ASA 5510 - no route problem

Unanswered Question
Mar 20th, 2010
User Badges:

I have the following network

Newmarket LAN - inside network connected to interface "inside"

Connection to ISP 1 - - interface "outside"

connection to ISP 2 - - interface "backup"

I am trying to build a VPN tunnel using the "backup" interface - to - but..

If you look at the debud logs it fails "no route to from

I think what I need to do is to tell the backup interface to route traffic from "backup" for via "outside" (the defaout route) but cannot figure this out.

This is the routing table from the show route

Result of the command: "show route"

Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
       i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
       * - candidate default, U - per-user static route, o - ODR
       P - periodic downloaded static route

Gateway of last resort is to network

C is directly connected, outside
S    Bury_LAN [1/0] via, outside
C    Newmarket_LAN is directly connected, inside
C is directly connected, backup
S [1/0] via, backup
S* [1/0] via, outside

I attach my config and debig is below

2010-03-20 20:28:04    Local4.Debug    %ASA-7-715077: Pitcher: received a key acquire message, spi 0x0

2010-03-20 20:28:04    Local4.Notice    %ASA-5-713041: IP =, IKE Initiator: New Phase 1, Intf backup, IKE Peer  local Proxy Address, remote Proxy Address,  Crypto map (backup_map)

2010-03-20 20:28:04    Local4.Debug    %ASA-7-715046: IP =, constructing ISAKMP SA payload

2010-03-20 20:28:04    Local4.Debug    %ASA-7-715046: IP =, constructing NAT-Traversal VID ver 02 payload

2010-03-20 20:28:04    Local4.Debug    %ASA-7-715046: IP =, constructing NAT-Traversal VID ver 03 payload

2010-03-20 20:28:04    Local4.Debug    %ASA-7-715046: IP =, constructing Fragmentation VID + extended capabilities payload

2010-03-20 20:28:04    Local4.Debug    %ASA-7-713236: IP =, IKE_DECODE SENDING Message (msgid=0) with payloads : HDR + SA (1) + VENDOR (13) + VENDOR (13) + VENDOR (13) + NONE (0) total length : 148

2010-03-20 20:28:04    Local4.Info    %ASA-6-110001: No route to from

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Jennifer Halim Sat, 03/20/2010 - 17:40
User Badges:
  • Cisco Employee,

If you would like to use the backup interface as the VPN termination for your LAN-to-LAN tunnel, here is the routes that you need to add:

route backup

route backup

route backup

Hope that helps.

mawallace Sun, 03/21/2010 - 14:59
User Badges:

So my issue is that all traffic for is routed via the outside interface due to default route - and if I want to have a VPN terminating on the backup interface I have to route traffic for etc via the backup interface. Is that correct?

Is there no way for me to tell the ASA that, while it uses the backup interrface to  terminate the VPN that it has to reach through the outside interface netwrok?

Jennifer Halim Sun, 03/21/2010 - 16:08
User Badges:
  • Cisco Employee,

You are right. There is no way to use a different interface other than the directly routed interface for VPN termination on ASA. Unline a router where you can use loopback interface for example.

So the following scenario is not supported:

- Backup interface as the VPN termination, but the actual VPN traffic comes from the Outside interface due to it being the default gateway.


This Discussion