<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I have now managed to break in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/port-forwarding-on-asa-5505-not-working-help/m-p/2692668#M193231</link>
    <description>&lt;P style="font-size: 14.399998664856px;"&gt;I have now managed to break it by adding another port forward this time to another subnet that is connected by VPN.&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;The command I have run from the CLI&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;object network UK2008SRV_WEB&lt;BR /&gt;host 172.27.0.136&lt;BR /&gt;nat (inside,outside) static interface service tcp 80 80&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;access-list UK2008SRV-in extended permit tcp any host 172.27.0.136 eq 80 log&lt;BR /&gt;access-group UK2008SRV-in in interface outside_Arena&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;How do I now fix to get both port forwards working? &amp;nbsp;Sorry this is confusing..&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;Result of the command: "show config"&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;&lt;BR /&gt;ASA Version 8.4(2)&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;hostname LYNQUKASA&lt;BR /&gt;domain-name ********&lt;BR /&gt;enable password ******** encrypted&lt;BR /&gt;passwd ********&amp;nbsp;encrypted&lt;BR /&gt;no names&lt;BR /&gt;name 172.26.0.32 DEMO.ILYNQ.COM_InternalIP description Used in NAT rule for port redir of pts 81 and 3389&lt;BR /&gt;name 172.26.0.26 UKFS_InternalIP description Used in NAT rule to port redirect FTP pt 21&lt;BR /&gt;name 92.237.118.233 VIRGIN_ISP_Gateway&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;&amp;nbsp;switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;&amp;nbsp;switchport access vlan 32&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;interface Vlan12&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 172.26.0.1 255.255.255.0&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface Vlan32&lt;BR /&gt;&amp;nbsp;nameif outside_Arena&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 95.130.99.137 255.255.255.240&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa842-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone GMT/BST 0&lt;BR /&gt;clock summer-time GMT/BDT recurring last Sun Mar 1:00 last Sun Oct 2:00&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;&amp;nbsp;domain-name lynq.co.uk&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network obj-172.26.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.26.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.29.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.29.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.27.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.27.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.23.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.23.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.25.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.25.0.0 255.255.255.0&lt;BR /&gt;object network obj-192.168.0.0&lt;BR /&gt;&amp;nbsp;subnet 192.168.0.0 255.255.252.0&lt;BR /&gt;object network obj-10.100.100.0&lt;BR /&gt;&amp;nbsp;subnet 10.100.100.0 255.255.255.0&lt;BR /&gt;object network obj-172.22.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.22.0.0 255.255.255.0&lt;BR /&gt;object network obj-192.168.40.0&lt;BR /&gt;&amp;nbsp;subnet 192.168.40.0 255.255.255.0&lt;BR /&gt;object network obj-172.20.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.20.0.0 255.255.255.0&lt;BR /&gt;object network obj-92.237.118.236&lt;BR /&gt;&amp;nbsp;host 92.237.118.236&lt;BR /&gt;object service obj-tcp-source-eq-80&lt;BR /&gt;&amp;nbsp;service tcp source eq www&amp;nbsp;&lt;BR /&gt;object service obj-tcp-source-eq-21&lt;BR /&gt;&amp;nbsp;service tcp source eq ftp&amp;nbsp;&lt;BR /&gt;object network obj-172.26.0.132&lt;BR /&gt;&amp;nbsp;host 172.26.0.132&lt;BR /&gt;object network obj-92.237.118.237&lt;BR /&gt;&amp;nbsp;host 92.237.118.237&lt;BR /&gt;object service obj-tcp-source-eq-3389&lt;BR /&gt;&amp;nbsp;service tcp source eq 3389&amp;nbsp;&lt;BR /&gt;object network obj-172.26.0.107&lt;BR /&gt;&amp;nbsp;host 172.26.0.107&lt;BR /&gt;object network obj-92.237.118.238&lt;BR /&gt;&amp;nbsp;host 92.237.118.238&lt;BR /&gt;object network obj-92.237.118.235&lt;BR /&gt;&amp;nbsp;host 92.237.118.235&lt;BR /&gt;object network BT_ISP_Gateway&lt;BR /&gt;&amp;nbsp;host 81.138.134.30&lt;BR /&gt;&amp;nbsp;description BT ISP Router&lt;BR /&gt;object network obj-172.26.0.26&lt;BR /&gt;&amp;nbsp;host 172.26.0.26&lt;BR /&gt;&amp;nbsp;description FTP server&lt;BR /&gt;object service ftp&lt;BR /&gt;&amp;nbsp;service tcp source eq ftp destination range 1 65535&amp;nbsp;&lt;BR /&gt;object network BT_NatHidingStaticIP&lt;BR /&gt;&amp;nbsp;host 81.138.134.25&lt;BR /&gt;object network NETWORK_OBJ_172.26.0.0_24&lt;BR /&gt;&amp;nbsp;subnet 172.26.0.0 255.255.255.0&lt;BR /&gt;object network NETWORK_OBJ_172.30.0.0_24&lt;BR /&gt;&amp;nbsp;subnet 172.30.0.0 255.255.255.0&lt;BR /&gt;object network NETWORK_OBJ_172.31.0.0_25&lt;BR /&gt;&amp;nbsp;subnet 172.31.0.0 255.255.255.128&lt;BR /&gt;object network obj-172.30.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.30.0.0 255.255.255.0&lt;BR /&gt;object network NETWORK_OBJ_172.31.0.192_26&lt;BR /&gt;&amp;nbsp;subnet 172.31.0.192 255.255.255.192&lt;BR /&gt;object network NETWORK_OBJ_192.168.50.0_26&lt;BR /&gt;&amp;nbsp;subnet 192.168.50.0 255.255.255.192&lt;BR /&gt;object network NETWORK_OBJ_10.0.0.0_28&lt;BR /&gt;&amp;nbsp;subnet 10.0.0.0 255.255.255.240&lt;BR /&gt;object network NETWORK_OBJ_10.11.1.0_27&lt;BR /&gt;&amp;nbsp;subnet 10.11.1.0 255.255.255.224&lt;BR /&gt;object network 172.26.0.19&lt;BR /&gt;&amp;nbsp;host 172.26.0.19&lt;BR /&gt;object service 8080&lt;BR /&gt;&amp;nbsp;service tcp source eq 8080 destination eq 8080&amp;nbsp;&lt;BR /&gt;object network Clarke-Aruba&lt;BR /&gt;&amp;nbsp;subnet 172.31.0.0 255.255.255.0&lt;BR /&gt;object network FENDI_Laptop&lt;BR /&gt;&amp;nbsp;host 172.26.0.19&lt;BR /&gt;object network 172.26.0.1&lt;BR /&gt;&amp;nbsp;host 172.26.0.1&lt;BR /&gt;&amp;nbsp;description Internal IP for Router&lt;BR /&gt;object network UK2008SRV_WEB&lt;BR /&gt;&amp;nbsp;host 172.27.0.136&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_1&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_2&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group service DM_INLINE_TCP_1 tcp&lt;BR /&gt;&amp;nbsp;port-object eq 3389&lt;BR /&gt;&amp;nbsp;port-object eq 3390&lt;BR /&gt;&amp;nbsp;port-object eq 81&lt;BR /&gt;&amp;nbsp;port-object eq 82&lt;BR /&gt;&amp;nbsp;port-object eq ftp&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;object-group network DM_INLINE_NETWORK_2&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.235&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.236&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.237&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.238&lt;BR /&gt;object-group service DM_INLINE_TCP_2 tcp&lt;BR /&gt;&amp;nbsp;port-object eq 3389&lt;BR /&gt;&amp;nbsp;port-object eq 81&lt;BR /&gt;&amp;nbsp;port-object eq 82&lt;BR /&gt;&amp;nbsp;port-object eq ftp&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;&amp;nbsp;port-object eq https&lt;BR /&gt;object-group service DM_INLINE_TCP_3 tcp&lt;BR /&gt;&amp;nbsp;port-object eq 3389&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;object-group network DM_INLINE_NETWORK_3&lt;BR /&gt;&amp;nbsp;network-object object obj-172.20.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.29.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-192.168.40.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.23.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.25.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-10.100.100.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.22.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-192.168.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.27.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.30.0.0&lt;BR /&gt;&amp;nbsp;network-object object Clarke-Aruba&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_5&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_3&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_4&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group protocol DM_INLINE_PROTOCOL_1&lt;BR /&gt;&amp;nbsp;protocol-object ip&lt;BR /&gt;&amp;nbsp;protocol-object icmp&lt;BR /&gt;object-group network DM_INLINE_NETWORK_1&lt;BR /&gt;&amp;nbsp;network-object 172.27.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.20.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.29.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-192.168.40.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_4&lt;BR /&gt;&amp;nbsp;network-object 172.30.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object object Clarke-Aruba&lt;BR /&gt;object-group network DM_INLINE_NETWORK_5&lt;BR /&gt;&amp;nbsp;network-object object Clarke-Aruba&lt;BR /&gt;&amp;nbsp;network-object object NETWORK_OBJ_172.30.0.0_24&lt;BR /&gt;object-group protocol DM_INLINE_PROTOCOL_2&lt;BR /&gt;&amp;nbsp;protocol-object udp&lt;BR /&gt;&amp;nbsp;protocol-object tcp&lt;BR /&gt;object-group protocol TCPUDP&lt;BR /&gt;&amp;nbsp;protocol-object udp&lt;BR /&gt;&amp;nbsp;protocol-object tcp&lt;BR /&gt;access-list inside_nat_outbound extended permit ip 172.26.0.0 255.255.255.0 any&amp;nbsp;&lt;BR /&gt;access-list inside_access_in extended permit ip 172.26.0.0 255.255.255.0 any&amp;nbsp;&lt;BR /&gt;access-list inside_access_in extended permit icmp any any object-group DM_INLINE_ICMP_1&amp;nbsp;&lt;BR /&gt;access-list inside_access_in extended permit object-group TCPUDP any any&amp;nbsp;&lt;BR /&gt;access-list dmz_access_in extended permit icmp any any object-group DM_INLINE_ICMP_2&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 172.23.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 172.25.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 192.168.0.0 255.255.252.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 10.100.100.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 172.22.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list outside_Arena_cryptomap extended permit ip 172.26.0.0 255.255.255.0 object-group DM_INLINE_NETWORK_1&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in extended permit icmp any any object-group DM_INLINE_ICMP_3&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_cryptomap_1 extended permit ip 172.26.0.0 255.255.255.0 172.23.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list outside_bt_isp_access_in extended permit icmp any any object-group DM_INLINE_ICMP_5&amp;nbsp;&lt;BR /&gt;access-list outside_bt_isp_access_in extended permit tcp any any eq ftp&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit icmp any any object-group DM_INLINE_ICMP_4&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit object-group DM_INLINE_PROTOCOL_1 any 192.168.0.0 255.255.252.0&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit ip host 80.88.92.106 any&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit icmp any any&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_cryptomap_2 extended permit ip 172.26.0.0 255.255.255.0 object obj-10.100.100.0&amp;nbsp;&lt;BR /&gt;access-list outside_Arena_cryptomap_1 extended permit ip 172.26.0.0 255.255.255.0 object-group DM_INLINE_NETWORK_4&amp;nbsp;&lt;BR /&gt;access-list SplitTunnel standard permit 172.26.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list NAT-EXEMPT extended permit ip 172.26.0.0 255.255.255.0 10.11.1.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list FENDI-in extended permit tcp any host 172.26.0.19 eq 3389 log&amp;nbsp;&lt;BR /&gt;access-list UK2008SRV-in extended permit tcp any host 172.27.0.136 eq www log&amp;nbsp;&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside_Arena 1500&lt;BR /&gt;ip local pool UKSSLUsers 172.31.0.200-172.31.0.240 mask 255.255.255.0&lt;BR /&gt;ip local pool AnyConnect 192.168.50.20-192.168.50.40 mask 255.255.255.0&lt;BR /&gt;ip local pool net-10 10.0.0.1-10.0.0.10 mask 255.255.255.0&lt;BR /&gt;ip local pool remotessl 10.11.1.2-10.11.1.20 mask 255.255.255.0&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-711.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;nat (inside,outside_Arena) source static obj-172.26.0.0 obj-172.26.0.0 destination static DM_INLINE_NETWORK_3 DM_INLINE_NETWORK_3 no-proxy-arp&lt;BR /&gt;nat (inside,outside_Arena) source static NETWORK_OBJ_172.26.0.0_24 NETWORK_OBJ_172.26.0.0_24 destination static DM_INLINE_NETWORK_5 DM_INLINE_NETWORK_5 no-proxy-arp route-lookup&lt;BR /&gt;!&lt;BR /&gt;object network FENDI_Laptop&lt;BR /&gt;&amp;nbsp;nat (inside,outside_Arena) static interface service tcp 3389 3389&amp;nbsp;&lt;BR /&gt;object network UK2008SRV_WEB&lt;BR /&gt;&amp;nbsp;nat (inside,outside_Arena) static interface service tcp www www&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;nat (inside,outside_Arena) after-auto source dynamic obj-172.26.0.0 interface&lt;BR /&gt;access-group inside_access_in in interface inside&lt;BR /&gt;access-group UK2008SRV-in in interface outside_Arena&lt;BR /&gt;route outside_Arena 0.0.0.0 0.0.0.0 95.130.99.129 180&lt;BR /&gt;route outside_Arena 172.20.