<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall ASA Blocking ftp session in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672364#M536094</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Dear Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the ftp mode is here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ga-asa-fw01# sh run ftp&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;ga-asa-fw01#&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;ga-asa-fw01# sh run ftp&lt;BR /&gt;ftp mode passive&lt;BR /&gt;ga-asa-fw01#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Jul 2011 11:44:15 GMT</pubDate>
    <dc:creator>zain_gabon</dc:creator>
    <dc:date>2011-07-13T11:44:15Z</dc:date>
    <item>
      <title>Firewall ASA Blocking ftp session</title>
      <link>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672362#M536090</link>
      <description>&lt;P&gt;Dear Support,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a strange issue, since yesterday, my Cisco ASA not alloed ftp session.&lt;/P&gt;&lt;P&gt;when i tried a ftp on a server, i have this error message from my server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\&amp;gt;ftp 10.3.1.18&lt;/P&gt;&lt;P&gt;&amp;gt; ftp: connect :Numéro d'erreur inconnu&lt;/P&gt;&lt;P&gt;c:\&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the server 10.3.1.18 is behind the firewall in my DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;whith the packet tracer, the result is allowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:58:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672362#M536090</guid>
      <dc:creator>zain_gabon</dc:creator>
      <dc:date>2019-03-11T20:58:29Z</dc:date>
    </item>
    <item>
      <title>Firewall ASA Blocking ftp session</title>
      <link>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672363#M536091</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you provide the configuration from the firewall?? we might need to take captures as well to isolate if its an issue with the ASA or the FTP server. Moreover can u tell me if you are usind active ftp or passive ftp??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jul 2011 11:31:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672363#M536091</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-13T11:31:26Z</dc:date>
    </item>
    <item>
      <title>Firewall ASA Blocking ftp session</title>
      <link>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672364#M536094</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Dear Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the ftp mode is here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ga-asa-fw01# sh run ftp&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;ga-asa-fw01#&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;ga-asa-fw01# sh run ftp&lt;BR /&gt;ftp mode passive&lt;BR /&gt;ga-asa-fw01#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jul 2011 11:44:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672364#M536094</guid>
      <dc:creator>zain_gabon</dc:creator>
      <dc:date>2011-07-13T11:44:15Z</dc:date>
    </item>
    <item>
      <title>Firewall ASA Blocking ftp session</title>
      <link>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672365#M536096</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the information, although this is not the right information that we need, this mode is the the mode for tftp from or to the firewall, not for connection going through the firewall. I would request you to provide me the running-config from your firewall so that I can take a look at it and suggest you the correct capture commands to identify the cause. Also do you get anything on the ASA logs when the connection is denied???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jul 2011 11:56:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672365#M536096</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-13T11:56:09Z</dc:date>
    </item>
    <item>
      <title>Firewall ASA Blocking ftp session</title>
      <link>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672366#M536099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Dear Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Find my configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;: Written by enable_15 at 13:05:32.389 CA Wed Jul 13 2011&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ASA Version 8.2(2) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ga-asa-fw01&lt;/P&gt;&lt;P&gt;domain-name ga.airtel.com&lt;/P&gt;&lt;P&gt;enable password v6SfSHGPNOg9Rn4j encrypted&lt;/P&gt;&lt;P&gt;passwd 0lvchVuN4vCKANGn encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 10.3.4.0 Vlan10&lt;/P&gt;&lt;P&gt;name 192.168.12.0 Vlan12 description Users Vlan 12&lt;/P&gt;&lt;P&gt;name 10.3.4.15 LAN_DNS1&lt;/P&gt;&lt;P&gt;name 10.3.4.16 LAN_DNS2&lt;/P&gt;&lt;P&gt;name 217.113.64.1 PUBLIC_DNS1&lt;/P&gt;&lt;P&gt;name 217.113.64.2 PUBLIC_DNS2&lt;/P&gt;&lt;P&gt;name 213.208.241.41 HQSigosServer1&lt;/P&gt;&lt;P&gt;name 213.208.241.42 HQSigosServer2&lt;/P&gt;&lt;P&gt;name 213.208.241.43 HQSigosServer3&lt;/P&gt;&lt;P&gt;name 217.113.76.131 PublicIP_DMZIcsServer description ICS Public IP&lt;/P&gt;&lt;P&gt;name 10.3.1.17 DMZIcsServer description DMZ ICS Server&lt;/P&gt;&lt;P&gt;name 10.3.1.0 DMZNetwork description DMZ Network&lt;/P&gt;&lt;P&gt;name 10.3.1.18 DMZFtpServer description DMZ FTP Server&lt;/P&gt;&lt;P&gt;name 192.168.1.160 M-Commerce_160&lt;/P&gt;&lt;P&gt;name 192.168.1.188 M-Commerce_188&lt;/P&gt;&lt;P&gt;name 192.168.1.191 M-Commerce_191&lt;/P&gt;&lt;P&gt;name 192.168.1.193 M-Commerce_193&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;nameif WanInterface&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 10.10.10.10 255.255.255.224 &lt;/P&gt;&lt;P&gt;ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;speed 1000&lt;/P&gt;&lt;P&gt;duplex full&lt;/P&gt;&lt;P&gt;nameif LanInterface&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.3.4.2 255.255.252.0 &lt;/P&gt;&lt;P&gt;ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;speed 1000&lt;/P&gt;&lt;P&gt;duplex full&lt;/P&gt;&lt;P&gt;nameif DmzInterface&lt;/P&gt;&lt;P&gt;security-level 50&lt;/P&gt;&lt;P&gt;ip address 10.3.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;no security-level&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt;nameif management&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;ospf cost 10&lt;/P&gt;&lt;P&gt;management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa822-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone CA 1&lt;/P&gt;&lt;P&gt;dns domain-lookup WanInterface&lt;/P&gt;&lt;P&gt;dns domain-lookup LanInterface&lt;/P&gt;&lt;P&gt;dns domain-lookup DmzInterface&lt;/P&gt;&lt;P&gt;dns domain-lookup management&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt;name-server LAN_DNS1&lt;/P&gt;&lt;P&gt;name-server LAN_DNS2&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object-group network LanNetworks&lt;/P&gt;&lt;P&gt;network-object Vlan13 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object OfficeLANWifi 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object Vlan10 255.255.252.0&lt;/P&gt;&lt;P&gt;network-object Vlan11 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host Consultant_Ericsson&lt;/P&gt;&lt;P&gt;network-object host consultant2_ERICSSON&lt;/P&gt;&lt;P&gt;network-object host Consultant4_Africa&lt;/P&gt;&lt;P&gt;network-object host Consultant3_ERICSSON&lt;/P&gt;&lt;P&gt;network-object host Consultant-ERICSSON&lt;/P&gt;&lt;P&gt;network-object Vlan14 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object host Machine_Charly&lt;/P&gt;&lt;P&gt;network-object Vlan12 255.255.255.0&lt;/P&gt;&lt;P&gt;network-object DG-HOME 255.255.255.0&lt;/P&gt;&lt;P&gt;object-group service WEB_SERVICES&lt;/P&gt;&lt;P&gt;service-object tcp eq ftp &lt;/P&gt;&lt;P&gt;service-object tcp eq ftp-data &lt;/P&gt;&lt;P&gt;service-object tcp eq www &lt;/P&gt;&lt;P&gt;group-object web_sg&lt;/P&gt;&lt;P&gt;group-object vpn_sg&lt;/P&gt;&lt;P&gt;group-object messengers_sg&lt;/P&gt;&lt;P&gt;service-object tcp-udp eq 593 &lt;/P&gt;&lt;P&gt;service-object tcp-udp eq 6001 &lt;/P&gt;&lt;P&gt;service-object tcp-udp eq 6002 &lt;/P&gt;&lt;P&gt;service-object tcp-udp eq 6004 &lt;/P&gt;&lt;P&gt;service-object tcp-udp eq 7870 &lt;/P&gt;&lt;P&gt;service-object tcp eq ssh &lt;/P&gt;&lt;P&gt;service-object tcp eq 8 &lt;/P&gt;&lt;P&gt;service-object icmp &lt;/P&gt;&lt;P&gt;service-object icmp echo&lt;/P&gt;&lt;P&gt;service-object icmp echo-reply&lt;/P&gt;&lt;P&gt;service-object icmp traceroute&lt;/P&gt;&lt;P&gt;service-object tcp eq 3101 &lt;/P&gt;&lt;P&gt;service-object tcp eq https &lt;/P&gt;&lt;P&gt;service-object tcp eq 9450 &lt;/P&gt;&lt;P&gt;service-object udp eq 8889 &lt;/P&gt;&lt;P&gt;service-object tcp eq 8181 &lt;/P&gt;&lt;P&gt;object-group service dns_sg tcp-udp&lt;/P&gt;&lt;P&gt;port-object eq domain&lt;/P&gt;&lt;P&gt;object-group service ftp_sg tcp&lt;/P&gt;&lt;P&gt;port-object eq ftp&lt;/P&gt;&lt;P&gt;port-object eq ftp-data&lt;/P&gt;&lt;P&gt;object-group service ftp-http-ssh_sg tcp&lt;/P&gt;&lt;P&gt;port-object eq ftp&lt;/P&gt;&lt;P&gt;port-object eq ftp-data&lt;/P&gt;&lt;P&gt;port-object eq www&lt;/P&gt;&lt;P&gt;port-object eq https&lt;/P&gt;&lt;P&gt;object-group service mssql_resolver_tcp tcp&lt;/P&gt;&lt;P&gt;port-object eq 1434&lt;/P&gt;&lt;P&gt;object-group service mssql_resolver_udp udp&lt;/P&gt;&lt;P&gt;port-object eq 1434&lt;/P&gt;&lt;P&gt;object-group service mssql_tcp tcp&lt;/P&gt;&lt;P&gt;port-object eq 1433&lt;/P&gt;&lt;P&gt;object-group service mssql_udp udp&lt;/P&gt;&lt;P&gt;port-object eq 1433&lt;/P&gt;&lt;P&gt;object-group service african1_tcp tcp&lt;/P&gt;&lt;P&gt;port-object eq 8030&lt;/P&gt;&lt;P&gt;object-group service erc_mgw_sg tcp&lt;/P&gt;&lt;P&gt;port-object eq 5001&lt;/P&gt;&lt;P&gt;object-group service mvoucher_tcp tcp&lt;/P&gt;&lt;P&gt;port-object eq 1024&lt;/P&gt;&lt;P&gt;object-group service rdc_tcp tcp&lt;/P&gt;&lt;P&gt;port-object eq 3389&lt;/P&gt;&lt;P&gt;object-group service http-https_sg tcp&lt;/P&gt;&lt;P&gt;port-object eq www&lt;/P&gt;&lt;P&gt;port-object eq https&lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit object-group DM_INLINE_SERVICE_1 object-group TechMahindra any &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in remark FULL ACCESS&lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit ip object-group DM_INLINE_NETWORK_2 any &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit object-group WEB_SERVICES object-group LanNetworks any &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in remark Internal Local DNS to Public ISP DNS&lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit object-group DNS_SERVICES object-group LAN_DNS object-group PUBLIC_DNS_ISP &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit ip object-group DM_INLINE_NETWORK_5 any &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit ip object-group LanNetworks DMZNetwork 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit object-group EDCH_FTP object-group EMM_GRP_EDCH object-group DM_INLINE_NETWORK_3 &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in remark OfficeLANSigosBox any&lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit ip host OfficeLANSigosBox object-group HQSigosServerGroup &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in remark LanPlanet_to_HQPlanetEVServers&lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit ip host LAN_Planet_EV object-group HQPlanetEVServersGroup &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit ip MPBN_NETWORK 255.255.0.0 DMZNetwork 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit ip object-group RA-GABON object-group RA-AMSTERDAM &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit ip Vlan10 255.255.252.0 HQ_NETWORK 255.255.254.0 &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit ip object-group M-Commerce_Grp object-group Oberthur_Net &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit ip host ZAIN_SERVER_VPN_BGFI host BGFI_SERVER_VPN &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit ip object-group COMVIVA-LOCAL-GROUP object-group COMVIVA-REMOTE &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit ip object-group PUSHMAIL-GABON object-group PUSHMAIL-AMS &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit ip object-group NEW-GABON object-group NEW-AMSTERDAM &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit ip host COMVIVA_SMSC_26 object-group NIGERIA-GROUP-VPN &lt;/P&gt;&lt;P&gt;access-list LanInterface_access_in extended permit ip host PPSMAIN host MACH-FTP-SERVER &lt;/P&gt;&lt;P&gt;access-list DmzInterface_access_in extended permit ip DMZNetwork 255.255.255.0 any &lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in remark UniverseSMTP_to_GatewaySMTPServer &amp;amp; OutlookWebAccess&lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in extended permit tcp any host MailPublic object-group owa_sg &lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in remark Universe_to_DMZFtpServer&lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in extended permit tcp any host PublicIP_DMZFtpServer object-group ftp_sg &lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in remark Universe_to_DMZIcsServer&lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in extended permit ip object-group HQSigosServerGroup host PublicIP_DMZIcsServer &lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in remark Universe to Citrix&lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in extended permit tcp any host PublicIP_DMZIcsServer object-group DM_INLINE_TCP_3 &lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in extended permit tcp any object-group ASTELLIA_GROUP_SERVERS object-group DM_INLINE_TCP_6 &lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in extended permit object-group OTA_SERVICES host Client_OTA host PublicIP_DMZFtpServer &lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in extended permit object-group EDCH_FTP host EDCH_SERVER_VPN object-group EMM_GRP_EDCH &lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in extended permit ip object-group Oberthur_Net object-group M-Commerce_Grp &lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in extended permit object-group Monitoring host ROUTER_ISP interface WanInterface &lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in extended permit ip host BGFI_SERVER_VPN host ZAIN_SERVER_VPN_BGFI &lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in extended permit ip object-group COMVIVA-REMOTE object-group COMVIVA-LOCAL-GROUP &lt;/P&gt;&lt;P&gt;access-list WanInterface_access_in extended permit ip host MACH-FTP-SERVER host PPSMAIN &lt;/P&gt;&lt;P&gt;access-list LanInterface_nat0_outbound extended permit ip host PPSMAIN host EDCH_SERVER_VPN &lt;/P&gt;&lt;P&gt;access-list LanInterface_nat0_outbound extended permit ip object-group RA-GABON object-group RA-AMSTERDAM &lt;/P&gt;&lt;P&gt;access-list LanInterface_nat0_outbound extended permit ip Vlan10 255.255.252.0 HQ_NETWORK 255.255.254.0 &lt;/P&gt;&lt;P&gt;access-list LanInterface_nat0_outbound extended permit ip MPBN_NETWORK 255.255.0.0 DMZNetwork 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list LanInterface_nat0_outbound extended permit ip object-group M-Commerce_Grp object-group Oberthur_Net &lt;/P&gt;&lt;P&gt;access-list LanInterface_nat0_outbound extended permit ip object-group MASIYA_GROUP 192.168.4.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list LanInterface_nat0_outbound extended permit ip object-group GroupLocal_VPN 192.168.6.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list LanInterface_nat0_outbound extended permit ip Vlan10 255.255.252.0 DMZNetwork 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list LanInterface_nat0_outbound extended permit ip host ZAIN_SERVER_VPN_BGFI host BGFI_SERVER_VPN &lt;/P&gt;&lt;P&gt;access-list LanInterface_nat0_outbound extended permit ip object-group COMVIVA-LOCAL-GROUP object-group COMVIVA-REMOTE &lt;/P&gt;&lt;P&gt;access-list LanInterface_nat0_outbound extended permit ip Vlan10 255.255.252.0 ROAMWARE_VPN_NETWORK 255.255.248.0 &lt;/P&gt;&lt;P&gt;access-list LanInterface_nat0_outbound extended permit ip object-group NEW-GABON object-group NEW-AMSTERDAM &lt;/P&gt;&lt;P&gt;access-list LanInterface_nat0_outbound extended permit ip host NAT-FROM-NIGERIA object-group NIGERIA-GROUP-VPN &lt;/P&gt;&lt;P&gt;access-list LanInterface_nat0_outbound extended permit ip host PPSMAIN host MACH-FTP-SERVER &lt;/P&gt;&lt;P&gt;access-list WanInterface_2_cryptomap extended permit ip Vlan10 255.255.252.0 HQ_NETWORK 255.255.254.0 &lt;/P&gt;&lt;P&gt;access-list WanInterface_nat0_outbound extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list WanInterface_nat0_outbound extended permit ip any Vlan10 255.255.252.0 &lt;/P&gt;&lt;P&gt;access-list global_mpc extended permit tcp any any object-group DM_INLINE_TCP_2 &lt;/P&gt;&lt;P&gt;access-list WanInterface_mpc extended permit tcp any any object-group DM_INLINE_TCP_4 &lt;/P&gt;&lt;P&gt;access-list DefaultRAGroup_splitTunnelAcl standard permit Vlan10 255.255.252.0 &lt;/P&gt;&lt;P&gt;access-list NAT-Nigeria extended permit ip host COMVIVA_SMSC_26 object-group NIGERIA-GROUP-VPN &lt;/P&gt;&lt;P&gt;access-list WanInterface_1_cryptomap extended permit ip host PPSMAIN host EDCH_SERVER_VPN &lt;/P&gt;&lt;P&gt;access-list tcp-traffic extended permit tcp any any &lt;/P&gt;&lt;P&gt;access-list WanInterface_2_cryptomap_1 extended permit ip object-group M-Commerce_Grp object-group Oberthur_Net &lt;/P&gt;&lt;P&gt;access-list cap extended permit ip any host 192.168.158.103 &lt;/P&gt;&lt;P&gt;access-list cap extended permit ip host 192.168.158.103 any &lt;/P&gt;&lt;P&gt;access-list cap extended permit ip any host 10.3.4.13 &lt;/P&gt;&lt;P&gt;access-list cap extended permit ip host 10.3.4.13 any &lt;/P&gt;&lt;P&gt;access-list cap extended permit ip any host RiverBed &lt;/P&gt;&lt;P&gt;access-list cap extended permit ip host RiverBed any &lt;/P&gt;&lt;P&gt;access-list cap extended permit ip host 192.168.249.240 any &lt;/P&gt;&lt;P&gt;access-list WanInterface_5_cryptomap extended permit ip Vlan10 255.255.252.0 ROAMWARE_VPN_NETWORK 255.255.248.0 &lt;/P&gt;&lt;P&gt;access-list WanInterface_6_cryptomap extended permit ip object-group NEW-GABON object-group NEW-AMSTERDAM &lt;/P&gt;&lt;P&gt;access-list WanInterface_7_cryptomap extended permit ip host NAT-FROM-NIGERIA object-group NIGERIA-GROUP-VPN &lt;/P&gt;&lt;P&gt;access-list WanInterface_8_cryptomap extended permit ip host PPSMAIN host MACH-FTP-SERVER &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tcp-map allow-probes&lt;/P&gt;&lt;P&gt;tcp-options range 76 78 allow&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging list EVENTS level errors class ip&lt;/P&gt;&lt;P&gt;logging monitor warnings&lt;/P&gt;&lt;P&gt;logging trap debugging&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging mail alerts&lt;/P&gt;&lt;P&gt;logging facility 16&lt;/P&gt;&lt;P&gt;logging class auth history emergencies &lt;/P&gt;&lt;P&gt;flow-export destination LanInterface SECURITYSERVER 2055&lt;/P&gt;&lt;P&gt;flow-export template timeout-rate 1&lt;/P&gt;&lt;P&gt;flow-export delay flow-create 60&lt;/P&gt;&lt;P&gt;mtu WanInterface 1500&lt;/P&gt;&lt;P&gt;mtu LanInterface 1500&lt;/P&gt;&lt;P&gt;mtu DmzInterface 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;ip local pool RemoteMasiya 192.168.4.10-192.168.4.250 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;ip local pool RemoteAirtel 192.168.6.10-192.168.6.250 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;ip local pool ip-pool 192.168.7.10-192.168.7.20 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp permit any LanInterface&lt;/P&gt;&lt;P&gt;icmp permit any DmzInterface&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-625.bin&lt;/P&gt;&lt;P&gt;asdm location LTC_NETWORK 255.255.255.192 LanInterface&lt;/P&gt;&lt;P&gt;asdm location MPBN_MGMT 255.255.255.192 LanInterface&lt;/P&gt;&lt;P&gt;asdm location Server_121 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location 192.168.10.151 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location FlorisseDR 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location ROUTER_ISP 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location SECURITYSERVER 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location BGFI_SERVER_VPN 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location ZAIN_SERVER_VPN_BGFI 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location BAHRTI 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location Remote_SERVER 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location consultantMarketing 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location RiverBed 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location Public_Riverbed 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location PROXY_AFRICA 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location Consultant-ERICSSON 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location Consultant3_ERICSSON 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location Consultant4_Africa 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location DC 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location consultant2_ERICSSON 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location MOUSTINGA 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location CSR 255.255.255.0 LanInterface&lt;/P&gt;&lt;P&gt;asdm location CONSULTANT_IBM 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location 192.168.11.27 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location Consultant_COMVIVA 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location Consultant_Ericsson 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location Consultant_TECH-MAHINDRA 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location Consultant6_ERICSSON 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location RoamUpgrade_185 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location RoamUpgrade_186 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location RoamUpgrade_189 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location RoamUpgrade_194 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location MAMO_Server 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location CONSULTANT_DAF 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location Consultant2_COMVIVA 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location EMM_162 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location EMM_166 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location EMM_187 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location Machine_Charly 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location Call_Center_Network 255.255.255.0 LanInterface&lt;/P&gt;&lt;P&gt;asdm location 10.3.6.72 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location TM_Link7 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location TM_Link2 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location TM_Link4-6-8 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location TM_link1 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location TM_Link9 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location TM_Link10 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location TM_Link11 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location TM_Link12 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location TM_Link3-5 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;asdm location DG-HOME 255.255.255.0 LanInterface&lt;/P&gt;&lt;P&gt;asdm location ROAMWARE_VPN_NETWORK 255.255.248.0 LanInterface&lt;/P&gt;&lt;P&gt;asdm location 192.9.200.0 255.255.255.0 LanInterface&lt;/P&gt;&lt;P&gt;asdm location 192.168.246.0 255.255.254.0 LanInterface&lt;/P&gt;&lt;P&gt;asdm location 192.168.250.0 255.255.254.0 LanInterface&lt;/P&gt;&lt;P&gt;asdm location 192.168.252.0 255.255.254.0 LanInterface&lt;/P&gt;&lt;P&gt;asdm location 10.127.0.0 255.255.0.0 LanInterface&lt;/P&gt;&lt;P&gt;asdm location MACH-FTP-SERVER 255.255.255.255 LanInterface&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;global (WanInterface) 101 interface&lt;/P&gt;&lt;P&gt;global (WanInterface) 1 MailPublic netmask 255.0.0.0&lt;/P&gt;&lt;P&gt;global (WanInterface) 10 192.168.13.15 netmask 255.0.0.0&lt;/P&gt;&lt;P&gt;global (LanInterface) 1 interface&lt;/P&gt;&lt;P&gt;global (DmzInterface) 2 interface&lt;/P&gt;&lt;P&gt;nat (LanInterface) 0 access-list LanInterface_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (LanInterface) 101 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;nat (DmzInterface) 1 DMZGatewaySMTP 255.255.255.255&lt;/P&gt;&lt;P&gt;nat (DmzInterface) 101 DMZNetwork 255.255.255.0&lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp PublicIP_DMZIcsServer 5900 OfficeLANSigosBox 5900 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp PublicIP_DMZIcsServer ssh OfficeLANSigosBox ssh netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp PublicIP_DMZIcsServer 51500 OfficeLANSigosBox 51500 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp PublicIP_DMZIcsServer 51501 OfficeLANSigosBox 51501 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) udp PublicIP_DMZIcsServer ntp OfficeLANSigosBox ntp netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp PublicIP_DMZIcsServer 123 OfficeLANSigosBox 123 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp PublicIP_DMZIcsServer telnet OfficeLANSigosBox telnet netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp PublicIP_DMZIcsServer ident OfficeLANSigosBox ident netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp PublicIP_DMZIcsServer 51605 OfficeLANSigosBox 51605 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp PublicIP_DMZIcsServer 51505 OfficeLANSigosBox 51505 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp 217.113.76.152 sqlnet OPTIMA sqlnet netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp 217.113.76.152 ftp OPTIMA ftp netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp PublicIP_DMZFtpServer ssh OTA_SERVER ssh netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp PublicIP_DMZFtpServer 8443 OTA_SERVER 8443 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp PublicIP_DMZFtpServer 8080 OTA_SERVER 8080 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp MailPublic www OfficeLANExFrontEndServer www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp MailPublic https OfficeLANExFrontEndServer https netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp Public_Astellia_136 ftp ASTELLIA_TA115 ftp netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp Public_Astellia_136 www ASTELLIA_TA115 www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp Public_Astellia_137 www ASTELLIA_TA116 www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp Public_Astellia_137 ftp ASTELLIA_TA116 ftp netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp Public_Astellia_138 www ASTELLIA_TA117 www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (LanInterface,WanInterface) tcp Public_Astellia_138 ftp ASTELLIA_TA117 ftp netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (DmzInterface,WanInterface) tcp MailPublic smtp DMZGatewaySMTP smtp netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (DmzInterface,WanInterface) tcp PublicIP_DMZFtpServer ftp-data DMZFtpServer ftp-data netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (DmzInterface,WanInterface) tcp PublicIP_DMZFtpServer ftp DMZFtpServer ftp netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (DmzInterface,WanInterface) tcp PublicIP_DMZIcsServer https DMZIcsServer https netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (DmzInterface,WanInterface) tcp PublicIP_DMZIcsServer www DMZIcsServer www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-group WanInterface_access_in in interface WanInterface&lt;/P&gt;&lt;P&gt;access-group LanInterface_access_in in interface LanInterface per-user-override&lt;/P&gt;&lt;P&gt;access-group DmzInterface_access_in in interface DmzInterface&lt;/P&gt;&lt;P&gt;route WanInterface 0.0.0.0 0.0.0.0 ROUTER_ISP 1&lt;/P&gt;&lt;P&gt;route LanInterface OfficeLANWifi 255.255.255.0 10.3.4.1 1&lt;/P&gt;&lt;P&gt;route LanInterface MPBN_NETWORK 255.255.0.0 10.3.4.93 1&lt;/P&gt;&lt;P&gt;route LanInterface 192.168.1.0 255.255.255.0 10.3.4.93 1&lt;/P&gt;&lt;P&gt;route LanInterface 192.168.3.0 255.255.255.0 10.3.4.1 1&lt;/P&gt;&lt;P&gt;route LanInterface Vlan8 255.255.255.0 10.3.4.1 1&lt;/P&gt;&lt;P&gt;route LanInterface Vlan11 255.255.255.0 10.3.4.1 1&lt;/P&gt;&lt;P&gt;route LanInterface Vlan12 255.255.255.0 10.3.4.1 1&lt;/P&gt;&lt;P&gt;route LanInterface Vlan13 255.255.255.0 10.3.4.1 1&lt;/P&gt;&lt;P&gt;route LanInterface Vlan14 255.255.255.0 10.3.4.1 1&lt;/P&gt;&lt;P&gt;route LanInterface DV_Network 255.255.255.0 10.3.4.1 1&lt;/P&gt;&lt;P&gt;route LanInterface PK8_Network 255.255.255.0 10.3.7.100 1&lt;/P&gt;&lt;P&gt;route LanInterface 192.168.140.0 255.255.255.0 10.3.4.1 1&lt;/P&gt;&lt;P&gt;route LanInterface 192.168.150.0 255.255.255.0 10.3.4.1 1&lt;/P&gt;&lt;P&gt;route WanInterface 192.168.158.103 255.255.255.255 ROUTER_ISP 1&lt;/P&gt;&lt;P&gt;route LanInterface Vlan160 255.255.255.0 10.3.4.1 1&lt;/P&gt;&lt;P&gt;route LanInterface Oloumi_Network 255.255.255.0 10.3.4.1 1&lt;/P&gt;&lt;P&gt;route LanInterface Call_Center_Network 255.255.255.0 10.3.7.100 1&lt;/P&gt;&lt;P&gt;route LanInterface Vlan180 255.255.255.0 10.3.4.1 1&lt;/P&gt;&lt;P&gt;route LanInterface 192.168.181.0 255.255.255.0 10.3.4.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;aaa-server VPN-RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server VPN-RADIUS (LanInterface) host SECURITYSERVER&lt;/P&gt;&lt;P&gt;key cisco&lt;/P&gt;&lt;P&gt;aaa-server VPN-RADIUS (LanInterface) host Network_Server&lt;/P&gt;&lt;P&gt;key cisco&lt;/P&gt;&lt;P&gt;aaa authentication telnet console VPN-RADIUS LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication http console VPN-RADIUS LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console VPN-RADIUS LOCAL&lt;/P&gt;&lt;P&gt;aaa authorization command LOCAL &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http Vlan10 255.255.252.0 LanInterface&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;http Vlan13 255.255.255.0 LanInterface&lt;/P&gt;&lt;P&gt;http Vlan14 255.255.255.0 LanInterface&lt;/P&gt;&lt;P&gt;snmp-server host LanInterface Roland_laptop community TexasAdmin version 2c udp-port 161&lt;/P&gt;&lt;P&gt;snmp-server host LanInterface SECURITYSERVER community TexasAdmin version 2c&lt;/P&gt;&lt;P&gt;snmp-server host LanInterface 10.3.6.27 community TexasAdmin&lt;/P&gt;&lt;P&gt;snmp-server location HQ&lt;/P&gt;&lt;P&gt;snmp-server contact IT Network&lt;/P&gt;&lt;P&gt;snmp-server community TexasAdmin&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;snmp-server enable traps syslog&lt;/P&gt;&lt;P&gt;svc rekey time 30&lt;/P&gt;&lt;P&gt;svc rekey method ssl&lt;/P&gt;&lt;P&gt;svc ask none default webvpn&lt;/P&gt;&lt;P&gt;customization value DfltCustomization&lt;/P&gt;&lt;P&gt;group-policy phone-policy internal&lt;/P&gt;&lt;P&gt;group-policy phone-policy attributes&lt;/P&gt;&lt;P&gt;vpn-tunnel-protocol svc &lt;/P&gt;&lt;P&gt;group-policy AirtelPolicy internal&lt;/P&gt;&lt;P&gt;group-policy AirtelPolicy attributes&lt;/P&gt;&lt;P&gt;banner value WELCOME TO AIRTEL GABON VPN ACCESS&lt;/P&gt;&lt;P&gt;dns-server value 10.3.4.16 10.3.4.15&lt;/P&gt;&lt;P&gt;vpn-tunnel-protocol IPSec svc webvpn&lt;/P&gt;&lt;P&gt;split-tunnel-policy tunnelspecified&lt;/P&gt;&lt;P&gt;split-tunnel-network-list value Roland&lt;/P&gt;&lt;P&gt;　&lt;/P&gt;&lt;P&gt;class-map netflow-export-class&lt;/P&gt;&lt;P&gt;match access-list netflow-export&lt;/P&gt;&lt;P&gt;class-map global-class&lt;/P&gt;&lt;P&gt;match access-list global_mpc_1&lt;/P&gt;&lt;P&gt;class-map tcp-traffic&lt;/P&gt;&lt;P&gt;match access-list tcp-traffic&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;class-map voice&lt;/P&gt;&lt;P&gt;match dscp ef &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;inspect ftp &lt;/P&gt;&lt;P&gt;inspect h323 h225 &lt;/P&gt;&lt;P&gt;inspect h323 ras &lt;/P&gt;&lt;P&gt;inspect rsh &lt;/P&gt;&lt;P&gt;inspect rtsp &lt;/P&gt;&lt;P&gt;inspect sqlnet &lt;/P&gt;&lt;P&gt;inspect skinny &lt;/P&gt;&lt;P&gt;inspect sunrpc &lt;/P&gt;&lt;P&gt;inspect xdmcp &lt;/P&gt;&lt;P&gt;inspect sip &lt;/P&gt;&lt;P&gt;inspect netbios &lt;/P&gt;&lt;P&gt;inspect tftp &lt;/P&gt;&lt;P&gt;inspect ip-options &lt;/P&gt;&lt;P&gt;class tcp-traffic&lt;/P&gt;&lt;P&gt;set connection advanced-options allow-probes&lt;/P&gt;&lt;P&gt;class global-class&lt;/P&gt;&lt;P&gt;csc fail-open&lt;/P&gt;&lt;P&gt;class netflow-export-class&lt;/P&gt;&lt;P&gt;flow-export event-type all destination SECURITYSERVER&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;imap4s&lt;/P&gt;&lt;P&gt;server OfficeLANExBackEndServer&lt;/P&gt;&lt;P&gt;no outstanding&lt;/P&gt;&lt;P&gt;authorization-server-group LOCAL&lt;/P&gt;&lt;P&gt;default-group-policy DfltGrpPolicy&lt;/P&gt;&lt;P&gt;authentication piggyback&lt;/P&gt;&lt;P&gt;pop3s&lt;/P&gt;&lt;P&gt;server OfficeLANExBackEndServer&lt;/P&gt;&lt;P&gt;no outstanding&lt;/P&gt;&lt;P&gt;authorization-server-group LOCAL&lt;/P&gt;&lt;P&gt;default-group-policy DfltGrpPolicy&lt;/P&gt;&lt;P&gt;authentication piggyback&lt;/P&gt;&lt;P&gt;smtps&lt;/P&gt;&lt;P&gt;server OfficeLANExBackEndServer&lt;/P&gt;&lt;P&gt;no outstanding&lt;/P&gt;&lt;P&gt;default-group-policy DfltGrpPolicy&lt;/P&gt;&lt;P&gt;authentication piggyback&lt;/P&gt;&lt;P&gt;authorization-dn-attributes C CN&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jul 2011 12:17:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672366#M536099</guid>
      <dc:creator>zain_gabon</dc:creator>
      <dc:date>2011-07-13T12:17:28Z</dc:date>
    </item>
    <item>
      <title>Firewall ASA Blocking ftp session</title>
