<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sqlnet Communication problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sqlnet-communication-problem/m-p/2134306#M357170</link>
    <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a challenge getting 2 Oracle servers with each located in "internal" and "DMZ" network segments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The oracle server on the internal network can communicate with the one on the DMZ but the one on the DMZ can NOT talk to the one on the internal network.&lt;/P&gt;&lt;P&gt;The customer wants the architecture to enable realtime data updates on the Oracle in DMZ.&lt;/P&gt;&lt;P&gt;My config is as follows: I need help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# wr t&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.4(3)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 10.1.184.131 Proxy_Server&lt;/P&gt;&lt;P&gt;name 192.168.10.1 Internet_Router&lt;/P&gt;&lt;P&gt;name 10.1.184.122 Mail_Server&lt;/P&gt;&lt;P&gt;name 10.1.184.116 Mail_Server_2&lt;/P&gt;&lt;P&gt;name 10.1.184.121 Mail_Server_3&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif Inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.1.184.1 255.255.248.0 standby 10.1.184.254&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; description LAN/STATE Failover Interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 192.168.30.1 255.255.255.0 standby 192.168.30.2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt; nameif Outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 192.168.10.2 255.255.255.0 standby 192.168.10.20&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa843-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone GMT 1&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;object network Proxy_Server&lt;/P&gt;&lt;P&gt; host 10.1.184.131&lt;/P&gt;&lt;P&gt;object network Mail_Server&lt;/P&gt;&lt;P&gt; host 10.1.184.122&lt;/P&gt;&lt;P&gt;object network Internet_Router&lt;/P&gt;&lt;P&gt; host 192.168.10.1&lt;/P&gt;&lt;P&gt; description Created during name migration&lt;/P&gt;&lt;P&gt;object network Mail_Server_2&lt;/P&gt;&lt;P&gt; host 10.1.184.116&lt;/P&gt;&lt;P&gt; description Created during name migration&lt;/P&gt;&lt;P&gt;object network Mail_Server_3&lt;/P&gt;&lt;P&gt; host 10.1.184.121&lt;/P&gt;&lt;P&gt; description Created during name migration&lt;/P&gt;&lt;P&gt;object network WebServer1&lt;/P&gt;&lt;P&gt; host 192.168.30.3&lt;/P&gt;&lt;P&gt;object network InternalNetwork&lt;/P&gt;&lt;P&gt; subnet 10.1.184.0 255.55.248.0&lt;/P&gt;&lt;P&gt;object network DMZ-IdentityPool&lt;/P&gt;&lt;P&gt; range 192.168.30.30 192.168.30.254&lt;/P&gt;&lt;P&gt;object network WebServer2&lt;/P&gt;&lt;P&gt; host 192.168.30.4&lt;/P&gt;&lt;P&gt;object network obj-remote&lt;/P&gt;&lt;P&gt; subnet 192.168.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-DMZ&lt;/P&gt;&lt;P&gt; subnet 192.16.30.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network DatabaseServer&lt;/P&gt;&lt;P&gt; host 10.1.184.134&lt;/P&gt;&lt;P&gt;object network AppServer&lt;/P&gt;&lt;P&gt; host 10.1.184.126&lt;/P&gt;&lt;P&gt;object network MailServer&lt;/P&gt;&lt;P&gt; host 10.1.184.116&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip object Proxy_Server any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.190 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.83 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit icmp host 10.1.184.190 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.67 any inactive&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.83 object Internet_Router&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.190 object Internet_Router&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit udp any any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip object Mail_Server any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit tcp object Mail_Server any eq smtp&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip object Mail_Server_2 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit tcp object Mail_Server_2 any eq smtp&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended deny tcp any any eq smtp&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit icmp host 10.1.184.43 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip object Mail_Server_3 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit tcp object Mail_Server_3 any eq smtp&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.190 host 192.168.30.3&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit tcp object InternalNetwork host 192.168.30.3 eq www&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.137 host 10.1.184.133&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.62 host 10.1.184.133&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.117 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.117 object Internet_Router&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.129 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.129 object Internet_Router&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.150 host 10.1.184.133&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.150 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.190 host 192.168.30.4&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit tcp object InternalNetwork host 192.168.30.4 eq www&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit tcp host 10.1.184.134 host 192.168.30.4 eq sqlnet&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit udp any eq domain object Proxy_Server&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp object Internet_Router any&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any host 10.1.184.190&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any host 10.1.184.83 inactive&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any object Proxy_Server eq https&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any object Proxy_Server eq www&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any object Mail_Server eq smtp inactive&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any object Mail_Server_2 eq pop3&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit udp any eq domain object Mail_Server_2&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any object Mail_Server eq imap4 inactive&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any object Mail_Server inactive&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any object Mail_Server_2 eq smtp&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any object Mail_Server_2 eq imap4&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any object Mail_Server_2&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any host 10.1.184.43&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any host 192.168.30.3 eq www&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any host 192.168.30.3 eq https&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any host 192.168.30.3&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any host 192.168.30.3 echo&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any host 192.168.30.4 eq www&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any host 192.168.30.4 eq https&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any host 192.168.30.4 echo&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any host 192.168.30.4&lt;/P&gt;&lt;P&gt;access-list branchgroup-SplitACL standard permit 10.0.0.0 255.0.0.0&lt;/P&gt;&lt;P&gt;access-list branchgroup-SplitACL standard permit 192.168.30.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp host 192.168.30.4 host 192.168.30.116 eq smtp&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit icmp host 192.168.30.4 any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit ip host 192.168.30.4 host 192.168.30.134&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp host 192.168.30.4 host 192.168.30.134 eq sqlnet&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging standby&lt;/P&gt;&lt;P&gt;logging emblem&lt;/P&gt;&lt;P&gt;logging list InformationalLog level informational&lt;/P&gt;&lt;P&gt;logging list InformationalLog message 101001&lt;/P&gt;&lt;P&gt;logging buffer-size 16384&lt;/P&gt;&lt;P&gt;logging console notifications&lt;/P&gt;&lt;P&gt;logging monitor errors&lt;/P&gt;&lt;P&gt;logging buffered critical&lt;/P&gt;&lt;P&gt;logging trap errors&lt;/P&gt;&lt;P&gt;logging asdm critical&lt;/P&gt;&lt;P&gt;logging mail informational&lt;/P&gt;&lt;P&gt;logging host Inside 10.1.184.132&lt;/P&gt;&lt;P&gt;logging host Inside 10.1.184.190 6/1470&lt;/P&gt;&lt;P&gt;logging debug-trace&lt;/P&gt;&lt;P&gt;logging ftp-server 10.1.184.190 \\marinasec\akanoa akanoa *****&lt;/P&gt;&lt;P&gt;logging permit-hostdown&lt;/P&gt;&lt;P&gt;logging class auth buffered emergencies trap emergencies&lt;/P&gt;&lt;P&gt;logging class bridge buffered emergencies trap emergencies&lt;/P&gt;&lt;P&gt;logging class config buffered alerts trap emergencies&lt;/P&gt;&lt;P&gt;logging class ip buffered emergencies trap alerts&lt;/P&gt;&lt;P&gt;logging class sys trap alerts&lt;/P&gt;&lt;P&gt;logging class ca trap emergencies&lt;/P&gt;&lt;P&gt;logging class email buffered emergencies trap errors&lt;/P&gt;&lt;P&gt;mtu Inside 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu Outside 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;ip local pool remoteusers 192.168.0.1-192.168.0.254&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit secondary&lt;/P&gt;&lt;P&gt;failover lan interface stateful_failover GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;failover link stateful_failover GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;failover interface ip stateful_failover 192.168.20.1 255.255.255.252 standby 192.168.20.2&lt;/P&gt;&lt;P&gt;no monitor-interface management&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp permit any Inside&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-647.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat (DMZ,Outside) source static obj-DMZ obj-DMZ destination static obj-remote obj-remote&lt;/P&gt;&lt;P&gt;nat (Inside,Outside) source static InternalNetwork InternalNetwork destination static obj-remote obj-remote&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network Mail_Server&lt;/P&gt;&lt;P&gt; nat (Inside,Outside) static Mail_Server no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;object network WebServer1&lt;/P&gt;&lt;P&gt; nat (DMZ,Outside) static 192.168.30.3 dns&lt;/P&gt;&lt;P&gt;object network WebServer2&lt;/P&gt;&lt;P&gt; nat (DMZ,Outside) static 192.168.30.4 dns&lt;/P&gt;&lt;P&gt;object network DatabaseServer&lt;/P&gt;&lt;P&gt; nat (Inside,DMZ) static 192.168.30.134&lt;/P&gt;&lt;P&gt;object network AppServer&lt;/P&gt;&lt;P&gt; nat (Inside,DMZ) static 192.168.30.126&lt;/P&gt;&lt;P&gt;object network MailServer&lt;/P&gt;&lt;P&gt; nat (Inside,DMZ) static 192.168.30.116&lt;/P&gt;&lt;P&gt;access-group Inside_access_in in interface Inside&lt;/P&gt;&lt;P&gt;access-group DMZ_access_in in interface DMZ&lt;/P&gt;&lt;P&gt;access-group Outside_access_in in interface Outside&lt;/P&gt;&lt;P&gt;route Outside 0.0.0.0 0.0.0.0 Internet_Router 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;aaa-server vpn protocol radius&lt;/P&gt;&lt;P&gt;aaa-server vpn (Inside) host 10.1.184.119&lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt;aaa-server vpn (Inside) host 10.1.184.120&lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 10.1.184.190 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;http 10.1.184.2 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;http 10.1.184.83 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set rmtset esp-3des esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto dynamic-map dyn1 1 set ikev1 transform-set rmtset&lt;/P&gt;&lt;P&gt;crypto dynamic-map dyn1 1 set reverse-route&lt;/P&gt;&lt;P&gt;crypto map mymap 1 ipsec-isakmp dynamic dyn1&lt;/P&gt;&lt;P&gt;crypto map mymap interface Outside&lt;/P&gt;&lt;P&gt;crypto ikev1 enable Outside&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 1&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 43200&lt;/P&gt;&lt;P&gt;telnet 10.1.184.83 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;telnet 10.1.184.190 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;telnet 10.1.184.167 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 10.1.184.83 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;ssh 10.1.184.190 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;ssh 10.1.184.43 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics&lt;/P&gt;&lt;P&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;group-policy branchgroup internal&lt;/P&gt;&lt;P&gt;group-policy branchgroup attributes&lt;/P&gt;&lt;P&gt; dns-server value 10.1.184.120&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value branchgroup-SplitACL&lt;/P&gt;&lt;P&gt; default-domain value marinasecuritieslimited.com&lt;/P&gt;&lt;P&gt;username sannib password 3gB/xWLMBVp/AjjW encrypted&lt;/P&gt;&lt;P&gt;username adebimpel password O./lZ/3rlYD/87u2 encrypted&lt;/P&gt;&lt;P&gt;username ojoawob password w1h9Aq2Welzv1fuW encrypted&lt;/P&gt;&lt;P&gt;username agbajer password NuDaZPLHC0BcF7iI encrypted&lt;/P&gt;&lt;P&gt;username oyenihib password eoxptVEUfczen6VR encrypted&lt;/P&gt;&lt;P&gt;username odewolef password yB12L9t1gcr.Wgx/ encrypted&lt;/P&gt;&lt;P&gt;username mainuser password 8KBTvbq5FOuoFce2 encrypted privilege 15&lt;/P&gt;&lt;P&gt;username maakano password c1Cb3uSluyfsyWUb encrypted&lt;/P&gt;&lt;P&gt;tunnel-group branchgroup type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group branchgroup general-attributes&lt;/P&gt;&lt;P&gt; address-pool remoteusers&lt;/P&gt;&lt;P&gt; default-group-policy branchgroup&lt;/P&gt;&lt;P&gt;tunnel-group branchgroup ipsec-attributes&lt;/P&gt;&lt;P&gt; ikev1 pre-shared-key *****&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; user-statistics accounting&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;call-home&lt;/P&gt;&lt;P&gt; profile CiscoTAC-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no active&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address http &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address email &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:callhome@cisco.com" target="_blank"&gt;callhome@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination transport-method http&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;/P&gt;&lt;P&gt;hpm topN enable&lt;/P&gt;&lt;P&gt;Cryptochecksum:bbe838eb9af33fc84083989823bc0c22&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;[OK]&lt;/P&gt;&lt;P&gt;ciscoasa#&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:55:44 GMT</pubDate>
    <dc:creator>olukayode.olabanji</dc:creator>
    <dc:date>2019-03-12T00:55:44Z</dc:date>
    <item>
      <title>Sqlnet Communication problem</title>
      <link>https://community.cisco.com/t5/network-security/sqlnet-communication-problem/m-p/2134306#M357170</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a challenge getting 2 Oracle servers with each located in "internal" and "DMZ" network segments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The oracle server on the internal network can communicate with the one on the DMZ but the one on the DMZ can NOT talk to the one on the internal network.&lt;/P&gt;&lt;P&gt;The customer wants the architecture to enable realtime data updates on the Oracle in DMZ.&lt;/P&gt;&lt;P&gt;My config is as follows: I need help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# wr t&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.4(3)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 10.1.184.131 Proxy_Server&lt;/P&gt;&lt;P&gt;name 192.168.10.1 Internet_Router&lt;/P&gt;&lt;P&gt;name 10.1.184.122 Mail_Server&lt;/P&gt;&lt;P&gt;name 10.1.184.116 Mail_Server_2&lt;/P&gt;&lt;P&gt;name 10.1.184.121 Mail_Server_3&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif Inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.1.184.1 255.255.248.0 standby 10.1.184.254&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; description LAN/STATE Failover Interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 192.168.30.1 255.255.255.0 standby 192.168.30.2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt; nameif Outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 192.168.10.2 255.255.255.0 standby 192.168.10.20&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa843-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone GMT 1&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;object network Proxy_Server&lt;/P&gt;&lt;P&gt; host 10.1.184.131&lt;/P&gt;&lt;P&gt;object network Mail_Server&lt;/P&gt;&lt;P&gt; host 10.1.184.122&lt;/P&gt;&lt;P&gt;object network Internet_Router&lt;/P&gt;&lt;P&gt; host 192.168.10.1&lt;/P&gt;&lt;P&gt; description Created during name migration&lt;/P&gt;&lt;P&gt;object network Mail_Server_2&lt;/P&gt;&lt;P&gt; host 10.1.184.116&lt;/P&gt;&lt;P&gt; description Created during name migration&lt;/P&gt;&lt;P&gt;object network Mail_Server_3&lt;/P&gt;&lt;P&gt; host 10.1.184.121&lt;/P&gt;&lt;P&gt; description Created during name migration&lt;/P&gt;&lt;P&gt;object network WebServer1&lt;/P&gt;&lt;P&gt; host 192.168.30.3&lt;/P&gt;&lt;P&gt;object network InternalNetwork&lt;/P&gt;&lt;P&gt; subnet 10.1.184.0 255.55.248.0&lt;/P&gt;&lt;P&gt;object network DMZ-IdentityPool&lt;/P&gt;&lt;P&gt; range 192.168.30.30 192.168.30.254&lt;/P&gt;&lt;P&gt;object network WebServer2&lt;/P&gt;&lt;P&gt; host 192.168.30.4&lt;/P&gt;&lt;P&gt;object network obj-remote&lt;/P&gt;&lt;P&gt; subnet 192.168.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-DMZ&lt;/P&gt;&lt;P&gt; subnet 192.16.30.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network DatabaseServer&lt;/P&gt;&lt;P&gt; host 10.1.184.134&lt;/P&gt;&lt;P&gt;object network AppServer&lt;/P&gt;&lt;P&gt; host 10.1.184.126&lt;/P&gt;&lt;P&gt;object network MailServer&lt;/P&gt;&lt;P&gt; host 10.1.184.116&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip object Proxy_Server any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.190 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.83 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit icmp host 10.1.184.190 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.67 any inactive&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.83 object Internet_Router&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.190 object Internet_Router&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit udp any any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip object Mail_Server any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit tcp object Mail_Server any eq smtp&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip object Mail_Server_2 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit tcp object Mail_Server_2 any eq smtp&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended deny tcp any any eq smtp&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit icmp host 10.1.184.43 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip object Mail_Server_3 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit tcp object Mail_Server_3 any eq smtp&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.190 host 192.168.30.3&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit tcp object InternalNetwork host 192.168.30.3 eq www&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.137 host 10.1.184.133&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.62 host 10.1.184.133&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.117 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.117 object Internet_Router&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.129 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.129 object Internet_Router&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.150 host 10.1.184.133&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.150 any&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit ip host 10.1.184.190 host 192.168.30.4&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit tcp object InternalNetwork host 192.168.30.4 eq www&lt;/P&gt;&lt;P&gt;access-list Inside_access_in extended permit tcp host 10.1.184.134 host 192.168.30.4 eq sqlnet&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit udp any eq domain object Proxy_Server&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp object Internet_Router any&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any host 10.1.184.190&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any host 10.1.184.83 inactive&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any object Proxy_Server eq https&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any object Proxy_Server eq www&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any object Mail_Server eq smtp inactive&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any object Mail_Server_2 eq pop3&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit udp any eq domain object Mail_Server_2&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any object Mail_Server eq imap4 inactive&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any object Mail_Server inactive&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any object Mail_Server_2 eq smtp&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any object Mail_Server_2 eq imap4&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any object Mail_Server_2&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any host 10.1.184.43&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any host 192.168.30.3 eq www&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any host 192.168.30.3 eq https&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any host 192.168.30.3&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any host 192.168.30.3 echo&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any host 192.168.30.4 eq www&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any host 192.168.30.4 eq https&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any host 192.168.30.4 echo&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit icmp any host 192.168.30.4&lt;/P&gt;&lt;P&gt;access-list branchgroup-SplitACL standard permit 10.0.0.0 255.0.0.0&lt;/P&gt;&lt;P&gt;access-list branchgroup-SplitACL standard permit 192.168.30.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp host 192.168.30.4 host 192.168.30.116 eq smtp&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit icmp host 192.168.30.4 any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit ip host 192.168.30.4 host 192.168.30.134&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp host 192.168.30.4 host 192.168.30.134 eq sqlnet&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging standby&lt;/P&gt;&lt;P&gt;logging emblem&lt;/P&gt;&lt;P&gt;logging list InformationalLog level informational&lt;/P&gt;&lt;P&gt;logging list InformationalLog message 101001&lt;/P&gt;&lt;P&gt;logging buffer-size 16384&lt;/P&gt;&lt;P&gt;logging console notifications&lt;/P&gt;&lt;P&gt;logging monitor errors&lt;/P&gt;&lt;P&gt;logging buffered critical&lt;/P&gt;&lt;P&gt;logging trap errors&lt;/P&gt;&lt;P&gt;logging asdm critical&lt;/P&gt;&lt;P&gt;logging mail informational&lt;/P&gt;&lt;P&gt;logging host Inside 10.1.184.132&lt;/P&gt;&lt;P&gt;logging host Inside 10.1.184.190 6/1470&lt;/P&gt;&lt;P&gt;logging debug-trace&lt;/P&gt;&lt;P&gt;logging ftp-server 10.1.184.190 \\marinasec\akanoa akanoa *****&lt;/P&gt;&lt;P&gt;logging permit-hostdown&lt;/P&gt;&lt;P&gt;logging class auth buffered emergencies trap emergencies&lt;/P&gt;&lt;P&gt;logging class bridge buffered emergencies trap emergencies&lt;/P&gt;&lt;P&gt;logging class config buffered alerts trap emergencies&lt;/P&gt;&lt;P&gt;logging class ip buffered emergencies trap alerts&lt;/P&gt;&lt;P&gt;logging class sys trap alerts&lt;/P&gt;&lt;P&gt;logging class ca trap emergencies&lt;/P&gt;&lt;P&gt;logging class email buffered emergencies trap errors&lt;/P&gt;&lt;P&gt;mtu Inside 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu Outside 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;ip local pool remoteusers 192.168.0.1-192.168.0.254&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit secondary&lt;/P&gt;&lt;P&gt;failover lan interface stateful_failover GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;failover link stateful_failover GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;failover interface ip stateful_failover 192.168.20.1 255.255.255.252 standby 192.168.20.2&lt;/P&gt;&lt;P&gt;no monitor-interface management&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp permit any Inside&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-647.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat (DMZ,Outside) source static obj-DMZ obj-DMZ destination static obj-remote obj-remote&lt;/P&gt;&lt;P&gt;nat (Inside,Outside) source static InternalNetwork InternalNetwork destination static obj-remote obj-remote&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network Mail_Server&lt;/P&gt;&lt;P&gt; nat (Inside,Outside) static Mail_Server no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;object network WebServer1&lt;/P&gt;&lt;P&gt; nat (DMZ,Outside) static 192.168.30.3 dns&lt;/P&gt;&lt;P&gt;object network WebServer2&lt;/P&gt;&lt;P&gt; nat (DMZ,Outside) static 192.168.30.4 dns&lt;/P&gt;&lt;P&gt;object network DatabaseServer&lt;/P&gt;&lt;P&gt; nat (Inside,DMZ) static 192.168.30.134&lt;/P&gt;&lt;P&gt;object network AppServer&lt;/P&gt;&lt;P&gt; nat (Inside,DMZ) static 192.168.30.126&lt;/P&gt;&lt;P&gt;object network MailServer&lt;/P&gt;&lt;P&gt; nat (Inside,DMZ) static 192.168.30.116&lt;/P&gt;&lt;P&gt;access-group Inside_access_in in interface Inside&lt;/P&gt;&lt;P&gt;access-group DMZ_access_in in interface DMZ&lt;/P&gt;&lt;P&gt;access-group Outside_access_in in interface Outside&lt;/P&gt;&lt;P&gt;route Outside 0.0.0.0 0.0.0.0 Internet_Router 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;aaa-server vpn protocol radius&lt;/P&gt;&lt;P&gt;aaa-server vpn (Inside) host 10.1.184.119&lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt;aaa-server vpn (Inside) host 10.1.184.120&lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 10.1.184.190 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;http 10.1.184.2 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;http 10.1.184.83 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec ikev1 transform-set rmtset esp-3des esp-md5-hmac&lt;/P&gt;&lt;P&gt;crypto dynamic-map dyn1 1 set ikev1 transform-set rmtset&lt;/P&gt;&lt;P&gt;crypto dynamic-map dyn1 1 set reverse-route&lt;/P&gt;&lt;P&gt;crypto map mymap 1 ipsec-isakmp dynamic dyn1&lt;/P&gt;&lt;P&gt;crypto map mymap interface Outside&lt;/P&gt;&lt;P&gt;crypto ikev1 enable Outside&lt;/P&gt;&lt;P&gt;crypto ikev1 policy 1&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 43200&lt;/P&gt;&lt;P&gt;telnet 10.1.184.83 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;telnet 10.1.184.190 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;telnet 10.1.184.167 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 10.1.184.83 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;ssh 10.1.184.190 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;ssh 10.1.184.43 255.255.255.255 Inside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics&lt;/P&gt;&lt;P&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;group-policy branchgroup internal&lt;/P&gt;&lt;P&gt;group-policy branchgroup attributes&lt;/P&gt;&lt;P&gt; dns-server value 10.1.184.120&lt;/P&gt;&lt;P&gt; split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list value branchgroup-SplitACL&lt;/P&gt;&lt;P&gt; default-domain value marinasecuritieslimited.com&lt;/P&gt;&lt;P&gt;username sannib password 3gB/xWLMBVp/AjjW encrypted&lt;/P&gt;&lt;P&gt;username adebimpel password O./lZ/3rlYD/87u2 encrypted&lt;/P&gt;&lt;P&gt;username ojoawob password w1h9Aq2Welzv1fuW encrypted&lt;/P&gt;&lt;P&gt;username agbajer password NuDaZPLHC0BcF7iI encrypted&lt;/P&gt;&lt;P&gt;username oyenihib password eoxptVEUfczen6VR encrypted&lt;/P&gt;&lt;P&gt;username odewolef password yB12L9t1gcr.Wgx/ encrypted&lt;/P&gt;&lt;P&gt;username mainuser password 8KBTvbq5FOuoFce2 encrypted privilege 15&lt;/P&gt;&lt;P&gt;username maakano password c1Cb3uSluyfsyWUb encrypted&lt;/P&gt;&lt;P&gt;tunnel-group branchgroup type remote-access&lt;/P&gt;&lt;P&gt;tunnel-group branchgroup general-attributes&lt;/P&gt;&lt;P&gt; address-pool remoteusers&lt;/P&gt;&lt;P&gt; default-group-policy branchgroup&lt;/P&gt;&lt;P&gt;tunnel-group branchgroup ipsec-attributes&lt;/P&gt;&lt;P&gt; ikev1 pre-shared-key *****&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; user-statistics accounting&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;call-home&lt;/P&gt;&lt;P&gt; profile CiscoTAC-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no active&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address http &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address email &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:callhome@cisco.com" target="_blank"&gt;callhome@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination transport-method http&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;/P&gt;&lt;P&gt;hpm topN enable&lt;/P&gt;&lt;P&gt;Cryptochecksum:bbe838eb9af33fc84083989823bc0c22&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;[OK]&lt;/P&gt;&lt;P&gt;ciscoasa#&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:55:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sqlnet-communication-problem/m-p/2134306#M357170</guid>
      <dc:creator>olukayode.olabanji</dc:creator>
      <dc:date>2019-03-12T00:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: Sqlnet Communication problem</title>
      <link>https://community.cisco.com/t5/network-security/sqlnet-communication-problem/m-p/2134307#M357171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems to me that you have configured Static NAT from "inside" to "dmz" so that the "inside" servers are visible to the "dmz" with the IP address belonging to the "dmz"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this something that you absolutely need? Is there something preventing you from using the IP address ranges on both "inside" and "dmz" and not doing NAT for them at all between those interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IF you want to keep the current setup intact regarding NAT, change the DMZ ACL to use the actual 10.1.184.x IP addresses as the destination IP address in the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words, always use the Real IP address of the host in the ACL configuration, NOT the NAT IP address. After doing that change I suppose it should also work for "dmz" to "inside". (NAT IP was used in the ACL in the ASA versions 8.2 and below, the Real IP address is used in software 8.3 and above)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Change&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp host 192.168.30.4 host 192.168.30.116 eq smtp&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit icmp host 192.168.30.4 any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit ip host 192.168.30.4 host 192.168.30.134&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp host 192.168.30.4 host 192.168.30.134 eq sqlnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;To&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp host 192.168.30.4 host 10.1.184.116 eq smtp&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit icmp host 192.168.30.4 any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit ip host 192.168.30.4 host 10.1.184.134&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp host 192.168.30.4 host 10.1.184.134 eq sqlnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also use the "object" names in the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which would be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp host 192.168.30.4 object MailServer eq smtp&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit icmp host 192.168.30.4 any&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit ip host 192.168.30.4 object DatabaseServer&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp host 192.168.30.4 object DatabaseServer eq sqlnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Hope the above helps &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; Please ask more if needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Feb 2013 17:10:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sqlnet-communication-problem/m-p/2134307#M357171</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-03T17:10:07Z</dc:date>
    </item>
  </channel>
</rss>

