASA-1/pri/act# packet-tracer input inside tcp 192.168.1.100 1234 10.3.20.$&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 1.2.3.4(public ip) using egress ifc azure002-vti&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group inside_access_in_1 in interface inside&lt;BR /&gt;access-list inside_access_in_1 extended permit ip any any&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: FLOW-EXPORT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: encrypt&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 9&lt;BR /&gt;Type: USER-STATISTICS&lt;BR /&gt;Subtype: user-statistics&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 10&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: ipsec-tunnel-flow&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 11&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 12&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 13&lt;BR /&gt;Type: USER-STATISTICS&lt;BR /&gt;Subtype: user-statistics&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 14&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 880104, packet dispatched to next module&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: azure002-vti&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 13:48:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-in-the-asa/m-p/4787978#M1098404</guid>
      <dc:creator>veerapandiyanrengasamy</dc:creator>
      <dc:date>2023-03-06T13:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet in the ASA.</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-in-the-asa/m-p/4788007#M1098406</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;Thanks for all your reply. Problem found on Azure subnet. Now everything good. Many thanks for your input.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 14:31:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-in-the-asa/m-p/4788007#M1098406</guid>
      <dc:creator>veerapandiyanrengasamy</dc:creator>
      <dc:date>2023-03-06T14:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new subnet in the ASA.</title>
      <link>https://community.cisco.com/t5/network-security/adding-new-subnet-in-the-asa/m-p/4788008#M1098407</link>
      <description>&lt;P&gt;Hello Balaji,&lt;/P&gt;&lt;P&gt;Thanks for all your reply. Problem found on Azure subnet. Now everything good. Many thanks for your input.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 14:31:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/adding-new-subnet-in-the-asa/m-p/4788008#M1098407</guid>
      <dc:creator>veerapandiyanrengasamy</dc:creator>
      <dc:date>2023-03-06T14:31:24Z</dc:date>
    </item>
  </channel>
</rss>

