<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to Access Some IP's from Outside Network in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196414#M1076566</link>
    <description>&lt;P&gt;PFA network diagram,,,&lt;/P&gt;</description>
    <pubDate>Thu, 10 Dec 2020 04:53:33 GMT</pubDate>
    <dc:creator>Dayanand.Jadhav</dc:creator>
    <dc:date>2020-12-10T04:53:33Z</dc:date>
    <item>
      <title>Unable to Access Some IP's from Outside Network</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4195969#M1076545</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;I am facing one strange issue with the Network. I am unable to access some specific range of IP's from outside network of CISCO ASA-5506. Below are ten ip routes configured . I could access all the IP's except 10.1.1.0.. Access rule for all the Host' are same. There is no any difference in the access rule configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;route INSIDE_L3 10.1.1.0 255.255.255.0 10.24.0.254 1&lt;BR /&gt;route INSIDE_L3 10.3.1.0 255.255.255.0 10.24.0.254 1&lt;BR /&gt;route INSIDE_L3 10.5.1.0 255.255.255.0 10.24.0.254 1&lt;BR /&gt;route INSIDE_L3 10.7.1.0 255.255.255.0 10.24.0.254 1&lt;BR /&gt;route INSIDE_L3 10.9.1.0 255.255.255.0 10.24.0.254 1&lt;BR /&gt;route INSIDE_L3 10.23.1.0 255.255.255.0 10.24.0.254 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you all please analyze the issue and let me know the Workaround.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 15:12:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4195969#M1076545</guid>
      <dc:creator>Dayanand.Jadhav</dc:creator>
      <dc:date>2020-12-09T15:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Access Some IP's from Outside Network</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4195986#M1076546</link>
      <description>&lt;P&gt;Do you have NAT ? or post complete config&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 15:20:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4195986#M1076546</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-12-09T15:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Access Some IP's from Outside Network</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196035#M1076552</link>
      <description>&lt;P&gt;Dont have NAT...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;interface GigabitEthernet1/1&lt;BR /&gt;description Connectivity to DCS Inside Netwrok / CMNESW02Y Port 3 [10.24.0.251]&lt;BR /&gt;speed 100&lt;BR /&gt;duplex full&lt;BR /&gt;nameif INSIDE_L3&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.24.0.231 255.255.248.0 standby 10.24.0.232&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;speed 100&lt;BR /&gt;duplex full&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;description Connectivity to PGIM Network + HWOPC Server&lt;BR /&gt;speed 100&lt;BR /&gt;duplex full&lt;BR /&gt;nameif FWDMZ&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 192.168.220.231 255.255.255.0 standby 192.168.220.232&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/4&lt;BR /&gt;description Connectivity to Corporate Network&lt;BR /&gt;speed 100&lt;BR /&gt;duplex full&lt;BR /&gt;nameif FWOUT-BUSINESS-LAN&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 192.168.116.231 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/5&lt;BR /&gt;description ALMS Core server connectivity interface&lt;BR /&gt;shutdown&lt;BR /&gt;nameif FWDMZ_ALMS&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 172.20.1.231 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/6&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/7&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/8&lt;BR /&gt;description LAN/STATE Failover Interface&lt;BR /&gt;!&lt;BR /&gt;interface Management1/1&lt;BR /&gt;description Management port&lt;BR /&gt;management-only&lt;BR /&gt;nameif Managment&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.0.1 255.255.255.0 standby 192.168.0.10&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone GST 4&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;domain-name &lt;A href="http://www.cisco.com" target="_blank"&gt;www.cisco.com&lt;/A&gt;&lt;BR /&gt;object network obj_any&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network L3.5_OPCSRV01_P&lt;BR /&gt;host 192.168.220.30&lt;BR /&gt;description 255.255.255.0&lt;BR /&gt;object network L2_U01SRV01A&lt;BR /&gt;host 10.1.1.1&lt;BR /&gt;description UNIT1- Primary Experion Server&lt;BR /&gt;object network L2_U01SRV01B&lt;BR /&gt;host 10.1.1.2&lt;BR /&gt;description UNIT1- Secondary Experion Server&lt;BR /&gt;object network L2_U02SRV01A&lt;BR /&gt;host 10.1.1.101&lt;BR /&gt;description UNIT2- Primary Experion Server&lt;BR /&gt;object network L2_U02SRV01B&lt;BR /&gt;host 10.1.1.102&lt;BR /&gt;description UNIT2- Secondary Experion Server&lt;BR /&gt;object network L2_U03SRV01A&lt;BR /&gt;host 10.3.1.1&lt;BR /&gt;description UNIT3- Primary Experion Server&lt;BR /&gt;object network L2_U03SRV01B&lt;BR /&gt;host 10.3.1.2&lt;BR /&gt;description UNIT3- Secondary Experion Server&lt;BR /&gt;object network L2_U04SRV01A&lt;BR /&gt;host 10.3.1.101&lt;BR /&gt;description UNIT4- Primary Experion Server&lt;BR /&gt;object network L2_U04SRV01B&lt;BR /&gt;host 10.3.1.102&lt;BR /&gt;description UNIT4- Secondary Experion Server&lt;BR /&gt;object network L2_U05SRV01A&lt;BR /&gt;host 10.5.1.1&lt;BR /&gt;description UNIT5- Primary Experion Server&lt;BR /&gt;object network L2_U05SRV01B&lt;BR /&gt;host 10.5.1.2&lt;BR /&gt;description UNIT5- Secondary Experion Server&lt;BR /&gt;object network L2_U06SRV01A&lt;BR /&gt;host 10.5.1.101&lt;BR /&gt;description UNIT6- Primary Experion Server&lt;BR /&gt;object network L2_U06SRV01B&lt;BR /&gt;host 10.5.1.102&lt;BR /&gt;description UNIT6- Secondary Experion Server&lt;BR /&gt;object network L2_ELESRV01A&lt;BR /&gt;host 10.7.1.1&lt;BR /&gt;description ELECTRICAL- Primary Experion Server&lt;BR /&gt;object network L2_ELESRV01B&lt;BR /&gt;host 10.7.1.2&lt;BR /&gt;description ELECTRICAL -Secondary Experion Server&lt;BR /&gt;object network L2_BOPSRV01A&lt;BR /&gt;host 10.9.1.1&lt;BR /&gt;description BOP-P-Primary Experion Server&lt;BR /&gt;object network L2_BOPSRV01B&lt;BR /&gt;host 10.9.1.2&lt;BR /&gt;description BOP-P-Secondary Experion Server&lt;BR /&gt;object network L2_BOPSRV02A&lt;BR /&gt;host 10.9.1.101&lt;BR /&gt;description BOP-D-Primary Experion Server&lt;BR /&gt;object network L2_BOPSRV02B&lt;BR /&gt;host 10.9.1.102&lt;BR /&gt;description BOP-D-Secondary Experion Server&lt;BR /&gt;object service TCP_9876&lt;BR /&gt;service tcp destination eq 9876&lt;BR /&gt;description Acronics backup Components&lt;BR /&gt;object service TCP_22&lt;BR /&gt;service tcp destination eq ssh&lt;BR /&gt;description SFTP&lt;BR /&gt;object service TCP_123&lt;BR /&gt;service tcp destination eq 123&lt;BR /&gt;description Time_sync&lt;BR /&gt;object service UDP_123&lt;BR /&gt;service udp destination eq ntp&lt;BR /&gt;description Time sync_UDP&lt;BR /&gt;object service TCP_80&lt;BR /&gt;service tcp destination eq www&lt;BR /&gt;description HTTP&lt;BR /&gt;object service TCP_8081&lt;BR /&gt;service tcp destination eq 8081&lt;BR /&gt;object service TCP_8443&lt;BR /&gt;service tcp destination eq 8443&lt;BR /&gt;object service TCP_8444&lt;BR /&gt;service tcp destination eq 8444&lt;BR /&gt;object service TCP_443&lt;BR /&gt;service tcp destination eq https&lt;BR /&gt;object service TCP_445&lt;BR /&gt;service tcp destination eq 445&lt;BR /&gt;object service UDP_8082&lt;BR /&gt;service udp destination eq 8082&lt;BR /&gt;object network L3_AVSRV01&lt;BR /&gt;host 10.23.1.2&lt;BR /&gt;description ePO Server at Level 3&lt;BR /&gt;object network L3_EBRSRV01&lt;BR /&gt;host 10.23.1.3&lt;BR /&gt;description EBR manager&lt;BR /&gt;object network L3.5_OPCSRV01_S&lt;BR /&gt;host 192.168.220.31&lt;BR /&gt;description OPC Server backup interface