<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA return Traffic on different interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-return-traffic-on-different-interface/m-p/1524198#M579348</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thnx a ton, You rock&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 27 Nov 2010 09:47:17 GMT</pubDate>
    <dc:creator>thundercisco</dc:creator>
    <dc:date>2010-11-27T09:47:17Z</dc:date>
    <item>
      <title>Cisco ASA return Traffic on different interface</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-return-traffic-on-different-interface/m-p/1524196#M579345</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;During my configuration of a network i found that if return traffic is comes on different interface , ASA block it.&lt;/P&gt;&lt;P&gt;e.g, lets say my ping originated from inside server on inside interface(Security level 100), This packet is router to sub interface .1, and server to which echo was sent reply back. but due to internal routing echo-reply comes back on subinterface .2. Although traffic coming back was allowed but still ASA didn't allow this kind of traffic. So to fix this i fixed internal routing and suddenly everything seems to be working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No my question is : Is this a way we can allow such config, for now i had control over customer routing so i could fix this issue, But in future if such situation occurs what to do&lt;/P&gt;&lt;P&gt;Thnx in advance&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:15:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-return-traffic-on-different-interface/m-p/1524196#M579345</guid>
      <dc:creator>thundercisco</dc:creator>
      <dc:date>2019-03-11T19:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA return Traffic on different interface</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-return-traffic-on-different-interface/m-p/1524197#M579346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Although what you did - fixing routing is the right way to fix it, this kind of asymmetry can be allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With ASA 8.2.1 and above you can configure tcp state-bypass:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/s1.html#wp1428242"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/s1.html#wp1428242&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following is an example configuration for TCP state bypass:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname(config)# access-list tcp_bypass extended permit tcp 10.1.1.0 255.255.255.224 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname(config)# class-map tcp_bypass&lt;BR /&gt;hostname(config-cmap)# description "TCP traffic that bypasses stateful firewall"&lt;BR /&gt;hostname(config-cmap)# match access-list tcp_bypass&lt;BR /&gt;hostname(config-cmap)# policy-map tcp_bypass_policy&lt;BR /&gt;hostname(config-pmap)# class tcp_bypass&lt;BR /&gt;hostname(config-pmap-c)# set connection advanced-options tcp-state-bypass&lt;BR /&gt;hostname(config-pmap-c)# service-policy tcp_bypass_policy outside&lt;BR /&gt;hostname(config-pmap-c)# static (inside,outside) 209.165.200.224 10.1.1.0 netmask&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Nov 2010 19:46:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-return-traffic-on-different-interface/m-p/1524197#M579346</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-11-26T19:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA return Traffic on different interface</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-return-traffic-on-different-interface/m-p/1524198#M579348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thnx a ton, You rock&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Nov 2010 09:47:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-return-traffic-on-different-interface/m-p/1524198#M579348</guid>
      <dc:creator>thundercisco</dc:creator>
      <dc:date>2010-11-27T09:47:17Z</dc:date>
    </item>
  </channel>
</rss>