      <link>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672367#M536100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Dear Varun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i tried a ftp connexion, i have this messages&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;|DMZFtpServer|21|Roland_laptop|1487|Teardown TCP connection 121446 for DmzInterface:DMZFtpServer/21 to LanInterface:Roland_laptop/1487 duration 0:00:00 bytes 0 TCP Reset-O&lt;/P&gt;&lt;P&gt;Roland_laptop|1487|DMZFtpServer|21|Built outbound TCP connection 121446 for DmzInterface:DMZFtpServer/21 (DMZFtpServer/21) to LanInterface:Roland_laptop/1487 (Roland_laptop/1487)&lt;/P&gt;&lt;P&gt;DMZFtpServer|21|Roland_laptop|1487|Teardown TCP connection 121441 for DmzInterface:DMZFtpServer/21 to LanInterface:Roland_laptop/1487 duration 0:00:00 bytes 0 TCP Reset-O&lt;/P&gt;&lt;P&gt;|Roland_laptop|1487|DMZFtpServer|21|Built outbound TCP connection 121441 for DmzInterface:DMZFtpServer/21 (DMZFtpServer/21) to LanInterface:Roland_laptop/1487 (Roland_laptop/1487)&lt;/P&gt;&lt;P&gt;|DMZFtpServer|21|Roland_laptop|1487|Teardown TCP connection 121438 for DmzInterface:DMZFtpServer/21 to LanInterface:Roland_laptop/1487 duration 0:00:00 bytes 0 TCP Reset-O&lt;/P&gt;&lt;P&gt;Roland_laptop|1487|DMZFtpServer|21|Built outbound TCP connection 121438 for DmzInterface:DMZFtpServer/21 (DMZFtpServer/21) to LanInterface:Roland_laptop/1487 (Roland_laptop/1487)&lt;/P&gt;&lt;P&gt;　&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jul 2011 13:30:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672367#M536100</guid>
      <dc:creator>zain_gabon</dc:creator>
      <dc:date>2011-07-13T13:30:33Z</dc:date>
    </item>
    <item>
      <title>Firewall ASA Blocking ftp session</title>
      <link>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672368#M536102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll have a look at it, plz give me some time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jul 2011 13:41:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672368#M536102</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-13T13:41:58Z</dc:date>
    </item>
    <item>
      <title>Firewall ASA Blocking ftp session</title>
      <link>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672369#M536104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zain,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have gone through the error messages and you are trying to access the FTP server on the DmzInterface from a laptop on the LanInterface but you do not have any static command for it, the only command taht you ahve is for DMA to WAN interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DmzInterface,WanInterface) tcp PublicIP_DMZFtpServer ftp-data DMZFtpServer ftp-data netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (DmzInterface,WanInterface) tcp PublicIP_DMZFtpServer ftp DMZFtpServer ftp netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You do not have any statement&amp;nbsp; for DMZ to LAN interface, was it working fine earlier??????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I woudl suggest you to add the following nats:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DmzInterface,LanInterface) tcp PublicIP_DMZFtpServer ftp-data DMZFtpServer ftp-data netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (DmzInterface,LanInterface) tcp PublicIP_DMZFtpServer ftp DMZFtpServer ftp netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try it and let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jul 2011 18:31:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672369#M536104</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-13T18:31:14Z</dc:date>
    </item>
    <item>
      <title>Firewall ASA Blocking ftp session</title>
      <link>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672370#M536107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thnaks Varun&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's working fine now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But before perfom your suggest, i put the ASA in factoty default then put the backup config again.&lt;/P&gt;&lt;P&gt;suddenly, it's working fine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your time&lt;/P&gt;&lt;P&gt;*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jul 2011 07:22:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672370#M536107</guid>
      <dc:creator>zain_gabon</dc:creator>
      <dc:date>2011-07-14T07:22:11Z</dc:date>
    </item>
    <item>
      <title>Firewall ASA Blocking ftp session</title>
      <link>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672371#M536109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;votre accueil Zain !!!!!!!&amp;nbsp; &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Jul 2011 07:28:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-asa-blocking-ftp-session/m-p/1672371#M536109</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-14T07:28:55Z</dc:date>
    </item>
  </channel>
</rss>

