<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-issue/m-p/1499277#M708338</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When I asked you earlier what is &lt;SPAN style="background-color: #f8fafd;"&gt;192.168.99.9, you advised that it is a firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there 2 firewalls in your network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the traceroute, it gave you a hop of the router, meaning it passes through the router OK, the next hop would be what is after the router interface of 192.168.99.10 (vlan 100). Base on the routing, it points to 192.168.99.9 which you advised earlier is a firewall. If it's not a firewall, please check what device it is, and what could be blocking it on that particular device.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Jun 2010 12:41:30 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2010-06-28T12:41:30Z</dc:date>
    <item>
      <title>Access Issue</title>
      <link>https://community.cisco.com/t5/network-security/access-issue/m-p/1499268#M708256</link>
      <description>&lt;P&gt;We are not able to ping the ip 10.2.1.240. Can anyone look into the issue and help us ? Here is the scenario described below........&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;server(192.162.2.X) -------&amp;gt; Switch------&amp;gt;Firewall--------&amp;gt;Router .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now we need to access the IP 10.2.1.240 from the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the server the tracert result is given below.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\&amp;gt;tracert 10.2.1.240&lt;/P&gt;&lt;P&gt;Tracing route to 10.2.1.240 over a maximum of 30 hops&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;1 ms&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;1 ms&amp;nbsp; 192.168.99.10-------------------------------&amp;gt;Router IP&lt;BR /&gt;&amp;nbsp; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp; 3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; *&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^C&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the router we have checked the below result......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router#sh ip route 10.2.1.240&lt;BR /&gt;Routing entry for 10.2.1.0/24&lt;BR /&gt;&amp;nbsp; Known via "static", distance 1, metric 0&lt;BR /&gt;&amp;nbsp; Routing Descriptor Blocks:&lt;BR /&gt;&amp;nbsp; * 10.252.126.1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Route metric is 0, traffic share count is 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following route has been configured on the router ........... ip route 10.2.1.0 255.255.255.0 10.252.126.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Waiting for your help and suggestion.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:04:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-issue/m-p/1499268#M708256</guid>
      <dc:creator>tuhinbhowmick</dc:creator>
      <dc:date>2019-03-11T18:04:28Z</dc:date>
    </item>
    <item>
      <title>Re: Access Issue</title>
      <link>https://community.cisco.com/t5/network-security/access-issue/m-p/1499269#M708268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pls advise ip address of each hop. If you can share the config of the firewall and router, that would help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 08:21:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-issue/m-p/1499269#M708268</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-28T08:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: Access Issue</title>
      <link>https://community.cisco.com/t5/network-security/access-issue/m-p/1499270#M708286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;here is the router config for your reference......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 5060 bytes&lt;BR /&gt;!&lt;BR /&gt;version 12.4&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname !&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;logging buffered 51200 warnings&lt;BR /&gt;!&lt;BR /&gt;no aaa new-model&lt;BR /&gt;!&lt;BR /&gt;resource policy&lt;BR /&gt;!