<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 5520 to 5525 all access rules being ignored. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/5520-to-5525-all-access-rules-being-ignored/m-p/2290958#M342352</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ASA using software 8.3 or above that does Static NAT between private and public IP addresses (or any NAT at all) and you want to allow traffic from public network to those Static NATed servers you will need to use the local/real IP address in the ACL statements.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your ASA5520 was running 8.3 or above software levels then there should be no major changes compared to an ASA5525-X running 8.6 software level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only situation I can think of right now is if you had used ASA5520 with software 8.2 or below BUT in that case you WOULD NOT have been able to directly copy/paste the configuration to the ASA5525-X device as the lowest software level that the ASA5525-X supports is 8.6(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I am kind of wondering what the situation has actually been.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But one thing is certain. You need to use the real/local IP address of the server in the ACL rules even if you are allowing traffic from the public/external network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; test used to simulate a connection coming to one of your Static NAT public IP address should also tell if your ACLs are configured correctly, among other things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Sep 2013 15:36:36 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-09-30T15:36:36Z</dc:date>
    <item>
      <title>5520 to 5525 all access rules being ignored.</title>
      <link>https://community.cisco.com/t5/network-security/5520-to-5525-all-access-rules-being-ignored/m-p/2290954#M342339</link>
      <description>&lt;P&gt;I copied my config from my old 5520 to our new 5525 and when I cut over to it from the inside out I could get to the internet no problem but from the outside in none of our access rules were working.&amp;nbsp; Could someone take a look at our config and maybe inlighten me on the problem please.&amp;nbsp; Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.ebay.com/itm/290951611556?ssPageName=STRK:MEWNX:IT&amp;amp;_trksid=p3984.m1497.l2649" target="_blank"&gt;http://www.ebay.com/itm/290951611556?ssPageName=STRK:MEWNX:IT&amp;amp;_trksid=p3984.m1497.l2649&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;: Written by admin at 02:33:30.875 EDT Mon Sep 30 2013&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ASA Version 8.6(1)2 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ColASA01-HA&lt;/P&gt;&lt;P&gt;domain-name corp.COMPANY.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 172.22.5.133 ColBarracuda description Colo Barracuda Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.133 ColBarracuda- description Colo Barracuda External&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.132 ColVPN- description Colo VPN External&lt;/P&gt;&lt;P&gt;name 172.22.5.138 ww2 description ww2 Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.138 ww2- description ww2 External&lt;/P&gt;&lt;P&gt;name 172.22.5.139 www1 description www1 Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.139 www1- description www1 External&lt;/P&gt;&lt;P&gt;name 172.22.5.140 www1-COMPANY.co.uk description www1 COMPANY.co.uk Internal&lt;/P&gt;&lt;P&gt;name 172.22.5.143 ColSysAid description ColSysAid Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.143 ColSysAid- description ColSysAid External&lt;/P&gt;&lt;P&gt;name 172.22.5.141 Colww3 description Colww3 Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.141 Colww3- description Colww3 External&lt;/P&gt;&lt;P&gt;name 10.1.1.100 Facts description Facts Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.135 Facts- description Facts External&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.144 ftp.boundree.co.uk- description ftp.COMPANY.co.uk External&lt;/P&gt;&lt;P&gt;name 172.22.5.144 ftp.COMPANY.co.uk description ftp.COMPANY.co.uk Internal&lt;/P&gt;&lt;P&gt;name 10.101.0.24 Dubmss01 description Voicemail Server - Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.145 Dubmss01- description Voicemail Sever - External&lt;/P&gt;&lt;P&gt;name 172.22.5.146 ColBI01 description ColBI01 Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.146 ColBI01- description ColBI01 External&lt;/P&gt;&lt;P&gt;name 172.22.5.147 ColMOSS01 description ColMOSS01 Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.147 ColMOSS01- description ColMOSS01 External&lt;/P&gt;&lt;P&gt;name 172.22.5.149 ambutrak description AmbuTRAK Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.149 ambutrak- description AmbuTRAK External&lt;/P&gt;&lt;P&gt;name 172.22.5.136 NSTrax description NSTrax Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.136 NSTrax- description NSTrax External&lt;/P&gt;&lt;P&gt;name 172.22.5.150 btmu description BTMU Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.150 btmu- description BTMU External&lt;/P&gt;&lt;P&gt;name 172.22.5.155 w2k-isoft description w2k-isoft Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.155 w2k-isoft- description w2k-isoft External&lt;/P&gt;&lt;P&gt;name 172.22.5.142 Colexch01 description Colexch01 Internal&lt;/P&gt;&lt;P&gt;name 172.22.5.151 Coltixdb description Coltxdb Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.151 Coltixdb- description Coltixdb External&lt;/P&gt;&lt;P&gt;name 172.22.5.156 colexcas description colexcas Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.156 colexcas- description colexcas External&lt;/P&gt;&lt;P&gt;name 172.22.3.74 colexcas01 description colexcas01 Internal&lt;/P&gt;&lt;P&gt;name 172.22.3.75 colexcas02 description colexcas02 Internal&lt;/P&gt;&lt;P&gt;name 172.22.5.157 ColFTP01 description ColFTP01 Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.157 ColFTP01- description ColFTP01 External&lt;/P&gt;&lt;P&gt;name 172.22.5.158 &lt;A href="https://community.cisco.com/www.COMPANY.com" target="_blank"&gt;www.COMPANY.com&lt;/A&gt; description &lt;A href="https://community.cisco.com/www.COMPANY.com" target="_blank"&gt;www.COMPANY.com&lt;/A&gt; Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.158 &lt;A href="https://community.cisco.com/www.COMPANY.com-" target="_blank"&gt;www.COMPANY.com-&lt;/A&gt; description &lt;A href="https://community.cisco.com/www.COMPANY.com" target="_blank"&gt;www.COMPANY.com&lt;/A&gt; External&lt;/P&gt;&lt;P&gt;name 172.22.5.159 act.COMPANY.com description COMPANY ACT Internal - colww4&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.159 act.COMPANY.com- description COMPANY ACT External&lt;/P&gt;&lt;P&gt;name 172.22.3.93 test.COMPANY.com description test.COMPANY.com Internal&lt;/P&gt;&lt;P&gt;name 172.22.5.161 ColdevAS2 description ColdevAS2 Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.160 Rewards.COMPANY.com- description COMPANY Rewards External&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.153 as2.COMPANY.com- description as2.COMPANY.com External&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.161 as2test.COMPANY.com- description as2test.COMPANY.com External&lt;/P&gt;&lt;P&gt;name 172.22.5.153 colas2 description colas2 Internal&lt;/P&gt;&lt;P&gt;name 172.22.5.160 colww5 description colww5 Internal&lt;/P&gt;&lt;P&gt;name 172.22.3.91 colexcas01NLB description colexcas01 NLB Interface&lt;/P&gt;&lt;P&gt;name 172.22.3.92 colexcas02NLB description colexcas02 NLB Interface&lt;/P&gt;&lt;P&gt;name 172.22.3.100 ColVPN description Colo VPN Internal&lt;/P&gt;&lt;P&gt;name 172.22.5.134 intra.COMPANY.com description on NewPortal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.134 intra.COMPANY.com- description It's on NewPortal&lt;/P&gt;&lt;P&gt;name 10.1.0.80 asgard description asgard Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.163 &lt;A href="https://community.cisco.com/www.COMPANY.net-" target="_blank"&gt;www.COMPANY.net-&lt;/A&gt; description &lt;A href="https://community.cisco.com/www.COMPANY.net" target="_blank"&gt;www.COMPANY.net&lt;/A&gt; External&lt;/P&gt;&lt;P&gt;name 172.22.5.165 crmws.COMPANY.com description ColCrmRouter01 Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.165 crmws.COMPANY.com- description ColCrmRouter01 External&lt;/P&gt;&lt;P&gt;name 10.1.5.137 dubngwt description Test Next Gen Web Farm Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.137 dubngwt- description Test Next Gen Web Farm External&lt;/P&gt;&lt;P&gt;name 10.1.0.87 dubexcas description Dublin CAS NLB&lt;/P&gt;&lt;P&gt;name 10.1.0.85 dubexcas01 description Dublin CAS Server&lt;/P&gt;&lt;P&gt;name 10.1.0.86 dubexcas02 description Dublin CAS Server&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.166 collync01- description Lync Edge Server External&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.167 coltmg01- description TMG Server External&lt;/P&gt;&lt;P&gt;name 172.23.2.166 collync01 description Lync Edge Server DMZ&lt;/P&gt;&lt;P&gt;name 172.23.2.167 coltmg01 description TMG Server DMZ&lt;/P&gt;&lt;P&gt;name 172.22.5.168 COMPANYfed.com description COMPANYfed.com Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.168 COMPANYfed.com- description COMPANYfed.com External&lt;/P&gt;&lt;P&gt;name 172.22.3.60 www1.COMPANY.com description www1.COMPANY.com Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.169 www1.COMPANY.com- description www1.COMPANY.com External&lt;/P&gt;&lt;P&gt;name 172.22.3.63 www1.COMPANYfed.com description www1.COMPANYfed.com Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.171 www1.COMPANYfed.com- description www1.COMPANYfed.com External&lt;/P&gt;&lt;P&gt;name 172.22.3.61 www2.COMPANY.com description www2.COMPANY.com Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.170 www2.COMPANY.com- description www2.COMPANY.com External&lt;/P&gt;&lt;P&gt;name 172.22.3.64 www2.COMPANYfed.com description www2.COMPANYfed.com Internal&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.172 www2.COMPANYfed.com- description www2.COMPANYfed.com External&lt;/P&gt;&lt;P&gt;name 172.22.5.154 COMPANY.com description COMPANY.com Web Farm Production&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.154 COMPANY.com- description COMPANY.com Web Farm Outside&lt;/P&gt;&lt;P&gt;name 184.XXX.XXX.226 PMISonicWALL description PMI SonicWALL&lt;/P&gt;&lt;P&gt;name 10.10.0.0 PMI_SonicWALL-Subnet description PMI LAN&lt;/P&gt;&lt;P&gt;name 10.1.0.0 DublinData description Dublin Data Network&lt;/P&gt;&lt;P&gt;name 10.2.0.0 SouthavenData description Southaven Data Network&lt;/P&gt;&lt;P&gt;name 10.0.0.0 BrentwoodData description Brentwood Data Network&lt;/P&gt;&lt;P&gt;name 10.8.0.0 GilbertData description Gilbert Data Network&lt;/P&gt;&lt;P&gt;name 10.101.0.0 DublinVoIP description Dublin VoIP Network&lt;/P&gt;&lt;P&gt;name 10.110.0.0 PMI_SonicWALL-VOICSubnet&lt;/P&gt;&lt;P&gt;name 172.24.3.50 ColUT04-PCITrust&lt;/P&gt;&lt;P&gt;name 172.22.3.31 coldc01&lt;/P&gt;&lt;P&gt;name 172.22.3.4 coldc02&lt;/P&gt;&lt;P&gt;name 172.22.3.23 ColWSUS02 description Windows Update Server&lt;/P&gt;&lt;P&gt;name 74.XXX.XXX.175 monitor.COMPANY.com- description PRTG Network Monitor&lt;/P&gt;&lt;P&gt;name 172.22.3.150 ColPRTG01 description PRTG Monitor&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; description Connected to Internet via COLRTR01&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 74.XXX.XXX.130 255.255.255.192 standby 74.XXX.XXX.176 &lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; description Connected to Colo LAN&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.22.1.8 255.255.0.0 standby 172.22.1.50 &lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt; authentication key eigrp 10 Fiyalt1 key-id 1&lt;/P&gt;&lt;P&gt; authentication mode eigrp 10 md5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 10&lt;/P&gt;&lt;P&gt; ip address 172.23.2.1 255.255.255.0 standby 172.23.2.50 &lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt; description Connected to COLSW01 port 9 - PCI Trust Area (no internet)&lt;/P&gt;&lt;P&gt; nameif Colo_PCI_Trust&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.24.3.1 255.255.255.0 standby ColUT04-PCITrust &lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/4&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/5&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/6&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/7&lt;/P&gt;&lt;P&gt; description LAN/STATE Failover Interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.1.200.20 255.255.0.0 standby 10.1.200.21 &lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa861-2-smp-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name corp.COMPANY.com&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object network obj-172.22.255.0&lt;/P&gt;&lt;P&gt; subnet 172.22.255.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network PMI_SonicWALL-Subnet&lt;/P&gt;&lt;P&gt; subnet 10.10.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;object network obj-172.24.3.0&lt;/P&gt;&lt;P&gt; subnet 172.24.