<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Access LAN Services from Other Interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-lan-services-from-other-interface/m-p/2293146#M345830</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I remember correctly you had 9.1 or some other new software running on the ASA when you previously asked about some Static PAT configurations here on CSC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I guess the software level you mention is for the ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would probably start by checking what the &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; command would say about a connection coming from the wireless network to these IP addresses and the services needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer &lt;WIRELESS interface="" name=""&gt; &lt;TCP or="" udp=""&gt; &lt;SOURCE ip=""&gt; &lt;RANDOM source="" port=""&gt; &lt;DESTINATION ip=""&gt; &lt;DESTINATION port=""&gt;&lt;/DESTINATION&gt;&lt;/DESTINATION&gt;&lt;/RANDOM&gt;&lt;/SOURCE&gt;&lt;/TCP&gt;&lt;/WIRELESS&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would tell us what the ASA would do to the packet arriving on its interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Jul 2013 11:20:15 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-07-25T11:20:15Z</dc:date>
    <item>
      <title>Access LAN Services from Other Interface</title>
      <link>https://community.cisco.com/t5/network-security/access-lan-services-from-other-interface/m-p/2293145#M345829</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I really can't get my head around this - I don't know if I'm NATting it wrong or if what I'm attempting just wont work. I'm using ASA 7.1 and Cisco 4500 Switches on my LAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On my LAN I have a Domain Controller (172.16.5.14) and and Exchange Box (172.16.5.222). The Exchange box has 1 NIC and 3 addresses, 1 for SMTP and 1 each for 2 seperate IIS OWA Sites (1 is a Public Folder, the other is OWA)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have my Wireless network behind another interface on my ASA (Security Level 90). I need users on the Wi-Fi (192.168.10.x) to be able to access DNS on my DC and OWA on my Exchange box. My DNS on the DC points all OWA traffic to the LAN address of the Exchange box. I know I could do it by routing traffic from the WiFi to the LAN via the Switch but then what's the point of firewalling if I'm going to bypass it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also have a DMZ network that accesses internal services (such as IIS on the DMZ to SQL on the LAN) which is working fine so I can't understand what I'm doing wrong&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Danny&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:16:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-lan-services-from-other-interface/m-p/2293145#M345829</guid>
      <dc:creator>Danny Cooke</dc:creator>
      <dc:date>2019-03-12T02:16:49Z</dc:date>
    </item>
    <item>
      <title>Access LAN Services from Other Interface</title>
      <link>https://community.cisco.com/t5/network-security/access-lan-services-from-other-interface/m-p/2293146#M345830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I remember correctly you had 9.1 or some other new software running on the ASA when you previously asked about some Static PAT configurations here on CSC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I guess the software level you mention is for the ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would probably start by checking what the &lt;STRONG&gt;"packet-tracer"&lt;/STRONG&gt; command would say about a connection coming from the wireless network to these IP addresses and the services needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer &lt;WIRELESS interface="" name=""&gt; &lt;TCP or="" udp=""&gt; &lt;SOURCE ip=""&gt; &lt;RANDOM source="" port=""&gt; &lt;DESTINATION ip=""&gt; &lt;DESTINATION port=""&gt;&lt;/DESTINATION&gt;&lt;/DESTINATION&gt;&lt;/RANDOM&gt;&lt;/SOURCE&gt;&lt;/TCP&gt;&lt;/WIRELESS&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would tell us what the ASA would do to the packet arriving on its interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jul 2013 11:20:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-lan-services-from-other-interface/m-p/2293146#M345830</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-07-25T11:20:15Z</dc:date>
    </item>
    <item>
      <title>Access LAN Services from Other Interface</title>
      <link>https://community.cisco.com/t5/network-security/access-lan-services-from-other-interface/m-p/2293147#M345831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you are correct - I was rushing to type things out &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Output from Packet-Tracer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: UN-NAT&lt;/P&gt;&lt;P&gt;Subtype: static&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (Wireless_LAN,Legacy_LAN) source static Wireless_LAN-network Wireless_LAN-network destination static SERVER22_LAN_OWA &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SERVER22_LAN_OWA net-to-net&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;NAT divert to egress interface Legacy_LAN&lt;/P&gt;&lt;P&gt;Untranslate 172.16.5.222/443 to 172.16.5.222/443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group Wireless_LAN_access_in in interface Wireless_LAN&lt;/P&gt;&lt;P&gt;access-list Wireless_LAN_access_in extended permit object-group DM_INLINE_SERVICE_7 object Wireless_LAN-network object-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group DM_INLINE_NETWORK_13&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_SERVICE_7&lt;/P&gt;&lt;P&gt; service-object tcp-udp destination eq domain&lt;/P&gt;&lt;P&gt; service-object tcp destination eq www&lt;/P&gt;&lt;P&gt; service-object tcp destination eq https&lt;/P&gt;&lt;P&gt;object-group network DM_INLINE_NETWORK_13&lt;/P&gt;&lt;P&gt; network-object object SERVER22_LAN_OWA&lt;/P&gt;&lt;P&gt; network-object object SERVER15_LAN&lt;/P&gt;&lt;P&gt; network-object object SERVER14_LAN&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (Wireless_LAN,Legacy_LAN) source static Wireless_LAN-network Wireless_LAN-network destination static SERVER22_LAN_OWA &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SERVER22_LAN_OWA net-to-net&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Static translate 192.168.10.62/41298 to 192.168.10.62/41298&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: per-session&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: FILTER&lt;/P&gt;&lt;P&gt;Subtype: filter-url&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 7&lt;/P&gt;&lt;P&gt;Type: FOVER&lt;/P&gt;&lt;P&gt;Subtype: standby-update&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 8&lt;/P&gt;&lt;P&gt;Type:&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 9&lt;/P&gt;&lt;P&gt;Type: FILTER&lt;/P&gt;&lt;P&gt;Subtype: filter-https&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 10&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: rpf-check&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (Wireless_LAN,Legacy_LAN) source static Wireless_LAN-network Wireless_LAN-network destination static SERVER22_LAN_OWA &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SERVER22_LAN_OWA net-to-net&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 11&lt;/P&gt;&lt;P&gt;Type: USER-STATISTICS&lt;/P&gt;&lt;P&gt;Subtype: user-statistics&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 12&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: per-session&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 13&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 14&lt;/P&gt;&lt;P&gt;Type: USER-STATISTICS&lt;/P&gt;&lt;P&gt;Subtype: user-statistics&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 15&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 32433132, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: Wireless_LAN&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: Legacy_LAN&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jul 2013 11:28:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-lan-services-from-other-interface/m-p/2293147#M345831</guid>
      <dc:creator>Danny Cooke</dc:creator>
      <dc:date>2013-07-25T11:28:53Z</dc:date>
    </item>
  </channel>
</rss>

