<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Stuck at work in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/stuck-at-work/m-p/2620915#M196577</link>
    <description>&lt;P&gt;Guys I have a Cisco asa 5505. It has been working perfectly fine until round 5pm yesterday evening when i got the call the internet was down at this office. i logged in to start to troubleshooting the issue and looked. nothing supposed changed on the firewall &amp;nbsp;I looked and didnt see anything either. so i called the isp no issues. even verified by plugging a laptop directly into the external and testing works fine. I'm stumped as i can test the ping from the asa no issues inbound or out bound. attached the config if any way could tell em anything that looks like would stop it. again i apologize for my ignorance as trying to learn as much on asa's as possible.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.30.5.2 255.255.255.0&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 72.64.148.113 255.255.255.0&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;&amp;nbsp;switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;&amp;nbsp;domain-name&amp;nbsp;&lt;BR /&gt;object network obj_any&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network NETWORK_OBJ_10.10.0.0_24&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.10.0.0 255.255.255.0&lt;BR /&gt;object network 10.10.11.0_24&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.10.11.0 255.255.255.0&lt;BR /&gt;object network 10.10.12.0_24&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.10.12.0 255.255.255.0&lt;BR /&gt;object network 10.10.13.0_24&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.10.13.0 255.255.255.0&lt;BR /&gt;object network 10.10.96.0_24&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.10.96.0 255.255.255.0&lt;BR /&gt;object network 10.2.0.0_24&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.2.0.0 255.255.255.0&lt;BR /&gt;object network 10.3.0.0_24&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.3.0.0 255.255.255.0&lt;BR /&gt;object network 10.30.1.0&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.30.1.0 255.255.255.0&lt;BR /&gt;object network 10.10.51.0&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.10.51.0 255.255.255.0&lt;BR /&gt;object network 10.5.0.0&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.5.0.0 255.255.255.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_1&lt;BR /&gt;&amp;nbsp;network-object 10.10.51.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.5.0.0 255.255.255.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_2&lt;BR /&gt;&amp;nbsp;network-object 10.10.51.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.5.0.0 255.255.255.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_3&lt;BR /&gt;&amp;nbsp;network-object 10.10.82.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.10.85.0 255.255.255.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_4&lt;BR /&gt;&amp;nbsp;network-object 10.10.51.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.5.0.0 255.255.255.0&lt;BR /&gt;object-group network Oak_New&lt;BR /&gt;&amp;nbsp;network-object object 10.10.11.0_24&lt;BR /&gt;&amp;nbsp;network-object object 10.10.12.0_24&lt;BR /&gt;&amp;nbsp;network-object object 10.10.13.0_24&lt;BR /&gt;&amp;nbsp;network-object object 10.10.96.0_24&lt;BR /&gt;&amp;nbsp;network-object object 10.2.0.0_24&lt;BR /&gt;&amp;nbsp;network-object object 10.3.0.0_24&lt;BR /&gt;object-group network DM_INLINE_NETWORK_5&lt;BR /&gt;&amp;nbsp;network-object 10.10.51.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.5.0.0 255.255.255.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_6&lt;BR /&gt;&amp;nbsp;network-object 10.5.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object object 10.10.51.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_7&lt;BR /&gt;&amp;nbsp;network-object object 10.10.51.0&lt;BR /&gt;&amp;nbsp;network-object object 10.5.0.0&lt;BR /&gt;access-list outside_access_in extended permit icmp any any time-exceeded&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit icmp any any unreachable&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit icmp any any echo-reply&amp;nbsp;&lt;BR /&gt;access-list outside_1_cryptomap extended permit ip object-group DM_INLINE_NETWORK_1 10.10.