<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Intra-Interface Communications in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/intra-interface-communications/m-p/1502749#M639983</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems like you are referring to Assymmetric routing problem. In such a situation, all non-connection oriented traffic will work fine. But conneciton oriented traffic (TCP based) will suffer. You have couple of options. The easiest one is to make the L3 switch as the gateway for your exchange server. This way, the switch will make the routing decision for the exchange traffic and will deliver all local lan traffic to respective VLAN interfaces and internet traffic to the firewall. The other option, if you are running 8.2 code version, is to configure TCP state bypass. This will ask the firewall not to keep track of the TCP status of certain traffic. Here is a document that outlines the configuration requirements for TCP State bypass.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_tcpstatebypass.pdf"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_tcpstatebypass.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Jul 2010 12:49:23 GMT</pubDate>
    <dc:creator>Nagaraja Thanthry</dc:creator>
    <dc:date>2010-07-12T12:49:23Z</dc:date>
    <item>
      <title>Intra-Interface Communications</title>
      <link>https://community.cisco.com/t5/network-security/intra-interface-communications/m-p/1502748#M639982</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have problem with communications through ASA to MS exchange server.&lt;/P&gt;&lt;P&gt;I'm testing new connection to the internet and ASA is a default-gateway for my VLAN (user VLAN).&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It's a similar problem described in this doc '&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/products/ps6120/products_tech_note09186a0080734db7.shtml" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/ps6120/products_tech_note09186a0080734db7.shtml&lt;/A&gt;&lt;SPAN&gt;'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The diferrence is that I'm connected to L3 switch but it doesn't matter in this situation.&lt;/P&gt;&lt;P&gt;All services (DNS, DHCP) in LAN works but I have problem with connection to exchange server only.&lt;/P&gt;&lt;P&gt;That mentioned services are VLAN's separated and on ASA is static routing added to this networks.&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" id="result_box"&gt;&lt;SPAN&gt;I have&amp;nbsp; no ACL blocking traffic on inside interface.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" id="result_box"&gt;&lt;SPAN&gt;Does&amp;nbsp; anyone have a similar problem?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3 class="r"&gt;&lt;A class="l" href="http://en.wikipedia.org/wiki/Default_gateway" onmousedown="" target="_blank"&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/A&gt;&lt;/H3&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:10:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intra-interface-communications/m-p/1502748#M639982</guid>
      <dc:creator>wkamil123</dc:creator>
      <dc:date>2019-03-11T18:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: Intra-Interface Communications</title>
      <link>https://community.cisco.com/t5/network-security/intra-interface-communications/m-p/1502749#M639983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems like you are referring to Assymmetric routing problem. In such a situation, all non-connection oriented traffic will work fine. But conneciton oriented traffic (TCP based) will suffer. You have couple of options. The easiest one is to make the L3 switch as the gateway for your exchange server. This way, the switch will make the routing decision for the exchange traffic and will deliver all local lan traffic to respective VLAN interfaces and internet traffic to the firewall. The other option, if you are running 8.2 code version, is to configure TCP state bypass. This will ask the firewall not to keep track of the TCP status of certain traffic. Here is a document that outlines the configuration requirements for TCP State bypass.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_tcpstatebypass.pdf"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/conns_tcpstatebypass.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jul 2010 12:49:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intra-interface-communications/m-p/1502749#M639983</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-07-12T12:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: Intra-Interface Communications</title>
      <link>https://community.cisco.com/t5/network-security/intra-interface-communications/m-p/1502750#M639984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The TCP State bypass resolved problem.&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards Kamil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jul 2010 14:46:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intra-interface-communications/m-p/1502750#M639984</guid>
      <dc:creator>wkamil123</dc:creator>
      <dc:date>2010-07-12T14:46:38Z</dc:date>
    </item>
  </channel>
</rss>

