cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
428
Views
0
Helpful
1
Replies

ASA Outside IP Transition Questions

dswillia74437
Level 1
Level 1

We currently use a /24 provided by our partner and have about 150 static nat's in this range.  I recently received a /23 from ARIN so that we could begin multi-homing our traffic.  This past weekend I was able to reconfigure our 7604 BGP configuration to use our new AS as well as advertise our current /24 and our new /23.  I also changed our access port going into our ASA Outside interface and created a trunk with 2 sub interfaces on vlans tied to the /24 and /23.  I created a new interface on the 5520 and supplied it with an IP on the new /23.  To this point everything is working as it should and traffic is getting to the /23 interface.  However I have run into an issue whereas if I create a new static nat for that range, the traffic comes in as it should, but because the default route in the ASA is set to the gateway of the /24 my return traffic cannot reach it.  Does anyone have any suggestions on how to be able to run both networks for a while as we transition our old static nats?

Thanks for the time!

Scott

1 Reply 1

Shrikant Sundaresh
Cisco Employee
Cisco Employee

Hi Scott,

From my initial understanding, I can see two issues over here.

1. Reverse Path Failure

2. Asymmetric Routing

If you can confirm that traffic is reaching the server using the /23 public ip, then issue 1 is not being encountered.

The asymmetric routing issue, can be solved by enabling tcp-state-bypass until the subnet transition takes place.

You can go through the following link for more details on asymmetric routing and how to mitigate it:

https://supportforums.cisco.com/docs/DOC-14491

I hope this helps.

-Shrikant

Review Cisco Networking for a $25 gift card