<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic add inter vlan to existing ASA 5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320496#M344527</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you, I am going to take my laptop on that switch and configure IP taht is in VLAN 30, than I use cmd that you have suggested me. &lt;/P&gt;&lt;P&gt;i will post my result later,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 Aug 2013 19:14:30 GMT</pubDate>
    <dc:creator>Mukesh Brahmbhatt</dc:creator>
    <dc:date>2013-08-19T19:14:30Z</dc:date>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320485#M344515</link>
      <description>&lt;P&gt;I am totally new for ASA line.&lt;/P&gt;&lt;P&gt;we add Shoretel phone system in network, security office has restricted us to install it in existing network, so I&amp;nbsp; create new vlan 30 on sub interface. I can't access any phone from internal network and phone are not able to get any boot image from internal network either. I am loosing sleep, i hav only deleted certification crypto off it.&lt;/P&gt;&lt;P&gt;below is our run config&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;gsfcasa# show run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.4(4)9&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;nameif ext&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 168.29.236.16 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;nameif int&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 172.21.191.121 255.255.0.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.1&lt;/P&gt;&lt;P&gt;description GSFC Guest Wifi access wpa2 key&lt;/P&gt;&lt;P&gt;vlan 10&lt;/P&gt;&lt;P&gt;nameif GSFC_GUEST_WIFI&lt;/P&gt;&lt;P&gt;security-level 1&lt;/P&gt;&lt;P&gt;ip address 172.17.10.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.30&lt;/P&gt;&lt;P&gt;vlan 30&lt;/P&gt;&lt;P&gt;nameif GSFC_ShoreTel_LAN&lt;/P&gt;&lt;P&gt;security-level 2&lt;/P&gt;&lt;P&gt;ip address 172.17.30.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.50&lt;/P&gt;&lt;P&gt;description Agency WiFi access to internal server&lt;/P&gt;&lt;P&gt;vlan 20&lt;/P&gt;&lt;P&gt;nameif GSFC_WiFi&lt;/P&gt;&lt;P&gt;security-level 1&lt;/P&gt;&lt;P&gt;ip address 172.17.20.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;description Email and IAG DMZ area&lt;/P&gt;&lt;P&gt;nameif DMZ&lt;/P&gt;&lt;P&gt;security-level 25&lt;/P&gt;&lt;P&gt;ip address 172.26.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;description Non-Public Education Commission (2nd floor across hall from I.T.)&lt;/P&gt;&lt;P&gt;nameif NPEC&lt;/P&gt;&lt;P&gt;security-level 50&lt;/P&gt;&lt;P&gt;ip address 172.26.100.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt;nameif train&lt;/P&gt;&lt;P&gt;security-level 75&lt;/P&gt;&lt;P&gt;ip address 172.17.2.200 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0.110&lt;/P&gt;&lt;P&gt;description Phyisical Security Monitoring VLAN&lt;/P&gt;&lt;P&gt;vlan 110&lt;/P&gt;&lt;P&gt;nameif PSM&lt;/P&gt;&lt;P&gt;security-level 75&lt;/P&gt;&lt;P&gt;ip address 172.17.3.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa844-9-k8.bin&lt;/P&gt;&lt;P&gt;boot system disk0:/asa843-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;dns domain-lookup ext&lt;/P&gt;&lt;P&gt;dns domain-lookup int&lt;/P&gt;&lt;P&gt;dns domain-lookup GSFC_WiFi&lt;/P&gt;&lt;P&gt;dns domain-lookup DMZ&lt;/P&gt;&lt;P&gt;dns domain-lookup NPEC&lt;/P&gt;&lt;P&gt;dns domain-lookup train&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt;name-server 172.21.192.134&lt;/P&gt;&lt;P&gt;name-server 172.21.192.133&lt;/P&gt;&lt;P&gt;domain-name gsfc.org&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object network Security_mgr&lt;/P&gt;&lt;P&gt;host 172.21.70.10&lt;/P&gt;&lt;P&gt;object network Int_net&lt;/P&gt;&lt;P&gt;subnet 172.21.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;description internal network&lt;/P&gt;&lt;P&gt;object network Ext_hide_behind&lt;/P&gt;&lt;P&gt;host 168.29.236.98&lt;/P&gt;&lt;P&gt;object network Dmz_hide_behind&lt;/P&gt;&lt;P&gt;host 172.26.1.11&lt;/P&gt;&lt;P&gt;object network DMZ_Net&lt;/P&gt;&lt;P&gt;subnet 172.26.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network NPEC_NET&lt;/P&gt;&lt;P&gt;subnet 172.26.100.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network NPEC_hide_behind&lt;/P&gt;&lt;P&gt;host 172.26.100.51&lt;/P&gt;&lt;P&gt;object network TMCS_IP&lt;/P&gt;&lt;P&gt;host 172.21.95.1&lt;/P&gt;&lt;P&gt;object network Npec_email_ext_address&lt;/P&gt;&lt;P&gt;host 168.29.236.101&lt;/P&gt;&lt;P&gt;object network Npec_ext_Hidebehind&lt;/P&gt;&lt;P&gt;host 168.29.236.55&lt;/P&gt;&lt;P&gt;object network GSFC_email_ext_address&lt;/P&gt;&lt;P&gt;host 168.29.236.100&lt;/P&gt;&lt;P&gt;object network Cartman&lt;/P&gt;&lt;P&gt;host 172.21.13.20&lt;/P&gt;&lt;P&gt;object network Connect_Direct_Ext_Address&lt;/P&gt;&lt;P&gt;host 168.29.236.50&lt;/P&gt;&lt;P&gt;object network DOR_GTA&lt;/P&gt;&lt;P&gt;host 167.192.62.227&lt;/P&gt;&lt;P&gt;object network Exchange07&lt;/P&gt;&lt;P&gt;host 172.21.13.7&lt;/P&gt;&lt;P&gt;object network IAG_Internal_Nic&lt;/P&gt;&lt;P&gt;host 172.26.1.30&lt;/P&gt;&lt;P&gt;object network IAG_Internet_address&lt;/P&gt;&lt;P&gt;host 168.29.236.26&lt;/P&gt;&lt;P&gt;object network Kenny&lt;/P&gt;&lt;P&gt;host 172.21.13.22&lt;/P&gt;&lt;P&gt;object service ConnectDirect&lt;/P&gt;&lt;P&gt;service tcp destination eq 1364&lt;/P&gt;&lt;P&gt;object service IAG_Ext_Port&lt;/P&gt;&lt;P&gt;service tcp destination eq 3443&lt;/P&gt;&lt;P&gt;object network int_hide_behind&lt;/P&gt;&lt;P&gt;host 172.21.191.221&lt;/P&gt;&lt;P&gt;object network GL_Int_nat&lt;/P&gt;&lt;P&gt;subnet 172.17.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;description Addresses Natted for GL to Gsfc internal access&lt;/P&gt;&lt;P&gt;object network GL_Subnet&lt;/P&gt;&lt;P&gt;subnet 64.73.69.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network GL_FW_INTERFACE&lt;/P&gt;&lt;P&gt;host 64.73.69.8&lt;/P&gt;&lt;P&gt;object network gl_nat_test_hidebhind&lt;/P&gt;&lt;P&gt;host 172.17.1.1&lt;/P&gt;&lt;P&gt;object network GL_Hidebehind_ipaddress&lt;/P&gt;&lt;P&gt;host 64.73.69.8&lt;/P&gt;&lt;P&gt;object network GL_TO_FUXAP_NAT&lt;/P&gt;&lt;P&gt;host 172.17.50.2&lt;/P&gt;&lt;P&gt;object network secureftp&lt;/P&gt;&lt;P&gt;host 172.21.80.100&lt;/P&gt;&lt;P&gt;object service CISCO_VPN&lt;/P&gt;&lt;P&gt;service udp destination eq 4500&lt;/P&gt;&lt;P&gt;object service CISCO_VPN_PORT&lt;/P&gt;&lt;P&gt;service tcp destination eq 8014&lt;/P&gt;&lt;P&gt;object service Citrix1495&lt;/P&gt;&lt;P&gt;service tcp destination eq 1495&lt;/P&gt;&lt;P&gt;object service Citrix1604&lt;/P&gt;&lt;P&gt;service udp destination eq 1604&lt;/P&gt;&lt;P&gt;object service Document_Direct&lt;/P&gt;&lt;P&gt;service tcp destination eq 203&lt;/P&gt;&lt;P&gt;description DOAS Payroll reporting&lt;/P&gt;&lt;P&gt;object service Edconnect&lt;/P&gt;&lt;P&gt;service tcp destination eq 26581&lt;/P&gt;&lt;P&gt;object service HTTP8000&lt;/P&gt;&lt;P&gt;service tcp destination eq 8000&lt;/P&gt;&lt;P&gt;object service HTTP8080&lt;/P&gt;&lt;P&gt;service tcp destination eq 8080&lt;/P&gt;&lt;P&gt;object service HTTP8890&lt;/P&gt;&lt;P&gt;service tcp destination eq 8890&lt;/P&gt;&lt;P&gt;object service TCP9000&lt;/P&gt;&lt;P&gt;service tcp destination eq 9000&lt;/P&gt;&lt;P&gt;object service TCP9191&lt;/P&gt;&lt;P&gt;service tcp destination eq 9191&lt;/P&gt;&lt;P&gt;object service Time&lt;/P&gt;&lt;P&gt;service tcp destination eq 37&lt;/P&gt;&lt;P&gt;object service Time_udp&lt;/P&gt;&lt;P&gt;service udp destination eq time&lt;/P&gt;&lt;P&gt;object network GL_Morpheus&lt;/P&gt;&lt;P&gt;host 172.17.1.106&lt;/P&gt;&lt;P&gt;object network GL_PRT_AUTHPRT&lt;/P&gt;&lt;P&gt;host 172.17.1.131&lt;/P&gt;&lt;P&gt;object network GL_PRT_CRLINE&lt;/P&gt;&lt;P&gt;host 172.17.1.152&lt;/P&gt;&lt;P&gt;object network GL_PRT_Computer_room_laser&lt;/P&gt;&lt;P&gt;host 172.17.1.122&lt;/P&gt;&lt;P&gt;object network GL_PRT_DISM&lt;/P&gt;&lt;P&gt;host 172.17.1.153&lt;/P&gt;&lt;P&gt;object network GL_PRT_GSLADM&lt;/P&gt;&lt;P&gt;host 172.17.1.147&lt;/P&gt;&lt;P&gt;object network GL_PRT_GSLCOL&lt;/P&gt;&lt;P&gt;host 172.17.1.46&lt;/P&gt;&lt;P&gt;object network GL_PRT_IS4SI&lt;/P&gt;&lt;P&gt;host 172.17.1.123&lt;/P&gt;&lt;P&gt;object network GL_Rhett&lt;/P&gt;&lt;P&gt;host 172.17.1.11&lt;/P&gt;&lt;P&gt;object network GL_Scarlett&lt;/P&gt;&lt;P&gt;host 172.17.1.10&lt;/P&gt;&lt;P&gt;object network GL_Tumbleweed&lt;/P&gt;&lt;P&gt;host 172.17.1.100&lt;/P&gt;&lt;P&gt;object network Morpheus&lt;/P&gt;&lt;P&gt;host 172.21.192.142&lt;/P&gt;&lt;P&gt;object network PRT_AUTH&lt;/P&gt;&lt;P&gt;host 172.21.193.131&lt;/P&gt;&lt;P&gt;object network PRT_CRLINE&lt;/P&gt;&lt;P&gt;host 172.21.193.152&lt;/P&gt;&lt;P&gt;object network PRT_DISM&lt;/P&gt;&lt;P&gt;host 172.21.193.140&lt;/P&gt;&lt;P&gt;object network PRT_GSLADM&lt;/P&gt;&lt;P&gt;host 172.21.193.147&lt;/P&gt;&lt;P&gt;object network PRT_IS4SI&lt;/P&gt;&lt;P&gt;host 172.21.193.123&lt;/P&gt;&lt;P&gt;object network PRT_computer_rm_laser&lt;/P&gt;&lt;P&gt;host 172.21.193.122&lt;/P&gt;&lt;P&gt;object network PRT_gslcolprt&lt;/P&gt;&lt;P&gt;host 172.21.193.46&lt;/P&gt;&lt;P&gt;object network Rhett&lt;/P&gt;&lt;P&gt;host 172.21.192.125&lt;/P&gt;&lt;P&gt;object network Scarlett&lt;/P&gt;&lt;P&gt;host 172.21.192.124&lt;/P&gt;&lt;P&gt;object network Tumbleweed&lt;/P&gt;&lt;P&gt;host 172.26.1.5&lt;/P&gt;&lt;P&gt;object network Balrog&lt;/P&gt;&lt;P&gt;host 172.21.192.134&lt;/P&gt;&lt;P&gt;object network Site_Protector&lt;/P&gt;&lt;P&gt;host 172.21.13.50&lt;/P&gt;&lt;P&gt;object service ISS902&lt;/P&gt;&lt;P&gt;service tcp destination eq 902&lt;/P&gt;&lt;P&gt;object service ISS_2998&lt;/P&gt;&lt;P&gt;service tcp destination eq 2998&lt;/P&gt;&lt;P&gt;object network Training_room_PCs&lt;/P&gt;&lt;P&gt;range 172.17.2.1 172.17.2.100&lt;/P&gt;&lt;P&gt;object network CRM_Server&lt;/P&gt;&lt;P&gt;host 172.21.13.15&lt;/P&gt;&lt;P&gt;object network GSFC_PORTAL&lt;/P&gt;&lt;P&gt;host 172.21.13.30&lt;/P&gt;&lt;P&gt;object network Imageapp&lt;/P&gt;&lt;P&gt;host 172.21.13.11&lt;/P&gt;&lt;P&gt;object network Intranet_server&lt;/P&gt;&lt;P&gt;host 172.21.195.125&lt;/P&gt;&lt;P&gt;object network MS_update_server&lt;/P&gt;&lt;P&gt;host 172.21.13.29&lt;/P&gt;&lt;P&gt;object network Novell_GSF1&lt;/P&gt;&lt;P&gt;host 172.21.192.123&lt;/P&gt;&lt;P&gt;object network Oraappprod&lt;/P&gt;&lt;P&gt;host 172.21.13.150&lt;/P&gt;&lt;P&gt;object network Symantec_Ent_Server&lt;/P&gt;&lt;P&gt;host 172.21.13.145&lt;/P&gt;&lt;P&gt;object network visnetic411&lt;/P&gt;&lt;P&gt;host 172.21.13.14&lt;/P&gt;&lt;P&gt;object service NCP&lt;/P&gt;&lt;P&gt;service tcp destination eq 524&lt;/P&gt;&lt;P&gt;object service ODBC&lt;/P&gt;&lt;P&gt;service tcp destination eq 1433&lt;/P&gt;&lt;P&gt;object service Oraapp&lt;/P&gt;&lt;P&gt;service tcp destination eq 7778&lt;/P&gt;&lt;P&gt;object network Train_Hide_Behind&lt;/P&gt;&lt;P&gt;host 172.17.2.25&lt;/P&gt;&lt;P&gt;object service ISS_901&lt;/P&gt;&lt;P&gt;service tcp destination eq 901&lt;/P&gt;&lt;P&gt;object network Marks_PC&lt;/P&gt;&lt;P&gt;host 172.21.70.236&lt;/P&gt;&lt;P&gt;description Security Admin&lt;/P&gt;&lt;P&gt;object network Blackberry_server&lt;/P&gt;&lt;P&gt;host 172.21.13.4&lt;/P&gt;&lt;P&gt;object service Time_123&lt;/P&gt;&lt;P&gt;service udp destination eq ntp&lt;/P&gt;&lt;P&gt;object network GL_FTP_SITE&lt;/P&gt;&lt;P&gt;host 64.73.69.41&lt;/P&gt;&lt;P&gt;object network GL_FUXAP&lt;/P&gt;&lt;P&gt;host 172.17.1.50&lt;/P&gt;&lt;P&gt;object network CR_File_transfer_server&lt;/P&gt;&lt;P&gt;host 172.21.70.86&lt;/P&gt;&lt;P&gt;object network Operator_PC1&lt;/P&gt;&lt;P&gt;host 172.21.70.57&lt;/P&gt;&lt;P&gt;object network visnetic&lt;/P&gt;&lt;P&gt;host 172.21.80.204&lt;/P&gt;&lt;P&gt;object service DOAS_PORT&lt;/P&gt;&lt;P&gt;service tcp destination eq 65051&lt;/P&gt;&lt;P&gt;object service SFTP&lt;/P&gt;&lt;P&gt;service tcp destination eq ssh&lt;/P&gt;&lt;P&gt;object network Salie_Mae_ftp_server&lt;/P&gt;&lt;P&gt;host 167.104.7.15&lt;/P&gt;&lt;P&gt;object network Terminal_server&lt;/P&gt;&lt;P&gt;host 172.21.13.97&lt;/P&gt;&lt;P&gt;object service DOAS_port2&lt;/P&gt;&lt;P&gt;service tcp destination eq 65001&lt;/P&gt;&lt;P&gt;object network Anthony_Rais&lt;/P&gt;&lt;P&gt;host 172.21.70.25&lt;/P&gt;&lt;P&gt;object service GTA_BILL2&lt;/P&gt;&lt;P&gt;service tcp destination eq 8443&lt;/P&gt;&lt;P&gt;object service VPN&lt;/P&gt;&lt;P&gt;service tcp destination eq 500&lt;/P&gt;&lt;P&gt;object service VPN_udp&lt;/P&gt;&lt;P&gt;service udp destination eq isakmp&lt;/P&gt;&lt;P&gt;object network gsfc.mylenderhome.org&lt;/P&gt;&lt;P&gt;host 64.73.69.136&lt;/P&gt;&lt;P&gt;object network SPA&lt;/P&gt;&lt;P&gt;host 172.21.13.12&lt;/P&gt;&lt;P&gt;object network SPB&lt;/P&gt;&lt;P&gt;host 172.21.13.13&lt;/P&gt;&lt;P&gt;object network DOR_GTA_2&lt;/P&gt;&lt;P&gt;host 167.196.94.180&lt;/P&gt;&lt;P&gt;object service Emulate_live&lt;/P&gt;&lt;P&gt;service tcp destination eq 2187&lt;/P&gt;&lt;P&gt;description For Sarah B&lt;/P&gt;&lt;P&gt;object service UGA_EDU_Web_Port&lt;/P&gt;&lt;P&gt;service tcp destination eq 5443&lt;/P&gt;&lt;P&gt;object service MS_Live_meeting_port&lt;/P&gt;&lt;P&gt;service tcp destination eq 8057&lt;/P&gt;&lt;P&gt;object network MS_Live_Meeting_srv&lt;/P&gt;&lt;P&gt;host 204.176.46.248&lt;/P&gt;&lt;P&gt;object network NETWORK_OBJ_172.21.86.0_29&lt;/P&gt;&lt;P&gt;subnet 172.21.86.0 255.255.255.248&lt;/P&gt;&lt;P&gt;object network Timmy&lt;/P&gt;&lt;P&gt;host 172.21.192.211&lt;/P&gt;&lt;P&gt;object network FUXAP&lt;/P&gt;&lt;P&gt;host 172.21.192.50&lt;/P&gt;&lt;P&gt;object network gsfcfaxserver&lt;/P&gt;&lt;P&gt;host 172.21.15.5&lt;/P&gt;&lt;P&gt;object network GL_Subnet_New&lt;/P&gt;&lt;P&gt;subnet 12.175.4.0 255.255.255.0&lt;/P&gt;&lt;P&gt;description Great Lakes New IP range&lt;/P&gt;&lt;P&gt;object network Oracle_DB_Admin&lt;/P&gt;&lt;P&gt;host 172.21.70.5&lt;/P&gt;&lt;P&gt;object network NPEC_ASA_FW&lt;/P&gt;&lt;P&gt;range 172.26.1.75 172.26.1.95&lt;/P&gt;&lt;P&gt;object service AES_SFTP_PORT&lt;/P&gt;&lt;P&gt;service tcp destination eq 10022&lt;/P&gt;&lt;P&gt;description AES non standard Secure FTP port&lt;/P&gt;&lt;P&gt;object service GL_TELNET_SSL&lt;/P&gt;&lt;P&gt;service tcp destination eq 992&lt;/P&gt;&lt;P&gt;object service gosaxfrd.dev.bor.usg.edu&lt;/P&gt;&lt;P&gt;service tcp destination eq 2065&lt;/P&gt;&lt;P&gt;object network gosaxfrd&lt;/P&gt;&lt;P&gt;host 168.25.9.11&lt;/P&gt;&lt;P&gt;description landing sever in the USG environment&lt;/P&gt;&lt;P&gt;object network log-me-in&lt;/P&gt;&lt;P&gt;host 64.74.103.144&lt;/P&gt;&lt;P&gt;object network VPN_Tumbleweed_NAT&lt;/P&gt;&lt;P&gt;host 172.21.81.211&lt;/P&gt;&lt;P&gt;object network vpn_tumbleweed_address&lt;/P&gt;&lt;P&gt;host 172.26.1.5&lt;/P&gt;&lt;P&gt;object network gsfcasaweb_int_nat&lt;/P&gt;&lt;P&gt;host 172.21.191.150&lt;/P&gt;&lt;P&gt;object network securemail_mygreatlakes_org&lt;/P&gt;&lt;P&gt;host 12.175.4.219&lt;/P&gt;&lt;P&gt;object network Default_Aversion_1&lt;/P&gt;&lt;P&gt;host 172.21.20.55&lt;/P&gt;&lt;P&gt;object network Default_Aversion_2&lt;/P&gt;&lt;P&gt;host 172.21.30.1&lt;/P&gt;&lt;P&gt;object network Default_Aversion_3&lt;/P&gt;&lt;P&gt;host 172.21.30.28&lt;/P&gt;&lt;P&gt;object network Default_Aversion_4&lt;/P&gt;&lt;P&gt;host 172.21.30.29&lt;/P&gt;&lt;P&gt;object network Default_Aversion_5&lt;/P&gt;&lt;P&gt;host 172.21.30.30&lt;/P&gt;&lt;P&gt;object network Default_Aversion_6&lt;/P&gt;&lt;P&gt;host 172.21.30.31&lt;/P&gt;&lt;P&gt;object network Default_Aversion_7&lt;/P&gt;&lt;P&gt;host 172.21.30.39&lt;/P&gt;&lt;P&gt;object network Default_Aversion_8&lt;/P&gt;&lt;P&gt;host 172.21.50.68&lt;/P&gt;&lt;P&gt;object service GOSAXFR.PROD.REGENTS.USG_ONS&lt;/P&gt;&lt;P&gt;service tcp destination eq 8065&lt;/P&gt;&lt;P&gt;object service GOSAXFRT.EAS.REGENTS.USG_ONS&lt;/P&gt;&lt;P&gt;service tcp destination eq 5065&lt;/P&gt;&lt;P&gt;object network gl_subnet_DR&lt;/P&gt;&lt;P&gt;subnet 12.45.44.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network Wifi_Hidebehind_ext&lt;/P&gt;&lt;P&gt;host 168.29.236.90&lt;/P&gt;&lt;P&gt;object network EdOne_sub&lt;/P&gt;&lt;P&gt;subnet 10.222.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network Int_to_EdOne_hidebehind&lt;/P&gt;&lt;P&gt;host 10.222.1.254&lt;/P&gt;&lt;P&gt;object network Brain&lt;/P&gt;&lt;P&gt;host 172.21.192.12&lt;/P&gt;&lt;P&gt;description Time Server&lt;/P&gt;&lt;P&gt;object network Solarwinds-LEM&lt;/P&gt;&lt;P&gt;host 172.21.80.201&lt;/P&gt;&lt;P&gt;object service Solarwinds_LEM_Ports&lt;/P&gt;&lt;P&gt;service tcp destination range 37890 37892&lt;/P&gt;&lt;P&gt;description Solarwinds LEM monitoring ports&lt;/P&gt;&lt;P&gt;object network Bldg_Manager&lt;/P&gt;&lt;P&gt;host 172.21.60.76&lt;/P&gt;&lt;P&gt;object service Security_cammeras&lt;/P&gt;&lt;P&gt;service tcp destination eq 943&lt;/P&gt;&lt;P&gt;object service Security_Cammeras_2&lt;/P&gt;&lt;P&gt;service tcp destination eq 4520&lt;/P&gt;&lt;P&gt;object network DL_Agent_PCs&lt;/P&gt;&lt;P&gt;range 10.222.1.1 10.222.1.255&lt;/P&gt;&lt;P&gt;object service AD_SMB&lt;/P&gt;&lt;P&gt;service tcp destination eq 445&lt;/P&gt;&lt;P&gt;object network Onesign&lt;/P&gt;&lt;P&gt;host 172.21.80.205&lt;/P&gt;&lt;P&gt;description Imprivata onesign 2FA&lt;/P&gt;&lt;P&gt;object network Onesign2&lt;/P&gt;&lt;P&gt;host 172.21.80.105&lt;/P&gt;&lt;P&gt;description Imprivata onesign 2fa backup server&lt;/P&gt;&lt;P&gt;object service Ldap_udp&lt;/P&gt;&lt;P&gt;service udp destination eq 389&lt;/P&gt;&lt;P&gt;object service SEP_UDP_8014&lt;/P&gt;&lt;P&gt;service udp destination eq 8014&lt;/P&gt;&lt;P&gt;object service ad_TCP135&lt;/P&gt;&lt;P&gt;service tcp destination eq 135&lt;/P&gt;&lt;P&gt;object service AD_Kerbrose_88&lt;/P&gt;&lt;P&gt;service tcp destination eq 88&lt;/P&gt;&lt;P&gt;object service AD_Client_49156&lt;/P&gt;&lt;P&gt;service tcp destination range 49156 49158&lt;/P&gt;&lt;P&gt;object service Outlook_Client_26020&lt;/P&gt;&lt;P&gt;service tcp destination eq 26020&lt;/P&gt;&lt;P&gt;object service Outlook_Client_26036&lt;/P&gt;&lt;P&gt;service tcp destination eq 26036&lt;/P&gt;&lt;P&gt;object service Outlook_Client_39388&lt;/P&gt;&lt;P&gt;service tcp destination eq 39388&lt;/P&gt;&lt;P&gt;object service AD_Client_3268&lt;/P&gt;&lt;P&gt;service tcp destination eq 3268&lt;/P&gt;&lt;P&gt;object service AD_Kerbrose_88udp&lt;/P&gt;&lt;P&gt;service udp destination eq 88&lt;/P&gt;&lt;P&gt;object service RDP&lt;/P&gt;&lt;P&gt;service tcp destination eq 3389&lt;/P&gt;&lt;P&gt;object service Blackberry_SRP&lt;/P&gt;&lt;P&gt;service tcp destination eq 3101&lt;/P&gt;&lt;P&gt;object service Galileo_portal&lt;/P&gt;&lt;P&gt;service tcp destination eq 2048&lt;/P&gt;&lt;P&gt;object network Local_unconfig_IP&lt;/P&gt;&lt;P&gt;subnet 169.254.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;object network Local_unconfig_ip2&lt;/P&gt;&lt;P&gt;subnet 1.0.0.0 255.0.0.0&lt;/P&gt;&lt;P&gt;object network PMS_SECURITY_DESK&lt;/P&gt;&lt;P&gt;host 172.17.3.13&lt;/P&gt;&lt;P&gt;object network PSM_OPER&lt;/P&gt;&lt;P&gt;host 172.17.3.12&lt;/P&gt;&lt;P&gt;object service Windows_FS_Ports&lt;/P&gt;&lt;P&gt;service tcp destination range 49152 65535&lt;/P&gt;&lt;P&gt;description Ports required for Access to fileshare&lt;/P&gt;&lt;P&gt;object network EdOne_FS&lt;/P&gt;&lt;P&gt;host 172.21.80.208&lt;/P&gt;&lt;P&gt;description EdOne Direct lending reports server&lt;/P&gt;&lt;P&gt;object network EdOne_Router&lt;/P&gt;&lt;P&gt;host 10.222.1.1&lt;/P&gt;&lt;P&gt;object network FSA_AUDIT&lt;/P&gt;&lt;P&gt;host 10.222.1.20&lt;/P&gt;&lt;P&gt;object network FSA_Audit2&lt;/P&gt;&lt;P&gt;host 110.222.0.22&lt;/P&gt;&lt;P&gt;object network VPN_Client&lt;/P&gt;&lt;P&gt;host 172.21.191.150&lt;/P&gt;&lt;P&gt;object network webtest&lt;/P&gt;&lt;P&gt;host 172.21.99.11&lt;/P&gt;&lt;P&gt;object service Real_Player&lt;/P&gt;&lt;P&gt;service tcp destination eq rtsp&lt;/P&gt;&lt;P&gt;object network Sireweb&lt;/P&gt;&lt;P&gt;host 172.21.13.41&lt;/P&gt;&lt;P&gt;object network ESO&lt;/P&gt;&lt;P&gt;host 172.21.70.103&lt;/P&gt;&lt;P&gt;object network CP_DNS1&lt;/P&gt;&lt;P&gt;host 10.100.98.98&lt;/P&gt;&lt;P&gt;object network CP_DNS2&lt;/P&gt;&lt;P&gt;host 10.100.98.99&lt;/P&gt;&lt;P&gt;object network PARS&lt;/P&gt;&lt;P&gt;host 172.21.80.207&lt;/P&gt;&lt;P&gt;object network Bandwidth_hog_1&lt;/P&gt;&lt;P&gt;subnet 208.44.23.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network Security_mgr_2&lt;/P&gt;&lt;P&gt;host 172.21.70.11&lt;/P&gt;&lt;P&gt;object network ED_ONE_SFTP_Server&lt;/P&gt;&lt;P&gt;host 10.222.1.253&lt;/P&gt;&lt;P&gt;object network Campus_Partners_FTP_server&lt;/P&gt;&lt;P&gt;host 10.100.30.50&lt;/P&gt;&lt;P&gt;object network Nessus&lt;/P&gt;&lt;P&gt;host 172.21.80.203&lt;/P&gt;&lt;P&gt;object network Latin_American_address_range&lt;/P&gt;&lt;P&gt;subnet 200.0.0.0 255.0.0.0&lt;/P&gt;&lt;P&gt;description Recieving lots of spam with zip files&lt;/P&gt;&lt;P&gt;object network Mailroom_PRT_PC_1&lt;/P&gt;&lt;P&gt;host 172.21.60.222&lt;/P&gt;&lt;P&gt;object network Mailroom_PRT_PC_2&lt;/P&gt;&lt;P&gt;host 172.21.60.244&lt;/P&gt;&lt;P&gt;object network Blackwoodchronicles&lt;/P&gt;&lt;P&gt;host 69.89.25.197&lt;/P&gt;&lt;P&gt;object network Stepstotransformation&lt;/P&gt;&lt;P&gt;host 92.61.152.183&lt;/P&gt;&lt;P&gt;description Phishing email destination&lt;/P&gt;&lt;P&gt;object network ftp-s2sys-com&lt;/P&gt;&lt;P&gt;host 23.25.203.145&lt;/P&gt;&lt;P&gt;description Security update site for camaras&lt;/P&gt;&lt;P&gt;object network www-fahrer-rspv-de&lt;/P&gt;&lt;P&gt;host 82.165.92.100&lt;/P&gt;&lt;P&gt;object network NPEC_EXCHANGE_SERVER&lt;/P&gt;&lt;P&gt;host 172.26.100.101&lt;/P&gt;&lt;P&gt;object network Wifi_Guest&lt;/P&gt;&lt;P&gt;subnet 172.17.50.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network GSFC_Guest_Internet_only_WIFI&lt;/P&gt;&lt;P&gt;subnet 172.17.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network GSFC_USER_WIFI&lt;/P&gt;&lt;P&gt;subnet 172.17.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network Wifi_hide_to_Int&lt;/P&gt;&lt;P&gt;host 172.21.21.21&lt;/P&gt;&lt;P&gt;object service ShoreTel_Call_Control&lt;/P&gt;&lt;P&gt;service udp destination eq 2427&lt;/P&gt;&lt;P&gt;description ShoreTel_Call_Control&lt;/P&gt;&lt;P&gt;object service ShoreTel_DHCP&lt;/P&gt;&lt;P&gt;service udp destination eq bootps&lt;/P&gt;&lt;P&gt;description ShoreTel_DHCP&lt;/P&gt;&lt;P&gt;object service ShoreTel_FTP_CTL_Boot_File&lt;/P&gt;&lt;P&gt;service tcp destination eq ftp&lt;/P&gt;&lt;P&gt;description ShoreTel_FTP_CTL_Boot_File&lt;/P&gt;&lt;P&gt;object service ShoreTel_FTP_Data_Boot_File&lt;/P&gt;&lt;P&gt;service tcp destination eq ftp-data&lt;/P&gt;&lt;P&gt;description ShoreTel_FTP_Data_Boot_File&lt;/P&gt;&lt;P&gt;object service ShoreTel_MGCP_Media_Proxy&lt;/P&gt;&lt;P&gt;service udp destination eq 2727&lt;/P&gt;&lt;P&gt;description ShoreTel_Port_Mapper&lt;/P&gt;&lt;P&gt;object service ShoreTel_Port_Mapper&lt;/P&gt;&lt;P&gt;service udp destination eq sunrpc&lt;/P&gt;&lt;P&gt;description ShoreTel_Port_Mapper&lt;/P&gt;&lt;P&gt;object service ShoreTel_RPC_NCC&lt;/P&gt;&lt;P&gt;service tcp destination range 1024 65535&lt;/P&gt;&lt;P&gt;description ShoreTel_RPC_NCC&lt;/P&gt;&lt;P&gt;object service ShoreTel_RTP&lt;/P&gt;&lt;P&gt;service udp destination eq 5004&lt;/P&gt;&lt;P&gt;description ShoreTel_RTP&lt;/P&gt;&lt;P&gt;object service ShoreTel_SIP&lt;/P&gt;&lt;P&gt;service tcp destination eq sip&lt;/P&gt;&lt;P&gt;description ShoreTel_SIP&lt;/P&gt;&lt;P&gt;object service ShoreTel_SMTP&lt;/P&gt;&lt;P&gt;service tcp destination eq smtp&lt;/P&gt;&lt;P&gt;description ShoreTel_SMTP&lt;/P&gt;&lt;P&gt;object service ShoreTel_SNMP_trap&lt;/P&gt;&lt;P&gt;service udp destination eq snmptrap&lt;/P&gt;&lt;P&gt;description ShoreTel_SNMP_trap&lt;/P&gt;&lt;P&gt;object service ShoreTel_TMS&lt;/P&gt;&lt;P&gt;service tcp destination eq 5432&lt;/P&gt;&lt;P&gt;description ShoreTel_TMS&lt;/P&gt;&lt;P&gt;object service ShoreTel_location_Service&lt;/P&gt;&lt;P&gt;service udp destination range 5440 5446&lt;/P&gt;&lt;P&gt;description ShoreTel_location_Service&lt;/P&gt;&lt;P&gt;object network Shoretel_DVM&lt;/P&gt;&lt;P&gt;host 172.21.13.53&lt;/P&gt;&lt;P&gt;object network Shoretel_Dir&lt;/P&gt;&lt;P&gt;host 172.21.13.51&lt;/P&gt;&lt;P&gt;object network Shoretel_ECC&lt;/P&gt;&lt;P&gt;host 172.21.13.52&lt;/P&gt;&lt;P&gt;object network Shoretel_SW1&lt;/P&gt;&lt;P&gt;host 172.21.13.54&lt;/P&gt;&lt;P&gt;object network Shoretel_SW2&lt;/P&gt;&lt;P&gt;host 172.21.13.55&lt;/P&gt;&lt;P&gt;object network VLAN30_Shoretel_net&lt;/P&gt;&lt;P&gt;subnet 172.17.30.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network vlan30_DIR_STS&lt;/P&gt;&lt;P&gt;host 172.17.30.51&lt;/P&gt;&lt;P&gt;object-group service GSFC_INT_USER_Ports&lt;/P&gt;&lt;P&gt;service-object object CISCO_VPN&lt;/P&gt;&lt;P&gt;service-object object CISCO_VPN_PORT&lt;/P&gt;&lt;P&gt;service-object object Citrix1495&lt;/P&gt;&lt;P&gt;service-object object Citrix1604&lt;/P&gt;&lt;P&gt;service-object object ConnectDirect&lt;/P&gt;&lt;P&gt;service-object object Document_Direct&lt;/P&gt;&lt;P&gt;service-object object Edconnect&lt;/P&gt;&lt;P&gt;service-object object HTTP8000&lt;/P&gt;&lt;P&gt;service-object object HTTP8080&lt;/P&gt;&lt;P&gt;service-object object HTTP8890&lt;/P&gt;&lt;P&gt;service-object object IAG_Ext_Port&lt;/P&gt;&lt;P&gt;service-object object TCP9000&lt;/P&gt;&lt;P&gt;service-object object TCP9191&lt;/P&gt;&lt;P&gt;service-object object Time&lt;/P&gt;&lt;P&gt;service-object object Time_udp&lt;/P&gt;&lt;P&gt;service-object tcp destination eq domain&lt;/P&gt;&lt;P&gt;service-object tcp destination eq ftp&lt;/P&gt;&lt;P&gt;service-object tcp destination eq ftp-data&lt;/P&gt;&lt;P&gt;service-object tcp destination eq www&lt;/P&gt;&lt;P&gt;service-object tcp destination eq https&lt;/P&gt;&lt;P&gt;service-object tcp destination eq lotusnotes&lt;/P&gt;&lt;P&gt;service-object tcp destination eq pop3&lt;/P&gt;&lt;P&gt;service-object udp destination eq domain&lt;/P&gt;&lt;P&gt;service-object udp destination eq nameserver&lt;/P&gt;&lt;P&gt;service-object object Time_123&lt;/P&gt;&lt;P&gt;service-object object SFTP&lt;/P&gt;&lt;P&gt;service-object object DOAS_PORT&lt;/P&gt;&lt;P&gt;service-object object DOAS_port2&lt;/P&gt;&lt;P&gt;service-object object GTA_BILL2&lt;/P&gt;&lt;P&gt;service-object object VPN&lt;/P&gt;&lt;P&gt;service-object object VPN_udp&lt;/P&gt;&lt;P&gt;service-object object Emulate_live&lt;/P&gt;&lt;P&gt;service-object object UGA_EDU_Web_Port&lt;/P&gt;&lt;P&gt;service-object object MS_Live_meeting_port&lt;/P&gt;&lt;P&gt;service-object object AES_SFTP_PORT&lt;/P&gt;&lt;P&gt;service-object object GL_TELNET_SSL&lt;/P&gt;&lt;P&gt;service-object object gosaxfrd.dev.bor.usg.edu&lt;/P&gt;&lt;P&gt;service-object object GOSAXFR.PROD.REGENTS.USG_ONS&lt;/P&gt;&lt;P&gt;service-object object GOSAXFRT.EAS.REGENTS.USG_ONS&lt;/P&gt;&lt;P&gt;service-object object Blackberry_SRP&lt;/P&gt;&lt;P&gt;service-object object Galileo_portal&lt;/P&gt;&lt;P&gt;service-object object Real_Player&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_15&lt;/P&gt;&lt;P&gt;group-object GSFC_INT_USER_Ports&lt;/P&gt;&lt;P&gt;service-object tcp destination eq ssh&lt;/P&gt;&lt;P&gt;service-object ip&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_5&lt;/P&gt;&lt;P&gt;service-object tcp destination eq domain&lt;/P&gt;&lt;P&gt;service-object udp destination eq domain&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_3&lt;/P&gt;&lt;P&gt;service-object icmp&lt;/P&gt;&lt;P&gt;service-object udp destination eq domain&lt;/P&gt;&lt;P&gt;service-object tcp destination eq domain&lt;/P&gt;&lt;P&gt;object-group network DMZ_Servers&lt;/P&gt;&lt;P&gt;network-object object IAG_Internal_Nic&lt;/P&gt;&lt;P&gt;network-object object Tumbleweed&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_3 tcp&lt;/P&gt;&lt;P&gt;port-object eq ftp&lt;/P&gt;&lt;P&gt;port-object eq ftp-data&lt;/P&gt;&lt;P&gt;port-object eq www&lt;/P&gt;&lt;P&gt;port-object eq https&lt;/P&gt;&lt;P&gt;object-group service DMZ_OUTBOUND_services&lt;/P&gt;&lt;P&gt;service-object tcp-udp destination eq domain&lt;/P&gt;&lt;P&gt;service-object tcp destination eq ftp&lt;/P&gt;&lt;P&gt;service-object tcp destination eq ftp-data&lt;/P&gt;&lt;P&gt;service-object tcp destination eq www&lt;/P&gt;&lt;P&gt;service-object tcp destination eq https&lt;/P&gt;&lt;P&gt;service-object udp destination eq time&lt;/P&gt;&lt;P&gt;object-group service AD_Req_Ports&lt;/P&gt;&lt;P&gt;service-object object AD_SMB&lt;/P&gt;&lt;P&gt;service-object tcp destination eq ldap&lt;/P&gt;&lt;P&gt;service-object tcp destination eq ldaps&lt;/P&gt;&lt;P&gt;service-object tcp destination eq netbios-ssn&lt;/P&gt;&lt;P&gt;service-object udp destination eq netbios-dgm&lt;/P&gt;&lt;P&gt;service-object udp destination eq netbios-ns&lt;/P&gt;&lt;P&gt;service-object object Ldap_udp&lt;/P&gt;&lt;P&gt;service-object tcp destination eq www&lt;/P&gt;&lt;P&gt;service-object object ad_TCP135&lt;/P&gt;&lt;P&gt;service-object tcp destination eq kerberos&lt;/P&gt;&lt;P&gt;service-object udp destination eq kerberos&lt;/P&gt;&lt;P&gt;service-object object AD_Kerbrose_88&lt;/P&gt;&lt;P&gt;service-object object AD_Client_49156&lt;/P&gt;&lt;P&gt;service-object object Time_123&lt;/P&gt;&lt;P&gt;service-object object Time_udp&lt;/P&gt;&lt;P&gt;service-object object AD_Client_3268&lt;/P&gt;&lt;P&gt;service-object object AD_Kerbrose_88udp&lt;/P&gt;&lt;P&gt;service-object tcp destination eq https&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_24&lt;/P&gt;&lt;P&gt;network-object object Kenny&lt;/P&gt;&lt;P&gt;network-object object Cartman&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_2&lt;/P&gt;&lt;P&gt;network-object object secureftp&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_3&lt;/P&gt;&lt;P&gt;network-object object Exchange07&lt;/P&gt;&lt;P&gt;network-object object Morpheus&lt;/P&gt;&lt;P&gt;network-object object visnetic411&lt;/P&gt;&lt;P&gt;network-object object visnetic&lt;/P&gt;&lt;P&gt;network-object object Anthony_Rais&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_2 tcp&lt;/P&gt;&lt;P&gt;port-object eq ftp&lt;/P&gt;&lt;P&gt;port-object eq ftp-data&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_4&lt;/P&gt;&lt;P&gt;network-object object CRM_Server&lt;/P&gt;&lt;P&gt;network-object object Cartman&lt;/P&gt;&lt;P&gt;network-object object Exchange07&lt;/P&gt;&lt;P&gt;network-object object GSFC_PORTAL&lt;/P&gt;&lt;P&gt;network-object object Kenny&lt;/P&gt;&lt;P&gt;network-object object MS_update_server&lt;/P&gt;&lt;P&gt;network-object object Rhett&lt;/P&gt;&lt;P&gt;network-object object Scarlett&lt;/P&gt;&lt;P&gt;network-object object gsfcfaxserver&lt;/P&gt;&lt;P&gt;network-object object Symantec_Ent_Server&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_5&lt;/P&gt;&lt;P&gt;network-object object Balrog&lt;/P&gt;&lt;P&gt;network-object object Imageapp&lt;/P&gt;&lt;P&gt;network-object object Intranet_server&lt;/P&gt;&lt;P&gt;network-object object Oraappprod&lt;/P&gt;&lt;P&gt;network-object object visnetic411&lt;/P&gt;&lt;P&gt;network-object object visnetic&lt;/P&gt;&lt;P&gt;network-object object Brain&lt;/P&gt;&lt;P&gt;network-object object Sireweb&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_6&lt;/P&gt;&lt;P&gt;network-object 172.21.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;network-object 172.26.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 172.26.100.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_1&lt;/P&gt;&lt;P&gt;service-object object Oraapp&lt;/P&gt;&lt;P&gt;service-object tcp-udp destination eq domain&lt;/P&gt;&lt;P&gt;service-object tcp destination eq www&lt;/P&gt;&lt;P&gt;service-object tcp destination eq https&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_7&lt;/P&gt;&lt;P&gt;network-object object Tumbleweed&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_8&lt;/P&gt;&lt;P&gt;network-object 172.17.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 172.26.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 172.26.100.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 172.17.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 172.20.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_9&lt;/P&gt;&lt;P&gt;network-object object Shoretel_DVM&lt;/P&gt;&lt;P&gt;network-object object Shoretel_Dir&lt;/P&gt;&lt;P&gt;network-object object Shoretel_ECC&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW1&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW2&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_0 tcp&lt;/P&gt;&lt;P&gt;port-object eq https&lt;/P&gt;&lt;P&gt;port-object eq smtp&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_1&lt;/P&gt;&lt;P&gt;protocol-object ip&lt;/P&gt;&lt;P&gt;protocol-object icmp&lt;/P&gt;&lt;P&gt;object-group network Security_Administrators&lt;/P&gt;&lt;P&gt;network-object object Marks_PC&lt;/P&gt;&lt;P&gt;network-object object Security_mgr&lt;/P&gt;&lt;P&gt;network-object object Balrog&lt;/P&gt;&lt;P&gt;network-object object Nessus&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_10&lt;/P&gt;&lt;P&gt;group-object Security_Administrators&lt;/P&gt;&lt;P&gt;network-object object Security_mgr&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_11&lt;/P&gt;&lt;P&gt;group-object Security_Administrators&lt;/P&gt;&lt;P&gt;network-object object Security_mgr&lt;/P&gt;&lt;P&gt;network-object object Terminal_server&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_12&lt;/P&gt;&lt;P&gt;group-object Security_Administrators&lt;/P&gt;&lt;P&gt;network-object object Security_mgr&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_13&lt;/P&gt;&lt;P&gt;network-object object Shoretel_DVM&lt;/P&gt;&lt;P&gt;network-object object Shoretel_Dir&lt;/P&gt;&lt;P&gt;network-object object Shoretel_ECC&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW1&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW2&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_14&lt;/P&gt;&lt;P&gt;network-object object Balrog&lt;/P&gt;&lt;P&gt;network-object object Cartman&lt;/P&gt;&lt;P&gt;network-object object Exchange07&lt;/P&gt;&lt;P&gt;network-object object Kenny&lt;/P&gt;&lt;P&gt;network-object object Solarwinds-LEM&lt;/P&gt;&lt;P&gt;network-object object Brain&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_15&lt;/P&gt;&lt;P&gt;network-object object Exchange07&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_16&lt;/P&gt;&lt;P&gt;network-object object Balrog&lt;/P&gt;&lt;P&gt;network-object object Brain&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_17&lt;/P&gt;&lt;P&gt;network-object object Balrog&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_1 tcp&lt;/P&gt;&lt;P&gt;port-object eq ftp&lt;/P&gt;&lt;P&gt;port-object eq www&lt;/P&gt;&lt;P&gt;port-object eq pop3&lt;/P&gt;&lt;P&gt;port-object eq smtp&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_4 tcp&lt;/P&gt;&lt;P&gt;port-object eq www&lt;/P&gt;&lt;P&gt;port-object eq smtp&lt;/P&gt;&lt;P&gt;port-object eq pop3&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_21&lt;/P&gt;&lt;P&gt;network-object object Shoretel_DVM&lt;/P&gt;&lt;P&gt;network-object object Shoretel_Dir&lt;/P&gt;&lt;P&gt;network-object object Shoretel_ECC&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW1&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW2&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_18&lt;/P&gt;&lt;P&gt;group-object Security_Administrators&lt;/P&gt;&lt;P&gt;network-object object Security_mgr&lt;/P&gt;&lt;P&gt;network-object object Terminal_server&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_19&lt;/P&gt;&lt;P&gt;network-object object Anthony_Rais&lt;/P&gt;&lt;P&gt;network-object object Exchange07&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_6 tcp&lt;/P&gt;&lt;P&gt;port-object eq www&lt;/P&gt;&lt;P&gt;port-object eq pop3&lt;/P&gt;&lt;P&gt;port-object eq smtp&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_20&lt;/P&gt;&lt;P&gt;network-object object Balrog&lt;/P&gt;&lt;P&gt;network-object object Brain&lt;/P&gt;&lt;P&gt;network-object object Exchange07&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCPUDP_1 tcp-udp&lt;/P&gt;&lt;P&gt;port-object eq sip&lt;/P&gt;&lt;P&gt;port-object eq talk&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_22&lt;/P&gt;&lt;P&gt;network-object object DMZ_Net&lt;/P&gt;&lt;P&gt;network-object object Int_net&lt;/P&gt;&lt;P&gt;object-group protocol ICMP&lt;/P&gt;&lt;P&gt;protocol-object ip&lt;/P&gt;&lt;P&gt;object-group icmp-type icmpall&lt;/P&gt;&lt;P&gt;icmp-object alternate-address&lt;/P&gt;&lt;P&gt;icmp-object conversion-error&lt;/P&gt;&lt;P&gt;icmp-object echo&lt;/P&gt;&lt;P&gt;icmp-object echo-reply&lt;/P&gt;&lt;P&gt;icmp-object information-reply&lt;/P&gt;&lt;P&gt;icmp-object information-request&lt;/P&gt;&lt;P&gt;icmp-object mask-reply&lt;/P&gt;&lt;P&gt;icmp-object mask-request&lt;/P&gt;&lt;P&gt;icmp-object mobile-redirect&lt;/P&gt;&lt;P&gt;icmp-object parameter-problem&lt;/P&gt;&lt;P&gt;icmp-object redirect&lt;/P&gt;&lt;P&gt;icmp-object router-advertisement&lt;/P&gt;&lt;P&gt;icmp-object router-solicitation&lt;/P&gt;&lt;P&gt;icmp-object source-quench&lt;/P&gt;&lt;P&gt;icmp-object time-exceeded&lt;/P&gt;&lt;P&gt;icmp-object timestamp-reply&lt;/P&gt;&lt;P&gt;icmp-object timestamp-request&lt;/P&gt;&lt;P&gt;icmp-object traceroute&lt;/P&gt;&lt;P&gt;icmp-object unreachable&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_27&lt;/P&gt;&lt;P&gt;network-object object DOR_GTA&lt;/P&gt;&lt;P&gt;network-object object DOR_GTA_2&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_26&lt;/P&gt;&lt;P&gt;network-object object Balrog&lt;/P&gt;&lt;P&gt;network-object object Brain&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_25&lt;/P&gt;&lt;P&gt;network-object 172.17.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 172.20.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 172.21.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;network-object 172.26.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 172.26.100.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object-group network Default_Aversion&lt;/P&gt;&lt;P&gt;network-object object Default_Aversion_1&lt;/P&gt;&lt;P&gt;network-object object Default_Aversion_2&lt;/P&gt;&lt;P&gt;network-object object Default_Aversion_3&lt;/P&gt;&lt;P&gt;network-object object Default_Aversion_4&lt;/P&gt;&lt;P&gt;network-object object Default_Aversion_5&lt;/P&gt;&lt;P&gt;network-object object Default_Aversion_6&lt;/P&gt;&lt;P&gt;network-object object Default_Aversion_7&lt;/P&gt;&lt;P&gt;network-object object Default_Aversion_8&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_7 tcp&lt;/P&gt;&lt;P&gt;port-object eq www&lt;/P&gt;&lt;P&gt;port-object eq https&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_28&lt;/P&gt;&lt;P&gt;network-object object Exchange07&lt;/P&gt;&lt;P&gt;network-object object GSFC_PORTAL&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_7&lt;/P&gt;&lt;P&gt;service-object object Security_cammeras&lt;/P&gt;&lt;P&gt;service-object tcp destination eq www&lt;/P&gt;&lt;P&gt;service-object object Security_Cammeras_2&lt;/P&gt;&lt;P&gt;service-object tcp destination eq https&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_6&lt;/P&gt;&lt;P&gt;service-object tcp destination eq domain&lt;/P&gt;&lt;P&gt;service-object udp destination eq domain&lt;/P&gt;&lt;P&gt;object-group service ShoreTel_Group&lt;/P&gt;&lt;P&gt;description ShoreTel_VOIP&lt;/P&gt;&lt;P&gt;service-object object ShoreTel_Call_Control&lt;/P&gt;&lt;P&gt;service-object object ShoreTel_DHCP&lt;/P&gt;&lt;P&gt;service-object object ShoreTel_FTP_CTL_Boot_File&lt;/P&gt;&lt;P&gt;service-object object ShoreTel_FTP_Data_Boot_File&lt;/P&gt;&lt;P&gt;service-object object ShoreTel_MGCP_Media_Proxy&lt;/P&gt;&lt;P&gt;service-object object ShoreTel_Port_Mapper&lt;/P&gt;&lt;P&gt;service-object object ShoreTel_RPC_NCC&lt;/P&gt;&lt;P&gt;service-object object ShoreTel_RTP&lt;/P&gt;&lt;P&gt;service-object object ShoreTel_SIP&lt;/P&gt;&lt;P&gt;service-object object ShoreTel_SMTP&lt;/P&gt;&lt;P&gt;service-object object ShoreTel_SNMP_trap&lt;/P&gt;&lt;P&gt;service-object object ShoreTel_TMS&lt;/P&gt;&lt;P&gt;service-object object ShoreTel_location_Service&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_23&lt;/P&gt;&lt;P&gt;network-object object Shoretel_DVM&lt;/P&gt;&lt;P&gt;network-object object Shoretel_Dir&lt;/P&gt;&lt;P&gt;network-object object Shoretel_ECC&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW1&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW2&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_29&lt;/P&gt;&lt;P&gt;network-object object Shoretel_DVM&lt;/P&gt;&lt;P&gt;network-object object Shoretel_Dir&lt;/P&gt;&lt;P&gt;network-object object Shoretel_ECC&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW1&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW2&lt;/P&gt;&lt;P&gt;object-group service Outlook_Client&lt;/P&gt;&lt;P&gt;service-object object Outlook_Client_26020&lt;/P&gt;&lt;P&gt;service-object object Outlook_Client_26036&lt;/P&gt;&lt;P&gt;service-object object Outlook_Client_39388&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_31&lt;/P&gt;&lt;P&gt;network-object object Cartman&lt;/P&gt;&lt;P&gt;network-object object Kenny&lt;/P&gt;&lt;P&gt;network-object object MS_update_server&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_30&lt;/P&gt;&lt;P&gt;network-object object Shoretel_DVM&lt;/P&gt;&lt;P&gt;network-object object Shoretel_Dir&lt;/P&gt;&lt;P&gt;network-object object Shoretel_ECC&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW1&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW2&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_37&lt;/P&gt;&lt;P&gt;network-object object Shoretel_DVM&lt;/P&gt;&lt;P&gt;network-object object Shoretel_Dir&lt;/P&gt;&lt;P&gt;network-object object Shoretel_ECC&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW1&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW2&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_11&lt;/P&gt;&lt;P&gt;group-object AD_Req_Ports&lt;/P&gt;&lt;P&gt;group-object GSFC_INT_USER_Ports&lt;/P&gt;&lt;P&gt;group-object Outlook_Client&lt;/P&gt;&lt;P&gt;service-object tcp destination eq telnet&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_33&lt;/P&gt;&lt;P&gt;network-object object Training_room_PCs&lt;/P&gt;&lt;P&gt;network-object object Tumbleweed&lt;/P&gt;&lt;P&gt;network-object object DL_Agent_PCs&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_12&lt;/P&gt;&lt;P&gt;group-object AD_Req_Ports&lt;/P&gt;&lt;P&gt;group-object GSFC_INT_USER_Ports&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_34&lt;/P&gt;&lt;P&gt;network-object object Marks_PC&lt;/P&gt;&lt;P&gt;network-object object Security_mgr&lt;/P&gt;&lt;P&gt;network-object object Security_mgr_2&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_32&lt;/P&gt;&lt;P&gt;network-object object Balrog&lt;/P&gt;&lt;P&gt;network-object object Cartman&lt;/P&gt;&lt;P&gt;network-object object Kenny&lt;/P&gt;&lt;P&gt;network-object object Brain&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_35&lt;/P&gt;&lt;P&gt;network-object 172.17.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 172.17.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 172.20.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 172.26.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object 172.26.100.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_8 tcp&lt;/P&gt;&lt;P&gt;port-object eq www&lt;/P&gt;&lt;P&gt;port-object eq pop3&lt;/P&gt;&lt;P&gt;port-object eq smtp&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_13&lt;/P&gt;&lt;P&gt;group-object AD_Req_Ports&lt;/P&gt;&lt;P&gt;service-object tcp destination eq domain&lt;/P&gt;&lt;P&gt;service-object udp destination eq domain&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_14&lt;/P&gt;&lt;P&gt;service-object tcp destination eq domain&lt;/P&gt;&lt;P&gt;service-object udp destination eq domain&lt;/P&gt;&lt;P&gt;object-group network DL_Boundry_Servers&lt;/P&gt;&lt;P&gt;network-object object Balrog&lt;/P&gt;&lt;P&gt;network-object object Brain&lt;/P&gt;&lt;P&gt;network-object object Cartman&lt;/P&gt;&lt;P&gt;network-object object EdOne_FS&lt;/P&gt;&lt;P&gt;network-object object Exchange07&lt;/P&gt;&lt;P&gt;network-object object Kenny&lt;/P&gt;&lt;P&gt;network-object object MS_update_server&lt;/P&gt;&lt;P&gt;network-object object Onesign&lt;/P&gt;&lt;P&gt;network-object object Onesign2&lt;/P&gt;&lt;P&gt;network-object object Solarwinds-LEM&lt;/P&gt;&lt;P&gt;network-object object Symantec_Ent_Server&lt;/P&gt;&lt;P&gt;network-object object PARS&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_2&lt;/P&gt;&lt;P&gt;protocol-object udp&lt;/P&gt;&lt;P&gt;protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group protocol TCPUDP&lt;/P&gt;&lt;P&gt;protocol-object udp&lt;/P&gt;&lt;P&gt;protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_3&lt;/P&gt;&lt;P&gt;protocol-object udp&lt;/P&gt;&lt;P&gt;protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_1&lt;/P&gt;&lt;P&gt;network-object object Cartman&lt;/P&gt;&lt;P&gt;network-object object Exchange07&lt;/P&gt;&lt;P&gt;network-object object Kenny&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_36&lt;/P&gt;&lt;P&gt;network-object object Bldg_Manager&lt;/P&gt;&lt;P&gt;network-object object Security_mgr&lt;/P&gt;&lt;P&gt;network-object object gsfcasaweb_int_nat&lt;/P&gt;&lt;P&gt;network-object object ESO&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_38&lt;/P&gt;&lt;P&gt;network-object object Shoretel_DVM&lt;/P&gt;&lt;P&gt;network-object object Shoretel_Dir&lt;/P&gt;&lt;P&gt;network-object object Shoretel_ECC&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW1&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW2&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_39&lt;/P&gt;&lt;P&gt;network-object object Shoretel_DVM&lt;/P&gt;&lt;P&gt;network-object object Shoretel_Dir&lt;/P&gt;&lt;P&gt;network-object object Shoretel_ECC&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW1&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW2&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_44&lt;/P&gt;&lt;P&gt;network-object object Shoretel_DVM&lt;/P&gt;&lt;P&gt;network-object object Shoretel_Dir&lt;/P&gt;&lt;P&gt;network-object object Shoretel_ECC&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW1&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW2&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_45&lt;/P&gt;&lt;P&gt;network-object object Shoretel_DVM&lt;/P&gt;&lt;P&gt;network-object object Shoretel_Dir&lt;/P&gt;&lt;P&gt;network-object object Shoretel_ECC&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW1&lt;/P&gt;&lt;P&gt;network-object object Shoretel_SW2&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_40&lt;/P&gt;&lt;P&gt;network-object object CP_DNS1&lt;/P&gt;&lt;P&gt;network-object object CP_DNS2&lt;/P&gt;&lt;P&gt;network-object object EdOne_sub&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_43&lt;/P&gt;&lt;P&gt;network-object object Blackwoodchronicles&lt;/P&gt;&lt;P&gt;network-object object Stepstotransformation&lt;/P&gt;&lt;P&gt;network-object object www-fahrer-rspv-de&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_41&lt;/P&gt;&lt;P&gt;network-object object Mailroom_PRT_PC_1&lt;/P&gt;&lt;P&gt;network-object object Mailroom_PRT_PC_2&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_42&lt;/P&gt;&lt;P&gt;network-object object Blackwoodchronicles&lt;/P&gt;&lt;P&gt;network-object object Latin_American_address_range&lt;/P&gt;&lt;P&gt;network-object object Stepstotransformation&lt;/P&gt;&lt;P&gt;network-object object www-fahrer-rspv-de&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_18&lt;/P&gt;&lt;P&gt;service-object ip&lt;/P&gt;&lt;P&gt;service-object tcp destination eq www&lt;/P&gt;&lt;P&gt;service-object tcp destination eq https&lt;/P&gt;&lt;P&gt;service-object tcp destination eq smtp&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_9 tcp&lt;/P&gt;&lt;P&gt;port-object eq ftp&lt;/P&gt;&lt;P&gt;port-object eq ftp-data&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_2&lt;/P&gt;&lt;P&gt;service-object tcp destination eq domain&lt;/P&gt;&lt;P&gt;service-object tcp destination eq www&lt;/P&gt;&lt;P&gt;service-object tcp destination eq https&lt;/P&gt;&lt;P&gt;service-object udp destination eq domain&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_4&lt;/P&gt;&lt;P&gt;service-object tcp destination eq domain&lt;/P&gt;&lt;P&gt;service-object tcp destination eq www&lt;/P&gt;&lt;P&gt;service-object tcp destination eq https&lt;/P&gt;&lt;P&gt;service-object udp destination eq domain&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit object-group GSFC_INT_USER_Ports object NPEC_ASA_FW any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in remark Tumbleweed email access to the internet&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp object Tumbleweed any eq smtp&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp object Tumbleweed object-group DM_INLINE_NETWORK_15 eq smtp&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit object Solarwinds_LEM_Ports object Tumbleweed object Solarwinds-LEM&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit object-group DM_INLINE_SERVICE_14 object Tumbleweed any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit object-group DM_INLINE_SERVICE_13 object Tumbleweed object-group DM_INLINE_NETWORK_32&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended deny ip object DMZ_Net object NPEC_NET log&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit object-group DMZ_OUTBOUND_services object-group DMZ_Servers any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp object-group DM_INLINE_NETWORK_7 object-group DM_INLINE_NETWORK_2 object-group DM_INLINE_TCP_2&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended deny ip 172.26.1.0 255.255.255.0 any log&lt;/P&gt;&lt;P&gt;access-list int_access_in remark Destination of phish attack email&lt;/P&gt;&lt;P&gt;access-list int_access_in extended deny ip any object-group DM_INLINE_NETWORK_43&lt;/P&gt;&lt;P&gt;access-list int_access_in extended deny ip object-group DM_INLINE_NETWORK_41 any&lt;/P&gt;&lt;P&gt;access-list int_access_in extended permit ip object-group DM_INLINE_NETWORK_23 172.17.30.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list int_access_in extended permit tcp object Anthony_Rais object ftp-s2sys-com object-group DM_INLINE_TCP_9&lt;/P&gt;&lt;P&gt;access-list int_access_in extended permit object IAG_Ext_Port object Terminal_server object Tumbleweed&lt;/P&gt;&lt;P&gt;access-list int_access_in extended permit object-group DM_INLINE_SERVICE_12 object-group DM_INLINE_NETWORK_31 object-group DM_INLINE_NETWORK_33&lt;/P&gt;&lt;P&gt;access-list int_access_in extended deny ip any object log-me-in log&lt;/P&gt;&lt;P&gt;access-list int_access_in extended permit tcp host 172.21.95.1 any eq 1023&lt;/P&gt;&lt;P&gt;access-list int_access_in extended permit object-group DM_INLINE_SERVICE_15 object-group DM_INLINE_NETWORK_10 any&lt;/P&gt;&lt;P&gt;access-list int_access_in extended permit object RDP object-group DM_INLINE_NETWORK_34 object-group DM_INLINE_NETWORK_35&lt;/P&gt;&lt;P&gt;access-list int_access_in extended permit tcp object TMCS_IP any object-group DM_INLINE_TCP_3&lt;/P&gt;&lt;P&gt;access-list int_access_in extended permit object-group DM_INLINE_SERVICE_3 object-group DM_INLINE_NETWORK_16 any&lt;/P&gt;&lt;P&gt;access-list int_access_in extended deny ip object Site_Protector any&lt;/P&gt;&lt;P&gt;access-list int_access_in extended permit tcp object-group DM_INLINE_NETWORK_3 object Tumbleweed eq smtp&lt;/P&gt;&lt;P&gt;access-list int_access_in extended permit tcp object Int_net object Tumbleweed eq https&lt;/P&gt;&lt;P&gt;access-list int_access_in extended permit object-group DM_INLINE_SERVICE_7 object-group DM_INLINE_NETWORK_36 172.17.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list int_access_in extended deny ip any object Local_unconfig_ip2 log&lt;/P&gt;&lt;P&gt;access-list int_access_in extended deny ip any object Local_unconfig_IP log&lt;/P&gt;&lt;P&gt;access-list int_access_in extended deny ip object Int_net object-group DM_INLINE_NETWORK_8 log&lt;/P&gt;&lt;P&gt;access-list int_access_in extended permit object-group GSFC_INT_USER_Ports object Blackberry_server any&lt;/P&gt;&lt;P&gt;access-list int_access_in extended permit object-group GSFC_INT_USER_Ports object Int_net any log warnings&lt;/P&gt;&lt;P&gt;access-list int_access_in extended deny ip object Int_net any log&lt;/P&gt;&lt;P&gt;access-list ext_access extended deny object-group DM_INLINE_SERVICE_18 object-group DM_INLINE_NETWORK_42 any&lt;/P&gt;&lt;P&gt;access-list ext_access extended permit tcp any object Tumbleweed object-group DM_INLINE_TCP_0&lt;/P&gt;&lt;P&gt;access-list ext_access extended permit tcp any object NPEC_EXCHANGE_SERVER eq smtp&lt;/P&gt;&lt;P&gt;access-list ext_access extended deny icmp any any traceroute log&lt;/P&gt;&lt;P&gt;access-list ext_access extended deny ip 127.0.0.0 255.0.0.0 any log&lt;/P&gt;&lt;P&gt;access-list ext_access extended deny ip 10.0.0.0 255.0.0.0 any log&lt;/P&gt;&lt;P&gt;access-list ext_access extended deny ip 0.0.0.0 255.0.0.0 any log&lt;/P&gt;&lt;P&gt;access-list ext_access extended deny ip 192.168.0.0 255.255.0.0 any log&lt;/P&gt;&lt;P&gt;access-list ext_access extended deny ip 192.0.2.0 255.255.255.0 any log&lt;/P&gt;&lt;P&gt;access-list ext_access extended deny ip 169.254.0.0 255.255.0.0 any log&lt;/P&gt;&lt;P&gt;access-list ext_access extended deny ip 224.0.0.0 255.0.0.0 any log&lt;/P&gt;&lt;P&gt;access-list ext_access extended deny ip host 255.255.255.255 any log&lt;/P&gt;&lt;P&gt;access-list ext_access extended deny ip any any log&lt;/P&gt;&lt;P&gt;access-list NPEC_access_in extended deny ip 172.26.100.0 255.255.255.0 object Bandwidth_hog_1 inactive&lt;/P&gt;&lt;P&gt;access-list NPEC_access_in extended permit tcp object NPEC_EXCHANGE_SERVER any eq smtp log&lt;/P&gt;&lt;P&gt;access-list NPEC_access_in extended permit tcp 172.26.100.0 255.255.255.0 object Tumbleweed eq https&lt;/P&gt;&lt;P&gt;access-list NPEC_access_in extended deny ip object NPEC_NET object Int_net log&lt;/P&gt;&lt;P&gt;access-list NPEC_access_in extended permit object ODBC 172.26.100.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list NPEC_access_in extended permit object-group GSFC_INT_USER_Ports object NPEC_NET any&lt;/P&gt;&lt;P&gt;access-list NPEC_access_in extended deny ip object NPEC_NET any log&lt;/P&gt;&lt;P&gt;access-list EdOne_access_in remark GSFC guest&amp;nbsp; Intrernet only Wifi Access&lt;/P&gt;&lt;P&gt;access-list EdOne_access_in extended permit object-group DM_INLINE_SERVICE_4 172.17.10.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list EdOne_access_in extended deny ip any any&lt;/P&gt;&lt;P&gt;access-list train_dmz_access_in extended permit object GL_TELNET_SSL object Training_room_PCs object GL_Subnet&lt;/P&gt;&lt;P&gt;access-list train_dmz_access_in extended permit object NCP object Training_room_PCs object Novell_GSF1&lt;/P&gt;&lt;P&gt;access-list train_dmz_access_in extended permit ip object Training_room_PCs object-group DM_INLINE_NETWORK_1&lt;/P&gt;&lt;P&gt;access-list train_dmz_access_in remark Training room PC's to internal servers&lt;/P&gt;&lt;P&gt;access-list train_dmz_access_in extended permit object-group DM_INLINE_SERVICE_11 object Training_room_PCs object-group DM_INLINE_NETWORK_4&lt;/P&gt;&lt;P&gt;access-list train_dmz_access_in extended permit object-group DM_INLINE_SERVICE_1 object Training_room_PCs object-group DM_INLINE_NETWORK_5&lt;/P&gt;&lt;P&gt;access-list train_dmz_access_in extended deny ip object Training_room_PCs object-group DM_INLINE_NETWORK_6 log&lt;/P&gt;&lt;P&gt;access-list train_dmz_access_in extended permit object-group GSFC_INT_USER_Ports object Training_room_PCs any&lt;/P&gt;&lt;P&gt;access-list train_dmz_access_in extended deny ip 172.17.2.0 255.255.255.0 any log&lt;/P&gt;&lt;P&gt;access-list global_mpc extended permit tcp any any object-group DM_INLINE_TCP_1&lt;/P&gt;&lt;P&gt;access-list int_mpc extended permit tcp any any eq www&lt;/P&gt;&lt;P&gt;access-list ext_mpc extended permit tcp any any object-group DM_INLINE_TCP_4&lt;/P&gt;&lt;P&gt;access-list NPEC_mpc extended permit tcp object NPEC_NET any object-group DM_INLINE_TCP_6&lt;/P&gt;&lt;P&gt;access-list GSFC_WiFi_access_in extended permit object-group DM_INLINE_SERVICE_6 object GSFC_USER_WIFI object-group DM_INLINE_NETWORK_26&lt;/P&gt;&lt;P&gt;access-list GSFC_WiFi_access_in extended permit object-group AD_Req_Ports 172.17.20.0 255.255.255.0 object-group DM_INLINE_NETWORK_24&lt;/P&gt;&lt;P&gt;access-list GSFC_WiFi_access_in remark GSFC Intrernet only Wifi Access&lt;/P&gt;&lt;P&gt;access-list GSFC_WiFi_access_in extended permit object-group DM_INLINE_SERVICE_2 object GSFC_USER_WIFI object-group DM_INLINE_NETWORK_28&lt;/P&gt;&lt;P&gt;access-list GSFC_WiFi_access_in extended deny ip any any&lt;/P&gt;&lt;P&gt;access-list PSM_access_in extended permit object-group DM_INLINE_SERVICE_5 172.17.3.0 255.255.255.0 object Balrog&lt;/P&gt;&lt;P&gt;access-list PSM_access_in extended permit tcp 172.17.3.0 255.255.255.0 object Exchange07 eq smtp&lt;/P&gt;&lt;P&gt;access-list PSM_access_in extended permit udp 172.17.3.0 255.255.255.0 object Brain eq ntp&lt;/P&gt;&lt;P&gt;access-list PSM_access_in extended deny ip 172.17.3.0 255.255.255.0 object-group DM_INLINE_NETWORK_25 log&lt;/P&gt;&lt;P&gt;access-list PSM_access_in extended permit tcp 172.17.3.0 255.255.255.0 any object-group DM_INLINE_TCP_7&lt;/P&gt;&lt;P&gt;access-list PSM_access_in extended deny ip 172.17.3.0 255.255.255.0 any log&lt;/P&gt;&lt;P&gt;access-list int_mpc_1 extended permit tcp object Int_net any object-group DM_INLINE_TCP_8&lt;/P&gt;&lt;P&gt;access-list global_mpc_1 extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list GSFC_ShoreTel_LAN_access_in extended permit icmp 172.17.30.0 255.255.255.0 object-group DM_INLINE_NETWORK_13 object-group icmpall log&lt;/P&gt;&lt;P&gt;access-list GSFC_ShoreTel_LAN_access_in extended permit ip 172.17.30.0 255.255.255.0 object-group DM_INLINE_NETWORK_9 log&lt;/P&gt;&lt;P&gt;access-list GSFC_ShoreTel_LAN_access_in extended permit object-group DM_INLINE_PROTOCOL_2 172.17.30.0 255.255.255.0 object-group DM_INLINE_NETWORK_21 object-group DM_INLINE_TCPUDP_1&lt;/P&gt;&lt;P&gt;access-list GSFC_ShoreTel_LAN_access_in extended deny ip any any log&lt;/P&gt;&lt;P&gt;access-list GSFC_ShoreTel_LAN_mpc extended permit ip 172.17.30.0 255.255.255.0 object-group DM_INLINE_NETWORK_29&lt;/P&gt;&lt;P&gt;access-list GSFC_ShoreTel_LAN_mpc_2 extended permit ip 172.17.30.0 255.255.255.0 object-group DM_INLINE_NETWORK_37&lt;/P&gt;&lt;P&gt;access-list GSFC_ShoreTel_LAN_mpc_3 extended permit ip 172.17.30.0 255.255.255.0 object-group DM_INLINE_NETWORK_38&lt;/P&gt;&lt;P&gt;access-list GSFC_ShoreTel_LAN_mpc_1 extended permit ip 172.17.30.0 255.255.255.0 object-group DM_INLINE_NETWORK_30&lt;/P&gt;&lt;P&gt;access-list GSFC_ShoreTel_LAN_mpc_4 extended permit ip 172.17.30.0 255.255.255.0 object-group DM_INLINE_NETWORK_39&lt;/P&gt;&lt;P&gt;access-list GSFC_ShoreTel_LAN_mpc_5 extended permit ip 172.17.30.0 255.255.255.0 object-group DM_INLINE_NETWORK_44&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging emblem&lt;/P&gt;&lt;P&gt;logging buffer-size 10096&lt;/P&gt;&lt;P&gt;logging asdm-buffer-size 400&lt;/P&gt;&lt;P&gt;logging buffered informational&lt;/P&gt;&lt;P&gt;logging trap debugging&lt;/P&gt;&lt;P&gt;logging history notifications&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging facility 18&lt;/P&gt;&lt;P&gt;logging host int 172.21.80.201&lt;/P&gt;&lt;P&gt;logging host int 172.21.70.10&lt;/P&gt;&lt;P&gt;logging permit-hostdown&lt;/P&gt;&lt;P&gt;no logging message 106015&lt;/P&gt;&lt;P&gt;no logging message 313001&lt;/P&gt;&lt;P&gt;no logging message 313008&lt;/P&gt;&lt;P&gt;no logging message 106023&lt;/P&gt;&lt;P&gt;no logging message 710003&lt;/P&gt;&lt;P&gt;no logging message 106100&lt;/P&gt;&lt;P&gt;no logging message 302015&lt;/P&gt;&lt;P&gt;no logging message 302014&lt;/P&gt;&lt;P&gt;no logging message 302013&lt;/P&gt;&lt;P&gt;no logging message 302018&lt;/P&gt;&lt;P&gt;no logging message 302017&lt;/P&gt;&lt;P&gt;no logging message 302016&lt;/P&gt;&lt;P&gt;no logging message 302021&lt;/P&gt;&lt;P&gt;no logging message 302020&lt;/P&gt;&lt;P&gt;flow-export destination int 172.21.70.10 2055&lt;/P&gt;&lt;P&gt;flow-export delay flow-create 10&lt;/P&gt;&lt;P&gt;mtu ext 1500&lt;/P&gt;&lt;P&gt;mtu int 1500&lt;/P&gt;&lt;P&gt;mtu GSFC_GUEST_WIFI 1500&lt;/P&gt;&lt;P&gt;mtu GSFC_WiFi 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu NPEC 1500&lt;/P&gt;&lt;P&gt;mtu train 1500&lt;/P&gt;&lt;P&gt;mtu PSM 1500&lt;/P&gt;&lt;P&gt;mtu GSFC_ShoreTel_LAN 1500&lt;/P&gt;&lt;P&gt;ip local pool GSFCASA_POOL 172.21.86.1-172.21.86.5 mask 255.255.0.0&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface GSFC_GUEST_WIFI&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface GSFC_WiFi&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface NPEC&lt;/P&gt;&lt;P&gt;ip audit name GSFC_Ext_info info action alarm&lt;/P&gt;&lt;P&gt;ip audit name GSFC_Ext attack action alarm drop&lt;/P&gt;&lt;P&gt;ip audit interface ext GSFC_Ext_info&lt;/P&gt;&lt;P&gt;ip audit interface ext GSFC_Ext&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp deny any ext&lt;/P&gt;&lt;P&gt;icmp permit 172.21.0.0 255.255.0.0 int&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-647.bin&lt;/P&gt;&lt;P&gt;asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;no arp permit-nonconnected&lt;/P&gt;&lt;P&gt;nat (int,train) source static Int_net Train_Hide_Behind destination static Training_room_PCs Training_room_PCs unidirectional&lt;/P&gt;&lt;P&gt;nat (GSFC_ShoreTel_LAN,int) source dynamic any interface destination static DM_INLINE_NETWORK_45 DM_INLINE_NETWORK_45&lt;/P&gt;&lt;P&gt;nat (train,int) source static Training_room_PCs int_hide_behind destination static Int_net Int_net unidirectional&lt;/P&gt;&lt;P&gt;nat (int,DMZ) source static DM_INLINE_NETWORK_19 DM_INLINE_NETWORK_19 destination static Tumbleweed Tumbleweed no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;nat (int,DMZ) source static DM_INLINE_NETWORK_11 DM_INLINE_NETWORK_18 destination static DMZ_Net DMZ_Net unidirectional&lt;/P&gt;&lt;P&gt;nat (int,DMZ) source static Int_net Int_net destination static Tumbleweed Tumbleweed no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;nat (NPEC,DMZ) source static NPEC_NET NPEC_NET destination static Tumbleweed Tumbleweed unidirectional&lt;/P&gt;&lt;P&gt;nat (int,NPEC) source static DM_INLINE_NETWORK_12 NPEC_hide_behind destination static NPEC_NET NPEC_NET unidirectional&lt;/P&gt;&lt;P&gt;nat (DMZ,NPEC) source static Tumbleweed Tumbleweed no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;nat (DMZ,int) source static any any destination static Brain Brain unidirectional&lt;/P&gt;&lt;P&gt;nat (DMZ,int) source static Tumbleweed Tumbleweed destination static DM_INLINE_NETWORK_14 DM_INLINE_NETWORK_14 no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;nat (int,GSFC_GUEST_WIFI) source dynamic Int_net Int_to_EdOne_hidebehind destination static DM_INLINE_NETWORK_40 DM_INLINE_NETWORK_40 inactive&lt;/P&gt;&lt;P&gt;nat (GSFC_GUEST_WIFI,ext) source dynamic GSFC_Guest_Internet_only_WIFI Wifi_Hidebehind_ext&lt;/P&gt;&lt;P&gt;nat (GSFC_WiFi,int) source static GSFC_USER_WIFI Wifi_hide_to_Int unidirectional&lt;/P&gt;&lt;P&gt;nat (GSFC_WiFi,ext) source dynamic GSFC_USER_WIFI Wifi_Hidebehind_ext&lt;/P&gt;&lt;P&gt;nat (train,ext) source static Training_room_PCs Ext_hide_behind unidirectional&lt;/P&gt;&lt;P&gt;nat (int,ext) source static DM_INLINE_NETWORK_17 Ext_hide_behind unidirectional&lt;/P&gt;&lt;P&gt;nat (int,ext) source dynamic Int_net interface&lt;/P&gt;&lt;P&gt;nat (int,ext) source static DM_INLINE_NETWORK_22 DM_INLINE_NETWORK_22 destination static NETWORK_OBJ_172.21.86.0_29 NETWORK_OBJ_172.21.86.0_29 no-proxy-arp route-lookup inactive&lt;/P&gt;&lt;P&gt;nat (PSM,int) source static any int_hide_behind destination static DM_INLINE_NETWORK_20 DM_INLINE_NETWORK_20 unidirectional&lt;/P&gt;&lt;P&gt;nat (PSM,ext) source dynamic any Wifi_Hidebehind_ext&lt;/P&gt;&lt;P&gt;nat (int,ext) source static any any destination static NETWORK_OBJ_172.21.86.0_29 NETWORK_OBJ_172.21.86.0_29 no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network Tumbleweed&lt;/P&gt;&lt;P&gt;nat (DMZ,ext) static GSFC_email_ext_address&lt;/P&gt;&lt;P&gt;object network NPEC_EXCHANGE_SERVER&lt;/P&gt;&lt;P&gt;nat (any,any) static Npec_email_ext_address&lt;/P&gt;&lt;P&gt;object network vlan30_DIR_STS&lt;/P&gt;&lt;P&gt;nat (GSFC_ShoreTel_LAN,int) dynamic Shoretel_Dir&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (NPEC,ext) after-auto source dynamic NPEC_NET Npec_ext_Hidebehind&lt;/P&gt;&lt;P&gt;nat (DMZ,ext) after-auto source static any Npec_email_ext_address unidirectional&lt;/P&gt;&lt;P&gt;access-group ext_access in interface ext&lt;/P&gt;&lt;P&gt;access-group int_access_in in interface int&lt;/P&gt;&lt;P&gt;access-group EdOne_access_in in interface GSFC_GUEST_WIFI&lt;/P&gt;&lt;P&gt;access-group GSFC_WiFi_access_in in interface GSFC_WiFi&lt;/P&gt;&lt;P&gt;access-group DMZ_access_in in interface DMZ&lt;/P&gt;&lt;P&gt;access-group NPEC_access_in in interface NPEC&lt;/P&gt;&lt;P&gt;access-group train_dmz_access_in in interface train&lt;/P&gt;&lt;P&gt;access-group PSM_access_in in interface PSM&lt;/P&gt;&lt;P&gt;access-group GSFC_ShoreTel_LAN_access_in in interface GSFC_ShoreTel_LAN&lt;/P&gt;&lt;P&gt;route ext 0.0.0.0 0.0.0.0 168.29.236.1 1&lt;/P&gt;&lt;P&gt;route GSFC_GUEST_WIFI 10.100.30.50 255.255.255.255 10.222.1.1 1&lt;/P&gt;&lt;P&gt;route GSFC_GUEST_WIFI 10.100.98.0 255.255.255.0 10.222.1.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 1:00:00&lt;/P&gt;&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;&lt;P&gt;timeout conn 0:15:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;aaa-server Network_Security protocol radius&lt;/P&gt;&lt;P&gt;aaa-server Network_Security (int) host kenny.gsfc.org&lt;/P&gt;&lt;P&gt;key *****&lt;/P&gt;&lt;P&gt;radius-common-pw *****&lt;/P&gt;&lt;P&gt;aaa-server Network_Auth protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server Network_Auth (int) host Kenny.gsfc.org&lt;/P&gt;&lt;P&gt;key *****&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication telnet console Network_Security&lt;/P&gt;&lt;P&gt;aaa authentication http console Network_Security LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication enable console Network_Security LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication serial console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console Network_Security LOCAL&lt;/P&gt;&lt;P&gt;aaa accounting enable console Network_Security&lt;/P&gt;&lt;P&gt;aaa accounting serial console Network_Security&lt;/P&gt;&lt;P&gt;aaa accounting ssh console Network_Security&lt;/P&gt;&lt;P&gt;aaa accounting telnet console Network_Security&lt;/P&gt;&lt;P&gt;aaa local authentication attempts max-fail 3&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http server idle-timeout 10&lt;/P&gt;&lt;P&gt;http server session-timeout 60&lt;/P&gt;&lt;P&gt;http 172.21.70.10 255.255.255.255 int&lt;/P&gt;&lt;P&gt;http 172.21.191.150 255.255.255.255 int&lt;/P&gt;&lt;P&gt;http 172.21.70.20 255.255.255.255 int&lt;/P&gt;&lt;P&gt;snmp-server host int 172.21.70.10 community ***** version 2c&lt;/P&gt;&lt;P&gt;snmp-server location Computer Room&lt;/P&gt;&lt;P&gt;snmp-server contact Eric Jorgensen&lt;/P&gt;&lt;P&gt;snmp-server community *****&lt;/P&gt;&lt;P&gt;fragment chain 1 ext&lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto ipsec ikev2 ipsec-proposal DES&lt;/P&gt;&lt;P&gt;protocol esp encryption des&lt;/P&gt;&lt;P&gt;protocol esp integrity sha-1 md5&lt;/P&gt;&lt;P&gt;crypto ipsec ikev2 ipsec-proposal 3DES&lt;/P&gt;&lt;P&gt;protocol esp encryption 3des&lt;/P&gt;&lt;P&gt;protocol esp integrity sha-1 md5&lt;/P&gt;&lt;P&gt;crypto ipsec ikev2 ipsec-proposal AES&lt;/P&gt;&lt;P&gt;protocol esp encryption aes&lt;/P&gt;&lt;P&gt;protocol esp integrity sha-1 md5&lt;/P&gt;&lt;P&gt;crypto ipsec ikev2 ipsec-proposal AES192&lt;/P&gt;&lt;P&gt;protocol esp encryption aes-192&lt;/P&gt;&lt;P&gt;protocol esp integrity sha-1 md5&lt;/P&gt;&lt;P&gt;crypto ipsec ikev2 ipsec-proposal AES256&lt;/P&gt;&lt;P&gt;protocol esp encryption aes-256&lt;/P&gt;&lt;P&gt;protocol esp integrity sha-1 md5&lt;/P&gt;&lt;P&gt;crypto ca trustpoint ASDM_TrustPoint0&lt;/P&gt;&lt;P&gt;enrollment self&lt;/P&gt;&lt;P&gt;subject-name O=Georgia Student Finance Commission,C=US,St=Georgia,L=Tucker&lt;/P&gt;&lt;P&gt;proxy-ldc-issuer&lt;/P&gt;&lt;P&gt;crl configure&lt;/P&gt;&lt;P&gt;crypto ca trustpoint ASDM_TrustPoint1&lt;/P&gt;&lt;P&gt;enrollment url &lt;/P&gt;&lt;P&gt;&lt;A href="http://168.29.236.19:80/+CSCOCA+/asa_ca.crl" target="_blank"&gt;http://168.29.236.19:80/+CSCOCA+/asa_ca.crl&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crl configure&lt;/P&gt;&lt;P&gt;crypto ca trustpoint ASDM_TrustPoint2&lt;/P&gt;&lt;P&gt;enrollment self&lt;/P&gt;&lt;P&gt;email &lt;/P&gt;&lt;P&gt;&lt;A href="mailto:ciso@gsfc.org" target="_blank"&gt;ciso@gsfc.org&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;subject-name CN=GSFCASA&lt;/P&gt;&lt;P&gt;ip-address 168.29.236.16&lt;/P&gt;&lt;P&gt;proxy-ldc-issuer&lt;/P&gt;&lt;P&gt;crl configure&lt;/P&gt;&lt;P&gt;crypto ca trustpoint _SmartCallHome_ServerCA&lt;/P&gt;&lt;P&gt;crl configure&lt;/P&gt;&lt;P&gt;crypto ca trustpoint LOCAL-CA-SERVER&lt;/P&gt;&lt;P&gt;keypair LOCAL-CA-SERVER&lt;/P&gt;&lt;P&gt;crl configure&lt;/P&gt;&lt;P&gt;crypto ca trustpoint ASDM_TrustPoint3&lt;/P&gt;&lt;P&gt;enrollment self&lt;/P&gt;&lt;P&gt;email &lt;/P&gt;&lt;P&gt;&lt;A href="mailto:ericj@gsfc.org" target="_blank"&gt;ericj@gsfc.org&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;subject-name CN=gsfcasa&lt;/P&gt;&lt;P&gt;ip-address 168.29.236.16&lt;/P&gt;&lt;P&gt;proxy-ldc-issuer&lt;/P&gt;&lt;P&gt;crl configure&lt;/P&gt;&lt;P&gt;crypto ca server&lt;/P&gt;&lt;P&gt;keysize 2048&lt;/P&gt;&lt;P&gt;keysize server 2048&lt;/P&gt;&lt;P&gt;smtp from-address &lt;/P&gt;&lt;P&gt;&lt;A href="mailto:ericjn@gsfc.org" target="_blank"&gt;ericjn@gsfc.org&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;publish-crl int 80&lt;/P&gt;&lt;P&gt;publish-crl ext 443&lt;/P&gt;&lt;P&gt;crypto ca certificate chain _SmartCallHome_ServerCA&lt;/P&gt;&lt;P&gt;crypto ca certificate chain ASDM_TrustPoint3&lt;/P&gt;&lt;P&gt;quit&lt;/P&gt;&lt;P&gt;crypto ikev2 policy 1&lt;/P&gt;&lt;P&gt;encryption aes-256&lt;/P&gt;&lt;P&gt;integrity sha&lt;/P&gt;&lt;P&gt;group 5&lt;/P&gt;&lt;P&gt;prf sha&lt;/P&gt;&lt;P&gt;lifetime seconds 86400&lt;/P&gt;&lt;P&gt;crypto ikev2 policy 10&lt;/P&gt;&lt;P&gt;encryption aes-192&lt;/P&gt;&lt;P&gt;integrity sha&lt;/P&gt;&lt;P&gt;group 5&lt;/P&gt;&lt;P&gt;prf sha&lt;/P&gt;&lt;P&gt;lifetime seconds 86400&lt;/P&gt;&lt;P&gt;crypto ikev2 policy 20&lt;/P&gt;&lt;P&gt;encryption aes&lt;/P&gt;&lt;P&gt;integrity sha&lt;/P&gt;&lt;P&gt;group 5&lt;/P&gt;&lt;P&gt;prf sha&lt;/P&gt;&lt;P&gt;lifetime seconds 86400&lt;/P&gt;&lt;P&gt;crypto ikev2 policy 30&lt;/P&gt;&lt;P&gt;encryption 3des&lt;/P&gt;&lt;P&gt;integrity sha&lt;/P&gt;&lt;P&gt;group 5&lt;/P&gt;&lt;P&gt;prf sha&lt;/P&gt;&lt;P&gt;lifetime seconds 86400&lt;/P&gt;&lt;P&gt;crypto ikev2 policy 40&lt;/P&gt;&lt;P&gt;encryption des&lt;/P&gt;&lt;P&gt;integrity sha&lt;/P&gt;&lt;P&gt;group 5&lt;/P&gt;&lt;P&gt;prf sha&lt;/P&gt;&lt;P&gt;lifetime seconds 86400&lt;/P&gt;&lt;P&gt;crypto ikev2 enable ext&lt;/P&gt;&lt;P&gt;crypto ikev2 remote-access trustpoint ASDM_TrustPoint2&lt;/P&gt;&lt;P&gt;crypto ikev1 enable ext&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 10&lt;/P&gt;&lt;P&gt;authentication crack&lt;/P&gt;&lt;P&gt;encryption aes-256&lt;/P&gt;&lt;P&gt;hash sha&lt;/P&gt;&lt;P&gt;group 2&lt;/P&gt;&lt;P&gt;lifetime 86400&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 20&lt;/P&gt;&lt;P&gt;authentication rsa-sig&lt;/P&gt;&lt;P&gt;encryption aes-256&lt;/P&gt;&lt;P&gt;hash sha&lt;/P&gt;&lt;P&gt;group 2&lt;/P&gt;&lt;P&gt;lifetime 86400&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 30&lt;/P&gt;&lt;P&gt;authentication pre-share&lt;/P&gt;&lt;P&gt;encryption aes-256&lt;/P&gt;&lt;P&gt;hash sha&lt;/P&gt;&lt;P&gt;group 2&lt;/P&gt;&lt;P&gt;lifetime 86400&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 40&lt;/P&gt;&lt;P&gt;authentication crack&lt;/P&gt;&lt;P&gt;encryption aes-192&lt;/P&gt;&lt;P&gt;hash sha&lt;/P&gt;&lt;P&gt;group 2&lt;/P&gt;&lt;P&gt;lifetime 86400&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 50&lt;/P&gt;&lt;P&gt;authentication rsa-sig&lt;/P&gt;&lt;P&gt;encryption aes-192&lt;/P&gt;&lt;P&gt;hash sha&lt;/P&gt;&lt;P&gt;group 2&lt;/P&gt;&lt;P&gt;lifetime 86400&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 60&lt;/P&gt;&lt;P&gt;authentication pre-share&lt;/P&gt;&lt;P&gt;encryption aes-192&lt;/P&gt;&lt;P&gt;hash sha&lt;/P&gt;&lt;P&gt;group 2&lt;/P&gt;&lt;P&gt;lifetime 86400&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 70&lt;/P&gt;&lt;P&gt;authentication crack&lt;/P&gt;&lt;P&gt;encryption aes&lt;/P&gt;&lt;P&gt;hash sha&lt;/P&gt;&lt;P&gt;group 2&lt;/P&gt;&lt;P&gt;lifetime 86400&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 80&lt;/P&gt;&lt;P&gt;authentication rsa-sig&lt;/P&gt;&lt;P&gt;encryption aes&lt;/P&gt;&lt;P&gt;hash sha&lt;/P&gt;&lt;P&gt;group 2&lt;/P&gt;&lt;P&gt;lifetime 86400&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 90&lt;/P&gt;&lt;P&gt;authentication pre-share&lt;/P&gt;&lt;P&gt;encryption aes&lt;/P&gt;&lt;P&gt;hash sha&lt;/P&gt;&lt;P&gt;group 2&lt;/P&gt;&lt;P&gt;lifetime 86400&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 100&lt;/P&gt;&lt;P&gt;authentication crack&lt;/P&gt;&lt;P&gt;encryption 3des&lt;/P&gt;&lt;P&gt;hash sha&lt;/P&gt;&lt;P&gt;group 2&lt;/P&gt;&lt;P&gt;lifetime 86400&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 110&lt;/P&gt;&lt;P&gt;authentication rsa-sig&lt;/P&gt;&lt;P&gt;encryption 3des&lt;/P&gt;&lt;P&gt;hash sha&lt;/P&gt;&lt;P&gt;group 2&lt;/P&gt;&lt;P&gt;lifetime 86400&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 120&lt;/P&gt;&lt;P&gt;authentication pre-share&lt;/P&gt;&lt;P&gt;encryption 3des&lt;/P&gt;&lt;P&gt;hash sha&lt;/P&gt;&lt;P&gt;group 2&lt;/P&gt;&lt;P&gt;lifetime 86400&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 172.21.80.203 255.255.255.255 int&lt;/P&gt;&lt;P&gt;ssh 172.21.70.10 255.255.255.255 int&lt;/P&gt;&lt;P&gt;ssh 172.21.70.20 255.255.255.255 int&lt;/P&gt;&lt;P&gt;ssh timeout 4&lt;/P&gt;&lt;P&gt;ssh version 2&lt;/P&gt;&lt;P&gt;ssh key-exchange group dh-group1-sha1&lt;/P&gt;&lt;P&gt;console timeout 9&lt;/P&gt;&lt;P&gt;priority-queue int&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection scanning-threat shun&lt;/P&gt;&lt;P&gt;threat-detection statistics port&lt;/P&gt;&lt;P&gt;threat-detection statistics protocol&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;/P&gt;&lt;P&gt;ntp server 64.250.177.145 source ext&lt;/P&gt;&lt;P&gt;ntp server 172.21.192.12 source int prefer&lt;/P&gt;&lt;P&gt;ssl server-version sslv3-only&lt;/P&gt;&lt;P&gt;ssl client-version tlsv1-only&lt;/P&gt;&lt;P&gt;ssl encryption aes128-sha1 aes256-sha1 3des-sha1&lt;/P&gt;&lt;P&gt;ssl trust-point ASDM_TrustPoint0 int&lt;/P&gt;&lt;P&gt;ssl trust-point ASDM_TrustPoint2 ext&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;anyconnect image disk0:/anyconnect-win-2.4.1012-k9.pkg 1&lt;/P&gt;&lt;P&gt;anyconnect profiles Security_admin_client_profile disk0:/Security_admin_client_profile.xml&lt;/P&gt;&lt;P&gt;tunnel-group-list enable&lt;/P&gt;&lt;P&gt;group-policy DfltGrpPolicy attributes&lt;/P&gt;&lt;P&gt;dns-server value 172.21.192.134 172.21.192.133&lt;/P&gt;&lt;P&gt;vpn-idle-timeout 15&lt;/P&gt;&lt;P&gt;vpn-tunnel-protocol l2tp-ipsec&lt;/P&gt;&lt;P&gt;default-domain value gsfc.org&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;&amp;nbsp; anyconnect ssl rekey time 20&lt;/P&gt;&lt;P&gt;&amp;nbsp; http-comp none&lt;/P&gt;&lt;P&gt;&amp;nbsp; activex-relay disable&lt;/P&gt;&lt;P&gt;&amp;nbsp; file-entry disable&lt;/P&gt;&lt;P&gt;&amp;nbsp; file-browsing disable&lt;/P&gt;&lt;P&gt;&amp;nbsp; url-entry disable&lt;/P&gt;&lt;P&gt;group-policy "GroupPolicy 12.45.44.8" internal&lt;/P&gt;&lt;P&gt;group-policy "GroupPolicy 12.45.44.8" attributes&lt;/P&gt;&lt;P&gt;vpn-tunnel-protocol ikev1&lt;/P&gt;&lt;P&gt;username ericjorgensen password /96HI3oHjDP5MXAu encrypted privilege 15&lt;/P&gt;&lt;P&gt;tunnel-group DefaultRAGroup general-attributes&lt;/P&gt;&lt;P&gt;authentication-server-group (int) Network_Security&lt;/P&gt;&lt;P&gt;authorization-server-group LOCAL&lt;/P&gt;&lt;P&gt;scep-enrollment enable&lt;/P&gt;&lt;P&gt;tunnel-group DefaultRAGroup ipsec-attributes&lt;/P&gt;&lt;P&gt;ikev1 pre-shared-key *****&lt;/P&gt;&lt;P&gt;peer-id-validate nocheck&lt;/P&gt;&lt;P&gt;ikev1 user-authentication none&lt;/P&gt;&lt;P&gt;tunnel-group DefaultWEBVPNGroup general-attributes&lt;/P&gt;&lt;P&gt;authentication-server-group (int) LOCAL&lt;/P&gt;&lt;P&gt;scep-enrollment enable&lt;/P&gt;&lt;P&gt;tunnel-group DefaultWEBVPNGroup webvpn-attributes&lt;/P&gt;&lt;P&gt;without-csd&lt;/P&gt;&lt;P&gt;tunnel-group DefaultWEBVPNGroup ipsec-attributes&lt;/P&gt;&lt;P&gt;peer-id-validate nocheck&lt;/P&gt;&lt;P&gt;tunnel-group DefaultWEBVPNGroup ppp-attributes&lt;/P&gt;&lt;P&gt;authentication ms-chap-v2&lt;/P&gt;&lt;P&gt;tunnel-group GSFCADMIN type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group GSFCADMIN general-attributes&lt;/P&gt;&lt;P&gt;address-pool GSFCASA_POOL&lt;/P&gt;&lt;P&gt;authentication-server-group Network_Security&lt;/P&gt;&lt;P&gt;tunnel-group GSFCADMIN ipsec-attributes&lt;/P&gt;&lt;P&gt;ikev1 pre-shared-key *****&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map global-class&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;class-map GSFC_ShoreTel_LAN-class&lt;/P&gt;&lt;P&gt;match access-list GSFC_ShoreTel_LAN_mpc&lt;/P&gt;&lt;P&gt;class-map NPEC-class&lt;/P&gt;&lt;P&gt;match access-list NPEC_mpc&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;class-map ext-class&lt;/P&gt;&lt;P&gt;match access-list ext_mpc&lt;/P&gt;&lt;P&gt;class-map int-class&lt;/P&gt;&lt;P&gt;match access-list int_mpc_1&lt;/P&gt;&lt;P&gt;class-map global-class1&lt;/P&gt;&lt;P&gt;description Netflow&lt;/P&gt;&lt;P&gt;match access-list global_mpc_1&lt;/P&gt;&lt;P&gt;class-map global_class&lt;/P&gt;&lt;P&gt;class-map GSFC_ShoreTel_LAN-class5&lt;/P&gt;&lt;P&gt;match access-list GSFC_ShoreTel_LAN_mpc_5&lt;/P&gt;&lt;P&gt;class-map GSFC_ShoreTel_LAN-class4&lt;/P&gt;&lt;P&gt;match access-list GSFC_ShoreTel_LAN_mpc_4&lt;/P&gt;&lt;P&gt;class-map GSFC_ShoreTel_LAN-class3&lt;/P&gt;&lt;P&gt;match access-list GSFC_ShoreTel_LAN_mpc_3&lt;/P&gt;&lt;P&gt;class-map GSFC_ShoreTel_LAN-class2&lt;/P&gt;&lt;P&gt;match access-list GSFC_ShoreTel_LAN_mpc_1&lt;/P&gt;&lt;P&gt;class-map GSFC_ShoreTel_LAN-class1&lt;/P&gt;&lt;P&gt;match access-list GSFC_ShoreTel_LAN_mpc_2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map ext-policy&lt;/P&gt;&lt;P&gt;class ext-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; csc fail-open&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;description NetFlow&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect http&lt;/P&gt;&lt;P&gt;class global-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect http&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;class global-class1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect http&lt;/P&gt;&lt;P&gt;class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; user-statistics accounting&lt;/P&gt;&lt;P&gt;&amp;nbsp; flow-export event-type all destination 172.21.70.10&lt;/P&gt;&lt;P&gt;policy-map int-policy&lt;/P&gt;&lt;P&gt;class int-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; csc fail-open&lt;/P&gt;&lt;P&gt;policy-map GSFC_ShoreTel_LAN-policy&lt;/P&gt;&lt;P&gt;class GSFC_ShoreTel_LAN-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect mgcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; priority&lt;/P&gt;&lt;P&gt;class GSFC_ShoreTel_LAN-class2&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;class GSFC_ShoreTel_LAN-class1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;class GSFC_ShoreTel_LAN-class3&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; priority&lt;/P&gt;&lt;P&gt;class GSFC_ShoreTel_LAN-class4&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;class GSFC_ShoreTel_LAN-class5&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; priority&lt;/P&gt;&lt;P&gt;policy-map NPEC-policy&lt;/P&gt;&lt;P&gt;class NPEC-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; csc fail-open&lt;/P&gt;&lt;P&gt;policy-map asa_global_fw_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;service-policy ext-policy interface ext&lt;/P&gt;&lt;P&gt;service-policy int-policy interface int&lt;/P&gt;&lt;P&gt;service-policy NPEC-policy interface NPEC&lt;/P&gt;&lt;P&gt;service-policy GSFC_ShoreTel_LAN-policy interface GSFC_ShoreTel_LAN&lt;/P&gt;&lt;P&gt;smtp-server 172.21.13.7&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;service call-home&lt;/P&gt;&lt;P&gt;call-home reporting anonymous&lt;/P&gt;&lt;P&gt;call-home&lt;/P&gt;&lt;P&gt;contact-email-addr &lt;/P&gt;&lt;P&gt;&lt;A href="mailto:ericj@gsfc.org" target="_blank"&gt;ericj@gsfc.org&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;profile CiscoTAC-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination address http &lt;/P&gt;&lt;P&gt;&lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination address email &lt;/P&gt;&lt;P&gt;&lt;A href="mailto:callhome@cisco.com" target="_blank"&gt;callhome@cisco.com&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination transport-method http&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;/P&gt;&lt;P&gt;hpm topN enable&lt;/P&gt;&lt;P&gt;Cryptochecksum:4c7a353f02d602ac8bc99bd1c5d1a977&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:26:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320485#M344515</guid>
      <dc:creator>Mukesh Brahmbhatt</dc:creator>
      <dc:date>2019-03-12T02:26:50Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320486#M344517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest starting with "packet-tracer" tests for both interface &lt;STRONG&gt;"int"&lt;/STRONG&gt; and &lt;STRONG&gt;"GSFC_ShoreTel_LAN"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input int tcp &lt;SOURCE ip=""&gt; &lt;SOURCE port=""&gt; &lt;DESTINATION ip=""&gt; &lt;DESTINATION port=""&gt;&lt;/DESTINATION&gt;&lt;/DESTINATION&gt;&lt;/SOURCE&gt;&lt;/SOURCE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input GSFC_ShoreTel_LAN tcp &lt;SOURCE ip=""&gt; &lt;SOURCE port=""&gt; &lt;DESTINATION ip=""&gt; &lt;DESTINATION port=""&gt;&lt;/DESTINATION&gt;&lt;/DESTINATION&gt;&lt;/SOURCE&gt;&lt;/SOURCE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Post some tests output here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 18:32:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320486#M344517</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-16T18:32:49Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320487#M344518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; here is result&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;gsfcasa# packet-tracer input int tcp 172.17.30.75 255.255.255.0 172.21.13.51 20&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;BR /&gt;gsfcasa# packet-tracer input int tcp 172.17.30.75 20 172.21.13.51 20&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 172.21.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; int&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: int&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: int&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;gsfcasa# packet-tracer input GSFC_ShoreTel_LAN tcp 172.17.30.75 20 172.21.13.5$&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 172.21.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; int&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: GSFC_ShoreTel_LAN&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: int&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;gsfcasa#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 19:07:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320487#M344518</guid>
      <dc:creator>Mukesh Brahmbhatt</dc:creator>
      <dc:date>2013-08-16T19:07:27Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320488#M344519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first command there is using the wrong source address that is not behind &lt;STRONG&gt;"int"&lt;/STRONG&gt; interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the destination IP address in the second command? It doesnt show the whole command you entered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 19:14:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320488#M344519</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-16T19:14:32Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320489#M344520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you JouniForss,&lt;/P&gt;&lt;P&gt; sorry I am not good with ASA firewall, IP is 172.21.13.51&lt;/P&gt;&lt;P&gt;other cmd 's output is as below&lt;/P&gt;&lt;P&gt;gsfcasa# packet-tracer input int tcp 172.21.13.51 20 172.17.30.75 20&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 172.17.30.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; GSFC_ShoreTel_LAN&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group int_access_in in interface int&lt;BR /&gt;access-list int_access_in extended permit object-group GSFC_INT_USER_Ports object Int_net any log warnings&lt;BR /&gt;object-group service GSFC_INT_USER_Ports&lt;BR /&gt; service-object object CISCO_VPN&lt;BR /&gt; service-object object CISCO_VPN_PORT&lt;BR /&gt; service-object object Citrix1495&lt;BR /&gt; service-object object Citrix1604&lt;BR /&gt; service-object object ConnectDirect&lt;BR /&gt; service-object object Document_Direct&lt;BR /&gt; service-object object Edconnect&lt;BR /&gt; service-object object HTTP8000&lt;BR /&gt; service-object object HTTP8080&lt;BR /&gt; service-object object HTTP8890&lt;BR /&gt; service-object object IAG_Ext_Port&lt;BR /&gt; service-object object TCP9000&lt;BR /&gt; service-object object TCP9191&lt;BR /&gt; service-object object Time&lt;BR /&gt; service-object object Time_udp&lt;BR /&gt; service-object tcp destination eq domain&lt;BR /&gt; service-object tcp destination eq ftp&lt;BR /&gt; service-object tcp destination eq ftp-data&lt;BR /&gt; service-object tcp destination eq www&lt;BR /&gt; service-object tcp destination eq https&lt;BR /&gt; service-object tcp destination eq lotusnotes&lt;BR /&gt; service-object tcp destination eq pop3&lt;BR /&gt; service-object udp destination eq domain&lt;BR /&gt; service-object udp destination eq nameserver&lt;BR /&gt; service-object object Time_123&lt;BR /&gt; service-object object SFTP&lt;BR /&gt; service-object object DOAS_PORT&lt;BR /&gt; service-object object DOAS_port2&lt;BR /&gt; service-object object GTA_BILL2&lt;BR /&gt; service-object object VPN&lt;BR /&gt; service-object object VPN_udp&lt;BR /&gt; service-object object Emulate_live&lt;BR /&gt; service-object object UGA_EDU_Web_Port&lt;BR /&gt; service-object object MS_Live_meeting_port&lt;BR /&gt; service-object object AES_SFTP_PORT&lt;BR /&gt; service-object object GL_TELNET_SSL&lt;BR /&gt; service-object object gosaxfrd.dev.bor.usg.edu&lt;BR /&gt; service-object object GOSAXFR.PROD.REGENTS.USG_ONS&lt;BR /&gt; service-object object GOSAXFRT.EAS.REGENTS.USG_ONS&lt;BR /&gt; service-object object Blackberry_SRP&lt;BR /&gt; service-object object Galileo_portal&lt;BR /&gt; service-object object Real_Player&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: INSPECT&lt;BR /&gt;Subtype: np-inspect&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type:&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: USER-STATISTICS&lt;BR /&gt;Subtype: user-statistics&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 9&lt;BR /&gt;Type: USER-STATISTICS&lt;BR /&gt;Subtype: user-statistics&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 10&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 8721219, packet dispatched to next module&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: int&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: GSFC_ShoreTel_LAN&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;&lt;P&gt;gsfcasa#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 19:30:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320489#M344520</guid>
      <dc:creator>Mukesh Brahmbhatt</dc:creator>
      <dc:date>2013-08-16T19:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320490#M344521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically the above output tells us the the test goes through the firewall rules and the traffic would be allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can also see that the traffic doesnt match any NAT configuration so the hosts should be visible to eachother with the original IP addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if there is a problem with connectivity from &lt;STRONG&gt;"int"&lt;/STRONG&gt; to &lt;STRONG&gt;"GSFC_ShoreTel_LAN"&lt;/STRONG&gt; then this would seem to indicate that its not on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you made sure that the network configurations from all the way from the hosts/devices to the ASA trunk interfaces are fine? Is the Vlan 30 added to the switch trunk interface connected to the ASA for example (unless it allows all Vlan IDs)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Do you see the actual hosts behind the new subinterface of the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can for example use the following command and see if there is anything in the ARP table for the new Vlan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show arp | inc GSFC_ShoreTel_LAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Aug 2013 19:41:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320490#M344521</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-16T19:41:33Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320491#M344522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Jouni,&lt;/P&gt;&lt;P&gt; I try that command and i can see 1 phone, i have check all vlan settings too everything is correct, i stll can't have no connection pass thru, I try packet tracer gui mode, if it will have some help, why packet get dropped. i didn't get any informational output except packet droped by access list, is there any way to get this information in more detail to diagnose this log?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 13:38:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320491#M344522</guid>
      <dc:creator>Mukesh Brahmbhatt</dc:creator>
      <dc:date>2013-08-19T13:38:47Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320492#M344523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;help!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 16:47:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320492#M344523</guid>
      <dc:creator>Mukesh Brahmbhatt</dc:creator>
      <dc:date>2013-08-19T16:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320493#M344524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would imagine that you should see more than that behind the interface if the ASA is the L3 gateway for the Vlan30?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the phones configure staticly with IP addresses or do they use DHCP? If they use DHCP then I can't see any DHCP configuration on the ASA or DHCP Relay configuration on the ASA. And seems that there is no router behind the Vlan30 interface that could be able to do the DHCP Relay/IP Helper Address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sadly I have little to no knowledge of VOIP related subjects but I would thing the first thing related to getting the phones working would be to get an IP address through DHCP after which I guess they might use TFTP connection towards some server (that might be defined in the DHCP options)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, if you know exactly what connections from the Vlan30 are failing, you can use the &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; to test those connections and see where they might fail according to the ASA. The above CLI configurations is very complex and hard to read for someone dealing mostly with CLI. It seems it has been done with ASDM which usually results in multiple &lt;STRONG&gt;"object-group"&lt;/STRONG&gt; created which makes reading the configuration even more of a nightmare without the help of &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another thing is to naturally monitor the ASA logs through a Syslog server or ASDM to see what happens during the connection attempts.&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 17:56:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320493#M344524</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-19T17:56:24Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320494#M344525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you Jouni,&lt;/P&gt;&lt;P&gt; I understand DHCP option, but we are not using any DHCP for this, we have assign static IP to phone, here is strange observation i just notice while i was doing test, In packet tracer if i start it from interface Shoretel and have IP of gateway 172.17.30.1 and ping to any int ip&amp;nbsp; 172.21.13.51-55 any ip it fails, but if i change shoretel IP 172.17.30.75 it pass ping or&amp;nbsp; any service i try, I am using Dell 6228p switches, it is&amp;nbsp; layer 3 swiches, but we are not doing any layer 3 routing on switch at all, cause we need to have some restriction/acces rule needed to implemented after i get this resolve, if I use this on vlan1 it works fine, even if i wanted to ping ASA vlan 30 interface from my workstation it fails too,&lt;/P&gt;&lt;P&gt; I am sorry i am asking too many dumb quastions, but as i say i am totally new to this cisco ASA line of products.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 18:50:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320494#M344525</guid>
      <dc:creator>Mukesh Brahmbhatt</dc:creator>
      <dc:date>2013-08-19T18:50:09Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320495#M344526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; will fail if you use the interface IP address as the source for the traffic. You should always use some IP address from the source network that is not used on the interface. It doesnt have to be an actual IP address configured on some host. As long as it belongs to some network routed behind that interface it should be fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first thing to confirm would be that the L2 and L3 are fine between the ASA gateway interface and the actual devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding the ASA by default allows ICMP to its interface IP address if you ping it from some host behind that interface. So if this is not working it would seem that there is something wrong with the actual setup between the ASA and the phones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So unless you can confirm that the connection between the Phones/hosts and the ASA subinterface is fine there is not much point checking the firewall settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you absolutely sure that all the configurations on the phones/hosts are correct? Since you are using 172.x.x.x IP addresses have you made sure that you have used the correct network mask for example so that couldnt cause the problem with connectivity?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to see what traffic is incoming/outgoing from the new interface then you can configure a traffic capture on the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list VLAN30-CAP permit ip 172.17.30.0 255.255.255.0 any&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list VLAN30-CAP permit ip any 172.17.30.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;capture VLAN30-CAP type raw-data access-list VLAN30-CAP interface GSFC_ShoreTel_LAN buffer 10000000 circular-buffer&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After this you could use the following command to check if any packets are captured with&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show capture&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the following command to upload the capture to some TFTP server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;copy /pcap capture:VLAN30-CAP t&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://x.x.x.x/VLAN30-CAP.pcap"&gt;ftp://x.x.x.x/VLAN30-CAP.pcap&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can then open the file with Wireshark to get a clearer picture of what the ASA sees from the Vlan30 network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 19:03:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320495#M344526</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-19T19:03:02Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320496#M344527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you, I am going to take my laptop on that switch and configure IP taht is in VLAN 30, than I use cmd that you have suggested me. &lt;/P&gt;&lt;P&gt;i will post my result later,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 19:14:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320496#M344527</guid>
      <dc:creator>Mukesh Brahmbhatt</dc:creator>
      <dc:date>2013-08-19T19:14:30Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320497#M344528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jouni,&lt;/P&gt;&lt;P&gt;I did that test and I can ping all device in subnet 172.17.30.x without any issue, but&amp;nbsp; when i am trying to ping any devices to 172.21.13.x it fails, I will do run some devices on 172.17.30.x subnet and will capture all, than i will check it with wireshark, i will do it tomorrow. i wil update any outcome.&lt;/P&gt;&lt;P&gt; thanks. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Aug 2013 19:41:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320497#M344528</guid>
      <dc:creator>Mukesh Brahmbhatt</dc:creator>
      <dc:date>2013-08-19T19:41:43Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320498#M344529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; can you help me to setup access rules. &lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt;Aug 20 2013&lt;/TD&gt;&lt;TD&gt;07:35:46&lt;/TD&gt;&lt;TD&gt;313004&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;Denied ICMP type=0, from laddr 172.17.30.75 on interface GSFC_ShoreTel_LAN to 172.21.13.55: no matching session&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;this is what i see, i have added rules to allow ping, but it is still failing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Aug 2013 11:46:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320498#M344529</guid>
      <dc:creator>Mukesh Brahmbhatt</dc:creator>
      <dc:date>2013-08-20T11:46:55Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320499#M344530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I had to guess then I would have to say that you probably have configured the new Vlan wrong somehow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA sees an ICMP Echo Reply (Type=0) coming from the new networks host 172.17.30.75 headed back to the host 172.21.13.55 which has seemingly sent the ICMP Echo (Type=8)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the ASA claims that it has not seen the ICMP Echo corresponding to this ICMP Echo Reply it blocks the Echo Reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would further indicate that when the host 172.21.13.55 sent the ICMP Echo, it went DIRECTLY to the host 172.17.30.75 through some device BEFORE the ASA. The host on the new Vlan then sent the reply to its default gateway ASA which had not seen the ICMP Echo and therefore blocked the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though to me it seems that the &lt;STRONG&gt;"int"&lt;/STRONG&gt; interface doesnt have any router behind it. Atleast something the ASA would have route for. So I am not totally sure if the above described situation is true. It atleast seems like so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you take the capture from a single host on the new Vlan? Did you confirm that for example an ICMP Echo sent from that device through ASA also got a Echo Reply through the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Aug 2013 12:08:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320499#M344530</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-20T12:08:19Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320500#M344531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;as you can see previous netwrok admin has assigned IP to&amp;nbsp; int 0/1&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;nameif int&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 172.21.191.121 255.255.0.0&lt;/P&gt;&lt;P&gt;is this can be root of all problem? lately we get lot of hickup in network. and when it does complate network will go down for least 20-30 minutes, &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Aug 2013 19:02:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320500#M344531</guid>
      <dc:creator>Mukesh Brahmbhatt</dc:creator>
      <dc:date>2013-08-20T19:02:46Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320501#M344532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From what I saw, the &lt;STRONG&gt;"int"&lt;/STRONG&gt; interface configuration doesnt cause any problems in traffic forwarding. There is no overlap in the networks. And to my understanding the ASA would not even let you configure overlapping networks on the actual interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;"int"&lt;/STRONG&gt; interface holds the address space &lt;STRONG&gt;172.21.0.0 - 172.21.255.255&lt;/STRONG&gt;, while the new subinterface holds only &lt;STRONG&gt;172.17.30.0 - 172.17.30.255&lt;/STRONG&gt;. So there is no overlap there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would have to presume that there is some problem related to the actual L3 switch network. It would seem like they were actually doing routing at the moment instead of acting like L2 switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Aug 2013 19:27:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320501#M344532</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-20T19:27:08Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320502#M344533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; below is my network layout.&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/0/8/151805-shoretel.png" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Aug 2013 19:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320502#M344533</guid>
      <dc:creator>Mukesh Brahmbhatt</dc:creator>
      <dc:date>2013-08-20T19:34:16Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320503#M344534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Jouni,&lt;/P&gt;&lt;P&gt; thanks for solutions, finally i found problem, you are right, it was 1 more swtich was in btween and it has vlan association attached, and it was doing routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for help.&lt;/P&gt;&lt;P&gt;you ROCK!!!!!!! thank sagain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Aug 2013 13:25:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320503#M344534</guid>
      <dc:creator>Mukesh Brahmbhatt</dc:creator>
      <dc:date>2013-08-21T13:25:09Z</dc:date>
    </item>
    <item>
      <title>add inter vlan to existing ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320504#M344536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to hear it working now. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It did sound like that kind of problem judging by the log message you posted earlier. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do remember to mark a reply as the correct answer if it answered question and rate helpfull answers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Aug 2013 13:29:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/add-inter-vlan-to-existing-asa-5510/m-p/2320504#M344536</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-08-21T13:29:30Z</dc:date>
    </item>
  </channel>
</rss>

