<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I need to DMZ access to internet and see the inside on ASA 5 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/i-need-to-dmz-access-to-internet-and-see-the-inside-on-asa-5520/m-p/2056509#M398866</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try using packet-tracer on the ASA to follow the logic through the box and determine why your DMZ-Inside traffic isn't working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;packet-tracer input dmz &lt;YOUR dmz="" pc="" address=""&gt; &lt;DESTINATION ip=""&gt; &lt;DESTINATION port=""&gt; detailed&lt;/DESTINATION&gt;&lt;/DESTINATION&gt;&lt;/YOUR&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The output should tell you why the packets aren't flowing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Oct 2012 14:05:32 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2012-10-18T14:05:32Z</dc:date>
    <item>
      <title>I need to DMZ access to internet and see the inside on ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/i-need-to-dmz-access-to-internet-and-see-the-inside-on-asa-5520/m-p/2056503#M398860</link>
      <description>&lt;P&gt;Hi everyone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am new in ASA, I have the DMZ (10.1.1.0/24) configured on ASA 5520 and I achieve the reach Internet from DMZ (10.1.1.0/24), but now need reach DMZ from inside (172.16.12.0/24) and inside (172.16.12.0/24) from DMZ&amp;nbsp; (10.1.1.0/24), in other words round trip. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ths show run is attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try with the next links, but dont work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/thread/2018253" target="_blank"&gt;https://supportforums.cisco.com/thread/2018253&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/thread/2045888" target="_blank"&gt;https://supportforums.cisco.com/thread/2045888&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thk for help me !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-need-to-dmz-access-to-internet-and-see-the-inside-on-asa-5520/m-p/2056503#M398860</guid>
      <dc:creator>josue jonathan rivero herrera</dc:creator>
      <dc:date>2019-03-11T23:58:34Z</dc:date>
    </item>
    <item>
      <title>Re: I need to DMZ access to internet and see the inside on ASA 5</title>
      <link>https://community.cisco.com/t5/network-security/i-need-to-dmz-access-to-internet-and-see-the-inside-on-asa-5520/m-p/2056504#M398861</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since the DMZ is lower security level than inside, you must create and apply and access-list to allow DMZ-originated traffic to access inside addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;access-list DMZ_IN extended permit &lt;WHATEVER policy="" you="" want=""&gt;&lt;/WHATEVER&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;access-group DMZ_IN in interface DMZ&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside to DMZ will automatically work (unless you start ACLing in in which case an implicit deny will be added at the end).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're new to the ASA, I recommend you use ASDM to create your changes. Set it to preview commands and look at what it generates to understand the CLI.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 01:46:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-need-to-dmz-access-to-internet-and-see-the-inside-on-asa-5520/m-p/2056504#M398861</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2012-09-25T01:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: I need to DMZ access to internet and see the inside on ASA 5</title>
      <link>https://community.cisco.com/t5/network-security/i-need-to-dmz-access-to-internet-and-see-the-inside-on-asa-5520/m-p/2056505#M398862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; hi Marvin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try with ASDM but I do not like, I think that is better with CLI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try with you tell me later, i think that this help me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_IN permit 10.1.1.0 255.255.255.0 172.16.12.0 255.255.255.0&lt;BR /&gt;access-list DMZ_IN permit 10.1.1.0 255.255.255.0 172.16.6.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-group DMZ_IN permit in interface DMZ&lt;/P&gt;&lt;P&gt;static (inside,DMZ) 10.1.1.0 10.1.1.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you tihink that this help me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR and THK!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 20:27:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-need-to-dmz-access-to-internet-and-see-the-inside-on-asa-5520/m-p/2056505#M398862</guid>
      <dc:creator>josue jonathan rivero herrera</dc:creator>
      <dc:date>2012-09-25T20:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: I need to DMZ access to internet and see the inside on ASA 5</title>
      <link>https://community.cisco.com/t5/network-security/i-need-to-dmz-access-to-internet-and-see-the-inside-on-asa-5520/m-p/2056506#M398863</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, what you have proposed looks good.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 20:50:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-need-to-dmz-access-to-internet-and-see-the-inside-on-asa-5520/m-p/2056506#M398863</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2012-09-25T20:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: I need to DMZ access to internet and see the inside on ASA 5</title>
      <link>https://community.cisco.com/t5/network-security/i-need-to-dmz-access-to-internet-and-see-the-inside-on-asa-5520/m-p/2056507#M398864</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; ok, let me try out production and update you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Sep 2012 21:04:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-need-to-dmz-access-to-internet-and-see-the-inside-on-asa-5520/m-p/2056507#M398864</guid>
      <dc:creator>josue jonathan rivero herrera</dc:creator>
      <dc:date>2012-09-25T21:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: I need to DMZ access to internet and see the inside on ASA 5</title>
      <link>https://community.cisco.com/t5/network-security/i-need-to-dmz-access-to-internet-and-see-the-inside-on-asa-5520/m-p/2056508#M398865</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Marvin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apologies for the delay but too much work here, I try with the next command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit tcp 10.1.1.0 255.255.255.0 172.16.12.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit udp 10.1.1.0 255.255.255.0 172.16.12.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit tcp 10.1.1.0 255.255.255.0 172.16.6.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list DMZ_IN extended permit udp 10.1.1.0 255.255.255.0 172.16.6.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-group DMZ_IN in interface DMZ&lt;/P&gt;&lt;P&gt;nat (DMZ) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (inside,DMZ) 10.1.1.0 10.1.1.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and when I configure the PC with DGW (interface DMZ`s firewall) I don't reach the LAN but Internet is reachable, i need to reach both (LAN-172.16.12.0, 172.16.6.0 and Internet).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do you have someone idea for help me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thk so much!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2012 16:29:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-need-to-dmz-access-to-internet-and-see-the-inside-on-asa-5520/m-p/2056508#M398865</guid>
      <dc:creator>josue jonathan rivero herrera</dc:creator>
      <dc:date>2012-10-17T16:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: I need to DMZ access to internet and see the inside on ASA 5</title>
      <link>https://community.cisco.com/t5/network-security/i-need-to-dmz-access-to-internet-and-see-the-inside-on-asa-5520/m-p/2056509#M398866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try using packet-tracer on the ASA to follow the logic through the box and determine why your DMZ-Inside traffic isn't working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;packet-tracer input dmz &lt;YOUR dmz="" pc="" address=""&gt; &lt;DESTINATION ip=""&gt; &lt;DESTINATION port=""&gt; detailed&lt;/DESTINATION&gt;&lt;/DESTINATION&gt;&lt;/YOUR&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The output should tell you why the packets aren't flowing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2012 14:05:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-need-to-dmz-access-to-internet-and-see-the-inside-on-asa-5520/m-p/2056509#M398866</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2012-10-18T14:05:32Z</dc:date>
    </item>
  </channel>
</rss>

