<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA-2-106016 on same interface, but two subnets in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-2-106016-on-same-interface-but-two-subnets/m-p/2432166#M269313</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Hi Richard,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;XXX.XXX.XXX is the primary subnet, YYY.YYY.YYY is the secondary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface Ethernet0/1 "outside", is up, line protocol is up&lt;/P&gt;&lt;P&gt;&amp;nbsp; Hardware is i82546GB rev03, BW 100 Mbps, DLY 100 usec&lt;/P&gt;&lt;P&gt; Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)&lt;/P&gt;&lt;P&gt; Input flow control is unsupported, output flow control is off&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;IP address &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;XXX.XXX.XXX&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;.42, subnet mask 255.255.255.248&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address &lt;SPAN style="font-size: 10pt;"&gt;XXX.XXX.XXX&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;.42 255.255.255.248 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;related config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network bloc-externe-supp&lt;/P&gt;&lt;P&gt; subnet YYY.YYY.YYY.32 255.255.255.248&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;object network YYY.YYY.YYY.34&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; host YYY.YYY.YYY.34&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 XXX.XXX.XXX.41 1&lt;/P&gt;&lt;P&gt;route outside YYY.YYY.YYY.32 255.255.255.248 YYY.YYY.YYY.33 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Feb 2014 14:25:59 GMT</pubDate>
    <dc:creator>druideinformatique</dc:creator>
    <dc:date>2014-02-20T14:25:59Z</dc:date>
    <item>
      <title>ASA-2-106016 on same interface, but two subnets</title>
      <link>https://community.cisco.com/t5/network-security/asa-2-106016-on-same-interface-but-two-subnets/m-p/2432163#M269308</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get a strange problem here. We got another subnet from our ISP because we needed another block of IPs. Everything works fine, except one thing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Deny IP spoof from (XXX.XXX.XXX.XXX) to &lt;SPAN style="font-size: 10pt;"&gt;XXX.XXX.XXX.XXX &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;on interface outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The source IP is our main IP from our primary subnet and the destination is one of the IP in the new subnet. Do I need to add a special rule to allow this trafic??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco ASA 5510&lt;/P&gt;&lt;P&gt;ASA Version 9.1(1) &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:47:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-2-106016-on-same-interface-but-two-subnets/m-p/2432163#M269308</guid>
      <dc:creator>druideinformatique</dc:creator>
      <dc:date>2019-03-12T03:47:45Z</dc:date>
    </item>
    <item>
      <title>ASA-2-106016 on same interface, but two subnets</title>
      <link>https://community.cisco.com/t5/network-security/asa-2-106016-on-same-interface-but-two-subnets/m-p/2432164#M269311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you tell us how you are using the second subnet that the ISP provided? And it might help if you would post from the config at least the parts that deal with both of the subnets? It is difficult to know if you need to add something until we know what you already have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Feb 2014 21:19:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-2-106016-on-same-interface-but-two-subnets/m-p/2432164#M269311</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2014-02-19T21:19:08Z</dc:date>
    </item>
    <item>
      <title>ASA-2-106016 on same interface, but two subnets</title>
      <link>https://community.cisco.com/t5/network-security/asa-2-106016-on-same-interface-but-two-subnets/m-p/2432165#M269312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that's almost normal behavior on ASA if you don't enable the Proxy ARP on that interface and enabled anti-spoofing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try with this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;ip verify reverse-path interface [interface_name (inside/outside/dmz)]




&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and this one&lt;/P&gt;&lt;P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;SPAN style="background-color: transparent; font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;arp permit-nonconnected&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/P&gt;&lt;P&gt;and this other one.&lt;/P&gt;&lt;P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;SPAN style="background-color: transparent; font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt; no sysopt noproxyarp &lt;/SPAN&gt;&lt;SPAN style="background-color: transparent; font-family: arial, helvetica, sans-serif; font-size: 10pt; white-space: pre;"&gt;[interface_name (inside/outside/dmz)]&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let us know if fix your problem !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;had a great day!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Feb 2014 21:47:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-2-106016-on-same-interface-but-two-subnets/m-p/2432165#M269312</guid>
      <dc:creator>INGENIERIA Y CONSULTORIAS WEBREDES LTDA</dc:creator>
