<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi there, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-communication-between-subinterfaces/m-p/2807697#M175137</link>
    <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;Please check if vlan 501 and vlan 503 is allowed on trunk ports connected to switch(ports which are part of port channel. They should be trunk on switch).&lt;/P&gt;
&lt;P&gt;Also please try below packet tracer :&lt;/P&gt;
&lt;P&gt;packet-tracer input Li tcp &amp;lt;li side ip&amp;gt; 12345 &amp;lt;oob side ip&amp;gt; 12345 det&lt;/P&gt;
&lt;P&gt;packet tracer input oob tcp &amp;lt;&lt;SPAN&gt;&amp;lt;oob side ip&amp;gt; 23451 &amp;lt;li side ip&amp;gt; 23453 det&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Check if traffic is allowed in these packet-tracer. If not then check the reason why its drop and troubleshoot. If it doesn't work, please share the output here.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
    <pubDate>Mon, 09 Nov 2015 13:10:03 GMT</pubDate>
    <dc:creator>Akshay Rastogi</dc:creator>
    <dc:date>2015-11-09T13:10:03Z</dc:date>
    <item>
      <title>ASA communication between subinterfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa-communication-between-subinterfaces/m-p/2807696#M175135</link>
      <description>&lt;P&gt;Hi everyone&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I've some question about asa5555, it can't communicate between subinterfaces (vlan 501(iLo) and 503(OOB)). I've config nat(OOB,iLo) static any any already but it doesn't work. Please guide me, show running config are below&lt;/P&gt;
&lt;P&gt;PPCIASA801# sh run&lt;BR /&gt;: Saved&lt;BR /&gt;: &lt;BR /&gt;: Serial Number: FCH19277H57&lt;BR /&gt;: Hardware:&amp;nbsp;&amp;nbsp; ASA5555, 16384 MB RAM, CPU Lynnfield 2792 MHz, 1 CPU (8 cores)&lt;BR /&gt;:&lt;BR /&gt;ASA Version 9.2(2)4 &lt;BR /&gt;!&lt;BR /&gt;hostname PPCIASA801&lt;BR /&gt;enable password uetIHtSiMvqRuhlL encrypted&lt;BR /&gt;names&lt;BR /&gt;ip local pool VPN_Pool 10.206.38.1-10.206.38.254 mask 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;&amp;nbsp;nameif LAN-Office&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.5.4.38 255.255.255.248 &lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;&amp;nbsp;channel-group 1 mode active&lt;BR /&gt;&amp;nbsp;no nameif&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3&lt;BR /&gt;&amp;nbsp;channel-group 1 mode active&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/4&lt;BR /&gt;&amp;nbsp;nameif WAN-CDN&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.5.97.81 255.255.255.248 standby 10.5.97.82 &lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/5&lt;BR /&gt;&amp;nbsp;nameif Telecom-OAM&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.216.200.38 255.255.255.248 standby 10.216.200.37 &lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/6&lt;BR /&gt;&amp;nbsp;nameif BE&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.206.33.254 255.255.255.0 standby 10.206.33.253 &lt;BR /&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;interface GigabitEthernet0/7&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;&amp;nbsp;management-only&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Port-channel1&lt;BR /&gt;&amp;nbsp;lacp max-bundle 8&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;&lt;STRONG&gt;interface Port-channel1.501&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;vlan 501&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;nameif iLo&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;security-level 100&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;ip address 10.206.36.1 255.255.255.224&lt;/STRONG&gt; &lt;BR /&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;interface Port-channel1.502&lt;BR /&gt;&amp;nbsp;vlan 502&lt;BR /&gt;&amp;nbsp;nameif iSCSI&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.206.36.33 255.255.255.224 &lt;BR /&gt;!&lt;BR /&gt;&lt;STRONG&gt;interface Port-channel1.503&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;vlan 503&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;nameif OOB&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;security-level 100&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;ip address 10.206.36.65 255.255.255.192&lt;/STRONG&gt; &lt;BR /&gt;!&lt;BR /&gt;interface Port-channel1.505&lt;BR /&gt;&amp;nbsp;vlan 505&lt;BR /&gt;&amp;nbsp;nameif CDN-OOB&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.206.36.129 255.255.255.224 standby 10.206.36.130 &lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa922-4-smp-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone BKK 7&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network NETWORK_OBJ_10.206.37.0_24&lt;BR /&gt;&amp;nbsp;subnet 10.206.37.0 255.255.255.0&lt;BR /&gt;object network PPCIMGSTRESW801&lt;BR /&gt;&amp;nbsp;host 10.206.36.126&lt;BR /&gt;object network NTP&lt;BR /&gt;&amp;nbsp;host 10.15.248.1&lt;BR /&gt;object service NTPport&lt;BR /&gt;&amp;nbsp;service udp source eq ntp destination eq ntp &lt;BR /&gt;object network LAN&lt;BR /&gt;&amp;nbsp;host 10.5.4.36&lt;BR /&gt;object network Nigios&lt;BR /&gt;&amp;nbsp;host 10.217.242.98&lt;BR /&gt;object network Alarm&lt;BR /&gt;&amp;nbsp;host 10.216.200.36&lt;BR /&gt;object network SSL-VPN&lt;BR /&gt;&amp;nbsp;subnet 10.217.0.0 255.255.0.0&lt;BR /&gt;object network NETWORK_OBJ_10.206.36.64_26&lt;BR /&gt;&amp;nbsp;subnet 10.206.36.64 255.255.255.192&lt;BR /&gt;object network Active&lt;BR /&gt;&amp;nbsp;host 10.235.4.180&lt;BR /&gt;object network Backup&lt;BR /&gt;&amp;nbsp;host 10.235.6.180&lt;BR /&gt;object network OOB-network&lt;BR /&gt;&amp;nbsp;subnet 10.206.36.64 255.255.255.192&lt;BR /&gt;object network iLo-network&lt;BR /&gt;&amp;nbsp;subnet 10.206.36.0 255.255.255.224&lt;BR /&gt;object network Nat-Cas&lt;BR /&gt;&amp;nbsp;host 10.206.36.61&lt;BR /&gt;object network CAS&lt;BR /&gt;&amp;nbsp;host 10.206.36.126&lt;BR /&gt;object-group network CAS-Terminal&lt;BR /&gt;&amp;nbsp;network-object host 10.217.200.134&lt;BR /&gt;&amp;nbsp;network-object host 10.235.4.180&lt;BR /&gt;&amp;nbsp;network-object host 10.235.6.180&lt;BR /&gt;object-group network PCI-DSS&lt;BR /&gt;&amp;nbsp;network-object object OOB-network&lt;BR /&gt;&amp;nbsp;network-object object iLo-network&lt;BR /&gt;access-list iSCSI_access_in extended permit ip any any &lt;BR /&gt;access-list global_access extended permit ip any any &lt;BR /&gt;access-list OOB_access_in extended permit ip any any &lt;BR /&gt;access-list LAN-Office_access_in extended permit ip any any &lt;BR /&gt;access-list iLo_access_in extended permit ip any any &lt;BR /&gt;access-list inside standard permit 10.206.36.0 255.255.255.224 &lt;BR /&gt;access-list inside standard permit 10.206.36.32 255.255.255.224 &lt;BR /&gt;access-list inside standard permit 10.5.4.32 255.255.255.248 &lt;BR /&gt;access-list inside standard permit 10.206.36.64 255.255.255.192 &lt;BR /&gt;access-list inside standard permit 10.206.36.128 255.255.255.224 &lt;BR /&gt;access-list inside standard permit 10.206.37.0 255.255.255.0 &lt;BR /&gt;access-list Telecom-OAM_access_in extended permit ip any any &lt;BR /&gt;access-list Telecom-OAM_cryptomap extended permit ip object-group PCI-DSS object-group CAS-Terminal &lt;BR /&gt;access-list CDN-OOB_access_in extended permit ip any any &lt;BR /&gt;access-list WAN-CDN_access_in extended permit ip any any &lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu LAN-Office 1500&lt;BR /&gt;mtu iLo 1500&lt;BR /&gt;mtu iSCSI 1500&lt;BR /&gt;mtu OOB 1500&lt;BR /&gt;mtu WAN-CDN 1500&lt;BR /&gt;mtu BE 1500&lt;BR /&gt;mtu Telecom-OAM 1500&lt;BR /&gt;mtu CDN-OOB 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;icmp permit any LAN-Office&lt;BR /&gt;icmp permit any iLo&lt;BR /&gt;icmp permit any iSCSI&lt;BR /&gt;icmp permit any OOB&lt;BR /&gt;icmp permit any WAN-CDN&lt;BR /&gt;icmp permit any BE&lt;BR /&gt;icmp permit any Telecom-OAM&lt;BR /&gt;icmp permit any CDN-OOB&lt;BR /&gt;asdm image disk0:/asdm-751.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;nat (Telecom-OAM,OOB) source static any any no-proxy-arp&lt;BR /&gt;nat (OOB,Telecom-OAM) source static any any no-proxy-arp&lt;BR /&gt;nat (Telecom-OAM,iLo) source static any any no-proxy-arp&lt;BR /&gt;nat (iLo,Telecom-OAM) source static any any no-proxy-arp&lt;BR /&gt;nat (OOB,CDN-OOB) source static any any no-proxy-arp&lt;BR /&gt;nat (CDN-OOB,OOB) source static any any no-proxy-arp&lt;BR /&gt;nat (WAN-CDN,CDN-OOB) source static any any no-proxy-arp&lt;BR /&gt;nat (CDN-OOB,WAN-CDN) source static any any no-proxy-arp&lt;BR /&gt;&lt;STRONG&gt;nat (OOB,iLo) source static any any no-proxy-arp&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;nat (iLo,OOB) source static any any no-proxy-arp&lt;/STRONG&gt;&lt;BR /&gt;access-group LAN-Office_access_in in interface LAN-Office&lt;BR /&gt;access-group iLo_access_in in interface iLo&lt;BR /&gt;access-group iSCSI_access_in in interface iSCSI&lt;BR /&gt;access-group OOB_access_in in interface OOB&lt;BR /&gt;access-group WAN-CDN_access_in in interface WAN-CDN&lt;BR /&gt;access-group Telecom-OAM_access_in in interface Telecom-OAM&lt;BR /&gt;access-group CDN-OOB_access_in in interface CDN-OOB&lt;BR /&gt;access-group global_access global&lt;BR /&gt;route LAN-Office 0.0.0.0 0.0.0.0 10.5.4.33 1&lt;BR /&gt;route WAN-CDN 10.5.0.0 255.255.0.0 10.5.97.86 1&lt;BR /&gt;route Telecom-OAM 10.217.0.0 255.255.0.0 10.216.200.33 1&lt;BR /&gt;route Telecom-OAM 10.235.4.0 255.255.255.0 10.216.200.33 1&lt;BR /&gt;route BE 10.251.53.25 255.255.255.255 10.206.33.1 1&lt;BR /&gt;route BE 10.251.54.25 255.255.255.255 10.206.33.1 1&lt;BR /&gt;route LAN-Office 172.0.0.0 255.0.0.0 10.5.4.33 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;aaa-server ACS-RSA-AD protocol radius&lt;BR /&gt;aaa-server ACS-RSA-AD (BE) host 10.251.54.25&lt;BR /&gt;&amp;nbsp;authentication-port 1812&lt;BR /&gt;&amp;nbsp;accounting-port 1813&lt;BR /&gt;aaa-server ACS-RSA-AD (BE) host 10.251.53.25&lt;BR /&gt;&amp;nbsp;authentication-port 1812&lt;BR /&gt;&amp;nbsp;accounting-port 1813&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;aaa authentication telnet console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 0.0.0.0 0.0.0.0 LAN-Office&lt;BR /&gt;http 0.0.0.0 0.0.0.0 OOB&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS esp-aes esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS esp-aes esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS esp-aes-192 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS esp-aes-192 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS esp-aes-256 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS esp-aes-256 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS esp-3des esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS esp-3des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS esp-des esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS esp-des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal 3DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption 3des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES192&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-192&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES256&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-256&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES&lt;BR /&gt;crypto map LAN-Office_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map LAN-Office_map interface LAN-Office&lt;BR /&gt;crypto map Telecom-OAM_map 1 match address Telecom-OAM_cryptomap&lt;BR /&gt;crypto map Telecom-OAM_map 1 set peer 10.217.200.14 &lt;BR /&gt;crypto map Telecom-OAM_map 1 set ikev1 transform-set ESP-3DES-SHA&lt;BR /&gt;crypto map Telecom-OAM_map interface Telecom-OAM&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint0&lt;BR /&gt;&amp;nbsp;enrollment self&lt;BR /&gt;&amp;nbsp;subject-name CN=PPCIASA801&lt;BR /&gt;&amp;nbsp;proxy-ldc-issuer&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint0&lt;BR /&gt;&amp;nbsp;certificate c326d155&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3082023c 308201a5 a0030201 020204c3 26d15530 0d06092a 864886f7 0d010105 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 05003030 31133011 06035504 03130a50 50434941 53413830 31311930 1706092a &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 864886f7 0d010902 160a5050 43494153 41383031 301e170d 31353038 31373031 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30353234 5a170d32 35303831 34303130 3532345a 30303113 30110603 55040313 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0a505043 49415341 38303131 19301706 092a8648 86f70d01 0902160a 50504349 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 41534138 30313081 9f300d06 092a8648 86f70d01 01010500 03818d00 30818902 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 818100c4 cd22e294 d5b6cf4a e3a322f9 e3dd5b12 1075542b e4efc9a7 d2af972e &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 45dc0eb5 ffecc0ff 6d7fdde4 5816b750 8d696ef7 1d3286fb 7c222e0d 32a037f7 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; f20ca92d 145ce815 78f35c3c d6b10478 e95fc236 7f1e6bb7 21049ff1 a8a40c19 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; a2b035fc 3cf3f877 5adf5baf dad05351 33981687 f11fc129 e8221ca3 309ce78a &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 026d9902 03010001 a3633061 300f0603 551d1301 01ff0405 30030101 ff300e06 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 03551d0f 0101ff04 04030201 86301f06 03551d23 04183016 80149c84 a44dd0c6 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 21d002fa ec6e5e76 1e2adb33 77a5301d 0603551d 0e041604 149c84a4 4dd0c621 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; d002faec 6e5e761e 2adb3377 a5300d06 092a8648 86f70d01 01050500 03818100 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7d4e271a afa5f593 92df2f6b eff02a6f 8f8f0fd0 e2626495 4aa4612a 6fe7a906 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9fb7ddad 0be1ba34 3bde93d3 b354b886 62b3f174 bcc7636b 6ba7aa48 dcae38c1 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ffee264e 17149f90 5de304e8 f2d75aaa a50f06c4 6cab1792 b7d39a6f aa0e637b &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; f3df482c 2f5023b7 ed43ea21 e5d8f399 96659051 cc8c3d48 8347d631 3eced959&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ikev2 policy 1&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 10&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 20&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 30&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 40&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 enable LAN-Office client-services port 443&lt;BR /&gt;crypto ikev2 enable Telecom-OAM&lt;BR /&gt;crypto ikev2 remote-access trustpoint ASDM_TrustPoint0&lt;BR /&gt;crypto ikev1 enable LAN-Office&lt;BR /&gt;crypto ikev1 enable Telecom-OAM&lt;BR /&gt;crypto ikev1 policy 10&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 20&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 30&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 40&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 50&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 60&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 70&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 80&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 90&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 100&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 110&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 120&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 130&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 140&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 150&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;telnet 0.0.0.0 0.0.0.0 LAN-Office&lt;BR /&gt;telnet 0.0.0.0 0.0.0.0 OOB&lt;BR /&gt;telnet timeout 30&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 LAN-Office&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 OOB&lt;BR /&gt;ssh timeout 30&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;BR /&gt;no vpn-addr-assign dhcp&lt;BR /&gt;!