06-29-2016 01:41 AM
Hello All,
I have issue in cisco asa.
Build traffic - DMZ1 --> INTRANET (PBR)
Return traffic - INTRANET(PBR) --> DMZ1 ( err : Routing failed to locate next-hop for protocol.... )
PBR says all traffic goes to DMZ1 gateway(10.192.154.1)
for eg : when connecting from 192.168.1.50( DMZ1) to 10.192.168.40(INTRANET), build traffic is fine and goes to INTRANET, when return traffic comes it can't find the route
firewall is having a default gw ( DMZ -10.192.110.1).
A work-out for this is to add two routes as
DMZ 192.168.1.50 gw 10.192.110.1 metric 1
DMZ1 192.168.1.50 gw 10.192.154.1 metric 128
and everything works fine.
I want to know why return traffic can't find the routing table ( if no specific routes are added ) ?
07-02-2016 05:09 AM
****BUMP*****
07-24-2016 08:15 AM
Do you have identity NAT rules without route-lookup keyword by chance?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide