Cisco Support Community
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

Problem with intra-interface routing on ASA

Hi Experts!

I´ve just set up an ASA5510 the intra-interface routing is not working as i expected. My topology is precisly as in the  The client have the ASA as their default gateway and then i have a second firewall on the same subnet.  I´ve used the "same-securty-level permit intra-interface" and a static route (the default route points to outside), icmp (and probably udp) works fine but not TCP. I´ve read a lot of explentations why it doesnt work and some solutions but i doesn´t help. According to : everthing should just work fine with that only command

I tried this

access-list INTRA_INTERFACE permit ip any

nat (inside) 1 access-list INTRA_INTERFACE

global (inside) 1 interface

But the then i didn´t get any traffic through the ASA

Do you guys have any suggestions?

Best regards


Everyone's tags (4)
Cisco Employee

Re: Problem with intra-interface routing on ASA


I assume that the is the network directly connected to the ASA. There is something missing, remember that the network you are trying to reach is also on a high security level.. or on the same security level... so it needs a translation as well.... lets assume that the network behind the second firewall is, so on the first firewall you will need the following configuration

static (inside,inside)

and on the second firewall you will need the following line in order to avoid nat on the second firewall when going to the 93 network

access-list nat0 permit ip

nat (inside) 0 access-list nat0

The ICMP is working because it doesnt care about the sequence of ICMP messages, if you put the inspection, it will die.

Try this out and let me know.


CreatePlease to create content