<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5505 Routing Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436362#M732674</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have recently added a layer2 leaf to my network configuring ASA's at each of my two locations. the remote site config is working fine but I have having major issues with my ASA5505. I use a tracked route to treat data going from my primary site to the remote site but the link keeps dropping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see below some of my config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.16.10 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 83.147.148.134 255.255.255.252&lt;BR /&gt;!&lt;BR /&gt;interface Vlan3&lt;BR /&gt; nameif digiwebl2&lt;BR /&gt; security-level 90&lt;BR /&gt; ip address 192.168.160.10 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; switchport access vlan 2&lt;BR /&gt; speed 100&lt;BR /&gt; duplex full&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt; switchport access vlan 3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;access-list L2_access_in extended permit icmp 192.168.160.0 255.255.255.0 192.168.160.0 255.255.255.0&lt;BR /&gt;access-list L2_access_in extended permit ip 192.168.20.0 255.255.255.0 192.168.16.0 255.255.255.0&lt;BR /&gt;access-list L2_access_in extended permit icmp 192.168.20.0 255.255.255.0 192.168.16.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;BR /&gt;access-group L2_access_in in interface digiwebl2&lt;BR /&gt;route digiwebl2 192.168.20.0 255.255.255.0 192.168.160.254 255 track 1&lt;BR /&gt;route inside 172.31.60.0 255.255.255.0 192.168.16.254 1&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 83.147.148.133 1&lt;BR /&gt;route outside 192.168.20.0 255.255.255.0 83.147.148.133 254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if I plug into ether0/4 I cannot ping back to the 192.168.16.10 interface which leads me to think that there is a bug somewhere on the applicance.&lt;/P&gt;&lt;P&gt;I have just had the device upgraded to version 7.2(5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Paul.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 18:16:30 GMT</pubDate>
    <dc:creator>pwynne2009</dc:creator>
    <dc:date>2019-03-11T18:16:30Z</dc:date>
    <item>
      <title>ASA5505 Routing Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436362#M732674</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have recently added a layer2 leaf to my network configuring ASA's at each of my two locations. the remote site config is working fine but I have having major issues with my ASA5505. I use a tracked route to treat data going from my primary site to the remote site but the link keeps dropping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see below some of my config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.16.10 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 83.147.148.134 255.255.255.252&lt;BR /&gt;!&lt;BR /&gt;interface Vlan3&lt;BR /&gt; nameif digiwebl2&lt;BR /&gt; security-level 90&lt;BR /&gt; ip address 192.168.160.10 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; switchport access vlan 2&lt;BR /&gt; speed 100&lt;BR /&gt; duplex full&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt; switchport access vlan 3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;access-list L2_access_in extended permit icmp 192.168.160.0 255.255.255.0 192.168.160.0 255.255.255.0&lt;BR /&gt;access-list L2_access_in extended permit ip 192.168.20.0 255.255.255.0 192.168.16.0 255.255.255.0&lt;BR /&gt;access-list L2_access_in extended permit icmp 192.168.20.0 255.255.255.0 192.168.16.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;BR /&gt;access-group L2_access_in in interface digiwebl2&lt;BR /&gt;route digiwebl2 192.168.20.0 255.255.255.0 192.168.160.254 255 track 1&lt;BR /&gt;route inside 172.31.60.0 255.255.255.0 192.168.16.254 1&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 83.147.148.133 1&lt;BR /&gt;route outside 192.168.20.0 255.255.255.0 83.147.148.133 254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if I plug into ether0/4 I cannot ping back to the 192.168.16.10 interface which leads me to think that there is a bug somewhere on the applicance.&lt;/P&gt;&lt;P&gt;I have just had the device upgraded to version 7.2(5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Paul.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:16:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436362#M732674</guid>
      <dc:creator>pwynne2009</dc:creator>
      <dc:date>2019-03-11T18:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Routing Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436363#M732683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paul,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; If you plug into Eth0/4 then you will be on Vlan 3 which is the 192.168.160.x subnet. While on this subnet, you will only be able to ping the interface facing you, the Vlan3 interface at 192.168.160.10. This is by design and summarized here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/trouble.html#wpmkr1048373"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/trouble.html#wpmkr1048373&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pN1_Note1"&gt;&lt;STRONG&gt;Note &lt;/STRONG&gt;&lt;IMG border="0" height="2" src="http://www.cisco.com/en/US/i/templates/blank.gif" width="1" /&gt;For&amp;nbsp; security purposes the security appliance does not support far-end&amp;nbsp; interface ping, that is pinging the IP address of the outside interface&amp;nbsp; from the inside network.&lt;/P&gt;&lt;P class="pN1_Note1"&gt;&lt;/P&gt;&lt;P class="pN1_Note1"&gt;This applies to other to-the-box traffic like telnet/ssh/asdm as well. You can only communicate withthe interface facing you. When you are plugged into Eth0/4, can you ping 192.168.160.10? Do you have any 'icmp permit' statements? What does 'show run icmp' show?&lt;/P&gt;&lt;P class="pN1_Note1"&gt;&lt;/P&gt;&lt;P class="pN1_Note1"&gt;- Magnus&lt;/P&gt;&lt;P class="pN1_Note1"&gt;&lt;/P&gt;&lt;P class="pN1_Note1"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jul 2010 10:53:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436363#M732683</guid>
      <dc:creator>Magnus Mortensen</dc:creator>
      <dc:date>2010-07-27T10:53:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Routing Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436364#M732693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Magnus,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i believe part of my issue is that I cannot ping the interface facing me. how i recovered this yesterday and only for a short period of time was to move another interface into the VLAN 3 but again this went down shortly after. Would you have any idea why it would not be able to ping the 192.168.160.10 interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jul 2010 10:58:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436364#M732693</guid>
      <dc:creator>pwynne2009</dc:creator>
      <dc:date>2010-07-27T10:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Routing Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436365#M732705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paul,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The interface should not go 'down' if a host is physically connected to the port. RIght after connecting the host to Eth0/4, can you ping 192.168.160.10? What is the output of 'show int vlan3' and 'show int eth0/4' at the time? Does your machine directly connected to Eth0/4 show any arp entries (on windows you can do 'arp -an' to see the arp cache).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Magnus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jul 2010 11:03:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436365#M732705</guid>
