<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Routing problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731856#M494075</link>
    <description>&lt;P&gt;I have&amp;nbsp; a problem with a routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ASA 5510 is at ip 192.168.1.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have alos a router on IP Adress 192.168.1.30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created static route on the ASA for network 10.1.1.0 and network 10.1.10.1 to the gateway 192.168.1.30.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem I cannot ping the 10.1.1.0 and 10.1.10.1 networks... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the logging I get Inbound ICMP deny message&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have open everything in the inbound Inside Interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why can't I reach those networks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My computer's gateway is the ASA 192.168.1.20. Everything else is working fine (WAN to LAN and LAN to WAN)&lt;/P&gt;&lt;P&gt;Only the LAN to LAN thing blocks...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:46:26 GMT</pubDate>
    <dc:creator>Jean-Francois Gagnon</dc:creator>
    <dc:date>2019-03-11T21:46:26Z</dc:date>
    <item>
      <title>ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731856#M494075</link>
      <description>&lt;P&gt;I have&amp;nbsp; a problem with a routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ASA 5510 is at ip 192.168.1.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have alos a router on IP Adress 192.168.1.30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created static route on the ASA for network 10.1.1.0 and network 10.1.10.1 to the gateway 192.168.1.30.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem I cannot ping the 10.1.1.0 and 10.1.10.1 networks... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the logging I get Inbound ICMP deny message&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have open everything in the inbound Inside Interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why can't I reach those networks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My computer's gateway is the ASA 192.168.1.20. Everything else is working fine (WAN to LAN and LAN to WAN)&lt;/P&gt;&lt;P&gt;Only the LAN to LAN thing blocks...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:46:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731856#M494075</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2019-03-11T21:46:26Z</dc:date>
    </item>
    <item>
      <title>ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731857#M494078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you add this??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and if it doesn.t work can you providfe th nat and acl's that you have added??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Nov 2011 17:33:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731857#M494078</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-11-04T17:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731858#M494079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I have added the inspect ICMP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created routes like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 10.1.1.0 255.255.255.0 192.168.1.30&lt;/P&gt;&lt;P&gt;route inside 10.1.10.0 255.255.255.252 192.168.1.30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a problem of nat? Do i have to create Nat rules instead of static routes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit udp any any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit icmp any any&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Nov 2011 19:02:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731858#M494079</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2011-11-04T19:02:03Z</dc:date>
    </item>
    <item>
      <title>ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731859#M494081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No if you are pinging from outside interface to inside interface, then you would need to appli these access-list on the outside interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt; access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt; alongwith the static.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know from where are you pinging, inside to outside or outside to inside??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Nov 2011 19:18:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731859#M494081</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-11-04T19:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731860#M494088</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Actually it's inside inside...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----------------------------------------------------&lt;/P&gt;&lt;P&gt;Mycomputer = 192.168.1.101&lt;/P&gt;&lt;P&gt;To Gateway = 192.168.1.20&lt;/P&gt;&lt;P&gt;Connected to subnet= 192.168.1.0&lt;/P&gt;&lt;P&gt;------------------------------------------------------&lt;/P&gt;&lt;P&gt;ASA = 192.168.1.20&lt;/P&gt;&lt;P&gt;Routes&lt;/P&gt;&lt;P&gt;route inside 10.1.1.0 255.255.255.0 192.168.1.30&lt;/P&gt;&lt;P&gt;route inside 10.1.10.0 255.255.255.252 192.168.1.30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Connected to subnet: 192.168.1.0 and WAN&lt;/P&gt;&lt;P&gt;-----------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router= 192.168.1.30&lt;/P&gt;&lt;P&gt;Connected to subnet 10.1.1.0 and 10.1.10.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it makes more sense&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Nov 2011 20:50:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731860#M494088</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2011-11-04T20:50:49Z</dc:date>
    </item>
    <item>
      <title>ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731861#M494090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then you must permit traffic entering an interface to exit the same interface with the global config command:&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Nov 2011 21:08:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731861#M494090</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-11-04T21:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731862#M494091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks I'll try this and get back to you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Nov 2011 22:39:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731862#M494091</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2011-11-04T22:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731863#M494093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;shouldn't be intra-interface ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Nov 2011 02:31:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731863#M494093</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2011-11-05T02:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731864#M494095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jean,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need the following configuration then:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,inside) 10.1.1.0 10.1.1.0 norand nailed&lt;/P&gt;&lt;P&gt;static (inside,inside) 10.1.10.0 10.1.10.0 norand nailed&lt;/P&gt;&lt;P&gt;nat (inside) 10 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;global (inside) 10 interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;sysopt noproxyarp inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this should do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Nov 2011 04:38:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731864#M494095</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-11-05T04:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731865#M494096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it's not working Alain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 13:43:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731865#M494096</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2011-11-07T13:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731866#M494097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now I get error: portmap translation creation failed for icmp src&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 13:46:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731866#M494097</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2011-11-07T13:46:06Z</dc:date>
