<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot get out to internet nor manage ASA from DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-get-out-to-internet-nor-manage-asa-from-dmz/m-p/1894477#M438156</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What could be the reason to prevent me from telnet or asdm to the ASA from 172.10.1.0/24 ? It seems that it's not responding at all. Could it be this line?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;management-access inside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Apr 2012 13:30:19 GMT</pubDate>
    <dc:creator>kpoon</dc:creator>
    <dc:date>2012-04-24T13:30:19Z</dc:date>
    <item>
      <title>Cannot get out to internet nor manage ASA from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cannot-get-out-to-internet-nor-manage-asa-from-dmz/m-p/1894473#M438152</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've created a DMZ on ASA5510, it can access anything internal but cannot get out to internet. I cannot manage the ASA from the DMZ subnet neither. Could you please help?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:57:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-get-out-to-internet-nor-manage-asa-from-dmz/m-p/1894473#M438152</guid>
      <dc:creator>kpoon</dc:creator>
      <dc:date>2019-03-11T22:57:14Z</dc:date>
    </item>
    <item>
      <title>Cannot get out to internet nor manage ASA from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cannot-get-out-to-internet-nor-manage-asa-from-dmz/m-p/1894474#M438153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your management issue is likely due to a missing http or ssh command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http x.x.x.x &lt;NETMASK&gt; &lt;INTERFACE&gt;&lt;/INTERFACE&gt;&lt;/NETMASK&gt;&lt;/P&gt;&lt;P&gt;ssh x.x.x.x &lt;NETMASK&gt; &lt;INTERFACE&gt;&lt;/INTERFACE&gt;&lt;/NETMASK&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can't download the file from my iPad but it's probably a NAT or ACL issue that's preventing traffic from exiting&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2012 02:06:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-get-out-to-internet-nor-manage-asa-from-dmz/m-p/1894474#M438153</guid>
      <dc:creator>Patrick0711</dc:creator>
      <dc:date>2012-04-24T02:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot get out to internet nor manage ASA from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cannot-get-out-to-internet-nor-manage-asa-from-dmz/m-p/1894475#M438154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;interface Ethernet0/2&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; description XXX DMZ&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; speed 100&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; duplex full&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; nameif DMZ&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; security-level 100&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; ip address 172.10.1.1 255.255.255.0&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Relevant management commands are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;http server enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;http 192.168.0.0 255.255.0.0 inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;http 0.0.0.0 0.0.0.0 outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="text-decoration: underline; font-family: 'courier new', courier; "&gt;http 172.10.1.0 255.255.255.0 DMZ&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;http redirect outside 80&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;telnet 0.0.0.0 0.0.0.0 outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;telnet 0.0.0.0 0.0.0.0 inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="text-decoration: underline; font-family: 'courier new', courier; "&gt;telnet 172.10.1.0 255.255.255.0 DMZ&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;telnet timeout 15&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ssh timeout 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the above you should be able to use ASDM or telnet (but not ssh) from the DMZ. However you do not specify an "asdm image" command anywhere in the script your provided so ASDM would not work. You need to both ahve it on the ASA's disk and point to it, e.g.:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;adsm image disk0:/asdm-647.bin&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(I'd lock down the outside telnet access and in fact not allow insecure telnet at all.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your access-lists look OK (albeit ineffectual since you allow everything)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;access-group DMZ_access_in_1 in interface DMZ control-plane&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;access-group DMZ_access_in in interface DMZ&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;access-group DMZ_access_out out interface DMZ&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;access-list DMZ_access_out extended permit ip any any &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;access-list DMZ_access_in extended permit ip any any &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;access-list DMZ_access_in_1 extended permit ip any any&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However you don't have any NAT statements for traffic leaving the DMZ. I'd expect something beginning like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;object network obj_any-07&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt; nat (outside,DMZ) dynamic obj-0.0.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2012 03:08:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-get-out-to-internet-nor-manage-asa-from-dmz/m-p/1894475#M438154</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2012-04-24T03:08:23Z</dc:date>
    </item>
    <item>
      <title>Cannot get out to internet nor manage ASA from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cannot-get-out-to-internet-nor-manage-asa-from-dmz/m-p/1894476#M438155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the pointers, I am going to try them shortly. I also do have the asdm image configured, I simply filtered out lines that are not necessary for the problem I'm having to shorten the config file. As for the DMZ, I was just trying to figure out what was causing the problem, I'll remove the allow all once it's working.&lt;/P&gt;&lt;P&gt;Thanks again and I'll post result.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2012 12:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-get-out-to-internet-nor-manage-asa-from-dmz/m-p/1894476#M438155</guid>
      <dc:creator>kpoon</dc:creator>
      <dc:date>2012-04-24T12:59:08Z</dc:date>
    </item>
    <item>
      <title>Cannot get out to internet nor manage ASA from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cannot-get-out-to-internet-nor-manage-asa-from-dmz/m-p/1894477#M438156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What could be the reason to prevent me from telnet or asdm to the ASA from 172.10.1.0/24 ? It seems that it's not responding at all. Could it be this line?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;management-access inside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2012 13:30:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-get-out-to-internet-nor-manage-asa-from-dmz/m-p/1894477#M438156</guid>
      <dc:creator>kpoon</dc:creator>
      <dc:date>2012-04-24T13:30:19Z</dc:date>
    </item>
    <item>
      <title>Cannot get out to internet nor manage ASA from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cannot-get-out-to-internet-nor-manage-asa-from-dmz/m-p/1894478#M438157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've added&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;object network obj_any-08&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;nat (DMZ,outside) dynamic obj-0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;but I still can't get out to the net.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;Any other idea?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2012 17:51:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-get-out-to-internet-nor-manage-asa-from-dmz/m-p/1894478#M438157</guid>
      <dc:creator>kpoon</dc:creator>
      <dc:date>2012-04-24T17:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot get out to internet nor manage ASA from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/cannot-get-out-to-internet-nor-manage-asa-from-dmz/m-p/1894479#M438158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;here's the config in the zip file&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; description XXX Cogent Internet Connection&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 99.99.99.130 255.255.255.224 &lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; description XXX internal connection from firewall to switch&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.10.1 255.255.255.0 &lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; description XXX DMZ&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&amp;nbsp; &lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.10.