<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing problem with ASA5520 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/routing-problem-with-asa5520/m-p/1208233#M876442</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why do you have 3 ACL's applied to the inside interface and 2 applied to the DMZ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group Core_access_in_1 in interface Core control-plane&lt;/P&gt;&lt;P&gt;access-group outside-in-acl in interface Core&lt;/P&gt;&lt;P&gt;access-group Core_access_out out interface Core&lt;/P&gt;&lt;P&gt;access-group outside-in-acl in interface DMZ&lt;/P&gt;&lt;P&gt;access-group DMZ_access_out out interface DMZ&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 Feb 2009 16:13:17 GMT</pubDate>
    <dc:creator>eddie.mitchell</dc:creator>
    <dc:date>2009-02-13T16:13:17Z</dc:date>
    <item>
      <title>Routing problem with ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem-with-asa5520/m-p/1208232#M876441</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having issues with routing on 2 ASA 5520 and wondering if anyone can help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is some of the running config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The setup is basically 2 asa 5520s running in a active/active configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3 out of the four interfaces are used and one for failover between each box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an interface dedicated to each zone as such:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Core (inside) 10.1.0.0&lt;/P&gt;&lt;P&gt;DMZ 10.8.0.0&lt;/P&gt;&lt;P&gt;Outside 11.1.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I have been trying to enable routing between the inside interface and the DMZ, and vice versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example I would like a host in the inside zone to be able to ping a host in the DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added exception for ICMP and also allow it both ways. To which it doesn't appear to work, also tried the same but for a host inside to connect to a web server in the dmz.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everytime I run the packet trace wizard in the ASDM it is almost like the ACL rules and not being picked up and am told that the implicit deny is causing the packet to be dropped?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried many combinations of nat exemptions and acl rules&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:50:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem-with-asa5520/m-p/1208232#M876441</guid>
      <dc:creator>asecisco1</dc:creator>
      <dc:date>2019-03-11T14:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Routing problem with ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem-with-asa5520/m-p/1208233#M876442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why do you have 3 ACL's applied to the inside interface and 2 applied to the DMZ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group Core_access_in_1 in interface Core control-plane&lt;/P&gt;&lt;P&gt;access-group outside-in-acl in interface Core&lt;/P&gt;&lt;P&gt;access-group Core_access_out out interface Core&lt;/P&gt;&lt;P&gt;access-group outside-in-acl in interface DMZ&lt;/P&gt;&lt;P&gt;access-group DMZ_access_out out interface DMZ&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Feb 2009 16:13:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem-with-asa5520/m-p/1208233#M876442</guid>
      <dc:creator>eddie.mitchell</dc:creator>
      <dc:date>2009-02-13T16:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Routing problem with ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem-with-asa5520/m-p/1208234#M876443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe the ASDM created them the first time I used it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Feb 2009 16:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem-with-asa5520/m-p/1208234#M876443</guid>
      <dc:creator>asecisco1</dc:creator>
      <dc:date>2009-02-13T16:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: Routing problem with ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem-with-asa5520/m-p/1208235#M876444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Verify your NAT rule or turn off the NATing from inside to DMZ.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Feb 2009 22:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem-with-asa5520/m-p/1208235#M876444</guid>
      <dc:creator>boots</dc:creator>
      <dc:date>2009-02-13T22:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: Routing problem with ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem-with-asa5520/m-p/1208236#M876445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have added a nat exmeption rule and tried specifying both explicit source and destinations ip addresses of the hosts as well as any any but still doesn't seem to route.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Feb 2009 08:48:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem-with-asa5520/m-p/1208236#M876445</guid>
      <dc:creator>asecisco1</dc:creator>
      <dc:date>2009-02-16T08:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: Routing problem with ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem-with-asa5520/m-p/1208237#M876446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I belive the problem is with ACL "outside-in-acl".  This has been applied to both the DMZ and Core interfaces.  So you need to allow icmp echo and icmp echo-reply on this ACL ie&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside-in-acl extended permit icmp any any echo&lt;/P&gt;&lt;P&gt;access-list outside-in-acl extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please try adding and let us know the result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Feb 2009 12:51:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem-with-asa5520/m-p/1208237#M876446</guid>
      <dc:creator>JamesLuther</dc:creator>
      <dc:date>2009-02-16T12:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: Routing problem with ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/routing-problem-with-asa5520/m-p/1208238#M876447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried to add that rule to any and all access-lists just in case and still get the same result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I used the built in packet inspection tool it seems that the implicit deny deny is causing the packet to be dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also tried to follow the information on &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080734db7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and still seem to end up with the same result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you got any other sugesstions you could help with?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Feb 2009 14:10:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-problem-with-asa5520/m-p/1208238#M876447</guid>
      <dc:creator>asecisco1</dc:creator>
      <dc:date>2009-02-16T14:10:38Z</dc:date>
    </item>
  </channel>
</rss>