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.23.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.26.0.19 255.255.255.255 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.27.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.30.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 192.168.0.0 255.255.252.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 193.120.165.154 255.255.255.255 95.130.99.129 1&lt;BR /&gt;route outside_Arena 194.44.55.5 255.255.255.255 95.130.99.129 1&lt;BR /&gt;route outside_Arena 194.44.136.114 255.255.255.255 95.130.99.129 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&amp;nbsp;&lt;BR /&gt;http server enable 8443&lt;BR /&gt;http 172.26.0.0 255.255.255.0 inside&lt;BR /&gt;http 194.44.136.114 255.255.255.255 outside_Arena&lt;BR /&gt;http 193.120.165.154 255.255.255.255 outside_Arena&lt;BR /&gt;http 194.44.55.0 255.255.255.0 outside_Arena&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;sysopt connection tcpmss 1350&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS esp-aes esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS esp-aes esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS esp-aes-192 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS esp-aes-192 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS esp-aes-256 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS esp-aes-256 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS esp-3des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS esp-3des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS esp-des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS esp-des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES256&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-256&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES192&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-192&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal 3DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption 3des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES&lt;BR /&gt;crypto map outside_virgin_isp_map 1 match address outside_Arena_cryptomap&lt;BR /&gt;crypto map outside_virgin_isp_map 1 set peer 193.120.165.154&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 1 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_virgin_isp_map 2 match address outside_Arena_cryptomap_1&lt;BR /&gt;crypto map outside_virgin_isp_map 2 set pfs&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 2 set peer 80.88.92.105&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 2 set ikev1 transform-set ESP-3DES-SHA ESP-AES-256-SHA&lt;BR /&gt;crypto map outside_virgin_isp_map 5 match address outside_virgin_isp_cryptomap_1&lt;BR /&gt;crypto map outside_virgin_isp_map 5 set peer 194.44.136.114&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 5 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_virgin_isp_map 6 match address outside_virgin_isp_cryptomap_2&lt;BR /&gt;crypto map outside_virgin_isp_map 6 set peer 212.87.74.171&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 6 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_virgin_isp_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map outside_virgin_isp_map interface outside_Arena&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint0&lt;BR /&gt;&amp;nbsp;enrollment self&lt;BR /&gt;&amp;nbsp;fqdn vpnuk.lynq.co.uk&lt;BR /&gt;&amp;nbsp;subject-name CN=LYNQUKASA&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint0&lt;BR /&gt;&amp;nbsp;certificate 5b0ba155&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 308201e1 3082014a a0030201 0202045b 0ba15530 0d06092a 864886f7 0d010105&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 05003035 31123010 06035504 0313094c 594e5155 4b415341 311f301d 06092a86&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 4886f70d 01090216 1076706e 756b2e6c 796e712e 636f2e75 6b301e17 0d313530&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 37323231 30323635 395a170d 32353037 31393130 32363539 5a303531 12301006&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 03550403 13094c59 4e51554b 41534131 1f301d06 092a8648 86f70d01 09021610&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 76706e75 6b2e6c79 6e712e63 6f2e756b 30819f30 0d06092a 864886f7 0d010101&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 05000381 8d003081 89028181 00b34b55 c66162ec f3fb376f 9f24491e a71b931e&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 3332434d f826ed42 ea1620fb 4cfa0ee1 6080fb0c e1b3470e 1a6b8bc2 8f7234c6&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; e65616e3 362bea14 9f45f49d 5f919c14 1f98986b a579b466 21149480 3b75ebe9&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 826116a0 92811587 1cffb55a 895a4a52 e2b5243c 1dccfe5d 3347a8f6 55235e2f&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 990a4f09 0cb3af08 34f538fa 21020301 0001300d 06092a86 4886f70d 01010505&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 00038181 0055e50c def67359 c835c88a 69527106 1272ca5f c1834613 4bbe4d9c&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 4fb0c526 b79b7836 257a38ff 11550295 ef0c54ad 71fcd7ed d030d150 6a4ddc80&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 6068b088 de6c656f 0591223d e03d93de 04191ab6 3280332a 5cb2e489 e0aabf4c&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; b92c609a 87d5d784 7119f96b f004005c 717877fc 66bd8abc fd6d8a5d 11f2ff23&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 3a9059ed be&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ikev2 policy 1&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 10&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 20&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 30&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 40&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 enable outside_Arena client-services port 443&lt;BR /&gt;crypto ikev2 remote-access trustpoint ASDM_TrustPoint0&lt;BR /&gt;crypto ikev1 enable outside_Arena&lt;BR /&gt;crypto ikev1 policy 5&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 28800&lt;BR /&gt;!&lt;BR /&gt;track 1 rtr 123 reachability&lt;BR /&gt;!&lt;BR /&gt;track 100 rtr 1 reachability&lt;BR /&gt;telnet 172.26.0.0 255.255.255.0 inside&lt;BR /&gt;telnet 172.26.0.0 255.255.0.0 inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh 172.26.0.0 255.255.255.0 inside&lt;BR /&gt;ssh 194.44.136.114 255.255.255.255 outside_Arena&lt;BR /&gt;ssh 193.120.165.154 255.255.255.255 outside_Arena&lt;BR /&gt;ssh 194.44.55.0 255.255.255.0 outside_Arena&lt;BR /&gt;ssh timeout 30&lt;BR /&gt;console timeout 0&lt;BR /&gt;vpdn group BTFibre request dialout pppoe&lt;BR /&gt;vpdn group BTFibre localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group BTFibre ppp authentication chap&lt;BR /&gt;vpdn group btpppoe request dialout pppoe&lt;BR /&gt;vpdn group btpppoe localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group btpppoe ppp authentication pap&lt;BR /&gt;vpdn group bt_pppoe request dialout pppoe&lt;BR /&gt;vpdn group bt_pppoe localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group bt_pppoe ppp authentication pap&lt;BR /&gt;vpdn group PPPOE_BT request dialout pppoe&lt;BR /&gt;vpdn group PPPOE_BT localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group PPPOE_BT ppp authentication pap&lt;BR /&gt;vpdn group BTDSL request dialout pppoe&lt;BR /&gt;vpdn group BTDSL localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group BTDSL ppp authentication pap&lt;BR /&gt;vpdn group D203277@hg52.btclick.com request dialout pppoe&lt;BR /&gt;vpdn group D203277@hg52.btclick.com localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group D203277@hg52.btclick.com ppp authentication chap&lt;BR /&gt;vpdn username D203277@hg52.btclick.com password password1 store-local&lt;BR /&gt;vpdn username 01329221836@talktalkbusiness.net password J7R5K6F2J6 store-local&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;ntp server 65.55.56.206&lt;BR /&gt;tftp-server inside 172.26.0.26 \&lt;BR /&gt;ssl trust-point ASDM_TrustPoint0 outside_Arena&lt;BR /&gt;webvpn&lt;BR /&gt;&amp;nbsp;enable outside_Arena&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-win-2.5.2014-k9.pkg 1&lt;BR /&gt;&amp;nbsp;anyconnect enable&lt;BR /&gt;&amp;nbsp;tunnel-group-list enable&lt;BR /&gt;group-policy DfltGrpPolicy attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 l2tp-ipsec ssl-clientless&lt;BR /&gt;group-policy GroupPolicy_RemoteSSL internal&lt;BR /&gt;group-policy GroupPolicy_RemoteSSL attributes&lt;BR /&gt;&amp;nbsp;wins-server none&lt;BR /&gt;&amp;nbsp;dns-server value 172.26.0.25&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ssl-client&amp;nbsp;&lt;BR /&gt;&amp;nbsp;split-tunnel-policy tunnelspecified&lt;BR /&gt;&amp;nbsp;split-tunnel-network-list value SplitTunnel&lt;BR /&gt;&amp;nbsp;default-domain value lynq.co.uk&lt;BR /&gt;group-policy GroupPolicy_80.88.92.105 internal&lt;BR /&gt;group-policy GroupPolicy_80.88.92.105 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1&amp;nbsp;&lt;BR /&gt;group-policy GroupPolicy_194.44.136.114 internal&lt;BR /&gt;group-policy GroupPolicy_194.44.136.114 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1&amp;nbsp;&lt;BR /&gt;group-policy GroupPolicy_193.120.165.154 internal&lt;BR /&gt;group-policy GroupPolicy_193.120.165.154 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1&amp;nbsp;&lt;BR /&gt;username tdb.admin password 66rOScYvr6BoMfol encrypted privilege 15&lt;BR /&gt;username paul.synnott password 3UDjotP6R7/M6C0B encrypted privilege 15&lt;BR /&gt;username sarah.kingswell password 5XyGsYkEdLoWOQiY encrypted privilege 15&lt;BR /&gt;username pete.hayes password aKXo6uAmPQjnwJ6q encrypted&lt;BR /&gt;username taras.chuhay password Yxj1fcjQ/tmX15oH encrypted privilege 15&lt;BR /&gt;username sean.timmins password ChKbOC6xl/qpg0kj encrypted privilege 15&lt;BR /&gt;username ciaran.raftery password 7IlPp0OBHDtzh4gY encrypted privilege 15&lt;BR /&gt;username colm.admin password 2MIbxjKQswsLMY/w encrypted privilege 15&lt;BR /&gt;tunnel-group 193.120.165.154 type ipsec-l2l&lt;BR /&gt;tunnel-group 193.120.165.154 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_193.120.165.154&lt;BR /&gt;tunnel-group 193.120.165.154 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;tunnel-group 194.44.136.114 type ipsec-l2l&lt;BR /&gt;tunnel-group 194.44.136.114 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_194.44.136.114&lt;BR /&gt;tunnel-group 194.44.136.114 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;tunnel-group 212.87.74.171 type ipsec-l2l&lt;BR /&gt;tunnel-group 212.87.74.171 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;tunnel-group RemoteSSL type remote-access&lt;BR /&gt;tunnel-group RemoteSSL general-attributes&lt;BR /&gt;&amp;nbsp;address-pool remotessl&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_RemoteSSL&lt;BR /&gt;tunnel-group RemoteSSL webvpn-attributes&lt;BR /&gt;&amp;nbsp;group-alias RemoteSSL enable&lt;BR /&gt;tunnel-group 80.88.92.105 type ipsec-l2l&lt;BR /&gt;tunnel-group 80.88.92.105 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_80.88.92.105&lt;BR /&gt;tunnel-group 80.88.92.105 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;&amp;nbsp;peer-id-validate nocheck&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 h225&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 ras&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rsh&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rtsp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect esmtp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sqlnet&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect xdmcp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect tftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect pptp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ip-options&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&amp;nbsp;&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt;&amp;nbsp;profile CiscoTAC-1&lt;BR /&gt;&amp;nbsp; no active&lt;BR /&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;BR /&gt;&amp;nbsp; destination transport-method http&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:c1da252a320bfa812b6b7fc3bb48f9eb&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jul 2015 12:48:55 GMT</pubDate>
    <dc:creator>sarah.kingswell1</dc:creator>
    <dc:date>2015-07-30T12:48:55Z</dc:date>
    <item>
      <title>Port Forwarding on ASA 5505 Not Working... Help!</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-on-asa-5505-not-working-help/m-p/2692662#M193219</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I am attempting to setup a RDP Port Forward on my ASA 5505 but I am unable to access the host on the inside of the network from outside the network. &amp;nbsp;I have created the correct NAT Rules and Access Rules (I think) but still it does not work. &amp;nbsp;I can RDP the internal IP of the host and cannot see any firewall that would restrict&amp;nbsp;connections from the&amp;nbsp;outside interface to this host.&lt;/P&gt;&lt;P&gt;Internal Host = 172.26.0.19&lt;BR /&gt;External Interface = Outside_Arena&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried to configure with both CLI and ASDM. &amp;nbsp;Have used the following commands in the CLI&lt;/P&gt;&lt;P&gt;object network FENDI_Laptop&lt;BR /&gt;host 172.26.0.19&lt;BR /&gt;nat (inside,outside) static interface service tcp 3389 3389&lt;/P&gt;&lt;P&gt;access-list FENDI-in extended permit tcp any host 172.26.0.19 eq 3389 log&lt;BR /&gt;access-group FENDI-in in interface outside_Arena&lt;/P&gt;&lt;P&gt;Please help I have spent hours trying to get this working and totally stuck. &amp;nbsp;&lt;/P&gt;&lt;P&gt;Result of the command: "show config"&lt;BR /&gt;!&lt;BR /&gt;ASA Version 8.4(2)&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;hostname ********&lt;BR /&gt;domain-name ********&lt;BR /&gt;enable password ********&amp;nbsp;encrypted&lt;BR /&gt;passwd ********&amp;nbsp;encrypted&lt;BR /&gt;no names&lt;BR /&gt;name 172.26.0.32 DEMO.ILYNQ.COM_InternalIP description Used in NAT rule for port redir of pts 81 and 3389&lt;BR /&gt;name 172.26.0.26 UKFS_InternalIP description Used in NAT rule to port redirect FTP pt 21&lt;BR /&gt;name 92.237.118.233 VIRGIN_ISP_Gateway&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;&amp;nbsp;switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;&amp;nbsp;switchport access vlan 32&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;interface Vlan12&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 172.26.0.1 255.255.255.0&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface Vlan32&lt;BR /&gt;&amp;nbsp;nameif outside_Arena&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 95.130.99.137 255.255.255.240&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa842-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone GMT/BST 0&lt;BR /&gt;clock summer-time GMT/BDT recurring last Sun Mar 1:00 last Sun Oct 2:00&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;&amp;nbsp;domain-name lynq.co.uk&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network obj-172.26.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.26.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.29.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.29.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.27.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.27.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.23.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.23.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.25.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.25.0.0 255.255.255.0&lt;BR /&gt;object network obj-192.168.0.0&lt;BR /&gt;&amp;nbsp;subnet 192.168.0.0 255.255.252.0&lt;BR /&gt;object network obj-10.100.100.0&lt;BR /&gt;&amp;nbsp;subnet 10.100.100.0 255.255.255.0&lt;BR /&gt;object network obj-172.22.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.22.0.0 255.255.255.0&lt;BR /&gt;object network obj-192.168.40.0&lt;BR /&gt;&amp;nbsp;subnet 192.168.40.0 255.255.255.0&lt;BR /&gt;object network obj-172.20.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.20.0.0 255.255.255.0&lt;BR /&gt;object network obj-92.237.118.236&lt;BR /&gt;&amp;nbsp;host 92.237.118.236&lt;BR /&gt;object service obj-tcp-source-eq-80&lt;BR /&gt;&amp;nbsp;service tcp source eq www&amp;nbsp;&lt;BR /&gt;object service obj-tcp-source-eq-21&lt;BR /&gt;&amp;nbsp;service tcp source eq ftp&amp;nbsp;&lt;BR /&gt;object network obj-172.26.0.132&lt;BR /&gt;&amp;nbsp;host 172.26.0.132&lt;BR /&gt;object network obj-92.237.118.237&lt;BR /&gt;&amp;nbsp;host 92.237.118.237&lt;BR /&gt;object service obj-tcp-source-eq-3389&lt;BR /&gt;&amp;nbsp;service tcp source eq 3389&amp;nbsp;&lt;BR /&gt;object network obj-172.26.0.107&lt;BR /&gt;&amp;nbsp;host 172.26.0.107&lt;BR /&gt;object network obj-92.237.118.238&lt;BR /&gt;&amp;nbsp;host 92.237.118.238&lt;BR /&gt;object network obj-92.237.118.235&lt;BR /&gt;&amp;nbsp;host 92.237.118.235&lt;BR /&gt;object network BT_ISP_Gateway&lt;BR /&gt;&amp;nbsp;host 81.138.134.30&lt;BR /&gt;&amp;nbsp;description BT ISP Router&lt;BR /&gt;object network obj-172.26.0.26&lt;BR /&gt;&amp;nbsp;host 172.26.0.26&lt;BR /&gt;&amp;nbsp;description FTP server&lt;BR /&gt;object service ftp&lt;BR /&gt;&amp;nbsp;service tcp source eq ftp destination range 1 65535&amp;nbsp;&lt;BR /&gt;object network BT_NatHidingStaticIP&lt;BR /&gt;&amp;nbsp;host 81.138.134.25&lt;BR /&gt;object network NETWORK_OBJ_172.26.0.0_24&lt;BR /&gt;&amp;nbsp;subnet 172.26.0.0 255.255.255.0&lt;BR /&gt;object network NETWORK_OBJ_172.30.0.0_24&lt;BR /&gt;&amp;nbsp;subnet 172.30.0.0 255.255.255.0&lt;BR /&gt;object network NETWORK_OBJ_172.31.0.0_25&lt;BR /&gt;&amp;nbsp;subnet 172.31.0.0 255.255.255.128&lt;BR /&gt;object network obj-172.30.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.30.0.0 255.255.255.0&lt;BR /&gt;object network NETWORK_OBJ_172.31.0.192_26&lt;BR /&gt;&amp;nbsp;subnet 172.31.0.192 255.255.255.192&lt;BR /&gt;object network NETWORK_OBJ_192.168.50.0_26&lt;BR /&gt;&amp;nbsp;subnet 192.168.50.0 255.255.255.192&lt;BR /&gt;object network NETWORK_OBJ_10.0.0.0_28&lt;BR /&gt;&amp;nbsp;subnet 10.0.0.0 255.255.255.240&lt;BR /&gt;object network NETWORK_OBJ_10.11.1.0_27&lt;BR /&gt;&amp;nbsp;subnet 10.11.1.0 255.255.255.224&lt;BR /&gt;object network 172.26.0.19&lt;BR /&gt;&amp;nbsp;host 172.26.0.19&lt;BR /&gt;object service 8080&lt;BR /&gt;&amp;nbsp;service tcp source eq 8080 destination eq 8080&amp;nbsp;&lt;BR /&gt;object network Clarke-Aruba&lt;BR /&gt;&amp;nbsp;subnet 172.31.0.0 255.255.255.0&lt;BR /&gt;object network FENDI_Laptop&lt;BR /&gt;&amp;nbsp;host 172.26.0.19&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_1&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_2&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group service DM_INLINE_TCP_1 tcp&lt;BR /&gt;&amp;nbsp;port-object eq 3389&lt;BR /&gt;&amp;nbsp;port-object eq 3390&lt;BR /&gt;&amp;nbsp;port-object eq 81&lt;BR /&gt;&amp;nbsp;port-object eq 82&lt;BR /&gt;&amp;nbsp;port-object eq ftp&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;object-group network DM_INLINE_NETWORK_2&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.235&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.236&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.237&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.238&lt;BR /&gt;object-group service DM_INLINE_TCP_2 tcp&lt;BR /&gt;&amp;nbsp;port-object eq 3389&lt;BR /&gt;&amp;nbsp;port-object eq 81&lt;BR /&gt;&amp;nbsp;port-object eq 82&lt;BR /&gt;&amp;nbsp;port-object eq ftp&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;&amp;nbsp;port-object eq https&lt;BR /&gt;object-group service DM_INLINE_TCP_3 tcp&lt;BR /&gt;&amp;nbsp;port-object eq 3389&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;object-group network DM_INLINE_NETWORK_3&lt;BR /&gt;&amp;nbsp;network-object object obj-172.20.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.29.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-192.168.40.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.23.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.25.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-10.100.100.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.22.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-192.168.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.27.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.30.0.0&lt;BR /&gt;&amp;nbsp;network-object object Clarke-Aruba&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_5&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_3&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_4&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group protocol DM_INLINE_PROTOCOL_1&lt;BR /&gt;&amp;nbsp;protocol-object ip&lt;BR /&gt;&amp;nbsp;protocol-object icmp&lt;BR /&gt;object-group network DM_INLINE_NETWORK_1&lt;BR /&gt;&amp;nbsp;network-object 172.27.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.20.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.29.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-192.168.40.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_4&lt;BR /&gt;&amp;nbsp;network-object 172.30.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object object Clarke-Aruba&lt;BR /&gt;object-group network DM_INLINE_NETWORK_5&lt;BR /&gt;&amp;nbsp;network-object object Clarke-Aruba&lt;BR /&gt;&amp;nbsp;network-object object NETWORK_OBJ_172.30.0.0_24&lt;BR /&gt;access-list inside_nat_outbound extended permit ip 172.26.0.0 255.255.255.0 any&amp;nbsp;&lt;BR /&gt;access-list inside_access_in extended permit ip 172.26.0.0 255.255.255.0 any&amp;nbsp;&lt;BR /&gt;access-list inside_access_in extended permit icmp any any object-group DM_INLINE_ICMP_1&amp;nbsp;&lt;BR /&gt;access-list inside_access_in extended permit tcp any any&amp;nbsp;&lt;BR /&gt;access-list dmz_access_in extended permit icmp any any object-group DM_INLINE_ICMP_2&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 172.23.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 172.25.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 192.168.0.0 255.255.252.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 10.100.100.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 172.22.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list outside_Arena_cryptomap extended permit ip 172.26.0.0 255.255.255.0 object-group DM_INLINE_NETWORK_1&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in extended permit icmp any any object-group DM_INLINE_ICMP_3&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_cryptomap_1 extended permit ip 172.26.0.0 255.255.255.0 172.23.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list outside_bt_isp_access_in extended permit icmp any any object-group DM_INLINE_ICMP_5&amp;nbsp;&lt;BR /&gt;access-list outside_bt_isp_access_in extended permit tcp any any eq ftp&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit icmp any any object-group DM_INLINE_ICMP_4&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit object-group DM_INLINE_PROTOCOL_1 any 192.168.0.0 255.255.252.0&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit ip host 80.88.92.106 any&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit icmp any any&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_cryptomap_2 extended permit ip 172.26.0.0 255.255.255.0 object obj-10.100.100.0&amp;nbsp;&lt;BR /&gt;access-list outside_Arena_cryptomap_1 extended permit ip 172.26.0.0 255.255.255.0 object-group DM_INLINE_NETWORK_4&amp;nbsp;&lt;BR /&gt;access-list SplitTunnel standard permit 172.26.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list NAT-EXEMPT extended permit ip 172.26.0.0 255.255.255.0 10.11.1.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list FENDI-in extended permit tcp any host 172.26.0.19 eq 3389 log&amp;nbsp;&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside_Arena 1500&lt;BR /&gt;ip local pool UKSSLUsers 172.31.0.200-172.31.0.240 mask 255.255.255.0&lt;BR /&gt;ip local pool AnyConnect 192.168.50.20-192.168.50.40 mask 255.255.255.0&lt;BR /&gt;ip local pool net-10 10.0.0.1-10.0.0.10 mask 255.255.255.0&lt;BR /&gt;ip local pool remotessl 10.11.1.2-10.11.1.20 mask 255.255.255.0&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-711.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;nat (inside,outside_Arena) source static obj-172.26.0.0 obj-172.26.0.0 destination static DM_INLINE_NETWORK_3 DM_INLINE_NETWORK_3 no-proxy-arp&lt;BR /&gt;nat (inside,outside_Arena) source dynamic obj-172.26.0.0 interface&lt;BR /&gt;nat (inside,outside_Arena) source static NETWORK_OBJ_172.26.0.0_24 NETWORK_OBJ_172.26.0.0_24 destination static DM_INLINE_NETWORK_5 DM_INLINE_NETWORK_5 no-proxy-arp route-lookup&lt;BR /&gt;!&lt;BR /&gt;object network FENDI_Laptop&lt;BR /&gt;&amp;nbsp;nat (inside,outside_Arena) static interface service tcp 3389 3389&amp;nbsp;&lt;BR /&gt;access-group inside_access_in in interface inside&lt;BR /&gt;access-group FENDI-in in interface outside_Arena&lt;BR /&gt;route outside_Arena 0.0.0.0 0.0.0.0 95.130.99.129 180&lt;BR /&gt;route outside_Arena 172.20.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.23.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.26.0.19 255.255.255.255 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.27.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.30.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 192.168.0.0 255.255.252.