<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to communicate between Interface Networks when internet is enabled on ASA5510. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-communicate-between-interface-networks-when-internet/m-p/1697505#M557304</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an&amp;nbsp; ASA 5510 working in Routed mode for a company with the following networks. everything works fine as desired.&lt;/P&gt;&lt;P&gt;Below are the interfaces, security and&amp;nbsp; ip addresses .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Ethernet0/0&amp;nbsp;&amp;nbsp; DC_SERVER&amp;nbsp;&amp;nbsp; security-level 100&lt;/P&gt;&lt;P&gt;ip address 172.16.11.12 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Ethernet0/1&amp;nbsp; Branches&amp;nbsp; security-level 50&lt;/P&gt;&lt;P&gt; ip address 172.16.1.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ethernet0/2&amp;nbsp;&amp;nbsp; DC_ADMIN&amp;nbsp; security-level 70&lt;/P&gt;&lt;P&gt;ip address 172.16.25.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now Customer has taken a&amp;nbsp; DSL&amp;nbsp; connection. I have configured the port E0/3 in PPPoE mode and I do get a public IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN lang="EN"&gt;&lt;P&gt;Ethernet0/3&lt;/P&gt;&lt;P&gt;description broadband connection&lt;/P&gt;&lt;P&gt;nameif Internet&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;pppoe client vpdn group bsnl&lt;/P&gt;&lt;P&gt;ip address pppoe setroute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I Enable NAT so that the DC_SERVER and DC_ADMIN can access internet, they are able to access the internet. BUT Now my DC_SERVER,&lt;/P&gt;&lt;P&gt;DC_ADMIN and&amp;nbsp; Branches networks are unable&amp;nbsp; to communicate with each other. Nothings works , Ping drops at this point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are the NAT commands to enable internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT (DC_ADMIN) 100&amp;nbsp; 172.16.25.0 255.255.255.0&lt;/P&gt;&lt;P&gt;NAT (DC_SERVER) 100 172.16.11.0 255.255.255.0&lt;/P&gt;&lt;P&gt;Global (Internet) 100 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If at this moment&amp;nbsp; I&amp;nbsp; disable NAT , now&amp;nbsp; the&amp;nbsp; Internal Networks are able to communicate with each other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't understand where I am making a mistake. Pls help .\&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the firewall configuration. without NAT enabled. I only add the obove NAT statements for internet access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN lang="EN"&gt;&lt;P&gt;ASA Version 8.2(1)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;enable password cGBMrLCcjheJaVE/ encrypted&lt;/P&gt;&lt;P&gt;passwd cGBMrLCcjheJaVE/ encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 172.16.11.1 App1 description Application server 1&lt;/P&gt;&lt;P&gt;name 172.16.11.2 App2 description Application server 2&lt;/P&gt;&lt;P&gt;name 172.16.11.3 App3 description Application server 3&lt;/P&gt;&lt;P&gt;name 172.16.11.4 App4 description Application server 4&lt;/P&gt;&lt;P&gt;name 172.16.11.16 Additional_DC description Replication DC&lt;/P&gt;&lt;P&gt;name 172.16.11.18 Antivirus_Server description Antivirus_Server&lt;/P&gt;&lt;P&gt;name 172.16.11.7 DB1 description database server1&lt;/P&gt;&lt;P&gt;name 172.16.11.8 DB2 description Database server 2&lt;/P&gt;&lt;P&gt;name 172.16.11.20 Domain_Controller description Main Domain controller&lt;/P&gt;&lt;P&gt;name 172.16.11.5 MIS description MIS server&lt;/P&gt;&lt;P&gt;name 172.16.11.6 Test_Server description Test Server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;description servers are connected to this port&lt;/P&gt;&lt;P&gt;nameif DC_SERVER&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 172.16.11.12 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;description All branches are connected to this port&lt;/P&gt;&lt;P&gt;nameif Branches&lt;/P&gt;&lt;P&gt;security-level 