<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot access to dmz from outside in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-access-to-dmz-from-outside/m-p/1997258#M440404</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could check you firewall settings (which seem ok though) with the command "packet-tracer" from the CLI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example with the following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input &lt;OUTSIDE interface="" name=""&gt; tcp 8.8.8.8 1025 41.225.12.250 7010&lt;/OUTSIDE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the output check especially what the NAT phases of the packet-tracer say.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also you can use the graphical user interface ASDM to check the realtime&amp;nbsp; monitor/logging to show what happens to the TCP connection. (For example if the connection is torn down because of SYN timeout or perhaps just TCP Reset)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And if you want to go even more deeper you can create a traffic capture on the ASAs outside interface for this traffic and view the capture on Wireshark for example to see whats happening on the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS. I guess you have changed you configurations abit since your attached configuration and the outside interface mentioned in the replys are different (&lt;/P&gt;&lt;P&gt;Foptique -&amp;gt; outside)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Jun 2012 09:05:11 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2012-06-28T09:05:11Z</dc:date>
    <item>
      <title>Cannot access to dmz from outside</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-to-dmz-from-outside/m-p/1997254#M440397</link>
      <description>&lt;P&gt;I have a new ASA 5510 firewall, the objective is to set up a DMZ zone. my problem is I can't access to the web server in the DMZ from outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ ==========&amp;gt; outside OK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;INSIDE ==========&amp;gt; DMZ OK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ ============&amp;gt; Inside OK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OUTSIDE ==========&amp;gt; DMZ&amp;nbsp; NOK "FAIL"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I put in attachment the running-config file. could you help me please?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:23:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-to-dmz-from-outside/m-p/1997254#M440397</guid>
      <dc:creator>strabelsi</dc:creator>
      <dc:date>2019-03-11T23:23:41Z</dc:date>
    </item>
    <item>
      <title>Cannot access to dmz from outside</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-to-dmz-from-outside/m-p/1997255#M440398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My guess would be missing NAT rule from outside to dmz ....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 13:28:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-to-dmz-from-outside/m-p/1997255#M440398</guid>
      <dc:creator>willem</dc:creator>
      <dc:date>2012-06-27T13:28:16Z</dc:date>
    </item>
    <item>
      <title>Cannot access to dmz from outside</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-to-dmz-from-outside/m-p/1997256#M440400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;could you give me more information?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I already put a static nat&lt;/P&gt;&lt;P&gt; "static (DMZ, outside) tcp interface 7010 10.10.10.2 7010 netmask 255.255.255.255"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 13:40:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-to-dmz-from-outside/m-p/1997256#M440400</guid>
      <dc:creator>strabelsi</dc:creator>
      <dc:date>2012-06-27T13:40:15Z</dc:date>
    </item>
    <item>
      <title>Cannot access to dmz from outside</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-to-dmz-from-outside/m-p/1997257#M440402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm, obvious maybe but is the dmz server listening at port 7010 ? Have you turned on debugging this will help you to see what is going wrong ... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 08:02:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-to-dmz-from-outside/m-p/1997257#M440402</guid>
      <dc:creator>willem</dc:creator>
      <dc:date>2012-06-28T08:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access to dmz from outside</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-to-dmz-from-outside/m-p/1997258#M440404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could check you firewall settings (which seem ok though) with the command "packet-tracer" from the CLI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example with the following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input &lt;OUTSIDE interface="" name=""&gt; tcp 8.8.8.8 1025 41.225.12.250 7010&lt;/OUTSIDE&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the output check especially what the NAT phases of the packet-tracer say.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also you can use the graphical user interface ASDM to check the realtime&amp;nbsp; monitor/logging to show what happens to the TCP connection. (For example if the connection is torn down because of SYN timeout or perhaps just TCP Reset)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And if you want to go even more deeper you can create a traffic capture on the ASAs outside interface for this traffic and view the capture on Wireshark for example to see whats happening on the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS. I guess you have changed you configurations abit since your attached configuration and the outside interface mentioned in the replys are different (&lt;/P&gt;&lt;P&gt;Foptique -&amp;gt; outside)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 09:05:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-to-dmz-from-outside/m-p/1997258#M440404</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-06-28T09:05:11Z</dc:date>
    </item>
    <item>
      <title>Cannot access to dmz from outside</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-to-dmz-from-outside/m-p/1997259#M440406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi willem,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, in the debug level, I see that everything is permitted. I was not blocking.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 09:50:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-to-dmz-from-outside/m-p/1997259#M440406</guid>
      <dc:creator>strabelsi</dc:creator>
      <dc:date>2012-06-28T09:50:10Z</dc:date>
    </item>
    <item>
      <title>Cannot access to dmz from outside</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-to-dmz-from-outside/m-p/1997260#M440408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Thank you for your help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I'll do the test with Packet trace just when I returned to the office and give you the answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Concerning the name of the interface, I changed it in the discuss to be meaningful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 10:06:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-to-dmz-from-outside/m-p/1997260#M440408</guid>
      <dc:creator>strabelsi</dc:creator>
      <dc:date>2012-06-28T10:06:34Z</dc:date>
    </item>
  </channel>
</rss>

