<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Routing problems? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-routing-problems/m-p/2058375#M399997</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version are you running, I do not think you have any NAT as you are already playing with a public range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any ACL applied to the public interface on the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you place here the Configuration from both devices?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 02 Sep 2012 19:11:11 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-09-02T19:11:11Z</dc:date>
    <item>
      <title>ASA Routing problems?</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problems/m-p/2058373#M399992</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;i have a problem with Routing on ASA 5505.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a brief explanation of the topology:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DC Upstream IP: 77.246.165.141/30&lt;/P&gt;&lt;P&gt;ASA 5505 Upstream to DC IP: 77.246.165.142/30&lt;/P&gt;&lt;P&gt;Interface outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a Cisco Switch connected to one of ASA Ethernet ports, forming Public/DMZ VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA 5505 Public VLAN interface ip: 31.24.36.1/26&lt;/P&gt;&lt;P&gt;Cisco 3750 Public VLAN interface ip: 31.24.36.62, default gateway: 31.24.36.1, IP Routing enabled on Switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the Cisco Switch I can access the Internet with source ip: 31.24.36.62.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I have asked from DC additional subnet: 31.24.36.192/26 and they have it routed correctly towards the ASA Outside interface ip: 77.246.165.142.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created additional Public2 VLAN on the Switch with IP address of: 31.24.36.193/26.&lt;/P&gt;&lt;P&gt;On the ASA 5505 i added the route to this Public2 VLAN:&lt;/P&gt;&lt;P&gt;#route public 31.24.36.192 255.255.255.192 31.24.36.62 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the problem is that from the Switch with Source IP: 31.24.36.193 i can ping ASA 5505 Public VLAN IP: 31.24.36.1 so the routing between subnets 31.24.36.0/26 and 31.24.36.192/26 is working OK on both the ASA 5505 and the Switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I can't access the Internet from the Switch with Source IP: 31.24.36.193.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:48:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problems/m-p/2058373#M399992</guid>
      <dc:creator>vlatko.runchev</dc:creator>
      <dc:date>2019-03-11T23:48:47Z</dc:date>
    </item>
    <item>
      <title>ASA Routing problems?</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problems/m-p/2058374#M399994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any NAT/PAT related config missed on ASA for the new Subnet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Post the sanitized configs from ASA &amp;amp; Switch. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Sep 2012 13:42:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problems/m-p/2058374#M399994</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2012-09-02T13:42:59Z</dc:date>
    </item>
    <item>
      <title>ASA Routing problems?</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problems/m-p/2058375#M399997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version are you running, I do not think you have any NAT as you are already playing with a public range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any ACL applied to the public interface on the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you place here the Configuration from both devices?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Sep 2012 19:11:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problems/m-p/2058375#M399997</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-09-02T19:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problems?</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problems/m-p/2058376#M399999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the replies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am running:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Cisco Adaptive Security Appliance Software Version 8.2(2)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for NAT configuration, there is NAT configured between the Outside Interface IP and the Internal Subnet:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;global (outside) 1 interface&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nat (inside) 1 192.168.X.0 255.255.255.0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also there is NAT exemption configured because of the Site-to-Site IPSec VPN that we have:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nat (inside) 0 access-list inside_nat0_outbound1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;access-list inside_nat0_outbound1 extended permit ip any 192.168.X.0 255.255.255.0 &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;access-list inside_nat0_outbound1 extended permit ip 192.168.X.0 255.255.255.0 OtherSiteLAN 255.255.255.0 &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;access-list inside_nat0_outbound1 extended permit ip any 192.168.X.240 255.255.255.248 &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;access-list inside_nat0_outbound1 extended permit ip 192.168.X.0 255.255.255.128 OtherSiteLAN 255.255.255.0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't have any ACL configured on the Public interface in any direction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the configuration on the Switch regarding this scenario:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface FastEthernet2/0/X&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; description Access Port for Public Subnet(31.24.32.0/26) to ASA&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; switchport access vlan 500&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; switchport mode access&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Vlan500&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; description Public VLAN 1&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; ip address 31.24.36.62 255.255.255.192&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Vlan510&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; description Public VLAN 2&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; ip address 31.24.36.193 255.255.255.192&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; !&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ip route 0.0.0.0 0.0.0.0 31.24.36.1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the output when pinging the ASA Public Interface IP with source IP address of: 31.24.36.193(VLAN 510)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;SWITCH#ping 31.24.36.1 source vlan 510&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Type escape sequence to abort.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Sending 5, 100-byte ICMP Echos to 31.24.36.1, timeout is 2 seconds:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Packet sent with a source address of 31.24.36.193&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;!!!!!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/4/9 ms&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; And here is when I try to ping some Internet host:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;SWITCH#ping 8.8.8.8 source vlan 510&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Type escape sequence to abort.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Packet sent with a source address of 31.24.36.193&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;.....&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Success rate is 0 percent (0/5)&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2012 08:43:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problems/m-p/2058376#M399999</guid>
      <dc:creator>vlatko.runchev</dc:creator>
      <dc:date>2012-09-07T08:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problems?</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problems/m-p/2058377#M400000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you add the following command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol icmp and provide us the result&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this does not work I would like to check the entire config of both devices&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;rate all the answers, that is more important for us that a thanks&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2012 16:12:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problems/m-p/2058377#M400000</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-09-07T16:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problems?</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problems/m-p/2058378#M400001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;sorry for the late response...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;fixup protocol icmp&lt;/STRONG&gt; also didn't solved the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can this have anything related to the Base licence, that this device is having and it's 3 VLAN limitation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan500&lt;/P&gt;&lt;P&gt; no forward interface Vlan1 &lt;STRONG&gt;&amp;lt;--Private VLAN&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 12:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problems/m-p/2058378#M400001</guid>
      <dc:creator>vlatko.runchev</dc:creator>
      <dc:date>2012-11-21T12:39:28Z</dc:date>
    </item>
  </channel>
</rss>

