<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't get traffic flowing between VLANs on an ASA 5505 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036738#M439125</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately that did not make it work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping 16jda 10.105.11.6 still gives the following error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6|Aug 22 2012 06:55:23|110003: Routing failed to locate next hop for icmp from NP Identity Ifc:10.16.2.1/0 to 16jda:10.105.11.6/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, for some reason, the ASDM java app freezes at the "Discovering Device Version..." stage when I try to open it. I can still ssh in though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the current config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 Aug 2012 19:06:03 GMT</pubDate>
    <dc:creator>timschwartz1</dc:creator>
    <dc:date>2012-08-22T19:06:03Z</dc:date>
    <item>
      <title>Can't get traffic flowing between VLANs on an ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036729#M439116</link>
      <description>&lt;P&gt;I've got an ASA 5505 with the Security Plus license that I'm trying to configure.&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #000000; font-family: verdana, geneva, lucida, 'lucida grande', arial, helvetica, sans-serif; background-color: #dfeaef;" /&gt;&lt;/P&gt;&lt;P&gt;So far I have setup NATing on two VLANs, one called 16jda (VLAN 16 - 10.16.2.0/24) and one called 16jdc (VLAN 11 - 10.105.11.0/24).&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #000000; font-family: verdana, geneva, lucida, 'lucida grande', arial, helvetica, sans-serif; background-color: #dfeaef;" /&gt;&lt;/P&gt;&lt;P&gt;From each subnet I am able to connect to the internet, but I need these subnets to also be able to talk to each other.&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #000000; font-family: verdana, geneva, lucida, 'lucida grande', arial, helvetica, sans-serif; background-color: #dfeaef;" /&gt;&lt;/P&gt;&lt;P&gt;I have each VLAN interface at security level 100 and enabled "same-security-traffic permit inter-interface", and I have setup static NAT mappings between the two subnets, but they still can't communicate.&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #000000; font-family: verdana, geneva, lucida, 'lucida grande', arial, helvetica, sans-serif; background-color: #dfeaef;" /&gt;&lt;/P&gt;&lt;P&gt;When I try to ping there is no reply and the only log message is:&lt;/P&gt;&lt;P&gt;6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Aug 21 2012&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;09:00:54&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;302020&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;10.16.2.10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;23336&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;10.105.11.6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Built inbound ICMP connection for faddr 10.16.2.10/23336 gaddr 10.105.11.6/0 laddr 10.105.11.6/0&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #000000; font-family: verdana, geneva, lucida, 'lucida grande', arial, helvetica, sans-serif; background-color: #dfeaef;" /&gt;&lt;/P&gt;&lt;P&gt;I have attached a copy of the router config.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036729#M439116</guid>
      <dc:creator>timschwartz1</dc:creator>
      <dc:date>2019-03-11T23:44:49Z</dc:date>
    </item>
    <item>
      <title>Can't get traffic flowing between VLANs on an ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036730#M439117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On a trunk is the following :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"same-security-traffic permit intra-interface"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2012 23:41:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036730#M439117</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-08-21T23:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic flowing between VLANs on an ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036731#M439118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;Please do this, and let me know how it goes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;config t&lt;/P&gt;&lt;P&gt;clear configure access-list acl&lt;/P&gt;&lt;P&gt;access-list inside permit ip any any&lt;BR /&gt;access-list outside permit ip any any&lt;BR /&gt;access-list 16jda permit ip any any&lt;BR /&gt;access-list 16jdc permit ip any any&lt;/P&gt;&lt;P&gt;access-group 16jdc in interface 16jdc&lt;BR /&gt;access-group 16jda in interface 16jda&lt;BR /&gt;access-group outside in interface outside&lt;BR /&gt;access-group inside in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list no-nat extended permit ip 10.105.0.0 255.255.0.0 10.16.0.0 255.255.0.0 &lt;BR /&gt;no access-list no-nat extended permit ip 10.16.0.0 255.255.0.0 10.105.0.0 255.255.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no nat (16jdc) 0 access-list no-nat&lt;BR /&gt;no nat (16jdc) 1 access-list acl&lt;BR /&gt;no nat (16jda) 0 access-list no-nat&lt;BR /&gt;no nat (16jda) 1 access-list acl&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;no static (16jdc,16jda) 10.105.11.0 10.105.11.0 netmask 255.255.255.0 &lt;BR /&gt;no static (16jda,16jdc) 10.16.2.0 10.16.2.0 netmask 255.255.255.0 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P/S: If you think this comment is useful, please do rate them nicely &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2012 03:55:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036731#M439118</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-08-22T03:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic flowing between VLANs on an ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036732#M439119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt;&lt;SPAN style="background-color: #f7fafb; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;On a trunk is the following :&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif; min-height: 8pt; height: 8pt;"&gt;&amp;gt;"same-security-traffic permit intra-interface"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the suggestion, but that didn't work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2012 05:27:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036732#M439119</guid>
      <dc:creator>timschwartz1</dc:creator>