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network ColWSUS02&lt;/P&gt;&lt;P&gt; host 172.22.3.23&lt;/P&gt;&lt;P&gt;object network ambutrak&lt;/P&gt;&lt;P&gt; host 172.22.5.149&lt;/P&gt;&lt;P&gt;object network ambutrak-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.149&lt;/P&gt;&lt;P&gt;object network btmu&lt;/P&gt;&lt;P&gt; host 172.22.5.150&lt;/P&gt;&lt;P&gt;object network btmu-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.150&lt;/P&gt;&lt;P&gt;object network ColBarracuda&lt;/P&gt;&lt;P&gt; host 172.22.5.133&lt;/P&gt;&lt;P&gt;object network ColBarracuda-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.133&lt;/P&gt;&lt;P&gt;object network ColBI01&lt;/P&gt;&lt;P&gt; host 172.22.5.146&lt;/P&gt;&lt;P&gt;object network ColBI01-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.146&lt;/P&gt;&lt;P&gt;object network colexcas&lt;/P&gt;&lt;P&gt; host 172.22.5.156&lt;/P&gt;&lt;P&gt;object network colexcas-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.156&lt;/P&gt;&lt;P&gt;object network ColMOSS01&lt;/P&gt;&lt;P&gt; host 172.22.5.147&lt;/P&gt;&lt;P&gt;object network ColMOSS01-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.147&lt;/P&gt;&lt;P&gt;object network COMPANY.com&lt;/P&gt;&lt;P&gt; host 172.22.5.154&lt;/P&gt;&lt;P&gt;object network COMPANY.com-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.154&lt;/P&gt;&lt;P&gt;object network Coltixdb&lt;/P&gt;&lt;P&gt; host 172.22.5.151&lt;/P&gt;&lt;P&gt;object network Coltixdb-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.151&lt;/P&gt;&lt;P&gt;object network Colww3&lt;/P&gt;&lt;P&gt; host 172.22.5.141&lt;/P&gt;&lt;P&gt;object network Colww3-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.141&lt;/P&gt;&lt;P&gt;object network ColSysAid&lt;/P&gt;&lt;P&gt; host 172.22.5.143&lt;/P&gt;&lt;P&gt;object network ColSysAid-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.143&lt;/P&gt;&lt;P&gt;object network ColVPN&lt;/P&gt;&lt;P&gt; host 172.22.3.100&lt;/P&gt;&lt;P&gt;object network ColVPN-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.132&lt;/P&gt;&lt;P&gt;object network colas2&lt;/P&gt;&lt;P&gt; host 172.22.5.153&lt;/P&gt;&lt;P&gt;object network as2.COMPANY.com-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.153&lt;/P&gt;&lt;P&gt;object network Dubmss01&lt;/P&gt;&lt;P&gt; host 10.101.0.24&lt;/P&gt;&lt;P&gt;object network Dubmss01-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.145&lt;/P&gt;&lt;P&gt;object network Facts&lt;/P&gt;&lt;P&gt; host 10.1.1.100&lt;/P&gt;&lt;P&gt;object network Facts-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.135&lt;/P&gt;&lt;P&gt;object network ftp.COMPANY.co.uk&lt;/P&gt;&lt;P&gt; host 172.22.5.144&lt;/P&gt;&lt;P&gt;object network ftp.boundree.co.uk-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.144&lt;/P&gt;&lt;P&gt;object network NSTrax&lt;/P&gt;&lt;P&gt; host 172.22.5.136&lt;/P&gt;&lt;P&gt;object network NSTrax-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.136&lt;/P&gt;&lt;P&gt;object network w2k-isoft&lt;/P&gt;&lt;P&gt; host 172.22.5.155&lt;/P&gt;&lt;P&gt;object network w2k-isoft-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.155&lt;/P&gt;&lt;P&gt;object network www1&lt;/P&gt;&lt;P&gt; host 172.22.5.139&lt;/P&gt;&lt;P&gt;object network www1-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.139&lt;/P&gt;&lt;P&gt;object network ww2&lt;/P&gt;&lt;P&gt; host 172.22.5.138&lt;/P&gt;&lt;P&gt;object network ww2-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.138&lt;/P&gt;&lt;P&gt;object network ColFTP01&lt;/P&gt;&lt;P&gt; host 172.22.5.157&lt;/P&gt;&lt;P&gt;object network ColFTP01-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.157&lt;/P&gt;&lt;P&gt;object network &lt;A href="http://www.COMPANY.com" target="_blank"&gt;www.COMPANY.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt; host 172.22.5.158&lt;/P&gt;&lt;P&gt;object network &lt;A href="http://www.COMPANY.com-" target="_blank"&gt;www.COMPANY.com-&lt;/A&gt;&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.158&lt;/P&gt;&lt;P&gt;object network act.COMPANY.com&lt;/P&gt;&lt;P&gt; host 172.22.5.159&lt;/P&gt;&lt;P&gt;object network act.COMPANY.com-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.159&lt;/P&gt;&lt;P&gt;object network colww5&lt;/P&gt;&lt;P&gt; host 172.22.5.160&lt;/P&gt;&lt;P&gt;object network Rewards.COMPANY.com-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.160&lt;/P&gt;&lt;P&gt;object network ColdevAS2&lt;/P&gt;&lt;P&gt; host 172.22.5.161&lt;/P&gt;&lt;P&gt;object network as2test.COMPANY.com-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.161&lt;/P&gt;&lt;P&gt;object network intra.COMPANY.com&lt;/P&gt;&lt;P&gt; host 172.22.5.134&lt;/P&gt;&lt;P&gt;object network intra.COMPANY.com-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.134&lt;/P&gt;&lt;P&gt;object network asgard&lt;/P&gt;&lt;P&gt; host 10.1.0.80&lt;/P&gt;&lt;P&gt;object network &lt;A href="http://www.COMPANY.net-" target="_blank"&gt;www.COMPANY.net-&lt;/A&gt;&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.163&lt;/P&gt;&lt;P&gt;object network crmws.COMPANY.com&lt;/P&gt;&lt;P&gt; host 172.22.5.165&lt;/P&gt;&lt;P&gt;object network crmws.COMPANY.com-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.165&lt;/P&gt;&lt;P&gt;object network dubngwt&lt;/P&gt;&lt;P&gt; host 10.1.5.137&lt;/P&gt;&lt;P&gt;object network dubngwt-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.137&lt;/P&gt;&lt;P&gt;object network COMPANYfed.com&lt;/P&gt;&lt;P&gt; host 172.22.5.168&lt;/P&gt;&lt;P&gt;object network COMPANYfed.com-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.168&lt;/P&gt;&lt;P&gt;object network www1.COMPANYfed.com&lt;/P&gt;&lt;P&gt; host 172.22.3.63&lt;/P&gt;&lt;P&gt;object network www1.COMPANYfed.com-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.171&lt;/P&gt;&lt;P&gt;object network www2.COMPANYfed.com&lt;/P&gt;&lt;P&gt; host 172.22.3.64&lt;/P&gt;&lt;P&gt;object network www2.COMPANYfed.com-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.172&lt;/P&gt;&lt;P&gt;object network www1.COMPANY.com&lt;/P&gt;&lt;P&gt; host 172.22.3.60&lt;/P&gt;&lt;P&gt;object network www1.COMPANY.com-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.169&lt;/P&gt;&lt;P&gt;object network www2.COMPANY.com&lt;/P&gt;&lt;P&gt; host 172.22.3.61&lt;/P&gt;&lt;P&gt;object network www2.COMPANY.com-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.170&lt;/P&gt;&lt;P&gt;object network ColPRTG01&lt;/P&gt;&lt;P&gt; host 172.22.3.150&lt;/P&gt;&lt;P&gt;object network monitor.COMPANY.com-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.175&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object network collync01&lt;/P&gt;&lt;P&gt; host 172.23.2.166&lt;/P&gt;&lt;P&gt;object network collync01-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.166&lt;/P&gt;&lt;P&gt;object network coltmg01&lt;/P&gt;&lt;P&gt; host 172.23.2.167&lt;/P&gt;&lt;P&gt;object network coltmg01-&lt;/P&gt;&lt;P&gt; host 74.XXX.XXX.167&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_1&lt;/P&gt;&lt;P&gt; service-object gre &lt;/P&gt;&lt;P&gt; service-object tcp destination eq pptp &lt;/P&gt;&lt;P&gt;object-group service Barracuda tcp&lt;/P&gt;&lt;P&gt; port-object eq 8000&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_1 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt; port-object eq smtp&lt;/P&gt;&lt;P&gt; port-object eq ssh&lt;/P&gt;&lt;P&gt; group-object Barracuda&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_2 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt; port-object eq smtp&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_3 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt; port-object eq smtp&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_5 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_7 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service mySQL tcp&lt;/P&gt;&lt;P&gt; description mySQL Database&lt;/P&gt;&lt;P&gt; port-object eq 3306&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_9 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_10 