<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Webmail not opening from inside IPs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531584#M675360</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear both,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your suggestions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried both options and both are working fine for me. but as a security measure i have adopted internal DNS method.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Nov 2010 22:26:10 GMT</pubDate>
    <dc:creator>Shibu Sreedharan</dc:creator>
    <dc:date>2010-11-18T22:26:10Z</dc:date>
    <item>
      <title>Webmail not opening from inside IPs</title>
      <link>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531573#M675268</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are unable to access webmail from inside ips using &lt;A href="https://mail.companyname" target="_blank"&gt;https://mail.companyname&lt;/A&gt; .&amp;nbsp; but we can access same thing from outside internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use IP from our pool public IP for PAT as well as this webmail natting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way we can access webmail from inside ips&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have asa 8.2 (1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:55:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531573#M675268</guid>
      <dc:creator>Shibu Sreedharan</dc:creator>
      <dc:date>2019-03-11T18:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: Webmail not opening from inside IPs</title>
      <link>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531574#M675289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shibu,&lt;/P&gt;&lt;P&gt;When you ping mail.company name from the inside hosts what do you get? The inside IP of webmail or outside IP of webmail?&lt;/P&gt;&lt;P&gt;Where is your DNS server?&lt;/P&gt;&lt;P&gt;Is this an internal DNS server?&lt;/P&gt;&lt;P&gt;Why doesn't it resolve to the inside IP of webmail?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;On the browser issue &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://inside_ip_address/exchange"&gt;http://inside_ip_address/exchange&lt;/A&gt;&lt;SPAN&gt; and see if it loads (I am assuming it is exchange).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If it does then pls. change the inside DNS server to hand out the inside IP address when computers want to resolve mail.company&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Oct 2010 13:26:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531574#M675289</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-10-17T13:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: Webmail not opening from inside IPs</title>
      <link>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531575#M675306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Kusankar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find my answers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you ping mail.company name from the inside hosts what do you get? The inside IP of webmail or outside IP of webmail?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I get outside IP of webmail when i ping mail.company.net. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is your DNS server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In PCs we have local server as DNS server . in the DNS server we have given our ISP dns severs IP in forweded list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this an internal DNS server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In PCs we have local server as DNS server . in the DNS server we have given our ISP dns severs IP in forweded list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why doesn't it resolve to the inside IP of webmail?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;On the browser issue &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://inside_ip_address/exchange"&gt;&lt;SPAN style="color: #2f6681;"&gt;http://inside_ip_address/exchange&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt; and see if it loads (I am assuming it is exchange).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If it does then pls. change the inside DNS server to hand out the inside IP address when computers want to resolve mail.company&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;How to do this DNS handout ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please find below some partial configuration of my ASA.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;nameif outside&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address *.186 255.255.255.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;nameif BACKUP&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address *.202 255.255.255.248&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;nameif INSIDE&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.10.10.10 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 94.200.* eq https&lt;/P&gt;&lt;P&gt;　&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;global (outside) 3 94.*&lt;/P&gt;&lt;P&gt;global (BROADCAST) 2 10.20.2.11-10.20.2.15 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (INSIDE) 0 access-list INSIDE_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (INSIDE) 2 access-list INSIDE_BROADCAST&lt;/P&gt;&lt;P&gt;nat (INSIDE) 3 access-list ROUTE_ADSL&lt;/P&gt;&lt;P&gt;nat (INSIDE) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (INSIDE,outside) 94.* CASServer2 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;　&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 94.* 1 track 1&lt;/P&gt;&lt;P&gt;route BACKUP 0.0.0.0 0.0.0.0 94.* 254&lt;/P&gt;&lt;P&gt;　&lt;/P&gt;&lt;P&gt;　&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt;inspect h323 h225&lt;/P&gt;&lt;P&gt;inspect h323 ras&lt;/P&gt;&lt;P&gt;inspect rsh&lt;/P&gt;&lt;P&gt;inspect rtsp&lt;/P&gt;&lt;P&gt;inspect sqlnet&lt;/P&gt;&lt;P&gt;inspect skinny&lt;/P&gt;&lt;P&gt;inspect sunrpc&lt;/P&gt;&lt;P&gt;inspect xdmcp&lt;/P&gt;&lt;P&gt;inspect sip&lt;/P&gt;&lt;P&gt;inspect netbios&lt;/P&gt;&lt;P&gt;inspect tftp&lt;/P&gt;&lt;P&gt;inspect ftp&lt;/P&gt;&lt;P&gt;inspect esmtp&lt;/P&gt;&lt;P&gt;class class-default&lt;/P&gt;&lt;P&gt;flow-export event-type all destination 10.10.2.16 10.10.2.26&lt;/P&gt;&lt;P&gt;policy-map my-ips-policy&lt;/P&gt;&lt;P&gt;class my-ips-class&lt;/P&gt;&lt;P&gt;ips inline fail-open&lt;/P&gt;&lt;P&gt;　&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thanks&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Oct 2010 15:24:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531575#M675306</guid>
      <dc:creator>Shibu Sreedharan</dc:creator>
      <dc:date>2010-10-17T15:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: Webmail not opening from inside IPs</title>
      <link>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531576#M675316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Who manages your inside DNS server? Is this Microsoft DNS server?&amp;nbsp; It needs to be done there.&lt;/P&gt;&lt;P&gt;Create a zone file for your domain and add "A" records for all the sites that you host. Like&lt;/P&gt;&lt;P&gt;ftp.mycompany.com&lt;/P&gt;&lt;P&gt;mail.mycompany.com&lt;/P&gt;&lt;P&gt;www.mycompany.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure mail.mycompany.com &amp;gt;&amp;gt;&amp;gt;point to 10.10.10.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Oct 2010 16:04:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531576#M675316</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-10-17T16:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: Webmail not opening from inside IPs</title>
      <link>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531577#M675332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Shibu,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope you are doing great, this is a very common issue. You can use one of the following options:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1-Create a U turning config, say that the static for your server is&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static (inside,outside) &lt;PUBLIC_IP&gt; &lt;PRIVATE_IP&gt; netmask 255.255.255.255&lt;/PRIVATE_IP&gt;&lt;/PUBLIC_IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do another one as this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static (inside,inside) &lt;PUBLIC_IP&gt; &lt;PRIVATE_IP&gt; netmask 255.255.255.255&lt;/PRIVATE_IP&gt;&lt;/PUBLIC_IP&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; global (inside) 1 interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2-Change the IP address on the DNS server, say for the domain name for your Webmail instead of resolving to the public, resolve to the private. That will remain locally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any of those options can work for you, if you have any questions regarding any of these options let us know, we will be more than glad to help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Oct 2010 16:19:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531577#M675332</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-10-17T16:19:34Z</dc:date>
