<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5505 Newbie, T1 interface multiple public IPs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776106#M1003549</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did that and SSH times out (trying via PuTTY).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Telnet wants a password and I try the password that I use same password that I use for ASDM and no luck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Jun 2007 14:40:41 GMT</pubDate>
    <dc:creator>thomas.estes</dc:creator>
    <dc:date>2007-06-08T14:40:41Z</dc:date>
    <item>
      <title>ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776102#M1003493</link>
      <description>&lt;P&gt;I am trying to setup up our ASA5505 on our T1. I have outside interface setup on xx.xx.170.18 (the first open public IP). We want non encrypted SMTP traffic to flow from this IP to the mail server at 192.168.1.50. Then I want encrypted mail on our next available public ip xx.xx.170.20 to come into the ASA5505 and route to 192.168.1.30 via SMTP port 25 also. I am stumped though as to how to accomplish this. Do I need an additional "outside" interface for the other public ip? There is 1 T1 line can that "line" have 2 ip addresses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:27:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776102#M1003493</guid>
      <dc:creator>thomas.estes</dc:creator>
      <dc:date>2019-03-11T10:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776103#M1003509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The whole /29 network is routed to you by the isp so you do not need another physical interface. You just need to add another static and acl entry for the new server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any host xx.xx.170.20 eq smtp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) xx.xx.170.20 192.168.1.30 netmask 255.255.255.255&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 14:23:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776103#M1003509</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-06-08T14:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776104#M1003522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am struggling with inputting these via the ASDM I always seem to get them backwards. So how do I telnet or SSH to the device so that I can CLI these commands to the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again sorry to be such a newbie.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try and access via telnet and I get:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Access verification&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PASSWORD:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try the password that I use for ASDM it does not work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 14:31:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776104#M1003522</guid>
      <dc:creator>thomas.estes</dc:creator>
      <dc:date>2007-06-08T14:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776105#M1003538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Configuration -&amp;gt; Properties -&amp;gt; Device Access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Add your ip address or network you are on to ssh or telnet lists. I recommend ssh.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 14:35:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776105#M1003538</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-06-08T14:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776106#M1003549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did that and SSH times out (trying via PuTTY).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Telnet wants a password and I try the password that I use same password that I use for ASDM and no luck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 14:40:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776106#M1003549</guid>
      <dc:creator>thomas.estes</dc:creator>
      <dc:date>2007-06-08T14:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776107#M1003556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try Config -&amp;gt; Properties -&amp;gt; Certificates -&amp;gt; Key pair&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should have a general purpose 1024 key there, if not hit add and generate now. Then try ssh.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;check your config for &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 14:51:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776107#M1003556</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-06-08T14:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776108#M1003563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok I generated the general purpose cert and can now get putty to connect via ssh but still can;t logon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It asks logon as:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried blank&lt;/P&gt;&lt;P&gt;I have tried enable_15&lt;/P&gt;&lt;P&gt;and a user id that I created to no avail.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 15:03:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776108#M1003563</guid>
      <dc:creator>thomas.estes</dc:creator>
      <dc:date>2007-06-08T15:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776109#M1003569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;device access -&amp;gt; aaa access -&amp;gt; check enable server group local and check ssh server group local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you should then be able to use the username you created in asa.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 15:08:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776109#M1003569</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-06-08T15:08:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776110#M1003573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that resolved my ssh access. thanks so much for your help. I will now try to apply these rules to fix my original issues.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 15:11:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776110#M1003573</guid>
      <dc:creator>thomas.estes</dc:creator>
