<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5505 Configuration Issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-configuration-issues/m-p/2723557#M177630</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have been given the task of configuring an ASA 5505 from scratch and been wrestling unsuccesfully with it now for over a week.&amp;nbsp; The scenario is 3 vlans outside, inside and dmz.&amp;nbsp;dmz&amp;nbsp;has one fixed ip server (at the moment)&lt;/P&gt;&lt;P&gt;what i need to get to is:&lt;/P&gt;&lt;P&gt;outside -&amp;gt; dmz webserver&lt;/P&gt;&lt;P&gt;inside -&amp;gt; no access to outside&lt;/P&gt;&lt;P&gt;inside&amp;nbsp; -&amp;gt; access to dmz webserver&amp;nbsp;with &amp;nbsp;rdp and ping&lt;/P&gt;&lt;P&gt;Here is the current no working config, intersingly rdp gets a response but thats all. I deally i would like to do all setup through asdm 6.3 but any ting that help, even a complete teardown would be great&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tony&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;BR /&gt;&amp;nbsp;no forward interface Vlan2&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 160.100.30.253 255.255.252.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 172.16.0.253 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan3&lt;BR /&gt;&amp;nbsp;nameif dmz&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 11.0.200.253 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;&amp;nbsp;switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;&amp;nbsp;switchport access vlan 3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;&amp;nbsp;switchport access vlan 3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;&amp;nbsp;switchport access vlan 3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network Dmztrans&lt;BR /&gt;&amp;nbsp;host 160.100.31.145&lt;BR /&gt;object network dmzhost&lt;BR /&gt;&amp;nbsp;host 11.0.200.145&lt;BR /&gt;&amp;nbsp;description DMZ Host Machine&lt;BR /&gt;object network PublicServer_NAT1&lt;BR /&gt;&amp;nbsp;host 11.0.200.145&lt;BR /&gt;object network network1&lt;BR /&gt;&amp;nbsp;subnet 11.0.200.0 255.255.255.0&lt;BR /&gt;object network inside-network&lt;BR /&gt;&amp;nbsp;subnet 160.100.30.0 255.255.255.0&lt;BR /&gt;object network inside-network2&lt;BR /&gt;&amp;nbsp;subnet 160.100.30.0 255.255.255.0&lt;BR /&gt;object network dmz&lt;BR /&gt;&amp;nbsp;subnet 11.0.200.0 255.255.255.0&lt;BR /&gt;object-group service RDP tcp&lt;BR /&gt;&amp;nbsp;port-object eq 3389&lt;BR /&gt;object-group network DM_INLINE_NETWORK_1&lt;BR /&gt;&amp;nbsp;network-object object Dmztrans&lt;BR /&gt;&amp;nbsp;network-object object dmzhost&lt;BR /&gt;access-list dmz_access_in extended permit tcp any object Dmztrans object-group RDP&lt;BR /&gt;access-list inside_access extended permit tcp any host 11.0.200.145 object-group RDP&lt;BR /&gt;access-list inside_access extended permit icmp any host 11.0.200.145 echo-reply&lt;BR /&gt;access-list inside_access extended permit icmp any host 11.0.200.145&lt;BR /&gt;access-list inside-in extended permit icmp 11.0.200.0 255.255.255.0 any&lt;BR /&gt;access-list outside-in extended permit icmp any any echo-reply&lt;BR /&gt;access-list outside-in extended permit icmp any any&lt;BR /&gt;access-list global_access extended permit tcp object-group DM_INLINE_NETWORK_1 object Dmztrans object-group RDP&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu dmz 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;nat (dmz,inside) source static dmzhost dmzhost destination static Dmztrans Dmztrans&lt;BR /&gt;nat (inside,dmz) source static inside-network inside-network destination static dmz dmz&lt;BR /&gt;!&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;BR /&gt;object network PublicServer_NAT1&lt;BR /&gt;&amp;nbsp;nat (dmz,inside) static Dmztrans&lt;BR /&gt;object network network1&lt;BR /&gt;&amp;nbsp;nat (dmz,inside) dynamic interface&lt;BR /&gt;access-group inside_access in interface inside&lt;BR /&gt;access-group dmz_access_in in interface dmz&lt;BR /&gt;access-group global_access global&lt;BR /&gt;route inside 0.0.0.0 0.0.0.0 160.100.30.253 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;http server enable&lt;BR /&gt;http 160.100.28.0 255.255.252.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet 11.0.200.0 255.255.255.0 dmz&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd auto_config outside&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 160.100.31.1-160.100.31.32 inside&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;webvpn&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;&amp;nbsp; inspect icmp&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:45:42 GMT</pubDate>
    <dc:creator>bettston1</dc:creator>
    <dc:date>2019-03-12T06:45:42Z</dc:date>
    <item>
      <title>ASA 5505 Configuration Issues</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-configuration-issues/m-p/2723557#M177630</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have been given the task of configuring an ASA 5505 from scratch and been wrestling unsuccesfully with it now for over a week.&amp;nbsp; The scenario is 3 vlans outside, inside and dmz.&amp;nbsp;dmz&amp;nbsp;has one fixed ip server (at the moment)&lt;/P&gt;&lt;P&gt;what i need to get to is:&lt;/P&gt;&lt;P&gt;outside -&amp;gt; dmz webserver&lt;/P&gt;&lt;P&gt;inside -&amp;gt; no access to outside&lt;/P&gt;&lt;P&gt;inside&amp;nbsp; -&amp;gt; access to dmz webserver&amp;nbsp;with &amp;nbsp;rdp and ping&lt;/P&gt;&lt;P&gt;Here is the current no working config, intersingly rdp gets a response but thats all. I deally i would like to do all setup through asdm 6.3 but any ting that help, even a complete teardown would be great&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Tony&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;BR /&gt;&amp;nbsp;no forward interface Vlan2&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 160.100.30.253 255.255.252.