<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA interface - Traffic on 2 different subnet in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-interface-traffic-on-2-different-subnet/m-p/2876665#M155079</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have an ASA 5515 where an interface is connected to a router whit 2 different networks defined 192.168.1.0 - 192.168.168.2.0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The interface configuration is the following:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;GigabitEthernet0/0 81.77.10.200 YES manual &lt;G class="gr_ gr_260 gr-alert gr_spell gr_disable_anim_appear undefined ContextualSpelling only-del replaceWithoutSep" id="260" data-gr-id="260"&gt;up up&lt;/G&gt;&amp;nbsp;&lt;SPAN&gt;outside&lt;/SPAN&gt;&lt;BR /&gt;GigabitEthernet0/1 192.168.66.1 YES manual &lt;G class="gr_ gr_689 gr-alert gr_spell undefined ContextualSpelling only-del replaceWithoutSep" id="689" data-gr-id="689"&gt;up up&lt;/G&gt;&amp;nbsp;inside&lt;BR /&gt;&lt;STRONG&gt;GigabitEthernet0/2 192.168.1.238 YES manual &lt;/STRONG&gt;&lt;G class="gr_ gr_690 gr-alert gr_spell undefined ContextualSpelling only-del replaceWithoutSep" id="690" data-gr-id="690"&gt;up up&lt;/G&gt;&amp;nbsp;office&lt;BR /&gt;GigabitEthernet0/3 192.168.5.2 YES manual &lt;G class="gr_ gr_691 gr-alert gr_spell undefined ContextualSpelling only-del replaceWithoutSep" id="691" data-gr-id="691"&gt;up up&lt;/G&gt;&amp;nbsp;&lt;G class="gr_ gr_724 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="724" data-gr-id="724"&gt;vpn&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;A device on interface 0/2 is able to access&amp;nbsp;192.168.1.0 traffic but not&amp;nbsp;&lt;SPAN&gt;192.168.168.2.0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Route rules looks as the following:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S* 0.0.0.0 0.0.0.0 [1/0] via 80.71.19.214, outside&lt;BR /&gt;C 81.77.10.208 255.255.255.248 is directly connected, outside&lt;BR /&gt;L 81.77.10.200 255.255.255.255 is directly connected, outside&lt;BR /&gt;C 192.168.5.0 255.255.255.0 is directly connected, vpn&lt;BR /&gt;L 192.168.5.2 255.255.255.255 is directly connected, vpn&lt;BR /&gt;C 192.168.11.0 255.255.255.0 is directly connected, office&lt;BR /&gt;L 192.168.1.238 255.255.255.255 is directly connected, office&lt;BR /&gt;&lt;STRONG&gt;S 192.168.2.0 255.255.255.0 [1/0] via 192.168.12.1, office&lt;/STRONG&gt;&lt;BR /&gt;C 192.168.66.0 255.255.255.0 is directly connected, inside&lt;BR /&gt;L 192.168.66.1 255.255.255.255 is directly connected, inside&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;and if I try to ping any address on&amp;nbsp;&lt;SPAN&gt;192.168.168.2.0 on the ASA it works:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; ping 192.168.2.1&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.2.1, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/10 ms&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any help?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 07:34:51 GMT</pubDate>
    <dc:creator>Renato Tuveri</dc:creator>
    <dc:date>2019-03-12T07:34:51Z</dc:date>
    <item>
      <title>ASA interface - Traffic on 2 different subnet</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-traffic-on-2-different-subnet/m-p/2876665#M155079</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have an ASA 5515 where an interface is connected to a router whit 2 different networks defined 192.168.1.0 - 192.168.168.2.0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The interface configuration is the following:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;GigabitEthernet0/0 81.77.10.200 YES manual &lt;G class="gr_ gr_260 gr-alert gr_spell gr_disable_anim_appear undefined ContextualSpelling only-del