<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-to-inside-routing-problem/m-p/2886861#M157112</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;sorry for my short answer I'm on the bus right now.&lt;/P&gt;
&lt;P&gt;why are you using nat?&lt;/P&gt;
&lt;P&gt;did you activate same-security interface feature?&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Mon, 04 Jul 2016 23:26:22 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2016-07-04T23:26:22Z</dc:date>
    <item>
      <title>Cisco ASA inside to inside routing problem</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-to-inside-routing-problem/m-p/2886860#M157109</link>
      <description>&lt;P&gt;Hello. I have two interfaces configured on ASA - 'inside' 10.100.60.1/24 and 'balancers' 10.100.40.1/24&lt;/P&gt;
&lt;P&gt;Also I have router R1 and subnet 10.100.7.0/24 &amp;nbsp;behind. &amp;nbsp;R1 has 2 interfaces - 10.100.70.1/24 and 10.100.60.150/24&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Problem is that i &lt;SPAN style="color: #000000; text-decoration: underline;"&gt;can't reach subnet 10.100.70.0/24 from host&amp;nbsp;10.100.60.34 (&lt;/SPAN&gt;&lt;SPAN style="color: #000000; text-decoration: underline;"&gt;Default gateway&amp;nbsp;is ASA 10.100.60.1)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I can&amp;nbsp;successfully reach&amp;nbsp;&lt;SPAN&gt;subnet 10.100.70.0/24 from ASA itself or from other subnets like 10.100.40.0/24&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have access rules for both directions:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;access-list access-inside-in extended permit ip object-group net_10.100.70 object-group net_10.100.60&lt;/SPAN&gt;&lt;SPAN&gt;&lt;BR /&gt;access-list access-inside-in extended permit ip object-group net_10.100.60 object-group net_10.100.70&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also i have NAT rules with 'route-lookup':&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;nat (any,inside) source static internal_nets internal_nets destination static net_10.100.60 net_10.100.60 no-proxy-arp route-lookup&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;nat (any,inside) source static internal_nets internal_nets destination static net_10.100.70 net_10.100.70 no-proxy-arp route-lookup&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;nat (any,balancers) source static internal_nets internal_nets destination static net_10.100.40 net_10.100.40 no-proxy-arp route-lookup&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/net70_1.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet0/2.60&lt;BR /&gt; vlan 60&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 10.100.60.1 255.255.255.0 standby 10.100.60.2&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet0/1.40&lt;BR /&gt; vlan 40&lt;BR /&gt; nameif balancers&lt;BR /&gt; security-level 60&lt;BR /&gt; ip address 10.100.40.1 255.255.255.0 standby 10.100.40.2&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;# show route&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;S 10.100.70.0 255.255.255.0 [1/0] via 10.100.60.150, inside&lt;BR /&gt;C 10.100.40.0 255.255.255.0 is directly connected, balancers&lt;BR /&gt;C 10.100.60.0 255.255.255.0 is directly connected, inside&lt;/P&gt;
&lt;P&gt;C ............&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;packet-tracer input inside icmp 10.100.60.34 8 0 10.100.70.103&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in 10.100.70.0 255.255.255.0 inside&lt;/P&gt;
&lt;P&gt;Phase: 3&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (any,inside) source static internal_nets internal_nets destination static net_10.100.60 net_10.100.60 no-proxy-arp route-lookup&amp;nbsp;&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface inside&lt;BR /&gt;Untranslate 10.100.70.103/0 to 10.100.70.103/0&lt;/P&gt;
&lt;P&gt;Phase: 4&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;input-interface: inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-to-inside-routing-problem/m-p/2886860#M157109</guid>
      <dc:creator>rStelmakh.loyalty-partners</dc:creator>
      <dc:date>2019-03-12T07:59:08Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-to-inside-routing-problem/m-p/2886861#M157112</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;sorry for my short answer I'm on the bus right now.&lt;/P&gt;
&lt;P&gt;why are you using nat?&lt;/P&gt;
&lt;P&gt;did you activate same-security interface feature?&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2016 23:26:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-to-inside-routing-problem/m-p/2886861#M157112</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-07-04T23:26:22Z</dc:date>
    </item>
    <item>
      <title>This rules wasn't configured</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-to-inside-routing-problem/m-p/2886862#M157116</link>
      <description>&lt;P&gt;This rules wasn't configured by me but i guess it stands for security.&lt;/P&gt;
&lt;P&gt;Are you asking about '&lt;STRONG&gt;noproxyarp&lt;/STRONG&gt;' option? It is disabled for all interfaces&lt;/P&gt;
&lt;P&gt;asa01# show run all sysopt&lt;BR /&gt;no sysopt connection timewait&lt;BR /&gt;sysopt connection tcpmss 1380&lt;BR /&gt;sysopt connection tcpmss minimum 0&lt;BR /&gt;sysopt connection permit-vpn&lt;BR /&gt;sysopt connection reclassify-vpn&lt;BR /&gt;no sysopt connection preserve-vpn-flows&lt;BR /&gt;no sysopt radius ignore-secret&lt;BR /&gt;no sysopt noproxyarp out&lt;BR /&gt;no sysopt noproxyarp public&lt;BR /&gt;no sysopt noproxyarp outside&lt;BR /&gt;no sysopt noproxyarp dmz&lt;BR /&gt;&lt;STRONG&gt;no sysopt noproxyarp balancers&lt;/STRONG&gt;&lt;BR /&gt;no sysopt noproxyarp in&lt;BR /&gt;&lt;STRONG&gt;no sysopt noproxyarp inside&lt;/STRONG&gt;&lt;BR /&gt;no sysopt noproxyarp management&lt;/P&gt;
&lt;P&gt;.....&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 07:16:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-to-inside-routing-problem/m-p/2886862#M157116</guid>
      <dc:creator>rStelmakh.loyalty-partners</dc:creator>
      <dc:date>2016-07-05T07:16:34Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-to-inside-routing-problem/m-p/2886863#M157118</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I don't see why you have nat exemption as the traffic remains on inside interface.&lt;/P&gt;
&lt;P&gt;Also verify that Same-security-traffic permit intra-interface is configured on your asa.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS: Please don't forget to rate and mark as correct answer if this solved your issue&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 11:15:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-to-inside-routing-problem/m-p/2886863#M157118</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-07-05T11:15:13Z</dc:date>
    </item>
    <item>
      <title>I did 'same-security-traffic</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-to-inside-routing-problem/m-p/2886864#M157120</link>
      <description>&lt;P&gt;I did '&lt;STRONG&gt;same-security-traffic permit intra-interface&lt;/STRONG&gt;' and&amp;nbsp;the problem is solved&lt;/P&gt;
&lt;P&gt;Thanks very much!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 12:16:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-to-inside-routing-problem/m-p/2886864#M157120</guid>
      <dc:creator>rStelmakh.loyalty-partners</dc:creator>
      <dc:date>2016-07-05T12:16:02Z</dc:date>
    </item>
    <item>
      <title>You're very welcome </title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-inside-to-inside-routing-problem/m-p/2886865#M157122</link>
      <description>&lt;P&gt;You're very welcome&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2016 12:59:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-inside-to-inside-routing-problem/m-p/2886865#M157122</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2016-07-05T12:59:59Z</dc:date>
    </item>
  </channel>
</rss>

