<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Host in DMZ cannot get outside (ASA 5505) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930774#M437042</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Getting an error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;gcxfw(config)# nat (dmz,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;/P&gt;&lt;P&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 May 2012 19:20:11 GMT</pubDate>
    <dc:creator>ralf.rottmann</dc:creator>
    <dc:date>2012-05-14T19:20:11Z</dc:date>
    <item>
      <title>Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930770#M437038</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the configuration pasted below, we believe the host (10.0.2.200 / 255.255.255.0 GW: 10.0.2.1 with external DNS servers configured) should have access to the web. However, it cannot resolve any names nor can it connect outside. Any idea why? Your help is greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# show running-configuration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;/P&gt;&lt;P&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;ciscoasa# show runn&lt;/P&gt;&lt;P&gt;ciscoasa# show running-config &lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.4(3) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;enable password *** encrypted&lt;/P&gt;&lt;P&gt;passwd *** encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt; switchport access vlan 12&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.0.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 195.14.245.70 255.255.255.224 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan12&lt;/P&gt;&lt;P&gt; nameif dmz&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 10.0.2.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns domain-lookup outside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 194.8.194.60&lt;/P&gt;&lt;P&gt; name-server 213.168.112.60&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu dmz 1500&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 195.14.245.65 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 10.0.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;/P&gt;&lt;P&gt;crypto ca trustpoint _SmartCallHome_ServerCA&lt;/P&gt;&lt;P&gt; crl configure&lt;/P&gt;&lt;P&gt;crypto ca certificate chain _SmartCallHome_ServerCA&lt;/P&gt;&lt;P&gt; certificate ca 6ecc7aa5a7032009b8cebcf4e952d491&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ***&lt;/P&gt;&lt;P&gt;&amp;nbsp; quit&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 10.0.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dhcpd dns 194.8.194.60 213.168.112.60&lt;/P&gt;&lt;P&gt;dhcpd auto_config inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics&lt;/P&gt;&lt;P&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;username *** password *** encrypted privilege 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options &lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; user-statistics accounting&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;call-home reporting anonymous&lt;/P&gt;&lt;P&gt;hpm topN enable&lt;/P&gt;&lt;P&gt;Cryptochecksum:***&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:06:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930770#M437038</guid>
      <dc:creator>ralf.rottmann</dc:creator>
      <dc:date>2019-03-11T23:06:46Z</dc:date>
    </item>
    <item>
      <title>Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930771#M437039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are currently nat'ing inside traffic to go outside, you need to do the same to allow your DMZ to get out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (dmz,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kevin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Please rate helpful posts and remember to mark your question as answered once resolved!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 19:04:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930771#M437039</guid>
      <dc:creator>Kevin P Sheahan</dc:creator>
      <dc:date>2012-05-14T19:04:56Z</dc:date>
    </item>
    <item>
      <title>Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930772#M437040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wow, that was a speedy response. Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you explain how I do that on a) CLI and b) ASDM? That would be just fantastic!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 19:12:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930772#M437040</guid>
      <dc:creator>ralf.rottmann</dc:creator>
      <dc:date>2012-05-14T19:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930773#M437041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Copy and paste the line below in your CLI. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (dmz,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 19:17:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930773#M437041</guid>
      <dc:creator>Kevin P Sheahan</dc:creator>
      <dc:date>2012-05-14T19:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930774#M437042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Getting an error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;gcxfw(config)# nat (dmz,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;/P&gt;&lt;P&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 19:20:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930774#M437042</guid>
      <dc:creator>ralf.rottmann</dc:creator>
      <dc:date>2012-05-14T19:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930775#M437043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (dmz,outside) 2 source dynamic any interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you copy and paste or type it verbatim.. there is a &lt;SPACE&gt; in between "nat" and "(dmz,outside)".&lt;/SPACE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 19:25:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930775#M437043</guid>
      <dc:creator>Kevin P Sheahan</dc:creator>
      <dc:date>2012-05-14T19:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930776#M437044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The command did work but the host stil seems to be unable to go outside...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 19:27:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930776#M437044</guid>
      <dc:creator>ralf.rottmann</dc:creator>
      <dc:date>2012-05-14T19:27:42Z</dc:date>
    </item>
    <item>
      <title>Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930777#M437045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to add:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_any_dmz&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat (dmz,outside) dynamic interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 19:28:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930777#M437045</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-05-14T19:28:26Z</dc:date>
    </item>
    <item>
      <title>Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930778#M437046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Varun, thanks for checking back in. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll add that in a moment. How can I rewoke this one before:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (dmz,outside) 2 source dynamic any interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;-Ralf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 19:29:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930778#M437046</guid>
      <dc:creator>ralf.rottmann</dc:creator>
      <dc:date>2012-05-14T19:29:58Z</dc:date>
    </item>
    <item>
      <title>Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930779#M437047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just put a "no" in front of it in the config mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 19:43:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930779#M437047</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-05-14T19:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930780#M437048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And repeat the exact command?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 19:52:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930780#M437048</guid>
      <dc:creator>ralf.rottmann</dc:creator>
      <dc:date>2012-05-14T19:52:43Z</dc:date>
    </item>
    <item>
      <title>Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930781#M437049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, once you delete it, you need to add this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_any_dmz&lt;/P&gt;&lt;P&gt;&amp;nbsp; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat (dmz,outside) dynamic interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 21:37:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930781#M437049</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-05-14T21:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930782#M437050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Worked like a charm. Could you briefly explain what the command does?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 21:41:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930782#M437050</guid>
      <dc:creator>ralf.rottmann</dc:creator>
      <dc:date>2012-05-14T21:41:20Z</dc:date>
    </item>
    <item>
      <title>Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930783#M437051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command just nats all your traffic from the DMZ interface to the outside interface of the ASA, glad it helped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 21:48:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930783#M437051</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-05-14T21:48:55Z</dc:date>
    </item>
    <item>
      <title>Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930784#M437052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks again. I thought NAT is only required for inbound traffic. Why do I have to NAT outgoing connections?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 06:49:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930784#M437052</guid>
      <dc:creator>ralf.rottmann</dc:creator>
      <dc:date>2012-05-15T06:49:34Z</dc:date>
    </item>
    <item>
      <title>Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930785#M437053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello.&lt;/P&gt;&lt;P&gt;I dont mean to highjack this thread but I have a similar situation as this one, only that i would like to NAT only my webserver which is the DMZ to the outside on a specified IP address and not PAT. my firewall wont allow the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; nat (dmz,outside) dynamic interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;unless, nat (dmz) 1......................................(am not certain how the command shoule end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how can i do this translation so that my webserver can be seen? also, i need it to be seen only on ports 80,443 and 20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 10:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930785#M437053</guid>
      <dc:creator>Amos Kafwembe</dc:creator>
      <dc:date>2012-12-18T10:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930786#M437054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With ASA software 8.3 and above the configuration format is the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Port Forward Configuration using the "outside" interface public IP address&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network STATIC-TCP20&lt;/P&gt;&lt;P&gt; host 10.10.10.10&lt;/P&gt;&lt;P&gt; nat (dmz,outside) static interface service tcp 20 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network STATIC-TCP80&lt;/P&gt;&lt;P&gt; host 10.10.10.10&lt;/P&gt;&lt;P&gt; nat (dmz,outside) static interface service tcp 80 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network STATIC-TCP443&lt;/P&gt;&lt;P&gt; host 10.10.10.10&lt;/P&gt;&lt;P&gt; nat (dmz,outside) static interface service tcp 443 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any object STATIC-TCP20 eq 20&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any object STATIC-TCP80 eq 80&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any object STATIC-TCP443 eq 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group OUTSIDE-IN in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;10.10.10.10 = example DMZ host IP address&lt;/LI&gt;&lt;LI&gt;STATIC-TCPxx = object name for each translation/portforward&lt;/LI&gt;&lt;LI&gt;OUTSIDE-IN = example outside interface ACL name&lt;/LI&gt;&lt;LI&gt;access-group = attach the ACL to outside interface (unless you already have an ACL attached)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IF you have a dedicated public IP address for the server -&amp;gt; REPLACE "interface" with the public IP address.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network STATIC-DMZ&lt;/P&gt;&lt;P&gt; host 10.10.10.10&lt;/P&gt;&lt;P&gt; nat (dmz,outside) static 1.2.3.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any object STATIC-DMZ eq 20&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any object STATIC-DMZ eq 80&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any object STATIC-DMZ eq 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group OUTSIDE-IN in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;10.10.10.10 = example DMZ host IP address&lt;/LI&gt;&lt;LI&gt;STATIC-DMZ = object name for the 1:1 Static NAT (in other words 10.10.10.10 owns this public IP address)&lt;/LI&gt;&lt;LI&gt;1.2.3.4 = example public IP address&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this solves your question please rate. Otherwise make another thread asking about this (copy/paste content there perhaps) and we will look furhter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 10:47:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930786#M437054</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-12-18T10:47:52Z</dc:date>
    </item>
    <item>
      <title>Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930787#M437055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for taking time to respond. my ASA version is pasted below. The command line is quite different.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 7.2(4)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;enable password Cxy6Egno9r1.xcqd encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 17:51:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930787#M437055</guid>
      <dc:creator>Amos Kafwembe</dc:creator>
      <dc:date>2012-12-18T17:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930788#M437056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Missunderstood/missread your post then.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the above software level the NAT command format is the following (unless I typo something or remember wrong)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Port Forward (Using "outside" interface IP address)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) tcp interface 20 10.10.10.10 20 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (dmz,outside) tcp interface 80 10.10.10.10 80 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (dmz,outside) tcp interface 443 10.10.10.10 443 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any host &lt;OUTSIDE interface="" ip="" address=""&gt; eq 20&lt;/OUTSIDE&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any host &lt;OUTSIDE interface="" ip="" address=""&gt; eq 80&lt;/OUTSIDE&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any host &lt;OUTSIDE interface="" ip="" address=""&gt; eq 443&lt;/OUTSIDE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Static NAT (Using own public IP address for server)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) 1.2.3.4 10.10.10.10 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any host 1.2.3.4 eq 20&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any host 1.2.3.4 eq 80&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN permit tcp any host 1.2.3.4 eq 443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 17:57:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930788#M437056</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-12-18T17:57:05Z</dc:date>
    </item>
    <item>
      <title>Host in DMZ cannot get outside (ASA 5505)</title>
      <link>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930789#M437057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for this......but now i need my webserver to be accessible form the inside as well. because i cant even ping it from inside. how do i enable communication between the web server and the inside network?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 19:22:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/host-in-dmz-cannot-get-outside-asa-5505/m-p/1930789#M437057</guid>
      <dc:creator>Amos Kafwembe</dc:creator>
      <dc:date>2012-12-18T19:22:20Z</dc:date>
    </item>
  </channel>
</rss>

