<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic access from outside in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288406#M310795</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here it is :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# show run nat&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANColt) source dynamic OBJ_GENERIC_ALL interface&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANBloom) source static obj-LANCarax obj-LANCarax destination static obj-LANBloom obj-LANBloom&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANEurex) source static obj-LANCarax obj-LANCarax destination static obj-LANEurex obj-LANEurex&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANAbn) source static obj-LANCarax obj-LANCarax destination static obj-LANAbn obj-LANAbn&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANMonaco) source static obj-LANCarax obj-LANCarax destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;nat (LANMonaco,DMZCarax) source static obj-LANMonaco obj-LANMonaco destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;nat (LANMonaco,LANBloom) source static obj-LANMonaco obj-LANMonaco destination static obj-LANBloom obj-LANBloom&lt;/P&gt;&lt;P&gt;nat (LANMonaco,LANAbn) source static obj-LANMonaco obj-LANMonaco destination static obj-LANAbn obj-LANAbn&lt;/P&gt;&lt;P&gt;nat (LANBloom,DMZCarax) source static obj-LANBloom obj-LANBloom destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;nat (LANBloom,LANMonaco) source static obj-LANBloom obj-LANBloom destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;nat (LANEurex,DMZCarax) source static obj-LANEurex obj-LANEurex destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;nat (LANEurex,LANMonaco) source static obj-LANEurex obj-LANEurex destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;nat (LANAbn,DMZCarax) source static obj-LANAbn obj-LANAbn destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;nat (LANAbn,LANMonaco) source static obj-LANAbn obj-LANAbn destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;nat (DMZCarax,DMZCarax) source static any any destination static NETWORK_OBJ_10.10.10.0_29 NETWORK_OBJ_10.10.10.0_29 no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;nat (LANColt,DMZCarax) source static any any destination static WebServer.Int WebServer.Int inactive&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANColt) source static any any destination static NETWORK_OBJ_10.10.10.0_29 NETWORK_OBJ_10.10.10.0_29 no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network STATIC-PAT&lt;/P&gt;&lt;P&gt; nat (DMZCarax,LANColt) static interface service tcp www www&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 Oct 2013 06:35:06 GMT</pubDate>
    <dc:creator>cbuschini</dc:creator>
    <dc:date>2013-10-21T06:35:06Z</dc:date>
    <item>
      <title>access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288395#M310782</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am new here and in the ASA world.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a small issue with allowing access to my webserver from the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet -------- Router COLT ---------- ASA ---------- MyLan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created an access-list :&lt;/P&gt;&lt;P&gt;access-list acl-out extended permit tcp any object WebServer eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created a NAT rule :&lt;/P&gt;&lt;P&gt;nat (LANColt,DMZCarax) source static any any destination static WebServer WebServer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The website is reachable when I plugged between the Route Colt and the ASA but not when I try from the Internet ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any idea ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Cedric&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:53:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288395#M310782</guid>
      <dc:creator>cbuschini</dc:creator>
      <dc:date>2019-03-12T02:53:14Z</dc:date>
    </item>
    <item>
      <title>access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288396#M310783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have Internet access from the inside? Is the IP address that you're translating to publicly routable? Is the translated IP address the same as the outside network of the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, this belongs in the Security --&amp;gt; Firewalling section. You should move it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sachin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Oct 2013 15:49:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288396#M310783</guid>
      <dc:creator>sganpat</dc:creator>
