<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problems when I put a server in the dmz in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062693#M397799</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried to check on the ASA in realtime what happens to the connections attempts throught it when you start up a server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you mean that for the LAN to work normally you wont have any servers up and running on the DMZ? Seems abit odd.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You sure there isnt somekind of loop with the server platform and switches that chokes the whole network including ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Oct 2012 22:44:10 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2012-10-09T22:44:10Z</dc:date>
    <item>
      <title>Problems when I put a server in the dmz</title>
      <link>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062692#M397798</link>
      <description>&lt;P&gt;I have a asa5505, with this software:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 8.4(4)1&lt;/P&gt;&lt;P&gt;Device Manager Version 6.4(7).&lt;/P&gt;&lt;P&gt;Im using vlans interface. I have the following vlan interfaces configured:&lt;/P&gt;&lt;P&gt;outside (called isp1),inside,dmz. &lt;/P&gt;&lt;P&gt;The asa is connected to a switch via trunk. There are several ESXi servers with VMs connected to the same switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The isp1 vlan interface is asociated with the e0/0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem, when I start any (linux or windows) server in the dmz, all the internal networks lose the internet connection (via isp1).&lt;/P&gt;&lt;P&gt;There is a static nat X.X.X.61 &amp;lt;-&amp;gt; 192.168.111.61 beetwen the test server and the outside.&lt;/P&gt;&lt;P&gt;There are dynamic nat (pat) between the internal networks and the public ip on the outside interface x.x.x.64.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After several attempts (with whatismyip.com) I get verify that the public ip is x.x.x.61&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is wrong?...&lt;/P&gt;&lt;P&gt;attached the most relevant config.&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/0/8/2/107280-LAN-DATA-VOIP.jpg" alt="LAN-DATA-VOIP.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:06:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062692#M397798</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2019-03-12T00:06:52Z</dc:date>
    </item>
    <item>
      <title>Problems when I put a server in the dmz</title>
      <link>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062693#M397799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried to check on the ASA in realtime what happens to the connections attempts throught it when you start up a server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you mean that for the LAN to work normally you wont have any servers up and running on the DMZ? Seems abit odd.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You sure there isnt somekind of loop with the server platform and switches that chokes the whole network including ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Oct 2012 22:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062693#M397799</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-10-09T22:44:10Z</dc:date>
    </item>
    <item>
      <title>Problems when I put a server in the dmz</title>
      <link>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062694#M397800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Jouni,&lt;/P&gt;&lt;P&gt;checking the realtime log, only nomal Build and TearDown messages, no deny msg.&lt;/P&gt;&lt;P&gt;Yes. in the moment the server in dmz try to access the internet , for example http, or dns all the internet goes down for all the internal networks.&lt;/P&gt;&lt;P&gt;I did a test putting the ASA alone. Also I assingned dmz and inside IP´s to the fisical ports, connected one pc in the inside interface, another pc in the dmz interface. &lt;/P&gt;&lt;P&gt;The pc in the iside interface is able to access internet until I plug the (dmz) cable in the pc. Exactly when the pc try to access the dns servers or I open the http browser.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im stucked because I need start the dmz for several servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 15:07:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062694#M397800</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2012-10-24T15:07:16Z</dc:date>
    </item>
    <item>
      <title>Problems when I put a server in the dmz</title>
      <link>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062695#M397801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please share the show run NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 20:02:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062695#M397801</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-10-24T20:02:28Z</dc:date>
    </item>
    <item>
      <title>Problems when I put a server in the dmz</title>
      <link>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062696#M397802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; show run nat:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network PCoIP-host&lt;/P&gt;&lt;P&gt; nat (dmz,isp1) static 190.147.134.61&lt;/P&gt;&lt;P&gt;object network web-mail-host&lt;/P&gt;&lt;P&gt; nat (dmz,isp1) static 190.147.134.48&lt;/P&gt;&lt;P&gt;object network smtp-host&lt;/P&gt;&lt;P&gt; nat (dmz1,isp2) static interface service tcp smtp smtp&lt;/P&gt;&lt;P&gt;object network www-host&lt;/P&gt;&lt;P&gt; nat (dmz1,isp2) static interface service tcp www www&lt;/P&gt;&lt;P&gt;object network pop3s-host&lt;/P&gt;&lt;P&gt; nat (dmz1,isp2) static interface service tcp 995 995&lt;/P&gt;&lt;P&gt;object network dns-tcp-host&lt;/P&gt;&lt;P&gt; nat (dmz1,isp2) static interface service tcp domain domain&lt;/P&gt;&lt;P&gt;object network dns-udp-host&lt;/P&gt;&lt;P&gt; nat (dmz1,isp2) static interface service udp domain domain&lt;/P&gt;&lt;P&gt;object network 172.16.1.x-190.147.134.64-PAT-network&lt;/P&gt;&lt;P&gt; nat (inside,isp1) dynamic interface&lt;/P&gt;&lt;P&gt;object network 172.16.1.x-200.116.11.57-PAT-network&lt;/P&gt;&lt;P&gt; nat (inside,isp2) dynamic interface&lt;/P&gt;&lt;P&gt;object network dvr-udp-host&lt;/P&gt;&lt;P&gt; nat (dmz,isp3) static interface service udp 8080 8080&lt;/P&gt;&lt;P&gt;object network dvr-tcp-host&lt;/P&gt;&lt;P&gt; nat (dmz,isp3) static interface service tcp 8080 8080&lt;/P&gt;&lt;P&gt;object network 10.10.10.x-190.147.134.64-PAT-network&lt;/P&gt;&lt;P&gt; nat (inside,isp1) dynamic interface&lt;/P&gt;&lt;P&gt;object network 10.10.10.x-200.116.11.57-PAT-network&lt;/P&gt;&lt;P&gt; nat (inside,isp2) dynamic interface&lt;/P&gt;&lt;P&gt;object network 172.16.1.48-190.147.134.64-PAT-network&lt;/P&gt;&lt;P&gt; nat (inside,isp1) dynamic interface&lt;/P&gt;&lt;P&gt;object network 172.16.1.48-200.116.11.57-PAT-network&lt;/P&gt;&lt;P&gt; nat (inside,isp1) dynamic interface&lt;/P&gt;&lt;P&gt;object network 192.168.x.x-200.116.11.57-PAT-network&lt;/P&gt;&lt;P&gt; nat (inside,isp2) dynamic interface&lt;/P&gt;&lt;P&gt;object network 192.168.10.x-190.147.134.64-PAT-network&lt;/P&gt;&lt;P&gt; nat (inside,isp1) static interface&lt;/P&gt;&lt;P&gt;object network 192.168.100.x-190.147.134.64-PAT-network&lt;/P&gt;&lt;P&gt; nat (inside,isp1) static interface&lt;/P&gt;&lt;P&gt;object network 192.168.15.x-190.147.134.64-PAT-network&lt;/P&gt;&lt;P&gt; nat (inside,isp1) static interface&lt;/P&gt;&lt;P&gt;object network 192.168.50.x-190.147.134.64-PAT-network&lt;/P&gt;&lt;P&gt; nat (inside,isp1) static interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#show run object:&lt;/P&gt;&lt;P&gt;object network PCoIP-host&lt;/P&gt;&lt;P&gt; host 192.168.111.61&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 20:11:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062696#M397802</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2012-10-24T20:11:04Z</dc:date>
    </item>
    <item>
      <title>Problems when I put a server in the dmz</title>
      <link>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062697#M397803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rafael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input inside tcp 172.16.1.100 1025 4.2.2.2 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 20:33:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062697#M397803</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-10-24T20:33:47Z</dc:date>
    </item>
    <item>
      <title>Problems when I put a server in the dmz</title>
      <link>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062698#M397804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;packet-tracer input inside tcp 172.16.1.100 1025 4.2.2.2 80&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; isp1&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;object network 172.16.1.x-190.147.134.64-PAT-network&lt;BR /&gt; nat (inside,isp1) dynamic interface&lt;BR /&gt;Additional Information:&lt;BR /&gt;Dynamic translate 172.16.1.100/1025 to 190.147.134.64/1025&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: USER-STATISTICS&lt;BR /&gt;Subtype: user-statistics&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: USER-STATISTICS&lt;BR /&gt;Subtype: user-statistics&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 61570, packet dispatched to next module&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: isp1&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 20:40:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062698#M397804</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2012-10-24T20:40:19Z</dc:date>
    </item>
    <item>
      <title>Problems when I put a server in the dmz</title>
      <link>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062699#M397805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rafael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okay so the packet-tracer shows the inside network gets Natted to the ISP1 interface. Configuration looks good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically what you are saying is as soon as you have the DMZ servers all of the internal users are unable to go to the internet correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would say the best way to handle this would be creating captures at the time you have the DMZ server on, what do you think?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2012 20:43:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062699#M397805</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-10-24T20:43:56Z</dc:date>
    </item>
    <item>
      <title>Problems when I put a server in the dmz</title>
      <link>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062700#M397806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My friends, &lt;/P&gt;&lt;P&gt;I think that is a proxy arp issue. But&amp;nbsp; I don't have a solution yet. &lt;/P&gt;&lt;P&gt;I need some help with this.&lt;/P&gt;&lt;P&gt;Thank.s&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 04:32:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062700#M397806</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2012-11-07T04:32:21Z</dc:date>
    </item>
    <item>
      <title>Problems when I put a server in the dmz</title>
      <link>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062701#M397807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rafael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you do some captures when the server is in place?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From an inside host, so we can determine if there is a problem with the ASA,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 05:13:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062701#M397807</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-07T05:13:59Z</dc:date>
    </item>
    <item>
      <title>Problems when I put a server in the dmz</title>
      <link>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062702#M397808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Julio,&amp;nbsp; &lt;/P&gt;&lt;P&gt;I did some changes to test. I just put the e0/0 and e0/1 in the outside vlan (isp).&lt;/P&gt;&lt;P&gt;The e0/2 is in the dmz vlan and the e0/3 is in the inside vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;internet in the isp vlan interface (E0/0) works fine alone. When I plug another pc in the E0/1 port, or if I plug a pc in the E0/2, all the traffic goin from the inside to internet (isp) goes down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I just take off the ASA and put back a Cisco RV042 that was working before the ASA, I have the same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the internet on the isp is ok. a Pc connecte alone in the modem works fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 12:04:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062702#M397808</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2012-11-07T12:04:21Z</dc:date>
    </item>
    <item>
      <title>Problems when I put a server in the dmz</title>
      <link>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062703#M397809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rafael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okay here is what I want you to do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;put the e0/0 and e0/1 in the outside vlan (isp).&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;The e0/2 is in the dmz vlan and the e0/3 is in the inside vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then connect a PC to the inside vlan &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture capin interface inside match icmp any host 4.2.2.2&lt;/P&gt;&lt;P&gt;capture capout interface outside match icmp any host 4.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then try to ping from the inside host to 4.2.2.2 and afterwards provide&lt;/P&gt;&lt;P&gt;show cap capin&lt;/P&gt;&lt;P&gt;show cap capout&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2012 17:40:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062703#M397809</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-07T17:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: Problems when I put a server in the dmz</title>
      <link>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062704#M397810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julio,&lt;/P&gt;&lt;P&gt;After try everything, I decided do a wireshark capture. Everything looks fine, I just was curiously about a "IP checksum offload" message, doing some research with google, I saw the light. All the problems starts when the virtual machines migrated (due to drs) to one of the servers that have Gigabits NIC with TOE (Broadcom NetXtreme II 5709 Dual Port Ethernet PCIe Card with TOE and iSCSI Offload).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just disabled the tso (tcp segmentation offload) for the affected OS. Now everything is fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Nov 2012 11:34:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062704#M397810</guid>
      <dc:creator>Rafael Jimenez</dc:creator>
      <dc:date>2012-11-09T11:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: Problems when I put a server in the dmz</title>
      <link>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062705#M397811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rafael,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Great to hear that,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some kudos for you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please mark the question as answered,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Nov 2012 17:37:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problems-when-i-put-a-server-in-the-dmz/m-p/2062705#M397811</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-09T17:37:40Z</dc:date>
    </item>
  </channel>
</rss>

