<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA doesn't route the packet in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877381#M958892</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See the attach&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Dec 2007 10:52:57 GMT</pubDate>
    <dc:creator>michelerossi</dc:creator>
    <dc:date>2007-12-12T10:52:57Z</dc:date>
    <item>
      <title>ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877372#M958877</link>
      <description>&lt;P&gt;I have an ASA 5500 and it has a gateway of my Lan.&lt;/P&gt;&lt;P&gt;The asa rotates the packets destined to 2 remote nets toward a router cisco,through a chart of static routes.&lt;/P&gt;&lt;P&gt;The problem is that it only passes the ping toward the remote lan, while all the other protocols and sessions are blocked !!!!&lt;/P&gt;&lt;P&gt;Only ICMP packet are forwarding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have capture this message into the ASA log:&lt;/P&gt;&lt;P&gt;" 106015 192.168.10.14 192.168.13.13Deny TCP (no connection) from 192.168.10.14/21438 to 192.168.13.13/1720 flags RST on interface LAN.&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:42:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877372#M958877</guid>
      <dc:creator>michelerossi</dc:creator>
      <dc:date>2019-03-11T11:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877373#M958879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post a diagram with IPs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Dec 2007 18:14:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877373#M958879</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2007-12-11T18:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877374#M958882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the attachments describe the network and Ip addresses assigned to the Cisco Routers and ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 08:47:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877374#M958882</guid>
      <dc:creator>michelerossi</dc:creator>
      <dc:date>2007-12-12T08:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877375#M958883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If this was a routing issue, you would have the following log in syslog&lt;/P&gt;&lt;P&gt;   No route to host 192.168.13.13&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This looks like an ACL issue. Is 192.168.10.14 in your inside network (inside interface)? And where is 192.168.13.13 located? DMZ interface? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 08:49:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877375#M958883</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-12-12T08:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877376#M958885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Michael&lt;/P&gt;&lt;P&gt;  IP adresses in diagram and in you post do not match. Can you correct please?&lt;/P&gt;&lt;P&gt;  Also please run&lt;/P&gt;&lt;P&gt;sh run access-group&lt;/P&gt;&lt;P&gt;access-group xxxx in interface inside&lt;/P&gt;&lt;P&gt;  If you see a line like above, (xxxx is your acl name) please send the output of&lt;/P&gt;&lt;P&gt;sh run access-list xxxx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 08:59:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877376#M958885</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-12-12T08:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877377#M958887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry&lt;/P&gt;&lt;P&gt;but this is the correct message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;106015 172.31.0.14 172.29.0.14 Deny TCP (no connection) from 172.31.0.14/21438 to 172.29.0.14/1720 flags RST on interface LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My first message was correlate to another ASA Log message, where I've the same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 09:37:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877377#M958887</guid>
      <dc:creator>michelerossi</dc:creator>
      <dc:date>2007-12-12T09:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877378#M958889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;  So can you please post the output of following commands &lt;/P&gt;&lt;P&gt;sh run access-group&lt;/P&gt;&lt;P&gt;access-list xxxx in interface LAN&lt;/P&gt;&lt;P&gt;(xxxx is the name of your ACL)&lt;/P&gt;&lt;P&gt;sh run access-list xxxx&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 09:47:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877378#M958889</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-12-12T09:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877379#M958890</link>
      <description>&lt;P&gt;Sent the attachment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Dec 2007 10:17:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877379#M958890</guid>
      <dc:creator>michelerossi</dc:creator>
      <dc:date>2007-12-12T10:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877380#M958891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. Please post the output of following also&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input tcp LAN 172.31.0.14 21438 172.29.0.14 1720 detailed&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 10:30:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877380#M958891</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-12-12T10:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877381#M958892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;See the attach&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 10:52:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877381#M958892</guid>
      <dc:creator>michelerossi</dc:creator>
      <dc:date>2007-12-12T10:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877382#M958893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to packet trace, ASA allows the flow, nothing wrong with ASA. And as I see RST statement in syslog, I suspect the remote client. Maybe restarting the client may work, do you encounter the same issue when you try to reach another client again in that subnet too?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 11:15:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877382#M958893</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-12-12T11:15:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877383#M958894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've got the same issue to reach all clients of all remote networks, include the Lan ip address routers.&lt;/P&gt;&lt;P&gt;The ASA version is 8.0.(2).&lt;/P&gt;&lt;P&gt;If I do a traceroute from ASDM Tools from the Lan to the 172.29.0.0 or 172.30.0.0, it function only if I flag "use ICMP" button&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I've the same problem into another client with the same ASA (version 8.0.(3)).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 11:25:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877383#M958894</guid>
