<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5520 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520/m-p/1529065#M615690</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thaer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to determine if the problem we're facing is with the server's not responding as they should or the ASA introducing latency, please arrange for wireshark captures to be taken on the server that is hosting the page.&lt;/P&gt;&lt;P&gt;The captures should give us a better picture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, these captures when analysed along side captures taken fron the ASA will be helpful in isolating the issue.&lt;/P&gt;&lt;P&gt;Please use the link below to understand the procedure behind running packet-captures on an ASA:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sundar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Nov 2010 01:33:41 GMT</pubDate>
    <dc:creator>susreeni</dc:creator>
    <dc:date>2010-11-29T01:33:41Z</dc:date>
    <item>
      <title>ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520/m-p/1529064#M615689</link>
      <description>&lt;P&gt;I have may be a problem in ASA firewall I configure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the nat and access-list and all other configuration that need&lt;/P&gt;&lt;P&gt;to secure my network but sometime the internet connection is lost fro the inside&lt;/P&gt;&lt;P&gt;or when the internet user need to brows the DMZ website I have a delay befor the page appear&lt;/P&gt;&lt;P&gt;my configuration is shown in the attachment file can any one help me to know if the configuration couses this problem or the problem from the network servers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN lang="EN"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 82.213.56.195 Webmailext&lt;/P&gt;&lt;P&gt;name 172.16.1.2 webmailint&lt;/P&gt;&lt;P&gt;name 82.213.56.197 webhrExt&lt;/P&gt;&lt;P&gt;name 172.16.1.3 webhrIn&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;nameif outside&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 82.213.56.194 255.255.255.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;nameif DMZ&lt;/P&gt;&lt;P&gt;security-level 50&lt;/P&gt;&lt;P&gt;ip address 172.16.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;no security-level&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt;nameif management&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns domain-lookup outside&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns name-server webmailint&lt;/P&gt;&lt;P&gt;dns name-server 217.66.226.8&lt;/P&gt;&lt;P&gt;dns name-server 192.168.1.15&lt;/P&gt;&lt;P&gt;object-group service VPNInUDP udp&lt;/P&gt;&lt;P&gt;port-object eq 5500&lt;/P&gt;&lt;P&gt;port-object eq isakmp&lt;/P&gt;&lt;P&gt;port-object eq 1701&lt;/P&gt;&lt;P&gt;object-group service msSQL udp&lt;/P&gt;&lt;P&gt;description MS-SQL Server&lt;/P&gt;&lt;P&gt;port-object eq www&lt;/P&gt;&lt;P&gt;port-object range 1433 1434&lt;/P&gt;&lt;P&gt;port-object range 150 150&lt;/P&gt;&lt;P&gt;port-object range 1215 1215&lt;/P&gt;&lt;P&gt;port-object range 118 118&lt;/P&gt;&lt;P&gt;access-list in-out extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list in-out extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list in-out extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list in-out extended permit tcp any host webhrExt eq www&lt;/P&gt;&lt;P&gt;access-list in-out extended permit tcp any host webhrExt eq pptp&lt;/P&gt;&lt;P&gt;access-list in-out extended permit tcp any host webhrExt eq sqlnet&lt;/P&gt;&lt;P&gt;access-list in-out extended permit tcp any host Webmailext eq pop3&lt;/P&gt;&lt;P&gt;access-list in-out extended permit tcp any host Webmailext eq imap4&lt;/P&gt;&lt;P&gt;access-list in-out extended permit tcp any host Webmailext eq smtp&lt;/P&gt;&lt;P&gt;access-list in-out extended permit tcp any host Webmailext eq www&lt;/P&gt;&lt;P&gt;access-list in-out extended permit tcp any host Webmailext eq https&lt;/P&gt;&lt;P&gt;access-list in-out extended permit udp any host webhrExt object-group VPNInUDP&lt;/P&gt;&lt;P&gt;access-list in-out extended permit udp any host webhrExt object-group msSQL&lt;/P&gt;&lt;P&gt;access-list in-out extended permit tcp any host Webmailext eq telnet&lt;/P&gt;&lt;P&gt;access-list dmz-in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list dmz-in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list dmz-in extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list dmz-in extended permit udp any any&lt;/P&gt;&lt;P&gt;access-list dmz-in extended permit gre any any&lt;/P&gt;&lt;P&gt;access-list no-nat extended permit ip 192.168.1.0 255.255.255.0 172.16.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-508.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;global (inside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list no-nat&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (DMZ) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (inside,DMZ) 192.168.1.0 192.168.1.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;static (DMZ,outside) Webmailext webmailint netmask 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;static (DMZ,outside) webhrExt webhrIn netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-group in-out in interface outside&lt;/P&gt;&lt;P&gt;access-group dmz-in in interface DMZ&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 82.213.56.193 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00&lt;/P&gt;&lt;P&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;username cisco password 3USUcOPFUiMCO4Jk encrypted privilege 15&lt;/P&gt;&lt;P&gt;aaa authentication http console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication telnet console LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;http 172.16.1.0 255.255.255.0 DMZ&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;telnet 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd lease 3600&lt;/P&gt;&lt;P&gt;dhcpd ping_timeout 50&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map exit&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;inspect ftp&lt;/P&gt;&lt;P&gt;inspect h323 h225&lt;/P&gt;&lt;P&gt;inspect h323 ras&lt;/P&gt;&lt;P&gt;inspect rsh&lt;/P&gt;&lt;P&gt;inspect rtsp&lt;/P&gt;&lt;P&gt;inspect esmtp&lt;/P&gt;&lt;P&gt;inspect sqlnet&lt;/P&gt;&lt;P&gt;inspect skinny&lt;/P&gt;&lt;P&gt;inspect sunrpc&lt;/P&gt;&lt;P&gt;inspect xdmcp&lt;/P&gt;&lt;P&gt;inspect sip&lt;/P&gt;&lt;P&gt;inspect netbios&lt;/P&gt;&lt;P&gt;inspect tftp&lt;/P&gt;&lt;P&gt;inspect dns maximum-length 512&lt;/P&gt;&lt;P&gt;policy-map typ&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;Cryptochecksum:9d222cc1013df87cb2fb85c426b97593&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:15:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520/m-p/1529064#M615689</guid>
      <dc:creator>ThaerJamous</dc:creator>
      <dc:date>2019-03-11T19:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520/m-p/1529065#M615690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thaer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to determine if the problem we're facing is with the server's not responding as they should or the ASA introducing latency, please arrange for wireshark captures to be taken on the server that is hosting the page.&lt;/P&gt;&lt;P&gt;The captures should give us a better picture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, these captures when analysed along side captures taken fron the ASA will be helpful in isolating the issue.&lt;/P&gt;&lt;P&gt;Please use the link below to understand the procedure behind running packet-captures on an ASA:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sundar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Nov 2010 01:33:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520/m-p/1529065#M615690</guid>
      <dc:creator>susreeni</dc:creator>
      <dc:date>2010-11-29T01:33:41Z</dc:date>
    </item>
  </channel>
</rss>

