<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site-2-Site unable to reach specific destination at Remote Site (ASA5506 v9.6) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/site-2-site-unable-to-reach-specific-destination-at-remote-site/m-p/3337136#M969233</link>
    <description>&lt;P&gt;I cant spot an issue with your config, the NAT seems correct and the crypto maps have the right objects in them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you double check and run the packet tracer on both ASAs and see if the traffic passes&amp;nbsp;through/ie isnt blockedn still&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers&lt;/P&gt;</description>
    <pubDate>Sat, 24 Feb 2018 13:07:25 GMT</pubDate>
    <dc:creator>Dennis Mink</dc:creator>
    <dc:date>2018-02-24T13:07:25Z</dc:date>
    <item>
      <title>Site-2-Site unable to reach specific destination at Remote Site (ASA5506 v9.6)</title>
      <link>https://community.cisco.com/t5/network-security/site-2-site-unable-to-reach-specific-destination-at-remote-site/m-p/3337107#M969230</link>
      <description>&lt;P&gt;At an customer site i have an Site to Site VPN Tunnel. At the Main Office (SiteA) i also have an AnyConnect VPN solution. At Side A the Firewall has two WAN Connections. One connection is for normal internet access and the other is an specific Intranetconnection to an Dealer Network. At the dealernetwork there are some webservers etc, i have to reach.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Site A is working perfect. Internet traffic is going over WAN, while the dealersites requests are going over WAN_PON (second WAN port at Site A). At site A i can ping any host at Site B (and Vice Versa). I Also can manage and reach both ASA Firewall's.&lt;/P&gt;
&lt;P&gt;The ony problem i have (and i cannot figure out why) is that at Site B, they have to be able to reach the dealernetwork (which is on site A) and i cannot see why.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both configurations of the ASA's are attached.&lt;/P&gt;
&lt;P&gt;Site A: ASA5506-X HQ.txt&lt;/P&gt;
&lt;P&gt;Site B: ASA5506-X Branche&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help to find the correct solution. Thank you so much for help...&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:25:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-2-site-unable-to-reach-specific-destination-at-remote-site/m-p/3337107#M969230</guid>
      <dc:creator>Robbert Tol</dc:creator>
      <dc:date>2020-02-21T15:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Site-2-Site unable to reach specific destination at Remote Site (ASA5506 v9.6)</title>
      <link>https://community.cisco.com/t5/network-security/site-2-site-unable-to-reach-specific-destination-at-remote-site/m-p/3337115#M969231</link>
      <description>&lt;P&gt;Robbert can you confirm that you have a problem between:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;192.168.1.254 255.255.255.0 site a&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt; ip address 192.168.100.1 255.255.255.0 hq&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if not state the subnets you have a problem with.&amp;nbsp; can you ping LAN if ASA to LAn interface other ASA at all?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Groeten&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2018 11:45:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-2-site-unable-to-reach-specific-destination-at-remote-site/m-p/3337115#M969231</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2018-02-24T11:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: Site-2-Site unable to reach specific destination at Remote Site (ASA5506 v9.6)</title>
      <link>https://community.cisco.com/t5/network-security/site-2-site-unable-to-reach-specific-destination-at-remote-site/m-p/3337117#M969232</link>
      <description>&lt;P&gt;Dennis,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Site A (HQ) ASA: 192.168.100.1&lt;/P&gt;
&lt;P&gt;Site B (Branche) ASA: 192.168.1.254&lt;/P&gt;
&lt;P&gt;ASA 's can ping each other. Hosts on the internal networks can also ping/reach each other.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Site B (Remote site) has also internet access, but from site B users must be able to reach 10.0.0.0 255.0.0.0 network, which is connected at Site A on the WAN_PON port (Second WAN).&lt;/P&gt;
&lt;P&gt;Users at Site A can reach this network already.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2018 12:05:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-2-site-unable-to-reach-specific-destination-at-remote-site/m-p/3337117#M969232</guid>
      <dc:creator>Robbert Tol</dc:creator>
      <dc:date>2018-02-24T12:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Site-2-Site unable to reach specific destination at Remote Site (ASA5506 v9.6)</title>
      <link>https://community.cisco.com/t5/network-security/site-2-site-unable-to-reach-specific-destination-at-remote-site/m-p/3337136#M969233</link>
      <description>&lt;P&gt;I cant spot an issue with your config, the NAT seems correct and the crypto maps have the right objects in them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you double check and run the packet tracer on both ASAs and see if the traffic passes&amp;nbsp;through/ie isnt blockedn still&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2018 13:07:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-2-site-unable-to-reach-specific-destination-at-remote-site/m-p/3337136#M969233</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2018-02-24T13:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: Site-2-Site unable to reach specific destination at Remote Site (ASA5506 v9.6)</title>
      <link>https://community.cisco.com/t5/network-security/site-2-site-unable-to-reach-specific-destination-at-remote-site/m-p/3337950#M969234</link>
      <description>&lt;P&gt;Packet trace from brancheoffice ASA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA5506X-ZTM(config)# packet-tracer input inside tcp 192.168.1.110 80 10.200.153.29 80&lt;/P&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 145.131.166.97 using egress ifc outside&lt;/P&gt;
&lt;P&gt;Phase: 3&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (inside,outside) source static Internal_LAN Internal_LAN destination static Waddinxveen_HQ_Group Waddinxveen_HQ_Group no-proxy-arp route-lookup&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface outside&lt;BR /&gt;Untranslate 10.200.153.29/80 to 10.200.153.29/80&lt;/P&gt;
&lt;P&gt;Phase: 4&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (inside,outside) source static Internal_LAN Internal_LAN destination static Waddinxveen_HQ_Group Waddinxveen_HQ_Group no-proxy-arp route-lookup&lt;BR /&gt;Additional Information:&lt;BR /&gt;Static translate 192.168.1.110/80 to 192.168.1.110/80&lt;/P&gt;
&lt;P&gt;Phase: 5&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 6&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 7&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: encrypt&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 8&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (inside,outside) source static Internal_LAN Internal_LAN destination static Waddinxveen_HQ_Group Waddinxveen_HQ_Group no-proxy-arp route-lookup&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 9&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: ipsec-tunnel-flow&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 10&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 11&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 12&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 12274, packet dispatched to next module&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;input-interface: inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2018 15:39:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-2-site-unable-to-reach-specific-destination-at-remote-site/m-p/3337950#M969234</guid>
      <dc:creator>Robbert Tol</dc:creator>
      <dc:date>2018-02-26T15:39:44Z</dc:date>
    </item>
  </channel>
</rss>

