<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic This is pretty much all I in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/failing-communication-b-w-networks/m-p/2681728#M191621</link>
    <description>&lt;P&gt;This is pretty much all I have for these two networks. Now does it matter that I have same subnets listed in the object groups for source and destination. Actually I have six subnets that all need to talk to each other. I created two object-group and put all six networks in them but named these object groups differently. I did not see any error message when applying ACL so i assume this was valid.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is nothing else I have on firewall &amp;nbsp;relevant to these networks. The firewall is working fine otherwise with no issues.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 May 2015 19:07:48 GMT</pubDate>
    <dc:creator>S891</dc:creator>
    <dc:date>2015-05-13T19:07:48Z</dc:date>
    <item>
      <title>Failing communication b/w networks</title>
      <link>https://community.cisco.com/t5/network-security/failing-communication-b-w-networks/m-p/2681726#M191616</link>
      <description>&lt;P&gt;I am facing an issue with connectivity between two networks. It seems simple but user is complaining that servers between the VLANs are not communicating (only ICMP is working but nothing else).&lt;/P&gt;&lt;P&gt;I cannot seem to find any issue with the below config. May be anyone can see anything missing. There is no NATTING configured. There are 6 networks that need to communicate with each other except for ICMP. I am showing just two here but it is the same for all.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface Vlan360&lt;BR /&gt;&amp;nbsp;nameif PUB-SERVERS&lt;BR /&gt;&amp;nbsp;security-level 40&lt;BR /&gt;&amp;nbsp;ip address 100.1.38.97 255.255.255.224 standby 100.1.38.98&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface Vlan361&lt;BR /&gt;&amp;nbsp;nameif PUB-USERS&lt;BR /&gt;&amp;nbsp;security-level 30&lt;BR /&gt;&amp;nbsp;ip address 100.1.40.225 255.255.255.224 standby 100.1.40.226&lt;/P&gt;&lt;P&gt;object-group network NETWORKS&lt;BR /&gt;&amp;nbsp; network-object 100.1.40.224 255.255.255.224&lt;BR /&gt;&amp;nbsp;network-object 100.1.38.96 255.255.255.224&lt;/P&gt;&lt;P&gt;object-group network NETWORKS2&lt;BR /&gt;network-object 100.1.40.224 255.255.255.224&lt;BR /&gt;network-object 100.1.38.96 255.255.255.224&lt;/P&gt;&lt;P&gt;access-list PUB-SERVERS_IN extended permit ip object-group NETWORKS object-group NETWORKS2&amp;nbsp;&lt;BR /&gt;access-list PUB-SERVERS_IN extended permit icmp object-group NETWORKS object-group NETWORKS2&amp;nbsp;&lt;BR /&gt;access-list PUB-USERS_IN extended permit ip object-group NETWORKS object-group NETWORKS2&amp;nbsp;&lt;BR /&gt;access-list PUB-USERS_IN extended permit icmp object-group NETWORKS object-group NETWORKS2&lt;/P&gt;&lt;P&gt;access-group PUB-SERVERS_IN in interface PUB-SERVERS&lt;BR /&gt;access-group PUB-USERS_IN in interface PUB-USERS&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:55:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failing-communication-b-w-networks/m-p/2681726#M191616</guid>
      <dc:creator>S891</dc:creator>
      <dc:date>2019-03-12T05:55:47Z</dc:date>
    </item>
    <item>
      <title>hi fawad,can you post the</title>
      <link>https://community.cisco.com/t5/network-security/failing-communication-b-w-networks/m-p/2681727#M191618</link>
      <description>&lt;P&gt;hi fawad,&lt;/P&gt;&lt;P&gt;can you post the whole config for us to assess further?&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2015 15:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failing-communication-b-w-networks/m-p/2681727#M191618</guid>
      <dc:creator>fatalXerror</dc:creator>
      <dc:date>2015-05-13T15:25:12Z</dc:date>
    </item>
    <item>
      <title>This is pretty much all I</title>
      <link>https://community.cisco.com/t5/network-security/failing-communication-b-w-networks/m-p/2681728#M191621</link>
      <description>&lt;P&gt;This is pretty much all I have for these two networks. Now does it matter that I have same subnets listed in the object groups for source and destination. Actually I have six subnets that all need to talk to each other. I created two object-group and put all six networks in them but named these object groups differently. I did not see any error message when applying ACL so i assume this was valid.&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is nothing else I have on firewall &amp;nbsp;relevant to these networks. The firewall is working fine otherwise with no issues.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2015 19:07:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failing-communication-b-w-networks/m-p/2681728#M191621</guid>
      <dc:creator>S891</dc:creator>
      <dc:date>2015-05-13T19:07:48Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/failing-communication-b-w-networks/m-p/2681729#M191624</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Why do you have both networks in both object-groups? I don't know if it would create a problem, but it doesn't make sence. What you should do instead:&lt;/P&gt;

&lt;PRE&gt;
object network PUB-SERVERS
subnet 100.1.38.96 255.255.255.224

object network PUB-USERS
subnet 100.1.40.224 255.255.255.224

access-list PUB-SERVERS_IN permit ip object PUB-SERVERS object PUB-USERS
access-list PUB-SERVERS_IN permit icmp object PUB-SERVERS object PUB-USERS

access-list PUB-USERS_IN permit ip object PUB-USERS object PUB-SERVERS
access-list PUB-USERS_IN permit icmp object PUB-USERS object PUB-SERVERS

access-group PUB-SERVERS_IN in interface PUB-SERVERS
access-group PUB-USERS_IN in interface PUB-USERS
&lt;/PRE&gt;

&lt;P&gt;When you have changed that, and it still doesn't work, try packet-tracer:&lt;/P&gt;

&lt;PRE&gt;
packet-tracer input PUB-USERS tcp 100.1.40.226 45644 100.1.38.96 45
packet-tracer input PUB-SERVERS tcp 100.1.38.96 45644 100.1.40.226 45&lt;/PRE&gt;

&lt;P&gt;And then post the output here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2015 19:43:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failing-communication-b-w-networks/m-p/2681729#M191624</guid>
      <dc:creator>Henrik Grankvist</dc:creator>
      <dc:date>2015-05-13T19:43:57Z</dc:date>
    </item>
  </channel>
</rss>