    </item>
    <item>
      <title>Re: Webmail not opening from inside IPs</title>
      <link>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531578#M675338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear both ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for your kind help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried the suggested first option but still i am unable to access webmail from inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (INSIDE,outside) 94.*.*. CASServer2 netmask 255.255.255.255&lt;BR /&gt;static (INSIDE,INSIDE)&amp;nbsp; 94.*.*.&amp;nbsp; CASServer2 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;global (inside) 1 interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help further to sort out this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Oct 2010 17:17:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531578#M675338</guid>
      <dc:creator>Shibu Sreedharan</dc:creator>
      <dc:date>2010-10-17T17:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: Webmail not opening from inside IPs</title>
      <link>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531579#M675343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Shibu,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you please paste the output of the following command?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input inside tcp 10.10.10.12 1025 &lt;SERVER_PUBLIC_IP&gt; 443&lt;/SERVER_PUBLIC_IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Oct 2010 17:25:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531579#M675343</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-10-17T17:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: Webmail not opening from inside IPs</title>
      <link>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531580#M675350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find below the trace&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA-5510-1# packet-tracer input INSIDE tcp 10.10.7.20 1025 94.X 443&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: FLOW-LOOKUP&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Found no matching flow, creating a new flow&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (INSIDE,INSIDE) 94.*.* CASServer2 netmask 255.255.255.255&lt;BR /&gt;&amp;nbsp; match ip INSIDE host CASServer2 INSIDE any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 94.*.*&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 365&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface INSIDE&lt;BR /&gt;Untranslate 94.*.*/0 to CASServer2/0 using netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: IDS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type:&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;nat (INSIDE) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp; match ip INSIDE any INSIDE any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 161, untranslate_hits = 0&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: INSIDE&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: INSIDE&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;ASA-5510-1#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Oct 2010 17:51:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531580#M675350</guid>
      <dc:creator>Shibu Sreedharan</dc:creator>
      <dc:date>2010-10-17T17:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: Webmail not opening from inside IPs</title>
      <link>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531581#M675353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Latest trace&lt;/P&gt;&lt;P&gt;========&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA-5510-1# packet-tracer input INSIDE tcp 10.10.7.20 1025 94.* 443&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: FLOW-LOOKUP&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Found no matching flow, creating a new flow&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: UN-NAT&lt;BR /&gt;Subtype: static&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;static (INSIDE,INSIDE) 94.* CASServer2 netmask 255.255.255.255&lt;BR /&gt;&amp;nbsp; match ip INSIDE host CASServer2 INSIDE any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; static translation to 94.*&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 0, untranslate_hits = 420&lt;BR /&gt;Additional Information:&lt;BR /&gt;NAT divert to egress interface INSIDE&lt;BR /&gt;Untranslate 94.*/0 to CASServer2/0 using netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: IDS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type:&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;nat (INSIDE) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp; match ip INSIDE any INSIDE any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; translate_hits = 194, untranslate_hits = 0&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: INSIDE&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: INSIDE&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;ASA-5510-1#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Oct 2010 17:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531581#M675353</guid>
      <dc:creator>Shibu Sreedharan</dc:creator>
      <dc:date>2010-10-17T17:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Webmail not opening from inside IPs</title>
      <link>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531582#M675357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seems you are doing it well, for somehow the firewall is not seeing the global (INSIDE) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (INSIDE) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp; match ip INSIDE any INSIDE any&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic translation to pool 1 &lt;STRONG&gt;(No matching global)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you please do a clear xlate and make sure that the global (INSIDE) 1 interface is in the configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Oct 2010 17:59:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531582#M675357</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-10-17T17:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Webmail not opening from inside IPs</title>
      <link>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531583#M675358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shibu,&lt;/P&gt;&lt;P&gt;These U-Turn x-lates may cause issue later on and may become very hard to manage, troubleshoot and maintain. These are hacks that are used to get things working that are not configured as they should.&lt;/P&gt;&lt;P&gt;My suggestion would be to configure your inside DNS server properly so that it returns the private ip address for the name mail.company.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Oct 2010 18:36:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531583#M675358</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-10-17T18:36:42Z</dc:date>
    </item>
    <item>
      <title>Re: Webmail not opening from inside IPs</title>
      <link>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531584#M675360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear both,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your suggestions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried both options and both are working fine for me. but as a security measure i have adopted internal DNS method.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Nov 2010 22:26:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/webmail-not-opening-from-inside-ips/m-p/1531584#M675360</guid>
      <dc:creator>Shibu Sreedharan</dc:creator>
      <dc:date>2010-11-18T22:26:10Z</dc:date>
    </item>
  </channel>
</rss>

