<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot RDP out through a 2811 with Firewall feature set in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472485#M655418</link>
    <description>&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt;Hi all,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt;I’ve inherited a 2811 router with a firewall feature pack from a previous support guy and it looks in a bit of a mess.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt;I'm having problems RDPing out through our 2811 with firewall feature set. I have a route map pointing to an access list permit ip internal-network any. There's another access list on the inside interface in, permit ip any any. I've attached my cleaned config. Any ideas how to get RDP working?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt;Also, since a recent save of the config, lots of the remarks in the access-lists seem to repeat themselves. Any ideas why? &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Egg&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 18:02:36 GMT</pubDate>
    <dc:creator>Eggzter100</dc:creator>
    <dc:date>2019-03-11T18:02:36Z</dc:date>
    <item>
      <title>Cannot RDP out through a 2811 with Firewall feature set</title>
      <link>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472485#M655418</link>
      <description>&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt;Hi all,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt;I’ve inherited a 2811 router with a firewall feature pack from a previous support guy and it looks in a bit of a mess.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt;I'm having problems RDPing out through our 2811 with firewall feature set. I have a route map pointing to an access list permit ip internal-network any. There's another access list on the inside interface in, permit ip any any. I've attached my cleaned config. Any ideas how to get RDP working?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt;Also, since a recent save of the config, lots of the remarks in the access-lists seem to repeat themselves. Any ideas why? &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0cm 0cm 0pt; line-height: normal;"&gt;&lt;SPAN style="font-size: 10pt; color: #333333; font-family: &amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;; mso-fareast-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Egg&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472485#M655418</guid>
      <dc:creator>Eggzter100</dc:creator>
      <dc:date>2019-03-11T18:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot RDP out through a 2811 with Firewall feature set</title>
      <link>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472486#M655422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please reattach the config, as it didn't get attached to your initial post.&lt;/P&gt;&lt;P&gt;Do you have NAT configured for the RDP traffic (TCP/3389)?&lt;/P&gt;&lt;P&gt;Where does the RDP fail? Prior to authentication or after it authenticates? Are you able to telnet on port 3389 to the RDP server?&lt;/P&gt;&lt;P&gt;Assuming that you can RDP from the same subnet, do you have any windows firewall on the host that might prevent RDP from different subnet?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 11:47:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472486#M655422</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-23T11:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot RDP out through a 2811 with Firewall feature set</title>
      <link>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472487#M655424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry, I'll try again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 12:08:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472487#M655424</guid>
      <dc:creator>Eggzter100</dc:creator>
      <dc:date>2010-06-23T12:08:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot RDP out through a 2811 with Firewall feature set</title>
      <link>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472488#M655427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please change the following ACL line for "adsl24outgoing" ACL:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;FROM&lt;/STRONG&gt;&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt; permit tcp 0.0.0.0 255.255.255.0 any eq 3389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;TO&lt;/STRONG&gt;&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt; permit tcp any any eq 3389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please kindly make sure that when you change the ACL, it's above the "deny ip any any" rule for "adsl24outgoing" ACL.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 12:16:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472488#M655427</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-23T12:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot RDP out through a 2811 with Firewall feature set</title>
      <link>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472489#M655429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Halijenn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scoolboy error, the subnet msk should've been reversed, yeah?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you make of the remarks repeating themselves in the access lists?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Egg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 12:56:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472489#M655429</guid>
      <dc:creator>Eggzter100</dc:creator>
      <dc:date>2010-06-23T12:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot RDP out through a 2811 with Firewall feature set</title>
      <link>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472490#M655431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The remarks seem to have been added by SDM automatically.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest that you check the line# for each ACL, for example ACL 109:&lt;/P&gt;&lt;P&gt;sh ip access-list 109&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then for those duplicated remarks just check out the line#, and remove it as follows:&lt;/P&gt;&lt;P&gt;ip access-list extended 109&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; no &lt;LINE&gt;&lt;/LINE&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; no &lt;NEXT-LINE&gt;&lt;/NEXT-LINE&gt;&lt;/P&gt;&lt;P&gt; etc ....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 13:01:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472490#M655431</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-23T13:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot RDP out through a 2811 with Firewall feature set</title>
      <link>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472491#M655432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi halijenn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah, I already thought of that but remarks don't show up as line# in the sho ip access-list adsl24external command. Only the permit and deny statements. How would I remove the remarks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Egg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 13:36:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472491#M655432</guid>
      <dc:creator>Eggzter100</dc:creator>
      <dc:date>2010-06-23T13:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot RDP out through a 2811 with Firewall feature set</title>
      <link>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472492#M655433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In that case, you would need to remove the complete ACL with a no statement, and reconfigure it without the remarks.&lt;/P&gt;&lt;P&gt;However, pls be very careful when you remove the ACL. I would suggest that you perform the change after hours and through console session, otherwise, you might lock yourself out from accessing the router (via ssh or telnet).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2010 21:55:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-rdp-out-through-a-2811-with-firewall-feature-set/m-p/1472492#M655433</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-23T21:55:49Z</dc:date>
    </item>
  </channel>
</rss>