    </item>
    <item>
      <title>ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731867#M494098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you try the config I suggested??? Its missing a nat statement, according to the error message.&lt;/P&gt;&lt;P&gt;Can you share your config with us? alongwith the source and teh destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 13:48:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731867#M494098</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-11-07T13:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731868#M494099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;varun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because the 10.1.1.0 and 10.1.10.0 are routed by the other router, not this one&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 13:53:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731868#M494099</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2011-11-07T13:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731869#M494100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Varun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 10.1.1.0 and 10.1.10.0 are connected to the other router 192.168.1.30 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I can't nat this subnet on this particular ASA. So I've created routes on the ASA to route this particular traffic to the 192.168.1.30 router. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 14:11:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731869#M494100</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2011-11-07T14:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731870#M494101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 16:33:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731870#M494101</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2011-11-07T16:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731871#M494102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;my problem is exactly like this one: &lt;/P&gt;&lt;P&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But how come it doesn't work??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 22:52:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731871#M494102</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2011-11-07T22:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731872#M494103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So far, I found that it seems to be a problem of natting. I've tried excluding inside traffic from natting but it blocks later on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here's a screen shot of packet tracer and my config. Please help, I'm reaaly bumped out about this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/8/0/66086-Cisco.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;BR /&gt;: Written by enable_15 at 08:56:18.018 EST Tue Nov 8 2011&lt;BR /&gt;!&lt;BR /&gt;ASA Version 8.2(5) &lt;BR /&gt;!&lt;BR /&gt;hostname FW-SERVERS&lt;BR /&gt;domain-name logid.com&lt;BR /&gt;enable password nC1TgPA/j9j.bzQi encrypted&lt;BR /&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;BR /&gt;names&lt;BR /&gt;name 192.168.23.122 FTPServer&lt;BR /&gt;name 192.168.23.18 MailServer&lt;BR /&gt;name 192.168.23.3 VPNServer&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;nameif Inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.1.20 255.255.252.0 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address X.X.X.X &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;nameif management&lt;BR /&gt;security-level 100&lt;BR /&gt;no ip address&lt;BR /&gt;management-only&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone EST -5&lt;BR /&gt;clock summer-time EDT recurring&lt;BR /&gt;dns domain-lookup outside&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;domain-name XXXX&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;access-list outside_Access_in extended permit tcp any host X.X.X.X eq ftp &lt;BR /&gt;access-list outside_Access_in extended permit tcp any host X.X.X.X eq https &lt;BR /&gt;access-list outside_Access_in extended permit tcp 67.22.232.0 255.255.255.0 host X.X.X.X eq smtp &lt;BR /&gt;access-list outside_Access_in extended permit tcp any host X.X.X.X eq pptp &lt;BR /&gt;access-list outside_Access_in extended permit tcp any host X.X.X.X eq 47 &lt;BR /&gt;access-list outside_Access_in extended permit tcp any any eq 123 &lt;BR /&gt;access-list outside_Access_in extended deny tcp any any &lt;BR /&gt;access-list outside_Access_in extended deny udp any any &lt;BR /&gt;access-list NAT0 standard permit any &lt;BR /&gt;access-list outside_1_cryptomap extended permit ip 192.168.23.0 255.255.255.0 192.168.20.0 255.255.255.0 &lt;BR /&gt;access-list Inside_Access_in standard permit any &lt;BR /&gt;access-list 101 extended permit ip 192.168.1.0 255.255.252.0 10.0.0.0 255.0.0.0 &lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu Inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu management 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (Inside) 0 access-list 101&lt;BR /&gt;nat (Inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;static (Inside,outside) tcp X.X.X.X ftp FTPServer ftp netmask 255.255.255.255 &lt;BR /&gt;static (Inside,outside) tcp X.X.X.X https MailServer https netmask 255.255.255.255 &lt;BR /&gt;static (Inside,outside) tcp X.X.X.X pptp VPNServer pptp netmask 255.255.255.255 &lt;BR /&gt;static (Inside,outside) tcp X.X.X.X smtp MailServer smtp netmask 255.255.255.255 &lt;BR /&gt;access-group outside_Access_in in interface outside&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 199.255.30.89 1&lt;BR /&gt;route Inside 10.1.1.0 255.255.255.0 192.168.1.30 2&lt;BR /&gt;route Inside 10.1.10.0 255.255.255.252 192.168.1.30 2&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.252.0 Inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;telnet 192.168.1.0 255.255.252.0 Inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;management-access Inside&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;ntp server 192.168.X.X source Inside prefer&lt;BR /&gt;webvpn&lt;BR /&gt;group-policy DfltGrpPolicy attributes&lt;BR /&gt;vpn-idle-timeout none&lt;BR /&gt;vpn-filter value NAT0&lt;BR /&gt;vpn-tunnel-protocol IPSec l2tp-ipsec svc webvpn&lt;BR /&gt;pre-shared-key LOGIS2SLOGIS2SLOGIS2S&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect dns preset_dns_map &lt;BR /&gt;inspect ftp &lt;BR /&gt;inspect h323 h225 &lt;BR /&gt;inspect h323 ras &lt;BR /&gt;inspect rsh &lt;BR /&gt;inspect rtsp &lt;BR /&gt;inspect esmtp &lt;BR /&gt;inspect sqlnet &lt;BR /&gt;inspect skinny &lt;BR /&gt;inspect sunrpc &lt;BR /&gt;inspect xdmcp &lt;BR /&gt;inspect sip &lt;BR /&gt;inspect netbios &lt;BR /&gt;inspect tftp &lt;BR /&gt;inspect ip-options &lt;BR /&gt;inspect pptp &lt;BR /&gt;inspect http &lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;Cryptochecksum:12b6abd11e12da8ecc8bcb3298f62ca7&lt;BR /&gt;: end&lt;BR /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Nov 2011 14:22:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731872#M494103</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2011-11-08T14:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Routing problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731873#M494105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good news, I found the problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Adding those routes to the NAT 0 did the trick&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Nov 2011 00:20:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-routing-problem/m-p/1731873#M494105</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2011-11-09T00:20:07Z</dc:date>
    </item>
  </channel>
</rss>

