<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic That also results in an allow in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769107#M171193</link>
    <description>&lt;P&gt;That also results in an allow.&amp;nbsp; And yes the device on the inside is accessible via port 80 to the vendor.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Oct 2015 14:17:15 GMT</pubDate>
    <dc:creator>Sandra Proesch</dc:creator>
    <dc:date>2015-10-29T14:17:15Z</dc:date>
    <item>
      <title>External Server Needs SNMP from Internal Device through ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769102#M171188</link>
      <description>&lt;P&gt;We have an external vendor who has placed a device (several actually) on our internal network.&amp;nbsp; We are using one external IP and natting to different devices inside by using different ports.&amp;nbsp; This works fine for http and a couple of custom tcp ports they are using.&amp;nbsp; What we cannot get to work is that they want to connect to one of the devices with UDP/161 (snmp).&amp;nbsp; Even though I've used the same type of rules and nat that I did for the other ports, this is not working.&amp;nbsp; The outside host still reports that port UDP/161 is not open.&amp;nbsp; Inside we can determine that yes, the device is running the snmp service.&lt;/P&gt;
&lt;P&gt;I think this may have something to do with the group policy on the ASA5520, but I'm not sure.&amp;nbsp; I can do access rules and nat, but I'm not enough of an expert to really understand the rest of the configuration.&amp;nbsp; Is there a good reference I can look at, or is anyone here doing something similar and can point me in the right direction?&lt;/P&gt;
&lt;P&gt;Thanks for the help.&lt;/P&gt;
&lt;P&gt;--Sandy&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:48:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769102#M171188</guid>
      <dc:creator>Sandra Proesch</dc:creator>
      <dc:date>2019-03-12T06:48:11Z</dc:date>
    </item>
    <item>
      <title>So it is the external server</title>
      <link>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769103#M171189</link>
      <description>&lt;P&gt;So it is the external server that needs to send SNMP to the internal device ?&lt;/P&gt;
&lt;P&gt;Just checking because your thread description suggests the other way round.&lt;/P&gt;
&lt;P&gt;If so can you run this command on your ASA and post here -&lt;/P&gt;
&lt;P&gt;"packet-tracer input outside udp &amp;lt;external server IP&amp;gt; 12345 &amp;lt;public IP of inside server&amp;gt; 161"&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 20:14:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769103#M171189</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-10-28T20:14:22Z</dc:date>
    </item>
    <item>
      <title>The external server will be</title>
      <link>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769104#M171190</link>
      <description>&lt;P&gt;The external server will be making the SNMP request to the internal device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The packet trace results in action allow.&amp;nbsp; Seems like this should mean it's working.&amp;nbsp; Let me get back with the vendor and see if he's seeing it now.&amp;nbsp; Thanks for your help.&amp;nbsp; I'll post back when I've determined how it looks to the vendor now.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 20:26:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769104#M171190</guid>
      <dc:creator>Sandra Proesch</dc:creator>
      <dc:date>2015-10-28T20:26:04Z</dc:date>
    </item>
    <item>
      <title>No, that didn't fix the</title>
      <link>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769105#M171191</link>
      <description>&lt;P&gt;No, that didn't fix the problem.&amp;nbsp; Back to the drawing board.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 12:57:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769105#M171191</guid>
      <dc:creator>Sandra Proesch</dc:creator>
      <dc:date>2015-10-29T12:57:50Z</dc:date>
    </item>
    <item>
      <title>Can you just check the other</title>
      <link>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769106#M171192</link>
      <description>&lt;P&gt;Can you just check the other way ie.&lt;/P&gt;
&lt;P&gt;"packet-tracer input inside udp &amp;lt;real server IP&amp;gt; 161 &amp;lt;external server IP&amp;gt; 12345"&lt;/P&gt;
&lt;P&gt;Also is this device on the inside accessble via any other ports to the vendor ?&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 13:15:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769106#M171192</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-10-29T13:15:39Z</dc:date>
    </item>
    <item>
      <title>That also results in an allow</title>
      <link>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769107#M171193</link>
      <description>&lt;P&gt;That also results in an allow.&amp;nbsp; And yes the device on the inside is accessible via port 80 to the vendor.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 14:17:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769107#M171193</guid>
      <dc:creator>Sandra Proesch</dc:creator>
      <dc:date>2015-10-29T14:17:15Z</dc:date>
    </item>
    <item>
      <title>Think you might need a new</title>
      <link>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769108#M171194</link>
      <description>&lt;P&gt;Think you might need a new vendor &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Unless you are doing some sort of NAT on their source IP as it comes through your firewall and you haven't set that up for this connection I can't see what is wrong.&lt;/P&gt;
&lt;P&gt;You would only need to do this type of NAT if the devices didn't send the traffic back to the ASA either direct or via other L3 devices internally.&lt;/P&gt;
&lt;P&gt;It is unlikely this is&amp;nbsp;the problem but I have seen it.&lt;/P&gt;
&lt;P&gt;Other than that you are going to have to do&amp;nbsp;some packet captures on the firewall I think to see if you are -&lt;/P&gt;
&lt;P&gt;1) seeing the UDP packets leaving the inside interface to the device&lt;/P&gt;
&lt;P&gt;and&lt;/P&gt;
&lt;P&gt;2) seeing the return UDP packets on the inside interface being sent back from the device&lt;/P&gt;
&lt;P&gt;This is a link on how to setup the capture but obviously you need to liase with your vendor to test and I would do it in a quiet time -&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/document/69281/asa-using-packet-capture-troubleshoot-asa-firewall-configuration-and-scenarios"&gt;https://supportforums.cisco.com/document/69281/asa-using-packet-capture-troubleshoot-asa-firewall-configuration-and-scenarios&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;if you want to post the configuration by all means do and someone may spot something.&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 14:42:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769108#M171194</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-10-29T14:42:16Z</dc:date>
    </item>
    <item>
      <title>Thanks very much for the help</title>
      <link>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769109#M171195</link>
      <description>&lt;P&gt;Thanks very much for the help.&amp;nbsp; You've pretty much confirmed what I thought.&amp;nbsp; I'm going back to the vendor and ask him where if anywhere does he have this working!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 14:42:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/external-server-needs-snmp-from-internal-device-through-asa5520/m-p/2769109#M171195</guid>
      <dc:creator>Sandra Proesch</dc:creator>
      <dc:date>2015-10-29T14:42:17Z</dc:date>
    </item>
  </channel>
</rss>

