<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ASA CX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360743#M310186</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the CX to filter URLs, however I am having issues with the updates. It seems that the CX module can't access the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I configure the CX/management interface of the ASA to reach the internet so that it can perform updates?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ash&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 02:56:50 GMT</pubDate>
    <dc:creator>Ashley Sahonta</dc:creator>
    <dc:date>2019-03-12T02:56:50Z</dc:date>
    <item>
      <title>Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360743#M310186</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the CX to filter URLs, however I am having issues with the updates. It seems that the CX module can't access the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I configure the CX/management interface of the ASA to reach the internet so that it can perform updates?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ash&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:56:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360743#M310186</guid>
      <dc:creator>Ashley Sahonta</dc:creator>
      <dc:date>2019-03-12T02:56:50Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360744#M310188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The CX uses the ASA management interface (on the 5512X through 5555X). You need a default route for the management interface on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the CX Quick Start Guide &lt;A href="http://www.cisco.com/en/US/docs/security/asa/quick_start/cx/cx_qsg.html#wp49902"&gt;here&lt;/A&gt; for more details.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 16:01:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360744#M310188</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-10-28T16:01:12Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360745#M310189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a default route for the management network, however it does not get out to the internet..?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 16:15:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360745#M310189</guid>
      <dc:creator>Ashley Sahonta</dc:creator>
      <dc:date>2013-10-28T16:15:34Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360746#M310192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The route doesn't need to point to the Internet per se but traffic sourced from the ASA / CX management interface to that gateway must be able to reach the Internet and get replies back. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A quick test is, from the ASA: "ping management 8.8.8.8".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 17:08:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360746#M310192</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-10-28T17:08:31Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360747#M310194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, I get that the gateway must reach the internet, but it's not currently. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know if there are any particular steps required to allow the management access to get internet access. When I run the packet tracer I get the following output -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;myvpn# packet-tracer input management icmp 10.0.125.2 8 0 4.2.2.2 detailed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: mgmt-deny-all&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt; Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt; in&amp;nbsp; id=0x7fff9f352740, priority=200, domain=mgmt-lockdown, deny=true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=2, user_data=0x0, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0 dscp=0x0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input_ifc=management, output_ifc=any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: management&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 17:18:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360747#M310194</guid>
      <dc:creator>Ashley Sahonta</dc:creator>
      <dc:date>2013-10-28T17:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360748#M310196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On my working CX, I see I have a default route set on the cx itself:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;seclabcx&amp;gt;show route&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Kernel IP routing table&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gateway&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Genmask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Flags Metric Ref&amp;nbsp;&amp;nbsp;&amp;nbsp; Use Iface&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;192.168.100.0&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; U&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 eth0&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;127.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; U&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 cplane&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.100.254 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UG&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 eth0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe this is done during the CX setup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 17:46:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360748#M310196</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-10-28T17:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360749#M310198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the default route on the CX set to our core switch, as stated on the setup guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does your default route point to the ASA management interface?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 09:01:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360749#M310198</guid>
      <dc:creator>Ashley Sahonta</dc:creator>
      <dc:date>2013-10-29T09:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360750#M310200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My default route for the CX is the core switch's L3 interface on the VLAN that the ASA / CX module management interface is assigned to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;seclabcx&amp;gt;show int&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;SNIP&gt;&lt;/SNIP&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt; eth0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Link encap:Ethernet&amp;nbsp; HWaddr 50:3D:E5:9E:38:70&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inet addr:192.168.100.6&amp;nbsp; Bcast:192.168.100.255&amp;nbsp; Mask:255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;SECLABCORE#sh mac address-table | i 3870&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; 100&amp;nbsp;&amp;nbsp;&amp;nbsp; 503d.e59e.3870&amp;nbsp;&amp;nbsp; dynamic ip,other&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; GigabitEthernet2/5&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;SECLABCORE#&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;SECLABCORE#sh run int gi2/5&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Building configuration...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Current configuration : 146 bytes&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;interface GigabitEthernet2/5&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; description ASA-CX module&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; switchport access vlan 100&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; logging event link-status&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; logging event trunk-status&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;end&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier;"&gt;SECLABCORE#show ip int br | i 100.254&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Vlan100&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.100.254 YES NVRAM&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;SECLABCORE#&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 15:58:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360750#M310200</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-10-29T15:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360751#M310203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmmmm. I have no idea why this isn't working then. Are you able to ping from the switch out the internet if you source the ping from VLAN 100?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 16:07:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360751#M310203</guid>
      <dc:creator>Ashley Sahonta</dc:creator>
      <dc:date>2013-10-29T16:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360752#M310205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I am able to do that:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;SECLABCORE#ping 8.8.8.8 source vlan 100&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Type escape sequence to abort.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Packet sent with a source address of 192.168.100.254 &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;!!!!!&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 20/20/20 ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;SECLABCORE#&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you potentially look at your firewall logs or packet capture to see if the traffic is seen when originated from your CX?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 16:11:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360752#M310205</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-10-29T16:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360753#M310206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just did a capture on the management interface and it shows as 0 whilst running continuous pings from the CX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture CX type raw-data trace interface management [Capturing - 0 bytes]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 16:27:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360753#M310206</guid>
      <dc:creator>Ashley Sahonta</dc:creator>
      <dc:date>2013-10-29T16:27:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360754#M310208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually I was thinking of looking for traffic from the CX while it transits the firewall inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your setup is like mine the flow is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA CX interface = physically the ASA's m0/0 but logically separate thus a capture from the ASA won't see it&lt;/P&gt;&lt;P&gt;to&lt;/P&gt;&lt;P&gt;core switch SVI = default gateway of CX&lt;/P&gt;&lt;P&gt;to&lt;/P&gt;&lt;P&gt;ASA Inside interface = default route for Interrnet-bound traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's on that Inside interface that I would capture to troubleshoot and isolate the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Re the NAT, on my lab firewall it's a simple dynamic NAT using the outside interface address:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;object network Inside-Any-Hide&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; subnet 0.0.0.0 0.0.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; description Inside-PAT-Hide &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;object network Inside-Any-Hide&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; nat (transit-inside,outside) dynamic interface&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 16:48:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360754#M310208</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-10-29T16:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360755#M310209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, my setup is the same as your's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Output from capture -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;20: 16:53:49.113077&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#5 P0 10.0.125.2 &amp;gt; 4.2.2.2: icmp: echo request&lt;/P&gt;&lt;P&gt;&amp;nbsp; 21: 16:53:50.113351&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#5 P0 10.0.125.2 &amp;gt; 4.2.2.2: icmp: echo request&lt;/P&gt;&lt;P&gt;&amp;nbsp; 22: 16:53:50.958278&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 802.1Q vlan#5 P0 10.0.125.2.51529 &amp;gt; 208.90.58.5.443: S 1355489554:1355489554(0) win 5840 &lt;MSS 1460=""&gt;&lt;/MSS&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 16:55:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360755#M310209</guid>
      <dc:creator>Ashley Sahonta</dc:creator>
      <dc:date>2013-10-29T16:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360756#M310210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So the capin shows your CX traffic (both the ping and what is probably an attempt to reach Cisco on port 443) going into the firewall - that's good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Working it hop-by-hop I would next look to see:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it going out the other side? Is it NATted as expected? Is there any WCCP redirection or other proxy involved?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it's going out the other side, are the replies coming in and allowed back through?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 17:06:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360756#M310210</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-10-29T17:06:09Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360757#M310211</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;NAT is showing -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(inside) to (outside) source dynamic CX-MANAGEMENT interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 15, untranslate_hits = 17&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not using any proxies&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 17:10:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360757#M310211</guid>
      <dc:creator>Ashley Sahonta</dc:creator>
      <dc:date>2013-10-29T17:10:15Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360758#M310212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, so in that case the replies should show up as outbound traffic on the ASA inside interface to the CX Management IP adddress. Does a capture show them?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 17:13:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360758#M310212</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-10-29T17:13:24Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360759#M310213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, the replies aren't showing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ping from the core switch sourced from any VLAN except the CX VLAN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 17:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360759#M310213</guid>
      <dc:creator>Ashley Sahonta</dc:creator>
      <dc:date>2013-10-29T17:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360760#M310214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does the ASA know to route the replies back via the core switch? If it also has its management address on the same subnet, that could be the issue since it thinks that network is connected. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try adding a /32 route on the ASA inside interface for both the CX VLAN SVI and the CX Management address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 17:34:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360760#M310214</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-10-29T17:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360761#M310215</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I previously had a /32 route for the CX interface, however I did add the route for the CX VLAN SVI. Still not able to get out. I ran a packet tracer and got the following output -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input insid icmp 10.0.125.2 0 8 4.2.2.2 det&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: CAPTURE&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt; Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt; in&amp;nbsp; id=0x7fff9f3b3350, priority=13, domain=capture, deny=false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=236269, user_data=0x7fff9dfbec70, cs_id=0x0, l3_type=0x0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src mac=0000.0000.0000, mask=0000.0000.0000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst mac=0000.0000.0000, mask=0000.0000.0000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input_ifc=inside, output_ifc=any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt; Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt; in&amp;nbsp; id=0x7fff9f2fe570, priority=1, domain=permit, deny=false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=27398061, user_data=0x0, cs_id=0x0, l3_type=0x8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src mac=0000.0000.0000, mask=0000.0000.0000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst mac=0000.0000.0000, mask=0100.0000.0000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input_ifc=inside, output_ifc=any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;object network CX-MANAGEMENT&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt; Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt; in&amp;nbsp; id=0x7fff984e5750, priority=6, domain=nat, deny=false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=207, user_data=0x7fffa1ea9380, cs_id=0x0, flags=0x0, protocol=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src ip/id=10.0.125.0, mask=255.255.255.0, port=0, tag=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0 dscp=0x0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input_ifc=inside, output_ifc=outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: per-session&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt; Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt; in&amp;nbsp; id=0x7fff9e8fb6e0, priority=0, domain=nat-per-session, deny=true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=418401, user_data=0x0, cs_id=0x0, reverse, use_real_addr, flags=0x0, protocol=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0 dscp=0x0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input_ifc=any, output_ifc=any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt; Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt; in&amp;nbsp; id=0x7fff9f307540, priority=0, domain=inspect-ip-options, deny=true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=1321622, user_data=0x0, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0 dscp=0x0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input_ifc=inside, output_ifc=any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (nat-cluster-unassigned-pool) NAT unassigned pool in cluster&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Oct 2013 21:32:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360761#M310215</guid>
      <dc:creator>Ashley Sahonta</dc:creator>
      <dc:date>2013-10-29T21:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA CX</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360762#M310216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well from that last trace, it's reporting an issue with your NAT setup. Can you share the network object and associated NAT configuration?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 13:29:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-cx/m-p/2360762#M310216</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-10-30T13:29:39Z</dc:date>
    </item>
  </channel>
</rss>

