We help IT Professionals succeed at work.
Get Started

Cisco ASA 5510, Two Inside Networks, Routing Error

3,202 Views
Last Modified: 2012-08-14
Hey all,

Well I'm a bit perplexed by this probably easy issue (easy when you know how to fix it, I guess...)

I need to have another interface acting like a second inside subnet.  When I try to access inside hosts on the secondary inside subnet from the outside, I get a routing error:

%ASA-6-110003: Routing failed to locate next-hop for protocol from src
interface:src IP/src port to dest interface:dest IP/dest port

Actual log entry: 6      Aug 13 2012      14:48:30      110003      x.x.123.232      59147      10.2.x.x      22      Routing failed to locate next hop for TCP from outside: x.x.123.232/59147 to inside:10.2.x.x/22


I dont care about accessing the actual inside to inside subnets as I know that is probably just a NAT statement between the two subnets (I think).  I am hoping its that simple with OUTSIDE to (secondary) INSIDE.

***********************************************

interface Ethernet0/0
 nameif outside
 security-level 0
 ip address 200.x.x.x 255.255.255.240
!
interface Ethernet0/1
 nameif inside
 security-level 100
 ip address 10.1.1.x 255.255.255.0
!
interface Ethernet0/2
 nameif aosoft
 security-level 100
 ip address 10.2.2.x 255.255.255.0

object network ITMS_VLAN
 subnet 10.1.1.0 255.255.255.0

object network AOSOFT_VLAN
 subnet 10.2.2.0 255.255.255.0

object network AOSOFT_DRAC_1
 host 10.2.2.11

access-list outside_access_in extended permit tcp any object ITMS_Exchange object-group smtp
access-list outside_access_in extended permit tcp any object AOSOFT_DRAC_1 object-group tftp

object network ITMS_Exchange
 nat (inside,outside) static 200.x.x.1

object network AOSOFT_DRAC_1
 nat (inside,outside) static 200.x.x.2

object network ANY
 nat (inside,outside) dynamic interface

access-group outside_access_in in interface outside

route outside 0.0.0.0 0.0.0.0 200.x.x.x 1

***********************************************

Hopefully this makes sense....
Comment
Watch Question
CERTIFIED EXPERT
Commented:
This problem has been solved!
Unlock 1 Answer and 4 Comments.
See Answer
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE