cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
287
Views
3
Helpful
9
Replies

Inconsistent connectivity going to/thru the Cisco ASA FW

DSterling
Level 1
Level 1

Having a issue with inconsistent connectivity going to/thru the Cisco ASA to the inside interface and going to devices on the outside interface from Vlan 111.

DSterling_0-1718290495261.png

Ping Switch 3 source vlan 111 to FW Inside interface 11.185.20.2 and I get a lot of drops, but it's inconsistent, some times it will gets thru for 100 pings and a min later it will drop most if not all packets. I have tested this during low traffic times. 

Ping Switch 3 source vlan 109 to FW Inside interface 11.185.20.2 and I get  0 drops every time.

Ping from Switch 3 to Switch 1 - 11.185.20.1 with no drops every time.

Ping from Switch 2 to the FW Inside interface 11.185.20.2 and I get  0 drops every time.

There are no ACLs on the vlans or between Switch 3 and the FW.

9 Replies 9

Hello,

tough one. Can you post the configs of all three switches as well as the ASA ? Maybe we can spot something...

 

Georg, 

I can't post the configs, it's on a secure network. I noticed that the MTU size is 9000 and other vlans are 1500, I'm going to get approval to change and test and see if that's the issue. 

v/r Dave

Hello,

maybe you can isolate the issue when you start pinging between Switch 3 and Switch 2, then between Switch 2 and Switch 1, then between Switch 2 and the ASA...?

MTU miss match can be issue here 
run 

show interface in ASA 

see if there is any Input drop 

MHM

asa# show nat pool <<- share this 
it can POOL dont have more port 

let check first 

MHM

DSterling
Level 1
Level 1

I changed the MTU size to 1500 and also tried 9216 on vlan 111 and it did not fix the issue so I changed it back to 9000. I'm thinking it's something with the FW. 

Show nat pool 

Share this output from asa

MHM

MHM we are not using NAT, no NAT rules are configured. 

Thank you,

Dave

Ok' 

Show interface  <INside> 

Check if you see overrun counter increase rapidly 

Do command at least twice and check counter each time 

If you see it increase 

Then enable flow-control in INside interface 

MHM