      <dc:creator>michelerossi</dc:creator>
      <dc:date>2007-12-12T11:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877384#M958895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what happens when you temporarily add &lt;/P&gt;&lt;P&gt;access-list LAN_access_in permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 13:06:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877384#M958895</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-12-12T13:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877385#M958896</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The same thing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 13:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877385#M958896</guid>
      <dc:creator>michelerossi</dc:creator>
      <dc:date>2007-12-12T13:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877386#M958897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Michel can you please post the following commands output also ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;traceroute 172.29.0.14 use-icmp&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;traceroute 172.29.0.14&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2007 11:26:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877386#M958897</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2007-12-14T11:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877387#M958898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the traceroute is to 172.29.0.254 ( IP Lan of the Remote Router ).&lt;/P&gt;&lt;P&gt;The 172.29.0.14 is switchoff.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2007 16:19:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877387#M958898</guid>
      <dc:creator>michelerossi</dc:creator>
      <dc:date>2007-12-14T16:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877388#M958899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi michele,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have same problem as you, do you have solution for it please ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;lukas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2007 17:35:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877388#M958899</guid>
      <dc:creator>lukasdrbo</dc:creator>
      <dc:date>2007-12-20T17:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877389#M958900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi everybody,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I experienced the same issue. My network diagram is similar. Do you find a solution to that problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Mar 2008 11:20:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877389#M958900</guid>
      <dc:creator>fbroussey</dc:creator>
      <dc:date>2008-03-18T11:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA doesn't route the packet</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877390#M958901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here, we must understand that the routing capabilities of a ASA  is limited compared to a router. Initially a PIX   would not allowed a packet to leave an interface on the same&lt;/P&gt;&lt;P&gt;interface that they came in. This was improved by adding the  "same-security-traffic permit intra-interface" command, wich i assume you are using. But this does not resolve everything,&lt;/P&gt;&lt;P&gt;because the ASA does not reroute the packet the way a router would , it creates a connection the same way it would if the packet  leave the outside interface.Your problem is that&lt;/P&gt;&lt;P&gt;the returning packet doesn't get back to the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let see with an example;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(I assume that the PC on the inside have the ASA as the default gateway)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;172.31.0.100  make a tcp connection on 172.29.0.100.   The SYN hits the ASA  wich opens a connection , then route the packet to the MPLS router at 172.31.0.254. &lt;/P&gt;&lt;P&gt;But the returning SYN  packet goes directly to the PC  172.31.0.100  because it is Directly Connected to the router. Then the PC sends the ACK to the ASA ( the default gateway) &lt;/P&gt;&lt;P&gt;but it is refused because the ASA never saw the returning SYN . So your TCP connection dies here. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem does not occur with icmp because there is no three way handshake and it doesn't matter if the replies doesn't pass through the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One solution could be to create a sub-interface on the inside interface, configure it on a /22 subnet , put the MPLS router in this subnet and create a static route in the MPLS router for your&lt;/P&gt;&lt;P&gt;inside network. This way it would force all returning traffic to go through the ASA. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Mar 2008 15:26:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877390#M958901</guid>
      <dc:creator>michelcaissie</dc:creator>
      <dc:date>2008-03-18T15:26:11Z</dc:date>
    </item>
    <item>
      <title>Posts in this discussion have</title>
      <link>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877391#M958902</link>
      <description>&lt;P&gt;Posts in this discussion have been&amp;nbsp;modified to comply to&amp;nbsp;the &lt;A href="https://supportforums.cisco.com/document/29951/cisco-support-community-acceptable-use-agreement"&gt;CSC terms of use&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2015 20:11:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-doesn-t-route-the-packet/m-p/877391#M958902</guid>
      <dc:creator>rosaho</dc:creator>
      <dc:date>2015-07-13T20:11:50Z</dc:date>
    </item>
  </channel>
</rss>

