<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Check below things. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982802#M148991</link>
    <description>&lt;P&gt;Check below things.&lt;/P&gt;
&lt;P&gt;1) Do you have default route or return route towards ASA on both router?&lt;/P&gt;
&lt;P&gt;2) Do you have command "same-security-traffic permit inter-interface" in ASA config if not you have to add that.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Kindly rate for useful post&lt;/P&gt;</description>
    <pubDate>Tue, 25 Oct 2016 11:12:31 GMT</pubDate>
    <dc:creator>Pawan Raut</dc:creator>
    <dc:date>2016-10-25T11:12:31Z</dc:date>
    <item>
      <title>ASA Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982801#M148990</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;my architecture is :&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/asa_5.jpg" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;and my ASA config is:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet0&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 192.168.2.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 10.30.60.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet2&lt;BR /&gt; nameif dmz&lt;BR /&gt; security-level 50&lt;BR /&gt; ip address 10.30.61.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;object network inside-subnet&lt;BR /&gt; subnet 10.30.60.0 255.255.255.0&lt;BR /&gt;object network dmz-subnet&lt;BR /&gt; subnet 10.30.61.0 255.255.255.0&lt;BR /&gt;pager lines 24&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu dmz 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;!&lt;BR /&gt;object network inside-subnet&lt;BR /&gt; nat (inside,outside) dynamic interface&lt;BR /&gt;object network dmz-subnet&lt;BR /&gt; nat (dmz,outside) dynamic interface&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;but ping is not work from R3 (inside) to R2 (outside)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks in advance,&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;MM&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:26:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982801#M148990</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2019-03-12T08:26:49Z</dc:date>
    </item>
    <item>
      <title>Check below things.</title>
      <link>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982802#M148991</link>
      <description>&lt;P&gt;Check below things.&lt;/P&gt;
&lt;P&gt;1) Do you have default route or return route towards ASA on both router?&lt;/P&gt;
&lt;P&gt;2) Do you have command "same-security-traffic permit inter-interface" in ASA config if not you have to add that.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Kindly rate for useful post&lt;/P&gt;</description>
      <pubDate>Tue, 25 Oct 2016 11:12:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982802#M148991</guid>
      <dc:creator>Pawan Raut</dc:creator>
      <dc:date>2016-10-25T11:12:31Z</dc:date>
    </item>
    <item>
      <title>Tahnks Pawan for your reply,</title>
      <link>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982803#M148992</link>
      <description>&lt;P&gt;Tahnks Pawan for your reply,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;How i can adjust default route?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;MM&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2016 08:41:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982803#M148992</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2016-10-26T08:41:09Z</dc:date>
    </item>
    <item>
      <title>give me the output sh ip</title>
      <link>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982804#M148993</link>
      <description>&lt;P&gt;give me the output sh ip route from both router&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2016 08:50:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982804#M148993</guid>
      <dc:creator>Pawan Raut</dc:creator>
      <dc:date>2016-10-26T08:50:14Z</dc:date>
    </item>
    <item>
      <title>Default route :</title>
      <link>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982805#M148994</link>
      <description>&lt;P&gt;Default route :&lt;/P&gt;
&lt;P&gt;do check the route below on ASA&lt;/P&gt;
&lt;P&gt;#route outside 0 0 &amp;nbsp;192.168.2.2&lt;/P&gt;
&lt;P&gt;also do check the global service policy inspection&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;#policy-map global_policy&lt;/P&gt;
&lt;P&gt;#inspect icmp&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2016 06:47:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982805#M148994</guid>
      <dc:creator>MANI .P</dc:creator>
      <dc:date>2016-10-27T06:47:32Z</dc:date>
    </item>
    <item>
      <title>R3#sh ip routeCodes: C -</title>
      <link>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982806#M148995</link>
      <description>&lt;P&gt;R3#sh ip route&lt;BR /&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;BR /&gt; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;BR /&gt; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;BR /&gt; E1 - OSPF external type 1, E2 - OSPF external type 2&lt;BR /&gt; i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;BR /&gt; ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;BR /&gt; o - ODR, P - periodic downloaded static route&lt;/P&gt;
&lt;P&gt;Gateway of last resort is not set&lt;/P&gt;
&lt;P&gt;C 10.30.60.0 is directly connected, FastEthernet0/0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;R2#sh ip route&lt;BR /&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;BR /&gt; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;BR /&gt; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;BR /&gt; E1 - OSPF external type 1, E2 - OSPF external type 2&lt;BR /&gt; i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;BR /&gt; ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;BR /&gt; o - ODR, P - periodic downloaded static route&lt;/P&gt;
&lt;P&gt;Gateway of last resort is not set&lt;/P&gt;
&lt;P&gt;C 192.168.2.0/24 is directly connected, FastEthernet0/0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks Pawan,&lt;/P&gt;
&lt;P&gt;Ragards,&lt;/P&gt;
&lt;P&gt;MM&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 10:05:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982806#M148995</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2016-11-02T10:05:27Z</dc:date>
    </item>
    <item>
      <title>You do not have route to</title>
      <link>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982807#M148996</link>
      <description>&lt;P&gt;You do not have route to reach each other please add below route.&lt;/P&gt;
&lt;P&gt;on R1&lt;/P&gt;
&lt;P&gt;ip route 192.168.2.0 2 255.255.255.0&amp;nbsp;&lt;SPAN&gt;10.30.60.1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;and on R2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ip route&amp;nbsp;10.30.60.0 255.255.255.0&amp;nbsp;192.168.2.1&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 10:11:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982807#M148996</guid>
      <dc:creator>Pawan Raut</dc:creator>
      <dc:date>2016-11-02T10:11:11Z</dc:date>
    </item>
    <item>
      <title>I tried that but don't</title>
      <link>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982808#M148997</link>
      <description>&lt;P&gt;I tried that but don't working&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;R3#ping 192.168.2.1&lt;/P&gt;
&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.2.1, timeout is 2 seconds:&lt;BR /&gt;.....&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 10:26:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982808#M148997</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2016-11-02T10:26:48Z</dc:date>
    </item>
    <item>
      <title>can you give me a basic</title>
      <link>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982809#M148998</link>
      <description>&lt;P&gt;can you give me a basic firewall configuration?&lt;/P&gt;
&lt;P&gt;Thanks Pawan,&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;MM&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 10:55:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982809#M148998</guid>
      <dc:creator>moussa.malqui1</dc:creator>
      <dc:date>2016-11-02T10:55:03Z</dc:date>
    </item>
    <item>
      <title>Do you have command "same</title>
      <link>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982810#M148999</link>
      <description>&lt;P&gt;&lt;SPAN&gt; Do you have command "same-security-traffic permit inter-interface" in ASA config if not you have to add that&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 11:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-configuration/m-p/2982810#M148999</guid>
      <dc:creator>Pawan Raut</dc:creator>
      <dc:date>2016-11-02T11:07:10Z</dc:date>
    </item>
  </channel>
</rss>

