<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 Interface Communication Help Needed in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-interface-communication-help-needed/m-p/1922070#M458003</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You inside hosts should be able to communicate with hosts on the test interface network (192.168.12.81-94) by virtue of the implicit rule allowing communication from higher to lower security level. (That would be assuming no more restrictive access-list is in place.) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on how you want things to work, you may also need a global (test) statement to nat traffic out the test interface or nat exempt statement. The latter would look something like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list EXEMPT permit ip 192.168.1.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;nat (test) 0 access-list EXEMPT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 18 Mar 2012 22:52:33 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2012-03-18T22:52:33Z</dc:date>
    <item>
      <title>ASA 5510 Interface Communication Help Needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-interface-communication-help-needed/m-p/1922069#M458001</link>
      <description>&lt;P&gt;I need some help in establishing communication between my “inside” interface and a third interface called “test” on an ASA 5510. This third interface called “test” is connected to a WatchGuard Firebox which is acting as a VPN device and has an IP address of 192.168.12.81. I have three interfaces setup on the ASA in the following fashion:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;interface Ethernet0/0&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;nameif outside&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;security-level 0&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;ip address xxx.xxx.xxx.xx 255.255.255.248 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;interface Ethernet0/1&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;nameif inside&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;security-level 100&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;ip address 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;interface Ethernet0/2&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;nameif test&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;security-level 0&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;ip address 192.168.12.83 255.255.255.240&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The inside interface is able to communicate with the Internet because of this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;global (outside) 1 interface&lt;/P&gt;&lt;P style="margin-left: 0.5in;"&gt;route outside 0.0.0.0 0.0.0.0 xxx.xxx.xxx.xx 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone please help with the commands which will allow communication from the inside interface to the test interface? No matter what I have tried, it does not work. I can provide any additional information which is required.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:43:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-interface-communication-help-needed/m-p/1922069#M458001</guid>
      <dc:creator>rashidjb1</dc:creator>
      <dc:date>2019-03-11T22:43:40Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 Interface Communication Help Needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-interface-communication-help-needed/m-p/1922070#M458003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You inside hosts should be able to communicate with hosts on the test interface network (192.168.12.81-94) by virtue of the implicit rule allowing communication from higher to lower security level. (That would be assuming no more restrictive access-list is in place.) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on how you want things to work, you may also need a global (test) statement to nat traffic out the test interface or nat exempt statement. The latter would look something like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list EXEMPT permit ip 192.168.1.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;nat (test) 0 access-list EXEMPT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Mar 2012 22:52:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-interface-communication-help-needed/m-p/1922070#M458003</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2012-03-18T22:52:33Z</dc:date>
    </item>
  </channel>
</rss>