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 193.120.165.154 255.255.255.255 95.130.99.129 1&lt;BR /&gt;route outside_Arena 194.44.55.5 255.255.255.255 95.130.99.129 1&lt;BR /&gt;route outside_Arena 194.44.136.114 255.255.255.255 95.130.99.129 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&amp;nbsp;&lt;BR /&gt;http server enable 8443&lt;BR /&gt;http 172.26.0.0 255.255.255.0 inside&lt;BR /&gt;http 194.44.136.114 255.255.255.255 outside_Arena&lt;BR /&gt;http 193.120.165.154 255.255.255.255 outside_Arena&lt;BR /&gt;http 194.44.55.0 255.255.255.0 outside_Arena&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;sysopt connection tcpmss 1350&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS esp-aes esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS esp-aes esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS esp-aes-192 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS esp-aes-192 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS esp-aes-256 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS esp-aes-256 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS esp-3des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS esp-3des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS esp-des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS esp-des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal 3DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption 3des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES192&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-192&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES256&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-256&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES&lt;BR /&gt;crypto map outside_virgin_isp_map 1 match address outside_Arena_cryptomap&lt;BR /&gt;crypto map outside_virgin_isp_map 1 set peer 193.120.165.154&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 1 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_virgin_isp_map 2 match address outside_Arena_cryptomap_1&lt;BR /&gt;crypto map outside_virgin_isp_map 2 set pfs&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 2 set peer 80.88.92.105&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 2 set ikev1 transform-set ESP-3DES-SHA ESP-AES-256-SHA&lt;BR /&gt;crypto map outside_virgin_isp_map 5 match address outside_virgin_isp_cryptomap_1&lt;BR /&gt;crypto map outside_virgin_isp_map 5 set peer 194.44.136.114&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 5 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_virgin_isp_map 6 match address outside_virgin_isp_cryptomap_2&lt;BR /&gt;crypto map outside_virgin_isp_map 6 set peer 212.87.74.171&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 6 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_virgin_isp_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map outside_virgin_isp_map interface outside_Arena&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint0&lt;BR /&gt;&amp;nbsp;enrollment self&lt;BR /&gt;&amp;nbsp;fqdn vpnuk.lynq.co.uk&lt;BR /&gt;&amp;nbsp;subject-name CN=LYNQUKASA&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint0&lt;BR /&gt;&amp;nbsp;certificate 5b0ba155&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 308201e1 3082014a a0030201 0202045b 0ba15530 0d06092a 864886f7 0d010105&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 05003035 31123010 06035504 0313094c 594e5155 4b415341 311f301d 06092a86&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 4886f70d 01090216 1076706e 756b2e6c 796e712e 636f2e75 6b301e17 0d313530&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 37323231 30323635 395a170d 32353037 31393130 32363539 5a303531 12301006&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 03550403 13094c59 4e51554b 41534131 1f301d06 092a8648 86f70d01 09021610&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 76706e75 6b2e6c79 6e712e63 6f2e756b 30819f30 0d06092a 864886f7 0d010101&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 05000381 8d003081 89028181 00b34b55 c66162ec f3fb376f 9f24491e a71b931e&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 3332434d f826ed42 ea1620fb 4cfa0ee1 6080fb0c e1b3470e 1a6b8bc2 8f7234c6&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; e65616e3 362bea14 9f45f49d 5f919c14 1f98986b a579b466 21149480 3b75ebe9&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 826116a0 92811587 1cffb55a 895a4a52 e2b5243c 1dccfe5d 3347a8f6 55235e2f&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 990a4f09 0cb3af08 34f538fa 21020301 0001300d 06092a86 4886f70d 01010505&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 00038181 0055e50c def67359 c835c88a 69527106 1272ca5f c1834613 4bbe4d9c&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 4fb0c526 b79b7836 257a38ff 11550295 ef0c54ad 71fcd7ed d030d150 6a4ddc80&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 6068b088 de6c656f 0591223d e03d93de 04191ab6 3280332a 5cb2e489 e0aabf4c&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; b92c609a 87d5d784 7119f96b f004005c 717877fc 66bd8abc fd6d8a5d 11f2ff23&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 3a9059ed be&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ikev2 policy 1&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 10&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 20&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 30&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 40&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 enable outside_Arena client-services port 443&lt;BR /&gt;crypto ikev2 remote-access trustpoint ASDM_TrustPoint0&lt;BR /&gt;crypto ikev1 enable outside_Arena&lt;BR /&gt;crypto ikev1 policy 5&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 28800&lt;BR /&gt;!&lt;BR /&gt;track 1 rtr 123 reachability&lt;BR /&gt;!&lt;BR /&gt;track 100 rtr 1 reachability&lt;BR /&gt;telnet 172.26.0.0 255.255.255.0 inside&lt;BR /&gt;telnet 172.26.0.0 255.255.0.0 inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh 172.26.0.0 255.255.255.0 inside&lt;BR /&gt;ssh 194.44.136.114 255.255.255.255 outside_Arena&lt;BR /&gt;ssh 193.120.165.154 255.255.255.255 outside_Arena&lt;BR /&gt;ssh 194.44.55.0 255.255.255.0 outside_Arena&lt;BR /&gt;ssh timeout 30&lt;BR /&gt;console timeout 0&lt;BR /&gt;vpdn group BTFibre request dialout pppoe&lt;BR /&gt;vpdn group BTFibre localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group BTFibre ppp authentication chap&lt;BR /&gt;vpdn group btpppoe request dialout pppoe&lt;BR /&gt;vpdn group btpppoe localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group btpppoe ppp authentication pap&lt;BR /&gt;vpdn group bt_pppoe request dialout pppoe&lt;BR /&gt;vpdn group bt_pppoe localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group bt_pppoe ppp authentication pap&lt;BR /&gt;vpdn group PPPOE_BT request dialout pppoe&lt;BR /&gt;vpdn group PPPOE_BT localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group PPPOE_BT ppp authentication pap&lt;BR /&gt;vpdn group BTDSL request dialout pppoe&lt;BR /&gt;vpdn group BTDSL localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group BTDSL ppp authentication pap&lt;BR /&gt;vpdn group D203277@hg52.btclick.com request dialout pppoe&lt;BR /&gt;vpdn group D203277@hg52.btclick.com localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group D203277@hg52.btclick.com ppp authentication chap&lt;BR /&gt;vpdn username D203277@hg52.btclick.com password password1 store-local&lt;BR /&gt;vpdn username 01329221836@talktalkbusiness.net password J7R5K6F2J6 store-local&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;ntp server 65.55.56.206&lt;BR /&gt;tftp-server inside 172.26.0.26 \&lt;BR /&gt;ssl trust-point ASDM_TrustPoint0 outside_Arena&lt;BR /&gt;webvpn&lt;BR /&gt;&amp;nbsp;enable outside_Arena&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-win-2.5.2014-k9.pkg 1&lt;BR /&gt;&amp;nbsp;anyconnect enable&lt;BR /&gt;&amp;nbsp;tunnel-group-list enable&lt;BR /&gt;group-policy DfltGrpPolicy attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 l2tp-ipsec ssl-clientless&lt;BR /&gt;group-policy GroupPolicy_RemoteSSL internal&lt;BR /&gt;group-policy GroupPolicy_RemoteSSL attributes&lt;BR /&gt;&amp;nbsp;wins-server none&lt;BR /&gt;&amp;nbsp;dns-server value 172.26.0.25&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ssl-client&amp;nbsp;&lt;BR /&gt;&amp;nbsp;split-tunnel-policy tunnelspecified&lt;BR /&gt;&amp;nbsp;split-tunnel-network-list value SplitTunnel&lt;BR /&gt;&amp;nbsp;default-domain value lynq.co.uk&lt;BR /&gt;group-policy GroupPolicy_80.88.92.105 internal&lt;BR /&gt;group-policy GroupPolicy_80.88.92.105 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1&amp;nbsp;&lt;BR /&gt;group-policy GroupPolicy_194.44.136.114 internal&lt;BR /&gt;group-policy GroupPolicy_194.44.136.114 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1&amp;nbsp;&lt;BR /&gt;group-policy GroupPolicy_193.120.165.154 internal&lt;BR /&gt;group-policy GroupPolicy_193.120.165.154 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1&amp;nbsp;&lt;BR /&gt;username tdb.admin password 66rOScYvr6BoMfol encrypted privilege 15&lt;BR /&gt;username paul.synnott password 3UDjotP6R7/M6C0B encrypted privilege 15&lt;BR /&gt;username sarah.kingswell password 5XyGsYkEdLoWOQiY encrypted privilege 15&lt;BR /&gt;username pete.hayes password aKXo6uAmPQjnwJ6q encrypted&lt;BR /&gt;username taras.chuhay password Yxj1fcjQ/tmX15oH encrypted privilege 15&lt;BR /&gt;username sean.timmins password ChKbOC6xl/qpg0kj encrypted privilege 15&lt;BR /&gt;username ciaran.raftery password 7IlPp0OBHDtzh4gY encrypted privilege 15&lt;BR /&gt;username colm.admin password 2MIbxjKQswsLMY/w encrypted privilege 15&lt;BR /&gt;tunnel-group 193.120.165.154 type ipsec-l2l&lt;BR /&gt;tunnel-group 193.120.165.154 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_193.120.165.154&lt;BR /&gt;tunnel-group 193.120.165.154 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;tunnel-group 194.44.136.114 type ipsec-l2l&lt;BR /&gt;tunnel-group 194.44.136.114 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_194.44.136.114&lt;BR /&gt;tunnel-group 194.44.136.114 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;tunnel-group 212.87.74.171 type ipsec-l2l&lt;BR /&gt;tunnel-group 212.87.74.171 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;tunnel-group RemoteSSL type remote-access&lt;BR /&gt;tunnel-group RemoteSSL general-attributes&lt;BR /&gt;&amp;nbsp;address-pool remotessl&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_RemoteSSL&lt;BR /&gt;tunnel-group RemoteSSL webvpn-attributes&lt;BR /&gt;&amp;nbsp;group-alias RemoteSSL enable&lt;BR /&gt;tunnel-group 80.88.92.105 type ipsec-l2l&lt;BR /&gt;tunnel-group 80.88.92.105 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_80.88.92.105&lt;BR /&gt;tunnel-group 80.88.92.105 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;&amp;nbsp;peer-id-validate nocheck&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 h225&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 ras&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rsh&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rtsp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect esmtp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sqlnet&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect xdmcp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect tftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect pptp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ip-options&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&amp;nbsp;&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt;&amp;nbsp;profile CiscoTAC-1&lt;BR /&gt;&amp;nbsp; no active&lt;BR /&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;BR /&gt;&amp;nbsp; destination transport-method http&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:c4d9ca18191a497c2a0aeb37c3c1a5d0&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:21:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-on-asa-5505-not-working-help/m-p/2692662#M193219</guid>
      <dc:creator>sarah.kingswell1</dc:creator>
      <dc:date>2019-03-12T06:21:26Z</dc:date>
    </item>
    <item>
      <title>one of the most common</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-on-asa-5505-not-working-help/m-p/2692663#M193221</link>
      <description>&lt;P&gt;one of the most common mistakes: The order of the NAT-statements is wrong:&lt;/P&gt;

&lt;PRE&gt;
&lt;SPAN style="font-size: 14px;"&gt;no nat (inside,outside_Arena) source dynamic obj-172.26.0.0 interface&lt;/SPAN&gt;
&lt;SPAN style="font-size: 14px;"&gt;nat (inside,outside_Arena) after-auto source dynamic obj-172.26.0.0 interface&lt;/SPAN&gt;
&lt;/PRE&gt;</description>
      <pubDate>Thu, 30 Jul 2015 10:37:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-on-asa-5505-not-working-help/m-p/2692663#M193221</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-07-30T10:37:05Z</dc:date>
    </item>
    <item>
      <title>Thanks Karsten - How do I</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-on-asa-5505-not-working-help/m-p/2692664#M193223</link>
      <description>&lt;P&gt;Thanks Karsten -&amp;nbsp;How do I correct the order? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2015 10:48:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-on-asa-5505-not-working-help/m-p/2692664#M193223</guid>
      <dc:creator>sarah.kingswell1</dc:creator>
      <dc:date>2015-07-30T10:48:33Z</dc:date>
    </item>
    <item>
      <title>The solution is directly in</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-on-asa-5505-not-working-help/m-p/2692665#M193225</link>
      <description>&lt;P&gt;The solution is directly in front of you, just look about 10&amp;nbsp;cm above ... &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2015 10:55:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-on-asa-5505-not-working-help/m-p/2692665#M193225</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-07-30T10:55:53Z</dc:date>
