<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ASA problem with third public IP Address in the Subnet in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-problem-with-third-public-ip-address-in-the-subnet/m-p/2012880#M440599</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have an intressted problem with my ASA 5510 CSC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i configured many firewalls till yet and i configure the normal static often times but this time it is not working as assumed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco ASA 5510 in failover&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Public Network: is a x.x.x.128 /28&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the two ip's that are configured on the outside(.130 &amp;amp;.131) are working fine with pat and static etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but when i configure the third public ip in the subnet with a static &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; static (inside,outside) x.x.x.133 172.x.x.x netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is not working &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the firewall has an default route to the ISP Router x.x.x.129&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here a capture &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw-001(config)# sh run access-list vpn&lt;BR /&gt; access-list test extended permit tcp any host x.x.x.132 eq 3389&lt;BR /&gt; access-list test extended permit tcp host x.x.x.132 any eq 3389&lt;BR /&gt; &lt;BR /&gt; fw-at-klu-serA-001(config)# sh capture&lt;BR /&gt; capture vpn type raw-data access-list test interface outside [Capturing - 0 bytes]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i try to access a server with rdp from the outside but no hit. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i set an traceroute from an client to the .130 the fw is working, if i trace to .132 the last hop that i can see is the one hop ago the ISP onsite Router the .129&lt;/P&gt;&lt;P&gt; &lt;BR /&gt; i thought that be an routing issue on the Provider site but they told me that everything is fine, because when i connect me with a PC to the Internet VLAN and give it the ip x.x.x.132 it is working fine. The Provider also told me during the test he cannot see an arp enrtry in the ISP Router from .132&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; has somebody an idea ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Martin &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 23:21:36 GMT</pubDate>
    <dc:creator>prutejmartin</dc:creator>
    <dc:date>2019-03-11T23:21:36Z</dc:date>
    <item>
      <title>Cisco ASA problem with third public IP Address in the Subnet</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-problem-with-third-public-ip-address-in-the-subnet/m-p/2012880#M440599</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have an intressted problem with my ASA 5510 CSC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i configured many firewalls till yet and i configure the normal static often times but this time it is not working as assumed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco ASA 5510 in failover&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Public Network: is a x.x.x.128 /28&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the two ip's that are configured on the outside(.130 &amp;amp;.131) are working fine with pat and static etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but when i configure the third public ip in the subnet with a static &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; static (inside,outside) x.x.x.133 172.x.x.x netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is not working &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the firewall has an default route to the ISP Router x.x.x.129&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here a capture &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw-001(config)# sh run access-list vpn&lt;BR /&gt; access-list test extended permit tcp any host x.x.x.132 eq 3389&lt;BR /&gt; access-list test extended permit tcp host x.x.x.132 any eq 3389&lt;BR /&gt; &lt;BR /&gt; fw-at-klu-serA-001(config)# sh capture&lt;BR /&gt; capture vpn type raw-data access-list test interface outside [Capturing - 0 bytes]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i try to access a server with rdp from the outside but no hit. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i set an traceroute from an client to the .130 the fw is working, if i trace to .132 the last hop that i can see is the one hop ago the ISP onsite Router the .129&lt;/P&gt;&lt;P&gt; &lt;BR /&gt; i thought that be an routing issue on the Provider site but they told me that everything is fine, because when i connect me with a PC to the Internet VLAN and give it the ip x.x.x.132 it is working fine. The Provider also told me during the test he cannot see an arp enrtry in the ISP Router from .132&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; has somebody an idea ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Martin &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:21:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-problem-with-third-public-ip-address-in-the-subnet/m-p/2012880#M440599</guid>
      <dc:creator>prutejmartin</dc:creator>
      <dc:date>2019-03-11T23:21:36Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA problem with third public IP Address in the Subnet</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-problem-with-third-public-ip-address-in-the-subnet/m-p/2012881#M440602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Martin,&lt;/P&gt;&lt;P&gt;Can you please check your Nat again :- &lt;/P&gt;&lt;P&gt;your Static command show .133 and you are complaing about 132. Is that a typo here or is also a typo on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also can you please check the Subnet Mask on your outside interface for /28 &amp;amp; have your ISP clear arp cache on their end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manish &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jun 2012 23:36:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-problem-with-third-public-ip-address-in-the-subnet/m-p/2012881#M440602</guid>
      <dc:creator>manish arora</dc:creator>
      <dc:date>2012-06-20T23:36:36Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA problem with third public IP Address in the Subnet</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-problem-with-third-public-ip-address-in-the-subnet/m-p/2012882#M440604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Manish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;problem is resolved, the problem was that proxy arp on the outside interface was disabled !!! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thnaks for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Br,&lt;/P&gt;&lt;P&gt;Martin &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jun 2012 07:41:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-problem-with-third-public-ip-address-in-the-subnet/m-p/2012882#M440604</guid>
      <dc:creator>prutejmartin</dc:creator>
      <dc:date>2012-06-21T07:41:40Z</dc:date>
    </item>
  </channel>
</rss>

