<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5506 issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174021#M1066762</link>
    <description>&lt;P&gt;I have a very simple configuration; however, the two same security level interfaces cannot talk to each other. I have had a TAC case open for 2+ weeks and I’m at the point of frustration.&amp;nbsp; Should I blow the configuration away and try again?&amp;nbsp; Everything I read says that I have the command to be able to talk between the two same security interfaces, but it doesn’t work.&amp;nbsp; Did NAT/PAT mess up?&amp;nbsp; I’m hoping someone can help me solve this one, and if not, does write erase effect any of my firepower lic.?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;: Hardware:&amp;nbsp;&amp;nbsp; ASA5506, 4096 MB RAM, CPU Atom C2000 series 1250 MHz, 1 CPU (4 cores)&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 9.8(1)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname BillsASAhome&lt;/P&gt;&lt;P&gt;enable password $&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/1&lt;/P&gt;&lt;P&gt;&amp;nbsp;nameif outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;security-level 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address dhcp setroute&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/2&lt;/P&gt;&lt;P&gt;&amp;nbsp;nameif insidewired&lt;/P&gt;&lt;P&gt;&amp;nbsp;security-level 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/3&lt;/P&gt;&lt;P&gt;&amp;nbsp;nameif eeroWIFI&lt;/P&gt;&lt;P&gt;&amp;nbsp;security-level 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address 192.168.7.2 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/4&lt;/P&gt;&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/5&lt;/P&gt;&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/6&lt;/P&gt;&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/7&lt;/P&gt;&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;nameif&lt;/P&gt;&lt;P&gt;&amp;nbsp;security-level 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address dhcp setroute&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management1/1&lt;/P&gt;&lt;P&gt;&amp;nbsp;management-only&lt;/P&gt;&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa981-lfbff-k8.SPA&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_2&lt;/P&gt;&lt;P&gt;&amp;nbsp;protocol-object udp&lt;/P&gt;&lt;P&gt;&amp;nbsp;protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group protocol TCPUDP&lt;/P&gt;&lt;P&gt;&amp;nbsp;protocol-object udp&lt;/P&gt;&lt;P&gt;&amp;nbsp;protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_1&lt;/P&gt;&lt;P&gt;&amp;nbsp;service-object ip&lt;/P&gt;&lt;P&gt;&amp;nbsp;service-object udp&lt;/P&gt;&lt;P&gt;&amp;nbsp;service-object tcp&lt;/P&gt;&lt;P&gt;&amp;nbsp;service-object udp destination eq www&lt;/P&gt;&lt;P&gt;access-list eeroWIFI_access_in remark test&lt;/P&gt;&lt;P&gt;access-list eeroWIFI_access_in extended permit object-group DM_INLINE_SERVICE_1 any object obj_any&lt;/P&gt;&lt;P&gt;access-list eeroWIFI_access_in extended permit object-group TCPUDP any4 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu eeroWIFI 1500&lt;/P&gt;&lt;P&gt;mtu eeroWifi2 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-781.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;no arp permit-nonconnected&lt;/P&gt;&lt;P&gt;arp rate-limit 16384&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt;&amp;nbsp;nat (any,outside) dynamic interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (eeroWIFI,outside) after-auto source dynamic any interface&lt;/P&gt;&lt;P&gt;access-group eeroWIFI_access_in in interface eeroWIFI&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;timeout conn-holddown 0:00:15&lt;/P&gt;&lt;P&gt;timeout igp stale-route 0:01:10&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication login-history&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;service sw-reset-button&lt;/P&gt;&lt;P&gt;crypto ipsec security-association pmtu-aging infinite&lt;/P&gt;&lt;P&gt;crypto ca trustpoint _SmartCallHome_ServerCA&lt;/P&gt;&lt;P&gt;&amp;nbsp;no validation-usage&lt;/P&gt;&lt;P&gt;&amp;nbsp;crl configure&lt;/P&gt;&lt;P&gt;crypto ca trustpool policy&lt;/P&gt;&lt;P&gt;crypto ca certificate chain _SmartCallHome_ServerCA&lt;/P&gt;&lt;P&gt;&amp;nbsp;certificate ca 18dad19e267de8bb4a2158cdcc6b3b4a&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 183f685c f2424a85 3854835f d1e82cf2 ac11d6a8 ed636a&lt;/P&gt;&lt;P&gt;&amp;nbsp; quit&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;no ssh stricthostkeycheck&lt;/P&gt;&lt;P&gt;ssh 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;ssh version 2&lt;/P&gt;&lt;P&gt;ssh key-exchange group dh-group1-sha1&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;management-access inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;dhcp-client client-id interface eeroWifi2&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.5-192.168.1.254 inside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.7.10-192.168.7.254 eeroWIFI&lt;/P&gt;&lt;P&gt;dhcpd enable eeroWIFI&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics port&lt;/P&gt;&lt;P&gt;threat-detection statistics protocol&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp;parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;&amp;nbsp; no tcp-inspection&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;service call-home&lt;/P&gt;&lt;P&gt;call-home reporting anonymous&lt;/P&gt;&lt;P&gt;call-home&lt;/P&gt;&lt;P&gt;&amp;nbsp;contact-email-addr william.w.barnes2.ctr@mail.mil&lt;/P&gt;&lt;P&gt;&amp;nbsp;profile CiscoTAC-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination transport-method http&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;/P&gt;&lt;P&gt;Cryptochecksum:6288f85add5f4cd8595239f3d0fcb1be&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;</description>
    <pubDate>Sat, 22 Feb 2020 07:34:38 GMT</pubDate>
    <dc:creator>wwbarnes</dc:creator>
    <dc:date>2020-02-22T07:34:38Z</dc:date>
    <item>
      <title>ASA 5506 issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174021#M1066762</link>
      <description>&lt;P&gt;I have a very simple configuration; however, the two same security level interfaces cannot talk to each other. I have had a TAC case open for 2+ weeks and I’m at the point of frustration.&amp;nbsp; Should I blow the configuration away and try again?&amp;nbsp; Everything I read says that I have the command to be able to talk between the two same security interfaces, but it doesn’t work.&amp;nbsp; Did NAT/PAT mess up?&amp;nbsp; I’m hoping someone can help me solve this one, and if not, does write erase effect any of my firepower lic.?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;: Hardware:&amp;nbsp;&amp;nbsp; ASA5506, 4096 MB RAM, CPU Atom C2000 series 1250 MHz, 1 CPU (4 cores)&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 9.8(1)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname BillsASAhome&lt;/P&gt;&lt;P&gt;enable password $&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/1&lt;/P&gt;&lt;P&gt;&amp;nbsp;nameif outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;security-level 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address dhcp setroute&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/2&lt;/P&gt;&lt;P&gt;&amp;nbsp;nameif insidewired&lt;/P&gt;&lt;P&gt;&amp;nbsp;security-level 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/3&lt;/P&gt;&lt;P&gt;&amp;nbsp;nameif eeroWIFI&lt;/P&gt;&lt;P&gt;&amp;nbsp;security-level 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address 192.168.7.2 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/4&lt;/P&gt;&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/5&lt;/P&gt;&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/6&lt;/P&gt;&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/7&lt;/P&gt;&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;nameif&lt;/P&gt;&lt;P&gt;&amp;nbsp;security-level 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address dhcp setroute&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management1/1&lt;/P&gt;&lt;P&gt;&amp;nbsp;management-only&lt;/P&gt;&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa981-lfbff-k8.SPA&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_2&lt;/P&gt;&lt;P&gt;&amp;nbsp;protocol-object udp&lt;/P&gt;&lt;P&gt;&amp;nbsp;protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group protocol TCPUDP&lt;/P&gt;&lt;P&gt;&amp;nbsp;protocol-object udp&lt;/P&gt;&lt;P&gt;&amp;nbsp;protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_1&lt;/P&gt;&lt;P&gt;&amp;nbsp;service-object ip&lt;/P&gt;&lt;P&gt;&amp;nbsp;service-object udp&lt;/P&gt;&lt;P&gt;&amp;nbsp;service-object tcp&lt;/P&gt;&lt;P&gt;&amp;nbsp;service-object udp destination eq www&lt;/P&gt;&lt;P&gt;access-list eeroWIFI_access_in remark test&lt;/P&gt;&lt;P&gt;access-list eeroWIFI_access_in extended permit object-group DM_INLINE_SERVICE_1 any object obj_any&lt;/P&gt;&lt;P&gt;access-list eeroWIFI_access_in extended permit object-group TCPUDP any4 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu eeroWIFI 1500&lt;/P&gt;&lt;P&gt;mtu eeroWifi2 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-781.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;no arp permit-nonconnected&lt;/P&gt;&lt;P&gt;arp rate-limit 16384&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt;&amp;nbsp;nat (any,outside) dynamic interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (eeroWIFI,outside) after-auto source dynamic any interface&lt;/P&gt;&lt;P&gt;access-group eeroWIFI_access_in in interface eeroWIFI&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;timeout conn-holddown 0:00:15&lt;/P&gt;&lt;P&gt;timeout igp stale-route 0:01:10&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication login-history&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;service sw-reset-button&lt;/P&gt;&lt;P&gt;crypto ipsec security-association pmtu-aging infinite&lt;/P&gt;&lt;P&gt;crypto ca trustpoint _SmartCallHome_ServerCA&lt;/P&gt;&lt;P&gt;&amp;nbsp;no validation-usage&lt;/P&gt;&lt;P&gt;&amp;nbsp;crl