<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: juniper netscreen with loopback interface to Cisco ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/juniper-netscreen-with-loopback-interface-to-cisco-asa/m-p/3708875#M13571</link>
    <description>Null routes should work. What issues are you facing with it. ? Static&lt;BR /&gt;routes might create issues with proxy arp but null routes should be safe to&lt;BR /&gt;use&lt;BR /&gt;</description>
    <pubDate>Tue, 18 Sep 2018 15:23:44 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2018-09-18T15:23:44Z</dc:date>
    <item>
      <title>juniper netscreen with loopback interface to Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/juniper-netscreen-with-loopback-interface-to-cisco-asa/m-p/3708838#M13568</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are migrating a juniper netscreen to a Cisco ASA. The firewall is running BGP with the upstream routers. The netscreen has a loopback interface created with subnets that are used for nating. The loop back is created to inject the nat networks into BGP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My question is how do you achieve this on a Cisco since it does not support loopback interfaces?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1 - use null routes? We found one article that suggested creating NULL routes for the natblocks and that will allow the subnets to be injected into BGP. But we tried that in the lab and having weird results. Not sure if its our config or if using the NULL routes is a bad idea.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2 - Static route on the router? Even though we are running bgp between router and fw.. can I add a static route as well from router to the fw?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3 - any other thoughts?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:15:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/juniper-netscreen-with-loopback-interface-to-cisco-asa/m-p/3708838#M13568</guid>
      <dc:creator>christianstp1</dc:creator>
      <dc:date>2020-02-21T16:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: juniper netscreen with loopback interface to Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/juniper-netscreen-with-loopback-interface-to-cisco-asa/m-p/3708875#M13571</link>
      <description>Null routes should work. What issues are you facing with it. ? Static&lt;BR /&gt;routes might create issues with proxy arp but null routes should be safe to&lt;BR /&gt;use&lt;BR /&gt;</description>
      <pubDate>Tue, 18 Sep 2018 15:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/juniper-netscreen-with-loopback-interface-to-cisco-asa/m-p/3708875#M13571</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2018-09-18T15:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: juniper netscreen with loopback interface to Cisco ASA</title>
      <link>https://community.cisco.com/t5/network-security/juniper-netscreen-with-loopback-interface-to-cisco-asa/m-p/3708926#M13572</link>
      <description>&lt;P&gt;Everything inbound doesn't seem to be working... We can see on the router's routing table the route been learned via the firewall so we know bgp&amp;nbsp;is advertising the route correctly, however, we can't pass traffic.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, our MX window was over and we had to rollback before troubleshooting further... We are thinking about static routes as a second workaround... Proxy ARP issue should be fixed by having the "arp permit-nonconnected" command, don't you think?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Juan Lombana&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Sep 2018 15:54:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/juniper-netscreen-with-loopback-interface-to-cisco-asa/m-p/3708926#M13572</guid>
      <dc:creator>julomban1</dc:creator>
      <dc:date>2018-09-18T15:54:09Z</dc:date>
    </item>
  </channel>
</rss>

