<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem accessing FW device in special configuration (with telne in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181242#M359958</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM&gt;The supplier is remote,&amp;nbsp; on the othe side of the VPN is a PIX firewall, behind it, two ASAs and one PIX.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;---From the internal interface of say, firewall two, I cannot ping the&amp;nbsp; supplier, but I can from the outside.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM&gt;This sounds like a problem with the Access-lists or NAT.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, the commands are there.&amp;nbsp; Do you see where I went wrong?&amp;nbsp; Do you wish to see the access list and Nat commands from firewall one?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Marty&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Mar 2013 14:13:52 GMT</pubDate>
    <dc:creator>fregeus.ca</dc:creator>
    <dc:date>2013-03-19T14:13:52Z</dc:date>
    <item>
      <title>Problem accessing FW device in special configuration (with telnet)</title>
      <link>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181237#M359953</link>
      <description>&lt;P&gt;Hello all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a special problem I would like to introduce to you all.&amp;nbsp; If you can help me, all the better.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a customer that has a PIX firewall in his network which a supplier uses to access their product.&amp;nbsp; There is actually four product in house.&amp;nbsp; Each product has its own firewall.&amp;nbsp; Because we could not create multiple vpn tunnels through the single external IP of the customer, we had to put three product with their firewall behing the fourth.&amp;nbsp; That way, there is only one firewall that does a VPN tunnel with the supplier VPN and it covers all four product.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is as follows;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall one is the firewall that does the VPN tunneling for all product.&amp;nbsp; It is a PIX 506E and it has the pix firewall version 6.3(5).&lt;/P&gt;&lt;P&gt;Firewall two is an ASA device that is connected to the Internal network of firewall one.&amp;nbsp; It's a 5505 and runs version 8.2(5)&lt;/P&gt;&lt;P&gt;Firewall three is also an ASA device that is connected to the internal network of firewall one.&amp;nbsp; It is also a 5505 and runs version 7.2(4)&lt;/P&gt;&lt;P&gt;Firewall four is a PIX connected to the internal network of firewall one.&amp;nbsp; It runs version 6.3(5) of the Pix firewall software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, the supplier can, through the VPN tunnel, access all of the product it supports.&amp;nbsp; What the supplier cannot do is access the firewalls that are behind the first.&amp;nbsp; The supplier can access firewall one without a problem, but they cannot access the others.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the three firewall behind the first are configured without NAT and without VPN.&amp;nbsp; They are just firewalling.&lt;/P&gt;&lt;P&gt;From the internal interface of say, firewall two, I cannot ping the supplier, but I can from the outside.&amp;nbsp; The supplier cannot telnet to the inside interface of firewall two, but can on the inside interface of firewall one.&amp;nbsp; The supplier can ping the inside interface of firewall one, its product and the outside interface of all three firewalls, but not the inside.&amp;nbsp; When I look at the logs of one of the FW, all I see is the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-7-710005: UDP request discarded from 10.103.xxx.xxx/137 to outside:10.103.xxx.xxx&lt;SPAN style="font-size: 10pt;"&gt;/137&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;%ASA-7-710005: UDP request discarded from 10.104.xxx.xxx/1025 to inside:255.255.25&lt;SPAN style="font-size: 10pt;"&gt;5.255/1947&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;%ASA-7-710005: TCP request discarded from 142.xxx.xxx.xxx/4020 to outside:10.104.xxx.xxx/23&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;%ASA-7-710005: UDP request discarded from 10.104.xxx.xxx/1025 to inside:255.255.25&lt;SPAN style="font-size: 10pt;"&gt;5.255/1947&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;%ASA-7-710005: UDP request discarded from 10.103.xxx.xxx/138 to outside:10.103.xxx.xxx&lt;SPAN style="font-size: 10pt;"&gt;/138&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Here are some configs from firewall two&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan100&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 10.103.xxx.xxx 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan101&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.104.xxx.xxx 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;access-list acl_inside_access extended permit icmp any any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;access-list acl_inside_access extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list acl_outside_access extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list acl_outside_access extended permit icmp any any&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;access-list nonat extended permit ip 10.104.xxx.0 255.255.255.0 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonat&lt;/P&gt;&lt;P&gt;access-group acl_outside_access in interface outside&lt;/P&gt;&lt;P&gt;access-group acl_inside_access in interface inside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 10.103.xxx.xxx 1&lt;/P&gt;&lt;P&gt;telnet 142.xxx.xxx.xxx 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm missing something, but I don't know what.&amp;nbsp; Can anyone help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:15:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181237#M359953</guid>
      <dc:creator>fregeus.ca</dc:creator>
      <dc:date>2019-03-12T01:15:41Z</dc:date>
    </item>
    <item>
      <title>Problem accessing FW device in special configuration (with telne</title>
      <link>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181238#M359954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if I understood everything correctly but here goes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;You have 4 firewalls&lt;/LI&gt;&lt;LI&gt;One firewall handles the Internet connectivity of all and also the L2L VPN to the Supplier&lt;/LI&gt;&lt;LI&gt;Supplier can only connect to the firewall doing the L2L VPN and Internet connectivity&lt;/LI&gt;&lt;LI&gt;Supplier cant connect to any of the 3 firewall behind the main firewall&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use Telnet to manage the Main firewall because you either&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Have &lt;STRONG&gt;"management-access inside"&lt;/STRONG&gt; configured on the firewall to enable to access the &lt;STRONG&gt;"inside"&lt;/STRONG&gt; interface IP&lt;/LI&gt;&lt;LI&gt;Or you use the "outside" interface IP address through L2L VPN to manage the firewall&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way to connect to an firewall "outside" inteface with &lt;STRONG&gt;"security-level 0&lt;/STRONG&gt;" with Telnet is to do it through a VPN connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now if all the 3 firewalls behind have &lt;STRONG&gt;"security-level 0"&lt;/STRONG&gt; on their interface facing the Main firewall on the edge of the network&amp;nbsp; then it wont simply accept Telnet connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Simplest solution is to use SSH and not Telnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that for some odd reason aint an option you can always consider changing the &lt;STRONG&gt;"security-level"&lt;/STRONG&gt; values of the 3 firewalls so they will accept even Telnet. This might naturally have effect on firewall operation if you have not enabled the configuration &lt;STRONG&gt;"same-security-traffic permit inter-interface"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Mar 2013 22:21:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181238#M359954</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-03-18T22:21:46Z</dc:date>
    </item>
    <item>
      <title>Problem accessing FW device in special configuration (with telne</title>
      <link>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181239#M359955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is what i got, correct me if i'm wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The supplier is remote,&amp;nbsp; on the othe side of the VPN is a PIX firewall, behind it, two ASAs and one PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;---From the internal interface of say, firewall two, I cannot ping the&amp;nbsp; supplier, but I can from the outside. &lt;/STRONG&gt;&lt;/EM&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This sounds like a problem with the Access-lists or NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;---The supplier cannot telnet to the&amp;nbsp; inside interface of firewall two, but can on the inside interface of&amp;nbsp; firewall one.&lt;/STRONG&gt;&lt;/EM&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason for this is because the inside interface of FW2 is seeing the traffic coming from the outside going to the inside interface, this is not allowed on Cisco firewalls. &lt;/P&gt;&lt;P&gt;The same applies for when we want to access the outside interface of the ASA from an internal host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reason why the supplier can reach the inside of FW1 is because of the &lt;STRONG&gt;"management-access inside"&lt;/STRONG&gt;&amp;nbsp; command, this makes this traffic look like it's coming form the inside network, not the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---&lt;EM&gt;&lt;STRONG&gt;The supplier can ping the inside interface of firewall&amp;nbsp; one, its product and the outside interface of all three firewalls, but&amp;nbsp; not the inside. &lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same answer as before.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 00:41:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181239#M359955</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-19T00:41:43Z</dc:date>
    </item>
    <item>
      <title>Problem accessing FW device in special configuration (with telne</title>
      <link>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181240#M359956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM&gt;I am not sure if I understood everything correctly but here goes&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM&gt;You have 4 firewalls&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;One firewall handles the Internet connectivity of all and also the L2L VPN to the Supplier&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;Supplier can only connect to the firewall doing the L2L VPN and Internet connectivity&lt;/EM&gt;&lt;/LI&gt;&lt;LI&gt;&lt;EM&gt;Supplier cant connect to any of the 3 firewall behind the main firewall&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif; min-height: 8pt; height: 8pt;"&gt;You understood correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM&gt;You can use Telnet to manage the Main firewall because you either&lt;/EM&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;EM&gt;Have &lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;"management-access inside"&lt;/STRONG&gt; configured on the firewall to enable to access the &lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;"inside"&lt;/STRONG&gt;interface IP&lt;/EM&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct, that is what I have on ALL firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;The only way to connect to an firewall "outside" inteface with &lt;STRONG style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;"security-level 0&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;EM&gt;&lt;STRONG&gt;"&lt;/STRONG&gt; with Telnet is to do it through a VPN connection&lt;/EM&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I raised the security level of the outside interface of firewall two to 50 and the supplier still cannot get a connection to the inside interface, although I am getting a different message in the logs;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-7-609001: Built local-host outside:142.xxx.xxx.xxx&lt;/P&gt;&lt;P&gt;%ASA-7-609001: Built local-host identity:10.106.xxx.xxx&lt;/P&gt;&lt;P&gt;%ASA-6-302013: Built inbound TCP connection 29742 for outside:142.xxx.xxx.xxx/1135 (&lt;SPAN style="font-size: 10pt;"&gt;142.xxx.xxx/1135) to identity:10.106.xxx.xxx/23 (10.106.xxx.xxx/23)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;%ASA-6-302014: Teardown TCP connection 29742 for outside:142.xxx.xxx.xxx/1135 to ide&lt;SPAN style="font-size: 10pt;"&gt;ntity:10.106.xxx.xxx/23 duration 0:00:00 bytes 0 TCP Reset by appliance&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;%ASA-7-609002: Teardown local-host outside:142.xxx.xxx.xxx duration 0:00:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's the first time I see this 'to identity' in log files.&amp;nbsp; I tried to do a search on it but I get billlions of hits that don't apply.&lt;/P&gt;&lt;P&gt;What is the lowest security level I need to accept telnet from the outside to the inside ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Simplest solution is to use SSH and not Telnet.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is another battle going on in another battlefield.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Marty&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 14:09:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181240#M359956</guid>
      <dc:creator>fregeus.ca</dc:creator>
      <dc:date>2013-03-19T14:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing FW device in special configuration (with t</title>
      <link>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181241#M359957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "management-access inside" command wont help with the firewalls behind the Main Firewall if I have understood the Cisco documentation correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will only work with the firewall that is terminating the VPN connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As the other 3 firewalls arent terminating any VPN connection (the Telnet connection isnt coming from a VPN connection terminated to the specific firewall) the "management-access" wont work with them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should change your configuration so that you connect to the "outside" interface IP of the 3 firewalls and not the "inside" interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is why I suggested playing around with the "security-level" value of the "outside" interface of the 3 Firewalls. Perhaps even changing it to "security-level 100" in which case you WILL NEED the "same-security-traffic" command so that "inside" to "outside" traffic wont stop.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EDIT: Corrected typos and added some text&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 14:13:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181241#M359957</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-03-19T14:13:14Z</dc:date>
    </item>
    <item>
      <title>Problem accessing FW device in special configuration (with telne</title>
      <link>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181242#M359958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM&gt;The supplier is remote,&amp;nbsp; on the othe side of the VPN is a PIX firewall, behind it, two ASAs and one PIX.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;---From the internal interface of say, firewall two, I cannot ping the&amp;nbsp; supplier, but I can from the outside.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM&gt;This sounds like a problem with the Access-lists or NAT.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, the commands are there.&amp;nbsp; Do you see where I went wrong?&amp;nbsp; Do you wish to see the access list and Nat commands from firewall one?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Marty&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 14:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181242#M359958</guid>
      <dc:creator>fregeus.ca</dc:creator>
      <dc:date>2013-03-19T14:13:52Z</dc:date>
    </item>
    <item>
      <title>Problem accessing FW device in special configuration (with telne</title>
      <link>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181243#M359959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks JourniForss&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Decided to try the ssh configuration on the outside interface.&amp;nbsp; A breeze.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Mar 2013 19:38:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181243#M359959</guid>
      <dc:creator>fregeus.ca</dc:creator>
      <dc:date>2013-03-19T19:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Problem accessing FW device in special configuration (with t</title>
      <link>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181244#M359960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume that when you say that you are "testing from the internal interface of firewall two" it means that you are testing from a host behind FW2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not, i assume you are using a customized version of the "&lt;STRONG&gt;ping&lt;/STRONG&gt;" command on the ASA. This won't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If yes, please provide the config form FW1 and the IP addressing information of the involved devices. Src &amp;amp; Dst adresses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 03:38:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181244#M359960</guid>
      <dc:creator>jocamare</dc:creator>
      <dc:date>2013-03-20T03:38:34Z</dc:date>
    </item>
    <item>
      <title>Problem accessing FW device in special configuration (with telne</title>
      <link>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181245#M359961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jocamare for your assistance, but I followed the suggestion of JouniFross and configured the access through SSH instead and use the external interface.&amp;nbsp; Its all configured and it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take care&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Marty.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 12:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-accessing-fw-device-in-special-configuration-with-telnet/m-p/2181245#M359961</guid>
      <dc:creator>fregeus.ca</dc:creator>
      <dc:date>2013-03-20T12:43:00Z</dc:date>
    </item>
  </channel>
</rss>

