cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3444
Views
0
Helpful
6
Replies

Cisco ASA

Bikash Shaw
Level 1
Level 1

Hi Everyone,

 

Please help me with my below question

 

From cloud 2 (user) i want to access internet(cloud1). I configured by no luck. please help me on this. i turned on logging and was getting below logs

 

ciscoasa(config)# %ASA-7-710005: UDP request discarded from 192.168.137.1/50945 to Outside:239.255.255.250/1900
%ASA-7-710005: UDP request discarded from 192.168.137.1/50945 to Outside:239.255.255.250/1900
%ASA-7-710005: UDP request discarded from 192.168.137.1/50945 to Outside:239.255.255.250/1900
%ASA-7-710005: UDP request discarded from 192.168.137.1/50945 to Outside:239.255.255.250/1900
%ASA-6-305011: Built dynamic TCP translation from Inside:10.1.1.11/1097 to Outside:192.168.137.10/54868
%ASA-6-302013: Built outbound TCP connection 81 for Outside:173.194.117.17/443 (173.194.117.17/443) to Inside:10.1.1.11/1097 (192.168.137.10/54868)
%ASA-6-302014: Teardown TCP connection 80 for Outside:173.194.117.17/443 to Inside:10.1.1.11/1096 duration 0:00:30 bytes 0 SYN Timeout
%ASA-6-305012: Teardown dynamic TCP translation from Inside:10.1.1.11/1095 to Outside:192.168.137.10/31826 duration 0:01:00
%ASA-7-710005: UDP request discarded from 192.168.137.1/50945 to Outside:239.255.255.250/1900
%ASA-7-710005: UDP request discarded from 192.168.137.1/50945 to Outside:239.255.255.250/1900
%ASA-7-710005: UDP request discarded from 192.168.137.1/50945 to Outside:239.255.255.250/1900
%ASA-7-710005: UDP request discarded from 192.168.137.1/49884 to Outside:224.0.0.252/5355
%ASA-7-710005: UDP request discarded from 192.168.137.1/49884 to Outside:224.0.0.252/5355
%ASA-6-302014: Teardown TCP connection 81 for Outside:173.194.117.17/443 to Inside:10.1.1.11/1097 duration 0:00:30 bytes 0 SYN Timeout
%ASA-7-609002: Teardown local-host Outside:173.194.117.17 duration 0:01:19
%ASA-7-710005: UDP request discarded from 192.168.137.1/50945 to Outside:239.255.255.250/1900
%ASA-7-710005: UDP request discarded from 192.168.137.1/50945 to Outside:239.255.255.250/1900
%ASA-7-710005: UDP request discarded from 192.168.137.1/50945 to Outside:239.255.255.250/1900
%ASA-6-305012: Teardown dynamic TCP translation from Inside:10.1.1.11/1096 to Outside:192.168.137.10/44325 duration 0:01:00

 configuration attached.

 

Regards

Bikash

1 Accepted Solution

Accepted Solutions

And I am assuming you have setup the Vnet interfaces for cloud1 and cloud2 on seperate VLANs?

The logs are stating that you are trying to access the inside interface IP on port 80.  This seems almost like you are either testing incorrectly (ie. accessing the wrong IP) or your network is setup incorrectly so that traffic is entering the incorrect interface on the ASA-

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts

View solution in original post

6 Replies 6

The debug is saying that IP 192.168.137.137 is entering the outside interface with a destination of 239.255.255.250.  You have a default route pointing back out the outside interface but you do not have same-security-traffic permit intra-interface configured.  So if you are trying to go from cloud 2 to coud 1, I would double check that the PC you are testing from is actually located off of the ASA inside interface with an IP in the 10.1.1.0/24 subnet.

Is the PC you are testing from also the PC you are testing to?  I mean does it have a loopback interface or physical interface for both networks?

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts

Hi Marius,

Thanks for reply.

Cloud 1 is Vnet logical interface and i have shared internet by my wireless interface. Cloud2 is also vnet interface. Cloud 2 (PC) is configured with 10.1.1.0/24 

 

Regards

Bikash

 

Hi Marius,

Please find the logs below

%ASA-3-710003: TCP access denied by ACL from 10.1.1.11/1103 to Inside:10.1.1.10/80
%ASA-7-710005: TCP request discarded from 10.1.1.11/1103 to Inside:10.1.1.10/80
%ASA-3-710003: TCP access denied by ACL from 10.1.1.11/1103 to Inside:10.1.1.10/80
%ASA-7-710005: TCP request discarded from 10.1.1.11/1103 to Inside:10.1.1.10/80
%ASA-3-710003: TCP access denied by ACL from 10.1.1.11/1103 to Inside:10.1.1.10/80
%ASA-7-710005: TCP request discarded from 10.1.1.11/1103 to Inside:10.1.1.10/80

 

Regards

Bikash

 

And I am assuming you have setup the Vnet interfaces for cloud1 and cloud2 on seperate VLANs?

The logs are stating that you are trying to access the inside interface IP on port 80.  This seems almost like you are either testing incorrectly (ie. accessing the wrong IP) or your network is setup incorrectly so that traffic is entering the incorrect interface on the ASA-

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts

Hi Marius,

Thanks for the help now i am able to download file through it. but still i am not able to access internet i am not able to understand if the file can download why can't the web page is getting access

 

Regards

Bikash 

issue a packet tracer on the ASA to see if the packet is allowed from the Inside interface to the Outside interface:(I am assuming you are trying to FTP from Inside to Outside)

packet-tracer input Inside tcp 10.1.1.11 12345 4.2.2.2 21 detail

Another thing you can do to troubleshoot is to do a packet capture. see the below link on how to do packet captures...You can also export the capture and view it in wireshark if you want to.

http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/110117-asa-capture-asdm-config.html

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card