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list outside_2_cryptomap extended permit ip object-group DM_INLINE_NETWORK_2 object-group DM_INLINE_NETWORK_3&amp;nbsp;&lt;BR /&gt;access-list outside_3_cryptomap extended permit ip object-group DM_INLINE_NETWORK_4 object-group Oak_New&amp;nbsp;&lt;BR /&gt;access-list outside_cryptomap extended permit ip object-group DM_INLINE_NETWORK_5 object-group Oak_New&amp;nbsp;&lt;BR /&gt;access-list outside_cryptomap_1 extended permit ip object-group DM_INLINE_NETWORK_6 object 10.30.1.0&amp;nbsp;&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;nat (inside,outside) source static DM_INLINE_NETWORK_7 DM_INLINE_NETWORK_7 destination static 10.30.1.0 10.30.1.0&lt;BR /&gt;nat (inside,outside) source static DM_INLINE_NETWORK_4 DM_INLINE_NETWORK_4 destination static Oak_New Oak_New&lt;BR /&gt;nat (inside,outside) source static DM_INLINE_NETWORK_1 DM_INLINE_NETWORK_1 destination static NETWORK_OBJ_10.10.0.0_24 NETWORK_OBJ_10.10.0.0_24&lt;BR /&gt;nat (inside,outside) source static DM_INLINE_NETWORK_2 DM_INLINE_NETWORK_2 destination static DM_INLINE_NETWORK_3 DM_INLINE_NETWORK_3&lt;BR /&gt;!&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;BR /&gt;!&lt;BR /&gt;nat (inside,outside) after-auto source dynamic any interface&lt;BR /&gt;access-group outside_access_in in interface outside&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 72.64.148.1 1&lt;BR /&gt;route inside 10.5.0.0 255.255.255.0 10.30.5.1 1&lt;BR /&gt;route inside 10.10.51.0 255.255.255.0 10.30.5.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside&lt;BR /&gt;http 50.199.101.249 255.255.255.255 outside&lt;BR /&gt;http 10.10.51.0 255.255.255.0 inside&lt;BR /&gt;http 10.30.5.0 255.255.255.0 inside&lt;BR /&gt;http 66.194.205.54 255.255.255.255 outside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-SHA-TRANS esp-aes esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-MD5-TRANS esp-aes esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-SHA-TRANS esp-aes-192 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-MD5-TRANS esp-aes-192 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-SHA-TRANS esp-aes-256 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-MD5-TRANS esp-aes-256 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-3DES-SHA-TRANS esp-3des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-3DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-3DES-MD5-TRANS esp-3des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-3DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-DES-SHA-TRANS esp-des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-DES-MD5-TRANS esp-des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;crypto map outside_map 1 match address outside_1_cryptomap&lt;BR /&gt;crypto map outside_map 1 set pfs&amp;nbsp;&lt;BR /&gt;crypto map outside_map 1 set peer 66.194.205.54&amp;nbsp;&lt;BR /&gt;crypto map outside_map 1 set transform-set ESP-3DES-SHA&lt;BR /&gt;crypto map outside_map 2 match address outside_2_cryptomap&lt;BR /&gt;crypto map outside_map 2 set pfs group1&lt;BR /&gt;crypto map outside_map 2 set peer 50.199.101.249&amp;nbsp;&lt;BR /&gt;crypto map outside_map 2 set transform-set ESP-3DES-SHA&lt;BR /&gt;crypto map outside_map 3 match address outside_3_cryptomap&lt;BR /&gt;crypto map outside_map 3 set peer 50.192.34.253&amp;nbsp;&lt;BR /&gt;crypto map outside_map 3 set transform-set ESP-AES-128-SHA&lt;BR /&gt;crypto map outside_map 4 match address outside_cryptomap&lt;BR /&gt;crypto map outside_map 4 set peer 50.192.34.253&amp;nbsp;&lt;BR /&gt;crypto map outside_map 4 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_map 5 match address outside_cryptomap_1&lt;BR /&gt;crypto map outside_map 5 set peer 50.79.225.66&amp;nbsp;&lt;BR /&gt;crypto map outside_map 5 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_map interface outside&lt;BR /&gt;crypto isakmp enable outside&lt;BR /&gt;crypto isakmp policy 10&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto isakmp policy 30&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 5&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd auto_config outside&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics port&lt;BR /&gt;threat-detection statistics protocol&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;webvpn&lt;BR /&gt;group-policy GroupPolicy1 internal&lt;BR /&gt;group-policy GroupPolicy1 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol IPSec&amp;nbsp;&lt;BR /&gt;username dkraut password 6iNmW1JnA8NEZk4S encrypted privilege 15&lt;BR /&gt;tunnel-group 66.194.205.54 type ipsec-l2l&lt;BR /&gt;tunnel-group 66.194.205.54 ipsec-attributes&lt;BR /&gt;&amp;nbsp;pre-shared-key *****&lt;BR /&gt;tunnel-group 50.199.101.249 type ipsec-l2l&lt;BR /&gt;tunnel-group 50.199.101.249 ipsec-attributes&lt;BR /&gt;&amp;nbsp;pre-shared-key *****&lt;BR /&gt;tunnel-group Oak type ipsec-l2l&lt;BR /&gt;tunnel-group Oak ipsec-attributes&lt;BR /&gt;&amp;nbsp;pre-shared-key *****&lt;BR /&gt;tunnel-group 50.192.34.253 type ipsec-l2l&lt;BR /&gt;tunnel-group 50.192.34.253 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy1&lt;BR /&gt;tunnel-group 50.192.34.253 ipsec-attributes&lt;BR /&gt;&amp;nbsp;pre-shared-key *****&lt;BR /&gt;tunnel-group 50.79.225.66 type ipsec-l2l&lt;BR /&gt;tunnel-group 50.79.225.66 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy1&lt;BR /&gt;tunnel-group 50.79.225.66 ipsec-attributes&lt;BR /&gt;&amp;nbsp;pre-shared-key *****&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 h225&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 ras&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rsh&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rtsp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect esmtp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sqlnet&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect xdmcp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect tftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ip-options&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect pptp&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&amp;nbsp;&lt;BR /&gt;call-home&lt;BR /&gt;&amp;nbsp;profile CiscoTAC-1&lt;BR /&gt;&amp;nbsp; no active&lt;BR /&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;BR /&gt;&amp;nbsp; destination transport-method http&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;hpm topN enable&lt;BR /&gt;Cryptochecksum:08ba45188992f77e9f9105aa46772839&lt;BR /&gt;: end&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:35:15 GMT</pubDate>
    <dc:creator>Shawn.gaston1</dc:creator>
    <dc:date>2019-03-12T05:35:15Z</dc:date>
    <item>
      <title>Stuck at work</title>
      <link>https://community.cisco.com/t5/network-security/stuck-at-work/m-p/2620915#M196577</link>
      <description>&lt;P&gt;Guys I have a Cisco asa 5505. It has been working perfectly fine until round 5pm yesterday evening when i got the call the internet was down at this office. i logged in to start to troubleshooting the issue and looked. nothing supposed changed on the firewall &amp;nbsp;I looked and didnt see anything either. so i called the isp no issues. even verified by plugging a laptop directly into the external and testing works fine. I'm stumped as i can test the ping from the asa no issues inbound or out bound. attached the config if any way could tell em anything that looks like would stop it. again i apologize for my ignorance as trying to learn as much on asa's as possible.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.30.5.2 255.255.255.0&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt;&amp;nbsp;nameif outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 72.64.148.113 255.255.255.0&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;&amp;nbsp;switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;&amp;nbsp;domain-name&amp;nbsp;&lt;BR /&gt;object network obj_any&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network NETWORK_OBJ_10.10.0.0_24&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.10.0.0 255.255.255.0&lt;BR /&gt;object network 10.10.11.0_24&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.10.11.0 255.255.255.0&lt;BR /&gt;object network 10.10.12.0_24&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.10.12.0 255.255.255.0&lt;BR /&gt;object network 10.10.13.0_24&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.10.13.0 255.255.255.0&lt;BR /&gt;object network 10.10.96.0_24&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.10.96.0 255.255.255.0&lt;BR /&gt;object network 10.2.0.0_24&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.2.0.0 255.255.255.0&lt;BR /&gt;object network 10.3.0.0_24&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.3.0.0 255.255.255.0&lt;BR /&gt;object network 10.30.1.0&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.30.1.0 255.255.255.0&lt;BR /&gt;object network 10.10.51.0&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.10.51.0 255.255.255.0&lt;BR /&gt;object network 10.5.0.0&amp;nbsp;&lt;BR /&gt;&amp;nbsp;subnet 10.5.0.0 255.255.255.