<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 8.4 no connection one interface to another in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-4-no-connection-one-interface-to-another/m-p/2117637#M357260</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry the IP add is 115.91 and 112.54&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit tcp 192.168.115.0 255.255.255.0 host 192.168.115.251 object-group srv_WebPorts&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit object-group srv_VMwareIn object-group DMZ_VirtualHosts object vCentre&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit ip object-group DMZ_VirtualHosts object vCentre&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit udp 192.168.115.0 255.255.255.0 host 192.168.112.100 eq ntp&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit tcp host 192.168.115.91 host 192.168.112.54 eq 5723&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit tcp host 192.168.112.54 host 192.168.115.91 eq 5723&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended deny ip any any log&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network inside_NAT&lt;/P&gt;&lt;P&gt;subnet 192.168.112.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network vCentre&lt;/P&gt;&lt;P&gt; host 192.168.112.206&lt;/P&gt;&lt;P&gt;object network vCentre-DMZ_NAT&lt;/P&gt;&lt;P&gt; host 192.168.115.253&lt;/P&gt;&lt;P&gt;object network SECISM&lt;/P&gt;&lt;P&gt; host 192.168.112.100&lt;/P&gt;&lt;P&gt;object network SECISM-DMZ_NAT&lt;/P&gt;&lt;P&gt; host 192.168.115.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static inside_NAT inside_NAT &lt;/P&gt;&lt;P&gt;nat (inside,dmz) source static vCentre vCentre-DMZ_NAT&lt;/P&gt;&lt;P&gt;nat (inside,dmz) source static SECISM SECISM-DMZ_NAT &lt;/P&gt;&lt;P&gt;nat (inside,outside) source dynamic inside_NAT interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network vCentre&lt;/P&gt;&lt;P&gt; nat (inside,dmz) static 192.168.115.253 dns&lt;/P&gt;&lt;P&gt;object network SECMGMT01&lt;/P&gt;&lt;P&gt; nat (inside,dmz) static 192.168.115.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 192.168.112.0&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; inside&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group DMZ_IN in interface dmz&lt;BR /&gt;access-list DMZ_IN extended permit tcp host 192.168.115.91 host 192.168.112.54 eq 5723&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 7901509, packet dispatched to next module&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: dmz&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 31 Jan 2013 12:50:56 GMT</pubDate>
    <dc:creator>JDMJeffy84</dc:creator>
    <dc:date>2013-01-31T12:50:56Z</dc:date>
    <item>
      <title>ASA 8.4 no connection one interface to another</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-no-connection-one-interface-to-another/m-p/2117633#M357256</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm stuck on a particular issue, I can see this in SYSLOG:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deny TCP (no connection) from 192.168.112.x./x to 192.168.115.x/x flags SYN ACK&amp;nbsp; on interface inside&lt;/P&gt;&lt;P&gt;Teardown TCP connection 7844974 for fw-mgmt:192.168.115.x/x to inside:192.168.112.x/x duration 0:00:00 bytes 0 No valid adjacency&lt;/P&gt;&lt;P&gt;Routing failed to locate next hop for TCP from inside:192.168.112.x/x to fw-mgmt:192.168.115.x/x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried adding a static route on firewall:&lt;/P&gt;&lt;P&gt;route fw-mgmt&amp;nbsp; 192.168.115.0 255.255.255.0 192.168.112.1&lt;BR /&gt;ERROR: Cannot add route, connected route exists&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas what this could be?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-no-connection-one-interface-to-another/m-p/2117633#M357256</guid>
      <dc:creator>JDMJeffy84</dc:creator>
      <dc:date>2019-03-12T00:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.4 no connection one interface to another</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-no-connection-one-interface-to-another/m-p/2117634#M357257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have an interface in the 192.168.115.0 network? Please post the output of&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;asa# sh int ip brie&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And which systems are communicating? What are there Locations (interfaces) and IP-addresses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni" rel="nofollow"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 12:04:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-no-connection-one-interface-to-another/m-p/2117634#M357257</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-01-31T12:04:16Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 no connection one interface to another</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-no-connection-one-interface-to-another/m-p/2117635#M357258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a server in the 115 subnet 192.168.115.100 and requires communication to 192.168.112.100 in 112 subnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ethernet0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;Ethernet0/1.112&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.112.x&amp;nbsp;&amp;nbsp;&amp;nbsp; inside&amp;nbsp; 100&lt;BR /&gt;Ethernet0/1.118&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.118.x&amp;nbsp;&amp;nbsp; fw-mgmt&amp;nbsp; 80&lt;BR /&gt;Ethernet0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.115.x&amp;nbsp; dmz&amp;nbsp; 50 &lt;BR /&gt;Ethernet0/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.64.x&amp;nbsp;&amp;nbsp;&amp;nbsp; inner-mgmt 100&lt;BR /&gt;Management0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.1.1.1&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 12:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-no-connection-one-interface-to-another/m-p/2117635#M357258</guid>
