<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Connections routing between two internal ASA's fail in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/connections-routing-between-two-internal-asa-s-fail/m-p/1907534#M436522</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No assumptions are needed, what we have is exactly what is in the shown inserted image.&amp;nbsp; Without a doubt routing is working, because if it wasn't.&amp;nbsp; Ping would also fail.&amp;nbsp; But we can ping fine.&amp;nbsp; What would a default route have anything to do with this problem?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What details would be needed?&amp;nbsp; Again, the remote MPLS nodes are recieving connections from this site.&amp;nbsp; Something is failing between both ASA's or the traffic in and out of this site.&amp;nbsp; That is proventing the connection to establish all the way. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 20 May 2012 22:45:24 GMT</pubDate>
    <dc:creator>nickhesson</dc:creator>
    <dc:date>2012-05-20T22:45:24Z</dc:date>
    <item>
      <title>Connections routing between two internal ASA's fail</title>
      <link>https://community.cisco.com/t5/network-security/connections-routing-between-two-internal-asa-s-fail/m-p/1907532#M436517</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem that I can not fix.&amp;nbsp; We have a site with two inbound circuits, one for internet and one for our MPLS.&amp;nbsp; Each circuit is being terminated by a 2921 Router and matching ASA 5510 Firewall.&amp;nbsp; For the internal network, the Internet ASA's inside interface (172.16.0.1) is the default gateway for all hosts.&amp;nbsp; OSPF is the routing protocol between all the routers and ASA's and routing is working.&amp;nbsp; In fact, ICMP is working as well.&amp;nbsp; From an inside host (172.16.0.81), we can ping anything on the MPLS network.&amp;nbsp; But when I try to use telnet (for example), the connection fails.&amp;nbsp; If I add a route to 10.10.10.0 to the host, or re-configure the host to point to the MPLS ASA (172.16.0.254) as it's default gateway, connections will establish.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/9/8/8/89889-Connection%20Problems.jpg" alt="Connection Problems.jpg" class="jive-image-thumbnail jive-image" onclick="" style="display: block; margin-left: auto; margin-right: auto;" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both ASAs are running 8.4(3), and have the following commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;same-security-traffic permit intra-interface&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Ethernet0/0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; nameif outside&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; security-level 0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;interface Ethernet0/1.1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; vlan 10&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; nameif inside&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; security-level 100&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And for now, and for testing, the MPLS ASA has this Access-List:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;access-list Outside_ACL extended permit ip any any&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I have found is this, if we point directly to the &lt;STRONG&gt;MPLS ASA&lt;/STRONG&gt;, connections are created successfully.&amp;nbsp; When poining to the &lt;STRONG&gt;Internet ASA&lt;/STRONG&gt;, only ping works and all other connection types fail to succeed (at lease TCP, have not tried udp applications).&amp;nbsp; If looking on both ASA's, i see a connection made:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA01# &lt;STRONG&gt;show conn all&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;TCP inside 10.10.10.10:443 inside 172.16.0.81:56192, idle 0:00:02, bytes 0, flags SaAB&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And from the MPLS nodes, I can see a tcp request is made.&amp;nbsp; So i'm guessing the problem is between the ASA's?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am I missing?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help,&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:09:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connections-routing-between-two-internal-asa-s-fail/m-p/1907532#M436517</guid>
      <dc:creator>nickhesson</dc:creator>
      <dc:date>2019-03-11T23:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Connections routing between two internal ASA's fail</title>
      <link>https://community.cisco.com/t5/network-security/connections-routing-between-two-internal-asa-s-fail/m-p/1907533#M436520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My assumption is that you have a single site with dual connections.  Please can you confirm the routing in those LANs and specifically the default route? You have highlighted the issue. However, you may need to furnish some detailed information to show the existing implementation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 May 2012 21:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connections-routing-between-two-internal-asa-s-fail/m-p/1907533#M436520</guid>
      <dc:creator>ju_mobile</dc:creator>
      <dc:date>2012-05-20T21:55:19Z</dc:date>
    </item>
    <item>
      <title>Connections routing between two internal ASA's fail</title>
      <link>https://community.cisco.com/t5/network-security/connections-routing-between-two-internal-asa-s-fail/m-p/1907534#M436522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No assumptions are needed, what we have is exactly what is in the shown inserted image.&amp;nbsp; Without a doubt routing is working, because if it wasn't.&amp;nbsp; Ping would also fail.&amp;nbsp; But we can ping fine.&amp;nbsp; What would a default route have anything to do with this problem?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What details would be needed?&amp;nbsp; Again, the remote MPLS nodes are recieving connections from this site.&amp;nbsp; Something is failing between both ASA's or the traffic in and out of this site.&amp;nbsp; That is proventing the connection to establish all the way. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 May 2012 22:45:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connections-routing-between-two-internal-asa-s-fail/m-p/1907534#M436522</guid>
