<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DISCUSSION (No Title) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/discussion-no-title/m-p/2489572#M268428</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cannot ping from LAN to DMZ public IP address.&lt;/P&gt;&lt;P&gt;I can ping to DMZ internal 172.16.0.x address from LAN.&lt;/P&gt;&lt;P&gt;DMZ LAN also can ping to Internal LAN.&lt;/P&gt;&lt;P&gt;If I add this config "static (DMZ,Inside) x.x.x.61 172.16.0.12 netmask 255.255.255.255"&lt;/P&gt;&lt;P&gt;Internal LAN cannot ping to DMZ private IP address. I can ping to DMZ public IP address.&lt;/P&gt;&lt;P&gt;I want to ping from LAN to DMZ private IP and DMZ Public IP address.&lt;/P&gt;&lt;P&gt;Please help me...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA Version 7.2(4)34&lt;BR /&gt;!&lt;BR /&gt;hostname ASAKT&lt;/P&gt;&lt;P&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;&amp;nbsp;description Link to Starhub&lt;BR /&gt;&amp;nbsp;nameif Outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address x.x.x.x 255.255.255.240&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;&amp;nbsp;description Link to Internal 100.x&lt;BR /&gt;&amp;nbsp;nameif Inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 192.168.100.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.100&lt;BR /&gt;&amp;nbsp;vlan 100&lt;BR /&gt;&amp;nbsp;nameif DMZ100&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.100.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.101&lt;BR /&gt;&amp;nbsp;vlan 101&lt;BR /&gt;&amp;nbsp;nameif DMZ101&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.101.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.102&lt;BR /&gt;&amp;nbsp;vlan 102&lt;BR /&gt;&amp;nbsp;nameif DMZ102&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.102.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.103&lt;BR /&gt;&amp;nbsp;vlan 103&lt;BR /&gt;&amp;nbsp;nameif DMZ103&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.103.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.104&lt;BR /&gt;&amp;nbsp;vlan 104&lt;BR /&gt;&amp;nbsp;nameif DMZ104&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.104.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.105&lt;BR /&gt;&amp;nbsp;vlan 105&lt;BR /&gt;&amp;nbsp;nameif DMZ105&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.105.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.106&lt;BR /&gt;&amp;nbsp;vlan 106&lt;BR /&gt;&amp;nbsp;nameif DMZ106&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.106.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.107&lt;BR /&gt;&amp;nbsp;vlan 107&lt;BR /&gt;&amp;nbsp;nameif DMZ107&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.107.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.108&lt;BR /&gt;&amp;nbsp;vlan 108&lt;BR /&gt;&amp;nbsp;nameif DMZ108&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.108.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.10&lt;BR /&gt;&amp;nbsp;vlan 10&lt;BR /&gt;&amp;nbsp;nameif DMZ&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.0.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.100&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.101&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.102&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.103&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.104&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.105&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.106&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.107&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.108&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;&amp;nbsp;nameif management&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;&amp;nbsp;management-only&lt;BR /&gt;!&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;boot system disk0:/asa724-34-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone MYT 8&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;&amp;nbsp;domain-name sxxxxxx&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object-group service TCP7760 tcp&lt;BR /&gt;&amp;nbsp;port-object eq 7760&lt;BR /&gt;object-group service UDP7760 udp&lt;BR /&gt;&amp;nbsp;port-object eq 7760&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.58 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.52 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq 5349&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.52 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq 5269&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 range 50000 59999&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.53 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq 5349&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.53 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq 5269&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 range 50000 59999&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 range sip 5065&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 range sip 5065&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.54 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq 5349&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.54 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq 5269&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 range 50000 59999&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 range sip 5065&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.55 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 eq 5349&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.55 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 eq 5269&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 range 50000 59999&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 range sip 5065&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.57 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.57 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.56 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq 5349&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.56 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq 5269&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 range 50000 59999&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 range sip 5065&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.57 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.57 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.57 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.56 range 50000 59999&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.57 eq 88&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.57 eq 81&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any host x.x.x.57&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host 192.168.100.2 range 40000 64999&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host 192.168.100.2 range 40000 64999&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp host x.x.x.8 host 192.168.100.2 range 40000 64999&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp host x.x.x.8 host 192.168.100.2 range 40000 64999&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp host x.x.x.8 host x.x.x.56 eq 7760&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp host x.x.x.8 host x.x.x.56 eq 7760&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host 192.168.100.13 eq 7760&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host 192.168.100.13 eq 7760&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any host x.x.x.56&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any any time-exceeded&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any any unreachable&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any any&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any any source-quench&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any any echo&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.56 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp host x.x.x.8 host x.x.x.56 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp host x.x.x.8 host x.x.x.56 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host 192.168.100.13 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host 192.168.100.13 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.50 eq 1000&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.50 eq 1001&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.50 eq 1002&lt;BR /&gt;access-list Outside_in_DMZ extended permit gre any host x.x.x.51&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq isakmp&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq 47&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq 47&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq pptp&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq 5949&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq 6049&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq 6149&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any host x.x.x.59&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any host x.x.x.60&lt;BR /&gt;access-list Outside_in_DMZ extended permit ip any host x.x.x.59&lt;BR /&gt;access-list Outside_in_DMZ extended permit ip any host x.x.x.60&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq 5061&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq 5061&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq 5061&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.62 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.62 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.62 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.62 eq 88&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.62 eq 81&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any host x.x.x.62&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.62 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.62 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit ip any host x.x.x.58&lt;BR /&gt;access-list Outside_in_DMZ extended permit ip any host x.x.x.69&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.61 eq smtp&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.61 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.61 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.61 eq pop3&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.61 eq imap4&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.61 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.61 eq 587&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.61 eq 993&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.61 eq 2220&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.61 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq 22545&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq 22545&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq 22544&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq 22544&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq 22543&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq 22543&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq 22542&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq 22542&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq 22541&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq 22541&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq 22540&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq 22540&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.60 eq 22540&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.60 eq 22540&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.60 eq 22541&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.60 eq 22541&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.60 eq 22542&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.60 eq 22542&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.60 eq 22543&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.60 eq 22543&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.60 eq 22544&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.60 eq 22544&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.60 eq 22545&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.60 eq 22545&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.58 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.58 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any host x.x.x.58&lt;BR /&gt;access-list DMZ_in_Internal extended permit ip any any&lt;BR /&gt;access-list Inside_in_Internal extended permit ip 192.168.100.0 255.255.255.0 host 172.16.0.5&lt;BR /&gt;access-list Inside_in_Internal extended permit tcp 192.168.100.0 255.255.255.0 host 172.16.0.5 eq www&lt;BR /&gt;access-list Inside_in_Internal extended permit ip 192.168.100.0 255.255.255.0 host 172.16.0.13&lt;BR /&gt;access-list Inside_in_Internal extended permit tcp 192.168.100.0 255.255.255.0 host 172.16.0.13 eq www&lt;BR /&gt;access-list Inside_in_Internal extended permit tcp 192.168.100.0 255.255.255.0 host 172.16.0.13 eq https&lt;BR /&gt;access-list Inside_access_in extended permit tcp host x.x.x.8 host 192.168.100.13 object-group TCP7760&lt;BR /&gt;access-list Inside_access_in extended permit udp host x.x.x.8 host 192.168.100.13 object-group UDP7760&lt;BR /&gt;access-list Pfingo_In extended permit tcp host x.x.x.8 host 192.168.100.13 eq 7760&lt;BR /&gt;access-list Pfingo_In extended permit udp host x.x.x.8 host 192.168.100.13 eq 7760&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 192.168.100.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 192.168.100.0 255.255.255.0 192.168.110.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 192.168.100.0 255.255.255.0 192.168.120.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 192.168.100.0 255.255.255.0 192.168.50.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 192.168.100.0 255.255.255.0 192.168.130.0 255.255.255.0&lt;BR /&gt;access-list INSIDE-NAT0 extended permit ip 192.168.100.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;BR /&gt;access-list 102 extended permit ip 192.168.100.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;BR /&gt;access-list outside_cryptomap_1 extended permit ip 192.168.100.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;BR /&gt;access-list outside_cryptomap_1 extended permit ip 192.168.50.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;BR /&gt;access-list outside_cryptomap_2 extended permit ip 192.168.100.0 255.255.255.0 192.168.110.0 255.255.255.0&lt;BR /&gt;access-list outside_cryptomap_2 extended permit ip 192.168.50.0 255.255.255.0 192.168.110.0 255.255.255.0&lt;BR /&gt;access-list outside_cryptomap_3 extended permit ip 192.168.100.0 255.255.255.0 192.168.120.0 255.255.255.0&lt;BR /&gt;access-list outside_cryptomap_3 extended permit ip 192.168.50.0 255.255.255.0 192.168.120.0 255.255.255.0&lt;BR /&gt;access-list outside_nat0_outbound extended permit ip 192.168.50.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;BR /&gt;access-list outside_nat0_outbound extended permit ip 192.168.50.0 255.255.255.0 192.168.120.0 255.255.255.0&lt;BR /&gt;access-list outside_nat0_outbound extended permit ip 192.168.50.0 255.255.255.0 192.168.110.0 255.255.255.0&lt;BR /&gt;access-list splittun-vpngrup1 extended permit ip 192.168.100.0 255.255.255.0 192.168.50.0 255.255.255.0&lt;BR /&gt;access-list splittun-vpngrup1 extended permit ip 192.168.1.0 255.255.255.0 192.168.50.0 255.255.255.0&lt;BR /&gt;access-list splittun-vpngrup1 extended permit ip 192.168.110.0 255.255.255.0 192.168.50.0 255.255.255.0&lt;BR /&gt;access-list splittun-vpngrup1 extended permit ip 192.168.120.0 255.255.255.0 192.168.50.0 255.255.255.0&lt;BR /&gt;access-list SPLIT-TUNNEL standard permit 192.168.100.0 255.255.255.0&lt;BR /&gt;access-list SPLIT-TUNNEL standard permit 192.168.1.0 255.255.255.0&lt;BR /&gt;access-list SPLIT-TUNNEL standard permit 192.168.110.0 255.255.255.0&lt;BR /&gt;access-list SPLIT-TUNNEL standard permit 192.168.120.0 255.255.255.0&lt;BR /&gt;access-list DMZ_in extended permit icmp any any echo-reply&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu Outside 1500&lt;BR /&gt;mtu Inside 1500&lt;BR /&gt;mtu DMZ100 1500&lt;BR /&gt;mtu DMZ101 1500&lt;BR /&gt;mtu DMZ102 1500&lt;BR /&gt;mtu DMZ103 1500&lt;BR /&gt;mtu DMZ104 1500&lt;BR /&gt;mtu DMZ105 1500&lt;BR /&gt;mtu DMZ106 1500&lt;BR /&gt;mtu DMZ107 1500&lt;BR /&gt;mtu DMZ108 1500&lt;BR /&gt;mtu DMZ 1500&lt;BR /&gt;mtu management 1500&lt;BR /&gt;ip local pool ippool 192.168.50.10-192.168.50.40 mask 255.255.255.0&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-523.