      <dc:date>2007-06-08T15:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776111#M1003576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I use this then email flows in from the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 25 192.168.1.50 25 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As soon as I change this to &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) xx.xx.170.18 192.168.1.50 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mail flow stops.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to be able to point at the specific incoming IP so that I can route between x.x.x.18 smtp and x.x.x.20 smtp zixvpm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 17:11:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776111#M1003576</guid>
      <dc:creator>thomas.estes</dc:creator>
      <dc:date>2007-06-08T17:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776112#M1003580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You said you wanted xx.xx.170.18 to map to 192.168.1.30....not 192.168.1.50.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that correct or no?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 17:16:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776112#M1003580</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-06-08T17:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776113#M1003585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;xx.xx.170.18 -&amp;gt; 192.168.1.50&lt;/P&gt;&lt;P&gt;xx.xx.170.20 -&amp;gt; 192.168.1.30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 17:18:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776113#M1003585</guid>
      <dc:creator>thomas.estes</dc:creator>
      <dc:date>2007-06-08T17:18:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776114#M1003590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, when the address is also your outside interface address and you are doing pat then you need to use the "interface" keyword in your static. Since xx.xx.172.18 = ASA outside interface address then...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) interface 192.168.1.50 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) xx.xx.170.20 192.168.1.30 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 17:21:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776114#M1003590</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-06-08T17:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776115#M1003597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok I have tried those.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need to do the PAT here as well for the smtp?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the new running config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "show running-config"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 7.2(2) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ASA5505&lt;/P&gt;&lt;P&gt;domain-name amcinc.us&lt;/P&gt;&lt;P&gt;enable password 8aPd93D5bXaT2fFZ encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; mac-address 0012.3f7f.9876&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; description NuVox T1&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address x.x.170.18 255.255.255.248 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name amcinc.us&lt;/P&gt;&lt;P&gt;object-group icmp-type icmp_grp&lt;/P&gt;&lt;P&gt; icmp-object echo-reply&lt;/P&gt;&lt;P&gt; icmp-object information-reply&lt;/P&gt;&lt;P&gt; icmp-object traceroute&lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any any eq smtp &lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any host x.x.170.18 eq https &lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any host x.x.170.18 eq 9850 &lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any any eq 1677 &lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any any eq 7205 &lt;/P&gt;&lt;P&gt;access-list out2in extended permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging from-address &lt;A href="mailto:thomas.estes@amcinc.us"&gt;thomas.estes@amcinc.us&lt;/A&gt;&lt;/P&gt;&lt;P&gt;logging recipient-address &lt;A href="mailto:thomas.estes@amcinc.us"&gt;thomas.estes@amcinc.us&lt;/A&gt; level errors&lt;/P&gt;&lt;P&gt;logging host inside 192.168.1.114&lt;/P&gt;&lt;P&gt;logging permit-hostdown&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-522.bin&lt;/P&gt;&lt;P&gt;asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface https 192.168.1.50 https netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 9850 192.168.1.50 9850 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 1677 192.168.1.50 1677 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 7205 192.168.1.50 7205 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface smtp 192.168.1.50 smtp netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) x.x.170.20 192.168.1.30 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-group out2in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 x.x.170.17 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;username xxxx password pfaW5bAu431sHznu encrypted privilege 15&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;ssh 192.168.1.110 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;ssh 192.168.1.114 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.100-192.168.1.149 inside&lt;/P&gt;&lt;P&gt;dhcpd dns 64.89.70.2 64.89.74.2 interface inside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;  inspect rtsp &lt;/P&gt;&lt;P&gt;  inspect esmtp &lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;  inspect skinny &lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt;  inspect sip &lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt; csd image disk0:/securedesktop-asa-3.1.1.29-k9.pkg&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;Cryptochecksum:1f035eed7192c5ef42cf50d5e477e8d3&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 17:31:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776115#M1003597</guid>
      <dc:creator>thomas.estes</dc:creator>
