<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic communication between same security levels in ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/communication-between-same-security-levels-in-asa/m-p/1936890#M458279</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rakesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You already told us you have the&amp;nbsp;&amp;nbsp; permit inter-interface command and also nat control disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You also told us you have the default setting on your asa so if that is true you should not have the inspection for the ICMP protocol.&lt;/P&gt;&lt;P&gt;Please add the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -fixup protocol icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then give it a try:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also provide the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input inside icmp 10.0.0.2 8 0 10.0.4.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="text-decoration: underline; "&gt;Do rate all the helpful posts&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Mar 2012 17:44:16 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-03-12T17:44:16Z</dc:date>
    <item>
      <title>communication between same security levels in ASA</title>
      <link>https://community.cisco.com/t5/network-security/communication-between-same-security-levels-in-asa/m-p/1936887#M458274</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing communication issue between the same security level. I have created two security zones with same security level &amp;amp; i have also configured the command same-security-traffic permit inter-interface &amp;amp; nat-control is disabled by default. But i am not able to communicate between same security level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i have checked the logs using sh logging coomand following output will come:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-6-302020: Built inbound ICMP connection for faddr 10.0.0.28/14 gaddr 10.0.4.1/0 laddr 10.0.4.1/0&lt;/P&gt;&lt;P&gt;%ASA-6-110003: Routing failed to locate next hop for icmp from HR:10.0.4.1/0 to HR:10.0.0.28/0&lt;/P&gt;&lt;P&gt;%ASA-6-302021: Teardown ICMP connection for faddr 10.0.0.28/14 gaddr 10.0.4.1/0 laddr 10.0.4.1/0&lt;/P&gt;&lt;P&gt;%ASA-3-219002: i2c_read_byte_w_suspend() error, slot = 0x4, device = 0xb0, address = 0x0, byte count = 1. Reason: I2C_SMBUS_UNSUPPORT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ASA lab configuration:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 2.2.2.1 255.255.255.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.1&lt;/P&gt;&lt;P&gt; vlan 2&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.0.0.1 255.255.252.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.2&lt;/P&gt;&lt;P&gt; vlan 3&lt;/P&gt;&lt;P&gt; nameif HR&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.0.4.1 255.255.252.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rest configuration is default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:40:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/communication-between-same-security-levels-in-asa/m-p/1936887#M458274</guid>
      <dc:creator>rakeshjss123</dc:creator>
      <dc:date>2019-03-11T22:40:37Z</dc:date>
    </item>
    <item>
      <title>communication between same security levels in ASA</title>
      <link>https://community.cisco.com/t5/network-security/communication-between-same-security-levels-in-asa/m-p/1936888#M458275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to be sure - I would configure a nat-exemption rule.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 15:47:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/communication-between-same-security-levels-in-asa/m-p/1936888#M458275</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2012-03-12T15:47:22Z</dc:date>
    </item>
    <item>
      <title>communication between same security levels in ASA</title>
      <link>https://community.cisco.com/t5/network-security/communication-between-same-security-levels-in-asa/m-p/1936889#M458277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can also add the following commands to allow the same security interface to talk to each other:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and let us know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kimberly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 16:57:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/communication-between-same-security-levels-in-asa/m-p/1936889#M458277</guid>
      <dc:creator>Kimberly Adams</dc:creator>
      <dc:date>2012-03-12T16:57:13Z</dc:date>
    </item>
    <item>
      <title>communication between same security levels in ASA</title>
      <link>https://community.cisco.com/t5/network-security/communication-between-same-security-levels-in-asa/m-p/1936890#M458279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rakesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You already told us you have the&amp;nbsp;&amp;nbsp; permit inter-interface command and also nat control disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You also told us you have the default setting on your asa so if that is true you should not have the inspection for the ICMP protocol.&lt;/P&gt;&lt;P&gt;Please add the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -fixup protocol icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then give it a try:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also provide the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input inside icmp 10.0.0.2 8 0 10.0.4.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="text-decoration: underline; "&gt;Do rate all the helpful posts&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Mar 2012 17:44:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/communication-between-same-security-levels-in-asa/m-p/1936890#M458279</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-03-12T17:44:16Z</dc:date>
    </item>
  </channel>
</rss>