50&lt;/P&gt;&lt;P&gt;ip address 172.16.1.254 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;description Administrator users connected to this port&lt;/P&gt;&lt;P&gt;nameif DC_ADMIN&lt;/P&gt;&lt;P&gt;security-level 70&lt;/P&gt;&lt;P&gt;ip address 172.16.25.254 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;description broadband connection&lt;/P&gt;&lt;P&gt;nameif Internet&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;pppoe client vpdn group bsnl&lt;/P&gt;&lt;P&gt;ip address pppoe setroute&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt;nameif mgmt&lt;/P&gt;&lt;P&gt;security-level 50&lt;/P&gt;&lt;P&gt;ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;object-group service rdp tcp&lt;/P&gt;&lt;P&gt;port-object eq 3389&lt;/P&gt;&lt;P&gt;object-group network All_Servers&lt;/P&gt;&lt;P&gt;description All servers group for branch access&lt;/P&gt;&lt;P&gt;network-object host Additional_DC&lt;/P&gt;&lt;P&gt;network-object host Antivirus_Server&lt;/P&gt;&lt;P&gt;network-object host App1&lt;/P&gt;&lt;P&gt;network-object host Domain_Controller&lt;/P&gt;&lt;P&gt;network-object host App2&lt;/P&gt;&lt;P&gt;network-object host App3&lt;/P&gt;&lt;P&gt;network-object host App4&lt;/P&gt;&lt;P&gt;network-object host MIS&lt;/P&gt;&lt;P&gt;network-object host Test_Server&lt;/P&gt;&lt;P&gt;network-object host DB1&lt;/P&gt;&lt;P&gt;network-object host DB2&lt;/P&gt;&lt;P&gt;access-list Internet_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list DC_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list DC_access_in extended permit ip any object-group All_Servers&lt;/P&gt;&lt;P&gt;access-list DC_ADMIN_access_in extended permit tcp any any object-group rdp&lt;/P&gt;&lt;P&gt;access-list DC_ADMIN_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list DC_ADMIN_access_in extended permit ip any object-group All_Servers&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu DC_SERVER 1500&lt;/P&gt;&lt;P&gt;mtu Branches 1500&lt;/P&gt;&lt;P&gt;mtu DC_ADMIN 1500&lt;/P&gt;&lt;P&gt;mtu Internet 1492&lt;/P&gt;&lt;P&gt;mtu mgmt 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-621.bin&lt;/P&gt;&lt;P&gt;asdm location App2 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location App3 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location App4 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location MIS 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location Test_Server 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location DB1 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location DB2 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location Additional_DC 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location Antivirus_Server 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location Domain_Controller 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (Internet) 1 interface&lt;/P&gt;&lt;P&gt;access-group DC_access_in in interface Branches&lt;/P&gt;&lt;P&gt;access-group DC_ADMIN_access_in in interface DC_ADMIN&lt;/P&gt;&lt;P&gt;access-group Internet_access_in in interface Internet&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 mgmt&lt;/P&gt;&lt;P&gt;http 172.168.25.0 255.255.255.0 DC_ADMIN&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;telnet 172.16.25.0 255.255.255.0 DC_ADMIN&lt;/P&gt;&lt;P&gt;telnet 0.0.0.0 0.0.0.0 mgmt&lt;/P&gt;&lt;P&gt;telnet 192.16.1.0 255.255.255.0 mgmt&lt;/P&gt;&lt;P&gt;telnet timeout 30&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;vpdn group bsnl request dialout pppoe&lt;/P&gt;&lt;P&gt;vpdn group bsnl localname tmucbl&lt;/P&gt;&lt;P&gt;vpdn group bsnl ppp authentication chap&lt;/P&gt;&lt;P&gt;vpdn username tmucbl password 2731087&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;username admin password hmTyXifrd1RbLFWE encrypted privilege 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;inspect ftp&lt;/P&gt;&lt;P&gt;inspect h323 h225&lt;/P&gt;&lt;P&gt;inspect h323 ras&lt;/P&gt;&lt;P&gt;inspect netbios&lt;/P&gt;&lt;P&gt;inspect rsh&lt;/P&gt;&lt;P&gt;inspect rtsp&lt;/P&gt;&lt;P&gt;inspect skinny&lt;/P&gt;&lt;P&gt;inspect esmtp&lt;/P&gt;&lt;P&gt;inspect sqlnet&lt;/P&gt;&lt;P&gt;inspect sunrpc&lt;/P&gt;&lt;P&gt;inspect tftp&lt;/P&gt;&lt;P&gt;inspect sip&lt;/P&gt;&lt;P&gt;inspect xdmcp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;Cryptochecksum:1a61843bd133114d24d618a26aee5423&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:24:28 GMT</pubDate>
    <dc:creator>favolmendes</dc:creator>
    <dc:date>2019-03-11T20:24:28Z</dc:date>
    <item>
      <title>Unable to communicate between Interface Networks when internet is enabled on ASA5510.</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-communicate-between-interface-networks-when-internet/m-p/1697505#M557304</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an&amp;nbsp; ASA 5510 working in Routed mode for a company with the following networks. everything works fine as desired.&lt;/P&gt;&lt;P&gt;Below are the interfaces, security and&amp;nbsp; ip addresses .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Ethernet0/0&amp;nbsp;&amp;nbsp; DC_SERVER&amp;nbsp;&amp;nbsp; security-level 100&lt;/P&gt;&lt;P&gt;ip address 172.16.11.12 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Ethernet0/1&amp;nbsp; Branches&amp;nbsp; security-level 50&lt;/P&gt;&lt;P&gt; ip address 172.16.1.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ethernet0/2&amp;nbsp;&amp;nbsp; DC_ADMIN&amp;nbsp; security-level 70&lt;/P&gt;&lt;P&gt;ip address 172.16.25.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now Customer has taken a&amp;nbsp; DSL&amp;nbsp; connection. I have configured the port E0/3 in PPPoE mode and I do get a public IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN lang="EN"&gt;&lt;P&gt;Ethernet0/3&lt;/P&gt;&lt;P&gt;description broadband connection&lt;/P&gt;&lt;P&gt;nameif Internet&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;pppoe client vpdn group bsnl&lt;/P&gt;&lt;P&gt;ip address pppoe setroute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I Enable NAT so that the DC_SERVER and DC_ADMIN can access internet, they are able to access the internet. BUT Now my DC_SERVER,&lt;/P&gt;&lt;P&gt;DC_ADMIN and&amp;nbsp; Branches networks are unable&amp;nbsp; to communicate with each other. Nothings works , Ping drops at this point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are the NAT commands to enable internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT (DC_ADMIN) 100&amp;nbsp; 172.16.25.0 255.255.255.0&lt;/P&gt;&lt;P&gt;NAT (DC_SERVER) 100 172.16.11.0 255.255.255.0&lt;/P&gt;&lt;P&gt;Global (Internet) 100 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If at this moment&amp;nbsp; I&amp;nbsp; disable NAT , now&amp;nbsp; the&amp;nbsp; Internal Networks are able to communicate with each other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't understand where I am making a mistake. Pls help .\&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the firewall configuration. without NAT enabled. I only add the obove NAT statements for internet access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;SPAN lang="EN"&gt;&lt;P&gt;ASA Version 8.2(1)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;enable password cGBMrLCcjheJaVE/ encrypted&lt;/P&gt;&lt;P&gt;passwd cGBMrLCcjheJaVE/ encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 172.16.11.1 App1 description Application server 1&lt;/P&gt;&lt;P&gt;name 172.16.11.2 App2 description Application server 2&lt;/P&gt;&lt;P&gt;name 172.16.11.3 App3 description Application server 3&lt;/P&gt;&lt;P&gt;name 172.16.11.4 App4 description Application server 4&lt;/P&gt;&lt;P&gt;name 172.16.11.16 Additional_DC description Replication DC&lt;/P&gt;&lt;P&gt;name 172.16.11.18 Antivirus_Server description Antivirus_Server&lt;/P&gt;&lt;P&gt;name 172.16.11.7 DB1 description database server1&lt;/P&gt;&lt;P&gt;name 172.16.11.8 DB2 description Database server 2&lt;/P&gt;&lt;P&gt;name 172.16.11.20 Domain_Controller description Main Domain controller&lt;/P&gt;&lt;P&gt;name 172.16.11.5 MIS description MIS server&lt;/P&gt;&lt;P&gt;name 172.16.11.6 Test_Server description Test Server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;description servers are connected to this port&lt;/P&gt;&lt;P&gt;nameif DC_SERVER&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 172.16.11.12 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;description All branches are connected to this port&lt;/P&gt;&lt;P&gt;nameif Branches&lt;/P&gt;&lt;P&gt;security-level 50&lt;/P&gt;&lt;P&gt;ip address 172.16.1.254 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;description Administrator users connected to this port&lt;/P&gt;&lt;P&gt;nameif DC_ADMIN&lt;/P&gt;&lt;P&gt;security-level 70&lt;/P&gt;&lt;P&gt;ip address 172.16.25.254 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;description broadband connection&lt;/P&gt;&lt;P&gt;nameif Internet&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;pppoe client vpdn group bsnl&lt;/P&gt;&lt;P&gt;ip address pppoe setroute&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt;nameif mgmt&lt;/P&gt;&lt;P&gt;security-level 50&lt;/P&gt;&lt;P&gt;ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;object-group service rdp tcp&lt;/P&gt;&lt;P&gt;port-object eq 3389&lt;/P&gt;&lt;P&gt;object-group network All_Servers&lt;/P&gt;&lt;P&gt;description All servers group for branch access&lt;/P&gt;&lt;P&gt;network-object host Additional_DC&lt;/P&gt;&lt;P&gt;network-object host Antivirus_Server&lt;/P&gt;&lt;P&gt;network-object host App1&lt;/P&gt;&lt;P&gt;network-object host Domain_Controller&lt;/P&gt;&lt;P&gt;network-object host App2&lt;/P&gt;&lt;P&gt;network-object host App3&lt;/P&gt;&lt;P&gt;network-object host App4&lt;/P&gt;&lt;P&gt;network-object host MIS&lt;/P&gt;&lt;P&gt;network-object host Test_Server&lt;/P&gt;&lt;P&gt;network-object host DB1&lt;/P&gt;&lt;P&gt;network-object host DB2&lt;/P&gt;&lt;P&gt;access-list Internet_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list DC_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list DC_access_in extended permit ip any object-group All_Servers&lt;/P&gt;&lt;P&gt;access-list DC_ADMIN_access_in extended permit tcp any any object-group rdp&lt;/P&gt;&lt;P&gt;access-list DC_ADMIN_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list DC_ADMIN_access_in extended permit ip any object-group All_Servers&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu DC_SERVER 1500&lt;/P&gt;&lt;P&gt;mtu Branches 1500&lt;/P&gt;&lt;P&gt;mtu DC_ADMIN 1500&lt;/P&gt;&lt;P&gt;mtu Internet 1492&lt;/P&gt;&lt;P&gt;mtu mgmt 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-621.bin&lt;/P&gt;&lt;P&gt;asdm location App2 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location App3 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location App4 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location MIS 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location Test_Server 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location DB1 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location DB2 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location Additional_DC 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location Antivirus_Server 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;asdm location Domain_Controller 255.255.255.255 DC_SERVER&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (Internet) 1 interface&lt;/P&gt;&lt;P&gt;access-group DC_access_in in interface Branches&lt;/P&gt;&lt;P&gt;access-group DC_ADMIN_access_in in interface DC_ADMIN&lt;/P&gt;&lt;P&gt;access-group Internet_access_in in interface Internet&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 mgmt&lt;/P&gt;&lt;P&gt;http 172.168.25.0 255.255.255.0 DC_ADMIN&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;telnet 172.16.25.0 255.255.255.0 DC_ADMIN&lt;/P&gt;&lt;P&gt;telnet 0.0.0.0 0.0.0.0 mgmt&lt;/P&gt;&lt;P&gt;telnet 192.16.1.0 255.255.255.0 mgmt&lt;/P&gt;&lt;P&gt;telnet timeout 30&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;vpdn group bsnl request dialout pppoe&lt;/P&gt;&lt;P&gt;vpdn group bsnl localname tmucbl&lt;/P&gt;&lt;P&gt;vpdn group bsnl ppp authentication chap&lt;/P&gt;&lt;P&gt;vpdn username tmucbl password 2731087&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;username admin password hmTyXifrd1RbLFWE encrypted privilege 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;inspect ftp&lt;/P&gt;&lt;P&gt;inspect h323 h225&lt;/P&gt;&lt;P&gt;inspect h323 ras&lt;/P&gt;&lt;P&gt;inspect netbios&lt;/P&gt;&lt;P&gt;inspect rsh&lt;/P&gt;&lt;P&gt;inspect rtsp&lt;/P&gt;&lt;P&gt;inspect skinny&lt;/P&gt;&lt;P&gt;inspect esmtp&lt;/P&gt;&lt;P&gt;inspect sqlnet&lt;/P&gt;&lt;P&gt;inspect sunrpc&lt;/P&gt;&lt;P&gt;inspect tftp&lt;/P&gt;&lt;P&gt;inspect sip&lt;/P&gt;&lt;P&gt;inspect xdmcp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;Cryptochecksum:1a61843bd133114d24d618a26aee5423&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:24:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-communicate-between-interface-networks-when-internet/m-p/1697505#M557304</guid>
      <dc:creator>favolmendes</dc:creator>
      <dc:date>2019-03-11T20:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to communicate between Interface Networks when intern</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-communicate-between-interface-networks-when-internet/m-p/1697506#M557306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Favol,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that you haven't configured NAT rules for the traffic between DC_SERVER, DC_ADMIN and&amp;nbsp; Branches&lt;/P&gt;&lt;P&gt;Your NAT configuration is:&lt;SPAN lang="EN"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;NAT (DC_ADMIN) 100&amp;nbsp; 172.16.25.0 255.255.255.0&lt;/P&gt;&lt;P&gt;NAT (DC_SERVER) 100 172.16.11.0 255.255.255.0&lt;/P&gt;&lt;P&gt;Global (Internet) 100 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So when traffic from DC_ADMIN tries to go to Branches, it will match the &lt;SPAN lang="EN"&gt;&lt;STRONG&gt;NAT (DC_ADMIN) 100 &lt;/STRONG&gt;but it has no matching Global for the Branches interface and hence gets dropped.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;There are two options for you to solve this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;1. configure PAT for other interfaces as well. &lt;STRONG&gt;global (Branches) 100 interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;This way, Admin and Server can contact Branches easily&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;2. Configure NAT exempt for these traffic so that they are not natted at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;STRONG&gt;access-list DC_SERVER_EXEMPT permit ip 172.16.11.0 255.255.255.0 172.16.1.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN"&gt;access-list DC_SERVER_EXEMPT permit ip 172.16.11.0 255.255.255.0 172.16.25.0 255.255.255.0&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;STRONG&gt;&lt;SPAN lang="EN"&gt;access-list DC_ADMIN_EXEMPT permit ip 172.16.25.0 255.255.255.0 172.16.1.0 255.255.255.0&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;STRONG&gt;nat (DC_SERVER) 0 access-list DC_SERVER_EXEMPT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;STRONG&gt;nat (DC_ADMIN) 0 access-list DC_ADMIN_EXEMPT&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;This way traffic travelling between Server -&amp;gt; Admin,Branches; and Admin-&amp;gt; Branches will be nat exempted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;-Shrikant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;P.S.: Please mark the question as answered, if it has been resolved. Do rate helpful posts. Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Apr 2011 12:25:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-communicate-between-interface-networks-when-internet/m-p/1697506#M557306</guid>
      <dc:creator>Shrikant Sundaresh</dc:creator>
      <dc:date>2011-04-21T12:25:03Z</dc:date>
    </item>
  </channel>
</rss>

