<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461213#M269637</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These networks are beind another router on different ports. The ASA actually has three different routers behind it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface 0 has the 2811&lt;/P&gt;&lt;P&gt;Interface 1 has the WAN&lt;/P&gt;&lt;P&gt;Interface 2 has the 2821&lt;/P&gt;&lt;P&gt;Interface 3 has the 3745&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These networks:&lt;/P&gt;&lt;P style="margin-top: 14pt; margin-bottom: 14pt;"&gt;&lt;STRONG&gt;route Inside 128.162.1.0 255.255.255.0 10.10.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-top: 14pt; margin-bottom: 14pt;"&gt;&lt;STRONG&gt;route Inside 128.162.10.0 255.255.255.0 10.10.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-top: 14pt; margin-bottom: 14pt;"&gt;&lt;STRONG&gt;route Inside 128.162.20.0 255.255.255.0 10.10.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; Are all behind the Cisco 2821.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 3745 has different subnets, but I haven't figured out how to get to it yet, it's IOS is different and since I updated it I can't seem to ssh to it, but that's not important right now as there is nothing behind it &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, let me input your suggestions and see what happens now that I am home and have a console cable if I need it.&lt;/P&gt;&lt;MENU id="menuid"&gt;&lt;/MENU&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 15 Feb 2014 19:17:11 GMT</pubDate>
    <dc:creator>metuckness</dc:creator>
    <dc:date>2014-02-15T19:17:11Z</dc:date>
    <item>
      <title>ASA 5510 with Cisco 2811 Router Behind it - Not forwarding traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461208#M269630</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some might know that I have been dealing with an issue where I cannot seem to get forwarded packets to reach their destinations behind an ASA 5510 that has a Cisco 2811 connected directly behind it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some examples that work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can SSH into the ASA.&lt;/P&gt;&lt;P&gt;I can SSH to the Cisco Routers behind the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot reach items beind the Cisco Routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Configuration is this (&lt;SPAN style="color: #993366;"&gt;I am sure I included a bunch of info I didn't need to, but I am hoping it'll help!&lt;/SPAN&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a static Ip assigned to my Ouside Interface Ethernet 0/1&lt;/P&gt;&lt;P&gt;It has an IP address of 199.195.xxx.xxx&lt;/P&gt;&lt;P&gt;I am trying to learn how to shape network traffic (this is all new to me) via the ASA and the Routers to specific devices.&lt;/P&gt;&lt;P&gt;The Inside Interface on the ASA is 10.10.1.1 255.255.255.252&lt;/P&gt;&lt;P&gt;The Outside Interface on the 2811 is 10.10.1.2 255.255.255.252&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ping the router from the ASA. I can SSH through the ASA to the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;EM style="text-decoration: underline; "&gt;&lt;STRONG&gt;BUT I CANNOT ACCESS DEVICES BEHIND THE ROUTER.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, I wanted to BAM that statement above because I just don't kjnow where the issue is. Is the issue on the router or the ASA, my guess is, the router, but I just don't know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are my configs, helpfully someone can help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA errors on the ASDM when I try and hit resources; specifically a web device behind the ASA and the 2811. It's Ip address 192.168.1.5 it's listening on port 80.Static IP, not assigned via DHCP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;Feb 14 2014&lt;/TD&gt;&lt;TD&gt;19:38:56&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;98.22.121.x&lt;/TD&gt;&lt;TD&gt;41164&lt;/TD&gt;&lt;TD&gt;192.168.1.5&lt;/TD&gt;&lt;TD&gt;80&lt;/TD&gt;&lt;TD&gt;Built inbound TCP connection 1922859 for Outside:98.22.121.x/41164 (98.22.121.x/41164) to Inside:192.168.1.5/80 (199.195.168.x/8080)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;6&lt;/TD&gt;&lt;TD&gt;Feb 14 2014&lt;/TD&gt;&lt;TD&gt;19:38:56&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;10.10.1.2&lt;/TD&gt;&lt;TD&gt;80&lt;/TD&gt;&lt;TD&gt;98.22.121.x&lt;/TD&gt;&lt;TD&gt;41164&lt;/TD&gt;&lt;TD&gt;Deny TCP (no connection) from 10.10.1.2/80 to 98.22.121.x/41164 flags SYN ACK&amp;nbsp; on interface Inside&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;ASA5510# sh nat&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;Auto NAT Policies (Section 2)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;1 (DMZ) to (Outside) source static ROUTER-2821 interface&amp;nbsp;&amp;nbsp; service tcp ssh 2222&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 1, untranslate_hits = 18&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;2 (Inside) to (Outside) source static ROUTER-2811 interface&amp;nbsp;&amp;nbsp; service tcp ssh 222&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 13&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;3 (VOIP) to (Outside) source static ROUTER-3745 interface&amp;nbsp;&amp;nbsp; service tcp ssh 2223&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;4 (Inside) to (Outside) source static RDP-DC1 interface&amp;nbsp;&amp;nbsp; service tcp 3389 3389&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 236&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;5 (Inside) to (Outside) source static WEBCAM-01 interface&amp;nbsp;&amp;nbsp; service tcp www 8080&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 162&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;Manual NAT Policies (Section 3)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;1 (any) to (Outside) source dynamic PAT-SOURCE interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993366;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 1056862, untranslate_hits = 83506&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;ASA5510# show access-list&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 4096)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; alert-interval 300&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list USERS; 1 elements; name hash: 0x50681c1e&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list USERS line 1 standard permit 10.10.1.0 255.255.255.0 (hitcnt=0) 0xdd6ba495&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list Outside_access_in; 5 elements; name hash: 0xe796c137&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list Outside_access_in line 1 extended permit tcp host 98.22.121.x object ROUTER-2811 eq ssh (hitcnt=37) 0x5a53778d&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;&amp;nbsp; access-list Outside_access_in line 1 extended permit tcp host 98.22.121.x host 10.10.1.2 eq ssh (hitcnt=37) 0x5a53778d&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list Outside_access_in line 2 extended permit tcp host 98.22.121.x object ROUTER-2821 eq ssh (hitcnt=8) 0x9f32bc21&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;&amp;nbsp; access-list Outside_access_in line 2 extended permit tcp host 98.22.121.x host 10.10.0.2 eq ssh (hitcnt=8) 0x9f32bc21&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list Outside_access_in line 3 extended permit tcp host 98.22.121.x interface Outside eq https (hitcnt=0) 0x385488b2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list Outside_access_in line 4 extended permit tcp host 98.22.121.x object WEBCAM-01 eq www (hitcnt=60) 0xe66674ec&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;&amp;nbsp; access-list Outside_access_in line 4 extended permit tcp host 98.22.121.x host 192.168.1.5 eq www (hitcnt=60) 0xe66674ec&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list Outside_access_in line 5 extended permit tcp host 98.22.121.x object RDP-DC1 eq 3389 (hitcnt=3) 0x02f13f4e&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;&amp;nbsp; access-list Outside_access_in line 5 extended permit tcp host 98.22.121.x host 192.168.1.2 eq 3389 (hitcnt=3) 0x02f13f4e&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list dmz-access-vlan1; 1 elements; name hash: 0xc3450860&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list dmz-access-vlan1 line 1 extended permit ip 128.162.1.0 255.255.255.0 any (hitcnt=0) 0x429fedf1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list dmz-access; 3 elements; name hash: 0xf53f5801&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list dmz-access line 1 remark Permit all traffic to DC1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list dmz-access line 2 extended permit ip 128.162.1.0 255.255.255.0 host 192.168.1.2 (hitcnt=0) 0xd2dced0a&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list dmz-access line 3 remark Permit only DNS traffic to DNS server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list dmz-access line 4 extended permit udp 128.162.1.0 255.255.255.0 host 192.168.1.2 eq domain (hitcnt=0) 0xbb21093e&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list dmz-access line 5 remark Permit ICMP to all devices in DC&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800080;"&gt;access-list dmz-access line 6 extended permit icmp 128.162.1.0 255.255.255.0 192.168.1.0 255.255.255.0 (hitcnt=0) 0x71269ef7&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;CISCO-2811#show access-lists&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;Standard IP access list 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 permit any (1581021 matches)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;CISCO-2811#show translate&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;CISCO-2811#show route&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;CISCO-2811#show route-map&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;CISCO-2811#show host&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;CISCO-2811#show hosts&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;Default domain is maladomini.int&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;Name/address lookup uses domain service&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;Name servers are 192.168.1.2, 199.195.168.4, 205.171.2.65, 205.171.3.65, 8.8.8.8&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;Codes: UN - unknown, EX - expired, OK - OK, ?? - revalidate&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; temp - temporary, perm - permanent&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NA - Not Applicable None - Not defined&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;Host&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port&amp;nbsp; Flags&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Age Type&amp;nbsp;&amp;nbsp; Address(es)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;api.mixpanel.com&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; None&amp;nbsp; (temp, OK)&amp;nbsp; 2&amp;nbsp;&amp;nbsp; IP&amp;nbsp;&amp;nbsp;&amp;nbsp; 198.23.64.21&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 198.23.64.22&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 198.23.64.18&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 198.23.64.19&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #99cc00;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 198.23.64.20&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;ASA5510:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ASA5510# sh run all&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff00ff;"&gt;ASA Version 9.1(4)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;command-alias exec h help&lt;/P&gt;&lt;P&gt;command-alias exec lo logout&lt;/P&gt;&lt;P&gt;command-alias exec p ping&lt;/P&gt;&lt;P&gt;command-alias exec s show&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;hostname ASA5510&lt;/P&gt;&lt;P&gt;domain-name maladomini.int&lt;/P&gt;&lt;P&gt;enable password x encrypted&lt;/P&gt;&lt;P&gt;no fips enable&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any4 any4&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any4 any6&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any6 any4&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any6 any6&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any4 any4 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any4 any6 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any6 any4 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any6 any6 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session permit tcp any4 any4&lt;/P&gt;&lt;P&gt;xlate per-session permit tcp any4 any6&lt;/P&gt;&lt;P&gt;xlate per-session permit tcp any6 any4&lt;/P&gt;&lt;P&gt;xlate per-session permit tcp any6 any6&lt;/P&gt;&lt;P&gt;xlate per-session permit udp any4 any4 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session permit udp any4 any6 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session permit udp any6 any4 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session permit udp any6 any6 eq domain&lt;/P&gt;&lt;P&gt;passwd x encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;lacp system-priority 32768&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff00ff;"&gt;interface Ethernet0/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff00ff;"&gt; description LAN Interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff00ff;"&gt; speed auto&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff00ff;"&gt; duplex auto&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff00ff;"&gt;no&amp;nbsp; flowcontrol send on&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff00ff;"&gt; nameif Inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff00ff;"&gt; security-level 100&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff00ff;"&gt; ip address 10.10.1.1 255.255.255.252&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff00ff;"&gt; delay 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt;interface Ethernet0/1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; description WAN Interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; speed auto&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; duplex auto&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt;no&amp;nbsp; flowcontrol send on&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; nameif Outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; security-level 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; ip address 199.195.168.xxx 255.255.255.240&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; delay 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;interface Ethernet0/2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; description DMZ&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; speed auto&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; duplex auto&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;no&amp;nbsp; flowcontrol send on&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; nameif DMZ&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; security-level 100&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; ip address 10.10.0.1 255.255.255.252&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; delay 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;interface Ethernet0/3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; description VOIP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; speed auto&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; duplex auto&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;no&amp;nbsp; flowcontrol send on&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; nameif VOIP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; security-level 100&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; ip address 10.10.2.1 255.255.255.252&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; delay 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; delay 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;regex _default_gator "Gator"&lt;/P&gt;&lt;P&gt;regex _default_firethru-tunnel_2 "[/\\]cgi[-]bin[/\\]proxy"&lt;/P&gt;&lt;P&gt;regex _default_shoutcast-tunneling-protocol "1"&lt;/P&gt;&lt;P&gt;regex _default_http-tunnel "[/\\]HT_PortLog.aspx"&lt;/P&gt;&lt;P&gt;regex _default_x-kazaa-network "[\r\n\t ]+[xX]-[kK][aA][zZ][aA][aA]-[nN][eE][tT][wW][oO][rR][kK]"&lt;/P&gt;&lt;P&gt;regex _default_msn-messenger "[Aa][Pp][Pp][Ll][Ii][Cc][Aa][Tt][Ii][Oo][Nn][/\\][Xx][-][Mm][Ss][Nn][-][Mm][Ee][Ss][Ss][Ee][Nn][Gg][Ee][Rr]"&lt;/P&gt;&lt;P&gt;regex _default_GoToMyPC-tunnel_2 "[/\\]erc[/\\]Poll"&lt;/P&gt;&lt;P&gt;regex _default_gnu-http-tunnel_uri "[/\\]index[.]html"&lt;/P&gt;&lt;P&gt;regex _default_aim-messenger "[Hh][Tt][Tt][Pp][.][Pp][Rr][Oo][Xx][Yy][.][Ii][Cc][Qq][.][Cc][Oo][Mm]"&lt;/P&gt;&lt;P&gt;regex _default_gnu-http-tunnel_arg "crap"&lt;/P&gt;&lt;P&gt;regex _default_icy-metadata "[\r\n\t ]+[iI][cC][yY]-[mM][eE][tT][aA][dD][aA][tT][aA]"&lt;/P&gt;&lt;P&gt;regex _default_GoToMyPC-tunnel "machinekey"&lt;/P&gt;&lt;P&gt;regex _default_windows-media-player-tunnel "NSPlayer"&lt;/P&gt;&lt;P&gt;regex _default_yahoo-messenger "YMSG"&lt;/P&gt;&lt;P&gt;regex _default_httport-tunnel "photo[.]exectech[-]va[.]com"&lt;/P&gt;&lt;P&gt;regex _default_firethru-tunnel_1 "firethru[.]com"&lt;/P&gt;&lt;P&gt;checkheaps check-interval 60&lt;/P&gt;&lt;P&gt;checkheaps validate-checksum 60&lt;/P&gt;&lt;P&gt;boot system disk0:/asa914-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone UTC 0&lt;/P&gt;&lt;P&gt;dns domain-lookup Outside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 199.195.168.4&lt;/P&gt;&lt;P&gt; name-server 205.171.2.65&lt;/P&gt;&lt;P&gt; name-server 205.171.3.65&lt;/P&gt;&lt;P&gt; domain-name maladomini.int&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;object service ah pre-defined&lt;/P&gt;&lt;P&gt; service ah&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service eigrp pre-defined&lt;/P&gt;&lt;P&gt; service eigrp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service esp pre-defined&lt;/P&gt;&lt;P&gt; service esp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service gre pre-defined&lt;/P&gt;&lt;P&gt; service gre&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp pre-defined&lt;/P&gt;&lt;P&gt; service icmp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6 pre-defined&lt;/P&gt;&lt;P&gt; service icmp6&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service igmp pre-defined&lt;/P&gt;&lt;P&gt; service igmp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service igrp pre-defined&lt;/P&gt;&lt;P&gt; service igrp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service ip pre-defined&lt;/P&gt;&lt;P&gt; service ip&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service ipinip pre-defined&lt;/P&gt;&lt;P&gt; service ipinip&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service ipsec pre-defined&lt;/P&gt;&lt;P&gt; service esp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service nos pre-defined&lt;/P&gt;&lt;P&gt; service nos&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service ospf pre-defined&lt;/P&gt;&lt;P&gt; service ospf&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service pcp pre-defined&lt;/P&gt;&lt;P&gt; service pcp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service pim pre-defined&lt;/P&gt;&lt;P&gt; service pim&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service pptp pre-defined&lt;/P&gt;&lt;P&gt; service gre&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service snp pre-defined&lt;/P&gt;&lt;P&gt; service snp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp pre-defined&lt;/P&gt;&lt;P&gt; service tcp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp pre-defined&lt;/P&gt;&lt;P&gt; service udp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-aol pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq aol&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-bgp pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq bgp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-chargen pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq chargen&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-cifs pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq cifs&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-citrix-ica pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq citrix-ica&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-ctiqbe pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq ctiqbe&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-daytime pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq daytime&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-discard pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq discard&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-domain pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq domain&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-echo pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq echo&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-exec pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq exec&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-finger pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq finger&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-ftp pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq ftp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-ftp-data pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq ftp-data&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-gopher pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq gopher&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-ident pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq ident&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-imap4 pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq imap4&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-irc pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq irc&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-hostname pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq hostname&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-kerberos pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq kerberos&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-klogin pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq klogin&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-kshell pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq kshell&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-ldap pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq ldap&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-ldaps pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq ldaps&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-login pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq login&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-lotusnotes pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq lotusnotes&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-nfs pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq nfs&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-netbios-ssn pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq netbios-ssn&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-whois pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq whois&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-nntp pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq nntp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-pcanywhere-data pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq pcanywhere-data&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-pim-auto-rp pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq pim-auto-rp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-pop2 pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq pop2&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-pop3 pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq pop3&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-pptp pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq pptp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-lpd pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq lpd&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-rsh pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq rsh&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-rtsp pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq rtsp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-sip pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq sip&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-smtp pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq smtp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-ssh pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq ssh&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-sunrpc pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq sunrpc&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-tacacs pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq tacacs&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-talk pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq talk&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-telnet pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq telnet&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-uucp pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq uucp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-www pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq www&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-http pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq www&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-https pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq https&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-cmd pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq rsh&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-sqlnet pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq sqlnet&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-h323 pre-defined&lt;/P&gt;&lt;P&gt; service tcp destination eq h323&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-udp-cifs pre-defined&lt;/P&gt;&lt;P&gt; service tcp-udp destination eq cifs&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-udp-discard pre-defined&lt;/P&gt;&lt;P&gt; service tcp-udp destination eq discard&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-udp-domain pre-defined&lt;/P&gt;&lt;P&gt; service tcp-udp destination eq domain&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-udp-echo pre-defined&lt;/P&gt;&lt;P&gt; service tcp-udp destination eq echo&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-udp-kerberos pre-defined&lt;/P&gt;&lt;P&gt; service tcp-udp destination eq kerberos&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-udp-nfs pre-defined&lt;/P&gt;&lt;P&gt; service tcp-udp destination eq nfs&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-udp-pim-auto-rp pre-defined&lt;/P&gt;&lt;P&gt; service tcp-udp destination eq pim-auto-rp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-udp-sip pre-defined&lt;/P&gt;&lt;P&gt; service tcp-udp destination eq sip&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-udp-sunrpc pre-defined&lt;/P&gt;&lt;P&gt; service tcp-udp destination eq sunrpc&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-udp-tacacs pre-defined&lt;/P&gt;&lt;P&gt; service tcp-udp destination eq tacacs&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-udp-www pre-defined&lt;/P&gt;&lt;P&gt; service tcp-udp destination eq www&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-udp-http pre-defined&lt;/P&gt;&lt;P&gt; service tcp-udp destination eq www&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service tcp-udp-talk pre-defined&lt;/P&gt;&lt;P&gt; service tcp-udp destination eq talk&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-biff pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq biff&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-bootpc pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq bootpc&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-bootps pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq bootps&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-cifs pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq cifs&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-discard pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq discard&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-domain pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq domain&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-dnsix pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq dnsix&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-echo pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq echo&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-www pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq www&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-http pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq www&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-nameserver pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq nameserver&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-kerberos pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq kerberos&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-mobile-ip pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq mobile-ip&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-nfs pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq nfs&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-netbios-ns pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq netbios-ns&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-netbios-dgm pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq netbios-dgm&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-ntp pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq ntp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-pcanywhere-status pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq pcanywhere-status&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-pim-auto-rp pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq pim-auto-rp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-radius pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq radius&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-radius-acct pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq radius-acct&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-rip pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq rip&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-secureid-udp pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq secureid-udp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-sip pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq sip&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-snmp pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq snmp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-snmptrap pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq snmptrap&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-sunrpc pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq sunrpc&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-syslog pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq syslog&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-tacacs pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq tacacs&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-talk pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq talk&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-tftp pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq tftp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-time pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq time&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-who pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq who&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-xdmcp pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq xdmcp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service udp-isakmp pre-defined&lt;/P&gt;&lt;P&gt; service udp destination eq isakmp&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6-unreachable pre-defined&lt;/P&gt;&lt;P&gt; service icmp6 unreachable&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6-packet-too-big pre-defined&lt;/P&gt;&lt;P&gt; service icmp6 packet-too-big&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6-time-exceeded pre-defined&lt;/P&gt;&lt;P&gt; service icmp6 time-exceeded&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6-parameter-problem pre-defined&lt;/P&gt;&lt;P&gt; service icmp6 parameter-problem&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6-echo pre-defined&lt;/P&gt;&lt;P&gt; service icmp6 echo&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6-echo-reply pre-defined&lt;/P&gt;&lt;P&gt; service icmp6 echo-reply&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6-membership-query pre-defined&lt;/P&gt;&lt;P&gt; service icmp6 membership-query&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6-membership-report pre-defined&lt;/P&gt;&lt;P&gt; service icmp6 membership-report&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6-membership-reduction pre-defined&lt;/P&gt;&lt;P&gt; service icmp6 membership-reduction&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6-router-renumbering pre-defined&lt;/P&gt;&lt;P&gt; service icmp6 router-renumbering&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6-router-solicitation pre-defined&lt;/P&gt;&lt;P&gt; service icmp6 router-solicitation&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6-router-advertisement pre-defined&lt;/P&gt;&lt;P&gt; service icmp6 router-advertisement&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6-neighbor-solicitation pre-defined&lt;/P&gt;&lt;P&gt; service icmp6 neighbor-solicitation&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6-neighbor-advertisement pre-defined&lt;/P&gt;&lt;P&gt; service icmp6 neighbor-advertisement&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp6-neighbor-redirect pre-defined&lt;/P&gt;&lt;P&gt; service icmp6 neighbor-redirect&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-echo pre-defined&lt;/P&gt;&lt;P&gt; service icmp echo&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-echo-reply pre-defined&lt;/P&gt;&lt;P&gt; service icmp echo-reply&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-unreachable pre-defined&lt;/P&gt;&lt;P&gt; service icmp unreachable&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-source-quench pre-defined&lt;/P&gt;&lt;P&gt; service icmp source-quench&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-redirect pre-defined&lt;/P&gt;&lt;P&gt; service icmp redirect&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-alternate-address pre-defined&lt;/P&gt;&lt;P&gt; service icmp alternate-address&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-router-advertisement pre-defined&lt;/P&gt;&lt;P&gt; service icmp router-advertisement&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-router-solicitation pre-defined&lt;/P&gt;&lt;P&gt; service icmp router-solicitation&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-time-exceeded pre-defined&lt;/P&gt;&lt;P&gt; service icmp time-exceeded&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-parameter-problem pre-defined&lt;/P&gt;&lt;P&gt; service icmp parameter-problem&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-timestamp-request pre-defined&lt;/P&gt;&lt;P&gt; service icmp timestamp-request&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-timestamp-reply pre-defined&lt;/P&gt;&lt;P&gt; service icmp timestamp-reply&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-information-request pre-defined&lt;/P&gt;&lt;P&gt; service icmp information-request&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-information-reply pre-defined&lt;/P&gt;&lt;P&gt; service icmp information-reply&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-mask-request pre-defined&lt;/P&gt;&lt;P&gt; service icmp mask-request&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-mask-reply pre-defined&lt;/P&gt;&lt;P&gt; service icmp mask-reply&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-traceroute pre-defined&lt;/P&gt;&lt;P&gt; service icmp traceroute&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-conversion-error pre-defined&lt;/P&gt;&lt;P&gt; service icmp conversion-error&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;object service icmp-mobile-redirect pre-defined&lt;/P&gt;&lt;P&gt; service icmp mobile-redirect&lt;/P&gt;&lt;P&gt; description This is a pre-defined object&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;object network ROUTER-2811&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; host 10.10.1.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;object network ROUTER-2821&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; host 10.10.0.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;object network WEBCAM-01&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; host 192.168.1.5&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;object network DNS-SERVER&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; host 192.168.1.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;object network ROUTER-3745&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; host 10.10.2.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;object network RDP-DC1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; host 192.168.1.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;object-group network PAT-SOURCE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; network-object 10.10.1.0 255.255.255.252&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; network-object 10.10.0.0 255.255.255.252&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; network-object 10.10.2.0 255.255.255.252&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; network-object 192.168.0.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; network-object 172.16.10.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; network-object 172.16.20.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; network-object 128.162.1.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; network-object 128.162.10.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; network-object 128.162.20.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;object-group network DM_INLINE_NETWORK_2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; network-object host 98.22.121.x&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;object-group network Outside_access_in&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;object-group protocol DM_INLINE_PROTOCOL_1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; protocol-object gre&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-list USERS standard permit 10.10.1.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-list Outside_access_in extended permit tcp host 98.22.121.x object ROUTER-2811 eq ssh&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-list Outside_access_in extended permit tcp host 98.22.121.x object ROUTER-2821 eq ssh&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-list Outside_access_in extended permit tcp host 98.22.121.x interface Outside eq https&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-list Outside_access_in extended permit tcp host 98.22.121.x object WEBCAM-01 eq www&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-list Outside_access_in extended permit tcp host 98.22.121.x object RDP-DC1 eq 3389&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-list dmz-access-vlan1 extended permit ip 128.162.1.0 255.255.255.0 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-list dmz-access remark Permit all traffic to DC1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-list dmz-access extended permit ip 128.162.1.0 255.255.255.0 host 192.168.1.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-list dmz-access remark Permit only DNS traffic to DNS server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-list dmz-access extended permit udp 128.162.1.0 255.255.255.0 host 192.168.1.2 eq domain&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-list dmz-access remark Permit ICMP to all devices in DC&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-list dmz-access extended permit icmp 128.162.1.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging buffer-size 4096&lt;/P&gt;&lt;P&gt;logging asdm-buffer-size 100&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging flash-minimum-free 3076&lt;/P&gt;&lt;P&gt;logging flash-maximum-allocation 1024&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 747001&lt;/P&gt;&lt;P&gt;logging rate-limit 1 1 message 402116&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 620002&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 717015&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 717018&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 201013&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 201012&lt;/P&gt;&lt;P&gt;logging rate-limit 1 1 message 313009&lt;/P&gt;&lt;P&gt;logging rate-limit 100 1 message 750003&lt;/P&gt;&lt;P&gt;logging rate-limit 100 1 message 750002&lt;/P&gt;&lt;P&gt;logging rate-limit 100 1 message 750004&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 419003&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 405002&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 405003&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 421007&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 405001&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 421001&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 421002&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 337004&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 337005&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 337001&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 337002&lt;/P&gt;&lt;P&gt;logging rate-limit 1 60 message 199020&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 337003&lt;/P&gt;&lt;P&gt;logging rate-limit 2 5 message 199011&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 199010&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 337009&lt;/P&gt;&lt;P&gt;logging rate-limit 2 5 message 199012&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 710002&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 209003&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 209004&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 209005&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 431002&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 431001&lt;/P&gt;&lt;P&gt;logging rate-limit 1 1 message 447001&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 110003&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 110002&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 429007&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 216004&lt;/P&gt;&lt;P&gt;logging rate-limit 1 10 message 450001&lt;/P&gt;&lt;P&gt;flow-export template timeout-rate 30&lt;/P&gt;&lt;P&gt;flow-export active refresh-interval 1&lt;/P&gt;&lt;P&gt;mtu Inside 1500&lt;/P&gt;&lt;P&gt;mtu Outside 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu VOIP 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp deny any Outside&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-715.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;no arp permit-nonconnected&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #339966;"&gt;object network ROUTER-2811&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #339966;"&gt; nat (Inside,Outside) static interface service tcp ssh 222&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #339966;"&gt;object network ROUTER-2821&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #339966;"&gt; nat (DMZ,Outside) static interface service tcp ssh 2222&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #339966;"&gt;object network WEBCAM-01&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #339966;"&gt; nat (Inside,Outside) static interface service tcp www 8080&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #339966;"&gt;object network ROUTER-3745&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #339966;"&gt; nat (VOIP,Outside) static interface service tcp ssh 2223&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #339966;"&gt;object network RDP-DC1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #339966;"&gt; nat (Inside,Outside) static interface service tcp 3389 3389&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993300;"&gt;nat (any,Outside) after-auto source dynamic PAT-SOURCE interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993300;"&gt;access-group Outside_access_in in interface Outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993300;"&gt;ipv6 dhcprelay timeout 60&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;router rip&lt;/P&gt;&lt;P&gt; network 10.0.0.0&lt;/P&gt;&lt;P&gt; version 2&lt;/P&gt;&lt;P&gt; no auto-summary&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff00ff;"&gt;route Outside 0.0.0.0 0.0.0.0 199.195.168.113 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993300;"&gt;route Inside 128.162.1.0 255.255.255.0 10.10.0.2 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993300;"&gt;route Inside 128.162.10.0 255.255.255.0 10.10.0.2 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993300;"&gt;route Inside 128.162.20.0 255.255.255.0 10.10.0.2 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993300;"&gt;route Inside 172.16.10.0 255.255.255.0 10.10.1.2 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993300;"&gt;route Inside 172.16.20.0 255.255.255.0 10.10.1.2 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #993300;"&gt;route Inside 192.168.1.0 255.255.255.0 10.10.1.2 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt; action continue&lt;/P&gt;&lt;P&gt;no cts server-group&lt;/P&gt;&lt;P&gt;no cts sxp enable&lt;/P&gt;&lt;P&gt;no cts sxp default&lt;/P&gt;&lt;P&gt;no cts sxp default source-ip&lt;/P&gt;&lt;P&gt;cts sxp reconciliation period 120&lt;/P&gt;&lt;P&gt;cts sxp retry period 120&lt;/P&gt;&lt;P&gt;user-identity enable&lt;/P&gt;&lt;P&gt;user-identity domain LOCAL&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;user-identity action mac-address-mismatch remove-user-ip&lt;/P&gt;&lt;P&gt;user-identity inactive-user-timer minutes 60&lt;/P&gt;&lt;P&gt;user-identity poll-import-user-group-timer hours 8&lt;/P&gt;&lt;P&gt;user-identity ad-agent active-user-database full-download&lt;/P&gt;&lt;P&gt;user-identity ad-agent hello-timer seconds 30 retry-times 5&lt;/P&gt;&lt;P&gt;no user-identity user-not-found enable&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;http server enable 443&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 Inside&lt;/P&gt;&lt;P&gt;http 98.22.121.x 255.255.255.255 Outside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;no snmp-server enable traps syslog&lt;/P&gt;&lt;P&gt;no snmp-server enable traps ipsec start stop&lt;/P&gt;&lt;P&gt;no snmp-server enable traps entity config-change fru-insert fru-remove fan-failure power-supply power-supply-presence cpu-temperature chassis-temperature power-supply-temperature chassis-fan-failure&lt;/P&gt;&lt;P&gt;no snmp-server enable traps memory-threshold&lt;/P&gt;&lt;P&gt;no snmp-server enable traps interface-threshold&lt;/P&gt;&lt;P&gt;no snmp-server enable traps remote-access session-threshold-exceeded&lt;/P&gt;&lt;P&gt;no snmp-server enable traps connection-limit-reached&lt;/P&gt;&lt;P&gt;no snmp-server enable traps cpu threshold rising&lt;/P&gt;&lt;P&gt;no snmp-server enable traps ikev2 start stop&lt;/P&gt;&lt;P&gt;no snmp-server enable traps nat packet-discard&lt;/P&gt;&lt;P&gt;snmp-server enable&lt;/P&gt;&lt;P&gt;snmp-server listen-port 161&lt;/P&gt;&lt;P&gt;fragment size 200 Inside&lt;/P&gt;&lt;P&gt;fragment chain 24 Inside&lt;/P&gt;&lt;P&gt;fragment timeout 5 Inside&lt;/P&gt;&lt;P&gt;no fragment reassembly full Inside&lt;/P&gt;&lt;P&gt;fragment size 200 Outside&lt;/P&gt;&lt;P&gt;fragment chain 24 Outside&lt;/P&gt;&lt;P&gt;fragment timeout 5 Outside&lt;/P&gt;&lt;P&gt;no fragment reassembly full Outside&lt;/P&gt;&lt;P&gt;fragment size 200 management&lt;/P&gt;&lt;P&gt;fragment chain 24 management&lt;/P&gt;&lt;P&gt;fragment timeout 5 management&lt;/P&gt;&lt;P&gt;no fragment reassembly full management&lt;/P&gt;&lt;P&gt;fragment size 200 DMZ&lt;/P&gt;&lt;P&gt;fragment chain 24 DMZ&lt;/P&gt;&lt;P&gt;fragment timeout 5 DMZ&lt;/P&gt;&lt;P&gt;no fragment reassembly full DMZ&lt;/P&gt;&lt;P&gt;fragment size 200 VOIP&lt;/P&gt;&lt;P&gt;fragment chain 24 VOIP&lt;/P&gt;&lt;P&gt;fragment timeout 5 VOIP&lt;/P&gt;&lt;P&gt;no fragment reassembly full VOIP&lt;/P&gt;&lt;P&gt;no sysopt connection timewait&lt;/P&gt;&lt;P&gt;sysopt connection tcpmss 1380&lt;/P&gt;&lt;P&gt;sysopt connection tcpmss minimum 0&lt;/P&gt;&lt;P&gt;sysopt connection permit-vpn&lt;/P&gt;&lt;P&gt;sysopt connection reclassify-vpn&lt;/P&gt;&lt;P&gt;no sysopt connection preserve-vpn-flows&lt;/P&gt;&lt;P&gt;no sysopt radius ignore-secret&lt;/P&gt;&lt;P&gt;no sysopt noproxyarp Inside&lt;/P&gt;&lt;P&gt;no sysopt noproxyarp Outside&lt;/P&gt;&lt;P&gt;no sysopt noproxyarp management&lt;/P&gt;&lt;P&gt;no sysopt noproxyarp DMZ&lt;/P&gt;&lt;P&gt;no sysopt noproxyarp VOIP&lt;/P&gt;&lt;P&gt;service password-recovery&lt;/P&gt;&lt;P&gt;no crypto ipsec ikev2 sa-strength-enforcement&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;crypto ipsec security-association replay window-size 64&lt;/P&gt;&lt;P&gt;crypto ipsec security-association pmtu-aging infinite&lt;/P&gt;&lt;P&gt;crypto ipsec fragmentation before-encryption Inside&lt;/P&gt;&lt;P&gt;crypto ipsec fragmentation before-encryption Outside&lt;/P&gt;&lt;P&gt;crypto ipsec fragmentation before-encryption management&lt;/P&gt;&lt;P&gt;crypto ipsec fragmentation before-encryption DMZ&lt;/P&gt;&lt;P&gt;crypto ipsec fragmentation before-encryption VOIP&lt;/P&gt;&lt;P&gt;crypto ipsec df-bit copy-df Inside&lt;/P&gt;&lt;P&gt;crypto ipsec df-bit copy-df Outside&lt;/P&gt;&lt;P&gt;crypto ipsec df-bit copy-df management&lt;/P&gt;&lt;P&gt;crypto ipsec df-bit copy-df DMZ&lt;/P&gt;&lt;P&gt;crypto ipsec df-bit copy-df VOIP&lt;/P&gt;&lt;P&gt;crypto ca trustpool policy&lt;/P&gt;&lt;P&gt; revocation-check none&lt;/P&gt;&lt;P&gt; crl cache-time 60&lt;/P&gt;&lt;P&gt; crl enforcenextupdate&lt;/P&gt;&lt;P&gt;crypto isakmp identity auto&lt;/P&gt;&lt;P&gt;crypto isakmp nat-traversal 20&lt;/P&gt;&lt;P&gt;crypto ikev2 cookie-challenge 50&lt;/P&gt;&lt;P&gt;crypto ikev2 limit max-in-negotiation-sa 100&lt;/P&gt;&lt;P&gt;no crypto ikev2 limit max-sa&lt;/P&gt;&lt;P&gt;crypto ikev2 redirect during-auth&lt;/P&gt;&lt;P&gt;crypto ikev1 limit max-in-negotiation-sa 20&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 Inside&lt;/P&gt;&lt;P&gt;ssh 98.22.121.x 255.255.255.255 Outside&lt;/P&gt;&lt;P&gt;ssh timeout 60&lt;/P&gt;&lt;P&gt;ssh version 2&lt;/P&gt;&lt;P&gt;ssh key-exchange group dh-group1-sha1&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;vpn-addr-assign aaa&lt;/P&gt;&lt;P&gt;vpn-addr-assign dhcp&lt;/P&gt;&lt;P&gt;vpn-addr-assign local reuse-delay 0&lt;/P&gt;&lt;P&gt;ipv6-vpn-addr-assign aaa&lt;/P&gt;&lt;P&gt;ipv6-vpn-addr-assign local reuse-delay 0&lt;/P&gt;&lt;P&gt;no vpn-sessiondb max-other-vpn-limit&lt;/P&gt;&lt;P&gt;no vpn-sessiondb max-anyconnect-premium-or-essentials-limit&lt;/P&gt;&lt;P&gt;no remote-access threshold&lt;/P&gt;&lt;P&gt;l2tp tunnel hello 60&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tls-proxy maximum-session 100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;threat-detection rate dos-drop rate-interval 600 average-rate 100 burst-rate 400&lt;/P&gt;&lt;P&gt;threat-detection rate dos-drop rate-interval 3600 average-rate 80 burst-rate 320&lt;/P&gt;&lt;P&gt;threat-detection rate bad-packet-drop rate-interval 600 average-rate 100 burst-rate 400&lt;/P&gt;&lt;P&gt;threat-detection rate bad-packet-drop rate-interval 3600 average-rate 80 burst-rate 320&lt;/P&gt;&lt;P&gt;threat-detection rate acl-drop rate-interval 600 average-rate 400 burst-rate 800&lt;/P&gt;&lt;P&gt;threat-detection rate acl-drop rate-interval 3600 average-rate 320 burst-rate 640&lt;/P&gt;&lt;P&gt;threat-detection rate conn-limit-drop rate-interval 600 average-rate 100 burst-rate 400&lt;/P&gt;&lt;P&gt;threat-detection rate conn-limit-drop rate-interval 3600 average-rate 80 burst-rate 320&lt;/P&gt;&lt;P&gt;threat-detection rate icmp-drop rate-interval 600 average-rate 100 burst-rate 400&lt;/P&gt;&lt;P&gt;threat-detection rate icmp-drop rate-interval 3600 average-rate 80 burst-rate 320&lt;/P&gt;&lt;P&gt;threat-detection rate scanning-threat rate-interval 600 average-rate 5 burst-rate 10&lt;/P&gt;&lt;P&gt;threat-detection rate scanning-threat rate-interval 3600 average-rate 4 burst-rate 8&lt;/P&gt;&lt;P&gt;threat-detection rate syn-attack rate-interval 600 average-rate 100 burst-rate 200&lt;/P&gt;&lt;P&gt;threat-detection rate syn-attack rate-interval 3600 average-rate 80 burst-rate 160&lt;/P&gt;&lt;P&gt;threat-detection rate fw-drop rate-interval 600 average-rate 400 burst-rate 1600&lt;/P&gt;&lt;P&gt;threat-detection rate fw-drop rate-interval 3600 average-rate 320 burst-rate 1280&lt;/P&gt;&lt;P&gt;threat-detection rate inspect-drop rate-interval 600 average-rate 400 burst-rate 1600&lt;/P&gt;&lt;P&gt;threat-detection rate inspect-drop rate-interval 3600 average-rate 320 burst-rate 1280&lt;/P&gt;&lt;P&gt;threat-detection rate interface-drop rate-interval 600 average-rate 2000 burst-rate 8000&lt;/P&gt;&lt;P&gt;threat-detection rate interface-drop rate-interval 3600 average-rate 1600 burst-rate 6400&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;ntp server 24.56.178.140 source Outside prefer&lt;/P&gt;&lt;P&gt;ssl server-version any&lt;/P&gt;&lt;P&gt;ssl client-version any&lt;/P&gt;&lt;P&gt;ssl encryption rc4-sha1 dhe-aes128-sha1 dhe-aes256-sha1 aes128-sha1 aes256-sha1 3des-sha1&lt;/P&gt;&lt;P&gt;ssl certificate-authentication fca-timeout 2&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt; memory-size percent 50&lt;/P&gt;&lt;P&gt; port 443&lt;/P&gt;&lt;P&gt; dtls port 443&lt;/P&gt;&lt;P&gt; character-encoding none&lt;/P&gt;&lt;P&gt; no http-proxy&lt;/P&gt;&lt;P&gt; no https-proxy&lt;/P&gt;&lt;P&gt; default-idle-timeout 1800&lt;/P&gt;&lt;P&gt; portal-access-rule none&lt;/P&gt;&lt;P&gt; no csd enable&lt;/P&gt;&lt;P&gt; no anyconnect enable&lt;/P&gt;&lt;P&gt; no tunnel-group-list enable&lt;/P&gt;&lt;P&gt; no tunnel-group-preference group-url&lt;/P&gt;&lt;P&gt; rewrite order 65535 enable resource-mask *&lt;/P&gt;&lt;P&gt; no internal-password&lt;/P&gt;&lt;P&gt; no onscreen-keyboard&lt;/P&gt;&lt;P&gt; no default-language&lt;/P&gt;&lt;P&gt; no smart-tunnel notification-icon&lt;/P&gt;&lt;P&gt; no keepout&lt;/P&gt;&lt;P&gt; cache&lt;/P&gt;&lt;P&gt;&amp;nbsp; no disable&lt;/P&gt;&lt;P&gt;&amp;nbsp; max-object-size 1000&lt;/P&gt;&lt;P&gt;&amp;nbsp; min-object-size 0&lt;/P&gt;&lt;P&gt;&amp;nbsp; no cache-static-content enable&lt;/P&gt;&lt;P&gt;&amp;nbsp; lmfactor 20&lt;/P&gt;&lt;P&gt;&amp;nbsp; expiry-time 1&lt;/P&gt;&lt;P&gt; no auto-signon&lt;/P&gt;&lt;P&gt; no error-recovery disable&lt;/P&gt;&lt;P&gt; no ssl-server-check&lt;/P&gt;&lt;P&gt; no mus password&lt;/P&gt;&lt;P&gt; mus host mus.cisco.com&lt;/P&gt;&lt;P&gt; no hostscan data-limit&lt;/P&gt;&lt;P&gt;: # show import webvpn customization&lt;/P&gt;&lt;P&gt;: Template&lt;/P&gt;&lt;P&gt;: DfltCustomization&lt;/P&gt;&lt;P&gt;: # show import webvpn url-list&lt;/P&gt;&lt;P&gt;: Template&lt;/P&gt;&lt;P&gt;: # show import webvpn translation-table&lt;/P&gt;&lt;P&gt;: Translation Tables' Templates:&lt;/P&gt;&lt;P&gt;:&amp;nbsp;&amp;nbsp; PortForwarder&lt;/P&gt;&lt;P&gt;:&amp;nbsp;&amp;nbsp; banners&lt;/P&gt;&lt;P&gt;:&amp;nbsp;&amp;nbsp; customization&lt;/P&gt;&lt;P&gt;:&amp;nbsp;&amp;nbsp; url-list&lt;/P&gt;&lt;P&gt;:&amp;nbsp;&amp;nbsp; webvpn&lt;/P&gt;&lt;P&gt;: Translation Tables:&lt;/P&gt;&lt;P&gt;:&amp;nbsp;&amp;nbsp; fr&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PortForwarder&lt;/P&gt;&lt;P&gt;:&amp;nbsp;&amp;nbsp; fr&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; customization&lt;/P&gt;&lt;P&gt;:&amp;nbsp;&amp;nbsp; fr&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; webvpn&lt;/P&gt;&lt;P&gt;:&amp;nbsp;&amp;nbsp; ja&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PortForwarder&lt;/P&gt;&lt;P&gt;:&amp;nbsp;&amp;nbsp; ja&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; customization&lt;/P&gt;&lt;P&gt;:&amp;nbsp;&amp;nbsp; ja&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; webvpn&lt;/P&gt;&lt;P&gt;:&amp;nbsp;&amp;nbsp; ru&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PortForwarder&lt;/P&gt;&lt;P&gt;:&amp;nbsp;&amp;nbsp; ru&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; customization&lt;/P&gt;&lt;P&gt;:&amp;nbsp;&amp;nbsp; ru&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; webvpn&lt;/P&gt;&lt;P&gt;: # show import webvpn mst-translation&lt;/P&gt;&lt;P&gt;: No MS translation tables defined&lt;/P&gt;&lt;P&gt;: # show import webvpn webcontent&lt;/P&gt;&lt;P&gt;: No custom webcontent is loaded&lt;/P&gt;&lt;P&gt;: # show import webvpn AnyConnect-customization&lt;/P&gt;&lt;P&gt;: No OEM resources defined&lt;/P&gt;&lt;P&gt;: # show import webvpn plug-in&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;group-policy DfltGrpPolicy internal&lt;/P&gt;&lt;P&gt;group-policy DfltGrpPolicy attributes&lt;/P&gt;&lt;P&gt; banner none&lt;/P&gt;&lt;P&gt; wins-server none&lt;/P&gt;&lt;P&gt; dns-server none&lt;/P&gt;&lt;P&gt; dhcp-network-scope none&lt;/P&gt;&lt;P&gt; vpn-access-hours none&lt;/P&gt;&lt;P&gt; vpn-simultaneous-logins 3&lt;/P&gt;&lt;P&gt; vpn-idle-timeout 30&lt;/P&gt;&lt;P&gt; vpn-idle-timeout alert-interval 1&lt;/P&gt;&lt;P&gt; vpn-session-timeout none&lt;/P&gt;&lt;P&gt; vpn-session-timeout alert-interval 1&lt;/P&gt;&lt;P&gt; vpn-filter none&lt;/P&gt;&lt;P&gt; ipv6-vpn-filter none&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol ikev1 ikev2 l2tp-ipsec ssl-clientless&lt;/P&gt;&lt;P&gt; password-storage disable&lt;/P&gt;&lt;P&gt; ip-comp disable&lt;/P&gt;&lt;P&gt; re-xauth disable&lt;/P&gt;&lt;P&gt; group-lock none&lt;/P&gt;&lt;P&gt; pfs disable&lt;/P&gt;&lt;P&gt; ipsec-udp disable&lt;/P&gt;&lt;P&gt; ipsec-udp-port 10000&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelall&lt;/P&gt;&lt;P&gt; ipv6-split-tunnel-policy tunnelall&lt;/P&gt;&lt;P&gt; split-tunnel-network-list none&lt;/P&gt;&lt;P&gt; default-domain none&lt;/P&gt;&lt;P&gt; split-dns none&lt;/P&gt;&lt;P&gt; split-tunnel-all-dns disable&lt;/P&gt;&lt;P&gt; intercept-dhcp 255.255.255.255 disable&lt;/P&gt;&lt;P&gt; secure-unit-authentication disable&lt;/P&gt;&lt;P&gt; user-authentication disable&lt;/P&gt;&lt;P&gt; user-authentication-idle-timeout 30&lt;/P&gt;&lt;P&gt; ip-phone-bypass disable&lt;/P&gt;&lt;P&gt; client-bypass-protocol disable&lt;/P&gt;&lt;P&gt; gateway-fqdn none&lt;/P&gt;&lt;P&gt; leap-bypass disable&lt;/P&gt;&lt;P&gt; nem disable&lt;/P&gt;&lt;P&gt; backup-servers keep-client-config&lt;/P&gt;&lt;P&gt; msie-proxy server none&lt;/P&gt;&lt;P&gt; msie-proxy method no-modify&lt;/P&gt;&lt;P&gt; msie-proxy except-list none&lt;/P&gt;&lt;P&gt; msie-proxy local-bypass disable&lt;/P&gt;&lt;P&gt; msie-proxy pac-url none&lt;/P&gt;&lt;P&gt; msie-proxy lockdown enable&lt;/P&gt;&lt;P&gt; vlan none&lt;/P&gt;&lt;P&gt; nac-settings none&lt;/P&gt;&lt;P&gt; address-pools none&lt;/P&gt;&lt;P&gt; ipv6-address-pools none&lt;/P&gt;&lt;P&gt; smartcard-removal-disconnect enable&lt;/P&gt;&lt;P&gt; scep-forwarding-url none&lt;/P&gt;&lt;P&gt; client-firewall none&lt;/P&gt;&lt;P&gt; client-access-rule none&lt;/P&gt;&lt;P&gt; webvpn&lt;/P&gt;&lt;P&gt;&amp;nbsp; url-list none&lt;/P&gt;&lt;P&gt;&amp;nbsp; filter none&lt;/P&gt;&lt;P&gt;&amp;nbsp; homepage none&lt;/P&gt;&lt;P&gt;&amp;nbsp; html-content-filter none&lt;/P&gt;&lt;P&gt;&amp;nbsp; port-forward name Application Access&lt;/P&gt;&lt;P&gt;&amp;nbsp; port-forward disable&lt;/P&gt;&lt;P&gt;&amp;nbsp; http-proxy disable&lt;/P&gt;&lt;P&gt;&amp;nbsp; sso-server none&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect ssl dtls enable&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect mtu 1406&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect firewall-rule client-interface private none&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect firewall-rule client-interface public none&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect keep-installer installed&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect ssl keepalive 20&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect ssl rekey time none&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect ssl rekey method none&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect dpd-interval client 30&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect dpd-interval gateway 30&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect ssl compression