      <dc:date>2007-06-08T17:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776116#M1003598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is pat...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and it has nothing to do with your smtp problem. Your config looks fine, .20 is not working or what? Try a "clear xlate".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 17:35:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776116#M1003598</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-06-08T17:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776117#M1003599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I told you this previously as well but you want to write your acl's to be more specific than any.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any x.x.170.18 eq smtp &lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any x.x.170.20 eq smtp&lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any host x.x.170.18 eq https &lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any host x.x.170.18 eq 9850 &lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any host x.x.170.18 eq 1677 &lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any host x.x.170.18 eq 7205 &lt;/P&gt;&lt;P&gt;access-list out2in extended permit icmp any any echo-reply&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 17:41:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776117#M1003599</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-06-08T17:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776118#M1003602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You had, I just have been so paranoid about email not flowing in that I did not want to change them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 17:44:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776118#M1003602</guid>
      <dc:creator>thomas.estes</dc:creator>
      <dc:date>2007-06-08T17:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776119#M1003609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No probs, what you have in your config should work fine for the second smtp server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 17:45:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776119#M1003609</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-06-08T17:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776120#M1003613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Last time, (hopefully).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since I am paranoid and skeptical.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my config. that I hope will allow traffic from our 2 different public IPs to one interface both on port 25.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "show running-config"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; mac-address 0012.3f7f.9876&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; description NuVox T1&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address x.x.170.18 255.255.255.248 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name amcinc.us&lt;/P&gt;&lt;P&gt;object-group icmp-type icmp_grp&lt;/P&gt;&lt;P&gt; icmp-object echo-reply&lt;/P&gt;&lt;P&gt; icmp-object information-reply&lt;/P&gt;&lt;P&gt; icmp-object traceroute&lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any host x.x.170.18 eq smtp &lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any host x.x.170.20 eq smtp &lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any host x.x.170.18 eq https &lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any host x.x.170.18 eq 9850 &lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any host x.x.170.18 eq 1677 &lt;/P&gt;&lt;P&gt;access-list out2in extended permit tcp any host x.x.170.18 eq 7205 &lt;/P&gt;&lt;P&gt;access-list out2in extended permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging from-address &lt;A href="mailto:thomas.estes@amcinc.us"&gt;thomas.estes@amcinc.us&lt;/A&gt;&lt;/P&gt;&lt;P&gt;logging recipient-address &lt;A href="mailto:thomas.estes@amcinc.us"&gt;thomas.estes@amcinc.us&lt;/A&gt; level errors&lt;/P&gt;&lt;P&gt;logging host inside 192.168.1.114&lt;/P&gt;&lt;P&gt;logging permit-hostdown&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-522.bin&lt;/P&gt;&lt;P&gt;asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface https 192.168.1.50 https netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 9850 192.168.1.50 9850 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 1677 192.168.1.50 1677 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 7205 192.168.1.50 7205 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface smtp 192.168.1.50 smtp netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) x.x.170.20 192.168.1.30 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-group out2in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 x.x.170.17 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;username xxxxx password pfaW5bAu431sHznu encrypted privilege 15&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.114 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;snmp-server host inside 192.168.1.1 community ASA5505&lt;/P&gt;&lt;P&gt;snmp-server location Data Room&lt;/P&gt;&lt;P&gt;snmp-server contact Tom Estes&lt;/P&gt;&lt;P&gt;snmp-server community ASA5505&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 192.168.1.110 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;ssh 192.168.1.114 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.100-192.168.1.149 inside&lt;/P&gt;&lt;P&gt;dhcpd dns 64.89.70.2 64.89.74.2 interface inside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;  inspect rtsp &lt;/P&gt;&lt;P&gt;  inspect esmtp &lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;  inspect skinny &lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt;  inspect sip &lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;Cryptochecksum:1f035eed7192c5ef42cf50d5e477e8d3&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 17:59:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776120#M1003613</guid>
      <dc:creator>thomas.estes</dc:creator>
      <dc:date>2007-06-08T17:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Newbie, T1 interface multiple public IPs</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776121#M1003616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's a lot of pressure, haha, but yes it looks fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2007 18:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-newbie-t1-interface-multiple-public-ips/m-p/776121#M1003616</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-06-08T18:02:24Z</dc:date>
    </item>
  </channel>
</rss>

