<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ASA5520 Basic configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa5520-basic-configuration/m-p/1919573#M436338</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also make sure you open the ACL on outside:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 100 permit tcp any interface outside eq 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 May 2012 11:18:49 GMT</pubDate>
    <dc:creator>varrao</dc:creator>
    <dc:date>2012-05-22T11:18:49Z</dc:date>
    <item>
      <title>Cisco ASA5520 Basic configuration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5520-basic-configuration/m-p/1919569#M436334</link>
      <description>&lt;P style="text-align: left;"&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;This is my 1st time trying to configure an ASA.&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;I'm trying to establish a very basic connection (ping) between 2 laptops, one sat on the outside interface, and one on the inside as per the diagram below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/5/4/9/89945-Capture.JPG" alt="Capture.JPG" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ping back and forth from the ASA to 192.168.1.4, and to 10.1.1.1. However, what I'm trying to achieve is to be able to ping from 10.1.1.1 to 192.168.1.4 and vice versa.&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;I have attached the configuration file with this post as well.&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;I suspect it's something simple and silly that I did. Can you please help?&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:09:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5520-basic-configuration/m-p/1919569#M436334</guid>
      <dc:creator>haidar_alm</dc:creator>
      <dc:date>2019-03-11T23:09:35Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA5520 Basic configuration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5520-basic-configuration/m-p/1919570#M436335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Haider,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you might just need to add this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 192.168.1.4 192.168.1.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;make sure you also put a default route on the 192.168.1.4 machine with ASA inside as the gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2012 10:17:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5520-basic-configuration/m-p/1919570#M436335</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-05-22T10:17:06Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA5520 Basic configuration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5520-basic-configuration/m-p/1919571#M436336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It worked, however, I would like to know how!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already had the (nat and global) command configured on it. Is that not enough?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, should the command not be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 10.1.1.2 192.168.1.4 255.255.255.255 ? &amp;lt;= i tried it and got an error. &lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want the inside address of 192.168.1.4 to be mapped to the outside interface address of 10.1.1.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I do show xlate, i can see that the 192 address is shown as itself globally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I look forward to your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;kr&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2012 10:59:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5520-basic-configuration/m-p/1919571#M436336</guid>
      <dc:creator>haidar_alm</dc:creator>
      <dc:date>2012-05-22T10:59:50Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA5520 Basic configuration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5520-basic-configuration/m-p/1919572#M436337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Haider,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The nat global statements that you have, that is to pat the internal users, when they go out of the outside interface, it is not for connections coming in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to nat the internal IP with the outside interface of the ASA, you would need:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) interface 192.168.1.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I would not advise that, because this statement would block the complete IP address for the internal server only. I would rather suggest port forwarding, which means, you are using only a single port on that IP. Here's the config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) interface 443 192.168.1.4 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This shoudl&amp;nbsp; be done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2012 11:17:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5520-basic-configuration/m-p/1919572#M436337</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-05-22T11:17:31Z</dc:date>
    </item>
    <item>
      <title>Cisco ASA5520 Basic configuration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa5520-basic-configuration/m-p/1919573#M436338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also make sure you open the ACL on outside:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 100 permit tcp any interface outside eq 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2012 11:18:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa5520-basic-configuration/m-p/1919573#M436338</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-05-22T11:18:49Z</dc:date>
    </item>
  </channel>
</rss>

