<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower 2120 with ASA Code - Web Services Hosting Failed in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-2120-with-asa-code-web-services-hosting-failed/m-p/3357285#M1026923</link>
    <description>&lt;P&gt;Configuration seems to be ok regarding the nat.&lt;/P&gt;
&lt;P&gt;Following command:&lt;/P&gt;
&lt;P&gt;route Internet 0.0.0.0 0.0.0.0 10.152.55.254 tunneled, I believe should be:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;route Internal 0.0.0.0 0.0.0.0 10.152.55.254 tunneled, but do not think is the problem with the nat.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can you post the output from packet-tracer ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;packet-tracer input&amp;nbsp;Internet tcp 2.2.2.2 1025 1.1.1.5 80&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Mar 2018 07:53:13 GMT</pubDate>
    <dc:creator>Bogdan Nita</dc:creator>
    <dc:date>2018-03-29T07:53:13Z</dc:date>
    <item>
      <title>Firepower 2120 with ASA Code - Web Services Hosting Failed</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2120-with-asa-code-web-services-hosting-failed/m-p/3357220#M1026922</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;We recently purchase Firepower 2120 with ASA Code 9.9.1. We managed to setup the AnyConnect and can be connected from internet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When we try to host a public server. We have the access rules and NAT in place. Just that from the log, it always throw SYN Timeout. Is the Firepower 2120 come with some security features that need to turn it off?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My Setup as follow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interface 1/1 - Internet - Security-Level 0&lt;/P&gt;
&lt;P&gt;1.1.1.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interface 1/2&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Internal- Security-Level 1&lt;/P&gt;
&lt;P&gt;10.152.55.254&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interface 1/3 - Services - Security-Level 1&lt;/P&gt;
&lt;P&gt;192.168.7.254&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My internal server located at Services zone with IP Addr 192.168.7.55.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access rule and NAT as follow:-&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;access-list Internet_access extended permit tcp any4 object&amp;nbsp;192.168.7.55&amp;nbsp;eq www&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;object network obj_any&lt;BR /&gt; nat (Internal,Internet) dynamic interface&lt;BR /&gt;object network test_Services&lt;BR /&gt; nat (Services,Internet) static&amp;nbsp;1.1.1.5&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When i access &lt;A href="http://1.1.1.5" target="_blank"&gt;http://1.1.1.5&lt;/A&gt; from public internet. It will just get SYN Timeout.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Anyone can advise?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I have attached the full config&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2120-with-asa-code-web-services-hosting-failed/m-p/3357220#M1026922</guid>
      <dc:creator>Boon Keat Gan</dc:creator>
      <dc:date>2020-02-21T15:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2120 with ASA Code - Web Services Hosting Failed</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2120-with-asa-code-web-services-hosting-failed/m-p/3357285#M1026923</link>
      <description>&lt;P&gt;Configuration seems to be ok regarding the nat.&lt;/P&gt;
&lt;P&gt;Following command:&lt;/P&gt;
&lt;P&gt;route Internet 0.0.0.0 0.0.0.0 10.152.55.254 tunneled, I believe should be:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;route Internal 0.0.0.0 0.0.0.0 10.152.55.254 tunneled, but do not think is the problem with the nat.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can you post the output from packet-tracer ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;packet-tracer input&amp;nbsp;Internet tcp 2.2.2.2 1025 1.1.1.5 80&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 07:53:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2120-with-asa-code-web-services-hosting-failed/m-p/3357285#M1026923</guid>
      <dc:creator>Bogdan Nita</dc:creator>
      <dc:date>2018-03-29T07:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2120 with ASA Code - Web Services Hosting Failed</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2120-with-asa-code-web-services-hosting-failed/m-p/3361560#M1026924</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Sorry for late reply. End up the configuration is fine. The problem is due to the server did not set gw in ip addr setting. Haha.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 06 Apr 2018 00:53:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2120-with-asa-code-web-services-hosting-failed/m-p/3361560#M1026924</guid>
      <dc:creator>Boon Keat Gan</dc:creator>
      <dc:date>2018-04-06T00:53:05Z</dc:date>
    </item>
  </channel>
</rss>

