<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What is going wrong with this config ?? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077013#M392641</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;lol,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okay at least we know we are good &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not have any other question, please mark the question as answered&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Remember to rate all of the helpful posts , that works as a thanks for the community users&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Feb 2013 17:17:09 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-02-08T17:17:09Z</dc:date>
    <item>
      <title>What is going wrong with this config ??</title>
      <link>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077006#M392614</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am busting my head to find out what is going wrong with this config and cant figure it out since i am not an advanced cisco technician.&lt;/P&gt;&lt;P&gt;Problem is that i cant access the 94.70.142.127 server that is supposed to be in a DMZ zone.&lt;/P&gt;&lt;P&gt;I know it is a bit chaotic but would really appreciate any help since i am running on a deadline.&lt;/P&gt;&lt;P&gt;I am building the config step by step and although it seems to be working access to the server all of the sudden is denied.&lt;/P&gt;&lt;P&gt;No idea if its a NAT issue a firewall issue or a security audit issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are 3 vlans. &lt;/P&gt;&lt;P&gt;Vlan 1 is the inside network.&lt;/P&gt;&lt;P&gt;Vlan 2 is the DMZ server&lt;/P&gt;&lt;P&gt;Vlan 3 is the Management Network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 11796 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;! Last configuration change at 11:28:33 PCTime Fri Jan 4 2013 by admin&lt;/P&gt;&lt;P&gt;! NVRAM config last updated at 11:27:51 PCTime Fri Jan 4 2013 by admin&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 12.4&lt;/P&gt;&lt;P&gt;no service pad&lt;/P&gt;&lt;P&gt;service tcp-keepalives-in&lt;/P&gt;&lt;P&gt;service tcp-keepalives-out&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec localtime show-timezone&lt;/P&gt;&lt;P&gt;service timestamps log datetime msec localtime&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;service sequence-numbers&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname R1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;security authentication failure rate 3 log&lt;/P&gt;&lt;P&gt;security passwords min-length 8&lt;/P&gt;&lt;P&gt;logging message-counter syslog&lt;/P&gt;&lt;P&gt;logging buffered 4096 informational&lt;/P&gt;&lt;P&gt;enable secret 5 $1$oT7y$BwhdEjMJfAaTQI3dzDVwP.&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no aaa new-model&lt;/P&gt;&lt;P&gt;memory-size iomem 10&lt;/P&gt;&lt;P&gt;clock timezone PCTime 2&lt;/P&gt;&lt;P&gt;clock summer-time PCTime date Mar 30 2003 3:00 Oct 26 2003 4:00&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto pki trustpoint TP-self-signed-2567543707&lt;/P&gt;&lt;P&gt; enrollment selfsigned&lt;/P&gt;&lt;P&gt; subject-name cn=IOS-Self-Signed-Certificate-2567543707&lt;/P&gt;&lt;P&gt; revocation-check none&lt;/P&gt;&lt;P&gt; rsakeypair TP-self-signed-2567543707&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto pki certificate chain TP-self-signed-2567543707&lt;/P&gt;&lt;P&gt; certificate self-signed 01&lt;/P&gt;&lt;P&gt;&amp;nbsp; 30820244 308201AD A0030201 02020101 300D0609 2A864886 F70D0101 04050030 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 69666963 6174652D 32353637 35343337 3037301E 170D3133 30313032 30383431 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 35335A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 35363735 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 34333730 3730819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 8100ABA4 B7FFF4F1 9FBE79D8 2CEBCA68 A14BE3AB DBF770C2 EB35A954 B271AE3E &lt;/P&gt;&lt;P&gt;&amp;nbsp; F8485837 F2E8566B 66E5EF6B BCFCDFA3 8F6F91F3 FD8E3015 879A67F5 85DD95F5 &lt;/P&gt;&lt;P&gt;&amp;nbsp; C26875C0 2202CA6C CE95888F 545AB4F6 6F708A0E C65E78D1 60967480 5589F5EE &lt;/P&gt;&lt;P&gt;&amp;nbsp; 80505E46 8767CE2C 37C994FE AB555AF0 BA4C4679 63FF7641 34FFF6EF 3EC38006 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 46B90203 010001A3 6C306A30 