Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

Not able to access different networks traffic on same interface

Unanswered Question
Apr 21st, 2008
User Badges:

I am having problems connecting to different networks which are connected on the same interface.

Port 0/0 - Internet

Port 0/1 - Connected to LAN (member of vlan 1)

Port 0/2 - Connected to Branch Router(member of vlan 1)

Vlan 1 -

Branch Router IP address -

whenever I want to connected to remote location I have to add manually route on the machine to reach the remote network with

Did anyone faced similar issue?

If yes please let me how this can be resolved.

Surprising part is that I am able to ping the remote branch but not able to access any applications/resources.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
pankajppawar Tue, 04/22/2008 - 00:30
User Badges:

Attached is the n/w diagram for better clarity

As you can see, the gateway of the machine is and to reach the, I have to add route in each machine pointing to

husycisco Tue, 04/22/2008 - 02:14
User Badges:
  • Gold, 750 points or more

Hi Pankaj,

Assuming that is a Cisco router, add the following command in

ip route


husycisco Tue, 04/22/2008 - 02:33
User Badges:
  • Gold, 750 points or more

I checked the diagram. Try my suggestion above.

husycisco Tue, 04/22/2008 - 03:05
User Badges:
  • Gold, 750 points or more

1)Please run the following command in a computer which has the gateway IP of, and paste here the result


2)Please run the following command in ASA and paste the results here

packet-tracer input inside tcp 3389 3389 detailed


sh route

wasiimcisco Tue, 04/22/2008 - 04:10
User Badges:

I am assuming that router, firewall and host computer are connected in a share media switch or hub.

U have two ways to achieve your goal, one is add the layer 3 switch and define routes in it, one default route that points towards Firewall that route takes the client to internet and one static route 192.168.0 0 which points towards the router interface

If u dont have switch with routing capabilities manually add the route in host computer one default route and on static route that points towards

Please rate if this is helpful

pankajppawar Tue, 04/22/2008 - 20:32
User Badges:


I had thought of this earlier.

But somehow I dont find doing this comfortable.

Doing this would mean that ASA is not supporting

"same-security-traffic permit intra-interface" command.

michelcaissie Wed, 04/23/2008 - 09:58
User Badges:

Here, we must understand that the routing capabilities of a ASA is limited compared to a router. Initially a PIX would not allowed a packet to leave an interface on the same

interface that they came in. This was improved by adding the "same-security-traffic permit intra-interface" command, wich i assume you are using. But this does not resolve everything,

because the ASA does not reroute the packet the way a router would , it creates a connection the same way it would if the packet leave the outside interface.Your problem is that

the returning packet doesn't get back to the ASA.

Let see with an example; makes a tcp connection on The SYN hits the ASA wich opens a connection , then route the packet to the MPLS router at

But the returning SYN packet goes directly to the PC because it is Directly Connected to the router. Then the PC sends the ACK to the ASA ( the default gateway)

but it is refused because the ASA never saw the returning SYN . So your TCP connection dies here.

One solution could be to create a sub-interface on the inside interface, configure it on a /22 subnet , put the MPLS router in this subnet and create a static route in the MPLS router for your

inside network. This way it would force all returning traffic to go through the ASA.


This Discussion