<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Eveybody , in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/finding-the-route-used-for-specified-destination-ip/m-p/1825760#M491569</link>
    <description>&lt;P&gt;Hi Eveybody ,&lt;/P&gt;
&lt;P&gt;I am seaching on the same topic . &amp;nbsp;ASA requires you identify the interface which is impossible in my case also due to the large number of interfaces&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any idea please&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Nov 2015 17:02:20 GMT</pubDate>
    <dc:creator>Mostafa Elmokadem</dc:creator>
    <dc:date>2015-11-11T17:02:20Z</dc:date>
    <item>
      <title>Finding the route used for specified destination IP</title>
      <link>https://community.cisco.com/t5/network-security/finding-the-route-used-for-specified-destination-ip/m-p/1825755#M491555</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm rather new to the ASA box. recently I tried to use:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa#show ip route &amp;lt;dest_ip&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which is not an asa command, ok. But show route does not accept parameter as an destination ip address. I have many outgoing interfaces (20 or so) which are only interconnecting networks /28. And behind them I have many other networks. I have hundred or so static route specified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I want easily verify used route (and I do not want to check it manually).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use an ASA SW version 8.4.2&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:47:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/finding-the-route-used-for-specified-destination-ip/m-p/1825755#M491555</guid>
      <dc:creator>Martin Jaburek</dc:creator>
      <dc:date>2019-03-26T00:47:41Z</dc:date>
    </item>
    <item>
      <title>Finding the route used for specified destination IP</title>
      <link>https://community.cisco.com/t5/network-security/finding-the-route-used-for-specified-destination-ip/m-p/1825756#M491558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi martin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you please try the following? " i " stands for include. then followed by the destination IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FW1# sh route | i 192.168.0.0&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.0.0 255.255.255.0 [1/0] via 82.12.10.15, outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate this post if it is helpful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Vipin&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Dec 2011 09:58:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/finding-the-route-used-for-specified-destination-ip/m-p/1825756#M491558</guid>
      <dc:creator>vipinrajrc</dc:creator>
      <dc:date>2011-12-07T09:58:25Z</dc:date>
    </item>
    <item>
      <title>Finding the route used for specified destination IP</title>
      <link>https://community.cisco.com/t5/network-security/finding-the-route-used-for-specified-destination-ip/m-p/1825757#M491560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;this will actually help. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is not exactly what I was looking for - it needs some refinement in case of suppernetting, but it is viable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there an alternative to #show ip route &lt;IP&gt; ?&lt;/IP&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Dec 2011 10:14:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/finding-the-route-used-for-specified-destination-ip/m-p/1825757#M491560</guid>
      <dc:creator>Martin Jaburek</dc:creator>
      <dc:date>2011-12-07T10:14:06Z</dc:date>
    </item>
    <item>
      <title>Finding the route used for specified destination IP</title>
      <link>https://community.cisco.com/t5/network-security/finding-the-route-used-for-specified-destination-ip/m-p/1825758#M491562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Martin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you try this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOCMEFW1# sh route outside 10.55.44.0&lt;/P&gt;&lt;P&gt;Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * - candidate default, U - per-user static route, o - ODR&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; P - periodic downloaded static route&lt;/P&gt;&lt;P&gt;Gateway of last resort is 12.24.9.4 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.55.55.0 255.255.255.0 [1/0] via 21.10.1.23, outside&lt;BR /&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.55.44.0 255.255.255.0 [1/0] via 21.10.1.23, outside&lt;BR /&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.66.1.0 255.255.255.0 [1/0] via 21.10.1.23, outside&lt;BR /&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.55.77.0 255.255.255.0 [11/0] via 21.10.1.23, outside&lt;BR /&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.55.66.0 255.255.255.0 [1/0] via 21.10.1.23, outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate this post if it is helpful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Vipin &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Dec 2011 10:28:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/finding-the-route-used-for-specified-destination-ip/m-p/1825758#M491562</guid>
      <dc:creator>vipinrajrc</dc:creator>
      <dc:date>2011-12-07T10:28:43Z</dc:date>
    </item>
    <item>
      <title>Finding the route used for specified destination IP</title>
      <link>https://community.cisco.com/t5/network-security/finding-the-route-used-for-specified-destination-ip/m-p/1825759#M491565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;unfortunately, this is not at all useful.&lt;/P&gt;&lt;P&gt;a) you must specify outgoing interface - that is exatly what I would like to avoid (I have too many of them)&lt;/P&gt;&lt;P&gt;b) as you can see even if you specified the IP address it actually printed out all configured routes on that interface&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Dec 2011 10:36:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/finding-the-route-used-for-specified-destination-ip/m-p/1825759#M491565</guid>
      <dc:creator>Martin Jaburek</dc:creator>
      <dc:date>2011-12-07T10:36:24Z</dc:date>
    </item>
    <item>
      <title>Hi Eveybody ,</title>
      <link>https://community.cisco.com/t5/network-security/finding-the-route-used-for-specified-destination-ip/m-p/1825760#M491569</link>
      <description>&lt;P&gt;Hi Eveybody ,&lt;/P&gt;
&lt;P&gt;I am seaching on the same topic . &amp;nbsp;ASA requires you identify the interface which is impossible in my case also due to the large number of interfaces&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any idea please&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Nov 2015 17:02:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/finding-the-route-used-for-specified-destination-ip/m-p/1825760#M491569</guid>
      <dc:creator>Mostafa Elmokadem</dc:creator>
      <dc:date>2015-11-11T17:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: Finding the route used for specified destination IP</title>
      <link>https://community.cisco.com/t5/network-security/finding-the-route-used-for-specified-destination-ip/m-p/3386285#M491572</link>
      <description>&lt;P&gt;The best way is to first check for a traceroute to the specific IP address, it will show you the egress interface.&lt;/P&gt;
&lt;P&gt;STEP 1.&lt;/P&gt;
&lt;P&gt;ASAt# traceroute 53.45.23.1&lt;BR /&gt;Tracing the route to 53.45.23.1&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;1&amp;nbsp; 172.24.120.10 0 msec 0 msec 0 msec&amp;nbsp; &amp;gt;&amp;gt; This is your next hop IP&lt;BR /&gt;&amp;nbsp;2&amp;nbsp; 172.24.222.245 0 msec 0 msec 0 msec&lt;/P&gt;
&lt;P&gt;STEP 2. Create an arp entry using next hop&lt;/P&gt;
&lt;P&gt;ping 172.24.120.10&lt;/P&gt;
&lt;P&gt;STEP3. Check arp to find egress interface&lt;/P&gt;
&lt;P&gt;ASA# show arp | in 172.24.120.10&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.24.120.10 4055.3909.2c41 1961 &amp;gt;&amp;gt; This is your egress interface (inside/outside etc.)&lt;/P&gt;
&lt;P&gt;STEP4. Now find for the longest match (manually)&lt;/P&gt;
&lt;P&gt;ASA# show route inside&lt;BR /&gt;&lt;BR /&gt;Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * - candidate default, U - per-user static route, o - ODR&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; P - periodic downloaded static route&lt;BR /&gt;&lt;BR /&gt;Gateway of last resort is 172.24.120.9 to network 0.0.0.0&lt;BR /&gt;&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.24.120.8 255.255.255.248 is directly connected, inside&lt;BR /&gt;S*&amp;nbsp;&amp;nbsp; 0.0.0.0 0.0.0.0 [1/0] via 172.24.120.9, inside&amp;nbsp; &amp;gt;&amp;gt; This will be the longest match&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this will help you.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 07:57:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/finding-the-route-used-for-specified-destination-ip/m-p/3386285#M491572</guid>
      <dc:creator>arun.surendran</dc:creator>
      <dc:date>2018-05-21T07:57:37Z</dc:date>
    </item>
  </channel>
</rss>