configure&lt;/P&gt;&lt;P&gt;crypto ca trustpool policy&lt;/P&gt;&lt;P&gt;crypto ca certificate chain _SmartCallHome_ServerCA&lt;/P&gt;&lt;P&gt;&amp;nbsp;certificate ca 18dad19e267de8bb4a2158cdcc6b3b4a&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 183f685c f2424a85 3854835f d1e82cf2 ac11d6a8 ed636a&lt;/P&gt;&lt;P&gt;&amp;nbsp; quit&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;no ssh stricthostkeycheck&lt;/P&gt;&lt;P&gt;ssh 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;ssh version 2&lt;/P&gt;&lt;P&gt;ssh key-exchange group dh-group1-sha1&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;management-access inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;dhcp-client client-id interface eeroWifi2&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.5-192.168.1.254 inside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.7.10-192.168.7.254 eeroWIFI&lt;/P&gt;&lt;P&gt;dhcpd enable eeroWIFI&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics port&lt;/P&gt;&lt;P&gt;threat-detection statistics protocol&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp;parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;&amp;nbsp; no tcp-inspection&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;service call-home&lt;/P&gt;&lt;P&gt;call-home reporting anonymous&lt;/P&gt;&lt;P&gt;call-home&lt;/P&gt;&lt;P&gt;&amp;nbsp;contact-email-addr william.w.barnes2.ctr@mail.mil&lt;/P&gt;&lt;P&gt;&amp;nbsp;profile CiscoTAC-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination transport-method http&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;/P&gt;&lt;P&gt;Cryptochecksum:6288f85add5f4cd8595239f3d0fcb1be&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2020 07:34:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174021#M1066762</guid>
      <dc:creator>wwbarnes</dc:creator>
      <dc:date>2020-02-22T07:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174026#M1066763</link>
      <description>Have you tested by removing the ACL you have attached Inbound on the wifi interface? Test connectivity by removing it.&lt;BR /&gt;no access-group eeroWIFI_access_in in interface eeroWIFI&lt;BR /&gt;Should traffic be able to flow freely between the Interfaces?&lt;BR /&gt;Either way, you will know if it is the ACL causing problems and can then look at tweaking it.</description>
      <pubDate>Tue, 22 Aug 2017 14:30:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174026#M1066763</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2017-08-22T14:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174050#M1066764</link>
      <description>&lt;P&gt;I will try that tonight, thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2017 15:33:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174050#M1066764</guid>
      <dc:creator>wwbarnes</dc:creator>
      <dc:date>2017-08-22T15:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174072#M1066765</link>
      <description>&lt;P&gt;Also, yes, goal on this one is for traffice to flow freely between both interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2017 16:07:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174072#M1066765</guid>
      <dc:creator>wwbarnes</dc:creator>
      <dc:date>2017-08-22T16:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174291#M1066766</link>
      <description>&lt;P&gt;OK, that did nothing to help, but at least it was a try.&amp;nbsp; I still can ping nothing or reach anything from one subnet to the other.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2017 23:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174291#M1066766</guid>
      <dc:creator>wwbarnes</dc:creator>
      <dc:date>2017-08-22T23:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174300#M1066767</link>
      <description>&lt;P&gt;hold the phone, I can now ping other equipment on the eeroWIFI.&amp;nbsp; I think we have it, not sure why it took a min to work, but it's working.&amp;nbsp; I'll try agin in morning and make sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2017 23:36:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174300#M1066767</guid>
      <dc:creator>wwbarnes</dc:creator>
      <dc:date>2017-08-22T23:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174619#M1066768</link>
      <description>&lt;P&gt;We are good to go, thank you!&amp;nbsp; We can close this one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 13:29:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174619#M1066768</guid>
      <dc:creator>wwbarnes</dc:creator>
      <dc:date>2017-08-23T13:29:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174664#M1066769</link>
      <description>Hi,&lt;BR /&gt;Glad you have it working.&lt;BR /&gt;You can accept the answer as the solution via the discussion. This will mark it as answered.&lt;BR /&gt;Thanks</description>
      <pubDate>Wed, 23 Aug 2017 14:21:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-issue/m-p/3174664#M1066769</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2017-08-23T14:21:42Z</dc:date>
    </item>
  </channel>
</rss>