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_11 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_12 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service as2 tcp&lt;/P&gt;&lt;P&gt; description as2&lt;/P&gt;&lt;P&gt; port-object eq 4080&lt;/P&gt;&lt;P&gt; port-object eq 5080&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt; port-object eq 6080&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_2&lt;/P&gt;&lt;P&gt; network-object host ColBarracuda&lt;/P&gt;&lt;P&gt; network-object host ww2&lt;/P&gt;&lt;P&gt; network-object host www1&lt;/P&gt;&lt;P&gt; network-object host colexcas01&lt;/P&gt;&lt;P&gt; network-object host colexcas02&lt;/P&gt;&lt;P&gt; network-object host colexcas&lt;/P&gt;&lt;P&gt; network-object host test.COMPANY.com&lt;/P&gt;&lt;P&gt; network-object host colexcas01NLB&lt;/P&gt;&lt;P&gt; network-object host colexcas02NLB&lt;/P&gt;&lt;P&gt; network-object host dubexcas01&lt;/P&gt;&lt;P&gt; network-object host dubexcas02&lt;/P&gt;&lt;P&gt; network-object host dubexcas&lt;/P&gt;&lt;P&gt;object-group service SQLServer tcp&lt;/P&gt;&lt;P&gt; description Microsoft SQL Server&lt;/P&gt;&lt;P&gt; port-object eq 1433&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_13 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt; port-object eq smtp&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_14 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_15 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_1&lt;/P&gt;&lt;P&gt; network-object host as2.COMPANY.com-&lt;/P&gt;&lt;P&gt; network-object host as2test.COMPANY.com-&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_6 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service rdp tcp&lt;/P&gt;&lt;P&gt; description Remote Desktop Protocol&lt;/P&gt;&lt;P&gt; port-object eq 3389&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_8 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_16 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_17 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_4 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service LyncEdge tcp-udp&lt;/P&gt;&lt;P&gt; description sip-tls, 443, 444, rtp 50000-59999, stun udp 3478&lt;/P&gt;&lt;P&gt; port-object eq 3478&lt;/P&gt;&lt;P&gt; port-object eq 443&lt;/P&gt;&lt;P&gt; port-object eq 444&lt;/P&gt;&lt;P&gt; port-object range 50000 59999&lt;/P&gt;&lt;P&gt; port-object eq 5061&lt;/P&gt;&lt;P&gt;object-group protocol TCPUDP&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_18 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_19 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_20 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_21 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_22 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;object-group network PMIVPNNetworks&lt;/P&gt;&lt;P&gt; description VPN Networks to PMI&lt;/P&gt;&lt;P&gt; network-object BrentwoodData 255.255.0.0&lt;/P&gt;&lt;P&gt; network-object DublinData 255.255.0.0&lt;/P&gt;&lt;P&gt; network-object SouthavenData 255.255.0.0&lt;/P&gt;&lt;P&gt; network-object GilbertData 255.255.0.0&lt;/P&gt;&lt;P&gt; network-object 172.22.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt; network-object DublinVoIP 255.255.0.0&lt;/P&gt;&lt;P&gt;object-group network PMI_SonicWALL-Subnets&lt;/P&gt;&lt;P&gt; network-object PMI_SonicWALL-Subnet 255.255.0.0&lt;/P&gt;&lt;P&gt; network-object PMI_SonicWALL-VOICSubnet 255.255.0.0&lt;/P&gt;&lt;P&gt;object-group network COLDCs&lt;/P&gt;&lt;P&gt; network-object host coldc01&lt;/P&gt;&lt;P&gt; network-object host coldc02&lt;/P&gt;&lt;P&gt;access-list inside_access_in remark Allow SMTP from certain servers.&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp object-group DM_INLINE_NETWORK_2 any eq smtp &lt;/P&gt;&lt;P&gt;access-list inside_access_in remark No SMTP except from allowed servers&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended deny tcp any any eq smtp log errors &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list inside_access_in remark For debugging (can enable logging)&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended deny ip any any &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow Ping&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow VPN&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group DM_INLINE_SERVICE_1 any object ColVPN- &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow SMTP, HTTP, and HTTPS to the Exchange CAS NLB Cluster&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object colexcas- object-group DM_INLINE_TCP_13 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow SMTP, SSH, and Web&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object ColBarracuda- object-group DM_INLINE_TCP_1 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow HTTP and HTTPS to AmbuTRAK&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object ambutrak- object-group DM_INLINE_TCP_10 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow SMTP, HTTP and HTTPS to ww2&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object ww2- object-group DM_INLINE_TCP_2 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow SMTP, HTTP and HTTPS to www1&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object www1- object-group DM_INLINE_TCP_3 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow portal.bouindtree.com to COLMOSS01&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object ColMOSS01- object-group DM_INLINE_TCP_9 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow HTTP and HTTPS to ems.COMPANY.com&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object Colww3- object-group DM_INLINE_TCP_5 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow HTTP and HTTPS to helpdesk.COMPANY.com&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object ColSysAid- object-group DM_INLINE_TCP_7 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow SSH to Facts&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object Facts- eq ssh inactive &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow mySQL to NSTrax for IQ&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object NSTrax- object-group mySQL inactive &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow FTP to ftp.COMPANY.co.uk&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object ftp.boundree.co.uk- eq ftp inactive &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow IMAP to the Voice Mail Server&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object Dubmss01- eq imap4 &lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;access-list outside_access_in remark Permit HTTPS to ColBI01 for &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://reports.COMPANY.com" target="_blank"&gt;https://reports.COMPANY.