<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Should the Router in the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936973#M155916</link>
    <description>&lt;P&gt;Should the Router in the second site not also have the ip route 0.0.0.0 0.0.0.0 10.1.100.4 so it would now where to cast the trafic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm unsure how to make a default route on the MPLS because what i have attempted in the previous post did not work, would you be able to tell me how i should make the default rate?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank You&lt;/P&gt;</description>
    <pubDate>Fri, 05 Aug 2016 07:06:07 GMT</pubDate>
    <dc:creator>coolmon1981</dc:creator>
    <dc:date>2016-08-05T07:06:07Z</dc:date>
    <item>
      <title>ASA WAN Through MPLS</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936968#M155911</link>
      <description>&lt;H6&gt;Hi Everyone,&lt;/H6&gt;
&lt;H6&gt;I hope one of you can help me or point me into the right direction. Please be gentle i'm a newbe.&lt;/H6&gt;
&lt;H6&gt;From my HQ i'm able to access internet through the ASA, and i would like my users at my branch site to use the same internet connection through the MPLS circuit&amp;nbsp;&lt;/H6&gt;
&lt;H6&gt;On my branch site i'm able to receive IP address from my DHCP server that stands in HQ, and i'm able to ping the ip address of the ASA firewall. from any vlan on my branch office.&amp;nbsp;&lt;/H6&gt;
&lt;H6 class="prettyprint"&gt;When i do a traceroute from the router on the branch site to the ip of firewall on HQ it looks like this.&lt;/H6&gt;
&lt;PRE class="prettyprint"&gt;Tracing the route to 10.1.100.4&lt;BR /&gt;VRF info: (vrf in name/id, vrf out name/id)&lt;BR /&gt; 1 172.16.33.1 0 msec 0 msec 0 msec&lt;BR /&gt; 2 172.16.22.1 4 msec 4 msec 4 msec&lt;BR /&gt; 3 172.16.1.1 0 msec 0 msec 4 msec&lt;BR /&gt; 4 172.16.1.2 4 msec 4 msec 4 msec&lt;/PRE&gt;
&lt;H6&gt;and if i do a traceroute to 8.8.8.8&lt;/H6&gt;
&lt;PRE class="prettyprint"&gt;Tracing the route to 8.8.8.8&lt;BR /&gt;VRF info: (vrf in name/id, vrf out name/id)&lt;BR /&gt; 1 172.16.33.1 0 msec 0 msec 0 msec&lt;BR /&gt; 2 172.16.33.2 0 msec 0 msec 0 msec&lt;BR /&gt; 3 172.16.33.1 0 msec 0 msec 0 msec&lt;BR /&gt; 4 172.16.33.2 4 msec 0 msec 0 msec&lt;BR /&gt; 5 172.16.33.1 0 msec 0 msec 0 msec&lt;BR /&gt; 6 172.16.33.2 4 msec 0 msec 0 msec&lt;BR /&gt; 7 172.16.33.1 4 msec 0 msec 4 msec&lt;BR /&gt; 8 172.16.33.2 0 msec 0 msec 0 msec&lt;BR /&gt; 9 172.16.33.1 4 msec 0 msec 8 msec&lt;BR /&gt; 10 172.16.33.2 0 msec 0 msec 0 msec&lt;/PRE&gt;
&lt;H6&gt;I hope some would be able to see what i'm missing&amp;nbsp;&lt;/H6&gt;
&lt;H6&gt;Thank You&lt;/H6&gt;
&lt;H6&gt;Best Regards.&lt;/H6&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:05:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936968#M155911</guid>
      <dc:creator>coolmon1981</dc:creator>
      <dc:date>2019-03-12T08:05:28Z</dc:date>
    </item>
    <item>
      <title>You need to tell your MPLS</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936969#M155912</link>
      <description>&lt;P&gt;You need to tell your MPLS provider to add a default route pointing to your ASA.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 03:08:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936969#M155912</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-08-04T03:08:36Z</dc:date>
    </item>
    <item>
      <title>Hi;</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936970#M155913</link>
      <description>&lt;P&gt;Hi;&lt;/P&gt;
&lt;P&gt;So i would need to add this to my PE1, PE2 and P Router in order to make it work&lt;/P&gt;
&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.1.100.4 where 10.1.100.4 is the ip of ASA&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 08:35:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936970#M155913</guid>
      <dc:creator>coolmon1981</dc:creator>
      <dc:date>2016-08-04T08:35:59Z</dc:date>
    </item>
    <item>
      <title>I have tried to add ip route</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936971#M155914</link>
      <description>&lt;H6 class="prettyprint"&gt;I have tried to add&amp;nbsp;&lt;SPAN&gt;ip route 0.0.0.0 0.0.0.0 10.1.100.4 to SW conected to PE1 and the Router connected to PE2&lt;BR /&gt;and i have added&amp;nbsp;default-information originate and&amp;nbsp;redistribute ospf 2 match internal external 1 to both provider edge router.&lt;/SPAN&gt;&lt;/H6&gt;
&lt;H6&gt;&lt;SPAN&gt;but the result is the same or am i completely wrong.&amp;nbsp;&lt;/SPAN&gt;&lt;/H6&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;router ospf 2 vrf DTL&lt;BR /&gt; redistribute bgp 3292 subnets&lt;BR /&gt; network 172.16.1.0 0.0.0.3 area 0&lt;BR /&gt; network 172.16.1.4 0.0.0.3 area 0&lt;BR /&gt;&amp;nbsp;default-information originate&lt;BR /&gt;!&lt;BR /&gt;router ospf 1&lt;BR /&gt; mpls ldp autoconfig&lt;BR /&gt; network 2.2.2.2 0.0.0.0 area 0&lt;BR /&gt; network 172.16.11.0 0.0.0.3 area 0&lt;BR /&gt;!&lt;BR /&gt;router bgp 3292&lt;BR /&gt; bgp log-neighbor-changes&lt;BR /&gt; neighbor 4.4.4.4 remote-as 3292&lt;BR /&gt; neighbor 4.4.4.4 update-source Loopback0&lt;BR /&gt; ! &lt;BR /&gt; address-family vpnv4&lt;BR /&gt; neighbor 4.4.4.4 activate&lt;BR /&gt; neighbor 4.4.4.4 send-community extended&lt;BR /&gt; exit-address-family&lt;BR /&gt; !&lt;BR /&gt; address-family ipv4 vrf DTL&lt;BR /&gt; redistribute ospf 2 match internal external 1&lt;BR /&gt; default-information originate&lt;BR /&gt; exit-address-family&lt;/PRE&gt;
&lt;H6&gt;Hope you will be able to tell we what i should add the the Provider Edge 1 router in order to make it work.&amp;nbsp;&lt;/H6&gt;
&lt;H6&gt;Thank You&lt;/H6&gt;</description>
      <pubDate>Thu, 04 Aug 2016 20:56:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936971#M155914</guid>
      <dc:creator>coolmon1981</dc:creator>
      <dc:date>2016-08-04T20:56:24Z</dc:date>
    </item>
    <item>
      <title>You should only need to add</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936972#M155915</link>
      <description>&lt;P&gt;You should only need to add it to the routers that are layer 3 adjacent to the firewall.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 00:13:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936972#M155915</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-08-05T00:13:31Z</dc:date>
    </item>
    <item>
      <title>Should the Router in the</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936973#M155916</link>
      <description>&lt;P&gt;Should the Router in the second site not also have the ip route 0.0.0.0 0.0.0.0 10.1.100.4 so it would now where to cast the trafic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm unsure how to make a default route on the MPLS because what i have attempted in the previous post did not work, would you be able to tell me how i should make the default rate?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 07:06:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936973#M155916</guid>
      <dc:creator>coolmon1981</dc:creator>
      <dc:date>2016-08-05T07:06:07Z</dc:date>
    </item>
    <item>
      <title>Hi;</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936974#M155917</link>
      <description>&lt;P style="margin-bottom: .0001pt; line-height: normal; tab-stops: 292.5pt;"&gt;Hi;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;After reviewing the configuration I found an extra command on your branch router which is telling you MPLS (PE2) Router to forward the traffic back to branch router. Please remove the default-information originate command under ospf process. This information need to advertise from HO DS switches.&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;STRONG&gt;Branch RTR:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;router ospf 1&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;no default-information originate always&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;The above configuration will resolve the looping issue b/w PE2 &amp;amp; Branch RTR.&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;If you want to enable to default information originate command from HO then you need to modify the following configuration:&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;STRONG&gt;(Optional) Part-1 HO DS Switches:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;router ospf 1&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&amp;nbsp;default-information originate always&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&lt;STRONG&gt;(Optional) Part-2 Branch RTR:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;no ip route 0.0.0.0 0.0.0.0 10.1.100.4&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;Thanks &amp;amp; Best regards;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Aug 2016 21:18:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936974#M155917</guid>
      <dc:creator>ahmedshoaib</dc:creator>
      <dc:date>2016-08-07T21:18:30Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936975#M155918</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have removed &lt;STRONG&gt;default-information originate always&lt;/STRONG&gt;&amp;nbsp;and removed &lt;STRONG&gt;ip route&amp;nbsp;0.0.0.0 0.0.0.0 10.1.100.4&amp;nbsp;&lt;/STRONG&gt;from the branch router.&lt;/P&gt;
&lt;P&gt;and i have added the&amp;nbsp;&lt;STRONG&gt;default-information originate always&amp;nbsp;&lt;/STRONG&gt;to both DSW in my HQ.&lt;/P&gt;
&lt;P&gt;I don't get the loop anymore on the branch router. but i cant do internet either.&amp;nbsp;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;From Windows&lt;BR /&gt;Tracing route to 8.8.8.8 over a maximum of 30 hops&lt;BR /&gt;  1     5 ms           1 ms     2 ms      10.2.99.2&lt;BR /&gt;  2   10.2.99.2     reports: Destination host unreachable.&lt;BR /&gt;&lt;BR /&gt;From Branch Router&lt;BR /&gt;Tracing the route to google-public-dns-a.google.com (8.8.8.8)&lt;BR /&gt;VRF info: (vrf in name/id, vrf out name/id)&lt;BR /&gt; 1 * * * &lt;BR /&gt; 2 * * * &lt;BR /&gt; 3 * * * &lt;BR /&gt; 4 * * * &lt;BR /&gt; 5 * * * &lt;BR /&gt; 6 * * * &lt;BR /&gt; 7 * * * &lt;BR /&gt; 8 * * * &lt;BR /&gt; 9 * * * &lt;BR /&gt; 10 * * * &lt;/PRE&gt;
&lt;PRE class="prettyprint"&gt;If i do a (show ip route)&lt;BR /&gt;&lt;BR /&gt;do show ip route &lt;BR /&gt;Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;BR /&gt; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area &lt;BR /&gt; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;BR /&gt; E1 - OSPF external type 1, E2 - OSPF external type 2&lt;BR /&gt; i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;BR /&gt; ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;BR /&gt; o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP&lt;BR /&gt; + - replicated route, % - next hop override&lt;BR /&gt;&lt;BR /&gt;Gateway of last resort is not set&lt;BR /&gt;&lt;BR /&gt; 1.0.0.0/32 is subnetted, 1 subnets&lt;BR /&gt;O IA 1.1.1.1 [110/3] via 172.16.33.1, 1d13h, GigabitEthernet1/0/1&lt;BR /&gt; 5.0.0.0/32 is subnetted, 1 subnets&lt;BR /&gt;C 5.5.5.5 is directly connected, Loopback0&lt;BR /&gt; 6.0.0.0/32 is subnetted, 1 subnets&lt;BR /&gt;O IA 6.6.6.6 [110/4] via 172.16.33.1, 1d13h, GigabitEthernet1/0/1&lt;BR /&gt; 7.0.0.0/32 is subnetted, 1 subnets&lt;BR /&gt;O 7.7.7.7 [110/2] via 10.2.50.2, 1d11h, Vlan50&lt;BR /&gt; [110/2] via 10.2.30.2, 1d11h, Vlan30&lt;BR /&gt; [110/2] via 10.2.20.2, 1d11h, Vlan20&lt;BR /&gt; [110/2] via 10.2.10.2, 1d11h, Vlan10&lt;BR /&gt; 10.0.0.0/8 is variably subnetted, 19 subnets, 2 masks&lt;BR /&gt;O IA 10.1.10.0/24 [110/3] via 172.16.33.1, 1d13h, GigabitEthernet1/0/1&lt;BR /&gt;O IA 10.1.20.0/24 [110/3] via 172.16.33.1, 1d13h, GigabitEthernet1/0/1&lt;BR /&gt;O IA 10.1.30.0/24 [110/3] via 172.16.33.1, 1d13h, GigabitEthernet1/0/1&lt;BR /&gt;O IA 10.1.40.0/24 [110/4] via 172.16.33.1, 1d13h, GigabitEthernet1/0/1&lt;BR /&gt;O IA 10.1.50.0/24 [110/3] via 172.16.33.1, 1d13h, GigabitEthernet1/0/1&lt;BR /&gt;O IA 10.1.99.0/24 [110/3] via 172.16.33.1, 1d13h, GigabitEthernet1/0/1&lt;BR /&gt;O IA 10.1.100.0/24 [110/3] via 172.16.33.1, 1d13h, GigabitEthernet1/0/1&lt;BR /&gt;C 10.2.10.0/24 is directly connected, Vlan10&lt;BR /&gt;L 10.2.10.1/32 is directly connected, Vlan10&lt;BR /&gt;C 10.2.20.0/24 is directly connected, Vlan20&lt;BR /&gt;L 10.2.20.1/32 is directly connected, Vlan20&lt;BR /&gt;C 10.2.30.0/24 is directly connected, Vlan30&lt;BR /&gt;L 10.2.30.1/32 is directly connected, Vlan30&lt;BR /&gt;C 10.2.40.0/24 is directly connected, Vlan40&lt;BR /&gt;L 10.2.40.1/32 is directly connected, Vlan40&lt;BR /&gt;C 10.2.50.0/24 is directly connected, Vlan50&lt;BR /&gt;L 10.2.50.1/32 is directly connected, Vlan50&lt;BR /&gt;C 10.2.99.0/24 is directly connected, Vlan99&lt;BR /&gt;L 10.2.99.1/32 is directly connected, Vlan99&lt;BR /&gt; 172.16.0.0/16 is variably subnetted, 5 subnets, 2 masks&lt;BR /&gt;O IA 172.16.1.0/30 [110/2] via 172.16.33.1, 1d13h, GigabitEthernet1/0/1&lt;BR /&gt;O IA 172.16.1.4/30 [110/2] via 172.16.33.1, 1d13h, GigabitEthernet1/0/1&lt;BR /&gt;C 172.16.33.0/30 is directly connected, GigabitEthernet1/0/1&lt;BR /&gt;L 172.16.33.2/32 is directly connected, GigabitEthernet1/0/1&lt;BR /&gt;O 172.16.33.4/30 [110/2] via 172.16.33.1, 1d12h, GigabitEthernet1/0/1&lt;BR /&gt; [110/2] via 10.2.50.2, 1d11h, Vlan50&lt;BR /&gt; [110/2] via 10.2.30.2, 1d11h, Vlan30&lt;BR /&gt; [110/2] via 10.2.20.2, 1d11h, Vlan20&lt;/PRE&gt;
&lt;P&gt;Thank You&lt;/P&gt;
&lt;P&gt;Best Regards&lt;/P&gt;</description>
      <pubDate>Sat, 13 Aug 2016 20:25:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936975#M155918</guid>
      <dc:creator>coolmon1981</dc:creator>
      <dc:date>2016-08-13T20:25:56Z</dc:date>
    </item>
    <item>
      <title>Hi Ahmedshoaib,</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936976#M155919</link>
      <description>&lt;P&gt;Hi Ahmedshoaib,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks alot i found the error, i have removed &lt;STRONG&gt;default-information originate&lt;/STRONG&gt; on PE2 under&lt;/P&gt;
&lt;H6&gt;router BGP 3292&lt;BR /&gt;address-family ipv4 vrf DTL&lt;BR /&gt;no default-information originate&lt;/H6&gt;
&lt;H5&gt;And on PE1 i removed&lt;/H5&gt;
&lt;H6&gt;router ospf 2 vrf DTL&lt;BR /&gt;no default-information originate&lt;/H6&gt;
&lt;H5&gt;Thanks again for your help&lt;/H5&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Aug 2016 21:56:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-through-mpls/m-p/2936976#M155919</guid>
      <dc:creator>coolmon1981</dc:creator>
      <dc:date>2016-08-13T21:56:38Z</dc:date>
    </item>
  </channel>
</rss>