none&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect dtls compression none&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect modules none&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect profiles none&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect ask none&lt;/P&gt;&lt;P&gt;&amp;nbsp; customization none&lt;/P&gt;&lt;P&gt;&amp;nbsp; keep-alive-ignore 4&lt;/P&gt;&lt;P&gt;&amp;nbsp; http-comp gzip&lt;/P&gt;&lt;P&gt;&amp;nbsp; download-max-size 2147483647&lt;/P&gt;&lt;P&gt;&amp;nbsp; upload-max-size 2147483647&lt;/P&gt;&lt;P&gt;&amp;nbsp; post-max-size 2147483647&lt;/P&gt;&lt;P&gt;&amp;nbsp; user-storage none&lt;/P&gt;&lt;P&gt;&amp;nbsp; storage-objects value cookies,credentials&lt;/P&gt;&lt;P&gt;&amp;nbsp; storage-key none&lt;/P&gt;&lt;P&gt;&amp;nbsp; hidden-shares none&lt;/P&gt;&lt;P&gt;&amp;nbsp; smart-tunnel disable&lt;/P&gt;&lt;P&gt;&amp;nbsp; activex-relay enable&lt;/P&gt;&lt;P&gt;&amp;nbsp; unix-auth-uid 65534&lt;/P&gt;&lt;P&gt;&amp;nbsp; unix-auth-gid 65534&lt;/P&gt;&lt;P&gt;&amp;nbsp; file-entry enable&lt;/P&gt;&lt;P&gt;&amp;nbsp; file-browsing enable&lt;/P&gt;&lt;P&gt;&amp;nbsp; url-entry enable&lt;/P&gt;&lt;P&gt;&amp;nbsp; deny-message value Login was successful, but because certain criteria have not been met or due to some specific group policy, you do not have permission to use any of the VPN features. Contact your IT administrator for more information&lt;/P&gt;&lt;P&gt;&amp;nbsp; smart-tunnel auto-signon disable&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect ssl df-bit-ignore disable&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect routing-filtering-ignore disable&lt;/P&gt;&lt;P&gt;&amp;nbsp; smart-tunnel tunnel-policy tunnelall&lt;/P&gt;&lt;P&gt;&amp;nbsp; always-on-vpn profile-setting&lt;/P&gt;&lt;P&gt;password-policy minimum-length 3&lt;/P&gt;&lt;P&gt;password-policy minimum-changes 0&lt;/P&gt;&lt;P&gt;password-policy minimum-lowercase 0&lt;/P&gt;&lt;P&gt;password-policy minimum-uppercase 0&lt;/P&gt;&lt;P&gt;password-policy minimum-numeric 0&lt;/P&gt;&lt;P&gt;password-policy minimum-special 0&lt;/P&gt;&lt;P&gt;password-policy lifetime 0&lt;/P&gt;&lt;P&gt;no password-policy authenticate-enable&lt;/P&gt;&lt;P&gt;quota management-session 0&lt;/P&gt;&lt;P&gt;tunnel-group DefaultL2LGroup type ipsec-l2l&lt;/P&gt;&lt;P&gt;tunnel-group DefaultL2LGroup general-attributes&lt;/P&gt;&lt;P&gt; no accounting-server-group&lt;/P&gt;&lt;P&gt; default-group-policy DfltGrpPolicy&lt;/P&gt;&lt;P&gt;tunnel-group DefaultL2LGroup ipsec-attributes&lt;/P&gt;&lt;P&gt; no ikev1 pre-shared-key&lt;/P&gt;&lt;P&gt; peer-id-validate req&lt;/P&gt;&lt;P&gt; no chain&lt;/P&gt;&lt;P&gt; no ikev1 trust-point&lt;/P&gt;&lt;P&gt; isakmp keepalive threshold 10 retry 2&lt;/P&gt;&lt;P&gt; no ikev2 remote-authentication&lt;/P&gt;&lt;P&gt; no ikev2 local-authentication&lt;/P&gt;&lt;P&gt;tunnel-group DefaultRAGroup type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group DefaultRAGroup general-attributes&lt;/P&gt;&lt;P&gt; no address-pool&lt;/P&gt;&lt;P&gt; no ipv6-address-pool&lt;/P&gt;&lt;P&gt; authentication-server-group LOCAL&lt;/P&gt;&lt;P&gt; secondary-authentication-server-group none&lt;/P&gt;&lt;P&gt; no accounting-server-group&lt;/P&gt;&lt;P&gt; default-group-policy DfltGrpPolicy&lt;/P&gt;&lt;P&gt; no dhcp-server&lt;/P&gt;&lt;P&gt; no strip-realm&lt;/P&gt;&lt;P&gt; no nat-assigned-to-public-ip&lt;/P&gt;&lt;P&gt; no scep-enrollment enable&lt;/P&gt;&lt;P&gt; no password-management&lt;/P&gt;&lt;P&gt; no override-account-disable&lt;/P&gt;&lt;P&gt; no strip-group&lt;/P&gt;&lt;P&gt; no authorization-required&lt;/P&gt;&lt;P&gt; username-from-certificate CN OU&lt;/P&gt;&lt;P&gt; secondary-username-from-certificate CN OU&lt;/P&gt;&lt;P&gt; authentication-attr-from-server primary&lt;/P&gt;&lt;P&gt; authenticated-session-username primary&lt;/P&gt;&lt;P&gt;tunnel-group DefaultRAGroup webvpn-attributes&lt;/P&gt;&lt;P&gt; customization DfltCustomization&lt;/P&gt;&lt;P&gt; authentication aaa&lt;/P&gt;&lt;P&gt; no override-svc-download&lt;/P&gt;&lt;P&gt; no radius-reject-message&lt;/P&gt;&lt;P&gt; no proxy-auth sdi&lt;/P&gt;&lt;P&gt; no pre-fill-username ssl-client&lt;/P&gt;&lt;P&gt; no pre-fill-username clientless&lt;/P&gt;&lt;P&gt; no secondary-pre-fill-username ssl-client&lt;/P&gt;&lt;P&gt; no secondary-pre-fill-username clientless&lt;/P&gt;&lt;P&gt; dns-group DefaultDNS&lt;/P&gt;&lt;P&gt; no without-csd&lt;/P&gt;&lt;P&gt;tunnel-group DefaultRAGroup ipsec-attributes&lt;/P&gt;&lt;P&gt; no ikev1 pre-shared-key&lt;/P&gt;&lt;P&gt; peer-id-validate req&lt;/P&gt;&lt;P&gt; no chain&lt;/P&gt;&lt;P&gt; no ikev1 trust-point&lt;/P&gt;&lt;P&gt; no ikev1 radius-sdi-xauth&lt;/P&gt;&lt;P&gt; isakmp keepalive threshold 300 retry 2&lt;/P&gt;&lt;P&gt; ikev1 user-authentication xauth&lt;/P&gt;&lt;P&gt; no ikev2 remote-authentication&lt;/P&gt;&lt;P&gt; no ikev2 local-authentication&lt;/P&gt;&lt;P&gt;tunnel-group DefaultRAGroup ppp-attributes&lt;/P&gt;&lt;P&gt; no authentication pap&lt;/P&gt;&lt;P&gt; authentication chap&lt;/P&gt;&lt;P&gt; authentication ms-chap-v1&lt;/P&gt;&lt;P&gt; no authentication ms-chap-v2&lt;/P&gt;&lt;P&gt; no authentication eap-proxy&lt;/P&gt;&lt;P&gt;tunnel-group DefaultWEBVPNGroup type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group DefaultWEBVPNGroup general-attributes&lt;/P&gt;&lt;P&gt; no address-pool&lt;/P&gt;&lt;P&gt; no ipv6-address-pool&lt;/P&gt;&lt;P&gt; authentication-server-group LOCAL&lt;/P&gt;&lt;P&gt; secondary-authentication-server-group none&lt;/P&gt;&lt;P&gt; no accounting-server-group&lt;/P&gt;&lt;P&gt; default-group-policy DfltGrpPolicy&lt;/P&gt;&lt;P&gt; no dhcp-server&lt;/P&gt;&lt;P&gt; no strip-realm&lt;/P&gt;&lt;P&gt; no nat-assigned-to-public-ip&lt;/P&gt;&lt;P&gt; no scep-enrollment enable&lt;/P&gt;&lt;P&gt; no password-management&lt;/P&gt;&lt;P&gt; no override-account-disable&lt;/P&gt;&lt;P&gt; no strip-group&lt;/P&gt;&lt;P&gt; no authorization-required&lt;/P&gt;&lt;P&gt; username-from-certificate CN OU&lt;/P&gt;&lt;P&gt; secondary-username-from-certificate CN OU&lt;/P&gt;&lt;P&gt; authentication-attr-from-server primary&lt;/P&gt;&lt;P&gt; authenticated-session-username primary&lt;/P&gt;&lt;P&gt;tunnel-group DefaultWEBVPNGroup webvpn-attributes&lt;/P&gt;&lt;P&gt; customization DfltCustomization&lt;/P&gt;&lt;P&gt; authentication aaa&lt;/P&gt;&lt;P&gt; no override-svc-download&lt;/P&gt;&lt;P&gt; no radius-reject-message&lt;/P&gt;&lt;P&gt; no proxy-auth sdi&lt;/P&gt;&lt;P&gt; no pre-fill-username ssl-client&lt;/P&gt;&lt;P&gt; no pre-fill-username clientless&lt;/P&gt;&lt;P&gt; no secondary-pre-fill-username ssl-client&lt;/P&gt;&lt;P&gt; no secondary-pre-fill-username clientless&lt;/P&gt;&lt;P&gt; dns-group DefaultDNS&lt;/P&gt;&lt;P&gt; no without-csd&lt;/P&gt;&lt;P&gt;tunnel-group DefaultWEBVPNGroup ipsec-attributes&lt;/P&gt;&lt;P&gt; no ikev1 pre-shared-key&lt;/P&gt;&lt;P&gt; peer-id-validate req&lt;/P&gt;&lt;P&gt; no chain&lt;/P&gt;&lt;P&gt; no ikev1 trust-point&lt;/P&gt;&lt;P&gt; no ikev1 radius-sdi-xauth&lt;/P&gt;&lt;P&gt; isakmp keepalive threshold 300 retry 2&lt;/P&gt;&lt;P&gt; ikev1 user-authentication xauth&lt;/P&gt;&lt;P&gt; no ikev2 remote-authentication&lt;/P&gt;&lt;P&gt; no ikev2 local-authentication&lt;/P&gt;&lt;P&gt;tunnel-group DefaultWEBVPNGroup ppp-attributes&lt;/P&gt;&lt;P&gt; no authentication pap&lt;/P&gt;&lt;P&gt; authentication chap&lt;/P&gt;&lt;P&gt; authentication ms-chap-v1&lt;/P&gt;&lt;P&gt; no authentication ms-chap-v2&lt;/P&gt;&lt;P&gt; no authentication eap-proxy&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all _default_gator&lt;/P&gt;&lt;P&gt; match request header user-agent regex _default_gator&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all _default_msn-messenger&lt;/P&gt;&lt;P&gt; match response header content-type regex _default_msn-messenger&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all _default_yahoo-messenger&lt;/P&gt;&lt;P&gt; match request body regex _default_yahoo-messenger&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all _default_windows-media-player-tunnel&lt;/P&gt;&lt;P&gt; match request header user-agent regex _default_windows-media-player-tunnel&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all _default_gnu-http-tunnel&lt;/P&gt;&lt;P&gt; match request args regex _default_gnu-http-tunnel_arg&lt;/P&gt;&lt;P&gt; match request uri regex _default_gnu-http-tunnel_uri&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all _default_firethru-tunnel&lt;/P&gt;&lt;P&gt; match request header host regex _default_firethru-tunnel_1&lt;/P&gt;&lt;P&gt; match request uri regex _default_firethru-tunnel_2&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all _default_aim-messenger&lt;/P&gt;&lt;P&gt; match request header host regex _default_aim-messenger&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all _default_http-tunnel&lt;/P&gt;&lt;P&gt; match request uri regex _default_http-tunnel&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all _default_kazaa&lt;/P&gt;&lt;P&gt; match response header regex _default_x-kazaa-network count gt 0&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all _default_shoutcast-tunneling-protocol&lt;/P&gt;&lt;P&gt; match request header regex _default_icy-metadata regex _default_shoutcast-tunneling-protocol&lt;/P&gt;&lt;P&gt;class-map class-default&lt;/P&gt;&lt;P&gt; match any&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all _default_GoToMyPC-tunnel&lt;/P&gt;&lt;P&gt; match request args regex _default_GoToMyPC-tunnel&lt;/P&gt;&lt;P&gt; match request uri regex _default_GoToMyPC-tunnel_2&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all _default_httport-tunnel&lt;/P&gt;&lt;P&gt; match request header host regex _default_httport-tunnel&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect rtsp _default_rtsp_map&lt;/P&gt;&lt;P&gt; description Default RTSP policymap&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;policy-map type inspect ipv6 _default_ipv6_map&lt;/P&gt;&lt;P&gt; description Default IPV6 policy-map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; verify-header type&lt;/P&gt;&lt;P&gt;&amp;nbsp; verify-header order&lt;/P&gt;&lt;P&gt; match header routing-type range 0 255&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop log&lt;/P&gt;&lt;P&gt;policy-map type inspect h323 _default_h323_map&lt;/P&gt;&lt;P&gt; description Default H.323 policymap&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; no rtp-conformance&lt;/P&gt;&lt;P&gt;policy-map type inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;&amp;nbsp; no message-length maximum server&lt;/P&gt;&lt;P&gt;&amp;nbsp; dns-guard&lt;/P&gt;&lt;P&gt;&amp;nbsp; protocol-enforcement&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-rewrite&lt;/P&gt;&lt;P&gt;&amp;nbsp; no id-randomization&lt;/P&gt;&lt;P&gt;&amp;nbsp; no id-mismatch&lt;/P&gt;&lt;P&gt;&amp;nbsp; no tsig enforced&lt;/P&gt;&lt;P&gt;policy-map type inspect esmtp _default_esmtp_map&lt;/P&gt;&lt;P&gt; description Default ESMTP policy-map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; mask-banner&lt;/P&gt;&lt;P&gt;&amp;nbsp; no mail-relay&lt;/P&gt;&lt;P&gt;&amp;nbsp; no special-character&lt;/P&gt;&lt;P&gt;&amp;nbsp; no allow-tls&lt;/P&gt;&lt;P&gt; match cmd line length gt 512&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection log&lt;/P&gt;&lt;P&gt; match cmd RCPT count gt 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection log&lt;/P&gt;&lt;P&gt; match body line length gt 998&lt;/P&gt;&lt;P&gt;&amp;nbsp; log&lt;/P&gt;&lt;P&gt; match header line length gt 998&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection log&lt;/P&gt;&lt;P&gt; match sender-address length gt 320&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection log&lt;/P&gt;&lt;P&gt; match MIME filename length gt 255&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection log&lt;/P&gt;&lt;P&gt; match ehlo-reply-parameter others&lt;/P&gt;&lt;P&gt;&amp;nbsp; mask&lt;/P&gt;&lt;P&gt;policy-map type inspect ip-options _default_ip_options_map&lt;/P&gt;&lt;P&gt; description Default IP-OPTIONS policy-map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; router-alert action allow&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 _default_h323_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras _default_h323_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp _default_esmtp_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options _default_ip_options_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp error&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect pptp&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;policy-map type inspect sip _default_sip_map&lt;/P&gt;&lt;P&gt; description Default SIP policymap&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; im&lt;/P&gt;&lt;P&gt;&amp;nbsp; no ip-address-privacy&lt;/P&gt;&lt;P&gt;&amp;nbsp; traffic-non-sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; no rtp-conformance&lt;/P&gt;&lt;P&gt;policy-map type inspect dns _default_dns_map&lt;/P&gt;&lt;P&gt; description Default DNS policy-map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; no message-length maximum client&lt;/P&gt;&lt;P&gt;&amp;nbsp; no message-length maximum&lt;/P&gt;&lt;P&gt;&amp;nbsp; no message-length maximum server&lt;/P&gt;&lt;P&gt;&amp;nbsp; dns-guard&lt;/P&gt;&lt;P&gt;&amp;nbsp; protocol-enforcement&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-rewrite&lt;/P&gt;&lt;P&gt;&amp;nbsp; no id-randomization&lt;/P&gt;&lt;P&gt;&amp;nbsp; no id-mismatch&lt;/P&gt;&lt;P&gt;&amp;nbsp; no tsig enforced&lt;/P&gt;&lt;P&gt;policy-map type inspect ipsec-pass-thru _default_ipsec_passthru_map&lt;/P&gt;&lt;P&gt; description Default IPSEC-PASS-THRU policy-map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; esp per-client-max 0 timeout 0:10:00&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;imap4s&lt;/P&gt;&lt;P&gt; port 993&lt;/P&gt;&lt;P&gt; no server&lt;/P&gt;&lt;P&gt; outstanding 20&lt;/P&gt;&lt;P&gt; name-separator :&lt;/P&gt;&lt;P&gt; server-separator @&lt;/P&gt;&lt;P&gt; authentication-server-group LOCAL&lt;/P&gt;&lt;P&gt; no authorization-server-group&lt;/P&gt;&lt;P&gt; no accounting-server-group&lt;/P&gt;&lt;P&gt; default-group-policy DfltGrpPolicy&lt;/P&gt;&lt;P&gt; no authentication&lt;/P&gt;&lt;P&gt; no authorization-required&lt;/P&gt;&lt;P&gt; authorization-dn-attributes CN OU&lt;/P&gt;&lt;P&gt;pop3s&lt;/P&gt;&lt;P&gt; port 995&lt;/P&gt;&lt;P&gt; no server&lt;/P&gt;&lt;P&gt; outstanding 20&lt;/P&gt;&lt;P&gt; name-separator :&lt;/P&gt;&lt;P&gt; server-separator @&lt;/P&gt;&lt;P&gt; authentication-server-group LOCAL&lt;/P&gt;&lt;P&gt; no authorization-server-group&lt;/P&gt;&lt;P&gt; no accounting-server-group&lt;/P&gt;&lt;P&gt; default-group-policy DfltGrpPolicy&lt;/P&gt;&lt;P&gt; no authentication&lt;/P&gt;&lt;P&gt; no authorization-required&lt;/P&gt;&lt;P&gt; authorization-dn-attributes CN OU&lt;/P&gt;&lt;P&gt;smtps&lt;/P&gt;&lt;P&gt; port 988&lt;/P&gt;&lt;P&gt; no server&lt;/P&gt;&lt;P&gt; outstanding 20&lt;/P&gt;&lt;P&gt; name-separator :&lt;/P&gt;&lt;P&gt; server-separator @&lt;/P&gt;&lt;P&gt; authentication-server-group LOCAL&lt;/P&gt;&lt;P&gt; no authorization-server-group&lt;/P&gt;&lt;P&gt; no accounting-server-group&lt;/P&gt;&lt;P&gt; default-group-policy DfltGrpPolicy&lt;/P&gt;&lt;P&gt; authentication aaa&lt;/P&gt;&lt;P&gt; no authorization-required&lt;/P&gt;&lt;P&gt; authorization-dn-attributes CN OU&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;auto-update device-id hostname&lt;/P&gt;&lt;P&gt;auto-update poll-period 720 0 5&lt;/P&gt;&lt;P&gt;auto-update timeout 0&lt;/P&gt;&lt;P&gt;compression anyconnect-ssl http-comp&lt;/P&gt;&lt;P&gt;no coredump enable&lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;call-home&lt;/P&gt;&lt;P&gt; alert-group all&lt;/P&gt;&lt;P&gt; alert-group-config environment&lt;/P&gt;&lt;P&gt;&amp;nbsp; threshold cpu 85-90&lt;/P&gt;&lt;P&gt;&amp;nbsp; threshold memory 85-90&lt;/P&gt;&lt;P&gt; event-queue-size 10&lt;/P&gt;&lt;P&gt; rate-limit 10&lt;/P&gt;&lt;P&gt; profile CiscoTAC-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no active&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address http &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address email &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:callhome@cisco.com" target="_blank"&gt;callhome@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination message-size-limit 3145728&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination preferred-msg-format xml&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination transport-method http&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group diagnostic severity informational&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group environment severity informational&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group inventory severity informational periodic monthly 26&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group configuration export minimum periodic monthly 26&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group telemetry severity informational periodic daily&lt;/P&gt;&lt;P&gt;password encryption aes&lt;/P&gt;&lt;P&gt;Cryptochecksum:6f99e1277a392a926d04735c7f6a8c50&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;Cisco 2811:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CISCO-2811#sh run all&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration with default configurations exposed : 35894 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;! Last configuration change at 23:24:57 UTC Mon Feb 3 2014 by redacted&lt;/P&gt;&lt;P&gt;version 15.1&lt;/P&gt;&lt;P&gt;parser cache&lt;/P&gt;&lt;P&gt;parser config partition&lt;/P&gt;&lt;P&gt;parser command serializer&lt;/P&gt;&lt;P&gt;downward-compatible-config 15.1&lt;/P&gt;&lt;P&gt;no service log backtrace&lt;/P&gt;&lt;P&gt;no service config&lt;/P&gt;&lt;P&gt;no service exec-callback&lt;/P&gt;&lt;P&gt;no service nagle&lt;/P&gt;&lt;P&gt;service slave-log&lt;/P&gt;&lt;P&gt;no service slave-coredump&lt;/P&gt;&lt;P&gt;no service pad to-xot&lt;/P&gt;&lt;P&gt;no service pad from-xot&lt;/P&gt;&lt;P&gt;no service pad cmns&lt;/P&gt;&lt;P&gt;service pad&lt;/P&gt;&lt;P&gt;no service telnet-zeroidle&lt;/P&gt;&lt;P&gt;no service tcp-keepalives-in&lt;/P&gt;&lt;P&gt;no service tcp-keepalives-out&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec&lt;/P&gt;&lt;P&gt;service timestamps log datetime msec&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;no service exec-wait&lt;/P&gt;&lt;P&gt;no service linenumber&lt;/P&gt;&lt;P&gt;no service internal&lt;/P&gt;&lt;P&gt;no service scripting&lt;/P&gt;&lt;P&gt;no service compress-config&lt;/P&gt;&lt;P&gt;service prompt config&lt;/P&gt;&lt;P&gt;no service old-slip-prompts&lt;/P&gt;&lt;P&gt;no service pt-vty-logging&lt;/P&gt;&lt;P&gt;no service disable-ip-fast-frag&lt;/P&gt;&lt;P&gt;no service sequence-numbers&lt;/P&gt;&lt;P&gt;no service call-home&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname CISCO-2811&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot system flash&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;shell processing&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no logging discriminator&lt;/P&gt;&lt;P&gt;logging exception 4096&lt;/P&gt;&lt;P&gt;no logging count&lt;/P&gt;&lt;P&gt;no logging message-counter log&lt;/P&gt;&lt;P&gt;no logging message-counter debug&lt;/P&gt;&lt;P&gt;logging message-counter syslog&lt;/P&gt;&lt;P&gt;no logging snmp-authfail&lt;/P&gt;&lt;P&gt;no logging userinfo&lt;/P&gt;&lt;P&gt;logging buginf&lt;/P&gt;&lt;P&gt;logging queue-limit 100&lt;/P&gt;&lt;P&gt;logging queue-limit esm 0&lt;/P&gt;&lt;P&gt;logging queue-limit trap 100&lt;/P&gt;&lt;P&gt;logging buffered 0 debugging&lt;/P&gt;&lt;P&gt;logging reload message-limit 1000 notifications&lt;/P&gt;&lt;P&gt;no logging persistent&lt;/P&gt;&lt;P&gt;logging rate-limit console 10 except errors&lt;/P&gt;&lt;P&gt;logging console guaranteed&lt;/P&gt;&lt;P&gt;logging console debugging&lt;/P&gt;&lt;P&gt;logging monitor debugging&lt;/P&gt;&lt;P&gt;logging cns-events informational&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;enable Redacted&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;autoupgrade disk-cleanup crashinfo&lt;/P&gt;&lt;P&gt;autoupgrade disk-cleanup core&lt;/P&gt;&lt;P&gt;autoupgrade disk-cleanup image&lt;/P&gt;&lt;P&gt;ipc holdq threshold upper 0&lt;/P&gt;&lt;P&gt;ipc holdq threshold lower 0&lt;/P&gt;&lt;P&gt;ipc header-cache permanent 1000 100&lt;/P&gt;&lt;P&gt;ipc buffers max-free 8&lt;/P&gt;&lt;P&gt;ipc buffers min-free 1&lt;/P&gt;&lt;P&gt;ipc buffers permanent 2&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication attempts login 3&lt;/P&gt;&lt;P&gt;aaa accounting jitter maximum 300&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt; port 1645&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt; port 1700&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;aaa memory threshold authentication reject 3&lt;/P&gt;&lt;P&gt;aaa memory threshold accounting disable 2&lt;/P&gt;&lt;P&gt;ethernet cfm ieee&lt;/P&gt;&lt;P&gt;ethernet cfm alarm notification mac-remote-error-xcon&lt;/P&gt;&lt;P&gt;ethernet cfm alarm delay 2500&lt;/P&gt;&lt;P&gt;ethernet cfm alarm reset 10000&lt;/P&gt;&lt;P&gt;ppp hold-queue 2800&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;process cpu extended history 12&lt;/P&gt;&lt;P&gt;process cpu autoprofile hog&lt;/P&gt;&lt;P&gt;cef table consistency-check IPv4 type scan-rib-ios count 1000 period 60&lt;/P&gt;&lt;P&gt;cef table consistency-check IPv4 type scan-ios-rib count 1000 period 60&lt;/P&gt;&lt;P&gt;no cef table consistency-check IPv4 data-checking&lt;/P&gt;&lt;P&gt;no cef table consistency-check IPv4 error-message&lt;/P&gt;&lt;P&gt;cef table consistency-check IPv4 auto-repair delay 10 holddown 300&lt;/P&gt;&lt;P&gt;cef table vrf tree IPv4 type MTRIE short-mask-protection 4 stride-pattern 8-8-8-8 hardware-api-notify off&lt;/P&gt;&lt;P&gt;cef table output-chain build favor default&lt;/P&gt;&lt;P&gt;cef table rate-monitor-period 5&lt;/P&gt;&lt;P&gt;errdisable detect cause all&lt;/P&gt;&lt;P&gt;errdisable recovery interval 300&lt;/P&gt;&lt;P&gt;network-clock-switch 10 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot11 syslog&lt;/P&gt;&lt;P&gt;dot11 activity-timeout unknown default 60&lt;/P&gt;&lt;P&gt;dot11 activity-timeout client default 60&lt;/P&gt;&lt;P&gt;dot11 activity-timeout repeater default 60&lt;/P&gt;&lt;P&gt;dot11 activity-timeout workgroup-bridge default 60&lt;/P&gt;&lt;P&gt;dot11 activity-timeout bridge default 60&lt;/P&gt;&lt;P&gt;dot11 aaa csid default&lt;/P&gt;&lt;P&gt;call-home&lt;/P&gt;&lt;P&gt; alert-group configuration&lt;/P&gt;&lt;P&gt; alert-group environment&lt;/P&gt;&lt;P&gt; alert-group inventory&lt;/P&gt;&lt;P&gt; alert-group syslog&lt;/P&gt;&lt;P&gt; rate-limit 20&lt;/P&gt;&lt;P&gt; profile "CiscoTAC-1"&lt;/P&gt;&lt;P&gt;&amp;nbsp; no active&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination preferred-msg-format xml&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination message-size-limit 3145728&lt;/P&gt;&lt;P&gt;&amp;nbsp; no destination transport-method http&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination transport-method email&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address email &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:callhome@cisco.com" target="_blank"&gt;callhome@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address http &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group environment severity minor&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group syslog severity major pattern ".*"&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly 21 13:47&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly 21 13:32&lt;/P&gt;&lt;P&gt;prompt config hostname-length 20&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;no ip source-route&lt;/P&gt;&lt;P&gt;ip routing protocol purge interface&lt;/P&gt;&lt;P&gt;ip arp queue 512&lt;/P&gt;&lt;P&gt;ip icmp redirect subnet&lt;/P&gt;&lt;P&gt;ip spd queue threshold minimum 73 maximum 74&lt;/P&gt;&lt;P&gt;ip verify drop-rate compute window 300&lt;/P&gt;&lt;P&gt;ip verify drop-rate compute interval 30&lt;/P&gt;&lt;P&gt;ip verify drop-rate notify hold-down 300&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip nbar bypass&lt;/P&gt;&lt;P&gt;ip nbar resources system 30 4236 128&lt;/P&gt;&lt;P&gt;ip nbar port-map edonkey tcp 4662&lt;/P&gt;&lt;P&gt;ip nbar port-map kazaa2 tcp 80&lt;/P&gt;&lt;P&gt;ip nbar port-map gnutella udp 6346 6347 6348&lt;/P&gt;&lt;P&gt;ip nbar port-map gnutella tcp 6346 6347 6348 6349 6355 5634&lt;/P&gt;&lt;P&gt;ip nbar port-map fasttrack tcp 1214&lt;/P&gt;&lt;P&gt;ip nbar port-map citrix udp 1604&lt;/P&gt;&lt;P&gt;ip nbar port-map citrix tcp 2598 2512 2513 1494&lt;/P&gt;&lt;P&gt;ip nbar port-map http tcp 80&lt;/P&gt;&lt;P&gt;ip nbar port-map sap tcp 3200 3300 3600&lt;/P&gt;&lt;P&gt;ip nbar port-map telepresence-control tcp 5060&lt;/P&gt;&lt;P&gt;ip nbar port-map microsoftds udp 445&lt;/P&gt;&lt;P&gt;ip nbar port-map microsoftds tcp 445&lt;/P&gt;&lt;P&gt;ip nbar port-map blizwow udp 3724&lt;/P&gt;&lt;P&gt;ip nbar port-map blizwow tcp 3724&lt;/P&gt;&lt;P&gt;ip nbar port-map youtube tcp 80&lt;/P&gt;&lt;P&gt;ip nbar port-map cisco-phone udp 5060&lt;/P&gt;&lt;P&gt;ip nbar port-map cisco-phone tcp 2000 2001 2002 5060&lt;/P&gt;&lt;P&gt;ip nbar port-map cifs tcp 445 139&lt;/P&gt;&lt;P&gt;ip nbar port-map aol-messenger tcp 5190 1080 443&lt;/P&gt;&lt;P&gt;ip nbar port-map yahoo-messenger tcp 80 119 1080 5050 5101&lt;/P&gt;&lt;P&gt;ip nbar port-map msn-messenger tcp 80 1863 1080&lt;/P&gt;&lt;P&gt;ip nbar port-map dns udp 53&lt;/P&gt;&lt;P&gt;ip nbar port-map dns tcp 53&lt;/P&gt;&lt;P&gt;ip nbar port-map smtp tcp 25 587&lt;/P&gt;&lt;P&gt;ip nbar port-map directconnect tcp 411 412 413&lt;/P&gt;&lt;P&gt;ip nbar port-map bittorrent udp 3724&lt;/P&gt;&lt;P&gt;ip nbar port-map bittorrent tcp 3724 1080 6969 6881 6882 6883 6884 6885 6886 6887 6888 6889&lt;/P&gt;&lt;P&gt;ip nbar port-map winmx tcp 6699&lt;/P&gt;&lt;P&gt;ip nbar port-map sip udp 5060&lt;/P&gt;&lt;P&gt;ip nbar port-map sip tcp 5060&lt;/P&gt;&lt;P&gt;ip nbar port-map h323 udp 1300 1718 1719 1720 11720&lt;/P&gt;&lt;P&gt;ip nbar port-map h323 tcp 1300 1718 1719 1720 11000 - 11999&lt;/P&gt;&lt;P&gt;ip nbar port-map skinny tcp 2000 2001 2002&lt;/P&gt;&lt;P&gt;ip nbar port-map mgcp udp 2427 2727&lt;/P&gt;&lt;P&gt;ip nbar port-map mgcp tcp 2427 2428 2727&lt;/P&gt;&lt;P&gt;ip nbar port-map rtsp tcp 554 8554&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-10 udp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-10 tcp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-09 udp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-09 tcp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-08 udp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-08 tcp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-07 udp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-07 tcp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-06 udp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-06 tcp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-05 udp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-05 tcp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-04 udp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-04 tcp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-03 udp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-03 tcp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-02 udp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-02 tcp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-01 udp&lt;/P&gt;&lt;P&gt;ip nbar port-map custom-01 tcp&lt;/P&gt;&lt;P&gt;ip nbar port-map streamwork udp 1558&lt;/P&gt;&lt;P&gt;ip nbar port-map sunrpc udp 111&lt;/P&gt;&lt;P&gt;ip nbar port-map sunrpc tcp 111&lt;/P&gt;&lt;P&gt;ip nbar port-map netshow tcp 1755&lt;/P&gt;&lt;P&gt;ip nbar port-map rcmd tcp 512 513 514&lt;/P&gt;&lt;P&gt;ip nbar port-map sqlnet tcp 1521&lt;/P&gt;&lt;P&gt;ip nbar port-map vdolive tcp 7000&lt;/P&gt;&lt;P&gt;ip nbar port-map exchange tcp 135&lt;/P&gt;&lt;P&gt;ip nbar port-map tftp udp 69&lt;/P&gt;&lt;P&gt;ip nbar port-map nntp udp 119&lt;/P&gt;&lt;P&gt;ip nbar port-map nntp tcp 119&lt;/P&gt;&lt;P&gt;ip nbar port-map socks tcp 1080&lt;/P&gt;&lt;P&gt;ip nbar port-map netbios udp 137 138&lt;/P&gt;&lt;P&gt;ip nbar port-map netbios tcp 139 137&lt;/P&gt;&lt;P&gt;ip nbar port-map secure-http tcp 443&lt;/P&gt;&lt;P&gt;ip nbar port-map submit tcp 773&lt;/P&gt;&lt;P&gt;ip nbar port-map tacacs udp 49 65&lt;/P&gt;&lt;P&gt;ip nbar port-map tacacs tcp 49 65&lt;/P&gt;&lt;P&gt;ip nbar port-map corba-iiop udp 683 684&lt;/P&gt;&lt;P&gt;ip nbar port-map corba-iiop tcp 683 684&lt;/P&gt;&lt;P&gt;ip nbar port-map vnc udp 5800 5900 5901&lt;/P&gt;&lt;P&gt;ip nbar port-map vnc tcp 5800 5900 5901&lt;/P&gt;&lt;P&gt;ip nbar port-map novadigm udp 3460 3461 3462 3463 3464 3465&lt;/P&gt;&lt;P&gt;ip nbar port-map novadigm tcp 3460 3461 3462 3463 3464 3465&lt;/P&gt;&lt;P&gt;ip nbar port-map xwindows tcp 6000 6001 6002 6003&lt;/P&gt;&lt;P&gt;ip nbar port-map shell tcp 514&lt;/P&gt;&lt;P&gt;ip nbar port-map syslog udp 514&lt;/P&gt;&lt;P&gt;ip nbar port-map snmp udp 161 162&lt;/P&gt;&lt;P&gt;ip nbar port-map snmp tcp 161 162&lt;/P&gt;&lt;P&gt;ip nbar port-map rsvp udp 1698 1699&lt;/P&gt;&lt;P&gt;ip nbar port-map pcanywhere udp 22 5632&lt;/P&gt;&lt;P&gt;ip nbar port-map pcanywhere tcp 65301 5631&lt;/P&gt;&lt;P&gt;ip nbar port-map kerberos udp 88 749&lt;/P&gt;&lt;P&gt;ip nbar port-map kerberos tcp 88 749&lt;/P&gt;&lt;P&gt;ip nbar port-map secure-imap udp 585 993&lt;/P&gt;&lt;P&gt;ip nbar port-map secure-imap tcp 585 993&lt;/P&gt;&lt;P&gt;ip nbar port-map imap udp 143 220&lt;/P&gt;&lt;P&gt;ip nbar port-map imap tcp 143 220&lt;/P&gt;&lt;P&gt;ip nbar port-map dhcp udp 67 68&lt;/P&gt;&lt;P&gt;ip nbar port-map cuseeme udp 7648 7649 24032&lt;/P&gt;&lt;P&gt;ip nbar port-map cuseeme tcp 7648 7649&lt;/P&gt;&lt;P&gt;ip nbar port-map ftp tcp 21&lt;/P&gt;&lt;P&gt;ip cef optimize neighbor resolution&lt;/P&gt;&lt;P&gt;ip cef&lt;/P&gt;&lt;P&gt;no ip cef accounting&lt;/P&gt;&lt;P&gt;ip cef load-sharing algorithm universal 309C488F&lt;/P&gt;&lt;P&gt;ip dhcp relay information policy replace&lt;/P&gt;&lt;P&gt;ip dhcp relay information check&lt;/P&gt;&lt;P&gt;ip dhcp use class&lt;/P&gt;&lt;P&gt;no ip dhcp use vrf connected&lt;/P&gt;&lt;P&gt;ip dhcp binding cleanup interval 120&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;ip dhcp compatibility suboption link-selection cisco&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;ip dhcp conflict logging&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;ip dhcp excluded-address 192.168.1.1 192.168.1.49&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;ip dhcp excluded-address 172.16.10.1 172.16.10.49&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;ip dhcp excluded-address 172.16.20.1 172.16.20.49&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;ip dhcp ping packets 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;ip dhcp ping timeout 500&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;ip dhcp pool Mitchs_Network&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; network 192.168.1.