    </item>
    <item>
      <title>Yep, thanks it's working now</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-on-asa-5505-not-working-help/m-p/2692666#M193227</link>
      <description>&lt;P&gt;Yep, thanks it's working now&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2015 10:57:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-on-asa-5505-not-working-help/m-p/2692666#M193227</guid>
      <dc:creator>sarah.kingswell1</dc:creator>
      <dc:date>2015-07-30T10:57:41Z</dc:date>
    </item>
    <item>
      <title>I have now managed to break</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-on-asa-5505-not-working-help/m-p/2692667#M193230</link>
      <description>&lt;P&gt;I have now managed to break it by adding another port forward this time to another subnet that is connected by VPN.&lt;/P&gt;&lt;P&gt;The command I have run from the CLI&lt;/P&gt;&lt;P&gt;object network UK2008SRV_WEB&lt;BR /&gt;host 172.27.0.136&lt;BR /&gt;nat (inside,outside) static interface service tcp 80 80&lt;/P&gt;&lt;P&gt;access-list UK2008SRV-in extended permit tcp any host 172.27.0.136 eq 80 log&lt;BR /&gt;access-group UK2008SRV-in in interface outside_Arena&lt;/P&gt;&lt;P&gt;How do I now fix to get both port forwards working? &amp;nbsp;Sorry this is confusing..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result of the command: "show config"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ASA Version 8.4(2)&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;hostname LYNQUKASA&lt;BR /&gt;domain-name ********&lt;BR /&gt;enable password ******** encrypted&lt;BR /&gt;passwd ********&amp;nbsp;encrypted&lt;BR /&gt;no names&lt;BR /&gt;name 172.26.0.32 DEMO.ILYNQ.COM_InternalIP description Used in NAT rule for port redir of pts 81 and 3389&lt;BR /&gt;name 172.26.0.26 UKFS_InternalIP description Used in NAT rule to port redirect FTP pt 21&lt;BR /&gt;name 92.237.118.233 VIRGIN_ISP_Gateway&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;&amp;nbsp;switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;&amp;nbsp;switchport access vlan 32&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;interface Vlan12&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 172.26.0.1 255.255.255.0&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface Vlan32&lt;BR /&gt;&amp;nbsp;nameif outside_Arena&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 95.130.99.137 255.255.255.240&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa842-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone GMT/BST 0&lt;BR /&gt;clock summer-time GMT/BDT recurring last Sun Mar 1:00 last Sun Oct 2:00&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;&amp;nbsp;domain-name lynq.co.uk&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network obj-172.26.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.26.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.29.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.29.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.27.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.27.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.23.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.23.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.25.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.25.0.0 255.255.255.0&lt;BR /&gt;object network obj-192.168.0.0&lt;BR /&gt;&amp;nbsp;subnet 192.168.0.0 255.255.252.0&lt;BR /&gt;object network obj-10.100.100.0&lt;BR /&gt;&amp;nbsp;subnet 10.100.100.0 255.255.255.0&lt;BR /&gt;object network obj-172.22.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.22.0.0 255.255.255.0&lt;BR /&gt;object network obj-192.168.40.0&lt;BR /&gt;&amp;nbsp;subnet 192.168.40.0 255.255.255.0&lt;BR /&gt;object network obj-172.20.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.20.0.0 255.255.255.0&lt;BR /&gt;object network obj-92.237.118.236&lt;BR /&gt;&amp;nbsp;host 92.237.118.236&lt;BR /&gt;object service obj-tcp-source-eq-80&lt;BR /&gt;&amp;nbsp;service tcp source eq www&amp;nbsp;&lt;BR /&gt;object service obj-tcp-source-eq-21&lt;BR /&gt;&amp;nbsp;service tcp source eq ftp&amp;nbsp;&lt;BR /&gt;object network obj-172.26.0.132&lt;BR /&gt;&amp;nbsp;host 172.26.0.132&lt;BR /&gt;object network obj-92.237.118.237&lt;BR /&gt;&amp;nbsp;host 92.237.118.237&lt;BR /&gt;object service obj-tcp-source-eq-3389&lt;BR /&gt;&amp;nbsp;service tcp source eq 3389&amp;nbsp;&lt;BR /&gt;object network obj-172.26.0.107&lt;BR /&gt;&amp;nbsp;host 172.26.0.107&lt;BR /&gt;object network obj-92.237.118.238&lt;BR /&gt;&amp;nbsp;host 92.237.118.238&lt;BR /&gt;object network obj-92.237.118.235&lt;BR /&gt;&amp;nbsp;host 92.237.118.235&lt;BR /&gt;object network BT_ISP_Gateway&lt;BR /&gt;&amp;nbsp;host 81.138.134.30&lt;BR /&gt;&amp;nbsp;description BT ISP Router&lt;BR /&gt;object network obj-172.26.0.26&lt;BR /&gt;&amp;nbsp;host 172.26.0.26&lt;BR /&gt;&amp;nbsp;description FTP server&lt;BR /&gt;object service ftp&lt;BR /&gt;&amp;nbsp;service tcp source eq ftp destination range 1 65535&amp;nbsp;&lt;BR /&gt;object network BT_NatHidingStaticIP&lt;BR /&gt;&amp;nbsp;host 81.138.134.25&lt;BR /&gt;object network NETWORK_OBJ_172.26.0.0_24&lt;BR /&gt;&amp;nbsp;subnet 172.26.0.0 255.255.255.0&lt;BR /&gt;object network NETWORK_OBJ_172.30.0.0_24&lt;BR /&gt;&amp;nbsp;subnet 172.30.0.0 255.255.255.0&lt;BR /&gt;object network NETWORK_OBJ_172.31.0.0_25&lt;BR /&gt;&amp;nbsp;subnet 172.31.0.0 255.255.255.128&lt;BR /&gt;object network obj-172.30.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.30.0.0 255.255.255.0&lt;BR /&gt;object network NETWORK_OBJ_172.31.0.192_26&lt;BR /&gt;&amp;nbsp;subnet 172.31.0.192 255.255.255.192&lt;BR /&gt;object network NETWORK_OBJ_192.168.50.0_26&lt;BR /&gt;&amp;nbsp;subnet 192.168.50.0 255.255.255.192&lt;BR /&gt;object network NETWORK_OBJ_10.0.0.0_28&lt;BR /&gt;&amp;nbsp;subnet 10.0.0.0 255.255.255.240&lt;BR /&gt;object network NETWORK_OBJ_10.11.1.0_27&lt;BR /&gt;&amp;nbsp;subnet 10.11.1.0 255.255.255.224&lt;BR /&gt;object network 172.26.0.19&lt;BR /&gt;&amp;nbsp;host 172.26.0.19&lt;BR /&gt;object service 8080&lt;BR /&gt;&amp;nbsp;service tcp source eq 8080 destination eq 8080&amp;nbsp;&lt;BR /&gt;object network Clarke-Aruba&lt;BR /&gt;&amp;nbsp;subnet 172.31.0.0 255.255.255.0&lt;BR /&gt;object network FENDI_Laptop&lt;BR /&gt;&amp;nbsp;host 172.26.0.19&lt;BR /&gt;object network 172.26.0.1&lt;BR /&gt;&amp;nbsp;host 172.26.0.1&lt;BR /&gt;&amp;nbsp;description Internal IP for Router&lt;BR /&gt;object network UK2008SRV_WEB&lt;BR /&gt;&amp;nbsp;host 172.27.0.136&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_1&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_2&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group service DM_INLINE_TCP_1 tcp&lt;BR /&gt;&amp;nbsp;port-object eq 3389&lt;BR /&gt;&amp;nbsp;port-object eq 3390&lt;BR /&gt;&amp;nbsp;port-object eq 81&lt;BR /&gt;&amp;nbsp;port-object eq 82&lt;BR /&gt;&amp;nbsp;port-object eq ftp&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;object-group network DM_INLINE_NETWORK_2&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.235&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.236&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.237&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.238&lt;BR /&gt;object-group service DM_INLINE_TCP_2 tcp&lt;BR /&gt;&amp;nbsp;port-object eq 3389&lt;BR /&gt;&amp;nbsp;port-object eq 81&lt;BR /&gt;&amp;nbsp;port-object eq 82&lt;BR /&gt;&amp;nbsp;port-object eq ftp&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;&amp;nbsp;port-object eq https&lt;BR /&gt;object-group service DM_INLINE_TCP_3 tcp&lt;BR /&gt;&amp;nbsp;port-object eq 3389&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;object-group network DM_INLINE_NETWORK_3&lt;BR /&gt;&amp;nbsp;network-object object obj-172.20.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.29.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-192.168.40.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.23.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.25.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-10.100.100.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.22.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-192.168.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.27.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.30.0.0&lt;BR /&gt;&amp;nbsp;network-object object Clarke-Aruba&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_5&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_3&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_4&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group protocol DM_INLINE_PROTOCOL_1&lt;BR /&gt;&amp;nbsp;protocol-object ip&lt;BR /&gt;&amp;nbsp;protocol-object icmp&lt;BR /&gt;object-group network DM_INLINE_NETWORK_1&lt;BR /&gt;&amp;nbsp;network-object 172.27.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.20.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.29.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-192.168.40.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_4&lt;BR /&gt;&amp;nbsp;network-object 172.30.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object object Clarke-Aruba&lt;BR /&gt;object-group network DM_INLINE_NETWORK_5&lt;BR /&gt;&amp;nbsp;network-object object Clarke-Aruba&lt;BR /&gt;&amp;nbsp;network-object object NETWORK_OBJ_172.30.0.0_24&lt;BR /&gt;object-group protocol DM_INLINE_PROTOCOL_2&lt;BR /&gt;&amp;nbsp;protocol-object udp&lt;BR /&gt;&amp;nbsp;protocol-object tcp&lt;BR /&gt;object-group protocol TCPUDP&lt;BR /&gt;&amp;nbsp;protocol-object udp&lt;BR /&gt;&amp;nbsp;protocol-object tcp&lt;BR /&gt;access-list inside_nat_outbound extended permit ip 172.26.0.0 255.255.255.0 any&amp;nbsp;&lt;BR /&gt;access-list inside_access_in extended permit ip 172.26.0.0 255.255.255.0 any&amp;nbsp;&lt;BR /&gt;access-list inside_access_in extended permit icmp any any object-group DM_INLINE_ICMP_1&amp;nbsp;&lt;BR /&gt;access-list inside_access_in extended permit object-group TCPUDP any any&amp;nbsp;&lt;BR /&gt;access-list dmz_access_in extended permit icmp any any object-group DM_INLINE_ICMP_2&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 172.23.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 172.25.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 192.168.0.0 255.255.252.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 10.100.100.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 172.22.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list outside_Arena_cryptomap extended permit ip 172.26.0.0 255.255.255.0 object-group DM_INLINE_NETWORK_1&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in extended permit icmp any any object-group DM_INLINE_ICMP_3&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_cryptomap_1 extended permit ip 172.26.0.0 255.255.255.0 172.23.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list outside_bt_isp_access_in extended permit icmp any any object-group DM_INLINE_ICMP_5&amp;nbsp;&lt;BR /&gt;access-list outside_bt_isp_access_in extended permit tcp any any eq ftp&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit icmp any any object-group DM_INLINE_ICMP_4&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit object-group DM_INLINE_PROTOCOL_1 any 192.168.0.0 255.255.252.0&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit ip host 80.88.92.106 any&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit icmp any any&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_cryptomap_2 extended permit ip 172.26.0.0 255.255.255.0 object obj-10.100.100.0&amp;nbsp;&lt;BR /&gt;access-list outside_Arena_cryptomap_1 extended permit ip 172.26.0.0 255.255.255.0 object-group DM_INLINE_NETWORK_4&amp;nbsp;&lt;BR /&gt;access-list SplitTunnel standard permit 172.26.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list NAT-EXEMPT extended permit ip 172.26.0.0 255.255.255.0 10.11.1.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list FENDI-in extended permit tcp any host 172.26.0.19 eq 3389 log&amp;nbsp;&lt;BR /&gt;access-list UK2008SRV-in extended permit tcp any host 172.27.0.136 eq www log&amp;nbsp;&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside_Arena 1500&lt;BR /&gt;ip local pool UKSSLUsers 172.31.0.200-172.31.0.240 mask 255.255.255.0&lt;BR /&gt;ip local pool AnyConnect 192.168.50.20-192.168.50.40 mask 255.255.255.0&lt;BR /&gt;ip local pool net-10 10.0.0.1-10.0.0.10 mask 255.255.255.0&lt;BR /&gt;ip local pool remotessl 10.11.1.2-10.11.1.20 mask 255.255.255.0&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-711.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;nat (inside,outside_Arena) source static obj-172.26.0.0 obj-172.26.0.0 destination static DM_INLINE_NETWORK_3 DM_INLINE_NETWORK_3 no-proxy-arp&lt;BR /&gt;nat (inside,outside_Arena) source static NETWORK_OBJ_172.26.0.0_24 NETWORK_OBJ_172.26.0.0_24 destination static DM_INLINE_NETWORK_5 DM_INLINE_NETWORK_5 no-proxy-arp route-lookup&lt;BR /&gt;!&lt;BR /&gt;object network FENDI_Laptop&lt;BR /&gt;&amp;nbsp;nat (inside,outside_Arena) static interface service tcp 3389 3389&amp;nbsp;&lt;BR /&gt;object network UK2008SRV_WEB&lt;BR /&gt;&amp;nbsp;nat (inside,outside_Arena) static interface service tcp www www&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;nat (inside,outside_Arena) after-auto source dynamic obj-172.26.0.0 interface&lt;BR /&gt;access-group inside_access_in in interface inside&lt;BR /&gt;access-group UK2008SRV-in in interface outside_Arena&lt;BR /&gt;route outside_Arena 0.0.0.0 0.0.0.0 95.130.99.129 180&lt;BR /&gt;route outside_Arena 172.20.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.23.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.26.0.19 255.255.255.255 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.27.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.30.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 192.168.0.0 255.255.252.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 193.120.165.154 255.255.255.255 95.130.99.129 1&lt;BR /&gt;route outside_Arena 194.44.55.5 255.255.255.255 95.130.99.129 1&lt;BR /&gt;route outside_Arena 194.44.136.114 255.255.255.255 95.130.99.129 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&amp;nbsp;&lt;BR /&gt;http server enable 8443&lt;BR /&gt;http 172.26.0.0 255.255.255.0 inside&lt;BR /&gt;http 194.44.136.114 255.255.255.255 outside_Arena&lt;BR /&gt;http 193.120.165.154 255.255.255.255 outside_Arena&lt;BR /&gt;http 194.44.55.0 255.255.255.0 outside_Arena&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;sysopt connection tcpmss 1350&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS esp-aes esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS esp-aes esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS esp-aes-192 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS esp-aes-192 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS esp-aes-256 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS esp-aes-256 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS esp-3des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS esp-3des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS esp-des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS esp-des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES256&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-256&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES192&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-192&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal 3DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption 3des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES&lt;BR /&gt;crypto map outside_virgin_isp_map 1 match address outside_Arena_cryptomap&lt;BR /&gt;crypto map outside_virgin_isp_map 1 set peer 193.120.165.154&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 1 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_virgin_isp_map 2 match address outside_Arena_cryptomap_1&lt;BR /&gt;crypto map outside_virgin_isp_map 2 set pfs&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 2 set peer 80.88.92.105&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 2 set ikev1 transform-set ESP-3DES-SHA ESP-AES-256-SHA&lt;BR /&gt;crypto map outside_virgin_isp_map 5 match address outside_virgin_isp_cryptomap_1&lt;BR /&gt;crypto map outside_virgin_isp_map 5 set peer 194.44.136.114&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 5 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_virgin_isp_map 6 match address outside_virgin_isp_cryptomap_2&lt;BR /&gt;crypto map outside_virgin_isp_map 6 set peer 212.87.74.171&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 6 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_virgin_isp_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map outside_virgin_isp_map interface outside_Arena&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint0&lt;BR /&gt;&amp;nbsp;enrollment self&lt;BR /&gt;&amp;nbsp;fqdn vpnuk.lynq.co.uk&lt;BR /&gt;&amp;nbsp;subject-name CN=LYNQUKASA&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint0&lt;BR /&gt;&amp;nbsp;certificate 5b0ba155&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 308201e1 3082014a a0030201 0202045b 0ba15530 0d06092a 864886f7 0d010105&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 05003035 31123010 06035504 0313094c 594e5155 4b415341 311f301d 06092a86&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 4886f70d 01090216 1076706e 756b2e6c 796e712e 636f2e75 6b301e17 0d313530&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 37323231 30323635 395a170d 32353037 31393130 32363539 5a303531 12301006&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 03550403 13094c59 4e51554b 41534131 1f301d06 092a8648 86f70d01 09021610&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 76706e75 6b2e6c79 6e712e63 6f2e756b 30819f30 0d06092a 864886f7 0d010101&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 05000381 8d003081 89028181 00b34b55 c66162ec f3fb376f 9f24491e a71b931e&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 3332434d f826ed42 ea1620fb 4cfa0ee1 6080fb0c e1b3470e 1a6b8bc2 8f7234c6&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; e65616e3 362bea14 9f45f49d 5f919c14 1f98986b a579b466 21149480 3b75ebe9&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 826116a0 92811587 1cffb55a 895a4a52 e2b5243c 1dccfe5d 3347a8f6 55235e2f&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 990a4f09 0cb3af08 34f538fa 21020301 0001300d 06092a86 4886f70d 01010505&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 00038181 0055e50c def67359 c835c88a 69527106 1272ca5f c1834613 4bbe4d9c&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 4fb0c526 b79b7836 257a38ff 11550295 ef0c54ad 71fcd7ed d030d150 6a4ddc80&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 6068b088 de6c656f 0591223d e03d93de 04191ab6 3280332a 5cb2e489 e0aabf4c&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; b92c609a 87d5d784 7119f96b f004005c 717877fc 66bd8abc fd6d8a5d 11f2ff23&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 3a9059ed be&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ikev2 policy 1&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 10&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 20&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 30&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 40&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 enable outside_Arena client-services port 443&lt;BR /&gt;crypto ikev2 remote-access trustpoint ASDM_TrustPoint0&lt;BR /&gt;crypto ikev1 enable outside_Arena&lt;BR /&gt;crypto ikev1 policy 5&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 28800&lt;BR /&gt;!&lt;BR /&gt;track 1 rtr 123 reachability&lt;BR /&gt;!&lt;BR /&gt;track 100 rtr 1 reachability&lt;BR /&gt;telnet 172.26.0.0 255.255.255.0 inside&lt;BR /&gt;telnet 172.26.0.0 255.255.0.0 inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh 172.26.0.0 255.255.255.0 inside&lt;BR /&gt;ssh 194.44.136.114 255.255.255.255 outside_Arena&lt;BR /&gt;ssh 193.120.165.154 255.255.255.255 outside_Arena&lt;BR /&gt;ssh 194.44.55.0 255.255.255.0 outside_Arena&lt;BR /&gt;ssh timeout 30&lt;BR /&gt;console timeout 0&lt;BR /&gt;vpdn group BTFibre request dialout pppoe&lt;BR /&gt;vpdn group BTFibre localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group BTFibre ppp authentication chap&lt;BR /&gt;vpdn group btpppoe request dialout pppoe&lt;BR /&gt;vpdn group btpppoe localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group btpppoe ppp authentication pap&lt;BR /&gt;vpdn group bt_pppoe request dialout pppoe&lt;BR /&gt;vpdn group bt_pppoe localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group bt_pppoe ppp authentication pap&lt;BR /&gt;vpdn group PPPOE_BT request dialout pppoe&lt;BR /&gt;vpdn group PPPOE_BT localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group PPPOE_BT ppp authentication pap&lt;BR /&gt;vpdn group BTDSL request dialout pppoe&lt;BR /&gt;vpdn group BTDSL localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group BTDSL ppp authentication pap&lt;BR /&gt;vpdn group D203277@hg52.btclick.com request dialout pppoe&lt;BR /&gt;vpdn group D203277@hg52.btclick.com localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group D203277@hg52.btclick.com ppp authentication chap&lt;BR /&gt;vpdn username D203277@hg52.btclick.com password password1 store-local&lt;BR /&gt;vpdn username 01329221836@talktalkbusiness.net password J7R5K6F2J6 store-local&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;ntp server 65.55.56.206&lt;BR /&gt;tftp-server inside 172.26.0.26 \&lt;BR /&gt;ssl trust-point ASDM_TrustPoint0 outside_Arena&lt;BR /&gt;webvpn&lt;BR /&gt;&amp;nbsp;enable outside_Arena&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-win-2.5.2014-k9.pkg 1&lt;BR /&gt;&amp;nbsp;anyconnect enable&lt;BR /&gt;&amp;nbsp;tunnel-group-list enable&lt;BR /&gt;group-policy DfltGrpPolicy attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 l2tp-ipsec ssl-clientless&lt;BR /&gt;group-policy GroupPolicy_RemoteSSL internal&lt;BR /&gt;group-policy GroupPolicy_RemoteSSL attributes&lt;BR /&gt;&amp;nbsp;wins-server none&lt;BR /&gt;&amp;nbsp;dns-server value 172.26.0.25&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ssl-client&amp;nbsp;&lt;BR /&gt;&amp;nbsp;split-tunnel-policy tunnelspecified&lt;BR /&gt;&amp;nbsp;split-tunnel-network-list value SplitTunnel&lt;BR /&gt;&amp;nbsp;default-domain value lynq.co.uk&lt;BR /&gt;group-policy GroupPolicy_80.88.92.105 internal&lt;BR /&gt;group-policy GroupPolicy_80.88.92.105 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1&amp;nbsp;&lt;BR /&gt;group-policy GroupPolicy_194.44.136.114 internal&lt;BR /&gt;group-policy GroupPolicy_194.44.136.114 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1&amp;nbsp;&lt;BR /&gt;group-policy GroupPolicy_193.120.165.154 internal&lt;BR /&gt;group-policy GroupPolicy_193.120.165.154 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1&amp;nbsp;&lt;BR /&gt;username tdb.admin password 66rOScYvr6BoMfol encrypted privilege 15&lt;BR /&gt;username paul.synnott password 3UDjotP6R7/M6C0B encrypted privilege 15&lt;BR /&gt;username sarah.kingswell password 5XyGsYkEdLoWOQiY encrypted privilege 15&lt;BR /&gt;username pete.hayes password aKXo6uAmPQjnwJ6q encrypted&lt;BR /&gt;username taras.chuhay password Yxj1fcjQ/tmX15oH encrypted privilege 15&lt;BR /&gt;username sean.timmins password ChKbOC6xl/qpg0kj encrypted privilege 15&lt;BR /&gt;username ciaran.raftery password 7IlPp0OBHDtzh4gY encrypted privilege 15&lt;BR /&gt;username colm.admin password 2MIbxjKQswsLMY/w encrypted privilege 15&lt;BR /&gt;tunnel-group 193.120.165.154 type ipsec-l2l&lt;BR /&gt;tunnel-group 193.120.165.154 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_193.120.165.154&lt;BR /&gt;tunnel-group 193.120.165.154 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;tunnel-group 194.44.136.114 type ipsec-l2l&lt;BR /&gt;tunnel-group 194.44.136.114 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_194.44.136.114&lt;BR /&gt;tunnel-group 194.44.136.114 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;tunnel-group 212.87.74.171 type ipsec-l2l&lt;BR /&gt;tunnel-group 212.87.74.171 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;tunnel-group RemoteSSL type remote-access&lt;BR /&gt;tunnel-group RemoteSSL general-attributes&lt;BR /&gt;&amp;nbsp;address-pool remotessl&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_RemoteSSL&lt;BR /&gt;tunnel-group RemoteSSL webvpn-attributes&lt;BR /&gt;&amp;nbsp;group-alias RemoteSSL enable&lt;BR /&gt;tunnel-group 80.88.92.105 type ipsec-l2l&lt;BR /&gt;tunnel-group 80.88.92.105 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_80.88.92.105&lt;BR /&gt;tunnel-group 80.88.92.105 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;&amp;nbsp;peer-id-validate nocheck&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 h225&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 ras&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rsh&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rtsp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect esmtp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sqlnet&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect xdmcp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect tftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect pptp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ip-options&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&amp;nbsp;&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt;&amp;nbsp;profile CiscoTAC-1&lt;BR /&gt;&amp;nbsp; no active&lt;BR /&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;BR /&gt;&amp;nbsp; destination transport-method http&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:c1da252a320bfa812b6b7fc3bb48f9eb&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2015 12:14:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-on-asa-5505-not-working-help/m-p/2692667#M193230</guid>
      <dc:creator>sarah.kingswell1</dc:creator>
      <dc:date>2015-07-30T12:14:53Z</dc:date>
    </item>
    <item>
      <title>I have now managed to break</title>
      <link>https://community.cisco.com/t5/network-security/port-forwarding-on-asa-5505-not-working-help/m-p/2692668#M193231</link>
