<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Asymmetric routing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421577#M307748</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA will always source the traffic from the closest interface to the server (no ip radius source or tacacs interface as the router).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the server is not on the Managment interface how are you sourcing the traffic from that interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate all of the helpful posts!!! &lt;BR /&gt; &lt;BR /&gt;Regards, &lt;BR /&gt; &lt;BR /&gt;Jcarvaja &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Dec 2013 21:45:53 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-12-04T21:45:53Z</dc:date>
    <item>
      <title>ASA Asymmetric routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421572#M307730</link>
      <description>&lt;P&gt;I believe I am seeing an asymmetric routing issue but not so sure. &lt;STRONG&gt;ASA version 9.1(1)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have the management interface (&lt;STRONG&gt;management-only&lt;/STRONG&gt; configured) connected to an upstream router. &lt;/P&gt;&lt;P&gt;Management default route out is towards this router ( and also its IP gateway)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We also have the inside interface (different subnet) attached to the same router running IGP (OSPF) with it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could not source ping (from management) to an external server (TACACS). I could see error&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA-7-710005: TCP request discarded error&lt;/STRONG&gt; between the sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source ping from "inside" works fine. When the inside was "shut" the Management started working. Has anyone run into this scenario&lt;/P&gt;&lt;P&gt;with the &lt;STRONG&gt;managment &lt;/STRONG&gt;and &lt;STRONG&gt;inside &lt;/STRONG&gt;going to the same box (but on different subnets) ? &lt;/P&gt;&lt;P&gt;I would think the management-only would be immune to this if it is asymmetric issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Pete&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:12:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421572#M307730</guid>
      <dc:creator>xayavongp</dc:creator>
      <dc:date>2019-03-12T03:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Asymmetric routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421573#M307731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where does the external server sits?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember that you have the management-only keyword with basically restrict the interface with any sort of routed traffic. it's only for management access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean routed traffic will not go out that interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate all of the helpful posts!!! &lt;BR /&gt; &lt;BR /&gt;Regards, &lt;BR /&gt; &lt;BR /&gt;Jcarvaja &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com" rel="nofollow"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Dec 2013 19:49:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421573#M307731</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-12-04T19:49:38Z</dc:date>
    </item>
    <item>
      <title>ASA Asymmetric routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421574#M307735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I understand that the managment-only does not pass traffic.&lt;/P&gt;&lt;P&gt;The server sits at another site and the WAN is stable. Is there any debugging that might be useful ?&lt;/P&gt;&lt;P&gt;Would there be a specific "asymmetric" error on the ASA if it sees it as such?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Dec 2013 20:03:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421574#M307735</guid>
      <dc:creator>xayavongp</dc:creator>
      <dc:date>2013-12-04T20:03:27Z</dc:date>
    </item>
    <item>
      <title>ASA Asymmetric routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421575#M307737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exactly does not allow you to let traffic go through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well you woud check for logs that would actually deny the tcp connection with a flag of no-connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, how are you trying to source the packets from the management&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean &lt;/P&gt;&lt;P&gt;ping management x.x.x.x is not the same as ping x.x.x.x source-interface management (as on a router)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the ping management you will be letting the ASA know it needs to send the traffic via that management interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate all of the helpful posts!!! &lt;BR /&gt; &lt;BR /&gt;Regards, &lt;BR /&gt; &lt;BR /&gt;Jcarvaja &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Dec 2013 20:07:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421575#M307737</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-12-04T20:07:07Z</dc:date>
    </item>
    <item>
      <title>ASA Asymmetric routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421576#M307742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The server is trying to reach the interface but the response from the ASA seems to not make it back for the full handshake.&lt;/P&gt;&lt;P&gt;Used&lt;STRONG&gt; ping management x.x.x.x &lt;/STRONG&gt;to verify that the management interface is able to reach the TACACS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was reachable when the &lt;STRONG&gt;inside &lt;/STRONG&gt;interface was "&lt;STRONG&gt;shut&lt;/STRONG&gt;"...and TACACS started working.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Dec 2013 21:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421576#M307742</guid>
      <dc:creator>xayavongp</dc:creator>
      <dc:date>2013-12-04T21:11:13Z</dc:date>
    </item>
    <item>
      <title>ASA Asymmetric routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421577#M307748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA will always source the traffic from the closest interface to the server (no ip radius source or tacacs interface as the router).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the server is not on the Managment interface how are you sourcing the traffic from that interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate all of the helpful posts!!! &lt;BR /&gt; &lt;BR /&gt;Regards, &lt;BR /&gt; &lt;BR /&gt;Jcarvaja &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Dec 2013 21:45:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421577#M307748</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-12-04T21:45:53Z</dc:date>
    </item>
    <item>
      <title>ASA Asymmetric routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421578#M307756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I removed &lt;STRONG&gt;management-access inside&lt;/STRONG&gt; and the management interface was able to communicate with the ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But something else broke. &lt;/P&gt;&lt;P&gt;I could ssh fine to the interface, but could not ping it and received this error.&lt;/P&gt;&lt;P&gt;&lt;TT&gt;Routing &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; failed to locate next-hop&lt;/TT&gt; for udp and icmp for the management interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I added &lt;STRONG&gt;management-access management &lt;/STRONG&gt;to test and the interface was able to process icmp traffic but the ACS&lt;/P&gt;&lt;P&gt;was not reachable anymore. Why would "management-access" effect the ASA this way? The "outside" is not even&lt;/P&gt;&lt;P&gt;connected yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Dec 2013 21:47:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421578#M307756</guid>
      <dc:creator>xayavongp</dc:creator>
      <dc:date>2013-12-09T21:47:59Z</dc:date>
    </item>
    <item>
      <title>ASA Asymmetric routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421579#M307763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hey bud I already asked you to explain the issue a little further, I have no idea where the ACS is connected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are not telling me how you are trying to connect to the ACS using the management, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate all of the helpful posts!!! &lt;BR /&gt; &lt;BR /&gt;Regards, &lt;BR /&gt; &lt;BR /&gt;Jcarvaja &lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Follow me on &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Dec 2013 00:58:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-asymmetric-routing/m-p/2421579#M307763</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-12-10T00:58:28Z</dc:date>
    </item>
  </channel>
</rss>

