<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Downgraded to 9.1(4) again - in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878625#M172367</link>
    <description>&lt;P&gt;Downgraded to 9.1(4) again - No problems.&lt;/P&gt;
&lt;P&gt;No I have the problem with the IKE vuln &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 20 Feb 2016 13:36:49 GMT</pubDate>
    <dc:creator>Christian Balzereit</dc:creator>
    <dc:date>2016-02-20T13:36:49Z</dc:date>
    <item>
      <title>ASA 5512X - Ping into DMZ not possible after update (9.1(4) to 9.1(7))</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878618#M172360</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;after I update from 9.1(4) to 9.1(7) I'm not able to access DMZ devices from my internal network.&lt;/P&gt;
&lt;P&gt;What are the changes where do I have to look?&lt;/P&gt;
&lt;P&gt;Do you need further information?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:21:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878618#M172360</guid>
      <dc:creator>Christian Balzereit</dc:creator>
      <dc:date>2019-03-12T07:21:44Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878619#M172361</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;if you have the old config, prior to your upgrade, you may want to compare the nat rules line by line if anything changed.&lt;/P&gt;
&lt;P&gt;But, we also have a problem after the upgrade with a destination nat rule, it seems it does not catch it anymore. I did compare our config and nothing changed so i am betting on a bug.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 12:30:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878619#M172361</guid>
      <dc:creator>Michael Braun</dc:creator>
      <dc:date>2016-02-20T12:30:42Z</dc:date>
    </item>
    <item>
      <title>Yeah, same here. He seems to</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878620#M172362</link>
      <description>&lt;P&gt;Yeah, same here. He seems to route the ICMP packets to the outside interface.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="http://i.imgur.com/M6Wsyeu.png" alt="" width="685" height="555" /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 12:38:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878620#M172362</guid>
      <dc:creator>Christian Balzereit</dc:creator>
      <dc:date>2016-02-20T12:38:48Z</dc:date>
    </item>
    <item>
      <title>Have you tried to disable</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878621#M172363</link>
      <description>&lt;P&gt;Have you tried to disable proxy arp? This seems to be causing issues by many others after upgrading due to the ike vulnerability.. If not needed, it should be disabled.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;On the other issue, i have just downgraded back to 911, NAT works again, back to 917, NAT does not work. So my problem seems to be a bug.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 12:54:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878621#M172363</guid>
      <dc:creator>Michael Braun</dc:creator>
      <dc:date>2016-02-20T12:54:41Z</dc:date>
    </item>
    <item>
      <title>Disabling Proxy ARP did not</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878622#M172364</link>
      <description>&lt;P&gt;Disabling Proxy ARP did not help &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 13:06:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878622#M172364</guid>
      <dc:creator>Christian Balzereit</dc:creator>
      <dc:date>2016-02-20T13:06:13Z</dc:date>
    </item>
    <item>
      <title>It was a try i guess. Have</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878623#M172365</link>
      <description>&lt;P&gt;It was a try i guess. Have you downgraded back to the old version, just to see if it will work again?&lt;/P&gt;
&lt;P&gt;i am checking if there is in interim release and try it - tried it, problem remains, so it is going to be a case at Cisco.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 13:14:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878623#M172365</guid>
      <dc:creator>Michael Braun</dc:creator>
      <dc:date>2016-02-20T13:14:36Z</dc:date>
    </item>
    <item>
      <title>I've found in some cases I</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878624#M172366</link>
      <description>&lt;P&gt;I've found in some cases I have had to add no-proxy-arp AND add route-lookup onto the NAT statements themeselves&lt;/P&gt;
&lt;P&gt;If it's feasible for you to try this then give it a shot&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 13:22:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878624#M172366</guid>
      <dc:creator>David99</dc:creator>
      <dc:date>2016-02-20T13:22:14Z</dc:date>
    </item>
    <item>
      <title>Downgraded to 9.1(4) again -</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878625#M172367</link>
