<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic thanks Jon for the info... in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621531#M195495</link>
    <description>&lt;P&gt;thanks Jon for the info....&lt;/P&gt;&lt;P&gt;will try this definitely on my router and will let u know..&lt;/P&gt;</description>
    <pubDate>Thu, 02 Apr 2015 06:25:17 GMT</pubDate>
    <dc:creator>mudasir05</dc:creator>
    <dc:date>2015-04-02T06:25:17Z</dc:date>
    <item>
      <title>unable to access internet from DMZ server</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621514#M195478</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a Server connected to the Vlan on 2960 switch which is connected to the ASA 5545.&lt;/P&gt;&lt;P&gt;The Server is accessed from outside as iam able to ping its public ip as well as able to ssh it,however the problem is iam not able to access the Internet from the Server.&lt;/P&gt;&lt;P&gt;I am using ASA version 9.1,also i created access-list and Nat rule through Public Server feature of the ASDM.&lt;/P&gt;&lt;P&gt;kindly help where iam wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:43:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621514#M195478</guid>
      <dc:creator>mudasir05</dc:creator>
      <dc:date>2019-03-12T05:43:04Z</dc:date>
    </item>
    <item>
      <title>Hi,If you check the NAT for</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621515#M195479</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;If you check the NAT for the Server , Is this a Static PAT/Port Forward or One-one Static NAT ?&lt;/P&gt;&lt;P&gt;If it is port Forward/Static PAT , Outbound ping would need a Dynamic NAT for the ping to be allowed to the internet.&lt;/P&gt;&lt;P&gt;Also , other than this , check these things:-&lt;/P&gt;&lt;P&gt;1) ICMP inspection is no ACL is applied on the Private Interface&lt;/P&gt;&lt;P&gt;2) Allow ICMP ACE on the ACL is applied on the private interface&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2015 10:19:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621515#M195479</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-03-30T10:19:04Z</dc:date>
    </item>
    <item>
      <title>thanks Vibhor,I have a static</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621516#M195480</link>
      <description>&lt;P&gt;thanks Vibhor,&lt;/P&gt;&lt;P&gt;I have a static one to one Nat applied,no port forwarding is done.&lt;/P&gt;&lt;P&gt;Kindly let me know how to allow icmp inspect for a particular interface.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2015 10:47:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621516#M195480</guid>
      <dc:creator>mudasir05</dc:creator>
      <dc:date>2015-03-30T10:47:01Z</dc:date>
    </item>
    <item>
      <title>Hi,You just need to run this</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621517#M195481</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You just need to run this command:- &lt;STRONG&gt;fixup protocol icmp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;This is a global feature and will be enabled for the complete device.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Also , run a packet trace to find out what policies are being hit on the ASA device for this traffic ?&lt;/P&gt;&lt;P&gt;Refer:-&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/document/29601/troubleshooting-access-problems-using-packet-tracer&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2015 11:29:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621517#M195481</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-03-30T11:29:57Z</dc:date>
    </item>
    <item>
      <title>i have a ubunto server which</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621518#M195482</link>
      <description>&lt;P&gt;i have a ubunto server which i am not able to update or upgrade as its not able to access the internet...&lt;/P&gt;&lt;P&gt;not sure where the problem is....i ran the packet tracer it shows the implicit configured rule is the problem for the configured dmz and when i checked that rule its there by default as iam unable to edit or delete it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2015 14:51:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621518#M195482</guid>
      <dc:creator>mudasir05</dc:creator>
      <dc:date>2015-03-30T14:51:33Z</dc:date>
    </item>
    <item>
      <title>How are you trying to access</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621519#M195483</link>
      <description>&lt;P&gt;How are you trying to access the internet from the server&amp;nbsp;ie. what port are you testing on ?&lt;/P&gt;&lt;P&gt;Can you post the ASA configuration.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2015 15:04:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621519#M195483</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-03-30T15:04:09Z</dc:date>
    </item>
    <item>
      <title>I have a Ubuntu Server which</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621520#M195484</link>
      <description>&lt;P&gt;I have a Ubuntu Server which is connected to the dmz port of the ASA and from there i try to ping google dns which iam not,also iam not able to update and upgrade my server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin: 0pt; padding: 0pt; color: rgb(87, 87, 87); font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;object network water_private&lt;/P&gt;&lt;P style="margin: 0pt; padding: 0pt; color: rgb(87, 87, 87); font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;&amp;nbsp;nat (dmz5,Jeraisy) static waterlevel_public&lt;/P&gt;&lt;P style="margin: 0pt; padding: 0pt; color: rgb(87, 87, 87); font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;access-group Jeraisy_access in interface Jeraisy&lt;/P&gt;&lt;P style="margin: 0pt; padding: 0pt; color: rgb(87, 87, 87); font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;access-list Jeraisy_access extended permit object-group DM_INLINE_SERVICE_6 any4 object water_private&lt;/P&gt;&lt;P style="margin: 0pt; padding: 0pt; color: rgb(87, 87, 87); font-family: arial, helvetica, sans-serif; font-size: 13px;"&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;route Jeraisy 0.0.0.0 0.0.0.0 83.101.xx.xx&amp;nbsp;2&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2015 15:59:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621520#M195484</guid>
      <dc:creator>mudasir05</dc:creator>
      <dc:date>2015-03-30T15:59:57Z</dc:date>
    </item>
    <item>
      <title>Hi,I see that you mentioned</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621521#M195485</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I see that you mentioned the packet tracer drops this traffic ? Can you post the trace output ?&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2015 00:45:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621521#M195485</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-03-31T00:45:08Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor,I tried with the</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621522#M195486</link>
      <description>&lt;P&gt;Hi Vibhor,&lt;/P&gt;&lt;P&gt;I tried with the&amp;nbsp;&lt;STRONG style="font-size: 14.4444446563721px;"&gt;fixup protocol icmp but didn't worked.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 14.4444446563721px;"&gt;kindly find the attached packet tracer from my outside&amp;nbsp;interface to google dns..&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2015 14:45:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621522#M195486</guid>
      <dc:creator>mudasir05</dc:creator>
      <dc:date>2015-03-31T14:45:56Z</dc:date>
    </item>
    <item>
      <title>I thought "Jeraisy" was your</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621523#M195487</link>
      <description>&lt;P&gt;I thought "Jeraisy" was your outside interface but that's not what your packet tracer is saying.&lt;/P&gt;&lt;P&gt;Can you just post the configuration of the firewall.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2015 15:17:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621523#M195487</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-03-31T15:17:42Z</dc:date>
    </item>
    <item>
      <title>Hi Jon, yes Jeraisy is our</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621524#M195488</link>
      <description>&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes Jeraisy is our another outside interface facing another ISP.&lt;/P&gt;&lt;P&gt;plz find attached config&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2015 15:42:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621524#M195488</guid>
      <dc:creator>mudasir05</dc:creator>
      <dc:date>2015-03-31T15:42:17Z</dc:date>
    </item>
    <item>
      <title>route outside 0.0.0.0 0.0.0.0</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621525#M195489</link>
      <description>&lt;P&gt;Can you post "sh route"&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2015 16:02:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621525#M195489</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-03-31T16:02:27Z</dc:date>
    </item>
    <item>
      <title>Okay I think the problem is</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621526#M195490</link>
      <description>&lt;P&gt;Okay I think the problem is you have two outside interfaces.&lt;/P&gt;&lt;P&gt;Your default route is pointing to the outside interface.&lt;/P&gt;&lt;P&gt;So when&amp;nbsp;the server initiates the connection you have setup a&amp;nbsp;static to the Jeraisy interface IP but the ASA routes the traffic to the outside interface and there is no translation for your server.&lt;/P&gt;&lt;P&gt;You cannot have multiple default routes via different interfaces.&lt;/P&gt;&lt;P&gt;So what you may have to do is -&lt;/P&gt;&lt;P&gt;1) setup static PAT translations for the ports you want using the Jeraisy interface&lt;/P&gt;&lt;P&gt;2) then setup up a dynamic NAT for the server to the outside interface for traffic it initiates.&lt;/P&gt;&lt;P&gt;You won't, unless Vibhor knows a way, be able to use the Jeraisy ISP for traffic initiated from the server.&lt;/P&gt;&lt;P&gt;Unless of course you wanted to use contexts in which case you could have the server DMZ and the Jeraisy outside interface in their own context.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2015 16:14:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621526#M195490</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-03-31T16:14:12Z</dc:date>
    </item>
    <item>
      <title>thanks Jon,if somehow I setup</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621527#M195491</link>
      <description>&lt;P&gt;thanks Jon,&lt;/P&gt;&lt;P&gt;if somehow I setup the static PAT translations and Dynamic NAT then in that case also I have to configure the static route.....am I right?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2015 06:15:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621527#M195491</guid>
      <dc:creator>mudasir05</dc:creator>
      <dc:date>2015-04-01T06:15:11Z</dc:date>
    </item>
    <item>
      <title>Hi,I agree with Jon on this</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621528#M195492</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I agree with Jon on this issue that because you have two ISP and the one which is secondary , would never be used for routing the traffic outbound to the internet.&lt;/P&gt;&lt;P&gt;There is a Workaround that can be used but that should only be used cautiously:-&lt;/P&gt;&lt;P&gt;If you are okay to route all the outbound traffic for a specific destination port out through the ISP 2 (Jeraisy ) For ex:-&lt;/P&gt;&lt;P&gt;If you want all the outbound traffic destined to port 80 to go out through this interface , you can create a statement like this:-&lt;/P&gt;&lt;P style="padding-left:90px"&gt;static (Jeraisy ,DMZ5) tcp 0.0.0.0 80 0.0.0.0 80&lt;/P&gt;&lt;P style="padding-left:90px"&gt;You can refer to these articles for all the possible options in this scenario:-&lt;/P&gt;&lt;P style="padding-left:90px"&gt;https://supportforums.cisco.com/document/49756/asapix-load-balancing-between-two-isp-options&lt;/P&gt;&lt;P style="padding-left:90px"&gt;https://supportforums.cisco.com/document/59986/loadbalancing-dual-isp-asa&lt;/P&gt;&lt;P style="padding-left:90px"&gt;Thanks and Regards,&lt;/P&gt;&lt;P style="padding-left:90px"&gt;Vibhor Amrodia&lt;/P&gt;&lt;P style="padding-left:90px"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2015 11:07:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621528#M195492</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-04-01T11:07:53Z</dc:date>
    </item>
    <item>
      <title>thanks Vibhor,Do i need to</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621529#M195493</link>
      <description>&lt;P&gt;thanks Vibhor,&lt;/P&gt;&lt;P&gt;Do i need to add router also in my topology?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2015 14:10:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621529#M195493</guid>
      <dc:creator>mudasir05</dc:creator>
      <dc:date>2015-04-01T14:10:16Z</dc:date>
    </item>
    <item>
      <title>A router in front of your</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621530#M195494</link>
      <description>&lt;P&gt;A router in front of your firewall would allow you to connect both ISPs to the router and only have one outside interface on the ASA.&lt;/P&gt;&lt;P&gt;Then you can use PBR on the router to direct traffic via whichever ISP you wanted based on the source IP address of the device i.e you would translate your server to a specific IP and then send it down the Jeraisy link.&lt;/P&gt;&lt;P&gt;PBR can also distinguish with ports as well which gives you more flexibility.&lt;/P&gt;&lt;P&gt;That said I believe there is a release of code for the ASA due soon that will support PBR and that would also solve your issue.&lt;/P&gt;&lt;P&gt;Perhaps Vibhor could provide some more details on that.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2015 17:05:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621530#M195494</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-04-01T17:05:26Z</dc:date>
    </item>
    <item>
      <title>thanks Jon for the info...</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621531#M195495</link>
      <description>&lt;P&gt;thanks Jon for the info....&lt;/P&gt;&lt;P&gt;will try this definitely on my router and will let u know..&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2015 06:25:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621531#M195495</guid>
      <dc:creator>mudasir05</dc:creator>
      <dc:date>2015-04-02T06:25:17Z</dc:date>
    </item>
    <item>
      <title>Hi,Yes , I think we already</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621532#M195496</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes , I think we already have the ASA code 9.4.1 which supports PBR. SO , an upgrade should help you out with this issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa94/release/notes/asarn94.html&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2015 10:13:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-internet-from-dmz-server/m-p/2621532#M195496</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-04-02T10:13:57Z</dc:date>
    </item>
  </channel>
</rss>

