<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ASA configuration issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-configuration-issue/m-p/3002669#M148349</link>
    <description>&lt;P&gt;Hi Freinds,&lt;/P&gt;
&lt;P&gt;i am implemented one scenario which can be reviewed in the diagram below &amp;nbsp;, in which i have two firewalls, &amp;nbsp;internal firewall and external firewall , i am doubt about the policy which i applied on my ASA's , which are not working properly , i expect support community experts can review and let me know where is my mistake , please friends i am little confuse so need clarification . with configuration as attached text file.&lt;/P&gt;
&lt;P&gt;model for firewall is ASA 5505. Notes&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Internal Firewall Network -&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;a) Inside network - 10.10.250.0/24&lt;/P&gt;
&lt;P&gt;b) inside1 network - 10.10.101.0/24&lt;/P&gt;
&lt;P&gt;c) voice &amp;nbsp;network - 10.10.120.0/24&lt;/P&gt;
&lt;P&gt;d) dmz network - 10.10.100.0/24&lt;/P&gt;
&lt;P&gt;e) outside network - 10.10.251.0/24&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;External Firewall Network -&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;a) Inside network - 10.10.251.0 /24&lt;/P&gt;
&lt;P&gt;b) dmz network - 10.10.150.0/24&lt;/P&gt;
&lt;P&gt;c) outside network - 10.10.249.0 /24&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Both Firewall Policies&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;1) Allow Access for User zones(inside) to Internet only for https , http &amp;amp; DNS .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;2) Allow Acces for User Zones (inside ) to internal server (On inernal&amp;nbsp;Firewall) &amp;amp; Vice versa for dns&amp;nbsp;, exchange services , rdp&amp;nbsp;, active directory &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; both TCP /UDP.&lt;/P&gt;
&lt;P&gt;3) Allow Lab User (inside1) to only internet (on internal firewall ) , deny all access to any other zone.&lt;/P&gt;
&lt;P&gt;4) Allow server to inside User zone (Internal Firewall) only for Active directory and dns&amp;nbsp;ports.&lt;/P&gt;
&lt;P&gt;5)&amp;nbsp;&lt;SPAN&gt; Allow Acces for User Zones (inside ) to External server (On External&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Firewall) &amp;amp; Vice versa for &lt;/SPAN&gt;dns&lt;SPAN&gt;&amp;nbsp;, exchange services , &lt;/SPAN&gt;rdp&lt;SPAN&gt;&amp;nbsp;, active directory &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; both TCP /UDP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;6) Whenever Inside User zone access server on internal firewall or external firewall should use same source ip , no natting.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/network_diagram__0.png" class="migrated-markup-image" /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 08:33:00 GMT</pubDate>
    <dc:creator>mohammed abdul naveed</dc:creator>
    <dc:date>2019-03-12T08:33:00Z</dc:date>
    <item>
      <title>Cisco ASA configuration issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-configuration-issue/m-p/3002669#M148349</link>
      <description>&lt;P&gt;Hi Freinds,&lt;/P&gt;
&lt;P&gt;i am implemented one scenario which can be reviewed in the diagram below &amp;nbsp;, in which i have two firewalls, &amp;nbsp;internal firewall and external firewall , i am doubt about the policy which i applied on my ASA's , which are not working properly , i expect support community experts can review and let me know where is my mistake , please friends i am little confuse so need clarification . with configuration as attached text file.&lt;/P&gt;
&lt;P&gt;model for firewall is ASA 5505. Notes&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Internal Firewall Network -&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;a) Inside network - 10.10.250.0/24&lt;/P&gt;
&lt;P&gt;b) inside1 network - 10.10.101.0/24&lt;/P&gt;
&lt;P&gt;c) voice &amp;nbsp;network - 10.10.120.0/24&lt;/P&gt;
&lt;P&gt;d) dmz network - 10.10.100.0/24&lt;/P&gt;
&lt;P&gt;e) outside network - 10.10.251.0/24&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;External Firewall Network -&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;a) Inside network - 10.10.251.0 /24&lt;/P&gt;
&lt;P&gt;b) dmz network - 10.10.150.0/24&lt;/P&gt;
&lt;P&gt;c) outside network - 10.10.249.0 /24&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Both Firewall Policies&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;1) Allow Access for User zones(inside) to Internet only for https , http &amp;amp; DNS .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;2) Allow Acces for User Zones (inside ) to internal server (On inernal&amp;nbsp;Firewall) &amp;amp; Vice versa for dns&amp;nbsp;, exchange services , rdp&amp;nbsp;, active directory &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; both TCP /UDP.&lt;/P&gt;
&lt;P&gt;3) Allow Lab User (inside1) to only internet (on internal firewall ) , deny all access to any other zone.&lt;/P&gt;
&lt;P&gt;4) Allow server to inside User zone (Internal Firewall) only for Active directory and dns&amp;nbsp;ports.&lt;/P&gt;
&lt;P&gt;5)&amp;nbsp;&lt;SPAN&gt; Allow Acces for User Zones (inside ) to External server (On External&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Firewall) &amp;amp; Vice versa for &lt;/SPAN&gt;dns&lt;SPAN&gt;&amp;nbsp;, exchange services , &lt;/SPAN&gt;rdp&lt;SPAN&gt;&amp;nbsp;, active directory &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; both TCP /UDP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;6) Whenever Inside User zone access server on internal firewall or external firewall should use same source ip , no natting.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/network_diagram__0.png" class="migrated-markup-image" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:33:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-configuration-issue/m-p/3002669#M148349</guid>
      <dc:creator>mohammed abdul naveed</dc:creator>
      <dc:date>2019-03-12T08:33:00Z</dc:date>
    </item>
    <item>
      <title>Which it isn't working?</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-configuration-issue/m-p/3002670#M148364</link>
      <description>&lt;P&gt;Which bit isn't working?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Nov 2016 23:40:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-configuration-issue/m-p/3002670#M148364</guid>
      <dc:creator>Simon Brooks</dc:creator>
      <dc:date>2016-11-21T23:40:58Z</dc:date>
    </item>
    <item>
      <title>Hi Simon ,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-configuration-issue/m-p/3002671#M148385</link>
      <description>&lt;P&gt;Hi Simon ,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;when I apply policy for inside LAN&amp;nbsp;to the internet only to permit for HTTP,HTTPS, DOMAIN ,but &amp;nbsp;its allowing , all traffic&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when I apply policy for inside LAN&amp;nbsp;to DMZ server and DMZ&amp;nbsp;server to inside LAN still same , I am trying to open specific ports but still, all the traffic is being allowed , maybe I am missing something in my configuration .&lt;/P&gt;</description>
      <pubDate>Tue, 22 Nov 2016 05:39:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-configuration-issue/m-p/3002671#M148385</guid>
      <dc:creator>mohammed abdul naveed</dc:creator>
      <dc:date>2016-11-22T05:39:40Z</dc:date>
    </item>
  </channel>
</rss>

