<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with ASA 5505 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-asa-5505/m-p/1768248#M532250</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA Version 7.2(4) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;domain-name cvnatural.local&lt;/P&gt;&lt;P&gt;enable password 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 189.11.**.*** oi234&lt;/P&gt;&lt;P&gt;name 172.16.0.140 local&lt;/P&gt;&lt;P&gt;name 189.11.**.*** oi235 description oi235&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address local 255.255.252.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address oi234 255.255.255.248 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan13&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; nameif inativo&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan23&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan33&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; switchport access vlan 23&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; switchport access vlan 33&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt; switchport access vlan 13&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt; switchport access vlan 13&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt; switchport access vlan 13&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt; switchport access vlan 13&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;banner exec&amp;nbsp; CRV - ACESSO RESTRITO&lt;/P&gt;&lt;P&gt;banner login&amp;nbsp; CRV - ACESSO RESTRITO&lt;/P&gt;&lt;P&gt;banner motd&amp;nbsp; CRV - ACESSO RESTRITO&lt;/P&gt;&lt;P&gt;banner asdm&amp;nbsp; CRV - ACESSO RESTRITO&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone BRST -3&lt;/P&gt;&lt;P&gt;clock summer-time BRDT recurring 2 Sun Oct 0:00 3 Sun Feb 0:00&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name cvnatural.local&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object-group protocol TCPUDP&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_1 tcp&lt;/P&gt;&lt;P&gt; port-object eq ftp&lt;/P&gt;&lt;P&gt; port-object eq ftp-data&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_2 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;access-list CRV_splitTunnelAcl standard permit any &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip any 172.16.0.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 172.16.0.0 255.255.252.0 any &lt;/P&gt;&lt;P&gt;access-list inside_access_in remark DNS&lt;/P&gt;&lt;P&gt;access-list inside_access_in remark SMTP&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit udp 172.16.0.0 255.255.252.0 any &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp 172.16.0.0 255.255.252.0 any &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip 172.16.0.0 255.255.252.0 any &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip interface outside 172.16.0.0 255.255.252.0 &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp interface outside 172.16.0.0 255.255.252.0 &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit udp interface outside 172.16.0.0 255.255.252.0 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group TCPUDP any any eq www &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 81 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq https &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq domain &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip 172.16.0.0 255.255.252.0 interface outside &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group TCPUDP 172.16.0.0 255.255.252.0 interface outside &lt;/P&gt;&lt;P&gt;access-list crv standard permit any &lt;/P&gt;&lt;P&gt;access-list outside_1_cryptomap extended permit ip 172.16.0.0 255.255.252.0 any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging buffered alerts&lt;/P&gt;&lt;P&gt;logging trap alerts&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inativo 1500&lt;/P&gt;&lt;P&gt;ip local pool CRV 172.16.3.150-172.16.3.160 mask 255.255.252.0&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;monitor-interface inside&lt;/P&gt;&lt;P&gt;monitor-interface outside&lt;/P&gt;&lt;P&gt;monitor-interface inativo&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-524.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 1 172.16.0.0 255.255.252.0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface www 172.16.0.22 www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface sip 172.16.0.102 sip netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp oi235 www 172.16.0.4 www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 189.11.**.*** 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 172.16.0.0 255.255.252.0 inside&lt;/P&gt;&lt;P&gt;http 201.22.57.115 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;http 200.146.84.147 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;sysopt connection tcpmss 0&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 20 set pfs &lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 match address outside_1_cryptomap&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set pfs group1&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set peer 187.16.33.130 &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;crypto isakmp enable inside&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash md5&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;crypto isakmp nat-traversal&amp;nbsp; 20&lt;/P&gt;&lt;P&gt;crypto isakmp ipsec-over-tcp port 10000 &lt;/P&gt;&lt;P&gt;vpn-sessiondb max-session-limit 25&lt;/P&gt;&lt;P&gt;telnet 172.16.0.0 255.255.252.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 172.16.0.0 255.255.252.0 inside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt; port 444&lt;/P&gt;&lt;P&gt; enable inside&lt;/P&gt;&lt;P&gt;group-policy CRV internal&lt;/P&gt;&lt;P&gt;group-policy CRV attributes&lt;/P&gt;&lt;P&gt; dns-server value 172.16.0.253 172.16.0.19&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec l2tp-ipsec webvpn&lt;/P&gt;&lt;P&gt; group-lock value CRV&lt;/P&gt;&lt;P&gt; ipsec-udp enable&lt;/P&gt;&lt;P&gt; ipsec-udp-port 10000&lt;/P&gt;&lt;P&gt; split-tunnel-policy excludespecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list none&lt;/P&gt;&lt;P&gt; nem enable&lt;/P&gt;&lt;P&gt;username luis password QYp.GVVJsgLuHoKE encrypted&lt;/P&gt;&lt;P&gt;username master password Z4lv47kJo.V6M7HB encrypted&lt;/P&gt;&lt;P&gt;tunnel-group DefaultL2LGroup ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group CRV type ipsec-ra&lt;/P&gt;&lt;P&gt;tunnel-group CRV general-attributes&lt;/P&gt;&lt;P&gt; dhcp-server 172.16.0.253&lt;/P&gt;&lt;P&gt;tunnel-group CRV ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group CRV ppp-attributes&lt;/P&gt;&lt;P&gt; authentication pap&lt;/P&gt;&lt;P&gt; authentication ms-chap-v2&lt;/P&gt;&lt;P&gt; authentication eap-proxy&lt;/P&gt;&lt;P&gt;tunnel-group 187.16.33.130 type ipsec-l2l&lt;/P&gt;&lt;P&gt;tunnel-group 187.16.33.130 ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;Cryptochecksum:14b4c4e2494f30db95c157d8727f8279&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Aug 2011 13:37:47 GMT</pubDate>
    <dc:creator>eduardodewes</dc:creator>
    <dc:date>2011-08-29T13:37:47Z</dc:date>
    <item>
      <title>Problem with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-5505/m-p/1768247#M532249</link>
      <description>&lt;P&gt;Hello, I have an ASA 5505, firmware 7.2 (4). Configured ACLs, NAT, it's all working, but after a while it seems that running crashes, no longer makes the directions of NATs, the logs until they stop working. To resolve, I have to restart the ASA, and everything will work again. Could it be a firmware problem, someone has had a similar problem?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-5505/m-p/1768247#M532249</guid>
      <dc:creator>eduardodewes</dc:creator>
      <dc:date>2019-03-11T21:18:07Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-5505/m-p/1768248#M532250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA Version 7.2(4) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;domain-name cvnatural.local&lt;/P&gt;&lt;P&gt;enable password 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 189.11.**.*** oi234&lt;/P&gt;&lt;P&gt;name 172.16.0.140 local&lt;/P&gt;&lt;P&gt;name 189.11.**.*** oi235 description oi235&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address local 255.255.252.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address oi234 255.255.255.248 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan13&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; nameif inativo&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan23&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan33&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; switchport access vlan 23&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; switchport access vlan 33&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt; switchport access vlan 13&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt; switchport access vlan 13&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt; switchport access vlan 13&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt; switchport access vlan 13&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;banner exec&amp;nbsp; CRV - ACESSO RESTRITO&lt;/P&gt;&lt;P&gt;banner login&amp;nbsp; CRV - ACESSO RESTRITO&lt;/P&gt;&lt;P&gt;banner motd&amp;nbsp; CRV - ACESSO RESTRITO&lt;/P&gt;&lt;P&gt;banner asdm&amp;nbsp; CRV - ACESSO RESTRITO&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone BRST -3&lt;/P&gt;&lt;P&gt;clock summer-time BRDT recurring 2 Sun Oct 0:00 3 Sun Feb 0:00&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name cvnatural.local&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object-group protocol TCPUDP&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_1 tcp&lt;/P&gt;&lt;P&gt; port-object eq ftp&lt;/P&gt;&lt;P&gt; port-object eq ftp-data&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_2 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt;access-list CRV_splitTunnelAcl standard permit any &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip any 172.16.0.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 172.16.0.0 255.255.252.0 any &lt;/P&gt;&lt;P&gt;access-list inside_access_in remark DNS&lt;/P&gt;&lt;P&gt;access-list inside_access_in remark SMTP&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit udp 172.16.0.0 255.255.252.0 any &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp 172.16.0.0 255.255.252.0 any &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip 172.16.0.0 255.255.252.0 any &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip interface outside 172.16.0.0 255.255.252.0 &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp interface outside 172.16.0.0 255.255.252.0 &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit udp interface outside 172.16.0.0 255.255.252.0 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group TCPUDP any any eq www &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 81 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq https &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq domain &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip 172.16.0.0 255.255.252.0 interface outside &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group TCPUDP 172.16.0.0 255.255.252.0 interface outside &lt;/P&gt;&lt;P&gt;access-list crv standard permit any &lt;/P&gt;&lt;P&gt;access-list outside_1_cryptomap extended permit ip 172.16.0.0 255.255.252.0 any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging buffered alerts&lt;/P&gt;&lt;P&gt;logging trap alerts&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inativo 1500&lt;/P&gt;&lt;P&gt;ip local pool CRV 172.16.3.150-172.16.3.160 mask 255.255.252.0&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;monitor-interface inside&lt;/P&gt;&lt;P&gt;monitor-interface outside&lt;/P&gt;&lt;P&gt;monitor-interface inativo&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-524.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 1 172.16.0.0 255.255.252.0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface www 172.16.0.22 www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface sip 172.16.0.102 sip netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp oi235 www 172.16.0.4 www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 189.11.**.*** 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 172.16.0.0 255.255.252.0 inside&lt;/P&gt;&lt;P&gt;http 201.22.57.115 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;http 200.146.84.147 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;sysopt connection tcpmss 0&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 20 set pfs &lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-MD5&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 match address outside_1_cryptomap&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set pfs group1&lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set peer 187.16.33.130 &lt;/P&gt;&lt;P&gt;crypto map outside_map 1 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;crypto isakmp enable inside&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt; hash md5&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;crypto isakmp nat-traversal&amp;nbsp; 20&lt;/P&gt;&lt;P&gt;crypto isakmp ipsec-over-tcp port 10000 &lt;/P&gt;&lt;P&gt;vpn-sessiondb max-session-limit 25&lt;/P&gt;&lt;P&gt;telnet 172.16.0.0 255.255.252.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 172.16.0.0 255.255.252.0 inside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt; port 444&lt;/P&gt;&lt;P&gt; enable inside&lt;/P&gt;&lt;P&gt;group-policy CRV internal&lt;/P&gt;&lt;P&gt;group-policy CRV attributes&lt;/P&gt;&lt;P&gt; dns-server value 172.16.0.253 172.16.0.19&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec l2tp-ipsec webvpn&lt;/P&gt;&lt;P&gt; group-lock value CRV&lt;/P&gt;&lt;P&gt; ipsec-udp enable&lt;/P&gt;&lt;P&gt; ipsec-udp-port 10000&lt;/P&gt;&lt;P&gt; split-tunnel-policy excludespecified&lt;/P&gt;&lt;P&gt; split-tunnel-network-list none&lt;/P&gt;&lt;P&gt; nem enable&lt;/P&gt;&lt;P&gt;username luis password QYp.GVVJsgLuHoKE encrypted&lt;/P&gt;&lt;P&gt;username master password Z4lv47kJo.V6M7HB encrypted&lt;/P&gt;&lt;P&gt;tunnel-group DefaultL2LGroup ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group CRV type ipsec-ra&lt;/P&gt;&lt;P&gt;tunnel-group CRV general-attributes&lt;/P&gt;&lt;P&gt; dhcp-server 172.16.0.253&lt;/P&gt;&lt;P&gt;tunnel-group CRV ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;tunnel-group CRV ppp-attributes&lt;/P&gt;&lt;P&gt; authentication pap&lt;/P&gt;&lt;P&gt; authentication ms-chap-v2&lt;/P&gt;&lt;P&gt; authentication eap-proxy&lt;/P&gt;&lt;P&gt;tunnel-group 187.16.33.130 type ipsec-l2l&lt;/P&gt;&lt;P&gt;tunnel-group 187.16.33.130 ipsec-attributes&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;Cryptochecksum:14b4c4e2494f30db95c157d8727f8279&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Aug 2011 13:37:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-5505/m-p/1768248#M532250</guid>
      <dc:creator>eduardodewes</dc:creator>
      <dc:date>2011-08-29T13:37:47Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-5505/m-p/1768249#M532251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Eduardo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whenever the device stops passing traffic, I would suggest you to kindly take captures on the firewall, to check if the request is going through the ASA and if you are able to get any reply back from the ISP device. Because I had a previous experience where in the ISP device was losing the arp entries aftemr every fixed time and the resolution was to create static arp for the ASA on the ISP device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For taking captures:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-1222"&gt;https://supportforums.cisco.com/docs/DOC-1222&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Aug 2011 18:02:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-5505/m-p/1768249#M532251</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-29T18:02:05Z</dc:date>
    </item>
  </channel>
</rss>