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object ColBI01- eq https inactive &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow FTP to btmu.COMPANY.com&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object btmu- eq ftp &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow HTTP and HTTPS to colngwt - the Test Next Gen Web Farm&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object dubngwt- object-group DM_INLINE_TCP_17 inactive &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow HTTP and HTTPS to COMPANYfed.com&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object COMPANYfed.com- object-group DM_INLINE_TCP_18 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow HTTP and HTTPS to colngwp - the Next Gen Web Farm&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object COMPANY.com- object-group DM_INLINE_TCP_11 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow HTTP and HTTPS to Colww5, which is one of our web servers.&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark rewards.COMPANY.com is going live first on this web server.&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object Rewards.COMPANY.com- object-group DM_INLINE_TCP_12 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow HTTP and HTTPS to act.COMPANY.com&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object act.COMPANY.com- object-group DM_INLINE_TCP_15 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow AS2 (443, 4080, 5080, 6080) to the AS2 Production and Test Machines&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object-group DM_INLINE_NETWORK_1 object-group as2 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow HTTP and HTTPS to &lt;A href="http://www.COMPANY.com" target="_blank"&gt;www.COMPANY.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object &lt;A href="https://community.cisco.com/www.COMPANY.com-" target="_blank"&gt;www.COMPANY.com-&lt;/A&gt; object-group DM_INLINE_TCP_14 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow AS2 to w2k-isoft&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object w2k-isoft- object-group as2 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark All SQL Server (SSL) to Coltixdb&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object Coltixdb- object-group SQLServer &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow FTP to ColFTP01&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object ColFTP01- eq ftp &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark allow http/https access in intra.COMPANY.com&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object intra.COMPANY.com- object-group DM_INLINE_TCP_6 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow http and https to asgard&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object &lt;A href="https://community.cisco.com/www.COMPANY.net-" target="_blank"&gt;www.COMPANY.net-&lt;/A&gt; object-group DM_INLINE_TCP_8 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow HTTP and HTTPS to ColCrmRouter01 (crmws.COMPANY.com)&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object crmws.COMPANY.com- object-group DM_INLINE_TCP_16 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow HTTP and HTTPS to coltmg01&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object coltmg01- object-group DM_INLINE_TCP_4 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow Lync Edgel traffic to collync01&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group TCPUDP any object collync01- object-group LyncEdge &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow HTTP and HTTPS to www1.COMPANY.com&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object www1.COMPANY.com- object-group DM_INLINE_TCP_19 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow HTTP and HTTPS to www2.COMPANY.com&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object www2.COMPANY.com- object-group DM_INLINE_TCP_20 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow HTTP and HTTPS to www1.COMPANYfed.com&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object www1.COMPANYfed.com- object-group DM_INLINE_TCP_21 &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark Allow HTTP and HTTPS to www2.COMPANYfed.com&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object www2.COMPANYfed.com- object-group DM_INLINE_TCP_22 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object monitor.COMPANY.com- eq www &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark For debugging (can enable logging)&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny ip any any &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip any 172.22.255.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip object-group PMIVPNNetworks object PMI_SonicWALL-Subnet &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound remark Domain Controller one to many rule so PCI Trust servers can reslove DNS names and authenticate.&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip object-group COLDCs 172.24.3.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip object ColWSUS02 172.24.3.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list outside_1_cryptomap extended permit ip object-group PMIVPNNetworks object-group PMI_SonicWALL-Subnets &lt;/P&gt;&lt;P&gt;access-list Colo_PCI_Trust_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm warnings&lt;/P&gt;&lt;P&gt;logging mail critical&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;logging from-address &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:colasa01@COMPANY.com" target="_blank"&gt;colasa01@COMPANY.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu Colo_PCI_Trust 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;ip local pool vpnphone-ip-pool 172.22.255.1-172.22.255.254 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface HA GigabitEthernet0/7&lt;/P&gt;&lt;P&gt;failover key Fiyalt!&lt;/P&gt;&lt;P&gt;failover link HA GigabitEthernet0/7&lt;/P&gt;&lt;P&gt;failover interface ip HA 172.16.200.1 255.255.255.248 standby 172.16.200.2&lt;/P&gt;&lt;P&gt;no monitor-interface DMZ&lt;/P&gt;&lt;P&gt;no monitor-interface Colo_PCI_Trust&lt;/P&gt;&lt;P&gt;no monitor-interface management&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;icmp permit 172.24.3.0 255.255.255.0 Colo_PCI_Trust&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-66114.bin&lt;/P&gt;&lt;P&gt;asdm location ColVPN- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ColBarracuda- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ColBarracuda 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ww2- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location www1- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ww2 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location www1 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location Colww3- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location Colww3 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ColSysAid- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ColSysAid 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location Facts 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location Facts- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location NSTrax- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ftp.boundree.co.uk- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ftp.COMPANY.co.uk 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location Dubmss01 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location Dubmss01- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ColBI01- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ColBI01 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ColMOSS01 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ColMOSS01- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ambutrak- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ambutrak 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location NSTrax 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location btmu- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location btmu 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location COMPANY.com- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location COMPANY.com 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location as2.COMPANY.com- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location colas2 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location w2k-isoft- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location w2k-isoft 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location Coltixdb- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location Coltixdb 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location colexcas- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location colexcas01 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location colexcas02 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location colexcas 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ColFTP01- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ColFTP01 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location &lt;A href="https://community.cisco.com/www.COMPANY.com-" target="_blank"&gt;www.COMPANY.com-&lt;/A&gt; 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location &lt;A href="https://community.cisco.com/www.COMPANY.com" target="_blank"&gt;www.COMPANY.com&lt;/A&gt; 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location act.COMPANY.com- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location act.COMPANY.com 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location Rewards.COMPANY.com- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location colww5 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location as2test.COMPANY.com- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ColdevAS2 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location test.COMPANY.com 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location colexcas01NLB 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location colexcas02NLB 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ColVPN 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location intra.COMPANY.com- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location intra.COMPANY.com 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location asgard 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location &lt;A href="https://community.cisco.com/www.COMPANY.net-" target="_blank"&gt;www.COMPANY.net-&lt;/A&gt; 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location crmws.COMPANY.com- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location crmws.COMPANY.com 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location dubngwt- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location dubngwt 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location dubexcas01 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location dubexcas02 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location dubexcas 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location collync01- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location coltmg01- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location collync01 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location coltmg01 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location COMPANYfed.com- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location COMPANYfed.com 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location www1.COMPANY.com- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location www2.COMPANY.com- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location www1.COMPANYfed.com- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location www2.COMPANYfed.com- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location www1.COMPANY.com 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location www2.COMPANY.com 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location www1.COMPANYfed.com 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location www2.COMPANYfed.com 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location PMI_SonicWALL-Subnet 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;asdm location PMISonicWALL 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location BrentwoodData 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;asdm location GilbertData 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;asdm location coldc01 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location coldc02 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ColWSUS02 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location monitor.COMPANY.com- 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;asdm location ColPRTG01 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat (inside,any) source static any any destination static obj-172.22.255.0 obj-172.22.255.0 no-proxy-arp&lt;/P&gt;&lt;P&gt;nat (inside,any) source static PMIVPNNetworks PMIVPNNetworks destination static PMI_SonicWALL-Subnet PMI_SonicWALL-Subnet no-proxy-arp&lt;/P&gt;&lt;P&gt;nat (inside,any) source static COLDCs COLDCs destination static obj-172.24.3.0 obj-172.24.3.0 no-proxy-arp&lt;/P&gt;&lt;P&gt;nat (inside,any) source static ColWSUS02 ColWSUS02 destination static obj-172.24.3.0 obj-172.24.3.0 no-proxy-arp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network ambutrak&lt;/P&gt;&lt;P&gt; nat (inside,outside) static ambutrak-&lt;/P&gt;&lt;P&gt;object network btmu&lt;/P&gt;&lt;P&gt; nat (inside,outside) static btmu-&lt;/P&gt;&lt;P&gt;object network ColBarracuda&lt;/P&gt;&lt;P&gt; nat (inside,outside) static ColBarracuda-&lt;/P&gt;&lt;P&gt;object network ColBI01&lt;/P&gt;&lt;P&gt; nat (inside,outside) static ColBI01-&lt;/P&gt;&lt;P&gt;object network colexcas&lt;/P&gt;&lt;P&gt; nat (inside,outside) static colexcas-&lt;/P&gt;&lt;P&gt;object network ColMOSS01&lt;/P&gt;&lt;P&gt; nat (inside,outside) static ColMOSS01-&lt;/P&gt;&lt;P&gt;object network COMPANY.com&lt;/P&gt;&lt;P&gt; nat (inside,outside) static COMPANY.com-&lt;/P&gt;&lt;P&gt;object network Coltixdb&lt;/P&gt;&lt;P&gt; nat (inside,outside) static Coltixdb-&lt;/P&gt;&lt;P&gt;object network Colww3&lt;/P&gt;&lt;P&gt; nat (inside,outside) static Colww3-&lt;/P&gt;&lt;P&gt;object network ColSysAid&lt;/P&gt;&lt;P&gt; nat (inside,outside) static