      <dc:date>2014-02-19T21:47:29Z</dc:date>
    </item>
    <item>
      <title>ASA-2-106016 on same interface, but two subnets</title>
      <link>https://community.cisco.com/t5/network-security/asa-2-106016-on-same-interface-but-two-subnets/m-p/2432166#M269313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Hi Richard,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;XXX.XXX.XXX is the primary subnet, YYY.YYY.YYY is the secondary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface Ethernet0/1 "outside", is up, line protocol is up&lt;/P&gt;&lt;P&gt;&amp;nbsp; Hardware is i82546GB rev03, BW 100 Mbps, DLY 100 usec&lt;/P&gt;&lt;P&gt; Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)&lt;/P&gt;&lt;P&gt; Input flow control is unsupported, output flow control is off&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;IP address &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;XXX.XXX.XXX&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;.42, subnet mask 255.255.255.248&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address &lt;SPAN style="font-size: 10pt;"&gt;XXX.XXX.XXX&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;.42 255.255.255.248 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;related config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network bloc-externe-supp&lt;/P&gt;&lt;P&gt; subnet YYY.YYY.YYY.32 255.255.255.248&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;object network YYY.YYY.YYY.34&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; host YYY.YYY.YYY.34&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 XXX.XXX.XXX.41 1&lt;/P&gt;&lt;P&gt;route outside YYY.YYY.YYY.32 255.255.255.248 YYY.YYY.YYY.33 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Feb 2014 14:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-2-106016-on-same-interface-but-two-subnets/m-p/2432166#M269313</guid>
      <dc:creator>druideinformatique</dc:creator>
      <dc:date>2014-02-20T14:25:59Z</dc:date>
    </item>
    <item>
      <title>ASA-2-106016 on same interface, but two subnets</title>
      <link>https://community.cisco.com/t5/network-security/asa-2-106016-on-same-interface-but-two-subnets/m-p/2432167#M269314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do have "arp permit-nonconnected", but not the other two. I will try it early next week.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Feb 2014 14:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-2-106016-on-same-interface-but-two-subnets/m-p/2432167#M269314</guid>
      <dc:creator>druideinformatique</dc:creator>
      <dc:date>2014-02-20T14:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA-2-106016 on same interface, but two subnets</title>
      <link>https://community.cisco.com/t5/network-security/asa-2-106016-on-same-interface-but-two-subnets/m-p/4008844#M269315</link>
      <description>&lt;P&gt;I hate to resurrect an old thread, but a very similar issue led me to this thread, and I tried the fix suggested above and ended up keeping the flood of logs, but now it's a different log entry:&lt;BR /&gt;&lt;BR /&gt;%ASA-1-106021: Deny UDP reverse path check from &amp;lt;IP bound inside interface&amp;gt; to &amp;lt;IP of server behind inside interface&amp;gt; on interface inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2020 14:39:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-2-106016-on-same-interface-but-two-subnets/m-p/4008844#M269315</guid>
      <dc:creator>RANT</dc:creator>
      <dc:date>2020-01-09T14:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA-2-106016 on same interface, but two subnets</title>
      <link>https://community.cisco.com/t5/network-security/asa-2-106016-on-same-interface-but-two-subnets/m-p/4298753#M1078845</link>
      <description>&lt;P&gt;From a reliable source:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"These messages [ASA-2-106016] indicate, as the &lt;A href="https://can01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.cisco.com%2Fc%2Fen%2Fus%2Ftd%2Fdocs%2Fsecurity%2Fasa%2Fsyslog%2Fb_syslog%2Fsyslogs1.html&amp;amp;data=04%7C01%7Cjohn.calvin%40utoronto.ca%7C945918fa4d734908397908d8daa442d8%7C78aac2262f034b4d9037b46d56c55210%7C0%7C0%7C637499746320410396%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C1000&amp;amp;sdata=p653AG9eO5Dmm4yXtcxm4U8oWwcOBojh5uNB98EL2H0%3D&amp;amp;reserved=0" target="_blank"&gt;documentation&lt;/A&gt; mentions, that the FW is receiving packets on the mentioned interfaces with dest IP of 0.0.0.0 and dest MAC that matches our FW interface. It seems that these messages are possible when we have a HA pair in which the standby ASA interfaces are left without IP and unaddressed. The standby appliance performs a FQDN lookup on its ACEs, and due to the fact that there is no IP to use those requests are sent with 0.0.0.0."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"We should be able to resolve this by adding a standby IP to interfaces in standby context."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Ethernet 0/1&lt;BR /&gt;&amp;nbsp; nameif inside&lt;BR /&gt;&amp;nbsp; security-level 100&lt;BR /&gt;&amp;nbsp; ip address 192.168.1.1 255.255.255.0 &lt;U&gt;standby 192.168.1.2&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Feb 2021 13:09:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-2-106016-on-same-interface-but-two-subnets/m-p/4298753#M1078845</guid>
      <dc:creator>John Calvin</dc:creator>
      <dc:date>2021-02-27T13:09:48Z</dc:date>
    </item>
  </channel>
</rss>

