<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA 5510 cannot connect to site through appliance in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-cannot-connect-to-site-through-appliance/m-p/1646019#M559339</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ricoh accepting all public IP addresses.&amp;nbsp; I apologize, I made a typo in my original post.&amp;nbsp; The IP address of the Ricoh appliance is 172.16.1.135.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Mar 2011 12:13:54 GMT</pubDate>
    <dc:creator>dancumming</dc:creator>
    <dc:date>2011-03-23T12:13:54Z</dc:date>
    <item>
      <title>Cisco ASA 5510 cannot connect to site through appliance</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-cannot-connect-to-site-through-appliance/m-p/1646017#M559331</link>
      <description>&lt;P&gt;Good morning,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an @Remote appliance through Ricoh for our copiers.&amp;nbsp; This appliance connects to their site to transfer meter readings and other information.&amp;nbsp; This appliance can't connect to their site to transmit data.&amp;nbsp; Ricoh is telling me the problem is on our firewill.&amp;nbsp; I have assigned the Ricoh appliance a static IP address in our network.&amp;nbsp; Our firewall is a Cisco ASA 5510.&amp;nbsp; I don't have much expereince with logging on the ASA, so I'm not sure what "teardown dynamic TCP translation from inside" means.&amp;nbsp; Is there something that is preventing this IP from contacting the Ricoh site?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the live log when I try to make the connection.&amp;nbsp; I have filtered it for the address of the appliance which is 172.16.1.135&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6|Mar 22 2011 08:55:58|305012: Teardown dynamic TCP translation from inside:172.16.1.135/60407 to outside:208.39.161.66/21292 duration 0:00:30&lt;BR /&gt;6|Mar 22 2011 08:55:55|305012: Teardown dynamic TCP translation from inside:172.16.1.135/43888 to outside:208.39.161.66/21289 duration 0:00:30&lt;BR /&gt;6|Mar 22 2011 08:55:51|305012: Teardown dynamic TCP translation from inside:172.16.1.135/54308 to outside:208.39.161.66/21284 duration 0:00:30&lt;BR /&gt;6|Mar 22 2011 08:55:48|305012: Teardown dynamic TCP translation from inside:172.16.1.135/35539 to outside:208.39.161.66/21282 duration 0:00:30&lt;BR /&gt;6|Mar 22 2011 08:55:47|305012: Teardown dynamic ICMP translation from inside:172.16.1.135/796 to outside:208.39.161.66/13 duration 0:00:30&lt;BR /&gt;6|Mar 22 2011 08:55:28|302014: Teardown TCP connection 312519 for outside:210.173.216.40/443 to inside:172.16.1.135/60407 duration 0:00:00 bytes 91 TCP Reset-I&lt;BR /&gt;6|Mar 22 2011 08:55:28|302013: Built outbound TCP connection 312519 for outside:210.173.216.40/443 (210.173.216.40/443) to inside:172.16.1.135/60407 (208.39.161.66/21292)&lt;BR /&gt;6|Mar 22 2011 08:55:28|305011: Built dynamic TCP translation from inside:172.16.1.135/60407 to outside:208.39.161.66/21292&lt;BR /&gt;6|Mar 22 2011 08:55:25|302014: Teardown TCP connection 312496 for outside:210.173.216.40/443 to inside:172.16.1.135/43888 duration 0:00:00 bytes 91 TCP Reset-I&lt;BR /&gt;6|Mar 22 2011 08:55:25|302013: Built outbound TCP connection 312496 for outside:210.173.216.40/443 (210.173.216.40/443) to inside:172.16.1.135/43888 (208.39.161.66/21289)&lt;BR /&gt;6|Mar 22 2011 08:55:25|305011: Built dynamic TCP translation from inside:172.16.1.135/43888 to outside:208.39.161.66/21289&lt;BR /&gt;6|Mar 22 2011 08:55:22|302014: Teardown TCP connection 312371 for outside:210.173.216.40/443 to inside:172.16.1.135/54308 duration 0:00:00 bytes 91 TCP Reset-I&lt;BR /&gt;6|Mar 22 2011 08:55:21|302013: Built outbound TCP connection 312371 for outside:210.173.216.40/443 (210.173.216.40/443) to inside:172.16.1.135/54308 (208.39.161.66/21284)&lt;BR /&gt;6|Mar 22 2011 08:55:21|305011: Built dynamic TCP translation from inside:172.16.1.135/54308 to outside:208.39.161.66/21284&lt;BR /&gt;6|Mar 22 2011 08:55:19|302021: Teardown ICMP connection for faddr 210.173.216.40/0 gaddr 208.39.161.66/13 laddr 172.16.1.135/796&lt;BR /&gt;6|Mar 22 2011 08:55:18|302014: Teardown TCP connection 312258 for outside:210.173.216.40/443 to inside:172.16.1.135/35539 duration 0:00:00 bytes 91 TCP Reset-I&lt;BR /&gt;6|Mar 22 2011 08:55:18|302013: Built outbound TCP connection 312258 for outside:210.173.216.40/443 (210.173.216.40/443) to inside:172.16.1.135/35539 (208.39.161.66/21282)&lt;BR /&gt;6|Mar 22 2011 08:55:18|305011: Built dynamic TCP translation from inside:172.16.1.135/35539 to outside:208.39.161.66/21282&lt;BR /&gt;6|Mar 22 2011 08:55:17|302020: Built outbound ICMP connection for faddr 210.173.216.40/0 gaddr 208.39.161.66/13 laddr 172.16.1.135/796&lt;BR /&gt;6|Mar 22 2011 08:55:17|305011: Built dynamic ICMP translation from inside:172.16.1.135/796 to outside:208.39.161.66/13&lt;BR /&gt;6|Mar 22 2011 08:54:54|305012: Teardown dynamic ICMP translation from inside:172.16.1.135/794 to outside:208.39.161.66/12 duration 0:00:30&lt;BR /&gt;6|Mar 22 2011 08:54:26|302021: Teardown ICMP connection for faddr 210.173.216.40/0 gaddr 208.39.161.66/12 laddr 172.16.1.135/794&lt;BR /&gt;6|Mar 22 2011 08:54:24|302020: Built outbound ICMP connection for faddr 210.173.216.40/0 gaddr 208.39.161.66/12 laddr 172.16.1.135/794&lt;BR /&gt;6|Mar 22 2011 08:54:24|305011: Built dynamic ICMP translation from inside:172.16.1.135/794 to outside:208.39.161.66/12&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the config for my ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bordentown-PIX# show run&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 7.0(8)&lt;BR /&gt;!&lt;BR /&gt;hostname Bordentown-PIX&lt;BR /&gt;domain-name bordentown.k12.nj.us&lt;BR /&gt;enable password A8EW9svYyTEcA4Ua encrypted&lt;BR /&gt;passwd A8EW9svYyTEcA4Ua encrypted&lt;BR /&gt;no names&lt;BR /&gt;name 172.16.1.41 BRSDPROXY&lt;BR /&gt;name 172.16.1.253 Voice_conf&lt;BR /&gt;name 208.39.161.68 Voice_conf_out&lt;BR /&gt;name 172.16.1.8 bordentownfs2&lt;BR /&gt;name 172.16.1.43 btprx&lt;BR /&gt;name 172.16.1.6 pri_ComCastMail&lt;BR /&gt;name 172.16.1.201 pri_bordentodell1&lt;BR /&gt;name 172.16.1.22 pri_brvstream&lt;BR /&gt;name 172.16.1.26 pri_remoteacc&lt;BR /&gt;name 172.16.1.200 pri_service_2&lt;BR /&gt;name 208.39.161.70 pub_ComCastMail&lt;BR /&gt;name 208.39.161.67 pub_bordentdell1&lt;BR /&gt;name 208.39.161.73 pub_bordentownfs2&lt;BR /&gt;name 208.39.161.72 pub_brvstream&lt;BR /&gt;name 208.39.161.76 pub_bsdinfosys&lt;BR /&gt;name 208.39.161.74 pub_remoteacc&lt;/P&gt;&lt;P&gt;name 208.39.161.69 pub_service_2&lt;BR /&gt;dns-guard&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 208.39.161.66 255.255.255.240&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 172.16.5.1 255.255.0.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt; nameif DMZ&lt;BR /&gt; security-level 50&lt;BR /&gt; ip address 192.168.0.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt; nameif management&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.1.1 255.255.255.0&lt;BR /&gt; management-only&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone EST -5&lt;BR /&gt;clock summer-time EDT recurring 1 Sun Apr 2:00 last Sun Oct 2:00&lt;BR /&gt;object-group service wwww tcp&lt;BR /&gt; port-object eq www&lt;BR /&gt;access-list inside_access_in extended permit icmp any any&lt;BR /&gt;access-list inside_access_in extended permit tcp any any&lt;BR /&gt;access-list inside_access_in extended permit tcp host 172.16.1.22 eq 8002 any&lt;BR /&gt;access-list inside_access_in extended permit tcp host 172.16.1.22 eq domain any&lt;BR /&gt;access-list inside_access_in extended permit tcp host 172.16.1.22 eq www any&lt;BR /&gt;access-list inside_access_in extended permit tcp host 172.16.1.135 eq https any&lt;BR /&gt;access-list inside_access_in extended permit tcp host 172.16.1.135 eq www any&lt;BR /&gt;access-list acl_in extended permit icmp any any&lt;BR /&gt;access-list acl_out extended permit icmp any any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.22 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.43 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.201 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.51 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.52 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.53 any&lt;BR /&gt;access-list acl_out extended permit tcp any host 208.39.161.72 eq www&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.226 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.242 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.1 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.2.9 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.6 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.8 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.35 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.41 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.230 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.231 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.200 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.48 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.24 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.26 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.250 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.3.36 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.4.110 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.240 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.229 any&lt;BR /&gt;access-list acl_out extended permit ip host 192.168.0.2 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.241 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.221 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.222 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.223 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.224 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.225 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.227 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.228 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.232 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.233 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.234 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.235 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.243 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.2.118 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.130 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.131 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.132 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.7 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.202 any&lt;BR /&gt;access-list acl_out extended permit ip host 192.168.0.3 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.2.177 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.253 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.14 any&lt;BR /&gt;access-list acl_out extended permit tcp any host 172.16.3.135 eq 5806&lt;BR /&gt;access-list acl_out extended permit tcp any host 172.16.1.31 eq ssh&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.5.17 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.5.18 any&lt;BR /&gt;access-list acl_out extended permit ip host 172.16.1.135 any&lt;BR /&gt;access-list dns extended permit udp any any&lt;BR /&gt;access-list dnstcp extended permit tcp any any&lt;BR /&gt;access-list dmz_access_in extended permit icmp any any&lt;BR /&gt;access-list outside_access_in extended permit tcp any host 208.39.161.73 eq www&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.70 eq smtp&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.70 eq pop3&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.70 eq imap4&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.70 eq 444&lt;BR /&gt;access-list outside_acl extended permit icmp any any&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.70 eq www&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.70 eq ssh&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.67 eq 3389&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.70 eq irc&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.72 eq www&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.74 eq www&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.74 eq 3389&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.74 eq 8080&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.74 eq 1755&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.73 eq 3101&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.73 eq www&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.67 eq www&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.68 eq smtp&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.68 eq www&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq 3389&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq 407&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq 1417&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq 1418&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq 1419&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq 1420&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.76 eq 1417&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.76 eq 1418&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.76 eq 1419&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.76 eq 1420&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.76 eq 407&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq https&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq www&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq 7880&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq smtp&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq 8080&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.76 eq 8080&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.72 eq 444&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.72 eq 444&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq 444&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.76 eq 444&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq 4125&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.76 eq 4125&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.70 eq 3389&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.70 eq https&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.72 eq www&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.70 eq 443&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.66 eq https&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.66 eq 443&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.75 eq smtp&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.75 eq 25&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.66 eq smtp&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.68 eq https&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.70 eq 81&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.70 eq 6891&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.67 eq 5641&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.67 eq 5641&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq 4550&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq 5550&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.74 eq 2512&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.74 eq 2513&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.72 eq 1701&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.74 eq 1701&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.74 eq 1702&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq 1702&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.76 eq 1701&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.67 eq 210&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.67 eq 7090&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.67 eq 5151&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.68 eq 210&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.68 eq 7090&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.68 eq 5151&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.68 eq h323&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.68 eq 555&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.68 eq 556&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.68 eq 1718&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.68 eq 1719&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.71 eq https&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.69 eq smtp&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.69 eq pop3&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.69 eq imap4&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.69 eq www&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.69 eq citrix-ica&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit tcp any host 208.39.161.69 eq 1604&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.69 eq 1023&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.69 eq 1431&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.69 eq 8081&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.66 eq ftp&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.75 eq ftp&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.66 eq ftp-data&lt;BR /&gt;access-list outside_acl extended permit tcp any host 172.17.1.103 eq smtp&lt;BR /&gt;access-list outside_acl extended permit tcp any host 172.17.1.103 eq imap4&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.75 eq 4125&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.65 eq 4125&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.65 eq 4125&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.66 eq 4125&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.66 eq 4125&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.66 eq 3389&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.65 eq 3389&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.75 eq 3389&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.75 eq 5806&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.65 eq 5806&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.65 eq 5806&lt;BR /&gt;access-list outside_acl extended permit udp any host 208.39.161.75 eq 5806&lt;BR /&gt;access-list outside_acl extended permit tcp any host 208.39.161.71 eq ssh&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging list high-priority level errors&lt;BR /&gt;logging asdm informational&lt;BR /&gt;&lt;SPAN&gt;logging from-address &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:administrator@bordentown.k12.nj.us" target="_blank"&gt;administrator@bordentown.k12.nj.us&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;logging recipient-address &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:administrator@bordentown.k12.nj.us" target="_blank"&gt;administrator@bordentown.k12.nj.us&lt;/A&gt;&lt;SPAN&gt; level errors&lt;/SPAN&gt;&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu DMZ 1500&lt;BR /&gt;mtu management 1500&lt;BR /&gt;no failover&lt;BR /&gt;asdm image disk0:/asdm-508.bin&lt;BR /&gt;asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;nat-control&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;global (outside) 2 208.39.161.73 netmask 255.255.255.255&lt;BR /&gt;nat (inside) 3 172.16.1.7 255.255.255.255&lt;BR /&gt;nat (inside) 1 172.16.0.0 255.255.0.0&lt;BR /&gt;nat (inside) 1 172.17.0.0 255.255.0.0&lt;BR /&gt;nat (DMZ) 1 192.168.0.0 255.255.255.0&lt;BR /&gt;static (inside,outside) 208.39.161.74 172.16.1.26 netmask 255.255.255.255&lt;BR /&gt;static (inside,outside) 208.39.161.75 172.16.1.43 netmask 255.255.255.255&lt;BR /&gt;static (inside,outside) 208.39.161.67 172.16.1.201 netmask 255.255.255.255&lt;BR /&gt;static (inside,outside) 208.39.161.72 172.16.1.22 netmask 255.255.255.255&lt;BR /&gt;static (inside,outside) 208.39.161.69 172.16.1.200 netmask 255.255.255.255&lt;BR /&gt;static (inside,outside) 208.39.161.76 172.16.1.242 netmask 255.255.255.255&lt;BR /&gt;static (inside,outside) 208.39.161.70 172.16.1.6 netmask 255.255.255.255&lt;BR /&gt;static (inside,outside) 208.39.161.73 172.16.1.8 netmask 255.255.255.255&lt;BR /&gt;static (inside,outside) 208.39.161.68 172.16.1.35 netmask 255.255.255.255&lt;BR /&gt;static (inside,outside) 208.39.161.71 172.16.1.31 netmask 255.255.255.255&lt;BR /&gt;access-group outside_acl in interface outside&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 208.39.161.66 1&lt;BR /&gt;route inside 172.30.0.0 255.255.0.0 172.16.6.1 1&lt;BR /&gt;route inside 172.17.0.0 255.255.0.0 172.16.6.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00&lt;BR /&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;BR /&gt;timeout uauth 0:05:00 absolute&lt;BR /&gt;aaa-server TACACS+ protocol tacacs+&lt;BR /&gt;aaa-server RADIUS protocol radius&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;http server enable&lt;BR /&gt;http 0.0.0.0 0.0.0.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server community public&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet 208.39.161.65 255.255.255.255 inside&lt;BR /&gt;telnet 208.39.161.64 255.255.255.252 inside&lt;BR /&gt;telnet 172.16.0.0 255.255.0.0 inside&lt;BR /&gt;telnet 208.39.161.65 255.255.255.255 DMZ&lt;BR /&gt;telnet 208.39.161.64 255.255.255.252 DMZ&lt;BR /&gt;telnet timeout 30&lt;BR /&gt;ssh 63.214.17.0 255.255.255.0 outside&lt;BR /&gt;ssh 68.44.187.221 255.255.255.255 outside&lt;BR /&gt;ssh 65.217.171.0 255.255.255.0 outside&lt;BR /&gt;ssh 68.81.65.0 255.255.255.0 outside&lt;BR /&gt;ssh timeout 45&lt;BR /&gt;console timeout 0&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;&amp;nbsp; inspect netbios&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect http&lt;BR /&gt;&amp;nbsp; inspect ils&lt;BR /&gt;&amp;nbsp; inspect ftp&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;smtp-server 172.16.1.6&lt;BR /&gt;Cryptochecksum:65bcb0e163783400f6c65c2b8a780d0f&lt;BR /&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&amp;nbsp; Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-cannot-connect-to-site-through-appliance/m-p/1646017#M559331</guid>
      <dc:creator>dancumming</dc:creator>
      <dc:date>2019-03-11T20:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5510 cannot connect to site through appliance</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-cannot-connect-to-site-through-appliance/m-p/1646018#M559336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is Ricoh expecting a specific public IP Address? or they are accepting any public IP Addresses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see that you have configured static NAT translation for the appliance:&lt;/P&gt;&lt;P&gt;static (inside,outside) 208.39.161.68 172.16.1.35 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, it still uses the dynamic translation to 208.39.161.66. Can you please advise if you have clear the translation after making changes to the static NAT statement? If you haven't, try to clear: &lt;STRONG&gt;clear local 172.16.1.35&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the connection outbound or inbound?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The syslog messages look OK. It gets tear down because it didn't seem to get any replies back.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Mar 2011 04:38:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-cannot-connect-to-site-through-appliance/m-p/1646018#M559336</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-03-23T04:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5510 cannot connect to site through appliance</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-cannot-connect-to-site-through-appliance/m-p/1646019#M559339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ricoh accepting all public IP addresses.&amp;nbsp; I apologize, I made a typo in my original post.&amp;nbsp; The IP address of the Ricoh appliance is 172.16.1.135.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Mar 2011 12:13:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-cannot-connect-to-site-through-appliance/m-p/1646019#M559339</guid>
      <dc:creator>dancumming</dc:creator>
      <dc:date>2011-03-23T12:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5510 cannot connect to site through appliance</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-cannot-connect-to-site-through-appliance/m-p/1646020#M559340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, then it is correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Doesn't seem to be your ASA configuration issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't access the site too, so seems like Ricoh's issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Mar 2011 12:44:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-cannot-connect-to-site-through-appliance/m-p/1646020#M559340</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2011-03-23T12:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5510 cannot connect to site through appliance</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5510-cannot-connect-to-site-through-appliance/m-p/3359911#M559343</link>
      <description>&lt;P&gt;You will want to remove the post containing your un-scrubbed config that contains your Internet IPs as well as your enable password&lt;/P&gt;</description>
      <pubDate>Tue, 03 Apr 2018 19:52:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5510-cannot-connect-to-site-through-appliance/m-p/3359911#M559343</guid>
      <dc:creator>eisenberg</dc:creator>
      <dc:date>2018-04-03T19:52:53Z</dc:date>
    </item>
  </channel>
</rss>