      <dc:date>2013-10-17T15:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288397#M310784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sachin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes I do have Internet access from the inside.&lt;/P&gt;&lt;P&gt;Yes the ip address is publicly routable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a quick description :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;62.23.x.x ------ &lt;STRONG&gt;Router Colt&lt;/STRONG&gt; [192.168.1.1] ---- [192.168.1.3] &lt;STRONG&gt;ASA &lt;/STRONG&gt;[192.168.10.2] ------- [192.168.10.4] &lt;STRONG&gt;Webserver&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Oct 2013 16:00:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288397#M310784</guid>
      <dc:creator>cbuschini</dc:creator>
      <dc:date>2013-10-17T16:00:18Z</dc:date>
    </item>
    <item>
      <title>access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288398#M310785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The provided information is not all we need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since your router actually holds the public IP address (and not the ASA) then your options to create a NAT configuraiton for the Web server would either be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Configure Static PAT (Port Forward) on the router that points to the ASA IP address 192.168.1.3 and the needed ports and then configure Static PAT (Port Forward) on the ASA from the IP address 192.168.1.3 to the actual IP address of the server for the needed ports and make sure the ACL on the ASA allows the traffic&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Make sure there is NO NAT between the ASAs &lt;STRONG&gt;"inside"&lt;/STRONG&gt; and &lt;STRONG&gt;"outside"&lt;/STRONG&gt; interface and configure the Static PAT for the actual server IP 192.168.10.x directly on the Router and make sure the ACL on the ASA allows the traffic.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So first we need to know if the router will see the actual 192.168.10.0/xx network (NONAT on ASA) or will it just see the ASA outside IP address 192.168.1.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The correct configuraiton format for Static PAT on ASA is for example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network STATIC-PAT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; host 192.168.10.x&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (inside,outside) static interface service tcp 80 80 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would forward the port TCP/80 if connections are coming to the &lt;STRONG&gt;"interface"&lt;/STRONG&gt; IP address of &lt;STRONG&gt;"outside"&lt;/STRONG&gt; with that destination port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Oct 2013 16:08:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288398#M310785</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-17T16:08:41Z</dc:date>
    </item>
    <item>
      <title>access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288399#M310786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The router only see the ASA on 192.168.1.3 and there is a NAT to this IP&lt;/P&gt;&lt;P&gt;(ip nat inside source static 192.168.1.3 62.23.xx.xx)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a NAT between ASAs inside and ouside interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried to create the static PAR on the ASA. But I still cannot reach the web server from the Internet.&lt;/P&gt;&lt;P&gt;Is the access-list I wrote fine ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cedric&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Oct 2013 16:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288399#M310786</guid>
      <dc:creator>cbuschini</dc:creator>
      <dc:date>2013-10-17T16:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288400#M310787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either post the configuration or post the output of this &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input outside tcp 8.8.8.8 12345 192.168.1.3 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or use the destination port&lt;STRONG&gt; "443"&lt;/STRONG&gt; if that is the one you are using&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Oct 2013 17:03:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288400#M310787</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-17T17:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288401#M310789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for the time to reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the output of the packet tracer :&lt;/P&gt;&lt;P&gt;ciscoasa# packet-tracer input LANColt tcp 8.8.8.8 12345 192.168.1.3 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 192.168.1.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.255 identity&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: LANColt&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: NP Identity Ifc&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packets are drop by an ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is "sh access-list" :&lt;/P&gt;&lt;P&gt;ciscoasa# sh access-list&lt;/P&gt;&lt;P&gt;access-list cached ACL log flows: total 397, denied 0 (deny-flow-max 4096)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; alert-interval 300&lt;/P&gt;&lt;P&gt;access-list LANColt_access_in; 4 elements; name hash: 0xa28dded0&lt;/P&gt;&lt;P&gt;access-list LANColt_access_in line 1 extended permit icmp any any object-group obj-i-all log informational interval 300 (hitcnt=0) 0x1507d1f7&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list LANColt_access_in line 1 extended permit icmp any any echo log informational interval 300 (hitcnt=0) 0x188a9836&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list LANColt_access_in line 1 extended permit icmp any any echo-reply log informational interval 300 (hitcnt=0) 0xada2a22a&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list LANColt_access_in line 1 extended permit icmp any any time-exceeded log informational interval 300 (hitcnt=19) 0xaf99f695&lt;/P&gt;&lt;P&gt;access-list LANColt_access_in line 2 extended permit tcp any any eq www (hitcnt=0) 0x25780758&lt;/P&gt;&lt;P&gt;access-list DMZCarax_access_in; 3 elements; name hash: 0xef6085d&lt;/P&gt;&lt;P&gt;access-list DMZCarax_access_in line 1 extended permit ip any any log debugging interval 300 (hitcnt=20007537) 0x563bb185&lt;/P&gt;&lt;P&gt;access-list DMZCarax_access_in line 2 extended permit icmp any any log informational interval 300 (hitcnt=0) 0x3ddebcbf&lt;/P&gt;&lt;P&gt;access-list DMZCarax_access_in line 3 extended permit udp host 192.168.2.2 any (hitcnt=0) 0xa1c4ec7c&lt;/P&gt;&lt;P&gt;access-list CARAX; 2 elements; name hash: 0xf5e4518b&lt;/P&gt;&lt;P&gt;access-list CARAX line 1 extended permit ip 192.168.2.0 255.255.255.0 192.168.1.0 255.255.255.0 inactive (hitcnt=0) (inactive) 0xc362eb9d&lt;/P&gt;&lt;P&gt;access-list CARAX line 2 extended permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0 inactive (hitcnt=0) (inactive) 0xdc4e01b7&lt;/P&gt;&lt;P&gt;access-list LANEurex_access_in; 3 elements; name hash: 0x77b8262a&lt;/P&gt;&lt;P&gt;access-list LANEurex_access_in line 1 extended permit ip object obj-h-Eurex object-group gobj-n-Global-Carax 0x741dc2a6&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list LANEurex_access_in line 1 extended permit ip host 193.29.93.173 192.168.20.0 255.255.255.0 (hitcnt=0) 0xbf558d64&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list LANEurex_access_in line 1 extended permit ip host 193.29.93.173 192.168.10.0 255.255.255.0 (hitcnt=0) 0xe6964c68&lt;/P&gt;&lt;P&gt;access-list LANEurex_access_in line 2 extended permit ip any any inactive (hitcnt=0) (inactive) 0xe0241ced&lt;/P&gt;&lt;P&gt;access-list LANAbn_access_in; 5 elements; name hash: 0xfc8d5221&lt;/P&gt;&lt;P&gt;access-list LANAbn_access_in line 1 extended permit ip object-group gobj-h-ABN object-group gobj-n-Global-Carax inactive (inactive) 0xe7ef84f4&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list LANAbn_access_in line 1 extended permit ip host 192.168.69.102 192.168.20.0 255.255.255.0 inactive (hitcnt=0) (inactive) 0x13f4adc8&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list LANAbn_access_in line 1 extended permit ip host 192.168.69.102 192.168.10.0 255.255.255.0 inactive (hitcnt=0) (inactive) 0xd1e47353&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list LANAbn_access_in line 1 extended permit ip host 192.168.69.103 192.168.20.0 255.255.255.0 inactive (hitcnt=0) (inactive) 0xc6f7ec02&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list LANAbn_access_in line 1 extended permit ip host 192.168.69.103 192.168.10.0 255.255.255.0 inactive (hitcnt=0) (inactive) 0x0e46a02e&lt;/P&gt;&lt;P&gt;access-list LANAbn_access_in line 2 extended permit ip any any (hitcnt=2) 0x0fdd7231&lt;/P&gt;&lt;P&gt;access-list LANBloom_access_in; 1 elements; name hash: 0xcc39ac70&lt;/P&gt;&lt;P&gt;access-list LANBloom_access_in line 1 extended permit ip any any (hitcnt=7872) 0xc86a3df1&lt;/P&gt;&lt;P&gt;access-list acl-out; 6 elements; name hash: 0x12815e8f&lt;/P&gt;&lt;P&gt;access-list acl-out line 1 extended permit icmp any any object-group obj-i-all (hitcnt=0) 0xc838e767&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list acl-out line 1 extended permit icmp any any echo (hitcnt=0) 0x9ab79491&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list acl-out line 1 extended permit icmp any any echo-reply (hitcnt=0) 0xa2377349&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-list acl-out line 1 extended permit icmp any any time-exceeded (hitcnt=0) 0xcb4b3851&lt;/P&gt;&lt;P&gt;access-list acl-out line 2 extended permit gre any host 192.168.10.221 (hitcnt=0) 0xdeafcf2f&lt;/P&gt;&lt;P&gt;access-list acl-out line 3 extended permit tcp any host 192.168.10.221 eq pptp (hitcnt=0) 0xdb7d38da&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Oct 2013 05:52:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288401#M310789</guid>
      <dc:creator>cbuschini</dc:creator>
      <dc:date>2013-10-21T05:52:31Z</dc:date>
    </item>
    <item>
