<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA inter vlan routing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-inter-vlan-routing/m-p/2642271#M196742</link>
    <description>&lt;P&gt;&lt;SPAN style="background-color: rgba(255, 255, 255, 0);"&gt;Hello&lt;BR /&gt;&lt;BR /&gt;Question, &amp;nbsp;I have an ASA 5505 with one vlan. I have created a DHCP superscope on our Microsoft server 192.168.1.0 192.168.3.254&lt;BR /&gt;&lt;BR /&gt;Clients get the right IP however Clients can not communicate between subnets they can ping out to 8.8.8.8 but not google.com&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;192.168,3.5 can not communicate with anything on 192.168.1.x&lt;BR /&gt;&lt;BR /&gt;No router between asa and clients all switches are cisco L2&lt;BR /&gt;&lt;BR /&gt;Anyway to overcome this ?&lt;BR /&gt;&lt;BR /&gt;Create vlan 2 with 192.168.3.0/24 on switches and asa ?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:33:40 GMT</pubDate>
    <dc:creator>galaga5656</dc:creator>
    <dc:date>2019-03-12T05:33:40Z</dc:date>
    <item>
      <title>ASA inter vlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-inter-vlan-routing/m-p/2642271#M196742</link>
      <description>Hello

Question,  I have an ASA 5505 with one vlan. I have created a DHCP superscope on our Microsoft server 192.168.1.0 192.168.3.254

Clients get the right IP however Clients can not communicate between subnets they can ping out to 8.8.8.8 but not google.com 

192.168,3.5 can not communicate with anything on 192.168.1.x

No router between asa and clients all switches are cisco L2

Anyway to overcome this ?

Create vlan 2 with 192.168.3.0/24 on switches and asa ?</description>
      <pubDate>Tue, 12 Mar 2019 05:33:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-inter-vlan-routing/m-p/2642271#M196742</guid>
      <dc:creator>galaga5656</dc:creator>
      <dc:date>2019-03-12T05:33:40Z</dc:date>
    </item>
    <item>
      <title>if they can ping by IP but</title>
      <link>https://community.cisco.com/t5/network-security/asa-inter-vlan-routing/m-p/2642272#M196743</link>
      <description>&lt;P&gt;if they can ping by IP but not by name, then the issue is DNS, not firewall. If the DNS translation request cannot get past the firewall, then it will fail. The fact that pinging by IP works shows that the ACL and NAT are setup correctly for ping at least. Now you just need to identify if the same areas are configured for dns resolution&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;RE: 192.168,3.5 can not communicate with anything on 192.168.1.x&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;This sounds like a netmask problem too. 255.255.252.0 yes? Your network actually has a bunch more IP's than you intended, I guess&lt;/P&gt;

&lt;PRE style="color: rgb(0, 0, 0); line-height: normal;"&gt;
&lt;FONT color="#000000"&gt;Address:   &lt;/FONT&gt;&lt;FONT color="#0000ff"&gt;192.168.1.0&lt;/FONT&gt;
&lt;FONT color="#000000"&gt;Netmask:   &lt;/FONT&gt;&lt;FONT color="#0000ff"&gt;255.255.252.0 = 22&lt;/FONT&gt;
&lt;FONT color="#000000"&gt;Wildcard:  &lt;/FONT&gt;&lt;FONT color="#0000ff"&gt;0.0.3.255&lt;/FONT&gt;
=&amp;gt;
&lt;FONT color="#000000"&gt;Network:   &lt;/FONT&gt;&lt;FONT color="#0000ff"&gt;192.168.0.0/22&lt;/FONT&gt;&lt;FONT color="#009900"&gt;
&lt;FONT color="#000000"&gt;Broadcast: &lt;/FONT&gt;&lt;FONT color="#0000ff"&gt;192.168.3.255        &lt;/FONT&gt;
&lt;FONT color="#000000"&gt;HostMin:   &lt;/FONT&gt;&lt;FONT color="#0000ff"&gt;192.168.0.1           &lt;/FONT&gt;
&lt;FONT color="#000000"&gt;HostMax:   &lt;/FONT&gt;&lt;FONT color="#0000ff"&gt;192.168.3.254         &lt;/FONT&gt;
&lt;FONT color="#000000"&gt;Hosts/Net: &lt;/FONT&gt;&lt;FONT color="#0000ff"&gt;1022&lt;/FONT&gt;&lt;/FONT&gt;&lt;/PRE&gt;

&lt;P&gt;Does everything have the correct netmask and gateway information? Can you post an IPconfig /all from a .3 workstation AND post the ASA's config please?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Feb 2015 13:56:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-inter-vlan-routing/m-p/2642272#M196743</guid>
      <dc:creator>cpgsystems</dc:creator>
      <dc:date>2015-02-27T13:56:53Z</dc:date>
    </item>
  </channel>
</rss>