ColSysAid-&lt;/P&gt;&lt;P&gt;object network ColVPN&lt;/P&gt;&lt;P&gt; nat (inside,outside) static ColVPN-&lt;/P&gt;&lt;P&gt;object network colas2&lt;/P&gt;&lt;P&gt; nat (inside,outside) static as2.COMPANY.com-&lt;/P&gt;&lt;P&gt;object network Dubmss01&lt;/P&gt;&lt;P&gt; nat (inside,outside) static Dubmss01-&lt;/P&gt;&lt;P&gt;object network Facts&lt;/P&gt;&lt;P&gt; nat (inside,outside) static Facts-&lt;/P&gt;&lt;P&gt;object network ftp.COMPANY.co.uk&lt;/P&gt;&lt;P&gt; nat (inside,outside) static ftp.COMPANY.co.uk-&lt;/P&gt;&lt;P&gt;object network NSTrax&lt;/P&gt;&lt;P&gt; nat (inside,outside) static NSTrax-&lt;/P&gt;&lt;P&gt;object network w2k-isoft&lt;/P&gt;&lt;P&gt; nat (inside,outside) static w2k-isoft-&lt;/P&gt;&lt;P&gt;object network www1&lt;/P&gt;&lt;P&gt; nat (inside,outside) static www1-&lt;/P&gt;&lt;P&gt;object network ww2&lt;/P&gt;&lt;P&gt; nat (inside,outside) static ww2-&lt;/P&gt;&lt;P&gt;object network ColFTP01&lt;/P&gt;&lt;P&gt; nat (inside,outside) static ColFTP01-&lt;/P&gt;&lt;P&gt;object network &lt;A href="http://www.COMPANY.com" target="_blank"&gt;www.COMPANY.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt; nat (inside,outside) static &lt;A href="http://www.COMPANY.com-" target="_blank"&gt;www.COMPANY.com-&lt;/A&gt;&lt;/P&gt;&lt;P&gt;object network act.COMPANY.com&lt;/P&gt;&lt;P&gt; nat (inside,outside) static act.COMPANY.com-&lt;/P&gt;&lt;P&gt;object network colww5&lt;/P&gt;&lt;P&gt; nat (inside,outside) static Rewards.COMPANY.com-&lt;/P&gt;&lt;P&gt;object network ColdevAS2&lt;/P&gt;&lt;P&gt; nat (inside,outside) static as2test.COMPANY.com-&lt;/P&gt;&lt;P&gt;object network intra.COMPANY.com&lt;/P&gt;&lt;P&gt; nat (inside,outside) static intra.COMPANY.com-&lt;/P&gt;&lt;P&gt;object network asgard&lt;/P&gt;&lt;P&gt; nat (inside,outside) static &lt;A href="http://www.COMPANY.net-" target="_blank"&gt;www.COMPANY.net-&lt;/A&gt;&lt;/P&gt;&lt;P&gt;object network crmws.COMPANY.com&lt;/P&gt;&lt;P&gt; nat (inside,outside) static crmws.COMPANY.com-&lt;/P&gt;&lt;P&gt;object network dubngwt&lt;/P&gt;&lt;P&gt; nat (inside,outside) static dubngwt-&lt;/P&gt;&lt;P&gt;object network COMPANYfed.com&lt;/P&gt;&lt;P&gt; nat (inside,outside) static COMPANYfed.com-&lt;/P&gt;&lt;P&gt;object network www1.COMPANYfed.com&lt;/P&gt;&lt;P&gt; nat (inside,outside) static www1.COMPANYfed.com-&lt;/P&gt;&lt;P&gt;object network www2.COMPANYfed.com&lt;/P&gt;&lt;P&gt; nat (inside,outside) static www2.COMPANYfed.com-&lt;/P&gt;&lt;P&gt;object network www1.COMPANY.com&lt;/P&gt;&lt;P&gt; nat (inside,outside) static www1.COMPANY.com-&lt;/P&gt;&lt;P&gt;object network www2.COMPANY.com&lt;/P&gt;&lt;P&gt; nat (inside,outside) static www2.COMPANY.com-&lt;/P&gt;&lt;P&gt;object network ColPRTG01&lt;/P&gt;&lt;P&gt; nat (inside,outside) static monitor.COMPANY.com-&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic 74.XXX.XXX.131&lt;/P&gt;&lt;P&gt;object network collync01&lt;/P&gt;&lt;P&gt; nat (DMZ,outside) static collync01-&lt;/P&gt;&lt;P&gt;object network coltmg01&lt;/P&gt;&lt;P&gt; nat (DMZ,outside) static coltmg01-&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group Colo_PCI_Trust_access_in in interface Colo_PCI_Trust&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;router eigrp 10&lt;/P&gt;&lt;P&gt; no auto-summary&lt;/P&gt;&lt;P&gt; eigrp router-id 172.22.1.8&lt;/P&gt;&lt;P&gt; network 172.22.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 74.XXX.XXX.129 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;aaa-server Colo protocol radius&lt;/P&gt;&lt;P&gt;aaa-server Colo (inside) host coldc02&lt;/P&gt;&lt;P&gt; timeout 5&lt;/P&gt;&lt;P&gt; key Bound/\Tree&lt;/P&gt;&lt;P&gt; radius-common-pw Bound/\Tree&lt;/P&gt;&lt;P&gt;aaa-server Colo (inside) host coldc01&lt;/P&gt;&lt;P&gt; timeout 5&lt;/P&gt;&lt;P&gt; key Bound/\Tree&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 172.22.0.0 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;http DublinData 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;http DublinData 255.255.0.0 management&lt;/P&gt;&lt;P&gt;snmp-server host inside 10.1.0.59 community public&lt;/P&gt;&lt;P&gt;snmp-server host inside ColPRTG01 community public&lt;/P&gt;&lt;P&gt;snmp-server location Columbus, OH - Colo&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 match address outside_1_cryptomap&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set pfs &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set peer PMISonicWALL &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set ikev1 transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set nat-t-disable&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;crypto ikev1 enable outside&lt;/P&gt;&lt;P&gt;crypto ikev1 enable inside&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 30&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 28800&lt;/P&gt;&lt;P&gt;telnet BrentwoodData 255.0.0.0 inside&lt;/P&gt;&lt;P&gt;telnet coldc02 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;telnet DublinData 255.255.0.0 management&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 172.22.0.0 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;ssh DublinData 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics&lt;/P&gt;&lt;P&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;/P&gt;&lt;P&gt;ntp server 74.14.179.211 source outside prefer&lt;/P&gt;&lt;P&gt;ntp server 69.64.72.238 source outside prefer&lt;/P&gt;&lt;P&gt;ntp server coldc02 source inside&lt;/P&gt;&lt;P&gt;ntp server 74.120.8.2 source outside prefer&lt;/P&gt;&lt;P&gt;ntp server 108.61.56.35 source outside prefer&lt;/P&gt;&lt;P&gt;ntp server coldc01 source inside&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;group-policy GroupPolicy_74.XXX.XXX.130 internal&lt;/P&gt;&lt;P&gt;group-policy GroupPolicy_74.XXX.XXX.130 attributes&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol ikev1 &lt;/P&gt;&lt;P&gt;group-policy VPNPHONE internal&lt;/P&gt;&lt;P&gt;group-policy VPNPHONE attributes&lt;/P&gt;&lt;P&gt; dns-server value 172.22.3.4 172.22.3.31&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol ikev1 &lt;/P&gt;&lt;P&gt; default-domain value corp.COMPANY.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group VPNPHONE type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group VPNPHONE general-attributes&lt;/P&gt;&lt;P&gt; address-pool vpnphone-ip-pool&lt;/P&gt;&lt;P&gt; authentication-server-group Colo&lt;/P&gt;&lt;P&gt; default-group-policy VPNPHONE&lt;/P&gt;&lt;P&gt;tunnel-group VPNPHONE ipsec-attributes&lt;/P&gt;&lt;P&gt; ikev1 pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group 184.XXX.XXX.226 type ipsec-l2l&lt;/P&gt;&lt;P&gt;tunnel-group 184.XXX.XXX.226 ipsec-attributes&lt;/P&gt;&lt;P&gt; ikev1 pre-shared-key *&lt;/P&gt;&lt;P&gt; peer-id-validate nocheck&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns migrated_dns_map_1 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect http &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect pptp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp error &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options &lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;smtp-server 172.22.5.156&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;call-home&lt;/P&gt;&lt;P&gt; profile CiscoTAC-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no active&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address http &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address email &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:callhome@cisco.com" target="_blank"&gt;callhome@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination transport-method http&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly 18&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly 18&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;/P&gt;&lt;P&gt;Cryptochecksum:65e78911eefb94bd98892700b143f716&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:45:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5520-to-5525-all-access-rules-being-ignored/m-p/2290954#M342339</guid>