port&lt;BR /&gt;object network L3_DMNSRV01A&lt;BR /&gt;host 10.23.1.4&lt;BR /&gt;description Additional Domain controller&lt;BR /&gt;object network L3_DMNSRV01B&lt;BR /&gt;host 10.23.1.5&lt;BR /&gt;description Root Domain controller&lt;BR /&gt;object service UDP_2911&lt;BR /&gt;service udp destination eq 2911&lt;BR /&gt;object service TCP_50001-50004&lt;BR /&gt;service tcp destination range 50001 50004&lt;BR /&gt;object network L3_DYNDESRV&lt;BR /&gt;host 10.23.1.6&lt;BR /&gt;description ALMS Server&lt;BR /&gt;object network L3_DYNMRSRV&lt;BR /&gt;host 10.23.1.7&lt;BR /&gt;description ALMS Server&lt;BR /&gt;object network L3.5_DYNCORSRV&lt;BR /&gt;host 192.168.116.232&lt;BR /&gt;description Core ALMS Server&lt;BR /&gt;object service TCP_449&lt;BR /&gt;service tcp destination eq 449&lt;BR /&gt;description Https&lt;BR /&gt;object network ABB_OGC200_ABB_192.168.220.32&lt;BR /&gt;host 192.168.220.32&lt;BR /&gt;description ABB_OGC200_Matricon scanner to fetch logs from OPC Server&lt;BR /&gt;object network L4_ALMS_Client1&lt;BR /&gt;host 192.168.116.208&lt;BR /&gt;description ALMS Client from Corporate NW access Dynamo Core server&lt;BR /&gt;object network L4_ALMS_Client2&lt;BR /&gt;host 192.168.112.209&lt;BR /&gt;description ALMS Client from Corporate NW access Dynamo Core server&lt;BR /&gt;object network L4_ALMS_Client3&lt;BR /&gt;host 192.168.112.210&lt;BR /&gt;description ALMS Client from Corporate NW access Dynamo Core server&lt;BR /&gt;object-group network DM_INLINE_NETWORK_2&lt;BR /&gt;network-object object L3.5_OPCSRV01_P&lt;BR /&gt;network-object object L3.5_OPCSRV01_S&lt;BR /&gt;object-group service EBR&lt;BR /&gt;service-object object TCP_22&lt;BR /&gt;service-object object TCP_9876&lt;BR /&gt;object-group service AV_Deloyement&lt;BR /&gt;service-object object TCP_443&lt;BR /&gt;service-object object TCP_445&lt;BR /&gt;service-object object TCP_80&lt;BR /&gt;service-object object TCP_8081&lt;BR /&gt;service-object object TCP_8443&lt;BR /&gt;service-object object TCP_8444&lt;BR /&gt;service-object object UDP_8082&lt;BR /&gt;object-group network DM_INLINE_NETWORK_1&lt;BR /&gt;network-object object L3.5_OPCSRV01_P&lt;BR /&gt;network-object object L3.5_OPCSRV01_S&lt;BR /&gt;object-group service OPC_and_EPKS_Comm&lt;BR /&gt;service-object object TCP_50001-50004&lt;BR /&gt;service-object object UDP_2911&lt;BR /&gt;object-group network EPKS_SERVERs_Grp&lt;BR /&gt;network-object object L2_BOPSRV01A&lt;BR /&gt;network-object object L2_BOPSRV01B&lt;BR /&gt;network-object object L2_BOPSRV02A&lt;BR /&gt;network-object object L2_BOPSRV02B&lt;BR /&gt;network-object object L2_ELESRV01A&lt;BR /&gt;network-object object L2_ELESRV01B&lt;BR /&gt;network-object object L2_U01SRV01A&lt;BR /&gt;network-object object L2_U01SRV01B&lt;BR /&gt;network-object object L2_U02SRV01A&lt;BR /&gt;network-object object L2_U02SRV01B&lt;BR /&gt;network-object object L2_U03SRV01A&lt;BR /&gt;network-object object L2_U03SRV01B&lt;BR /&gt;network-object object L2_U04SRV01A&lt;BR /&gt;network-object object L2_U04SRV01B&lt;BR /&gt;network-object object L2_U05SRV01A&lt;BR /&gt;network-object object L2_U05SRV01B&lt;BR /&gt;network-object object L2_U06SRV01A&lt;BR /&gt;network-object object L2_U06SRV01B&lt;BR /&gt;object-group network DM_INLINE_NETWORK_3&lt;BR /&gt;network-object object L3.5_OPCSRV01_P&lt;BR /&gt;network-object object L3.5_OPCSRV01_S&lt;BR /&gt;object-group network DM_INLINE_NETWORK_4&lt;BR /&gt;network-object object L3.5_OPCSRV01_P&lt;BR /&gt;network-object object L3.5_OPCSRV01_S&lt;BR /&gt;object-group network DM_INLINE_NETWORK_5&lt;BR /&gt;network-object object L3.5_OPCSRV01_P&lt;BR /&gt;network-object object L3.5_OPCSRV01_S&lt;BR /&gt;object-group network DM_INLINE_NETWORK_6&lt;BR /&gt;network-object object L3.5_OPCSRV01_P&lt;BR /&gt;network-object object L3.5_OPCSRV01_S&lt;BR /&gt;object-group network DM_INLINE_NETWORK_7&lt;BR /&gt;network-object object L3_DMNSRV01A&lt;BR /&gt;network-object object L3_DMNSRV01B&lt;BR /&gt;object-group network DM_INLINE_NETWORK_8&lt;BR /&gt;network-object object L3.5_OPCSRV01_P&lt;BR /&gt;network-object object L3.5_OPCSRV01_S&lt;BR /&gt;object-group network DM_INLINE_NETWORK_10&lt;BR /&gt;network-object object L3_DMNSRV01A&lt;BR /&gt;network-object object L3_DMNSRV01B&lt;BR /&gt;object-group network DM_INLINE_NETWORK_9&lt;BR /&gt;network-object object L3.5_OPCSRV01_P&lt;BR /&gt;network-object object L3.5_OPCSRV01_S&lt;BR /&gt;object-group service DM_INLINE_SERVICE_1&lt;BR /&gt;service-object icmp&lt;BR /&gt;group-object EBR&lt;BR /&gt;object-group service DM_INLINE_SERVICE_2&lt;BR /&gt;service-object icmp&lt;BR /&gt;group-object AV_Deloyement&lt;BR /&gt;object-group service DM_INLINE_SERVICE_3&lt;BR /&gt;service-object icmp&lt;BR /&gt;group-object OPC_and_EPKS_Comm&lt;BR /&gt;object-group service DM_INLINE_SERVICE_4&lt;BR /&gt;service-object icmp&lt;BR /&gt;service-object object TCP_123&lt;BR /&gt;object-group service DM_INLINE_SERVICE_5&lt;BR /&gt;service-object icmp&lt;BR /&gt;group-object OPC_and_EPKS_Comm&lt;BR /&gt;object-group service DM_INLINE_SERVICE_6&lt;BR /&gt;service-object icmp&lt;BR /&gt;group-object AV_Deloyement&lt;BR /&gt;object-group service DM_INLINE_SERVICE_7&lt;BR /&gt;service-object icmp&lt;BR /&gt;group-object EBR&lt;BR /&gt;object-group service DM_INLINE_SERVICE_8&lt;BR /&gt;service-object icmp&lt;BR /&gt;service-object object TCP_123&lt;BR /&gt;object-group network L4_ALMS_Client_Grp&lt;BR /&gt;network-object object L4_ALMS_Client2&lt;BR /&gt;network-object object L4_ALMS_Client3&lt;BR /&gt;network-object object L4_ALMS_Client1&lt;BR /&gt;object-group network DM_INLINE_NETWORK_11&lt;BR /&gt;network-object object L3_DYNDESRV&lt;BR /&gt;network-object object L3_DYNMRSRV&lt;BR /&gt;object-group network DM_INLINE_NETWORK_12&lt;BR /&gt;network-object object L3_DYNDESRV&lt;BR /&gt;network-object object L3_DYNMRSRV&lt;BR /&gt;object-group service DM_INLINE_SERVICE_10&lt;BR /&gt;service-object icmp&lt;BR /&gt;service-object object TCP_80&lt;BR /&gt;object-group service DM_INLINE_SERVICE_9&lt;BR /&gt;service-object icmp&lt;BR /&gt;service-object icmp echo&lt;BR /&gt;service-object icmp echo-reply&lt;BR /&gt;service-object object TCP_80&lt;BR /&gt;object-group service DM_INLINE_SERVICE_11&lt;BR /&gt;service-object icmp&lt;BR /&gt;service-object object TCP_80&lt;BR /&gt;object-group service DM_INLINE_SERVICE_12&lt;BR /&gt;service-object icmp&lt;BR /&gt;service-object object TCP_80&lt;BR /&gt;object-group network DM_INLINE_NETWORK_13&lt;BR /&gt;network-object object L3_DYNDESRV&lt;BR /&gt;network-object object L3_DYNMRSRV&lt;BR /&gt;object-group service DM_INLINE_SERVICE_13&lt;BR /&gt;service-object icmp&lt;BR /&gt;service-object object TCP_449&lt;BR /&gt;access-list FWDMZ_access_in remark EBR functionality.&lt;BR /&gt;access-list FWDMZ_access_in extended permit object-group DM_INLINE_SERVICE_1 object-group DM_INLINE_NETWORK_1 object L3_EBRSRV01&lt;BR /&gt;access-list FWDMZ_access_in remark AV patch deployement.&lt;BR /&gt;access-list FWDMZ_access_in extended permit object-group DM_INLINE_SERVICE_2 object-group DM_INLINE_NETWORK_2 object L3_AVSRV01&lt;BR /&gt;access-list FWDMZ_access_in remark OPC Server and All the unit Experion Servers comm.&lt;BR /&gt;access-list FWDMZ_access_in extended permit object-group DM_INLINE_SERVICE_3 object-group DM_INLINE_NETWORK_3 object-group EPKS_SERVERs_Grp&lt;BR /&gt;access-list FWDMZ_access_in extended permit object-group DM_INLINE_SERVICE_4 object-group DM_INLINE_NETWORK_9 object-group DM_INLINE_NETWORK_10&lt;BR /&gt;access-list FWIN1_access_in remark OPC Server and All the units Expenion Server comm&lt;BR /&gt;access-list FWIN1_access_in extended permit object-group DM_INLINE_SERVICE_5 object-group EPKS_SERVERs_Grp object-group DM_INLINE_NETWORK_4&lt;BR /&gt;access-list FWIN1_access_in remark AV Patch deployment.&lt;BR /&gt;access-list FWIN1_access_in extended permit object-group DM_INLINE_SERVICE_6 object L3_AVSRV01 object-group DM_INLINE_NETWORK_5&lt;BR /&gt;access-list FWIN1_access_in remark EBR Functionality.&lt;BR /&gt;access-list FWIN1_access_in extended permit object-group DM_INLINE_SERVICE_7 object L3_EBRSRV01 object-group DM_INLINE_NETWORK_6&lt;BR /&gt;access-list FWIN1_access_in remark Time sync.&lt;BR /&gt;access-list FWIN1_access_in extended permit object-group DM_INLINE_SERVICE_8 object-group DM_INLINE_NETWORK_7 object-group DM_INLINE_NETWORK_8&lt;BR /&gt;access-list FWIN1_access_in extended permit object-group DM_INLINE_SERVICE_10 object-group DM_INLINE_NETWORK_12 object L3.5_DYNCORSRV&lt;BR /&gt;access-list FWDMZ_ALMS_access_in extended permit object-group DM_INLINE_SERVICE_9 object L3.5_DYNCORSRV object-group DM_INLINE_NETWORK_11 inactive&lt;BR /&gt;access-list FWDMZ_ALMS_access_in extended permit object-group DM_INLINE_SERVICE_11 object L3.5_DYNCORSRV object-group L4_ALMS_Client_Grp inactive&lt;BR /&gt;access-list FWDMZ_ALMS_access_in extended permit ip any any inactive&lt;BR /&gt;access-list FWOUT1_access_in extended permit object-group DM_INLINE_SERVICE_12 object-group L4_ALMS_Client_Grp object L3.5_DYNCORSRV inactive&lt;BR /&gt;access-list FWOUT1_access_in extended permit ip any any inactive&lt;BR /&gt;access-list FWOUT1_access_in extended permit object-group DM_INLINE_SERVICE_13 object L3.5_DYNCORSRV object-group DM_INLINE_NETWORK_13&lt;BR /&gt;access-list FWOUT1_access_in extended permit icmp object L3.5_DYNCORSRV object L4_ALMS_Client1 inactive&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu INSIDE_L3 1500&lt;BR /&gt;mtu FWDMZ 1500&lt;BR /&gt;mtu FWOUT-BUSINESS-LAN 1500&lt;BR /&gt;mtu FWDMZ_ALMS 1500&lt;BR /&gt;mtu Managment 1500&lt;BR /&gt;failover&lt;BR /&gt;failover lan unit primary&lt;BR /&gt;failover lan interface folink GigabitEthernet1/8&lt;BR /&gt;failover replication http&lt;BR /&gt;failover link folink GigabitEthernet1/8&lt;BR /&gt;failover interface ip folink 172.18.1.251 255.255.255.0 standby 172.18.1.252&lt;BR /&gt;no monitor-interface FWOUT-BUSINESS-LAN&lt;BR /&gt;no monitor-interface FWDMZ_ALMS&lt;BR /&gt;no monitor-interface Managment&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;access-group FWIN1_access_in in interface INSIDE_L3&lt;BR /&gt;access-group FWDMZ_access_in in interface FWDMZ&lt;BR /&gt;access-group FWOUT1_access_in in interface FWOUT-BUSINESS-LAN&lt;BR /&gt;access-group FWDMZ_ALMS_access_in in interface FWDMZ_ALMS&lt;BR /&gt;route INSIDE_L3 10.1.1.0 255.255.255.0 10.24.0.254 1&lt;BR /&gt;route INSIDE_L3 10.3.1.0 255.255.255.0 10.24.0.254 1&lt;BR /&gt;route INSIDE_L3 10.5.1.0 255.255.255.0 10.24.0.254 1&lt;BR /&gt;route INSIDE_L3 10.7.1.0 255.255.255.0 10.24.0.254 1&lt;BR /&gt;route INSIDE_L3 10.9.1.0 255.255.255.0 10.24.0.254 1&lt;BR /&gt;route INSIDE_L3 10.23.1.0 255.255.255.0 10.24.0.254 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.0.0 255.255.255.0 Managment&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;auth-prompt prompt Please enter your username and password&lt;BR /&gt;service sw-reset-button&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;telnet timeout 300&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config INSIDE_L3&lt;BR /&gt;!&lt;BR /&gt;ntp server 10.23.1.11 source INSIDE_L3 prefer&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;username admin password i9yVQvvf7pGDUqaP encrypted&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect dns preset_dns_map&lt;BR /&gt;inspect ftp&lt;BR /&gt;inspect h323 h225&lt;BR /&gt;inspect h323 ras&lt;BR /&gt;inspect rsh&lt;BR /&gt;inspect rtsp&lt;BR /&gt;inspect esmtp&lt;BR /&gt;inspect sqlnet&lt;BR /&gt;inspect skinny&lt;BR /&gt;inspect sunrpc&lt;BR /&gt;inspect xdmcp&lt;BR /&gt;inspect sip&lt;BR /&gt;inspect netbios&lt;BR /&gt;inspect tftp&lt;BR /&gt;inspect ip-options&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 16:26:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196035#M1076552</guid>
      <dc:creator>Dayanand.Jadhav</dc:creator>
      <dc:date>2020-12-09T16:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Access Some IP's from Outside Network</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196190#M1076559</link>
      <description>&lt;P&gt;as per the config you have only 1 entry that is static route point to below IP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;route INSIDE_L3 10.1.1.0 255.255.255.0 10.24.0.254 1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we need more information what is that 10.24.0.254 ? do you have route back from 10.24.0.254 to FW ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we need more topology where this traffic coming&amp;nbsp; ?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 19:17:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196190#M1076559</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-12-09T19:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Access Some IP's from Outside Network</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196232#M1076560</link>
      <description>&lt;P&gt;Routing issue most probably. Well, static routes don't propagate through the network just by themselves.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 20:30:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196232#M1076560</guid>
      <dc:creator>Rafal Sobecki</dc:creator>
      <dc:date>2020-12-09T20:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Access Some IP's from Outside Network</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196387#M1076564</link>
      <description>&lt;P&gt;10.24.0.254 is standby ip for Vlan in Inside Network at Router side&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/3&lt;BR /&gt;description **** CONNECTION TO Firewall Inside /CMNFWL1A 10.24.0.1 Port No : 1 ****&lt;BR /&gt;switchport access vlan 201&lt;BR /&gt;switchport mode access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Vlan201&lt;BR /&gt;ip address 10.24.0.251 255.255.248.0&lt;BR /&gt;no ip redirects&lt;BR /&gt;no ip unreachables&lt;BR /&gt;no ip proxy-arp&lt;BR /&gt;standby 200 ip 10.24.0.254&lt;BR /&gt;standby 200 timers 1 3&lt;BR /&gt;standby 200 priority 106&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ip route 10.1.0.0 255.255.248.0 10.11.0.251&lt;BR /&gt;ip route 10.3.0.0 255.255.248.0 10.11.0.251&lt;BR /&gt;ip route 10.5.0.0 255.255.248.0 10.11.0.251&lt;BR /&gt;ip route 10.7.0.0 255.255.248.0 10.11.0.251&lt;BR /&gt;ip route 10.9.0.0 255.255.248.0 10.11.0.251&lt;BR /&gt;ip route 10.9.1.0 255.255.255.0 10.11.0.251&lt;BR /&gt;ip route 10.24.0.0 255.255.255.0 10.24.0.231&lt;BR /&gt;ip route 172.20.1.0 255.255.255.0 10.24.0.231&lt;BR /&gt;ip route 192.168.116.0 255.255.255.0 10.24.0.231&lt;BR /&gt;ip route 192.168.220.0 255.255.255.0 10.24.0.231&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 03:36:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196387#M1076564</guid>
      <dc:creator>Dayanand.Jadhav</dc:creator>
      <dc:date>2020-12-10T03:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Access Some IP's from Outside Network</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196408#M1076565</link>
      <description>&lt;P&gt;&amp;nbsp;I get that that is the virtual IP of the device. but from that device? you routing to again&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ip route 10.1.0.0 255.255.248.0 10.11.0.251 ? So looks like you have many static routes here.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;take small paper and pen, write your network, give us information about how your network looks like&amp;nbsp; ? It hard to say for now what is the issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;High level it is routing issue.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 04:38:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196408#M1076565</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-12-10T04:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Access Some IP's from Outside Network</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196414#M1076566</link>
