<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA will not pass traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025038#M30282</link>
    <description>&lt;P&gt;Good Morning&lt;/P&gt;&lt;P&gt;My team recent received ASA 5506.&amp;nbsp; I'm currently in the process of setting one up for scanning and ran into some issues.&amp;nbsp; I can not get the thing to pass traffic.&amp;nbsp; I can piing the inside&amp;nbsp; from the inside network and outside from the outside network.&amp;nbsp; But I can not ping thru the device.&amp;nbsp; Any help would be grateful.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA Version 9.8(2)&lt;BR /&gt;!&lt;BR /&gt;hostname CGASATEST&lt;BR /&gt;enable password $sha512$5000$fWOBFLyMFFvJ7MXr8LExZg==$HXiVH3aMwKaatZMylDevDw== pbkdf2&lt;BR /&gt;names&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;interface GigabitEthernet1/1&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 192.168.83.45 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.90.185 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_2&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/4&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_3&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/5&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_4&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/6&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_5&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/7&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_6&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/8&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_7&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface Management1/1&lt;BR /&gt;management-only&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface BVI1&lt;BR /&gt;no nameif&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;object network obj_any1&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any2&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any3&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any4&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any5&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any6&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any7&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu inside_2 1500&lt;BR /&gt;mtu inside_3 1500&lt;BR /&gt;mtu inside_4 1500&lt;BR /&gt;mtu inside_5 1500&lt;BR /&gt;mtu inside_6 1500&lt;BR /&gt;mtu inside_7 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;arp rate-limit 16384&lt;BR /&gt;!&lt;BR /&gt;object network obj_any2&lt;BR /&gt;nat (inside_2,outside) dynamic interface&lt;BR /&gt;object network obj_any3&lt;BR /&gt;nat (inside_3,outside) dynamic interface&lt;BR /&gt;object network obj_any4&lt;BR /&gt;nat (inside_4,outside) dynamic interface&lt;BR /&gt;object network obj_any5&lt;BR /&gt;nat (inside_5,outside) dynamic interface&lt;BR /&gt;object network obj_any6&lt;BR /&gt;nat (inside_6,outside) dynamic interface&lt;BR /&gt;object network obj_any7&lt;BR /&gt;nat (inside_7,outside) dynamic interface&lt;BR /&gt;!&lt;BR /&gt;nat (inside,outside) after-auto source dynamic any interface&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 192.168.83.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;timeout conn-holddown 0:00:15&lt;BR /&gt;timeout igp stale-route 0:01:10&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;aaa authentication login-history&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_2&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_3&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_4&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_5&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_6&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_7&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;service sw-reset-button&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto ca trustpoint _SmartCallHome_ServerCA&lt;BR /&gt;no validation-usage&lt;BR /&gt;crl configure&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ca certificate chain _SmartCallHome_ServerCA&lt;BR /&gt;certificate ca 513fb9743870b73440418d30930699ff&lt;BR /&gt;30820538 30820420 a0030201 02021051 3fb97438 70b73440 418d3093 0699ff30&lt;BR /&gt;0d06092a 864886f7 0d01010b 05003081 ca310b30 09060355 04061302 55533117&lt;BR /&gt;30150603 55040a13 0e566572 69536967 6e2c2049 6e632e31 1f301d06 0355040b&lt;BR /&gt;13165665 72695369 676e2054 72757374 204e6574 776f726b 313a3038 06035504&lt;BR /&gt;0b133128 63292032 30303620 56657269 5369676e 2c20496e 632e202d 20466f72&lt;BR /&gt;20617574 686f7269 7a656420 75736520 6f6e6c79 31453043 06035504 03133c56&lt;BR /&gt;65726953 69676e20 436c6173 73203320 5075626c 69632050 72696d61 72792043&lt;BR /&gt;65727469 66696361 74696f6e 20417574 686f7269 7479202d 20473530 1e170d31&lt;BR /&gt;33313033 31303030 3030305a 170d3233 31303330 32333539 35395a30 7e310b30&lt;BR /&gt;09060355 04061302 5553311d 301b0603 55040a13 1453796d 616e7465 6320436f&lt;BR /&gt;72706f72 6174696f 6e311f30 1d060355 040b1316 53796d61 6e746563 20547275&lt;BR /&gt;7374204e 6574776f 726b312f 302d0603 55040313 2653796d 616e7465 6320436c&lt;BR /&gt;61737320 33205365 63757265 20536572 76657220 4341202d 20473430 82012230&lt;BR /&gt;0d06092a 864886f7 0d010101 05000382 010f0030 82010a02 82010100 b2d805ca&lt;BR /&gt;1c742db5 175639c5 4a520996 e84bd80c f1689f9a 422862c3 a530537e 5511825b&lt;BR /&gt;037a0d2f e17904c9 b4967719 81019459 f9bcf77a 9927822d b783dd5a 277fb203&lt;BR /&gt;7a9c5325 e9481f46 4fc89d29 f8be7956 f6f7fdd9 3a68da8b 4b823341 12c3c83c&lt;BR /&gt;ccd6967a 84211a22 04032717 8b1c6861 930f0e51 80331db4 b5ceeb7e d062acee&lt;BR /&gt;b37b0174 ef6935eb cad53da9 ee9798ca 8daa440e 25994a15 96a4ce6d 02541f2a&lt;BR /&gt;6a26e206 3a6348ac b44cd175 9350ff13 2fd6dae1 c618f59f c9255df3 003ade26&lt;BR /&gt;4db42909 cd0f3d23 6f164a81 16fbf283 10c3b8d6 d855323d f1bd0fbd 8c52954a&lt;BR /&gt;16977a52 2163752f 16f9c466 bef5b509 d8ff2700 cd447c6f 4b3fb0f7 02030100&lt;BR /&gt;01a38201 63308201 5f301206 03551d13 0101ff04 08300601 01ff0201 00303006&lt;BR /&gt;03551d1f 04293027 3025a023 a021861f 68747470 3a2f2f73 312e7379 6d63622e&lt;BR /&gt;636f6d2f 70636133 2d67352e 63726c30 0e060355 1d0f0101 ff040403 02010630&lt;BR /&gt;2f06082b 06010505 07010104 23302130 1f06082b 06010505 07300186 13687474&lt;BR /&gt;703a2f2f 73322e73 796d6362 2e636f6d 306b0603 551d2004 64306230 60060a60&lt;BR /&gt;86480186 f8450107 36305230 2606082b 06010505 07020116 1a687474 703a2f2f&lt;BR /&gt;7777772e 73796d61 7574682e 636f6d2f 63707330 2806082b 06010505 07020230&lt;BR /&gt;1c1a1a68 7474703a 2f2f7777 772e7379 6d617574 682e636f 6d2f7270 61302906&lt;BR /&gt;03551d11 04223020 a41e301c 311a3018 06035504 03131153 796d616e 74656350&lt;BR /&gt;4b492d31 2d353334 301d0603 551d0e04 1604145f 60cf6190 55df8443 148a602a&lt;BR /&gt;b2f57af4 4318ef30 1f060355 1d230418 30168014 7fd365a7 c2ddecbb f03009f3&lt;BR /&gt;4339fa02 af333133 300d0609 2a864886 f70d0101 0b050003 82010100 5e945649&lt;BR /&gt;dd8e2d65 f5c13651 b603e3da 9e7319f2 1f59ab58 7e6c2605 2cfa81d7 5c231722&lt;BR /&gt;2c3793f7 86ec85e6 b0a3fd1f e232a845 6fe1d9fb b9afd270 a0324265 bf84fe16&lt;BR /&gt;2a8f3fc5 a6d6a393 7d43e974 21913528 f463e92e edf7f55c 7f4b9ab5 20e90abd&lt;BR /&gt;e045100c 14949a5d a5e34b91 e8249b46 4065f422 72cd99f8 8811f5f3 7fe63382&lt;BR /&gt;e6a8c57e fed008e2 25580871 68e6cda2 e614de4e 52242dfd e5791353 e75e2f2d&lt;BR /&gt;4d1b6d40 15522bf7 87897812 816ed94d aa2d78d4 c22c3d08 5f87919e 1f0eb0de&lt;BR /&gt;30526486 89aa9d66 9c0e760c 80f274d8 2af8b83a ced7d60f 11be6bab 14f5bd41&lt;BR /&gt;a0226389 f1ba0f6f 2963662d 3fac8c72 c5fbc7e4 d40ff23b 4f8c29c7&lt;BR /&gt;quit&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 192.168.83.0 255.255.255.0 outside&lt;BR /&gt;ssh 192.168.90.0 255.255.255.0 inside&lt;BR /&gt;ssh timeout 30&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;username spawar password $sha512$5000$HNaO3pmjIzQfSi53n/iLgA==$doLniCACelb8m3E2XJUKGQ== pbkdf2 privilege 15&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;no tcp-inspection&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect dns preset_dns_map&lt;BR /&gt;inspect ftp&lt;BR /&gt;inspect h323 h225&lt;BR /&gt;inspect h323 ras&lt;BR /&gt;inspect rsh&lt;BR /&gt;inspect rtsp&lt;BR /&gt;inspect esmtp&lt;BR /&gt;inspect sqlnet&lt;BR /&gt;inspect skinny&lt;BR /&gt;inspect sunrpc&lt;BR /&gt;inspect xdmcp&lt;BR /&gt;inspect sip&lt;BR /&gt;inspect netbios&lt;BR /&gt;inspect tftp&lt;BR /&gt;inspect ip-options&lt;BR /&gt;inspect icmp&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;call-home reporting anonymous&lt;BR /&gt;Cryptochecksum:d9c5b91cad618c11797edf1251d025f0&lt;BR /&gt;: end&lt;/P&gt;</description>
    <pubDate>Thu, 06 Feb 2020 15:47:42 GMT</pubDate>
    <dc:creator>blake.d.green.mil1</dc:creator>
    <dc:date>2020-02-06T15:47:42Z</dc:date>
    <item>
      <title>ASA will not pass traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025038#M30282</link>
      <description>&lt;P&gt;Good Morning&lt;/P&gt;&lt;P&gt;My team recent received ASA 5506.&amp;nbsp; I'm currently in the process of setting one up for scanning and ran into some issues.&amp;nbsp; I can not get the thing to pass traffic.&amp;nbsp; I can piing the inside&amp;nbsp; from the inside network and outside from the outside network.&amp;nbsp; But I can not ping thru the device.&amp;nbsp; Any help would be grateful.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA Version 9.8(2)&lt;BR /&gt;!&lt;BR /&gt;hostname CGASATEST&lt;BR /&gt;enable password $sha512$5000$fWOBFLyMFFvJ7MXr8LExZg==$HXiVH3aMwKaatZMylDevDw== pbkdf2&lt;BR /&gt;names&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;interface GigabitEthernet1/1&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 192.168.83.45 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.90.185 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_2&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/4&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_3&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/5&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_4&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/6&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_5&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/7&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_6&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/8&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_7&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface Management1/1&lt;BR /&gt;management-only&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface BVI1&lt;BR /&gt;no nameif&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;object network obj_any1&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any2&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any3&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any4&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any5&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any6&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any7&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu inside_2 1500&lt;BR /&gt;mtu inside_3 1500&lt;BR /&gt;mtu inside_4 1500&lt;BR /&gt;mtu inside_5 1500&lt;BR /&gt;mtu inside_6 1500&lt;BR /&gt;mtu inside_7 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;arp rate-limit 16384&lt;BR /&gt;!&lt;BR /&gt;object network obj_any2&lt;BR /&gt;nat (inside_2,outside) dynamic interface&lt;BR /&gt;object network obj_any3&lt;BR /&gt;nat (inside_3,outside) dynamic interface&lt;BR /&gt;object network obj_any4&lt;BR /&gt;nat (inside_4,outside) dynamic interface&lt;BR /&gt;object network obj_any5&lt;BR /&gt;nat (inside_5,outside) dynamic interface&lt;BR /&gt;object network obj_any6&lt;BR /&gt;nat (inside_6,outside) dynamic interface&lt;BR /&gt;object network obj_any7&lt;BR /&gt;nat (inside_7,outside) dynamic interface&lt;BR /&gt;!&lt;BR /&gt;nat (inside,outside) after-auto source dynamic any interface&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 192.168.83.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;timeout conn-holddown 0:00:15&lt;BR /&gt;timeout igp stale-route 0:01:10&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;aaa authentication login-history&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_2&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_3&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_4&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_5&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_6&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_7&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;service sw-reset-button&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto ca trustpoint _SmartCallHome_ServerCA&lt;BR /&gt;no validation-usage&lt;BR /&gt;crl configure&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ca certificate chain _SmartCallHome_ServerCA&lt;BR /&gt;certificate ca 513fb9743870b73440418d30930699ff&lt;BR /&gt;30820538 30820420 a0030201 02021051 3fb97438 70b73440 418d3093 0699ff30&lt;BR /&gt;0d06092a 864886f7 0d01010b 05003081 ca310b30 09060355 04061302 55533117&lt;BR /&gt;30150603 55040a13 0e566572 69536967 6e2c2049 6e632e31 1f301d06 0355040b&lt;BR /&gt;13165665 72695369 676e2054 72757374 204e6574 776f726b 313a3038 06035504&lt;BR /&gt;0b133128 63292032 30303620 56657269 5369676e 2c20496e 632e202d 20466f72&lt;BR /&gt;20617574 686f7269 7a656420 75736520 6f6e6c79 31453043 06035504 03133c56&lt;BR /&gt;65726953 69676e20 436c6173 73203320 5075626c 69632050 72696d61 72792043&lt;BR /&gt;65727469 66696361 74696f6e 20417574 686f7269 7479202d 20473530 1e170d31&lt;BR /&gt;33313033 31303030 3030305a 170d3233 31303330 32333539 35395a30 7e310b30&lt;BR /&gt;09060355 04061302 5553311d 301b0603 55040a13 1453796d 616e7465 6320436f&lt;BR /&gt;72706f72 6174696f 6e311f30 1d060355 040b1316 53796d61 6e746563 20547275&lt;BR /&gt;7374204e 6574776f 726b312f 302d0603 55040313 2653796d 616e7465 6320436c&lt;BR /&gt;61737320 33205365 63757265 20536572 76657220 4341202d 20473430 82012230&lt;BR /&gt;0d06092a 864886f7 0d010101 05000382 010f0030 82010a02 82010100 b2d805ca&lt;BR /&gt;1c742db5 175639c5 4a520996 e84bd80c f1689f9a 422862c3 a530537e 5511825b&lt;BR /&gt;037a0d2f e17904c9 b4967719 81019459 f9bcf77a 9927822d b783dd5a 277fb203&lt;BR /&gt;7a9c5325 e9481f46 4fc89d29 f8be7956 f6f7fdd9 3a68da8b 4b823341 12c3c83c&lt;BR /&gt;ccd6967a 84211a22 04032717 8b1c6861 930f0e51 80331db4 b5ceeb7e d062acee&lt;BR /&gt;b37b0174 ef6935eb cad53da9 ee9798ca 8daa440e 25994a15 96a4ce6d 02541f2a&lt;BR /&gt;6a26e206 3a6348ac b44cd175 9350ff13 2fd6dae1 c618f59f c9255df3 003ade26&lt;BR /&gt;4db42909 cd0f3d23 6f164a81 16fbf283 10c3b8d6 d855323d f1bd0fbd 8c52954a&lt;BR /&gt;16977a52 2163752f 16f9c466 bef5b509 d8ff2700 cd447c6f 4b3fb0f7 02030100&lt;BR /&gt;01a38201 63308201 5f301206 03551d13 0101ff04 08300601 01ff0201 00303006&lt;BR /&gt;03551d1f 04293027 3025a023 a021861f 68747470 3a2f2f73 312e7379 6d63622e&lt;BR /&gt;636f6d2f 70636133 2d67352e 63726c30 0e060355 1d0f0101 ff040403 02010630&lt;BR /&gt;2f06082b 06010505 07010104 23302130 1f06082b 06010505 07300186 13687474&lt;BR /&gt;703a2f2f 73322e73 796d6362 2e636f6d 306b0603 551d2004 64306230 60060a60&lt;BR /&gt;86480186 f8450107 36305230 2606082b 06010505 07020116 1a687474 703a2f2f&lt;BR /&gt;7777772e 73796d61 7574682e 636f6d2f 63707330 2806082b 06010505 07020230&lt;BR /&gt;1c1a1a68 7474703a 2f2f7777 772e7379 6d617574 682e636f 6d2f7270 61302906&lt;BR /&gt;03551d11 04223020 a41e301c 311a3018 06035504 03131153 796d616e 74656350&lt;BR /&gt;4b492d31 2d353334 301d0603 551d0e04 1604145f 60cf6190 55df8443 148a602a&lt;BR /&gt;b2f57af4 4318ef30 1f060355 1d230418 30168014 7fd365a7 c2ddecbb f03009f3&lt;BR /&gt;4339fa02 af333133 300d0609 2a864886 f70d0101 0b050003 82010100 5e945649&lt;BR /&gt;dd8e2d65 f5c13651 b603e3da 9e7319f2 1f59ab58 7e6c2605 2cfa81d7 5c231722&lt;BR /&gt;2c3793f7 86ec85e6 b0a3fd1f e232a845 6fe1d9fb b9afd270 a0324265 bf84fe16&lt;BR /&gt;2a8f3fc5 a6d6a393 7d43e974 21913528 f463e92e edf7f55c 7f4b9ab5 20e90abd&lt;BR /&gt;e045100c 14949a5d a5e34b91 e8249b46 4065f422 72cd99f8 8811f5f3 7fe63382&lt;BR /&gt;e6a8c57e fed008e2 25580871 68e6cda2 e614de4e 52242dfd e5791353 e75e2f2d&lt;BR /&gt;4d1b6d40 15522bf7 87897812 816ed94d aa2d78d4 c22c3d08 5f87919e 1f0eb0de&lt;BR /&gt;30526486 89aa9d66 9c0e760c 80f274d8 2af8b83a ced7d60f 11be6bab 14f5bd41&lt;BR /&gt;a0226389 f1ba0f6f 2963662d 3fac8c72 c5fbc7e4 d40ff23b 4f8c29c7&lt;BR /&gt;quit&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 192.168.83.0 255.255.255.0 outside&lt;BR /&gt;ssh 192.168.90.0 255.255.255.0 inside&lt;BR /&gt;ssh timeout 30&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;username spawar password $sha512$5000$HNaO3pmjIzQfSi53n/iLgA==$doLniCACelb8m3E2XJUKGQ== pbkdf2 privilege 15&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;no tcp-inspection&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect dns preset_dns_map&lt;BR /&gt;inspect ftp&lt;BR /&gt;inspect h323 h225&lt;BR /&gt;inspect h323 ras&lt;BR /&gt;inspect rsh&lt;BR /&gt;inspect rtsp&lt;BR /&gt;inspect esmtp&lt;BR /&gt;inspect sqlnet&lt;BR /&gt;inspect skinny&lt;BR /&gt;inspect sunrpc&lt;BR /&gt;inspect xdmcp&lt;BR /&gt;inspect sip&lt;BR /&gt;inspect netbios&lt;BR /&gt;inspect tftp&lt;BR /&gt;inspect ip-options&lt;BR /&gt;inspect icmp&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;call-home reporting anonymous&lt;BR /&gt;Cryptochecksum:d9c5b91cad618c11797edf1251d025f0&lt;BR /&gt;: end&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 15:47:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025038#M30282</guid>
      <dc:creator>blake.d.green.mil1</dc:creator>
      <dc:date>2020-02-06T15:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA will not pass traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025049#M30295</link>
      <description>Hi,&lt;BR /&gt;You are inspecting icmp so I'd expect you to be able to recieve a response to a ping and you are natting behind the outside interface.&lt;BR /&gt;What are you pinging from the inside of the ASA?&lt;BR /&gt;What ever device you are pinging to that have a route to your ASA's outside interface?&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Thu, 06 Feb 2020 15:58:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025049#M30295</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-02-06T15:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA will not pass traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025086#M30315</link>
      <description>&lt;P&gt;RJI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First thanks for you imput.&amp;nbsp; But I trying to ping from the outside(192.168.83.0 network to a rtr sitting off the insides(192.168.90.0 network) interface.&amp;nbsp; But unable to ping or even ssh to that device. Yes the device has a route&amp;nbsp;&lt;SPAN&gt;ASA's outside interface&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 16:39:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025086#M30315</guid>
      <dc:creator>blake.d.green.mil1</dc:creator>
      <dc:date>2020-02-06T16:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA will not pass traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025094#M30330</link>
      <description>&lt;P&gt;Ok, so if you are attempting to ping from outside to inside then that currently won't work until you define an ACL inbound on the outside interface permitting the traffic. You will also probably need a static NAT.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 16:48:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025094#M30330</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-02-06T16:48:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA will not pass traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025196#M30343</link>
