We have this ASA connected to Cisco 6506 switch:
VLAN 30 subnet 10.10.10.0/27 for TMG internal on the switch the interface VLAN 30 is 10.10.10.30
VLAN 36 subnet 192.168.29.0/27 for TMG external on the switch the interface VLAN 36 is 192.168.29.30
inside LAN subnets:
Subnets through the LAN connect to our HQ:
DMVPN subnet 220.127.116.11/30 this one connected to Cisco 2821 DMVPN router
we added this TMG-IN and OUT recently they are trying to configure Microsoft TMG server to be in a DMZ kind of thing. When they configure static route on the TMG server 10.10.10.30 (interface VLAN 30 on the switch) as a next hob they can ping everything on the LAN and it looks like everything open wide! from 10.10.10.0 network to 172.x.x.x network and I don’t see the traffic coming to the ASA for the 10.10.10.0 network! I asked them to configure static route on the TMG server 10.10.10.29 (Interface TMG-IN on ASA) as next hob but as soon as they do that they lose connectivity and I see this in the ASA log:
Asymmetric NAT rules matched for forward and reverse flows; Connection for tcp 80 172.24.21.x src TMG-IN 10.10.10.1 denied due to NAT reverse path failure
Network diagram and ASA config are attached.
Any help would be appreciated!