<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PBR with tracking error in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pbr-with-tracking-error/m-p/2800913#M175202</link>
    <description>&lt;P&gt;I already upgraded my ASA version to 9.4 and now it working with PBR.&lt;/P&gt;
&lt;P&gt;But I'm having issues on setting up the sla monitor.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Test# sh track&lt;/P&gt;
&lt;P&gt;Track 1&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Response Time Reporter 1 reachability&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; Reachability is Up&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 276 changes, last change 00:03:02&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Latest operation return code: OK&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Latest RTT (millisecs) 1&lt;/P&gt;
&lt;P&gt;Track 2&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Response Time Reporter 2 reachability&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; Reachability is Down&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 1 change, last change 05:49:34&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Latest operation return code: Timeout&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sla monitor 1&lt;/P&gt;
&lt;P&gt;type echo protocol ipIcmpEcho 122.X.X.X interface outside&lt;/P&gt;
&lt;P&gt;frequency 10&lt;/P&gt;
&lt;P&gt;sla monitor schedule 1 life forever start-time now&lt;/P&gt;
&lt;P&gt;sla monitor 2&lt;/P&gt;
&lt;P&gt;type echo protocol ipIcmpEcho 121.X.X.X interface outside2&lt;/P&gt;
&lt;P&gt;frequency 10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From FW: ping test on both WAN&lt;/P&gt;
&lt;P&gt;T# ping 122.X.X.X&lt;/P&gt;
&lt;P&gt;!!!!!&lt;/P&gt;
&lt;P&gt;T# ping 121.X.X.X&lt;/P&gt;
&lt;P&gt;!!!!!&lt;/P&gt;
&lt;P&gt;all end point was able to ping.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:50:41 GMT</pubDate>
    <dc:creator>Lost &amp; Found</dc:creator>
    <dc:date>2019-03-12T06:50:41Z</dc:date>
    <item>
      <title>PBR with tracking error</title>
      <link>https://community.cisco.com/t5/network-security/pbr-with-tracking-error/m-p/2800913#M175202</link>
      <description>&lt;P&gt;I already upgraded my ASA version to 9.4 and now it working with PBR.&lt;/P&gt;
&lt;P&gt;But I'm having issues on setting up the sla monitor.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Test# sh track&lt;/P&gt;
&lt;P&gt;Track 1&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Response Time Reporter 1 reachability&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; Reachability is Up&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 276 changes, last change 00:03:02&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Latest operation return code: OK&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Latest RTT (millisecs) 1&lt;/P&gt;
&lt;P&gt;Track 2&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Response Time Reporter 2 reachability&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; Reachability is Down&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; 1 change, last change 05:49:34&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Latest operation return code: Timeout&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;sla monitor 1&lt;/P&gt;
&lt;P&gt;type echo protocol ipIcmpEcho 122.X.X.X interface outside&lt;/P&gt;
&lt;P&gt;frequency 10&lt;/P&gt;
&lt;P&gt;sla monitor schedule 1 life forever start-time now&lt;/P&gt;
&lt;P&gt;sla monitor 2&lt;/P&gt;
&lt;P&gt;type echo protocol ipIcmpEcho 121.X.X.X interface outside2&lt;/P&gt;
&lt;P&gt;frequency 10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From FW: ping test on both WAN&lt;/P&gt;
&lt;P&gt;T# ping 122.X.X.X&lt;/P&gt;
&lt;P&gt;!!!!!&lt;/P&gt;
&lt;P&gt;T# ping 121.X.X.X&lt;/P&gt;
&lt;P&gt;!!!!!&lt;/P&gt;
&lt;P&gt;all end point was able to ping.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:50:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-with-tracking-error/m-p/2800913#M175202</guid>
      <dc:creator>Lost &amp; Found</dc:creator>
      <dc:date>2019-03-12T06:50:41Z</dc:date>
    </item>
    <item>
      <title>I suspect what is happening</title>
      <link>https://community.cisco.com/t5/network-security/pbr-with-tracking-error/m-p/2800914#M175203</link>
      <description>&lt;P&gt;I suspect what is happening is the IP SLA is using the default route to ping the IPs and so the traffic is sourced from outside2 but it goes out and comes back in via the outside interface.&lt;/P&gt;
&lt;P&gt;You can use PBR for traffic generated by the device itself with IOS but it doesn't seem to be supported on the ASA or at least I can't find it.&lt;/P&gt;
&lt;P&gt;So have you tied your PBR confiiguration to the IP SLA ?&lt;/P&gt;
&lt;P&gt;If so try adding a host specific route to the ASA for the IP you are pinging on the outside2 interface ie.&lt;/P&gt;
&lt;P&gt;route (outside2) 121.x.x.x 255.255.255.255 &amp;lt;next hop IP&amp;gt;&lt;/P&gt;
&lt;P&gt;this should force the ping to go out of the right interface.&lt;/P&gt;
&lt;P&gt;Unless of course the IPs you are pinging are the actual next hop IPs in which case not sure what is happening.&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2015 16:55:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-with-tracking-error/m-p/2800914#M175203</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-11-06T16:55:57Z</dc:date>
    </item>
    <item>
      <title>Hi Jon,</title>
      <link>https://community.cisco.com/t5/network-security/pbr-with-tracking-error/m-p/2800915#M175204</link>
      <description>&lt;P&gt;Hi Jon,&lt;/P&gt;
&lt;P&gt;Thanks. Youre right. Because upon check traffic is routing on 122. &amp;nbsp;Anyway ill the new conf. Ill just give you the update.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Nov 2015 12:59:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-with-tracking-error/m-p/2800915#M175204</guid>
      <dc:creator>Lost &amp; Found</dc:creator>
      <dc:date>2015-11-07T12:59:43Z</dc:date>
    </item>
    <item>
      <title>Hi Jon,</title>
      <link>https://community.cisco.com/t5/network-security/pbr-with-tracking-error/m-p/2800916#M175205</link>
      <description>&lt;P&gt;Hi Jon,&lt;/P&gt;
&lt;P&gt;I forgot to edit the post. now It's working.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 12:42:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-with-tracking-error/m-p/2800916#M175205</guid>
      <dc:creator>Lost &amp; Found</dc:creator>
      <dc:date>2015-11-13T12:42:37Z</dc:date>
    </item>
    <item>
      <title>Sorry but can't see photo.</title>
      <link>https://community.cisco.com/t5/network-security/pbr-with-tracking-error/m-p/2800917#M175206</link>
      <description>&lt;P&gt;Sorry but can't see photo.&lt;/P&gt;
&lt;P&gt;Can you post a "sh route" from your ASA ?&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 12:42:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pbr-with-tracking-error/m-p/2800917#M175206</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-11-13T12:42:38Z</dc:date>
    </item>
  </channel>
</rss>

