<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Source and destination ip under same interface of ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207752#M350124</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will check the routing table to know whats the default static route there and will let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 11 May 2013 04:44:08 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2013-05-11T04:44:08Z</dc:date>
    <item>
      <title>Source and destination ip under same interface of ASA</title>
      <link>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207746#M350115</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i was checking some rule on ASA to find specfic port open on the destination IP or not?&amp;nbsp; and was given source and destination subnets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Object group network was used&amp;nbsp; for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Found that say we have interface Cisco&lt;/P&gt;&lt;P&gt;say interface of ASA&amp;nbsp; is on subnet 172.30.100.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have network object groups came x and y&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;X has subnet 172.30.10.x&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ------------------source&lt;/P&gt;&lt;P&gt;Y has subnet 172.30.250.x -------------------------------destination&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can see that ASA interface and network objects all 3 are of different network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to know as source and destinations are under same ASA interface but&amp;nbsp; under different subnets is the traffic flow from source to destination will&lt;/P&gt;&lt;P&gt;pass through ASA&amp;nbsp; or not?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:41:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207746#M350115</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T01:41:38Z</dc:date>
    </item>
    <item>
      <title>Source and destination ip under same interface of ASA</title>
      <link>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207747#M350117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your interface network is for example 172.30.100.0/24 and the source and destination networks are 172.30.10.0/24 and 172.30.250.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THEN if the source and destination networks are both routed out from interface Cisco then the traffic SHOULD NOT go through the ASA at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 May 2013 19:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207747#M350117</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-10T19:23:26Z</dc:date>
    </item>
    <item>
      <title>Source and destination ip under same interface of ASA</title>
      <link>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207748#M350119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this normal to have source and destination having different subnets under same ASA interface?&lt;/P&gt;&lt;P&gt;When you say should not go through the ASA&amp;nbsp; does it mean traffic will&amp;nbsp; passthrough the ASA but no rules will apply to it?&lt;/P&gt;&lt;P&gt;Need more explanation on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 May 2013 19:33:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207748#M350119</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-10T19:33:39Z</dc:date>
    </item>
    <item>
      <title>Source and destination ip under same interface of ASA</title>
      <link>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207749#M350120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naturally you can have many different subnets behind another interface. Most of the time in those cases you WONT need ACL rules to allow traffic between them as the traffic shouldnt go through the ASA at all at any point between those 2 subnets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you need to confirm (if I understood you correctly)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have an interface for example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface GigabitEthernet0/0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nameif Cisco&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; security-level 100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; ip add 172.30.100.1 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then IF you have the following routes for example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route Cisco 172.30.10.0 255.255.255.0 172.30.100.x&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route Cisco 172.30.250.0 255.255.255.0 172.30.100.x&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then this would mean that the 2 networks that have routes on the same interface of the ASA would communicate between eachother through some router behind the interface "Cisco" (Router 172.30.100.x)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in a typical setup the traffic between the 2 subnets in this case SHOULDNT go through the ASA at any point. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But you will have to confirm the above configurations refeclet your current situation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 May 2013 19:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207749#M350120</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-10T19:41:18Z</dc:date>
    </item>
    <item>
      <title>Source and destination ip under same interface of ASA</title>
      <link>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207750#M350122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To verify that traffic does not pass through the ASA&amp;nbsp; i have to check that&amp;nbsp; route command for both different subnets has interface Cisco IP address as next hop?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 May 2013 20:01:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207750#M350122</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-10T20:01:30Z</dc:date>
    </item>
    <item>
      <title>Source and destination ip under same interface of ASA</title>
      <link>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207751#M350123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the following command to list all static routes on the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run route&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to check routes for a certain interface then you can use the following command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run route | inc &lt;INTERFACE nameif=""&gt;&lt;/INTERFACE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you can naturally in this case try to use also the commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run route | inc 172.30.10&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run route | inc 172.30.250&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And they should list static routes for the networks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naturally you can also simply go through the routing table and find the routes for those 2 networks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show route&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basicly lets say if you see something like this in the configuration output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route Cisco 172.30.10.0 255.255.255.0 172.30.100.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route Cisco 172.30.250.0 255.255.255.0 172.30.100.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It means those 2 networks are found behind the same router behind the ASA interface Cisco. Since they are found on the same router behind the ASA then the router doesnt really have the need to route the traffic between those networks to the ASA at any point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will simply see a route on itself to the other network and has no need to send the traffic to ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But naturally all these things have to be confirmed in the configurations and routing tables of the devices&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have multiple routers behind single ASA interface there is possibility that traffic would go through the ASA but to determine if this is the case I would have to know how the routing table/configurations look like on the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 May 2013 20:29:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207751#M350123</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-10T20:29:44Z</dc:date>
    </item>
    <item>
      <title>Source and destination ip under same interface of ASA</title>
      <link>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207752#M350124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will check the routing table to know whats the default static route there and will let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 May 2013 04:44:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207752#M350124</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-11T04:44:08Z</dc:date>
    </item>
    <item>
      <title>Source and destination ip under same interface of ASA</title>
      <link>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207753#M350125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found this on the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route Cisco 172.30.10.0 255.255.255.0 172.30.100.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route Cisco 172.30.250.0 255.255.255.0 172.30.100.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems now it confirms that both subnets are behind the same ASA interface and Router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 May 2013 13:16:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/source-and-destination-ip-under-same-interface-of-asa/m-p/2207753#M350125</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-05-13T13:16:58Z</dc:date>
    </item>
  </channel>
</rss>

