<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 DMZ and Inside cannot talk to one another in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001606#M439938</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;""So what ACL actually controls what gets between the DMZ and the Inside interfaces?" Is to control what is permited to leave dmz.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please follow the steps I posted in my very last post and upldate me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Jul 2012 02:05:23 GMT</pubDate>
    <dc:creator>rizwanr74</dc:creator>
    <dc:date>2012-07-06T02:05:23Z</dc:date>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001595#M439924</link>
      <description>&lt;P&gt;I have several machines out in my DMZ and cannot get a ping going between them and anything on the inside of my network. I've even tried setting my access list attached to my DMZ to ip any any with no luck. Attached is my (sanitized) config. Any help is appreciated, everything looks good to me, but obviously something is wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:26:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001595#M439924</guid>
      <dc:creator>Adam Hudson</dc:creator>
      <dc:date>2019-03-11T23:26:57Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001596#M439927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Packet tracer results running from DMZ to Inside:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SiteA-Firewall# packet-tracer input dmz icmp 173.17.1.4 0 0 11.2.1.23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: FLOW-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Found no matching flow, creating a new flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: UN-NAT&lt;/P&gt;&lt;P&gt;Subtype: static&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;static (inside,dmz) 11.2.1.0 11.2.1.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside 11.2.1.0 255.255.255.0 dmz any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 11.2.1.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 1, untranslate_hits = 3&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;NAT divert to egress interface inside&lt;/P&gt;&lt;P&gt;Untranslate 11.2.1.0/0 to 11.2.1.0/0 using netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group dmz_access_in in interface dmz&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; description Internet_Netflow&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 7&lt;/P&gt;&lt;P&gt;Type:&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 8&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: host-limits&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (dmz) 1 173.17.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip dmz 173.17.1.0 255.255.255.0 dmz any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (173.17.1.1 [Interface PAT])&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 9&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: rpf-check&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;static (inside,dmz) 11.2.1.0 11.2.1.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside 11.2.1.0 255.255.255.0 dmz any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 11.2.1.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 1, untranslate_hits = 3&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 10&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 263043, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: dmz&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: inside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 18:16:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001596#M439927</guid>
      <dc:creator>Adam Hudson</dc:creator>
      <dc:date>2012-07-05T18:16:34Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001597#M439929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A few inputs based on the configs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a.&amp;nbsp; &lt;/P&gt;&lt;P&gt;route outside 11.2.2.0 255.255.255.0 24.106.253.3 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 11.2.2.0 11.2.2.0 netmask 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have a static nat for real address on inside 11.2.2.0 but the route for it is via outside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would expect this to be:&lt;/P&gt;&lt;P&gt;route inside 11.2.2.0 255.255.255.0 24.106.253.3 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b.&amp;nbsp; Hoping that all the below 6 inside networks are being learnt via eigrp? The reason i asked is i don't see static routes for any of them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 11.1.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 1 11.2.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 1 11.2.70.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 11.2.1.0 11.2.1.0 netmask 255.255.255.0 &lt;/P&gt;&lt;P&gt;static (inside,dmz) 11.1.1.0 11.1.1.0 netmask 255.255.255.0 &lt;/P&gt;&lt;P&gt;static (inside,dmz) 173.17.2.0 173.17.2.0 netmask 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;c.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (dmz) 1 interface&lt;/P&gt;&lt;P&gt;Do you real need this statement? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;d. &lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list no_nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list no_nat extended permit ip 173.17.1.0 255.255.255.0 11.8.0.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list no_nat extended permit ip 173.17.1.0 255.255.255.0 11.2.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list no_nat extended permit ip 173.17.1.0 255.255.255.0 11.1.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list no_nat extended permit ip 173.17.1.0 255.255.255.0 11.2.2.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list no_nat extended permit ip 173.17.1.0 255.255.255.0 173.17.2.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above 5 lines are not required at all. 173.17.1.0 is a DMZ network. It doesn't have to be included as a source in the access-list for a nat on the inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (dmz) 0 access-list no_nat_dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't see any access-list like no_nat_dmz in the configuration. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can be more specific on the flow not working, i can probably give more inputs. But from the info provided so far, this is what i infer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 18:23:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001597#M439929</guid>
      <dc:creator>Gautam Bhagwandas</dc:creator>
      <dc:date>2012-07-05T18:23:12Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001598#M439930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From inside to DMZ: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SiteA-Firewall# packet-tracer input inside icmp 11.2.1.23 0 0 173.17.1.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;MAC Access list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: FLOW-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Found no matching flow, creating a new flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 173.17.1.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; description Internet_Netflow&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 7&lt;/P&gt;&lt;P&gt;Type:&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 8&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;static (inside,dmz) 11.2.1.0 11.2.1.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside 11.2.1.0 255.255.255.0 dmz any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 11.2.1.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 2, untranslate_hits = 3&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Static translate 11.2.1.0/0 to 11.2.1.0/0 using netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 9&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: host-limits&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;static (inside,dmz) 11.2.1.0 11.2.1.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside 11.2.1.0 255.255.255.0 dmz any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 11.2.1.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 2, untranslate_hits = 3&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 10&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 266708, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: dmz&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 18:24:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001598#M439930</guid>
