<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic able to connect to anyconnect and access ssh,ftp,telnet,http and in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/able-to-connect-to-anyconnect-and-access-ssh-ftp-telnet-http-and/m-p/2107754#M395410</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tried doin so but no luck dear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &lt;BR /&gt;Thanveer &lt;BR /&gt;"Everybody is genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is a stupid."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 21 Nov 2012 11:07:58 GMT</pubDate>
    <dc:creator>Muhammad Thanveer</dc:creator>
    <dc:date>2012-11-21T11:07:58Z</dc:date>
    <item>
      <title>able to connect to anyconnect and access ssh,ftp,telnet,http and https but not rdp</title>
      <link>https://community.cisco.com/t5/network-security/able-to-connect-to-anyconnect-and-access-ssh-ftp-telnet-http-and/m-p/2107750#M395400</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to connect to any connect and able to access ssh telnet ftp http and https but not able to connect rdp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &lt;BR /&gt;Thanveer &lt;BR /&gt;"Everybody is genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is a stupid."&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:25:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/able-to-connect-to-anyconnect-and-access-ssh-ftp-telnet-http-and/m-p/2107750#M395400</guid>
      <dc:creator>Muhammad Thanveer</dc:creator>
      <dc:date>2019-03-12T00:25:20Z</dc:date>
    </item>
    <item>
      <title>able to connect to anyconnect and access ssh,ftp,telnet,http and</title>
      <link>https://community.cisco.com/t5/network-security/able-to-connect-to-anyconnect-and-access-ssh-ftp-telnet-http-and/m-p/2107751#M395403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide where you are connecting with RDP from and to what destination IP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you connecting with RDP to the same host where you are able to connect with SHH, Telnet, FTP, HTTP and HTTPS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 09:07:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/able-to-connect-to-anyconnect-and-access-ssh-ftp-telnet-http-and/m-p/2107751#M395403</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-11-21T09:07:07Z</dc:date>
    </item>
    <item>
      <title>able to connect to anyconnect and access ssh,ftp,telnet,http and</title>
      <link>https://community.cisco.com/t5/network-security/able-to-connect-to-anyconnect-and-access-ssh-ftp-telnet-http-and/m-p/2107752#M395405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi JouniForss,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Source will be from the pool 192.168.60.0/24 and thd destination will be 192.168.50.0/24&lt;/P&gt;&lt;P&gt;2) Yes I am tryinh to take rdp to one of my servers for which http and rdp services are enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &lt;BR /&gt;Thanveer &lt;BR /&gt;"Everybody is genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is a stupid."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 09:18:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/able-to-connect-to-anyconnect-and-access-ssh-ftp-telnet-http-and/m-p/2107752#M395405</guid>
      <dc:creator>Muhammad Thanveer</dc:creator>
      <dc:date>2012-11-21T09:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: able to connect to anyconnect and access ssh,ftp,telnet,http</title>
      <link>https://community.cisco.com/t5/network-security/able-to-connect-to-anyconnect-and-access-ssh-ftp-telnet-http-and/m-p/2107753#M395406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you are connection to the ASA first with Cisco AnyConnect VPN and the VPN pool is &lt;STRONG&gt;192.168.60.2-192.168.60.9&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you want to connect to the network &lt;STRONG&gt;192.168.50.0/24&lt;/STRONG&gt; with their original IP addresses and not do NAT you need a NAT0 configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems you have the following NAT0 configuration for your &lt;STRONG&gt;"inside"&lt;/STRONG&gt; interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list inside_nat0_outbound extended permit ip 192.168.50.0 255.255.255.0 172.30.1.0 255.255.255.0 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list inside_nat0_outbound extended permit ip any object-group DM_INLINE_NETWORK_1 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;access-list inside_nat0_outbound extended permit ip 192.168.60.0 255.255.255.0 192.168.50.0 255.255.255.0&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems to me atleast that you NAT0 rule doesnt include the traffic between 192.168.50.0/24 and 192.168.60.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you by any chance added the last &lt;STRONG&gt;"inside_nat0_outbound"&lt;/STRONG&gt; ACL line (marked with red) while trying to get this to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;access-list inside_nat0_outbound extended permit ip 192.168.60.0 255.255.255.0 192.168.50.0 255.255.255.0&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To me it seems you would need to reverse the networks in that statement to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #339966;"&gt;&lt;STRONG&gt;access-list inside_nat0_outbound extended permit ip 192.168.50.0 255.255.255.0 192.168.60.0 255.255.255.0&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is because the NAT rule and the ACL is done for the &lt;STRONG&gt;"inside"&lt;/STRONG&gt; interface, therefore you need to use the &lt;STRONG&gt;"inside"&lt;/STRONG&gt; interface networks as the source address for the NAT0 rule. This will still apply to traffic from the VPN pool to the LAN network of 192.168.50.0/24 also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is atleast what it seems to me. Though if I'm correct this would mean you could not at the moment connect to any host on the 192.168.50.0/24 LAN network from your VPN Pool of 192.168.60.0/24?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 09:39:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/able-to-connect-to-anyconnect-and-access-ssh-ftp-telnet-http-and/m-p/2107753#M395406</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-11-21T09:39:23Z</dc:date>
    </item>
    <item>
      <title>able to connect to anyconnect and access ssh,ftp,telnet,http and</title>
      <link>https://community.cisco.com/t5/network-security/able-to-connect-to-anyconnect-and-access-ssh-ftp-telnet-http-and/m-p/2107754#M395410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tried doin so but no luck dear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &lt;BR /&gt;Thanveer &lt;BR /&gt;"Everybody is genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is a stupid."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 11:07:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/able-to-connect-to-anyconnect-and-access-ssh-ftp-telnet-http-and/m-p/2107754#M395410</guid>
      <dc:creator>Muhammad Thanveer</dc:creator>
      <dc:date>2012-11-21T11:07:58Z</dc:date>
    </item>
    <item>
      <title>able to connect to anyconnect and access ssh,ftp,telnet,http and</title>
      <link>https://community.cisco.com/t5/network-security/able-to-connect-to-anyconnect-and-access-ssh-ftp-telnet-http-and/m-p/2107755#M395415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible, you should try to get log information of the connection attempt from the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Log about the connection when its formed and when its torn down from the ASA. Unless its ofcouse blocked by the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 11:13:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/able-to-connect-to-anyconnect-and-access-ssh-ftp-telnet-http-and/m-p/2107755#M395415</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-11-21T11:13:38Z</dc:date>
    </item>
    <item>
      <title>able to connect to anyconnect and access ssh,ftp,telnet,http and</title>
      <link>https://community.cisco.com/t5/network-security/able-to-connect-to-anyconnect-and-access-ssh-ftp-telnet-http-and/m-p/2107756#M395422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Might be&amp;nbsp; IP Pool i have asigned is overlapping with the Pool on my coreswitch, let me also check this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &lt;BR /&gt;Thanveer &lt;BR /&gt;"Everybody is genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is a stupid."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2012 11:59:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/able-to-connect-to-anyconnect-and-access-ssh-ftp-telnet-http-and/m-p/2107756#M395422</guid>
      <dc:creator>Muhammad Thanveer</dc:creator>
      <dc:date>2012-11-21T11:59:22Z</dc:date>
    </item>
  </channel>
</rss>