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_1&lt;BR /&gt;&amp;nbsp;network-object 10.10.51.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.5.0.0 255.255.255.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_2&lt;BR /&gt;&amp;nbsp;network-object 10.10.51.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.5.0.0 255.255.255.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_3&lt;BR /&gt;&amp;nbsp;network-object 10.10.82.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.10.85.0 255.255.255.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_4&lt;BR /&gt;&amp;nbsp;network-object 10.10.51.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.5.0.0 255.255.255.0&lt;BR /&gt;object-group network Oak_New&lt;BR /&gt;&amp;nbsp;network-object object 10.10.11.0_24&lt;BR /&gt;&amp;nbsp;network-object object 10.10.12.0_24&lt;BR /&gt;&amp;nbsp;network-object object 10.10.13.0_24&lt;BR /&gt;&amp;nbsp;network-object object 10.10.96.0_24&lt;BR /&gt;&amp;nbsp;network-object object 10.2.0.0_24&lt;BR /&gt;&amp;nbsp;network-object object 10.3.0.0_24&lt;BR /&gt;object-group network DM_INLINE_NETWORK_5&lt;BR /&gt;&amp;nbsp;network-object 10.10.51.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object 10.5.0.0 255.255.255.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_6&lt;BR /&gt;&amp;nbsp;network-object 10.5.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;network-object object 10.10.51.0&lt;BR /&gt;object-group network DM_INLINE_NETWORK_7&lt;BR /&gt;&amp;nbsp;network-object object 10.10.51.0&lt;BR /&gt;&amp;nbsp;network-object object 10.5.0.0&lt;BR /&gt;access-list outside_access_in extended permit icmp any any time-exceeded&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit icmp any any unreachable&amp;nbsp;&lt;BR /&gt;access-list outside_access_in extended permit icmp any any echo-reply&amp;nbsp;&lt;BR /&gt;access-list outside_1_cryptomap extended permit ip object-group DM_INLINE_NETWORK_1 10.10.0.0 255.255.255.0&amp;nbsp;&lt;BR /&gt;access-list outside_2_cryptomap extended permit ip object-group DM_INLINE_NETWORK_2 object-group DM_INLINE_NETWORK_3&amp;nbsp;&lt;BR /&gt;access-list outside_3_cryptomap extended permit ip object-group DM_INLINE_NETWORK_4 object-group Oak_New&amp;nbsp;&lt;BR /&gt;access-list outside_cryptomap extended permit ip object-group DM_INLINE_NETWORK_5 object-group Oak_New&amp;nbsp;&lt;BR /&gt;access-list outside_cryptomap_1 extended permit ip object-group DM_INLINE_NETWORK_6 object 10.30.1.0&amp;nbsp;&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;nat (inside,outside) source static DM_INLINE_NETWORK_7 DM_INLINE_NETWORK_7 destination static 10.30.1.0 10.30.1.0&lt;BR /&gt;nat (inside,outside) source static DM_INLINE_NETWORK_4 DM_INLINE_NETWORK_4 destination static Oak_New Oak_New&lt;BR /&gt;nat (inside,outside) source static DM_INLINE_NETWORK_1 DM_INLINE_NETWORK_1 destination static NETWORK_OBJ_10.10.0.0_24 NETWORK_OBJ_10.10.0.0_24&lt;BR /&gt;nat (inside,outside) source static DM_INLINE_NETWORK_2 DM_INLINE_NETWORK_2 destination static DM_INLINE_NETWORK_3 DM_INLINE_NETWORK_3&lt;BR /&gt;!&lt;BR /&gt;object network obj_any&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;BR /&gt;!&lt;BR /&gt;nat (inside,outside) after-auto source dynamic any interface&lt;BR /&gt;access-group outside_access_in in interface outside&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 72.64.148.1 1&lt;BR /&gt;route inside 10.5.0.0 255.255.255.0 10.30.5.1 1&lt;BR /&gt;route inside 10.10.51.0 255.255.255.0 10.30.5.