<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic It is a little unclear if you in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-9-1-unable-to-allow-traffic-from-internet-to-internal-hosts/m-p/2587884#M199337</link>
    <description>&lt;P&gt;It is a little unclear if you are trying to access the servers from the internet or if you are having problems accessing the servers over the VPN?&lt;/P&gt;&lt;P&gt;If you are trying to access the servers over the VPN then make sure that the server IP addresses are included in the VPN ACL and that this traffic is also excluded from being NATed.&amp;nbsp; This needs to be done at both ends of the VPN tunnel.&lt;/P&gt;&lt;P&gt;If you require further help, please be more specific in where you are trying to access the servers from and, if this is over the VPN, please provide the running config from both sites.&amp;nbsp; This should be the running config of the two ASAs that are working incorrectly and not the running config of the rollback ASA.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
    <pubDate>Tue, 30 Dec 2014 13:12:40 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2014-12-30T13:12:40Z</dc:date>
    <item>
      <title>ASA 9.1 Unable to allow traffic from internet to internal hosts using  Static PAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-unable-to-allow-traffic-from-internet-to-internal-hosts/m-p/2587882#M199333</link>
      <description>&lt;P&gt;Hello, we have recently purchased a new Cisco ASA 5545-x running version 9.1 with ASDM 7.1. &amp;nbsp; I was able to configure the firewall for internal access to the outside, and have our remote site-to-site VPN tunnels working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, when I try to configure static PAT and ACL for access to our internal servers,our ouside network unable to access our inside servers that are connected to the DMZ interface but the hosts in the inside are able to access the servers located in the DMZ .&lt;/P&gt;&lt;P&gt;Outside traffic are trying &amp;nbsp;to access below servers from gateway through the dmz to the servers.&lt;/P&gt;&lt;P&gt;below are the ip's for the dmz,inside,outside interfaces:&lt;/P&gt;&lt;P&gt;Context: single_vf, Interface: DMZ&lt;BR /&gt;&amp;nbsp; 192.168.200.46 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Active &amp;nbsp; 0016.3e1a.6c1d hits 0&lt;BR /&gt;&amp;nbsp; 192.168.200.45 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Active &amp;nbsp; 00ff.4cdb.3a68 hits 353&lt;BR /&gt;&amp;nbsp; 192.168.200.37 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Active &amp;nbsp; 0026.557e.c22a hits 9&lt;BR /&gt;&amp;nbsp; 192.168.200.5 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Active &amp;nbsp; 0023.7de9.06f4 hits 17060&lt;BR /&gt;&amp;nbsp; 192.168.200.44 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Active &amp;nbsp; 18a9.0576.edd8 hits 193&lt;BR /&gt;&amp;nbsp; 192.168.200.220 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Active &amp;nbsp; 0023.ead2.34c0 hits 134&lt;BR /&gt;&amp;nbsp; 192.168.200.47 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Active &amp;nbsp; f4ce.4680.77c4 hits 5&lt;BR /&gt;&amp;nbsp; 192.168.200.35 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Active &amp;nbsp; 0026.557c.1d80 hits 10496&lt;BR /&gt;&amp;nbsp; 192.168.200.36 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Active &amp;nbsp; 0016.3e5c.6400 hits 40&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;Context: single_vf, Interface: inside&lt;BR /&gt;&amp;nbsp; 192.168.55.2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Active &amp;nbsp; 0000.0c07.ac37 hits 491437&lt;/P&gt;&lt;P&gt;Context: single_vf, Interface: outside&lt;BR /&gt;&amp;nbsp; 87.101.181.165 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Active &amp;nbsp; 0024.1466.12e7 hits 3179&lt;BR /&gt;&amp;nbsp; 86.51.14.50 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Active &amp;nbsp; 0024.1466.12e7 hits 190993&lt;/P&gt;&lt;P&gt;I have attached a running config as well for your reference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have this configuration working on ASA-5510 unfortunately i had to do roll back to this firewall &amp;nbsp;ASA 5510 from the new one connected to do the ASA 5545-x.&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;&lt;P&gt;Thank you...&lt;BR /&gt;Farooq Mirza.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:17:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-unable-to-allow-traffic-from-internet-to-internal-hosts/m-p/2587882#M199333</guid>
      <dc:creator>farooq.mirza</dc:creator>
      <dc:date>2019-03-12T05:17:02Z</dc:date>
    </item>
    <item>
      <title>Hi,I think you would need to</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-unable-to-allow-traffic-from-internet-to-internal-hosts/m-p/2587883#M199335</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I think you would need to share the Non-Working configuration from the ASA device as well.&lt;/P&gt;&lt;P&gt;Also , try to run the packet tracer simulating the traffic from the Outside to Inside and see which policy is dropping the traffic for you.&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/document/29601/troubleshooting-access-problems-using-packet-tracer&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2014 10:24:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-unable-to-allow-traffic-from-internet-to-internal-hosts/m-p/2587883#M199335</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2014-12-30T10:24:24Z</dc:date>
    </item>
    <item>
      <title>It is a little unclear if you</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-unable-to-allow-traffic-from-internet-to-internal-hosts/m-p/2587884#M199337</link>
      <description>&lt;P&gt;It is a little unclear if you are trying to access the servers from the internet or if you are having problems accessing the servers over the VPN?&lt;/P&gt;&lt;P&gt;If you are trying to access the servers over the VPN then make sure that the server IP addresses are included in the VPN ACL and that this traffic is also excluded from being NATed.&amp;nbsp; This needs to be done at both ends of the VPN tunnel.&lt;/P&gt;&lt;P&gt;If you require further help, please be more specific in where you are trying to access the servers from and, if this is over the VPN, please provide the running config from both sites.&amp;nbsp; This should be the running config of the two ASAs that are working incorrectly and not the running config of the rollback ASA.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2014 13:12:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-unable-to-allow-traffic-from-internet-to-internal-hosts/m-p/2587884#M199337</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-12-30T13:12:40Z</dc:date>
    </item>
    <item>
      <title>Hello,I am trying to access</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-unable-to-allow-traffic-from-internet-to-internal-hosts/m-p/2587885#M199339</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am trying to access the the servers over L2TP VPN not over Site to Site VPN.&lt;/P&gt;&lt;P&gt;I have attached the Non-Working configuration from the ASA as well.&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;&lt;P&gt;Thank you..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2014 14:12:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-unable-to-allow-traffic-from-internet-to-internal-hosts/m-p/2587885#M199339</guid>
      <dc:creator>farooq.mirza</dc:creator>
      <dc:date>2014-12-30T14:12:45Z</dc:date>
    </item>
    <item>
      <title>Hello,I am trying to access</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-unable-to-allow-traffic-from-internet-to-internal-hosts/m-p/2587886#M199340</link>
      <description>&lt;P style="font-size: 14px;"&gt;Hello,&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;I am trying to access the the servers over L2TP VPN not over Site to Site VPN.&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;I have attached the Non-Working configuration from the ASA as well.&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;Please advise.&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;Thank you..&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2014 05:59:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-unable-to-allow-traffic-from-internet-to-internal-hosts/m-p/2587886#M199340</guid>
      <dc:creator>farooq.mirza</dc:creator>
      <dc:date>2014-12-31T05:59:20Z</dc:date>
    </item>
  </channel>
</rss>

