06-21-2018 05:44 AM - edited 02-21-2020 07:54 AM
what trouble shooting commands are there available for PBR on ASA?
ive created a pbr and its working outbound fine, the problem I have is an external IP coming inbound is translated and routed correctly however the return traffic doesnt see to leave the firewall.
A packet cap on the outside and dmz interface shows traffic coming into the firewall from the internet. it gets translated from the public ip to the internal ip and routed to the dmz interface. I can see packets coming back from the internal server destined to the internet on the dmz interface but i dont see the packets leave the outside interface.
Thanks
06-21-2018 05:52 AM
06-21-2018 05:57 AM
im not using SIP. its just internet traffic to an internal server on 443
06-21-2018 06:41 AM
06-21-2018 07:04 AM
Thanks
the outbound dynamic nat with PBR seems to work ok. Im using v9.8
is there a compatibility table?
06-25-2018 03:47 AM
06-26-2018 05:38 AM
I have managed to find the problem but im not sure I understand why its happening.
Outbound traffic is using the pbr and working.
inbound traffic from the internet to one of our public IP's translated to a server in the dmz doesnt work.
The problem seems to be with the return route from the server.
I can only get it working with a static route. I assumed inbound traffic would create a session and return the traffic back to the interface it came in on.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide