<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem accessing DMZ Servers from inside LAN in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-accessing-dmz-servers-from-inside-lan/m-p/3184730#M1066085</link>
    <description>&lt;P&gt;You´re welcome.&lt;/P&gt;</description>
    <pubDate>Fri, 15 Sep 2017 14:42:48 GMT</pubDate>
    <dc:creator>Flavio Miranda</dc:creator>
    <dc:date>2017-09-15T14:42:48Z</dc:date>
    <item>
      <title>Problem accessing DMZ Servers from inside LAN</title>
      <link>https://community.cisco.com/t5/network-security/problem-accessing-dmz-servers-from-inside-lan/m-p/3184608#M1066082</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I'm an newbie on the ASA5512 and cannot find the correct answer.&lt;/P&gt;&lt;P&gt;I've setup an ASA5512X with an WAN with public subnet, LAN (inside) and DMZ (used for camera's)&lt;/P&gt;&lt;P&gt;I can reach the camera's from the internet, but i cannot see the camera's or ping the camera nas from the LAN (inside)&lt;/P&gt;&lt;P&gt;Please advise how to make it work&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;BR /&gt;: Serial Number: FCH210676AV&lt;BR /&gt;: Hardware:&amp;nbsp;&amp;nbsp; ASA5512, 4096 MB RAM, CPU Clarkdale 2792 MHz, 1 CPU (2 cores)&lt;BR /&gt;: Written by enable_15 at 12:57:15.871 CEDT Fri Sep 15 2017&lt;BR /&gt;!&lt;BR /&gt;ASA Version 9.6(3)1&lt;BR /&gt;!&lt;BR /&gt;hostname ASA5512X-Company&lt;BR /&gt;domain-name company.local&lt;BR /&gt;enable password rkFxeLNX6Jlr4Q/9 encrypted&lt;BR /&gt;names&lt;BR /&gt;ip local pool DHCP-VPN-Clients 10.0.12.210-10.0.12.229 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;&amp;nbsp;nameif WAN&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 10.99.50.134 255.255.255.248&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;&amp;nbsp;nameif LAN&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.0.12.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;&amp;nbsp;nameif DMZ&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 10.0.20.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3&lt;BR /&gt;&amp;nbsp;nameif WLAN&lt;BR /&gt;&amp;nbsp;security-level 20&lt;BR /&gt;&amp;nbsp;ip address 10.0.100.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/4&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/5&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;&amp;nbsp;management-only&lt;BR /&gt;&amp;nbsp;nameif management&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.0.1.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa963-1-smp-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CEST 1&lt;BR /&gt;clock summer-time CEDT recurring last Sun Mar 2:00 last Sun Oct 3:00&lt;BR /&gt;dns domain-lookup WAN&lt;BR /&gt;dns domain-lookup LAN&lt;BR /&gt;dns domain-lookup DMZ&lt;BR /&gt;dns domain-lookup management&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;&amp;nbsp;name-server 8.8.8.8&lt;BR /&gt;&amp;nbsp;name-server 8.8.4.4&lt;BR /&gt;&amp;nbsp;domain-name company.local&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network ASA5512X-company&lt;BR /&gt;&amp;nbsp;host 10.99.50.134&lt;BR /&gt;&amp;nbsp;description WAN Address Cisco ASA 5512-X company&lt;BR /&gt;object network mailserver_Server_LAN&lt;BR /&gt;&amp;nbsp;host 10.0.12.44&lt;BR /&gt;&amp;nbsp;description company Microsoft Exchange 2010 Server LAN&lt;BR /&gt;object network mailserver_Server_WAN&lt;BR /&gt;&amp;nbsp;host 10.99.50.130&lt;BR /&gt;&amp;nbsp;description company Microsoft Exchange 2010 Server WAN&lt;BR /&gt;object network VLAN20-Subnet&lt;BR /&gt;&amp;nbsp;subnet 10.0.20.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;description VLAN 20 Subnet company Camera LAN&lt;BR /&gt;object network mailserver_Server_LAN_SMTP&lt;BR /&gt;&amp;nbsp;host 10.0.12.44&lt;BR /&gt;&amp;nbsp;description company Microsoft Exchange 2010 Server LAN SMTP&lt;BR /&gt;object network mailserver_Server_LAN_HTTPS&lt;BR /&gt;&amp;nbsp;host 10.0.12.44&lt;BR /&gt;&amp;nbsp;description company Microsoft Exchange 2010 Server LAN HTTPS&lt;BR /&gt;object network Outside_CAM_WAN&lt;BR /&gt;&amp;nbsp;host 10.99.50.132&lt;BR /&gt;object network CameraNAS_HTTP_LAN&lt;BR /&gt;&amp;nbsp;host 10.0.20.200&lt;BR /&gt;&amp;nbsp;description company Camera NAS DMZ&lt;BR /&gt;object network CameraNAS_LAN&lt;BR /&gt;&amp;nbsp;host 10.0.20.200&lt;BR /&gt;&amp;nbsp;description company Camera NAS DMZ&lt;BR /&gt;object network company_Network&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network NETWORK_OBJ_10.0.12.192_26&lt;BR /&gt;&amp;nbsp;subnet 10.0.12.192 255.255.255.192&lt;BR /&gt;object network WLAN_WAN&lt;BR /&gt;&amp;nbsp;subnet 10.0.100.0 255.255.255.0&lt;BR /&gt;object network VLAN14_Gateway&lt;BR /&gt;&amp;nbsp;host 10.0.14.201&lt;BR /&gt;object network Location1&lt;BR /&gt;&amp;nbsp;subnet 10.0.10.0 255.255.255.0&lt;BR /&gt;object network Luna_Server_LAN&lt;BR /&gt;&amp;nbsp;host 10.0.12.42&lt;BR /&gt;object network Luna_Server_WAN&lt;BR /&gt;&amp;nbsp;host 10.99.50.131&lt;BR /&gt;object service FTP_60510&lt;BR /&gt;&amp;nbsp;service tcp source eq 60510 destination eq 60510&lt;BR /&gt;&amp;nbsp;description FTP Service Luna 60510&lt;BR /&gt;object network Luna_Server_LAN_FTP&lt;BR /&gt;&amp;nbsp;host 10.0.12.42&lt;BR /&gt;&amp;nbsp;description company Luna FTP&lt;BR /&gt;object network Luna_Server_LAN_FTP-DATA&lt;BR /&gt;&amp;nbsp;host 10.0.12.42&lt;BR /&gt;&amp;nbsp;description company Luna FTP-DATA&lt;BR /&gt;object network Luna_Server_LAN_FTP60510&lt;BR /&gt;&amp;nbsp;host 10.0.12.42&lt;BR /&gt;&amp;nbsp;description company Luna FTP60510&lt;BR /&gt;object network Luna_Server_LAN_FTP_DATA&lt;BR /&gt;object network Inside-Camera&lt;BR /&gt;&amp;nbsp;host 10.0.20.200&lt;BR /&gt;object network DMZ-Network&lt;BR /&gt;&amp;nbsp;subnet 10.0.20.0 255.255.255.0&lt;BR /&gt;object-group service mailserver-Services&lt;BR /&gt;&amp;nbsp;service-object tcp destination eq smtp&lt;BR /&gt;&amp;nbsp;service-object tcp destination eq https&lt;BR /&gt;object-group network INTERNAL-NETWORKS&lt;BR /&gt;&amp;nbsp;description All Internal Networks&lt;BR /&gt;&amp;nbsp;network-object 10.0.10.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.0.12.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.0.14.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.0.15.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.0.20.0 255.255.255.0&lt;BR /&gt;object-group service Camera-Services&lt;BR /&gt;&amp;nbsp;service-object tcp destination eq www&lt;BR /&gt;object-group network Location2_Subnet&lt;BR /&gt;&amp;nbsp;network-object 10.0.12.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.0.14.0 255.255.255.0&lt;BR /&gt;object-group service Luna-Services&lt;BR /&gt;&amp;nbsp;service-object tcp destination eq ftp&lt;BR /&gt;&amp;nbsp;service-object tcp destination eq ftp-data&lt;BR /&gt;&amp;nbsp;service-object object FTP_60510&lt;BR /&gt;access-list outside_inside extended permit icmp any any echo&lt;BR /&gt;access-list outside_inside extended permit udp any any range 33434 33523&lt;BR /&gt;access-list outside_inside extended permit icmp any any time-exceeded&lt;BR /&gt;access-list outside_inside extended permit icmp any any source-quench&lt;BR /&gt;access-list outside_inside extended permit icmp any any echo-reply&lt;BR /&gt;access-list outside_inside extended permit icmp any any unreachable&lt;BR /&gt;access-list outside_inside extended permit object-group mailserver-Services any object mailserver_Server_LAN&lt;BR /&gt;access-list outside_inside extended permit object-group Camera-Services any object CameraNAS_LAN&lt;BR /&gt;access-list outside_inside extended permit object-group Luna-Services any object Luna_Server_LAN&lt;BR /&gt;access-list outside_inside extended deny ip any any&lt;BR /&gt;access-list ICMPACL extended permit icmp any any&lt;BR /&gt;access-list outbound extended permit tcp host 10.0.12.44 any eq smtp&lt;BR /&gt;access-list outbound extended deny tcp any any eq smtp&lt;BR /&gt;access-list outbound extended permit ip any any&lt;BR /&gt;access-list Internal-LAN standard permit 10.0.12.0 255.255.255.0&lt;BR /&gt;access-list Internal-LAN standard permit 10.0.10.0 255.255.255.0&lt;BR /&gt;access-list Internal-LAN standard permit 10.0.15.0 255.255.255.0&lt;BR /&gt;access-list Internal-LAN standard permit 10.0.14.0 255.255.255.0&lt;BR /&gt;access-list Internal-LAN standard permit 10.0.20.0 255.255.255.0&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu WAN 1500&lt;BR /&gt;mtu LAN 1500&lt;BR /&gt;mtu DMZ 1500&lt;BR /&gt;mtu WLAN 1500&lt;BR /&gt;mtu management 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-781-150.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;arp permit-nonconnected&lt;BR /&gt;arp rate-limit 8192&lt;BR /&gt;nat (LAN,WAN) source static any any destination static NETWORK_OBJ_10.0.12.192_26 NETWORK_OBJ_10.0.12.192_26 no-proxy-arp route-lookup&lt;BR /&gt;!&lt;BR /&gt;object network mailserver_Server_LAN&lt;BR /&gt;&amp;nbsp;nat (LAN,WAN) static mailserver_Server_WAN&lt;BR /&gt;object network mailserver_Server_LAN_SMTP&lt;BR /&gt;&amp;nbsp;nat (LAN,WAN) static mailserver_Server_WAN service tcp smtp smtp&lt;BR /&gt;object network mailserver_Server_LAN_HTTPS&lt;BR /&gt;&amp;nbsp;nat (LAN,WAN) static mailserver_Server_WAN service tcp https https&lt;BR /&gt;object network CameraNAS_HTTP_LAN&lt;BR /&gt;&amp;nbsp;nat (DMZ,WAN) static Outside_CAM_WAN service tcp www www&lt;BR /&gt;object network company_Network&lt;BR /&gt;&amp;nbsp;nat (LAN,WAN) dynamic interface&lt;BR /&gt;object network WLAN_WAN&lt;BR /&gt;&amp;nbsp;nat (WLAN,WAN) dynamic interface&lt;BR /&gt;object network Luna_Server_LAN_FTP&lt;BR /&gt;&amp;nbsp;nat (LAN,WAN) static Luna_Server_WAN service tcp ftp ftp&lt;BR /&gt;object network Luna_Server_LAN_FTP-DATA&lt;BR /&gt;&amp;nbsp;nat (LAN,WAN) static Luna_Server_WAN service tcp ftp-data ftp-data&lt;BR /&gt;object network Luna_Server_LAN_FTP60510&lt;BR /&gt;&amp;nbsp;nat (LAN,WAN) static Luna_Server_WAN service tcp 60510 60510&lt;BR /&gt;access-group outside_inside in interface WAN&lt;BR /&gt;route WAN 0.0.0.0 0.0.0.0 10.99.50.129 1&lt;BR /&gt;route LAN 10.0.10.0 255.255.255.0 10.0.14.201 1&lt;BR /&gt;route LAN 10.0.14.0 255.255.255.0 10.0.14.201 1&lt;BR /&gt;route LAN 10.0.15.0 255.255.255.0 10.0.14.201 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;timeout conn-holddown 0:00:15&lt;BR /&gt;aaa-server Company-Radius protocol radius&lt;BR /&gt;aaa-server Company-Radius (LAN) host 10.0.12.43&lt;BR /&gt;&amp;nbsp;key *****&lt;BR /&gt;&amp;nbsp;radius-common-pw Company***********&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;http server enable&lt;BR /&gt;http 10.0.1.0 255.255.255.0 management&lt;BR /&gt;http 10.0.0.0 255.255.0.0 LAN&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto ca trustpoint vpn.company.com&lt;BR /&gt;&amp;nbsp;enrollment terminal&lt;BR /&gt;&amp;nbsp;subject-name CN=vpn.company.com,OU=ICT,O=company en Kroon BV,C=NL,St=Zuid-Holland&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ca certificate chain vpn.company.com&lt;BR /&gt;&amp;nbsp;certificate 776dbc8a918b3823c4c3b68eb379a36f&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3082055d 30820445 a0030201 02021077 6dbc8a91 8b3823c4 c3b68eb3 79a36f30&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0d06092a 864886f7 0d01010b 05003081 90310b30 09060355 04061302 4742311b&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30190603 55040813 12477265 61746572 204d616e 63686573 74657231 10300e06&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 03550407 13075361 6c666f72 64311a30 18060355 040a1311 434f4d4f 444f2043&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 41204c69 6d697465 64313630 34060355 0403132d 434f4d4f 444f2052 53412044&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6f6d6169 6e205661 6c696461 74696f6e 20536563 75726520 53657276 65722043&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 41301e17 0d313730 37313030 30303030 305a170d 32303037 30393233 35393539&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5a305731 21301f06 0355040b 1318446f 6d61696e 20436f6e 74726f6c 2056616c&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 69646174 65643114 30120603 55040b13 0b506f73 69746976 6553534c 311c301a&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 06035504 03131376 706e2e62 656d6d65 6c2d6b72 6f6f6e2e 6e6c3082 0122300d&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 06092a86 4886f70d 01010105 00038201 0f003082 010a0282 010100a4 e56f46d8&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; a5002fdd 2498943e 53076e8c e4953dcc 2d0ac1fe cbdd2a47 90bbd154 e5787660&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 50e3c261 31a7c7d1 58f3a7cb ddc16989 5248aa16 d2e71c32 f88b30ee 2f432e5e&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3b542ad4 1413f360 bc8e3fe2 6bd53344 4e8035bb 039e9f56 41909343 f0f88a5e&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 06ebb4f3 e41ae8e4 1b540089 8de5ba6f 94d3fa17 d3c4689c 5c41069a 4fb861e4&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5be736de 9f45ff69 cd410c86 1f6c7f82 f862f408 5a514194 6cd740ac 7fc38d60&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2eb0a3fd dda3ce2d d1e42830 d4e6633b 07360f44 ae85c2a2 81592f28 6d5b6663&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; eadf51c4 98b3b59b d7d3bc33 e8f9726f 6870352a d19ed052 66428988 5a8e952d&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7866731e 4bf2aeb5 c49b1b0d 8d09249c 778702ab 8a0ae988 e0269f02 03010001&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; a38201e9 308201e5 301f0603 551d2304 18301680 1490af6a 3a945a0b d890ea12&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5673df43 b43a28da e7301d06 03551d0e 04160414 848ea047 78747a13 40c52e5c&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 82543cb5 c448e14b 300e0603 551d0f01 01ff0404 030205a0 300c0603 551d1301&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 01ff0402 3000301d 0603551d 25041630 1406082b 06010505 07030106 082b0601&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 05050703 02304f06 03551d20 04483046 303a060b 2b060104 01b23101 02020730&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2b302906 082b0601 05050702 01161d68 74747073 3a2f2f73 65637572 652e636f&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6d6f646f 2e636f6d 2f435053 30080606 67810c01 02013054 0603551d 1f044d30&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4b3049a0 47a04586 43687474 703a2f2f 63726c2e 636f6d6f 646f6361 2e636f6d&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2f434f4d 4f444f52 5341446f 6d61696e 56616c69 64617469 6f6e5365 