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (Outside) 101 interface&lt;BR /&gt;global (DMZ100) 101 interface&lt;BR /&gt;global (DMZ101) 101 interface&lt;BR /&gt;global (DMZ102) 101 interface&lt;BR /&gt;global (DMZ103) 101 interface&lt;BR /&gt;global (DMZ104) 101 interface&lt;BR /&gt;global (DMZ105) 101 interface&lt;BR /&gt;global (DMZ106) 101 interface&lt;BR /&gt;global (DMZ107) 101 interface&lt;BR /&gt;global (DMZ108) 101 interface&lt;BR /&gt;global (DMZ) 101 interface&lt;BR /&gt;nat (Outside) 0 access-list outside_nat0_outbound&lt;BR /&gt;nat (Inside) 0 access-list inside_nat0_outbound&lt;BR /&gt;nat (Inside) 101 192.168.100.0 255.255.255.0&lt;BR /&gt;nat (DMZ100) 101 172.16.100.0 255.255.255.0&lt;BR /&gt;nat (DMZ101) 101 172.16.101.0 255.255.255.0&lt;BR /&gt;nat (DMZ102) 101 172.16.102.0 255.255.255.0&lt;BR /&gt;nat (DMZ103) 101 172.16.103.0 255.255.255.0&lt;BR /&gt;nat (DMZ104) 101 172.16.104.0 255.255.255.0&lt;BR /&gt;nat (DMZ105) 101 172.16.105.0 255.255.255.0&lt;BR /&gt;nat (DMZ106) 101 172.16.106.0 255.255.255.0&lt;BR /&gt;nat (DMZ107) 101 172.16.107.0 255.255.255.0&lt;BR /&gt;nat (DMZ108) 101 172.16.108.0 255.255.255.0&lt;BR /&gt;static (Inside,Outside) tcp x.x.x.50 1000 192.168.100.87 www netmask 255.255.255.255&lt;BR /&gt;static (Inside,Outside) tcp x.x.x.50 1001 192.168.100.88 www netmask 255.255.255.255&lt;BR /&gt;static (Inside,Outside) tcp x.x.x.50 1002 192.168.100.89 www netmask 255.255.255.255&lt;BR /&gt;static (Inside,Outside) x.x.x.56 192.168.100.13 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.55 172.16.0.4 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.57 172.16.0.5 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.52 172.16.0.7 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.53 172.16.0.8 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.54 172.16.0.9 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.62 172.16.0.13 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.61 172.16.0.12 netmask 255.255.255.255&lt;BR /&gt;static (DMZ101,Outside) x.x.x.164 172.16.101.1 netmask 255.255.255.255&lt;BR /&gt;static (DMZ103,Outside) x.x.x.166 172.16.103.1 netmask 255.255.255.255&lt;BR /&gt;static (DMZ102,Outside) x.x.x.165 172.16.102.1 netmask 255.255.255.255&lt;BR /&gt;static (DMZ104,Outside) x.x.x.167 172.16.104.1 netmask 255.255.255.255&lt;BR /&gt;static (DMZ105,Outside) x.x.x.168 172.16.105.1 netmask 255.255.255.255&lt;BR /&gt;static (DMZ106,Outside) x.x.x.169 172.16.106.1 netmask 255.255.255.255&lt;BR /&gt;static (DMZ107,Outside) x.x.x.170 172.16.107.1 netmask 255.255.255.255&lt;BR /&gt;static (DMZ101,Outside) x.x.x.163 172.16.101.2 netmask 255.255.255.255&lt;BR /&gt;static (DMZ101,Outside) x.x.x.174 172.16.101.3 netmask 255.255.255.255&lt;BR /&gt;static (DMZ101,Outside) x.x.x.171 172.16.101.4 netmask 255.255.255.255&lt;BR /&gt;static (DMZ101,Outside) x.x.x.172 172.16.101.5 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.59 172.16.0.6 netmask 255.255.255.255&lt;BR /&gt;static (Inside,Outside) x.x.x.60 192.168.100.102 netmask 255.255.255.255&lt;BR /&gt;static (Inside,Outside) x.x.x.58 192.168.100.189 netmask 255.255.255.255&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;access-group Outside_in_DMZ in interface Outside&lt;BR /&gt;access-group DMZ_in_Internal in interface DMZ&lt;BR /&gt;route Outside 0.0.0.0 0.0.0.0 x.x.x.49 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;infoakh&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 03:55:11 GMT</pubDate>
    <dc:creator>aung.htwe</dc:creator>
    <dc:date>2019-03-12T03:55:11Z</dc:date>
    <item>
      <title>DISCUSSION (No Title)</title>
      <link>https://community.cisco.com/t5/network-security/discussion-no-title/m-p/2489572#M268428</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cannot ping from LAN to DMZ public IP address.&lt;/P&gt;&lt;P&gt;I can ping to DMZ internal 172.16.0.x address from LAN.&lt;/P&gt;&lt;P&gt;DMZ LAN also can ping to Internal LAN.&lt;/P&gt;&lt;P&gt;If I add this config "static (DMZ,Inside) x.x.x.61 172.16.0.12 netmask 255.255.255.255"&lt;/P&gt;&lt;P&gt;Internal LAN cannot ping to DMZ private IP address. I can ping to DMZ public IP address.&lt;/P&gt;&lt;P&gt;I want to ping from LAN to DMZ private IP and DMZ Public IP address.&lt;/P&gt;&lt;P&gt;Please help me...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA Version 7.2(4)34&lt;BR /&gt;!&lt;BR /&gt;hostname ASAKT&lt;/P&gt;&lt;P&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;&amp;nbsp;description Link to Starhub&lt;BR /&gt;&amp;nbsp;nameif Outside&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address x.x.x.x 255.255.255.240&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;&amp;nbsp;description Link to Internal 100.x&lt;BR /&gt;&amp;nbsp;nameif Inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 192.168.100.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.100&lt;BR /&gt;&amp;nbsp;vlan 100&lt;BR /&gt;&amp;nbsp;nameif DMZ100&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.100.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.101&lt;BR /&gt;&amp;nbsp;vlan 101&lt;BR /&gt;&amp;nbsp;nameif DMZ101&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.101.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.102&lt;BR /&gt;&amp;nbsp;vlan 102&lt;BR /&gt;&amp;nbsp;nameif DMZ102&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.102.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.103&lt;BR /&gt;&amp;nbsp;vlan 103&lt;BR /&gt;&amp;nbsp;nameif DMZ103&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.103.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.104&lt;BR /&gt;&amp;nbsp;vlan 104&lt;BR /&gt;&amp;nbsp;nameif DMZ104&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.104.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.105&lt;BR /&gt;&amp;nbsp;vlan 105&lt;BR /&gt;&amp;nbsp;nameif DMZ105&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.105.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.106&lt;BR /&gt;&amp;nbsp;vlan 106&lt;BR /&gt;&amp;nbsp;nameif DMZ106&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.106.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.107&lt;BR /&gt;&amp;nbsp;vlan 107&lt;BR /&gt;&amp;nbsp;nameif DMZ107&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.107.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2.108&lt;BR /&gt;&amp;nbsp;vlan 108&lt;BR /&gt;&amp;nbsp;nameif DMZ108&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.108.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.10&lt;BR /&gt;&amp;nbsp;vlan 10&lt;BR /&gt;&amp;nbsp;nameif DMZ&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 172.16.0.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.100&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.101&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.102&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.103&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.104&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.105&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.106&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.107&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3.108&lt;BR /&gt;&amp;nbsp;no vlan&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;&amp;nbsp;nameif management&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;&amp;nbsp;management-only&lt;BR /&gt;!&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;banner motd Do not attempt unauthorized access.&lt;BR /&gt;boot system disk0:/asa724-34-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone MYT 8&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;&amp;nbsp;domain-name sxxxxxx&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object-group service TCP7760 tcp&lt;BR /&gt;&amp;nbsp;port-object eq 7760&lt;BR /&gt;object-group service UDP7760 udp&lt;BR /&gt;&amp;nbsp;port-object eq 7760&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.58 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.52 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq 5349&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.52 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq 5269&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 range 50000 59999&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.53 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq 5349&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.53 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq 5269&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 range 50000 59999&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 range sip 5065&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 range sip 5065&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.54 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq 5349&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.54 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq 5269&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 range 50000 59999&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 range sip 5065&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.55 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 eq 5349&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.55 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 eq 5269&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 range 50000 59999&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.55 range sip 5065&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.57 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.57 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.56 eq 3478&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq 5349&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.56 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq 5269&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 range 50000 59999&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 range sip 5065&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.57 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.57 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.57 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.56 range 50000 59999&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.57 eq 88&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.57 eq 81&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any host x.x.x.57&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host 192.168.100.2 range 40000 64999&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host 192.168.100.2 range 40000 64999&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp host x.x.x.8 host 192.168.100.2 range 40000 64999&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp host x.x.x.8 host 192.168.100.2 range 40000 64999&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp host x.x.x.8 host x.x.x.56 eq 7760&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp host x.x.x.8 host x.x.x.56 eq 7760&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host 192.168.100.13 eq 7760&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host 192.168.100.13 eq 7760&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any