      <dc:creator>sarnovait</dc:creator>
      <dc:date>2019-03-12T02:45:07Z</dc:date>
    </item>
    <item>
      <title>5520 to 5525 all access rules being ignored.</title>
      <link>https://community.cisco.com/t5/network-security/5520-to-5525-all-access-rules-being-ignored/m-p/2290955#M342344</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess it would be best to start with a &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; test and see if there is anything clear problem with the configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So take some server that has Static NAT and ACL rule and issue a&lt;STRONG&gt; "packet-tracer"&lt;/STRONG&gt; command simulating a connection that should pass the firewall ACL and configurations&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input outside tcp &lt;SOURCE ip=""&gt; &lt;SOURCE port=""&gt; &lt;DESTINATION nat="" ip=""&gt; &lt;DESTINATION port=""&gt;&lt;/DESTINATION&gt;&lt;/DESTINATION&gt;&lt;/SOURCE&gt;&lt;/SOURCE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And post the output here while masking your public IP address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I presume from your above post that NOTHING is working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didnt go through the whole external ACL but it seems to me that there is quite a lot of ACL rules that refer to the NAT IP address of the servers you have? In the newer software you have to always allow traffic to the real IP address, never to the NAT IP address like in 8.2 and before software levels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though to my understanding your ASA5520 was already running some software that is 8.3 or above since otherwise the ASA5525-X running 8.6 minimum wouldnt accept the configurations since there are huge NAT changes and the above mentioned ACL change.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 14:41:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5520-to-5525-all-access-rules-being-ignored/m-p/2290955#M342344</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-09-30T14:41:52Z</dc:date>
    </item>
    <item>
      <title>5520 to 5525 all access rules being ignored.</title>
      <link>https://community.cisco.com/t5/network-security/5520-to-5525-all-access-rules-being-ignored/m-p/2290956#M342346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And just to add,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to me that you have &lt;STRONG&gt;"object"&lt;/STRONG&gt; that are otherwise the same but other have the &lt;STRONG&gt;DASH ( - ) &lt;/STRONG&gt;mark at the end of the name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The one with the &lt;STRONG&gt;DASH&lt;/STRONG&gt; seems to have the public NAT IP address inside it and the one &lt;STRONG&gt;WITHOUT&lt;/STRONG&gt; the &lt;STRONG&gt;DASH&lt;/STRONG&gt; has the real IP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should therefore use the &lt;STRONG&gt;"object" WITHOUT&lt;/STRONG&gt; the &lt;STRONG&gt;DASH&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 14:44:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5520-to-5525-all-access-rules-being-ignored/m-p/2290956#M342346</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-09-30T14:44:17Z</dc:date>
    </item>
    <item>
      <title>5520 to 5525 all access rules being ignored.</title>
      <link>https://community.cisco.com/t5/network-security/5520-to-5525-all-access-rules-being-ignored/m-p/2290957#M342350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes the one's with the dash '-' at the end is the external IP address.&amp;nbsp; I always thought this was strange as I inherited this setup/config.&amp;nbsp; So the destination in the Access Rules should be the internal address not the external address.&amp;nbsp; Correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But is it not strange that this works on the old ASA 5520?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 15:29:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5520-to-5525-all-access-rules-being-ignored/m-p/2290957#M342350</guid>
      <dc:creator>sarnovait</dc:creator>
      <dc:date>2013-09-30T15:29:52Z</dc:date>
    </item>
    <item>
      <title>5520 to 5525 all access rules being ignored.</title>
      <link>https://community.cisco.com/t5/network-security/5520-to-5525-all-access-rules-being-ignored/m-p/2290958#M342352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ASA using software 8.3 or above that does Static NAT between private and public IP addresses (or any NAT at all) and you want to allow traffic from public network to those Static NATed servers you will need to use the local/real IP address in the ACL statements.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your ASA5520 was running 8.3 or above software levels then there should be no major changes compared to an ASA5525-X running 8.6 software level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only situation I can think of right now is if you had used ASA5520 with software 8.2 or below BUT in that case you WOULD NOT have been able to directly copy/paste the configuration to the ASA5525-X device as the lowest software level that the ASA5525-X supports is 8.6(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I am kind of wondering what the situation has actually been.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But one thing is certain. You need to use the real/local IP address of the server in the ACL rules even if you are allowing traffic from the public/external network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; test used to simulate a connection coming to one of your Static NAT public IP address should also tell if your ACLs are configured correctly, among other things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 15:36:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5520-to-5525-all-access-rules-being-ignored/m-p/2290958#M342352</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-09-30T15:36:36Z</dc:date>
    </item>
  </channel>
</rss>