63757265&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 53657276 65724341 2e63726c 30818506 082b0601 05050701 01047930 77304f06&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 082b0601 05050730 02864368 7474703a 2f2f6372 742e636f 6d6f646f 63612e63&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6f6d2f43 4f4d4f44 4f525341 446f6d61 696e5661 6c696461 74696f6e 53656375&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 72655365 72766572 43412e63 72743024 06082b06 01050507 30018618 68747470&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3a2f2f6f 6373702e 636f6d6f 646f6361 2e636f6d 30370603 551d1104 30302e82&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1376706e 2e62656d 6d656c2d 6b726f6f 6e2e6e6c 82177777 772e7670 6e2e6265&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6d6d656c 2d6b726f 6f6e2e6e 6c300d06 092a8648 86f70d01 010b0500 03820101&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0085fa8d fa7f4006 43d4b5a0 c1876130 14b3e7f6 b637f477 99d95aaf 408a36a2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 97c37e6b 2dc08b8e 9605d650 6190d799 b8427472 69284993 238d0bd2 422db8ae&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ce1eddad 6e7b7de8 adbee03c 3dfaecc8 dcb973ff 4c4984c5 7b869514 ee1fd4af&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7120c457 7a1d658d 42748e94 beb87e2d 7c32a51d 030ad564 92f41f94 ad3b1f8a&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; d7a6b602 aff948c9 5be324fa 3dfcb32b 77ade144 6173e2f9 3e5bac5c e1676d2c&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; fce89762 5898610e 0a4d9eb5 c5526ee4 70cb4ea4 4cfa6094 ab94bec2 9c6e371b&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 89531033 253e8f5e c7aa6de8 a3b62158 9b3c8d30 d6574cbe c01077de 62d40268&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ce471630 ea7321ab dbcdfa19 4bb0385a a9d7e685 032a2b68 de2d1a30 75178fb7&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8d&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;no ssh stricthostkeycheck&lt;BR /&gt;ssh 10.0.0.0 255.255.0.0 LAN&lt;BR /&gt;ssh 10.0.1.0 255.255.255.0 management&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh cipher encryption all&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd address 10.0.100.1-10.0.100.200 WLAN&lt;BR /&gt;dhcpd dns 8.8.8.8 8.8.4.4 interface WLAN&lt;BR /&gt;dhcpd enable WLAN&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 10.0.1.2-10.0.1.254 management&lt;BR /&gt;dhcpd enable management&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics host&lt;BR /&gt;threat-detection statistics port&lt;BR /&gt;threat-detection statistics protocol&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;ntp server 10.0.12.43 source LAN prefer&lt;BR /&gt;ssl cipher default custom "RC4-SHA:AES128-SHA:AES256-SHA:DES-CBC3-SHA"&lt;BR /&gt;ssl cipher tlsv1 custom "RC4-SHA:AES128-SHA:AES256-SHA:DES-CBC3-SHA"&lt;BR /&gt;ssl cipher dtlsv1 custom "RC4-SHA:AES128-SHA:AES256-SHA:DES-CBC3-SHA"&lt;BR /&gt;ssl trust-point vpn.company.com WAN&lt;BR /&gt;ssl trust-point vpn.company.com LAN&lt;BR /&gt;ssl trust-point vpn.company.com DMZ&lt;BR /&gt;webvpn&lt;BR /&gt;&amp;nbsp;enable WAN&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-macos-4.5.00058-webdeploy-k9.pkg 1&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-win-4.5.00058-webdeploy-k9.pkg 2&lt;BR /&gt;&amp;nbsp;anyconnect enable&lt;BR /&gt;&amp;nbsp;tunnel-group-list enable&lt;BR /&gt;&amp;nbsp;cache&lt;BR /&gt;&amp;nbsp; disable&lt;BR /&gt;&amp;nbsp;error-recovery disable&lt;BR /&gt;group-policy GroupPolicy_vpn.company.com internal&lt;BR /&gt;group-policy GroupPolicy_vpn.company.com attributes&lt;BR /&gt;&amp;nbsp;wins-server none&lt;BR /&gt;&amp;nbsp;dns-server value 10.0.12.43 10.0.12.35&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ssl-client&lt;BR /&gt;&amp;nbsp;split-tunnel-policy tunnelspecified&lt;BR /&gt;&amp;nbsp;split-tunnel-network-list value Internal-LAN&lt;BR /&gt;&amp;nbsp;default-domain value company.local&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;username admin password SepHHjScvkb8.RYh encrypted privilege 15&lt;BR /&gt;tunnel-group vpn.company.com type remote-access&lt;BR /&gt;tunnel-group vpn.company.com general-attributes&lt;BR /&gt;&amp;nbsp;address-pool DHCP-VPN-Clients&lt;BR /&gt;&amp;nbsp;authentication-server-group Company-Radius&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_vpn.company.com&lt;BR /&gt;tunnel-group vpn.company.com webvpn-attributes&lt;BR /&gt;&amp;nbsp;group-alias vpn.company.com enable&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;&amp;nbsp; no tcp-inspection&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect sip&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect skinny&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:18:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-accessing-dmz-servers-from-inside-lan/m-p/3184608#M1066082</guid>
      <dc:creator>Robbert Tol</dc:creator>
      <dc:date>2020-02-21T14:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing DMZ Servers from inside LAN</title>
      <link>https://community.cisco.com/t5/network-security/problem-accessing-dmz-servers-from-inside-lan/m-p/3184648#M1066083</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;For ping from Inside to DMZ you should add inspect:&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect dns preset_dns_map&lt;BR /&gt;inspect h323 h225&lt;BR /&gt;inspect h323 ras&lt;BR /&gt;inspect rsh&lt;BR /&gt;inspect rtsp&lt;BR /&gt;inspect sqlnet&lt;BR /&gt;inspect sunrpc&lt;BR /&gt;inspect xdmcp&lt;BR /&gt;inspect sip&lt;BR /&gt;inspect netbios&lt;BR /&gt;inspect ip-options&lt;BR /&gt;inspect tftp&lt;BR /&gt;inspect ftp&lt;BR /&gt;inspect skinny&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;inspect icmp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;For camera access, I didnt see any access list:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;access-group outside_inside in interface DMZ.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 12:37:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-accessing-dmz-servers-from-inside-lan/m-p/3184648#M1066083</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-09-15T12:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing DMZ Servers from inside LAN</title>
      <link>https://community.cisco.com/t5/network-security/problem-accessing-dmz-servers-from-inside-lan/m-p/3184716#M1066084</link>
      <description>&lt;P&gt;Flavio thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 14:29:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-accessing-dmz-servers-from-inside-lan/m-p/3184716#M1066084</guid>
      <dc:creator>Robbert Tol</dc:creator>
      <dc:date>2017-09-15T14:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing DMZ Servers from inside LAN</title>
      <link>https://community.cisco.com/t5/network-security/problem-accessing-dmz-servers-from-inside-lan/m-p/3184730#M1066085</link>
      <description>&lt;P&gt;You´re welcome.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 14:42:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-accessing-dmz-servers-from-inside-lan/m-p/3184730#M1066085</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-09-15T14:42:48Z</dc:date>
    </item>
  </channel>
</rss>

