<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic It is a carryover from its in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/routing-problem/m-p/3028584#M145448</link>
    <description>&lt;P&gt;It is a carryover from its PIX days I believe. Basically the ASA does not allow you to access any resource on any interface if the traffic is sourced from any other interface. These checks happen even before NAT is checked, so it is not a problem with your NAT.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Mar 2017 14:43:30 GMT</pubDate>
    <dc:creator>Rahul Govindan</dc:creator>
    <dc:date>2017-03-27T14:43:30Z</dc:date>
    <item>
      <title>Routing Problem</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem/m-p/3028581#M145440</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When i want to open a website from the public ip on the firewall the internal LAN i cannot open it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What`s the problem? Is it not possible to open a connection to a server from the inside to the public IP of the firewall?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;From outside everything is working fine.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:08:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem/m-p/3028581#M145440</guid>
      <dc:creator>Raimund Schimanovits</dc:creator>
      <dc:date>2019-03-12T09:08:00Z</dc:date>
    </item>
    <item>
      <title>No this is not possible by</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem/m-p/3028582#M145442</link>
      <description>&lt;P&gt;No this is not possible by design. You cannot access anything on a far end interface of the ASA when coming in from another interface. This is documented here:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/admin_management.html#29729&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 13:44:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem/m-p/3028582#M145442</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-03-27T13:44:22Z</dc:date>
    </item>
    <item>
      <title>Hmmm but what is the probem?</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem/m-p/3028583#M145445</link>
      <description>&lt;P&gt;Hmmm but what is the probem?&lt;/P&gt;
&lt;P&gt;I open a http request to an public IP.&lt;/P&gt;
&lt;P&gt;On the outside interface i made a NAT to the Server inside.&lt;/P&gt;
&lt;P&gt;The NAT is working perfect when the package comes from the internet. When i open the http request from the inside interface to the public IP from the NAT i get an unreachable.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So the package from the inside went through NAT comes to the outside Interface and goes back to the NAT to the server inside.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Am i right?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 14:19:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem/m-p/3028583#M145445</guid>
      <dc:creator>Raimund Schimanovits</dc:creator>
      <dc:date>2017-03-27T14:19:37Z</dc:date>
    </item>
    <item>
      <title>It is a carryover from its</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem/m-p/3028584#M145448</link>
      <description>&lt;P&gt;It is a carryover from its PIX days I believe. Basically the ASA does not allow you to access any resource on any interface if the traffic is sourced from any other interface. These checks happen even before NAT is checked, so it is not a problem with your NAT.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 14:43:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem/m-p/3028584#M145448</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-03-27T14:43:30Z</dc:date>
    </item>
    <item>
      <title>Ok Thanks for the perfect</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem/m-p/3028585#M145450</link>
      <description>&lt;P&gt;Ok Thanks for the perfect answer. The problem i had is that i alwas have now error messages in the log.&lt;/P&gt;
&lt;P&gt;When someone in the network makes a connection to the public ip i had this message.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Deny IP spoof from (xxx.xxxx.xxxx.xxxx) to xxx.xxx.xxx.xxxx on interface outside&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;then i only can block the ip from inside to outside or do you have a better idea?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2017 07:28:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem/m-p/3028585#M145450</guid>
      <dc:creator>Raimund Schimanovits</dc:creator>
      <dc:date>2017-03-28T07:28:44Z</dc:date>
    </item>
    <item>
      <title>Yeah the log is shown because</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem/m-p/3028586#M145451</link>
      <description>&lt;P&gt;Yeah the log is shown because the inside user gets translated to the same public ip address as the destination, resulting in the Source and destination IP address fields to be the same. You can stop this by applying an ACL on your inside interface to block traffic to the public ip address for your inside users.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2017 10:16:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem/m-p/3028586#M145451</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2017-03-28T10:16:21Z</dc:date>
    </item>
  </channel>
</rss>

