<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5505 Routing Problem!!!!!!!!! in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720708#M561538</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it is possible. Your configuration seems to be ok. However, i would recommend defining "swtichport access vlan 1" command under the physical interface where VLAN 1 is connected to. Secondly, if it is not working i would recommend defining mac addresses on the physical interfaces manually. By default, all the ports on a 5505 share the same MAC address. If your adjacent switch has some problems with this behaviour you can set virtual mac addresses manually using mac-address command under the Interface VLAN configuration. If it is still not working, can you run a debug icmp trace while pinging from a host in VLAN 5 to a host in VLAN1 or vice-versa. Also a show interface and show route output would be useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, i am assuming that you can ping the IP addresses on Inter vlan 1 and inter vlan 5 from respective VLANs. If the hosts from where you are pinging are a L3 hop away, i hope the routing has been set there properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Zubair&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;######Please rate if this was helpful##############&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 31 May 2011 17:14:39 GMT</pubDate>
    <dc:creator>zujalal</dc:creator>
    <dc:date>2011-05-31T17:14:39Z</dc:date>
    <item>
      <title>ASA 5505 Routing Problem!!!!!!!!!</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720703#M561532</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have ASA 5505 Firewall with security plus license, I configured two VLAN 1 and VLAN 5 as my inside VLAN for different subnet, i need to route the traffic between this two VLANs through ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int vlan 1&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;Security level 100&lt;/P&gt;&lt;P&gt;Ip address 172.16.100.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Int vlan 5&lt;/P&gt;&lt;P&gt;namaeif camera&lt;/P&gt;&lt;P&gt;security level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.22.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security traffic permit inter interface&lt;/P&gt;&lt;P&gt;same-security traffic permit intra interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router eigrp 2&lt;/P&gt;&lt;P&gt;network 172.16.100.0&lt;/P&gt;&lt;P&gt;network 192.168.22.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int e0/6&lt;/P&gt;&lt;P&gt;switchport access vlan 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is i am not able to ping other subnet, for ex my pc is in VLAN 1 not able to ping 192.168.22.1 ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For troubleshoot i type debug icmp trace while pinging other sunbet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ICMP echo request from 192.168.22.2 to 172.16.100.101 ID=512 seq=4608 len=32&lt;BR /&gt;ICMP echo request from 192.168.22.2 to 172.16.100.101 ID=512 seq=4864 len=32&lt;BR /&gt;ICMP echo request from 192.168.22.2 to 172.16.100.101 ID=512 seq=5120 len=32&lt;BR /&gt;ICMP echo request from 192.168.22.2 to 172.16.100.101 ID=512 seq=5376 len=32&lt;/P&gt;&lt;P&gt;I trun off the firewall on my local machine, can any one plz help me out??????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Abhishek&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:40:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720703#M561532</guid>
      <dc:creator>abhishek.shah</dc:creator>
      <dc:date>2019-03-11T20:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Routing Problem!!!!!!!!!</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720704#M561534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Abhishek.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;..."&lt;SPAN&gt;The problem is i am not able to ping other subnet, for ex my pc is in VLAN 1 not able to ping 192.168.22.1"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is as per design. The ASA will not allow you to ping another interface while your PC is behind another interface. You can only ping the VLAN1 interface if your PC is in VLAN 1...you cannot ping the VLAN2 interface on the ASA. Try pinging some other PC in VLAN 2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Zubair&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2011 15:33:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720704#M561534</guid>
      <dc:creator>zujalal</dc:creator>
      <dc:date>2011-05-31T15:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Routing Problem!!!!!!!!!</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720705#M561535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my knowledge ASA is a layer 3 device, it can able to route the traffic between different subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA will not allow you to ping another interface while your PC is behind another interface.&amp;nbsp; I doubt abt your statement, beacuse before i configured the same senario and it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i configure routing protocol and allow same security traffic allow statement, ASA should route the traffic between different subnet. plz correct me if i am wroung????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Abhishek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2011 15:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720705#M561535</guid>
      <dc:creator>abhishek.shah</dc:creator>
      <dc:date>2011-05-31T15:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Routing Problem!!!!!!!!!</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720706#M561536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you are right by saying that ASA can be a L3 device but you dont need a dynamic routing protocol to route between two subnets which are directly connected to the ASA. These two subnets will appear as connected routes. You just need the same-security permit inter-interface command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding Pinging VLAN5 interface from VLAN1, you cannot do it. You might have done it on a router but it is a very basic check in the ASA alogrithm.The ASA only responds to ICMP traffic sent to the interface that traffic comes in on; you cannot send ICMP traffic through an interface to a far interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2011 15:59:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720706#M561536</guid>
      <dc:creator>zujalal</dc:creator>
      <dc:date>2011-05-31T15:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Routing Problem!!!!!!!!!</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720707#M561537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I removed the eigrp from my config and apply same-security permit inter interface, by doing this on ASA 5505 can route the traffic between different subnet. I did that its not working.......&lt;/P&gt;&lt;P&gt;As you are agree that asa is layer 3 device, i have one question.....if i have two inside netwrok and i want to route the traffic between this two inside network through asa 5505 is that possible or not?? If yes than how can i do it??????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Abhishek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2011 16:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720707#M561537</guid>
      <dc:creator>abhishek.shah</dc:creator>
      <dc:date>2011-05-31T16:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Routing Problem!!!!!!!!!</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720708#M561538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it is possible. Your configuration seems to be ok. However, i would recommend defining "swtichport access vlan 1" command under the physical interface where VLAN 1 is connected to. Secondly, if it is not working i would recommend defining mac addresses on the physical interfaces manually. By default, all the ports on a 5505 share the same MAC address. If your adjacent switch has some problems with this behaviour you can set virtual mac addresses manually using mac-address command under the Interface VLAN configuration. If it is still not working, can you run a debug icmp trace while pinging from a host in VLAN 5 to a host in VLAN1 or vice-versa. Also a show interface and show route output would be useful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, i am assuming that you can ping the IP addresses on Inter vlan 1 and inter vlan 5 from respective VLANs. If the hosts from where you are pinging are a L3 hop away, i hope the routing has been set there properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Zubair&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;######Please rate if this was helpful##############&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2011 17:14:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720708#M561538</guid>
