<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trouble reaching webserver on inside interface from guest in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421638#M309594</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah it seems that the devices on the 192.168.190.0 netwok have a default gateway of the ip configured on the HP switch which is 192.168.190.1..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the 10.10.10.0 network uses the 10.10.10.1 which is the ip on Guest interface of the ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Nov 2013 11:48:08 GMT</pubDate>
    <dc:creator>Shane Riley</dc:creator>
    <dc:date>2013-11-06T11:48:08Z</dc:date>
    <item>
      <title>Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421624#M309553</link>
      <description>&lt;P&gt;I have a problem once again &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to reach a webserver which is located on the inside interface 192.168.190.27 from the Guest Interface which has 10.10.10.0&lt;/P&gt;&lt;P&gt;See the diagram: &lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/3/8/2/165283-topology.png" alt="topology.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ping from for example 10.10.10.103 a windows 7 client to the server 192.168.190.27.. Which works without a problem.&lt;/P&gt;&lt;P&gt;Pinging from the server to the client works fine..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But when i try to browse to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://192.168.190.27" target="_blank"&gt;http://192.168.190.27&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://192.168.190.27" target="_blank"&gt;https://192.168.190.27&lt;/A&gt;&lt;SPAN&gt; no luck &lt;/SPAN&gt;&lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packet capture from the client &lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/8/0/3/165308-packetcapture.png" alt="packetcapture.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;a bunch of RST packets &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And here is a pic from the logging in the ASA..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/9/0/3/165309-log.png" alt="log.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh run | in Guest&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif Guest&lt;/P&gt;&lt;P&gt;access-list Guest_access_in extended permit ip 10.10.10.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list Guest_nat0_outbound extended permit ip 10.10.10.0 255.255.255.0 192.168.190.0 255.255.255.0&lt;/P&gt;&lt;P&gt;mtu Guest 1500&lt;/P&gt;&lt;P&gt;nat (Guest) 0 access-list Guest_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (Guest) 1 10.10.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;static (inside,Guest) 192.168.190.0 192.168.190.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;static (Guest,inside) 10.10.10.0 10.10.10.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;access-group Guest_access_in in interface Guest&lt;/P&gt;&lt;P&gt;dhcpd address 10.10.10.100-10.10.10.200 Guest&lt;/P&gt;&lt;P&gt;dhcpd dns 192.168.190.91 192.168.190.15 interface Guest&lt;/P&gt;&lt;P&gt;dhcpd enable Guest&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate all your help!&lt;/P&gt;&lt;P&gt;Shane &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:00:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421624#M309553</guid>
      <dc:creator>Shane Riley</dc:creator>
      <dc:date>2019-03-12T03:00:31Z</dc:date>
    </item>
    <item>
      <title>Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421625#M309556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to be sure, can you provide the output of &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input Guest tcp 10.10.10.103 12345 192.168.190.27 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The screencapture from Wireshark seems to have its packets in the wrong order? Do you have a complete capture file of connection attempts that you could provide to us?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the HP switch you are using purely a L2 switch or does it have L3/Routing capabilities?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 13:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421625#M309556</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-05T13:00:36Z</dc:date>
    </item>
    <item>
      <title>Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421626#M309558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The output from the packet-tracer:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: FLOW-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Found no matching flow, creating a new flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: UN-NAT&lt;/P&gt;&lt;P&gt;Subtype: static&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;static (inside,Guest) 192.168.190.0 192.168.190.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside 192.168.190.0 255.255.255.0 Guest any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 192.168.190.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 1560025&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;NAT divert to egress interface inside&lt;/P&gt;&lt;P&gt;Untranslate 192.168.190.0/0 to 192.168.190.0/0 using netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group Guest_access_in in interface Guest&lt;/P&gt;&lt;P&gt;access-list Guest_access_in extended permit ip 10.10.10.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: NAT-EXEMPT&lt;/P&gt;&lt;P&gt;Subtype: rpf-check&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;static (Guest,inside) 10.10.10.0 10.10.10.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip Guest 10.10.10.0 255.255.255.0 inside any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 10.10.10.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 15571, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Static translate 10.10.10.0/0 to 10.10.10.0/0 using netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 7&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: host-limits&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;static (Guest,inside) 10.10.10.0 10.10.10.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip Guest 10.10.10.0 255.255.255.0 inside any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 10.10.10.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 15571, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 8&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: rpf-check&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;static (inside,Guest) 192.168.190.0 192.168.190.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside 192.168.190.0 255.255.255.0 Guest any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 192.168.190.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 1560028&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 9&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: host-limits&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;static (inside,outside) x.x.x.x 192.168.190.27 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside host 192.168.190.27 outside any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to x.x.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 251573, untranslate_hits = 636450&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 10&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 11&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 17190653, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 12&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: output and adjacency&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;found next-hop 192.168.190.27 using egress ifc inside&lt;/P&gt;&lt;P&gt;adjacency Active&lt;/P&gt;&lt;P&gt;next-hop mac address 000c.2946.f8e5 hits 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: Guest&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: inside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The HP switch is a L3..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll get back to you asap with the capture file..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Shane&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 13:28:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421626#M309558</guid>
      <dc:creator>Shane Riley</dc:creator>
      <dc:date>2013-11-05T13:28:17Z</dc:date>
    </item>
    <item>
      <title>Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421627#M309562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if the HP switch is indeed L3 and doing routing then could you tell me if both "inside" and "Guest" networks have an Vlan interface with IP address on the HP Switch? If they do, does that IP act as the default gateway for either of "inside" / "Guest" user networks? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 13:31:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421627#M309562</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-05T13:31:05Z</dc:date>
    </item>
    <item>
      <title>Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421628#M309566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it does.. here is the output from the show ip route on the switch..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/1/3/165314-showiproute.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/shane&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 13:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421628#M309566</guid>
      <dc:creator>Shane Riley</dc:creator>
      <dc:date>2013-11-05T13:57:33Z</dc:date>
    </item>
    <item>
      <title>Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421629#M309568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the configured gateway IP address for the &lt;STRONG&gt;"inside"&lt;/STRONG&gt; and &lt;STRONG&gt;"Guest"&lt;/STRONG&gt; networks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it some IP address configured on the HP Switch or the ASA5505.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If one network is using ASA as the gateway and the other is using the HP Switch then you will have routing problems&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 14:02:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421629#M309568</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-05T14:02:14Z</dc:date>
    </item>
    <item>
      <title>Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421630#M309570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway for the inside= 192.168.190.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; guest= 10.10.10.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its the ip configured on the interfaces of the ASA..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the pcap file: &lt;/P&gt;&lt;P&gt;&lt;A href="https://lifesthlm.com/owncloud/public.php?service=files&amp;amp;t=718a347d89adc98c3836b2835546ce21"&gt;https://lifesthlm.com/owncloud/public.php?service=files&amp;amp;t=718a347d89adc98c3836b2835546ce21&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/shane&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 15:26:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421630#M309570</guid>
      <dc:creator>Shane Riley</dc:creator>
      <dc:date>2013-11-05T15:26:16Z</dc:date>
    </item>
    <item>
      <title>Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421631#M309574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just remove the layer 3 configuraton from the HP switch for the 10 network and haver server and PC point to the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have a lot of devices pointing to the switch IP remove the IP from the switch and swap it out on the interface of the ASA guest interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 17:09:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421631#M309574</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-05T17:09:28Z</dc:date>
    </item>
    <item>
      <title>Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421632#M309576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe you should also share the ASA configuration that we can be sure there there is no problem there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The capture only seems to show TCP SYNs that the host sends and Resets right away after sending the SYN. There is absolutely no return traffic from the server itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If neither network uses the HP switch as their L3 gateway then I imagine that there should not be problems regarding the routing though it would still be best to have no routing related to the different LAN Networks on the HP Switch but only have some Management Vlan on the switch for remote management from some LAN network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 17:23:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421632#M309576</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-05T17:23:59Z</dc:date>
    </item>
    <item>
