05-04-2010 04:17 AM - edited 03-06-2019 10:55 AM
Hi,
I'm seeing the following on my firewall which serves as the default gateway for my network:
%ASA-3-305006: regular translation creation failed for icmp src inside:10.224.102.60 dst outside:10.189.0.10 (type 0, code 0)
the range 10.244.x.x doesn't even exist on my network. I'm stuck scratching my head because whatever this is is hitting the firewall frequently. Can someone please suggest how I can start to track where this is coming from?
Many thanks
Dan
05-04-2010 05:09 AM
It is a private address.....
Try doing a traceroute, let's see if you can guess which interermediate devices are there ....
05-04-2010 06:44 AM
Thanks for the reply. The only thing is that there isn't a route for that ip to the inside zone, so when doing a traceroute from the firewall the trace goes to the default gateway i.e the outside interface (internet), which is wrong.
Any traceroute on my inside switches doesn't work as there isn't a route for the subnet, so traceroute won't work there either.
Any other thoughts?
Thanks,
Dan
05-04-2010 11:26 AM
Is there any way that the subnet could possibly be on the other end of a tunnel? Do you have tunnels that terminate to the ASA by chance?
HTH,
John
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide