<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FPR1010 Drop-reason: (no-route) No route to host in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fpr1010-drop-reason-no-route-no-route-to-host/m-p/4856095#M1101693</link>
    <description>&lt;P&gt;you need o NATing from private to public IP.&lt;/P&gt;
&lt;P&gt;You need defualt route also&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jun 2023 09:51:06 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-06-16T09:51:06Z</dc:date>
    <item>
      <title>FPR1010 Drop-reason: (no-route) No route to host</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-drop-reason-no-route-no-route-to-host/m-p/4856081#M1101691</link>
      <description>&lt;P&gt;&lt;FONT face="courier new,courier"&gt;I'm a beginner to the firewall configuration using a new FPR 1010. I can't make inside network connect to the internet, except I can ping the ISP gateway ! Is this mean ingress is being blocked?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Attempting TCP_Bypass always failed deployment with these warnings.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;WARNING: Pool (0.0.0.0) overlap with existing pool.&lt;BR /&gt;WARNING: Pool (0.0.0.0) overlap with existing pool.&lt;BR /&gt;WARNING: All traffic destined to the IP address of the outside interface is being redirected&lt;BR /&gt;WARNING: Users may not be able to access any service enabled on the outside interface&lt;BR /&gt;WARNING: Pool (0.0.0.0) overlap with existing pool.&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Here is packet-tracer https bypass cmd result. Is there any common policy that block by default? Am I missed something?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;firepower# packet-tracer input inside tcp 10.10.10.1 https 20X.XXX.XXX.XXX https bypass-checks&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Phase: 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Type: Pix security check&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Subtype:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Result: ALLOW&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Config:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Additional Information:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;PIX security check: user is not allowed to access a firewall&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;interface from a network that is connected to another interface&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Phase: 2&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Type: Pix security check&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Subtype:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Result: ALLOW&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Config:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Additional Information:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;PIX security check: user is not allowed to access a firewall&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;interface from a network that is connected to another interface&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Result:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;input-interface: inside(vrfid:0)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;input-status: up&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;input-line-status: up&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Action: drop&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Drop-reason: (no-route) No route to host, Drop-location: frame 0x000056082f3d9311 flow (NA)/NA&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;I will post show running-config later.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 09:29:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-drop-reason-no-route-no-route-to-host/m-p/4856081#M1101691</guid>
      <dc:creator>Anoudeth</dc:creator>
      <dc:date>2023-06-16T09:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 Drop-reason: (no-route) No route to host</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-drop-reason-no-route-no-route-to-host/m-p/4856095#M1101693</link>
      <description>&lt;P&gt;you need o NATing from private to public IP.&lt;/P&gt;
&lt;P&gt;You need defualt route also&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jun 2023 09:51:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-drop-reason-no-route-no-route-to-host/m-p/4856095#M1101693</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-06-16T09:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 Drop-reason: (no-route) No route to host</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-drop-reason-no-route-no-route-to-host/m-p/4858043#M1101774</link>
      <description>&lt;P&gt;Thank you for your guidance. It turns out that it is the NAT. The issue is resolved. Here is what I did, just want to share with other beginners.&lt;/P&gt;&lt;P&gt;NAT Rule (Before Auto) - MANUAL STATIC&lt;BR /&gt;inside &amp;gt; outside&lt;/P&gt;&lt;P&gt;Original Source Address: dmz-network-192.168.1.0-30&lt;BR /&gt;Original Destination Address: any-ipv4&lt;BR /&gt;Translated Source Address: Interface&lt;BR /&gt;Translated Destination Address: any-ipv4&lt;/P&gt;&lt;P&gt;For Routing: Static Routing&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network 192.168.2.0/30&amp;nbsp; - Gateway: 192.168.1.1 (And this 192.168.1.1 will be the WAN of the router)&lt;BR /&gt;Network 0.0.0.0/24 - Gateway: 2XX.XXX.XXX.241 (gateway provided by ISP)&lt;/P&gt;&lt;P&gt;Interfaces on the Firewall:&lt;/P&gt;&lt;P&gt;Outside Interface:&amp;nbsp;2XX.XXX.XXX.246 (IP provided by ISP)&lt;BR /&gt;Inside (DMZ) Interface: 192.168.1.2&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 06:14:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-drop-reason-no-route-no-route-to-host/m-p/4858043#M1101774</guid>
      <dc:creator>Anoudeth</dc:creator>
      <dc:date>2023-06-20T06:14:57Z</dc:date>
    </item>
  </channel>
</rss>

