Improve company productivity with a Business Account.Sign Up

x
?
Solved

ASA5500 Connections not working on select outside IPs

Posted on 2013-02-01
5
Medium Priority
?
229 Views
Last Modified: 2013-03-01
We have a situation where we can not connect to  certain ip addresses.  We have worked with the it staff at destinations and they say we are not blocked.

If we send from a DMZ (virtual machine) out another internet connection it works fine.  We believe we have it down to the ASA, or Extreme switch.  We can ping 99% of external locations. But we are not able to reach some sites through various ports or protocols.  We have no rules restricting these IPs.  Other locations work great for email, telnet tests, etc...
0
Comment
Question by:PostQ
  • 3
5 Comments
 
LVL 10

Expert Comment

by:joelsplace
ID: 38844337
Are you sure the IPs are blocked or could it be DNS?  I've had a similar issue and it ended up being an ISP router issue.  Does tracert show the pings failing at your ASA?
0
 
LVL 2

Author Comment

by:PostQ
ID: 38844363
Updated info:  Traffic seems to route from other internal switches. Just not this Extreme Summit switch.

We plan an IOS upgrade and a reboot next weekend.  I will continue the thread if that does not fix it.

Thanks
0
 
LVL 17

Expert Comment

by:Marius Gunnerud
ID: 38923704
can you reach these same sites using other protocols?  Lets say you are being blocked when trying to access port 80 at a certain site, but will you be blocked if you try to access port 21?

You say when you when you send out another internet connection it works fine.  Where is this internet connection located? is it also connected to the ASA?

Would you be able to post a sanitized configuration output?
0
 
LVL 2

Accepted Solution

by:
PostQ earned 0 total points
ID: 38924198
We have it solved down to one extreme switch that uses 4 ports aggregated.  

The others switches send out any asa fine.  So it's just a link aggregation issue to work through.
0
 
LVL 2

Author Closing Comment

by:PostQ
ID: 38941485
We found the link agg. bug in this path with any protocol.
0

Featured Post

What Kind of Coding Program is Right for You?

There are many ways to learn to code these days. From coding bootcamps like Flatiron School to online courses to totally free beginner resources. The best way to learn to code depends on many factors, but the most important one is you. See what course is best for you.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Let’s face it: one of the reasons your organization chose a SaaS solution (whether Microsoft Dynamics 365, Netsuite or SAP) is that it is subscription-based. The upkeep is done. Or so you think.
This article is about building a site to site VPN tunnels in Cisco CSR1000V router with IOS XE. There are two Policy Based IPsec VPN tunnels configured on CSR1000V router one with NAT and another without NAT.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

606 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question