      <description>&lt;P&gt;Downgraded to 9.1(4) again - No problems.&lt;/P&gt;
&lt;P&gt;No I have the problem with the IKE vuln &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 13:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878625#M172367</guid>
      <dc:creator>Christian Balzereit</dc:creator>
      <dc:date>2016-02-20T13:36:49Z</dc:date>
    </item>
    <item>
      <title>It may be another issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878626#M172368</link>
      <description>&lt;P&gt;It may be another issue entirely. The image above does NAT from DMZ to outside, so this is correct. For LAN/DMZ you should use NAT BEFORE Object NAT, unless there is a specific reason not to.... So it may be that with the upgrade, the ASA is a little bit more picky about NAT rules. Do you see any error messages in the log? Usually the ASA is very chatty if there is a problem.&lt;/P&gt;
&lt;P&gt;Interface security Level is another this to keep in mind with NAT, and do you realy NAT from LAN to DMZ or is it just identity NAT, so no translation is done?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 13:43:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878626#M172368</guid>
      <dc:creator>Michael Braun</dc:creator>
      <dc:date>2016-02-20T13:43:13Z</dc:date>
    </item>
    <item>
      <title>You could also try 9.1(6.11)</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878627#M172369</link>
      <description>&lt;P&gt;You could also try &lt;SPAN class="more"&gt;9.1(6.11)&lt;/SPAN&gt; - Cisco update the recommended upgrade to this version per this page:&lt;/P&gt;
&lt;P&gt;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160210-asa-ike&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 13:48:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878627#M172369</guid>
      <dc:creator>David99</dc:creator>
      <dc:date>2016-02-20T13:48:46Z</dc:date>
    </item>
    <item>
      <title>Where d I find the 9.1(6.11)?</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878628#M172370</link>
      <description>&lt;P&gt;Where d I find the 9.1(6.11)?&lt;/P&gt;
&lt;P&gt;I can downoad&amp;nbsp;&lt;SPAN&gt;9.1.6.SMP&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 13:58:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878628#M172370</guid>
      <dc:creator>Christian Balzereit</dc:creator>
      <dc:date>2016-02-20T13:58:37Z</dc:date>
    </item>
    <item>
      <title>Check under all releases,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878629#M172371</link>
      <description>&lt;P&gt;Check under all releases,"interim", there it is. If the ike bug is fixed in that one, it may be ok too. But the recommended release is still 917...&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 14:04:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878629#M172371</guid>
      <dc:creator>Michael Braun</dc:creator>
      <dc:date>2016-02-20T14:04:39Z</dc:date>
    </item>
    <item>
      <title>Hey Michael,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878630#M172372</link>
      <description>&lt;P&gt;Hey Michael,&lt;/P&gt;
&lt;P&gt;I was under the same impression, but I read that due to reported issues with 9.1(7) Cisco changed the recommendation &lt;/P&gt;
&lt;P&gt;That of course may just be hear say, and I had read that 9.1.(7.1) was coming but if you see in the official vulnerability page link that it recommends now 9.1(6.11) or later&lt;/P&gt;
&lt;P&gt;https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160210-asa-ike&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 14:11:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878630#M172372</guid>
      <dc:creator>David99</dc:creator>
      <dc:date>2016-02-20T14:11:49Z</dc:date>
    </item>
    <item>
      <title>Thanks for the hint, although</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878631#M172373</link>
      <description>&lt;P&gt;Thanks for the hint, although, all our 5512s are on 9.4.2.6 without issues, i did not bother with 917, which i only use on non X series (5505, 5510 etc)&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 14:15:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878631#M172373</guid>
      <dc:creator>Michael Braun</dc:creator>
      <dc:date>2016-02-20T14:15:20Z</dc:date>
    </item>
    <item>
      <title>OK, short update, i have</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878632#M172374</link>
      <description>&lt;P&gt;OK, short update, i have tried 916-11, it did not fix our issue with destination nat. bummer... (btw. interim 917.4, same problem)&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 14:26:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878632#M172374</guid>
      <dc:creator>Michael Braun</dc:creator>
      <dc:date>2016-02-20T14:26:24Z</dc:date>
    </item>
    <item>
      <title>I replied earlier but the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878633#M172375</link>
      <description>&lt;P&gt;I replied earlier but the comment keeps going to the very bottom (noob error on my part, no doubt)&lt;/P&gt;
&lt;P&gt;Have you tried 'no-proxy-arp route-lookup' in your NAT configuration?&lt;/P&gt;
&lt;P&gt;You don't have something which hiterto didn't cause a problem such as same security levels on interfaces or anything like that, do you?&lt;/P&gt;
&lt;P&gt;Without seeing the specific rule it's hard to say exactly what's going on but I think also there were some reports of the ordering being broken so could always be worth trying to remove and re-add this rule.&lt;/P&gt;
&lt;P&gt;Other than that, I'm all out!&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 14:34:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878633#M172375</guid>
      <dc:creator>David99</dc:creator>
      <dc:date>2016-02-20T14:34:08Z</dc:date>
    </item>
    <item>
      <title>Thx again.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878634#M172376</link>
      <description>&lt;P&gt;Thx again.&lt;/P&gt;
&lt;P&gt;Same errors with the Interim build &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 14:42:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878634#M172376</guid>
      <dc:creator>Christian Balzereit</dc:creator>
      <dc:date>2016-02-20T14:42:24Z</dc:date>
    </item>
    <item>
      <title>Same here, even tried latest</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878635#M172377</link>
      <description>&lt;P&gt;Same here, even tried latest 9.2.x.x interim, no change, NAT keeps failing. I have a case open with Cisco because of that, once i get some infos, i will be posting.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Cheers everyone, (off to some other problem)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;Markus&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8.0pt; font-family: 'Arial',sans-serif; color: #1f497d;"&gt;&amp;nbsp;Cisco ID CSCO11583512&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Verdana',sans-serif; color: #1f497d;"&gt;CCDA, CCNA, CCNA Security, CCNP Security&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 8.0pt; font-family: 'Arial',sans-serif; color: #1f497d;"&gt;ASA Specialist, Firewall Security Specialist, IOS Security Specialist,&lt;BR /&gt;IPS Specialist, VPN Security Specialist, NSA CNSS 4011 and 4013 Recognition, INFOSEC&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 7.5pt; font-family: 'Verdana',sans-serif; color: #1f497d;"&gt;Amideo Networks&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 7.5pt; font-family: 'Verdana',sans-serif; color: #1f497d;"&gt;Ringeisenstrasse 2, 86836 Graben / GT Lagerlechfeld&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #1f497d; font-size: 8pt;"&gt;Phone: +49 8232 956 9197&amp;nbsp; ,&amp;nbsp;&amp;nbsp; Fax: +49 8232 959 4031&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 8.0pt; font-family: 'Arial',sans-serif; color: #1f497d;"&gt;Amideo Networks Public IPv6 Address Range: 2003:44:2010::/48 &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="font-size: 8.0pt; font-family: 'Arial',sans-serif; color: #1f497d;"&gt;ipv6.amideo.de&lt;BR /&gt;IPv6 DNS Deutsche Telekom: 2003:40:2000::53, 2003:56::53, 2003:40:4000::53&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Feb 2016 14:47:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878635#M172377</guid>
      <dc:creator>Michael Braun</dc:creator>
      <dc:date>2016-02-20T14:47:59Z</dc:date>
    </item>
    <item>
      <title>Hello Michael,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878636#M172378</link>
      <description>&lt;P&gt;Hello Michael,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Intern -&amp;gt; DMZ = No NAT&lt;/P&gt;
&lt;P&gt;DMZ -&amp;gt; outside = Static NAT&lt;/P&gt;
&lt;P&gt;NAT for VPN&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;EDIT: When I access my intern LAN via VPN I'm able to access my DMZ&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 09:13:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878636#M172378</guid>
      <dc:creator>Christian Balzereit</dc:creator>
      <dc:date>2016-02-22T09:13:57Z</dc:date>
    </item>
    <item>
      <title>Have you debugged at the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878637#M172379</link>
      <description>&lt;P&gt;Have you debugged at the console ?&lt;/P&gt;
&lt;P&gt;Debug trace icmp&lt;/P&gt;
&lt;P&gt;and you see if and what happens to the packets.&lt;/P&gt;
&lt;P&gt;But you may want to stop Nagius/Solarwinds etc. for this or you will get a ton of messages.&lt;/P&gt;
&lt;P&gt;Alternatively logg debug to syslog and filter it out.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2016 10:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512x-ping-into-dmz-not-possible-after-update-9-1-4-to-9-1-7/m-p/2878637#M172379</guid>
      <dc:creator>Michael Braun</dc:creator>
      <dc:date>2016-02-22T10:34:56Z</dc:date>
    </item>
  </channel>
</rss>

