<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTD failed simulation : Drop-reason: (no-adjacency) No valid adjacency in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-failed-simulation-drop-reason-no-adjacency-no-valid/m-p/3352976#M924213</link>
    <description>&lt;P&gt;Hi team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm simulating packet tracer before putting my FTD on production:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when sending a packet from a Lan machine to google :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I get always this result :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Result:&lt;/P&gt;
&lt;P&gt;input-interface: inside&lt;/P&gt;
&lt;P&gt;input-status: up&lt;/P&gt;
&lt;P&gt;input-line-status: up&lt;/P&gt;
&lt;P&gt;output-interface: outside&lt;/P&gt;
&lt;P&gt;output-status: up&lt;/P&gt;
&lt;P&gt;output-line-status: up&lt;/P&gt;
&lt;P&gt;Action: drop&lt;/P&gt;
&lt;P&gt;Drop-reason: (no-adjacency) No valid adjacency&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="X10.png" style="width: 916px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/9257i1056ED7465405AE5/image-size/large?v=v2&amp;amp;px=999" role="button" title="X10.png" alt="X10.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does any one knows if this message (&lt;SPAN&gt;Drop-reason: (no-adjacency) No valid adjacency) means a NAT problem or routing problem ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:32:58 GMT</pubDate>
    <dc:creator>sam cook</dc:creator>
    <dc:date>2020-02-21T15:32:58Z</dc:date>
    <item>
      <title>FTD failed simulation : Drop-reason: (no-adjacency) No valid adjacency</title>
      <link>https://community.cisco.com/t5/network-security/ftd-failed-simulation-drop-reason-no-adjacency-no-valid/m-p/3352976#M924213</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm simulating packet tracer before putting my FTD on production:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when sending a packet from a Lan machine to google :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I get always this result :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Result:&lt;/P&gt;
&lt;P&gt;input-interface: inside&lt;/P&gt;
&lt;P&gt;input-status: up&lt;/P&gt;
&lt;P&gt;input-line-status: up&lt;/P&gt;
&lt;P&gt;output-interface: outside&lt;/P&gt;
&lt;P&gt;output-status: up&lt;/P&gt;
&lt;P&gt;output-line-status: up&lt;/P&gt;
&lt;P&gt;Action: drop&lt;/P&gt;
&lt;P&gt;Drop-reason: (no-adjacency) No valid adjacency&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="X10.png" style="width: 916px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/9257i1056ED7465405AE5/image-size/large?v=v2&amp;amp;px=999" role="button" title="X10.png" alt="X10.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does any one knows if this message (&lt;SPAN&gt;Drop-reason: (no-adjacency) No valid adjacency) means a NAT problem or routing problem ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:32:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-failed-simulation-drop-reason-no-adjacency-no-valid/m-p/3352976#M924213</guid>
      <dc:creator>sam cook</dc:creator>
      <dc:date>2020-02-21T15:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: FTD failed simulation : Drop-reason: (no-adjacency) No valid adjacency</title>
      <link>https://community.cisco.com/t5/network-security/ftd-failed-simulation-drop-reason-no-adjacency-no-valid/m-p/3352991#M924214</link>
      <description>&lt;P&gt;Generally that would be a routing issue. Although since your target is a FQDN it could also be DNS lookup. Substitute a target public IP to rule that out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you configured a default route on the device?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 10:18:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-failed-simulation-drop-reason-no-adjacency-no-valid/m-p/3352991#M924214</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-03-22T10:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: FTD failed simulation : Drop-reason: (no-adjacency) No valid adjacency</title>
      <link>https://community.cisco.com/t5/network-security/ftd-failed-simulation-drop-reason-no-adjacency-no-valid/m-p/3352995#M924215</link>
      <description>&lt;P&gt;Thank you Marvin ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In fact I found the issue :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;seen that I'm testing this outside the production , the FTD did not find the mac adress of next hop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So i think when i will put it in production , it will resolve the mac adress and packet will be allowed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 10:33:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-failed-simulation-drop-reason-no-adjacency-no-valid/m-p/3352995#M924215</guid>
      <dc:creator>sam cook</dc:creator>
      <dc:date>2018-03-22T10:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: FTD failed simulation : Drop-reason: (no-adjacency) No valid adjacency</title>
      <link>https://community.cisco.com/t5/network-security/ftd-failed-simulation-drop-reason-no-adjacency-no-valid/m-p/4057354#M1068617</link>
