<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA No valid adjacency in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-no-valid-adjacency/m-p/2452018#M269191</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jon/ Marvin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the response. I will change the configuration to match&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Feb 2014 18:53:13 GMT</pubDate>
    <dc:creator>craig bache</dc:creator>
    <dc:date>2014-02-21T18:53:13Z</dc:date>
    <item>
      <title>ASA No valid adjacency</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-valid-adjacency/m-p/2452015#M269180</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully some one can help? I have a setup of wireless clients that are not able to connect to the internet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see packets on both the Wireless-DMZ and outside interfaces, but I can see from the logging the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 21 2014 18:06:03: %ASA-7-609001: Built local-host WIRELESS-DMZ:192.168.87.210&lt;/P&gt;&lt;P&gt;Feb 21 2014 18:06:03: %ASA-6-305011: Built dynamic UDP translation from WIRELESS-DMZ:192.168.87.210/56197 to OUTSIDE:x.x.x.x/53547&lt;/P&gt;&lt;P&gt;Feb 21 2014 18:06:03: %ASA-6-302015: Built outbound UDP connection 21496269 for OUTSIDE:8.8.4.4/53 (8.8.4.4/53) to WIRELESS-DMZ:192.168.87.210/56197 (x.x.x.x/53547)&lt;/P&gt;&lt;P&gt;Feb 21 2014 18:06:03: %ASA-6-110003: Routing failed to locate next hop for UDP from OUTSIDE:8.8.4.4/53 to WIRELESS-DMZ:192.168.87.210/56197&lt;/P&gt;&lt;P&gt;Feb 21 2014 18:06:03: %ASA-6-302016: Teardown UDP connection 21496269 for OUTSIDE:8.8.4.4/53 to WIRELESS-DMZ:192.168.87.210/56197 duration 0:00:00 bytes 210&lt;/P&gt;&lt;P&gt;NHSE-SW-ASA01/act#&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Feb 21 2014 18:06:03: %ASA-7-609001: Built local-host WIRELESS-DMZ:192.168.87.210&lt;BR /&gt;Feb 21 2014 18:06:03: %ASA-6-305011: Built dynamic UDP translation from WIRELESS-DMZ:192.168.87.210/56197 to OUTSIDE:x.x.x.x/53547&lt;BR /&gt;Feb 21 2014 18:06:03: %ASA-6-302015: Built outbound UDP connection 21496269 for OUTSIDE:8.8.4.4/53 (8.8.4.4/53) to WIRELESS-DMZ:192.168.87.210/56197 (x.x.x.x/53547)&lt;BR /&gt;Feb 21 2014 18:06:03: %ASA-6-110003: Routing failed to locate next hop for UDP from OUTSIDE:8.8.4.4/53 to WIRELESS-DMZ:192.168.87.210/56197&lt;BR /&gt;Feb 21 2014 18:06:03: %ASA-6-302016: Teardown UDP connection 21496269 for OUTSIDE:8.8.4.4/53 to WIRELESS-DMZ:192.168.87.210/56197 duration 0:00:00 bytes 210&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;NAT CONFIG&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SE-SW-ASA01/act# sh run nat&lt;BR /&gt;nat (WIRELESS-DMZ) 1 192.168.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;sh run global &lt;BR /&gt;global (OUTSIDE) 1 x.x.x.x&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;Interface gig 0/2 has 2 sub interfaces,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW-ASA01/act# sh run int Ethernet0/2.666&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.666&lt;BR /&gt;vlan 666&lt;BR /&gt;nameif WIRELESS-DMZ&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 192.168.84.1 255.255.254.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;Connected ROUTE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW-ASA01/act# sh route wiRELESS-DMZ&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.84.0 255.255.254.0 is directly connected, WIRELESS-DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;ARP TABLE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW-ASA01/act# sh arp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.199 a0ed.cda1.8725 3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.210 b09f.bab3.d860 7&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.219 b09f.bac8.fa8f 579&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.202 a888.0856.b5d3 3197&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.146 6c88.140c.552c 3486&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.145 0c30.218a.5fd4 3492&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.218 b09f.bac8.6ddd 3585&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.212 8cfa.ba4a.4b1e 3632&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.217 4874.6e54.ceb4 3641&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.209 6c88.140c.5a80 3787&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.213 6c88.1409.6f64 4210&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.141 843a.4bae.74d8 5470&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.195 6c88.140c.5a38 6292&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.206 444c.0cda.b1e1 7206&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.182 cc78.5fb6.79a9 7347&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.181 0c30.2193.a477 7385&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.198 a0ed.cd9d.395a 9394&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.192 6c88.1409.ec90 9447&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WIRELESS-DMZ 192.168.87.211 ec35.86d0.af7d 12006&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;ERROR MESSAGE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 1: 17:48:19.786671 8.8.4.4.53 &amp;gt; 192.168.87.210.56759:&amp;nbsp; udp 179 Drop-reason: (no-adjacency) No valid adjacency&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 2: 17:48:20.787251 8.8.4.4.53 &amp;gt; 192.168.87.210.56759:&amp;nbsp; udp 179 &lt;BR /&gt;&amp;nbsp;&amp;nbsp; 3: 17:48:23.800800 8.8.8.8.53 &amp;gt; 192.168.87.210.56759:&amp;nbsp; udp 179 Drop-reason: (no-adjacency) No valid adjacency&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 4: 17:48:24.802921 8.8.8.8.53 &amp;gt; 192.168.87.210.56759:&amp;nbsp; udp 179 Drop-reason: (no-adjacency) No valid adjacency&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 5: 17:48:27.804523 8.8.4.4.53 &amp;gt; 192.168.87.210.56759:&amp;nbsp; udp 179 Drop-reason: (no-adjacency) No valid adjacency&lt;BR /&gt;&amp;nbsp;&amp;nbsp; 6: 17:48:36.823336 8.8.4.4.53 &amp;gt; 192.168.87.210.56759:&amp;nbsp; udp 179 &lt;BR /&gt;&amp;nbsp;&amp;nbsp; 7: 17:49:03.885131 8.8.8.8.53 &amp;gt; 192.168.87.210.56759:&amp;nbsp; udp 179 Drop-reason: (no-adjacency) No valid adjacency&lt;BR /&gt;7 packets shown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;SWITCH CONFIG&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;SW-CORESW01#sh run int gig 1/0/1&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/1&lt;BR /&gt;description SW-ASA01-P GI0/1 : INSIDE FIREWALL&lt;BR /&gt;switchport access vlan 999&lt;BR /&gt;switchport trunk encapsulation dot1q&lt;BR /&gt;switchport trunk native vlan 901&lt;BR /&gt;switchport trunk allowed vlan 144,666,1016&lt;BR /&gt;switchport mode trunk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;SWITCH MAC ADDRESS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW-CORESW01#sh mac address-table | in&amp;nbsp; d48c.b5c2.7246&lt;BR /&gt;666&amp;nbsp;&amp;nbsp;&amp;nbsp; d48c.b5c2.7246&amp;nbsp;&amp;nbsp;&amp;nbsp; DYNAMIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi1/0/1&lt;BR /&gt;1016&amp;nbsp;&amp;nbsp;&amp;nbsp; d48c.b5c2.7246&amp;nbsp;&amp;nbsp;&amp;nbsp; DYNAMIC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gi1/0/1&lt;/P&gt;&lt;P&gt;SW-CORESW01#sh run int gig 1/0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;VLAN 666&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW-CORESW01#sh vlan id 666&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;VLAN Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Status&amp;nbsp;&amp;nbsp;&amp;nbsp; Ports&lt;BR /&gt;---- -------------------------------- --------- -------------------------------&lt;BR /&gt;666&amp;nbsp; WIRELESS-GUEST&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&amp;nbsp;&amp;nbsp;&amp;nbsp; Fa1/0/47, Gi1/0/1, Fa2/0/47, Gi2/0/1, Fa3/0/47&lt;/P&gt;&lt;P&gt;VLAN Type&amp;nbsp; SAID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MTU&amp;nbsp;&amp;nbsp; Parent RingNo BridgeNo Stp&amp;nbsp; BrdgMode Trans1 Trans2&lt;BR /&gt;---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------&lt;BR /&gt;666&amp;nbsp; enet&amp;nbsp; 100666&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1500&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Craig&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:48:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-valid-adjacency/m-p/2452015#M269180</guid>
      <dc:creator>craig bache</dc:creator>
      <dc:date>2019-03-12T03:48:53Z</dc:date>
    </item>
    <item>
      <title>ASA No valid adjacency</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-valid-adjacency/m-p/2452016#M269184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The eth0/2.666 WIRELESS-DMZ interface is addressed as a /23 but the NAT definition is a /16. They should match. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2014 18:42:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-valid-adjacency/m-p/2452016#M269184</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-02-21T18:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA No valid adjacency</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-valid-adjacency/m-p/2452017#M269187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Craig &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your wireless clients are using 192.168.87.x addressing but your DMZ IP subnet is 192.168.84.0 255.255.254.0 ie. this is - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;network address = 192.168.84.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;useable IPs = 192.168.84.1 -&amp;gt; 192.168.85.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;broacast address = 192.168.85.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so your clients do not fall into the network. You need to either - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) change the network on the DMZ interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) change your client addresses to fall within the 192.168.84.0/31 network. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps the mask should be 255.255.252.0 ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2014 18:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-valid-adjacency/m-p/2452017#M269187</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-02-21T18:44:49Z</dc:date>
    </item>
    <item>
      <title>ASA No valid adjacency</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-valid-adjacency/m-p/2452018#M269191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jon/ Marvin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the response. I will change the configuration to match&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2014 18:53:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-valid-adjacency/m-p/2452018#M269191</guid>
      <dc:creator>craig bache</dc:creator>
      <dc:date>2014-02-21T18:53:13Z</dc:date>
    </item>
  </channel>
</rss>

