<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: hairpinning - ok or not ok? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/hairpinning-ok-or-not-ok/m-p/1637086#M591507</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hairpinning on ASA is not a problem, however, we often found that it breaks traffic flow more than resolving problem especially in this scenario:&lt;/P&gt;&lt;P&gt;- Traffic originates from the same subnet as ASA interface and it has been configured as its default gateway --&amp;gt; this will break TCP application due to the following reason:&lt;/P&gt;&lt;P&gt;TCP SYN: from host-A - ASA interface - destination-B&lt;/P&gt;&lt;P&gt;TCP SYN-ACK: from destination-B - directly to host-A (because ASA interface is in the same subnet as host-A, it will go directly instead of routed to ASA interface first).&lt;/P&gt;&lt;P&gt;TCP ACK: from host-A - ASA interface (ASA in this instance will drop the connection since it never saw the TCP SYN-ACK).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Feb 2011 23:48:55 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2011-02-16T23:48:55Z</dc:date>
    <item>
      <title>hairpinning - ok or not ok?</title>
      <link>https://community.cisco.com/t5/network-security/hairpinning-ok-or-not-ok/m-p/1637085#M591506</link>
      <description>&lt;P&gt;We have found that hairpinning an interface on our ASA will resolve a problem, but we're not sure if it's a good or bad idea. Is hairpinning an ok or not ok practice?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hairpinning-ok-or-not-ok/m-p/1637085#M591506</guid>
      <dc:creator>mikeccit</dc:creator>
      <dc:date>2019-03-11T19:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: hairpinning - ok or not ok?</title>
      <link>https://community.cisco.com/t5/network-security/hairpinning-ok-or-not-ok/m-p/1637086#M591507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hairpinning on ASA is not a problem, however, we often found that it breaks traffic flow more than resolving problem especially in this scenario:&lt;/P&gt;&lt;P&gt;- Traffic originates from the same subnet as ASA interface and it has been configured as its default gateway --&amp;gt; this will break TCP application due to the following reason:&lt;/P&gt;&lt;P&gt;TCP SYN: from host-A - ASA interface - destination-B&lt;/P&gt;&lt;P&gt;TCP SYN-ACK: from destination-B - directly to host-A (because ASA interface is in the same subnet as host-A, it will go directly instead of routed to ASA interface first).&lt;/P&gt;&lt;P&gt;TCP ACK: from host-A - ASA interface (ASA in this instance will drop the connection since it never saw the TCP SYN-ACK).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Feb 2011 23:48:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hairpinning-ok-or-not-ok/m-p/1637086#M591507</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-02-16T23:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: hairpinning - ok or not ok?</title>
      <link>https://community.cisco.com/t5/network-security/hairpinning-ok-or-not-ok/m-p/1637087#M591508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have found hairpinning to be indeed a useful hack many times.&amp;nbsp; You need explicity allow intra interface and&lt;/P&gt;&lt;P&gt;have ACL allows.&amp;nbsp; Also you might want to look at using static arp ( for another ip address on the ASA interface)&amp;nbsp; and&amp;nbsp; assigning a different default gateway to a class of servers with a smaller subnet than the ASA interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Feb 2011 00:08:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/hairpinning-ok-or-not-ok/m-p/1637087#M591508</guid>
      <dc:creator>Sudeep Khuraijam</dc:creator>
      <dc:date>2011-02-17T00:08:00Z</dc:date>
    </item>
  </channel>
</rss>