      <description>&lt;P&gt;◄ I have same issue ►&lt;/P&gt;&lt;P&gt;packet-tracer input inside icmp 70.1.2.2 8 0 172.16.111.100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 13&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 172.16.111.100 using egress ifc outside&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (no-adjacency) No valid adjacency&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;==========[ fix ]&amp;nbsp;==========&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;no xlate per-session deny tcp any4 any4&lt;BR /&gt;no xlate per-session deny tcp any4 any6&lt;BR /&gt;no xlate per-session deny tcp any6 any4&lt;BR /&gt;no xlate per-session deny tcp any6 any6&lt;BR /&gt;no xlate per-session deny udp any4 any4 eq domain&lt;BR /&gt;no xlate per-session deny udp any4 any6 eq domain&lt;BR /&gt;no xlate per-session deny udp any6 any4 eq domain&lt;BR /&gt;no xlate per-session deny udp any6 any6 eq domain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;========[ verification ]&amp;nbsp;========&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 13&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 192.168.201.111 using egress ifc outside&lt;/P&gt;&lt;P&gt;Phase: 14&lt;BR /&gt;Type: ADJACENCY-LOOKUP&lt;BR /&gt;Subtype: next-hop and adjacency&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;adjacency Active&lt;BR /&gt;next-hop mac address 5254.0094.9ec5 hits 31930 reference 3&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Hossam&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 04:16:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-failed-simulation-drop-reason-no-adjacency-no-valid/m-p/4057354#M1068617</guid>
      <dc:creator>hossam helal</dc:creator>
      <dc:date>2020-04-02T04:16:36Z</dc:date>
    </item>
    <item>
      <title>Re: FTD failed simulation : Drop-reason: (no-adjacency) No valid adjacency</title>
      <link>https://community.cisco.com/t5/network-security/ftd-failed-simulation-drop-reason-no-adjacency-no-valid/m-p/4057358#M1068618</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; This is either a bug, either there is no valid adjacency (IP-to-MAC binding) for the next-hop.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 04:34:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-failed-simulation-drop-reason-no-adjacency-no-valid/m-p/4057358#M1068618</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-04-02T04:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: FTD failed simulation : Drop-reason: (no-adjacency) No valid adjacency</title>
      <link>https://community.cisco.com/t5/network-security/ftd-failed-simulation-drop-reason-no-adjacency-no-valid/m-p/4059580#M1068809</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I use that version&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA# show version&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.9(1)&lt;BR /&gt;Firepower Extensible Operating System Version 2.3(1.54)&lt;BR /&gt;Device Manager Version 7.9(1)&lt;/P&gt;&lt;P&gt;Compiled on Thu 30-Nov-17 20:21 PST by builders&lt;BR /&gt;System image file is "boot:/asa991-smp-k8.bin"&lt;BR /&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;ASA up 2 hours 24 mins&lt;/P&gt;&lt;P&gt;Hardware: ASAv, 4096 MB RAM, CPU Pentium II 1699 MHz, 1 CPU (2 cores)&lt;BR /&gt;Model Id: ASAv30&lt;BR /&gt;Internal ATA Compact Flash, 129024MB&lt;BR /&gt;Slot 1: ATA Compact Flash, 129024MB&lt;BR /&gt;BIOS Flash Firmware Hub @ 0x0, 0KB&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;0: Ext: Management0/0 : address is 5254.003c.3c2c, irq 11&lt;BR /&gt;1: Ext: GigabitEthernet0/0 : address is 5254.a4a4.0f4e, irq 11&lt;BR /&gt;2: Ext: GigabitEthernet0/1 : address is 5254.b1b1.0ee7, irq 10&lt;/P&gt;&lt;P&gt;License mode: Smart Licensing&lt;BR /&gt;ASAv Platform License State: Unlicensed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;◄================================== ►&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;◄================[config: -]================== ►&lt;/P&gt;&lt;P&gt;access-list OUTSIDE_INBOUND extended permit icmp any any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;icmp permit any echo outside&lt;BR /&gt;icmp permit any echo-reply outside&lt;BR /&gt;icmp permit any outside&lt;BR /&gt;icmp permit any echo inside&lt;BR /&gt;icmp permit any echo-reply inside&lt;BR /&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-group OUTSIDE_INBOUND in interface outside&lt;BR /&gt;access-group OUTSIDE_INBOUND out interface outside&lt;BR /&gt;access-group OUTSIDE_INBOUND in interface inside&lt;BR /&gt;access-group OUTSIDE_INBOUND out interface inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect icmp&lt;BR /&gt;inspect icmp error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;no xlate per-session deny tcp any4 any4&lt;BR /&gt;no xlate per-session deny tcp any4 any6&lt;BR /&gt;no xlate per-session deny tcp any6 any4&lt;BR /&gt;no xlate per-session deny tcp any6 any6&lt;BR /&gt;no xlate per-session deny udp any4 any4 eq domain&lt;BR /&gt;no xlate per-session deny udp any4 any6 eq domain&lt;BR /&gt;no xlate per-session deny udp any6 any4 eq domain&lt;BR /&gt;no xlate per-session deny udp any6 any6 eq domain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;may be we should open bug with cisco&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hossam&lt;/P&gt;</description>
      <pubDate>Mon, 06 Apr 2020 04:59:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-failed-simulation-drop-reason-no-adjacency-no-valid/m-p/4059580#M1068809</guid>
      <dc:creator>hossam helal</dc:creator>
      <dc:date>2020-04-06T04:59:56Z</dc:date>
    </item>
  </channel>
</rss>

