<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sla from a specific IP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sla-from-a-specific-ip/m-p/2706915#M190673</link>
    <description>&lt;P&gt;Good morning everyone,&lt;/P&gt;&lt;P&gt;I'm having an issue with a cloud provider that will not allow traffic to be initiated from their end on a certain SA.I did the debug 1(27) and see my ASA reaching out and them essentially timing out. I've read about this and even TAC confirmed what I was seeing, so the only fix is to initiate a ping from the box itself as I'm only allowing one specific host to this cloud, as it runs through a hub and spoke VPN. The box in question is a linux box that I don't have access to, so if it were ever to stop then that SA would come down. I was thinking about doing an SLA from the far end ASA, but I you can't do a specific source SLA on an ASA, correct? I realize I could open it up to the entire range, but was wondering if anyone had any thoughts on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:06:18 GMT</pubDate>
    <dc:creator>Will Phinney</dc:creator>
    <dc:date>2019-03-12T06:06:18Z</dc:date>
    <item>
      <title>Sla from a specific IP</title>
      <link>https://community.cisco.com/t5/network-security/sla-from-a-specific-ip/m-p/2706915#M190673</link>
      <description>&lt;P&gt;Good morning everyone,&lt;/P&gt;&lt;P&gt;I'm having an issue with a cloud provider that will not allow traffic to be initiated from their end on a certain SA.I did the debug 1(27) and see my ASA reaching out and them essentially timing out. I've read about this and even TAC confirmed what I was seeing, so the only fix is to initiate a ping from the box itself as I'm only allowing one specific host to this cloud, as it runs through a hub and spoke VPN. The box in question is a linux box that I don't have access to, so if it were ever to stop then that SA would come down. I was thinking about doing an SLA from the far end ASA, but I you can't do a specific source SLA on an ASA, correct? I realize I could open it up to the entire range, but was wondering if anyone had any thoughts on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:06:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sla-from-a-specific-ip/m-p/2706915#M190673</guid>
      <dc:creator>Will Phinney</dc:creator>
      <dc:date>2019-03-12T06:06:18Z</dc:date>
    </item>
    <item>
      <title>Hi Will,I think as per the</title>
      <link>https://community.cisco.com/t5/network-security/sla-from-a-specific-ip/m-p/2706916#M190674</link>
      <description>&lt;P&gt;Hi Will,&lt;/P&gt;&lt;P&gt;I think as per the requirement , you want the traffic to be initiated from the ASA outside interface for the tunnel to stay up. I think if you configure the SLA in the Outside interface that should generate the necessary ICMP request to keep the tunnel UP and you can change destination as the VPN peer.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jun 2015 01:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sla-from-a-specific-ip/m-p/2706916#M190674</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-06-14T01:48:39Z</dc:date>
    </item>
    <item>
      <title>Right, but that's assuming I</title>
      <link>https://community.cisco.com/t5/network-security/sla-from-a-specific-ip/m-p/2706917#M190677</link>
      <description>&lt;P&gt;Right, but that's assuming I'm allowing all traffic from a certain segment. For example, if I'm only NAT'ing&amp;nbsp;a specific host, say 10.13.20.5 to 10.5.0.0, then I would have to open up to all of 10.13.20.x/24 as I don't believe there is a way to setup an SLA to source from just 10.13.20.5,correct?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2015 14:26:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sla-from-a-specific-ip/m-p/2706917#M190677</guid>
      <dc:creator>Will Phinney</dc:creator>
      <dc:date>2015-06-15T14:26:02Z</dc:date>
    </item>
  </channel>
</rss>

