<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traffic between two internal interface ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/traffic-between-two-internal-interface-asa/m-p/2573539#M205106</link>
    <description>&lt;P&gt;I have ASA 5512 configured like below:&lt;/P&gt;&lt;P&gt;g0/0 : outside ---&amp;gt; &amp;nbsp;security 0, connect to the internet via GW router, private IP /30, no NAT (NAT is occur on the GW router)&lt;/P&gt;&lt;P&gt;g0/1 : inside1 ---&amp;gt; security 100,&amp;nbsp;connect directly&amp;nbsp;to LAN 10.x.x.x&lt;/P&gt;&lt;P&gt;g0/2 : inside2 ----&amp;gt; security 100, connect to another router, lets call it router-X&amp;nbsp;using /30 private IP, and behind that router is another LAN in segment 192.168.x.x&lt;/P&gt;&lt;P&gt;I configured via ASDM and have enabled the option "Enable traffic between two or more&amp;nbsp;interfaces which are configured with the same security level"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Routing in ASA:&lt;/P&gt;&lt;P&gt;outside, 0.0.0.0 0.0.0.0 (GW router IP)&lt;/P&gt;&lt;P&gt;inside2, 192.168.0.0 255.255.0.0 (router-X IP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything works as it should, I can go either from inside1/inside2 to the internet, and I can also access between segments 10.x.x.x &amp;lt;-&amp;gt;&amp;nbsp;192.168.x.x under normal condition&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But there is this one accident where the internet connection is down (on the provider side) so I cannot access the internet, but at the same time I also cannot access the other inside interface ( I cannot access 192.168.x.x from 10.x.x.x). this is so weird to me, the inter-segment connection&amp;nbsp;should still be working even without the internet isn't it?&lt;/P&gt;&lt;P&gt;And as soon as the internet connection is up and active again, the inter-segment connection is also comes up again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What did I do wrong?&lt;/P&gt;&lt;P&gt;PLease help me, this is an existing and active production network&amp;nbsp;in my office so i cant just do a trial-and-error here&lt;/P&gt;&lt;P&gt;Any help will be highly appreciated... thanks!&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:12:59 GMT</pubDate>
    <dc:creator>randms2610</dc:creator>
    <dc:date>2019-03-12T05:12:59Z</dc:date>
    <item>
      <title>Traffic between two internal interface ASA</title>
      <link>https://community.cisco.com/t5/network-security/traffic-between-two-internal-interface-asa/m-p/2573539#M205106</link>
      <description>&lt;P&gt;I have ASA 5512 configured like below:&lt;/P&gt;&lt;P&gt;g0/0 : outside ---&amp;gt; &amp;nbsp;security 0, connect to the internet via GW router, private IP /30, no NAT (NAT is occur on the GW router)&lt;/P&gt;&lt;P&gt;g0/1 : inside1 ---&amp;gt; security 100,&amp;nbsp;connect directly&amp;nbsp;to LAN 10.x.x.x&lt;/P&gt;&lt;P&gt;g0/2 : inside2 ----&amp;gt; security 100, connect to another router, lets call it router-X&amp;nbsp;using /30 private IP, and behind that router is another LAN in segment 192.168.x.x&lt;/P&gt;&lt;P&gt;I configured via ASDM and have enabled the option "Enable traffic between two or more&amp;nbsp;interfaces which are configured with the same security level"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Routing in ASA:&lt;/P&gt;&lt;P&gt;outside, 0.0.0.0 0.0.0.0 (GW router IP)&lt;/P&gt;&lt;P&gt;inside2, 192.168.0.0 255.255.0.0 (router-X IP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Everything works as it should, I can go either from inside1/inside2 to the internet, and I can also access between segments 10.x.x.x &amp;lt;-&amp;gt;&amp;nbsp;192.168.x.x under normal condition&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But there is this one accident where the internet connection is down (on the provider side) so I cannot access the internet, but at the same time I also cannot access the other inside interface ( I cannot access 192.168.x.x from 10.x.x.x). this is so weird to me, the inter-segment connection&amp;nbsp;should still be working even without the internet isn't it?&lt;/P&gt;&lt;P&gt;And as soon as the internet connection is up and active again, the inter-segment connection is also comes up again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What did I do wrong?&lt;/P&gt;&lt;P&gt;PLease help me, this is an existing and active production network&amp;nbsp;in my office so i cant just do a trial-and-error here&lt;/P&gt;&lt;P&gt;Any help will be highly appreciated... thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:12:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-between-two-internal-interface-asa/m-p/2573539#M205106</guid>
      <dc:creator>randms2610</dc:creator>
      <dc:date>2019-03-12T05:12:59Z</dc:date>
    </item>
    <item>
      <title>Hi randms2610,That is weird !</title>
      <link>https://community.cisco.com/t5/network-security/traffic-between-two-internal-interface-asa/m-p/2573540#M205107</link>
      <description>&lt;P&gt;Hi &lt;SPAN class="fullname" itemprop="author"&gt;&lt;A class="username" href="https://supportforums.cisco.com/users/randms2610" title="View user profile."&gt;randms2610,&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="fullname" itemprop="author"&gt;That is weird ! i can't think of a reason unless we know how routing for both segments is working on the router x.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="fullname" itemprop="author"&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="fullname" itemprop="author"&gt;Murali&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2014 14:03:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-between-two-internal-interface-asa/m-p/2573540#M205107</guid>
      <dc:creator>Murali</dc:creator>
      <dc:date>2014-12-12T14:03:51Z</dc:date>
    </item>
    <item>
      <title>Hello Murali,there's nothing</title>
      <link>https://community.cisco.com/t5/network-security/traffic-between-two-internal-interface-asa/m-p/2573541#M205108</link>
      <description>&lt;P&gt;Hello Murali,&lt;/P&gt;&lt;P&gt;there's nothing fancy in router X routing, only static route&lt;/P&gt;&lt;P&gt;- ip route 0.0.0.0 0.0.0.0 (ASA g0/2 IP)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this problem has occur again today, and this time all the hosts are showing destination host unreachable message from their own IP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Dec 2014 15:45:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traffic-between-two-internal-interface-asa/m-p/2573541#M205108</guid>
      <dc:creator>randms2610</dc:creator>
      <dc:date>2014-12-12T15:45:15Z</dc:date>
    </item>
  </channel>
</rss>

