<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic help in ASA configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703206#M535741</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;route are&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA#&amp;nbsp; route outside 0.0.0.0 0.0.0.0 192.168.100.1 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server# IP=10.34.249.35&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DG gateway is: 192.168.5.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;juniper int 10.34.249.0 is directly connted to ASA e2 interface&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Jul 2011 07:10:15 GMT</pubDate>
    <dc:creator>pawanharlecisco</dc:creator>
    <dc:date>2011-07-19T07:10:15Z</dc:date>
    <item>
      <title>help in ASA configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703199#M535719</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Please go thorugh my daigram.&amp;nbsp; ip want to assign 10.34.249.34,10.34.249.35,10.34.249.36 ip address directly to servers and this server would be accesable from 20.20.20.20 HQ router.&lt;/P&gt;&lt;P&gt;and if server want to go to internet then it would use 192.168.100.1 bsnl access internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me , i have not yet configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Pawan&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:00:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703199#M535719</guid>
      <dc:creator>pawanharlecisco</dc:creator>
      <dc:date>2019-03-11T21:00:10Z</dc:date>
    </item>
    <item>
      <title>help in ASA configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703200#M535722</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pawan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No issues with that, you would need the following config, let say e0/2 interface is named "juniper", then: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;lets say you want to access the servers from there real ip only:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,juniper) 10.34.249.34 10.34.249.34&lt;/P&gt;&lt;P&gt;static (inside,juniper) 10.34.249.35 10.34.249.35&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,juniper) 10.34.249.36 10.34.249.36&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and for internet access:&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.34.249.0 255.255.255.0&lt;/P&gt;&lt;P&gt;global (bsnl) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thats it,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 02:18:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703200#M535722</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-19T02:18:42Z</dc:date>
    </item>
    <item>
      <title>help in ASA configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703201#M535727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thnx sir.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; please tell me, what will the gateway of server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 04:44:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703201#M535727</guid>
      <dc:creator>pawanharlecisco</dc:creator>
      <dc:date>2011-07-19T04:44:19Z</dc:date>
    </item>
    <item>
      <title>help in ASA configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703202#M535732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The gateway for the server would be the ASA inisde interface or if the switch is an L3 switch, it would be the switch interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;-Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 04:55:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703202#M535732</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-19T04:55:47Z</dc:date>
    </item>
    <item>
      <title>help in ASA configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703203#M535736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sir,&lt;/P&gt;&lt;P&gt;it is not working..&lt;/P&gt;&lt;P&gt;Server to juniper and juniper to server:shows request time out.&lt;/P&gt;&lt;P&gt;server to bsnl modem: show request time out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please find the config below, and suggest me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;pawan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 192.168.100.200 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.5.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet2&lt;/P&gt;&lt;P&gt; nameif juniper&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 10.34.249.50 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet4&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;access-list outside-in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list outside-in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list 101 extended permit ip any host 10.34.249.35&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu juniper 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.34.249.0 255.255.255.0&lt;/P&gt;&lt;P&gt;static (inside,juniper) 10.34.249.35 10.34.249.35 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,juniper) 10.34.249.36 10.34.249.36 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-group outside-in in interface outside&lt;/P&gt;&lt;P&gt;access-group 101 in interface juniper&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.100.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;Cryptochecksum:00000000000000000000000000000000&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 05:58:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703203#M535736</guid>
      <dc:creator>pawanharlecisco</dc:creator>
      <dc:date>2011-07-19T05:58:37Z</dc:date>
    </item>
    <item>
      <title>help in ASA configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703204#M535737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take captures for both the traffics:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list cap permit ip host 10.34.249.35 host 192.168.100.1&lt;/P&gt;&lt;P&gt;access-list cap permit ip host 192.168.100.1 host 10.34.249.35 &lt;/P&gt;&lt;P&gt;access-list cap permit ip host 192.168.100.1 host 192.168.100.200&lt;/P&gt;&lt;P&gt;access-list cap permit ip host 192.168.100.200 host 192.168.100.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cap capo access-list cap interface outside&lt;/P&gt;&lt;P&gt;cap capin access-list cap interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for server to inside:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;add the following:&lt;/P&gt;&lt;P&gt;global (juniper) 1 interface&lt;/P&gt;&lt;P&gt;access-list 101 extended permit icmp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list cap1 permit ip host 10.34.249.35 host 20.20.20.20&lt;/P&gt;&lt;P&gt;access-list cap1 permit ip host 20.20.20.20 host 10.34.249.35 &lt;/P&gt;&lt;P&gt;access-list cap1 permit ip host 10.34.249.50 host 20.20.20.20&lt;/P&gt;&lt;P&gt;access-list cap1 permit ip host 20.20.20.20 host 10.34.249.50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cap capjun access-list cap1 interface juniper&lt;/P&gt;&lt;P&gt;cap capi access-list cap1 interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After doing this config, initiate pings and then collect these captures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the logs on the ASA, why it is denying traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/docs/DOC-17345"&gt;https://supportforums.cisco.com/docs/DOC-17345#comment-8416&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 06:34:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703204#M535737</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-19T06:34:33Z</dc:date>
    </item>
    <item>
      <title>help in ASA configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703205#M535739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA# sh capture&lt;/P&gt;&lt;P&gt;capture cap type raw-data [Capturing - 0 bytes]&lt;/P&gt;&lt;P&gt;capture capo type raw-data access-list cap interface outside [Capturing - 0 bytes]&lt;/P&gt;&lt;P&gt;capture capin type raw-data access-list cap interface inside [Capturing - 0 bytes]&lt;/P&gt;&lt;P&gt;capture capjun type raw-data access-list cap1 interface juniper [Capturing - 0 bytes]&lt;/P&gt;&lt;P&gt;capture capi type raw-data access-list cap1 interface inside [Capturing - 0 bytes]&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 07:01:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703205#M535739</guid>
      <dc:creator>pawanharlecisco</dc:creator>
      <dc:date>2011-07-19T07:01:48Z</dc:date>
    </item>
    <item>
      <title>help in ASA configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703206#M535741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;route are&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA#&amp;nbsp; route outside 0.0.0.0 0.0.0.0 192.168.100.1 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server# IP=10.34.249.35&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DG gateway is: 192.168.5.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;juniper int 10.34.249.0 is directly connted to ASA e2 interface&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 07:10:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703206#M535741</guid>
      <dc:creator>pawanharlecisco</dc:creator>
      <dc:date>2011-07-19T07:10:15Z</dc:date>
    </item>
    <item>
      <title>help in ASA configuration</title>
      <link>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703207#M535742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sir please help me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jul 2011 09:01:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-in-asa-configuration/m-p/1703207#M535742</guid>
      <dc:creator>pawanharlecisco</dc:creator>
      <dc:date>2011-07-19T09:01:48Z</dc:date>
    </item>
  </channel>
</rss>

