01-23-2018 07:00 AM - edited 02-21-2020 07:11 AM
Scenario: A customer has an existing LAN 192.168.100.0/24 with a gateway of .1 on the ASA. They have a new phone system that uses 172.16.2.0/24. The phone system has its own switch for the phones as well as a router. External phone traffic has to traverse the 192.168.100.0 subnet due to equipment and cabling limitations. Routes are configured on both the router and the ASA. Phone calls are working. The last issue is that the customer wants to be able to use a web interface to manage some phone features. Testing this is done from a server at 192.168.100.155, trying to reach 172.16.2.254 (port 8080 and 8443). Same-security permit intra-interface is enabled and pings are successful between the devices. However, when attempting to browse to 172.16.2.254:8080 (or 8443), the page just times out. Is some kind of NAT statement needed? I've tried a few combinations of NAT and even a NAT exclusion, but to no avail. As a note, if I add a static route on the server (100.155), I can successfully browse to 172.16.2.254:8080. This makes me think NAT is not the issue. I have attached a network map.
Solved! Go to Solution.
01-23-2018 09:02 AM
Hi Ben,
I presume that the ASA 192.168.100.1 is the default gateway for 192.168.100.55. In that case you will also need to do a tcp bypass for the traffic. Here is a link that explains the process:
In your case there is a second workaround available, you could use the router 192.168.100.10 as default gateway. By default the router does not have a problem sending the packets out the same interface they came in and also should send icmp redirect messages to the host.
HTH
Bogdan
01-23-2018 09:02 AM
Hi Ben,
I presume that the ASA 192.168.100.1 is the default gateway for 192.168.100.55. In that case you will also need to do a tcp bypass for the traffic. Here is a link that explains the process:
In your case there is a second workaround available, you could use the router 192.168.100.10 as default gateway. By default the router does not have a problem sending the packets out the same interface they came in and also should send icmp redirect messages to the host.
HTH
Bogdan
01-23-2018 11:40 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide