<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Interesting ASA problem -- duplicate IP &amp; IPsec VPN remote access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/interesting-asa-problem-duplicate-ip-ipsec-vpn-remote-access/m-p/889543#M961942</link>
    <description>&lt;P&gt;I am running 8.0(2), look at the following output from ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5500#sh interface gi0/0&lt;/P&gt;&lt;P&gt;Interface GigabitEthernet0/0 "Outside", is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is i82546GB rev03, BW 1000 Mbps, DLY 10 usec&lt;/P&gt;&lt;P&gt;	Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)&lt;/P&gt;&lt;P&gt;	MAC address 0018.b91b.55b6, MTU 1500&lt;/P&gt;&lt;P&gt;	IP address 205.3.164.1, subnet mask 255.255.255.224&lt;/P&gt;&lt;P&gt;	3421353595 packets input, 1734453023897 bytes, 10860859 no buffer&lt;/P&gt;&lt;P&gt;	Received 276528 broadcasts, 0 runts, 0 giants&lt;/P&gt;&lt;P&gt;	0 input errors, 0 CRC, 0 frame, 6484383 overrun, 0 ignored, 0 abort&lt;/P&gt;&lt;P&gt;	0 L2 decode drops&lt;/P&gt;&lt;P&gt;	1394329286 packets output, 279509809309 bytes, 0 underruns&lt;/P&gt;&lt;P&gt;	0 output errors, 0 collisions, 3 interface resets&lt;/P&gt;&lt;P&gt;	0 late collisions, 0 deferred&lt;/P&gt;&lt;P&gt;	0 input reset drops, 0 output reset drops&lt;/P&gt;&lt;P&gt;	input queue (curr/max packets): hardware (1/33) software (0/0)&lt;/P&gt;&lt;P&gt;	output queue (curr/max packets): hardware (0/95) software (0/0)&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "Outside":&lt;/P&gt;&lt;P&gt;	3421137849 packets input, 1646043223864 bytes&lt;/P&gt;&lt;P&gt;	1394329411 packets output, 250264599199 bytes&lt;/P&gt;&lt;P&gt;	86153516 packets dropped&lt;/P&gt;&lt;P&gt;      1 minute input rate 3032 pkts/sec,  4145066 bytes/sec&lt;/P&gt;&lt;P&gt;      1 minute output rate 1579 pkts/sec,  85978 bytes/sec&lt;/P&gt;&lt;P&gt;      1 minute drop rate, 12 pkts/sec&lt;/P&gt;&lt;P&gt;      5 minute input rate 627 pkts/sec,  725869 bytes/sec&lt;/P&gt;&lt;P&gt;      5 minute output rate 389 pkts/sec,  41285 bytes/sec&lt;/P&gt;&lt;P&gt;      5 minute drop rate, 11 pkts/sec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5500# sh route&lt;/P&gt;&lt;P&gt;&amp;lt;irrelevant routes snipped&amp;gt;&lt;/P&gt;&lt;P&gt;O E2 205.3.164.1 255.255.255.255 [110/20] via 10.31.64.129, 0:40:47, Inside&lt;/P&gt;&lt;P&gt;&amp;lt;snipped&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I have 205.3.164.1/27 as Outside interface IP address, and 205.3.164.1/32 is also learned from Internal network. Obviously this is a configuration mistake, no question about that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now here is my question: I happened to have this IP address for IPsec VPN remote access, when connection request comes in to this IP address, shouldn't ASA process it? in reality, it does not, but I want to understand what ASA is doing. If this is a router, CEF adjacency for this IP address would be receive, and this router would be able to process incoming request correctly. How would ASA behave differently?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:21:32 GMT</pubDate>
    <dc:creator>oldcreek12</dc:creator>
    <dc:date>2019-03-11T11:21:32Z</dc:date>
    <item>
      <title>Interesting ASA problem -- duplicate IP &amp; IPsec VPN remote access</title>
      <link>https://community.cisco.com/t5/network-security/interesting-asa-problem-duplicate-ip-ipsec-vpn-remote-access/m-p/889543#M961942</link>
      <description>&lt;P&gt;I am running 8.0(2), look at the following output from ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5500#sh interface gi0/0&lt;/P&gt;&lt;P&gt;Interface GigabitEthernet0/0 "Outside", is up, line protocol is up&lt;/P&gt;&lt;P&gt;  Hardware is i82546GB rev03, BW 1000 Mbps, DLY 10 usec&lt;/P&gt;&lt;P&gt;	Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)&lt;/P&gt;&lt;P&gt;	MAC address 0018.b91b.55b6, MTU 1500&lt;/P&gt;&lt;P&gt;	IP address 205.3.164.1, subnet mask 255.255.255.224&lt;/P&gt;&lt;P&gt;	3421353595 packets input, 1734453023897 bytes, 10860859 no buffer&lt;/P&gt;&lt;P&gt;	Received 276528 broadcasts, 0 runts, 0 giants&lt;/P&gt;&lt;P&gt;	0 input errors, 0 CRC, 0 frame, 6484383 overrun, 0 ignored, 0 abort&lt;/P&gt;&lt;P&gt;	0 L2 decode drops&lt;/P&gt;&lt;P&gt;	1394329286 packets output, 279509809309 bytes, 0 underruns&lt;/P&gt;&lt;P&gt;	0 output errors, 0 collisions, 3 interface resets&lt;/P&gt;&lt;P&gt;	0 late collisions, 0 deferred&lt;/P&gt;&lt;P&gt;	0 input reset drops, 0 output reset drops&lt;/P&gt;&lt;P&gt;	input queue (curr/max packets): hardware (1/33) software (0/0)&lt;/P&gt;&lt;P&gt;	output queue (curr/max packets): hardware (0/95) software (0/0)&lt;/P&gt;&lt;P&gt;  Traffic Statistics for "Outside":&lt;/P&gt;&lt;P&gt;	3421137849 packets input, 1646043223864 bytes&lt;/P&gt;&lt;P&gt;	1394329411 packets output, 250264599199 bytes&lt;/P&gt;&lt;P&gt;	86153516 packets dropped&lt;/P&gt;&lt;P&gt;      1 minute input rate 3032 pkts/sec,  4145066 bytes/sec&lt;/P&gt;&lt;P&gt;      1 minute output rate 1579 pkts/sec,  85978 bytes/sec&lt;/P&gt;&lt;P&gt;      1 minute drop rate, 12 pkts/sec&lt;/P&gt;&lt;P&gt;      5 minute input rate 627 pkts/sec,  725869 bytes/sec&lt;/P&gt;&lt;P&gt;      5 minute output rate 389 pkts/sec,  41285 bytes/sec&lt;/P&gt;&lt;P&gt;      5 minute drop rate, 11 pkts/sec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5500# sh route&lt;/P&gt;&lt;P&gt;&amp;lt;irrelevant routes snipped&amp;gt;&lt;/P&gt;&lt;P&gt;O E2 205.3.164.1 255.255.255.255 [110/20] via 10.31.64.129, 0:40:47, Inside&lt;/P&gt;&lt;P&gt;&amp;lt;snipped&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I have 205.3.164.1/27 as Outside interface IP address, and 205.3.164.1/32 is also learned from Internal network. Obviously this is a configuration mistake, no question about that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now here is my question: I happened to have this IP address for IPsec VPN remote access, when connection request comes in to this IP address, shouldn't ASA process it? in reality, it does not, but I want to understand what ASA is doing. If this is a router, CEF adjacency for this IP address would be receive, and this router would be able to process incoming request correctly. How would ASA behave differently?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:21:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interesting-asa-problem-duplicate-ip-ipsec-vpn-remote-access/m-p/889543#M961942</guid>
      <dc:creator>oldcreek12</dc:creator>
      <dc:date>2019-03-11T11:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: Interesting ASA problem -- duplicate IP &amp; IPsec VPN remote a</title>
      <link>https://community.cisco.com/t5/network-security/interesting-asa-problem-duplicate-ip-ipsec-vpn-remote-access/m-p/889544#M961945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ASA is learning the route for 205.3.264.1 from two different sources, this is different from having a vpn connection request. So the ASA is not taking this as a vpn request but just like a route which is learned from a neighbour.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2007 20:41:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/interesting-asa-problem-duplicate-ip-ipsec-vpn-remote-access/m-p/889544#M961945</guid>
      <dc:creator>amritpatek</dc:creator>
      <dc:date>2007-10-11T20:41:05Z</dc:date>
    </item>
  </channel>
</rss>