      <dc:creator>Adam Hudson</dc:creator>
      <dc:date>2012-07-05T18:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001599#M439931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I apologize, that was an older santized config. The attached file is the most up to date config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 20:21:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001599#M439931</guid>
      <dc:creator>Adam Hudson</dc:creator>
      <dc:date>2012-07-05T20:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001600#M439932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gautam, a) b) and e) are different in the changed config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;c) Would this line cause problems if it was left in?&lt;/P&gt;&lt;P&gt;d) Explanation:&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;access-list no_nat extended permit ip 173.17.1.0 255.255.255.0 11.8.0.0 255.255.255.0&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Site A's DMZ and Site C's main subnet&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;access-list no_nat extended permit ip 173.17.1.0 255.255.255.0 11.2.1.0 255.255.255.0&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Site A's DMZ and Site A subnet&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;access-list no_nat extended permit ip 173.17.1.0 255.255.255.0 11.1.1.0 255.255.255.0&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Site A's DMZ and Site A's main subnet&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;access-list no_nat extended permit ip 173.17.1.0 255.255.255.0 11.2.2.0 255.255.255.0&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Site A's DMZ and Site B's main subnet&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;access-list no_nat extended permit ip 173.17.1.0 255.255.255.0 173.17.2.0 255.255.255.0&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Site A's DMZ and Site B's DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Thanks for you help so far!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 20:34:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001600#M439932</guid>
      <dc:creator>Adam Hudson</dc:creator>
      <dc:date>2012-07-05T20:34:06Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001601#M439933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Adam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please remove these highlighted lines below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (inside,dmz) 11.2.1.0 11.2.1.0 netmask 255.255.255.0 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (inside,dmz) 11.1.1.0 11.1.1.0 netmask 255.255.255.0 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (inside,dmz) 11.2.2.0 11.2.2.0 netmask 255.255.255.0 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (inside,dmz) 173.17.2.0 173.17.2.0 netmask 255.255.255.0 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (inside,dmz) 11.8.0.0 11.8.0.0 netmask 255.255.255.0 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (inside,dmz) 11.2.70.0 11.2.70.0 netmask 255.255.255.0 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nat (dmz) 0 access-list no_nat_dmz&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now copy this line and try it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 173.17.1.0 173.17.2.0 netmask 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know, if that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 20:48:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001601#M439933</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2012-07-05T20:48:27Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001602#M439934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Removed all of the bolded selections, no communication. Re-added just the "nat (dmz) 0 access-list no_nat_dmz", no communication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You suggested addition is confusing, the 173.17.1.0 network is the dmz at this site/on this machine, the 172.17.2.0 network is the dmz at another site and while technically on the "inside" the subnet is not located at the site and not one of the zones I'm currently trying to get to talk to one another.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anything else you can see wrong with the config? This seems to be a real stumper!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 01:03:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001602#M439934</guid>
      <dc:creator>Adam Hudson</dc:creator>
      <dc:date>2012-07-06T01:03:47Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001603#M439935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Adam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please remote this as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (inside,dmz) 173.17.1.0 173.17.2.0 netmask 255.255.255.0 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please remove this as well: &lt;/STRONG&gt;&lt;STRONG&gt;"nat (dmz) 0 access-list no_nat_dmz",&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Just add one one shown below.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 10.0.0.0 10.0.0.0 netmask 255.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Rizwan Rafeek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 01:44:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001603#M439935</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2012-07-06T01:44:51Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001604#M439936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had a co-working check my config, he noticed the no_nat acl wasn't being applied to anything. We went through some old configs where the DMZ was still working, the command "nat (inside) 0 access-list no_nat" was present in some of those old configs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I applied this command was able to ping, success! My question after that was "So what ACL actually controls what gets between the DMZ and the Inside interfaces?" I ran the following command to remove the dmz_access_in ACL from the device "clear configure access-list dmz_access_in" then I tried to ping again. I pinged the interface, which I reasoned I should still be able to because technically there's nothing coming "in" to the DMZ. But, when I pinged a machine inside the DMZ, I thought nothing would come back because there's no acl on DMZ letting things back "in" to the interface. Well that ping worked as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, my question is, "Why does pinging stop when the ACL no_nat is removed, but it continues if the previous ACL is in play but the dmz_access_in ACL is removed?" additionally, "What does that dmz_access_in ACL control if anything? Because it doesn't appear to be controlling what goes "in" to that dmz interface."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 01:48:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001604#M439936</guid>
      <dc:creator>Adam Hudson</dc:creator>
      <dc:date>2012-07-06T01:48:18Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001605#M439937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If packet-tracer results are to be believed, my issue is not solved, they can ping, but when I simulate traffice coming out of a machine on the DMZ, it gets dropped. Results below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SiteA-Firewall# packet-tracer input dmz icmp 173.17.1.4 0 0 11.2.1.23&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: FLOW-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Found no matching flow, creating a new flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 11.2.1.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: log&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;access-group dmz_access_in in interface dmz&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; description Internet_Netflow&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 7&lt;/P&gt;&lt;P&gt;Type:&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 8&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: host-limits&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (dmz) 1 173.17.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip dmz 173.17.1.0 255.255.255.0 dmz any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (173.17.1.1 [Interface PAT])&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 9&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: rpf-check&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;&amp;nbsp; match ip inside any dmz any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (173.17.1.1 [Interface PAT])&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 1, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: dmz&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: inside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 01:51:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001605#M439937</guid>
      <dc:creator>Adam Hudson</dc:creator>
      <dc:date>2012-07-06T01:51:19Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001606#M439938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;""So what ACL actually controls what gets between the DMZ and the Inside interfaces?" Is to control what is permited to leave dmz.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please follow the steps I posted in my very last post and upldate me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 02:05:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001606#M439938</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2012-07-06T02:05:23Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001607#M439939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Addition, the above results are with a "permit ip any any" as the only line of dmz_access_in.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 02:07:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001607#M439939</guid>
      <dc:creator>Adam Hudson</dc:creator>
      <dc:date>2012-07-06T02:07:43Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001608#M439940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tested the below nat before on my ASA and it works fine.&amp;nbsp; there is no ACL in the test lab, meaning it is more restrictive than having ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 10.0.0.0 10.0.0.0 netmask 255.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 02:12:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001608#M439940</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2012-07-06T02:12:24Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001609#M439941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;I removed the line &lt;/STRONG&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;"nat (dmz) 0 access-list no_nat_dmz",&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif; min-height: 8pt; height: 8pt;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt; &lt;/STRONG&gt; &lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;And added the line: static (inside,dmz) 10.0.0.0 10.0.0.0 netmask 255.0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;The pings work through packet tracer. I'm a bit confused as to why though. If I understand right the static command you had me put in "maps" the 10.0.0.0 subnet on the dmz to that same network on the inside interface. But if that's right, how do I control what comes and goes from the dmz interface? Specifically since I don't have an acl controlling the show anymore.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Thanks for your help so far.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 02:21:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001609#M439941</guid>
      <dc:creator>Adam Hudson</dc:creator>
      <dc:date>2012-07-06T02:21:16Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001610#M439942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But I need the flexibility of letting certain ports and ip addresses in and out of the DMZ, how do I do that now?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 02:34:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001610#M439942</guid>
      <dc:creator>Adam Hudson</dc:creator>
      <dc:date>2012-07-06T02:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001611#M439943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"But if that's right, how do I control what comes and goes from the dmz interface?"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More secure interface such as "inside" should be able to access dmz without any problem with the static that I showned you.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can still add an ACL on the DMZ interface as shown below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"But I need the flexibility of letting certain ports and ip addresses in and out of the DMZ, how do I do that now?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz_incoming extended deny ip host 173.17.1.111 host 11.255.1.250&lt;/P&gt;&lt;P&gt;access-group dmz_incoming in interface dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Rizwan Rafeek&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Rizwan Mohamed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 02:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001611#M439943</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2012-07-06T02:34:16Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001612#M439944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I must be doing something wrong then. I put in the following commands trying to block pings from coming "in" to the DMZ interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended deny icmp any any&lt;/P&gt;&lt;P&gt;access-group dmz_access_in in interface dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pings and packet tracer simulation are still successful. What am I missing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 02:55:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001612#M439944</guid>
      <dc:creator>Adam Hudson</dc:creator>
      <dc:date>2012-07-06T02:55:23Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001613#M439945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For some reason my later post is posting higher than yours on my machine. Please see my comment, which appears to me as the post above yours.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 03:06:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001613#M439945</guid>
      <dc:creator>Adam Hudson</dc:creator>
      <dc:date>2012-07-06T03:06:11Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 DMZ and Inside cannot talk to one another</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001614#M439946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; "access-list dmz_access_in extended deny icmp any any&lt;/P&gt;&lt;P&gt;access-group dmz_access_in in interface dmz"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above lines will work, if you ping from a dmz host, it will deny the traffic.&amp;nbsp; meaning traffic will entre into dmz interface, from dmz zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you want to control what can access from inside interface, you would do that same from inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope that answers your questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2012 03:06:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-dmz-and-inside-cannot-talk-to-one-another/m-p/2001614#M439946</guid>
      <dc:creator>rizwanr74</dc:creator>
      <dc:date>2012-07-06T03:06:39Z</dc:date>
    </item>
  </channel>
</rss>

