cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
474
Views
0
Helpful
1
Replies

Strange issue with an ASA - need help

jlmickens
Level 1
Level 1

I'm not quite sure if the problem is the ASA, or something else in the network design, but the ASA is at the heart of what's going on, so I started this here.

I have a remote site - directly connected via fiber so it can basically considered local - that needs access to a website that while internal, is on an untrusted network.  As such, there is an ASA 5505 between the corporate network here and the untrusted network (labeled as VOD).  The ASA is configured to NAT traffic from any other internal network to this VOD network.  Each internal subnet has its own NAT configured.  Two of them work just fine, but the one site doesn't work at all.  According to the ASA's ASDM logging, connections are being created, but no traffic is flowing. 

When I try to connect from the remote subnet, I'm seeing a couple log entries (from the ASDM interface) that I don't see when I try from the other two internal subnets.

6    Aug 01 2011    10:30:34        10.105.10.103    1292    192.168.200.4    80    Built outbound TCP connection 42090 for VOD:192.168.200.4/80 (192.168.200.4/80) to inside:10.105.10.103/1292 (192.168.200.105/1292) <- Looks like it's making a connection and is NATing correctly

6    Aug 01 2011    10:30:34        172.16.0.1    0    192.168.200.4    0    Built outbound ICMP connection for faddr 192.168.200.4/0 gaddr 192.168.200.105/0 laddr 172.16.0.1/0 <- Not sure why these are happening

6    Aug 01 2011    10:30:44        172.16.0.1    0    192.168.200.4    0    Built outbound ICMP connection for faddr 192.168.200.4/0 gaddr 192.168.200.105/0 laddr 172.16.0.1/0

As you can see, the gaddr on the two ICMP entries is matching the NAT for the 10.105 subnet.  I'm not sure why this is happening, but it seems to be at the root of why the connection isn't working.  When I connect from 172.16.0.0/16 or 10.101.1.0/24, I don't get these entries.  I've attached a network diagram and a config from the ASA.  It's probably something obvious to one of you, but it's eluding me thus far.

1 Reply 1

jlmickens
Level 1
Level 1

Ok, so apparently it's not an issue with the ASA.  There was an ACL on VLAN 1 of the 3750 router (see diagram) that was preventing the traffic from coming back to the remote site's subnet.  Fixed that and all is right with the world again.  The powers that be can feel free to move, or remove, this as necessary.

Review Cisco Networking for a $25 gift card