2 Replies Latest reply on Jun 5, 2015 12:54 PM by mike18

    Routing failed to locate next hop

    mike18

      Hi Everyone,

       

      Here is setup

       

      Cisco fw1----Ext-------------Inside -------Mcafee ------External

       

      Cisco Switch is connected to External Interface of Firewall.

      I can ping it from Mcafee firewall.

      But when i try to connect to switch connected to external interface of MCafee via ssh it says

       

      30

      Routing failed to locate next hop for TCP from Inside :192.168.50.1/22 to Inside :172.30.50.1

       

      Regards

      Mike

        • 1. Re: Routing failed to locate next hop
          PhilM

          I'm not 100% sure of your diagram (does the presence of two externals - "Ext" and "External" mean there are two Firewalls here?), but it would suggest that there may well be a routing issue, but not necessarily with McAfee Firewall.

           

          • Does the source host have an explicit route or default gateway that would route traffic for the destination network via the internal IP address of the 1st Firewall?
          • Does that first Firewall have an explicit route or default gateway that would route traffic for the destinaion network via the internal IP address of the McAfee Firewall?
          • If the traffic passing through the 1st Firewall is not having source NAT applied (retaining the original source IP address), is there a static route present on the McAfee Firewall that would route traffic for the source host's subnet back via the "external" address of the 1st Firewall?

           

          If any one of the above questions is answered "no", and assuming there is an appropriate SSH rule allowing this traffic to pass through each Firewall, then this is why the connection attempt is failing.

           

          -Phil.

          • 2. Re: Routing failed to locate next hop
            mike18

            Hi Phil,

             

            You were spot on it was routing issue with Switch.It has no Route back to MCafee firewall.

            I added the Route to switch and all worked fine.

             

            Regards

            Mike