<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ask the Expert: Firewall Security and Troubleshooting VPN fo in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099685#M392056</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Krishna,&lt;/P&gt;&lt;P&gt;When you have to send/receive packets with higher payload size, you require to chage the MSS size on the device. If you need to allow payload with higher packet size you need change the MSS size on the interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will be using NAT-T when there is an device in between your two VPN end point is perfroming PAT. This feature is already enable by default. If you want to disable it you can use crypto ipsec nat-transperency udp-encapsulation on the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The device running behind PAT enable router/firewall will perform NAT-T on by sending packet on udp port 4500&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Feb 2013 10:04:13 GMT</pubDate>
    <dc:creator>bhavjosh</dc:creator>
    <dc:date>2013-02-08T10:04:13Z</dc:date>
    <item>
      <title>Ask the Expert - Firewall Security and Troubleshooting VPN for Adaptive Security Appliance(ASA)</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099662#M392028</link>
      <description>&lt;P&gt;Learn and ask questions regarding Firewall Security and&amp;nbsp; Troubleshooting VPN for Adaptive Security Appliance(ASA) . This event&amp;nbsp; will be a continuation of the live Facebook Forum.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bhavik&amp;nbsp; Joshi is a Network Consulting Engineer with Service Provider Delivery&amp;nbsp; team in Bangalore and has more than 3 years of experience working with&amp;nbsp; security solutions implementation and troubleshooting network issues. &lt;/P&gt;&lt;P&gt;He&amp;nbsp; has been actively working on multi-vendor security device and migration&amp;nbsp; of multi-vendor security devices with cisco security solution. He also&amp;nbsp; holds a CCIE Security certification #26263.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Where: &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Please go to Cisco Support Facebook Page on the event day: &lt;A href="http://www.facebook.com/CiscoSupportCommunity" rel="nofollow" target="_blank"&gt;http://www.facebook.com/CiscoSupportCommunity&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;When: &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;8:00 AM PST (San Francisco; UTC -7 hrs)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This corresponds to:&lt;/P&gt;&lt;P&gt;5:00 PM CET(Paris; UTC +1 hr)&lt;/P&gt;&lt;P&gt;9:00 PM PKT (Pakistan, UTC +5 hrs) &lt;/P&gt;&lt;P&gt;9:30 PM IST (India; UTC +5:30 hrs)&lt;/P&gt;&lt;P&gt;11:00 PM (Indonesia; UTC +7 hrs)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What is Facebook Forum?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Facebook&amp;nbsp; forums are online conversations, held at a pre-arranged time on our&amp;nbsp; Facebook page. It gives you an opportunity to interact with a live Cisco&amp;nbsp; expert and get more information about a particular technology, service&amp;nbsp; or product.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:53:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099662#M392028</guid>
      <dc:creator>ciscomoderator</dc:creator>
      <dc:date>2019-03-12T00:53:50Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099663#M392029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bhavik ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm happy that this topic came up in Ask The Expert section.Most of my work involves setting up Site to Site VPN tunnels to securely access client locations. We have a Cisco ASA 5505 in place. Is it possible that I can restrict communication from client end to our location through the tunnel , ie , restrict access for client location machines from accessing our network? Can I use access lists for the same ? What access lists should I be configuring ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anup&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2013 18:50:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099663#M392029</guid>
      <dc:creator>Anup Sasikumar</dc:creator>
      <dc:date>2013-01-29T18:50:22Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099664#M392030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bhavik ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm interested in learning how to troubleshoot Site-To-Site VPN's, IPSec and Web VPN. What material would you recommend to assist in this adventure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 12:23:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099664#M392030</guid>
      <dc:creator>JOHN MURPHY</dc:creator>
      <dc:date>2013-01-30T12:23:03Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099665#M392031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bhavik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to configure two cisco ASA 5520 in a redundant mode with IPv4 &amp;amp; IPv6 support for our VPN clients (runs Cisco ANy connect).&amp;nbsp; My questions are &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;Is IPv6 support available in the above setup ? if yes please share document.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;Can it be possible to run both ASAs in Active-Active state. In case the one goes down, shall the associated vpn clients needs reconnection ?&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size: 10pt;"&gt;Can you share helpful document for confguring ASA in redundant mode.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thanks !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Umair&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2013 13:38:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099665#M392031</guid>
      <dc:creator>kthned</dc:creator>
      <dc:date>2013-01-30T13:38:26Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099666#M392032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bhavik,&lt;/P&gt;&lt;P&gt;My ASA5505 does not work properly when I click AJAX button; it should reload the new pages when I changed the contents. But not responding and nothing happen.　I checked through the Cisco support community, I found some questions and answers related this problem, but not quietly solvedas the following links;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;ASA5505 Clientless SSL and Ajax issue&lt;BR /&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3187376#3187376"&gt;https://supportforums.cisco.com/message/3187376#3187376&lt;/A&gt;&lt;BR /&gt;CISCO ASA 5505 SSL VPN not able to display web pages properly with &lt;BR /&gt;Javascript&lt;BR /&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3143207#3143207"&gt;https://supportforums.cisco.com/message/3143207#3143207&lt;/A&gt;&lt;BR /&gt;WebVPN - SSL Portal - URL Rewrite&lt;BR /&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3609935#3609935"&gt;https://supportforums.cisco.com/message/3609935#3609935&lt;/A&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCub09280" target="_blank"&gt;CSCub09280&lt;/A&gt; ASA Content rewrite HTML content was treated as ajax response&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCtk95435" target="_blank"&gt;CSCtk95435&lt;/A&gt; ASA rewriter: radcontrols based AJAX/ASP website not working properly&lt;/P&gt;&lt;P&gt;My question is: if I update the ASA-5505's ASA OS and the ASDM,&lt;BR /&gt;that would fix the problem?&lt;/P&gt;&lt;P&gt;Please help me!!&lt;/P&gt;&lt;P&gt;Here is the current ASA OS and ASDM version and I will try to the update version.&lt;/P&gt;&lt;P&gt; &lt;BR /&gt;Cisco ASA-5505&lt;BR /&gt;ASA OS&lt;BR /&gt;current:8.4(2)&lt;BR /&gt;⇒to：9.1(1)&lt;/P&gt;&lt;P&gt;ASDM&lt;BR /&gt;current:6.4(5）&lt;BR /&gt;⇒to：7.1(1)&lt;/P&gt;&lt;P&gt; &lt;BR /&gt;Cisco Adaptive Security Appliance Software Version 8.4(2)&lt;BR /&gt;Device Manager Version 6.4(5)&lt;BR /&gt;Hardware: ASA5505, 512 MB RAM, CPU Geode 500 MHz&lt;BR /&gt;BIOS Flash M50FW016 @ 0xfff00000, 2048KB&lt;BR /&gt;Encryption hardware device : Cisco ASA-5505&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 08:46:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099666#M392032</guid>
      <dc:creator>deansakai1</dc:creator>
      <dc:date>2013-01-31T08:46:27Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099667#M392033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thx for such kind of easy support community!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We support&amp;nbsp; VERY CRITICAL business process and we need to replace ASA5510&amp;nbsp; 8.0&amp;nbsp;&amp;nbsp; to&amp;nbsp;&amp;nbsp;&amp;nbsp; ASA5540&amp;nbsp; 9.1 version&lt;/P&gt;&lt;P&gt;we have very large config file&amp;nbsp; need minimum downtime.&lt;/P&gt;&lt;P&gt;What is ur reccomendation ?&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;apply&amp;nbsp; old config to new ASA&amp;nbsp; with same IOS (8.0)&amp;nbsp;&amp;nbsp; , then upgade it&amp;nbsp; to new one&amp;nbsp; (9.1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or backup from ASA5510 (8.0)&amp;nbsp; with ASDM and restore it at&amp;nbsp; 5540 (9.1) ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx beforehand &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 13:14:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099667#M392033</guid>
      <dc:creator>elmayir777</dc:creator>
      <dc:date>2013-01-31T13:14:53Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099668#M392034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Bhavik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to find the answer if the ASA can perform load balancing per-packet or per-destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In a situation where I have an ASA ver8.4.4.1 and load balance two routers (two default routes).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 21:31:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099668#M392034</guid>
      <dc:creator>gaboughanem</dc:creator>
      <dc:date>2013-01-31T21:31:29Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099669#M392035</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can actually do that very easily using the ACL for the the site to site VPN.&amp;nbsp; You can even get it down to the port level.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2013 19:07:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099669#M392035</guid>
      <dc:creator>ALIAOF_</dc:creator>
      <dc:date>2013-02-01T19:07:05Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099670#M392036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a pretty cool site for troubleshooting VPN's &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2013 19:08:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099670#M392036</guid>
      <dc:creator>ALIAOF_</dc:creator>
      <dc:date>2013-02-01T19:08:08Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099671#M392037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohamad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's a very useful one ! Thanks for sharing !&lt;/P&gt;&lt;P&gt; &lt;BR /&gt;Regards, &lt;BR /&gt;Anup &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Feb 2013 05:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099671#M392037</guid>
      <dc:creator>Anup Sasikumar</dc:creator>
      <dc:date>2013-02-02T05:05:09Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099672#M392038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohammad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Great ! I should be reconfiguring&amp;nbsp; the access lists which defines the " interesting" traffic through the tunnel , right? &lt;/P&gt;&lt;P&gt;But I am just wondering , Let's say if I have the following setup&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;LAN1&lt;/STRONG&gt; (192.168.1.X)-&amp;gt;(192.168.1.1- Inside) &lt;STRONG&gt;MainASA&lt;/STRONG&gt; (Outside -1.1.1.1) ----- Internet -------(Outside -2.2.2.2) &lt;STRONG&gt;BranchASA&amp;nbsp; &lt;/STRONG&gt;( Inside - 192.168.2.1) -&amp;gt;&lt;STRONG&gt;LAN 2&lt;/STRONG&gt;(192.168.2.X)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I configure access lists for intresting traffic in Crypto map configuration , Is it necessary that I should be allowing traffic between ASA Inside IP address to establish a tunnel or since we are already specifying the Remote Peer details with the public IP of the ASA on the other end , allowing traffic to ASA Inside IP address is not required?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I need to meet the follwing conidtions&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. All nodes in the main location should be able to access all nodes in Branch location &lt;/P&gt;&lt;P&gt;2. Branch location nodes should only be able access node 192.168.1.100 in Main location &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would the access list for interesting traffic to be defined in Cryptomap configuratios be &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Main location&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list MAIN2BRANCH extended permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Branch location&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list BRANCH2MAIN extended permit ip 192.168.2.0 255.255.255.0 host 192.168.1.100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would that also prevent the return traffic (lets say , ping reply ) from 192.168.2.X network when trying to access any node on Branch from Main location , which is not desired ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, &lt;BR /&gt;Anup &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Feb 2013 05:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099672#M392038</guid>
      <dc:creator>Anup Sasikumar</dc:creator>
      <dc:date>2013-02-02T05:41:18Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099673#M392039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Anup,&lt;/P&gt;&lt;P&gt;You can use the ACL with restricted source and destination IP. This ACL you have to use with you match address statement with the used crypto map&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 13:54:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099673#M392039</guid>
      <dc:creator>bhavjosh</dc:creator>
      <dc:date>2013-02-04T13:54:44Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099674#M392040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi John,&lt;/P&gt;&lt;P&gt;There are too many technotes and debugging documents available on cisco websites, also refer books like Cisco VPN Troubleshooting &amp;amp; CCNP Security VPN official Cert Guide&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 14:03:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099674#M392040</guid>
      <dc:creator>bhavjosh</dc:creator>
      <dc:date>2013-02-04T14:03:39Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099675#M392042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Syed,&lt;/P&gt;&lt;P&gt;Please refer the cisco document given below on the link. hope it help you to clear you doubts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa84/asdm64/configuration_guide/ha_active_active.pdf"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/asdm64/configuration_guide/ha_active_active.pdf&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 14:09:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099675#M392042</guid>
      <dc:creator>bhavjosh</dc:creator>
      <dc:date>2013-02-04T14:09:40Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099676#M392044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sakai,&lt;/P&gt;&lt;P&gt;You have to upgrade on 9.1(1) or 8.4(5) as this is a bug and fixed in this ios.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 14:17:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099676#M392044</guid>
      <dc:creator>bhavjosh</dc:creator>
      <dc:date>2013-02-04T14:17:07Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099677#M392046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Elmayir,&lt;/P&gt;&lt;P&gt;You should go through the release nots of 9.1, it will help you to and let you know the precautions that should be taken while upgrading from 8.0 to 9.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please go through the below link once.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa91/release/notes/asarn91.html#wp678072"&gt;http://www.cisco.com/en/US/docs/security/asa/asa91/release/notes/asarn91.html#wp678072&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 14:21:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099677#M392046</guid>
      <dc:creator>bhavjosh</dc:creator>
      <dc:date>2013-02-04T14:21:30Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099678#M392048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;You can do the load balancing by configuring cluster.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/vpn_params.html#wp1048834"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/vpn_params.html#wp1048834&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 14:25:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099678#M392048</guid>
      <dc:creator>bhavjosh</dc:creator>
      <dc:date>2013-02-04T14:25:23Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099679#M392050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well what you can do is try the VPN filter option, check out this link.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808c9a87.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808c9a87.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 20:20:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099679#M392050</guid>
      <dc:creator>ALIAOF_</dc:creator>
      <dc:date>2013-02-04T20:20:46Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099680#M392051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bhavik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please explain in what scenario we will use MSS (Maximum Segment Size) configuration and its importance in troubleshooting VPN related issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also if you can please explain NAT traversal configuration ? Where do i need to configure NAT traversal? It should be on NAT device next to Firewall or on Firewall itself. What does this NAT configuration actually do?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;IMG ___jive_emoticon_name="happy" jivemacro="emoticon" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" /&gt;&lt;/P&gt;&lt;P&gt;Krishnanand Yadav&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2013 04:34:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099680#M392051</guid>
      <dc:creator>krishnanand.yadav</dc:creator>
      <dc:date>2013-02-05T04:34:11Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Firewall Security and Troubleshooting VPN for Ad</title>
      <link>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099681#M392052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bhavik,&lt;/P&gt;&lt;P&gt;I really appreciated your support, because before you gave me the advice, &lt;/P&gt;&lt;P&gt;I haven't had the confidence to be able to fix this problerm. &lt;/P&gt;&lt;P&gt;Now, I'll try to upgrade the ios. Thanks again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2013 04:02:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ask-the-expert-firewall-security-and-troubleshooting-vpn-for/m-p/2099681#M392052</guid>
      <dc:creator>deansakai1</dc:creator>
      <dc:date>2013-02-06T04:02:59Z</dc:date>
    </item>
  </channel>
</rss>