host x.x.x.56&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any any time-exceeded&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any any unreachable&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any any&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any any source-quench&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any any echo&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.56 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.56 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp host x.x.x.8 host x.x.x.56 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp host x.x.x.8 host x.x.x.56 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host 192.168.100.13 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host 192.168.100.13 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.50 eq 1000&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.50 eq 1001&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.50 eq 1002&lt;BR /&gt;access-list Outside_in_DMZ extended permit gre any host x.x.x.51&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq isakmp&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq 47&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq 47&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq pptp&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq 5949&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq 6049&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq 6149&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any host x.x.x.59&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any host x.x.x.60&lt;BR /&gt;access-list Outside_in_DMZ extended permit ip any host x.x.x.59&lt;BR /&gt;access-list Outside_in_DMZ extended permit ip any host x.x.x.60&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.52 eq 5061&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq 5061&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.53 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq sip&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.54 eq 5061&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.62 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.62 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.62 eq 3389&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.62 eq 88&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.62 eq 81&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any host x.x.x.62&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.62 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.62 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit ip any host x.x.x.58&lt;BR /&gt;access-list Outside_in_DMZ extended permit ip any host x.x.x.69&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.61 eq smtp&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.61 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.61 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.61 eq pop3&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.61 eq imap4&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.61 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.61 eq 587&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.61 eq 993&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.61 eq 2220&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.61 eq domain&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq 22545&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq 22545&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq 22544&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq 22544&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq 22543&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq 22543&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq 22542&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq 22542&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq 22541&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq 22541&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.51 eq 22540&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.51 eq 22540&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.60 eq 22540&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.60 eq 22540&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.60 eq 22541&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.60 eq 22541&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.60 eq 22542&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.60 eq 22542&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.60 eq 22543&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.60 eq 22543&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.60 eq 22544&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.60 eq 22544&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.60 eq 22545&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.60 eq 22545&lt;BR /&gt;access-list Outside_in_DMZ extended permit udp any host x.x.x.58 eq www&lt;BR /&gt;access-list Outside_in_DMZ extended permit tcp any host x.x.x.58 eq https&lt;BR /&gt;access-list Outside_in_DMZ extended permit icmp any host x.x.x.58&lt;BR /&gt;access-list DMZ_in_Internal extended permit ip any any&lt;BR /&gt;access-list Inside_in_Internal extended permit ip 192.168.100.0 255.255.255.0 host 172.16.0.5&lt;BR /&gt;access-list Inside_in_Internal extended permit tcp 192.168.100.0 255.255.255.0 host 172.16.0.5 eq www&lt;BR /&gt;access-list Inside_in_Internal extended permit ip 192.168.100.0 255.255.255.0 host 172.16.0.13&lt;BR /&gt;access-list Inside_in_Internal extended permit tcp 192.168.100.0 255.255.255.0 host 172.16.0.13 eq www&lt;BR /&gt;access-list Inside_in_Internal extended permit tcp 192.168.100.0 255.255.255.0 host 172.16.0.13 eq https&lt;BR /&gt;access-list Inside_access_in extended permit tcp host x.x.x.8 host 192.168.100.13 object-group TCP7760&lt;BR /&gt;access-list Inside_access_in extended permit udp host x.x.x.8 host 192.168.100.13 object-group UDP7760&lt;BR /&gt;access-list Pfingo_In extended permit tcp host x.x.x.8 host 192.168.100.13 eq 7760&lt;BR /&gt;access-list Pfingo_In extended permit udp host x.x.x.8 host 192.168.100.13 eq 7760&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 192.168.100.