<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: problem using same-security-traffic permit intra-interface i in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-using-same-security-traffic-permit-intra-interface-in/m-p/1332332#M811876</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You wouldn't need it if this were a router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also do..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,inside) 10.8.0.0 10.8.0.0 netmask 255.255.0.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 31 Jul 2009 16:06:10 GMT</pubDate>
    <dc:creator>acomiskey</dc:creator>
    <dc:date>2009-07-31T16:06:10Z</dc:date>
    <item>
      <title>problem using same-security-traffic permit intra-interface in inside Interf</title>
      <link>https://community.cisco.com/t5/network-security/problem-using-same-security-traffic-permit-intra-interface-in/m-p/1332329#M811873</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem on using same-security-traffic permit intra-interface at ASA5505, although I enable "same-security-traffic permit intra-interface", the TCP connection still can't be built-up, but icmp is no problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't make the TCP connection from 10.8.103.100 to 10.8.111.103, but I can ping from 10.8.103.100 to 10.8.111.103, the routing should be no problem. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC 10.13.1.10 can't configure subnet route for 192.168.1.0/24 via 10.13.1.201, only default route is configured to 10.13.1.254.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface eth2&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.8.103.53 255.255.255.0 standby 10.8.103.54&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside-in extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 10.8.111.0 255.255.255.0 10.8.103.5 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list gcot_acl line 49 extended permit tcp host 10.8.111.103 eq telnet 10.8.103.100 255.255.255.0 (hitcnt=16) 0x9fe49e6b&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oct 04 2008 17:46:41: %ASA-6-106015: Deny TCP (no connection) from 10.8.111.103/23 to 10.8.103.100/40962 flags SYN ACK on interface gcot&lt;/P&gt;&lt;P&gt;Oct 04 2008 17:46:43: %ASA-6-106015: Deny TCP (no connection) from 10.8.111.103/23 to 10.8.103.100/40962 flags ACK on interface gcot&lt;/P&gt;&lt;P&gt;Oct 04 2008 17:46:43: %ASA-6-106015: Deny TCP (no connection) from 10.8.111.103/23 to 10.8.103.100/40962 flags SYN ACK on interface gcot&lt;/P&gt;&lt;P&gt;Oct 04 2008 17:46:47: %ASA-6-106015: Deny TCP (no connection) from 10.8.111.103/23 to 10.8.103.100/40962 flags ACK on interface gcot&lt;/P&gt;&lt;P&gt;Oct 04 2008 17:46:47: %ASA-6-106015: Deny TCP (no connection) from 10.8.111.103/23 to 10.8.103.100/40962 flags SYN ACK on interface gcot&lt;/P&gt;&lt;P&gt;Oct 04 2008 17:46:55: %ASA-6-106015: Deny TCP (no connection) from 10.8.111.103/23 to 10.8.103.100/40962 flags ACK on interface gcot&lt;/P&gt;&lt;P&gt;Oct 04 2008 17:46:55: %ASA-6-106015: Deny TCP (no connection) from 10.8.111.103/23 to 10.8.103.100/40962 flags SYN ACK on interface gcot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What configuration am I missing, please advise, your help is much apppreciated, thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:01:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-using-same-security-traffic-permit-intra-interface-in/m-p/1332329#M811873</guid>
      <dc:creator>wilverav05</dc:creator>
      <dc:date>2019-03-11T16:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: problem using same-security-traffic permit intra-interface i</title>
      <link>https://community.cisco.com/t5/network-security/problem-using-same-security-traffic-permit-intra-interface-in/m-p/1332330#M811874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This should get it going, but may not be exactly what you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0 &lt;/P&gt;&lt;P&gt;global (inside) 1 interface&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Jul 2009 12:43:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-using-same-security-traffic-permit-intra-interface-in/m-p/1332330#M811874</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2009-07-31T12:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: problem using same-security-traffic permit intra-interface i</title>
      <link>https://community.cisco.com/t5/network-security/problem-using-same-security-traffic-permit-intra-interface-in/m-p/1332331#M811875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But is needed that translation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Functionality should be a redirect from the traffic  on the interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Jul 2009 15:15:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-using-same-security-traffic-permit-intra-interface-in/m-p/1332331#M811875</guid>
      <dc:creator>wilverav05</dc:creator>
      <dc:date>2009-07-31T15:15:20Z</dc:date>
    </item>
    <item>
      <title>Re: problem using same-security-traffic permit intra-interface i</title>
      <link>https://community.cisco.com/t5/network-security/problem-using-same-security-traffic-permit-intra-interface-in/m-p/1332332#M811876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You wouldn't need it if this were a router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also do..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,inside) 10.8.0.0 10.8.0.0 netmask 255.255.0.0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Jul 2009 16:06:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-using-same-security-traffic-permit-intra-interface-in/m-p/1332332#M811876</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2009-07-31T16:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: problem using same-security-traffic permit intra-interface i</title>
      <link>https://community.cisco.com/t5/network-security/problem-using-same-security-traffic-permit-intra-interface-in/m-p/1332333#M811877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is your setup like because no matter what configuration you put it on the firewall it won't work. All traffic must flow through the firewall in order for it to work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Jul 2009 18:36:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-using-same-security-traffic-permit-intra-interface-in/m-p/1332333#M811877</guid>
      <dc:creator>kwillacey</dc:creator>
      <dc:date>2009-07-31T18:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: problem using same-security-traffic permit intra-interface i</title>
      <link>https://community.cisco.com/t5/network-security/problem-using-same-security-traffic-permit-intra-interface-in/m-p/1332334#M811878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would like to know if the "same-security-traffic permit intra-interface"  command in the ASA Firewall can supplement the functionalities of does a router redirect?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Aug 2009 21:03:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-using-same-security-traffic-permit-intra-interface-in/m-p/1332334#M811878</guid>
      <dc:creator>wilverav05</dc:creator>
      <dc:date>2009-08-03T21:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: problem using same-security-traffic permit intra-interface i</title>
      <link>https://community.cisco.com/t5/network-security/problem-using-same-security-traffic-permit-intra-interface-in/m-p/1332335#M811879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One-arm routing/U-Turning-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;	&lt;/P&gt;&lt;P&gt;	&lt;/P&gt;&lt;P&gt;		-------&lt;/P&gt;&lt;P&gt;		| ASA |&lt;/P&gt;&lt;P&gt;		-------192.168.1.1&lt;/P&gt;&lt;P&gt;		   |&lt;/P&gt;&lt;P&gt;		   |&lt;/P&gt;&lt;P&gt;		--------192.168.1.0/24 n/w&lt;/P&gt;&lt;P&gt;	    ----|Switch|----&lt;/P&gt;&lt;P&gt;	    |   --------   |&lt;/P&gt;&lt;P&gt;	    |              |&lt;/P&gt;&lt;P&gt;      192.168.1.10      -------192.168.1.2(F0)&lt;/P&gt;&lt;P&gt;          host          |Router|&lt;/P&gt;&lt;P&gt;			-------192.168.2.1(F1)&lt;/P&gt;&lt;P&gt;			   |&lt;/P&gt;&lt;P&gt;		  --------------------&lt;/P&gt;&lt;P&gt;		  |192.168.2.0/24 n/w|&lt;/P&gt;&lt;P&gt;		  --------------------&lt;/P&gt;&lt;P&gt;			   |&lt;/P&gt;&lt;P&gt;		      192.168.2.10&lt;/P&gt;&lt;P&gt;                          host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer to above topology-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Inside interface: 		192.168.1.1&lt;/P&gt;&lt;P&gt;ASA Inside interface n/w:	192.168.1.0/24&lt;/P&gt;&lt;P&gt;Internal router F0 interface:	192.168.1.2 &lt;/P&gt;&lt;P&gt;Internal router F1 interface:	192.168.2.1 &lt;/P&gt;&lt;P&gt;Network behind router:		192.168.2.0/24&lt;/P&gt;&lt;P&gt;Gateway IP of router:		192.168.1.1&lt;/P&gt;&lt;P&gt;Gateway of 192.168.1.0/24 n/w:	192.168.1.1&lt;/P&gt;&lt;P&gt;Gatewau of 192.168.2.0/24 n/w:	192.168.2.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Requirement-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.1.0/24 and 192.168.2.0/24 networks should be able to talk each other.&lt;/P&gt;&lt;P&gt;Hence, access to both networks should be available in both directions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,inside) 192.168.1.0 192.168.1.0 netmask 255.255.255.0 norandom nailed&lt;/P&gt;&lt;P&gt;static (inside,inside) 192.168.2.0 192.168.2.0 netmask 255.255.255.0 norandom nailed&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;sysopt noproxyarp inside&lt;/P&gt;&lt;P&gt;failover timeout -1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why would command set 1 cause issues? Using following static command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,inside) 192.168.1.0 192.168.1.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are telling firewall to proxyarp for any IP address in 192.168.1.0/24 network.&lt;/P&gt;&lt;P&gt;Now if host 192.168.1.10 needs to talk to 192.168.1.20, it would do and ARP for&lt;/P&gt;&lt;P&gt;192.168.1.20. In this case, this ARP request would reach both firewall inside&lt;/P&gt;&lt;P&gt;interface as well as the actual host 192.168.1.20. Both will respond with their&lt;/P&gt;&lt;P&gt;own MAC-Address. Now it depends which response gets to 192.168.1.10 first. If it&lt;/P&gt;&lt;P&gt;receives response from firewall first, communication will not work, if it receives&lt;/P&gt;&lt;P&gt;resposne from actual host first then only communication would work. Hence, customer&lt;/P&gt;&lt;P&gt;would face intermittent issues in his internal network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We had to use norandom nailed option along with failover time -1 command to enable&lt;/P&gt;&lt;P&gt;assymetric routing for these networks when sending traffic to same interface destination.&lt;/P&gt;&lt;P&gt;This is required as response for some requests would not be seen by firewall and&lt;/P&gt;&lt;P&gt;if stateful filtering is on, communication would be dropped by firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Aug 2009 21:05:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-using-same-security-traffic-permit-intra-interface-in/m-p/1332335#M811879</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2009-08-03T21:05:44Z</dc:date>
    </item>
  </channel>
</rss>

