<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA: How to allow active directory to traverse outside and i in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216664#M418170</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have attempted this, but all I get when I ping is negotiating IP security.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this should be working but I'm obviously missing something.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Apr 2009 18:50:40 GMT</pubDate>
    <dc:creator>dirkmelvin</dc:creator>
    <dc:date>2009-04-16T18:50:40Z</dc:date>
    <item>
      <title>ASA: How to allow active directory to traverse outside and inside?</title>
      <link>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216659#M418165</link>
      <description>&lt;P&gt;I am attempting to get AD to cooperate from a parent domain on the outside of the ASA to a child domain on the inside of the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far when I first setup the child domain all is well (assuming because the inside server is initiating the chatter) but after a little while (not sure of time frame) AD stops synching and get errors on the servers about such.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216659#M418165</guid>
      <dc:creator>dirkmelvin</dc:creator>
      <dc:date>2020-02-21T11:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: How to allow active directory to traverse outside and i</title>
      <link>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216660#M418166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is just off the top of my head, but you'll need LDAP, DNS, and Kerberos opened up. If you want filing browsing, you'll have to open RPC all ports &amp;gt;1024 and 137-139, &amp;amp; 445. You have a couple of other options though. You can use an IPSec tunnel between the two servers and/or RPC over HTTPS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Apr 2009 12:57:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216660#M418166</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2009-04-16T12:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: How to allow active directory to traverse outside and i</title>
      <link>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216661#M418167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will try to illustrate my setup here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet----ASA1--Domain1&lt;/P&gt;&lt;P&gt;              |&lt;/P&gt;&lt;P&gt;              |&lt;/P&gt;&lt;P&gt;            ASA2--Domain1.1&lt;/P&gt;&lt;P&gt;I'll post my configs from both ASAs later today.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Apr 2009 13:33:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216661#M418167</guid>
      <dc:creator>dirkmelvin</dc:creator>
      <dc:date>2009-04-16T13:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: How to allow active directory to traverse outside and i</title>
      <link>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216662#M418168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would recommend using an IPSEC tunnel for this if possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following link shows a list of required ports&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://technet.microsoft.com/en-us/library/bb727063.aspx" target="_blank"&gt;http://technet.microsoft.com/en-us/library/bb727063.aspx&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Apr 2009 18:47:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216662#M418168</guid>
      <dc:creator>AxiomConsulting</dc:creator>
      <dc:date>2009-04-16T18:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: How to allow active directory to traverse outside and i</title>
      <link>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216663#M418169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nice link Steve, thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Apr 2009 18:49:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216663#M418169</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2009-04-16T18:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: How to allow active directory to traverse outside and i</title>
      <link>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216664#M418170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have attempted this, but all I get when I ping is negotiating IP security.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this should be working but I'm obviously missing something.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Apr 2009 18:50:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216664#M418170</guid>
      <dc:creator>dirkmelvin</dc:creator>
      <dc:date>2009-04-16T18:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: How to allow active directory to traverse outside and i</title>
      <link>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216665#M418171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are able to, please post your configs for us to review.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Apr 2009 18:53:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216665#M418171</guid>
      <dc:creator>AxiomConsulting</dc:creator>
      <dc:date>2009-04-16T18:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: How to allow active directory to traverse outside and i</title>
      <link>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216666#M418172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here my 2 configs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outside is the ASA connected to Internet, inside is the ASA on the inside interface of the outside ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are 3 AD servers on the inside interface of the outside ASA, and there are 2 AD servers on the inside interface of the inside ASA. all 5 of these servers need to speak AD to each other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Apr 2009 15:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-how-to-allow-active-directory-to-traverse-outside-and-inside/m-p/1216666#M418172</guid>
      <dc:creator>dirkmelvin</dc:creator>
      <dc:date>2009-04-20T15:38:17Z</dc:date>
    </item>
  </channel>
</rss>

