cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2679
Views
0
Helpful
15
Replies

ASA5505 - Blocking internal traffic between 2 servers

Richard Lawes
Level 1
Level 1

Hi guys/ladies

I have a cisco ASA5505, it runs a wide site to site VPN network and has 4 servers connected to it

10.50.15.4 > fileserver

10.50.15.5 > domain controller (exchange)

10.50.15.6 > terminal server

10.50.15.7 > terminal server

Now yesterday i removed 10.50.15.6 and replaced it with a new terminal server with the same ip address, ever since the ASA is blocking traffic between it and the domain controller (example)

2Oct 27 201214:51:0510600710.50.15.655978DNS
Deny inbound UDP from 10.50.15.6/55978 to 10.50.15.5/53 due to DNS Query

What has me baffled is the only thing different between today and yesterday is the new server is windows server 2008 and the old one was windows server 2003. The new server has the same LAN ip address as the old one to make the changeover seamless for the users.

Any idea why all the sudden my ASA has decided to block the traffic between those machines? all the other machines can talk to it fine just not the domain controller, and seeing that this is a terminal server naturally you can see the problem i face!

Any help you can give would be great as this router has worked flawlessly for 2 years now without any config changes and i cant work out why its blocking traffic between those 2 machines.

15 Replies 15

Please check your CSC inbox again

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Review Cisco Networking for a $25 gift card