<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Routing and ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/routing-and-asa/m-p/743975#M422219</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to use an ASA (7.2) as the DG for clients on a single subnet site. The site does not have a router that i have access to. However, the site also has dedicated circuit connected to the LAN allowing access to several remote sites. However, i have no control of the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to add routes on the inside interface of the ASA directing selected traffic to the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, despite setting same-security-traffic inter-interface. I still have problems. Despite explicitly allowing the traffic i see the following syslog messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;106015|LAN_IP|REMOTE_IP|Deny TCP (no connection) from LAN_IP/3422 to REMOTE_IP/80 flags RST on interface Inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My questions are - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Is what im trying to do possible&lt;/P&gt;&lt;P&gt;2) If yes, what do i need to do to enable it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 09:31:32 GMT</pubDate>
    <dc:creator>serotonin888</dc:creator>
    <dc:date>2020-02-21T09:31:32Z</dc:date>
    <item>
      <title>Routing and ASA</title>
      <link>https://community.cisco.com/t5/network-security/routing-and-asa/m-p/743975#M422219</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to use an ASA (7.2) as the DG for clients on a single subnet site. The site does not have a router that i have access to. However, the site also has dedicated circuit connected to the LAN allowing access to several remote sites. However, i have no control of the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to add routes on the inside interface of the ASA directing selected traffic to the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, despite setting same-security-traffic inter-interface. I still have problems. Despite explicitly allowing the traffic i see the following syslog messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;106015|LAN_IP|REMOTE_IP|Deny TCP (no connection) from LAN_IP/3422 to REMOTE_IP/80 flags RST on interface Inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My questions are - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Is what im trying to do possible&lt;/P&gt;&lt;P&gt;2) If yes, what do i need to do to enable it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:31:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-and-asa/m-p/743975#M422219</guid>
      <dc:creator>serotonin888</dc:creator>
      <dc:date>2020-02-21T09:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Routing and ASA</title>
      <link>https://community.cisco.com/t5/network-security/routing-and-asa/m-p/743976#M422220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been told this is very difficult to do.  Supposedly, you can make the ASA route "in and out" of the same interface but it's difficult and not recommended. It's much better to have a router or layer-3 switch internally and have the clients use that as their DG.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 May 2007 20:14:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-and-asa/m-p/743976#M422220</guid>
      <dc:creator>keith_chilek</dc:creator>
      <dc:date>2007-05-18T20:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Routing and ASA</title>
      <link>https://community.cisco.com/t5/network-security/routing-and-asa/m-p/743977#M422221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is intra-interface, not inter-interface to allow traffic in and out of same interface. Inter is for traffic between interfaces with same security level.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 May 2007 23:20:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-and-asa/m-p/743977#M422221</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-05-18T23:20:22Z</dc:date>
    </item>
  </channel>
</rss>