&lt;BR /&gt;tls-proxy maximum-session 1000&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;ntp server 10.15.248.1 source LAN-Office&lt;BR /&gt;ssl encryption rc4-sha1 aes128-sha1 aes256-sha1 3des-sha1&lt;BR /&gt;ssl trust-point ASDM_TrustPoint0 LAN-Office&lt;BR /&gt;webvpn&lt;BR /&gt;&amp;nbsp;enable LAN-Office&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-win-4.1.04011-k9.pkg 1&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-macosx-i386-2.5.2014-k9.pkg 2&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-win-2.5.2014-k9.pkg 3&lt;BR /&gt;&amp;nbsp;anyconnect profiles LANOFFICE_client_profile disk0:/LANOFFICE_client_profile.xml&lt;BR /&gt;&amp;nbsp;anyconnect enable&lt;BR /&gt;&amp;nbsp;tunnel-group-list enable&lt;BR /&gt;group-policy DfltGrpPolicy attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 ikev2 l2tp-ipsec ssl-client ssl-clientless&lt;BR /&gt;group-policy GroupPolicy_LANOFFICE internal&lt;BR /&gt;group-policy GroupPolicy_LANOFFICE attributes&lt;BR /&gt;&amp;nbsp;wins-server none&lt;BR /&gt;&amp;nbsp;dns-server none&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 ikev2 ssl-client ssl-clientless&lt;BR /&gt;&amp;nbsp;password-storage enable&lt;BR /&gt;&amp;nbsp;ip-comp enable&lt;BR /&gt;&amp;nbsp;pfs enable&lt;BR /&gt;&amp;nbsp;ipsec-udp enable&lt;BR /&gt;&amp;nbsp;ipsec-udp-port 10000&lt;BR /&gt;&amp;nbsp;split-tunnel-policy tunnelspecified&lt;BR /&gt;&amp;nbsp;split-tunnel-network-list value inside&lt;BR /&gt;&amp;nbsp;default-domain none&lt;BR /&gt;&amp;nbsp;client-bypass-protocol enable&lt;BR /&gt;&amp;nbsp;webvpn&lt;BR /&gt;&amp;nbsp; anyconnect profiles value LANOFFICE_client_profile type user&lt;BR /&gt;&amp;nbsp; anyconnect ssl df-bit-ignore enable&lt;BR /&gt;group-policy GroupPolicy_10.217.200.14 internal&lt;BR /&gt;group-policy GroupPolicy_10.217.200.14 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 &lt;BR /&gt;username pareeya password F7dtVus2GTHMhm0A encrypted privilege 15&lt;BR /&gt;username passakj7 password 39Kg5YajS30zqIK5 encrypted privilege 15&lt;BR /&gt;username pareeyp7 password MV45Bqo4DOiP92mZ encrypted privilege 15&lt;BR /&gt;username wutthiks password jCCPsXUkl86IYeV8 encrypted privilege 15&lt;BR /&gt;username sarunyak password R90pUvmo4lMQoGm6 encrypted privilege 15&lt;BR /&gt;username sarawuti password odS/BHaPrbnEUcY9 encrypted privilege 15&lt;BR /&gt;username barasupport2 password vVgx5fGsrKNi19hk encrypted privilege 15&lt;BR /&gt;username barasupport1 password vVgx5fGsrKNi19hk encrypted privilege 15&lt;BR /&gt;username arnondhc password GtkSN5kul7YoM1Ru encrypted privilege 15&lt;BR /&gt;username jiraponl password levnSq4nvIHDrJve encrypted privilege 15&lt;BR /&gt;username aekkana7 password AEHowVhDc2vmdPWu encrypted privilege 15&lt;BR /&gt;username atasitn7 password aw.sjzkwsqAgMGVE encrypted privilege 15&lt;BR /&gt;username tanatatp password bTy2rIo7kWwpgKgM encrypted privilege 15&lt;BR /&gt;username surachta password QdjcnY299cJF1mYB encrypted privilege 15&lt;BR /&gt;username sutinunp password QOGC/a1o2G6hhRz0 encrypted privilege 15&lt;BR /&gt;username sujitrl7 password yQ5quuq2LMKJemve encrypted privilege 15&lt;BR /&gt;username vasarucr password ECSEkjTxOu8KXooU encrypted privilege 15&lt;BR /&gt;username phatths7 password ywSj/mOFJGNNqD9H encrypted privilege 15&lt;BR /&gt;username harutais password 3765CYz1zxqeOBHr encrypted privilege 15&lt;BR /&gt;username kanoktiy password VjXymcmvHAhXxiyW encrypted privilege 15&lt;BR /&gt;username mfec5 password WmXaFl9dLue2Yc2d encrypted privilege 15&lt;BR /&gt;username mfec4 password WmXaFl9dLue2Yc2d encrypted privilege 15&lt;BR /&gt;username nuttakou password XpHrpeeEcZUcyL/m encrypted privilege 15&lt;BR /&gt;username mfec1 password WmXaFl9dLue2Yc2d encrypted privilege 15&lt;BR /&gt;username chaio114 password O7IVmcp3aIxOsL9v encrypted privilege 15&lt;BR /&gt;username mfec password WmXaFl9dLue2Yc2d encrypted privilege 15&lt;BR /&gt;username mfec3 password WmXaFl9dLue2Yc2d encrypted privilege 15&lt;BR /&gt;username mfec2 password WmXaFl9dLue2Yc2d encrypted privilege 15&lt;BR /&gt;username thitiso7 password lX3P1WyfKv9PoFsB encrypted privilege 15&lt;BR /&gt;username jumpb114 password cvTEONQEhr.yp.1v encrypted privilege 15&lt;BR /&gt;tunnel-group LANOFFICE type remote-access&lt;BR /&gt;tunnel-group LANOFFICE general-attributes&lt;BR /&gt;&amp;nbsp;address-pool (LAN-Office) VPN_Pool&lt;BR /&gt;&amp;nbsp;address-pool VPN_Pool&lt;BR /&gt;&amp;nbsp;authentication-server-group (LAN-Office) LOCAL&lt;BR /&gt;&amp;nbsp;authorization-server-group LOCAL&lt;BR /&gt;&amp;nbsp;authorization-server-group (LAN-Office) LOCAL&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_LANOFFICE&lt;BR /&gt;tunnel-group LANOFFICE webvpn-attributes&lt;BR /&gt;&amp;nbsp;group-alias LANOFFICE enable&lt;BR /&gt;&amp;nbsp;group-alias PPCIASA801 disable&lt;BR /&gt;tunnel-group LANOFFICE ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;&amp;nbsp;ikev1 trust-point ASDM_TrustPoint0&lt;BR /&gt;tunnel-group 10.217.200.14 type ipsec-l2l&lt;BR /&gt;tunnel-group 10.217.200.14 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_10.217.200.14&lt;BR /&gt;tunnel-group 10.217.200.14 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;&amp;nbsp;ikev2 remote-authentication pre-shared-key *****&lt;BR /&gt;&amp;nbsp;ikev2 local-authentication pre-shared-key *****&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;&amp;nbsp; inspect ip-options &lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;!&lt;BR /&gt;jumbo-frame reservation&lt;BR /&gt;!&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;Cryptochecksum:893204b323e3bbf728f506730cc1ffc7&lt;BR /&gt;: end&lt;BR /&gt;PPCIASA801#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;PPCIASA801# &lt;BR /&gt;PPCIASA801#&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:50:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-communication-between-subinterfaces/m-p/2807696#M175135</guid>
      <dc:creator>Kool1sttt</dc:creator>
      <dc:date>2019-03-12T06:50:56Z</dc:date>
    </item>
    <item>
      <title>Hi there,</title>
      <link>https://community.cisco.com/t5/network-security/asa-communication-between-subinterfaces/m-p/2807697#M175137</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;Please check if vlan 501 and vlan 503 is allowed on trunk ports connected to switch(ports which are part of port channel. They should be trunk on switch).&lt;/P&gt;
&lt;P&gt;Also please try below packet tracer :&lt;/P&gt;
&lt;P&gt;packet-tracer input Li tcp &amp;lt;li side ip&amp;gt; 12345 &amp;lt;oob side ip&amp;gt; 12345 det&lt;/P&gt;
&lt;P&gt;packet tracer input oob tcp &amp;lt;&lt;SPAN&gt;&amp;lt;oob side ip&amp;gt; 23451 &amp;lt;li side ip&amp;gt; 23453 det&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Check if traffic is allowed in these packet-tracer. If not then check the reason why its drop and troubleshoot. If it doesn't work, please share the output here.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 13:10:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-communication-between-subinterfaces/m-p/2807697#M175137</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-09T13:10:03Z</dc:date>
    </item>
    <item>
      <title>Hi Akshay</title>
      <link>https://community.cisco.com/t5/network-security/asa-communication-between-subinterfaces/m-p/2807698#M175139</link>
      <description>&lt;P&gt;Hi Akshay&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Thanks for your reply, i found mistake config already. Because i use nat() any any, packets nat to first nat and not go to the nat rule that i want.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 06:35:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-communication-between-subinterfaces/m-p/2807698#M175139</guid>
      <dc:creator>Kool1sttt</dc:creator>
      <dc:date>2015-11-10T06:35:54Z</dc:date>
    </item>
  </channel>
</rss>