replaceWithoutSep" id="260" data-gr-id="260"&gt;up up&lt;/G&gt;&amp;nbsp;&lt;SPAN&gt;outside&lt;/SPAN&gt;&lt;BR /&gt;GigabitEthernet0/1 192.168.66.1 YES manual &lt;G class="gr_ gr_689 gr-alert gr_spell undefined ContextualSpelling only-del replaceWithoutSep" id="689" data-gr-id="689"&gt;up up&lt;/G&gt;&amp;nbsp;inside&lt;BR /&gt;&lt;STRONG&gt;GigabitEthernet0/2 192.168.1.238 YES manual &lt;/STRONG&gt;&lt;G class="gr_ gr_690 gr-alert gr_spell undefined ContextualSpelling only-del replaceWithoutSep" id="690" data-gr-id="690"&gt;up up&lt;/G&gt;&amp;nbsp;office&lt;BR /&gt;GigabitEthernet0/3 192.168.5.2 YES manual &lt;G class="gr_ gr_691 gr-alert gr_spell undefined ContextualSpelling only-del replaceWithoutSep" id="691" data-gr-id="691"&gt;up up&lt;/G&gt;&amp;nbsp;&lt;G class="gr_ gr_724 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="724" data-gr-id="724"&gt;vpn&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;A device on interface 0/2 is able to access&amp;nbsp;192.168.1.0 traffic but not&amp;nbsp;&lt;SPAN&gt;192.168.168.2.0&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Route rules looks as the following:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;S* 0.0.0.0 0.0.0.0 [1/0] via 80.71.19.214, outside&lt;BR /&gt;C 81.77.10.208 255.255.255.248 is directly connected, outside&lt;BR /&gt;L 81.77.10.200 255.255.255.255 is directly connected, outside&lt;BR /&gt;C 192.168.5.0 255.255.255.0 is directly connected, vpn&lt;BR /&gt;L 192.168.5.2 255.255.255.255 is directly connected, vpn&lt;BR /&gt;C 192.168.11.0 255.255.255.0 is directly connected, office&lt;BR /&gt;L 192.168.1.238 255.255.255.255 is directly connected, office&lt;BR /&gt;&lt;STRONG&gt;S 192.168.2.0 255.255.255.0 [1/0] via 192.168.12.1, office&lt;/STRONG&gt;&lt;BR /&gt;C 192.168.66.0 255.255.255.0 is directly connected, inside&lt;BR /&gt;L 192.168.66.1 255.255.255.255 is directly connected, inside&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;and if I try to ping any address on&amp;nbsp;&lt;SPAN&gt;192.168.168.2.0 on the ASA it works:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; ping 192.168.2.1&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.2.1, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/10 ms&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any help?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:34:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-traffic-on-2-different-subnet/m-p/2876665#M155079</guid>
      <dc:creator>Renato Tuveri</dc:creator>
      <dc:date>2019-03-12T07:34:51Z</dc:date>
    </item>
    <item>
      <title>Hello Renato,</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-traffic-on-2-different-subnet/m-p/2876666#M155080</link>
      <description>&lt;P&gt;Hello Renato,&lt;/P&gt;
&lt;P&gt;Can you please confirm if there are any access-list applied on the interfaces since the to the box traffic and through the box traffic will be processed differently.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Please share the output of&amp;nbsp;&lt;BR /&gt;show run access-group&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Do a traceroute from &lt;G class="gr_ gr_524 gr-alert gr_gramm undefined Grammar only-ins replaceWithoutSep gr-progress" id="524" data-gr-id="524"&gt;firewall&lt;/G&gt; to 192.168.2.x and check what are all the hops and also confirm those hops have a correct route for your subnet.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Dinesh Moudgil&lt;/P&gt;
&lt;P&gt;P.S. Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2016 10:24:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-traffic-on-2-different-subnet/m-p/2876666#M155080</guid>
      <dc:creator>Dinesh Moudgil</dc:creator>