&lt;BR /&gt;ip subnet-zero&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip cef&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip domain name yourdomain.com&lt;BR /&gt;ip name-server 213.42.20.20&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt; description $ETH-LAN$$ETH-SW-LAUNCH$$INTF-INFO-GE 0/0$$ES_LAN$$FW_INSIDE$&lt;BR /&gt; ip address 86.96.194.214 255.255.255.240&lt;BR /&gt; ip nat outside&lt;BR /&gt; ip virtual-reassembly&lt;BR /&gt; duplex auto&lt;BR /&gt; speed auto&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt; ip address 192.168.98.10 255.255.255.0&lt;BR /&gt; ip nat inside&lt;BR /&gt; ip virtual-reassembly&lt;BR /&gt; duplex auto&lt;BR /&gt; speed auto&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1/0&lt;BR /&gt; description -- Connected TO&amp;nbsp; LAN -----&lt;BR /&gt; switchport access vlan 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1/1&lt;BR /&gt; description --- SITE TO SITE L3&amp;nbsp; LINK----&lt;BR /&gt; switchport access vlan 200&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1/2&lt;BR /&gt; description --- *********MARKET WAN LINK -----&lt;BR /&gt; switchport access vlan 126&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1/3&lt;BR /&gt; description -- ********MARKET CONNECTION -----&lt;BR /&gt; switchport access vlan 34&lt;BR /&gt; spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface Serial0/0/0&lt;BR /&gt; no ip address&lt;BR /&gt; shutdown&lt;BR /&gt; clock rate 2000000&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan34&lt;BR /&gt; ip address 10.16.34.5 255.255.255.0&lt;BR /&gt; ip nat outside&lt;BR /&gt; ip virtual-reassembly&lt;BR /&gt;!&lt;BR /&gt;interface Vlan100&lt;BR /&gt; ip address 192.168.99.10 255.255.255.0&lt;BR /&gt; ip nat inside&lt;BR /&gt; ip nat enable&lt;BR /&gt; ip virtual-reassembly&lt;BR /&gt;!&lt;BR /&gt;interface Vlan126&lt;BR /&gt; ip address 10.252.126.2 255.255.255.252&lt;BR /&gt; ip nat outside&lt;BR /&gt; ip virtual-reassembly&lt;BR /&gt;!&lt;BR /&gt;interface Vlan200&lt;BR /&gt; ip address 192.168.100.26 255.255.255.252&lt;BR /&gt; ip ospf network point-to-point&lt;BR /&gt; ip ospf priority 0&lt;BR /&gt; ip ospf mtu-ignore&lt;BR /&gt;!&lt;BR /&gt;interface Vlan426&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;router ospf 100&lt;BR /&gt; log-adjacency-changes&lt;BR /&gt; network 192.168.11.224 0.0.0.31 area 0&lt;BR /&gt; network 192.168.100.4 0.0.0.3 area 0&lt;BR /&gt;!&lt;BR /&gt;router ospf 1&lt;BR /&gt; log-adjacency-changes&lt;BR /&gt; network 192.168.99.10 0.0.0.0 area 0&lt;BR /&gt; network 192.168.100.26 0.0.0.0 area 0&lt;BR /&gt;!&lt;BR /&gt;ip classless&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 86.96.194.209&lt;BR /&gt;ip route 10.2.1.0 255.255.255.0 10.252.126.1&lt;BR /&gt;ip route 10.50.5.0 255.255.255.0 10.16.34.1&lt;BR /&gt;ip route 10.250.126.0 255.255.255.0 192.168.99.9&lt;BR /&gt;ip route 150.100.0.0 255.255.0.0 10.16.34.1&lt;BR /&gt;ip route 172.168.10.0 255.255.255.0 192.168.98.9&lt;BR /&gt;ip route 172.168.10.0 255.255.255.0 192.168.3.34&lt;BR /&gt;ip route 192.168.30.0 255.255.255.0 10.16.34.1&lt;BR /&gt;ip route 213.42.105.160 255.255.255.224 10.16.34.1 10&lt;BR /&gt;!&lt;BR /&gt;ip http server&lt;BR /&gt;ip http access-class 23&lt;BR /&gt;ip http authentication local&lt;BR /&gt;ip http secure-server&lt;BR /&gt;ip http timeout-policy idle 60 life 86400 requests 10000&lt;BR /&gt;ip nat translation timeout 60&lt;BR /&gt;ip nat pool DFM_M 10.16.34.10 10.16.34.10 netmask 255.255.255.0&lt;BR /&gt;ip nat inside source list 100 interface GigabitEthernet0/0 overload&lt;BR /&gt;ip nat inside source list DFM pool DFM_M overload&lt;BR /&gt;ip nat inside source static 172.168.10.102 86.96.194.212&lt;BR /&gt;ip nat inside source static 172.168.10.8 86.96.194.213&lt;BR /&gt;ip nat inside source static 192.168.2.27 86.96.194.217&lt;BR /&gt;!&lt;BR /&gt;ip access-list extended DFM&lt;BR /&gt; permit ip any 213.42.105.0 0.0.0.255 log&lt;BR /&gt; permit ip any 213.42.105.160 0.0.0.31 log&lt;BR /&gt; permit ip any 192.168.30.0 0.0.0.255 log&lt;BR /&gt; permit ip any 150.100.0.0 0.0.255.255 log&lt;BR /&gt; permit ip any 10.50.5.0 0.0.0.255&lt;BR /&gt;!&lt;BR /&gt;no logging trap&lt;BR /&gt;access-list 100 deny&amp;nbsp;&amp;nbsp; ip any 213.42.105.0 0.0.0.255 log&lt;BR /&gt;access-list 100 deny&amp;nbsp;&amp;nbsp; ip host 172.168.10.8 any log&lt;BR /&gt;access-list 100 deny&amp;nbsp;&amp;nbsp; ip host 86.96.194.213 any log&lt;BR /&gt;access-list 100 deny&amp;nbsp;&amp;nbsp; ip host 172.168.10.102 any log&lt;BR /&gt;access-list 100 deny&amp;nbsp;&amp;nbsp; ip host 86.96.194.212 any log&lt;BR /&gt;access-list 100 permit ip any any!&lt;BR /&gt;line con 0&lt;BR /&gt; logging synchronous&lt;BR /&gt; login&lt;BR /&gt;line aux 0&lt;BR /&gt;line vty 0 4&lt;BR /&gt; privilege level 15&lt;BR /&gt; password 7 02070D5D18070B2C1D40&lt;BR /&gt; logging synchronous&lt;BR /&gt; login&lt;BR /&gt; transport input telnet ssh&lt;BR /&gt;line vty 5 15&lt;BR /&gt; access-class 23 in&lt;BR /&gt; privilege level 15&lt;BR /&gt; login local&lt;BR /&gt; transport input telnet ssh&lt;BR /&gt;!&lt;BR /&gt;scheduler allocate 20000 1000&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router#sh ip route 10.2.1.240&lt;BR /&gt;Routing entry for 10.2.1.0/24&lt;BR /&gt;&amp;nbsp; Known via "static", distance 1, metric 0&lt;BR /&gt;&amp;nbsp; Routing Descriptor Blocks:&lt;BR /&gt;&amp;nbsp; * 10.252.126.1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Route metric is 0, traffic share count is 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router#ping 10.2.1.240&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 10.2.1.240, timeout is 2 seconds:&lt;BR /&gt;.....