      <dc:creator>Magnus Mortensen</dc:creator>
      <dc:date>2010-07-27T11:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Routing Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436366#M732723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Strange thing is I cannot ping the interface when directly connected to ether0/4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Arp on the laptop returns an empty mac-address field. all Zero's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5505Crecora# sh int vlan 3&lt;BR /&gt;Interface Vlan3 "digiwebl2", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is EtherSVI&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC address 0024.9740.0af7, MTU 1500&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address 192.168.160.10, subnet mask 255.255.255.0&lt;BR /&gt;&amp;nbsp; Traffic Statistics for "digiwebl2":&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 46446 packets input, 7095832 bytes&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40823 packets output, 10948114 bytes&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1254 packets dropped&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute input rate 0 pkts/sec,&amp;nbsp; 80 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute output rate 0 pkts/sec,&amp;nbsp; 110 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 minute drop rate, 0 pkts/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute input rate 0 pkts/sec,&amp;nbsp; 83 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute output rate 0 pkts/sec,&amp;nbsp; 122 bytes/sec&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5 minute drop rate, 0 pkts/sec&lt;/P&gt;&lt;P&gt;5505Crecora# sh int ether0/4&lt;BR /&gt;Interface Ethernet0/4 "", is up, line protocol is up&lt;BR /&gt;&amp;nbsp; Hardware is 88E6095, BW 100 Mbps&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Auto-Duplex(Half-duplex), Auto-Speed(100 Mbps)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Available but not configured via nameif&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC address 0024.9740.0af3, MTU not set&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address unassigned&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 78844 packets input, 10359034 bytes, 0 no buffer&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Received 7 broadcasts, 0 runts, 0 giants&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 L2 decode drops&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 32373 switch ingress policy drops&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40843 packets output, 11718191 bytes, 0 underruns&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 41 output errors, 39 collisions, 0 interface resets&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 babbles, 0 late collisions, 30 deferred&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 lost carrier, 0 no carrier&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 input reset drops, 0 output reset drops&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 rate limit drops&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 switch egress policy drops&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;Paul.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jul 2010 12:42:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436366#M732723</guid>
      <dc:creator>pwynne2009</dc:creator>
      <dc:date>2010-07-27T12:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Routing Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436367#M732737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From your output, it seems like the interface Ethernet 0/4 is in half dulpex mode. This looks more like a physical layer issue. What kind of Ethernet cable you are using? Could you please try straight cable instead of crossover (if you are using crossover)? Also, check the speed/duplex settings on the laptop and make sure that they are set to auto. If we can fix the physical layer issue, I guess the other issues will get fixed automatically.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jul 2010 13:20:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436367#M732737</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-07-27T13:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Routing Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436368#M732743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just got a reply from the NOC at my SP regarding the layer 2 supplied and I think this may explain it however not quite sure how to get around it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;"Both connections to our switch on site with you in Limerick should be set to 100mbit full duplex with auto-negotiation turned off.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;Both the internet and the layer2 connections are presented as access ports on the switch on site with you in Limerick, so there should be no vlan tagging presented to our switch on either port."&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;Paul.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="font-family: Calibri; color: #000000; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jul 2010 14:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436368#M732743</guid>
      <dc:creator>pwynne2009</dc:creator>
      <dc:date>2010-07-27T14:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Routing Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436369#M732755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok! the physical side of things is now sorted however a sh conn address 192.168.16.57 (My IP) is showin paths out over the VPN still but some traffic is going up the layer2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need the vpn as a backup so i dont want to take it down. can i clear out the connections learned my the ASA so the tracked route will take preference?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jul 2010 14:55:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436369#M732755</guid>
      <dc:creator>pwynne2009</dc:creator>
      <dc:date>2010-07-27T14:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Routing Issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436370#M732761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok! I can answer this one now myself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once the ping issue from the interface back to the Firewall interface was resolved there was still little or no utilization of the layer2 pipe. The reason for this was that all users were working from previously learned paths which in this case was the VPN connection. this was identified through the&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"sh conn address 192.168.16.57" - My IP address. "sh conn" showed that all other users were using VPN also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I issued a "clear conn all" and this dropped the ASA connection momentarily but it enforced the tracked route entry in the firewall and now over 90% of my traffic is using the Layer2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Magnus thanks for your assistance with the MAC issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jul 2010 09:20:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-routing-issue/m-p/1436370#M732761</guid>
      <dc:creator>pwynne2009</dc:creator>
      <dc:date>2010-07-28T09:20:09Z</dc:date>
    </item>
  </channel>
</rss>