      <dc:date>2012-08-22T05:27:03Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic flowing between VLANs on an ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036733#M439120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Thank you, &lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;I tried making these changes, but it stil doesn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;When I run the command "ping 16jda 10.105.11.6" on the firewall I get this message in the log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;Aug 21 2012&lt;/TD&gt;&lt;TD&gt;17:22:01&lt;/TD&gt;&lt;TD&gt;110003&lt;/TD&gt;&lt;TD&gt;10.16.2.1&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;10.105.11.6&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;Routing failed to locate next hop for icmp from NP Identity Ifc:10.16.2.1/0 to 16jda:10.105.11.6/0&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2012 05:30:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036733#M439120</guid>
      <dc:creator>timschwartz1</dc:creator>
      <dc:date>2012-08-22T05:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic flowing between VLANs on an ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036734#M439121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you have changed your config, if you want help from us you will need to attach it or post it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2012 05:35:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036734#M439121</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-08-22T05:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic flowing between VLANs on an ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036735#M439122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you paste your latest config here, so that everyone here can assist you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2012 06:19:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036735#M439122</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-08-22T06:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic flowing between VLANs on an ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036736#M439123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the current config:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2012 15:34:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036736#M439123</guid>
      <dc:creator>timschwartz1</dc:creator>
      <dc:date>2012-08-22T15:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic flowing between VLANs on an ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036737#M439124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;I know your problem and I know exactly how to solve it too. You could refer to &lt;A _jive_internal="true" href="https://community.cisco.com/message/3714412#3714412" rel="nofollow"&gt;https://supportforums.cisco.com/message/3714412#3714412&lt;/A&gt; for further details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Moving forward, this is what you’re gonna paste in your FW. This should work like a charm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list from-inside permit ip 10.105.1.0 255.255.255.0 10.105.11.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list from-inside permit ip 10.105.1.0 255.255.255.0 10.16.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list from-16jda permit ip 10.16.2.0 255.255.255.0 10.105.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list from-16jda permit ip 10.16.2.0 255.255.255.0 10.105.11.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list from-16jdc permit ip 10.105.11.0 255.255.255.0 10.105.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list from-16jdc permit ip 10.105.11.0 255.255.255.0 10.16.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list from-inside&lt;/P&gt;&lt;P&gt;nat (16jdc) 0 access-list from-16jdc&lt;/P&gt;&lt;P&gt;nat (16jda) 0 access-list from-16jda&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.105.1.0 255.255.255.0 &amp;lt;-- You forgot this!!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically, when inside wants to communicate with the other interfaces bearing security-level 100 e.g. 16jda or 16jdc or vice-versa, you’ll need to enable “NAT Exemption” i.e. nat (nameif) 0 &lt;ACCESS-LIST&gt;. I know you have already enabled the same-security permit inter-interface command, but this command becomes useless once you’ve enable dynamic nat on one of those interfaces. It’s as if the same-security traffic command wasn't even entered in the first place. Hence, the Cisco ASA is behaving as expected as per Cisco's documentation. For further details on this, you could refer to the URLs below;&lt;/ACCESS-LIST&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/thread/223898" rel="nofollow"&gt;https://supportforums.cisco.com/thread/223898&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/cfgnat.html#wp1042530" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/cfgnat.html#wp1042530&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2012 16:47:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036737#M439124</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-08-22T16:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic flowing between VLANs on an ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036738#M439125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately that did not make it work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping 16jda 10.105.11.6 still gives the following error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6|Aug 22 2012 06:55:23|110003: Routing failed to locate next hop for icmp from NP Identity Ifc:10.16.2.1/0 to 16jda:10.105.11.6/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, for some reason, the ASDM java app freezes at the "Discovering Device Version..." stage when I try to open it. I can still ssh in though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the current config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2012 19:06:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036738#M439125</guid>
      <dc:creator>timschwartz1</dc:creator>