      <dc:date>2016-04-05T10:24:43Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-traffic-on-2-different-subnet/m-p/2876667#M155081</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;show run access-group:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;access-group outside_access_in in interface outside&lt;BR /&gt;access-group inside_in in interface inside&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;traceroute 192.168.2.1&lt;/P&gt;
&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Tracing the route to 192.168.2.1&lt;/P&gt;
&lt;P&gt;1 192.168.2.1 10 msec 0 msec 0 msec&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Renato&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2016 10:45:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-traffic-on-2-different-subnet/m-p/2876667#M155081</guid>
      <dc:creator>Renato Tuveri</dc:creator>
      <dc:date>2016-04-05T10:45:27Z</dc:date>
    </item>
    <item>
      <title>Please share the output of</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-traffic-on-2-different-subnet/m-p/2876668#M155082</link>
      <description>&lt;P&gt;Please share the output of&amp;nbsp;&lt;BR /&gt;show &lt;G class="gr_ gr_32 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="32" data-gr-id="32"&gt;ip&lt;/G&gt;&lt;BR /&gt;&lt;G class="gr_ gr_43 gr-alert gr_gramm undefined Grammar multiReplace" id="43" data-gr-id="43"&gt;show&lt;/G&gt; run route&lt;BR /&gt;show&amp;nbsp;access-list&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Dinesh Moudgil&lt;/P&gt;
&lt;P&gt;P.S. Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2016 13:12:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-traffic-on-2-different-subnet/m-p/2876668#M155082</guid>
      <dc:creator>Dinesh Moudgil</dc:creator>
      <dc:date>2016-04-05T13:12:53Z</dc:date>
    </item>
    <item>
      <title>show ip</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-traffic-on-2-different-subnet/m-p/2876669#M155083</link>
      <description>&lt;P&gt;show &lt;G class="gr_ gr_14 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="14" data-gr-id="14"&gt;ip&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;Interface Name IP address Subnet mask Method&lt;BR /&gt;GigabitEthernet0/0 outside ****&lt;G class="gr_ gr_16 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="16" data-gr-id="16"&gt;Pubblic&lt;/G&gt; &lt;G class="gr_ gr_17 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="17" data-gr-id="17"&gt;ip&lt;/G&gt;*** 255.255.255.248 manual&lt;BR /&gt;GigabitEthernet0/1 inside 192.168.66.1 255.255.255.0 manual&lt;BR /&gt;GigabitEthernet0/2 office 192.168.1.238 255.255.255.0 manual&lt;BR /&gt;GigabitEthernet0/3 &lt;G class="gr_ gr_18 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="18" data-gr-id="18"&gt;vpn&lt;/G&gt; 192.168.5.2 255.255.255.0 manual&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;show run route&lt;BR /&gt;route outsideBA 0.0.0.0 0.0.0.0 80.71.19.214 1&lt;BR /&gt;route office 192.168.2.0 255.255.255.0 192.168.2.1 1&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;show access-list&lt;BR /&gt;access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 4096)&lt;BR /&gt;alert-interval 300&lt;BR /&gt;access-list outside_access_in; 18 elements; name hash: 0x60092435&lt;BR /&gt;access-list outside_access_in line 1 remark Allor ssh to BA London&lt;BR /&gt;access-list outside_access_in line 2 extended permit object-group DM_INLINE_SERVICE_1 any object-group DM_INLINE_NETWORK_1 (hitcnt=184) 0x1b0c2864&lt;BR /&gt;access-list outside_access_in line 2 extended permit tcp any eq 16022 192.168.66.0 255.255.255.0 eq ssh (hitcnt=1) 0xb9f3a481&lt;BR /&gt;access-list outside_access_in line 2 extended permit tcp any eq 16022 host 192.168.66.160 eq ssh (hitcnt=0) 0x3e417c21&lt;BR /&gt;access-list outside_access_in line 2 extended permit tcp any 192.168.66.0 255.255.255.0 eq ssh (hitcnt=183) 