<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The Cisco 3560 probably has in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-reverse-route-issue/m-p/3028079#M134952</link>
    <description>&lt;P&gt;The Cisco 3560 probably has proxy arp enabled which was allowing this situation to work.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I bet if you put a "no ip proxy-arp" on each of the switch VLANs it would have broken.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jun 2017 01:24:12 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2017-06-13T01:24:12Z</dc:date>
    <item>
      <title>Cisco ASA Reverse Route Issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-reverse-route-issue/m-p/3028078#M134951</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; I have ASA failover bundle for one of the project and need one clarification about reverse route.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1. Before ASA i have a L3 3560 installed where three L3&amp;nbsp;vlan's are created. each SVI have following IP's.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;SVI1 : 192.168.1.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;SVI2:192.168.2.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;SVI3:192.168.3.1&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;2. Firewall is connected to SVI1 interface and 192.168.1.5 is assigned to the firewall.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So now in order to communicate other subnets with firewall i should have reverse route as below.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;route inside 192.168.2.0 255.255.255.0 192.168.1.1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;route inside 192.168.3.0 255.255.255.0 192.168.1.1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Today i have some issues with one of the Vlan. I.e VLAN 3 is not able to connect to applications which are after firewall. When i have checked the reverse route for that subnet notice below entry.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;route inside 192.168.3.0 255.255.255.0 192.168.3.1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;when i have changed the next hope to 192.168.1.1 then it started working.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Until here is very expected behavior .&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;*** key thing to notice: i have verified the backup firewall configuration for couple of months and noticed the reverse route for 192.168.3.0/24 is pointed to 192.168.3.1 only and none of the team complained about connectivity issue. I have a confusion here how this worked till now.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Note :- we upgraded&amp;nbsp;IOS from 8.3 to 8.4 and then to 9.1.7 . after 3 hours of upgradation we got this issue.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Can some please explain how it was working from last 3 years&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:28:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-reverse-route-issue/m-p/3028078#M134951</guid>
      <dc:creator>ciscoavinash</dc:creator>
      <dc:date>2019-03-12T09:28:24Z</dc:date>
    </item>
    <item>
      <title>The Cisco 3560 probably has</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-reverse-route-issue/m-p/3028079#M134952</link>
      <description>&lt;P&gt;The Cisco 3560 probably has proxy arp enabled which was allowing this situation to work.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I bet if you put a "no ip proxy-arp" on each of the switch VLANs it would have broken.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2017 01:24:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-reverse-route-issue/m-p/3028079#M134952</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2017-06-13T01:24:12Z</dc:date>
    </item>
  </channel>
</rss>

