<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Access issues &amp;quot;no valid adjacency&amp;quot;. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-issues-quot-no-valid-adjacency-quot/m-p/2330316#M310952</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh my lord I didn't notice I was pointing the nat rule to the inside interface instead of inside2.&amp;nbsp; This is what happens when your boss has you messing abot with firewalls when you have the flu.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you so much JouniForss for the sanity check.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Oct 2013 06:50:26 GMT</pubDate>
    <dc:creator>gosborne1969</dc:creator>
    <dc:date>2013-10-15T06:50:26Z</dc:date>
    <item>
      <title>Access issues "no valid adjacency".</title>
      <link>https://community.cisco.com/t5/network-security/access-issues-quot-no-valid-adjacency-quot/m-p/2330314#M310947</link>
      <description>&lt;P&gt;Hi I'm running a 5505 version 8.4(2).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Around a month ago i addedd a second interface called inside2.&amp;nbsp; Everthing was going fine until I needed to expose some websites on the new network to external parties.&amp;nbsp; If i try to access the sites via my outside interface I see "no valid adjacency" in the log files.&amp;nbsp; If I run a packet trace from the outside interface to the inside2 interface is see the following...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="padding: .75pt .75pt .75pt .75pt;"&gt;&lt;TABLE border="1" cellpadding="0" style="border: solid #CCCCCC 1.0pt; padding: px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border: none; padding: .75pt .75pt .75pt .75pt;"&gt;&lt;P&gt;Type - &lt;/P&gt;&lt;/TD&gt;&lt;TD style="border: none; padding: .75pt .75pt .75pt .75pt;"&gt;&lt;P&gt;NAT &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;TD style="padding: .75pt .75pt .75pt .75pt;"&gt;&lt;TABLE border="1" cellpadding="0" style="border: solid #CCCCCC 1.0pt; padding: px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border: none; padding: .75pt .75pt .75pt .75pt;"&gt;&lt;P&gt;Subtype - &lt;/P&gt;&lt;/TD&gt;&lt;TD style="border: none; padding: .75pt .75pt .75pt .75pt;"&gt;&lt;P&gt;rpf-check &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;TD style="padding: .75pt .75pt .75pt .75pt;"&gt;&lt;TABLE border="1" cellpadding="0" style="border: solid #CCCCCC 1.0pt; padding: px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border: none; padding: .75pt .75pt .75pt .75pt;"&gt;&lt;P&gt;Action - &lt;/P&gt;&lt;/TD&gt;&lt;TD style="border: none; padding: .75pt .75pt .75pt .75pt;"&gt;&lt;P&gt;DROP &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;TD style="padding: .75pt .75pt .75pt .75pt;"&gt;&lt;TABLE border="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="padding: .75pt .75pt .75pt .75pt;"&gt;&lt;P&gt;Show rule in NAT Rules table. &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="padding: .75pt .75pt .75pt .75pt;"&gt;&lt;TABLE border="1" cellpadding="0" style="border: solid #CCCCCC 1.0pt; padding: px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="border: none; padding: .75pt .75pt .75pt .75pt;"&gt;&lt;P&gt;Config &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="border: none; padding: .75pt .75pt .75pt .75pt;"&gt;&lt;P&gt;object network obj_any_inside2&lt;BR /&gt; nat (inside2,outside) dynamic interface &lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the relevant portion of my config...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "sh run"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.4(2) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt; switchport access vlan 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt; switchport access vlan 5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.57.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 77.221.164.138 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan15&lt;/P&gt;&lt;P&gt; nameif inside2&lt;/P&gt;&lt;P&gt; security-level 75&lt;/P&gt;&lt;P&gt; ip address 192.168.59.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj_any_inside2&lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network webserver16&lt;/P&gt;&lt;P&gt; host 192.168.59.22&lt;/P&gt;&lt;P&gt;object network webserver14&lt;/P&gt;&lt;P&gt; host 192.168.59.19&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access extended permit object-group HTTP(S) any object webserver16 &lt;/P&gt;&lt;P&gt;access-list outside_access extended permit object-group HTTP(S) any object webserver14 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface &lt;/P&gt;&lt;P&gt;object network obj_any_inside2&lt;/P&gt;&lt;P&gt; nat (spinsport,outside) dynamic interface&lt;/P&gt;&lt;P&gt;object network webserver16&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 77.221.164.141&lt;/P&gt;&lt;P&gt;object network webserver14&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 77.221.164.142&lt;/P&gt;&lt;P&gt;access-group outside_access in interface outside&lt;/P&gt;&lt;P&gt;access-group global_access global&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 77.221.164.137 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What exactly am i doing wrong here? &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:52:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-issues-quot-no-valid-adjacency-quot/m-p/2330314#M310947</guid>
      <dc:creator>gosborne1969</dc:creator>
      <dc:date>2019-03-12T02:52:00Z</dc:date>
    </item>
    <item>
      <title>Access issues "no valid adjacency".</title>
      <link>https://community.cisco.com/t5/network-security/access-issues-quot-no-valid-adjacency-quot/m-p/2330315#M310949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The NAT configuration at the very top is a Dynamic PAT usually configured for internal networks to enable outbound connections to the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For inbound connections from the Internet you would have to specify a Static NAT which binds a single public IP address to a single local IP address. Or you would have to specify a Static PAT which binds a single public port of a public IP address to a single local port of a local IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Essentially you would need a configuration like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network NEW-SERVER&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 192.168.59.x&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (inside2,outside) static &lt;PUBLIC ip=""&gt;&lt;/PUBLIC&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list &lt;ACL name=""&gt; permit tcp any object NEW-SERVER eq &lt;PORT&gt;&lt;/PORT&gt;&lt;/ACL&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or are the &lt;STRONG&gt;"webserver14"&lt;/STRONG&gt; and &lt;STRONG&gt;"webserver16"&lt;/STRONG&gt; perhaps the Static NAT configurations you are trying to use? If they are notice that they are using the wrong source interface of &lt;STRONG&gt;"inside" &lt;/STRONG&gt;instead of &lt;STRONG&gt;"inside2"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the problem might most likely be the wrong interface in the &lt;STRONG&gt;"nat"&lt;/STRONG&gt; command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do remember to mark a reply as the correct answer if it answered your question&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feel free to ask more if needed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Oct 2013 17:34:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-issues-quot-no-valid-adjacency-quot/m-p/2330315#M310949</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-14T17:34:28Z</dc:date>
    </item>
    <item>
      <title>Access issues "no valid adjacency".</title>
      <link>https://community.cisco.com/t5/network-security/access-issues-quot-no-valid-adjacency-quot/m-p/2330316#M310952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh my lord I didn't notice I was pointing the nat rule to the inside interface instead of inside2.&amp;nbsp; This is what happens when your boss has you messing abot with firewalls when you have the flu.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you so much JouniForss for the sanity check.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Oct 2013 06:50:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-issues-quot-no-valid-adjacency-quot/m-p/2330316#M310952</guid>
      <dc:creator>gosborne1969</dc:creator>
      <dc:date>2013-10-15T06:50:26Z</dc:date>
    </item>
  </channel>
</rss>