      <description>&lt;P style="font-size: 14.399998664856px;"&gt;I have now managed to break it by adding another port forward this time to another subnet that is connected by VPN.&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;The command I have run from the CLI&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;object network UK2008SRV_WEB&lt;BR /&gt;host 172.27.0.136&lt;BR /&gt;nat (inside,outside) static interface service tcp 80 80&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;access-list UK2008SRV-in extended permit tcp any host 172.27.0.136 eq 80 log&lt;BR /&gt;access-group UK2008SRV-in in interface outside_Arena&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;How do I now fix to get both port forwards working? &amp;nbsp;Sorry this is confusing..&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;Result of the command: "show config"&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;&lt;BR /&gt;ASA Version 8.4(2)&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;hostname LYNQUKASA&lt;BR /&gt;domain-name ********&lt;BR /&gt;enable password ******** encrypted&lt;BR /&gt;passwd ********&amp;nbsp;encrypted&lt;BR /&gt;no names&lt;BR /&gt;name 172.26.0.32 DEMO.ILYNQ.COM_InternalIP description Used in NAT rule for port redir of pts 81 and 3389&lt;BR /&gt;name 172.26.0.26 UKFS_InternalIP description Used in NAT rule to port redirect FTP pt 21&lt;BR /&gt;name 92.237.118.233 VIRGIN_ISP_Gateway&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;&amp;nbsp;switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;&amp;nbsp;switchport access vlan 32&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;&amp;nbsp;switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;interface Vlan12&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 172.26.0.1 255.255.255.0&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface Vlan32&lt;BR /&gt;&amp;nbsp;nameif outside_Arena&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 95.130.99.137 255.255.255.240&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa842-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone GMT/BST 0&lt;BR /&gt;clock summer-time GMT/BDT recurring last Sun Mar 1:00 last Sun Oct 2:00&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;&amp;nbsp;domain-name lynq.co.uk&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network obj-172.26.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.26.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.29.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.29.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.27.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.27.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.23.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.23.0.0 255.255.255.0&lt;BR /&gt;object network obj-172.25.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.25.0.0 255.255.255.0&lt;BR /&gt;object network obj-192.168.0.0&lt;BR /&gt;&amp;nbsp;subnet 192.168.0.0 255.255.252.0&lt;BR /&gt;object network obj-10.100.100.0&lt;BR /&gt;&amp;nbsp;subnet 10.100.100.0 255.255.255.0&lt;BR /&gt;object network obj-172.22.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.22.0.0 255.255.255.0&lt;BR /&gt;object network obj-192.168.40.0&lt;BR /&gt;&amp;nbsp;subnet 192.168.40.0 255.255.255.0&lt;BR /&gt;object network obj-172.20.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.20.0.0 255.255.255.0&lt;BR /&gt;object network obj-92.237.118.236&lt;BR /&gt;&amp;nbsp;host 92.237.118.236&lt;BR /&gt;object service obj-tcp-source-eq-80&lt;BR /&gt;&amp;nbsp;service tcp source eq www&amp;nbsp;&lt;BR /&gt;object service obj-tcp-source-eq-21&lt;BR /&gt;&amp;nbsp;service tcp source eq ftp&amp;nbsp;&lt;BR /&gt;object network obj-172.26.0.132&lt;BR /&gt;&amp;nbsp;host 172.26.0.132&lt;BR /&gt;object network obj-92.237.118.237&lt;BR /&gt;&amp;nbsp;host 92.237.118.237&lt;BR /&gt;object service obj-tcp-source-eq-3389&lt;BR /&gt;&amp;nbsp;service tcp source eq 3389&amp;nbsp;&lt;BR /&gt;object network obj-172.26.0.107&lt;BR /&gt;&amp;nbsp;host 172.26.0.107&lt;BR /&gt;object network obj-92.237.118.238&lt;BR /&gt;&amp;nbsp;host 92.237.118.238&lt;BR /&gt;object network obj-92.237.118.235&lt;BR /&gt;&amp;nbsp;host 92.237.118.235&lt;BR /&gt;object network BT_ISP_Gateway&lt;BR /&gt;&amp;nbsp;host 81.138.134.30&lt;BR /&gt;&amp;nbsp;description BT ISP Router&lt;BR /&gt;object network obj-172.26.0.26&lt;BR /&gt;&amp;nbsp;host 172.26.0.26&lt;BR /&gt;&amp;nbsp;description FTP server&lt;BR /&gt;object service ftp&lt;BR /&gt;&amp;nbsp;service tcp source eq ftp destination range 1 65535&amp;nbsp;&lt;BR /&gt;object network BT_NatHidingStaticIP&lt;BR /&gt;&amp;nbsp;host 81.138.134.25&lt;BR /&gt;object network NETWORK_OBJ_172.26.0.0_24&lt;BR /&gt;&amp;nbsp;subnet 172.26.0.0 255.255.255.0&lt;BR /&gt;object network NETWORK_OBJ_172.30.0.0_24&lt;BR /&gt;&amp;nbsp;subnet 172.30.0.0 255.255.255.0&lt;BR /&gt;object network NETWORK_OBJ_172.31.0.0_25&lt;BR /&gt;&amp;nbsp;subnet 172.31.0.0 255.255.255.128&lt;BR /&gt;object network obj-172.30.0.0&lt;BR /&gt;&amp;nbsp;subnet 172.30.0.0 255.255.255.0&lt;BR /&gt;object network NETWORK_OBJ_172.31.0.192_26&lt;BR /&gt;&amp;nbsp;subnet 172.31.0.192 255.255.255.192&lt;BR /&gt;object network NETWORK_OBJ_192.168.50.0_26&lt;BR /&gt;&amp;nbsp;subnet 192.168.50.0 255.255.255.192&lt;BR /&gt;object network NETWORK_OBJ_10.0.0.0_28&lt;BR /&gt;&amp;nbsp;subnet 10.0.0.0 255.255.255.240&lt;BR /&gt;object network NETWORK_OBJ_10.11.1.0_27&lt;BR /&gt;&amp;nbsp;subnet 10.11.1.0 255.255.255.224&lt;BR /&gt;object network 172.26.0.19&lt;BR /&gt;&amp;nbsp;host 172.26.0.19&lt;BR /&gt;object service 8080&lt;BR /&gt;&amp;nbsp;service tcp source eq 8080 destination eq 8080&amp;nbsp;&lt;BR /&gt;object network Clarke-Aruba&lt;BR /&gt;&amp;nbsp;subnet 172.31.0.0 255.255.255.0&lt;BR /&gt;object network FENDI_Laptop&lt;BR /&gt;&amp;nbsp;host 172.26.0.19&lt;BR /&gt;object network 172.26.0.1&lt;BR /&gt;&amp;nbsp;host 172.26.0.1&lt;BR /&gt;&amp;nbsp;description Internal IP for Router&lt;BR /&gt;object network UK2008SRV_WEB&lt;BR /&gt;&amp;nbsp;host 172.27.0.136&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_1&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_2&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group service DM_INLINE_TCP_1 tcp&lt;BR /&gt;&amp;nbsp;port-object eq 3389&lt;BR /&gt;&amp;nbsp;port-object eq 3390&lt;BR /&gt;&amp;nbsp;port-object eq 81&lt;BR /&gt;&amp;nbsp;port-object eq 82&lt;BR /&gt;&amp;nbsp;port-object eq ftp&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;object-group network DM_INLINE_NETWORK_2&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.235&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.236&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.237&lt;BR /&gt;&amp;nbsp;network-object host 92.237.118.238&lt;BR /&gt;object-group service DM_INLINE_TCP_2 tcp&lt;BR /&gt;&amp;nbsp;port-object eq 3389&lt;BR /&gt;&amp;nbsp;port-object eq 81&lt;BR /&gt;&amp;nbsp;port-object eq 82&lt;BR /&gt;&amp;nbsp;port-object eq ftp&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;&amp;nbsp;port-object eq https&lt;BR /&gt;object-group service DM_INLINE_TCP_3 tcp&lt;BR /&gt;&amp;nbsp;port-object eq 3389&lt;BR /&gt;&amp;nbsp;port-object eq www&lt;BR /&gt;object-group network DM_INLINE_NETWORK_3&lt;BR /&gt;&amp;nbsp;network-object object obj-172.20.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.29.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-192.168.40.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.23.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.25.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-10.100.100.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.22.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-192.168.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.27.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.30.0.0&lt;BR /&gt;&amp;nbsp;network-object object Clarke-Aruba&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_5&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_3&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group icmp-type DM_INLINE_ICMP_4&lt;BR /&gt;&amp;nbsp;icmp-object echo&lt;BR /&gt;&amp;nbsp;icmp-object echo-reply&lt;BR /&gt;&amp;nbsp;icmp-object source-quench&lt;BR /&gt;&amp;nbsp;icmp-object time-exceeded&lt;BR /&gt;&amp;nbsp;icmp-object traceroute&lt;BR /&gt;&amp;nbsp;icmp-object unreachable&lt;BR /&gt;object-group protocol DM_INLINE_PROTOCOL_1&lt;BR /&gt;&amp;nbsp;protocol-object ip&lt;BR /&gt;&amp;nbsp;protocol-object icmp&lt;BR /&gt;object-group network DM_INLINE_NETWORK_1&lt;BR /&gt;&amp;nbsp;network-object 172.27.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.20.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-172.29.0.0&lt;BR /&gt;&amp;nbsp;network-object object obj-192.168.40.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_4&lt;BR /&gt;&amp;nbsp;network-object 172.30.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object object Clarke-Aruba&lt;BR /&gt;object-group network DM_INLINE_NETWORK_5&lt;BR /&gt;&amp;nbsp;network-object object Clarke-Aruba&lt;BR /&gt;&amp;nbsp;network-object object NETWORK_OBJ_172.30.0.0_24&lt;BR /&gt;object-group protocol DM_INLINE_PROTOCOL_2&lt;BR /&gt;&amp;nbsp;protocol-object udp&lt;BR /&gt;&amp;nbsp;protocol-object tcp&lt;BR /&gt;object-group protocol TCPUDP&lt;BR /&gt;&amp;nbsp;protocol-object udp&lt;BR /&gt;&amp;nbsp;protocol-object tcp&lt;BR /&gt;access-list inside_nat_outbound extended permit ip 172.26.0.0 255.255.255.0 any&amp;nbsp;&lt;BR /&gt;access-list inside_access_in extended permit ip 172.26.0.0 255.255.255.0 any&amp;nbsp;&lt;BR /&gt;access-list inside_access_in extended permit icmp any any object-group DM_INLINE_ICMP_1&amp;nbsp;&lt;BR /&gt;access-list inside_access_in extended permit object-group TCPUDP any any&amp;nbsp;&lt;BR /&gt;access-list dmz_access_in extended permit icmp any any object-group DM_INLINE_ICMP_2&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 172.23.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 172.25.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 192.168.0.0 255.255.252.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 10.100.100.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 172.26.0.0 255.255.255.0 172.22.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list outside_Arena_cryptomap extended permit ip 172.26.0.0 255.255.255.0 object-group DM_INLINE_NETWORK_1&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in extended permit icmp any any object-group DM_INLINE_ICMP_3&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_cryptomap_1 extended permit ip 172.26.0.0 255.255.255.0 172.23.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list outside_bt_isp_access_in extended permit icmp any any object-group DM_INLINE_ICMP_5&amp;nbsp;&lt;BR /&gt;access-list outside_bt_isp_access_in extended permit tcp any any eq ftp&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit icmp any any object-group DM_INLINE_ICMP_4&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit object-group DM_INLINE_PROTOCOL_1 any 192.168.0.0 255.255.252.0&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit ip host 80.88.92.106 any&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_access_in_1 extended permit icmp any any&amp;nbsp;&lt;BR /&gt;access-list outside_virgin_isp_cryptomap_2 extended permit ip 172.26.0.0 255.255.255.0 object obj-10.100.100.0&amp;nbsp;&lt;BR /&gt;access-list outside_Arena_cryptomap_1 extended permit ip 172.26.0.0 255.255.255.0 object-group DM_INLINE_NETWORK_4&amp;nbsp;&lt;BR /&gt;access-list SplitTunnel standard permit 172.26.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list NAT-EXEMPT extended permit ip 172.26.0.0 255.255.255.0 10.11.1.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list FENDI-in extended permit tcp any host 172.26.0.19 eq 3389 log&amp;nbsp;&lt;BR /&gt;access-list UK2008SRV-in extended permit tcp any host 172.27.0.136 eq www log&amp;nbsp;&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside_Arena 1500&lt;BR /&gt;ip local pool UKSSLUsers 172.31.0.200-172.31.0.240 mask 255.255.255.0&lt;BR /&gt;ip local pool AnyConnect 192.168.50.20-192.168.50.40 mask 255.255.255.0&lt;BR /&gt;ip local pool net-10 10.0.0.1-10.0.0.10 mask 255.255.255.0&lt;BR /&gt;ip local pool remotessl 10.11.1.2-10.11.1.20 mask 255.255.255.0&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-711.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;nat (inside,outside_Arena) source static obj-172.26.0.0 obj-172.26.0.0 destination static DM_INLINE_NETWORK_3 DM_INLINE_NETWORK_3 no-proxy-arp&lt;BR /&gt;nat (inside,outside_Arena) source static NETWORK_OBJ_172.26.0.0_24 NETWORK_OBJ_172.26.0.0_24 destination static DM_INLINE_NETWORK_5 DM_INLINE_NETWORK_5 no-proxy-arp route-lookup&lt;BR /&gt;!&lt;BR /&gt;object network FENDI_Laptop&lt;BR /&gt;&amp;nbsp;nat (inside,outside_Arena) static interface service tcp 3389 3389&amp;nbsp;&lt;BR /&gt;object network UK2008SRV_WEB&lt;BR /&gt;&amp;nbsp;nat (inside,outside_Arena) static interface service tcp www www&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;nat (inside,outside_Arena) after-auto source dynamic obj-172.26.0.0 interface&lt;BR /&gt;access-group inside_access_in in interface inside&lt;BR /&gt;access-group UK2008SRV-in in interface outside_Arena&lt;BR /&gt;route outside_Arena 0.0.0.0 0.0.0.0 95.130.99.129 180&lt;BR /&gt;route outside_Arena 172.20.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.23.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.26.0.19 255.255.255.255 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.27.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 172.30.0.0 255.255.255.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 192.168.0.0 255.255.252.0 95.130.99.129 1&lt;BR /&gt;route outside_Arena 193.120.165.154 255.255.255.255 95.130.99.129 1&lt;BR /&gt;route outside_Arena 194.44.55.5 255.255.255.255 95.130.99.129 1&lt;BR /&gt;route outside_Arena 194.44.136.114 255.255.255.255 95.130.99.129 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&amp;nbsp;&lt;BR /&gt;http server enable 8443&lt;BR /&gt;http 172.26.0.0 255.255.255.0 inside&lt;BR /&gt;http 194.44.136.114 255.255.255.255 outside_Arena&lt;BR /&gt;http 193.120.165.154 255.255.255.255 outside_Arena&lt;BR /&gt;http 194.44.55.0 255.255.255.0 outside_Arena&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;sysopt connection tcpmss 1350&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS esp-aes esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS esp-aes esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS esp-aes-192 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS esp-aes-192 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS esp-aes-256 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS esp-aes-256 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS esp-3des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS esp-3des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS esp-des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS esp-des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES256&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-256&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES192&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes-192&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES&lt;BR /&gt;&amp;nbsp;protocol esp encryption aes&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal 3DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption 3des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal DES&lt;BR /&gt;&amp;nbsp;protocol esp encryption des&lt;BR /&gt;&amp;nbsp;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev2 ipsec-proposal AES256 AES192 AES 3DES DES&lt;BR /&gt;crypto map outside_virgin_isp_map 1 match address outside_Arena_cryptomap&lt;BR /&gt;crypto map outside_virgin_isp_map 1 set peer 193.120.165.154&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 1 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_virgin_isp_map 2 match address outside_Arena_cryptomap_1&lt;BR /&gt;crypto map outside_virgin_isp_map 2 set pfs&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 2 set peer 80.88.92.105&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 2 set ikev1 transform-set ESP-3DES-SHA ESP-AES-256-SHA&lt;BR /&gt;crypto map outside_virgin_isp_map 5 match address outside_virgin_isp_cryptomap_1&lt;BR /&gt;crypto map outside_virgin_isp_map 5 set peer 194.44.136.114&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 5 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_virgin_isp_map 6 match address outside_virgin_isp_cryptomap_2&lt;BR /&gt;crypto map outside_virgin_isp_map 6 set peer 212.87.74.171&amp;nbsp;&lt;BR /&gt;crypto map outside_virgin_isp_map 6 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_virgin_isp_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map outside_virgin_isp_map interface outside_Arena&lt;BR /&gt;crypto ca trustpoint ASDM_TrustPoint0&lt;BR /&gt;&amp;nbsp;enrollment self&lt;BR /&gt;&amp;nbsp;fqdn vpnuk.lynq.co.uk&lt;BR /&gt;&amp;nbsp;subject-name CN=LYNQUKASA&lt;BR /&gt;&amp;nbsp;crl configure&lt;BR /&gt;crypto ca certificate chain ASDM_TrustPoint0&lt;BR /&gt;&amp;nbsp;certificate 5b0ba155&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 308201e1 3082014a a0030201 0202045b 0ba15530 0d06092a 864886f7 0d010105&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 05003035 31123010 06035504 0313094c 594e5155 4b415341 311f301d 06092a86&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 4886f70d 01090216 1076706e 756b2e6c 796e712e 636f2e75 6b301e17 0d313530&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 37323231 30323635 395a170d 32353037 31393130 32363539 5a303531 12301006&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 03550403 13094c59 4e51554b 41534131 1f301d06 092a8648 86f70d01 09021610&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 76706e75 6b2e6c79 6e712e63 6f2e756b 30819f30 0d06092a 864886f7 0d010101&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 05000381 8d003081 89028181 00b34b55 c66162ec f3fb376f 9f24491e a71b931e&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 3332434d f826ed42 ea1620fb 4cfa0ee1 6080fb0c e1b3470e 1a6b8bc2 8f7234c6&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; e65616e3 362bea14 9f45f49d 5f919c14 1f98986b a579b466 21149480 3b75ebe9&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 826116a0 92811587 1cffb55a 895a4a52 e2b5243c 1dccfe5d 3347a8f6 55235e2f&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 990a4f09 0cb3af08 34f538fa 21020301 0001300d 06092a86 4886f70d 01010505&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 00038181 0055e50c def67359 c835c88a 69527106 1272ca5f c1834613 4bbe4d9c&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 4fb0c526 b79b7836 257a38ff 11550295 ef0c54ad 71fcd7ed d030d150 6a4ddc80&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 6068b088 de6c656f 0591223d e03d93de 04191ab6 3280332a 5cb2e489 e0aabf4c&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; b92c609a 87d5d784 7119f96b f004005c 717877fc 66bd8abc fd6d8a5d 11f2ff23&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; 3a9059ed be&lt;BR /&gt;&amp;nbsp; quit&lt;BR /&gt;crypto ikev2 policy 1&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 10&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 20&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 30&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 40&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;integrity sha&lt;BR /&gt;&amp;nbsp;group 5 2&lt;BR /&gt;&amp;nbsp;prf sha&lt;BR /&gt;&amp;nbsp;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 enable outside_Arena client-services port 443&lt;BR /&gt;crypto ikev2 remote-access trustpoint ASDM_TrustPoint0&lt;BR /&gt;crypto ikev1 enable outside_Arena&lt;BR /&gt;crypto ikev1 policy 5&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 28800&lt;BR /&gt;!&lt;BR /&gt;track 1 rtr 123 reachability&lt;BR /&gt;!&lt;BR /&gt;track 100 rtr 1 reachability&lt;BR /&gt;telnet 172.26.0.0 255.255.255.0 inside&lt;BR /&gt;telnet 172.26.0.0 255.255.0.0 inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh 172.26.0.0 255.255.255.0 inside&lt;BR /&gt;ssh 194.44.136.114 255.255.255.255 outside_Arena&lt;BR /&gt;ssh 193.120.165.154 255.255.255.255 outside_Arena&lt;BR /&gt;ssh 194.44.55.0 255.255.255.0 outside_Arena&lt;BR /&gt;ssh timeout 30&lt;BR /&gt;console timeout 0&lt;BR /&gt;vpdn group BTFibre request dialout pppoe&lt;BR /&gt;vpdn group BTFibre localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group BTFibre ppp authentication chap&lt;BR /&gt;vpdn group btpppoe request dialout pppoe&lt;BR /&gt;vpdn group btpppoe localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group btpppoe ppp authentication pap&lt;BR /&gt;vpdn group bt_pppoe request dialout pppoe&lt;BR /&gt;vpdn group bt_pppoe localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group bt_pppoe ppp authentication pap&lt;BR /&gt;vpdn group PPPOE_BT request dialout pppoe&lt;BR /&gt;vpdn group PPPOE_BT localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group PPPOE_BT ppp authentication pap&lt;BR /&gt;vpdn group BTDSL request dialout pppoe&lt;BR /&gt;vpdn group BTDSL localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group BTDSL ppp authentication pap&lt;BR /&gt;vpdn group D203277@hg52.btclick.com request dialout pppoe&lt;BR /&gt;vpdn group D203277@hg52.btclick.com localname D203277@hg52.btclick.com&lt;BR /&gt;vpdn group D203277@hg52.btclick.com ppp authentication chap&lt;BR /&gt;vpdn username D203277@hg52.btclick.com password password1 store-local&lt;BR /&gt;vpdn username 01329221836@talktalkbusiness.net password J7R5K6F2J6 store-local&lt;/P&gt;&lt;P style="font-size: 14.399998664856px;"&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;ntp server 65.55.56.206&lt;BR /&gt;tftp-server inside 172.26.0.26 \&lt;BR /&gt;ssl trust-point ASDM_TrustPoint0 outside_Arena&lt;BR /&gt;webvpn&lt;BR /&gt;&amp;nbsp;enable outside_Arena&lt;BR /&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-win-2.5.2014-k9.pkg 1&lt;BR /&gt;&amp;nbsp;anyconnect enable&lt;BR /&gt;&amp;nbsp;tunnel-group-list enable&lt;BR /&gt;group-policy DfltGrpPolicy attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 l2tp-ipsec ssl-clientless&lt;BR /&gt;group-policy GroupPolicy_RemoteSSL internal&lt;BR /&gt;group-policy GroupPolicy_RemoteSSL attributes&lt;BR /&gt;&amp;nbsp;wins-server none&lt;BR /&gt;&amp;nbsp;dns-server value 172.26.0.25&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ssl-client&amp;nbsp;&lt;BR /&gt;&amp;nbsp;split-tunnel-policy tunnelspecified&lt;BR /&gt;&amp;nbsp;split-tunnel-network-list value SplitTunnel&lt;BR /&gt;&amp;nbsp;default-domain value lynq.co.uk&lt;BR /&gt;group-policy GroupPolicy_80.88.92.105 internal&lt;BR /&gt;group-policy GroupPolicy_80.88.92.105 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1&amp;nbsp;&lt;BR /&gt;group-policy GroupPolicy_194.44.136.114 internal&lt;BR /&gt;group-policy GroupPolicy_194.44.136.114 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1&amp;nbsp;&lt;BR /&gt;group-policy GroupPolicy_193.120.165.154 internal&lt;BR /&gt;group-policy GroupPolicy_193.120.165.154 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1&amp;nbsp;&lt;BR /&gt;username tdb.admin password 66rOScYvr6BoMfol encrypted privilege 15&lt;BR /&gt;username paul.synnott password 3UDjotP6R7/M6C0B encrypted privilege 15&lt;BR /&gt;username sarah.kingswell password 5XyGsYkEdLoWOQiY encrypted privilege 15&lt;BR /&gt;username pete.hayes password aKXo6uAmPQjnwJ6q encrypted&lt;BR /&gt;username taras.chuhay password Yxj1fcjQ/tmX15oH encrypted privilege 15&lt;BR /&gt;username sean.timmins password ChKbOC6xl/qpg0kj encrypted privilege 15&lt;BR /&gt;username ciaran.raftery password 7IlPp0OBHDtzh4gY encrypted privilege 15&lt;BR /&gt;username colm.admin password 2MIbxjKQswsLMY/w encrypted privilege 15&lt;BR /&gt;tunnel-group 193.120.165.154 type ipsec-l2l&lt;BR /&gt;tunnel-group 193.120.165.154 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_193.120.165.154&lt;BR /&gt;tunnel-group 193.120.165.154 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;tunnel-group 194.44.136.114 type ipsec-l2l&lt;BR /&gt;tunnel-group 194.44.136.114 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_194.44.136.114&lt;BR /&gt;tunnel-group 194.44.136.114 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;tunnel-group 212.87.74.171 type ipsec-l2l&lt;BR /&gt;tunnel-group 212.87.74.171 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;tunnel-group RemoteSSL type remote-access&lt;BR /&gt;tunnel-group RemoteSSL general-attributes&lt;BR /&gt;&amp;nbsp;address-pool remotessl&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_RemoteSSL&lt;BR /&gt;tunnel-group RemoteSSL webvpn-attributes&lt;BR /&gt;&amp;nbsp;group-alias RemoteSSL enable&lt;BR /&gt;tunnel-group 80.88.92.105 type ipsec-l2l&lt;BR /&gt;tunnel-group 80.88.92.105 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy_80.88.92.105&lt;BR /&gt;tunnel-group 80.88.92.105 ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;&amp;nbsp;peer-id-validate nocheck&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 h225&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 ras&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rsh&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rtsp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect esmtp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sqlnet&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect xdmcp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect tftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect pptp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ip-options&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&amp;nbsp;&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt;&amp;nbsp;profile CiscoTAC-1&lt;BR /&gt;&amp;nbsp; no active&lt;BR /&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;BR /&gt;&amp;nbsp; destination transport-method http&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:c1da252a320bfa812b6b7fc3bb48f9eb&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jul 2015 12:48:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/port-forwarding-on-asa-5505-not-working-help/m-p/2692668#M193231</guid>
      <dc:creator>sarah.kingswell1</dc:creator>
      <dc:date>2015-07-30T12:48:55Z</dc:date>
    </item>
  </channel>
</rss>

