[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

Question
[x]
Attachment Details

Cisco ASA Source & Destination IP's shown on opposite networks

Asked by djspin007 in Networking Hardware Firewalls, Network Routers, Network Switches & Hubs

Seeing a weird deny entry in Syslog. Two ASA's have a VPN tunnel between them, to connect 10.5.0.0/16 and 10.10.0.0/16. Traffic flows just fine between the two networks. However, we noticed on the firewall 10.10.25.8 for the 10.10.0.0/16 subnet a weird entry:

Deny udp src inside:10.5.1.1/137 dst inside:10.10.40.43/137 by access-group "inside_access_in" [0xbe9efe96, 0x0]

First off, 10.10.40.43 is not an active device. The IP is bogus. That's not the question though. The question is why would the 10.10.0.0/16 firewall show the source as being 10.5.1.1 on the Inside interface? Is this because the VPN tunnel terminates on the inside interface, so when the packet comes in, the actual source is 10.5.1.1 on the inside? However, if 10.5.1.1 pings a valid IP on the 10.10.0.0/16 subnet, there are no deny ACL entries - all traffic to valid

On the firewall, there is a static route saying:
route inside 10.10.0.0 255.255.0.0 10.10.25.2 2
... and there are no VLAN's or subnets with 10.10.40.0 subnet. Does this have something to do with the L3 switch at 10.10.25.2?

What's also odd is if I ping (from the 10.5.1.1 server) up to 10.10.39.254, I don't get that deny ACL entry. Once I start trying to ping 10.10.40.0 and up, I get that deny ACL. The 10.10.39.254 is invalid too, so what's the difference in going up to .40 in the third octet?

I'm just having a hard time trying to wrap my head around this.

Thanks
[+][-]11/05/09 09:21 AM, ID: 25751727Author Comment

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 30-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]11/05/09 09:22 AM, ID: 25751738Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20091111-EE-VQP-89 - Hierarchy / EE_QW_3_20080625