<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5510 - all inside IPs have same MAC address in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5510-all-inside-ips-have-same-mac-address/m-p/1760068#M529724</link>
    <description>&lt;P&gt;My customer has a 5510 with the inside interface connected to a routed port on a Cat3560G&lt;/P&gt;&lt;P&gt;When I look at the arp cache on the 5510 all inside IPs have the MAC of the 3560's routed port&lt;/P&gt;&lt;P&gt;Partial output:&lt;/P&gt;&lt;P&gt;asa# sho arp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.20.1.138 0024.1397.f8c1 1407&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.20.1.104 0024.1397.f8c1 2983&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.20.1.148 0024.1397.f8c1 2995&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.20.1.20 0024.1397.f8c1 3057&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.20.1.130 0024.1397.f8c1 3379&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.20.1.102 0024.1397.f8c1 3592&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.20.1.144 0024.1397.f8c1 3928&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;I cannot see why this is happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suggestions??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:31:28 GMT</pubDate>
    <dc:creator>Phil Williamson</dc:creator>
    <dc:date>2019-03-11T21:31:28Z</dc:date>
    <item>
      <title>ASA5510 - all inside IPs have same MAC address</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-all-inside-ips-have-same-mac-address/m-p/1760068#M529724</link>
      <description>&lt;P&gt;My customer has a 5510 with the inside interface connected to a routed port on a Cat3560G&lt;/P&gt;&lt;P&gt;When I look at the arp cache on the 5510 all inside IPs have the MAC of the 3560's routed port&lt;/P&gt;&lt;P&gt;Partial output:&lt;/P&gt;&lt;P&gt;asa# sho arp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.20.1.138 0024.1397.f8c1 1407&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.20.1.104 0024.1397.f8c1 2983&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.20.1.148 0024.1397.f8c1 2995&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.20.1.20 0024.1397.f8c1 3057&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.20.1.130 0024.1397.f8c1 3379&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.20.1.102 0024.1397.f8c1 3592&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside 172.20.1.144 0024.1397.f8c1 3928&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;I cannot see why this is happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suggestions??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:31:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-all-inside-ips-have-same-mac-address/m-p/1760068#M529724</guid>
      <dc:creator>Phil Williamson</dc:creator>
      <dc:date>2019-03-11T21:31:28Z</dc:date>
    </item>
    <item>
      <title>ASA5510 - all inside IPs have same MAC address</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-all-inside-ips-have-same-mac-address/m-p/1760069#M529725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Surely the 3560G is doing proxy-arp.&lt;/P&gt;&lt;P&gt;Can you provide sh route from ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 15:05:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-all-inside-ips-have-same-mac-address/m-p/1760069#M529725</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-09-28T15:05:45Z</dc:date>
    </item>
    <item>
      <title>ASA5510 - all inside IPs have same MAC address</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-all-inside-ips-have-same-mac-address/m-p/1760070#M529726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your interest.&amp;nbsp; It has me stumped too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA show route with only inside interface routes:&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.1.1.0 255.255.255.240 is directly connected, inside&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.20.1.0 255.255.255.0 [1/0] via 1.1.1.1, inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also from ASA:&lt;BR /&gt;show run all | in arp&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;no sysopt noproxyarp inside&lt;/P&gt;&lt;P&gt;no sysopt noproxyarp outside&lt;/P&gt;&lt;P&gt;no sysopt noproxyarp management&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From 3560G:&lt;/P&gt;&lt;P&gt;Gateway of last resort is 1.1.1.1 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;S*&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0 [1/0] via 1.1.1.1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.0.0.0/8 is variably subnetted, 2 subnets, 2 masks&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.1.1.0/28 is directly connected, GigabitEthernet0/1&lt;BR /&gt;L&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.1.1.14/32 is directly connected, GigabitEthernet0/1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.20.0.0/16 is variably subnetted, 2 subnets, 2 masks&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.20.1.0/24 is directly connected, Vlan1&lt;BR /&gt;L&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.20.1.30/32 is directly connected, Vlan1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C3560G24-1#sh ip int gi 0/1&lt;/P&gt;&lt;P&gt;GigabitEthernet0/1 is up, line protocol is up&lt;/P&gt;&lt;P&gt;&amp;nbsp; Internet address is 1.1.1.14/28&lt;/P&gt;&lt;P&gt;&amp;nbsp; Broadcast address is 255.255.255.255&lt;/P&gt;&lt;P&gt;&amp;nbsp; Address determined by non-volatile memory&lt;/P&gt;&lt;P&gt;&amp;nbsp; MTU is 1500 bytes&lt;/P&gt;&lt;P&gt;&amp;nbsp; Helper address is not set&lt;/P&gt;&lt;P&gt;&amp;nbsp; Directed broadcast forwarding is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; Outgoing access list is not set&lt;/P&gt;&lt;P&gt;&amp;nbsp; Inbound&amp;nbsp; access list is not set&lt;/P&gt;&lt;P&gt;&amp;nbsp; Proxy ARP is enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; Local Proxy ARP is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; Security level is default&lt;/P&gt;&lt;P&gt;&amp;nbsp; Split horizon is enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; ICMP