      <dc:creator>JDMJeffy84</dc:creator>
      <dc:date>2013-01-31T12:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.4 no connection one interface to another</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-no-connection-one-interface-to-another/m-p/2117636#M357259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you have a communication from dmz to inside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paste your NAT- config and the ACL on the dmz-interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And what is the output of packet-tracer:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;packet-tracer input dmz 192.168.115.100 1234 192.168.112.100 PORT-YOU-WANT-TO-USE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni" rel="nofollow"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 12:32:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-no-connection-one-interface-to-another/m-p/2117636#M357259</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-01-31T12:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.4 no connection one interface to another</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-no-connection-one-interface-to-another/m-p/2117637#M357260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry the IP add is 115.91 and 112.54&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit tcp 192.168.115.0 255.255.255.0 host 192.168.115.251 object-group srv_WebPorts&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit object-group srv_VMwareIn object-group DMZ_VirtualHosts object vCentre&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit ip object-group DMZ_VirtualHosts object vCentre&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit udp 192.168.115.0 255.255.255.0 host 192.168.112.100 eq ntp&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit tcp host 192.168.115.91 host 192.168.112.54 eq 5723&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit tcp host 192.168.112.54 host 192.168.115.91 eq 5723&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended deny ip any any log&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network inside_NAT&lt;/P&gt;&lt;P&gt;subnet 192.168.112.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network vCentre&lt;/P&gt;&lt;P&gt; host 192.168.112.206&lt;/P&gt;&lt;P&gt;object network vCentre-DMZ_NAT&lt;/P&gt;&lt;P&gt; host 192.168.115.253&lt;/P&gt;&lt;P&gt;object network SECISM&lt;/P&gt;&lt;P&gt; host 192.168.112.100&lt;/P&gt;&lt;P&gt;object network SECISM-DMZ_NAT&lt;/P&gt;&lt;P&gt; host 192.168.115.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static inside_NAT inside_NAT &lt;/P&gt;&lt;P&gt;nat (inside,dmz) source static vCentre vCentre-DMZ_NAT&lt;/P&gt;&lt;P&gt;nat (inside,dmz) source static SECISM SECISM-DMZ_NAT &lt;/P&gt;&lt;P&gt;nat (inside,outside) source dynamic inside_NAT interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network vCentre&lt;/P&gt;&lt;P&gt; nat (inside,dmz) static 192.168.115.253 dns&lt;/P&gt;&lt;P&gt;object network SECMGMT01&lt;/P&gt;&lt;P&gt; nat (inside,dmz) static 192.168.115.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 192.168.112.0&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; inside&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group DMZ_IN in interface dmz&lt;BR /&gt;access-list DMZ_IN extended permit tcp host 192.168.115.91 host 192.168.112.54 eq 5723&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: FOVER&lt;BR /&gt;Subtype: standby-update&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 7901509, packet dispatched to next module&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: dmz&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 12:50:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-no-connection-one-interface-to-another/m-p/2117637#M357260</guid>
      <dc:creator>JDMJeffy84</dc:creator>
      <dc:date>2013-01-31T12:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.4 no connection one interface to another</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-no-connection-one-interface-to-another/m-p/2117638#M357261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your ASA says that the traffic should work. What config do you have regarding interface "fw-mgmt"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And test again and show the corresponding log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 13:50:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-no-connection-one-interface-to-another/m-p/2117638#M357261</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-01-31T13:50:05Z</dc:date>
    </item>
  </channel>
</rss>