      <description>&lt;P&gt;PFA network diagram,,,&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 04:53:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196414#M1076566</guid>
      <dc:creator>Dayanand.Jadhav</dc:creator>
      <dc:date>2020-12-10T04:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Access Some IP's from Outside Network</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196774#M1076581</link>
      <description>&lt;P&gt;Despite the diagram, we don't even know how many hops there are end-to-end.&lt;/P&gt;&lt;P&gt;Is the path from src to&amp;nbsp;&lt;SPAN&gt;10.1.1.0 expected the same as&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;10.3.1.0?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Issue traceroute from same src to both dst again to compare assumptions with facts.&lt;/P&gt;&lt;P&gt;If traceroute incomplete (ref. firewall), find another way to determine the paths to compare them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 17:24:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196774#M1076581</guid>
      <dc:creator>Rafal Sobecki</dc:creator>
      <dc:date>2020-12-10T17:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Access Some IP's from Outside Network</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196838#M1076582</link>
      <description>&lt;P&gt;PFA Detailed Network diagram. and error logs in FW for Ping request from 10.1.X.X TO 192.168.220.30&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;Path from&amp;nbsp;&lt;SPAN&gt;src to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;10.1.1.0 expected the same as&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;10.3.1.0.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 18:11:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196838#M1076582</guid>
      <dc:creator>Dayanand.Jadhav</dc:creator>
      <dc:date>2020-12-10T18:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Access Some IP's from Outside Network</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196846#M1076583</link>
      <description>&lt;P&gt;I would ask you to check from to bottom and bottom to top you have all the route corect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or post all the device config, if confidential remove the config confidential post or PM me the config to look and advise what is wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 18:20:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4196846#M1076583</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-12-10T18:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Access Some IP's from Outside Network</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4197019#M1076587</link>
      <description>&lt;P&gt;PFA tracert output from 10.1.1.1&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 03:57:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4197019#M1076587</guid>
      <dc:creator>Dayanand.Jadhav</dc:creator>
      <dc:date>2020-12-11T03:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Access Some IP's from Outside Network</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4197043#M1076589</link>
      <description>&lt;P&gt;as per your tracert 10.11.0.241 - check routing from there to down. also do same from top to down also.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 385px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/90319i02C043A5EC3E230F/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 07:34:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-some-ip-s-from-outside-network/m-p/4197043#M1076589</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-12-11T07:34:02Z</dc:date>
    </item>
  </channel>
</rss>