0F060355 1D130101 FF040530 030101FF 30170603 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 551D1104 10300E82 0C52312E 646F636E 65742E67 72301F06 03551D23 04183016 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 8014F0DE 85318FB3 70C36B4A FEB4B0CA 446025F0 329C301D 0603551D 0E041604 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 14F0DE85 318FB370 C36B4AFE B4B0CA44 6025F032 9C300D06 092A8648 86F70D01 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 01040500 03818100 5D76D5F4 5FB659C3 1E5B3777 420E1703 CD019889 AE79390D &lt;/P&gt;&lt;P&gt;&amp;nbsp; A2AA4D26 AD9913B4 B3292277 97ACACDD D7093465 78279B4D 5FAC0A21 EFBF3B74 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 6A25BC5B ACFB648F 08F92678 00BB495C 037DEAF7 C5910944 3D2C0643 EA19E9BD &lt;/P&gt;&lt;P&gt;&amp;nbsp; 0AFE5423 AADBB3C2 B2C94296 DABE0D3D 6438F7A8 32B0A92B 3E8E0D26 635070A3 &lt;/P&gt;&lt;P&gt;&amp;nbsp; ACF87E49 65A9E468&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; quit&lt;/P&gt;&lt;P&gt;no ip source-route&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip cef&lt;/P&gt;&lt;P&gt;no ip bootp server&lt;/P&gt;&lt;P&gt;ip domain name docnet.gr&lt;/P&gt;&lt;P&gt;ip name-server 195.170.0.1&lt;/P&gt;&lt;P&gt;no ipv6 cef&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username admin privilege 15 view root secret 5 $1$Lny5$et1FhWOpIKOOYRUtN89H10&lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;archive&lt;/P&gt;&lt;P&gt; log config&lt;/P&gt;&lt;P&gt;&amp;nbsp; hidekeys&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip tcp synwait-time 10&lt;/P&gt;&lt;P&gt;ip ssh version 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map type inspect match-any WebService&lt;/P&gt;&lt;P&gt; match protocol http&lt;/P&gt;&lt;P&gt; match protocol https&lt;/P&gt;&lt;P&gt;class-map type inspect match-all sdm-cls-sdm-pol-NATOutsideToInside-1-1&lt;/P&gt;&lt;P&gt; match class-map WebService&lt;/P&gt;&lt;P&gt; match access-group name WebServer&lt;/P&gt;&lt;P&gt;class-map type inspect match-all ccp-cls-sdm-pol-NATOutsideToInside-1-1&lt;/P&gt;&lt;P&gt; match access-group name Spoofing&lt;/P&gt;&lt;P&gt;class-map type inspect match-any CCP-Voice-permit&lt;/P&gt;&lt;P&gt; match protocol h323&lt;/P&gt;&lt;P&gt; match protocol skinny&lt;/P&gt;&lt;P&gt; match protocol sip&lt;/P&gt;&lt;P&gt;class-map type inspect match-any tcp-udp&lt;/P&gt;&lt;P&gt; match protocol http&lt;/P&gt;&lt;P&gt; match protocol https&lt;/P&gt;&lt;P&gt; match protocol dns&lt;/P&gt;&lt;P&gt; match protocol icmp&lt;/P&gt;&lt;P&gt;class-map type inspect match-all ccp-cls--3&lt;/P&gt;&lt;P&gt; match access-group name mng-out&lt;/P&gt;&lt;P&gt; match class-map tcp-udp&lt;/P&gt;&lt;P&gt;class-map type inspect match-all ccp-cls--2&lt;/P&gt;&lt;P&gt; match access-group name mng-self&lt;/P&gt;&lt;P&gt;class-map type inspect match-all ccp-cls--4&lt;/P&gt;&lt;P&gt; match access-group name mng-out-drop&lt;/P&gt;&lt;P&gt;class-map type inspect match-any ccp-cls-insp-traffic&lt;/P&gt;&lt;P&gt; match protocol cuseeme&lt;/P&gt;&lt;P&gt; match protocol dns&lt;/P&gt;&lt;P&gt; match protocol ftp&lt;/P&gt;&lt;P&gt; match protocol h323&lt;/P&gt;&lt;P&gt; match protocol https&lt;/P&gt;&lt;P&gt; match protocol icmp&lt;/P&gt;&lt;P&gt; match protocol imap&lt;/P&gt;&lt;P&gt; match protocol pop3&lt;/P&gt;&lt;P&gt; match protocol netshow&lt;/P&gt;&lt;P&gt; match protocol shell&lt;/P&gt;&lt;P&gt; match protocol realmedia&lt;/P&gt;&lt;P&gt; match protocol rtsp&lt;/P&gt;&lt;P&gt; match protocol smtp extended&lt;/P&gt;&lt;P&gt; match protocol sql-net&lt;/P&gt;&lt;P&gt; match protocol streamworks&lt;/P&gt;&lt;P&gt; match protocol tftp&lt;/P&gt;&lt;P&gt; match protocol vdolive&lt;/P&gt;&lt;P&gt; match protocol tcp&lt;/P&gt;&lt;P&gt; match protocol udp&lt;/P&gt;&lt;P&gt;class-map type inspect match-all ccp-insp-traffic&lt;/P&gt;&lt;P&gt; match class-map ccp-cls-insp-traffic&lt;/P&gt;&lt;P&gt;class-map type inspect match-any http-https-DMZ&lt;/P&gt;&lt;P&gt; match protocol http&lt;/P&gt;&lt;P&gt; match protocol https&lt;/P&gt;&lt;P&gt;class-map type inspect match-all sdm-cls--2&lt;/P&gt;&lt;P&gt; match class-map http-https-DMZ&lt;/P&gt;&lt;P&gt; match access-group name web_server&lt;/P&gt;&lt;P&gt;class-map type inspect match-any MySQLService&lt;/P&gt;&lt;P&gt; match protocol mysql&lt;/P&gt;&lt;P&gt;class-map type inspect match-all sdm-cls--1&lt;/P&gt;&lt;P&gt; match class-map MySQLService&lt;/P&gt;&lt;P&gt; match access-group name DMZtoMySQL&lt;/P&gt;&lt;P&gt;class-map type inspect match-any ccp-cls-icmp-access&lt;/P&gt;&lt;P&gt; match protocol icmp&lt;/P&gt;&lt;P&gt; match protocol tcp&lt;/P&gt;&lt;P&gt; match protocol udp&lt;/P&gt;&lt;P&gt;class-map type inspect match-all ccp-icmp-access&lt;/P&gt;&lt;P&gt; match class-map ccp-cls-icmp-access&lt;/P&gt;&lt;P&gt;class-map type inspect match-all ccp-invalid-src&lt;/P&gt;&lt;P&gt; match access-group 100&lt;/P&gt;&lt;P&gt;class-map type inspect match-all sdm-nat-https-1&lt;/P&gt;&lt;P&gt; match access-group 102&lt;/P&gt;&lt;P&gt; match protocol https&lt;/P&gt;&lt;P&gt;class-map type inspect match-all ccp-protocol-http&lt;/P&gt;&lt;P&gt; match protocol http&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect ccp-permit-icmpreply&lt;/P&gt;&lt;P&gt; class type inspect ccp-icmp-access&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect &lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; pass&lt;/P&gt;&lt;P&gt;policy-map type inspect sdm-pol-NATOutsideToInside-1&lt;/P&gt;&lt;P&gt; class type inspect ccp-cls-sdm-pol-NATOutsideToInside-1-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop&lt;/P&gt;&lt;P&gt; class type inspect sdm-cls-sdm-pol-NATOutsideToInside-1-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect &lt;/P&gt;&lt;P&gt; class type inspect sdm-nat-https-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect &lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop&lt;/P&gt;&lt;P&gt;policy-map type inspect ccp-inspect&lt;/P&gt;&lt;P&gt; class type inspect ccp-invalid-src&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop log&lt;/P&gt;&lt;P&gt; class type inspect ccp-protocol-http&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect &lt;/P&gt;&lt;P&gt; class type inspect ccp-insp-traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect &lt;/P&gt;&lt;P&gt; class type inspect CCP-Voice-permit&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect &lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop&lt;/P&gt;&lt;P&gt;policy-map type inspect ccp-permit&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop&lt;/P&gt;&lt;P&gt;policy-map type inspect sdm-policy-sdm-cls--1&lt;/P&gt;&lt;P&gt; class type inspect sdm-cls--1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect &lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop&lt;/P&gt;&lt;P&gt;policy-map type inspect ccp-policy-ccp-cls--1&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop&lt;/P&gt;&lt;P&gt;policy-map type inspect ccp-policy-ccp-cls--3&lt;/P&gt;&lt;P&gt; class type inspect ccp-cls--3&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect &lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop&lt;/P&gt;&lt;P&gt;policy-map type inspect sdm-policy-sdm-cls--2&lt;/P&gt;&lt;P&gt; class type inspect sdm-cls--2&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect &lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop&lt;/P&gt;&lt;P&gt;policy-map type inspect ccp-policy-ccp-cls--2&lt;/P&gt;&lt;P&gt; class type inspect ccp-cls--2&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect &lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop&lt;/P&gt;&lt;P&gt;policy-map type inspect ccp-policy-ccp-cls--5&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;zone security out-zone&lt;/P&gt;&lt;P&gt;zone security in-zone&lt;/P&gt;&lt;P&gt;zone security dmz-zone&lt;/P&gt;&lt;P&gt;zone security mng&lt;/P&gt;&lt;P&gt;zone-pair security ccp-zp-self-out source self destination out-zone&lt;/P&gt;&lt;P&gt; service-policy type inspect ccp-permit-icmpreply&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-NATOutsideToInside-1 source out-zone destination in-zone&lt;/P&gt;&lt;P&gt; service-policy type inspect sdm-pol-NATOutsideToInside-1&lt;/P&gt;&lt;P&gt;zone-pair security ccp-zp-in-out source in-zone destination out-zone&lt;/P&gt;&lt;P&gt; service-policy type inspect ccp-inspect&lt;/P&gt;&lt;P&gt;zone-pair security ccp-zp-out-self source out-zone destination self&lt;/P&gt;&lt;P&gt; service-policy type inspect ccp-permit&lt;/P&gt;&lt;P&gt;zone-pair security zp-dmz-to-outside source dmz-zone destination out-zone&lt;/P&gt;&lt;P&gt; service-policy type inspect ccp-inspect&lt;/P&gt;&lt;P&gt;zone-pair security zp-outside-to-dmz source out-zone destination dmz-zone&lt;/P&gt;&lt;P&gt; service-policy type inspect sdm-pol-NATOutsideToInside-1&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-dmz-zone-in-zone source dmz-zone destination in-zone&lt;/P&gt;&lt;P&gt; service-policy type inspect sdm-policy-sdm-cls--1&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-in-zone-dmz-zone source in-zone destination dmz-zone&lt;/P&gt;&lt;P&gt; service-policy type inspect sdm-policy-sdm-cls--2&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-dmz-zone-self source dmz-zone destination self&lt;/P&gt;&lt;P&gt; service-policy type inspect ccp-policy-ccp-cls--1&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-mng-self source mng destination self&lt;/P&gt;&lt;P&gt; service-policy type inspect ccp-policy-ccp-cls--2&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-mng-out-zone source mng destination out-zone&lt;/P&gt;&lt;P&gt; service-policy type inspect ccp-policy-ccp-cls--3&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-out-zone-mng source out-zone destination mng&lt;/P&gt;&lt;P&gt; service-policy type inspect ccp-policy-ccp-cls--5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Null0&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface BRI0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip flow ingress&lt;/P&gt;&lt;P&gt; encapsulation hdlc&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; isdn termination multidrop&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface ATM0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip flow ingress&lt;/P&gt;&lt;P&gt; no atm ilmi-keepalive&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface ATM0.1 point-to-point&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip flow ingress&lt;/P&gt;&lt;P&gt; pvc 8/35 &lt;/P&gt;&lt;P&gt;&amp;nbsp; pppoe-client dial-pool-number 1&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet2&lt;/P&gt;&lt;P&gt; switchport access vlan 3&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet3&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; description $FW_INSIDE$&lt;/P&gt;&lt;P&gt; ip address 192.168.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip flow ingress&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; zone-member security in-zone&lt;/P&gt;&lt;P&gt; ip tcp adjust-mss 1412&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; description $FW_INSIDE$&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip flow ingress&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; zone-member security dmz-zone&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan3&lt;/P&gt;&lt;P&gt; description $FW_INSIDE$&lt;/P&gt;&lt;P&gt; ip address 10.0.10.1 255.255.255.0&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip flow ingress&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; zone-member security mng&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dialer0&lt;/P&gt;&lt;P&gt; description $FW_OUTSIDE$&lt;/P&gt;&lt;P&gt; ip address negotiated&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip mtu 1452&lt;/P&gt;&lt;P&gt; ip flow ingress&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly max-reassemblies 64&lt;/P&gt;&lt;P&gt; zone-member security out-zone&lt;/P&gt;&lt;P&gt; encapsulation ppp&lt;/P&gt;&lt;P&gt; dialer pool 1&lt;/P&gt;&lt;P&gt; dialer-group 1&lt;/P&gt;&lt;P&gt; ppp authentication chap pap callin&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; ppp chap hostname &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:dikt15@otenet.gr" target="_blank"&gt;dikt15@otenet.gr&lt;/A&gt;&lt;/P&gt;&lt;P&gt; ppp chap password 7 0918425001505245&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; ppp pap sent-username &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:dikt15@otenet.gr" target="_blank"&gt;dikt15@otenet.gr&lt;/A&gt;&lt;SPAN&gt; password 7 13511B4B1359417D&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip forward-protocol nd&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 Dialer0&lt;/P&gt;&lt;P&gt;ip route 10.0.10.0 255.255.255.0 Vlan3&lt;/P&gt;&lt;P&gt;no ip http server&lt;/P&gt;&lt;P&gt;ip http secure-server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip nat inside source list 1 interface Dialer0 overload&lt;/P&gt;&lt;P&gt;ip nat inside source static 192.168.0.101 94.70.142.113&lt;/P&gt;&lt;P&gt;ip nat inside source static 192.168.1.102 94.70.142.127&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip access-list extended DMZtoMySQL&lt;/P&gt;&lt;P&gt; remark CCP_ACL Category=128&lt;/P&gt;&lt;P&gt; permit ip host 192.168.1.102 host 192.168.0.101&lt;/P&gt;&lt;P&gt;ip access-list extended Spoofing&lt;/P&gt;&lt;P&gt; remark CCP_ACL Category=128&lt;/P&gt;&lt;P&gt; permit ip 10.0.0.0 0.255.255.255 any&lt;/P&gt;&lt;P&gt; permit ip 192.168.0.0 0.0.255.255 any&lt;/P&gt;&lt;P&gt; permit ip 172.16.0.0 0.15.255.255 any&lt;/P&gt;&lt;P&gt;ip access-list extended VTY_incoming&lt;/P&gt;&lt;P&gt; remark CCP_ACL Category=1&lt;/P&gt;&lt;P&gt; permit ip host 10.0.10.2 any&lt;/P&gt;&lt;P&gt;ip access-list extended WebServer&lt;/P&gt;&lt;P&gt; remark CCP_ACL Category=128&lt;/P&gt;&lt;P&gt; permit ip any host 192.168.1.102&lt;/P&gt;&lt;P&gt;ip access-list extended mng-out&lt;/P&gt;&lt;P&gt; remark CCP_ACL Category=128&lt;/P&gt;&lt;P&gt; permit ip 10.0.10.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;ip access-list extended mng-out-drop&lt;/P&gt;&lt;P&gt; remark CCP_ACL Category=128&lt;/P&gt;&lt;P&gt; permit ip any any&lt;/P&gt;&lt;P&gt;ip access-list extended mng-self&lt;/P&gt;&lt;P&gt; remark CCP_ACL Category=128&lt;/P&gt;&lt;P&gt; permit ip any any&lt;/P&gt;&lt;P&gt;ip access-list extended web_server&lt;/P&gt;&lt;P&gt; remark CCP_ACL Category=128&lt;/P&gt;&lt;P&gt; permit ip 192.168.0.0 0.0.0.255 host 192.168.1.102&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;logging 10.0.10.2&lt;/P&gt;&lt;P&gt;access-list 1 remark INSIDE_IF=Vlan1&lt;/P&gt;&lt;P&gt;access-list 1 remark CCP_ACL Category=2&lt;/P&gt;&lt;P&gt;access-list 1 remark VLan 1 Access&lt;/P&gt;&lt;P&gt;access-list 1 permit 192.168.0.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 1 remark VLan 3 Access&lt;/P&gt;&lt;P&gt;access-list 1 permit 10.0.10.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 1 remark Vlan 2 Access&lt;/P&gt;&lt;P&gt;access-list 1 permit 192.168.1.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 100 remark CCP_ACL Category=128&lt;/P&gt;&lt;P&gt;access-list 100 permit ip host 255.255.255.255 any&lt;/P&gt;&lt;P&gt;access-list 100 permit ip 127.0.0.0 0.255.255.255 any&lt;/P&gt;&lt;P&gt;access-list 102 remark CCP_ACL Category=0&lt;/P&gt;&lt;P&gt;access-list 102 permit ip any host 192.168.0.101&lt;/P&gt;&lt;P&gt;dialer-list 1 protocol ip permit&lt;/P&gt;&lt;P&gt;no cdp run&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;control-plane&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;banner login ^CWARNING!!!This is a highly monitored private system. Access is prohibited!!^C&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; no modem enable&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; access-class VTY_incoming in&lt;/P&gt;&lt;P&gt; password 7 12292504011C5C162E&lt;/P&gt;&lt;P&gt; login local&lt;/P&gt;&lt;P&gt; transport input ssh&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;scheduler max-task-time 5000&lt;/P&gt;&lt;P&gt;ntp authentication-key 1 md5 10603D29214711255F106B2677 7&lt;/P&gt;&lt;P&gt;ntp authenticate&lt;/P&gt;&lt;P&gt;ntp trusted-key 1&lt;/P&gt;&lt;P&gt;ntp master 2&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:48:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077006#M392614</guid>
      <dc:creator>nemiath76</dc:creator>
      <dc:date>2019-03-12T00:48:27Z</dc:date>
    </item>
    <item>
      <title>What is going wrong with this config ??</title>
      <link>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077007#M392619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello karolos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You said you are trying to access 94.70.142.113 and that is a server on the DMZ but based in your configuration that is not true&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source static 192.168.0.101 94.70.142.113&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So 192.168.0.101 is on Vlan 1 witch is the in-zone &lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt;description $FW_INSIDE$&lt;/P&gt;&lt;P&gt;ip address 192.168.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;security in-zone&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you got confused with&amp;nbsp; the security zone that the host is assigned to then just add the following and it should work&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip access-list extended WebServer&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;permit ip any host &lt;SPAN style="font-size: 10pt;"&gt;192.168.0.101&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 18:21:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077007#M392619</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-17T18:21:15Z</dc:date>
    </item>
    <item>
      <title>What is going wrong with this config ??</title>
      <link>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077008#M392624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My bad. the correct DMZ server ip address is .127 and not .113&lt;/P&gt;&lt;P&gt;I corrected my original post. sorry for the trouble.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 18:26:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077008#M392624</guid>
      <dc:creator>nemiath76</dc:creator>
      <dc:date>2013-01-17T18:26:04Z</dc:date>
    </item>
    <item>
      <title>What is going wrong with this config ??</title>
      <link>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077009#M392629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They are using the same policy so add what I said and let me know the result&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 18:30:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077009#M392629</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-17T18:30:12Z</dc:date>
    </item>
    <item>
      <title>What is going wrong with this config ??</title>
      <link>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077010#M392633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dont quite follow you.. &lt;/P&gt;&lt;P&gt;There is already an entry&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip access-list extended WebServer&lt;/P&gt;&lt;P&gt; remark CCP_ACL Category=128&lt;/P&gt;&lt;P&gt; permit ip any host 192.168.1.102&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which is the internal ip of the DMZ server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access to 192.168.0.101 has been removed since it was not not correct.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 18:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077010#M392633</guid>
      <dc:creator>nemiath76</dc:creator>
      <dc:date>2013-01-17T18:44:49Z</dc:date>
    </item>
    <item>
      <title>What is going wrong with this config ??</title>
      <link>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077011#M392637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, you are right..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Got confused because of the wrong topic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okay add the following&lt;/P&gt;&lt;P&gt;ip inspect log drop-pkt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then try to connect to the server and do&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show logging | include 192.168.1.102&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 19:11:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077011#M392637</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-17T19:11:33Z</dc:date>
    </item>
    <item>
      <title>What is going wrong with this config ??</title>
      <link>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077012#M392640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;after a lot of time i discovered that the security audit was causing the problem and specifically the ip unreachables command. No idea why!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 07:51:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077012#M392640</guid>
      <dc:creator>nemiath76</dc:creator>
      <dc:date>2013-02-08T07:51:28Z</dc:date>
    </item>
    <item>
      <title>What is going wrong with this config ??</title>
      <link>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077013#M392641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;lol,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okay at least we know we are good &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not have any other question, please mark the question as answered&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Remember to rate all of the helpful posts , that works as a thanks for the community users&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Feb 2013 17:17:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-is-going-wrong-with-this-config/m-p/2077013#M392641</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-02-08T17:17:09Z</dc:date>
    </item>
  </channel>
</rss>