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside&lt;BR /&gt;http 50.199.101.249 255.255.255.255 outside&lt;BR /&gt;http 10.10.51.0 255.255.255.0 inside&lt;BR /&gt;http 10.30.5.0 255.255.255.0 inside&lt;BR /&gt;http 66.194.205.54 255.255.255.255 outside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-SHA-TRANS esp-aes esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-MD5-TRANS esp-aes esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-SHA-TRANS esp-aes-192 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-MD5-TRANS esp-aes-192 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-192-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-SHA-TRANS esp-aes-256 esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-MD5-TRANS esp-aes-256 esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-256-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-3DES-SHA-TRANS esp-3des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-3DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-3DES-MD5-TRANS esp-3des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-3DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-DES-SHA-TRANS esp-des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-DES-MD5-TRANS esp-des esp-md5-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&amp;nbsp;&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;crypto map outside_map 1 match address outside_1_cryptomap&lt;BR /&gt;crypto map outside_map 1 set pfs&amp;nbsp;&lt;BR /&gt;crypto map outside_map 1 set peer 66.194.205.54&amp;nbsp;&lt;BR /&gt;crypto map outside_map 1 set transform-set ESP-3DES-SHA&lt;BR /&gt;crypto map outside_map 2 match address outside_2_cryptomap&lt;BR /&gt;crypto map outside_map 2 set pfs group1&lt;BR /&gt;crypto map outside_map 2 set peer 50.199.101.249&amp;nbsp;&lt;BR /&gt;crypto map outside_map 2 set transform-set ESP-3DES-SHA&lt;BR /&gt;crypto map outside_map 3 match address outside_3_cryptomap&lt;BR /&gt;crypto map outside_map 3 set peer 50.192.34.253&amp;nbsp;&lt;BR /&gt;crypto map outside_map 3 set transform-set ESP-AES-128-SHA&lt;BR /&gt;crypto map outside_map 4 match address outside_cryptomap&lt;BR /&gt;crypto map outside_map 4 set peer 50.192.34.253&amp;nbsp;&lt;BR /&gt;crypto map outside_map 4 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_map 5 match address outside_cryptomap_1&lt;BR /&gt;crypto map outside_map 5 set peer 50.79.225.66&amp;nbsp;&lt;BR /&gt;crypto map outside_map 5 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map outside_map interface outside&lt;BR /&gt;crypto isakmp enable outside&lt;BR /&gt;crypto isakmp policy 10&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto isakmp policy 30&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 5&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd auto_config outside&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics port&lt;BR /&gt;threat-detection statistics protocol&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;webvpn&lt;BR /&gt;group-policy GroupPolicy1 internal&lt;BR /&gt;group-policy GroupPolicy1 attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol IPSec&amp;nbsp;&lt;BR /&gt;username dkraut password 6iNmW1JnA8NEZk4S encrypted privilege 15&lt;BR /&gt;tunnel-group 66.194.205.54 type ipsec-l2l&lt;BR /&gt;tunnel-group 66.194.205.54 ipsec-attributes&lt;BR /&gt;&amp;nbsp;pre-shared-key *****&lt;BR /&gt;tunnel-group 50.199.101.249 type ipsec-l2l&lt;BR /&gt;tunnel-group 50.199.101.249 ipsec-attributes&lt;BR /&gt;&amp;nbsp;pre-shared-key *****&lt;BR /&gt;tunnel-group Oak type ipsec-l2l&lt;BR /&gt;tunnel-group Oak ipsec-attributes&lt;BR /&gt;&amp;nbsp;pre-shared-key *****&lt;BR /&gt;tunnel-group 50.192.34.253 type ipsec-l2l&lt;BR /&gt;tunnel-group 50.192.34.253 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy1&lt;BR /&gt;tunnel-group 50.192.34.253 ipsec-attributes&lt;BR /&gt;&amp;nbsp;pre-shared-key *****&lt;BR /&gt;tunnel-group 50.79.225.66 type ipsec-l2l&lt;BR /&gt;tunnel-group 50.79.225.66 general-attributes&lt;BR /&gt;&amp;nbsp;default-group-policy GroupPolicy1&lt;BR /&gt;tunnel-group 50.79.225.66 ipsec-attributes&lt;BR /&gt;&amp;nbsp;pre-shared-key *****&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 h225&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect h323 ras&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rsh&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect rtsp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect esmtp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sqlnet&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sunrpc&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect xdmcp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect netbios&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect tftp&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect ip-options&amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect pptp&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&amp;nbsp;&lt;BR /&gt;call-home&lt;BR /&gt;&amp;nbsp;profile CiscoTAC-1&lt;BR /&gt;&amp;nbsp; no active&lt;BR /&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;BR /&gt;&amp;nbsp; destination transport-method http&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;hpm topN enable&lt;BR /&gt;Cryptochecksum:08ba45188992f77e9f9105aa46772839&lt;BR /&gt;: end&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:35:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/stuck-at-work/m-p/2620915#M196577</guid>
      <dc:creator>Shawn.gaston1</dc:creator>
      <dc:date>2019-03-12T05:35:15Z</dc:date>
    </item>
    <item>
      <title>Hi, Does everyone on the LAN</title>
      <link>https://community.cisco.com/t5/network-security/stuck-at-work/m-p/2620916#M196578</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does everyone on the LAN have the problem? Can anyone connect to the Internet?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your post seems to indicate that the ASA has normal connectivity through the WAN link to the Internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess next I would take one example host from the LAN for which connection dont work and step by step go through the situation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Check where the host tries to connect. I would imagine its always using a name that the host queries from the DNS server. If you have a local server acting as DNS server I would confirm that its able to provide the host with the IP address to its DNS queries. On a computer running Windows you could use the Start Menu -&amp;gt; Run -&amp;gt; nslookup and then write the destination DNS name to which the host tries to connect to determine if the host gets a DNS reply.&lt;/LI&gt;&lt;LI&gt;If the DNS portion is fine then I would confirm that the connectivity from the host to the firewall is fine. There are naturally multiple ways. You could ping the interface IP address of the ASA behind which the host is. If there is no reply then look through ASDM logs if you can see anything of the ICMP there.&lt;/LI&gt;&lt;LI&gt;You can naturally just try to connect with the host to the Internet and at the same time monitor the connection attempts through ASDM from this single host.&lt;/LI&gt;&lt;LI&gt;If you can't even see connection attempts on the firewall then I would turn my eye on the LAN networks devices. It seems you have an internal router since the ASA has routes towards some internal IP address. Make sure all the devices on the LAN are ok and have connectivity. Make sure that no changes have been made to them.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2015 08:35:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/stuck-at-work/m-p/2620916#M196578</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2015-03-04T08:35:46Z</dc:date>
    </item>
    <item>
      <title>Jouni I finally got it fixed.</title>
      <link>https://community.cisco.com/t5/network-security/stuck-at-work/m-p/2620917#M196579</link>
      <description>&lt;P&gt;Jouni I finally got it fixed. it was a nat issue. but why it changed I don't know. one thing is can you explain to me why I had to put the any any inside outside nat rule below any static nats for this to work? I don't really understand that part but as soon as I did that all came up fine. thanks for all your help again.&lt;/P&gt;</description>
      <pubDate>Sun, 08 Mar 2015 14:26:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/stuck-at-work/m-p/2620917#M196579</guid>
      <dc:creator>Shawn.gaston1</dc:creator>
      <dc:date>2015-03-08T14:26:47Z</dc:date>
    </item>
  </channel>
</rss>