      <title>access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288402#M310791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should use your external interface as the input interface of this test. Not your LAN interface which you are using now. The hosts on the Internet wont be using that as the input interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Oct 2013 06:14:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288402#M310791</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-21T06:14:24Z</dc:date>
    </item>
    <item>
      <title>access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288403#M310792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Or,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this was the interface connected to the router then you either are missing a NAT configuration or you have an overriding NAT configuration in your current configuration which is most likely a Dynamic PAT configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Oct 2013 06:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288403#M310792</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-21T06:18:27Z</dc:date>
    </item>
    <item>
      <title>access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288404#M310793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;LANColt is the interface facing the router Colt. It is the 192.168.1.3 interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# sh nat&lt;/P&gt;&lt;P&gt;Manual NAT Policies (Section 1)&lt;/P&gt;&lt;P&gt;1 (DMZCarax) to (LANColt) source dynamic OBJ_GENERIC_ALL interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 18933401, untranslate_hits = 1516833&lt;/P&gt;&lt;P&gt;2 (DMZCarax) to (LANBloom) source static obj-LANCarax obj-LANCarax&amp;nbsp;&amp;nbsp; destination static obj-LANBloom obj-LANBloom&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 15244&lt;/P&gt;&lt;P&gt;3 (DMZCarax) to (LANEurex) source static obj-LANCarax obj-LANCarax&amp;nbsp;&amp;nbsp; destination static obj-LANEurex obj-LANEurex&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;4 (DMZCarax) to (LANAbn) source static obj-LANCarax obj-LANCarax&amp;nbsp;&amp;nbsp; destination static obj-LANAbn obj-LANAbn&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 21955&lt;/P&gt;&lt;P&gt;5 (DMZCarax) to (LANMonaco) source static obj-LANCarax obj-LANCarax&amp;nbsp;&amp;nbsp; destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;6 (LANMonaco) to (DMZCarax) source static obj-LANMonaco obj-LANMonaco&amp;nbsp;&amp;nbsp; destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 138065&lt;/P&gt;&lt;P&gt;7 (LANMonaco) to (LANBloom) source static obj-LANMonaco obj-LANMonaco&amp;nbsp;&amp;nbsp; destination static obj-LANBloom obj-LANBloom&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 23&lt;/P&gt;&lt;P&gt;8 (LANMonaco) to (LANAbn) source static obj-LANMonaco obj-LANMonaco&amp;nbsp;&amp;nbsp; destination static obj-LANAbn obj-LANAbn&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;9 (LANBloom) to (DMZCarax) source static obj-LANBloom obj-LANBloom&amp;nbsp;&amp;nbsp; destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 89964&lt;/P&gt;&lt;P&gt;10 (LANBloom) to (LANMonaco) source static obj-LANBloom obj-LANBloom&amp;nbsp;&amp;nbsp; destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;11 (LANEurex) to (DMZCarax) source static obj-LANEurex obj-LANEurex&amp;nbsp;&amp;nbsp; destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 96&lt;/P&gt;&lt;P&gt;12 (LANEurex) to (LANMonaco) source static obj-LANEurex obj-LANEurex&amp;nbsp;&amp;nbsp; destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;13 (LANAbn) to (DMZCarax) source static obj-LANAbn obj-LANAbn&amp;nbsp;&amp;nbsp; destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 49854&lt;/P&gt;&lt;P&gt;14 (LANAbn) to (LANMonaco) source static obj-LANAbn obj-LANAbn&amp;nbsp;&amp;nbsp; destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;15 (DMZCarax) to (DMZCarax) source static any any&amp;nbsp;&amp;nbsp; destination static NETWORK_OBJ_10.10.10.0_29 NETWORK_OBJ_10.10.10.0_29 no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;16 (LANColt) to (DMZCarax) source static any any&amp;nbsp;&amp;nbsp; destination static WebServer.Int WebServer.Int inactive&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;17 (DMZCarax) to (LANColt) source static any any&amp;nbsp;&amp;nbsp; destination static NETWORK_OBJ_10.10.10.0_29 NETWORK_OBJ_10.10.10.0_29 no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Auto NAT Policies (Section 2)&lt;/P&gt;&lt;P&gt;1 (DMZCarax) to (LANColt) source static STATIC-PAT interface&amp;nbsp;&amp;nbsp; service tcp www www&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Oct 2013 06:28:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288404#M310793</guid>
      <dc:creator>cbuschini</dc:creator>
      <dc:date>2013-10-21T06:28:28Z</dc:date>
    </item>
    <item>
