<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Strange behaviour... Could in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-traceroute-issue/m-p/2676707#M190833</link>
    <description>&lt;P&gt;Strange behaviour... Could you, please, post the output of &lt;SPAN style="font-family:courier new,courier,monospace;"&gt;show route&lt;/SPAN&gt; command?&lt;/P&gt;</description>
    <pubDate>Mon, 08 Jun 2015 11:53:09 GMT</pubDate>
    <dc:creator>Boris Uskov</dc:creator>
    <dc:date>2015-06-08T11:53:09Z</dc:date>
    <item>
      <title>ASA Traceroute issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-traceroute-issue/m-p/2676704#M190830</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am newbie on ASA configuration. The network topology should be below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internet -- (Outside)&amp;nbsp;ASA 5520 (Inside) -- Router -- MPLS Connection&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case, there is a solarwind server at MPLS connection side and responsible to collecting syslog of ASA. However, now, ASA can't be connected to the server. I have doing traceroute from ASA and found the first hop is going to Internet. How can I fix the first hop back to the router side. Below is the ASA configuration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;================================================================================================================&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;&amp;nbsp;nameif outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;security-level 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address xx.xx.xx.xx 255.255.255.248&lt;/P&gt;&lt;P&gt;&amp;nbsp;ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;&amp;nbsp;nameif inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;security-level 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address 10.131.3.2 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.0.0.0 255.0.0.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 (Outside GW) 1&lt;/P&gt;&lt;P&gt;route inside 10.0.0.0 255.0.0.0 10.131.3.1 1&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-traceroute-issue/m-p/2676704#M190830</guid>
      <dc:creator>Kurt Lei</dc:creator>
      <dc:date>2019-03-12T06:04:20Z</dc:date>
    </item>
    <item>
      <title>Hello, What is the IP-address</title>
      <link>https://community.cisco.com/t5/network-security/asa-traceroute-issue/m-p/2676705#M190831</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the IP-address of&amp;nbsp;solarwind server? If it is not from 10.0.0.0/8 net, you need to add a static route:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;route inside x.x.x.x 255.255.255.255 y.y.y.y&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;where x.x.x.x - ip-address of&amp;nbsp;solarwind, y.y.y.y - ip-address of Router's interface, who is responsible for connection to MPLS-Cloud.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2015 10:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-traceroute-issue/m-p/2676705#M190831</guid>
      <dc:creator>Boris Uskov</dc:creator>
      <dc:date>2015-06-08T10:40:55Z</dc:date>
    </item>
    <item>
      <title>Hi Boris,The solarwind server</title>
      <link>https://community.cisco.com/t5/network-security/asa-traceroute-issue/m-p/2676706#M190832</link>
      <description>&lt;P&gt;Hi Boris,&lt;/P&gt;&lt;P&gt;The solarwind server is 10.130.8.248 and should belong to 10.0.0.0/8. And I wonder to it can't route to inside and going to Outside Interface.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2015 11:33:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-traceroute-issue/m-p/2676706#M190832</guid>
      <dc:creator>Kurt Lei</dc:creator>
      <dc:date>2015-06-08T11:33:00Z</dc:date>
    </item>
    <item>
      <title>Strange behaviour... Could</title>
      <link>https://community.cisco.com/t5/network-security/asa-traceroute-issue/m-p/2676707#M190833</link>
      <description>&lt;P&gt;Strange behaviour... Could you, please, post the output of &lt;SPAN style="font-family:courier new,courier,monospace;"&gt;show route&lt;/SPAN&gt; command?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2015 11:53:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-traceroute-issue/m-p/2676707#M190833</guid>
      <dc:creator>Boris Uskov</dc:creator>
      <dc:date>2015-06-08T11:53:09Z</dc:date>
    </item>
    <item>
      <title>Theoretically, NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-traceroute-issue/m-p/2676708#M190834</link>
      <description>&lt;P&gt;Theoretically, NAT-translations can influence the selection of exit interface. I'm not sure, that it'll help, but you can try&amp;nbsp;to remove nat-configurations and issue &lt;SPAN style="font-family:courier new,courier,monospace;"&gt;clear xlate&lt;/SPAN&gt; command. Attention! If it is production network, it could influence the packet handling. Don't do it in production environment.