<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sorry. After everything I did in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050764#M147357</link>
    <description>&lt;P&gt;&lt;SPAN style="margin: 0px; color: #1f497d; font-family: 'Calibri',sans-serif; font-size: 11pt;"&gt;Sorry. After everything I did figure out that they are showing up outside the network after testing on my cell phone. The problem is that inside my network I cannot access them. &lt;/SPAN&gt;&lt;SPAN style="margin: 0px; color: #1f497d; font-family: 'Calibri',sans-serif; font-size: 11pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;"&gt;&lt;SPAN style="margin: 0px; color: #1f497d; font-family: 'Calibri',sans-serif; font-size: 11pt;"&gt;I have checked the DNS and everything seems fine. I cannot still access it from inside the network. I also cannot ping the outside interface from inside the network. Any ideas? &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;"&gt;&lt;SPAN style="margin: 0px; color: #1f497d; font-family: 'Calibri',sans-serif; font-size: 11pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="margin: 0px; color: #1f497d; font-family: 'Calibri',sans-serif; font-size: 11pt;"&gt;A&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; color: #1f497d; font-family: 'Calibri',sans-serif; font-size: 11pt;"&gt;lso I have turn on our old gateway which the ASA replaced, I setup a PC to use that as the gateway as a test. I am about to get to the sites with no problem. It seems it only happens via the ASA that we cannot access it on the network.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jan 2017 23:17:31 GMT</pubDate>
    <dc:creator>Kayson Daley</dc:creator>
    <dc:date>2017-01-26T23:17:31Z</dc:date>
    <item>
      <title>unable to public server</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050753#M147340</link>
      <description>&lt;P&gt;This is driving me a little crazy so any help would be nice. I am having trouble with public server. I was about to&amp;nbsp;one for smtp and it seem to work, but when I tried doing one for the web server using https and http I am having issues. I am unable to get to the servers after setting them up. I have tried a few different Access Rules and NAT Rules but I just seem able to get this to work. I have a ASA 5506. Attached is&amp;nbsp;my current running config. I am not running a DMZ. I would be glad for any help!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:49:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050753#M147340</guid>
      <dc:creator>Kayson Daley</dc:creator>
      <dc:date>2019-03-12T08:49:49Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050754#M147341</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'm sorry but I don't understand what issue your facing?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I checked your config and you have 2 NAT that seems to be ok.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 01:43:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050754#M147341</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-01-25T01:43:52Z</dc:date>
    </item>
    <item>
      <title>Can you confirm if the issue</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050755#M147342</link>
      <description>&lt;P&gt;Can you confirm if the issue is with&amp;nbsp;20.1.1.37. I see that you have NAT and access rule allowing smtp and https traffic. Please attach packet-tracer output for&amp;nbsp;20.1.1.37 and port 443 and lets see what ASA is doing with this traffic.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I would also advise to remove the below NAT statement since there is one already in twice nat section. Use of 'any' keyword in NAT statement can sometimes get us unexpected results:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;object network obj_any
 nat (any,outside) dynamic interface&lt;/PRE&gt;
&lt;P&gt;In future, it would be best if you can attach some more useful info like related ip address, packet-tracer output etc. It saves time for everyone.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 01:48:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050755#M147342</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2017-01-25T01:48:02Z</dc:date>
    </item>
    <item>
      <title>Yeah I removed that one. Well</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050756#M147343</link>
      <description>&lt;P&gt;Yeah I removed that one. Well 20.1.1.37 is the ip for the web server. There are two that I am trying to make public the other is 20.1.1.6. the outside ip's are 85.150.14.26 &amp;amp; 29.&lt;/P&gt;
&lt;P&gt;Sorry about not given enough info.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 05:19:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050756#M147343</guid>
      <dc:creator>Kayson Daley</dc:creator>
      <dc:date>2017-01-25T05:19:03Z</dc:date>
    </item>
    <item>
      <title>Well I setup these public</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050757#M147344</link>
      <description>&lt;P&gt;Well I setup these public servers to allow our web servers to make a site accessible off network via ssl https. But I cannot seem to get it to work.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 05:23:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050757#M147344</guid>
      <dc:creator>Kayson Daley</dc:creator>
      <dc:date>2017-01-25T05:23:16Z</dc:date>
    </item>
    <item>
      <title>ok, so 20.1.1.6 maps to 85</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050758#M147345</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;ok, so&amp;nbsp;20.1.1.6 maps to&amp;nbsp;85.150.14.26 and 20.1.1.37 maps to&amp;nbsp;85.150.14.26.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;And you need to access these servers from internet over https.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Now, please clarify which one is not working. The config seems to be legit, although it can fine tuned but&amp;nbsp;we can keep it for a later stage once testing is done.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Can you check if the ip addresses you are using is routable if you are using them for the first time. One thing we can do for testing is to create a test nat using outside interface and see if that works:&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN style="font-size: 10pt;"&gt;object network owa-server
 nat (inside,outside) static interface service tcp 443 443 &lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Please test it. If it works, then we will have to check if the public ip address you are using are routable. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;As a tshoot step, we can also set up captures on outside interface to see if traffic is arriving for a specific ip address:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;cap capo interface outside match ip any host&amp;nbsp;85.150.14.26&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;and then initiate traffic on this ip on port 443.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;then take output of &lt;STRONG&gt;show cap capo&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;-&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;AJ&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 11:22:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050758#M147345</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2017-01-25T11:22:56Z</dc:date>
    </item>
    <item>
      <title>Can you check if the ip</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050759#M147347</link>
      <description>&lt;P style="line-height: normal;"&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Times New Roman',serif;"&gt;Can you check if the ip addresses you are using is routable if you are using them for the first time. One thing we can do for testing is to create a test nat using outside interface and see if that works:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Courier New';"&gt;object network owa-server&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: .0001pt; line-height: normal; tab-stops: 45.8pt 91.6pt 137.4pt 183.2pt 229.0pt 274.8pt 320.6pt 366.4pt 412.2pt 458.0pt 503.8pt 549.6pt 595.4pt 641.2pt 687.0pt 732.8pt;"&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Courier New';"&gt;&amp;nbsp;nat (inside,outside) static interface service tcp 443 443 &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="line-height: normal;"&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Times New Roman',serif;"&gt;Please test it. If it works, then we will have to check if the public ip address you are using are routable. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="line-height: normal;"&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Times New Roman',serif;"&gt;As a tshoot step, we can also set up captures on outside interface to see if traffic is arriving for a specific ip address:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="line-height: normal;"&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Times New Roman',serif;"&gt;cap capo interface outside match ip any host&amp;nbsp;85.150.14.26&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="line-height: normal;"&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Times New Roman',serif;"&gt;and then initiate traffic on this ip on port 443.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="line-height: normal; border: none; padding: 0cm;"&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Times New Roman',serif;"&gt;then take output of &lt;STRONG&gt;show cap capo&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 12:43:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050759#M147347</guid>
      <dc:creator>Farhan Mohamed</dc:creator>
      <dc:date>2017-01-25T12:43:33Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050760#M147349</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Did you do the capture?&lt;/P&gt;
&lt;P&gt;For the firewall rules, everything is fine but as it has been told, you can make some cleanup and/or tweak rules /NAT already existing&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 13:32:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050760#M147349</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-01-25T13:32:58Z</dc:date>
    </item>
    <item>
      <title>Thanks for the help that kind</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050761#M147351</link>
      <description>&lt;P&gt;Thanks for the help that kind of lead me to some more testing and I found out that I can access it but just not from inside my network. I have to now figure out what is blocking it from inside.&amp;nbsp; Maybe I need to setup a NAT Loopback?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 16:45:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050761#M147351</guid>
      <dc:creator>Kayson Daley</dc:creator>
      <dc:date>2017-01-25T16:45:22Z</dc:date>
    </item>
    <item>
      <title>On your ASA, please do the</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050762#M147353</link>
      <description>&lt;P&gt;On your ASA, please do the following packet-tracer and paste the output:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;packet-tracer input outside tcp 8.8.8.8 5565 85.150.14.29 443&lt;/PRE&gt;
&lt;P&gt;If it's allowed then the issue isn't coming from ASA but something else internally.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 16:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050762#M147353</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-01-25T16:58:05Z</dc:date>
    </item>
    <item>
      <title>Yeah agreed  All are allowed</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050763#M147354</link>
      <description>&lt;P&gt;Yeah agreed&amp;nbsp; All are allowed&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 17:43:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050763#M147354</guid>
      <dc:creator>Kayson Daley</dc:creator>
      <dc:date>2017-01-25T17:43:44Z</dc:date>
    </item>
    <item>
      <title>Sorry. After everything I did</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050764#M147357</link>
      <description>&lt;P&gt;&lt;SPAN style="margin: 0px; color: #1f497d; font-family: 'Calibri',sans-serif; font-size: 11pt;"&gt;Sorry. After everything I did figure out that they are showing up outside the network after testing on my cell phone. The problem is that inside my network I cannot access them. &lt;/SPAN&gt;&lt;SPAN style="margin: 0px; color: #1f497d; font-family: 'Calibri',sans-serif; font-size: 11pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;"&gt;&lt;SPAN style="margin: 0px; color: #1f497d; font-family: 'Calibri',sans-serif; font-size: 11pt;"&gt;I have checked the DNS and everything seems fine. I cannot still access it from inside the network. I also cannot ping the outside interface from inside the network. Any ideas? &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin: 0px;"&gt;&lt;SPAN style="margin: 0px; color: #1f497d; font-family: 'Calibri',sans-serif; font-size: 11pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="margin: 0px; color: #1f497d; font-family: 'Calibri',sans-serif; font-size: 11pt;"&gt;A&lt;/SPAN&gt;&lt;SPAN style="margin: 0px; color: #1f497d; font-family: 'Calibri',sans-serif; font-size: 11pt;"&gt;lso I have turn on our old gateway which the ASA replaced, I setup a PC to use that as the gateway as a test. I am about to get to the sites with no problem. It seems it only happens via the ASA that we cannot access it on the network.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 23:17:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050764#M147357</guid>
      <dc:creator>Kayson Daley</dc:creator>
      <dc:date>2017-01-26T23:17:31Z</dc:date>
    </item>
    <item>
      <title>Doing the capture lead me to</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050765#M147359</link>
      <description>&lt;P&gt;Doing the capture lead me to test on my cell phone. I am still trying to fine what is stopping it from being accessible from the inside.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 23:19:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050765#M147359</guid>
      <dc:creator>Kayson Daley</dc:creator>
      <dc:date>2017-01-26T23:19:13Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050766#M147360</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Can you tell what tests are you doing? What it isn't accessible?&lt;/P&gt;
&lt;P&gt;And please provide packet-tracer logs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 23:55:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050766#M147360</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-01-26T23:55:19Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050767#M147363</link>
      <description>&lt;P style="margin-bottom: 0px;"&gt;&lt;SPAN style="font-family: Tahoma, sans-serif;"&gt;Hi&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0px;"&gt;&lt;SPAN style="font-family: Tahoma, sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0px;"&gt;&lt;FONT face="Tahoma, sans-serif"&gt;We get a private IM for your concern and the answer was:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0px;"&gt;&lt;FONT face="Tahoma, sans-serif"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0px;"&gt;&lt;SPAN style="font-family: Tahoma, sans-serif;"&gt;You won't be able to ping your Outside IP from internal zone and even your NAT Public IP. If you look at your logs (try pinging &amp;nbsp;your nat public IP), you should see a message like&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt; font-family: Arial, sans-serif; color: #333333; background-color: #f9f9f9; background-position: initial initial; background-repeat: initial initial;"&gt;Deny IP due to Land Attack from&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0px;"&gt;&lt;SPAN style="font-family: Tahoma, sans-serif;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0px;"&gt;&lt;SPAN style="font-family: Tahoma, sans-serif;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0px;"&gt;&lt;SPAN style="font-family: Tahoma, sans-serif;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0px;"&gt;&lt;SPAN style="font-family: Tahoma, sans-serif;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="margin-bottom: 0px;"&gt;&lt;SPAN style="font-family: Tahoma, sans-serif;"&gt;PS: Please don't forget to rate and mark as correct answer if this answered your question&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 18:14:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-public-server/m-p/3050767#M147363</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-01-27T18:14:56Z</dc:date>
    </item>
  </channel>
</rss>