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 192.168.100.0 255.255.255.0 192.168.110.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 192.168.100.0 255.255.255.0 192.168.120.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 192.168.100.0 255.255.255.0 192.168.50.0 255.255.255.0&lt;BR /&gt;access-list inside_nat0_outbound extended permit ip 192.168.100.0 255.255.255.0 192.168.130.0 255.255.255.0&lt;BR /&gt;access-list INSIDE-NAT0 extended permit ip 192.168.100.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;BR /&gt;access-list 102 extended permit ip 192.168.100.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;BR /&gt;access-list outside_cryptomap_1 extended permit ip 192.168.100.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;BR /&gt;access-list outside_cryptomap_1 extended permit ip 192.168.50.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;BR /&gt;access-list outside_cryptomap_2 extended permit ip 192.168.100.0 255.255.255.0 192.168.110.0 255.255.255.0&lt;BR /&gt;access-list outside_cryptomap_2 extended permit ip 192.168.50.0 255.255.255.0 192.168.110.0 255.255.255.0&lt;BR /&gt;access-list outside_cryptomap_3 extended permit ip 192.168.100.0 255.255.255.0 192.168.120.0 255.255.255.0&lt;BR /&gt;access-list outside_cryptomap_3 extended permit ip 192.168.50.0 255.255.255.0 192.168.120.0 255.255.255.0&lt;BR /&gt;access-list outside_nat0_outbound extended permit ip 192.168.50.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;BR /&gt;access-list outside_nat0_outbound extended permit ip 192.168.50.0 255.255.255.0 192.168.120.0 255.255.255.0&lt;BR /&gt;access-list outside_nat0_outbound extended permit ip 192.168.50.0 255.255.255.0 192.168.110.0 255.255.255.0&lt;BR /&gt;access-list splittun-vpngrup1 extended permit ip 192.168.100.0 255.255.255.0 192.168.50.0 255.255.255.0&lt;BR /&gt;access-list splittun-vpngrup1 extended permit ip 192.168.1.0 255.255.255.0 192.168.50.0 255.255.255.0&lt;BR /&gt;access-list splittun-vpngrup1 extended permit ip 192.168.110.0 255.255.255.0 192.168.50.0 255.255.255.0&lt;BR /&gt;access-list splittun-vpngrup1 extended permit ip 192.168.120.0 255.255.255.0 192.168.50.0 255.255.255.0&lt;BR /&gt;access-list SPLIT-TUNNEL standard permit 192.168.100.0 255.255.255.0&lt;BR /&gt;access-list SPLIT-TUNNEL standard permit 192.168.1.0 255.255.255.0&lt;BR /&gt;access-list SPLIT-TUNNEL standard permit 192.168.110.0 255.255.255.0&lt;BR /&gt;access-list SPLIT-TUNNEL standard permit 192.168.120.0 255.255.255.0&lt;BR /&gt;access-list DMZ_in extended permit icmp any any echo-reply&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu Outside 1500&lt;BR /&gt;mtu Inside 1500&lt;BR /&gt;mtu DMZ100 1500&lt;BR /&gt;mtu DMZ101 1500&lt;BR /&gt;mtu DMZ102 1500&lt;BR /&gt;mtu DMZ103 1500&lt;BR /&gt;mtu DMZ104 1500&lt;BR /&gt;mtu DMZ105 1500&lt;BR /&gt;mtu DMZ106 1500&lt;BR /&gt;mtu DMZ107 1500&lt;BR /&gt;mtu DMZ108 1500&lt;BR /&gt;mtu DMZ 1500&lt;BR /&gt;mtu management 1500&lt;BR /&gt;ip local pool ippool 192.168.50.10-192.168.50.40 mask 255.255.255.0&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-523.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (Outside) 101 interface&lt;BR /&gt;global (DMZ100) 101 interface&lt;BR /&gt;global (DMZ101) 101 interface&lt;BR /&gt;global (DMZ102) 101 interface&lt;BR /&gt;global (DMZ103) 101 interface&lt;BR /&gt;global (DMZ104) 101 interface&lt;BR /&gt;global (DMZ105) 101 interface&lt;BR /&gt;global (DMZ106) 101 interface&lt;BR /&gt;global (DMZ107) 101 interface&lt;BR /&gt;global (DMZ108) 101 interface&lt;BR /&gt;global (DMZ) 101 interface&lt;BR /&gt;nat (Outside) 0 access-list outside_nat0_outbound&lt;BR /&gt;nat (Inside) 0 access-list inside_nat0_outbound&lt;BR /&gt;nat (Inside) 101 192.168.100.0 255.255.255.0&lt;BR /&gt;nat (DMZ100) 101 172.16.100.0 255.255.255.0&lt;BR /&gt;nat (DMZ101) 101 172.16.101.0 255.255.255.0&lt;BR /&gt;nat (DMZ102) 101 172.16.102.0 255.255.255.0&lt;BR /&gt;nat (DMZ103) 101 172.16.103.0 255.255.255.0&lt;BR /&gt;nat (DMZ104) 101 172.16.104.0 255.255.255.0&lt;BR /&gt;nat (DMZ105) 101 172.16.105.0 255.255.255.0&lt;BR /&gt;nat (DMZ106) 101 172.16.106.0 255.255.255.0&lt;BR /&gt;nat (DMZ107) 101 172.16.107.0 255.255.255.0&lt;BR /&gt;nat (DMZ108) 101 172.16.108.0 255.255.255.0&lt;BR /&gt;static (Inside,Outside) tcp x.x.x.50 1000 192.168.100.87 www netmask 255.255.255.255&lt;BR /&gt;static (Inside,Outside) tcp x.x.x.50 1001 192.168.100.88 www netmask 255.255.255.255&lt;BR /&gt;static (Inside,Outside) tcp x.x.x.50 1002 192.168.100.89 www netmask 255.255.255.255&lt;BR /&gt;static (Inside,Outside) x.x.x.56 192.168.100.13 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.55 172.16.0.4 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.57 172.16.0.5 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.52 172.16.0.7 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.53 