<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Basic setup and testing: Static Route/ACLs not working. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-basic-setup-and-testing-static-route-acls-not-working/m-p/550568#M425643</link>
    <description>&lt;P&gt;This is my current setup. I have put a server on the Outside66 Interface and am trying to access a default IIS Website on a server on the DMZ. I am not sure why but it wont allow me to access it through the firewall. I have included my config as well as a show nat command (there are translations happening its just not going anywhere after the translation I think).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icm-xxxx(config)# show run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 7.0(4)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname icm-xxxxx&lt;/P&gt;&lt;P&gt;domain-name xxxxxxxx.com&lt;/P&gt;&lt;P&gt;enable password xxxxxxxxx encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif Outside66&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 66.38.xxx.xxx 255.255.255.224 standby 66.38.xxx.xxx&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.x.x 255.255.255.0 standby 10.10.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; nameif Private&lt;/P&gt;&lt;P&gt; security-level 40&lt;/P&gt;&lt;P&gt; ip address 192.168.x.x 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt; description LAN/STATE Failover Interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; description Outside64 Interface&lt;/P&gt;&lt;P&gt; nameif Outside64&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 64.187.x.x 255.255.255.224 standby 64.187.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd 16ZH0HY6cUga4at6 encrypted&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;access-list out extended permit tcp any host 66.38.x.x eq www&lt;/P&gt;&lt;P&gt;access-list out extended permit tcp any host 66.38.x.x&lt;/P&gt;&lt;P&gt;access-list out extended permit tcp host 66.38.x.x any&lt;/P&gt;&lt;P&gt;access-list out extended permit tcp host 66.38.x.x any eq www&lt;/P&gt;&lt;P&gt;access-list dmz extended permit tcp host 10.10.x.x any eq www&lt;/P&gt;&lt;P&gt;access-list dmz extended permit tcp host 10.10.x.x any&lt;/P&gt;&lt;P&gt;access-list dmz extended permit tcp 10.10.x.x 255.255.255.0 any eq domain&lt;/P&gt;&lt;P&gt;access-list dmz extended permit udp 10.10.x.x 255.255.255.0 any eq domain&lt;/P&gt;&lt;P&gt;access-list dmz extended permit tcp any host 10.10.x.x&lt;/P&gt;&lt;P&gt;access-list dmz extended permit tcp any host 10.10.x.x eq www&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging monitor debugging&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu Outside66 1500&lt;/P&gt;&lt;P&gt;mtu Outside64 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu Private 1500&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface FoInt GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;failover link FoInt GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;failover interface ip FoInt 192.168.x.x 255.255.255.0 standby 192.168.x.x&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm504.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (Outside66) 1 66.38.x.x&lt;/P&gt;&lt;P&gt;static (DMZ,Outside66) 66.38.x.x 10.10.x.x netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (Outside66,DMZ) 10.10.x.x 66.38.x.x netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-group out in interface Outside66&lt;/P&gt;&lt;P&gt;access-group dmz out interface DMZ&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00&lt;/P&gt;&lt;P&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;telnet 192.x.x.x 255.255.255.0 Private&lt;/P&gt;&lt;P&gt;telnet timeout 30&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd lease 3600&lt;/P&gt;&lt;P&gt;dhcpd ping_timeout 50&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  inspect h323 h225&lt;/P&gt;&lt;P&gt;  inspect h323 ras&lt;/P&gt;&lt;P&gt;  inspect http&lt;/P&gt;&lt;P&gt;  inspect ils&lt;/P&gt;&lt;P&gt;  inspect rsh&lt;/P&gt;&lt;P&gt;  inspect rtsp&lt;/P&gt;&lt;P&gt;  inspect sip&lt;/P&gt;&lt;P&gt;  inspect skinny&lt;/P&gt;&lt;P&gt;  inspect esmtp&lt;/P&gt;&lt;P&gt;  inspect sqlnet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icm-asa01(config)# show nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT policies on Interface Outside66:&lt;/P&gt;&lt;P&gt;  match ip Outside66 host 66.38.x.x DMZ any&lt;/P&gt;&lt;P&gt;    static translation to 10.10.x.x&lt;/P&gt;&lt;P&gt;    translate_hits = 12, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT policies on Interface DMZ:&lt;/P&gt;&lt;P&gt;  match ip DMZ host 10.10.x.x Outside66 any&lt;/P&gt;&lt;P&gt;    static translation to 66.38.x.x&lt;/P&gt;&lt;P&gt;    translate_hits = 10, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have no idea why I cant get from one end to the other?? I have actually tried from DMZ -&amp;gt; Outside66 and the other way around. I know the ACLs seem a little bit of over kill... I was just trying to make it work so I made the "opposite" of all the ones I already had... with no luck of course! Any help would be very appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time,&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:58:52 GMT</pubDate>
    <dc:creator>chrisbicm</dc:creator>
    <dc:date>2020-02-21T08:58:52Z</dc:date>
    <item>
      <title>ASA Basic setup and testing: Static Route/ACLs not working.</title>
      <link>https://community.cisco.com/t5/network-security/asa-basic-setup-and-testing-static-route-acls-not-working/m-p/550568#M425643</link>
      <description>&lt;P&gt;This is my current setup. I have put a server on the Outside66 Interface and am trying to access a default IIS Website on a server on the DMZ. I am not sure why but it wont allow me to access it through the firewall. I have included my config as well as a show nat command (there are translations happening its just not going anywhere after the translation I think).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icm-xxxx(config)# show run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 7.0(4)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname icm-xxxxx&lt;/P&gt;&lt;P&gt;domain-name xxxxxxxx.com&lt;/P&gt;&lt;P&gt;enable password xxxxxxxxx encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif Outside66&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 66.38.xxx.xxx 255.255.255.224 standby 66.38.xxx.xxx&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.x.x 255.255.255.0 standby 10.10.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; nameif Private&lt;/P&gt;&lt;P&gt; security-level 40&lt;/P&gt;&lt;P&gt; ip address 192.168.x.x 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt; description LAN/STATE Failover Interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; description Outside64 Interface&lt;/P&gt;&lt;P&gt; nameif Outside64&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 64.187.x.x 255.255.255.224 standby 64.187.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd 16ZH0HY6cUga4at6 encrypted&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;access-list out extended permit tcp any host 66.38.x.x eq www&lt;/P&gt;&lt;P&gt;access-list out extended permit tcp any host 66.38.x.x&lt;/P&gt;&lt;P&gt;access-list out extended permit tcp host 66.38.x.x any&lt;/P&gt;&lt;P&gt;access-list out extended permit tcp host 66.38.x.x any eq www&lt;/P&gt;&lt;P&gt;access-list dmz extended permit tcp host 10.10.x.x any eq www&lt;/P&gt;&lt;P&gt;access-list dmz extended permit tcp host 10.10.x.x any&lt;/P&gt;&lt;P&gt;access-list dmz extended permit tcp 10.10.x.x 255.255.255.0 any eq domain&lt;/P&gt;&lt;P&gt;access-list dmz extended permit udp 10.10.x.x 255.255.255.0 any eq domain&lt;/P&gt;&lt;P&gt;access-list dmz extended permit tcp any host 10.10.x.x&lt;/P&gt;&lt;P&gt;access-list dmz extended permit tcp any host 10.10.x.x eq www&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging monitor debugging&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu Outside66 1500&lt;/P&gt;&lt;P&gt;mtu Outside64 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu Private 1500&lt;/P&gt;&lt;P&gt;failover&lt;/P&gt;&lt;P&gt;failover lan unit primary&lt;/P&gt;&lt;P&gt;failover lan interface FoInt GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;failover link FoInt GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;failover interface ip FoInt 192.168.x.x 255.255.255.0 standby 192.168.x.x&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm504.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (Outside66) 1 66.38.x.x&lt;/P&gt;&lt;P&gt;static (DMZ,Outside66) 66.38.x.x 10.10.x.x netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (Outside66,DMZ) 10.10.x.x 66.38.x.x netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-group out in interface Outside66&lt;/P&gt;&lt;P&gt;access-group dmz out interface DMZ&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00&lt;/P&gt;&lt;P&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;telnet 192.x.x.x 255.255.255.0 Private&lt;/P&gt;&lt;P&gt;telnet timeout 30&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd lease 3600&lt;/P&gt;&lt;P&gt;dhcpd ping_timeout 50&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  inspect h323 h225&lt;/P&gt;&lt;P&gt;  inspect h323 ras&lt;/P&gt;&lt;P&gt;  inspect http&lt;/P&gt;&lt;P&gt;  inspect ils&lt;/P&gt;&lt;P&gt;  inspect rsh&lt;/P&gt;&lt;P&gt;  inspect rtsp&lt;/P&gt;&lt;P&gt;  inspect sip&lt;/P&gt;&lt;P&gt;  inspect skinny&lt;/P&gt;&lt;P&gt;  inspect esmtp&lt;/P&gt;&lt;P&gt;  inspect sqlnet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icm-asa01(config)# show nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT policies on Interface Outside66:&lt;/P&gt;&lt;P&gt;  match ip Outside66 host 66.38.x.x DMZ any&lt;/P&gt;&lt;P&gt;    static translation to 10.10.x.x&lt;/P&gt;&lt;P&gt;    translate_hits = 12, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT policies on Interface DMZ:&lt;/P&gt;&lt;P&gt;  match ip DMZ host 10.10.x.x Outside66 any&lt;/P&gt;&lt;P&gt;    static translation to 66.38.x.x&lt;/P&gt;&lt;P&gt;    translate_hits = 10, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have no idea why I cant get from one end to the other?? I have actually tried from DMZ -&amp;gt; Outside66 and the other way around. I know the ACLs seem a little bit of over kill... I was just trying to make it work so I made the "opposite" of all the ones I already had... with no luck of course! Any help would be very appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time,&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:58:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-basic-setup-and-testing-static-route-acls-not-working/m-p/550568#M425643</guid>
      <dc:creator>chrisbicm</dc:creator>
      <dc:date>2020-02-21T08:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Basic setup and testing: Static Route/ACLs not working.</title>
      <link>https://community.cisco.com/t5/network-security/asa-basic-setup-and-testing-static-route-acls-not-working/m-p/550569#M425644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your config looks fine. Add a default route on the ASA and see what happens.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 x.x.x.x&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jun 2006 18:06:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-basic-setup-and-testing-static-route-acls-not-working/m-p/550569#M425644</guid>
      <dc:creator>imanl</dc:creator>
      <dc:date>2006-06-19T18:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Basic setup and testing: Static Route/ACLs not working.</title>
      <link>https://community.cisco.com/t5/network-security/asa-basic-setup-and-testing-static-route-acls-not-working/m-p/550570#M425645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have actually tried a few different default routes without any luck. Do you think that is my major problem?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Jun 2006 11:02:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-basic-setup-and-testing-static-route-acls-not-working/m-p/550570#M425645</guid>
      <dc:creator>chrisbicm</dc:creator>
      <dc:date>2006-06-20T11:02:34Z</dc:date>
    </item>
  </channel>
</rss>

