<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot access outside from dmz, ASA 5505. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-access-outside-from-dmz-asa-5505/m-p/1498382#M689810</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are awesome,&lt;/P&gt;&lt;P&gt;Thanks very much, works great. Think I need to brush up on DMZ setups.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 19 May 2010 09:28:45 GMT</pubDate>
    <dc:creator>danparsons</dc:creator>
    <dc:date>2010-05-19T09:28:45Z</dc:date>
    <item>
      <title>Cannot access outside from dmz, ASA 5505.</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-outside-from-dmz-asa-5505/m-p/1498380#M689805</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have looked over my config and gone through several cisco helpsheets, I still cannot access the outside from "inside" the dmz. Here is an overview of what I can and cannot do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OUTSIDE &amp;gt;&amp;gt;&amp;gt; DMZ = OK&lt;/P&gt;&lt;P&gt;INSIDE &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; DMZ = OK&lt;/P&gt;&lt;P&gt;DMZ &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; INSIDE = OK&lt;/P&gt;&lt;P&gt;DMZ &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; OUTSIDE = FAIL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I need to do is to be able to access an external SMTP server from the DMZ. If I telnet pt 25 to an "OUTSIDE" server it fails. If I do it to my "INSIDE" server it works.&lt;/P&gt;&lt;P&gt;Here are the relevant sections of the config. I assume I have missed something stupid and have looked over it too many times and need some fresh eyes.&lt;/P&gt;&lt;P&gt;Many thanks for your help.&lt;/P&gt;&lt;P&gt;Dan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.0.20 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 99.99.99.99 255.255.255.248&lt;BR /&gt;!&lt;BR /&gt;interface Vlan3&lt;BR /&gt; nameif dmz&lt;BR /&gt; security-level 50&lt;BR /&gt; ip address 10.30.30.1 255.255.255.0&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt; domain-name cheese&lt;BR /&gt;access-list services extended permit tcp any host 99.99.99.98 eq www&lt;BR /&gt;access-list inside extended permit tcp host 10.30.30.30 any eq smtp&lt;BR /&gt;access-list inside extended permit ip any any&lt;BR /&gt;access-list dmz-in extended permit udp host 10.30.30.30 host 192.168.0.10 eq domain&lt;BR /&gt;access-list dmz-in extended permit tcp host 10.30.30.30 host 192.168.0.10 eq 88&lt;BR /&gt;access-list dmz-in extended permit udp host 10.30.30.30 host 192.168.0.10 eq 389&lt;BR /&gt;access-list dmz-in extended permit ip any any&lt;BR /&gt;access-list dmz-in extended permit icmp any any&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu dmz 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-523.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 0 access-list nonat&lt;BR /&gt;nat (inside) 1 10.30.30.0 255.255.255.0&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;static (dmz,outside) tcp 99.99.99.98 www 10.30.30.30 www netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz) 10.30.30.30 192.168.0.111 netmask 255.255.255.255&lt;BR /&gt;static (inside,dmz) 192.168.0.0 192.168.0.0 netmask 255.255.255.0&lt;BR /&gt;access-group inside in interface inside&lt;BR /&gt;access-group services in interface outside&lt;BR /&gt;access-group dmz-in in interface dmz&lt;BR /&gt;route inside 10.1.0.0 255.255.0.0 192.168.0.250 1&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 99.99.99.99 1&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:47:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-outside-from-dmz-asa-5505/m-p/1498380#M689805</guid>
      <dc:creator>danparsons</dc:creator>
      <dc:date>2019-03-11T17:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access outside from dmz, ASA 5505.</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-outside-from-dmz-asa-5505/m-p/1498381#M689808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Add the following statement and you should have access to the outside from dmz:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no nat (inside) 1 10.30.30.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (dmz) 1 10.30.30.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"clear xlate" after the above changes, and dmz should have access to the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 May 2010 09:24:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-outside-from-dmz-asa-5505/m-p/1498381#M689808</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-19T09:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access outside from dmz, ASA 5505.</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-outside-from-dmz-asa-5505/m-p/1498382#M689810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are awesome,&lt;/P&gt;&lt;P&gt;Thanks very much, works great. Think I need to brush up on DMZ setups.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 May 2010 09:28:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-outside-from-dmz-asa-5505/m-p/1498382#M689810</guid>
      <dc:creator>danparsons</dc:creator>
      <dc:date>2010-05-19T09:28:45Z</dc:date>
    </item>
  </channel>
</rss>

