<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with same interface ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/issue-with-same-interface-asa/m-p/2346855#M343254</link>
    <description>&lt;P&gt;Good day!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can any one please give me some advice, how to solve this problem. In our topology i've&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is tunnel topology&lt;/P&gt;&lt;P&gt;(192.168.1.0/24) HQ with 2911 &lt;SPAN style="font-size: 10pt;"&gt;(GRE TUNNEL) (10.10.100.1) &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;---- (GRE TUNNEL) &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;(10.10.100.1) &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;Remote Office with 2901 (10.20.36.0/24) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Also in remote office i've ASA5505 - which is a default gateway for devices in remote office. Routing - is OK between offices, cause icmp goes without a problem. But when i try to ssh from HQ to remote office (another devices) - session didnt establish.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I've entered this command &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but nothig happens. Dont know where can be the problem, also i've applied this ACL - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ALLOW_LAN extended permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to inside interface, but it still didnt solve the problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you point me, where can be the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 02:36:07 GMT</pubDate>
    <dc:creator>Dmitri Popkov</dc:creator>
    <dc:date>2019-03-12T02:36:07Z</dc:date>
    <item>
      <title>Issue with same interface ASA</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-same-interface-asa/m-p/2346855#M343254</link>
      <description>&lt;P&gt;Good day!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can any one please give me some advice, how to solve this problem. In our topology i've&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is tunnel topology&lt;/P&gt;&lt;P&gt;(192.168.1.0/24) HQ with 2911 &lt;SPAN style="font-size: 10pt;"&gt;(GRE TUNNEL) (10.10.100.1) &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;---- (GRE TUNNEL) &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;(10.10.100.1) &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;Remote Office with 2901 (10.20.36.0/24) &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Also in remote office i've ASA5505 - which is a default gateway for devices in remote office. Routing - is OK between offices, cause icmp goes without a problem. But when i try to ssh from HQ to remote office (another devices) - session didnt establish.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I've entered this command &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but nothig happens. Dont know where can be the problem, also i've applied this ACL - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ALLOW_LAN extended permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to inside interface, but it still didnt solve the problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you point me, where can be the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:36:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-same-interface-asa/m-p/2346855#M343254</guid>
      <dc:creator>Dmitri Popkov</dc:creator>
      <dc:date>2019-03-12T02:36:07Z</dc:date>
    </item>
    <item>
      <title>Issue with same interface ASA</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-same-interface-asa/m-p/2346856#M343260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From where to where are you trying to connect,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Provide a detail diagram specificing Source IP adresses and destination ip addresses&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For more information about Core and Security Networking follow my website at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;SPAN&gt;Any question contact me at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Sep 2013 16:11:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-same-interface-asa/m-p/2346856#M343260</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-09-10T16:11:01Z</dc:date>
    </item>
    <item>
      <title>Issue with same interface ASA</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-same-interface-asa/m-p/2346857#M343267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/8/2/157280-topology.jpeg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my topology. So, where can be the problem? Can anyone tell please. Icmp packets from 192.168.1.0/24 to 10.20.36.0 goes with out ant problem, but all tcp, udp traffic doesn't...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Sep 2013 13:57:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-same-interface-asa/m-p/2346857#M343267</guid>
      <dc:creator>Dmitri Popkov</dc:creator>
      <dc:date>2013-09-13T13:57:02Z</dc:date>
    </item>
    <item>
      <title>Issue with same interface ASA</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-same-interface-asa/m-p/2346858#M343269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems to me that you have Asymmetric routing. This will essentially result in the fact that the 10.20.36.0/24 site ASA will not see the complete TCP conversation between the host on the 2 sites. This will mean that the ASA will block these TCP connections because it has not seen all the packets when the TCP connections is brought up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I mean is that is that when host on network 192.168.1.0/24 connects to network 10.20.36.0/24 with a TCP connection the following happens&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Host 192.168.1.100 connecs to host 10.20.36.100 by sending TCP SYN&lt;/LI&gt;&lt;LI&gt;The TCP SYN goes through the sites and arrives on the other sites Router which then forwards it directly to host 10.20.36.100&lt;/LI&gt;&lt;LI&gt;Host 10.20.36 sends TCP SYN ACK to its default gateway (ASA) because the destination is in a remote network (network other than the network where this host resides)&lt;/LI&gt;&lt;LI&gt;ASA sees the TCP SYN ACK from host 10.20.36.100 but as it has not seen the original TCP SYN from host 192.168.1.100 it drops the packet and the TCP connection never forms.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One solution would be to configure TCP State Bypass but to me this is more of a workaround which could instead be handled by modifying the whole network layout.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a link to a document describing it&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080b2d922.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080b2d922.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would rather change the network setup so that I would connect the router 10.20.36.2 to the ASA firewall on that site. Naturally you would have to change the network between the Router and the ASA to something else. What this would do is that any traffic between networks 192.168.1.0/24 and 10.20.36.0/24 would have to always pass the ASA and you wouldnt run into the problem I mentioned above. This would naturally also give you the change to control the traffic between the sites better.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Sep 2013 15:56:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-same-interface-asa/m-p/2346858#M343269</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-09-15T15:56:52Z</dc:date>
    </item>
    <item>
      <title>Issue with same interface ASA</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-same-interface-asa/m-p/2346859#M343271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are right. I've enabled &lt;SPAN style="font-size: 10pt;"&gt;TCP State Bypass and applied rull to internal hosts and problem was solved&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thank you &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 12:51:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-same-interface-asa/m-p/2346859#M343271</guid>
      <dc:creator>Dmitri Popkov</dc:creator>
      <dc:date>2013-09-23T12:51:32Z</dc:date>
    </item>
  </channel>
</rss>

