11-04-2015 04:02 AM - edited 03-05-2019 02:40 AM
I am supporting network that is having a route issue and I want to be sure it would be the 3rd party device
3rd party router: 192.168.1.1/24
ASA: 192.168.2.1/24
RouterA: 192.168.3.1/24
Nexus: 192.168.4.1/24
192.168.1.1<--IPSEC TUNNEL-->192.168.2.1-->192.168.3.1<---P2P Network-->192.168.4.1
192.168.2.1, 192.168.3.1 and 192.168.4.1 are connected to eachother via ospf and the ASA is redistributing the routes from the ipsec tunnel
the nexus can see the routes from the 3rd party router but cannot ping anything on the 192.168.1.1 network, but 192.168.3.1 can ping the 192.168.1.0 network
A traceroute from the nexus shows it getting to RouterA but then RouterA does not know what to do with this. I do not believe the 3rd party router has any routes or ACLs on the 192.168.4.0 network
Does the 3rd party router need routes for the 192.168.4.0 network so the Nexus can ping the 192.168.1.0 network?
11-04-2015 04:20 AM
Hello
Is the subnet connecting R3 -R4 advertised in ospf, Can you ping 3rd party RTR from RTR A sourced from this interface?
Can you share the routing table of R3 and R4
res
Paul
11-04-2015 05:15 AM
Router A can ping the 3rd party router
I can only do part of the routing table due to security standards
destination gateway vlan type
192.168.1.0/24 192.168.2.1 5 ospf
192.168.4.0/24 192.168.4.1 10 connected
11-04-2015 06:26 AM
looks like ASA doesnt have information about 192.168.4.0 network. Try pinging ASA from Nexus and Vice versa, if that doesnt work then problem is route towards 192.168.4.0 from ASA.
11-04-2015 04:51 AM
Are you sending the IPs through the VPN tunnel without being translated ?
Have you included the Nexus subnet in your crypto map on the ASA ?
Are you actually exchanging OSPF routes with the 3rd party ?
Jon
11-04-2015 05:09 AM
Yes I am sending the nexus subnet into the crypto map, the router and nexus are in the same object group
The 3rd party is not part of the ospf, I am redistributing the static routes via reverse route into the ospf network
11-04-2015 05:11 AM
Then assuming you are not translating the IPs through the tunnel you need to check what routes the 3rd party router has.
Jon
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide