<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Suggestion is needed in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/suggestion-is-needed/m-p/1995503#M434591</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;both the customer's residing in inside zone of the ASA box by having the sub interfaces created on the ASA?????&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Jun 2012 11:29:04 GMT</pubDate>
    <dc:creator>nkarthikeyan</dc:creator>
    <dc:date>2012-06-08T11:29:04Z</dc:date>
    <item>
      <title>Suggestion is needed</title>
      <link>https://community.cisco.com/t5/network-security/suggestion-is-needed/m-p/1995502#M434590</link>
      <description>&lt;P&gt;Hey, forks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a hosted data center environment. We use dual ASA 5510 for connection going out to Internet. On the internal side of the ASA5510, we use unique VLANs to identify different hosted customers and also isolate traffic among them. Recently we run into an issue that one customer can not email another customer whoes email servers are both residing in our hosted environment. For Example, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer A email server is configured with 10.10.1.1 with public IP mapped on ASA5510 as 23.24.25.26. Customer B email server is configured with 192.168.2.1 with public IP mapped on same ASA5510 as 23.24.25.28. When customer A send email to customer B, traffic got blocked, which is expected on ASA. Now we are trying to keep the proper security while somehow allow 2 customer to communicating emails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We could configure ACL specific to do the job but it will not be managable if there are 50 customers need to email another 50 customers in the same environment...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/S&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:16:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suggestion-is-needed/m-p/1995502#M434590</guid>
      <dc:creator>SIMMN</dc:creator>
      <dc:date>2019-03-11T23:16:49Z</dc:date>
    </item>
    <item>
      <title>Suggestion is needed</title>
      <link>https://community.cisco.com/t5/network-security/suggestion-is-needed/m-p/1995503#M434591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;both the customer's residing in inside zone of the ASA box by having the sub interfaces created on the ASA?????&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2012 11:29:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suggestion-is-needed/m-p/1995503#M434591</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-06-08T11:29:04Z</dc:date>
    </item>
    <item>
      <title>Suggestion is needed</title>
      <link>https://community.cisco.com/t5/network-security/suggestion-is-needed/m-p/1995504#M434592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; That is correct. That is I guess the main reason I am searching for alternative way to allow certain communication while maintaining the setup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2012 11:38:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suggestion-is-needed/m-p/1995504#M434592</guid>
      <dc:creator>SIMMN</dc:creator>
      <dc:date>2012-06-08T11:38:58Z</dc:date>
    </item>
    <item>
      <title>Suggestion is needed</title>
      <link>https://community.cisco.com/t5/network-security/suggestion-is-needed/m-p/1995505#M434593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still waiting for suggestions...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW, Do other big hosting environment use single routing/firewall instance for each customer?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jun 2012 13:59:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suggestion-is-needed/m-p/1995505#M434593</guid>
      <dc:creator>SIMMN</dc:creator>
      <dc:date>2012-06-14T13:59:27Z</dc:date>
    </item>
    <item>
      <title>Suggestion is needed</title>
      <link>https://community.cisco.com/t5/network-security/suggestion-is-needed/m-p/1995506#M434594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bro&lt;/P&gt;&lt;P&gt;To resolve your issue, you'll need to configure Cisco DNS Doctoring. This will work like a charm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In most enterprise deployment, that hosts hundreds of tenants, they would normally use Cisco FWSM running in multi-context mode. This mean one virtual FW per customer. On the switching side, Cisco Nexus 7K is used instead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P/S: if you think this comment is useful, please do rate them nicely &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Jul 2012 02:23:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suggestion-is-needed/m-p/1995506#M434594</guid>
      <dc:creator>Ramraj Sivagnanam Sivajanam</dc:creator>
      <dc:date>2012-07-29T02:23:20Z</dc:date>
    </item>
    <item>
      <title>Suggestion is needed</title>
      <link>https://community.cisco.com/t5/network-security/suggestion-is-needed/m-p/1995507#M434595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shuai Yu,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do a hairpinning enabled to make this work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer the below document as well along with doctoring concept which ramraj has suggested. Here you are doing within the sub interfaces. Both are almost similar in concepts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to create nat rules in such a way to achive this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://ckdake.com/content/2009/hairpinning-with-a-cisco-asa.html"&gt;http://ckdake.com/content/2009/hairpinning-with-a-cisco-asa.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do rate if the given information helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;by&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Jul 2012 14:22:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suggestion-is-needed/m-p/1995507#M434595</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-07-29T14:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: Suggestion is needed</title>
      <link>https://community.cisco.com/t5/network-security/suggestion-is-needed/m-p/1995508#M434596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the suggestion. But multi-context on Asa will not be applicable for us. IPSec VPNs are used between data enter and customers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plus, we prefer to not configure acl/nay rules to accomplish this. What if there are 10 or 20 customers need this setup? Just don't want to loss configuration control.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are considering the email relay server or CSR1000v.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If u have any other suggestion, please post.&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Jul 2012 14:46:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suggestion-is-needed/m-p/1995508#M434596</guid>
      <dc:creator>SIMMN</dc:creator>
      <dc:date>2012-07-29T14:46:42Z</dc:date>
    </item>
  </channel>
</rss>