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 172.16.0.253 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan3&lt;BR /&gt;&amp;nbsp;nameif dmz&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 11.0.200.253 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;&amp;nbsp;switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;&amp;nbsp;switchport access vlan 3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;&amp;nbsp;switchport access vlan 3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;&amp;nbsp;switchport access vlan 3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network Dmztrans&lt;BR /&gt;&amp;nbsp;host 160.100.31.145&lt;BR /&gt;object network dmzhost&lt;BR /&gt;&amp;nbsp;host 11.0.200.145&lt;BR /&gt;&amp;nbsp;description DMZ Host Machine&lt;BR /&gt;object network PublicServer_NAT1&lt;BR /&gt;&amp;nbsp;host 11.0.200.145&lt;BR /&gt;object network network1&lt;BR /&gt;&amp;nbsp;subnet 11.0.200.0 255.255.255.0&lt;BR /&gt;object network inside-network&lt;BR /&gt;&amp;nbsp;subnet 160.100.30.0 255.255.255.0&lt;BR /&gt;object network inside-network2&lt;BR /&gt;&amp;nbsp;subnet 160.100.30.0 255.255.255.0&lt;BR /&gt;object network dmz&lt;BR /&gt;&amp;nbsp;subnet 11.0.200.0 255.255.255.0&lt;BR /&gt;object-group service RDP tcp&lt;BR /&gt;&amp;nbsp;port-object eq 3389&lt;BR /&gt;object-group network DM_INLINE_NETWORK_1&lt;BR /&gt;&amp;nbsp;network-object object Dmztrans&lt;BR /&gt;&amp;nbsp;network-object object dmzhost&lt;BR /&gt;access-list dmz_access_in extended permit tcp any object Dmztrans object-group RDP&lt;BR /&gt;access-list inside_access extended permit tcp any host 11.0.200.145 object-group RDP&lt;BR /&gt;access-list inside_access extended permit icmp any host 11.0.200.145 echo-reply&lt;BR /&gt;access-list inside_access extended permit icmp any host 11.0.200.145&lt;BR /&gt;access-list inside-in extended permit icmp 11.0.200.0 255.255.255.0 any&lt;BR /&gt;access-list outside-in extended permit icmp any any echo-reply&lt;BR /&gt;access-list outside-in extended permit icmp any any&lt;BR /&gt;access-list global_access extended permit tcp object-group DM_INLINE_NETWORK_1 object Dmztrans object-group RDP&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu dmz 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;nat (dmz,inside) source static dmzhost dmzhost destination static Dmztrans Dmztrans&lt;BR /&gt;nat (inside,dmz) source static inside-network inside-network destination static dmz dmz&lt;BR /&gt;!&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;BR /&gt;object network PublicServer_NAT1&lt;BR /&gt;&amp;nbsp;nat (dmz,inside) static Dmztrans&lt;BR /&gt;object network network1&lt;BR /&gt;&amp;nbsp;nat (dmz,inside) dynamic interface&lt;BR /&gt;access-group inside_access in interface inside&lt;BR /&gt;access-group dmz_access_in in interface dmz&lt;BR /&gt;access-group global_access global&lt;BR /&gt;route inside 0.0.0.0 0.0.0.0 160.100.30.253 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;http server enable&lt;BR /&gt;http 160.100.28.0 255.255.252.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet 11.0.200.0 255.255.255.0 dmz&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd auto_config outside&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 160.100.31.1-160.100.31.32 inside&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;webvpn&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect esmtp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect ip-options&lt;BR /&gt;&amp;nbsp; inspect icmp&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:45:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-configuration-issues/m-p/2723557#M177630</guid>
      <dc:creator>bettston1</dc:creator>
      <dc:date>2019-03-12T06:45:42Z</dc:date>
    </item>
    <item>
      <title>Hello, It could be a license</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-configuration-issues/m-p/2723558#M177631</link>
      <description>&lt;P&gt;Hello, It could be a &lt;SPAN style="font-size: 14.4px; line-height: normal; background-color: rgb(245, 249, 237);"&gt;license issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If you can SSH into the device, try and do a show version as shown below.&lt;/P&gt;&lt;P&gt;or through the ASDM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Configuration &amp;gt; Device Management &amp;gt; Licensing &amp;gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA-PLUS# show version&lt;/P&gt;&lt;P&gt;For security plus License&lt;/P&gt;&lt;P&gt;~ out-put~&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;line-height:15.0pt"&gt;&lt;SPAN style="font-size: 7pt;"&gt;Licensed features for this platform:&lt;BR /&gt;Maximum Physical Interfaces &amp;nbsp; &amp;nbsp; &amp;nbsp; : 8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;perpetual&lt;BR /&gt;VLANs &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : &lt;/SPAN&gt;&lt;SPAN style="font-size: 7pt; color: red;"&gt;20 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; DMZ Unrestricted&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 7pt;"&gt;Dual ISPs &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : Enabled &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;perpetual&lt;BR /&gt;VLAN Trunk Ports &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: 8 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;perpetual&lt;BR /&gt;Inside Hosts &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: Unlimited &amp;nbsp; &amp;nbsp; &amp;nbsp;perpetual&lt;BR /&gt;Failover &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: Active/Standby perpetual&lt;BR /&gt;Encryption-DES &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: Enabled &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;perpetual&lt;BR /&gt;Encryption-3DES-AES &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : Enabled &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;perpetual&lt;BR /&gt;AnyConnect Premium Peers &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: 2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;perpetual&lt;BR /&gt;AnyConnect Essentials &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : Disabled &amp;nbsp; &amp;nbsp; &amp;nbsp; perpetual&lt;BR /&gt;Other VPN Peers &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 25 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; perpetual&lt;BR /&gt;Total VPN Peers &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 25 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; perpetual&lt;BR /&gt;Shared License &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: Disabled &amp;nbsp; &amp;nbsp; &amp;nbsp; perpetual&lt;BR /&gt;AnyConnect for Mobile &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : Disabled &amp;nbsp; &amp;nbsp; &amp;nbsp; perpetual&lt;BR /&gt;AnyConnect for Cisco VPN Phone &amp;nbsp; &amp;nbsp;: Disabled &amp;nbsp; &amp;nbsp; &amp;nbsp; perpetual&lt;BR /&gt;Advanced Endpoint Assessment &amp;nbsp; &amp;nbsp; &amp;nbsp;: Disabled &amp;nbsp; &amp;nbsp; &amp;nbsp; perpetual&lt;BR /&gt;UC Phone Proxy Sessions &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;perpetual&lt;BR /&gt;Total UC Proxy Sessions &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : 2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;perpetual&lt;BR /&gt;Botnet Traffic Filter &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : Disabled &amp;nbsp; &amp;nbsp; &amp;nbsp; perpetual&lt;BR /&gt;Intercompany Media Engine &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : Disabled &amp;nbsp; &amp;nbsp; &amp;nbsp; perpetual&lt;BR /&gt;Cluster &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : Disabled &amp;nbsp; &amp;nbsp; &amp;nbsp; perpetual&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;&lt;SPAN style="font-size: 7pt;"&gt;This platform has an ASA 5505 Security Plus license.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA-BASE# show version&lt;/P&gt;&lt;P&gt;For Base&amp;nbsp;License&lt;/P&gt;&lt;P&gt;~ out-put~&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;Licensed features for this platform:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;Maximum Physical Interfaces&amp;nbsp;&amp;nbsp;&amp;nbsp; : 8&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;VLANs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : &lt;STRONG&gt;&lt;SPAN style="color:#FF0000;"&gt;3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ Restricted&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;Dual ISPs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Disabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;VLAN Trunk Ports&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;Inside Hosts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 50&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;Failover&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Disabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;VPN-DES&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: Enabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;VPN-3DES-AES&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;SSL VPN Peers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;Total VPN Peers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;Shared License&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Disabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;AnyConnect for Mobile&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Disabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;AnyConnect for Cisco VPN Phone : Disabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;AnyConnect Essentials&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Disabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;Advanced Endpoint Assessment&amp;nbsp;&amp;nbsp; : Disabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;UC Phone Proxy Sessions&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;Total UC Proxy Sessions&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;Botnet Traffic Filter&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Disabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;Intercompany Media Engine&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Disabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:9px;"&gt;This platform has a Base license.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;If it says 3 DMZ restricted. That could be your problem.&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;The inside &amp;lt;==&amp;gt; DMZ might not be able to talk to each other.&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 15px; line-height: 19.5px;"&gt;"The Base license restricts you to three(3) VLAN's, with the third VLAN only being able to initiate communicate with one of the other two."&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;Source.&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;http://security.stackexchange.com/questions/57045/asa5505-dmz-issue&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0in 0in 0.0001pt; line-height: 15pt;"&gt;&lt;P&gt;&lt;/P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 22:08:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-configuration-issues/m-p/2723558#M177631</guid>
      <dc:creator>stevechege</dc:creator>
      <dc:date>2015-10-20T22:08:52Z</dc:date>
    </item>
  </channel>
</rss>

