<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5510 intervlan routing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538509#M616137</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;From DMZ to Internal , try bellow config:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;CODE&gt;hostname(config)# object network host-obj&lt;BR /&gt;2.hostname(config-network-object)# host &lt;/CODE&gt;&lt;SPAN style="font-family: Arial; color: #000000; font-size: 10pt;"&gt;172.25.154.107&lt;/SPAN&gt;&lt;BR /&gt;&lt;CODE&gt;3.hostname(config-network-object)# nat (inside,dmz) static &lt;/CODE&gt;&lt;SPAN style="font-family: Arial; color: #000000; font-size: 10pt;"&gt;172.25.130.250&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Access-list DMZ permit ip any host 172.25.130.250&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Access-group DMZ in interface DMZ2&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;And From Outside to DMZ, try the following:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG style="color: #000000; font-size: 10pt; font-family: Arial; "&gt;object network DMZ2_static&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG style="color: #000000; font-size: 10pt; font-family: Arial; "&gt;&lt;SPAN&gt; &lt;/SPAN&gt;host 192.25.154.107&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG style="color: #000000; font-size: 10pt; font-family: Arial; "&gt;&lt;SPAN&gt; &lt;/SPAN&gt;nat (DMZ2,OUT) static 192.25.152.246&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG&gt;&lt;SPAN style="color: #000000; font-size: 10pt;"&gt;access-list OUTSIDE_IN extended permit tcp any host &lt;/SPAN&gt;&lt;SPAN style="font-family: Arial; color: #000000; font-size: 10pt;"&gt;172.25.130.250 &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 10pt;"&gt;object-group PORT_GROUP&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG style=": ; color: #000000; font-size: 10pt; "&gt;access-group OUTSIDE_IN in interface OUT&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;HTH&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;Mohamed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Nov 2010 17:40:35 GMT</pubDate>
    <dc:creator>Mohamed Sobair</dc:creator>
    <dc:date>2010-11-30T17:40:35Z</dc:date>
    <item>
      <title>ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538500#M616128</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;Could you please help to advise? I have issue on my project . I have already setup the ASA 5510 and configured eth0 for outside ( security-level 0) , eth1 for DMZ (security-level 50 ) and eth3 for internal network ( security-level 100 ). I want to route / ftp to ping / ftp from each VLAN to another .&lt;/P&gt;&lt;P&gt;I have configured the necessary ACL to allow the traffic ( DMZ &amp;lt;=&amp;gt; Outside ) interfaces .&lt;/P&gt;&lt;P&gt;Using packet tracer from Outside to DMZ , the packet is allowed. But I can't ping / ftp from one interface to another . Pls. see the attached screen shot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But according to what i ve read from this forum, &lt;STRONG style="text-decoration: underline;"&gt;"&amp;nbsp; If you are trying inter-vlan routing, then make sure that both sub-interfaces have a nameif and security level set to same value."&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Does it apply to DMZ , internal and external interfaces with diff security level ? Really appreciate your advise since I am now confused.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:11:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538500#M616128</guid>
      <dc:creator>Nay Myo Tun</dc:creator>
      <dc:date>2019-03-11T19:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538501#M616129</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For traffic to and from inside and DMZ, you would need to configure static 1:1 NAT in addition to the access-list to permit the traffic through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming that your inside subnet is 172.25.152.0/24, then you would need to configure the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,dmz) 172.25.152.0 172.25.152.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then "clear xlate" after the above. You should be able to access to and from between inside and dmz, providing that you already configure the access-list to permit the traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Nov 2010 05:42:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538501#M616129</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-11-18T05:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538502#M616130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry,late response,Jennifer. I still cannot resolve .&lt;/P&gt;&lt;P&gt; My requirement is&lt;/P&gt;&lt;P&gt;( 1 )&amp;nbsp; I'd like to ssh/ ftp&amp;nbsp; from internal server to DMZ server&lt;/P&gt;&lt;P&gt;( 2 )&amp;nbsp; would like to ssh / telnet access to Router from internal network. ( currently no way to control/ configure RTR from internal segment unless using console access )&lt;/P&gt;&lt;P&gt;( 3 )&amp;nbsp; outside &amp;lt; --- &amp;gt; DMZ ftp traffic . And also But the current config still doen't fullfill my requirement. Kindly take note my FW is &lt;SPAN style="Courier New&amp;quot;: ; color: #000000; font-size: 10pt; font-family: &amp;quot; "&gt;ASA Version 8.3(1)with 5510 HW. My config is as per attach. What could be the blocking issue?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Nov 2010 15:41:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538502#M616130</guid>
      <dc:creator>Nay Myo Tun</dc:creator>
      <dc:date>2010-11-26T15:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538503#M616131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In firewall terminology, from Higher Security level to access lower securtiy level Only nat is required, From&amp;nbsp; Lower Security level to higher security level an access-list or conduit must be used to permit the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your configuration looks Ok except that you dont have dynamic Nat for the inside Network to DMZ and Outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For ASA version 8.3 , The configuration is slightly different, please add the following commands and check out your Access:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style=": ; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; line-height: 115%; Courier New&amp;quot;: ; color: #000000; font-size: 10pt; mso-ansi-language: EN-US; font-family: &amp;quot; mso-fareast-theme-font: minor-fareast; mso-fareast-font-family: 'Times New Roman'; "&gt;object network obj-192.25.130.0&amp;nbsp;&amp;nbsp; subnet 192.25.130.0 255.255.255.0&amp;nbsp;&amp;nbsp; nat (inside,outside) dynamic 192.25.152.250&lt;BR /&gt;object network obj-192.25.130.0-01&amp;nbsp;&amp;nbsp; subnet 192.25.130.0 255.255.255.0&amp;nbsp;&amp;nbsp; nat (inside,dmz1) dynamic 192.25.156.250&lt;BR /&gt;object network obj-192.25.130.0-02&amp;nbsp;&amp;nbsp; subnet 192.25.130.0 255.255.255.0&amp;nbsp;&amp;nbsp; nat (inside,dmz2) dynamic 192.25.154.250&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style=": ; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; line-height: 115%; Courier New&amp;quot;: ; color: #000000; font-size: 10pt; mso-ansi-language: EN-US; font-family: &amp;quot; mso-fareast-theme-font: minor-fareast; mso-fareast-font-family: 'Times New Roman'; "&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style=": ; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; line-height: 115%; Courier New&amp;quot;: ; color: #000000; font-size: 10pt; mso-ansi-language: EN-US; font-family: &amp;quot; mso-fareast-theme-font: minor-fareast; mso-fareast-font-family: 'Times New Roman'; "&gt;Mohamed&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Nov 2010 17:14:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538503#M616131</guid>
      <dc:creator>Mohamed Sobair</dc:creator>
      <dc:date>2010-11-26T17:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538504#M616132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi sobair,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks and really appreciate your expertise. I am now able to access the DMZ server/ External Router from the internal network.But still trying the opposite direction&amp;nbsp; from the lower security level to the higer security level. (&amp;nbsp; External to DMZ server , and DMZ server to Interal Network ).So should I configure just ACL only in order to permit the traffic from lower security to higher security ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Current Config is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;object-group service PORT_GROUPtcp&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;port-object eq echo&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;port-object eq ftp&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;port-object eq ssh&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 11pt; font-family: Cambria; color: #006fc0;"&gt;! Allow access from Internet to DMZ SVR&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;access-list OUT_IN extended permit tcp any host 192.25.154.107 object-group PORT_GROUP&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;Pls. see the attached for more detail.&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;BR /&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Nov 2010 12:26:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538504#M616132</guid>
      <dc:creator>Nay Myo Tun</dc:creator>
      <dc:date>2010-11-29T12:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538505#M616133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;if you want access from out to dmz then you need an ACL permitting the traffic from lower to higher security but you also have to do static nat from dmz server to outside.&lt;/P&gt;&lt;P&gt;For dmz to in you need an ACL&amp;nbsp; but you don't need static nat just dynamic nat from dmz to in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Nov 2010 13:59:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538505#M616133</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2010-11-29T13:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538506#M616134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No not only an ACL, you need static Nat from inside to DMZ&amp;nbsp; that allows access from DMZ network to the inside Network along with ACL applied on the DMZ interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Mohamed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Nov 2010 14:50:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538506#M616134</guid>
      <dc:creator>Mohamed Sobair</dc:creator>
      <dc:date>2010-11-29T14:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538507#M616135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohamed,&lt;/P&gt;&lt;P&gt;I didn't say only an ACL but also dynamic nat from dmz to in&amp;nbsp; but you're surely right about static but I can't test it as I haven't got any ASA in my lab&amp;nbsp; and it's been a long time since I've configured one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Nov 2010 21:36:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538507#M616135</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2010-11-29T21:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538508#M616136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohamed,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have tried added the static nat . But still error message and didn't go through from DMZ to IN and OUT to DMZ.&amp;nbsp; Kindly advise. Attach is the network diagram.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;( For Extenal to DMZ2 )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: Arial; "&gt;object network DMZ2_static&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: Arial; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;host 192.25.154.107&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: Arial; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;nat (DMZ2,OUT) static 192.25.152.246&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: Arial; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: Arial; "&gt;( For DMZ to&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; &lt;/SPAN&gt;internal )&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: Arial; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: Arial; "&gt;object network DMZ2_IN_static&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: Arial; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;host 172.25.154.107&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: Arial; "&gt;&lt;SPAN style="mso-spacerun: yes;"&gt; &lt;/SPAN&gt;nat ( DMZ2,IN) static 172.25.130.250&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="color: #000000; font-size: 10pt; font-family: Arial; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Existing ACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="Courier New&amp;quot;: ; color: #000000; font-size: 10pt; font-family: &amp;quot; "&gt;access-list OUT_IN extended permit tcp any host 192.25.154.107 object-group PORT_GROUP&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; Courier New&amp;quot;: ; color: #000000; font-size: 10pt; mso-ansi-language: EN-US; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;access-list IN_IN extended permit ip 192.25.130.0 255.255.255.0 any &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; Courier New&amp;quot;: ; color: #000000; font-size: 10pt; mso-ansi-language: EN-US; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;Existing Group&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;&lt;SPAN style="mso-bidi-language: AR-SA; mso-fareast-language: EN-US; : ; Courier New&amp;quot;: ; color: #000000; font-size: 10pt; mso-ansi-language: EN-US; font-family: &amp;quot; mso-fareast-font-family: 'Times New Roman'; "&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;access-group OUTSIDE_IN in interface OUT&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-size: 10pt; font-family: &amp;quot;Courier New&amp;quot;;"&gt;access-group INSIDE_IN in interface IN&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Courier New;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;( error message : )&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source IP&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Source&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Destination IP&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Dest&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp; (port)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Description &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;TABLE border="0" cellpadding="0" class="MsoNormalTable" style="width: 813px; mso-cellspacing: 1.5pt;"&gt;&lt;TBODY&gt;&lt;TR style="mso-yfti-irow: 0; mso-yfti-firstrow: yes;"&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;192.25.154.107&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;37457&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;192.25.130.22&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt; 22&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="width: 276.05pt; background-color: transparent; border: #ece9d8; padding: 0.75pt;" width="368"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;Inbound TCP connection denied from 192.25.154.107/37457 to 192.25.130.102/22 flags SYN on interface DMZ2&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 1;"&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;192.25.154.107&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;43166&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;192.25.130.22&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;21&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="width: 276.05pt; background-color: transparent; border: #ece9d8; padding: 0.75pt;" width="368"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;Inbound TCP connection denied from 192.25.154.107/43166 to 192.25.130.102/21 flags SYN on interface DMZ2&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 2;"&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;192.25.158.60&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;3096&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;192.25.158.248&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;443&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="width: 276.05pt; background-color: transparent; border: #ece9d8; padding: 0.75pt;" width="368"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;Teardown TCP connection 3215 for management:192.25.158.60/3096 to identity:192.25.158.248/443 duration 0:03:01 bytes 989 TCP Reset-O&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="mso-yfti-irow: 3; mso-yfti-lastrow: yes;"&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;192.25.158.60&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;4026&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;192.25.158.248&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="background-color: transparent; border: #ece9d8; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;80&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="width: 276.05pt; background-color: transparent; border: #ece9d8; padding: 0.75pt;" width="368"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: 12pt; font-family: Times New Roman; "&gt;TCP access denied by ACL from 192.25.158.60/4026 to management:192.25.158.248/80&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt; mso-pagination: none; mso-layout-grid-align: none;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt; ( Note: 192.25.158.60 is management station @ 158 network. )&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Nov 2010 15:34:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538508#M616136</guid>
      <dc:creator>Nay Myo Tun</dc:creator>
      <dc:date>2010-11-30T15:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538509#M616137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;From DMZ to Internal , try bellow config:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;CODE&gt;hostname(config)# object network host-obj&lt;BR /&gt;2.hostname(config-network-object)# host &lt;/CODE&gt;&lt;SPAN style="font-family: Arial; color: #000000; font-size: 10pt;"&gt;172.25.154.107&lt;/SPAN&gt;&lt;BR /&gt;&lt;CODE&gt;3.hostname(config-network-object)# nat (inside,dmz) static &lt;/CODE&gt;&lt;SPAN style="font-family: Arial; color: #000000; font-size: 10pt;"&gt;172.25.130.250&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Access-list DMZ permit ip any host 172.25.130.250&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Access-group DMZ in interface DMZ2&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;And From Outside to DMZ, try the following:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG style="color: #000000; font-size: 10pt; font-family: Arial; "&gt;object network DMZ2_static&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG style="color: #000000; font-size: 10pt; font-family: Arial; "&gt;&lt;SPAN&gt; &lt;/SPAN&gt;host 192.25.154.107&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG style="color: #000000; font-size: 10pt; font-family: Arial; "&gt;&lt;SPAN&gt; &lt;/SPAN&gt;nat (DMZ2,OUT) static 192.25.152.246&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG&gt;&lt;SPAN style="color: #000000; font-size: 10pt;"&gt;access-list OUTSIDE_IN extended permit tcp any host &lt;/SPAN&gt;&lt;SPAN style="font-family: Arial; color: #000000; font-size: 10pt;"&gt;172.25.130.250 &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 10pt;"&gt;object-group PORT_GROUP&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;STRONG style=": ; color: #000000; font-size: 10pt; "&gt;access-group OUTSIDE_IN in interface OUT&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;HTH&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;Mohamed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Nov 2010 17:40:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538509#M616137</guid>
      <dc:creator>Mohamed Sobair</dc:creator>
      <dc:date>2010-11-30T17:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538510#M616138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohamed,&lt;/P&gt;&lt;P&gt;Thanks for your kind support. I still have issue to access from OUT to DMZ and DMZ to internal network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;ASA01# sh nat translated interface OUT&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;Auto NAT Policies (Section 2)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;1 (DMZ2) to (OUT) source static OUT_TO_DMZ2 172.25.152.246&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;translate_hits = 0, untranslate_hits = 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;2 (DMZ2) to (OUT) source dynamic OUT 172.25.152.250&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;translate_hits = 77, untranslate_hits = 0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;ASA01# sh access-list&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 4096)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;alert-interval 300&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list OUT_IN; 6 elements; name hash: 0xc608a2be&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list OUT_IN line 1 extended permit tcp any host 172.25.154.107 object-group PORT_GROUP 0x93ff2600&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list OUT_IN line 1 extended permit tcp any host 172.25.154.107 eq echo (hitcnt=2) 0x9124577b&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list OUT_IN line 1 extended permit tcp any host 172.25.154.107 eq ftp (hitcnt=28) 0x4450eadc&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list OUT_IN line 1 extended permit tcp any host 172.25.154.107 eq ssh (hitcnt=25) 0x8bf2d476&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list OUT_IN line 2 extended permit tcp any host 172.25.154.250 object-group PORT_GROUP 0xc2fa2030&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list OUT_IN line 2 extended permit tcp any host 172.25.154.250 eq echo (hitcnt=2) 0xe7ad53a7&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list OUT_IN line 2 extended permit tcp any host 172.25.154.250 eq ftp (hitcnt=2) 0x01d86629&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list OUT_IN line 2 extended permit tcp any host 172.25.154.250 eq ssh (hitcnt=0) 0x8814dc01&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list INSIDE_IN; 1 elements; name hash: 0xcf1073ab&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list INSIDE_IN line 1 extended permit ip 172.25.130.0 255.255.255.0 any (hitcnt=0) 0xf2f5e4a1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list DMZ2; 5 elements; name hash: 0x85355895&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list DMZ2 line 1 extended permit ip any host 172.25.130.250 (hitcnt=0) 0x7d17c44b&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list DMZ2 line 2 extended permit icmp 172.25.154.0 255.255.255.0 host 172.25.130.250 (hitcnt=0) 0xc172bb61&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list DMZ2 line 3 extended permit tcp 172.25.154.0 255.255.255.0 host 172.25.130.250 object-group PORT_GROUP 0x84222e17&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list DMZ2 line 3 extended permit tcp 172.25.154.0 255.255.255.0 host 172.25.130.250 eq echo (hitcnt=0) 0x950b8d32&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list DMZ2 line 3 extended permit tcp 172.25.154.0 255.255.255.0 host 172.25.130.250 eq ftp (hitcnt=0) 0x704a9bc5&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;access-list DMZ2 line 3 extended permit tcp 172.25.154.0 255.255.255.0 host 172.25.130.250 eq ssh (hitcnt=0) 0xc6b3d207&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial;"&gt;ASA01#&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;object network DMZ1 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; subnet 172.25.156.0 255.255.255.0&lt;BR /&gt;object network DMZ2 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; subnet 172.25.130.0 255.255.255.0&lt;BR /&gt;object network OUT &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; subnet 172.25.130.0 255.255.255.0&lt;BR /&gt;object network DMZ2 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; host 172.25.154.107&lt;BR /&gt;object network DMZ1 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; subnet 172.25.130.0 255.255.255.0&lt;BR /&gt;object network DMZ2_TO_INSIDE &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; host 172.25.154.107&lt;BR /&gt;object network OUT_TO_DMZ2 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; host 172.25.154.107&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;object network DMZ2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; nat (INSIDE,DMZ2) dynamic 172.25.154.250&lt;BR /&gt;object network OUT&lt;BR /&gt;&amp;nbsp;&amp;nbsp; nat (DMZ2,OUT) dynamic 172.25.152.250&lt;BR /&gt;object network DMZ1&lt;BR /&gt;&amp;nbsp;&amp;nbsp; nat (DMZ2,DMZ1) dynamic 172.25.156.250&lt;BR /&gt;object network DMZ2_TO_INSIDE&lt;BR /&gt;&amp;nbsp;&amp;nbsp; nat (INSIDE,DMZ2) static 172.25.130.250&lt;BR /&gt;object network OUT_TO_DMZ2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; nat (DMZ2,OUT) static 172.25.152.246&lt;BR /&gt;access-group OUT_IN in interface OUT&lt;BR /&gt;access-group DMZ2 in interface DMZ2&lt;BR /&gt;route OUT 0.0.0.0 0.0.0.0 172.25.152.246 1&lt;BR /&gt;route OUT 172.25.240.0 255.255.255.0 172.25.152.246 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the syslog&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dst IP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
&lt;/style&gt;
&lt;![endif]--&gt; &lt;TABLE border="0" cellpadding="0" class="MsoNormalTable" style="width: 643px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;5&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;Dec 01 2010&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;16:16:52&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;305013&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;172.25.154.107&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;22&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;Asymmetric NAT rules matched for forward and reverse&amp;nbsp;&amp;nbsp; flows; Connection for tcp src OUT:172.25.240.111/48863 dst DMZ2:172.25.154.107/22 denied due to NAT reverse path failure&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;3&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;Dec 01 2010&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;16:17:55&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;710003&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;172.25.158.60&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;2472&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;172.25.158.248&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;80&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;TCP access denied by ACL from 172.25.158.60/2472 to&amp;nbsp;&amp;nbsp; management:172.25.158.248/80&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;5&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;Dec 01 2010&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;16:20:07&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;305013&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;172.25.154.107&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;22&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;Asymmetric NAT rules matched for forward and reverse&amp;nbsp;&amp;nbsp; flows; Connection for tcp src OUT:172.25.240.111/49079 dst DMZ2:172.25.154.107/22 denied due to NAT reverse path failure&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;4&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;Dec 01 2010&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;16:28:25&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;106023&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;172.25.240.111&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;172.25.154.107&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;/TD&gt;&lt;TD style="padding: 0.75pt;"&gt;&lt;P class="MsoNormal"&gt;Deny icmp src OUT:172.25.240.111 dst DMZ2:172.25.154.107 (type 8, code 0) by access-group&amp;nbsp;&amp;nbsp; "OUT_IN" [0x0, 0x0]&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Note: 172.25.240.111 is the IP address of the server which is connected to the External to gi0/0 RTR 3825 172.25.240.110/24.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; RTR 3825 gi0/1&amp;nbsp; 172.25.152.246 is connected to FW OUT 172.25.152.248.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 15:17:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538510#M616138</guid>
      <dc:creator>Nay Myo Tun</dc:creator>
      <dc:date>2010-12-01T15:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538511#M616139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DO you have nat excemption configured? could you post the output of (show run nat)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mohamed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 16:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538511#M616139</guid>
      <dc:creator>Mohamed Sobair</dc:creator>
      <dc:date>2010-12-01T16:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538512#M616140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,Mohamed. I don't have nat excemption configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AODWASA01# sh run&amp;nbsp; nat&lt;BR /&gt;!&lt;BR /&gt;object network DWH-MAIN&lt;BR /&gt; nat (DWH-MAIN,GDG_MAIN) dynamic 172.25.154.250&lt;BR /&gt;object network FW_EXT&lt;BR /&gt; nat (DWH-MAIN,FW_EXT) dynamic 172.25.152.250&lt;BR /&gt;object network GDG-MGT&lt;BR /&gt; nat (DWH-MAIN,GDG_MGT) dynamic 172.25.156.250&lt;BR /&gt;object network GDG_MAIN_TO_DWH-MAIN&lt;BR /&gt; nat (DWH-MAIN,GDG_MAIN) static 172.25.130.250&lt;BR /&gt;object network FW_EXT_TO_GDG_MAIN&lt;BR /&gt; nat (GDG_MAIN,FW_EXT) static 172.25.152.246&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 01:47:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538512#M616140</guid>
      <dc:creator>Nay Myo Tun</dc:creator>
      <dc:date>2010-12-02T01:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538513#M616141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohamed, Here is the output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AODWASA01# sh run&amp;nbsp; nat&lt;BR /&gt;!&lt;BR /&gt;object network IN&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (IN,DMZ2) dynamic 172.25.154.250&lt;BR /&gt;object network OUT&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (IN,OUT) dynamic 172.25.152.250&lt;BR /&gt;object network DMZ1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (IN,DMZ1) dynamic 172.25.156.250&lt;BR /&gt;object network DMZ2_TO_IN&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (IN,DMZ2) static 172.25.130.250&lt;BR /&gt;object network OUT_TO_DMZ2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (DMZ2,OUT) static 172.25.152.246&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 02:08:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538513#M616141</guid>
      <dc:creator>Nay Myo Tun</dc:creator>
      <dc:date>2010-12-02T02:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538514#M616142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Remove the following commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network DMZ2_TO_INSIDE&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; host 172.25.154.107&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network DMZ2_TO_INSIDE&lt;BR /&gt;&amp;nbsp;&amp;nbsp; nat (INSIDE,DMZ2) static 172.25.130.250&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Add the following commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network DMZ2-TO-INSIDE&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; subnet 172.25.104.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network DMZ2-TO-INSUIDE&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat (INSIDE,DMZ2) static 172.25.104.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access-group dmz in interface DMZ2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz permit ip 172.25.130.0 255.255.255.0 172.25.104.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clear xlate , and check the access from the DMZ to the inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mohamed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 11:32:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538514#M616142</guid>
      <dc:creator>Mohamed Sobair</dc:creator>
      <dc:date>2010-12-02T11:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538515#M616143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohamed,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Kindly check the packet tracer result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA01#&amp;nbsp; packet-tracer input DMZ2 tcp 172.25.154.107 ftp 172.25.130.250 ftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;object network DMZ2_TO_INSIDE&lt;BR /&gt; nat (INSIDE,DMZ2) static 172.25.130.250&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface INSIDE&lt;BR /&gt;Untranslate 172.25.130.250/21 to 172.25.154.107/21&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: DMZ2&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: INSIDE&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA01#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA01# packet-tracer input OUT tcp 172.25.152.250 ftp 172.25.154.107 ftp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 172.25.154.0&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; DMZ2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: log&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;access-group OUT_IN in interface OUT&lt;BR /&gt;access-list OUT_IN extended permit tcp any host 172.25.154.107 object-group DW_GROUP&lt;BR /&gt;object-group service DW_GROUP tcp&lt;BR /&gt; port-object eq echo&lt;BR /&gt; port-object eq ftp&lt;BR /&gt; port-object eq ssh&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;object network OUT_TO_DMZ2&lt;BR /&gt; nat (DMZ2,OUT) static 172.25.152.246&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: OUT&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: DMZ2&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA01#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 14:30:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538515#M616143</guid>
      <dc:creator>Nay Myo Tun</dc:creator>
      <dc:date>2010-12-02T14:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538516#M616144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, Mohamed. I will do it the first thing in the morning and will update accordingly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 14:33:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538516#M616144</guid>
      <dc:creator>Nay Myo Tun</dc:creator>
      <dc:date>2010-12-02T14:33:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 intervlan routing</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538517#M616145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohamed,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;I have managed to configure all outbound direction ( INSIDE--&amp;gt; DMZ1&amp;amp; 2&amp;nbsp;&amp;nbsp; , INSIDE --&amp;gt; OUTSIDE ,&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ1,2 ---&amp;gt; OUTSIDE.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;But still not able to access inbound direction ( OUT --&amp;gt; DMZ 1,2 ,&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ1,2 ---&amp;gt; INSIDE ). Kindly advise how to allow traffic from DMZ --&amp;gt; INSIDE, OUTSIDE ---&amp;gt; DMZ. I need to be able to ping / ftp inbound direction from lower to higher security level.&amp;nbsp;&amp;nbsp;&amp;nbsp; Kindly take note that my IOS version is ASA Version 8.3(1).&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;For outbound direction, these dynamic NAT config seems to be OK since I can access ssh / ftp outbound direction ( higher to lower security interface)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;interface Ethernet0/0&lt;BR /&gt;&amp;nbsp; nameif OUTSIDE&lt;BR /&gt;&amp;nbsp; security-level 0&lt;BR /&gt;&amp;nbsp; ip address 172.25152.248 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;&amp;nbsp; nameif DMZ1&lt;BR /&gt;&amp;nbsp; security-level 50&lt;BR /&gt;&amp;nbsp; ip address 172.25.154.249 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;&amp;nbsp; nameif DMZ2&lt;BR /&gt;&amp;nbsp; security-level 50&lt;BR /&gt;&amp;nbsp; ip address 172.25.156.249 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;&amp;nbsp; nameif INSIDE&lt;BR /&gt;&amp;nbsp; security-level 100&lt;BR /&gt;&amp;nbsp; ip address 172.25.130.248 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;STRONG style="text-decoration: underline; "&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: red; font-size: 9pt; mso-ansi-language: EN;"&gt;Dynamic NATs ( successful for outbound&amp;nbsp; access )&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;STRONG style="text-decoration: underline; "&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;( Outbound from inside to DMZ2 )&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;object network INSIDE_dynamic_DMZ2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;subnet 172.25.130.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;nat (INSIDE,DMZ2) dynamic 172.25154.250&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;STRONG style="text-decoration: underline; "&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;( Outbound from DMZ2 to outside )&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;object network DMZ2_dynamic_OUTSIDE&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;host 172.25.154.107&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;nat (DMZ2,OUTSIDE) dynamic 172.25152.251&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;STRONG style="text-decoration: underline; "&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;( Outbound from inside to outside )&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;object network INSIDE_dynamic_OUTSIDE&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;subnet 172.25.130.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;nat (INSIDE,OUTSIDE) dynamic 172.25152.250&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;STRONG style="text-decoration: underline; "&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;( Outbound from inside to DMZ1 )&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;object network INSIDE_dynamic_DMZ1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;&amp;nbsp; subnet 172.25.130.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;&amp;nbsp; nat (INSIDE,DMZ1) dynamic 172.25.156.250&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;STRONG style="text-decoration: underline; "&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: red; font-size: 9pt; mso-ansi-language: EN;"&gt;STATIC NATs ( Not successful for inbound access )&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;STRONG style="text-decoration: underline; "&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;( Inbound from outside to DMZ1 )&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;object network OUTSIDE-static_DMZ1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;subnet 172.25.156.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;nat (DMZ1,OUTSIDE) static 172.25.152.252&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;STRONG style="text-decoration: underline; "&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;( Inbound from DMZ2 to INSIDE )&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;object network DMZ2-static-INSIDE&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;subnet 172.25.154.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;nat (INSIDE,DMZ2) static 172.25.130.253&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;Errror Message I got when I ssh "172.25.130.101" ( inside server ) from DMZ1 server 172.25154.107 .&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" class="MsoNormalTable" style="WIDTH: 98%; BORDER-COLLAPSE: collapse; mso-padding-alt: 1.5pt 1.5pt 1.5pt 1.5pt"&gt;&lt;TBODY&gt;&lt;TR style="mso-yfti-irow: 0; mso-yfti-firstrow: yes; mso-yfti-lastrow: yes;"&gt;&lt;TD style="background-color: transparent; mso-border-alt: solid black .5pt; border: black 1pt solid; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN-US" style="color: #333333;"&gt;4&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: black 1pt solid; border-left: #000000; background-color: transparent; border-top: black 1pt solid; border-right: black 1pt solid; mso-border-alt: solid black .5pt; mso-border-left-alt: solid black .5pt; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN-US" style="color: #333333;"&gt;Dec 07 2010&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: black 1pt solid; border-left: #000000; background-color: transparent; border-top: black 1pt solid; border-right: black 1pt solid; mso-border-alt: solid black .5pt; mso-border-left-alt: solid black .5pt; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN-US" style="color: #333333;"&gt;17:40:53&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: black 1pt solid; border-left: #000000; background-color: transparent; border-top: black 1pt solid; border-right: black 1pt solid; mso-border-alt: solid black .5pt; mso-border-left-alt: solid black .5pt; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN-US" style="color: #333333;"&gt;106023&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: black 1pt solid; border-left: #000000; background-color: transparent; border-top: black 1pt solid; border-right: black 1pt solid; mso-border-alt: solid black .5pt; mso-border-left-alt: solid black .5pt; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN-US" style="color: #333333;"&gt;172.25.154.107&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: black 1pt solid; border-left: #000000; background-color: transparent; border-top: black 1pt solid; border-right: black 1pt solid; mso-border-alt: solid black .5pt; mso-border-left-alt: solid black .5pt; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN-US" style="color: #333333;"&gt;60815&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: black 1pt solid; border-left: #000000; background-color: transparent; border-top: black 1pt solid; border-right: black 1pt solid; mso-border-alt: solid black .5pt; mso-border-left-alt: solid black .5pt; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN-US" style="color: #333333;"&gt;172.25.154.101&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: black 1pt solid; border-left: #000000; background-color: transparent; border-top: black 1pt solid; border-right: black 1pt solid; mso-border-alt: solid black .5pt; mso-border-left-alt: solid black .5pt; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN-US" style="color: #333333;"&gt;22&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-bottom: black 1pt solid; border-left: #000000; background-color: transparent; border-top: black 1pt solid; border-right: black 1pt solid; mso-border-alt: solid black .5pt; mso-border-left-alt: solid black .5pt; padding: 0.75pt;"&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN-US" style="color: #333333;"&gt;Deny tcp src DMZ2:172.25.154.107/60815 dst INSIDE:172.25.154.101/22&amp;nbsp;&amp;nbsp; by access-group "DMZ2_INSIDE" [0x0, 0x0]&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;STRONG style="text-decoration: underline; "&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;( Inbound from outside to DMZ2 )&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;object network OUTSIDE-static-DMZ2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;subnet 172.25.154.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;nat (DMZ2, OUTSIDE) static 172.25.152.253&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;( Error message when ssh from the external server which is located external interface of Router to DMZ2 server 172.25154.107 : )&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;#ssh 172.25.154.107&lt;BR /&gt;&amp;nbsp;&amp;nbsp; ssh: connect to host 172.25.154.107 port 22: No route to host&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;&amp;nbsp;&amp;nbsp; ( Note: routing has been added in the external server and can ping to ext interface of FW )&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;STRONG style="text-decoration: underline; "&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;Access Lists&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;access-list OUTSIDE_IN extended permit tcp any host 172.25154.107 object-group PORT_GROUP&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;access-list INSIDE_IN extended permit ip 172.25.130.0 255.255.255.0 any&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;access-list OUTSIDE_DMZ1 extended permit ip 172.25.156.0 255.255.255.0 172.25152.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;access-list DMZ2_INSIDE extended permit ip 172.25130.0 255.255.255.0 172.25154.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;access-list DMZ1_INSIDE extended permit ip 172.25130.0 255.255.255.0 172.25150.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;access-list OUTSIDE_DMZ2 extended permit ip 172.25.154.0 255.255.255.0 172.25152.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;access-group OUTSIDE_DMZ1 in interface OUTSIDE&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;access-group DMZ2_INSIDE in interface DMZ2&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;access-group DMZ1_INSIDE in interface DMZ1&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN lang="EN" style="font-family: &amp;quot;Arial&amp;quot;, &amp;quot;sans-serif&amp;quot;; color: #333333; font-size: 9pt; mso-ansi-language: EN;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt;"&gt;&lt;SPAN style="color: #000000; font-size: 12pt; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 15:04:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-intervlan-routing/m-p/1538517#M616145</guid>
      <dc:creator>Nay Myo Tun</dc:creator>
      <dc:date>2010-12-14T15:04:27Z</dc:date>
    </item>
  </channel>
</rss>