      <title>access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288405#M310794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you rather post the output of&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run nat&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Oct 2013 06:32:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288405#M310794</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-21T06:32:22Z</dc:date>
    </item>
    <item>
      <title>access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288406#M310795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here it is :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# show run nat&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANColt) source dynamic OBJ_GENERIC_ALL interface&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANBloom) source static obj-LANCarax obj-LANCarax destination static obj-LANBloom obj-LANBloom&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANEurex) source static obj-LANCarax obj-LANCarax destination static obj-LANEurex obj-LANEurex&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANAbn) source static obj-LANCarax obj-LANCarax destination static obj-LANAbn obj-LANAbn&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANMonaco) source static obj-LANCarax obj-LANCarax destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;nat (LANMonaco,DMZCarax) source static obj-LANMonaco obj-LANMonaco destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;nat (LANMonaco,LANBloom) source static obj-LANMonaco obj-LANMonaco destination static obj-LANBloom obj-LANBloom&lt;/P&gt;&lt;P&gt;nat (LANMonaco,LANAbn) source static obj-LANMonaco obj-LANMonaco destination static obj-LANAbn obj-LANAbn&lt;/P&gt;&lt;P&gt;nat (LANBloom,DMZCarax) source static obj-LANBloom obj-LANBloom destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;nat (LANBloom,LANMonaco) source static obj-LANBloom obj-LANBloom destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;nat (LANEurex,DMZCarax) source static obj-LANEurex obj-LANEurex destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;nat (LANEurex,LANMonaco) source static obj-LANEurex obj-LANEurex destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;nat (LANAbn,DMZCarax) source static obj-LANAbn obj-LANAbn destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;nat (LANAbn,LANMonaco) source static obj-LANAbn obj-LANAbn destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;nat (DMZCarax,DMZCarax) source static any any destination static NETWORK_OBJ_10.10.10.0_29 NETWORK_OBJ_10.10.10.0_29 no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;nat (LANColt,DMZCarax) source static any any destination static WebServer.Int WebServer.Int inactive&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANColt) source static any any destination static NETWORK_OBJ_10.10.10.0_29 NETWORK_OBJ_10.10.10.0_29 no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network STATIC-PAT&lt;/P&gt;&lt;P&gt; nat (DMZCarax,LANColt) static interface service tcp www www&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Oct 2013 06:35:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288406#M310795</guid>
      <dc:creator>cbuschini</dc:creator>
      <dc:date>2013-10-21T06:35:06Z</dc:date>
    </item>
    <item>
      <title>access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288407#M310796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no nat (DMZCarax,LANColt) source dynamic OBJ_GENERIC_ALL interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would have to remove this command which would essentially cause a small outage to all users that use the Dynamic PAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you would enter it with&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (DMZCarax,LANColt) after-auto source dynamic OBJ_GENERIC_ALL interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then the new Static PAT (Port Forward) would work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Oct 2013 06:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288407#M310796</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-21T06:40:34Z</dc:date>
    </item>
    <item>
      <title>access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288408#M310797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank Jouni,&lt;/P&gt;&lt;P&gt;I will do this this evening because users are already here browsing the web.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Oct 2013 06:57:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288408#M310797</guid>
      <dc:creator>cbuschini</dc:creator>
      <dc:date>2013-10-21T06:57:19Z</dc:date>
    </item>
    <item>
      <title>access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288409#M310798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have done what you recommand but it still not working :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh run nat&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANBloom) source static obj-LANCarax obj-LANCarax destination static obj-LANBloom obj-LANBloom&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANEurex) source static obj-LANCarax obj-LANCarax destination static obj-LANEurex obj-LANEurex&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANAbn) source static obj-LANCarax obj-LANCarax destination static obj-LANAbn obj-LANAbn&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANMonaco) source static obj-LANCarax obj-LANCarax destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;nat (LANMonaco,DMZCarax) source static obj-LANMonaco obj-LANMonaco destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;nat (LANMonaco,LANBloom) source static obj-LANMonaco obj-LANMonaco destination static obj-LANBloom obj-LANBloom&lt;/P&gt;&lt;P&gt;nat (LANMonaco,LANAbn) source static obj-LANMonaco obj-LANMonaco destination static obj-LANAbn obj-LANAbn&lt;/P&gt;&lt;P&gt;nat (LANBloom,DMZCarax) source static obj-LANBloom obj-LANBloom destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;nat (LANBloom,LANMonaco) source static obj-LANBloom obj-LANBloom destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;nat (LANEurex,DMZCarax) source static obj-LANEurex obj-LANEurex destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;nat (LANEurex,LANMonaco) source static obj-LANEurex obj-LANEurex destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;nat (LANAbn,DMZCarax) source static obj-LANAbn obj-LANAbn destination static obj-LANCarax obj-LANCarax&lt;/P&gt;&lt;P&gt;nat (LANAbn,LANMonaco) source static obj-LANAbn obj-LANAbn destination static obj-LANMonaco obj-LANMonaco&lt;/P&gt;&lt;P&gt;nat (DMZCarax,DMZCarax) source static any any destination static NETWORK_OBJ_10.10.10.0_29 NETWORK_OBJ_10.10.10.0_29 no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;nat (LANColt,DMZCarax) source static any any destination static WebServer.Int WebServer.Int inactive&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANColt) source static any any destination static NETWORK_OBJ_10.10.10.0_29 NETWORK_OBJ_10.10.10.0_29 no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network STATIC-PAT&lt;/P&gt;&lt;P&gt; nat (DMZCarax,LANColt) static interface service tcp www www&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (DMZCarax,LANColt) after-auto source dynamic OBJ_GENERIC_ALL interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# packet-tracer input LANColt tcp 8.8.8.8 12354 192.168.1.3 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: UN-NAT&lt;/P&gt;&lt;P&gt;Subtype: static&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;object network STATIC-PAT&lt;/P&gt;&lt;P&gt; nat (DMZCarax,LANColt) static interface service tcp www www&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;NAT divert to egress interface DMZCarax&lt;/P&gt;&lt;P&gt;Untranslate 192.168.1.3/80 to 192.168.10.4/80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: LANColt&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: DMZCarax&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ceders&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Oct 2013 05:30:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288409#M310798</guid>
      <dc:creator>cbuschini</dc:creator>
      <dc:date>2013-10-22T05:30:43Z</dc:date>
    </item>
    <item>
      <title>access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288410#M310799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My mistake.&lt;/P&gt;&lt;P&gt;It is working ... I had to add an access-list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much Jouni !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But now I have an other question about access-list... May I ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Oct 2013 05:42:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288410#M310799</guid>
      <dc:creator>cbuschini</dc:creator>
      <dc:date>2013-10-22T05:42:20Z</dc:date>
    </item>
    <item>
      <title>access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288411#M310800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that question is related to this case then its usually fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If its related to something else than this actual case then it is usually clearer to create a new discussion/question on the forums for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But go ahead&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Oct 2013 07:22:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288411#M310800</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-10-22T07:22:21Z</dc:date>
    </item>
    <item>
      <title>access from outside</title>
      <link>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288412#M310801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is kind of related because it deals with access-list BUT I will first try to find the answer on my own ... &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Ceders&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Oct 2013 10:23:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-from-outside/m-p/2288412#M310801</guid>
      <dc:creator>cbuschini</dc:creator>
      <dc:date>2013-10-22T10:23:24Z</dc:date>
    </item>
  </channel>
</rss>

