Glad I'm not alone wkim623. Do you have the same setup as me 5505 with security+ and failover configured?
Let me know if you find anything.
To get around it have resorted to transparent firewall with the latest IOS, but I still havent been given the 19 public IPs I will need from ISP for this...
Real don't think it's a NAT issue since the packet tracer comes up fine and icmp traffic is ok and all in-out traffic ok, it's just internal traffic other than icmp that's the problem. Thinking it's either routing or packet filtering problem or some other feature causing the problem.
Thanks billybluelight but I have allready tried that. No joy. :(
I don't think the ASA is acting as gateway for the internal network some reason. However I can ping between the servers ok. icmp travel ok other traffic won't.
I don't think it's a routing, NAT or security config problem because the packet tracer brings back an ok result.
This ACL
access-list inside_access_in extended permit ip 192.168.50.0 255.255.255.0 192.1
68.50.0 255.255.255.0
is allowing any internal traffic, are you asking me to change this...
Here is the config, don't be confused by my vlan title, I have no idea whats wrong. Also attached physical design. http://www.box.net/shared/9hake8zdlk
show startup-config
asa-live(config)# show startup-config
: Saved
: Written by enable_15 at 10:13:53.056 GMT/BST Sat Mar 21 2009
!
ASA Version...
This is my setup, 4 server all with 2 NICs, these 2NICs on each server are teamed using broadcom suite 3.
I have 2 ASA 5505 with security plus. And I have setup NAT and failover on these. There will be a router on the outside interface of both ASAs using HSRP for failover.
However traffic is...
Don't worry sorted..
"Failover LAN Interface: failover Vlan111 (down)"
should have been a clue that I had pluged the failover cable into the wrong ethernet port. Stupid me.
A bit of a novice at all this so please bare with me.
I have 2 ASA5505 with security+ licences.
I have setup failover on both devices using the following commands-
failover
failover lan unit primary
failover lan interface failover Vlan111
failover interface ip failover 192.168.255.1...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.