<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Network to Network access. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/network-to-network-access/m-p/2383627#M307403</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you mean that the gateway behind which the Opera network is found is supposed to be 172.16.10.200?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am just wondering as your ASA has a route towards a gateway address of 172.16.10.221&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I am kind of wondering how this setup has worked. It would seem to me to possibly be a setup with asymmetric routing. I mean your hosts on the network 172.16.10.0/24 probably use the ASA as their gateway and you have the network to which you need to connect through a gateway that is located in the same network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To me it would seem that the connection forming would go like this&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Host on the network 172.16.10.0/24 sends TCP SYN to Opera server through ASA (default gateway)&lt;/LI&gt;&lt;LI&gt;TCP SYN reaches the server and server replies but the TCP SYN ACK is sent back from the Opera gateway directly to the host&lt;/LI&gt;&lt;LI&gt;Host sends the TCP ACK to the ASA (default gateway) and ASA blocks it as it has not seen the TCP SYN ACK at any point&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Atleast to me it would seem to be the situation but I might be wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This situation is usually avoided by using TCP State Bypass.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I am not sure what the actual problem is at the moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Dec 2013 23:13:13 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-12-09T23:13:13Z</dc:date>
    <item>
      <title>Network to Network access.</title>
      <link>https://community.cisco.com/t5/network-security/network-to-network-access/m-p/2383626#M307400</link>
      <description>&lt;P&gt;We have asa's at our hotels. We have a brand network and our local network. I am trying to get the 172 nw to access the opera server and back. The given us a port on their netgate to access the server and assigned it the 172.16.10.200 address. I had the sae configuration that you see now working and then we had to replace the asa and we can no longer get the connection to access the opera server. I have a host entry on all the workstations that use to access the server. any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:15:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-to-network-access/m-p/2383626#M307400</guid>
      <dc:creator>davbrew2005</dc:creator>
      <dc:date>2019-03-12T03:15:05Z</dc:date>
    </item>
    <item>
      <title>Network to Network access.</title>
      <link>https://community.cisco.com/t5/network-security/network-to-network-access/m-p/2383627#M307403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you mean that the gateway behind which the Opera network is found is supposed to be 172.16.10.200?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am just wondering as your ASA has a route towards a gateway address of 172.16.10.221&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I am kind of wondering how this setup has worked. It would seem to me to possibly be a setup with asymmetric routing. I mean your hosts on the network 172.16.10.0/24 probably use the ASA as their gateway and you have the network to which you need to connect through a gateway that is located in the same network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To me it would seem that the connection forming would go like this&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Host on the network 172.16.10.0/24 sends TCP SYN to Opera server through ASA (default gateway)&lt;/LI&gt;&lt;LI&gt;TCP SYN reaches the server and server replies but the TCP SYN ACK is sent back from the Opera gateway directly to the host&lt;/LI&gt;&lt;LI&gt;Host sends the TCP ACK to the ASA (default gateway) and ASA blocks it as it has not seen the TCP SYN ACK at any point&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Atleast to me it would seem to be the situation but I might be wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This situation is usually avoided by using TCP State Bypass.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I am not sure what the actual problem is at the moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Dec 2013 23:13:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-to-network-access/m-p/2383627#M307403</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-12-09T23:13:13Z</dc:date>
    </item>
    <item>
      <title>Network to Network access.</title>
      <link>https://community.cisco.com/t5/network-security/network-to-network-access/m-p/2383628#M307404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The gateway is&amp;nbsp; 172.16 10.221. Sorry about that.&amp;nbsp; We use to be able to access the opera server&amp;nbsp; through a browser at 10.170.195.12 but it no longer resolves after I replaced the asa. 172.16.10.221 is the address they assigned to the netgate port we plugged into.&amp;nbsp; All traffic from 172.16.10.0 going to the operaserver went through that port on their netgate. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Dec 2013 23:26:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-to-network-access/m-p/2383628#M307404</guid>
      <dc:creator>davbrew2005</dc:creator>
      <dc:date>2013-12-09T23:26:33Z</dc:date>
    </item>
  </channel>
</rss>

