<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about routes in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/question-about-routes/m-p/1432573#M820743</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sidcracker,&lt;/P&gt;&lt;P&gt;only permitted traffic is allowed to pass through firewall, means if you have allowed ping (ICMP type &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; in firewall then only it crosses firewall otherwise it drops at firewall. other config is ok.&lt;/P&gt;&lt;P&gt;hope this helps a bit in troubleshooting this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jigar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Aug 2010 04:34:51 GMT</pubDate>
    <dc:creator>Jigar Dave</dc:creator>
    <dc:date>2010-08-19T04:34:51Z</dc:date>
    <item>
      <title>Question about routes</title>
      <link>https://community.cisco.com/t5/network-security/question-about-routes/m-p/1432569#M820673</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 redundant layer 3 switches which are connected to the core router. The switches are also connected to the redundant firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ISP Network&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Core Router &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;BR /&gt;Redundant Layer 3Core Switch ----------Redundant Firewalls -------- VPN Router---------Core Router ---------Internet&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a default route on the Core switch saying all traffic goes towards the Core Router. I add a route on the Firewall saying that a host (20.20.20.20) should go towards the VPN router. I add NAT statement to nat the traffic towards the VPN router and out the Internet. When I ping from the firewall to 20.20.20.20 it doesnt ping. However when i remove the nats and the routes it pings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is if there is a default route on the switch pointing to the core router, then will another specific static route on the firewall towards the VPN router work? it should work since its logical that I am pinging from the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my nat statement&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 10 access-list site_to_site&lt;/P&gt;&lt;P&gt;global (vpn-network) 10 192.168.10.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list site_to_site extended permit ip object-group internal_hosts host 20.20.20.20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:27:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-routes/m-p/1432569#M820673</guid>
      <dc:creator>sidcracker</dc:creator>
      <dc:date>2019-03-11T18:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Question about routes</title>
      <link>https://community.cisco.com/t5/network-security/question-about-routes/m-p/1432570#M820677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #0000ff; font-size: 12pt; font-family: Tahoma; "&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Tahoma; color: #0000ff; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #0000ff; font-size: 12pt; font-family: Tahoma; "&gt;Your NAT configuration are perfectly OK.After configured NAT on the firewalls, have you tried to ping from core switch.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Tahoma; color: #0000ff; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #0000ff; font-size: 12pt; font-family: Tahoma; "&gt;One more thing, Default route point towards which core router. since you have mentioned two core router, i am bit confused.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Tahoma; color: #0000ff; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #0000ff; font-size: 12pt; font-family: Tahoma; "&gt;If you have default route point towards ISP core router, then you need to configure specific routes to reach internet towards firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: Tahoma; color: #0000ff; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #0000ff; font-size: 12pt; font-family: Tahoma; "&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoPlainText" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #0000ff; font-size: 12pt; font-family: Tahoma; "&gt;Samy&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Aug 2010 02:17:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-routes/m-p/1432570#M820677</guid>
      <dc:creator>KARUPPUCHAMY MALAIYANDI</dc:creator>
      <dc:date>2010-08-19T02:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: Question about routes</title>
      <link>https://community.cisco.com/t5/network-security/question-about-routes/m-p/1432571#M820700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Samy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default route goes towards the ISP Router from the switch. Even if this is the case, since i have a default route on the firewall telling it to pass traffic towards the VPN router, isnt it logical that if i am pinging from the firewall it should pass towards the vpn router. The switches are behind the firewall so it wont even be looking at that side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Aug 2010 02:34:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-routes/m-p/1432571#M820700</guid>
      <dc:creator>sidcracker</dc:creator>
      <dc:date>2010-08-19T02:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Question about routes</title>
      <link>https://community.cisco.com/t5/network-security/question-about-routes/m-p/1432572#M820719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have default routes on the firewall towards the VPN, then no need of specific routes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am saying that after you have done NAT on firewall, have you tried to ping to 20.xx.xx.xx IP from core switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Samy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Aug 2010 02:39:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-routes/m-p/1432572#M820719</guid>
      <dc:creator>KARUPPUCHAMY MALAIYANDI</dc:creator>
      <dc:date>2010-08-19T02:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Question about routes</title>
      <link>https://community.cisco.com/t5/network-security/question-about-routes/m-p/1432573#M820743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sidcracker,&lt;/P&gt;&lt;P&gt;only permitted traffic is allowed to pass through firewall, means if you have allowed ping (ICMP type &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; in firewall then only it crosses firewall otherwise it drops at firewall. other config is ok.&lt;/P&gt;&lt;P&gt;hope this helps a bit in troubleshooting this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jigar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Aug 2010 04:34:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-about-routes/m-p/1432573#M820743</guid>
      <dc:creator>Jigar Dave</dc:creator>
      <dc:date>2010-08-19T04:34:51Z</dc:date>
    </item>
  </channel>
</rss>

