<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can we check now ?? . I need in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540204#M236326</link>
    <description>&lt;P&gt;Can we check now ?? . I need to check few things&lt;/P&gt;&lt;P&gt;1) NAT&lt;/P&gt;&lt;P&gt;join below webex&amp;nbsp;&lt;/P&gt;&lt;P&gt;https://meetings.webex.com/collabs/meetings/join?uuid=M7EXGIM8ID8WZKIJFTFXAJM5BK-512H&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Sandy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jul 2014 16:13:15 GMT</pubDate>
    <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
    <dc:date>2014-07-23T16:13:15Z</dc:date>
    <item>
      <title>asa explicit rule blocking the traffic.</title>
      <link>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540198#M236320</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;&lt;SPAN style="font-size:12px;"&gt;Hello All,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;&lt;SPAN style="font-size:12px;"&gt;On &lt;/SPAN&gt;ASA 5515 version 8.6,&amp;nbsp;&lt;SPAN style="font-size:12px;"&gt;I am trying to create a NAT and access list to allow RDP from outside public to inside private network.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;&lt;SPAN style="font-size:12px;"&gt;I was able to create it using the ASDM as I am comfortable with it and not a expert with CLI.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;&lt;SPAN style="font-size:12px;"&gt;When I tested it, it does not work no matter what. I tried to see the packet tracer and it said that the traffic was blocked by implicit rule.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;&lt;SPAN style="font-size:12px;"&gt;I tried to create an ACL and it said the ACL exists. However, it does not work as the packets are dropped.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;&lt;SPAN style="font-size:12px;"&gt;Any assistance or ideas is very much appreciated.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;&lt;SPAN style="font-size:12px;"&gt;Thanks!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;&lt;SPAN style="font-size:12px;"&gt;Saji&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:31:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540198#M236320</guid>
      <dc:creator>Saji Thomas</dc:creator>
      <dc:date>2019-03-12T04:31:05Z</dc:date>
    </item>
    <item>
      <title>Hi Share me your asa show</title>
      <link>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540199#M236321</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Share me your asa show runn configuration .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Sandy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2014 16:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540199#M236321</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-07-22T16:42:41Z</dc:date>
    </item>
    <item>
      <title>Can I email it to you? I am</title>
      <link>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540200#M236322</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;&lt;SPAN style="font-size:11px;"&gt;Can I email it to you? I am little hesitant to post the complete run config on the blog.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;&lt;SPAN style="font-size:11px;"&gt;I can also send you some screenshot of Packet tracer that shows that the packets are dropped at the inside interface because of a implicit rule. I think I have to create an access rule on the inside interface also which I do not see but I am worried to break something.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;&lt;SPAN style="font-size:11px;"&gt;Thanks Sandy!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2014 18:13:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540200#M236322</guid>
      <dc:creator>Saji Thomas</dc:creator>
      <dc:date>2014-07-22T18:13:46Z</dc:date>
    </item>
    <item>
      <title>Hi Sandy, Please take a look</title>
      <link>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540201#M236323</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;Hi Sandy, Please take a look at the picture.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2014 18:33:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540201#M236323</guid>
      <dc:creator>Saji Thomas</dc:creator>
      <dc:date>2014-07-22T18:33:27Z</dc:date>
    </item>
    <item>
      <title>Hi , What is your ASA code</title>
      <link>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540202#M236324</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;What is your ASA code version ??&lt;/P&gt;&lt;P&gt;share me following output alone&lt;/P&gt;&lt;P&gt;1) show runn access-list&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) show runn access-group&lt;/P&gt;&lt;P&gt;3) show runn static&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Sandy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2014 04:20:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540202#M236324</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-07-23T04:20:30Z</dc:date>
    </item>
    <item>
      <title>ASA Code is 8.6(1).I think</title>
      <link>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540203#M236325</link>
      <description>&lt;P&gt;ASA Code is 8.6(1).&lt;/P&gt;&lt;P&gt;I think the issue is we do not have any access list on the internal interface. Bit I am worried to change it because it is a implicit rule to allow everything from less secure networks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;Result of the command: "show run access-list"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;access-list 102 extended permit tcp any host 67.208.160.156 eq www&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.156 eq 3389&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit icmp any any echo-reply&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit icmp any any source-quench&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit icmp any any unreachable&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit icmp any any time-exceeded&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit ip any host 67.208.160.155&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.158 eq www&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit udp any host 67.208.160.158 eq netbios-ns inactive&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit udp any host 67.208.160.158 eq netbios-dgm inactive&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.158 eq netbios-ssn inactive&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.158 eq 445&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.158 eq ftp inactive&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.158 eq https&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.158 eq rtsp inactive&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.158 eq domain inactive&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit udp any host 67.208.160.158 eq domain inactive&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit udp any host 67.208.160.158 eq ntp&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.158 eq smtp inactive&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.158 eq ldap inactive&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.158 eq ldaps inactive&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.158 eq ssh inactive&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit object-group TCPUDP any host 67.208.160.158 eq 445&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit object-group TCPUDP any host 67.208.160.158 eq 554&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.158 object-group DM_INLINE_TCP_1&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit object-group TCPUDP any host 67.208.160.158 eq 4743&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.157 eq www&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.159 eq 2011&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit udp any host 67.208.160.159 eq 2011&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.159 eq 6001&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit udp any host 67.208.160.159 eq 6001&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.159 eq 22609&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit udp any host 67.208.160.159 eq 22609&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.160 eq 2011&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit udp any host 67.208.160.160 eq 2011&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit tcp any host 67.208.160.160 eq 6001&amp;nbsp;&lt;BR /&gt;access-list 102 extended permit udp any host 67.208.160.160 eq 6001&amp;nbsp;&lt;BR /&gt;access-list aaa standard permit host 0.0.0.0&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;Result of the command: "show runn access-group"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;access-group 102 in interface outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;Result of the command: "show runn static"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:georgia,serif;"&gt;show runn static&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2014 12:15:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540203#M236325</guid>
      <dc:creator>Saji Thomas</dc:creator>
      <dc:date>2014-07-23T12:15:58Z</dc:date>
    </item>
    <item>
      <title>Can we check now ?? . I need</title>
      <link>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540204#M236326</link>
      <description>&lt;P&gt;Can we check now ?? . I need to check few things&lt;/P&gt;&lt;P&gt;1) NAT&lt;/P&gt;&lt;P&gt;join below webex&amp;nbsp;&lt;/P&gt;&lt;P&gt;https://meetings.webex.com/collabs/meetings/join?uuid=M7EXGIM8ID8WZKIJFTFXAJM5BK-512H&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Sandy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2014 16:13:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540204#M236326</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-07-23T16:13:15Z</dc:date>
    </item>
    <item>
      <title>Yes.</title>
      <link>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540205#M236327</link>
      <description>&lt;P&gt;Yes.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2014 16:13:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540205#M236327</guid>
      <dc:creator>Saji Thomas</dc:creator>
      <dc:date>2014-07-23T16:13:16Z</dc:date>
    </item>
    <item>
      <title>Join Below meetinghttps:/</title>
      <link>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540206#M236328</link>
      <description>&lt;P&gt;Join Below meeting&lt;/P&gt;&lt;P&gt;&lt;A href="https://meetings.webex.com/collabs/meetings/join?uuid=M7EXGIM8ID8WZKIJFTFXAJM5BK-512H"&gt;https://meetings.webex.com/collabs/meetings/join?uuid=M7EXGIM8ID8WZKIJFTFXAJM5BK-512H&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2014 16:39:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540206#M236328</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-07-23T16:39:18Z</dc:date>
    </item>
    <item>
      <title>Hi ,Join this webex meeting</title>
      <link>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540207#M236329</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;Join this webex meeting&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;https://meetings.webex.com/collabs/meetings/join?uuid=M5G5MMW7PC5GDNDV05Z9VB1N6J-512H&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2014 16:40:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540207#M236329</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-07-23T16:40:26Z</dc:date>
    </item>
    <item>
      <title>On Remote session below</title>
      <link>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540208#M236330</link>
      <description>&lt;P&gt;On Remote session below configuration is updated on your ASA device&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) mismatch on your ACL&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-family: georgia, serif; font-size: 14px;"&gt;no access-list 102 extended permit tcp any host 67.208.x.x eq www&amp;nbsp;&lt;/SPAN&gt;&lt;BR style="color: rgb(119, 119, 119); font-family: georgia, serif; font-size: 14px;" /&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-family: georgia, serif; font-size: 14px;"&gt;no access-list 102 extended permit tcp any host 67.208.x.x.x eq 3389&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-family: georgia, serif; font-size: 14px;"&gt;access-list 102 extended permit tcp any host 10.90.230.xe q 3389&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-family: georgia, serif; font-size: 14px;"&gt;2) Mismatch on your NAT config&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-family: georgia, serif; font-size: 14px;"&gt;object network rdp_server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-family: georgia, serif; font-size: 14px;"&gt;host 10.90.230.x&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-family: georgia, serif; font-size: 14px;"&gt;nat (inside,outside) static 67.208.x.x service tcp 3389 3389&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-family: georgia, serif; font-size: 14px;"&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-family: georgia, serif; font-size: 14px;"&gt;Sandy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2014 18:44:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-explicit-rule-blocking-the-traffic/m-p/2540208#M236330</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-07-23T18:44:08Z</dc:date>
    </item>
  </channel>
</rss>

