<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5510 Reverse Route Injection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383211#M857517</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I couldn't wait - I disabled ISAKMP and the dynamic map on the inside interface.&amp;nbsp; I was able to configure RRI on the outside interface.&amp;nbsp; I see the static entry on the ASA for the reverse route, but it doesn't appear in the EIGRP topology table.&amp;nbsp; And without it showing up in the topology table, it's not being advertised to neighbors.&amp;nbsp; Now what?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Jan 2010 01:40:34 GMT</pubDate>
    <dc:creator>Scott Pickles</dc:creator>
    <dc:date>2010-01-01T01:40:34Z</dc:date>
    <item>
      <title>ASA5510 Reverse Route Injection</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383210#M857515</link>
      <description>&lt;P&gt;ASA version 8.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ran the IPsec wizard on my 5510 for remote access.&amp;nbsp; It would seem that by default ISAKMP is enabled on both the inside and outside interfaces.&amp;nbsp; Furthermore, my default dynamic crypto map is enabled on both the inside and outside interfaces.&amp;nbsp; I would like to enable RRI for pools of addresses assigned to my remote workers.&amp;nbsp; Right now I have static routes - I'd ideally like RRI and redistribution.&amp;nbsp; Enabling RRI fails due to the fact that the dynamic mapping exists on multiple interfaces.&amp;nbsp; When I try to delete the map from the inside interface, it deletes the outside map as well.&amp;nbsp; So my questions are these:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Should I have ISAKMP enabled on my inside interface if I'm terminating my VPN tunnels on the outside interface?&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Is having ISAKMP enabled on the inside interface the reason why deleting the dynamic crypto map on the inside interface also deletes it from the outside interface? (this occurs in the ASDM, haven't tried it on the CLI).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can concede that I may have to configure this manually on the CLI as opposed to wizards due to the advanced configuration to enable RRI.&amp;nbsp; Any thoughts/suggestions would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Scott&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:52:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383210#M857515</guid>
      <dc:creator>Scott Pickles</dc:creator>
      <dc:date>2019-03-11T16:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510 Reverse Route Injection</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383211#M857517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I couldn't wait - I disabled ISAKMP and the dynamic map on the inside interface.&amp;nbsp; I was able to configure RRI on the outside interface.&amp;nbsp; I see the static entry on the ASA for the reverse route, but it doesn't appear in the EIGRP topology table.&amp;nbsp; And without it showing up in the topology table, it's not being advertised to neighbors.&amp;nbsp; Now what?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jan 2010 01:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383211#M857517</guid>
      <dc:creator>Scott Pickles</dc:creator>
      <dc:date>2010-01-01T01:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510 Reverse Route Injection</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383212#M857522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Scott,&lt;/P&gt;&lt;P&gt;Pls. refer this link below:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00809d07de.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00809d07de.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The link will talk about ospf.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did a quick research but didn't find any known issues with RRI and redistribution in 8.2.x code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jan 2010 03:07:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383212#M857522</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-01-01T03:07:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510 Reverse Route Injection</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383213#M857523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i configured RRI on my asa for a site to site vpn tunnel. however when the tunnel is down the route is still advertised to the network therefore preventing it from going via our altrenative path.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does anybody know how to stop redistributing a remote subnet when the tunnel is down?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Nov 2010 05:03:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383213#M857523</guid>
      <dc:creator>loizosko</dc:creator>
      <dc:date>2010-11-19T05:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510 Reverse Route Injection</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383214#M857525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;You could use SLA monitoring to help your purpose for L2L VPN's.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Instead of using RRI, you could configure a static route to the remote network via your primary link and a back route to the remote network via your back link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configure SLA tracking on the primary route. This should bring your back up route up if the VPN tunnel is down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Be sure to ping a host in the remote private network for the SLA tracking,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;STRONG&gt;type echo protocol ipIcmpEcho 10.0.0.1 interface outside&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;10.0.0.1 being a device in the remote network at the other end of the VPN tunnel&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;Let me know if you have any questions.&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;&lt;BR /&gt;Nash.&lt;BR /&gt;&lt;/PRE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Nov 2010 08:43:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383214#M857525</guid>
      <dc:creator>apothula</dc:creator>
      <dc:date>2010-11-19T08:43:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510 Reverse Route Injection</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383215#M857527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this might be a problem since the remote host will respond to icmp going via the backup link.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Nov 2010 13:32:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383215#M857527</guid>
      <dc:creator>loizosko</dc:creator>
      <dc:date>2010-11-19T13:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510 Reverse Route Injection</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383216#M857529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The backup link would not have the same ingress interface as the Primary link. Would it ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so we got a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Nash.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Nov 2010 13:56:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383216#M857529</guid>
      <dc:creator>apothula</dc:creator>
      <dc:date>2010-11-19T13:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510 Reverse Route Injection</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383217#M857531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the backup link will be from the inside interface. coming off lets say mpls network or another vpn device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the primary link will be from vpn.&lt;/P&gt;&lt;P&gt;i don't think you can specify a route just to go from a vpn, can you?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Nov 2010 14:00:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383217#M857531</guid>
      <dc:creator>loizosko</dc:creator>
      <dc:date>2010-11-19T14:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5510 Reverse Route Injection</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383218#M857532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Consider this set up,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; X&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Y&lt;/P&gt;&lt;P&gt;MPLS---Inside Network---- ASA---Outside/Internet---VPN Tunnel---- ASA/Router----Remote Site network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To get to the Remote site via the VPN tunnel, you obviously need to take the default route.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;So, you could add a route to the remote site Network with the internet gateway on the ASA as the next hop.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Something like,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 172.16.10.0 255.255.255.0 64.54.44.34 , 64.54.44.34 being the internet gateway on the ASA.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nash.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Nov 2010 15:06:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-reverse-route-injection/m-p/1383218#M857532</guid>
      <dc:creator>apothula</dc:creator>
      <dc:date>2010-11-19T15:06:41Z</dc:date>
    </item>
  </channel>
</rss>

