cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
969
Views
10
Helpful
2
Replies

Unable to see proxy arp working for a staic nat entry on Cisco ASA

jamesholley
Level 1
Level 1

Hi Guys

I have an HA pair of ASA5508 firewalls and I am having trouble getting a simple static Nat statement working.

I am unable to see any traffic towards the interface VIP hitting my outside interface of the firewall.

 

I have run a capture for arp specifically, and I don't see any requests come in from the directly connected switch to request the mac address of the IP in question.

I have a exact same set up working OK on another firewall that is a single instance (non HA) and it works fine. Replicating it on this firewall pair has seen issues.

The Nat statement itself looks fine, and packet tracer confirms that everything looks good when you simulate a packet.

 

IOS = Cisco Adaptive Security Appliance Software Version 9.8(4)32

Nat statement

nat (OUT_CORP,FB_LIMS) source static BM_RSD_Remote_Access_Network BM_RSD_Remote_Access_Network destination static RSD_NAS_VIP_10.x.x.167 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service https https net-to-net

I assumed that proxy arp works by default when using a VIP. The VIP sits in the same /28 subnet that is configured on the outside interface.

ARP CAPTURE

hostname/act/pri(config)# sh cap arp

 

15 packets captured

 

   1: 18:10:50.344296       arp who-has 10.x.x.161 tell 10.x.x.164

   2: 18:10:50.345761       arp reply 10.x.x.161 is-at 0:0:c:9f:fa:8e

   3: 18:10:50.345959       arp reply 10.x.x.161 is-at 0:0:c:9f:fa:8e

   4: 18:16:03.062039       arp who-has 10.x.x.164 (70:b3:17:e4:70:a8) tell 10.x.x.161

   5: 18:16:03.062222       arp reply 10.x.x.164 is-at 70:b3:17:e4:70:a8

   6: 18:21:07.986948       arp who-has 10.x.x.164 (70:b3:17:e4:70:a8) tell 10.x.x.161

   7: 18:21:07.987131       arp reply 10.x.x.164 is-at 70:b3:17:e4:70:a8

   8: 18:26:12.652660       arp who-has 10.x.x.164 (70:b3:17:e4:70:a8) tell 10.x.x.161

   9: 18:26:12.652844       arp reply 10.x.x.164 is-at 70:b3:17:e4:70:a8

  10: 18:31:26.273438       arp who-has 10.x.x.164 (70:b3:17:e4:70:a8) tell 10.x.x.161

  11: 18:31:26.273621       arp reply 10.x.x.164 is-at 70:b3:17:e4:70:a8

  12: 18:36:30.174856       arp who-has 10.x.x.164 (70:b3:17:e4:70:a8) tell 10.x.x.161

  13: 18:36:30.175039       arp reply 10.x.x.164 is-at 70:b3:17:e4:70:a8

  14: 18:41:45.855790       arp who-has 10.x.x.164 (70:b3:17:e4:70:a8) tell 10.x.x.161

  15: 18:41:45.855989       arp reply 10.x.x.164 is-at 70:b3:17:e4:70:a8

15 packets shown

 

Any help would be gratefully received.

Thanks

 

 

James

2 Replies 2

Chakshu Piplani
Cisco Employee
Cisco Employee

Hi James,

 

It will be a good idea to look at "sh nat proxy-arp" output to understand if the nat is configured and working as expected.

 

You can also send a grat arp by running commands:

debug menu ipaddrutl 6 <IP>

Example:

#debug menu ipaddrutl 6 1.1.1.1

Gratuitous ARP sent for 1.1.1.1

 

Regards,

Chakshu

 

Do rate helpful posts !

Thanks Chakshu a useful command.

I do see the right proxy arp entry at the bottom, but cannot work out why I would see proxy arp statements for what are effectively my source remote access networks. Comparing it to the working firewall, this doesn't look right.

hostname/act/pri(config)# sh nat proxy-arp

 

Nat Proxy-arp Table

id=0x00007fc00ac898b0, ip/id=x.x.109.161, mask=255.255.255.255 ifc=FB_LIMS

        config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks  destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional

id=0x00007fc00ac898b0, ip/id=x.x.109.162, mask=255.255.255.254 ifc=FB_LIMS

        config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks  destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional

id=0x00007fc00ac898b0, ip/id=x.x.109.164, mask=255.255.255.252 ifc=FB_LIMS

        config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks  destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional

id=0x00007fc00ac898b0, ip/id=x.x.109.168, mask=255.255.255.248 ifc=FB_LIMS

        config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks  destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional

id=0x00007fc00ac898b0, ip/id=x.x.109.177, mask=255.255.255.255 ifc=FB_LIMS

        config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks  destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional

id=0x00007fc00ac898b0, ip/id=x.x.109.178, mask=255.255.255.254 ifc=FB_LIMS

        config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks  destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional

id=0x00007fc00ac898b0, ip/id=x.x.109.180, mask=255.255.255.252 ifc=FB_LIMS

        config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks  destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional

id=0x00007fc00ac898b0, ip/id=x.x.109.184, mask=255.255.255.248 ifc=FB_LIMS

        config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks  destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional

id=0x00007fc00ac898b0, ip/id=10.x.x.167, mask=255.255.255.255 ifc=OUT_CORP

        config:(OUT_CORP) to (FB_LIMS) source static BM_&_MR_RSD_Remote_Access_Networks BM_&_MR_RSD_Remote_Access_Networks  destination static RSD_REM_ACC_VIP_10.x.x.161 FB_SOPHOS_RAVPN_NAT_192.x.x.2 service RSD_RA_VPN RSD_RA_VPN net-to-net unidirectional

 

Thanks

 

 

James

Review Cisco Networking products for a $25 gift card