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; dns-server 192.168.1.2 199.195.168.4 205.171.2.65 205.171.3.65 8.8.8.8&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; default-router 192.168.1.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;ip dhcp pool VLAN10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; network 172.16.10.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; default-router 172.16.10.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; dns-server 199.195.168.4 205.171.2.65 205.171.3.65 8.8.8.8&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;ip dhcp pool VLAN20&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; network 172.16.20.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; dns-server 199.195.168.4 205.171.2.65 205.171.3.65 8.8.8.8&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; default-router 172.16.20.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip sctp asconf auto&lt;/P&gt;&lt;P&gt;ip sctp asconf authenticate check&lt;/P&gt;&lt;P&gt;no ip sctp authenticate data&lt;/P&gt;&lt;P&gt;no ip sctp authenticate init&lt;/P&gt;&lt;P&gt;no ip sctp authenticate init-ack&lt;/P&gt;&lt;P&gt;no ip sctp authenticate sack&lt;/P&gt;&lt;P&gt;no ip sctp authenticate heartbeat&lt;/P&gt;&lt;P&gt;no ip sctp authenticate heartbeat-ack&lt;/P&gt;&lt;P&gt;no ip sctp authenticate abort&lt;/P&gt;&lt;P&gt;no ip sctp authenticate shutdown&lt;/P&gt;&lt;P&gt;no ip sctp authenticate shutdown-ack&lt;/P&gt;&lt;P&gt;no ip sctp authenticate error&lt;/P&gt;&lt;P&gt;no ip sctp authenticate cookie-echo&lt;/P&gt;&lt;P&gt;no ip sctp authenticate cookie-ack&lt;/P&gt;&lt;P&gt;no ip sctp authenticate ecne&lt;/P&gt;&lt;P&gt;no ip sctp authenticate cwr&lt;/P&gt;&lt;P&gt;no ip sctp authenticate shutdown-complete&lt;/P&gt;&lt;P&gt;no ip sctp authenticate authentication&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 16&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 17&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 18&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 19&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 20&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 21&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 22&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 23&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 24&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 25&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 26&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 27&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 28&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 29&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 30&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 31&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 32&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 33&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 34&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 35&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 36&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 37&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 38&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 39&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 40&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 41&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 42&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 43&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 44&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 45&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 46&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 47&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 48&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 49&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 50&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 51&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 52&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 53&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 54&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 55&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 56&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 57&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 58&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 59&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 60&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 61&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 62&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 63&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 64&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 65&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 66&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 67&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 68&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 69&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 70&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 71&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 72&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 73&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 74&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 75&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 76&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 77&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 78&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 79&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 80&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 81&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 82&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 83&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 84&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 85&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 86&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 87&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 88&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 89&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 90&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 91&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 92&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 93&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 94&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 95&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 96&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 97&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 98&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 99&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 100&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 101&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 102&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 103&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 104&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 105&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 106&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 107&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 108&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 109&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 110&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 111&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 112&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 113&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 114&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 115&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 116&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 117&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 118&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 119&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 120&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 121&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 122&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 123&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 124&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 125&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 126&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 127&lt;/P&gt;&lt;P&gt;no ip sctp authenticate packet-drop&lt;/P&gt;&lt;P&gt;no ip sctp authenticate stream-reset&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 131&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 132&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 133&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 134&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 135&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 136&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 137&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 138&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 139&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 140&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 141&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 142&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 143&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 145&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 146&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 147&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 148&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 149&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 150&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 151&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 152&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 153&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 154&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 155&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 156&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 157&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 158&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 159&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 160&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 161&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 162&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 163&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 164&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 165&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 166&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 167&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 168&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 169&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 170&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 171&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 172&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 173&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 174&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 175&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 176&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 177&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 178&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 179&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 180&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 181&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 182&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 183&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 184&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 185&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 186&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 187&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 188&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 189&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 190&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 191&lt;/P&gt;&lt;P&gt;no ip sctp authenticate fwd-tsn&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 194&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 195&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 196&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 197&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 198&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 199&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 200&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 201&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 202&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 203&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 204&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 205&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 206&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 207&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 208&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 209&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 210&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 211&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 212&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 213&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 214&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 215&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 216&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 217&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 218&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 219&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 220&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 221&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 222&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 223&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 224&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 225&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 226&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 227&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 228&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 229&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 230&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 231&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 232&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 233&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 234&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 235&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 236&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 237&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 238&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 239&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 240&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 241&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 242&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 243&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 244&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 245&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 246&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 247&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 248&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 249&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 250&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 251&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 252&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 253&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 254&lt;/P&gt;&lt;P&gt;no ip sctp authenticate 255&lt;/P&gt;&lt;P&gt;ip flow-cache entries 4096&lt;/P&gt;&lt;P&gt;ip flow-cache timeout inactive 15&lt;/P&gt;&lt;P&gt;ip flow-cache timeout active 30&lt;/P&gt;&lt;P&gt;ip bootp server&lt;/P&gt;&lt;P&gt;ip domain name maladomini.int&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;ip name-server 192.168.1.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;ip name-server 199.195.168.4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;ip name-server 205.171.2.65&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;ip name-server 205.171.3.65&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;ip name-server 8.8.8.8&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ip sap cache-timeout 1440&lt;/P&gt;&lt;P&gt;ip multicast route-limit 2147483647&lt;/P&gt;&lt;P&gt;ip mfib&lt;/P&gt;&lt;P&gt;ip pgm host ttl 255&lt;/P&gt;&lt;P&gt;ip pgm host stream-type apdu&lt;/P&gt;&lt;P&gt;ip pgm host nak-gen-ivl 60000&lt;/P&gt;&lt;P&gt;ip pgm host nak-rb-ivl 500&lt;/P&gt;&lt;P&gt;ip pgm host nak-rpt-ivl 2000&lt;/P&gt;&lt;P&gt;ip pgm host nak-rdata-ivl 2000&lt;/P&gt;&lt;P&gt;ip pgm host rx-buffer-mgmt minimum&lt;/P&gt;&lt;P&gt;ip pgm host tpdu-size 1400&lt;/P&gt;&lt;P&gt;ip pgm host ihb-min 1000&lt;/P&gt;&lt;P&gt;ip pgm host ihb-max 10000&lt;/P&gt;&lt;P&gt;ip pgm host join 0&lt;/P&gt;&lt;P&gt;ip pgm host spm-ambient-ivl 6000&lt;/P&gt;&lt;P&gt;ip pgm host txw-adv-secs 6000&lt;/P&gt;&lt;P&gt;ip pgm host txw-adv-timeout-max 3600000&lt;/P&gt;&lt;P&gt;ip pgm host txw-rte 16384&lt;/P&gt;&lt;P&gt;ip pgm host txw-secs 30000&lt;/P&gt;&lt;P&gt;ip pgm host ncf-max 4294967295&lt;/P&gt;&lt;P&gt;ip pgm host spm-rpt-ivl 3000&lt;/P&gt;&lt;P&gt;ip pgm host tx-buffer-mgmt return&lt;/P&gt;&lt;P&gt;ip pgm host txw-adv-method time&lt;/P&gt;&lt;P&gt;ip pgm router elimination-interval 2&lt;/P&gt;&lt;P&gt;ip ips memory threshold 14&lt;/P&gt;&lt;P&gt;ip dhcp-server query lease retries 2&lt;/P&gt;&lt;P&gt;ip dhcp-server query lease timeout 10&lt;/P&gt;&lt;P&gt; ip dhcp-client broadcast-flag&lt;/P&gt;&lt;P&gt;ip dhcp-client default-router distance 254&lt;/P&gt;&lt;P&gt;ip igmp snooping vlan 1&lt;/P&gt;&lt;P&gt;ip igmp snooping vlan 1 mrouter learn pim-dvmrp&lt;/P&gt;&lt;P&gt;ip igmp snooping&lt;/P&gt;&lt;P&gt;ip igmp ssm-map query dns&lt;/P&gt;&lt;P&gt;kerberos timeout 15&lt;/P&gt;&lt;P&gt;kerberos retry 4&lt;/P&gt;&lt;P&gt;kerberos processes 1&lt;/P&gt;&lt;P&gt;ntp max-associations 100&lt;/P&gt;&lt;P&gt;no vlan accounting input&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;multilink virtual-template 0&lt;/P&gt;&lt;P&gt;multilink bundle-name authenticated&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;cwmp agent&lt;/P&gt;&lt;P&gt; no enable download&lt;/P&gt;&lt;P&gt; no enable&lt;/P&gt;&lt;P&gt; request outstanding 5&lt;/P&gt;&lt;P&gt; parameter change notify interval 60&lt;/P&gt;&lt;P&gt; session retry limit 11&lt;/P&gt;&lt;P&gt; management server username 00000C-SICCO2811V03-FTX1041A07T&lt;/P&gt;&lt;P&gt; no management server password&lt;/P&gt;&lt;P&gt; no management server url&lt;/P&gt;&lt;P&gt; no provision code&lt;/P&gt;&lt;P&gt; no connection request username&lt;/P&gt;&lt;P&gt; no connection request password&lt;/P&gt;&lt;P&gt; no wan ipaddress&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;parameter-map type inspect default&lt;/P&gt;&lt;P&gt; audit-trail off&lt;/P&gt;&lt;P&gt; alert on&lt;/P&gt;&lt;P&gt; sessions maximum 2147483647&lt;/P&gt;&lt;P&gt; max-incomplete low 2147483647&lt;/P&gt;&lt;P&gt; max-incomplete high 2147483647&lt;/P&gt;&lt;P&gt; one-minute low 2147483647&lt;/P&gt;&lt;P&gt; one-minute high 2147483647&lt;/P&gt;&lt;P&gt; udp idle-time 30&lt;/P&gt;&lt;P&gt; icmp idle-time 10&lt;/P&gt;&lt;P&gt; dns-timeout 5&lt;/P&gt;&lt;P&gt; tcp idle-time 3600&lt;/P&gt;&lt;P&gt; tcp finwait-time 5&lt;/P&gt;&lt;P&gt; tcp synwait-time 30&lt;/P&gt;&lt;P&gt; tcp max-incomplete host 4294967295 block-time 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type ooo global&lt;/P&gt;&lt;P&gt; tcp reassembly timeout 5&lt;/P&gt;&lt;P&gt; tcp reassembly queue length 16&lt;/P&gt;&lt;P&gt; tcp reassembly memory limit 1024&lt;/P&gt;&lt;P&gt;isis display delimiter return 1&lt;/P&gt;&lt;P&gt;frame-relay address registration auto-address&lt;/P&gt;&lt;P&gt;mls qos map cos-dscp 0 8 16 26 32 46 48 56&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;password encryption aes&lt;/P&gt;&lt;P&gt;no virtual-template subinterface&lt;/P&gt;&lt;P&gt;no virtual-template snmp&lt;/P&gt;&lt;P&gt;crypto pki token default removal timeout 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto pki trustpoint TP-self-signed-1290569776&lt;/P&gt;&lt;P&gt; enrollment selfsigned&lt;/P&gt;&lt;P&gt; subject-name cn=IOS-Self-Signed-Certificate-1290569776&lt;/P&gt;&lt;P&gt; revocation-check none&lt;/P&gt;&lt;P&gt; rsakeypair TP-self-signed-1290569776&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto pki certificate chain TP-self-signed-1290569776&lt;/P&gt;&lt;P&gt; certificate self-signed 01&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3082022B 30820194 A0030201 02020101 300D0609 2A864886 F70D0101 05050030&lt;/P&gt;&lt;P&gt;&amp;nbsp; 31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274&lt;/P&gt;&lt;P&gt;&amp;nbsp; 69666963 6174652D 31323930 35363937 3736301E 170D3134 30313035 30363130&lt;/P&gt;&lt;P&gt;&amp;nbsp; 33395A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 32393035&lt;/P&gt;&lt;P&gt;&amp;nbsp; 36393737 3630819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281&lt;/P&gt;&lt;P&gt;&amp;nbsp; 8100B18F F63C5121 00785DE0 854601BA EE77DAA3 21286D8C 6E700C37 237CC1BE&lt;/P&gt;&lt;P&gt;&amp;nbsp; 611023AF FBE04BBE 7B4B3233 E4E129DD A74604E5 62AA39BF 77F98D5D D63944E9&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2345AE37 D93C5753 E425E85A&amp;nbsp; CFC5D1A0 F800449B 0419A5C8 A0A101EC&lt;/P&gt;&lt;P&gt;&amp;nbsp; 02928172 7B30A609 71ADA3D4 68F4F484 AF2B3249 0E225DB2 C72C136A E670D761&lt;/P&gt;&lt;P&gt;&amp;nbsp; DDE30203 010001A3 53305130 0F060355 1D130101 FF040530 030101FF 301F0603&lt;/P&gt;&lt;P&gt;&amp;nbsp; 551D2304 18301680 1461F6DE 8EF50F7B 0E46359F 421EA106 9375F65F 30301D06&lt;/P&gt;&lt;P&gt;&amp;nbsp; 03551D0E 04160414 61F6DE8E F50F7B0E 46359F42 1EA10693 75F65F30 300D0609&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2A864886 F70D0101 05050003 81810049 BA55F695 8525265F ED2D77EE 8706BF10&lt;/P&gt;&lt;P&gt;&amp;nbsp; 63A7E644 202F6663 9EA5551F 47F7FC50 D4021EDD E3DC5A80 39FD161A C337D20D&lt;/P&gt;&lt;P&gt;&amp;nbsp; 71B98875 0F1FE887 649E81D3 F93F7A1B A1E18B99 A77B1A59 84DB4711 867913FD&lt;/P&gt;&lt;P&gt;&amp;nbsp; 044084FB 651ECA6E C6EDF35C E43A2946 8C01781E 26DB9484 C8740A82 4A7CA266&lt;/P&gt;&lt;P&gt;&amp;nbsp; A0655526 CBCB4982 F30D68E9 D70753&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; quit&lt;/P&gt;&lt;P&gt;no snap notification exclude service acl&lt;/P&gt;&lt;P&gt;no snap notification exclude service eem&lt;/P&gt;&lt;P&gt;no snap notification exclude service snapt&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;port-channel load-balance src-dst-ip&lt;/P&gt;&lt;P&gt;license udi pid CISCO2811 sn FTX1041A07T&lt;/P&gt;&lt;P&gt;license agent max-sessions 9&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;license agent default authenticate&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;license call-home url &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://tools.cisco.com/SWIFT/Licensing" target="_blank"&gt;https://tools.cisco.com/SWIFT/Licensing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;memory check-interval 60&lt;/P&gt;&lt;P&gt;memory statistics history table 24&lt;/P&gt;&lt;P&gt;memory validate-checksum 60&lt;/P&gt;&lt;P&gt;memory lite&lt;/P&gt;&lt;P&gt;memory reserve console 0&lt;/P&gt;&lt;P&gt;memory chunk siblings threshold 10000&lt;/P&gt;&lt;P&gt;file prompt alert&lt;/P&gt;&lt;P&gt;emm clear 1b5b324a1b5b303b30480d&lt;/P&gt;&lt;P&gt;vtp file flash:vlan.dat&lt;/P&gt;&lt;P&gt;vtp mode server&lt;/P&gt;&lt;P&gt;vtp version 1&lt;/P&gt;&lt;P&gt;username Redacted&lt;/P&gt;&lt;P&gt;username Redacted&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;redundancy&lt;/P&gt;&lt;P&gt; no maintenance-mode&lt;/P&gt;&lt;P&gt;scripting tcl low-memory 33095074&lt;/P&gt;&lt;P&gt;scripting tcl trustpoint untrusted terminate&lt;/P&gt;&lt;P&gt;no scripting tcl secure-mode&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;process-max-time 200&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip finger&lt;/P&gt;&lt;P&gt;no ip tcp ecn&lt;/P&gt;&lt;P&gt;no ip tcp selective-ack&lt;/P&gt;&lt;P&gt;no ip tcp timestamp&lt;/P&gt;&lt;P&gt;ip tcp delayed-ack&lt;/P&gt;&lt;P&gt;ip tcp chunk-size 0&lt;/P&gt;&lt;P&gt;ip tcp mss 0&lt;/P&gt;&lt;P&gt;ip tcp window-size 4128&lt;/P&gt;&lt;P&gt;ip tcp queuemax 20&lt;/P&gt;&lt;P&gt;ip tcp synwait-time 30&lt;/P&gt;&lt;P&gt;no ip tcp path-mtu-discovery&lt;/P&gt;&lt;P&gt;no ip tcp async-mobility server&lt;/P&gt;&lt;P&gt;ip tcp RST-count 10 RST-window 5000&lt;/P&gt;&lt;P&gt;ip telnet tos C0&lt;/P&gt;&lt;P&gt;ip telnet timeout retransmit 0&lt;/P&gt;&lt;P&gt;no ip telnet quiet&lt;/P&gt;&lt;P&gt;no ip telnet hidden hostnames&lt;/P&gt;&lt;P&gt;no ip telnet hidden addresses&lt;/P&gt;&lt;P&gt;ip telnet comport enable&lt;/P&gt;&lt;P&gt;ip telnet comport flow level 16&lt;/P&gt;&lt;P&gt;ip telnet comport receive window 4128&lt;/P&gt;&lt;P&gt;ip telnet comport disconnect delay 0&lt;/P&gt;&lt;P&gt;ip ftp passive&lt;/P&gt;&lt;P&gt;ip tftp min-timeout 3000&lt;/P&gt;&lt;P&gt;no ip tftp claim-netascii&lt;/P&gt;&lt;P&gt;ip ssh time-out 60&lt;/P&gt;&lt;P&gt;ip ssh authentication-retries 5&lt;/P&gt;&lt;P&gt;ip ssh break-string ~break&lt;/P&gt;&lt;P&gt;ip ssh version 2&lt;/P&gt;&lt;P&gt;ip ssh dh min size 1024&lt;/P&gt;&lt;P&gt;ip rcmd domain-lookup&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto engine software ipsec&lt;/P&gt;&lt;P&gt;crypto ctcp keepalive 5&lt;/P&gt;&lt;P&gt;crypto isakmp aggressive-mode disable&lt;/P&gt;&lt;P&gt;crypto ipsec optional retry 300&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 3600&lt;/P&gt;&lt;P&gt;no crypto ipsec security-association replay disable&lt;/P&gt;&lt;P&gt;crypto ipsec security-association replay window-size 64&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto ipsec default transform-set&lt;/P&gt;&lt;P&gt;crypto ipsec nat-transparency udp-encapsulation&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto call admission limit ike sa 0&lt;/P&gt;&lt;P&gt;crypto call admission limit ike in-negotiation-sa 1000&lt;/P&gt;&lt;P&gt;crypto call admission limit ipsec sa 0&lt;/P&gt;&lt;P&gt;crypto mib ipsec flowmib history tunnel size 200&lt;/P&gt;&lt;P&gt;crypto mib ipsec flowmib history failure size 200&lt;/P&gt;&lt;P&gt;buffers element permanent 500&lt;/P&gt;&lt;P&gt;buffers element minimum 100&lt;/P&gt;&lt;P&gt;buffers header permanent 768&lt;/P&gt;&lt;P&gt;buffers header max-free 1024&lt;/P&gt;&lt;P&gt;buffers header min-free 128&lt;/P&gt;&lt;P&gt;buffers header initial 0&lt;/P&gt;&lt;P&gt;buffers fastswitching permanent 768&lt;/P&gt;&lt;P&gt;buffers fastswitching max-free 1024&lt;/P&gt;&lt;P&gt;buffers fastswitching min-free 128&lt;/P&gt;&lt;P&gt;buffers fastswitching initial 0&lt;/P&gt;&lt;P&gt;buffers small permanent 50&lt;/P&gt;&lt;P&gt;buffers small max-free 150&lt;/P&gt;&lt;P&gt;buffers small min-free 20&lt;/P&gt;&lt;P&gt;buffers small initial 0&lt;/P&gt;&lt;P&gt;buffers middle permanent 25&lt;/P&gt;&lt;P&gt;buffers middle max-free 150&lt;/P&gt;&lt;P&gt;buffers middle min-free 10&lt;/P&gt;&lt;P&gt;buffers middle initial 0&lt;/P&gt;&lt;P&gt;buffers big permanent 50&lt;/P&gt;&lt;P&gt;buffers big max-free 150&lt;/P&gt;&lt;P&gt;buffers big min-free 5&lt;/P&gt;&lt;P&gt;buffers big initial 0&lt;/P&gt;&lt;P&gt;buffers verybig permanent 10&lt;/P&gt;&lt;P&gt;buffers verybig max-free 100&lt;/P&gt;&lt;P&gt;buffers verybig min-free 0&lt;/P&gt;&lt;P&gt;buffers verybig initial 0&lt;/P&gt;&lt;P&gt;buffers large permanent 0&lt;/P&gt;&lt;P&gt;buffers large max-free 10&lt;/P&gt;&lt;P&gt;buffers large min-free 0&lt;/P&gt;&lt;P&gt;buffers large initial 0&lt;/P&gt;&lt;P&gt;buffers huge permanent 0&lt;/P&gt;&lt;P&gt;buffers huge max-free 4&lt;/P&gt;&lt;P&gt;buffers huge min-free 0&lt;/P&gt;&lt;P&gt;buffers huge size 18024&lt;/P&gt;&lt;P&gt;buffers huge initial 0&lt;/P&gt;&lt;P&gt;no buffers tune automatic&lt;/P&gt;&lt;P&gt;buffers FastEthernet0/0 permanent 384&lt;/P&gt;&lt;P&gt;buffers FastEthernet0/0 max-free 384&lt;/P&gt;&lt;P&gt;buffers FastEthernet0/0 min-free 0&lt;/P&gt;&lt;P&gt;buffers FastEthernet0/0 initial 0&lt;/P&gt;&lt;P&gt;buffers FastEthernet0/1 permanent 384&lt;/P&gt;&lt;P&gt;buffers FastEthernet0/1 max-free 384&lt;/P&gt;&lt;P&gt;buffers FastEthernet0/1 min-free 0&lt;/P&gt;&lt;P&gt;buffers FastEthernet0/1 initial 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;interface FastEthernet0/0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; description CONNECTION TO INSIDE INT. OF ASA&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; mtu 1500&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; ip address 10.10.1.2 255.255.255.252&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; ip redirects&lt;/P&gt;&lt;P&gt; ip proxy-arp&lt;/P&gt;&lt;P&gt; ip load-sharing per-destination&lt;/P&gt;&lt;P&gt; ip cef accounting non-recursive internal&lt;/P&gt;&lt;P&gt; ip pim dr-priority 1&lt;/P&gt;&lt;P&gt; ip pim query-interval 30&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip mfib forwarding input&lt;/P&gt;&lt;P&gt; ip mfib forwarding output&lt;/P&gt;&lt;P&gt; ip mfib cef input&lt;/P&gt;&lt;P&gt; ip mfib cef output&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; ip route-cache cef&lt;/P&gt;&lt;P&gt; ip split-horizon&lt;/P&gt;&lt;P&gt; ip igmp last-member-query-interval 1000&lt;/P&gt;&lt;P&gt; ip igmp last-member-query-count 2&lt;/P&gt;&lt;P&gt; ip igmp query-max-response-time 10&lt;/P&gt;&lt;P&gt; ip igmp version 2&lt;/P&gt;&lt;P&gt; ip igmp query-interval 60&lt;/P&gt;&lt;P&gt; ip igmp tcn query count 2&lt;/P&gt;&lt;P&gt; ip igmp tcn query interval 10&lt;/P&gt;&lt;P&gt; load-interval 300&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; dot1q tunneling ethertype 0x8100&lt;/P&gt;&lt;P&gt; snmp trap link-status&lt;/P&gt;&lt;P&gt; max-reserved-bandwidth 75&lt;/P&gt;&lt;P&gt; hold-queue 75 in&lt;/P&gt;&lt;P&gt; hold-queue 0 out&lt;/P&gt;&lt;P&gt; no bgp-policy accounting input&lt;/P&gt;&lt;P&gt; no bgp-policy accounting output&lt;/P&gt;&lt;P&gt; no bgp-policy accounting input source&lt;/P&gt;&lt;P&gt; no bgp-policy accounting output source&lt;/P&gt;&lt;P&gt; no bgp-policy source ip-prec-map&lt;/P&gt;&lt;P&gt; no bgp-policy source ip-qos-map&lt;/P&gt;&lt;P&gt; no bgp-policy destination ip-prec-map&lt;/P&gt;&lt;P&gt; no bgp-policy destination ip-qos-map&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;interface FastEthernet0/1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; mtu 1500&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; no ip address&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; ip redirects&lt;/P&gt;&lt;P&gt; ip proxy-arp&lt;/P&gt;&lt;P&gt; ip load-sharing per-destination&lt;/P&gt;&lt;P&gt; ip cef accounting non-recursive internal&lt;/P&gt;&lt;P&gt; ip pim dr-priority 1&lt;/P&gt;&lt;P&gt; ip pim query-interval 30&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip mfib forwarding input&lt;/P&gt;&lt;P&gt; ip mfib forwarding output&lt;/P&gt;&lt;P&gt; ip mfib cef input&lt;/P&gt;&lt;P&gt; ip mfib cef output&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; ip route-cache cef&lt;/P&gt;&lt;P&gt; ip split-horizon&lt;/P&gt;&lt;P&gt; ip igmp last-member-query-interval 1000&lt;/P&gt;&lt;P&gt; ip igmp last-member-query-count 2&lt;/P&gt;&lt;P&gt; ip igmp query-max-response-time 10&lt;/P&gt;&lt;P&gt; ip igmp version 2&lt;/P&gt;&lt;P&gt; ip igmp query-interval 60&lt;/P&gt;&lt;P&gt; ip igmp tcn query count 2&lt;/P&gt;&lt;P&gt; ip igmp tcn query interval 10&lt;/P&gt;&lt;P&gt; load-interval 300&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; dot1q tunneling ethertype 0x8100&lt;/P&gt;&lt;P&gt; snmp trap link-status&lt;/P&gt;&lt;P&gt; max-reserved-bandwidth 75&lt;/P&gt;&lt;P&gt; hold-queue 75 in&lt;/P&gt;&lt;P&gt; hold-queue 0 out&lt;/P&gt;&lt;P&gt; no bgp-policy accounting input&lt;/P&gt;&lt;P&gt; no bgp-policy accounting output&lt;/P&gt;&lt;P&gt; no bgp-policy accounting input source&lt;/P&gt;&lt;P&gt; no bgp-policy accounting output source&lt;/P&gt;&lt;P&gt; no bgp-policy source ip-prec-map&lt;/P&gt;&lt;P&gt; no bgp-policy source ip-qos-map&lt;/P&gt;&lt;P&gt; no bgp-policy destination ip-prec-map&lt;/P&gt;&lt;P&gt; no bgp-policy destination ip-qos-map&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;interface FastEthernet0/1.