<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with Aironet IP redirection on ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-aironet-ip-redirection-on-asa/m-p/2068836#M399572</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the running configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;: Written by enable_15 at 12:14:12.994 CDT Mon Sep 10 2012&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ASA Version 8.4(2) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ASA&lt;/P&gt;&lt;P&gt;domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 10.7.1.0 ScottNet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; switchport access vlan 3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; switchport access vlan 5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; switchport access vlan 5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt; switchport access vlan 6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt; switchport access vlan 3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt; switchport trunk allowed vlan 3,5,7,16&lt;/P&gt;&lt;P&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; backup interface Vlan16&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address XXX.XXX.XXX.XXX 255.255.255.240 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan3&lt;/P&gt;&lt;P&gt; nameif Development&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 172.16.32.254 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan5&lt;/P&gt;&lt;P&gt; nameif Corp&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.0.1.254 255.255.252.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan6&lt;/P&gt;&lt;P&gt; nameif NED&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.60.0.254 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan16&lt;/P&gt;&lt;P&gt; nameif BACKUP&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 192.168.15.2 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa842-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone CST -6&lt;/P&gt;&lt;P&gt;clock summer-time CDT recurring&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap extended permit ip 10.0.0.0 255.255.0.0 10.7.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip 172.16.32.0 255.255.255.0 any inactive &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit 53 any any inactive &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit object-group TCPUDP 172.16.32.0 255.255.255.0 host 10.0.1.221 eq domain &lt;/P&gt;&lt;P&gt;access-list Development_access_in extended permit 53 any any &lt;/P&gt;&lt;P&gt;access-list Development_access_in extended permit object-group TCPUDP any any &lt;/P&gt;&lt;P&gt;access-list Development_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list Development_access_in extended deny tcp any any eq smtp &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 10.0.0.0 255.255.255.0 10.0.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Corp_nat0_outbound extended permit ip 10.0.0.0 255.255.255.0 10.70.0.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Corp_nat0_outbound extended permit ip 10.0.1.0 255.255.255.0 10.70.0.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Corp_nat0_outbound extended permit ip 172.16.30.0 255.255.255.0 10.0.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Corp_nat0_outbound extended permit ip 10.0.1.0 255.255.255.0 10.1.2.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Corp_nat0_outbound extended permit ip 10.70.0.0 255.255.255.0 10.0.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Corp_nat0_outbound extended permit ip 10.0.1.0 255.255.255.0 object ScottNet &lt;/P&gt;&lt;P&gt;access-list Corp_access_in extended permit ip 10.70.0.0 255.255.255.0 10.0.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Corp_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list Corp_access_in extended permit gre any any &lt;/P&gt;&lt;P&gt;access-list Corp_access_in extended permit udp any any eq domain &lt;/P&gt;&lt;P&gt;access-list Corp_access_in extended permit tcp any any eq pptp &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_1 extended permit ip 10.0.0.0 255.255.252.0 object CoryNet &lt;/P&gt;&lt;P&gt;access-list NED_access_in extended permit ip 10.0.1.0 255.255.255.0 10.70.0.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list NED_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list Backup_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.221 object-group DM_INLINE_TCP_1 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.144 object-group TMS_Services &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.146 object-group TMS_Services &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit gre any host 10.0.1.221 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.161 object-group DM_INLINE_TCP_2 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp any host 10.0.1.221 eq domain &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp host XXX.XXX.XXX.XXX any eq tftp &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group TCPUDP any object-group DM_INLINE_NETWORK_1 eq 8005 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip 172.16.30.0 255.255.255.0 any &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group DM_INLINE_SERVICE_1 any host 10.0.1.151 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.116 eq pptp &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit gre any host 10.0.1.116 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.116 object-group DM_INLINE_TCP_4 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.41 eq 3389 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.125 eq smtp &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm warnings&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu Development 1500&lt;/P&gt;&lt;P&gt;mtu Corp 1500&lt;/P&gt;&lt;P&gt;mtu NED 1500&lt;/P&gt;&lt;P&gt;mtu BACKUP 1500&lt;/P&gt;&lt;P&gt;ip local pool VPN-address-pool 10.0.2.20-10.0.2.50 mask 255.255.252.0&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-645-206.bin&lt;/P&gt;&lt;P&gt;asdm location ScottNet 255.255.255.0 Corp&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;access-group Development_access_in in interface Development&lt;/P&gt;&lt;P&gt;access-group Corp_access_in in interface Corp&lt;/P&gt;&lt;P&gt;access-group NED_access_in in interface NED&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 XXX.XXX.XXX.30 1 track 1&lt;/P&gt;&lt;P&gt;route BACKUP 0.0.0.0 0.0.0.0 192.168.15.1 254&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication telnet console LOCAL &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 10.0.3.0 255.255.255.0 Corp&lt;/P&gt;&lt;P&gt;http 10.0.1.0 255.255.255.0 Corp&lt;/P&gt;&lt;P&gt;http 172.16.32.0 255.255.255.0 Development&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;track 1 rtr 123 reachability&lt;/P&gt;&lt;P&gt;telnet 172.16.32.0 255.255.255.0 Development&lt;/P&gt;&lt;P&gt;telnet 10.0.0.0 255.255.252.0 Corp&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 172.16.32.15-172.16.32.100 Development&lt;/P&gt;&lt;P&gt;dhcpd dns 4.2.2.1 4.2.2.2 interface Development&lt;/P&gt;&lt;P&gt;dhcpd enable Development&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 10.0.1.101-10.0.1.124 Corp&lt;/P&gt;&lt;P&gt;dhcpd dns 10.0.1.221 10.0.1.160 interface Corp&lt;/P&gt;&lt;P&gt;dhcpd wins 10.0.1.221 interface Corp&lt;/P&gt;&lt;P&gt;dhcpd option 66 ip 10.0.1.1 interface Corp&lt;/P&gt;&lt;P&gt;dhcpd option 150 ip 10.0.1.1 interface Corp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd dns 10.0.1.221 4.2.2.1 interface NED&lt;/P&gt;&lt;P&gt;dhcpd wins 10.0.1.221 interface NED&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect pptp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Sep 2012 17:19:43 GMT</pubDate>
    <dc:creator>jamesdborden</dc:creator>
    <dc:date>2012-09-10T17:19:43Z</dc:date>
    <item>
      <title>Problem with Aironet IP redirection on ASA</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-aironet-ip-redirection-on-asa/m-p/2068834#M399570</link>
      <description>&lt;P&gt;Ok, so I have an aironet redirecting all traffic to the ASA, the problem is that I can ping websites, however I can not access the web page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I go through the ASA log here is what I get.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Sep 10 2012&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;09:52:58&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;10.0.3.41&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2120&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;10.0.1.254&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;80&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;TCP access denied by ACL from 10.0.3.41/2120 to Corp:10.0.1.254/80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the incoming rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellspacing="0" style="font-family: 'Times New Roman';"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD bgcolor="#FFFFE1" colspan="11"&gt;Corp (5 incoming rules)&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;1&lt;/TD&gt;&lt;TD&gt;True&lt;/TD&gt;&lt;TD&gt;10.70.0.0/24&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt;10.0.1.0/24&lt;/TD&gt;&lt;TD&gt;ip&lt;/TD&gt;&lt;TD&gt;Permit&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;Default&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;2&lt;/TD&gt;&lt;TD&gt;True&lt;/TD&gt;&lt;TD&gt;any&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt;any&lt;/TD&gt;&lt;TD&gt;ip&lt;/TD&gt;&lt;TD&gt;Permit&lt;/TD&gt;&lt;TD&gt;19110969&lt;/TD&gt;&lt;TD&gt;Default&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;3&lt;/TD&gt;&lt;TD&gt;True&lt;/TD&gt;&lt;TD&gt;any&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt;any&lt;/TD&gt;&lt;TD&gt;gre&lt;/TD&gt;&lt;TD&gt;Permit&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;Default&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt;True&lt;/TD&gt;&lt;TD&gt;any&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt;any&lt;/TD&gt;&lt;TD&gt;udp/domain&lt;/TD&gt;&lt;TD&gt;Permit&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;Default&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;TD&gt;True&lt;/TD&gt;&lt;TD&gt;any&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt;any&lt;/TD&gt;&lt;TD&gt;tcp/pptp&lt;/TD&gt;&lt;TD&gt;Permit&lt;/TD&gt;&lt;TD&gt;0&lt;/TD&gt;&lt;TD&gt;Default&lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;TD&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:52:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-aironet-ip-redirection-on-asa/m-p/2068834#M399570</guid>
      <dc:creator>jamesdborden</dc:creator>
      <dc:date>2019-03-11T23:52:06Z</dc:date>
    </item>
    <item>
      <title>Problem with Aironet IP redirection on ASA</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-aironet-ip-redirection-on-asa/m-p/2068835#M399571</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi James,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please post the config of your ASA in order for us to help further.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Terence&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2012 15:42:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-aironet-ip-redirection-on-asa/m-p/2068835#M399571</guid>
      <dc:creator>terrencepayet</dc:creator>
      <dc:date>2012-09-10T15:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Aironet IP redirection on ASA</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-aironet-ip-redirection-on-asa/m-p/2068836#M399572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the running configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;: Written by enable_15 at 12:14:12.994 CDT Mon Sep 10 2012&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ASA Version 8.4(2) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ASA&lt;/P&gt;&lt;P&gt;domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 10.7.1.0 ScottNet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; switchport access vlan 3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; switchport access vlan 5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; switchport access vlan 5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt; switchport access vlan 6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt; switchport access vlan 3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt; switchport trunk allowed vlan 3,5,7,16&lt;/P&gt;&lt;P&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; backup interface Vlan16&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address XXX.XXX.XXX.XXX 255.255.255.240 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan3&lt;/P&gt;&lt;P&gt; nameif Development&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 172.16.32.254 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan5&lt;/P&gt;&lt;P&gt; nameif Corp&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.0.1.254 255.255.252.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan6&lt;/P&gt;&lt;P&gt; nameif NED&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.60.0.254 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan16&lt;/P&gt;&lt;P&gt; nameif BACKUP&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 192.168.15.2 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa842-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone CST -6&lt;/P&gt;&lt;P&gt;clock summer-time CDT recurring&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;access-list outside_cryptomap extended permit ip 10.0.0.0 255.255.0.0 10.7.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip 172.16.32.0 255.255.255.0 any inactive &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit 53 any any inactive &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit object-group TCPUDP 172.16.32.0 255.255.255.0 host 10.0.1.221 eq domain &lt;/P&gt;&lt;P&gt;access-list Development_access_in extended permit 53 any any &lt;/P&gt;&lt;P&gt;access-list Development_access_in extended permit object-group TCPUDP any any &lt;/P&gt;&lt;P&gt;access-list Development_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list Development_access_in extended deny tcp any any eq smtp &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 10.0.0.0 255.255.255.0 10.0.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Corp_nat0_outbound extended permit ip 10.0.0.0 255.255.255.0 10.70.0.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Corp_nat0_outbound extended permit ip 10.0.1.0 255.255.255.0 10.70.0.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Corp_nat0_outbound extended permit ip 172.16.30.0 255.255.255.0 10.0.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Corp_nat0_outbound extended permit ip 10.0.1.0 255.255.255.0 10.1.2.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Corp_nat0_outbound extended permit ip 10.70.0.0 255.255.255.0 10.0.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Corp_nat0_outbound extended permit ip 10.0.1.0 255.255.255.0 object ScottNet &lt;/P&gt;&lt;P&gt;access-list Corp_access_in extended permit ip 10.70.0.0 255.255.255.0 10.0.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list Corp_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list Corp_access_in extended permit gre any any &lt;/P&gt;&lt;P&gt;access-list Corp_access_in extended permit udp any any eq domain &lt;/P&gt;&lt;P&gt;access-list Corp_access_in extended permit tcp any any eq pptp &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap_1 extended permit ip 10.0.0.0 255.255.252.0 object CoryNet &lt;/P&gt;&lt;P&gt;access-list NED_access_in extended permit ip 10.0.1.0 255.255.255.0 10.70.0.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list NED_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list Backup_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.221 object-group DM_INLINE_TCP_1 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.144 object-group TMS_Services &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.146 object-group TMS_Services &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit gre any host 10.0.1.221 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.161 object-group DM_INLINE_TCP_2 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp any host 10.0.1.221 eq domain &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp host XXX.XXX.XXX.XXX any eq tftp &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group TCPUDP any object-group DM_INLINE_NETWORK_1 eq 8005 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip 172.16.30.0 255.255.255.0 any &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group DM_INLINE_SERVICE_1 any host 10.0.1.151 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.116 eq pptp &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit gre any host 10.0.1.116 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.116 object-group DM_INLINE_TCP_4 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.41 eq 3389 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.0.1.125 eq smtp &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm warnings&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu Development 1500&lt;/P&gt;&lt;P&gt;mtu Corp 1500&lt;/P&gt;&lt;P&gt;mtu NED 1500&lt;/P&gt;&lt;P&gt;mtu BACKUP 1500&lt;/P&gt;&lt;P&gt;ip local pool VPN-address-pool 10.0.2.20-10.0.2.50 mask 255.255.252.0&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-645-206.bin&lt;/P&gt;&lt;P&gt;asdm location ScottNet 255.255.255.0 Corp&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;access-group Development_access_in in interface Development&lt;/P&gt;&lt;P&gt;access-group Corp_access_in in interface Corp&lt;/P&gt;&lt;P&gt;access-group NED_access_in in interface NED&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 XXX.XXX.XXX.30 1 track 1&lt;/P&gt;&lt;P&gt;route BACKUP 0.0.0.0 0.0.0.0 192.168.15.1 254&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication telnet console LOCAL &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 10.0.3.0 255.255.255.0 Corp&lt;/P&gt;&lt;P&gt;http 10.0.1.0 255.255.255.0 Corp&lt;/P&gt;&lt;P&gt;http 172.16.32.0 255.255.255.0 Development&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;track 1 rtr 123 reachability&lt;/P&gt;&lt;P&gt;telnet 172.16.32.0 255.255.255.0 Development&lt;/P&gt;&lt;P&gt;telnet 10.0.0.0 255.255.252.0 Corp&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 172.16.32.15-172.16.32.100 Development&lt;/P&gt;&lt;P&gt;dhcpd dns 4.2.2.1 4.2.2.2 interface Development&lt;/P&gt;&lt;P&gt;dhcpd enable Development&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 10.0.1.101-10.0.1.124 Corp&lt;/P&gt;&lt;P&gt;dhcpd dns 10.0.1.221 10.0.1.160 interface Corp&lt;/P&gt;&lt;P&gt;dhcpd wins 10.0.1.221 interface Corp&lt;/P&gt;&lt;P&gt;dhcpd option 66 ip 10.0.1.1 interface Corp&lt;/P&gt;&lt;P&gt;dhcpd option 150 ip 10.0.1.1 interface Corp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd dns 10.0.1.221 4.2.2.1 interface NED&lt;/P&gt;&lt;P&gt;dhcpd wins 10.0.1.221 interface NED&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect pptp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2012 17:19:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-aironet-ip-redirection-on-asa/m-p/2068836#M399572</guid>
      <dc:creator>jamesdborden</dc:creator>
      <dc:date>2012-09-10T17:19:43Z</dc:date>
    </item>
    <item>
      <title>Problem with Aironet IP redirection on ASA</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-aironet-ip-redirection-on-asa/m-p/2068837#M399573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I take it that the 10.0.3.0 network is the WiFi network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First thing first. It seems you don't have route for this network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please add a route for the mentioned network.&lt;/P&gt;&lt;P&gt;route corp 10.0.3.0 255.255.255.0 gateway of network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And you also need to parse through your config and clean it up a bit especially in your ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Terence&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2012 17:43:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-aironet-ip-redirection-on-asa/m-p/2068837#M399573</guid>
      <dc:creator>terrencepayet</dc:creator>
      <dc:date>2012-09-10T17:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Aironet IP redirection on ASA</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-aironet-ip-redirection-on-asa/m-p/2068838#M399575</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The corp network is 10.0.0.0/22 but unfortunately that isn't included in the running config.&amp;nbsp; When I remove the redirect everything works fine.&amp;nbsp; The problem is that it is hitting an acl when I set an ip redirect to the gateway 10.0.1.254&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2012 20:35:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-aironet-ip-redirection-on-asa/m-p/2068838#M399575</guid>
      <dc:creator>jamesdborden</dc:creator>
      <dc:date>2012-09-11T20:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Aironet IP redirection on ASA</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-aironet-ip-redirection-on-asa/m-p/2068839#M399577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello James,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please remove the HTTP configuration and put it back.&lt;/P&gt;&lt;P&gt;clear configure http &lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;http server enable&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;http 10.0.3.0 255.255.255.0 Corp&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;http 10.0.1.0 255.255.255.0 Corp&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;http 172.16.32.0 255.255.255.0 Development&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Also remove the ACL as its not doing anything in here:&lt;/P&gt;&lt;P&gt;clear configure access-list&amp;nbsp; Corp_access_in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2012 21:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-aironet-ip-redirection-on-asa/m-p/2068839#M399577</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-09-11T21:03:38Z</dc:date>
    </item>
  </channel>
</rss>

