<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic OSPF PTP with ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ospf-ptp-with-asa/m-p/1757772#M531590</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the ASA the "non-broadcast" option is required.&amp;nbsp; When I try to leave it off I get a "command incomplete" message.&lt;/P&gt;&lt;P&gt;There are no other options available so I used "ospf network point-to-point &lt;STRONG&gt;non-broadcast&lt;/STRONG&gt;" option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the 6500 IOS switch I can simply put in "ip ospf network point-to-point" with no further options.&amp;nbsp; Here the "non-broadcast" option is not available even if I wanted it.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So with the ASA using "ospf network point-to-point nonbroadcast" and the 6500 IOS using "ip ospf network point-to-point" I can't get the adjacency up.&amp;nbsp;&amp;nbsp; Both network types are listed as "POINT-TO-POINT" for each interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any further thougths anyone?&amp;nbsp;&amp;nbsp; Is there a different command on the ASA that doesn't require the non-broadcast option?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chuck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Sep 2011 13:34:05 GMT</pubDate>
    <dc:creator>c.fuller</dc:creator>
    <dc:date>2011-09-08T13:34:05Z</dc:date>
    <item>
      <title>OSPF PTP with ASA</title>
      <link>https://community.cisco.com/t5/network-security/ospf-ptp-with-asa/m-p/1757769#M531587</link>
      <description>&lt;P&gt;Hello &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to bring up a L3 PTP between an ASA and a 6500 running IOS.&amp;nbsp;&amp;nbsp; The ASA is in routed mode configured for OSPF.&amp;nbsp; On the ASA I configure the interface to the 6500 with an IP address and define the network type as point-to-point.&amp;nbsp;&amp;nbsp; I add that network to the OSPF process configuration. Likewise on the 6500 I configure the interface as a L3 interface with IP and network type as point-to-point.&amp;nbsp;&amp;nbsp; I add the same /30 network to that OSPF process.&amp;nbsp; I can ping across the /30 both ways but the adjacency is not forming.&amp;nbsp;&amp;nbsp; The ASA debugs show the hello coming from the correct 6500 interface.&amp;nbsp;&amp;nbsp; However the ASA can't find the 6500 interface.&amp;nbsp; The debug indicates "cannot locate nbr x.x.x.x (ip address of 6500 interface).&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I remove the "ospf network point-to-point nonbroadcast" command on the ASA the adjacency does form.&amp;nbsp;&amp;nbsp;&amp;nbsp; However, on the ASA side it's "2way/drother" and on the 6500 side "full".&amp;nbsp;&amp;nbsp; The LSDB's look good.&amp;nbsp;&amp;nbsp; But the 6500 is not injecting the routes advertised from the ASA into the routing table.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thoughts?&amp;nbsp; I suspect I am missing a concept or simple command.&amp;nbsp;&amp;nbsp; As far as I can tell this is a supported configuration on the ASA.&amp;nbsp;&amp;nbsp;&amp;nbsp; But have not been able to find any point-to-point configuration examples.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any information is much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Chuck&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:21:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ospf-ptp-with-asa/m-p/1757769#M531587</guid>
      <dc:creator>c.fuller</dc:creator>
      <dc:date>2019-03-11T21:21:38Z</dc:date>
    </item>
    <item>
      <title>OSPF PTP with ASA</title>
      <link>https://community.cisco.com/t5/network-security/ospf-ptp-with-asa/m-p/1757770#M531588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Update:&amp;nbsp; I was able to get this to work by removing the network type "point-to-point" from both sides of the /30 layer 3 link.&amp;nbsp; The ASA routes are now showing up in the 6500 routing table.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I am still confused as to why I could not get the full adjacency when configuring point-to-point on the interfaces.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's working now but as a "broadcast" network type.&amp;nbsp;&amp;nbsp; Even though it's physically a point-to-point setup.&amp;nbsp;&amp;nbsp; One link between two devices only.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any information is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chuck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Sep 2011 14:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ospf-ptp-with-asa/m-p/1757770#M531588</guid>
      <dc:creator>c.fuller</dc:creator>
      <dc:date>2011-09-07T14:21:04Z</dc:date>
    </item>
    <item>
      <title>OSPF PTP with ASA</title>
      <link>https://community.cisco.com/t5/network-security/ospf-ptp-with-asa/m-p/1757771#M531589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;When I remove the "ospf network point-to-point nonbroadcast"&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suppose this is a typo because this network type doesn't exist but point-to-multipoint non broadcast does exist.&lt;/P&gt;&lt;P&gt;I you use this type then you must use unicast for hellos and so enter a neighbour command but if other side is broadcast this can't work.&lt;/P&gt;&lt;P&gt;Normally if you use point-to-point on both ends then you must have an adjacency and get all the routes.&lt;/P&gt;&lt;P&gt;You may have a neighbourship forming if the hello/dead timers are the same but if the network types are not compatible then you won't get the routes and full adjacency.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 12:01:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ospf-ptp-with-asa/m-p/1757771#M531589</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-09-08T12:01:16Z</dc:date>
    </item>
    <item>
      <title>OSPF PTP with ASA</title>
      <link>https://community.cisco.com/t5/network-security/ospf-ptp-with-asa/m-p/1757772#M531590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the ASA the "non-broadcast" option is required.&amp;nbsp; When I try to leave it off I get a "command incomplete" message.&lt;/P&gt;&lt;P&gt;There are no other options available so I used "ospf network point-to-point &lt;STRONG&gt;non-broadcast&lt;/STRONG&gt;" option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the 6500 IOS switch I can simply put in "ip ospf network point-to-point" with no further options.&amp;nbsp; Here the "non-broadcast" option is not available even if I wanted it.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So with the ASA using "ospf network point-to-point nonbroadcast" and the 6500 IOS using "ip ospf network point-to-point" I can't get the adjacency up.&amp;nbsp;&amp;nbsp; Both network types are listed as "POINT-TO-POINT" for each interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any further thougths anyone?&amp;nbsp;&amp;nbsp; Is there a different command on the ASA that doesn't require the non-broadcast option?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chuck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 13:34:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ospf-ptp-with-asa/m-p/1757772#M531590</guid>
      <dc:creator>c.fuller</dc:creator>
      <dc:date>2011-09-08T13:34:05Z</dc:date>
    </item>
    <item>
      <title>Here's a doc http://www.cisco</title>
      <link>https://community.cisco.com/t5/network-security/ospf-ptp-with-asa/m-p/1757773#M531591</link>
      <description>&lt;P&gt;Here's a doc http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/general/asa_91_general_config/route_ospf.html#52085&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have to specify the neighbor under the OSPF process. Example below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface gi0&lt;/P&gt;&lt;P&gt;ip address 192.168.1.2 255.255.255.252&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ospf network point-to-point non-broadcast&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;router ospf 65000&lt;/P&gt;&lt;P&gt;network 192.168.1.0 255.255.255.252 area 0&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;neighbor 192.168.1.1 interface inside&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2015 14:43:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ospf-ptp-with-asa/m-p/1757773#M531591</guid>
      <dc:creator>avang2004</dc:creator>
      <dc:date>2015-03-13T14:43:58Z</dc:date>
    </item>
  </channel>
</rss>