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; description VLAN 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; encapsulation dot1Q 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; ip address 172.16.10.1 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; ip redirects&lt;/P&gt;&lt;P&gt; ip proxy-arp&lt;/P&gt;&lt;P&gt; ip load-sharing per-destination&lt;/P&gt;&lt;P&gt; ip cef accounting non-recursive internal&lt;/P&gt;&lt;P&gt; ip pim dr-priority 1&lt;/P&gt;&lt;P&gt; ip pim query-interval 30&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip mfib forwarding input&lt;/P&gt;&lt;P&gt; ip mfib forwarding output&lt;/P&gt;&lt;P&gt; ip mfib cef input&lt;/P&gt;&lt;P&gt; ip mfib cef output&lt;/P&gt;&lt;P&gt; ip rip initial-delay 0&lt;/P&gt;&lt;P&gt; ip rip advertise 30&lt;/P&gt;&lt;P&gt; ip rip authentication mode text&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; ip split-horizon&lt;/P&gt;&lt;P&gt; ip igmp last-member-query-interval 1000&lt;/P&gt;&lt;P&gt; ip igmp last-member-query-count 2&lt;/P&gt;&lt;P&gt; ip igmp query-max-response-time 10&lt;/P&gt;&lt;P&gt; ip igmp version 2&lt;/P&gt;&lt;P&gt; ip igmp query-interval 60&lt;/P&gt;&lt;P&gt; ip igmp tcn query count 2&lt;/P&gt;&lt;P&gt; ip igmp tcn query interval 10&lt;/P&gt;&lt;P&gt; no snmp trap link-status&lt;/P&gt;&lt;P&gt; no bgp-policy accounting input&lt;/P&gt;&lt;P&gt; no bgp-policy accounting output&lt;/P&gt;&lt;P&gt; no bgp-policy accounting input source&lt;/P&gt;&lt;P&gt; no bgp-policy accounting output source&lt;/P&gt;&lt;P&gt; no bgp-policy source ip-prec-map&lt;/P&gt;&lt;P&gt; no bgp-policy source ip-qos-map&lt;/P&gt;&lt;P&gt; no bgp-policy destination ip-prec-map&lt;/P&gt;&lt;P&gt; no bgp-policy destination ip-qos-map&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;interface FastEthernet0/1.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; description VLAN 20&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; encapsulation dot1Q 20&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; ip address 172.16.20.1 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; ip redirects&lt;/P&gt;&lt;P&gt; ip proxy-arp&lt;/P&gt;&lt;P&gt; ip load-sharing per-destination&lt;/P&gt;&lt;P&gt; ip cef accounting non-recursive internal&lt;/P&gt;&lt;P&gt; ip pim dr-priority 1&lt;/P&gt;&lt;P&gt; ip pim query-interval 30&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip mfib forwarding input&lt;/P&gt;&lt;P&gt; ip mfib forwarding output&lt;/P&gt;&lt;P&gt; ip mfib cef input&lt;/P&gt;&lt;P&gt; ip mfib cef output&lt;/P&gt;&lt;P&gt; ip rip initial-delay 0&lt;/P&gt;&lt;P&gt; ip rip advertise 30&lt;/P&gt;&lt;P&gt; ip rip authentication mode text&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; ip split-horizon&lt;/P&gt;&lt;P&gt; ip igmp last-member-query-interval 1000&lt;/P&gt;&lt;P&gt; ip igmp last-member-query-count 2&lt;/P&gt;&lt;P&gt; ip igmp query-max-response-time 10&lt;/P&gt;&lt;P&gt; ip igmp version 2&lt;/P&gt;&lt;P&gt; ip igmp query-interval 60&lt;/P&gt;&lt;P&gt; ip igmp tcn query count 2&lt;/P&gt;&lt;P&gt; ip igmp tcn query interval 10&lt;/P&gt;&lt;P&gt; no snmp trap link-status&lt;/P&gt;&lt;P&gt; no bgp-policy accounting input&lt;/P&gt;&lt;P&gt; no bgp-policy accounting output&lt;/P&gt;&lt;P&gt; no bgp-policy accounting input source&lt;/P&gt;&lt;P&gt; no bgp-policy accounting output source&lt;/P&gt;&lt;P&gt; no bgp-policy source ip-prec-map&lt;/P&gt;&lt;P&gt; no bgp-policy source ip-qos-map&lt;/P&gt;&lt;P&gt; no bgp-policy destination ip-prec-map&lt;/P&gt;&lt;P&gt; no bgp-policy destination ip-qos-map&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt;interface FastEthernet0/1.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; description Trunk Interface VLAN 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; encapsulation dot1Q 1 native&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff9900;"&gt; ip address 192.168.1.1 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; ip redirects&lt;/P&gt;&lt;P&gt; ip proxy-arp&lt;/P&gt;&lt;P&gt; ip load-sharing per-destination&lt;/P&gt;&lt;P&gt; ip cef accounting non-recursive internal&lt;/P&gt;&lt;P&gt; ip pim dr-priority 1&lt;/P&gt;&lt;P&gt; ip pim query-interval 30&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip mfib forwarding input&lt;/P&gt;&lt;P&gt; ip mfib forwarding output&lt;/P&gt;&lt;P&gt; ip mfib cef input&lt;/P&gt;&lt;P&gt; ip mfib cef output&lt;/P&gt;&lt;P&gt; ip rip initial-delay 0&lt;/P&gt;&lt;P&gt; ip rip advertise 30&lt;/P&gt;&lt;P&gt; ip rip authentication mode text&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; ip split-horizon&lt;/P&gt;&lt;P&gt; ip igmp last-member-query-interval 1000&lt;/P&gt;&lt;P&gt; ip igmp last-member-query-count 2&lt;/P&gt;&lt;P&gt; ip igmp query-max-response-time 10&lt;/P&gt;&lt;P&gt; ip igmp version 2&lt;/P&gt;&lt;P&gt; ip igmp query-interval 60&lt;/P&gt;&lt;P&gt; ip igmp tcn query count 2&lt;/P&gt;&lt;P&gt; ip igmp tcn query interval 10&lt;/P&gt;&lt;P&gt; no snmp trap link-status&lt;/P&gt;&lt;P&gt; no bgp-policy accounting input&lt;/P&gt;&lt;P&gt; no bgp-policy accounting output&lt;/P&gt;&lt;P&gt; no bgp-policy accounting input source&lt;/P&gt;&lt;P&gt; no bgp-policy accounting output source&lt;/P&gt;&lt;P&gt; no bgp-policy source ip-prec-map&lt;/P&gt;&lt;P&gt; no bgp-policy source ip-qos-map&lt;/P&gt;&lt;P&gt; no bgp-policy destination ip-prec-map&lt;/P&gt;&lt;P&gt; no bgp-policy destination ip-qos-map&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dialer0&lt;/P&gt;&lt;P&gt; mtu 1500&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; ip redirects&lt;/P&gt;&lt;P&gt; ip proxy-arp&lt;/P&gt;&lt;P&gt; ip load-sharing per-destination&lt;/P&gt;&lt;P&gt; ip cef accounting non-recursive internal&lt;/P&gt;&lt;P&gt; ip pim dr-priority 1&lt;/P&gt;&lt;P&gt; ip pim query-interval 30&lt;/P&gt;&lt;P&gt; ip mfib forwarding input&lt;/P&gt;&lt;P&gt; ip mfib forwarding output&lt;/P&gt;&lt;P&gt; ip mfib cef input&lt;/P&gt;&lt;P&gt; ip mfib cef output&lt;/P&gt;&lt;P&gt; ip route-cache cef&lt;/P&gt;&lt;P&gt; ip split-horizon&lt;/P&gt;&lt;P&gt; ip igmp last-member-query-interval 1000&lt;/P&gt;&lt;P&gt; ip igmp last-member-query-count 2&lt;/P&gt;&lt;P&gt; ip igmp query-max-response-time 10&lt;/P&gt;&lt;P&gt; ip igmp version 2&lt;/P&gt;&lt;P&gt; ip igmp query-interval 60&lt;/P&gt;&lt;P&gt; ip igmp tcn query count 2&lt;/P&gt;&lt;P&gt; ip igmp tcn query interval 10&lt;/P&gt;&lt;P&gt; load-interval 300&lt;/P&gt;&lt;P&gt; dot1q tunneling ethertype 0x8100&lt;/P&gt;&lt;P&gt; snmp trap link-status&lt;/P&gt;&lt;P&gt; max-reserved-bandwidth 75&lt;/P&gt;&lt;P&gt; hold-queue 75 in&lt;/P&gt;&lt;P&gt; hold-queue 0 out&lt;/P&gt;&lt;P&gt; no bgp-policy accounting input&lt;/P&gt;&lt;P&gt; no bgp-policy accounting output&lt;/P&gt;&lt;P&gt; no bgp-policy accounting input source&lt;/P&gt;&lt;P&gt; no bgp-policy accounting output source&lt;/P&gt;&lt;P&gt; no bgp-policy source ip-prec-map&lt;/P&gt;&lt;P&gt; no bgp-policy source ip-qos-map&lt;/P&gt;&lt;P&gt; no bgp-policy destination ip-prec-map&lt;/P&gt;&lt;P&gt; no bgp-policy destination ip-qos-map&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt;router rip&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; version 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; validate-update-source&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; timers basic 30 180 180 240&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; network 172.16.0.0 mask 255.255.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; network 192.168.1.0 mask 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; network 199.195.168.0 mask 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; maximum-paths 4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; input-queue 150&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; distance 120&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt; no auto-summary&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff6600;"&gt;ip default-gateway 10.10.1.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip forward-protocol nd&lt;/P&gt;&lt;P&gt;no ip http server&lt;/P&gt;&lt;P&gt;ip http port 80&lt;/P&gt;&lt;P&gt;ip http authentication local&lt;/P&gt;&lt;P&gt;ip http secure-server&lt;/P&gt;&lt;P&gt;ip http secure-port 443&lt;/P&gt;&lt;P&gt;ip http secure-active-session-modules all&lt;/P&gt;&lt;P&gt;ip http max-connections 5&lt;/P&gt;&lt;P&gt;ip http timeout-policy idle 180 life 180 requests 1&lt;/P&gt;&lt;P&gt;ip http active-session-modules all&lt;/P&gt;&lt;P&gt;ip http digest algorithm md5&lt;/P&gt;&lt;P&gt;ip http client cache memory pool 100&lt;/P&gt;&lt;P&gt;ip http client cache memory file 2&lt;/P&gt;&lt;P&gt;ip http client cache ager interval 5&lt;/P&gt;&lt;P&gt;ip http client connection timeout 10&lt;/P&gt;&lt;P&gt;ip http client connection retry 1&lt;/P&gt;&lt;P&gt;ip http client connection pipeline-length 5&lt;/P&gt;&lt;P&gt;ip http client connection idle timeout 30&lt;/P&gt;&lt;P&gt;ip http client response timeout 30&lt;/P&gt;&lt;P&gt;ip http path&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dns server&lt;/P&gt;&lt;P&gt;ip pim dm-fallback&lt;/P&gt;&lt;P&gt;ip pim autorp&lt;/P&gt;&lt;P&gt;ip pim bidir-offer-interval 100 msec&lt;/P&gt;&lt;P&gt;ip pim bidir-offer-limit 3&lt;/P&gt;&lt;P&gt;ip pim v1-rp-reachability&lt;/P&gt;&lt;P&gt;ip pim log-neighbor-changes&lt;/P&gt;&lt;P&gt;ip msdp timer 30&lt;/P&gt;&lt;P&gt;ip rtcp report interval 5000&lt;/P&gt;&lt;P&gt;ip rtcp sub-rtcp message-type 209&lt;/P&gt;&lt;P&gt;ip nat inside source list 1 interface FastEthernet0/0 overload&lt;/P&gt;&lt;P&gt;ip route static adjust-time 60&lt;/P&gt;&lt;P&gt;ip route static inter-vrf&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.10.1.1&lt;/P&gt;&lt;P&gt;ip ospf name-lookup&lt;/P&gt;&lt;P&gt;ip rsvp policy cops timeout 300&lt;/P&gt;&lt;P&gt;ip rsvp authentication type md5&lt;/P&gt;&lt;P&gt;ip rsvp pq-profile 12288 592 110&lt;/P&gt;&lt;P&gt;ip rsvp signalling initial-retransmit-delay 1000&lt;/P&gt;&lt;P&gt;ip rsvp signalling refresh reduction ack-delay 250&lt;/P&gt;&lt;P&gt;ip rsvp signalling refresh interval 30000&lt;/P&gt;&lt;P&gt;ip rsvp signalling refresh misses 4&lt;/P&gt;&lt;P&gt;no ip identd&lt;/P&gt;&lt;P&gt;no ip access-list helper egress check&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt; ip prefix-list sequence-number&lt;/P&gt;&lt;P&gt;ip sla responder twamp&lt;/P&gt;&lt;P&gt; timeout 900&lt;/P&gt;&lt;P&gt;ip sla low-memory 28001275&lt;/P&gt;&lt;P&gt;ip sla server twamp&lt;/P&gt;&lt;P&gt; port 862&lt;/P&gt;&lt;P&gt; timer inactivity 900&lt;/P&gt;&lt;P&gt;logging policy-firewall rate-limit 30&lt;/P&gt;&lt;P&gt;logging history size 1&lt;/P&gt;&lt;P&gt;logging history warnings&lt;/P&gt;&lt;P&gt;logging trap informational&lt;/P&gt;&lt;P&gt;logging delimiter tcp&lt;/P&gt;&lt;P&gt;no logging origin-id&lt;/P&gt;&lt;P&gt;logging facility local7&lt;/P&gt;&lt;P&gt;no logging source-interface&lt;/P&gt;&lt;P&gt;access-list 1 permit any&lt;/P&gt;&lt;P&gt;dialer-list 1 protocol ip permit&lt;/P&gt;&lt;P&gt;ethernet cfm mep crosscheck start-delay 30&lt;/P&gt;&lt;P&gt;mac-address-table aging-time 300&lt;/P&gt;&lt;P&gt;cdp run&lt;/P&gt;&lt;P&gt;terminal-queue entry-retry-interval 60&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;snmp-server inform retries 3 timeout 15 pending 25&lt;/P&gt;&lt;P&gt;snmp mib event sample minimum 60&lt;/P&gt;&lt;P&gt;snmp mib event sample instance maximum 0&lt;/P&gt;&lt;P&gt;snmp mib expression delta minimum 1&lt;/P&gt;&lt;P&gt;snmp mib expression delta wildcard maximum 0&lt;/P&gt;&lt;P&gt; snmp mib nhrp&lt;/P&gt;&lt;P&gt;snmp mib notification-log globalsize 500&lt;/P&gt;&lt;P&gt;snmp mib notification-log globalageout 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tftp-server system:running-config 1&lt;/P&gt;&lt;P&gt;tacacs-server cache expiry 24 enforce hours&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;radius-server attribute 77 include-in-acct-req&lt;/P&gt;&lt;P&gt;radius-server attribute 77 include-in-access-req&lt;/P&gt;&lt;P&gt;radius-server attribute 11 default direction out&lt;/P&gt;&lt;P&gt;radius-server attribute nas-port format a&lt;/P&gt;&lt;P&gt;radius-server attribute 31 mac format default&lt;/P&gt;&lt;P&gt;radius-server cache expiry 24 enforce hours&lt;/P&gt;&lt;P&gt;radius-server transaction max-tries 8&lt;/P&gt;&lt;P&gt;radius-server retransmit 3&lt;/P&gt;&lt;P&gt;radius-server timeout 5&lt;/P&gt;&lt;P&gt;radius-server ipc-limit in 10&lt;/P&gt;&lt;P&gt;radius-server ipc-limit done 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;control-plane&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;vstack join-window mode auto&lt;/P&gt;&lt;P&gt;alias exec h help&lt;/P&gt;&lt;P&gt;alias exec lo logout&lt;/P&gt;&lt;P&gt;alias exec p ping&lt;/P&gt;&lt;P&gt;alias exec r resume&lt;/P&gt;&lt;P&gt;alias exec s show&lt;/P&gt;&lt;P&gt;alias exec u undebug&lt;/P&gt;&lt;P&gt;alias exec un undebug&lt;/P&gt;&lt;P&gt;alias exec w where&lt;/P&gt;&lt;P&gt;no configuration mode exclusive&lt;/P&gt;&lt;P&gt;default-value exec-character-bits 7&lt;/P&gt;&lt;P&gt;default-value special-character-bits 7&lt;/P&gt;&lt;P&gt;default-value data-character-bits 8&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; exec-timeout 0 0&lt;/P&gt;&lt;P&gt; timeout login response 30&lt;/P&gt;&lt;P&gt; privilege level 1&lt;/P&gt;&lt;P&gt; password Redacted&lt;/P&gt;&lt;P&gt; flush-at-activation&lt;/P&gt;&lt;P&gt; logout-warning 20&lt;/P&gt;&lt;P&gt; absolute-timeout 0&lt;/P&gt;&lt;P&gt; modem answer-timeout 15&lt;/P&gt;&lt;P&gt; modem dtr-delay 5&lt;/P&gt;&lt;P&gt; data-character-bits 8&lt;/P&gt;&lt;P&gt; exec-character-bits 7&lt;/P&gt;&lt;P&gt; special-character-bits 7&lt;/P&gt;&lt;P&gt; length 24&lt;/P&gt;&lt;P&gt; width 80&lt;/P&gt;&lt;P&gt; history size 20&lt;/P&gt;&lt;P&gt; databits 8&lt;/P&gt;&lt;P&gt; stopbits 2&lt;/P&gt;&lt;P&gt; start-character 17&lt;/P&gt;&lt;P&gt; stop-character 19&lt;/P&gt;&lt;P&gt; speed 9600&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt; exec-timeout 10 0&lt;/P&gt;&lt;P&gt; timeout login response 30&lt;/P&gt;&lt;P&gt; privilege level 1&lt;/P&gt;&lt;P&gt; flush-at-activation&lt;/P&gt;&lt;P&gt; logout-warning 20&lt;/P&gt;&lt;P&gt; absolute-timeout 0&lt;/P&gt;&lt;P&gt; modem answer-timeout 15&lt;/P&gt;&lt;P&gt; modem dtr-delay 5&lt;/P&gt;&lt;P&gt; data-character-bits 8&lt;/P&gt;&lt;P&gt; exec-character-bits 7&lt;/P&gt;&lt;P&gt; special-character-bits 7&lt;/P&gt;&lt;P&gt; length 24&lt;/P&gt;&lt;P&gt; width 80&lt;/P&gt;&lt;P&gt; history size 20&lt;/P&gt;&lt;P&gt; callback forced-wait 4&lt;/P&gt;&lt;P&gt; callback nodsr-wait 5000&lt;/P&gt;&lt;P&gt; databits 8&lt;/P&gt;&lt;P&gt; stopbits 2&lt;/P&gt;&lt;P&gt; start-character 17&lt;/P&gt;&lt;P&gt; stop-character 19&lt;/P&gt;&lt;P&gt; speed 9600&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; access-class 20 in&lt;/P&gt;&lt;P&gt; exec-timeout 0 0&lt;/P&gt;&lt;P&gt; timeout login response 30&lt;/P&gt;&lt;P&gt; privilege level 1&lt;/P&gt;&lt;P&gt; password Redacted&lt;/P&gt;&lt;P&gt; flush-at-activation&lt;/P&gt;&lt;P&gt; logout-warning 20&lt;/P&gt;&lt;P&gt; absolute-timeout 0&lt;/P&gt;&lt;P&gt; modem answer-timeout 15&lt;/P&gt;&lt;P&gt; modem dtr-delay 5&lt;/P&gt;&lt;P&gt; data-character-bits 8&lt;/P&gt;&lt;P&gt; exec-character-bits 7&lt;/P&gt;&lt;P&gt; special-character-bits 7&lt;/P&gt;&lt;P&gt; length 24&lt;/P&gt;&lt;P&gt; width 80&lt;/P&gt;&lt;P&gt; history size 20&lt;/P&gt;&lt;P&gt; transport input ssh&lt;/P&gt;&lt;P&gt; start-character 17&lt;/P&gt;&lt;P&gt; stop-character 19&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;exception-slave core-file CISCO-2811-core&lt;/P&gt;&lt;P&gt;exception-slave protocol tftp&lt;/P&gt;&lt;P&gt;exception protocol tftp&lt;/P&gt;&lt;P&gt;exception region-size 131072&lt;/P&gt;&lt;P&gt;exception crashinfo file flash:crashinfo&lt;/P&gt;&lt;P&gt;exception crashinfo buffersize 32&lt;/P&gt;&lt;P&gt;exception crashinfo maximum files 1&lt;/P&gt;&lt;P&gt;no exception crashinfo dump garbage-detector&lt;/P&gt;&lt;P&gt;monitor event-trace stacktrace&lt;/P&gt;&lt;P&gt;monitor event-trace timestamps datetime msec&lt;/P&gt;&lt;P&gt;scheduler max-task-time 2000&lt;/P&gt;&lt;P&gt;scheduler process-watchdog normal&lt;/P&gt;&lt;P&gt;scheduler allocate 20000 1000&lt;/P&gt;&lt;P&gt;ntp maxdistance 8&lt;/P&gt;&lt;P&gt;ntp broadcastdelay 0&lt;/P&gt;&lt;P&gt;cns id hostname&lt;/P&gt;&lt;P&gt;cns id hostname event&lt;/P&gt;&lt;P&gt;cns id hostname image&lt;/P&gt;&lt;P&gt;cns image retry 60&lt;/P&gt;&lt;P&gt;netconf max-sessions 4&lt;/P&gt;&lt;P&gt;netconf lock-time 10&lt;/P&gt;&lt;P&gt;netconf max-message 0&lt;/P&gt;&lt;P&gt;wsma id hostname&lt;/P&gt;&lt;P&gt;event manager scheduler script thread class default number 1&lt;/P&gt;&lt;P&gt;event manager scheduler applet thread class default number 32&lt;/P&gt;&lt;P&gt;event manager scheduler call-home thread class default number 32&lt;/P&gt;&lt;P&gt;event manager scheduler shell thread class default number 1&lt;/P&gt;&lt;P&gt;event manager scheduler shell thread class Z number 1&lt;/P&gt;&lt;P&gt;event manager history size events 10&lt;/P&gt;&lt;P&gt;event manager history size traps 10&lt;/P&gt;&lt;P&gt;event manager detector rpc max-sessions 4&lt;/P&gt;&lt;P&gt;event manager detector routing bootup-delay 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;webvpn sslvpn-vif nat outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;webvpn sslvpn-vif nat inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;webvpn sslvpn-vif nat enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no webvpn cef&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:45:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461208#M269630</guid>
      <dc:creator>metuckness</dc:creator>
      <dc:date>2019-03-12T03:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461209#M269631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you rather edit the above post and copy/paste the output of &lt;STRONG&gt;"show run"&lt;/STRONG&gt; instead of &lt;STRONG&gt;"show run all"&lt;/STRONG&gt; as they show way to many configurations that dont play a role in this situation and make the actual setup extremely hard to read.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I remember answering some previous thread and it seems to me that the same situation that I suggested avoiding still is present in the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That situation is the fact that you are running Dynamic Routing protocols on a small network where you could handle everything needed with default routes on towards the ASA interface from the router (I presume that each where directly connected to ASA and there is no connections directly from Router to Router) and on the ASA have routes for all the local networks pointing towards their appropriate ASA interface and next hop IP address located on the Router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You also are doing NAT on the internal router that does not make sense as there is no real need to perform NAT anywhere else than on the device that is on the edge of the network. Also when you are doing Dynamic PAT for the network 192.168.1.0/24 towards the ASA breaks any connectivity the external hosts on the Internet can have to these hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So again, please remove the Dynamic Routing and configure Static Routing instead and remove any NAT configurations on the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could take a look at the configurations if you could post the outputs of &lt;STRONG&gt;"show run"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Feb 2014 20:12:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461209#M269631</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-02-14T20:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461210#M269633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The logs messages you post show the problem with the Router NAT configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A connections comes from the external network and is untranslated to point to the 192.168.1.5 port TCP/80. Connection goes to the internal server but the return message through the Router gets PATed to the interface IP address of the Router that is facing the ASA. ASA doesnt not recognize this as a part of an existing connection as its expecting the reply from the 192.168.1.5 IP address and not 10.10.1.2. It then drops that packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Feb 2014 20:16:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461210#M269633</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-02-14T20:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461211#M269635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, here is the show run. You have mentioned those suggestions, but I can't seem to get the proper statements setupo. When I try and modify them to what I think they should be, i lose all connectivity. i am just learning this so when you make statements like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"So again, please remove the Dynamic Routing and configure Static Routing&amp;nbsp; instead and remove any NAT configurations on the router."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know it's simple and I would probably agree if I knew how and where to make those statements, but alas, I can't seem to make the correct ones &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;. That's why I have been making and reading different things for the last few weeks trying NOT to come back and ask for specifics, but I can't seem to get them myself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also had replies to leave the PAT statements so that even confuses me more. I am very sorry, I hate to ask. I like to learn this on my own but sometimes I just get stuck and seeing the statements that should be there help me understand what I was missing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# show run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 9.1(4)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ASA5510&lt;/P&gt;&lt;P&gt;domain-name maladomini.int&lt;/P&gt;&lt;P&gt;enable password Redacted&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any4 any4&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any4 any6&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any6 any4&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any6 any6&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any4 any4 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any4 any6 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any6 any4 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any6 any6 eq domain&lt;/P&gt;&lt;P&gt;passwd redacted encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; description LAN Interface&lt;/P&gt;&lt;P&gt; nameif Inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.1.1 255.255.255.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; description WAN Interface&lt;/P&gt;&lt;P&gt; nameif Outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 199.195.168.x 255.255.255.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; description DMZ&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.0.1 255.255.255.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; description VOIP&lt;/P&gt;&lt;P&gt; nameif VOIP&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.2.1 255.255.255.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa914-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns domain-lookup Outside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 199.195.168.4&lt;/P&gt;&lt;P&gt; name-server 205.171.2.65&lt;/P&gt;&lt;P&gt; name-server 205.171.3.65&lt;/P&gt;&lt;P&gt; domain-name maladomini.int&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;object network ROUTER-2811&lt;/P&gt;&lt;P&gt; host 10.10.1.2&lt;/P&gt;&lt;P&gt;object network ROUTER-2821&lt;/P&gt;&lt;P&gt; host 10.10.0.2&lt;/P&gt;&lt;P&gt;object network WEBCAM-01&lt;/P&gt;&lt;P&gt; host 192.168.1.5&lt;/P&gt;&lt;P&gt;object network DNS-SERVER&lt;/P&gt;&lt;P&gt; host 192.168.1.2&lt;/P&gt;&lt;P&gt;object network ROUTER-3745&lt;/P&gt;&lt;P&gt; host 10.10.2.2&lt;/P&gt;&lt;P&gt;object network RDP-DC1&lt;/P&gt;&lt;P&gt; host 192.168.1.2&lt;/P&gt;&lt;P&gt;object-group network PAT-SOURCE&lt;/P&gt;&lt;P&gt; network-object 10.10.1.0 255.255.255.252&lt;/P&gt;&lt;P&gt; network-object 10.10.0.0 255.255.255.252&lt;/P&gt;&lt;P&gt; network-object 10.10.2.0 255.255.255.252&lt;/P&gt;&lt;P&gt; network-object 192.168.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 172.16.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 172.16.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 128.162.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 128.162.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt; network-object 128.162.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_2&lt;/P&gt;&lt;P&gt; network-object host 98.22.121.x&lt;/P&gt;&lt;P&gt;object-group network Outside_access_in&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_1&lt;/P&gt;&lt;P&gt; protocol-object gre&lt;/P&gt;&lt;P&gt;access-list USERS standard permit 10.10.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.121.x object ROUTER-2811 eq ssh&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.121.x object ROUTER-2821 eq ssh&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.121.x interface Outside eq https&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.121.x object WEBCAM-01 eq www&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp host 98.22.121.x object RDP-DC1 eq 3389&lt;/P&gt;&lt;P&gt;access-list dmz-access-vlan1 extended permit ip 128.162.1.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list dmz-access remark Permit all traffic to DC1&lt;/P&gt;&lt;P&gt;access-list dmz-access extended permit ip 128.162.1.0 255.255.255.0 host 192.168.1.2&lt;/P&gt;&lt;P&gt;access-list dmz-access remark Permit only DNS traffic to DNS server&lt;/P&gt;&lt;P&gt;access-list dmz-access extended permit udp 128.162.1.0 255.255.255.0 host 192.168.1.2 eq domain&lt;/P&gt;&lt;P&gt;access-list dmz-access remark Permit ICMP to all devices in DC&lt;/P&gt;&lt;P&gt;access-list dmz-access extended permit icmp 128.162.1.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu Inside 1500&lt;/P&gt;&lt;P&gt;mtu Outside 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu VOIP 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp deny any Outside&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-715.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;no arp permit-nonconnected&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network ROUTER-2811&lt;/P&gt;&lt;P&gt; nat (Inside,Outside) static interface service tcp ssh 222&lt;/P&gt;&lt;P&gt;object network ROUTER-2821&lt;/P&gt;&lt;P&gt; nat (DMZ,Outside) static interface service tcp ssh 2222&lt;/P&gt;&lt;P&gt;object network WEBCAM-01&lt;/P&gt;&lt;P&gt; nat (Inside,Outside) static interface service tcp www 8080&lt;/P&gt;&lt;P&gt;object network ROUTER-3745&lt;/P&gt;&lt;P&gt; nat (VOIP,Outside) static interface service tcp ssh 2223&lt;/P&gt;&lt;P&gt;object network RDP-DC1&lt;/P&gt;&lt;P&gt; nat (Inside,Outside) static interface service tcp 3389 3389&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (any,Outside) after-auto source dynamic PAT-SOURCE interface&lt;/P&gt;&lt;P&gt;access-group Outside_access_in in interface Outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;router rip&lt;/P&gt;&lt;P&gt; network 10.0.0.0&lt;/P&gt;&lt;P&gt; version 2&lt;/P&gt;&lt;P&gt; no auto-summary&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route Outside 0.0.0.0 0.0.0.0 199.195.168.113 1&lt;/P&gt;&lt;P&gt;route Inside 128.162.1.0 255.255.255.0 10.10.0.2 1&lt;/P&gt;&lt;P&gt;route Inside 128.162.10.0 255.255.255.0 10.10.0.2 1&lt;/P&gt;&lt;P&gt;route Inside 128.162.20.0 255.255.255.0 10.10.0.2 1&lt;/P&gt;&lt;P&gt;route Inside 172.16.10.0 255.255.255.0 10.10.1.2 1&lt;/P&gt;&lt;P&gt;route Inside 172.16.20.0 255.255.255.0 10.10.1.2 1&lt;/P&gt;&lt;P&gt;route Inside 192.168.1.0 255.255.255.0 10.10.1.2 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 Inside&lt;/P&gt;&lt;P&gt;http 98.22.121.x 255.255.255.255 Outside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec security-association pmtu-aging infinite&lt;/P&gt;&lt;P&gt;crypto ca trustpool policy&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 Inside&lt;/P&gt;&lt;P&gt;ssh 98.22.121.x 255.255.255.255 Outside&lt;/P&gt;&lt;P&gt;ssh timeout 60&lt;/P&gt;&lt;P&gt;ssh version 2&lt;/P&gt;&lt;P&gt;ssh key-exchange group dh-group1-sha1&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;ntp server 24.56.178.140 source Outside prefer&lt;/P&gt;&lt;P&gt;username redacted encrypted privilege 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp error&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect pptp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;call-home&lt;/P&gt;&lt;P&gt; profile CiscoTAC-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no active&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address http &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://tools.cisco.com/its/service/oddce/services/DDCEService"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address email &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:callhome@cisco.com"&gt;callhome@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination transport-method http&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;/P&gt;&lt;P&gt;password encryption aes&lt;/P&gt;&lt;P&gt;Cryptochecksum:6f99e1277a392a926d04735c7f6a8c50&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco 2811:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CISCO-2811#sh run&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 4778 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;! Last configuration change at 23:24:57 UTC Mon Feb 3 2014&lt;/P&gt;&lt;P&gt;version 15.1&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec&lt;/P&gt;&lt;P&gt;service timestamps log datetime msec&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname CISCO-2811&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot system flash&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;enable redacted&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot11 syslog&lt;/P&gt;&lt;P&gt;no ip source-route&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip cef&lt;/P&gt;&lt;P&gt;no ip dhcp use vrf connected&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.1.1 192.168.1.49&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 172.16.10.1 172.16.10.49&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 172.16.20.1 172.16.20.49&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool Mitchs_Network&lt;/P&gt;&lt;P&gt; network 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt; dns-server 192.168.1.2 199.195.168.4 205.171.2.65 205.171.3.65 8.8.8.8&lt;/P&gt;&lt;P&gt; default-router 192.168.1.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool VLAN10&lt;/P&gt;&lt;P&gt; network 172.16.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt; default-router 172.16.10.1&lt;/P&gt;&lt;P&gt; dns-server 199.195.168.4 205.171.2.65 205.171.3.65 8.8.8.8&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool VLAN20&lt;/P&gt;&lt;P&gt; network 172.16.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt; dns-server 199.195.168.4 205.171.2.65 205.171.3.65 8.8.8.8&lt;/P&gt;&lt;P&gt; default-router 172.16.20.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip domain name maladomini.int&lt;/P&gt;&lt;P&gt;ip name-server 192.168.1.2&lt;/P&gt;&lt;P&gt;ip name-server 199.195.168.4&lt;/P&gt;&lt;P&gt;ip name-server 205.171.2.65&lt;/P&gt;&lt;P&gt;ip name-server 205.171.3.65&lt;/P&gt;&lt;P&gt;ip name-server 8.8.8.8&lt;/P&gt;&lt;P&gt;no vlan accounting input&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;multilink bundle-name authenticated&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;password encryption aes&lt;/P&gt;&lt;P&gt;crypto pki token default removal timeout 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto pki trustpoint TP-self-signed-1290569776&lt;/P&gt;&lt;P&gt; enrollment selfsigned&lt;/P&gt;&lt;P&gt; subject-name cn=IOS-Self-Signed-Certificate-1290569776&lt;/P&gt;&lt;P&gt; revocation-check none&lt;/P&gt;&lt;P&gt; rsakeypair TP-self-signed-1290569776&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto pki certificate chain TP-self-signed-1290569776&lt;/P&gt;&lt;P&gt; certificate self-signed 01&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3082022B 30820194 A0030201 02020101 300D0609 2A864886 F70D0101 05050030&lt;/P&gt;&lt;P&gt;&amp;nbsp; 31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274&lt;/P&gt;&lt;P&gt;&amp;nbsp; 69666963 6174652D 31323930 35363937 3736301E 170D3134 30313035 30363130&lt;/P&gt;&lt;P&gt;&amp;nbsp; 33395A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 32393035&lt;/P&gt;&lt;P&gt;&amp;nbsp; 36393737 3630819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281&lt;/P&gt;&lt;P&gt;&amp;nbsp; 8100B18F F63C5121 00785DE0 854601BA EE77DAA3 21286D8C 6E700C37 237CC1BE&lt;/P&gt;&lt;P&gt;&amp;nbsp; 611023AF FBE04BBE 7B4B3233 E4E129DD A74604E5 62AA39BF 77F98D5D D63944E9&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2345AE37 D93C5753 E425E85A EB22C2C9 CFC5D1A0 F800449B 0419A5C8 A0A101EC&lt;/P&gt;&lt;P&gt;&amp;nbsp; 02928172 7B30A609 71ADA3D4 68F4F484 AF2B3249 0E225DB2 C72C136A E670D761&lt;/P&gt;&lt;P&gt;&amp;nbsp; DDE30203 010001A3 53305130 0F060355 1D130101 FF040530 030101FF 301F0603&lt;/P&gt;&lt;P&gt;&amp;nbsp; 551D2304 1461F6DE 8EF50F7B 0E46359F 421EA106 9375F65F 30301D06&lt;/P&gt;&lt;P&gt;&amp;nbsp; 03551D0E 04160414 61F6DE8E F50F7B0E 46359F42 1EA10693 75F65F30 300D0609&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2A864886 F70D0101 05050003 81810049 BA55F695 8525265F ED2D77EE 8706BF10&lt;/P&gt;&lt;P&gt;&amp;nbsp; 63A7E644 202F6663 9EA5551F 47F7FC50 D4021EDD E3DC5A80 39FD161A C337D20D&lt;/P&gt;&lt;P&gt;&amp;nbsp; 71B98875 0F1FE887 649E81D3 F93F7A1B A1E18B99 A77B1A59 84DB4711 867913FD&lt;/P&gt;&lt;P&gt;&amp;nbsp; 044084FB 651ECA6E C6EDF35C E43A2946 8C01781E 26DB9484 C8740A82 4A7CA266&lt;/P&gt;&lt;P&gt;&amp;nbsp; A0655526 CBCB4982 F30D68E9 D70753&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; quit&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;license udi pid CISCO2811 sn FTX1041A07T&lt;/P&gt;&lt;P&gt;username redacted&lt;/P&gt;&lt;P&gt;username redacted&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;redundancy&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip ssh time-out 60&lt;/P&gt;&lt;P&gt;ip ssh authentication-retries 5&lt;/P&gt;&lt;P&gt;ip ssh version 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; description CONNECTION TO INSIDE INT. OF ASA&lt;/P&gt;&lt;P&gt; ip address 10.10.1.2 255.255.255.252&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1.1&lt;/P&gt;&lt;P&gt; description VLAN 10&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 10&lt;/P&gt;&lt;P&gt; ip address 172.16.10.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1.2&lt;/P&gt;&lt;P&gt; description VLAN 20&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 20&lt;/P&gt;&lt;P&gt; ip address 172.16.20.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1.3&lt;/P&gt;&lt;P&gt; description Trunk Interface VLAN 1&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 1 native&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dialer0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;router rip&lt;/P&gt;&lt;P&gt; version 2&lt;/P&gt;&lt;P&gt; network 172.16.0.0&lt;/P&gt;&lt;P&gt; network 192.168.1.0&lt;/P&gt;&lt;P&gt; network 199.195.168.0&lt;/P&gt;&lt;P&gt; no auto-summary&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip default-gateway 10.10.1.1&lt;/P&gt;&lt;P&gt;ip forward-protocol nd&lt;/P&gt;&lt;P&gt;no ip http server&lt;/P&gt;&lt;P&gt;ip http authentication local&lt;/P&gt;&lt;P&gt;ip http secure-server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dns server&lt;/P&gt;&lt;P&gt;ip nat inside source list 1 interface FastEthernet0/0 overload&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.10.1.1&lt;/P&gt;&lt;P&gt;ip ospf name-lookup&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list 1 permit any&lt;/P&gt;&lt;P&gt;dialer-list 1 protocol ip permit&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tftp-server system:running-config 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;control-plane&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; exec-timeout 0 0&lt;/P&gt;&lt;P&gt; password Redacted&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; access-class 20 in&lt;/P&gt;&lt;P&gt; exec-timeout 0 0&lt;/P&gt;&lt;P&gt; password Redacted&lt;/P&gt;&lt;P&gt; transport input ssh&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;scheduler allocate 20000 1000&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Feb 2014 20:28:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461211#M269635</guid>
      <dc:creator>metuckness</dc:creator>
      <dc:date>2014-02-14T20:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461212#M269636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So we could have a look at the Routing/NAT/etc between the ASA and this Router (only).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You basically have all the Static routes present on both devices that are needed between the ASA and the Router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Router has these LAN networks behind it&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;192.168.1.0/24&lt;/LI&gt;&lt;LI&gt;172.16.10.0/24&lt;/LI&gt;&lt;LI&gt;172.16.20.0/24&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA has the correct routes for these networks that are pointing towards the Router behind the &lt;STRONG&gt;"Inside"&lt;/STRONG&gt; interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route Inside 172.16.10.0 255.255.255.0 10.10.1.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route Inside 172.16.20.0 255.255.255.0 10.10.1.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route Inside 192.168.1.0 255.255.255.0 10.10.1.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I however dont have an idea what these networks are?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route Inside 128.162.1.0 255.255.255.0 10.10.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route Inside 128.162.10.0 255.255.255.0 10.10.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route Inside 128.162.20.0 255.255.255.0 10.10.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They have a &lt;STRONG&gt;"route"&lt;/STRONG&gt; on the ASA but I can't see them on the Router and to my understanding there is no other Router directly connected to this one? So the question is are these needed at all?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your Router also has a default route towards the the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip route 0.0.0.0 0.0.0.0 10.10.1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So all in all the Static Routes you have should be fine for the ASA and Router to know where to forward traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards to NAT the ASA seems to have the proper configurations so that each LAN network has a Dynamic PAT configuration and should therefore have a public IP address when they access the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the Router you also have a Dynamic PAT configured&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip nat inside source list 1 interface FastEthernet0/0 overload&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This configuration together with the ACL 1 and the &lt;STRONG&gt;"ip nat inside"&lt;/STRONG&gt; and &lt;STRONG&gt;"ip nat outside"&lt;/STRONG&gt; configurations essentially do a Dynamic PAT that translates all the networks 192.168.1.0/24, 172.16.10.0/24 and 172.16.20.0/24 to the IP address 10.10.1.2 when they connect towards the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA will in other words see all the connections coming from that IP address 10.10.1.2. It wont see anything from the internal networks directly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While the above might work ok for any outbound connections formed from those LAN networks it will break connectivity to all those networks from other networks behind the ASA. This is because the Router sees a connection coming to one of its LAN networks and when that return packet comes through the Router it translates that source address (like 192.168.1.5) to the IP address 10.10.1.2 and therefore essentially prevent any connection forming from remote networks to these LAN networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have the samekind of Dynamic PAT on each of your Routers it will mean that LAN networks behind different Routers wont be able to connect with eachother.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naturally you seem to have a switched network behind the Router also. So you will have to make sure that the Trunk interface on the switch is configured correctly and includes all the Vlan IDs configured on the Router interface also. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my eye in the above setup the main problem is the Dynamic PAT on the Router. I am not sure what the purpose of it would be. I have never configured Dynamic PAT on a customer LAN router that is connected to a firewall. There is simply no need for it as we have no need to mask the IP address of the LAN users towards other LAN networks. The only real need to NAT the source IP address is when the host is connecting to the public network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Removing the NAT or changing the routing configurations should naturally be done when you are able to also have console access locally to the device incase something goes wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Feb 2014 21:02:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461212#M269636</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-02-14T21:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461213#M269637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These networks are beind another router on different ports. The ASA actually has three different routers behind it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface 0 has the 2811&lt;/P&gt;&lt;P&gt;Interface 1 has the WAN&lt;/P&gt;&lt;P&gt;Interface 2 has the 2821&lt;/P&gt;&lt;P&gt;Interface 3 has the 3745&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These networks:&lt;/P&gt;&lt;P style="margin-top: 14pt; margin-bottom: 14pt;"&gt;&lt;STRONG&gt;route Inside 128.162.1.0 255.255.255.0 10.10.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-top: 14pt; margin-bottom: 14pt;"&gt;&lt;STRONG&gt;route Inside 128.162.10.0 255.255.255.0 10.10.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-top: 14pt; margin-bottom: 14pt;"&gt;&lt;STRONG&gt;route Inside 128.162.20.0 255.255.255.0 10.10.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; Are all behind the Cisco 2821.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 3745 has different subnets, but I haven't figured out how to get to it yet, it's IOS is different and since I updated it I can't seem to ssh to it, but that's not important right now as there is nothing behind it &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, let me input your suggestions and see what happens now that I am home and have a console cable if I need it.&lt;/P&gt;&lt;MENU id="menuid"&gt;&lt;/MENU&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Feb 2014 19:17:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461213#M269637</guid>
      <dc:creator>metuckness</dc:creator>
      <dc:date>2014-02-15T19:17:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461214#M269638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So should I remove the overload statement from the router?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip nat inside source list 1 interface FastEthernet0/0 overload&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;remove that?&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;MENU id="menuid"&gt;So should I remove the overload statement from the router?So &lt;/MENU&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Feb 2014 19:26:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461214#M269638</guid>
      <dc:creator>metuckness</dc:creator>
      <dc:date>2014-02-15T19:26:25Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 with Cisco 2811 Router Behind it - Not forwarding traff</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461215#M269639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, and you should probably also remove the statements from the interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface FastEthernet0/0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; no ip nat outside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface FastEthernet0/1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; no ip nat inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface FastEthernet0/1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; no ip nat inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface FastEthernet0/1.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; no ip nat inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface FastEthernet0/1.3&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; no ip nat inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; - Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Feb 2014 19:35:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461215#M269639</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-02-15T19:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461216#M269640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also with regards to the routes above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The device behind &lt;STRONG&gt;"Inside"&lt;/STRONG&gt; interface of ASA is 2811 correct and those routes should be pointing to another interface with a 2821?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That would mean that they are pointing towards the wrong router at the moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Feb 2014 19:37:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461216#M269640</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-02-15T19:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461217#M269641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As soon as I remove the statement:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source list 1 interface FastEthernet0/0 overload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I lose internet connectivity on all devices behind the 2811.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know. The 2821 in on a different port on the ASA. I don't have anything behind it right now so I don't know other than one laptop that I use to test and it is able to get to the internet. BUT, the 2821 has the same basic configuration as the 2811. including the overload statement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a link to all my configurations and a network diagram.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://drive.google.com/a/maladomini.com/?pli=1#folders/0BzsKCe89GscxanUwQWI0bEI3azQ" rel="nofollow"&gt;https://drive.google.com/a/maladomini.com/?pli=1#folders/0BzsKCe89GscxanUwQWI0bEI3azQ&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A friend of mine that knows routers told me to use the Overload feature, but I am assuming that isn't needed in this config, I just have the wrong nat or route somewhere.&lt;/P&gt;&lt;MENU id="menuid"&gt;&lt;/MENU&gt;&lt;P&gt;&lt;/P&gt;&lt;MENU id="menuid"&gt;&lt;/MENU&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Feb 2014 20:00:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461217#M269641</guid>
      <dc:creator>metuckness</dc:creator>
      <dc:date>2014-02-15T20:00:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461218#M269642</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;MENU id="menuid"&gt;&lt;/MENU&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;JouniForss wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also with regards to the routes above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The device behind &lt;STRONG&gt;"Inside"&lt;/STRONG&gt; interface of ASA is 2811 correct and those routes should be pointing to another interface with a 2821?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That would mean that they are pointing towards the wrong router at the moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;No, I don't believe that is true. The 2821 is on a different port on the ASA and is not between the 2811 and the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet ----- ASA----2811&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----2821&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----3745&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;MENU id="menuid"&gt;&lt;/MENU&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Feb 2014 20:01:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461218#M269642</guid>
      <dc:creator>metuckness</dc:creator>
      <dc:date>2014-02-15T20:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461219#M269643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;MENU id="menuid"&gt;&lt;/MENU&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;JouniForss wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, and you should probably also remove the statements from the interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface FastEthernet0/0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; no ip nat outside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface FastEthernet0/1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; no ip nat inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface FastEthernet0/1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; no ip nat inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface FastEthernet0/1.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; no ip nat inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface FastEthernet0/1.3&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; no ip nat inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; - Jouni&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, when I remove these statements, I lose internet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Feb 2014 20:24:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461219#M269643</guid>
      <dc:creator>metuckness</dc:creator>
      <dc:date>2014-02-15T20:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461220#M269644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is getting confusing again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You state the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface 0 has the 2811 and that means the 2811 is behind &lt;STRONG&gt;"Inside"&lt;/STRONG&gt; interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface 2 has the 2821 and that means the 2821 is behind&lt;STRONG&gt; "DMZ"&lt;/STRONG&gt; interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next you mention the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;These networks:&lt;/P&gt;&lt;P style="margin-top: 14pt; margin-bottom: 14pt;"&gt;&lt;STRONG&gt;route Inside 128.162.1.0 255.255.255.0 10.10.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-top: 14pt; margin-bottom: 14pt;"&gt;&lt;STRONG&gt;route Inside 128.162.10.0 255.255.255.0 10.10.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-top: 14pt; margin-bottom: 14pt;"&gt;&lt;STRONG&gt;route Inside 128.162.20.0 255.255.255.0 10.10.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; Are all behind the Cisco 2821.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would mean that the above routes are wrong as the 2821 is NOT behind the &lt;STRONG&gt;"Inside"&lt;/STRONG&gt; interface. These routes should actually be pointing towards the &lt;STRONG&gt;"DMZ"&lt;/STRONG&gt; interface and not&lt;STRONG&gt; "Inside" &lt;/STRONG&gt;since even the gateway IP address 10.10.0.2 used is located behind &lt;STRONG&gt;"DMZ"&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though that is not the main issue here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition to removing the NAT configurations I would also suggest you remove the Dynamic Routing configurations. I imagine this could be done with the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no router rip &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On both of the devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it still does not work after this I would like to see the following output from the devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show arp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show route&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show xlate&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sh conn all&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sh ip arp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sh ip route&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It might not hurt saving the Router configurations (that does not have the NAT and Dynamic Routing on the Router) and rebooting the router after these changes. And then trying again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only thing removing the NAT from the Router should do is allow the hosts on the internal networks behind the router to connect to towards the ASA with their original IP address. The ASA would then translate those IP addresses to its public IP address if they were connecting to the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I basically have an identical setup at home at the moment but a bit different model devices. I have an ASA connected to a Cisco 1841 Router that is connected with a Trunk to a Cisco 2950 which has the hosts and other devices connected to it. So at the moment I am basically using the same network setup as you are.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason your friend might have suggested configuring Dynamic PAT (overload) on the Router is that he might have thought that you were going to use it at the edge of the network. Between the LAN and external network. Then it would have made sense. In the current setup it is not usefull.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Feb 2014 21:27:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461220#M269644</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-02-15T21:27:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461221#M269645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;MENU id="menuid"&gt;&lt;/MENU&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;JouniForss wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is getting confusing again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You state the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface 0 has the 2811 and that means the 2811 is behind &lt;STRONG&gt;"Inside"&lt;/STRONG&gt; interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface 2 has the 2821 and that means the 2821 is behind&lt;STRONG&gt; "DMZ"&lt;/STRONG&gt; interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next you mention the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;P&gt;These networks:&lt;/P&gt;&lt;P style="margin-top: 14pt; margin-bottom: 14pt;"&gt;&lt;STRONG&gt;route Inside 128.162.1.0 255.255.255.0 10.10.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-top: 14pt; margin-bottom: 14pt;"&gt;&lt;STRONG&gt;route Inside 128.162.10.0 255.255.255.0 10.10.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-top: 14pt; margin-bottom: 14pt;"&gt;&lt;STRONG&gt;route Inside 128.162.20.0 255.255.255.0 10.10.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; Are all behind the Cisco 2821.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would mean that the above routes are wrong as the 2821 is NOT behind the &lt;STRONG&gt;"Inside"&lt;/STRONG&gt; interface. These routes should actually be pointing towards the &lt;STRONG&gt;"DMZ"&lt;/STRONG&gt; interface and not&lt;STRONG&gt; "Inside" &lt;/STRONG&gt;since even the gateway IP address 10.10.0.2 used is located behind &lt;STRONG&gt;"DMZ"&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though that is not the main issue here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition to removing the NAT configurations I would also suggest you remove the Dynamic Routing configurations. I imagine this could be done with the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no router rip &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On both of the devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it still does not work after this I would like to see the following output from the devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show arp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show route&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show xlate&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sh conn all&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sh ip arp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sh ip route&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It might not hurt saving the Router configurations (that does not have the NAT and Dynamic Routing on the Router) and rebooting the router after these changes. And then trying again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only thing removing the NAT from the Router should do is allow the hosts on the internal networks behind the router to connect to towards the ASA with their original IP address. The ASA would then translate those IP addresses to its public IP address if they were connecting to the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I basically have an identical setup at home at the moment but a bit different model devices. I have an ASA connected to a Cisco 1841 Router that is connected with a Trunk to a Cisco 2950 which has the hosts and other devices connected to it. So at the moment I am basically using the same network setup as you are.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason your friend might have suggested configuring Dynamic PAT (overload) on the Router is that he might have thought that you were going to use it at the edge of the network. Between the LAN and external network. Then it would have made sense. In the current setup it is not usefull.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;You would be correct, those statements should read:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510(config)# route DMZ 128.162.1.0 255.255.255.0 10.10.0.2&lt;/P&gt;&lt;P&gt;ASA5510(config)# route DMZ 128.162.10.0 255.255.255.0 10.10.0.2&lt;/P&gt;&lt;P&gt;ASA5510(config)# route DMZ 128.162.20.0 255.255.255.0 10.10.0.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That was my mistake in not linking the interface names with the statement. I have fixed those as above. That should route that traffic accordingly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am going to remove the statements you have suggested and see if I can establish traffic. If not I will restore them and come back and post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As in my previous post, I post a link that has all my configs and a simple diagram of my network, which I think is accurate &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So here I go.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Feb 2014 00:06:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461221#M269645</guid>
      <dc:creator>metuckness</dc:creator>
      <dc:date>2014-02-16T00:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461222#M269646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, it didn't work. Unless I add the overload statement to the router, I cannot access the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the results of the commands you requested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# sh arp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside 10.10.1.2 0019.55a7.2ae8 728&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside 199.195.168.113 000c.4243.581a 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside 199.195.168.116 e05f.b947.116b 5375&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside 199.195.168.120 0017.c58a.1123 12106&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ 10.10.0.2 0025.849f.63e0 5926&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VOIP 10.10.2.2 000d.bcdc.fc40 10311&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# sh route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * - candidate default, U - per-user static route, o - ODR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; P - periodic downloaded static route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway of last resort is 199.195.168.113 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.20.0 255.255.255.0 [1/0] via 10.10.1.2, Inside&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.10.0 255.255.255.0 [1/0] via 10.10.1.2, Inside&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 128.162.1.0 255.255.255.0 [1/0] via 10.10.0.2, DMZ&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 128.162.10.0 255.255.255.0 [1/0] via 10.10.0.2, DMZ&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 128.162.20.0 255.255.255.0 [1/0] via 10.10.0.2, DMZ&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 199.195.168.112 255.255.255.240 is directly connected, Outside&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.0.0 255.255.255.252 is directly connected, DMZ&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.0 255.255.255.252 is directly connected, Inside&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.2.0 255.255.255.252 is directly connected, VOIP&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0 255.255.255.0 [1/0] via 10.10.1.2, Inside&lt;/P&gt;&lt;P&gt;S*&amp;nbsp;&amp;nbsp; 0.0.0.0 0.0.0.0 [1/0] via 199.195.168.113, Outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# sh xlate&lt;/P&gt;&lt;P&gt;39 in use, 784 most used&lt;/P&gt;&lt;P&gt;Flags: D - DNS, e - extended, I - identity, i - dynamic, r - portmap,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; s - static, T - twice, N - net-to-net&lt;/P&gt;&lt;P&gt;TCP PAT from DMZ:10.10.0.2 22-22 to Outside:199.195.168.12x 2222-2222&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 458:44:04 timeout 0:00:00&lt;/P&gt;&lt;P&gt;TCP PAT from Inside:10.10.1.2 22-22 to Outside:199.195.168.12x 222-222&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 27:56:36 timeout 0:00:00&lt;/P&gt;&lt;P&gt;TCP PAT from VOIP:10.10.2.2 22-22 to Outside:199.195.168.12x 2223-2223&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 664:22:17 timeout 0:00:00&lt;/P&gt;&lt;P&gt;TCP PAT from Inside:192.168.1.2 3389-3389 to Outside:199.195.168.12x 3389-3389&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 434:06:51 timeout 0:00:00&lt;/P&gt;&lt;P&gt;TCP PAT from Inside:192.168.1.5 80-80 to Outside:199.195.168.12x 8080-8080&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 29:08:48 timeout 0:00:00&lt;/P&gt;&lt;P&gt;NAT from Outside:0.0.0.0/0 to any:0.0.0.0/0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sIT idle 330:00:11 timeout 0:00:00&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/47191 to Outside:199.195.168.12x/47191 flags ri idle 0:00:13 timeout 0:00:30&lt;/P&gt;&lt;P&gt;UDP PAT from any:10.10.1.2/64013 to Outside:199.195.168.12x/64013 flags ri idle 0:00:13 timeout 0:00:30&lt;/P&gt;&lt;P&gt;UDP PAT from any:10.10.1.2/65466 to Outside:199.195.168.12x/65466 flags ri idle 0:00:13 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57563 to Outside:199.195.168.12x/57563 flags ri idle 0:00:43 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57561 to Outside:199.195.168.12x/57561 flags ri idle 0:00:44 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/55952 to Outside:199.195.168.12x/55952 flags ri idle 0:00:59 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/53254 to Outside:199.195.168.12x/53254 flags ri idle 0:01:13 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57560 to Outside:199.195.168.12x/57560 flags ri idle 0:01:13 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/55951 to Outside:199.195.168.12x/55951 flags ri idle 0:01:30 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57557 to Outside:199.195.168.12x/57557 flags ri idle 0:01:43 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57556 to Outside:199.195.168.12x/57556 flags ri idle 0:01:44 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57555 to Outside:199.195.168.12x/57555 flags ri idle 0:01:45 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57554 to Outside:199.195.168.12x/57554 flags ri idle 0:01:51 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57549 to Outside:199.195.168.12x/57549 flags ri idle 0:02:00 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57548 to Outside:199.195.168.12x/57548 flags ri idle 0:02:01 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/2492 to Outside:199.195.168.12x/2492 flags ri idle 0:02:22 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57503 to Outside:199.195.168.12x/57503 flags ri idle 0:03:40 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57493 to Outside:199.195.168.12x/57493 flags ri idle 0:03:48 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57488 to Outside:199.195.168.12x/57488 flags ri idle 0:03:53 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/55948 to Outside:199.195.168.12x/55948 flags ri idle 0:03:57 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57468 to Outside:199.195.168.12x/57468 flags ri idle 0:04:01 timeout 0:00:30&lt;/P&gt;&lt;P&gt;UDP PAT from any:10.10.1.2/57609 to Outside:199.195.168.12x/57609 flags ri idle 0:04:29 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57455 to Outside:199.195.168.12x/57455 flags ri idle 0:00:10 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/36739 to Outside:199.195.168.12x/36739 flags ri idle 0:04:53 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57435 to Outside:199.195.168.12x/57435 flags ri idle 0:04:58 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57389 to Outside:199.195.168.12x/57389 flags ri idle 0:00:06 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57375 to Outside:199.195.168.12x/57375 flags ri idle 0:05:05 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57361 to Outside:199.195.168.12x/57361 flags ri idle 0:05:08 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/55944 to Outside:199.195.168.12x/55944 flags ri idle 0:05:09 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57318 to Outside:199.195.168.12x/57318 flags ri idle 0:05:13 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57315 to Outside:199.195.168.12x/57315 flags ri idle 0:05:15 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/55942 to Outside:199.195.168.12x/55942 flags ri idle 0:05:15 timeout 0:00:30&lt;/P&gt;&lt;P&gt;UDP PAT from any:172.16.20.3/123 to Outside:199.195.168.12x/123 flags ri idle 0:06:24 timeout 0:00:30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# show conn all&lt;/P&gt;&lt;P&gt;28 in use, 815 most used&lt;/P&gt;&lt;P&gt;TCP DMZ&amp;nbsp; 10.10.0.2:22 Inside&amp;nbsp; 10.10.1.2:55509, idle 0:54:51, bytes 14947, flags UIOB&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.142.125:5222 Inside&amp;nbsp; 10.10.1.2:57468, idle 0:00:07, bytes 8944, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 31.13.74.128:443 Inside&amp;nbsp; 10.10.1.2:57493, idle 0:00:54, bytes 39300, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 98.22.121.19:443 Inside&amp;nbsp; 10.10.1.2:57568, idle 0:00:31, bytes 4480, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.142.189:443 Inside&amp;nbsp; 10.10.1.2:57315, idle 0:00:08, bytes 51097, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.142.84:443 Inside&amp;nbsp; 10.10.1.2:57567, idle 0:00:16, bytes 2940, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 23.206.216.93:80 Inside&amp;nbsp; 10.10.1.2:53254, idle 0:05:57, bytes 303, flags UfFrIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 17.149.36.180:5223 Inside&amp;nbsp; 10.10.1.2:55951, idle 0:06:16, bytes 4322, flags UIO&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 10.10.1.2:64021, idle 0:00:00, bytes 44, flags -&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 65.55.122.234:2492 Inside&amp;nbsp; 10.10.1.2:2492, idle 0:06:55, bytes 1361, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.225.54:443 Inside&amp;nbsp; 10.10.1.2:57554, idle 0:00:04, bytes 139418, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.225.37:443 Inside&amp;nbsp; 10.10.1.2:57582, idle 0:00:58, bytes 9965, flags UIO&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 96.226.242.9:123 Inside&amp;nbsp; 172.16.20.3:123, idle 0:00:25, bytes 96, flags -&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 17.149.32.75:5223 Inside&amp;nbsp; 10.10.1.2:57435, idle 0:09:43, bytes 4540, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 69.171.248.16:443 Inside&amp;nbsp; 10.10.1.2:57606, idle 0:00:05, bytes 6236, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 69.171.248.16:443 Inside&amp;nbsp; 10.10.1.2:57548, idle 0:00:02, bytes 20177, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 23.207.17.227:443 Inside&amp;nbsp; 10.10.1.2:57607, idle 0:00:24, bytes 9290, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.225.47:443 Inside&amp;nbsp; 10.10.1.2:57602, idle 0:00:44, bytes 5570, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 64.4.23.147:33033 Inside&amp;nbsp; 10.10.1.2:55944, idle 0:01:01, bytes 23274, flags UIO&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 66.104.81.70:5070 Inside&amp;nbsp; 10.10.1.2:57609, idle 0:00:14, bytes 5357, flags -&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 134.170.18.190:443 Inside&amp;nbsp; 10.10.1.2:55948, idle 0:01:01, bytes 19804, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 143.127.93.105:80 Inside&amp;nbsp; 10.10.1.2:57503, idle 0:08:26, bytes 331, flags UO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.225.38:443 Inside&amp;nbsp; 10.10.1.2:57596, idle 0:00:16, bytes 23761, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 91.190.218.59:443 Inside&amp;nbsp; 10.10.1.2:55942, idle 0:01:01, bytes 1217, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 143.127.93.107:80 Inside&amp;nbsp; 10.10.1.2:57318, idle 0:09:59, bytes 350, flags UO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 54.196.88.252:443 Inside&amp;nbsp; 10.10.1.2:36739, idle 0:00:00, bytes 10912322, flags UIO&lt;/P&gt;&lt;P&gt;TCP Inside&amp;nbsp; 10.10.1.2:57457 NP Identity Ifc&amp;nbsp; 10.10.1.1:22, idle 0:00:00, bytes 38999, flags UOB&lt;/P&gt;&lt;P&gt;TCP Inside&amp;nbsp; 192.168.1.20:55987 NP Identity Ifc&amp;nbsp; 10.10.1.1:22, idle 0:15:54, bytes 40611, flags UOB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco 2811 Router:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CISCO-2811#sh ip arp&lt;/P&gt;&lt;P&gt;Protocol&amp;nbsp; Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Age (min)&amp;nbsp; Hardware Addr&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp; Interface&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 10.10.1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 21&amp;nbsp;&amp;nbsp; c47d.4f3b.8ea6&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/0&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 10.10.1.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp; 0019.55a7.2ae8&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/0&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 172.16.10.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp; 0019.55a7.2ae9&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.1&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 172.16.10.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&amp;nbsp;&amp;nbsp; 0011.5c73.28c1&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.1&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 172.16.20.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp; 0019.55a7.2ae9&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.2&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 172.16.20.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&amp;nbsp;&amp;nbsp; 0011.5c73.28c2&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.2&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp; 0019.55a7.2ae9&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; 0024.e864.01a8&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&amp;nbsp;&amp;nbsp; 0011.5c73.28c0&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; 5cf9.dd52.5fa9&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.50&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11&amp;nbsp;&amp;nbsp; 308c.fb47.f2d9&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.51&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7&amp;nbsp;&amp;nbsp; ec35.8677.4057&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.52&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 11&amp;nbsp;&amp;nbsp; b418.d136.ef72&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.53&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&amp;nbsp;&amp;nbsp; b418.d136.ef72&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.57&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15&amp;nbsp;&amp;nbsp; ec35.8677.4057&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.174&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; b8ac.6fff.af83&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.226&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; f47b.5e9a.7ae5&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CISCO-2811#sh ip route&lt;/P&gt;&lt;P&gt;Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; + - replicated route, % - next hop override&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway of last resort is 10.10.1.1 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S*&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0 [1/0] via 10.10.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.0/8 is variably subnetted, 2 subnets, 2 masks&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.0/30 is directly connected, FastEthernet0/0&lt;/P&gt;&lt;P&gt;L&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.2/32 is directly connected, FastEthernet0/0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.0.0/16 is variably subnetted, 4 subnets, 2 masks&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.10.0/24 is directly connected, FastEthernet0/1.1&lt;/P&gt;&lt;P&gt;L&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.10.1/32 is directly connected, FastEthernet0/1.1&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.20.0/24 is directly connected, FastEthernet0/1.2&lt;/P&gt;&lt;P&gt;L&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.20.1/32 is directly connected, FastEthernet0/1.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0/24 is variably subnetted, 2 subnets, 2 masks&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0/24 is directly connected, FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;L&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.1/32 is directly connected, FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;MENU id="menuid"&gt;&lt;/MENU&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Feb 2014 00:56:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461222#M269646</guid>
      <dc:creator>metuckness</dc:creator>
      <dc:date>2014-02-16T00:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461223#M269647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The link you posted earlier just takes to the google page and asks for credentials which I dont have. If you have some picture and information you can also post/attach it here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't see no reason why the connections should not work after changing the Router configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to me that the ASA command outputs have been taken when the Router still had the configurations present because each connection is from the source address of 10.10.1.2 and not the real source.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When there is no translation configuration for the hosts on the Router then the connections would go like this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Host on a certain Vlan starts to form a connection and sends packet/frame to the Router through the switch&lt;/LI&gt;&lt;LI&gt;The router checks its routing table where to forward this packet and sees that it should forward it with the default route to the ASA&lt;/LI&gt;&lt;LI&gt;The ASA checks again where it should forward the packet and sees that it should use the default route and forward it to the ISP. The source address is also translated according to the Dynamic PAT rule and the traffic is allowed because of the &lt;STRONG&gt;"security-level"&lt;/STRONG&gt; settings as there is no interface ACL.&lt;/LI&gt;&lt;LI&gt;Traffic/reply comes back from the Internet host and uses the existing connection and Dynamic PAT translation created initially to pass the traffic through the ASA.&lt;/LI&gt;&lt;LI&gt;The ASA then forwards the traffic to the Router&lt;/LI&gt;&lt;LI&gt;The Router sees the destination IP address of the packet belonging to one of the LAN hosts&lt;/LI&gt;&lt;LI&gt;It then checks the ARP table to which MAC address to forward the traffic. If it cant find that information it will ARP for the MAC address of the host&lt;/LI&gt;&lt;LI&gt;Router sends the packet to the host that opened the connection.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't see anything in the above configuration preventing this from happening. There should be no reason that this should not work. There might well be something involved that I am missing but the configuration is quite simple and I can't see and error in it and why the changes we do should matter at all for connectivity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the configurations on the Router are changed (and configuration saved + router is reloaded) I would open the ASDM on the ASA through some other computer and monitor what happens to the connection attempts from behind the Router. I would check if we get any logs from the source addresses from networks 192.168.1.0/24 , 172.16.10.0/24 and 172.16.20.0/24. I would also monitor looking at those logs if they get translated by the ASA. I would perhaps also try to ping from this router to the ASA and to the ISP gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; command should also tell what happens with the ASA when a packet from the original source addresses of the host comes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input Inside tcp 192.168.1.100 12345 8.8.8.8 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Feb 2014 09:19:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461223#M269647</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-02-16T09:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461224#M269648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right, th elink should of let anyone with it view the files. Now it it set to public. I'll also attach them here. These are the configs as they stand now, working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I remove the Overload statement on the router, I lose internet access. I can't ping anything pass the ASA. I can ping the ASA, the ASA can ping the router, but no traffic will pass beyond that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't pasted configs from when I remove those statements because all I have to do is remove the overload and everything stops. Even if I go and remove the rest of the statements, reboot, it doesn't allow the traffic past.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://drive.google.com/file/d/0BzsKCe89GscxM1lqckI3SkV2bTA/edit?usp=sharing"&gt;https://drive.google.com/file/d/0BzsKCe89GscxM1lqckI3SkV2bTA/edit?usp=sharing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://drive.google.com/file/d/0BzsKCe89GscxMmxTblF4UmlGUE0/edit?usp=sharing"&gt;https://drive.google.com/file/d/0BzsKCe89GscxMmxTblF4UmlGUE0/edit?usp=sharing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://drive.google.com/file/d/0BzsKCe89GscxZ1owclN2UTYwVDg/edit?usp=sharing"&gt;https://drive.google.com/file/d/0BzsKCe89GscxZ1owclN2UTYwVDg/edit?usp=sharing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://drive.google.com/file/d/0BzsKCe89GscxaDE1VDRKaEdfcUU/edit?usp=sharing"&gt;https://drive.google.com/file/d/0BzsKCe89GscxaDE1VDRKaEdfcUU/edit?usp=sharing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://drive.google.com/file/d/0BzsKCe89GscxaGhYR3BNenBlNUU/edit?usp=sharing"&gt;https://drive.google.com/file/d/0BzsKCe89GscxaGhYR3BNenBlNUU/edit?usp=sharing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://drive.google.com/file/d/0BzsKCe89GscxdEptTkc4M3ZuSGs/edit?usp=sharing"&gt;https://drive.google.com/file/d/0BzsKCe89GscxdEptTkc4M3ZuSGs/edit?usp=sharing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://drive.google.com/file/d/0BzsKCe89GscxdTJ4eFR5QWJBdlE/edit?usp=sharing"&gt;https://drive.google.com/file/d/0BzsKCe89GscxdTJ4eFR5QWJBdlE/edit?usp=sharing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/9/2/7/180729-Network.jpg" alt="Network.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;MENU id="menuid"&gt;&lt;/MENU&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Feb 2014 23:41:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461224#M269648</guid>
      <dc:creator>metuckness</dc:creator>
      <dc:date>2014-02-16T23:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461225#M269649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I ran those commands while I had the nat off on the router and here are the results. note, i didn't make any changes to the ASA as you only said to remove the router RIP which I did and reloaded and no change.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As long as the statements ip nat outside on the Fastethernet 0/0 is off and the ip nat inside is off on the vlan and the overload statement is taken out, I cannot hit the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CISCO-2811#conf t&lt;/P&gt;&lt;P&gt;Enter configuration commands, one per line.&amp;nbsp; End with CNTL/Z.&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#int&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#interface f&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#interface fastEthernet 0/1.3&lt;/P&gt;&lt;P&gt;CISCO-2811(config-subif)#no ip nat inside&lt;/P&gt;&lt;P&gt;CISCO-2811(config-subif)#exit&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#inter&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#interface f&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#interface fastEthernet 0/0&lt;/P&gt;&lt;P&gt;CISCO-2811(config-if)#no ip nat outside&lt;/P&gt;&lt;P&gt;CISCO-2811(config-if)#exit&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#$nside source list 1 interface FastEthernet0/0 overload&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dynamic mapping in use, do you want to delete all entries? [no]: y&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#exit&lt;/P&gt;&lt;P&gt;CISCO-2811#sh ip arp&lt;/P&gt;&lt;P&gt;Protocol&amp;nbsp; Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Age (min)&amp;nbsp; Hardware Addr&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp; Interface&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 10.10.1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 202&amp;nbsp;&amp;nbsp; c47d.4f3b.8ea6&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/0&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 10.10.1.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp; 0019.55a7.2ae8&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/0&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 172.16.10.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp; 0019.55a7.2ae9&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.1&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 172.16.10.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 238&amp;nbsp;&amp;nbsp; 0011.5c73.28c1&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.1&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 172.16.10.50&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 72&amp;nbsp;&amp;nbsp; cc2d.8c78.065a&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.1&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 172.16.20.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp; 0019.55a7.2ae9&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.2&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 172.16.20.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 196&amp;nbsp;&amp;nbsp; 0011.5c73.28c2&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.2&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp; 0019.55a7.2ae9&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; 0024.e864.01a8&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 155&amp;nbsp;&amp;nbsp; 0011.5c73.28c0&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 61&amp;nbsp;&amp;nbsp; 4802.2a4c.1c74&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; 5cf9.dd52.5fa9&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.50&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; 308c.fb47.f2d9&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.51&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp; ec35.8677.4057&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.52&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp; b418.d136.ef72&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.53&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp; 8853.9572.e113&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.54&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 12&amp;nbsp;&amp;nbsp; 0009.b044.9f23&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.55&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; f47b.5e9a.7ae5&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.149&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; 001e.4fc5.a199&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;Internet&amp;nbsp; 192.168.1.174&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; b8ac.6fff.af83&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CISCO-2811#sh ip route&lt;/P&gt;&lt;P&gt;Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E1 - OSPF external type 1, E2 - OSPF external type 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; + - replicated route, % - next hop override&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway of last resort is 10.10.1.1 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S*&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0/0 [1/0] via 10.10.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.0/8 is variably subnetted, 2 subnets, 2 masks&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.0/30 is directly connected, FastEthernet0/0&lt;/P&gt;&lt;P&gt;L&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.2/32 is directly connected, FastEthernet0/0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.0.0/16 is variably subnetted, 4 subnets, 2 masks&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.10.0/24 is directly connected, FastEthernet0/1.1&lt;/P&gt;&lt;P&gt;L&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.10.1/32 is directly connected, FastEthernet0/1.1&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.20.0/24 is directly connected, FastEthernet0/1.2&lt;/P&gt;&lt;P&gt;L&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.20.1/32 is directly connected, FastEthernet0/1.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0/24 is variably subnetted, 2 subnets, 2 masks&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0/24 is directly connected, FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;L&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.1/32 is directly connected, FastEthernet0/1.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# sh arp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inside 10.10.1.2 0019.55a7.2ae8 12342&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside 199.195.168.113 000c.4243.581a 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside 199.195.168.116 e05f.b947.116b 2436&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside 199.195.168.120 0017.c58a.1123 9192&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ 10.10.0.2 0025.849f.63e0 3192&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VOIP 10.10.2.2 000d.bcdc.fc40 7754&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# sh route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * - candidate default, U - per-user static route, o - ODR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; P - periodic downloaded static route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway of last resort is 199.195.168.113 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.20.0 255.255.255.0 [1/0] via 10.10.1.2, Inside&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.10.0 255.255.255.0 [1/0] via 10.10.1.2, Inside&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 128.162.1.0 255.255.255.0 [1/0] via 10.10.0.2, DMZ&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 128.162.10.0 255.255.255.0 [1/0] via 10.10.0.2, DMZ&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 128.162.20.0 255.255.255.0 [1/0] via 10.10.0.2, DMZ&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 199.195.168.112 255.255.255.240 is directly connected, Outside&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.0.0 255.255.255.252 is directly connected, DMZ&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.1.0 255.255.255.252 is directly connected, Inside&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0 255.255.255.0 [1/0] via 10.10.1.2, Inside&lt;/P&gt;&lt;P&gt;S*&amp;nbsp;&amp;nbsp; 0.0.0.0 0.0.0.0 [1/0] via 199.195.168.113, Outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# show xlate&lt;/P&gt;&lt;P&gt;35 in use, 784 most used&lt;/P&gt;&lt;P&gt;Flags: D - DNS, e - extended, I - identity, i - dynamic, r - portmap,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; s - static, T - twice, N - net-to-net&lt;/P&gt;&lt;P&gt;TCP PAT from DMZ:10.10.0.2 22-22 to Outside:199.195.168.x 2222-2222&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 481:54:14 timeout 0:00:00&lt;/P&gt;&lt;P&gt;TCP PAT from Inside:10.10.1.2 22-22 to Outside:199.195.168.x 222-222&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 51:06:46 timeout 0:00:00&lt;/P&gt;&lt;P&gt;TCP PAT from VOIP:10.10.2.2 22-22 to Outside:199.195.168.x 2223-2223&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 687:32:27 timeout 0:00:00&lt;/P&gt;&lt;P&gt;TCP PAT from Inside:192.168.1.2 3389-3389 to Outside:199.195.168.x 3389-3389&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 457:17:01 timeout 0:00:00&lt;/P&gt;&lt;P&gt;TCP PAT from Inside:192.168.1.5 80-80 to Outside:199.195.168.x 8080-8080&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sr idle 52:18:58 timeout 0:00:00&lt;/P&gt;&lt;P&gt;NAT from Outside:0.0.0.0/0 to any:0.0.0.0/0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; flags sIT idle 353:10:21 timeout 0:00:00&lt;/P&gt;&lt;P&gt;UDP PAT from any:10.10.1.2/52581 to Outside:199.195.168.x/52581 flags ri idle 0:00:00 timeout 0:00:30&lt;/P&gt;&lt;P&gt;UDP PAT from any:10.10.1.2/55389 to Outside:199.195.168.x/55389 flags ri idle 0:00:03 timeout 0:00:30&lt;/P&gt;&lt;P&gt;UDP PAT from any:10.10.1.2/51936 to Outside:199.195.168.x/51936 flags ri idle 0:00:04 timeout 0:00:30&lt;/P&gt;&lt;P&gt;UDP PAT from any:10.10.1.2/51345 to Outside:199.195.168.x/51345 flags ri idle 0:00:09 timeout 0:00:30&lt;/P&gt;&lt;P&gt;UDP PAT from any:10.10.1.2/55985 to Outside:199.195.168.x/55985 flags ri idle 0:00:18 timeout 0:00:30&lt;/P&gt;&lt;P&gt;UDP PAT from any:10.10.1.2/49368 to Outside:199.195.168.x/49368 flags ri idle 0:00:22 timeout 0:00:30&lt;/P&gt;&lt;P&gt;UDP PAT from any:10.10.1.2/52441 to Outside:199.195.168.x/52441 flags ri idle 0:00:23 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57908 to Outside:199.195.168.x/57908 flags ri idle 0:08:37 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57907 to Outside:199.195.168.x/57907 flags ri idle 0:08:37 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57906 to Outside:199.195.168.x/57906 flags ri idle 0:08:37 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57896 to Outside:199.195.168.x/57896 flags ri idle 0:09:09 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57879 to Outside:199.195.168.x/57879 flags ri idle 0:10:23 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/49441 to Outside:199.195.168.x/49441 flags ri idle 0:20:52 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57868 to Outside:199.195.168.x/57868 flags ri idle 0:25:28 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/60519 to Outside:199.195.168.x/60519 flags ri idle 0:44:11 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/60491 to Outside:199.195.168.x/60491 flags ri idle 0:44:20 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/60484 to Outside:199.195.168.x/60484 flags ri idle 0:44:35 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/60480 to Outside:199.195.168.x/60480 flags ri idle 0:44:51 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/53851 to Outside:199.195.168.x/53851 flags ri idle 0:54:14 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57812 to Outside:199.195.168.x/57812 flags ri idle 0:58:30 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57810 to Outside:199.195.168.x/57810 flags ri idle 0:58:32 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/53847 to Outside:199.195.168.x/53847 flags ri idle 1:00:18 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/57808 to Outside:199.195.168.x/57808 flags ri idle 1:07:58 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/60406 to Outside:199.195.168.x/60406 flags ri idle 1:42:13 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/49259 to Outside:199.195.168.x/49259 flags ri idle 7:39:44 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/49191 to Outside:199.195.168.x/49191 flags ri idle 7:42:39 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/55951 to Outside:199.195.168.x/55951 flags ri idle 23:11:40 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/55944 to Outside:199.195.168.x/55944 flags ri idle 23:15:19 timeout 0:00:30&lt;/P&gt;&lt;P&gt;TCP PAT from any:10.10.1.2/55942 to Outside:199.195.168.x/55942 flags ri idle 23:15:24 timeout 0:00:30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510# sh conn all&lt;/P&gt;&lt;P&gt;149 in use, 815 most used&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.193.108:993 Inside&amp;nbsp; 10.10.1.2:57879, idle 0:12:37, bytes 6398, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 174.35.24.74:80 Inside&amp;nbsp; 192.168.1.20:53879, idle 0:00:01, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 174.35.24.74:80 Inside&amp;nbsp; 192.168.1.20:53878, idle 0:00:01, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 17.149.36.177:5223 Inside&amp;nbsp; 10.10.1.2:60480, idle 0:16:53, bytes 4539, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 98.22.121.19:443 Inside&amp;nbsp; 192.168.1.20:53877, idle 0:00:02, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 98.22.121.19:443 Inside&amp;nbsp; 192.168.1.20:53876, idle 0:00:02, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 98.22.121.19:443 Inside&amp;nbsp; 192.168.1.20:53875, idle 0:00:05, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 98.22.121.19:443 Inside&amp;nbsp; 192.168.1.20:53874, idle 0:00:05, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 98.22.121.19:443 Inside&amp;nbsp; 192.168.1.20:53872, idle 0:00:11, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 98.22.121.19:443 Inside&amp;nbsp; 192.168.1.20:53871, idle 0:00:11, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 98.22.121.19:443 Inside&amp;nbsp; 192.168.1.20:53868, idle 0:00:08, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 98.22.121.19:443 Inside&amp;nbsp; 192.168.1.20:53867, idle 0:00:08, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 98.22.121.19:443 Inside&amp;nbsp; 192.168.1.20:53860, idle 0:00:17, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 98.22.121.19:443 Inside&amp;nbsp; 192.168.1.20:53859, idle 0:00:17, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 17.172.233.95:5223 Inside&amp;nbsp; 10.10.1.2:49191, idle 0:18:48, bytes 7384, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 17.178.100.43:443 Inside&amp;nbsp; 10.10.1.2:57810, idle 0:56:21, bytes 5797, flags UFIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 23.206.216.93:80 Inside&amp;nbsp; 10.10.1.2:53847, idle 0:54:15, bytes 2683, flags UFIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 143.127.93.90:80 Inside&amp;nbsp; 10.10.1.2:49259, idle 0:12:20, bytes 13315, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.225.53:443 Inside&amp;nbsp; 192.168.1.20:53864, idle 0:00:11, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:49204, idle 0:00:04, bytes 67, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.174:50122, idle 0:00:07, bytes 43, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:63275, idle 0:00:08, bytes 54, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:63306, idle 0:00:18, bytes 51, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:65059, idle 0:00:22, bytes 46, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:64681, idle 0:00:30, bytes 54, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:64661, idle 0:00:30, bytes 51, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.20:55618, idle 0:00:32, bytes 43, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:65056, idle 0:00:33, bytes 48, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.55:59433, idle 0:00:41, bytes 33, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.20:52178, idle 0:00:42, bytes 33, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.174:61414, idle 0:00:43, bytes 34, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:65438, idle 0:00:44, bytes 44, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:63686, idle 0:00:44, bytes 51, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:65416, idle 0:00:45, bytes 45, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.52:53047, idle 0:00:47, bytes 32, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.52:62213, idle 0:00:46, bytes 74, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.52:52347, idle 0:00:46, bytes 92, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.52:58069, idle 0:00:46, bytes 64, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.52:50753, idle 0:00:46, bytes 74, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:65381, idle 0:00:50, bytes 50, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:65082, idle 0:00:50, bytes 51, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:64038, idle 0:00:50, bytes 54, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:49309, idle 0:00:51, bytes 43, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:64034, idle 0:00:51, bytes 54, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:49197, idle 0:00:51, bytes 50, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:64728, idle 0:00:51, bytes 49, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:64309, idle 0:00:51, bytes 54, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:63289, idle 0:00:51, bytes 51, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:64174, idle 0:00:52, bytes 54, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.55:39286, idle 0:01:09, bytes 33, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:63726, idle 0:01:09, bytes 54, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:65482, idle 0:01:12, bytes 51, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:65091, idle 0:01:13, bytes 61, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:64976, idle 0:01:13, bytes 57, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:63749, idle 0:00:51, bytes 103, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:64043, idle 0:01:14, bytes 52, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:64267, idle 0:01:24, bytes 45, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:64467, idle 0:01:26, bytes 45, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:65504, idle 0:01:26, bytes 46, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.55:38946, idle 0:01:35, bytes 33, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:63701, idle 0:01:38, bytes 51, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:63879, idle 0:01:46, bytes 45, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.174:58516, idle 0:01:49, bytes 51, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:63227, idle 0:01:51, bytes 62, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.174:65446, idle 0:01:53, bytes 43, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.2:49166, idle 0:01:55, bytes 54, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 199.195.168.4:53 Inside&amp;nbsp; 192.168.1.55:56680, idle 0:02:01, bytes 33, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 192.55.83.30:53 Inside&amp;nbsp; 192.168.1.2:65073, idle 0:00:44, bytes 50, flags -&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.193.109:993 Inside&amp;nbsp; 10.10.1.2:57808, idle 0:39:33, bytes 6392, flags UFIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.225.54:443 Inside&amp;nbsp; 192.168.1.20:53863, idle 0:00:13, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 143.127.93.89:80 Inside&amp;nbsp; 10.10.1.2:60519, idle 0:46:30, bytes 346, flags UO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.225.32:443 Inside&amp;nbsp; 192.168.1.20:53881, idle 0:00:01, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.225.32:443 Inside&amp;nbsp; 192.168.1.20:53880, idle 0:00:01, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.3.65:53 Inside&amp;nbsp; 192.168.1.52:60627, idle 0:00:39, bytes 78, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.3.65:53 Inside&amp;nbsp; 192.168.1.52:52088, idle 0:00:39, bytes 86, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.3.65:53 Inside&amp;nbsp; 192.168.1.52:50533, idle 0:00:39, bytes 76, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.3.65:53 Inside&amp;nbsp; 192.168.1.52:63347, idle 0:00:39, bytes 80, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.3.65:53 Inside&amp;nbsp; 192.168.1.52:62213, idle 0:00:40, bytes 37, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.3.65:53 Inside&amp;nbsp; 192.168.1.52:52347, idle 0:00:40, bytes 46, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.3.65:53 Inside&amp;nbsp; 192.168.1.52:58069, idle 0:00:40, bytes 32, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.3.65:53 Inside&amp;nbsp; 192.168.1.52:50753, idle 0:00:40, bytes 37, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.3.65:53 Inside&amp;nbsp; 192.168.1.174:52254, idle 0:01:09, bytes 43, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.3.65:53 Inside&amp;nbsp; 192.168.1.174:50791, idle 0:01:25, bytes 35, flags -&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.225.46:443 Inside&amp;nbsp; 192.168.1.20:53870, idle 0:00:08, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 17.173.255.101:443 Inside&amp;nbsp; 10.10.1.2:53851, idle 0:56:33, bytes 58, flags UfIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 64.4.23.147:33033 Inside&amp;nbsp; 10.10.1.2:55944, idle 0:44:45, bytes 558164, flags UFIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.225.35:443 Inside&amp;nbsp; 192.168.1.20:53869, idle 0:00:09, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 64.4.23.175:33033 Inside&amp;nbsp; 192.168.1.174:26511, idle 0:01:17, bytes 28, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 192.54.112.30:53 Inside&amp;nbsp; 192.168.1.2:65380, idle 0:00:44, bytes 49, flags -&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.142.108:993 Inside&amp;nbsp; 10.10.1.2:57908, idle 0:10:47, bytes 7895, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.142.108:993 Inside&amp;nbsp; 10.10.1.2:57907, idle 0:10:49, bytes 20323, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.142.108:993 Inside&amp;nbsp; 10.10.1.2:57906, idle 0:10:47, bytes 6539, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.142.108:993 Inside&amp;nbsp; 10.10.1.2:57868, idle 0:27:44, bytes 6395, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 91.190.218.59:443 Inside&amp;nbsp; 10.10.1.2:55942, idle 0:41:39, bytes 2727, flags UFIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 17.172.233.123:5223 Inside&amp;nbsp; 10.10.1.2:49441, idle 0:23:10, bytes 4409, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.225.41:443 Inside&amp;nbsp; 192.168.1.20:53862, idle 0:00:16, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.225.41:443 Inside&amp;nbsp; 192.168.1.20:53861, idle 0:00:16, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 143.127.93.115:80 Inside&amp;nbsp; 10.10.1.2:60406, idle 0:42:59, bytes 970, flags UFIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 143.127.93.118:80 Inside&amp;nbsp; 10.10.1.2:60484, idle 0:46:54, bytes 328, flags UO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 17.172.233.98:5223 Inside&amp;nbsp; 10.10.1.2:57896, idle 0:11:28, bytes 5081, flags UIO&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 111.221.74.16:33033 Inside&amp;nbsp; 192.168.1.174:26511, idle 0:01:18, bytes 31, flags -&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 17.149.36.103:5223 Inside&amp;nbsp; 192.168.1.174:60729, idle 0:00:04, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 192.5.6.30:53 Inside&amp;nbsp; 192.168.1.2:65317, idle 0:00:44, bytes 51, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 192.12.94.30:53 Inside&amp;nbsp; 192.168.1.2:65356, idle 0:00:44, bytes 54, flags -&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 17.149.36.180:5223 Inside&amp;nbsp; 10.10.1.2:55951, idle 0:46:08, bytes 14059, flags UFIO&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 111.221.74.28:33033 Inside&amp;nbsp; 192.168.1.174:26511, idle 0:01:20, bytes 33, flags -&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 63.235.20.160:80 Inside&amp;nbsp; 192.168.1.20:53873, idle 0:00:08, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 50.19.127.112:443 Inside&amp;nbsp; 192.168.1.50:60678, idle 0:00:00, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 65.55.122.234:80 Inside&amp;nbsp; 192.168.1.174:60728, idle 0:00:14, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 65.55.122.234:80 Inside&amp;nbsp; 192.168.1.174:60727, idle 0:00:15, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 65.55.122.234:80 Inside&amp;nbsp; 192.168.1.174:60726, idle 0:00:15, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 65.55.122.234:443 Inside&amp;nbsp; 192.168.1.174:2492, idle 0:00:16, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 65.55.122.234:2492 Inside&amp;nbsp; 192.168.1.174:2492, idle 0:00:16, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 157.55.56.170:33033 Inside&amp;nbsp; 192.168.1.174:26511, idle 0:01:21, bytes 37, flags -&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.230.207:443 Inside&amp;nbsp; 192.168.1.20:53866, idle 0:00:11, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 74.125.230.207:443 Inside&amp;nbsp; 192.168.1.20:53865, idle 0:00:11, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 111.221.74.18:33033 Inside&amp;nbsp; 192.168.1.174:26511, idle 0:01:17, bytes 29, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 8.8.8.8:53 Inside&amp;nbsp; 192.168.1.20:55546, idle 0:00:06, bytes 46, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 8.8.8.8:53 Inside&amp;nbsp; 192.168.1.20:60277, idle 0:00:06, bytes 46, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 8.8.8.8:53 Inside&amp;nbsp; 192.168.1.20:55618, idle 0:00:34, bytes 43, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 8.8.8.8:53 Inside&amp;nbsp; 192.168.1.52:60627, idle 0:00:36, bytes 78, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 8.8.8.8:53 Inside&amp;nbsp; 192.168.1.52:52088, idle 0:00:36, bytes 86, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 8.8.8.8:53 Inside&amp;nbsp; 192.168.1.52:50533, idle 0:00:36, bytes 76, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 8.8.8.8:53 Inside&amp;nbsp; 192.168.1.52:63347, idle 0:00:36, bytes 80, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 8.8.8.8:53 Inside&amp;nbsp; 192.168.1.20:56958, idle 0:01:24, bytes 34, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 8.8.8.8:53 Inside&amp;nbsp; 192.168.1.20:51360, idle 0:01:26, bytes 34, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 8.8.8.8:53 Inside&amp;nbsp; 192.168.1.174:50791, idle 0:01:27, bytes 35, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 8.8.8.8:53 Inside&amp;nbsp; 192.168.1.20:54134, idle 0:01:46, bytes 34, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 8.8.8.8:53 Inside&amp;nbsp; 192.168.1.174:58516, idle 0:01:50, bytes 51, flags -&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 23.207.7.46:80 Inside&amp;nbsp; 192.168.1.55:59350, idle 0:00:02, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 23.207.7.46:80 Inside&amp;nbsp; 192.168.1.55:59349, idle 0:00:16, bytes 0, flags saA&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.2.65:53 Inside&amp;nbsp; 192.168.1.174:50122, idle 0:00:09, bytes 43, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.2.65:53 Inside&amp;nbsp; 192.168.1.55:48088, idle 0:00:42, bytes 33, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.2.65:53 Inside&amp;nbsp; 192.168.1.52:62213, idle 0:00:45, bytes 74, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.2.65:53 Inside&amp;nbsp; 192.168.1.52:52347, idle 0:00:45, bytes 92, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.2.65:53 Inside&amp;nbsp; 192.168.1.52:58069, idle 0:00:45, bytes 64, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.2.65:53 Inside&amp;nbsp; 192.168.1.52:50753, idle 0:00:45, bytes 74, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.2.65:53 Inside&amp;nbsp; 192.168.1.174:61414, idle 0:00:47, bytes 34, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.2.65:53 Inside&amp;nbsp; 192.168.1.55:54481, idle 0:01:08, bytes 33, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.2.65:53 Inside&amp;nbsp; 192.168.1.174:52254, idle 0:01:09, bytes 43, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.2.65:53 Inside&amp;nbsp; 192.168.1.55:40285, idle 0:01:34, bytes 33, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.2.65:53 Inside&amp;nbsp; 192.168.1.174:65446, idle 0:01:55, bytes 43, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 205.171.2.65:53 Inside&amp;nbsp; 192.168.1.55:46155, idle 0:02:00, bytes 33, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 66.104.81.70:5070 Inside&amp;nbsp; 192.168.1.174:57609, idle 0:00:11, bytes 46, flags -&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 64.4.23.156:33033 Inside&amp;nbsp; 192.168.1.174:26511, idle 0:01:14, bytes 38, flags -&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 65.54.167.15:12350 Inside&amp;nbsp; 10.10.1.2:60491, idle 0:11:02, bytes 1405, flags UIO&lt;/P&gt;&lt;P&gt;TCP Outside&amp;nbsp; 17.172.192.35:443 Inside&amp;nbsp; 10.10.1.2:57812, idle 0:56:11, bytes 6116, flags UFIO&lt;/P&gt;&lt;P&gt;UDP Outside&amp;nbsp; 157.55.56.176:33033 Inside&amp;nbsp; 192.168.1.174:26511, idle 0:01:16, bytes 32, flags -&lt;/P&gt;&lt;P&gt;TCP Inside&amp;nbsp; 192.168.1.20:53667 NP Identity Ifc&amp;nbsp; 10.10.1.1:22, idle 0:00:00, bytes 37555, flags UOB&lt;/P&gt;&lt;P&gt;TCP Inside&amp;nbsp; 10.10.1.2:53431 NP Identity Ifc&amp;nbsp; 10.10.1.1:22, idle 0:09:03, bytes 20739, flags UOB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Ran on the ASA while overload statements were down on the router:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510#&amp;nbsp;&amp;nbsp; packet-tracer input Inside tcp 192.168.1.100 12345 8.8.8.8 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: per-session&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: per-session&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 1988699, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: Inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: Outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Had to put these back in to get to the internet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CISCO-2811#conf t&lt;/P&gt;&lt;P&gt;Enter configuration commands, one per line.&amp;nbsp; End with CNTL/Z.&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#inter&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#interface f&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#interface fastEthernet 0/0&lt;/P&gt;&lt;P&gt;CISCO-2811(config-if)#ip nat&lt;/P&gt;&lt;P&gt;CISCO-2811(config-if)#ip nat Outside&lt;/P&gt;&lt;P&gt;CISCO-2811(config-if)#exit&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#in&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#interface f&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#interface fastEthernet 0/1.3&lt;/P&gt;&lt;P&gt;CISCO-2811(config-subif)#ip nat inside&lt;/P&gt;&lt;P&gt;CISCO-2811(config-subif)#exit&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#$de source list 1 interface FastEthernet0/0 overload&lt;/P&gt;&lt;P&gt;CISCO-2811(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Screenshot of ASDM:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/4/3/7/180734-asa.jpg" alt="asa.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;MENU id="menuid"&gt;&lt;/MENU&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Feb 2014 00:20:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461225#M269649</guid>
      <dc:creator>metuckness</dc:creator>
      <dc:date>2014-02-17T00:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461226#M269650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok this new output helped out alot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What we are essentially seeing is that the ASA is not doing any translation for this traffic. Even though there is a NAT configuration clearly set for all the LAN networks it seems the ASA completely ignores. What makes it strange is the fact that the NAT seems to work just fine for your Routers link network when the Dynamic PAT is enabled on the Router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;"show conn all"&lt;/STRONG&gt; output is something that I see every now and then and its always problem with either the ASA routing (or rather routing towards the ASA from the WAN) or missing NAT configuration. You see plenty of DNS queries that dont go through and also some TCP connections that timeout with SYN Timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can I would next suggest that you change the Dynamic PAT rule on the ASA and then remove the NAT configuration again on the Router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (any,Outside) after-auto source dynamic any interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no nat (any,Outside) after-auto source dynamic PAT-SOURCE interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The NAT configuration we add should enable Dynamic PAT on the ASA for any source address. The next command will remove the current Dynamic PAT configuration with the &lt;STRONG&gt;"PAT-SOURCE"&lt;/STRONG&gt; object.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I am not sure why its not being matched but its starting to seem like a bug and a major bug really since this should be a very basic configuration. This is the very basic configuration type we use on our firewalls. If there is major bug in the 9.1(4) software that somehow prevents this from working correctly then its a good thing to know. I will probably have to test this out myself also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So can you try removing the Router NAT configurations again and then changing the NAT configuration on the ASA as described above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Feb 2014 09:46:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461226#M269650</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-02-17T09:46:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 with Cisco 2811 Router Behind it - Not forwarding t</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461227#M269651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;JouniForss wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok this new output helped out alot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What we are essentially seeing is that the ASA is not doing any translation for this traffic. Even though there is a NAT configuration clearly set for all the LAN networks it seems the ASA completely ignores. What makes it strange is the fact that the NAT seems to work just fine for your Routers link network when the Dynamic PAT is enabled on the Router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;"show conn all"&lt;/STRONG&gt; output is something that I see every now and then and its always problem with either the ASA routing (or rather routing towards the ASA from the WAN) or missing NAT configuration. You see plenty of DNS queries that dont go through and also some TCP connections that timeout with SYN Timeout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can I would next suggest that you change the Dynamic PAT rule on the ASA and then remove the NAT configuration again on the Router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (any,Outside) after-auto source dynamic any interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no nat (any,Outside) after-auto source dynamic PAT-SOURCE interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The NAT configuration we add should enable Dynamic PAT on the ASA for any source address. The next command will remove the current Dynamic PAT configuration with the &lt;STRONG&gt;"PAT-SOURCE"&lt;/STRONG&gt; object.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I am not sure why its not being matched but its starting to seem like a bug and a major bug really since this should be a very basic configuration. This is the very basic configuration type we use on our firewalls. If there is major bug in the 9.1(4) software that somehow prevents this from working correctly then its a good thing to know. I will probably have to test this out myself also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So can you try removing the Router NAT configurations again and then changing the NAT configuration on the ASA as described above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will have to do it this afternoon when I get home from work. If I do it remotely I will get disconnected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, when I get ready to do this I should add this statement on to the &lt;STRONG&gt;ASA:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (any,Outside) after-auto source dynamic any interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And remove this statement:&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;no nat (any,Outside) after-auto source dynamic PAT-SOURCE interface&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The&lt;STRONG&gt;n do the other steps on the 2811:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;no ip nat outside on FastEthernet 0/0 &lt;/STRONG&gt;&lt;/STRONG&gt;on the 2811&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;no ip nat inside on the FastEthernet 0/1.3 &lt;/STRONG&gt;&lt;/STRONG&gt;on the 2811&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;no&lt;/STRONG&gt; ip nat inside source list 1 interface FastEthernet0/0 overload&lt;/STRONG&gt; on the 2811&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Feb 2014 16:09:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-with-cisco-2811-router-behind-it-not-forwarding-traffic/m-p/2461227#M269651</guid>
      <dc:creator>metuckness</dc:creator>
      <dc:date>2014-02-18T16:09:32Z</dc:date>
    </item>
  </channel>
</rss>

