Access list blocking communication on ASA.
Posted on 2013-05-28
I would like some help in locating access list lines on the ASA.
Recently, after a switch change, the monitoring network lost access to one of our management networks. The funny thing is that the monitoring network that comes to the ASA, can reach the ASA perfectly, and the monitored network can reach the gateway ( which is the ASA), without any issue.
eg. The ASA can ping both ends without any issue but both ends cant ping each other, and the ASA is the being the break point.
Both networks reach the ASA
Packets are arriving to the ASA (checked with capture )
I did a packet tracer from end to end, and according to it the traffic from the monitoring network network to the management network should work fine. And in the capture i can see the echo request.
However the way back shows me a drop due to access list. And of course i cant see the echo reply
I tried locating that access-list id on the configuration but I just cant find it!!!!
The id showed on the packet tracer is not shown on the show run command.
Please if someone cud help giving a clue on how to get the line that blocks traffic it will be great. So far i just have the id number for the ACL and that number is not in the access lists applied to the interfaces.
Thanks a lot !!!