<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing traffic and setting rules 101 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717940#M534483</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually I found out that problem too LOL...&amp;nbsp; I had other interfaces on those two machines allowing me to remote connect without issues while I was configuring my router remotely...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything seems to be working as it should now.&amp;nbsp; Thanks for all your help guys!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Aug 2011 21:32:31 GMT</pubDate>
    <dc:creator>Arvo Bowen</dc:creator>
    <dc:date>2011-08-02T21:32:31Z</dc:date>
    <item>
      <title>Routing traffic and setting rules 101</title>
      <link>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717931#M534474</link>
      <description>&lt;P&gt;I have been at this for days and still can not seem to grasp why it will not work for me.&amp;nbsp; First things first...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG style="text-decoration: underline; "&gt;Layout of my network:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/6/7/1/55176-Network%20Layout%20Example.png" alt="Network Layout Example.png" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG style="text-decoration: underline; "&gt;Current Config:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;ASA Version 7.2(4)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ACS-000-ROU2&lt;/P&gt;&lt;P&gt;domain-name ACS-ATLANTA.LOCAL&lt;/P&gt;&lt;P&gt;enable password xxxxxxxxxxxxxxxx encrypted&lt;/P&gt;&lt;P&gt;passwd xxxxxxxxxxxxxxxxx encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 10.71.1.3 ACS-000-ADS1&lt;/P&gt;&lt;P&gt;name 10.71.5.2 ACS-000-FTP1&lt;/P&gt;&lt;P&gt;name 10.71.1.0 ACS_Atlanta_LAN&lt;/P&gt;&lt;P&gt;name 10.71.5.0 ACS_FTP_DMZ&lt;/P&gt;&lt;P&gt;name 12.125.10.192 Public_Internet_Subnet&lt;/P&gt;&lt;P&gt;name 10.71.5.1 Router_FTP_DMZ_IP&lt;/P&gt;&lt;P&gt;name 12.125.10.206 PublicFTPIP&lt;/P&gt;&lt;P&gt;name 12.125.10.204 PublicRouterIP&lt;/P&gt;&lt;P&gt;name 10.71.1.1 Router_ACS_LAN_IP&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; description ACS Atlanta LAN&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address Router_ACS_LAN_IP 255.255.255.0&lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan11&lt;/P&gt;&lt;P&gt; description Outside - Public internet&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address PublicRouterIP 255.255.255.224&lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan21&lt;/P&gt;&lt;P&gt; description ACS Atlanta FTP DMZ&lt;/P&gt;&lt;P&gt; nameif dmz_ftp&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address Router_FTP_DMZ_IP 255.255.255.0&lt;/P&gt;&lt;P&gt; ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 11&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; switchport access vlan 21&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; switchport access vlan 31&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt; switchport access vlan 31&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt; switchport access vlan 31&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt; switchport access vlan 31&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt; switchport access vlan 31&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns domain-lookup dmz_ftp&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server ACS-000-ADS1&lt;/P&gt;&lt;P&gt; domain-name ACS-ATLANTA.LOCAL&lt;/P&gt;&lt;P&gt;object-group icmp-type debug_network&lt;/P&gt;&lt;P&gt; description Pings, Traceroutes, Etc...&lt;/P&gt;&lt;P&gt; icmp-object echo&lt;/P&gt;&lt;P&gt; icmp-object echo-reply&lt;/P&gt;&lt;P&gt; icmp-object time-exceeded&lt;/P&gt;&lt;P&gt; icmp-object traceroute&lt;/P&gt;&lt;P&gt; icmp-object unreachable&lt;/P&gt;&lt;P&gt;object-group protocol TCPUDP&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_1 tcp&lt;/P&gt;&lt;P&gt; port-object eq domain&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt;object-group service rdp tcp&lt;/P&gt;&lt;P&gt; description Remote Desktop Protocall&lt;/P&gt;&lt;P&gt; port-object eq 3389&lt;/P&gt;&lt;P&gt;access-list dmz_ftp_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list dmz_ftp_access_in extended permit icmp any any object-group debug_netwrk&lt;/P&gt;&lt;P&gt;access-list dmz_ftp_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list dmz_ftp_access_in extended permit tcp ACS_FTP_DMZ 255.255.255.0 host Ruter_FTP_DMZ_IP eq domain inactive&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit icmp any any object-group debug_netwok&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit object-group TCPUDP ACS_Atlanta_LAN 25.255.255.0 any eq www&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit object-group TCPUDP ACS_Atlanta_LAN 25.255.255.0 any eq domain&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit icmp ACS_Atlanta_LAN 255.255.255.0 an object-group debug_network inactive&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark new - ftp access to dmz&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host PublicFTPIP eq ftp inacive&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark new - Remote Desktop Access&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host PublicFTPIP object-grou rdp inactive&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu dmz_ftp 1500&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-524.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (inside) 1 interface&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 ACS_Atlanta_LAN 255.255.255.0&lt;/P&gt;&lt;P&gt;static (inside,dmz_ftp) ACS_Atlanta_LAN ACS_Atlanta_LAN netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;access-group dmz_ftp_access_in in interface dmz_ftp&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 12.125.10.193 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;router rip&lt;/P&gt;&lt;P&gt; passive-interface outside&lt;/P&gt;&lt;P&gt; version 2&lt;/P&gt;&lt;P&gt; no auto-summary&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http ACS_Atlanta_LAN 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh scopy enable&lt;/P&gt;&lt;P&gt;ssh ACS_Atlanta_LAN 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;ssh timeout 60&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username Administrator password xxxxxxxxxxxx encrypted privilege 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG style="text-decoration: underline; "&gt;&lt;STRONG style="text-decoration: underline; "&gt;Issue:&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I'm currently trying to get my DMZed FTP server to be able to talk to the Local LAN (inside) allowing just IMCP (pinging).&amp;nbsp; I have tried many many configs and nothing I do seems to be working.&amp;nbsp; I think it has something to do with the NAT rules but not 100% positive.&amp;nbsp; Any ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:06:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717931#M534474</guid>
      <dc:creator>Arvo Bowen</dc:creator>
      <dc:date>2019-03-11T21:06:33Z</dc:date>
    </item>
    <item>
      <title>Routing traffic and setting rules 101</title>
      <link>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717932#M534475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Arvo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz_ftp) &lt;IP of="" local="" lan=""&gt; &lt;IP of="" local="" lan=""&gt;&lt;/IP&gt;&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (dmz_ftp) 2 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;global (inside) 2 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if this still doesn't work then, take th output of :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input dmz_ftp icmp &lt;IP of="" ftp=""&gt; 8 0 &lt;IP of="" local="" lan=""&gt; detailed&lt;/IP&gt;&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also you would need a route :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 0.0.0.0 0.0.0.0 &lt;NEXT hop="" for="" asa=""&gt; 1&lt;/NEXT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Aug 2011 16:09:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717932#M534475</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-01T16:09:29Z</dc:date>
    </item>
    <item>
      <title>Routing traffic and setting rules 101</title>
      <link>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717933#M534476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Varun &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;static (inside,dmz_ftp) &lt;IP of="" local="" lan=""&gt; &lt;IP of="" local="" lan=""&gt;&lt;/IP&gt;&lt;/IP&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that is actually in there, the config is just using names in the static.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;route inside 0.0.0.0 0.0.0.0 &lt;NEXT hop="" for="" asa=""&gt; 1&lt;/NEXT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the 10.71.1.x is directly connected so it wouldn't need a route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nat (dmz_ftp) 2 0.0.0.0 0.0.0.0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;global (inside) 2 interface&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you explain this for my clarification because as i asked in the other thread, why do you need this as you don't need to nat internet addresses coming in from outside to either a dmz or the inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Aug 2011 16:19:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717933#M534476</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2011-08-01T16:19:50Z</dc:date>
    </item>
    <item>
      <title>Routing traffic and setting rules 101</title>
      <link>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717934#M534477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Was that a question for Varun?&amp;nbsp; &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Aug 2011 16:52:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717934#M534477</guid>
      <dc:creator>Arvo Bowen</dc:creator>
      <dc:date>2011-08-01T16:52:25Z</dc:date>
    </item>
    <item>
      <title>Routing traffic and setting rules 101</title>
      <link>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717935#M534478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Arvo &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes it was.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Aug 2011 16:53:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717935#M534478</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2011-08-01T16:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Routing traffic and setting rules 101</title>
      <link>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717936#M534479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since your inside and dmz interfaces are set for the same security level, wouldn't you need to run the 'same-security-traffic permit inter-interface' command to allow the traffic to pass?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Aug 2011 03:23:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717936#M534479</guid>
      <dc:creator>creggerd</dc:creator>
      <dc:date>2011-08-02T03:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: Routing traffic and setting rules 101</title>
      <link>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717937#M534480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Opps!!!&amp;nbsp; I didn't mean for the dmz_ftp to be security level 100 &lt;SPAN __jive_emoticon_name="blush" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ment to have it at 50...&amp;nbsp; But I was trying to avoid depending on any of the security levels for rules...&amp;nbsp; The ASDM removed the rules allowing the interfaces to talk to the lower security interfaces as soon as I set up my first rule anyway...&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Aug 2011 16:39:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717937#M534480</guid>
      <dc:creator>Arvo Bowen</dc:creator>
      <dc:date>2011-08-02T16:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Routing traffic and setting rules 101</title>
      <link>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717938#M534481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;BR /&gt;Creggerd wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since your inside and dmz interfaces are set for the same security level, wouldn't you need to run the 'same-security-traffic permit inter-interface' command to allow the traffic to pass?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;Credderd,&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&amp;nbsp; When I add that rule though I now get a new deny message...&amp;nbsp; &lt;/P&gt;&lt;DIV&gt;2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Aug 02 2011&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;12:40:17&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;106016&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Deny IP spoof from (ACS-000-FTP1) to Router_ACS_LAN_IP on interface dmz_ftp&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;It used to just say denied packet, now it says IP spoof...&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Aug 2011 16:44:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717938#M534481</guid>
      <dc:creator>Arvo Bowen</dc:creator>
      <dc:date>2011-08-02T16:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Routing traffic and setting rules 101</title>
      <link>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717939#M534482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok so an update...&amp;nbsp; I got all of the issues above worked out thanks to creggerd's comment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found out that if both the &lt;STRONG&gt;inside&lt;/STRONG&gt; and &lt;STRONG&gt;dmz&lt;/STRONG&gt; are the same security level then you MUST use...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;STRONG&gt;same-security-traffic permit inter-interface&lt;/STRONG&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...to allow the traffic to flow from the interfaces.&amp;nbsp; In my case I ended up NOT using that setting and simply setting the dmz vlan to security level &lt;STRONG&gt;50&lt;/STRONG&gt; and keeping the inside at &lt;STRONG&gt;100&lt;/STRONG&gt;.&amp;nbsp; That along with the nat rule...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (inside,dmz_ftp) 10.71.1.0 10.71.1.0 netmask 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...My traffic started flowing nicely!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now on to something else...&amp;nbsp; Same config but I have an issue with my security rules...&amp;nbsp; I have &lt;STRONG&gt;NO &lt;/STRONG&gt;rules at all in the security policy area yet I can go strait through the router with my FTP server (10.71.5.2) and browse a share on my AD Server (10.71.1.3).&amp;nbsp; The funny thing is I can control traceroutes, pings, dns, http (or so it seems at least) traffic by creating rules to allow that type of traffic.&amp;nbsp; When I delete those rules the traffic is no longer aloud through (this is what I expect).&amp;nbsp; But for some reason it lets windows domain shares have all the traffic it wants...&amp;nbsp; &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Aug 2011 21:23:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717939#M534482</guid>
      <dc:creator>Arvo Bowen</dc:creator>
      <dc:date>2011-08-02T21:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: Routing traffic and setting rules 101</title>
      <link>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717940#M534483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually I found out that problem too LOL...&amp;nbsp; I had other interfaces on those two machines allowing me to remote connect without issues while I was configuring my router remotely...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything seems to be working as it should now.&amp;nbsp; Thanks for all your help guys!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Aug 2011 21:32:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717940#M534483</guid>
      <dc:creator>Arvo Bowen</dc:creator>
      <dc:date>2011-08-02T21:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: Routing traffic and setting rules 101</title>
      <link>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717941#M534484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad I was able to help!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Aug 2011 01:41:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/routing-traffic-and-setting-rules-101/m-p/1717941#M534484</guid>
      <dc:creator>creggerd</dc:creator>
      <dc:date>2011-08-03T01:41:21Z</dc:date>
    </item>
  </channel>
</rss>

