<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic routing is not configured.So in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/allow-routing-for-return-traffic-from-asa/m-p/2677163#M193791</link>
    <description>&lt;P&gt;routing is not configured.&lt;/P&gt;&lt;P&gt;So right now ASA interface connected to switch only allows sigle vlan.&lt;/P&gt;&lt;P&gt;To allow another vlan on the same interface so that routing is enabled should i config port on ASA&lt;/P&gt;&lt;P&gt;as multiple sub interfaces ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jul 2015 18:25:16 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2015-07-16T18:25:16Z</dc:date>
    <item>
      <title>Allow routing for  return traffic from ASA</title>
      <link>https://community.cisco.com/t5/network-security/allow-routing-for-return-traffic-from-asa/m-p/2677161#M193787</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to fix the routing issue in ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Layer 3 traffic&amp;nbsp; flow&lt;/P&gt;&lt;P&gt;PC-----L3 switch1------int x-------ASA--int y----Layer 3 switch2 --- server&lt;/P&gt;&lt;P&gt;Here traffic flow is allowed from PC to server.&lt;/P&gt;&lt;P&gt;But for return traffic from server to PC&amp;nbsp; via ASA&amp;nbsp; X interface the next hop to L3 switch 1 is not pingable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;L2 traffic flow&lt;/P&gt;&lt;P&gt;L3 switch&amp;nbsp;&amp;nbsp;1&amp;nbsp; ------trunk to&amp;nbsp;&amp;nbsp; switch3----------trunk to&amp;nbsp; switch4-----access vlan 510 ------x interface of ASA.&lt;/P&gt;&lt;P&gt;Switch4 port connected to ASA interface x is access port only carrying single vlan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need to know in order for ping to work from X interface of ASA to next hop address which is vlan 520 on L3 switch1 what can i do?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:16:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-routing-for-return-traffic-from-asa/m-p/2677161#M193787</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T06:16:24Z</dc:date>
    </item>
    <item>
      <title>Hi Mahesh, With necessary</title>
      <link>https://community.cisco.com/t5/network-security/allow-routing-for-return-traffic-from-asa/m-p/2677162#M193789</link>
      <description>&lt;P&gt;Hi Mahesh,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With necessary routing configured, try adding 'inspect icmp' on ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2015 09:23:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-routing-for-return-traffic-from-asa/m-p/2677162#M193789</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2015-07-16T09:23:22Z</dc:date>
    </item>
    <item>
      <title>routing is not configured.So</title>
      <link>https://community.cisco.com/t5/network-security/allow-routing-for-return-traffic-from-asa/m-p/2677163#M193791</link>
      <description>&lt;P&gt;routing is not configured.&lt;/P&gt;&lt;P&gt;So right now ASA interface connected to switch only allows sigle vlan.&lt;/P&gt;&lt;P&gt;To allow another vlan on the same interface so that routing is enabled should i config port on ASA&lt;/P&gt;&lt;P&gt;as multiple sub interfaces ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2015 18:25:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-routing-for-return-traffic-from-asa/m-p/2677163#M193791</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2015-07-16T18:25:16Z</dc:date>
    </item>
    <item>
      <title>You can configure</title>
      <link>https://community.cisco.com/t5/network-security/allow-routing-for-return-traffic-from-asa/m-p/2677164#M193794</link>
      <description>&lt;P&gt;You can configure subinterfaces. But IMO it will be better for you to use the layer 3 switch for your inter-vlan routing. Unless you need specific access&amp;nbsp;policies for each VLAN you have. Otherwise, just do your routing on the layer 3 switch. This will take some load off your ASA. You may also need to tune Same-Secutiry level traffic, etc.The ASA also behaves a bit funny when you use it as a client default gateway. So to keep you config simple, I would not do any inter-vlan routing on the ASA.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 06:04:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-routing-for-return-traffic-from-asa/m-p/2677164#M193794</guid>
      <dc:creator>Andre Neethling</dc:creator>
      <dc:date>2015-07-17T06:04:39Z</dc:date>
    </item>
    <item>
      <title> Hi Andre, How can i use</title>
      <link>https://community.cisco.com/t5/network-security/allow-routing-for-return-traffic-from-asa/m-p/2677165#M193798</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Andre,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can i use layer 3 switch for routing?&lt;/P&gt;&lt;P&gt;Can you please&amp;nbsp;explain &amp;nbsp;me with example what config i need to put on switch and ASA&lt;/P&gt;&lt;P&gt;for inter vlan routing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 19:47:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-routing-for-return-traffic-from-asa/m-p/2677165#M193798</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2015-07-17T19:47:06Z</dc:date>
    </item>
    <item>
      <title>you need to add the command</title>
      <link>https://community.cisco.com/t5/network-security/allow-routing-for-return-traffic-from-asa/m-p/2677166#M193800</link>
      <description>&lt;P&gt;you need to add the command &lt;STRONG&gt;ip routing &lt;/STRONG&gt;on the L3 switch. Then you will be able to add routing commmands such as the following:&lt;/P&gt;&lt;P&gt;ip route 1.2.3.0 255.255.255.0 11.11.11.1&lt;/P&gt;&lt;P&gt;just replace the 1.2.3.0 with the subnet you are trying to reach, 255.255.255.0 with the actual subnet of the network you are trying to reach, and replace 11.11.11.1 with the next hop IP toward the subnet you are trying to reach.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2015 07:18:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-routing-for-return-traffic-from-asa/m-p/2677166#M193800</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2015-07-18T07:18:25Z</dc:date>
    </item>
    <item>
      <title>Many thanks</title>
      <link>https://community.cisco.com/t5/network-security/allow-routing-for-return-traffic-from-asa/m-p/2677167#M193803</link>
      <description>&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jul 2015 18:21:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/allow-routing-for-return-traffic-from-asa/m-p/2677167#M193803</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2015-07-28T18:21:33Z</dc:date>
    </item>
  </channel>
</rss>