      <title>Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421633#M309579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also the complete capture because I can't confirm who is sending the RST, it could be another device.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 17:30:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421633#M309579</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-05T17:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421634#M309581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would seem to me that the TCP Reset is from the same source MAC address as the actual host that sent the TCP SYN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would imagine that if the ASA was sending the TCP Reset for example (or some other device) that the TCP Reset would also be coming with the source IP address of the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure why the host itself sending the TCP Reset.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I presume this capture is from the actual host or is it from the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 18:19:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421634#M309581</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-05T18:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421635#M309583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well if we can't see the MAC addresses we cannot confirm, that is why I'm asking for the sniffer file.&lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 18:40:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421635#M309583</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-05T18:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421636#M309585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I just said we can see the MAC address? But more importantly I would imagine that if some other device was sending the TCP Reset it would not be sending the TCP Reset with the source IP address of the connecting host but rather then destination hosts/servers IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We havent seen the configuration of the ASA but the information would seem to suggest that both network are directly connected to the ASA so whether the capture was taken from the host or the ASA we should be seeing the actual source MAC address of the packet in the capture file that was linked in the earlier post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though it does seem strange that in the capture there is nothing from the server or from any other device. I am not sure why that would happen though unless there is another NIC involved somehow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 18:45:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421636#M309585</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-05T18:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421637#M309592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ups did not see the file LoL&lt;SPAN __jive_emoticon_name="silly" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt; just saw the image&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 18:50:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421637#M309592</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-05T18:50:38Z</dc:date>
    </item>
    <item>
      <title>Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421638#M309594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah it seems that the devices on the 192.168.190.0 netwok have a default gateway of the ip configured on the HP switch which is 192.168.190.1..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the 10.10.10.0 network uses the 10.10.10.1 which is the ip on Guest interface of the ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 11:48:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421638#M309594</guid>
      <dc:creator>Shane Riley</dc:creator>
      <dc:date>2013-11-06T11:48:08Z</dc:date>
    </item>
    <item>
      <title>Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421639#M309596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is a clear problem with regards to the operation of the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you now have routing activated on the HP Switch (as you say) and you have a Guest&amp;nbsp; Vlan interface on the HP switch with an IP address from the network&amp;nbsp; 10.10.10.0/24 then traffic (or return traffic) from network&amp;nbsp; 192.168.190.0/24 will never pass through the ASA. ASA has to see the whole TCP conversation between the devices in different network, not just the other half.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The simplest solution for ASA would be to have a the HP Switch only act as a L2 switch for the 2 user Vlans and the ASA act as the L3 point for the network. Alternatively you could remove any L3 related operation for Guest Vlan from the HP Switch and leave the original LAN network 192.168.190.0/24 as it is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if possible you could remove the Vlan interface IP address for the Guest Vlan so the only routing device for that Vlan would be the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 12:21:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421639#M309596</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-06T12:21:01Z</dc:date>
    </item>
    <item>
      <title>Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421640#M309598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you had the chance to try changing the network setup regarding the gateways of the different networks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 20:09:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421640#M309598</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-08T20:09:09Z</dc:date>
    </item>
    <item>
      <title>Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421641#M309600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry about that, but been busy with another issue &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; I am going to try changing it today and get back to you &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Shane&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Nov 2013 07:02:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421641#M309600</guid>
      <dc:creator>Shane Riley</dc:creator>
      <dc:date>2013-11-11T07:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble reaching webserver on inside interface from guest</title>
      <link>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421642#M309602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks alot, i removed the Vlan interface IP address for the&amp;nbsp; Guest Vlan so the only routing device for that Vlan is the ASA. In the near future i am going to remove the routing alltogehter on the switch, to let it act only as a layer 2 switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once again thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a wonderful weekend&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Shane&lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 20:52:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/trouble-reaching-webserver-on-inside-interface-from-guest/m-p/2421642#M309602</guid>
      <dc:creator>Shane Riley</dc:creator>
      <dc:date>2013-11-21T20:52:38Z</dc:date>
    </item>
  </channel>
</rss>

