04-29-2023 09:22 AM
Hi everyone,
I'm unable to access the interface of cisco asa from a vlan which is present on the router connected below. Packet-tracer shows no route to host.
04-29-2023 09:23 AM
Can anyone guide me why it says no route to host?
04-29-2023 09:28 AM
The asa not support equal cost path'
So you need to make only one link between asa and router
04-29-2023 09:31 AM
I'm doing redundant interfaces on asa it should be okay right ?
04-29-2023 09:40 AM
No asa can drop asymmetric traffic' remove one link' keep sure asa have route toward router for vlan subnet and check again
04-29-2023 09:55 AM
ASA supports equal cost routes since version 9.3 using traffic zones - https://www.cisco.com/c/en/us/td/docs/security/asa/asa916/configuration/general/asa-916-general-config/interface-zones.html
04-29-2023 09:57 AM
I know that but he have lab and his asa not support zone.
04-29-2023 10:13 AM
I see no information in this post why this lab cannot support traffic zones, but that won't be related to this issue.
@gautamgadeela don't run packet-tracer to the IP address of the isp1 interface IP address (192.168.1.2) - change the destination to an IP address behind that interface. The ASA does not support communicating from behind one of its interfaces through the ASA to one of the ASAs own interfaces.
Also when packet-tracer using ICMP usse type 8 and code 0, not 1 1.
04-29-2023 10:49 AM
Thank you guys I'm able to figure out where i was making a mistake. I ran into issue now where i have created two vlans on R3 as 192,168.1.4 and 2.4 and 1.1 and 2.2 on R2. The link between R2 and R3 is trunk. I'm able to reach 192.168.1.1 from R1 but unable to reach 2.2 on R2 and 1.4 and 2.4 on R3 is there anything i'm overlooking.
Thanks for you help
04-29-2023 11:08 AM
You change topology replace router with sw?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide