<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dmz unable to access the internet in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dmz-unable-to-access-the-internet/m-p/1458666#M654945</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are testing with ping, please make sure that icmp inspection has been turned on/enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are using the default policy map on the ASA, the configuration will be as follows:&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Jul 2010 22:52:08 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2010-07-02T22:52:08Z</dc:date>
    <item>
      <title>dmz unable to access the internet</title>
      <link>https://community.cisco.com/t5/network-security/dmz-unable-to-access-the-internet/m-p/1458664#M654943</link>
      <description>&lt;P&gt;I have DMZ interface with 192.168.1.0\24with the following config on the firewall:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (dmz) 2 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;global (outside) 2 &amp;lt;publicIP&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the dmz interface on the firewall is 192.168.1.1 and it can ping all dmz servers, so routing is not the issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and no access-group for the dmz interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yet dmz servers are unable to access the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is there anything missing in this config?&lt;/P&gt;&lt;P&gt;when I run a capture I see the traffic hitting the dmz interface yet nothing coming back, ie:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;158: 06:27:07.126000 192.168.1.13 &amp;gt; 4.2.2.2: icmp: echo request&lt;BR /&gt; 159: 06:27:12.625822 192.168.1.13 &amp;gt; 4.2.2.2: icmp: echo request&lt;BR /&gt; 160: 06:27:18.125771 192.168.1.13 &amp;gt; 4.2.2.2: icmp: echo request&lt;BR /&gt; 161: 06:27:23.625639 192.168.1.13 &amp;gt; 4.2.2.2: icmp: echo request&lt;BR /&gt; 162: 06:27:29.125573 192.168.1.13 &amp;gt; 4.2.2.2: icmp: echo request&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:07:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-unable-to-access-the-internet/m-p/1458664#M654943</guid>
      <dc:creator>ronshuster</dc:creator>
      <dc:date>2019-03-11T18:07:04Z</dc:date>
    </item>
    <item>
      <title>Re: dmz unable to access the internet</title>
      <link>https://community.cisco.com/t5/network-security/dmz-unable-to-access-the-internet/m-p/1458665#M654944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks good from my point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the security lvl of your interfaces.&lt;/P&gt;&lt;P&gt;Maybe you need to assign a higher security lvl to your DMZ interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH (if so please rate &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt; )&lt;/P&gt;&lt;P&gt;cheers Michael&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jul 2010 20:14:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-unable-to-access-the-internet/m-p/1458665#M654944</guid>
      <dc:creator>Michael Dombek</dc:creator>
      <dc:date>2010-07-02T20:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: dmz unable to access the internet</title>
      <link>https://community.cisco.com/t5/network-security/dmz-unable-to-access-the-internet/m-p/1458666#M654945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are testing with ping, please make sure that icmp inspection has been turned on/enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are using the default policy map on the ASA, the configuration will be as follows:&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jul 2010 22:52:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-unable-to-access-the-internet/m-p/1458666#M654945</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-07-02T22:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: dmz unable to access the internet</title>
      <link>https://community.cisco.com/t5/network-security/dmz-unable-to-access-the-internet/m-p/1458667#M654946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you enabled ICMP traffic on the outside interface of the firewall? If no, please try "icmp permit any outside". Also, which firewall you are using? Is it 5505? If it is 5505, you might have license limitations.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jul 2010 04:48:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-unable-to-access-the-internet/m-p/1458667#M654946</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-07-06T04:48:09Z</dc:date>
    </item>
  </channel>
</rss>