      <dc:creator>nickhesson</dc:creator>
      <dc:date>2012-05-20T22:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: Connections routing between two internal ASA's fail</title>
      <link>https://community.cisco.com/t5/network-security/connections-routing-between-two-internal-asa-s-fail/m-p/1907535#M436524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apologies,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't see any image may be my device. You highlighted and I don't know your network so have to either make an assumption or ask further questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a site with two inbound circuits, one for internet and one for our MPLS.  Each circuit is being terminated by a 2921 Router and matching ASA 5510 Firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my assumption is that you have a single site with an internet connection and interconnect back into the wan.&lt;/P&gt;&lt;P&gt;Wan----&lt;DEL&gt;router&lt;/DEL&gt;&lt;DEL&gt;-5510&lt;/DEL&gt;--&lt;DEL&gt;-local lan&lt;/DEL&gt;--&lt;DEL&gt;-5510&lt;/DEL&gt;--&lt;DEL&gt;router&lt;/DEL&gt;--&lt;/P&gt;&lt;HR originaltext="----" /&gt;&lt;P&gt;www is my assumption correct?&lt;/P&gt;&lt;P&gt;                                              172.16.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you running single or multiple ospf instances ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you add a static route via the wan asa your telnet works. Smells like the traffics hitting the wrong firewall. &lt;/P&gt;&lt;P&gt;Have you run a debug to verify if that is the case or do you see the deny in your logs on the wan firewall?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2012 23:09:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connections-routing-between-two-internal-asa-s-fail/m-p/1907535#M436524</guid>
      <dc:creator>ju_mobile</dc:creator>
      <dc:date>2012-05-21T23:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: Connections routing between two internal ASA's fail</title>
      <link>https://community.cisco.com/t5/network-security/connections-routing-between-two-internal-asa-s-fail/m-p/1907536#M436526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry Ju_Moblie,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do appreciate the attempt to help.&amp;nbsp; But if you read the whole post, you will see that we're getting connection attempts at the device on the MPLS network.&amp;nbsp; Futhermore, if routing was the issue, Pings would also fail!!!&amp;nbsp; So Once and for all, Routing is not the issue.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see the traffic pass over both internet and MPLS ASAs, and hit the device on the MPLS side.&amp;nbsp; But the connection never finishes and ICMP works fine.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone else that can see the image, possibly get me a clue?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time and help,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 00:49:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connections-routing-between-two-internal-asa-s-fail/m-p/1907536#M436526</guid>
      <dc:creator>nickhesson</dc:creator>
      <dc:date>2012-05-23T00:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Connections routing between two internal ASA's fail</title>
      <link>https://community.cisco.com/t5/network-security/connections-routing-between-two-internal-asa-s-fail/m-p/1907537#M436531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have asymmetric routing in your network, which is not supported with ASA firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the way to the remote site, the packet will travel:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Host -&amp;gt; Internet ASA -&amp;gt; MPLS ASA -&amp;gt; MPLS router -&amp;gt; remote host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But since the inside interface of the MPLS ASA is in the same subnet as the host, the packet back travels:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;remote host -&amp;gt; MPLS router -&amp;gt; MPLS ASA -&amp;gt; host. (It skips the internet ASA).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the connection to the MPLS ASA was orignally build from the internet ASA, this will fail.&lt;/P&gt;&lt;P&gt;Ping is not a 3-way handshake, but rather the echo and echo reply are 2 seperate flows. The ASA does not by default build a connection for that (it only does if you enable ICMP inspection). Therefor ping will work. UDP will also work because of the same reason.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 07:34:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connections-routing-between-two-internal-asa-s-fail/m-p/1907537#M436531</guid>
      <dc:creator>Marcel Verbruggen - Pennings</dc:creator>
      <dc:date>2012-05-23T07:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: Connections routing between two internal ASA's fail</title>
      <link>https://community.cisco.com/t5/network-security/connections-routing-between-two-internal-asa-s-fail/m-p/1907538#M436533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;THANK YOU!&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That fixed the problem!&amp;nbsp; All anyone would have to tell me was asymmetric routing.&amp;nbsp; Below fixed my problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;EM&gt;access-list MPLS_IN extended permit ip 172.16.0.0 255.255.0.0 10.10.0.0 255.255.0.0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;EM&gt;class-map MPLS_IN&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; &lt;SPAN style="font-family: Calibri; font-size: 11pt;"&gt;match access-list MPLS_IN&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-family: Calibri; font-size: 11pt;"&gt;policy-map MPLS_IN&lt;/SPAN&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;EM&gt; class MPLS_IN&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; &lt;SPAN style="font-family: Calibri; font-size: 11pt;"&gt;set connection advanced-options tcp-state-bypass&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;EM&gt;service-policy MPLS_IN interface inside&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 20:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/connections-routing-between-two-internal-asa-s-fail/m-p/1907538#M436533</guid>
      <dc:creator>nickhesson</dc:creator>
      <dc:date>2012-05-23T20:40:34Z</dc:date>
    </item>
  </channel>
</rss>

