01-25-2022 10:45 AM
Hi Guys
I have an HA pair of ASA5508 firewalls and I am having trouble getting a simple static Nat statement working.
I am unable to see any traffic towards the interface VIP hitting my outside interface of the firewall.
I have run a capture for arp specifically, and I don't see any requests come in from the directly connected switch to request the mac address of the IP in question.
I have a exact same set up working OK on another firewall that is a single instance (non HA) and it works fine. Replicating it on this firewall pair has seen issues.
The Nat statement itself looks fine, and packet tracer confirms that everything looks good when you simulate a packet.
IOS = Cisco Adaptive Security Appliance Software Version 9.8(4)32
Nat statement
nat (OUT_CORP,FB_LIMS) source static BM_RSD_Remote_Access_Network BM_RSD_Remote_Access_Network destination static RSD_NAS_VIP_10.x.x.167 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service https https net-to-net
I assumed that proxy arp works by default when using a VIP. The VIP sits in the same /28 subnet that is configured on the outside interface.
ARP CAPTURE
hostname/act/pri(config)# sh cap arp
15 packets captured
1: 18:10:50.344296 arp who-has 10.x.x.161 tell 10.x.x.164
2: 18:10:50.345761 arp reply 10.x.x.161 is-at 0:0:c:9f:fa:8e
3: 18:10:50.345959 arp reply 10.x.x.161 is-at 0:0:c:9f:fa:8e
4: 18:16:03.062039 arp who-has 10.x.x.164 (70:b3:17:e4:70:a8) tell 10.x.x.161
5: 18:16:03.062222 arp reply 10.x.x.164 is-at 70:b3:17:e4:70:a8
6: 18:21:07.986948 arp who-has 10.x.x.164 (70:b3:17:e4:70:a8) tell 10.x.x.161
7: 18:21:07.987131 arp reply 10.x.x.164 is-at 70:b3:17:e4:70:a8
8: 18:26:12.652660 arp who-has 10.x.x.164 (70:b3:17:e4:70:a8) tell 10.x.x.161
9: 18:26:12.652844 arp reply 10.x.x.164 is-at 70:b3:17:e4:70:a8
10: 18:31:26.273438 arp who-has 10.x.x.164 (70:b3:17:e4:70:a8) tell 10.x.x.161
11: 18:31:26.273621 arp reply 10.x.x.164 is-at 70:b3:17:e4:70:a8
12: 18:36:30.174856 arp who-has 10.x.x.164 (70:b3:17:e4:70:a8) tell 10.x.x.161
13: 18:36:30.175039 arp reply 10.x.x.164 is-at 70:b3:17:e4:70:a8
14: 18:41:45.855790 arp who-has 10.x.x.164 (70:b3:17:e4:70:a8) tell 10.x.x.161
15: 18:41:45.855989 arp reply 10.x.x.164 is-at 70:b3:17:e4:70:a8
15 packets shown
Any help would be gratefully received.
Thanks
James
01-25-2022 11:10 AM
Hi James,
It will be a good idea to look at "sh nat proxy-arp" output to understand if the nat is configured and working as expected.
You can also send a grat arp by running commands:
debug menu ipaddrutl 6 <IP>
Example:
#debug menu ipaddrutl 6 1.1.1.1
Gratuitous ARP sent for 1.1.1.1
Regards,
Chakshu
Do rate helpful posts !
01-25-2022 11:24 AM
Thanks Chakshu a useful command.
I do see the right proxy arp entry at the bottom, but cannot work out why I would see proxy arp statements for what are effectively my source remote access networks. Comparing it to the working firewall, this doesn't look right.
hostname/act/pri(config)# sh nat proxy-arp
Nat Proxy-arp Table
id=0x00007fc00ac898b0, ip/id=x.x.109.161, mask=255.255.255.255 ifc=FB_LIMS
config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional
id=0x00007fc00ac898b0, ip/id=x.x.109.162, mask=255.255.255.254 ifc=FB_LIMS
config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional
id=0x00007fc00ac898b0, ip/id=x.x.109.164, mask=255.255.255.252 ifc=FB_LIMS
config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional
id=0x00007fc00ac898b0, ip/id=x.x.109.168, mask=255.255.255.248 ifc=FB_LIMS
config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional
id=0x00007fc00ac898b0, ip/id=x.x.109.177, mask=255.255.255.255 ifc=FB_LIMS
config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional
id=0x00007fc00ac898b0, ip/id=x.x.109.178, mask=255.255.255.254 ifc=FB_LIMS
config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional
id=0x00007fc00ac898b0, ip/id=x.x.109.180, mask=255.255.255.252 ifc=FB_LIMS
config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional
id=0x00007fc00ac898b0, ip/id=x.x.109.184, mask=255.255.255.248 ifc=FB_LIMS
config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional
id=0x00007fc00ac898b0, ip/id=10.x.x.167, mask=255.255.255.255 ifc=OUT_CORP
config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional
Thanks
James
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide