<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strange behaviour on network due to improperly configured AS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606924#M594405</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To reply to Marcin, when I run my ASDM GUI, under&amp;nbsp; configuration/firewall/access rules/IPv4 Network Objects, I do have 2 IP&amp;nbsp; addresses set for the mail server.&amp;nbsp; ADDON-INT points to 192.168.1.26&amp;nbsp; and ADDON-EXT points to the public IP address.&amp;nbsp; What other info do you&amp;nbsp; need?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Jan 2011 14:53:18 GMT</pubDate>
    <dc:creator>bluemookie</dc:creator>
    <dc:date>2011-01-13T14:53:18Z</dc:date>
    <item>
      <title>Strange behaviour on network due to improperly configured ASA?</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606919#M594395</link>
      <description>&lt;P&gt;My company recently deployed a new mail server last month.&amp;nbsp; Since then, every hour or so, one user will be unable to recieve mail.&amp;nbsp; It's an Ubuntu 10.04 server running Zimbra mail, and all clients are configured for POP access.&amp;nbsp; Most of the errors will say the the connection has been interrupted.&amp;nbsp; From the workstation, I will try to ping the mail server at 192.168.1.26 and get no reply.&amp;nbsp; If I go to the mail server and ping the workstation, after a couple seconds, there is data flow.&amp;nbsp; If I check the workstation again, it is now able to ping the server, and now, able to receive mail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have another linux mail server in place (192.168.1.25) that works without any problems.&amp;nbsp; We are getting rid of this old mail server in a couple months.&amp;nbsp; My concern is that when I modified the firewall (Cisco ASA 5505, 8.2(2)), I might not have done everything correctly or may have missed a step.&amp;nbsp; Is there anyone out there that can look at a show run log or give me some idea what to do?&amp;nbsp; I'm not well versed at Cisco stuff.&amp;nbsp; I administer this firewall using the ASDM software version 6.2(5).&amp;nbsp; What would be my first step at troubleshooting this strange behaviour?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606919#M594395</guid>
      <dc:creator>bluemookie</dc:creator>
      <dc:date>2019-03-11T19:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606920#M594396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kyle,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From your description it's clear to me that the behavior you describe is something stateful.&lt;/P&gt;&lt;P&gt;My first guess would be to check xlates.&lt;/P&gt;&lt;P&gt;Can you please confirm for me if there is static NAT entry for IP address of server between interface where server resides and the interface where client resides?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jan 2011 20:56:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606920#M594396</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2011-01-12T20:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606921#M594399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you tell me specifically how to provide this information to you using the ASDM GUI?&amp;nbsp; I can also use the "Command Line Interface" from the GUI to enter a command.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jan 2011 21:02:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606921#M594399</guid>
      <dc:creator>bluemookie</dc:creator>
      <dc:date>2011-01-12T21:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606922#M594401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From your description, it kind of sounds like this problem workstation and the mail server are both on the inside network.If that is the case, the firewall has no role in these issues.Regardless of that detail, anytime one client workstation presents a problem while others are happy, focus on that one workstation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe it has an old network card and/or driver. Maybe the network cable is bad or loose at either end. Maybe the drop is bad. Maybe the OS isn't patched. Maybe it's full of spyware and malware and is degraded or compromised.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a general troubleshooting technique, a centralized resource like a firewall is more likely to exhibit behavior that affects more than one client, since all clients traffic pass through it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 00:07:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606922#M594401</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2011-01-13T00:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606923#M594403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem is happening at random intervals throughout the day on random workstations.&amp;nbsp; The only common link is the mail server or the gateway/firewall.&amp;nbsp; I've done my due dilligence on troubleshooting the mail server and have found no problems with the softtware or hardware.&amp;nbsp; Could it be that xlates that the other guy was talking about?&amp;nbsp; Whatever xlates are....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 14:31:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606923#M594403</guid>
      <dc:creator>bluemookie</dc:creator>
      <dc:date>2011-01-13T14:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606924#M594405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To reply to Marcin, when I run my ASDM GUI, under&amp;nbsp; configuration/firewall/access rules/IPv4 Network Objects, I do have 2 IP&amp;nbsp; addresses set for the mail server.&amp;nbsp; ADDON-INT points to 192.168.1.26&amp;nbsp; and ADDON-EXT points to the public IP address.&amp;nbsp; What other info do you&amp;nbsp; need?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 14:53:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606924#M594405</guid>
      <dc:creator>bluemookie</dc:creator>
      <dc:date>2011-01-13T14:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606925#M594407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To reply to Marcin, when I run my ASDM GUI, under&amp;nbsp; configuration/firewall/access rules/IPv4 Network Objects, I do have 2 IP&amp;nbsp; addresses set for the mail server.&amp;nbsp; ADDON-INT points to 192.168.1.26&amp;nbsp; and ADDON-EXT points to the public IP address.&amp;nbsp; What other info do you&amp;nbsp; need?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 14:54:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606925#M594407</guid>
      <dc:creator>bluemookie</dc:creator>
      <dc:date>2011-01-13T14:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606926#M594412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kyle,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you attach running config? feel free to mask any information you don't want public to see (IP addresses on WAN, hashes of password).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 16:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606926#M594412</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2011-01-13T16:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606927#M594415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Result of the command: "sh run"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.2(2)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname AIM-ASA-FW&lt;/P&gt;&lt;P&gt;domain-name aim-cc.com&lt;/P&gt;&lt;P&gt;enable password 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;passwd mZkiFXWaEb.AkII6 encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 192.168.1.25 ACCMX-INT&lt;/P&gt;&lt;P&gt;name 192.168.1.44 ACCSUN-INT&lt;/P&gt;&lt;P&gt;name 192.168.1.28 ACCIRON-INT&lt;/P&gt;&lt;P&gt;name 192.168.1.43 HRMS-INT&lt;/P&gt;&lt;P&gt;name 69.130.7.116 ACCIRON-EXT&lt;/P&gt;&lt;P&gt;name 69.130.7.115 ACCMX-EXT&lt;/P&gt;&lt;P&gt;name 69.130.7.117 ACCSUN-EXT&lt;/P&gt;&lt;P&gt;name 69.130.7.118 FacileHR-EXT&lt;/P&gt;&lt;P&gt;name 69.130.7.119 HRMS-EXT&lt;/P&gt;&lt;P&gt;name 192.168.1.42 FacileHR-INT&lt;/P&gt;&lt;P&gt;name 69.130.7.120 NRIYP-EXT&lt;/P&gt;&lt;P&gt;name 192.168.1.27 NRIYP-INT&lt;/P&gt;&lt;P&gt;name 69.130.7.126 ADDON-EXT&lt;/P&gt;&lt;P&gt;name 192.168.1.26 ADDON-INT&lt;/P&gt;&lt;P&gt;name 192.168.1.21 Kyle&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; description LAN [INSIDE INTERFACE]&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; description T1 LINE [EXTERNAL INTERFACE]&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 69.130.7.114 255.255.255.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa822-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name aim-cc.com&lt;/P&gt;&lt;P&gt;object-group service aptela udp&lt;/P&gt;&lt;P&gt; description for Aptela Phones&lt;/P&gt;&lt;P&gt; port-object range 10000 20000&lt;/P&gt;&lt;P&gt; port-object range sip 5061&lt;/P&gt;&lt;P&gt;object-group service RDP tcp-udp&lt;/P&gt;&lt;P&gt; port-object range 3389 3389&lt;/P&gt;&lt;P&gt;object-group network BLACKLIST&lt;/P&gt;&lt;P&gt; network-object host 190.18.107.140&lt;/P&gt;&lt;P&gt; network-object host 121.244.106.2&lt;/P&gt;&lt;P&gt; network-object host 187.11.194.28&lt;/P&gt;&lt;P&gt; network-object host 188.2.237.199&lt;/P&gt;&lt;P&gt; network-object host 190.48.38.184&lt;/P&gt;&lt;P&gt; network-object host 201.47.229.72&lt;/P&gt;&lt;P&gt; network-object host 207.155.250.20&lt;/P&gt;&lt;P&gt; network-object host 209.85.160.56&lt;/P&gt;&lt;P&gt; network-object host 209.85.222.199&lt;/P&gt;&lt;P&gt; network-object host 63.246.10.50&lt;/P&gt;&lt;P&gt; network-object host 66.77.56.84&lt;/P&gt;&lt;P&gt; network-object host 83.168.1.28&lt;/P&gt;&lt;P&gt; network-object host 124.121.68.190&lt;/P&gt;&lt;P&gt; network-object host 174.35.12.35&lt;/P&gt;&lt;P&gt; network-object host 174.37.81.160&lt;/P&gt;&lt;P&gt; network-object host 188.192.97.110&lt;/P&gt;&lt;P&gt; network-object host 188.38.164.31&lt;/P&gt;&lt;P&gt; network-object host 208.75.123.162&lt;/P&gt;&lt;P&gt; network-object host 41.131.81.19&lt;/P&gt;&lt;P&gt; network-object host 65.168.1.28&lt;/P&gt;&lt;P&gt; network-object host 74.125.83.174&lt;/P&gt;&lt;P&gt; network-object host 74.125.83.184&lt;/P&gt;&lt;P&gt; network-object host 74.208.4.191&lt;/P&gt;&lt;P&gt; network-object host 82.230.100.32&lt;/P&gt;&lt;P&gt; network-object host 89.173.0.9&lt;/P&gt;&lt;P&gt; network-object host 89.228.129.126&lt;/P&gt;&lt;P&gt; network-object host 93.86.217.140&lt;/P&gt;&lt;P&gt; network-object host 123.21.107.67&lt;/P&gt;&lt;P&gt; network-object host 178.92.126.228&lt;/P&gt;&lt;P&gt; network-object host 189.10.192.107&lt;/P&gt;&lt;P&gt; network-object host 189.55.158.40&lt;/P&gt;&lt;P&gt; network-object host 189.70.186.225&lt;/P&gt;&lt;P&gt; network-object host 201.11.0.98&lt;/P&gt;&lt;P&gt; network-object host 207.250.58.8&lt;/P&gt;&lt;P&gt; network-object host 208.75.123.163&lt;/P&gt;&lt;P&gt; network-object host 208.75.123.226&lt;/P&gt;&lt;P&gt; network-object host 209.85.211.156&lt;/P&gt;&lt;P&gt; network-object host 209.85.221.146&lt;/P&gt;&lt;P&gt; network-object host 209.85.222.159&lt;/P&gt;&lt;P&gt; network-object host 211.170.114.154&lt;/P&gt;&lt;P&gt; network-object host 24.38.18.233&lt;/P&gt;&lt;P&gt; network-object host 64.49.82.68&lt;/P&gt;&lt;P&gt; network-object host 64.50.170.80&lt;/P&gt;&lt;P&gt; network-object host 65.217.159.98&lt;/P&gt;&lt;P&gt; network-object host 68.200.154.75&lt;/P&gt;&lt;P&gt; network-object host 74.208.4.195&lt;/P&gt;&lt;P&gt; network-object host 75.146.94.187&lt;/P&gt;&lt;P&gt; network-object host 80.14.122.109&lt;/P&gt;&lt;P&gt; network-object host 92.84.207.252&lt;/P&gt;&lt;P&gt; network-object host 93.153.0.155&lt;/P&gt;&lt;P&gt; network-object host 93.73.179.61&lt;/P&gt;&lt;P&gt; network-object host 96.252.6.79&lt;/P&gt;&lt;P&gt; network-object host 99.174.113.44&lt;/P&gt;&lt;P&gt; network-object host 117.6.64.137&lt;/P&gt;&lt;P&gt; network-object host 178.93.144.158&lt;/P&gt;&lt;P&gt; network-object host 190.245.171.12&lt;/P&gt;&lt;P&gt; network-object host 195.174.128.15&lt;/P&gt;&lt;P&gt; network-object host 199.238.178.138&lt;/P&gt;&lt;P&gt; network-object host 208.75.123.228&lt;/P&gt;&lt;P&gt; network-object host 209.85.217.193&lt;/P&gt;&lt;P&gt; network-object host 24.103.215.120&lt;/P&gt;&lt;P&gt; network-object host 74.208.4.194&lt;/P&gt;&lt;P&gt; network-object host 84.24.253.217&lt;/P&gt;&lt;P&gt; network-object host 98.117.251.114&lt;/P&gt;&lt;P&gt; network-object host 12.164.54.36&lt;/P&gt;&lt;P&gt; network-object host 160.75.192.3&lt;/P&gt;&lt;P&gt; network-object host 186.87.3.225&lt;/P&gt;&lt;P&gt; network-object host 190.174.208.57&lt;/P&gt;&lt;P&gt; network-object host 190.59.189.71&lt;/P&gt;&lt;P&gt; network-object host 201.4.160.18&lt;/P&gt;&lt;P&gt; network-object host 207.155.248.47&lt;/P&gt;&lt;P&gt; network-object host 208.111.169.150&lt;/P&gt;&lt;P&gt; network-object host 208.89.132.145&lt;/P&gt;&lt;P&gt; network-object host 209.85.160.46&lt;/P&gt;&lt;P&gt; network-object host 209.85.210.163&lt;/P&gt;&lt;P&gt; network-object host 62.248.88.175&lt;/P&gt;&lt;P&gt; network-object host 64.202.189.25&lt;/P&gt;&lt;P&gt; network-object host 66.165.70.198&lt;/P&gt;&lt;P&gt; network-object host 67.132.93.114&lt;/P&gt;&lt;P&gt; network-object host 69.174.244.158&lt;/P&gt;&lt;P&gt; network-object host 69.67.52.156&lt;/P&gt;&lt;P&gt; network-object host 69.74.142.209&lt;/P&gt;&lt;P&gt; network-object host 74.125.92.25&lt;/P&gt;&lt;P&gt; network-object host 74.203.196.51&lt;/P&gt;&lt;P&gt; network-object host 79.110.128.212&lt;/P&gt;&lt;P&gt; network-object host 87.70.217.30&lt;/P&gt;&lt;P&gt; network-object host 88.146.41.234&lt;/P&gt;&lt;P&gt; network-object host 88.76.127.77&lt;/P&gt;&lt;P&gt; network-object host 93.86.37.241&lt;/P&gt;&lt;P&gt; network-object host 94.70.115.94&lt;/P&gt;&lt;P&gt; network-object host 95.168.100.87&lt;/P&gt;&lt;P&gt; network-object host 123.201.69.230&lt;/P&gt;&lt;P&gt; network-object host 186.9.50.90&lt;/P&gt;&lt;P&gt; network-object host 189.73.235.78&lt;/P&gt;&lt;P&gt; network-object host 195.2.236.11&lt;/P&gt;&lt;P&gt; network-object host 202.63.105.220&lt;/P&gt;&lt;P&gt; network-object host 205.178.146.55&lt;/P&gt;&lt;P&gt; network-object host 205.178.146.57&lt;/P&gt;&lt;P&gt; network-object host 205.178.146.58&lt;/P&gt;&lt;P&gt; network-object host 205.178.146.61&lt;/P&gt;&lt;P&gt; network-object host 209.85.160.184&lt;/P&gt;&lt;P&gt; network-object host 209.85.221.171&lt;/P&gt;&lt;P&gt; network-object host 218.147.37.219&lt;/P&gt;&lt;P&gt; network-object host 64.120.250.82&lt;/P&gt;&lt;P&gt; network-object host 66.227.62.183&lt;/P&gt;&lt;P&gt; network-object host 67.228.227.25&lt;/P&gt;&lt;P&gt; network-object host 87.109.179.247&lt;/P&gt;&lt;P&gt; network-object host 87.163.5.34&lt;/P&gt;&lt;P&gt; network-object host 89.78.170.200&lt;/P&gt;&lt;P&gt; network-object host 89.78.3.139&lt;/P&gt;&lt;P&gt; network-object host 92.29.204.146&lt;/P&gt;&lt;P&gt; network-object host 94.189.180.81&lt;/P&gt;&lt;P&gt; network-object host 95.180.64.244&lt;/P&gt;&lt;P&gt; network-object host 122.169.182.129&lt;/P&gt;&lt;P&gt; network-object host 122.169.182.213&lt;/P&gt;&lt;P&gt; network-object host 111.224.250.131&lt;/P&gt;&lt;P&gt; network-object host 115.184.136.110&lt;/P&gt;&lt;P&gt; network-object host 123.176.39.134&lt;/P&gt;&lt;P&gt; network-object host 123.237.6.173&lt;/P&gt;&lt;P&gt; network-object host 209.250.243.135&lt;/P&gt;&lt;P&gt; network-object host 216.87.164.19&lt;/P&gt;&lt;P&gt; network-object host 217.23.15.143&lt;/P&gt;&lt;P&gt; network-object host 61.49.36.166&lt;/P&gt;&lt;P&gt; network-object host 67.138.108.151&lt;/P&gt;&lt;P&gt; network-object host 67.138.109.158&lt;/P&gt;&lt;P&gt; network-object host 111.118.156.170&lt;/P&gt;&lt;P&gt; network-object host 111.224.250.132&lt;/P&gt;&lt;P&gt; network-object host 111.224.250.133&lt;/P&gt;&lt;P&gt; network-object host 117.96.18.118&lt;/P&gt;&lt;P&gt; network-object host 121.151.149.220&lt;/P&gt;&lt;P&gt; network-object host 121.183.243.205&lt;/P&gt;&lt;P&gt; network-object host 123.19.170.237&lt;/P&gt;&lt;P&gt; network-object host 125.176.14.67&lt;/P&gt;&lt;P&gt; network-object host 183.107.94.151&lt;/P&gt;&lt;P&gt; network-object host 183.97.35.5&lt;/P&gt;&lt;P&gt; network-object host 186.104.230.5&lt;/P&gt;&lt;P&gt; network-object host 187.52.232.152&lt;/P&gt;&lt;P&gt; network-object host 189.211.159.220&lt;/P&gt;&lt;P&gt; network-object host 190.102.239.219&lt;/P&gt;&lt;P&gt; network-object host 190.235.13.233&lt;/P&gt;&lt;P&gt; network-object host 190.35.206.68&lt;/P&gt;&lt;P&gt; network-object host 190.7.109.65&lt;/P&gt;&lt;P&gt; network-object host 200.87.116.58&lt;/P&gt;&lt;P&gt; network-object host 204.188.223.222&lt;/P&gt;&lt;P&gt; network-object host 204.45.2.197&lt;/P&gt;&lt;P&gt; network-object host 208.83.232.3&lt;/P&gt;&lt;P&gt; network-object host 209.250.243.107&lt;/P&gt;&lt;P&gt; network-object host 209.250.243.15&lt;/P&gt;&lt;P&gt; network-object host 209.250.243.83&lt;/P&gt;&lt;P&gt; network-object host 212.200.197.62&lt;/P&gt;&lt;P&gt; network-object host 216.1.203.94&lt;/P&gt;&lt;P&gt; network-object host 220.227.80.226&lt;/P&gt;&lt;P&gt; network-object host 41.186.0.212&lt;/P&gt;&lt;P&gt; network-object host 41.249.114.143&lt;/P&gt;&lt;P&gt; network-object host 58.26.151.196&lt;/P&gt;&lt;P&gt; network-object host 62.19.51.5&lt;/P&gt;&lt;P&gt; network-object host 64.212.196.228&lt;/P&gt;&lt;P&gt; network-object host 67.138.109.68&lt;/P&gt;&lt;P&gt; network-object host 67.138.110.68&lt;/P&gt;&lt;P&gt; network-object host 68.142.134.126&lt;/P&gt;&lt;P&gt; network-object host 70.98.204.112&lt;/P&gt;&lt;P&gt; network-object host 70.98.205.140&lt;/P&gt;&lt;P&gt; network-object host 70.98.205.165&lt;/P&gt;&lt;P&gt; network-object host 74.63.107.46&lt;/P&gt;&lt;P&gt; network-object host 78.97.189.115&lt;/P&gt;&lt;P&gt; network-object host 79.106.2.46&lt;/P&gt;&lt;P&gt; network-object host 84.22.56.50&lt;/P&gt;&lt;P&gt; network-object host 89.123.211.42&lt;/P&gt;&lt;P&gt; network-object host 89.46.84.214&lt;/P&gt;&lt;P&gt; network-object host 90.169.74.53&lt;/P&gt;&lt;P&gt; network-object host 90.185.163.176&lt;/P&gt;&lt;P&gt; network-object host 95.35.16.79&lt;/P&gt;&lt;P&gt; network-object host 95.65.253.179&lt;/P&gt;&lt;P&gt;object-group service SMTP-587 tcp&lt;/P&gt;&lt;P&gt; description SMTP 587&lt;/P&gt;&lt;P&gt; port-object eq 587&lt;/P&gt;&lt;P&gt;object-group service smtp-587 tcp&lt;/P&gt;&lt;P&gt; description smtp 587&lt;/P&gt;&lt;P&gt; port-object eq 587&lt;/P&gt;&lt;P&gt;object-group protocol TCPUDP&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group service SMTP-465 tcp&lt;/P&gt;&lt;P&gt; port-object eq 465&lt;/P&gt;&lt;P&gt;object-group service TCP-993 tcp&lt;/P&gt;&lt;P&gt; port-object eq 993&lt;/P&gt;&lt;P&gt;object-group service TCP-995 tcp&lt;/P&gt;&lt;P&gt; port-object eq 995&lt;/P&gt;&lt;P&gt;object-group service TCP-7071 tcp&lt;/P&gt;&lt;P&gt; port-object eq 7071&lt;/P&gt;&lt;P&gt;object-group service TCP-10000 tcp&lt;/P&gt;&lt;P&gt; port-object eq 10000&lt;/P&gt;&lt;P&gt;object-group service TCP-8080 tcp&lt;/P&gt;&lt;P&gt; port-object eq 8080&lt;/P&gt;&lt;P&gt;object-group service TCP-8443 tcp&lt;/P&gt;&lt;P&gt; port-object eq 8443&lt;/P&gt;&lt;P&gt;object-group service TCP-23781 tcp&lt;/P&gt;&lt;P&gt; port-object eq 23781&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended deny tcp object-group BLACKLIST any eq smtp inactive&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit ip any host ACCSUN-EXT&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any eq www host ACCSUN-EXT eq www&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit ip any host FacileHR-EXT&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any eq www host FacileHR-EXT eq www&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit ip any host ACCSUN-INT&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit ip any host FacileHR-INT&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any eq www host ACCSUN-INT eq www&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any eq www host FacileHR-INT eq www&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host ACCSUN-EXT eq ssh&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any eq ssh host FacileHR-EXT eq ssh&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit ip any host ACCMX-EXT&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit object-group TCPUDP any host ADDON-EXT eq www&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit ip any host ADDON-EXT&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit ip any host ACCIRON-EXT&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit ip any host NRIYP-EXT&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host NRIYP-EXT eq www&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit udp any any object-group aptela&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit udp any host 64.50.254.253 inactive&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit ip any host HRMS-EXT&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host HRMS-EXT&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit ip any host HRMS-INT&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host HRMS-INT&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended deny ip host 216.101.194.154 any&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended deny tcp host 216.101.194.154 any&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended deny udp host 216.101.194.154 any&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any any eq 15250&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any eq 3389 any eq 3389&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any eq 23781 host 192.168.1.121 eq 23781&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any eq smtp any eq smtp inactive&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended deny ip any host 192.168.1.188&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended deny tcp any host 192.168.1.188&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT eq smtp&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit object-group TCPUDP any host ADDON-EXT eq domain&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT eq ssh&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT eq https&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT object-group SMTP-587&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT object-group SMTP-465&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT object-group TCP-993&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT object-group TCP-995&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT eq imap4&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT eq pop3&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT object-group TCP-8080&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT object-group TCP-10000&lt;/P&gt;&lt;P&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT object-group TCP-8443&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit udp any any&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended deny ip host 216.101.194.154 any&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended deny tcp host 216.101.194.154 any&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended deny udp host 216.101.194.154 any&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any host ADDON-EXT object-group TCP-7071&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any host ADDON-EXT object-group TCP-10000&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any host ADDON-EXT object-group TCP-8080&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any host Kyle object-group TCP-23781&lt;/P&gt;&lt;P&gt;access-list inside_access_out extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list inside_access_out extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list inside_access_out extended permit udp any any&lt;/P&gt;&lt;P&gt;access-list inside_access_out extended permit tcp any eq 3389 any eq 3389&lt;/P&gt;&lt;P&gt;access-list inside_access_out extended permit tcp any eq domain any eq domain&lt;/P&gt;&lt;P&gt;access-list inside_access_out extended permit udp any eq domain any eq domain&lt;/P&gt;&lt;P&gt;access-list inside_access_out extended permit tcp any eq www any eq www&lt;/P&gt;&lt;P&gt;access-list inside_access_out extended permit udp any eq www any eq www&lt;/P&gt;&lt;P&gt;access-list inside_access_out extended permit tcp any eq https any eq https&lt;/P&gt;&lt;P&gt;access-list inside_access_out extended permit udp any eq 443 any eq 443&lt;/P&gt;&lt;P&gt;access-list inside_access_out extended permit tcp any eq smtp any eq smtp&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-625.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp outside HRMS-INT 0019.d137.8533&lt;/P&gt;&lt;P&gt;arp inside HRMS-INT 0019.d137.8533&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (inside,outside) ACCMX-EXT ACCMX-INT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) ACCSUN-EXT ACCSUN-INT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (outside,inside) ACCSUN-INT ACCSUN-EXT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (outside,inside) ACCIRON-INT ACCIRON-EXT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (outside,inside) HRMS-INT HRMS-EXT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (outside,inside) FacileHR-INT FacileHR-EXT netmask 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;static (inside,outside) FacileHR-EXT FacileHR-INT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) HRMS-EXT HRMS-INT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) ACCIRON-EXT ACCIRON-INT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) NRIYP-EXT NRIYP-INT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (outside,inside) NRIYP-INT NRIYP-EXT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) ADDON-EXT ADDON-INT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (outside,inside) ADDON-INT ADDON-EXT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group inside_access_out out interface inside&lt;/P&gt;&lt;P&gt;access-group outside_in_inside in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 69.130.7.113 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication http console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication telnet console LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;snmp-server location AIM Computer Consulting - Closet&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;snmp-server contact Red Level Networks - &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:support@redlevelnetworks.com"&gt;support@redlevelnetworks.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;telnet 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 30&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;ssh timeout 15&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd dns ACCMX-INT ADDON-INT&lt;/P&gt;&lt;P&gt;dhcpd domain aim-cc.com&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.150-192.168.1.250 inside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics&lt;/P&gt;&lt;P&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;/P&gt;&lt;P&gt;ssl encryption aes256-sha1 aes128-sha1 3des-sha1 des-sha1&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;username redlevel password OqxvfJhMsUFUOSg7 encrypted privilege 15&lt;/P&gt;&lt;P&gt;username aimfwadm password a87SLutMml8bG8MZ encrypted privilege 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;policy-map global-policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;call-home&lt;/P&gt;&lt;P&gt; profile CiscoTAC-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no active&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address http &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://tools.cisco.com/its/service/oddce/services/DDCEService"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address email &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:callhome@cisco.com"&gt;callhome@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination transport-method http&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;/P&gt;&lt;P&gt;Cryptochecksum:a7feb075228263020177238df1fe1ecb&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 17:08:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606927#M594415</guid>
      <dc:creator>bluemookie</dc:creator>
      <dc:date>2011-01-13T17:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606928#M594419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;static (inside,outside) NRIYP-EXT NRIYP-INT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (outside,inside) NRIYP-INT NRIYP-EXT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,outside) ADDON-EXT ADDON-INT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (outside,inside) ADDON-INT ADDON-EXT netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;Thos NATs look wrong to me (and more).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You only need to have static (inside,outside) EXTERNAL_IP INTERNAL_IP most of the time. Creating static NAT the other way ... well not needed and probably asking for trouble, unless some particular functionality is intended with this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please remove unnecessary outside,inside NAT statments (and remember that you need to do "clear xlate" after doing any chnages to static config - some traffic might be lost)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 18:45:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606928#M594419</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2011-01-13T18:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606929#M594423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All 4 of those entries are incorrect?&amp;nbsp; Or just number 2 and 4?&amp;nbsp; Can you instruct me on how to remove those two using the ASDM graphical interface?&amp;nbsp; Would I find those entries under Configuration/Firewall/NAT Rules?&amp;nbsp; There, I have 2 sections, inside and outside.&amp;nbsp; Inside has 7 static rules, outside has 6 static rules.&amp;nbsp; Am I removing 2 entries from this table?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 19:16:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606929#M594423</guid>
      <dc:creator>bluemookie</dc:creator>
      <dc:date>2011-01-13T19:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606930#M594425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay, I removed those entries.&amp;nbsp; Here's what my SH RUN looks like now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "sh run"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 8.2(2) &lt;BR /&gt;!&lt;BR /&gt;hostname AIM-ASA-FW&lt;BR /&gt;domain-name aim-cc.com&lt;BR /&gt;enable password 2KFQnbNIdI.2KYOU encrypted&lt;BR /&gt;passwd mZkiFXWaEb.AkII6 encrypted&lt;BR /&gt;names&lt;BR /&gt;name 192.168.1.25 ACCMX-INT&lt;BR /&gt;name 192.168.1.44 ACCSUN-INT&lt;BR /&gt;name 192.168.1.28 ACCIRON-INT&lt;BR /&gt;name 192.168.1.43 HRMS-INT&lt;BR /&gt;name 69.130.7.116 ACCIRON-EXT&lt;BR /&gt;name 69.130.7.115 ACCMX-EXT&lt;BR /&gt;name 69.130.7.117 ACCSUN-EXT&lt;BR /&gt;name 69.130.7.118 FacileHR-EXT&lt;BR /&gt;name 69.130.7.119 HRMS-EXT&lt;BR /&gt;name 192.168.1.42 FacileHR-INT&lt;BR /&gt;name 69.130.7.120 NRIYP-EXT&lt;BR /&gt;name 69.130.7.126 ADDON-EXT&lt;BR /&gt;name 192.168.1.26 ADDON-INT&lt;BR /&gt;name 192.168.1.21 Kyle&lt;BR /&gt;name 192.168.1.30 NRIYP-INT&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; description LAN [INSIDE INTERFACE]&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.1.1 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt; description T1 LINE [EXTERNAL INTERFACE]&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 69.130.7.114 255.255.255.240 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa822-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone EST -5&lt;BR /&gt;clock summer-time EDT recurring&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt; domain-name aim-cc.com&lt;BR /&gt;object-group service aptela udp&lt;BR /&gt; description for Aptela Phones&lt;BR /&gt; port-object range 10000 20000&lt;BR /&gt; port-object range sip 5061&lt;BR /&gt;object-group service RDP tcp-udp&lt;BR /&gt; port-object range 3389 3389&lt;BR /&gt;object-group network BLACKLIST&lt;BR /&gt; network-object host 190.18.107.140&lt;BR /&gt; network-object host 121.244.106.2&lt;BR /&gt; network-object host 187.11.194.28&lt;BR /&gt; network-object host 188.2.237.199&lt;BR /&gt; network-object host 190.48.38.184&lt;BR /&gt; network-object host 201.47.229.72&lt;BR /&gt; network-object host 207.155.250.20&lt;BR /&gt; network-object host 209.85.160.56&lt;BR /&gt; network-object host 209.85.222.199&lt;BR /&gt; network-object host 63.246.10.50&lt;BR /&gt; network-object host 66.77.56.84&lt;BR /&gt; network-object host 83.168.1.28&lt;BR /&gt; network-object host 124.121.68.190&lt;BR /&gt; network-object host 174.35.12.35&lt;BR /&gt; network-object host 174.37.81.160&lt;BR /&gt; network-object host 188.192.97.110&lt;BR /&gt; network-object host 188.38.164.31&lt;BR /&gt; network-object host 208.75.123.162&lt;BR /&gt; network-object host 41.131.81.19&lt;BR /&gt; network-object host 65.168.1.28&lt;BR /&gt; network-object host 74.125.83.174&lt;BR /&gt; network-object host 74.125.83.184&lt;BR /&gt; network-object host 74.208.4.191&lt;BR /&gt; network-object host 82.230.100.32&lt;BR /&gt; network-object host 89.173.0.9&lt;BR /&gt; network-object host 89.228.129.126&lt;BR /&gt; network-object host 93.86.217.140&lt;BR /&gt; network-object host 123.21.107.67&lt;BR /&gt; network-object host 178.92.126.228&lt;BR /&gt; network-object host 189.10.192.107&lt;BR /&gt; network-object host 189.55.158.40&lt;BR /&gt; network-object host 189.70.186.225&lt;BR /&gt; network-object host 201.11.0.98&lt;BR /&gt; network-object host 207.250.58.8&lt;BR /&gt; network-object host 208.75.123.163&lt;BR /&gt; network-object host 208.75.123.226&lt;BR /&gt; network-object host 209.85.211.156&lt;BR /&gt; network-object host 209.85.221.146&lt;BR /&gt; network-object host 209.85.222.159&lt;BR /&gt; network-object host 211.170.114.154&lt;BR /&gt; network-object host 24.38.18.233&lt;BR /&gt; network-object host 64.49.82.68&lt;BR /&gt; network-object host 64.50.170.80&lt;BR /&gt; network-object host 65.217.159.98&lt;BR /&gt; network-object host 68.200.154.75&lt;BR /&gt; network-object host 74.208.4.195&lt;BR /&gt; network-object host 75.146.94.187&lt;BR /&gt; network-object host 80.14.122.109&lt;BR /&gt; network-object host 92.84.207.252&lt;BR /&gt; network-object host 93.153.0.155&lt;BR /&gt; network-object host 93.73.179.61&lt;BR /&gt; network-object host 96.252.6.79&lt;BR /&gt; network-object host 99.174.113.44&lt;BR /&gt; network-object host 117.6.64.137&lt;BR /&gt; network-object host 178.93.144.158&lt;BR /&gt; network-object host 190.245.171.12&lt;BR /&gt; network-object host 195.174.128.15&lt;BR /&gt; network-object host 199.238.178.138&lt;BR /&gt; network-object host 208.75.123.228&lt;BR /&gt; network-object host 209.85.217.193&lt;BR /&gt; network-object host 24.103.215.120&lt;BR /&gt; network-object host 74.208.4.194&lt;BR /&gt; network-object host 84.24.253.217&lt;BR /&gt; network-object host 98.117.251.114&lt;BR /&gt; network-object host 12.164.54.36&lt;BR /&gt; network-object host 160.75.192.3&lt;BR /&gt; network-object host 186.87.3.225&lt;BR /&gt; network-object host 190.174.208.57&lt;BR /&gt; network-object host 190.59.189.71&lt;BR /&gt; network-object host 201.4.160.18&lt;BR /&gt; network-object host 207.155.248.47&lt;BR /&gt; network-object host 208.111.169.150&lt;BR /&gt; network-object host 208.89.132.145&lt;BR /&gt; network-object host 209.85.160.46&lt;BR /&gt; network-object host 209.85.210.163&lt;BR /&gt; network-object host 62.248.88.175&lt;BR /&gt; network-object host 64.202.189.25&lt;BR /&gt; network-object host 66.165.70.198&lt;BR /&gt; network-object host 67.132.93.114&lt;BR /&gt; network-object host 69.174.244.158&lt;BR /&gt; network-object host 69.67.52.156&lt;BR /&gt; network-object host 69.74.142.209&lt;BR /&gt; network-object host 74.125.92.25&lt;BR /&gt; network-object host 74.203.196.51&lt;BR /&gt; network-object host 79.110.128.212&lt;BR /&gt; network-object host 87.70.217.30&lt;BR /&gt; network-object host 88.146.41.234&lt;BR /&gt; network-object host 88.76.127.77&lt;BR /&gt; network-object host 93.86.37.241&lt;BR /&gt; network-object host 94.70.115.94&lt;BR /&gt; network-object host 95.168.100.87&lt;BR /&gt; network-object host 123.201.69.230&lt;BR /&gt; network-object host 186.9.50.90&lt;BR /&gt; network-object host 189.73.235.78&lt;BR /&gt; network-object host 195.2.236.11&lt;BR /&gt; network-object host 202.63.105.220&lt;BR /&gt; network-object host 205.178.146.55&lt;BR /&gt; network-object host 205.178.146.57&lt;BR /&gt; network-object host 205.178.146.58&lt;BR /&gt; network-object host 205.178.146.61&lt;BR /&gt; network-object host 209.85.160.184&lt;BR /&gt; network-object host 209.85.221.171&lt;BR /&gt; network-object host 218.147.37.219&lt;BR /&gt; network-object host 64.120.250.82&lt;BR /&gt; network-object host 66.227.62.183&lt;BR /&gt; network-object host 67.228.227.25&lt;BR /&gt; network-object host 87.109.179.247&lt;BR /&gt; network-object host 87.163.5.34&lt;BR /&gt; network-object host 89.78.170.200&lt;BR /&gt; network-object host 89.78.3.139&lt;BR /&gt; network-object host 92.29.204.146&lt;BR /&gt; network-object host 94.189.180.81&lt;BR /&gt; network-object host 95.180.64.244&lt;BR /&gt; network-object host 122.169.182.129&lt;BR /&gt; network-object host 122.169.182.213&lt;BR /&gt; network-object host 111.224.250.131&lt;BR /&gt; network-object host 115.184.136.110&lt;BR /&gt; network-object host 123.176.39.134&lt;BR /&gt; network-object host 123.237.6.173&lt;BR /&gt; network-object host 209.250.243.135&lt;BR /&gt; network-object host 216.87.164.19&lt;BR /&gt; network-object host 217.23.15.143&lt;BR /&gt; network-object host 61.49.36.166&lt;BR /&gt; network-object host 67.138.108.151&lt;BR /&gt; network-object host 67.138.109.158&lt;BR /&gt; network-object host 111.118.156.170&lt;BR /&gt; network-object host 111.224.250.132&lt;BR /&gt; network-object host 111.224.250.133&lt;BR /&gt; network-object host 117.96.18.118&lt;BR /&gt; network-object host 121.151.149.220&lt;BR /&gt; network-object host 121.183.243.205&lt;BR /&gt; network-object host 123.19.170.237&lt;BR /&gt; network-object host 125.176.14.67&lt;BR /&gt; network-object host 183.107.94.151&lt;BR /&gt; network-object host 183.97.35.5&lt;BR /&gt; network-object host 186.104.230.5&lt;BR /&gt; network-object host 187.52.232.152&lt;BR /&gt; network-object host 189.211.159.220&lt;BR /&gt; network-object host 190.102.239.219&lt;BR /&gt; network-object host 190.235.13.233&lt;BR /&gt; network-object host 190.35.206.68&lt;BR /&gt; network-object host 190.7.109.65&lt;BR /&gt; network-object host 200.87.116.58&lt;BR /&gt; network-object host 204.188.223.222&lt;BR /&gt; network-object host 204.45.2.197&lt;BR /&gt; network-object host 208.83.232.3&lt;BR /&gt; network-object host 209.250.243.107&lt;BR /&gt; network-object host 209.250.243.15&lt;BR /&gt; network-object host 209.250.243.83&lt;BR /&gt; network-object host 212.200.197.62&lt;BR /&gt; network-object host 216.1.203.94&lt;BR /&gt; network-object host 220.227.80.226&lt;BR /&gt; network-object host 41.186.0.212&lt;BR /&gt; network-object host 41.249.114.143&lt;BR /&gt; network-object host 58.26.151.196&lt;BR /&gt; network-object host 62.19.51.5&lt;BR /&gt; network-object host 64.212.196.228&lt;BR /&gt; network-object host 67.138.109.68&lt;BR /&gt; network-object host 67.138.110.68&lt;BR /&gt; network-object host 68.142.134.126&lt;BR /&gt; network-object host 70.98.204.112&lt;BR /&gt; network-object host 70.98.205.140&lt;BR /&gt; network-object host 70.98.205.165&lt;BR /&gt; network-object host 74.63.107.46&lt;BR /&gt; network-object host 78.97.189.115&lt;BR /&gt; network-object host 79.106.2.46&lt;BR /&gt; network-object host 84.22.56.50&lt;BR /&gt; network-object host 89.123.211.42&lt;BR /&gt; network-object host 89.46.84.214&lt;BR /&gt; network-object host 90.169.74.53&lt;BR /&gt; network-object host 90.185.163.176&lt;BR /&gt; network-object host 95.35.16.79&lt;BR /&gt; network-object host 95.65.253.179&lt;BR /&gt;object-group service SMTP-587 tcp&lt;BR /&gt; description SMTP 587&lt;BR /&gt; port-object eq 587&lt;BR /&gt;object-group service smtp-587 tcp&lt;BR /&gt; description smtp 587&lt;BR /&gt; port-object eq 587&lt;BR /&gt;object-group protocol TCPUDP&lt;BR /&gt; protocol-object udp&lt;BR /&gt; protocol-object tcp&lt;BR /&gt;object-group service SMTP-465 tcp&lt;BR /&gt; port-object eq 465&lt;BR /&gt;object-group service TCP-993 tcp&lt;BR /&gt; port-object eq 993&lt;BR /&gt;object-group service TCP-995 tcp&lt;BR /&gt; port-object eq 995&lt;BR /&gt;object-group service TCP-7071 tcp&lt;BR /&gt; port-object eq 7071&lt;BR /&gt;object-group service TCP-10000 tcp&lt;BR /&gt; port-object eq 10000&lt;BR /&gt;object-group service TCP-8080 tcp&lt;BR /&gt; port-object eq 8080&lt;BR /&gt;object-group service TCP-8443 tcp&lt;BR /&gt; port-object eq 8443&lt;BR /&gt;object-group service TCP-23781 tcp&lt;BR /&gt; port-object eq 23781&lt;BR /&gt;access-list outside_in_inside extended deny tcp object-group BLACKLIST any eq smtp inactive &lt;BR /&gt;access-list outside_in_inside extended permit ip any host ACCSUN-EXT &lt;BR /&gt;access-list outside_in_inside extended permit tcp any eq www host ACCSUN-EXT eq www &lt;BR /&gt;access-list outside_in_inside extended permit ip any host FacileHR-EXT &lt;BR /&gt;access-list outside_in_inside extended permit tcp any eq www host FacileHR-EXT eq www &lt;BR /&gt;access-list outside_in_inside extended permit ip any host ACCSUN-INT &lt;BR /&gt;access-list outside_in_inside extended permit ip any host FacileHR-INT &lt;BR /&gt;access-list outside_in_inside extended permit tcp any eq www host ACCSUN-INT eq www &lt;BR /&gt;access-list outside_in_inside extended permit tcp any eq www host FacileHR-INT eq www &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host ACCSUN-EXT eq ssh &lt;BR /&gt;access-list outside_in_inside extended permit tcp any eq ssh host FacileHR-EXT eq ssh &lt;BR /&gt;access-list outside_in_inside extended permit ip any host ACCMX-EXT &lt;BR /&gt;access-list outside_in_inside extended permit object-group TCPUDP any host ADDON-EXT eq www &lt;BR /&gt;access-list outside_in_inside extended permit ip any host ADDON-EXT &lt;BR /&gt;access-list outside_in_inside extended permit ip any host ACCIRON-EXT &lt;BR /&gt;access-list outside_in_inside extended permit ip any host NRIYP-EXT &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host NRIYP-EXT eq www &lt;BR /&gt;access-list outside_in_inside extended permit udp any any object-group aptela &lt;BR /&gt;access-list outside_in_inside extended permit udp any host 64.50.254.253 inactive &lt;BR /&gt;access-list outside_in_inside extended permit ip any host HRMS-EXT &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host HRMS-EXT &lt;BR /&gt;access-list outside_in_inside extended permit ip any host HRMS-INT &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host HRMS-INT &lt;BR /&gt;access-list outside_in_inside extended deny ip host 216.101.194.154 any &lt;BR /&gt;access-list outside_in_inside extended deny tcp host 216.101.194.154 any &lt;BR /&gt;access-list outside_in_inside extended deny udp host 216.101.194.154 any &lt;BR /&gt;access-list outside_in_inside extended permit tcp any any eq 15250 &lt;BR /&gt;access-list outside_in_inside extended permit tcp any eq 3389 any eq 3389 &lt;BR /&gt;access-list outside_in_inside extended permit tcp any eq 23781 host 192.168.1.121 eq 23781 &lt;BR /&gt;access-list outside_in_inside extended permit tcp any eq smtp any eq smtp inactive &lt;BR /&gt;access-list outside_in_inside extended deny ip any host 192.168.1.188 &lt;BR /&gt;access-list outside_in_inside extended deny tcp any host 192.168.1.188 &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT eq smtp &lt;BR /&gt;access-list outside_in_inside extended permit object-group TCPUDP any host ADDON-EXT eq domain &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT eq ssh &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT eq https &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT object-group SMTP-587 &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT object-group SMTP-465 &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT object-group TCP-993 &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT object-group TCP-995 &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT eq imap4 &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT eq pop3 &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT object-group TCP-8080 &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT object-group TCP-10000 &lt;BR /&gt;access-list outside_in_inside extended permit tcp any host ADDON-EXT object-group TCP-8443 &lt;BR /&gt;access-list inside_access_in extended permit ip any any &lt;BR /&gt;access-list inside_access_in extended permit tcp any any &lt;BR /&gt;access-list inside_access_in extended permit udp any any &lt;BR /&gt;access-list inside_access_in extended deny ip host 216.101.194.154 any &lt;BR /&gt;access-list inside_access_in extended deny tcp host 216.101.194.154 any &lt;BR /&gt;access-list inside_access_in extended deny udp host 216.101.194.154 any &lt;BR /&gt;access-list inside_access_in extended permit tcp any host ADDON-EXT object-group TCP-7071 &lt;BR /&gt;access-list inside_access_in extended permit tcp any host ADDON-EXT object-group TCP-10000 &lt;BR /&gt;access-list inside_access_in extended permit tcp any host ADDON-EXT object-group TCP-8080 &lt;BR /&gt;access-list inside_access_in extended permit tcp any host Kyle object-group TCP-23781 &lt;BR /&gt;access-list inside_access_out extended permit tcp any any &lt;BR /&gt;access-list inside_access_out extended permit ip any any &lt;BR /&gt;access-list inside_access_out extended permit udp any any &lt;BR /&gt;access-list inside_access_out extended permit tcp any eq 3389 any eq 3389 &lt;BR /&gt;access-list inside_access_out extended permit tcp any eq domain any eq domain &lt;BR /&gt;access-list inside_access_out extended permit udp any eq domain any eq domain &lt;BR /&gt;access-list inside_access_out extended permit tcp any eq www any eq www &lt;BR /&gt;access-list inside_access_out extended permit udp any eq www any eq www &lt;BR /&gt;access-list inside_access_out extended permit tcp any eq https any eq https &lt;BR /&gt;access-list inside_access_out extended permit udp any eq 443 any eq 443 &lt;BR /&gt;access-list inside_access_out extended permit tcp any eq smtp any eq smtp &lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;icmp permit any inside&lt;BR /&gt;icmp permit any outside&lt;BR /&gt;asdm image disk0:/asdm-625.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp outside HRMS-INT 0019.d137.8533 &lt;BR /&gt;arp inside HRMS-INT 0019.d137.8533 &lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 1 192.168.1.0 255.255.255.0&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;static (inside,outside) ACCMX-EXT ACCMX-INT netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) ACCSUN-EXT ACCSUN-INT netmask 255.255.255.255 &lt;BR /&gt;static (outside,inside) ACCSUN-INT ACCSUN-EXT netmask 255.255.255.255 &lt;BR /&gt;static (outside,inside) ACCIRON-INT ACCIRON-EXT netmask 255.255.255.255 &lt;BR /&gt;static (outside,inside) HRMS-INT HRMS-EXT netmask 255.255.255.255 &lt;BR /&gt;static (outside,inside) FacileHR-INT FacileHR-EXT netmask 255.255.255.255 dns &lt;BR /&gt;static (inside,outside) FacileHR-EXT FacileHR-INT netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) HRMS-EXT HRMS-INT netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) ACCIRON-EXT ACCIRON-INT netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) NRIYP-EXT NRIYP-INT netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) ADDON-EXT ADDON-INT netmask 255.255.255.255 &lt;BR /&gt;access-group inside_access_in in interface inside&lt;BR /&gt;access-group inside_access_out out interface inside&lt;BR /&gt;access-group outside_in_inside in interface outside&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 69.130.7.113 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;aaa authentication http console LOCAL &lt;BR /&gt;aaa authentication telnet console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside&lt;BR /&gt;snmp-server location AIM Computer Consulting - Closet&lt;BR /&gt;&lt;SPAN&gt;snmp-server contact Red Level Networks - &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:support@redlevelnetworks.com"&gt;support@redlevelnetworks.com&lt;/A&gt;&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet 0.0.0.0 0.0.0.0 inside&lt;BR /&gt;telnet timeout 30&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;ssh timeout 15&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd dns ACCMX-INT ADDON-INT&lt;BR /&gt;dhcpd domain aim-cc.com&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 192.168.1.150-192.168.1.250 inside&lt;BR /&gt;dhcpd enable inside&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics&lt;BR /&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;BR /&gt;ssl encryption aes256-sha1 aes128-sha1 3des-sha1 des-sha1&lt;BR /&gt;webvpn&lt;BR /&gt;username redlevel password OqxvfJhMsUFUOSg7 encrypted privilege 15&lt;BR /&gt;username aimfwadm password a87SLutMml8bG8MZ encrypted privilege 15&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;&amp;nbsp; inspect ip-options &lt;BR /&gt;policy-map global-policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;call-home&lt;BR /&gt; profile CiscoTAC-1&lt;BR /&gt;&amp;nbsp; no active&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; destination address http &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://tools.cisco.com/its/service/oddce/services/DDCEService"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; destination address email &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:callhome@cisco.com"&gt;callhome@cisco.com&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; destination transport-method http&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:dc3a634149d26ea33b9129e154015536&lt;BR /&gt;: end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 21:04:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606930#M594425</guid>
      <dc:creator>bluemookie</dc:creator>
      <dc:date>2011-01-13T21:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606931#M594427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kyle,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config looks better now &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;... did you clear existing xlates?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I would like you do to is to add those lines:&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;logging buffer-size 1000000&lt;/P&gt;&lt;P&gt;logging buffered info&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;to the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Than execute a failing test and check:&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;show logg | i IP_ADDRESS_OF_CLIENT&lt;/P&gt;&lt;P&gt;show logg | i IP_ADDRESS_OF_SERVER&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And attach all and any output you see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2011 22:34:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606931#M594427</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2011-01-13T22:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606932#M594429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I did clear xlates as you instructed.&amp;nbsp; Since I am using the GUI to do this, and not telnet or whatever most people use, I'm probably not seeing what you would normally see.&amp;nbsp; This is my output for the lines you gave me...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "logging buffer-size 1000000"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command has been sent to the device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "logging buffered info"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command has been sent to the device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "show logg | i IP_ADDRESS_OF_CLIENT"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command has been sent to the device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "show logg | i IP_ADDRESS_OF_SERVER"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command has been sent to the device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I be using something else other than the ASDM GUI?&amp;nbsp; I haven't seen any failures since yesterday afternoon.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jan 2011 15:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606932#M594429</guid>
      <dc:creator>bluemookie</dc:creator>
      <dc:date>2011-01-14T15:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606933#M594431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kyle,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well obviously IP_ADDRESS_OF_CLIENT should be substituted with IP of client which is attempting to connect to server. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if the ASDM CLU access will return you the lines we need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASDM is probably not the best to do troubleshooting &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume no problem since yesterday afternoon is a good sign? How often was the problem happening before ;-D&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW xlate = translation table entry. static command introduces a static xlate into the table.. for clarity sake.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jan 2011 16:21:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606933#M594431</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2011-01-14T16:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606934#M594433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, what should I use?&amp;nbsp; Telnet?&amp;nbsp; Just telnet to it and log on as the normal user that I logon with on the GUI?&amp;nbsp; And I would see this problem once an hour.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jan 2011 16:26:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606934#M594433</guid>
      <dc:creator>bluemookie</dc:creator>
      <dc:date>2011-01-14T16:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: Strange behaviour on network due to improperly configured AS</title>
      <link>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606935#M594435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kyle,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Telnet/ssh access with same credentials you use for ASDM access should be fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you have not seen it for almost 24 hours, I'm hoping for the best &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jan 2011 16:34:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/strange-behaviour-on-network-due-to-improperly-configured-asa/m-p/1606935#M594435</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2011-01-14T16:34:54Z</dc:date>
    </item>
  </channel>
</rss>