&lt;/P&gt;&lt;P&gt;Alternatively, you can try to add a nat exception for host 10.130.8.248. It'll be something like this:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;access-list inside_nat0_outbound extended permit ip host&amp;nbsp;10.130.8.248 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;access-list inside_nat0_outbound extended permit ip any host&amp;nbsp;10.130.8.248&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;clear xlate&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/route_overview.html"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/route_overview.html&lt;/A&gt;&lt;/P&gt;&lt;H2 class="p_H_Head1" style="font-size: 14.1680002212524px; color: rgb(51, 102, 102); font-weight: bold; font-family: Arial, Helvetica, sans-serif; margin: 14px 0em 7px -0.1in; line-height: normal;"&gt;&lt;SPAN style="color: black;"&gt;How Routing Behaves Within the Adaptive Security Appliance&lt;/SPAN&gt;&lt;/H2&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pB1_Body1" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.2360000610352px; margin: 1px 0em 6px; line-height: normal;"&gt;The ASA uses both routing table and XLATE tables for routing decisions. To handle destination IP translated traffic, that is, untranslated traffic, the ASA searches for existing XLATE, or static translation to select the egress interface. The selection process is as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H3 class="p_H_Head3" style="font-size: 12.8800001144409px; color: rgb(0, 0, 0); font-weight: bold; font-family: Arial, Helvetica, sans-serif; margin: 14px 0em 7px -0.1in; line-height: normal;"&gt;Egress Interface Selection Process&lt;/H3&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pNF_NumFirst" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.2360000610352px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.25in; text-indent: -0.25in; line-height: normal;"&gt;&lt;B&gt;1.&amp;nbsp;&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="10" /&gt;If destination IP translating XLATE already exists, the egress interface for the packet is determined from the XLATE table, but not from the routing table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pNN_NumNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.2360000610352px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.25in; text-indent: -0.25in; line-height: normal;"&gt;&lt;B&gt;2.&amp;nbsp;&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="10" /&gt;If destination IP translating XLATE does not exist, but a matching static translation exists, then the egress interface is determined from the static route and an XLATE is created, and the routing table is not used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pNN_NumNext" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.2360000610352px; margin-right: 0em; margin-bottom: 7px; margin-left: 0.25in; text-indent: -0.25in; line-height: normal;"&gt;&lt;B&gt;3.&amp;nbsp;&lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="10" /&gt;If destination IP translating XLATE does not exist and no matching static translation exists, the packet is not destination IP translated. The ASA processes this packet by looking up the route to select egress interface, then source IP translation is performed (if necessary).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pB2_Body2" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.2360000610352px; margin: 1px 0em 6px 0.25in; line-height: normal;"&gt;For regular dynamic outbound NAT, initial outgoing packets are routed using the route table and then creating the XLATE. Incoming return packets are forwarded using existing XLATE only. For static NAT, destination translated incoming packets are always forwarded using existing XLATE or static translation rules.&lt;/P&gt;&lt;P class="pB2_Body2" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.2360000610352px; margin: 1px 0em 6px 0.25in; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pB2_Body2" style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12.2360000610352px; margin: 1px 0em 6px 0.25in; line-height: normal;"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2015 12:35:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-traceroute-issue/m-p/2676708#M190834</guid>
      <dc:creator>Boris Uskov</dc:creator>
      <dc:date>2015-06-08T12:35:29Z</dc:date>
    </item>
    <item>
      <title>Yes, I finally got the show</title>
      <link>https://community.cisco.com/t5/network-security/asa-traceroute-issue/m-p/2676709#M190835</link>
      <description>&lt;P&gt;Yes, I finally got the show route from the customer. It's really strange, there is no static route on the configuration but there is an entry when show route.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;S &amp;nbsp; &amp;nbsp;10.130.0.0 255.255.0.0 [1/0] via (Outside GW), outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I have another issue is that some subnet should go to this Outside gateway. The criteria is that only the inside subnet (i.e. 10.131.3.0) will back to MPLS connection and should use below route.&amp;nbsp;&lt;/P&gt;&lt;P&gt;S &amp;nbsp; &amp;nbsp;10.0.0.0 255.0.0.0 [1/0] via 10.131.3.1, inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know there is no any policy routing in ASA 8.0, how can I achieve it ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2015 02:21:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-traceroute-issue/m-p/2676709#M190835</guid>
      <dc:creator>Kurt Lei</dc:creator>
      <dc:date>2015-06-09T02:21:46Z</dc:date>
    </item>
    <item>
      <title>Hello, Kurt.I'm afraid, there</title>
      <link>https://community.cisco.com/t5/network-security/asa-traceroute-issue/m-p/2676710#M190836</link>
      <description>&lt;P&gt;Hello, Kurt.&lt;/P&gt;&lt;P&gt;I'm afraid, there is no way to configure your task on ASA.&lt;/P&gt;&lt;P&gt;I believe, you have to change default gateway on devices from subnet 10.131.3.0/24 to&amp;nbsp;10.131.3.1 (Router) and implemet all routing logic&amp;nbsp;on the router.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2015 09:30:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-traceroute-issue/m-p/2676710#M190836</guid>
      <dc:creator>Boris Uskov</dc:creator>
      <dc:date>2015-06-09T09:30:38Z</dc:date>
    </item>
  </channel>
</rss>

