<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi David, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/simple-routing-without-firewalling-on-inside-interface/m-p/2898295#M154997</link>
    <description>&lt;P&gt;Hi David,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can go for TCP state bypass:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/111986-asa-tcp-bypass-00.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This will stop inspecting the traffic on the inside interface for your MPLS.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
    <pubDate>Fri, 08 Apr 2016 14:58:45 GMT</pubDate>
    <dc:creator>Aditya Ganjoo</dc:creator>
    <dc:date>2016-04-08T14:58:45Z</dc:date>
    <item>
      <title>Simple routing without firewalling on inside interface</title>
      <link>https://community.cisco.com/t5/network-security/simple-routing-without-firewalling-on-inside-interface/m-p/2898294#M154995</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have the following problem :&lt;/P&gt;
&lt;P&gt;In my datacenter I have an Internet gateway, my ASA,&amp;nbsp;a local network and another gateway to my private network (MPLS).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The gateway to my network is on the inside network of the ASA.&lt;/P&gt;
&lt;P&gt;I also have a lot of&amp;nbsp;servers on the same inside network.&lt;/P&gt;
&lt;P&gt;So, the ASA inside network, the MPLS gw and the servers are on the same network (192.168.2.0/24)&lt;/P&gt;
&lt;P&gt;The ASA is the default router for my servers.&lt;/P&gt;
&lt;P&gt;I&amp;nbsp;can't get a connection from any client in the MPLS network to my servers.&lt;/P&gt;
&lt;P&gt;I tracked down the problem and I think that the problem is the following:&lt;/P&gt;
&lt;P&gt;When a TCP connection is initiated from my servers, it goes to the ASA then to the MPLS.&lt;/P&gt;
&lt;P&gt;But when the ACK comes back from the MPLS, it goes directly to the server, so the ASA tears down the connection.&lt;/P&gt;
&lt;P&gt;Same thing the other way around.&lt;/P&gt;
&lt;P&gt;My servers can ping to the MPLS (ICMP is stateless) but clients from the MPLS can't ping the servers.&lt;/P&gt;
&lt;P&gt;In my lab, I tried using a third interface for the MPLS and everything works fine.&lt;/P&gt;
&lt;P&gt;I also changed the default router to be the MPLS gw and it also works fine.&lt;/P&gt;
&lt;P&gt;But, in the real world,&amp;nbsp;I have no control over both gateways so I can't change the networking settings.&lt;/P&gt;
&lt;P&gt;I'm not allowed to use the MPLS&amp;nbsp;gateway as default router for my servers.&lt;/P&gt;
&lt;P&gt;And changing all the my servers IP is not an acceptable solution.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The question is : is there a way to simply route the&amp;nbsp;packets from the inside LAN to the MPLS network without inspecting them at all ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:35:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-routing-without-firewalling-on-inside-interface/m-p/2898294#M154995</guid>
      <dc:creator>dbrajort1</dc:creator>
      <dc:date>2019-03-12T07:35:49Z</dc:date>
    </item>
    <item>
      <title>Hi David,</title>
      <link>https://community.cisco.com/t5/network-security/simple-routing-without-firewalling-on-inside-interface/m-p/2898295#M154997</link>
      <description>&lt;P&gt;Hi David,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can go for TCP state bypass:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/111986-asa-tcp-bypass-00.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This will stop inspecting the traffic on the inside interface for your MPLS.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 14:58:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-routing-without-firewalling-on-inside-interface/m-p/2898295#M154997</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-04-08T14:58:45Z</dc:date>
    </item>
  </channel>
</rss>

