<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA default route ACL and default route redistributing/defau in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560653#M608634</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking into this at this point, Normally what you would do is to redistribute the whole protocol and filter. The ACL is not wrong, it is created as an standard ACL and what it is telling the ASA is not to redistribute only the default route, but you are telling him to redistribute everything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me get back to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Oct 2010 01:25:36 GMT</pubDate>
    <dc:creator>Maykol Rojas</dc:creator>
    <dc:date>2010-10-21T01:25:36Z</dc:date>
    <item>
      <title>ASA default route ACL and default route redistributing/default-info config</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560652#M608633</link>
      <description>&lt;P&gt;I'm trying to release a default route learned via OSPF&amp;nbsp; into EIGRP in an ASA running version 8.2.2. my config is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router eigrp 1&lt;BR /&gt;redist ospf 1 metric 10000 100 100 100 1500 route-map STATIC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DEFAULT permit 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route-map STATIC permit 10&lt;BR /&gt; match ip address DEFAULT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;however, my upstream eigrp neig peering with the ASA seem to see all my other routes beside the default route. I can filter it out by putting a deny lines ahead fo the permit 0.0.0.0 of course but wondering am I writing to ACL correctly ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on a side note, if try to use this config instead, I don't see the default route on my upstream eigrp neig at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router eigrp 1&lt;/P&gt;&lt;P&gt;default-information out DEFAULT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DEFAULT permit 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route-map STATIC permit 10&lt;BR /&gt; match ip address DEFAULT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:57:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560652#M608633</guid>
      <dc:creator>kwanm63my</dc:creator>
      <dc:date>2019-03-11T18:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default route ACL and default route redistributing/defau</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560653#M608634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking into this at this point, Normally what you would do is to redistribute the whole protocol and filter. The ACL is not wrong, it is created as an standard ACL and what it is telling the ASA is not to redistribute only the default route, but you are telling him to redistribute everything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me get back to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2010 01:25:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560653#M608634</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-10-21T01:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default route ACL and default route redistributing/defau</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560654#M608635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sounds like 2 things ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) you have to redistribute the 'ENTIRE' protocol in a ASA....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) that's not how you write a 'default route' only ACL unlike a router ACL...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2010 02:23:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560654#M608635</guid>
      <dc:creator>kwanm63</dc:creator>
      <dc:date>2010-10-21T02:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default route ACL and default route redistributing/defau</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560655#M608636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for replying. I dont understand your last post. If you use that ACL you mention in the first post it is going to redistribute all routes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can be more specific on what you tried to say it would be great.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2010 02:27:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560655#M608636</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-10-21T02:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default route ACL and default route redistributing/defau</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560656#M608637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry MIke, Let's me just ask this for now.. I'm&amp;nbsp; really more of a routing /switching guy so I'm usually thinking from that perspective.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to write a default route only acl in a ASA ? In a router you can just do an acl or prefix-list to advertise a default route as follows..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip prefix-list DEFAULT-ONLY seq 10 permit 0.0.0.0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router eigrp 1&lt;/P&gt;&lt;P&gt; distribute-list prefix DEFAULT-ONLY out FastEthernet0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list standard DEFAULT&lt;BR /&gt; permit 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router eigrp 1&lt;/P&gt;&lt;P&gt;distribute-list DEFAULT&amp;nbsp; out fa0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so I was following the same logic, if I can write a default route only acl.. when I redistribute the protocol, then by using the acl, I will only redistribute the default route only...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope I'm more clear ..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2010 02:36:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560656#M608637</guid>
      <dc:creator>kwanm63</dc:creator>
      <dc:date>2010-10-21T02:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default route ACL and default route redistributing/defau</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560657#M608638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Great! Thanks a lot for the clarification, you are totally right...I tried your setup really quickly and the ASAgrabbed&amp;nbsp; that statement for 0.0.0.0 0.0.0.0 as everything instead of the default route :S&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess as a workaround you can create the default route on the ASA that will be doing the redistribution and if that is the only route, do the redistribute static.Or the other option would be just redistribute everything and filter on the receiving end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2010 03:13:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560657#M608638</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-10-21T03:13:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default route ACL and default route redistributing/defau</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560658#M608639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;unfortunally, I'm learning that defalt route via ospf so it will have to be a redistribute option. Luckily, it 's only 2&amp;nbsp; routes so filtering is an option.. However, if I had more routes , I can imagine how annoying it can be.&amp;nbsp; But believe it or not, I have another site in which my ASA has a static default route and even just doing a "redistribute static metric x x x x&amp;nbsp; x&amp;nbsp; route-map DEFAULT"&amp;nbsp;&amp;nbsp; only configuration into eigrp, it STILL redistributes ALL routes..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;the route-map DEFAULT references an acl which again is&amp;nbsp;&amp;nbsp; "access-list DEFAULT standard permit any" ..&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;. I think it's just an ASA thing....&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2010 03:28:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560658#M608639</guid>
      <dc:creator>kwanm63</dc:creator>
      <dc:date>2010-10-21T03:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA default route ACL and default route redistributing/defau</title>
      <link>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560659#M608640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember that the ASA with take all 0's as everything, it will not try to take the default route that he learned, he will redistribute everything. I tried with several versions and the same thing happened. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess filters will be the way to go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anything else just let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2010 03:36:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-default-route-acl-and-default-route-redistributing-default/m-p/1560659#M608640</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-10-21T03:36:34Z</dc:date>
    </item>
  </channel>
</rss>

