<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Migrating from a PIX to ASA. Access lists don't work.. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/migrating-from-a-pix-to-asa-access-lists-don-t-work/m-p/1752978#M533384</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very good point Varun! But wouldn't I still see the traffic going to .137 in a capture? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had to roll back and add the pix back since this is for an email server. I will try again tomorrow&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Aug 2011 18:19:21 GMT</pubDate>
    <dc:creator>jomar050485</dc:creator>
    <dc:date>2011-08-16T18:19:21Z</dc:date>
    <item>
      <title>Migrating from a PIX to ASA. Access lists don't work..</title>
      <link>https://community.cisco.com/t5/network-security/migrating-from-a-pix-to-asa-access-lists-don-t-work/m-p/1752976#M533381</link>
      <description>&lt;P&gt;Not sure why it doesn't work...I even created a capture of any any and the ASA doesn't even see the traffic to .137. It does see traffic to .136. As far as I can see, the config is identical. Packet Tracer says my config is good. Internet connectivity is good but I can't hit anything on .137. I have verified that the internal host is indeed open on those ports (as it works when the pix is in place and not when the asa is in place)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can a fresh set of eyes help me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the old pix config (firewallpix.txt), the new asa config (asa.txt) and the results of packet tracer (packettracer.txt)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advanced!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:12:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrating-from-a-pix-to-asa-access-lists-don-t-work/m-p/1752976#M533381</guid>
      <dc:creator>jomar050485</dc:creator>
      <dc:date>2019-03-11T21:12:41Z</dc:date>
    </item>
    <item>
      <title>Migrating from a PIX to ASA. Access lists don't work..</title>
      <link>https://community.cisco.com/t5/network-security/migrating-from-a-pix-to-asa-access-lists-don-t-work/m-p/1752977#M533382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jomar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You migt just need to reload all the device, so that the arp tables are cleared and neqw arp entry for your ASA is craeted, try it and let me know if it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2011 18:08:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrating-from-a-pix-to-asa-access-lists-don-t-work/m-p/1752977#M533382</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-16T18:08:40Z</dc:date>
    </item>
    <item>
      <title>Migrating from a PIX to ASA. Access lists don't work..</title>
      <link>https://community.cisco.com/t5/network-security/migrating-from-a-pix-to-asa-access-lists-don-t-work/m-p/1752978#M533384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very good point Varun! But wouldn't I still see the traffic going to .137 in a capture? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had to roll back and add the pix back since this is for an email server. I will try again tomorrow&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2011 18:19:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrating-from-a-pix-to-asa-access-lists-don-t-work/m-p/1752978#M533384</guid>
      <dc:creator>jomar050485</dc:creator>
      <dc:date>2011-08-16T18:19:21Z</dc:date>
    </item>
    <item>
      <title>Migrating from a PIX to ASA. Access lists don't work..</title>
      <link>https://community.cisco.com/t5/network-security/migrating-from-a-pix-to-asa-access-lists-don-t-work/m-p/1752979#M533387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, if the router still has the arp entrues for the pix device then you would not even see the packets reaching the ASA interface, so yes the captures are correct. The router woudl not know which interface to route the packets without the correct mac-address entry into the table. I am very positive this hould resolve it for you. You can try it and let me know the result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2011 18:22:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrating-from-a-pix-to-asa-access-lists-don-t-work/m-p/1752979#M533387</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-16T18:22:38Z</dc:date>
    </item>
    <item>
      <title>Migrating from a PIX to ASA. Access lists don't work..</title>
      <link>https://community.cisco.com/t5/network-security/migrating-from-a-pix-to-asa-access-lists-don-t-work/m-p/1752980#M533389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Varun.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no router involved though. Do you mean the ISP router? I can't clear those ARP entries. The ASA is directly connected to the smartjack.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2011 19:27:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrating-from-a-pix-to-asa-access-lists-don-t-work/m-p/1752980#M533389</guid>
      <dc:creator>jomar050485</dc:creator>
      <dc:date>2011-08-16T19:27:06Z</dc:date>
    </item>
    <item>
      <title>Migrating from a PIX to ASA. Access lists don't work..</title>
      <link>https://community.cisco.com/t5/network-security/migrating-from-a-pix-to-asa-access-lists-don-t-work/m-p/1752981#M533390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You were correct. Client informed me of a modem that was on site. Once we restarted it, everything went well!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the insight!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Aug 2011 16:23:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrating-from-a-pix-to-asa-access-lists-don-t-work/m-p/1752981#M533390</guid>
      <dc:creator>jomar050485</dc:creator>
      <dc:date>2011-08-17T16:23:19Z</dc:date>
    </item>
    <item>
      <title>Migrating from a PIX to ASA. Access lists don't work..</title>
      <link>https://community.cisco.com/t5/network-security/migrating-from-a-pix-to-asa-access-lists-don-t-work/m-p/1752982#M533391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad it work well for you &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;, thanks for the rating.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Aug 2011 16:29:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migrating-from-a-pix-to-asa-access-lists-don-t-work/m-p/1752982#M533391</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-17T16:29:26Z</dc:date>
    </item>
  </channel>
</rss>

