cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
429
Views
4
Helpful
5
Replies

No Route even as there is a static route

lemmy1234
Level 1
Level 1

Hi there,

there is a PIX 525 with 7.2(2) running.

The following issue occured:

- suddenly the PIX cannot find a route to one specific host

- There is a static route to the net in which the host resides.

- The hosts one figure above and below are reachable (cannot reache x.x.x.243 but x.x.x.244 and 242).

- The specific host is only from one single interface unreacheable, from the others it can be reached.

- The connection/routing works for a day and suddenly the routing fails.

- There is also ospf running on this machine (as a ASBR).

Is there a bug in the IOS?

Does static routing and ospf not work together?

What can I do to get closer to the cause or how can the issue be resolved?

Thanks in advance

5 Replies 5

Hi,

Do you have natting configured?

#########################################

#If you found this post usefull

#please don't forget to rate this

#########################################

#Iwan Hoogendoorn

#CCIE#13084

#########################################

Historicaly there is static NAT configured. The source ip stays the same on the translated interface.

In the new IOS there is additionaly "enable traffic through the firewall without NAT" enabled.

In the firewall log is the following entry:

%PIX-6-110001: No route to x.x.x.243 from x.x.x.x

Before the issue occured the first time no changes have been made on routing (except ospf dynamic entries) or natting.

Hi,

Can you send a output of you "sh route" Thanks,

#########################################

#If you find this post usefull

#please don't forget to rate this

#########################################

#Iwan Hoogendoorn

#CCIE#13084

#########################################

Hi,

thank you for your reply.

Unfortunatelly the routing table is too long

to post here and I am also not allowed to post it.

The host which is not reachable is in the same static route included like the hosts which can be reached (even in the case of failure).

The route is during the failure still in the routing table and other host have to use the entry (because I can get them via ping).

By the way currently is all working - no failure. So I suppose that there is currently no misconfiguration visible.

The problem occurs "suddenly" and vanishes as soon as I reload the machine.

Can you tell me on which things I shoud have a look on - especially if the failure occurs?

Hi,

Look at the administrative distance of the route ... maybe OSPF is cousing a second route to the same path ...

If it occurs sometimes it might be the OSPF routingupdates

check the uplates frequantly and see if a OSPF route times out (dead timer) and is advertised again ...

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: