<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic New twist to an old issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/new-twist-to-an-old-issue/m-p/2115423#M393607</link>
    <description>&lt;P&gt;I had a very similar issue (NAT/routing issue from one subinterface to another)...and i used this resolution for another problem between two interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the attached config you'll see my Franklin interface 3.146 which has a web server behind it.&amp;nbsp; Users behind my AUD interface on 3.133 were not able to get to the web server.&amp;nbsp; Traffic was always supposed to go from AUD to Franklin, so:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.Raised security level on AUD to 95 (Franklin is at 90)&lt;/P&gt;&lt;P&gt;2.Added the appropriate DNS zone to the AUD internal DNS server for the website, using the local IP addresse&lt;/P&gt;&lt;P&gt;3.Added a static nat between the two interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I believe that was it and it worked perfectly!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem now, i have traffic that's sourced at Franklin and they need to access an email server behind AUD.&amp;nbsp; It doesn't work.&amp;nbsp; Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance as always!!!&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:41:50 GMT</pubDate>
    <dc:creator>WStoffel1</dc:creator>
    <dc:date>2019-03-12T00:41:50Z</dc:date>
    <item>
      <title>New twist to an old issue</title>
      <link>https://community.cisco.com/t5/network-security/new-twist-to-an-old-issue/m-p/2115423#M393607</link>
      <description>&lt;P&gt;I had a very similar issue (NAT/routing issue from one subinterface to another)...and i used this resolution for another problem between two interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the attached config you'll see my Franklin interface 3.146 which has a web server behind it.&amp;nbsp; Users behind my AUD interface on 3.133 were not able to get to the web server.&amp;nbsp; Traffic was always supposed to go from AUD to Franklin, so:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.Raised security level on AUD to 95 (Franklin is at 90)&lt;/P&gt;&lt;P&gt;2.Added the appropriate DNS zone to the AUD internal DNS server for the website, using the local IP addresse&lt;/P&gt;&lt;P&gt;3.Added a static nat between the two interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I believe that was it and it worked perfectly!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem now, i have traffic that's sourced at Franklin and they need to access an email server behind AUD.&amp;nbsp; It doesn't work.&amp;nbsp; Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance as always!!!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-twist-to-an-old-issue/m-p/2115423#M393607</guid>
      <dc:creator>WStoffel1</dc:creator>
      <dc:date>2019-03-12T00:41:50Z</dc:date>
    </item>
    <item>
      <title>New twist to an old issue</title>
      <link>https://community.cisco.com/t5/network-security/new-twist-to-an-old-issue/m-p/2115424#M393608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried using the "packet-tracer" command to simulate the connection attempt and see what the output is?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can take the output of the "packet-tracer" command, copy/paste it here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2012 16:54:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-twist-to-an-old-issue/m-p/2115424#M393608</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-12-28T16:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: New twist to an old issue</title>
      <link>https://community.cisco.com/t5/network-security/new-twist-to-an-old-issue/m-p/2115425#M393609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Of course:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input Franklin tcp 192.168.146.10 32000 192.168.133.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;MAC Access list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: FLOW-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Found no matching flow, creating a new flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: UN-NAT&lt;/P&gt;&lt;P&gt;Subtype: static&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;static (AUD,Franklin) 192.168.133.0 192.168.133.0 netmask 255.255.255&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; .0&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip AUD 192.168.133.0 255.255.255.0 Franklin any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 192.168.133.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 17, untranslate_hits = 1&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;NAT divert to egress interface AUD&lt;/P&gt;&lt;P&gt;Untranslate 192.168.133.0/0 to 192.168.133.0/0 using netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: Franklin&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: AUD&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configured rule is of course the implicit deny from a lower security interface to a higher, correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I attached the packet trace in the other direction for what's currently working...in case it's any help..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2012 17:28:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-twist-to-an-old-issue/m-p/2115425#M393609</guid>
      <dc:creator>WStoffel1</dc:creator>
      <dc:date>2012-12-28T17:28:05Z</dc:date>
    </item>
    <item>
      <title>New twist to an old issue</title>
      <link>https://community.cisco.com/t5/network-security/new-twist-to-an-old-issue/m-p/2115426#M393610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It does seem you have ACL attached to only 2 interfaces and neither of them is related to this connection attempt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess you need to configure an appropriate ACL for the Franklin interface to allow the traffic in this direction since the security-level is blocking the connection attempts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2012 17:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-twist-to-an-old-issue/m-p/2115426#M393610</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-12-28T17:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: New twist to an old issue</title>
      <link>https://community.cisco.com/t5/network-security/new-twist-to-an-old-issue/m-p/2115427#M393611</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to build the ACL in a way that it still follows the logic of your Security-level setup I guess you should first block some traffic on the ACL and then allow all the rest of the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems the following interfaces have higher Security-level than Franklin&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;AUD&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Little&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;LV&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could for example build the ACL in the following way.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;First&lt;/STRONG&gt; configure ACL statements that allow the traffic you are attempting from Franklin to AUD&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Second&lt;/STRONG&gt; configure ACL statements that block all the (rest) traffic from Franklin to AUD, Little and LV networks&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Third&lt;/STRONG&gt; configure ACL statement that allow all rest of the traffic&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding with the above way you would still limit traffic from Franklin from entering AUD,Little and LV (like it was to my understanding with the security-levels alone controlling the traffic) BUT still allow the specific connections from Franklin to AUD server. If you just confired an ACL that permitted all traffic it would make it possible for Franklin to connect to the higher security-level interfaces/network. Provided ofcourse that the NAT or something else doesnt prevent the communication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully I havent missed something while going through the configuration. Theres quite alot of it and getting tired &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2012 17:37:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-twist-to-an-old-issue/m-p/2115427#M393611</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-12-28T17:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: New twist to an old issue</title>
      <link>https://community.cisco.com/t5/network-security/new-twist-to-an-old-issue/m-p/2115428#M393612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That config is a nightmare.&amp;nbsp; No question about it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the input, let me digest it and see what i can accomplish.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got a long weekend with some downtime I can try a few different things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Will&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2012 18:02:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-twist-to-an-old-issue/m-p/2115428#M393612</guid>
      <dc:creator>WStoffel1</dc:creator>
      <dc:date>2012-12-28T18:02:17Z</dc:date>
    </item>
  </channel>
</rss>