0x83d4a48a&lt;BR /&gt;access-list outside_access_in line 2 extended permit tcp any host 192.168.66.160 eq ssh (hitcnt=0) 0xe8a3c0f7&lt;BR /&gt;access-list outside_access_in line 3 remark Allow AIstore Cloud Mirror VPN&lt;BR /&gt;access-list outside_access_in line 4 extended permit object 1195-dest any object-group DM_INLINE_NETWORK_2 log notifications interval 300 (hitcnt=1285) 0x3e72a4fc&lt;BR /&gt;access-list outside_access_in line 4 extended permit udp any 192.168.66.0 255.255.255.0 eq 1195 log notifications interval 300 (hitcnt=1285) 0x5d0b3fe2&lt;BR /&gt;access-list outside_access_in line 4 extended permit udp any host 192.168.66.170 eq 1195 log notifications interval 300 (hitcnt=0) 0xd9fdef26&lt;BR /&gt;access-list outside_access_in line 5 extended permit udp any host 192.168.66.170 eq 1195 (hitcnt=0) 0xd9fdef26&lt;BR /&gt;access-list outside_access_in line 6 extended permit udp host 192.168.66.170 any eq 1195 (hitcnt=0) 0x32c8ee84&lt;BR /&gt;access-list outside_access_in line 7 remark NAT for BA London HTPPS/HTTP/SMTP&lt;BR /&gt;access-list outside_access_in line 8 extended permit object-group DM_INLINE_SERVICE_2 any object-group DM_INLINE_NETWORK_3 (hitcnt=3523) 0x7ab78e2b&lt;BR /&gt;access-list outside_access_in line 8 extended permit tcp any 192.168.66.0 255.255.255.0 eq www (hitcnt=0) 0x5c9d5b78&lt;BR /&gt;access-list outside_access_in line 8 extended permit tcp any host 192.168.66.160 eq www (hitcnt=0) 0xc3c067d0&lt;BR /&gt;access-list outside_access_in line 8 extended permit udp any 192.168.66.0 255.255.255.0 eq www (hitcnt=0) 0x61a77cc7&lt;BR /&gt;access-list outside_access_in line 8 extended permit udp any host 192.168.66.160 eq www (hitcnt=0) 0xa7c94c8f&lt;BR /&gt;access-list outside_access_in line 8 extended permit tcp any 192.168.66.0 255.255.255.0 eq https (hitcnt=3096) 0x5372ab57&lt;BR /&gt;access-list outside_access_in line 8 extended permit tcp any host 192.168.66.160 eq https (hitcnt=0) 0x883d395a&lt;BR /&gt;access-list outside_access_in line 8 extended permit tcp any 192.168.66.0 255.255.255.0 eq smtp (hitcnt=258) 0x787c50ac&lt;BR /&gt;access-list outside_access_in line 8 extended permit tcp any host 192.168.66.160 eq smtp (hitcnt=0) 0x5c6dd0a6&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Renato&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2016 13:38:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-traffic-on-2-different-subnet/m-p/2876669#M155083</guid>
      <dc:creator>Renato Tuveri</dc:creator>
      <dc:date>2016-04-05T13:38:16Z</dc:date>
    </item>
    <item>
      <title>Your route statements points</title>
      <link>https://community.cisco.com/t5/network-security/asa-interface-traffic-on-2-different-subnet/m-p/2876670#M155084</link>
      <description>&lt;P&gt;Your route statements &lt;G class="gr_ gr_31 gr-alert gr_gramm undefined Grammar multiReplace" id="31" data-gr-id="31"&gt;points&lt;/G&gt; the packets at 192.168.2.1 and the routing output shows the next hop as 192.168.12.1 which is contradictory&lt;/P&gt;
&lt;P&gt;route office 192.168.2.0 255.255.255.0 &lt;STRONG&gt;192.168.2.1&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;S 192.168.2.0 255.255.255.0 [1/0] via &lt;STRONG&gt;192.168.12.1,&lt;/STRONG&gt; office&lt;/P&gt;
&lt;P&gt;Moreover, why is the next hop for "office" interface set up for 192.168.2.1 (not in the subnet of interface address i.e. 192.168.1.238 )&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Dinesh Moudgil&lt;/P&gt;
&lt;P&gt;P.S. Please rate helpful posts.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2016 00:48:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-interface-traffic-on-2-different-subnet/m-p/2876670#M155084</guid>
      <dc:creator>Dinesh Moudgil</dc:creator>
      <dc:date>2016-04-06T00:48:16Z</dc:date>
    </item>
  </channel>
</rss>