      <description>Can you please help with the last recommendations&lt;BR /&gt;&lt;BR /&gt;here what I created&lt;BR /&gt;&lt;BR /&gt;access-list outside_inbound extended permit icmp any any log&lt;BR /&gt;&lt;BR /&gt;nat (inside,outside) after-auto source static any interface&lt;BR /&gt;access-group outside_inbound in interface outside?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 06 Feb 2020 20:11:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025196#M30343</guid>
      <dc:creator>blake.d.green.mil1</dc:creator>
      <dc:date>2020-02-06T20:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA will not pass traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025203#M30356</link>
      <description>&lt;P&gt;That won't work for accesing the inside network from the outside, you'll need a 121 static nat, e.g:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;object network SRV1&lt;BR /&gt; host 192.168.90.100&lt;BR /&gt; nat (inside,outside) static 192.168.83.100&lt;BR /&gt;&lt;BR /&gt;access-list outside_inbound permit icmp any host 192.168.90.100&lt;BR /&gt;&lt;BR /&gt;access-group outside_inbound in interface outside&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 21:41:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025203#M30356</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-02-06T21:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA will not pass traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025258#M30371</link>
      <description>still no joy&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;hostname CGASATEST&lt;BR /&gt;enable password $sha512$5000$fWOBFLyMFFvJ7MXr8LExZg==$HXiVH3aMwKaatZMylDevDw== pbkdf2&lt;BR /&gt;names&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/1&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 192.168.83.45 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.90.185 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_2&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/4&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_3&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/5&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_4&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/6&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_5&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/7&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_6&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/8&lt;BR /&gt;bridge-group 1&lt;BR /&gt;nameif inside_7&lt;BR /&gt;security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface Management1/1&lt;BR /&gt;management-only&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface BVI1&lt;BR /&gt;no nameif&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;object network obj_any1&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any2&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any3&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any4&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any5&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any6&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj_any7&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network SRV1&lt;BR /&gt;host 192.168.90.100&lt;BR /&gt;access-list outside_inbound extended permit icmp any host 192.168.83.100&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu inside_2 1500&lt;BR /&gt;mtu inside_3 1500&lt;BR /&gt;mtu inside_4 1500&lt;BR /&gt;mtu inside_5 1500&lt;BR /&gt;mtu inside_6 1500&lt;BR /&gt;mtu inside_7 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;arp rate-limit 16384&lt;BR /&gt;!&lt;BR /&gt;object network obj_any2&lt;BR /&gt;nat (inside_2,outside) dynamic interface&lt;BR /&gt;object network obj_any3&lt;BR /&gt;nat (inside_3,outside) dynamic interface&lt;BR /&gt;object network obj_any4&lt;BR /&gt;nat (inside_4,outside) dynamic interface&lt;BR /&gt;object network obj_any5&lt;BR /&gt;nat (inside_5,outside) dynamic interface&lt;BR /&gt;object network obj_any6&lt;BR /&gt;nat (inside_6,outside) dynamic interface&lt;BR /&gt;object network obj_any7&lt;BR /&gt;nat (inside_7,outside) dynamic interface&lt;BR /&gt;object network SRV1&lt;BR /&gt;nat (inside,outside) static 192.168.83.100&lt;BR /&gt;access-group outside_inbound in interface outside&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 192.168.83.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;timeout conn-holddown 0:00:15&lt;BR /&gt;timeout igp stale-route 0:01:10&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;aaa authentication login-history&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_2&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_3&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_4&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_5&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_6&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside_7&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;service sw-reset-button&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto ca trustpoint _SmartCallHome_ServerCA&lt;BR /&gt;no validation-usage&lt;BR /&gt;crl configure&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ca certificate chain _SmartCallHome_ServerCA&lt;BR /&gt;certificate ca 513fb9743870b73440418d30930699ff&lt;BR /&gt;30820538 30820420 a0030201 02021051 3fb97438 70b73440 418d3093 0699ff30&lt;BR /&gt;0d06092a 864886f7 0d01010b 05003081 ca310b30 09060355 04061302 55533117&lt;BR /&gt;30150603 55040a13 0e566572 69536967 6e2c2049 6e632e31 1f301d06 0355040b&lt;BR /&gt;13165665 72695369 676e2054 72757374 204e6574 776f726b 313a3038 06035504&lt;BR /&gt;0b133128 63292032 30303620 56657269 5369676e 2c20496e 632e202d 20466f72&lt;BR /&gt;20617574 686f7269 7a656420 75736520 6f6e6c79 31453043 06035504 03133c56&lt;BR /&gt;65726953 69676e20 436c6173 73203320 5075626c 69632050 72696d61 72792043&lt;BR /&gt;65727469 66696361 74696f6e 20417574 686f7269 7479202d 20473530 1e170d31&lt;BR /&gt;33313033 31303030 3030305a 170d3233 31303330 32333539 35395a30 7e310b30&lt;BR /&gt;09060355 04061302 5553311d 301b0603 55040a13 1453796d 616e7465 6320436f&lt;BR /&gt;72706f72 6174696f 6e311f30 1d060355 040b1316 53796d61 6e746563 20547275&lt;BR /&gt;7374204e 6574776f 726b312f 302d0603 55040313 2653796d 616e7465 6320436c&lt;BR /&gt;61737320 33205365 63757265 20536572 76657220 4341202d 20473430 82012230&lt;BR /&gt;0d06092a 864886f7 0d010101 05000382 010f0030 82010a02 82010100 b2d805ca&lt;BR /&gt;1c742db5 175639c5 4a520996 e84bd80c f1689f9a 422862c3 a530537e 5511825b&lt;BR /&gt;037a0d2f e17904c9 b4967719 81019459 f9bcf77a 9927822d b783dd5a 277fb203&lt;BR /&gt;7a9c5325 e9481f46 4fc89d29 f8be7956 f6f7fdd9 3a68da8b 4b823341 12c3c83c&lt;BR /&gt;ccd6967a 84211a22 04032717 8b1c6861 930f0e51 80331db4 b5ceeb7e d062acee&lt;BR /&gt;b37b0174 ef6935eb cad53da9 ee9798ca 8daa440e 25994a15 96a4ce6d 02541f2a&lt;BR /&gt;6a26e206 3a6348ac b44cd175 9350ff13 2fd6dae1 c618f59f c9255df3 003ade26&lt;BR /&gt;4db42909 cd0f3d23 6f164a81 16fbf283 10c3b8d6 d855323d f1bd0fbd 8c52954a&lt;BR /&gt;16977a52 2163752f 16f9c466 bef5b509 d8ff2700 cd447c6f 4b3fb0f7 02030100&lt;BR /&gt;01a38201 63308201 5f301206 03551d13 0101ff04 08300601 01ff0201 00303006&lt;BR /&gt;03551d1f 04293027 3025a023 a021861f 68747470 3a2f2f73 312e7379 6d63622e&lt;BR /&gt;636f6d2f 70636133 2d67352e 63726c30 0e060355 1d0f0101 ff040403 02010630&lt;BR /&gt;2f06082b 06010505 07010104 23302130 1f06082b 06010505 07300186 13687474&lt;BR /&gt;703a2f2f 73322e73 796d6362 2e636f6d 306b0603 551d2004 64306230 60060a60&lt;BR /&gt;86480186 f8450107 36305230 2606082b 06010505 07020116 1a687474 703a2f2f&lt;BR /&gt;7777772e 73796d61 7574682e 636f6d2f 63707330 2806082b 06010505 07020230&lt;BR /&gt;1c1a1a68 7474703a 2f2f7777 772e7379 6d617574 682e636f 6d2f7270 61302906&lt;BR /&gt;03551d11 04223020 a41e301c 311a3018 06035504 03131153 796d616e 74656350&lt;BR /&gt;4b492d31 2d353334 301d0603 551d0e04 1604145f 60cf6190 55df8443 148a602a&lt;BR /&gt;b2f57af4 4318ef30 1f060355 1d230418 30168014 7fd365a7 c2ddecbb f03009f3&lt;BR /&gt;4339fa02 af333133 300d0609 2a864886 f70d0101 0b050003 82010100 5e945649&lt;BR /&gt;dd8e2d65 f5c13651 b603e3da 9e7319f2 1f59ab58 7e6c2605 2cfa81d7 5c231722&lt;BR /&gt;2c3793f7 86ec85e6 b0a3fd1f e232a845 6fe1d9fb b9afd270 a0324265 bf84fe16&lt;BR /&gt;2a8f3fc5 a6d6a393 7d43e974 21913528 f463e92e edf7f55c 7f4b9ab5 20e90abd&lt;BR /&gt;e045100c 14949a5d a5e34b91 e8249b46 4065f422 72cd99f8 8811f5f3 7fe63382&lt;BR /&gt;e6a8c57e fed008e2 25580871 68e6cda2 e614de4e 52242dfd e5791353 e75e2f2d&lt;BR /&gt;4d1b6d40 15522bf7 87897812 816ed94d aa2d78d4 c22c3d08 5f87919e 1f0eb0de&lt;BR /&gt;30526486 89aa9d66 9c0e760c 80f274d8 2af8b83a ced7d60f 11be6bab 14f5bd41&lt;BR /&gt;a0226389 f1ba0f6f 2963662d 3fac8c72 c5fbc7e4 d40ff23b 4f8c29c7&lt;BR /&gt;quit&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 192.168.83.0 255.255.255.0 outside&lt;BR /&gt;ssh 192.168.90.0 255.255.255.0 inside&lt;BR /&gt;ssh timeout 30&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;BR /&gt;&lt;BR /&gt;dhcpd auto_config outside&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;username spawar password $sha512$5000$HNaO3pmjIzQfSi53n/iLgA==$doLniCACelb8m3E2XJUKGQ== pbkdf2 privilege 15&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;no tcp-inspection&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect dns preset_dns_map&lt;BR /&gt;inspect ftp&lt;BR /&gt;inspect h323 h225&lt;BR /&gt;inspect h323 ras&lt;BR /&gt;inspect rsh&lt;BR /&gt;inspect rtsp&lt;BR /&gt;inspect esmtp&lt;BR /&gt;inspect sqlnet&lt;BR /&gt;inspect skinny&lt;BR /&gt;inspect sunrpc&lt;BR /&gt;inspect xdmcp&lt;BR /&gt;inspect sip&lt;BR /&gt;inspect netbios&lt;BR /&gt;inspect tftp&lt;BR /&gt;inspect ip-options&lt;BR /&gt;inspect icmp&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;call-home reporting anonymous&lt;BR /&gt;Cryptochecksum:da77ea1e7cb7812c77a5f1842b94ab4c&lt;BR /&gt;: end&lt;BR /&gt;&lt;BR /&gt;?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 06 Feb 2020 21:27:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025258#M30371</guid>
      <dc:creator>blake.d.green.mil1</dc:creator>
      <dc:date>2020-02-06T21:27:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA will not pass traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025266#M30379</link>
      <description>I gave you the wrong example on the ACL, modify the destination to be the real IP address. E.g. "access-list outside_inbound permit icmp any host 192.168.90.100" - bear in mind this is an example, change 192.168.90.100 to be the real IP address of the host on the inside of the network. Connect to it using from the outside using the nat ip address - 192.168.83.100 &amp;lt; this address could be changed if required.&lt;BR /&gt;&lt;BR /&gt;Also confirm your existing nat rules are not above this new nat rule, provide the output of "show nat detail" if needs be.&lt;BR /&gt;&lt;BR /&gt;If this is an internal firewall segmenting traffic inside your network, you could of course just route traffic and remove all nat.</description>
      <pubDate>Thu, 06 Feb 2020 21:41:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025266#M30379</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-02-06T21:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA will not pass traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025299#M30391</link>
      <description>&lt;DIV&gt;Good news I was able to go back and make some correction and I can now go from outside to inside.&amp;nbsp; my next issues is now I cant hit me server vlan on&amp;nbsp; my router .&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;output listed below&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;ASA Version 9.8(2)&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;hostname CGASATEST&lt;/DIV&gt;&lt;DIV&gt;enable password $sha512$5000$fWOBFLyMFFvJ7MXr8LExZg==$HXiVH3aMwKaatZMylDevDw== pbkdf2&lt;/DIV&gt;&lt;DIV&gt;names&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet1/1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;nameif outside&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;security-level 0&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;ip address 192.168.83.45 255.255.255.0&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet1/2&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;nameif inside&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;security-level 100&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;ip address 192.168.90.185 255.255.255.0&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet1/3&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;bridge-group 1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;nameif inside_2&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;security-level 100&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet1/4&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;bridge-group 1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;nameif inside_3&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;security-level 100&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet1/5&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;bridge-group 1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;nameif inside_4&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;security-level 100&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet1/6&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;bridge-group 1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;nameif inside_5&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;security-level 100&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet1/7&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;bridge-group 1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;nameif inside_6&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;security-level 100&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet1/8&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;bridge-group 1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;nameif inside_7&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;security-level 100&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface Management1/1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;management-only&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;no nameif&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;no security-level&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;no ip address&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface BVI1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;no nameif&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;security-level 100&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;ip address 192.168.1.1 255.255.255.0&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;ftp mode passive&lt;/DIV&gt;&lt;DIV&gt;same-security-traffic permit inter-interface&lt;/DIV&gt;&lt;DIV&gt;object network obj_any1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/DIV&gt;&lt;DIV&gt;object network obj_any2&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/DIV&gt;&lt;DIV&gt;object network obj_any3&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/DIV&gt;&lt;DIV&gt;object network obj_any4&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/DIV&gt;&lt;DIV&gt;object network obj_any5&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/DIV&gt;&lt;DIV&gt;object network obj_any6&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/DIV&gt;&lt;DIV&gt;object network obj_any7&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/DIV&gt;&lt;DIV&gt;object network inside-subnet&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;subnet 192.168.83.0 255.255.255.0&lt;/DIV&gt;&lt;DIV&gt;object network outside_IP&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;host 10.19.83.45&lt;/DIV&gt;&lt;DIV&gt;access-list inside_out_acl extended permit ip any any&lt;/DIV&gt;&lt;DIV&gt;access-list inside_out_acl extended permit icmp any any&lt;/DIV&gt;&lt;DIV&gt;pager lines 24&lt;/DIV&gt;&lt;DIV&gt;logging asdm informational&lt;/DIV&gt;&lt;DIV&gt;mtu outside 1500&lt;/DIV&gt;&lt;DIV&gt;mtu inside 1500&lt;/DIV&gt;&lt;DIV&gt;mtu inside_2 1500&lt;/DIV&gt;&lt;DIV&gt;mtu inside_3 1500&lt;/DIV&gt;&lt;DIV&gt;mtu inside_4 1500&lt;/DIV&gt;&lt;DIV&gt;mtu inside_5 1500&lt;/DIV&gt;&lt;DIV&gt;mtu inside_6 1500&lt;/DIV&gt;&lt;DIV&gt;mtu inside_7 1500&lt;/DIV&gt;&lt;DIV&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/DIV&gt;&lt;DIV&gt;no asdm history enable&lt;/DIV&gt;&lt;DIV&gt;arp timeout 14400&lt;/DIV&gt;&lt;DIV&gt;no arp permit-nonconnected&lt;/DIV&gt;&lt;DIV&gt;arp rate-limit 16384&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;object network obj_any2&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;nat (inside_2,outside) dynamic interface&lt;/DIV&gt;&lt;DIV&gt;object network obj_any3&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;nat (inside_3,outside) dynamic interface&lt;/DIV&gt;&lt;DIV&gt;object network obj_any4&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;nat (inside_4,outside) dynamic interface&lt;/DIV&gt;&lt;DIV&gt;object network obj_any5&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;nat (inside_5,outside) dynamic interface&lt;/DIV&gt;&lt;DIV&gt;object network obj_any6&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;nat (inside_6,outside) dynamic interface&lt;/DIV&gt;&lt;DIV&gt;object network obj_any7&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;nat (inside_7,outside) dynamic interface&lt;/DIV&gt;&lt;DIV&gt;object network inside-subnet&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;/DIV&gt;&lt;DIV&gt;access-group inside_out_acl in interface outside&lt;/DIV&gt;&lt;DIV&gt;access-group inside_out_acl out interface outside&lt;/DIV&gt;&lt;DIV&gt;route outside 0.0.0.0 0.0.0.0 192.168.83.1 1&lt;/DIV&gt;&lt;DIV&gt;timeout xlate 3:00:00&lt;/DIV&gt;&lt;DIV&gt;timeout pat-xlate 0:00:30&lt;/DIV&gt;&lt;DIV&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;/DIV&gt;&lt;DIV&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/DIV&gt;&lt;DIV&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/DIV&gt;&lt;DIV&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/DIV&gt;&lt;DIV&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/DIV&gt;&lt;DIV&gt;timeout floating-conn 0:00:00&lt;/DIV&gt;&lt;DIV&gt;timeout conn-holddown 0:00:15&lt;/DIV&gt;&lt;DIV&gt;timeout igp stale-route 0:01:10&lt;/DIV&gt;&lt;DIV&gt;user-identity default-domain LOCAL&lt;/DIV&gt;&lt;DIV&gt;aaa authentication ssh console LOCAL&lt;/DIV&gt;&lt;DIV&gt;aaa authentication login-history&lt;/DIV&gt;&lt;DIV&gt;http server enable&lt;/DIV&gt;&lt;DIV&gt;http 192.168.1.0 255.255.255.0 inside_2&lt;/DIV&gt;&lt;DIV&gt;http 192.168.1.0 255.255.255.0 inside_3&lt;/DIV&gt;&lt;DIV&gt;http 192.168.1.0 255.255.255.0 inside_4&lt;/DIV&gt;&lt;DIV&gt;http 192.168.1.0 255.255.255.0 inside_5&lt;/DIV&gt;&lt;DIV&gt;http 192.168.1.0 255.255.255.0 inside_6&lt;/DIV&gt;&lt;DIV&gt;http 192.168.1.0 255.255.255.0 inside_7&lt;/DIV&gt;&lt;DIV&gt;no snmp-server location&lt;/DIV&gt;&lt;DIV&gt;no snmp-server contact&lt;/DIV&gt;&lt;DIV&gt;service sw-reset-button&lt;/DIV&gt;&lt;DIV&gt;crypto ipsec security-association pmtu-aging infinite&lt;/DIV&gt;&lt;DIV&gt;crypto ca trustpoint _SmartCallHome_ServerCA&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;no validation-usage&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;crl configure&lt;/DIV&gt;&lt;DIV&gt;crypto ca trustpool policy&lt;/DIV&gt;&lt;DIV&gt;crypto ca certificate chain _SmartCallHome_ServerCA&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;certificate ca 513fb9743870b73440418d30930699ff&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 30820538 30820420 a0030201 02021051 3fb97438 70b73440 418d3093 0699ff30&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 0d06092a 864886f7 0d01010b 05003081 ca310b30 09060355 04061302 55533117&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 30150603 55040a13 0e566572 69536967 6e2c2049 6e632e31 1f301d06 0355040b&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 13165665 72695369 676e2054 72757374 204e6574 776f726b 313a3038 06035504&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 0b133128 63292032 30303620 56657269 5369676e 2c20496e 632e202d 20466f72&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 20617574 686f7269 7a656420 75736520 6f6e6c79 31453043 06035504 03133c56&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 65726953 69676e20 436c6173 73203320 5075626c 69632050 72696d61 72792043&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 65727469 66696361 74696f6e 20417574 686f7269 7479202d 20473530 1e170d31&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 33313033 31303030 3030305a 170d3233 31303330 32333539 35395a30 7e310b30&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 09060355 04061302 5553311d 301b0603 55040a13 1453796d 616e7465 6320436f&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 72706f72 6174696f 6e311f30 1d060355 040b1316 53796d61 6e746563 20547275&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 7374204e 6574776f 726b312f 302d0603 55040313 2653796d 616e7465 6320436c&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 61737320 33205365 63757265 20536572 76657220 4341202d 20473430 82012230&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 0d06092a 864886f7 0d010101 05000382 010f0030 82010a02 82010100 b2d805ca&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 1c742db5 175639c5 4a520996 e84bd80c f1689f9a 422862c3 a530537e 5511825b&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 037a0d2f e17904c9 b4967719 81019459 f9bcf77a 9927822d b783dd5a 277fb203&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 7a9c5325 e9481f46 4fc89d29 f8be7956 f6f7fdd9 3a68da8b 4b823341 12c3c83c&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; ccd6967a 84211a22 04032717 8b1c6861 930f0e51 80331db4 b5ceeb7e d062acee&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; b37b0174 ef6935eb cad53da9 ee9798ca 8daa440e 25994a15 96a4ce6d 02541f2a&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 6a26e206 3a6348ac b44cd175 9350ff13 2fd6dae1 c618f59f c9255df3 003ade26&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 4db42909 cd0f3d23 6f164a81 16fbf283 10c3b8d6 d855323d f1bd0fbd 8c52954a&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 16977a52 2163752f 16f9c466 bef5b509 d8ff2700 cd447c6f 4b3fb0f7 02030100&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 01a38201 63308201 5f301206 03551d13 0101ff04 08300601 01ff0201 00303006&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 03551d1f 04293027 3025a023 a021861f 68747470 3a2f2f73 312e7379 6d63622e&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 636f6d2f 70636133 2d67352e 63726c30 0e060355 1d0f0101 ff040403 02010630&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 2f06082b 06010505 07010104 23302130 1f06082b 06010505 07300186 13687474&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 703a2f2f 73322e73 796d6362 2e636f6d 306b0603 551d2004 64306230 60060a60&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 86480186 f8450107 36305230 2606082b 06010505 07020116 1a687474 703a2f2f&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 7777772e 73796d61 7574682e 636f6d2f 63707330 2806082b 06010505 07020230&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 1c1a1a68 7474703a 2f2f7777 772e7379 6d617574 682e636f 6d2f7270 61302906&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 03551d11 04223020 a41e301c 311a3018 06035504 03131153 796d616e 74656350&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 4b492d31 2d353334 301d0603 551d0e04 1604145f 60cf6190 55df8443 148a602a&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; b2f57af4 4318ef30 1f060355 1d230418 30168014 7fd365a7 c2ddecbb f03009f3&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 4339fa02 af333133 300d0609 2a864886 f70d0101 0b050003 82010100 5e945649&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; dd8e2d65 f5c13651 b603e3da 9e7319f2 1f59ab58 7e6c2605 2cfa81d7 5c231722&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 2c3793f7 86ec85e6 b0a3fd1f e232a845 6fe1d9fb b9afd270 a0324265 bf84fe16&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 2a8f3fc5 a6d6a393 7d43e974 21913528 f463e92e edf7f55c 7f4b9ab5 20e90abd&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; e045100c 14949a5d a5e34b91 e8249b46 4065f422 72cd99f8 8811f5f3 7fe63382&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; e6a8c57e fed008e2 25580871 68e6cda2 e614de4e 52242dfd e5791353 e75e2f2d&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 4d1b6d40 15522bf7 87897812 816ed94d aa2d78d4 c22c3d08 5f87919e 1f0eb0de&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; 30526486 89aa9d66 9c0e760c 80f274d8 2af8b83a ced7d60f 11be6bab 14f5bd41&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; a0226389 f1ba0f6f 2963662d 3fac8c72 c5fbc7e4 d40ff23b 4f8c29c7&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; quit&lt;/DIV&gt;&lt;DIV&gt;telnet timeout 5&lt;/DIV&gt;&lt;DIV&gt;ssh stricthostkeycheck&lt;/DIV&gt;&lt;DIV&gt;ssh 192.168.83.0 255.255.255.0 outside&lt;/DIV&gt;&lt;DIV&gt;ssh 192.168.90.0 255.255.255.0 inside&lt;/DIV&gt;&lt;DIV&gt;ssh timeout 30&lt;/DIV&gt;&lt;DIV&gt;ssh version 2&lt;/DIV&gt;&lt;DIV&gt;ssh key-exchange group dh-group1-sha1&lt;/DIV&gt;&lt;DIV&gt;console timeout 0&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;dhcpd auto_config outside&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;threat-detection basic-threat&lt;/DIV&gt;&lt;DIV&gt;threat-detection statistics access-list&lt;/DIV&gt;&lt;DIV&gt;no threat-detection statistics tcp-intercept&lt;/DIV&gt;&lt;DIV&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/DIV&gt;&lt;DIV&gt;username spawar password $sha512$5000$HNaO3pmjIzQfSi53n/iLgA==$doLniCACelb8m3E2XJUKGQ== pbkdf2 privilege 15&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;class-map inspection_default&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;match default-inspection-traffic&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;policy-map type inspect dns preset_dns_map&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;parameters&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; message-length maximum client auto&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; message-length maximum 512&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; no tcp-inspection&lt;/DIV&gt;&lt;DIV&gt;policy-map global_policy&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;class inspection_default&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect ftp&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect h323 h225&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect h323 ras&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect rsh&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect rtsp&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect esmtp&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect sqlnet&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect skinny&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect sunrpc&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect xdmcp&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect sip&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect netbios&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect tftp&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect ip-options&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; inspect icmp&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;service-policy global_policy global&lt;/DIV&gt;&lt;DIV&gt;prompt hostname context&lt;/DIV&gt;&lt;DIV&gt;call-home reporting anonymous&lt;/DIV&gt;&lt;DIV&gt;Cryptochecksum:bb53ef66da7015a5afd23b14d5867193&lt;/DIV&gt;&lt;DIV&gt;: end&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;and here is my router output&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet0/0/0&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;description Connection to Rack 82 Switch&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;ip address 192.168.90.186 255.255.255.252&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;negotiation auto&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet0/0/1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;no ip address&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;shutdown&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;negotiation auto&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet0/1/0&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;switchport access vlan 30&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;switchport mode access&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet0/1/1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;switchport access vlan 40&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;switchport mode access&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet0/1/2&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;switchport access vlan 40&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;switchport mode access&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet0/1/3&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;switchport access vlan 40&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;switchport mode access&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet0/1/4&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;switchport access vlan 40&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;switchport mode access&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet0/1/5&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;switchport access vlan 40&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;switchport mode access&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet0/1/6&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet0/1/7&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface GigabitEthernet0&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;vrf forwarding Mgmt-intf&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;no ip address&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;shutdown&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;negotiation auto&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface Vlan1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;no ip address&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface Vlan30&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;description Server VLAN&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;ip address 192.168.90.161 255.255.255.240&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;interface Vlan40&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;description Workstations VLAN&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;ip address 192.168.90.129 255.255.255.224&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;router ospf 1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;network 192.168.90.128 0.0.0.31 area 0&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;network 192.168.90.160 0.0.0.15 area 0&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;network 192.168.90.184 0.0.0.3 area 0&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;​&lt;/DIV&gt;</description>
      <pubDate>Thu, 06 Feb 2020 22:33:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025299#M30391</guid>
      <dc:creator>blake.d.green.mil1</dc:creator>
      <dc:date>2020-02-06T22:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA will not pass traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025307#M30403</link>
      <description>So the ASA is connected to the router's Gi0/0/0 interface?&lt;BR /&gt;On the ASA you've defined the internal network as 192.168.90.0/24 but then on the router the Gi0/0/0 subnet mask is /30 and then the VLANs are also segmented in to a /28 and /29 within the 192.168.90.0/24 subnet.&lt;BR /&gt;&lt;BR /&gt;Change the Gi0/0/0 subnet mask to /24 to match the ASA and then change the VLANs to something else, e.g 192.168.91.0/24 and 192.168.92.0/24. Define a static route on the ASA for those networks pointing to the Gi0/0/0 IP address of the router.</description>
      <pubDate>Thu, 06 Feb 2020 22:48:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-will-not-pass-traffic/m-p/4025307#M30403</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-02-06T22:48:24Z</dc:date>
    </item>
  </channel>
</rss>