      <dc:date>2012-08-22T19:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic flowing between VLANs on an ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036739#M439126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your config looks good to me. Can you confirm all those devices in inside, 16jda and 16jdc can access the internet? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2012 21:00:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036739#M439126</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-08-22T21:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: Can't get traffic flowing between VLANs on an ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036740#M439127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just checked the test device in VLAN 11 and realized that it did not have a default gateway set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The changes you made work, thanks for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2012 21:12:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036740#M439127</guid>
      <dc:creator>timschwartz1</dc:creator>
      <dc:date>2012-08-22T21:12:15Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036741#M439128</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have ASA 5505 with 3 VLANs but they are unable to communicate. please advise.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;following is the configuration.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HAWK-ASA# sh run&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 8.2(5) &lt;BR /&gt;!&lt;BR /&gt;hostname HAWK-ASA&lt;BR /&gt;domain-name hsmea.com&lt;BR /&gt;enable password A4KROCQZQWlF.ct5 encrypted&lt;BR /&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; description WAN OUTSIDE&lt;BR /&gt; switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt; description LAN INSIDE&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt; description Servers-Vlan&lt;BR /&gt; switchport access vlan 10&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt; description Voice Gateway 2811&lt;BR /&gt; switchport access vlan 10&lt;BR /&gt; shutdown&lt;BR /&gt;! &lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.1.254 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt; description OUTSIDE INTERFACE PPPOE&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; pppoe client vpdn group hawksol&lt;BR /&gt; ip address pppoe setroute &lt;BR /&gt;!&lt;BR /&gt;interface Vlan10&lt;BR /&gt; no forward interface Vlan1&lt;BR /&gt; nameif DMZ&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 10.172.192.254 255.255.255.0 &lt;BR /&gt;! &lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone GST 4&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt; domain-name hsmea.com&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object-group network HAWK_BURDUBAI_LAN&lt;BR /&gt; network-object 192.168.172.0 255.255.255.0&lt;BR /&gt;object-group network HAWK_HQ_LAN&lt;BR /&gt; network-object 192.168.1.0 255.255.255.0&lt;BR /&gt;access-list HAWKSOL_VPN_TRAFFIC extended permit ip 192.168.172.0 255.255.255.0 192.168.1.0 255.255.255.0 &lt;BR /&gt;access-list NO-NAT-TRAFFIC extended permit ip 192.168.172.0 255.255.255.0 192.168.1.0 255.255.255.0 &lt;BR /&gt;access-list outside_access_in extended permit tcp any interface outside eq 3389 &lt;BR /&gt;access-list outside_access_in extended permit icmp any any &lt;BR /&gt;access-list LANtoDMZ extended permit ip 192.168.1.0 255.255.255.0 10.172.192.0 255.255.255.0 &lt;BR /&gt;access-list DMZtoLAN extended permit ip 10.172.192.0 255.255.255.0 192.168.1.0 255.255.255.0 &lt;BR /&gt;pager lines 24&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu DMZ 1500 &lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 0 access-list LANtoDMZ&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;nat (DMZ) 0 access-list DMZtoLAN&lt;BR /&gt;static (inside,outside) tcp interface 3389 192.168.1.110 3389 netmask 255.255.255.255 &lt;BR /&gt;access-group outside_access_in in interface outside&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside&lt;BR /&gt;http 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec transform-set MYSET esp-3des esp-sha-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac &lt;BR /&gt;crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac &lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;crypto map OUTSIDE_MAP 1 match address HAWKSOL_VPN_TRAFFIC&lt;BR /&gt;crypto map OUTSIDE_MAP 1 set pfs &lt;BR /&gt;crypto map OUTSIDE_MAP 1 set peer 86.96.28.55 &lt;BR /&gt;crypto map OUTSIDE_MAP 1 set transform-set MYSET&lt;BR /&gt;crypto map OUTSIDE_MAP interface outside&lt;BR /&gt;crypto isakmp policy 10&lt;BR /&gt; authentication pre-share&lt;BR /&gt; encryption 3des&lt;BR /&gt; hash sha&lt;BR /&gt; group 2&lt;BR /&gt; lifetime 86400&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;ssh timeout 60&lt;BR /&gt;console timeout 0&lt;BR /&gt;vpdn group hawksol request dialout pppoe&lt;BR /&gt;vpdn group hawksol localname nh1304&lt;BR /&gt;vpdn group hawksol ppp authentication pap&lt;BR /&gt;vpdn username nh1304 password ***** &lt;BR /&gt;dhcpd dns 8.8.8.8&lt;BR /&gt;dhcpd auto_config outside&lt;BR /&gt;dhcpd option 150 ip 10.172.192.1&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 192.168.1.50-192.168.1.80 inside&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;ntp server 128.138.141.172 source outside&lt;BR /&gt;webvpn&lt;BR /&gt;username admin password FSSr.BWCYVdYyR3l encrypted privilege 15&lt;BR /&gt;tunnel-group HAWKSOL-BURDUBAI-HQ-VPN type ipsec-l2l&lt;BR /&gt;tunnel-group HAWKSOL-BURDUBAI-HQ-VPN ipsec-attributes&lt;BR /&gt; pre-shared-key *****&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;! &lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt; message-length maximum client auto&lt;BR /&gt; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt; inspect dns preset_dns_map &lt;BR /&gt; inspect ftp &lt;BR /&gt; inspect h323 h225 &lt;BR /&gt; inspect h323 ras &lt;BR /&gt; inspect rsh &lt;BR /&gt; inspect rtsp &lt;BR /&gt; inspect esmtp &lt;BR /&gt; inspect sqlnet &lt;BR /&gt; inspect skinny &lt;BR /&gt; inspect sunrpc &lt;BR /&gt; inspect xdmcp &lt;BR /&gt; inspect sip &lt;BR /&gt; inspect netbios &lt;BR /&gt; inspect tftp &lt;BR /&gt; inspect ip-options &lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;Cryptochecksum:15b8c30eecfa8f169bc7c2d0e706d255&lt;BR /&gt;: end&lt;BR /&gt;ASA#&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2016 08:55:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-get-traffic-flowing-between-vlans-on-an-asa-5505/m-p/2036741#M439128</guid>
      <dc:creator>haider.rizwan</dc:creator>
      <dc:date>2016-01-28T08:55:00Z</dc:date>
    </item>
  </channel>
</rss>