redirects are always sent&lt;/P&gt;&lt;P&gt;&amp;nbsp; ICMP unreachables are always sent&lt;/P&gt;&lt;P&gt;&amp;nbsp; ICMP mask replies are never sent&lt;/P&gt;&lt;P&gt;&amp;nbsp; IP fast switching is enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; IP Flow switching is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; IP CEF switching is enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; IP CEF switching turbo vector&lt;/P&gt;&lt;P&gt;&amp;nbsp; IP Null turbo vector&lt;/P&gt;&lt;P&gt;&amp;nbsp; IP multicast fast switching is enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; IP multicast distributed fast switching is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; IP route-cache flags are Fast, CEF&lt;/P&gt;&lt;P&gt;&amp;nbsp; Router Discovery is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; IP output packet accounting is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; IP access violation accounting is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; TCP/IP header compression is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; RTP/IP header compression is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; Probe proxy name replies are disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; Policy routing is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; Network address translation is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; BGP Policy Mapping is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; Input features: MCI Check&lt;/P&gt;&lt;P&gt;&amp;nbsp; Output features: Check hwidb&lt;/P&gt;&lt;P&gt;C3560G24-1#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 15:20:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-all-inside-ips-have-same-mac-address/m-p/1760070#M529726</guid>
      <dc:creator>Phil Williamson</dc:creator>
      <dc:date>2011-09-28T15:20:02Z</dc:date>
    </item>
    <item>
      <title>ASA5510 - all inside IPs have same MAC address</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-all-inside-ips-have-same-mac-address/m-p/1760071#M529727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you clear arp cache on ASA and ping one of those addresses again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 17:50:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-all-inside-ips-have-same-mac-address/m-p/1760071#M529727</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-09-28T17:50:29Z</dc:date>
    </item>
    <item>
      <title>ASA5510 - all inside IPs have same MAC address</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-all-inside-ips-have-same-mac-address/m-p/1760072#M529729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've done that many times and all IPs come back with same switchport MAC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I connect to the switch and ping a non-existant IP I get the expected result:&lt;/P&gt;&lt;P&gt;C3560G24-1#sho arp | in 172.20.1.53&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 172.20.1.53&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; Incomplete&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ARPA&lt;/P&gt;&lt;P&gt;C3560G24-1#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I clear the ASA's arp cache and ping that same IP I GET A PING REPLY which I infer is from the Cat3560 routed port doing the proxy-arp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I noted above proxy-arp is enabled on that switchport.&amp;nbsp; I'll turn it off - will be after hours today - and see what happens.&amp;nbsp; I don't like fooling with a live customer network during business hours.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 18:45:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-all-inside-ips-have-same-mac-address/m-p/1760072#M529729</guid>
      <dc:creator>Phil Williamson</dc:creator>
      <dc:date>2011-09-28T18:45:03Z</dc:date>
    </item>
    <item>
      <title>ASA5510 - all inside IPs have same MAC address</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-all-inside-ips-have-same-mac-address/m-p/1760073#M529731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no need to turn off proxy-arp on the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you notice&amp;nbsp; here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA &lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.1.1.0 255.255.255.240 is directly connected, inside&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.20.1.0 255.255.255.0 [1/0] via &lt;STRONG&gt;1.1.1.1&lt;/STRONG&gt;, inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 3560G:&lt;/P&gt;&lt;P&gt;Gateway of last resort is 1.1.1.1 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;S*&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0 [1/0] &lt;STRONG&gt;via 1.1.1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You did a typo in your route config on the ASA, you put ip address of ASA as next-hop.&lt;/P&gt;&lt;P&gt;Change it to ip of switch and it will be ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 19:52:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-all-inside-ips-have-same-mac-address/m-p/1760073#M529731</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-09-28T19:52:38Z</dc:date>
    </item>
    <item>
      <title>ASA5510 - all inside IPs have same MAC address</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-all-inside-ips-have-same-mac-address/m-p/1760074#M529732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alain - Yes, I cannot see the forest for the trees.&amp;nbsp; I've stared at this for a day and could not see the error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 172.20.1.0 255.255.255.0 1.1.1.14 (not 1.1.1.1) !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the arp cache looks like it should with currently only the 1.1.1.14 in the cache.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Sep 2011 02:38:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-all-inside-ips-have-same-mac-address/m-p/1760074#M529732</guid>
      <dc:creator>Phil Williamson</dc:creator>
      <dc:date>2011-09-29T02:38:04Z</dc:date>
    </item>
  </channel>
</rss>