      <dc:creator>zujalal</dc:creator>
      <dc:date>2011-05-31T17:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Routing Problem!!!!!!!!!</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720709#M561539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After applied below commands both subnet can ping eachother,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VLAN 1 Inside Network&lt;/P&gt;&lt;P&gt;VLAN 5 Camera Network &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need both VLAN 1 and VLAN 5 Should talk to each other, and its working the only problem is VLAN 5 subnet host not able to access internert,&lt;/P&gt;&lt;P&gt;when i applied nat (camera) 1 0.0.0.0 0.0.0.0 both subnet stop pinging each other, able to access internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;BR /&gt; switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt; switchport access vlan 4&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt; switchport trunk allowed vlan 1,5&lt;BR /&gt; switchport trunk native vlan 1&lt;BR /&gt; switchport mode trunk&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt; switchport trunk allowed vlan 1-5&lt;BR /&gt; switchport trunk native vlan 1&lt;BR /&gt; switchport mode trunk&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt; switchport access vlan 32&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;switchport access vlan 5&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 172.16.100.101 255.255.255.0 standby 172.16.100.102&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan5&lt;BR /&gt; nameif camera&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.22.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;global (inside) 2 interface&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;global (backup) 1 interface&lt;BR /&gt;nat (inside) 0 access-list nonat&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;nat (camera) 1 0.0.0.0 0.0.0.0---- once i removed this command both subnet able to ping each other but no internet access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i think its a nat issue,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following is the out put of my packet tracer which clearly states packet drop beacuse of nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ADA-# packet-tracer input camera icmp 192.168.22.2 255 255 172.16.100.11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: dynamic&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface inside&lt;BR /&gt;Untranslate 172.16.100.11/0 to 172.16.100.11/0 using netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: INSPECT&lt;BR /&gt;Subtype: np-inspect&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect icmp &lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: INSPECT&lt;BR /&gt;Subtype: np-inspect&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: NAT-EXEMPT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;&amp;lt;--- More ---&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Phase: 7&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;nat (camera) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp; match ip camera any inside any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 167, untranslate_hits = 0&lt;BR /&gt;&lt;/STRONG&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: camera&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Abhishek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 14:53:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720709#M561539</guid>
      <dc:creator>abhishek.shah</dc:creator>
      <dc:date>2011-06-01T14:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Routing Problem!!!!!!!!!</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720710#M561540</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont see the config of the outside interface below. I am assuming it is there. Use a different NAT ID and you should be good to go. you just need the below commands.Also i am not sure what the backup interface is?.&amp;nbsp; Remove the other nat and global commands.&amp;nbsp; VLAN 1 and VLAN 5 can still talk to each other unless you have not enabled nat-control.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;global (outside) 1 interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (camera) 2 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;global (outside) 2 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Zubair&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;######Please rate if this was useful#########&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 15:07:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720710#M561540</guid>
      <dc:creator>zujalal</dc:creator>
      <dc:date>2011-06-01T15:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Routing Problem!!!!!!!!!</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720711#M561541</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find the attachment of my current config,&amp;nbsp; i applied the commands but no luck, i disable the no-natcontrol still no luck. Can you suggest other option, packet has been denided by&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;nat (camera) 2 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp; match ip camera any inside any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 2 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 79, untranslate_hits = 0&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: camera&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: inside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Abhishek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 15:32:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720711#M561541</guid>
      <dc:creator>abhishek.shah</dc:creator>
      <dc:date>2011-06-01T15:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Routing Problem!!!!!!!!!</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720712#M561542</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont know why the routes are configured the way they are right now. the next hops mentioned are the Interface IP's defined on the ASA itself???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 1.1.1.1 1&lt;/P&gt;&lt;P&gt;route backup 0.0.0.0 0.0.0.0 2.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you have put these for reference only...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you ping any public IP like 4.2.2.2 from the ASA itself. If yes, then can you remove the global (backup) 2 commands and then test. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 15:44:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720712#M561542</guid>
      <dc:creator>zujalal</dc:creator>
      <dc:date>2011-06-01T15:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Routing Problem!!!!!!!!!</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720713#M561543</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes the route which i used is only reference, in real i am using different IP address. I removed global (backup) 2 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes from firewall i am able to ping 4.2.2.2, and able to access internet from 172.16.100.x subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only problem is i am not able to access internet from 192.168.22.x subnet, once i remove the command nat(camera) 2 0.0.0.0 0.0.0.0 i am able to access the internet but not able to ping other subnet,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Abhishek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jun 2011 13:34:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-routing-problem/m-p/1720713#M561543</guid>
      <dc:creator>abhishek.shah</dc:creator>
      <dc:date>2011-06-02T13:34:46Z</dc:date>
    </item>
  </channel>
</rss>

