cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1208
Views
0
Helpful
7
Replies

DC and ADC Synchronization through ASA 5580

rajeeshp
Level 1
Level 1

Hi , I have a Windows 2008 server acing as DC connected to one of the interface of ASA 5580, and have couple of ADC in the branches which are connected to different interfaces of ASA.  The routing is happening through the ASA. When trying to do DCPROMO on the ADC it’s giving an error.  Natting is not there in the ASA and I have access-list configured for “Permit IP Any any ” for all interface.  Any clue wht could be the problem ?

7 Replies 7

Jennifer Halim
Cisco Employee
Cisco Employee

When you say there is no NATing, where is the traffic to and from? High security level interface to low, or low security level interface to high?

Both are with the same security level and I have

same-security-traffic permit inter-interface
same-security-traffic permit intra-interface

configured on the ASA.

OK, but you still need to configure static NAT to itself eventhough same-security-traffic permit inter-interface has been configured as that is for the ACL, not for NAT.

To add to my previous post;  I can ping the DC from the ADC, there is no basic communication issue.  Network reachability is there.

to take care about the NAT i have 'no nat-control'

1) Please check the syslog to see if it's being blocked by the firewall.

2) Run packet capture on both interfaces with ACL just between the DC and ADC:

access-list cap-test permit ip host host

access-list cap-test permit ip host host

capture cap-DC access-list cap-test interface

capture cap-ADC access-list cap-test interface

Try the "DCPROMO", and check the packet capture to see where it is breaking.

kloc_marek
Level 1
Level 1

Probably, dcerpc inspection drop some comunication. Try "sh policy-map" and search in dcerpc section, number of drop packet.

Review Cisco Networking products for a $25 gift card