<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA routing oddity help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-routing-oddity-help/m-p/3074267#M136239</link>
    <description>&lt;P&gt;Need a hand here trying to figure out an odd situation.&lt;/P&gt;
&lt;P&gt;I have 2 ASAs directly connected to each other at Site A and Site B. I have site to site vpns terminating at Site A. Remote sites communicate with networks inside Site A (172.25.0.0/16). Every once in a while, I notice that my MAN connection between the 2 firewalls is saturated with 20Mb/s of traffic in each direction. It seems that Site A ASA is sending traffic from the site to site destined for 172.25.x.x towards Site B. Then site B turns around and sends the traffic back to Site A, Site A ASA then sends back to Site B. Routing ping pong? This repeats itself over and over again. Routing tables are correct in each device. Site A 5516-x should be sending traffic destined to 172.25.4.x to vlan4 interface, not GRN interface. I have no idea why this is happening.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;(outside vpns, 172.16.x.x)&lt;/P&gt;
&lt;P&gt;Site A 5516-x (GRN interface 172.27.10.17) &amp;lt;--------------------&amp;gt; Site B 5510 (177 interface 172.27.10.18)&lt;/P&gt;
&lt;P&gt;(inside vlans, 172.25.0.0/16)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Site A sho conn&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;ICMP &lt;STRONG&gt;GRN&lt;/STRONG&gt; 172.16.10.246:1 &lt;STRONG&gt;GRN&lt;/STRONG&gt;&amp;nbsp; 172.25.4.40:0, idle 0:00:00, bytes 41602656, flags X&lt;BR /&gt;this would also show the UDP connection shown below in Site B, but I deleted this connection (actually had to shun the ip and delete the conn as it kept reappearing)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="text-decoration: underline;"&gt;Site A sho route&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;172.25.4.0&lt;/STRONG&gt; 255.255.255.0 &lt;STRONG&gt;is directly connected, vlan4&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Site B sho conn&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;ICMP &lt;STRONG&gt;177&lt;/STRONG&gt; 172.16.10.246:1 &lt;STRONG&gt;177 172.25.4.40&lt;/STRONG&gt;:0, idle 0:00:00, bytes 9644640&lt;/P&gt;
&lt;P&gt;UDP &lt;STRONG&gt;177&lt;/STRONG&gt; 172.16.9.5:161 &lt;STRONG&gt;177 172.25.4.20&lt;/STRONG&gt;:60393, idle 0:00:00, bytes 2553741606, flags -&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Site B sho route&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;R&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;172.25.4.0&lt;/STRONG&gt; 255.255.255.0 [120/1] via &lt;STRONG&gt;172.27.0.17, 0:00:21, 177&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 09:15:36 GMT</pubDate>
    <dc:creator>acomiskey</dc:creator>
    <dc:date>2019-03-12T09:15:36Z</dc:date>
    <item>
      <title>ASA routing oddity help</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-oddity-help/m-p/3074267#M136239</link>
      <description>&lt;P&gt;Need a hand here trying to figure out an odd situation.&lt;/P&gt;
&lt;P&gt;I have 2 ASAs directly connected to each other at Site A and Site B. I have site to site vpns terminating at Site A. Remote sites communicate with networks inside Site A (172.25.0.0/16). Every once in a while, I notice that my MAN connection between the 2 firewalls is saturated with 20Mb/s of traffic in each direction. It seems that Site A ASA is sending traffic from the site to site destined for 172.25.x.x towards Site B. Then site B turns around and sends the traffic back to Site A, Site A ASA then sends back to Site B. Routing ping pong? This repeats itself over and over again. Routing tables are correct in each device. Site A 5516-x should be sending traffic destined to 172.25.4.x to vlan4 interface, not GRN interface. I have no idea why this is happening.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;(outside vpns, 172.16.x.x)&lt;/P&gt;
&lt;P&gt;Site A 5516-x (GRN interface 172.27.10.17) &amp;lt;--------------------&amp;gt; Site B 5510 (177 interface 172.27.10.18)&lt;/P&gt;
&lt;P&gt;(inside vlans, 172.25.0.0/16)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Site A sho conn&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;ICMP &lt;STRONG&gt;GRN&lt;/STRONG&gt; 172.16.10.246:1 &lt;STRONG&gt;GRN&lt;/STRONG&gt;&amp;nbsp; 172.25.4.40:0, idle 0:00:00, bytes 41602656, flags X&lt;BR /&gt;this would also show the UDP connection shown below in Site B, but I deleted this connection (actually had to shun the ip and delete the conn as it kept reappearing)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="text-decoration: underline;"&gt;Site A sho route&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;172.25.4.0&lt;/STRONG&gt; 255.255.255.0 &lt;STRONG&gt;is directly connected, vlan4&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Site B sho conn&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;ICMP &lt;STRONG&gt;177&lt;/STRONG&gt; 172.16.10.246:1 &lt;STRONG&gt;177 172.25.4.40&lt;/STRONG&gt;:0, idle 0:00:00, bytes 9644640&lt;/P&gt;
&lt;P&gt;UDP &lt;STRONG&gt;177&lt;/STRONG&gt; 172.16.9.5:161 &lt;STRONG&gt;177 172.25.4.20&lt;/STRONG&gt;:60393, idle 0:00:00, bytes 2553741606, flags -&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Site B sho route&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;R&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;172.25.4.0&lt;/STRONG&gt; 255.255.255.0 [120/1] via &lt;STRONG&gt;172.27.0.17, 0:00:21, 177&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:15:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-oddity-help/m-p/3074267#M136239</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2019-03-12T09:15:36Z</dc:date>
    </item>
    <item>
      <title>Could you please attach the</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-oddity-help/m-p/3074268#M136240</link>
      <description>&lt;P&gt;Could you please attach the running config from side A. It could be a some overlapping crypto map or NAT config that might be causing it. Also, attach show route from ASA A.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 20:05:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-oddity-help/m-p/3074268#M136240</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2017-04-24T20:05:36Z</dc:date>
    </item>
    <item>
      <title>Hi Aj, thanks for the</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-oddity-help/m-p/3074269#M136241</link>
      <description>&lt;P&gt;Hi Aj, thanks for the response. I will have to do some sanitizing. I'll try to get it up tomorrow.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 20:09:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-oddity-help/m-p/3074269#M136241</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2017-04-24T20:09:42Z</dc:date>
    </item>
  </channel>
</rss>