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; description Management Service-ENLARGE-40&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; nameif E-40&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 10.40.86.248 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa842-8-k8.bin&lt;/P&gt;&lt;P&gt;boot system disk0:/asa824-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;dns domain-lookup outside&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns domain-lookup management&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 8.8.8.8&lt;/P&gt;&lt;P&gt; name-server 8.8.4.4&lt;/P&gt;&lt;P&gt; name-server 208.67.222.222&lt;/P&gt;&lt;P&gt; name-server 208.67.220.220&lt;/P&gt;&lt;P&gt; name-server 66.28.0.45&lt;/P&gt;&lt;P&gt; name-server 66.28.0.61&lt;/P&gt;&lt;P&gt; domain-name XXXtelecom.com&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object network obj-172.30.1.0&lt;/P&gt;&lt;P&gt; subnet 172.30.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-10.40.86.0&lt;/P&gt;&lt;P&gt; subnet 10.40.86.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-192.168.99.0&lt;/P&gt;&lt;P&gt; subnet 192.168.99.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-192.168.1.13&lt;/P&gt;&lt;P&gt; host 192.168.1.13&lt;/P&gt;&lt;P&gt;object network obj-192.168.1.13-01&lt;/P&gt;&lt;P&gt; host 192.168.1.13&lt;/P&gt;&lt;P&gt;object network obj-192.168.1.13-02&lt;/P&gt;&lt;P&gt; host 192.168.1.13&lt;/P&gt;&lt;P&gt;object network obj-172.30.1.70&lt;/P&gt;&lt;P&gt; host 172.30.1.70&lt;/P&gt;&lt;P&gt;object network obj-192.168.106.144&lt;/P&gt;&lt;P&gt; host 192.168.106.144&lt;/P&gt;&lt;P&gt;object network obj-192.168.106.144-01&lt;/P&gt;&lt;P&gt; host 192.168.106.144&lt;/P&gt;&lt;P&gt;object network obj-192.168.106.144-02&lt;/P&gt;&lt;P&gt; host 192.168.106.144&lt;/P&gt;&lt;P&gt;object network obj-192.168.10.2&lt;/P&gt;&lt;P&gt; host 192.168.10.2&lt;/P&gt;&lt;P&gt;object network obj-172.30.1.50&lt;/P&gt;&lt;P&gt; host 172.30.1.50&lt;/P&gt;&lt;P&gt;object network obj-172.30.1.40&lt;/P&gt;&lt;P&gt; host 172.30.1.40&lt;/P&gt;&lt;P&gt;object network obj-192.168.1.10&lt;/P&gt;&lt;P&gt; host 192.168.1.10&lt;/P&gt;&lt;P&gt;object network obj-192.168.106.99&lt;/P&gt;&lt;P&gt; host 192.168.106.99&lt;/P&gt;&lt;P&gt;object network obj-172.30.1.102&lt;/P&gt;&lt;P&gt; host 172.30.1.102&lt;/P&gt;&lt;P&gt;object network obj-172.30.1.31&lt;/P&gt;&lt;P&gt; host 172.30.1.31&lt;/P&gt;&lt;P&gt;object network obj-172.30.1.40-01&lt;/P&gt;&lt;P&gt; host 172.30.1.40&lt;/P&gt;&lt;P&gt;object network obj-172.30.1.50-01&lt;/P&gt;&lt;P&gt; host 172.30.1.50&lt;/P&gt;&lt;P&gt;object network obj-172.30.1.101&lt;/P&gt;&lt;P&gt; host 172.30.1.101&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj_any-01&lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj-0.0.0.0&lt;/P&gt;&lt;P&gt; host 0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj_any-02&lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj_any-03&lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj_any-04&lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj_any-05&lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj_any-06&lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj-192.168.0.0&lt;/P&gt;&lt;P&gt; subnet 192.168.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;object service ftp&lt;/P&gt;&lt;P&gt; service tcp source range ftp-data ftp destination range ftp-data ftp &lt;/P&gt;&lt;P&gt;object network obj-192.168.1.15&lt;/P&gt;&lt;P&gt; host 192.168.1.15&lt;/P&gt;&lt;P&gt;object network obj-192.168.1.15-01&lt;/P&gt;&lt;P&gt; host 192.168.1.15&lt;/P&gt;&lt;P&gt;object network NETWORK_OBJ_172.30.1.0_24&lt;/P&gt;&lt;P&gt; subnet 172.30.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network NETWORK_OBJ_172.31.2.0_24&lt;/P&gt;&lt;P&gt; subnet 172.31.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network obj-172.10.1.136&lt;/P&gt;&lt;P&gt; host 172.10.1.136&lt;/P&gt;&lt;P&gt; description VCS Express 01 NIC 01&lt;/P&gt;&lt;P&gt;object network obj-172.10.1.0&lt;/P&gt;&lt;P&gt; subnet 172.10.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt; description DMZ&lt;/P&gt;&lt;P&gt;object-group service ExchangeOWA tcp&lt;/P&gt;&lt;P&gt; description Exchange Web and Mobile Access&lt;/P&gt;&lt;P&gt; port-object eq smtp&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt;object-group network admin-ip&lt;/P&gt;&lt;P&gt; access-list inside_nat0_outbound_1 extended permit ip 172.30.1.0 255.255.255.0 10.40.86.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound_1 extended permit ip object-group DM_INLINE_NETWORK_3 192.168.99.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list dzm extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list dzm extended permit icmp any any &lt;/P&gt;&lt;P&gt;access-list ouside extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list cont_in extended permit ip host 99.99.99.135 any &lt;/P&gt;&lt;P&gt;access-list Split_tunnel_ACL standard permit 192.168.0.0 255.255.0.0 &lt;/P&gt;&lt;P&gt;access-list Split_tunnel_ACL standard permit 172.30.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside extended permit tcp host 192.168.1.13 any eq smtp &lt;/P&gt;&lt;P&gt;access-list inside extended permit tcp any object-group DM_INLINE_NETWORK_9 eq smtp &lt;/P&gt;&lt;P&gt;access-list inside extended deny tcp any any eq smtp &lt;/P&gt;&lt;P&gt;access-list inside extended deny tcp any any eq pop3 &lt;/P&gt;&lt;P&gt;access-list inside extended permit tcp any object-group DM_INLINE_NETWORK_5 eq pptp &lt;/P&gt;&lt;P&gt;access-list inside extended deny tcp any any eq pptp &lt;/P&gt;&lt;P&gt;access-list inside extended permit tcp object-group BypassFacebook object-group Facebook eq https &lt;/P&gt;&lt;P&gt;access-list inside extended deny tcp any object-group Facebook eq https &lt;/P&gt;&lt;P&gt;access-list inside extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip object-group DM_INLINE_NETWORK_2 192.168.99.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 192.168.1.0 255.255.255.0 192.168.123.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 192.168.1.0 255.255.255.0 host 172.19.4.50 &lt;/P&gt;&lt;P&gt;access-list E-40_access_out extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list inside-out-acl extended permit ip object-group DM_INLINE_NETWORK_12 172.30.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside-out-acl extended permit ip object-group DM_INLINE_NETWORK_4 host 192.168.1.18 inactive &lt;/P&gt;&lt;P&gt;access-list inside-out-acl extended permit ip object-group DM_INLINE_NETWORK_6 host 192.168.1.19 inactive &lt;/P&gt;&lt;P&gt;access-list inside-out-acl extended deny ip object-group DM_INLINE_NETWORK_7 any inactive &lt;/P&gt;&lt;P&gt;access-list inside-out-acl extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list throttle_frontline extended permit ip host 74.213.162.33 any inactive &lt;/P&gt;&lt;P&gt;access-list throttle_frontline extended permit ip any host 74.213.162.33 inactive &lt;/P&gt;&lt;P&gt;access-list outside remark Migration, ACE (line 3) expanded: permit tcp any object-group DM_INLINE_NETWORK_8&lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp any host 99.99.99.141 eq 8129 &lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp any host 172.30.1.70 eq www &lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp any host 99.99.99.141 eq https &lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp any host 192.168.106.144 eq 8129 &lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp any host 192.168.106.144 eq www &lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp any host 192.168.106.144 eq https &lt;/P&gt;&lt;P&gt;access-list outside remark Migration: End of expansion&lt;/P&gt;&lt;P&gt;access-list outside remark Migration, ACE (line 4) expanded: permit tcp any host 99.99.99.133 object-group ExchangeOWA&lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp any host 192.168.1.13 eq smtp &lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp any host 192.168.1.13 eq https &lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp any host 192.168.1.13 eq www &lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp object-group DM_INLINE_NETWORK_10 host 192.168.1.15 object-group DM_INLINE_TCP_3 &lt;/P&gt;&lt;P&gt;access-list outside remark Migration: End of expansion&lt;/P&gt;&lt;P&gt;access-list outside extended permit ip any host 192.168.106.99 &lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp any host 192.168.1.10 eq pptp &lt;/P&gt;&lt;P&gt;access-list outside extended permit gre any host 192.168.1.10 &lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp any host 192.168.10.2 eq telnet inactive &lt;/P&gt;&lt;P&gt;access-list outside extended permit tcp any host 172.30.1.40 object-group DM_INLINE_TCP_1 &lt;/P&gt;&lt;P&gt;access-list outside extended permit ip object-group tms-ip host 172.30.1.50 &lt;/P&gt;&lt;P&gt;access-list outside extended permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;access-list ENLARGE-40_access_in extended permit object-group DM_INLINE_SERVICE_1 any object-group DM_INLINE_NETWORK_1_2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list cscTraffic remark Migration: End of expansion&lt;/P&gt;&lt;P&gt;access-list cscTraffic extended permit tcp any any eq www &lt;/P&gt;&lt;P&gt;access-list cscTraffic extended permit tcp any any eq smtp &lt;/P&gt;&lt;P&gt;access-list cscTraffic extended permit tcp any any eq ftp inactive &lt;/P&gt;&lt;P&gt;access-list cscTraffic extended deny ip any 172.10.1.0 255.255.255.0 inactive &lt;/P&gt;&lt;P&gt;access-list outside_cryptomap extended permit ip 172.30.1.0 255.255.255.0 172.31.2.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list DMZ_access_out extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list DMZ_access_in_1 extended permit ip any any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging buffered informational&lt;/P&gt;&lt;P&gt;logging trap debugging&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging facility 19&lt;/P&gt;&lt;P&gt;logging host inside 192.168.1.15 format emblem&lt;/P&gt;&lt;P&gt;logging permit-hostdown&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu E-40 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;ip local pool XXX-pool 192.168.99.1-192.168.99.50 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,any) source static obj-172.30.1.0 obj-172.30.1.0 destination static obj-10.40.86.0 obj-10.40.86.0 no-proxy-arp&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static DM_INLINE_NETWORK_3 DM_INLINE_NETWORK_3 destination static obj-192.168.99.0 obj-192.168.99.0 no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static NETWORK_OBJ_172.30.1.0_24 NETWORK_OBJ_172.30.1.0_24 destination static NETWORK_OBJ_172.31.2.0_24 NETWORK_OBJ_172.31.2.0_24 no-proxy-arp route-lookup&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network obj-192.168.1.13&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 99.99.99.133 service tcp smtp smtp &lt;/P&gt;&lt;P&gt;object network obj-192.168.1.13-01&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 99.99.99.133 service tcp www www &lt;/P&gt;&lt;P&gt;object network obj-192.168.1.13-02&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 99.99.99.133 service tcp https https &lt;/P&gt;&lt;P&gt;object network obj-172.30.1.70&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 99.99.99.141 service tcp www www &lt;/P&gt;&lt;P&gt;object network obj-192.168.106.144&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 99.99.99.144 service tcp www www &lt;/P&gt;&lt;P&gt;object network obj-192.168.106.144-01&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 99.99.99.144 service tcp https https &lt;/P&gt;&lt;P&gt;object network obj-192.168.106.144-02&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 99.99.99.144 service tcp 8129 8129 &lt;/P&gt;&lt;P&gt;object network obj-192.168.10.2&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 99.99.99.132 service tcp telnet telnet &lt;/P&gt;&lt;P&gt;object network obj-172.30.1.50&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 99.99.99.134&lt;/P&gt;&lt;P&gt;object network obj-172.30.1.40&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 99.99.99.139&lt;/P&gt;&lt;P&gt;object network obj-192.168.1.10&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 99.99.99.137&lt;/P&gt;&lt;P&gt;object network obj-192.168.106.99&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 99.99.99.140&lt;/P&gt;&lt;P&gt;object network obj-172.30.1.102&lt;/P&gt;&lt;P&gt; nat (inside,E-40) static 10.40.86.102&lt;/P&gt;&lt;P&gt;object network obj-172.30.1.31&lt;/P&gt;&lt;P&gt; nat (inside,E-40) static 10.40.86.31&lt;/P&gt;&lt;P&gt;object network obj-172.30.1.40-01&lt;/P&gt;&lt;P&gt; nat (inside,E-40) static 10.40.86.40&lt;/P&gt;&lt;P&gt;object network obj-172.30.1.50-01&lt;/P&gt;&lt;P&gt; nat (inside,E-40) static 10.40.86.50&lt;/P&gt;&lt;P&gt;object network obj-172.30.1.101&lt;/P&gt;&lt;P&gt; nat (inside,E-40) static 10.40.86.101&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;object network obj_any-01&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic obj-0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj_any-02&lt;/P&gt;&lt;P&gt; nat (inside,DMZ) dynamic obj-0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj_any-03&lt;/P&gt;&lt;P&gt; nat (inside,E-40) dynamic obj-0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj_any-04&lt;/P&gt;&lt;P&gt; nat (management,outside) dynamic obj-0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj_any-05&lt;/P&gt;&lt;P&gt; nat (management,DMZ) dynamic obj-0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj_any-06&lt;/P&gt;&lt;P&gt; nat (management,E-40) dynamic obj-0.0.0.0&lt;/P&gt;&lt;P&gt;object network obj-192.168.1.15&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 99.99.99.138 service tcp ftp ftp &lt;/P&gt;&lt;P&gt;object network obj-192.168.1.15-01&lt;/P&gt;&lt;P&gt; nat (inside,outside) static 99.99.99.138 service tcp ftp-data ftp-data &lt;/P&gt;&lt;P&gt;access-group outside in interface outside&lt;/P&gt;&lt;P&gt;access-group inside in interface inside&lt;/P&gt;&lt;P&gt;access-group inside-out-acl out interface inside&lt;/P&gt;&lt;P&gt;access-group DMZ_access_in_1 in interface DMZ control-plane&lt;/P&gt;&lt;P&gt;access-group DMZ_access_in in interface DMZ&lt;/P&gt;&lt;P&gt;access-group DMZ_access_out out interface DMZ&lt;/P&gt;&lt;P&gt;access-group ENLARGE-40_access_in in interface E-40&lt;/P&gt;&lt;P&gt;access-group E-40_access_out out interface E-40&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 99.99.99.129 1&lt;/P&gt;&lt;P&gt;route E-40 10.4.86.0 255.255.255.0 10.40.86.249 1&lt;/P&gt;&lt;P&gt;route E-40 10.70.86.0 255.255.255.0 10.40.86.249 1&lt;/P&gt;&lt;P&gt;route E-40 10.96.86.0 255.255.255.0 10.40.86.249 1&lt;/P&gt;&lt;P&gt;route DMZ 172.10.1.0 255.255.255.0 192.168.10.2 1&lt;/P&gt;&lt;P&gt;route inside 172.20.20.0 255.255.255.0 192.168.10.2 1&lt;/P&gt;&lt;P&gt;route inside 172.30.1.0 255.255.255.0 192.168.10.2 1&lt;/P&gt;&lt;P&gt;route inside 192.168.1.0 255.255.255.0 192.168.10.2 1&lt;/P&gt;&lt;P&gt;route inside 192.168.2.0 255.255.255.0 192.168.10.2 1&lt;/P&gt;&lt;P&gt;route inside 192.168.3.0 255.255.255.0 192.168.10.2 1&lt;/P&gt;&lt;P&gt;route inside 192.168.6.0 255.255.255.0 192.168.10.2 1&lt;/P&gt;&lt;P&gt;route inside 192.168.99.0 255.255.255.0 192.168.10.2 255&lt;/P&gt;&lt;P&gt;route inside 192.168.101.0 255.255.255.0 192.168.10.2 1&lt;/P&gt;&lt;P&gt;route inside 192.168.102.0 255.255.255.0 192.168.10.2 1&lt;/P&gt;&lt;P&gt;route inside 192.168.103.0 255.255.255.0 192.168.10.2 1&lt;/P&gt;&lt;P&gt;route inside 192.168.106.0 255.255.255.0 192.168.10.2 1&lt;/P&gt;&lt;P&gt;route inside 192.168.201.0 255.255.255.0 192.168.10.2 1&lt;/P&gt;&lt;P&gt;route inside 0.0.0.0 0.0.0.0 192.168.10.2 tunneled&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.0.0 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;http 172.10.1.0 255.255.255.0 DMZ&lt;/P&gt;&lt;P&gt;http redirect outside 80&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;telnet 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;telnet 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;telnet 172.10.1.0 255.255.255.0 DMZ&lt;/P&gt;&lt;P&gt;telnet timeout 15&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;ssh timeout 10&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;management-access inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;priority-queue outside&lt;/P&gt;&lt;P&gt;priority-queue inside&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics&lt;/P&gt;&lt;P&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;/P&gt;&lt;P&gt;ntp server 192.168.1.10 source inside&lt;/P&gt;&lt;P&gt;ntp server 129.6.15.29 source outside prefer&lt;/P&gt;&lt;P&gt;ntp server 129.6.15.28 source outside prefer&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt; enable outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; cache&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; disable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map global-class&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;class-map csc-class&lt;/P&gt;&lt;P&gt; match access-list cscTraffic&lt;/P&gt;&lt;P&gt;class-map throttle_frontline&lt;/P&gt;&lt;P&gt; match access-list throttle_frontline&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect sip DefaultSIP&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; max-forwards-validation action drop log&lt;/P&gt;&lt;P&gt;policy-map throttle-policy&lt;/P&gt;&lt;P&gt; class throttle_frontline&lt;/P&gt;&lt;P&gt;&amp;nbsp; police input 600000 2000&lt;/P&gt;&lt;P&gt;&amp;nbsp; police output 600000 2000&lt;/P&gt;&lt;P&gt;policy-map global-policy&lt;/P&gt;&lt;P&gt; class global-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect pptp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ipsec-pass-thru &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;/P&gt;&lt;P&gt; class csc-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; csc fail-open&lt;/P&gt;&lt;P&gt;policy-map type inspect h323 DefaultH323&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global-policy global&lt;/P&gt;&lt;P&gt;service-policy throttle-policy interface outside&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa#&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Apr 2012 18:40:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-get-out-to-internet-nor-manage-asa-from-dmz/m-p/1894479#M438158</guid>
      <dc:creator>kpoon</dc:creator>
      <dc:date>2012-04-24T18:40:39Z</dc:date>
    </item>
  </channel>
</rss>

