<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5505 Configuration issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5505-configuration-issue/m-p/1877727#M490025</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the configuration you provided we cannot see the following line&lt;/P&gt;&lt;P&gt;access-list permit outside_access_in tcp any host 30.30.0.50 eq 110&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if you say is there you got to be right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So lets do the following packet tracer and see the result, then based on that we will create some captures&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input outside tcp 4.2.2.2 1025 30.30.0.50 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do please rate helpful posts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Dec 2011 06:26:00 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2011-12-29T06:26:00Z</dc:date>
    <item>
      <title>ASA5505 Configuration issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-configuration-issue/m-p/1877724#M490009</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;I’m trying to configure my ASA 5505, in order to allow my inbound and outbound mail communications. Here with this mail I’ve attached a diagram which illustrates my exact network setup along with ip addresses.&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;In this setup I’ve enabled port forwarding on my ADSL router (port 25 and 110) and configured the ASA accordingly, and my mail server is located inside my network.&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;My problem is currently I can send mails from my inside network to outside but my not receiving any mails which originate from outside. I’ve attached my current ASA configuration as well,&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Can someone assist me with this request?&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;C:\Users\Suthakar\Documents\Office_Docs\Thakral\ABC Computers&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;/////////////////////////&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Final config on ASA5505&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.155.201 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt;nameif outside&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 30.0.0.10 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any any inactive&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 30.0.0.10 eq smtp&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 30.0.0.10 eq pop3&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-641.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp &lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-weight: bold !important; color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;"&gt;30.0.0.50&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt; smtp 192.168.155.3 smtp netmask 255.255.255.255 (this ip is not used anywhere in the asa or network)&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 30.0.0.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;http 192.168.155.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;telnet 192.168.155.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;inspect ftp&lt;/P&gt;&lt;P&gt;inspect h323 h225&lt;/P&gt;&lt;P&gt;inspect h323 ras&lt;/P&gt;&lt;P&gt;inspect rsh&lt;/P&gt;&lt;P&gt;inspect rtsp&lt;/P&gt;&lt;P&gt;inspect sqlnet&lt;/P&gt;&lt;P&gt;inspect skinny&lt;/P&gt;&lt;P&gt;inspect sunrpc&lt;/P&gt;&lt;P&gt;inspect xdmcp&lt;/P&gt;&lt;P&gt;inspect sip&lt;/P&gt;&lt;P&gt;inspect netbios&lt;/P&gt;&lt;P&gt;inspect tftp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;Cryptochecksum:e05333a5df17af9d37e5415caeb89daf&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;ciscoasa#&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR style="color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;" /&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;suthakar&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-configuration-issue/m-p/1877724#M490009</guid>
      <dc:creator>suthakar sundaralingam</dc:creator>
      <dc:date>2019-03-26T00:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Configuration issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-configuration-issue/m-p/1877725#M490011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Suthakar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After checking your configuration I can see the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp&lt;STRONG style="font-weight: bold !important; color: #282828; font-family: helvetica, arial, sans-serif; font-size: 14px; line-height: 22px; text-align: -webkit-auto; background-color: #ffffff;"&gt; 30.0.0.50&lt;/STRONG&gt; smtp 192.168.155.3 smtp netmask 255.255.255.255 (this ip is not used anywhere in the asa or network)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you mean by that??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I mean what is the ip address of the SMTP server?? 192.168.155.3 right?&lt;/P&gt;&lt;P&gt;We need to do an static nat or Port forwarding based on that IP and then allow access to that server to allow inbound connections from a higher to a lower security level when nat control is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the static is fine, but the ACL is wrong. It should be like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list permit outside_access_in tcp any host 30.30.0.50 eq 25&lt;/P&gt;&lt;P&gt;access-list permit outside_access_in tcp any host 30.30.0.50 eq 110&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do please rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Dec 2011 17:41:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-configuration-issue/m-p/1877725#M490011</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-27T17:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Configuration issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-configuration-issue/m-p/1877726#M490012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've used 30.0.0.50, because obviously you can put a one-to-one static NAT to the same interface ip (30.0.0.10) right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and 192.168.155.3 is the SMTP server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Further I've used the above given ACL as well ( access-list permit outside_access_in tcp any host 30.30.0.50 eq 25 , &lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;access-list permit outside_access_in tcp any host 30.30.0.50 eq 110 ) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;but still i've the same issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Regards,&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;Suthakar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Dec 2011 04:53:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-configuration-issue/m-p/1877726#M490012</guid>
      <dc:creator>suthakar sundaralingam</dc:creator>
      <dc:date>2011-12-29T04:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 Configuration issue</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-configuration-issue/m-p/1877727#M490025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the configuration you provided we cannot see the following line&lt;/P&gt;&lt;P&gt;access-list permit outside_access_in tcp any host 30.30.0.50 eq 110&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if you say is there you got to be right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So lets do the following packet tracer and see the result, then based on that we will create some captures&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input outside tcp 4.2.2.2 1025 30.30.0.50 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do please rate helpful posts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Dec 2011 06:26:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-configuration-issue/m-p/1877727#M490025</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-29T06:26:00Z</dc:date>
    </item>
  </channel>
</rss>

