<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote connection on inside interface ASA5505 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/remote-connection-on-inside-interface-asa5505/m-p/1067672#M894335</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check the IP addressing for the local LAN and the remote PC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Oct 2008 17:54:14 GMT</pubDate>
    <dc:creator>andrew.prince</dc:creator>
    <dc:date>2008-10-29T17:54:14Z</dc:date>
    <item>
      <title>Remote connection on inside interface ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/remote-connection-on-inside-interface-asa5505/m-p/1067671#M894333</link>
      <description>&lt;P&gt;We're upgrading our network. As a part of the process we're replacing our 1750 Routers with a ASA 5505 with the latest software version 8.0.4.&lt;/P&gt;&lt;P&gt;As far as ACLs, NAT'ing and routing goes so the config is the same on the new box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is with a remote PC we have on the other end of a point to point SHDSL connection. The connection is VLAN, layer2 based and there are no routers in between, just a modem at each end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what happens is that traffic is dropped on the inside interface of the ASA box from the remote PC. Traffic from the ASA to the remote PC (ping for example) is fine, also the remote PC can ping other IP addresses at the other end of the DSL line but not the inside IP of the ASA.&lt;/P&gt;&lt;P&gt;It makes no difference if the link from the remote site is connected directly to an ASA port or via another switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've discovered that if we clear the ARP cache of the remote PC we get 1 ping reply before traffic is dropped.&lt;/P&gt;&lt;P&gt;Pinging the remote site from the ASA works though we experience a certain amount of lost packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's something about the ASA and this type of link that's causing this but we don't know what. Our best guess is that it's some kind of security feature ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Put in a PC with the same inside IP, mac address as the ASA, cable etc. and traffic flows both ways without a problem which is why we think it's down to the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;is already enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions ? We're stuck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Uli&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:04:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-connection-on-inside-interface-asa5505/m-p/1067671#M894333</guid>
      <dc:creator>Iske</dc:creator>
      <dc:date>2019-03-11T14:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Remote connection on inside interface ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/remote-connection-on-inside-interface-asa5505/m-p/1067672#M894335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check the IP addressing for the local LAN and the remote PC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Oct 2008 17:54:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-connection-on-inside-interface-asa5505/m-p/1067672#M894335</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-10-29T17:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: Remote connection on inside interface ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/remote-connection-on-inside-interface-asa5505/m-p/1067673#M894336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like we got it, the provider uses a different vlan tag for the shdsl connection but&lt;/P&gt;&lt;P&gt;uses the same ip network 192.168.x.x. So we&lt;/P&gt;&lt;P&gt;have vlan 1 on the inside Network and vlan 101 over the shdsl connection. We're now trying the&lt;/P&gt;&lt;P&gt;Security Plus License and define a trunk on the&lt;/P&gt;&lt;P&gt;inside Interface with vlan 1 and 101. Hope&lt;/P&gt;&lt;P&gt;this will work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Nov 2008 18:06:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/remote-connection-on-inside-interface-asa5505/m-p/1067673#M894336</guid>
      <dc:creator>Iske</dc:creator>
      <dc:date>2008-11-08T18:06:42Z</dc:date>
    </item>
  </channel>
</rss>

