We are converting our offices from MPLS to VPN Site2Site tunnels.
the tunnels are all operating properly with all traffic going in both directions.
Our issue is with Traceroute between sites.
On MPLS, everything replies during a traceroute. Between the ASA devices, I can get the "internal" one (local to the site) to respond, but not the "external" one (at the far end)
I have added the following according to what I can find on the internet about this issue:
access-list outside_access_in extended permit icmp any any time-exceeded
access-list outside_access_in remark ICMP type 3 for Cisco and Linux
access-list outside_access_in extended permit icmp any any unreachable
access-group outside_access_in in interface outside
set connection decrement-ttl
icmp unreachable rate-limit 10 burst-size 5
The issue I end up with is that the remote ASA doesn't show up in the list
See this trace:
1 <1 ms <1 ms <1 ms mwspcoresw1.mycompany.com [192.168.3.251] 2 <1 ms <1 ms <1 ms router.mycompany.com [192.168.3.253] 3 <1 ms <1 ms <1 ms asa_inside.mycompany.com [172.16.100.2] 4 * * * Request timed out. 5 84 ms 86 ms 83 ms 192.168.26.11
I'm assuming the request timed out is the remote end ASA.
set connection decrement-ttl is part of my config.
the local ASA responds, just not the remote one.
it happens in both directions. from NJ to remote, or remote to NJ. the "local" asa responds, but not the remote one.
1 1 ms <1 ms <1 ms nj_coresw [192.168.3.251] 2 <1 ms <1 ms <1 ms nj_router [192.168.3.253] 3 <1 ms <1 ms <1 ms nj_asa_inside [172.16.100.2] 4 * * * Request timed out. <--I assume the is the remote ASA 5 143 ms 139 ms 139 ms 192.168.25.11 <-- this is what I was trying to trace to.
Question We run asr9001 with XR 6.1.3, and we have a very long delay to
login w/ SSH 1 or 2 to the device compare to IOS device. After
investigation, the there is 1s delay between the client KEXDH_INIT and
the server (XR) KEXDH_REPLY. After debug ssh serv...
Introduction The purpose of this document is to demonstrate the Open
Shortest Path First (OSPF) behavior when the V-bit (Virtual-link bit) is
present in a non-backbone area. The V-bit is signaled in Type-1 LSA only
if the router is the endpoint of one or ...
Hi, I am seeing quite a few issues with patch install and wanted to
share my experience and workaround to this. Login to admin via CLI, then
access root with the “shell” command Issue “df –h” and you’ll probably
see the following directory full or nearly ...