172.16.0.8 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.54 172.16.0.9 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.62 172.16.0.13 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.61 172.16.0.12 netmask 255.255.255.255&lt;BR /&gt;static (DMZ101,Outside) x.x.x.164 172.16.101.1 netmask 255.255.255.255&lt;BR /&gt;static (DMZ103,Outside) x.x.x.166 172.16.103.1 netmask 255.255.255.255&lt;BR /&gt;static (DMZ102,Outside) x.x.x.165 172.16.102.1 netmask 255.255.255.255&lt;BR /&gt;static (DMZ104,Outside) x.x.x.167 172.16.104.1 netmask 255.255.255.255&lt;BR /&gt;static (DMZ105,Outside) x.x.x.168 172.16.105.1 netmask 255.255.255.255&lt;BR /&gt;static (DMZ106,Outside) x.x.x.169 172.16.106.1 netmask 255.255.255.255&lt;BR /&gt;static (DMZ107,Outside) x.x.x.170 172.16.107.1 netmask 255.255.255.255&lt;BR /&gt;static (DMZ101,Outside) x.x.x.163 172.16.101.2 netmask 255.255.255.255&lt;BR /&gt;static (DMZ101,Outside) x.x.x.174 172.16.101.3 netmask 255.255.255.255&lt;BR /&gt;static (DMZ101,Outside) x.x.x.171 172.16.101.4 netmask 255.255.255.255&lt;BR /&gt;static (DMZ101,Outside) x.x.x.172 172.16.101.5 netmask 255.255.255.255&lt;BR /&gt;static (DMZ,Outside) x.x.x.59 172.16.0.6 netmask 255.255.255.255&lt;BR /&gt;static (Inside,Outside) x.x.x.60 192.168.100.102 netmask 255.255.255.255&lt;BR /&gt;static (Inside,Outside) x.x.x.58 192.168.100.189 netmask 255.255.255.255&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;access-group Outside_in_DMZ in interface Outside&lt;BR /&gt;access-group DMZ_in_Internal in interface DMZ&lt;BR /&gt;route Outside 0.0.0.0 0.0.0.0 x.x.x.49 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;infoakh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:55:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discussion-no-title/m-p/2489572#M268428</guid>
      <dc:creator>aung.htwe</dc:creator>
      <dc:date>2019-03-12T03:55:11Z</dc:date>
    </item>
    <item>
      <title>The reason you lose</title>
      <link>https://community.cisco.com/t5/network-security/discussion-no-title/m-p/2489573#M268435</link>
      <description>&lt;P&gt;The reason you lose connectivity to the DMZ when you enter the command:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (DMZ,Inside) x.x.x.61 172.16.0.12 netmask 255.255.255.255&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;is because as of this point you will be NATing all ports to 172.16.0.12, so you are effectively saying that only that private IP should be reacable.&lt;/P&gt;&lt;P&gt;Is there a particular reason you want to be able to ping the public address of the DMZ from the internal network?&lt;/P&gt;&lt;P&gt;As the public IP is associated with the outside interface, the ASA will not allow you ping this IP because the packet would need to leave the outside interface and the be routed back to the ASA, so basically the ASA will see this as a spoofed packet and drop it.&amp;nbsp; The only way around this is to configure NAT.&amp;nbsp; But this depends really on what you are trying to do.&amp;nbsp; If you just want to ping the public DMZ address for the sake of pinging it, this can become a very ugly and unstable configuration.&amp;nbsp; However, if you are trying to allow users to connect to the company web server using the public IP, for example, because that is what the DNS server resolves the FQDN to then you could use DNS doctoring, depending on where the DNS server is located of course.&lt;/P&gt;&lt;P&gt;Please define your requirements for being able to ping the public IP of the DMZ so we can help you further.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to rate and select a correct answer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2014 12:31:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discussion-no-title/m-p/2489573#M268435</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-03-10T12:31:14Z</dc:date>
    </item>
    <item>
      <title>Hello, As soon as you enable</title>
      <link>https://community.cisco.com/t5/network-security/discussion-no-title/m-p/2489574#M268443</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As soon as you enable the static nat you mentioned you will be able to only access the server via it's public IP.&lt;/P&gt;&lt;P&gt;Why would you like to access it via both IPs anyway?&lt;/P&gt;&lt;P&gt;When you point it to the public IP do the following&lt;/P&gt;&lt;P&gt;packet-tracer input inside tcp x.x.x.x 1025 y.y.y.y 3389&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where x.x.x it's an Internal IP&lt;/P&gt;&lt;P&gt;and y.y.y.y is the public IP of the server sitting on the DMZ&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2014 12:45:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discussion-no-title/m-p/2489574#M268443</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2014-03-10T12:45:12Z</dc:date>
    </item>
    <item>
      <title>Hi, Thanks all your answer,</title>
      <link>https://community.cisco.com/t5/network-security/discussion-no-title/m-p/2489575#M268448</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks all your answer, so if I will access to Public IP from LAN,no way to access to DMZ LAN IP address?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;infoakh&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 02:31:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discussion-no-title/m-p/2489575#M268448</guid>
      <dc:creator>aung.htwe</dc:creator>
      <dc:date>2014-03-11T02:31:46Z</dc:date>
    </item>
  </channel>
</rss>

