<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Switching traffic between interfaces in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/switching-traffic-between-interfaces/m-p/2954084#M148757</link>
    <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am facing an issue for a IP. The packet tracer on the asdm says the packet will be routed correctly and without any error from the ingress interface to the egress interface.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Now, when I capture the ingress interface, I can see the packets in wireshark. But I can't see those packets in the egress capture.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;NB:- this particular ip is not reachable from the Firewall.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So my Question is, Is this a normal behavior that the ASA will not switch the packets from the ingress to egress if the destination host is not reachable, or it will be switched regardless of the reachability of the destination.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or is this something on the ASA itself. I doubt this, because the rules pretty straight forward and another IP from the same subnet is working fine and again, the packet tracer tells me everything is fine for this particular IP.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you everyone in advance.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 08:29:49 GMT</pubDate>
    <dc:creator>Fazil Haneefa</dc:creator>
    <dc:date>2019-03-12T08:29:49Z</dc:date>
    <item>
      <title>Switching traffic between interfaces</title>
      <link>https://community.cisco.com/t5/network-security/switching-traffic-between-interfaces/m-p/2954084#M148757</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am facing an issue for a IP. The packet tracer on the asdm says the packet will be routed correctly and without any error from the ingress interface to the egress interface.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Now, when I capture the ingress interface, I can see the packets in wireshark. But I can't see those packets in the egress capture.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;NB:- this particular ip is not reachable from the Firewall.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So my Question is, Is this a normal behavior that the ASA will not switch the packets from the ingress to egress if the destination host is not reachable, or it will be switched regardless of the reachability of the destination.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or is this something on the ASA itself. I doubt this, because the rules pretty straight forward and another IP from the same subnet is working fine and again, the packet tracer tells me everything is fine for this particular IP.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you everyone in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:29:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/switching-traffic-between-interfaces/m-p/2954084#M148757</guid>
      <dc:creator>Fazil Haneefa</dc:creator>
      <dc:date>2019-03-12T08:29:49Z</dc:date>
    </item>
    <item>
      <title>Your firewall (the same is</title>
      <link>https://community.cisco.com/t5/network-security/switching-traffic-between-interfaces/m-p/2954085#M148758</link>
      <description>&lt;P&gt;Your firewall (the same is true for every IP-device) needs to know to which address on layer2 the packet should be forwarded, For that an ARP packet is sent out. If there is no one answering, then the actual packet is discarded. This is normal behavior.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Nov 2016 09:19:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/switching-traffic-between-interfaces/m-p/2954085#M148758</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-11-06T09:19:32Z</dc:date>
    </item>
    <item>
      <title>U mean the arp of the next</title>
      <link>https://community.cisco.com/t5/network-security/switching-traffic-between-interfaces/m-p/2954086#M148759</link>
      <description>&lt;P&gt;U mean the arp of the next hop for the egress interface, right?&lt;/P&gt;
&lt;P&gt;The next hop is reachable by the way.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 04:43:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/switching-traffic-between-interfaces/m-p/2954086#M148759</guid>
      <dc:creator>Fazil Haneefa</dc:creator>
      <dc:date>2016-11-08T04:43:54Z</dc:date>
    </item>
    <item>
      <title>So you have a remote</title>
      <link>https://community.cisco.com/t5/network-security/switching-traffic-between-interfaces/m-p/2954087#M148760</link>
      <description>&lt;P&gt;So you have a remote destination in your case that is not reachable? I assumed your host is on the same outside network of the ASA.&lt;/P&gt;
&lt;P&gt;Only the next hop (which can be a router) needs to be reachable in that case. If you don't see the egress-packets in that case, then I assume that your capture-statement is not matching that traffic.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2016 06:10:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/switching-traffic-between-interfaces/m-p/2954087#M148760</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2016-11-08T06:10:06Z</dc:date>
    </item>
  </channel>
</rss>