&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Router#sh ip route&lt;BR /&gt;Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E1 - OSPF external type 1, E2 - OSPF external type 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ia - IS-IS inter area, * - candidate default, U - per-user static route&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; o - ODR, P - periodic downloaded static route&lt;/P&gt;&lt;P&gt;Gateway of last resort is 86.96.194.209 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;O E2 192.168.14.0/24 [110/51] via 192.168.100.25, 01:11:46, Vlan200&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 86.0.0.0/28 is subnetted, 1 subnets&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 86.96.194.208 is directly connected, GigabitEthernet0/0&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.99.0/24 is directly connected, Vlan100&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.0/8 is variably subnetted, 3 subnets, 2 masks&lt;BR /&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.2.1.0/24 [1/0] via 10.252.126.1&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.252.126.0/30 is directly connected, Vlan126&lt;BR /&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.250.126.0/24 [1/0] via 192.168.99.9&lt;BR /&gt;O E2 192.168.1.0/24 [110/51] via 192.168.100.25, 01:11:46, Vlan200&lt;BR /&gt;O&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.2.0/24 [110/11] via 192.168.99.9, 01:11:46, Vlan100&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.100.0/30 is subnetted, 2 subnets&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.100.24 is directly connected, Vlan200&lt;BR /&gt;O E2&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.100.20 [110/1] via 192.168.100.25, 01:11:46, Vlan200&lt;BR /&gt;S*&amp;nbsp;&amp;nbsp; 0.0.0.0/0 [1/0] via 86.96.194.209&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If anything else you require.....then let us know...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 08:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-issue/m-p/1499270#M708286</guid>
      <dc:creator>tuhinbhowmick</dc:creator>
      <dc:date>2010-06-28T08:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: Access Issue</title>
      <link>https://community.cisco.com/t5/network-security/access-issue/m-p/1499271#M708295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you advise what device is 10.252.126.1 and 192.168.99.9?&lt;/P&gt;&lt;P&gt;As advised earlier, you would need to check each hop to make sure that the traffic pass through each hop successfully. At this point, from the limited information, I won't be able to tell you where it's breaking.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 09:00:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-issue/m-p/1499271#M708295</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-28T09:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: Access Issue</title>
      <link>https://community.cisco.com/t5/network-security/access-issue/m-p/1499272#M708305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;192.168.99.9 is the firewall ip&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;and 10.252.126.1 is the IP of the market WAN link (though we have limited information regarding the actual scenario) .....that is the next hop ip for any traffic from our network to the outside world. one of the vlan 126 has been configured on our side router with 10.252.126.2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Also we are not able to ping the IP 10.252.126.1 from the router itself.......&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 09:23:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-issue/m-p/1499272#M708305</guid>
      <dc:creator>tuhinbhowmick</dc:creator>
      <dc:date>2010-06-28T09:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: Access Issue</title>
      <link>https://community.cisco.com/t5/network-security/access-issue/m-p/1499273#M708316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Base on the topology describes so far, here is what i understand it:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.2.1.240 -- Market WAN (10.252.126.1) -- (10.252.126.2) Router (192.168.99.10) -- (192.168.99.9) Firewall -- 192.168.2.x (server).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Is the server 192.168.2.x directly connected to the firewall?&lt;/P&gt;&lt;P&gt;2) If it is, can you ping the server from the firewall?&lt;/P&gt;&lt;P&gt;3) Does the firewall have any rules that might be blocking the access?&lt;/P&gt;&lt;P&gt;4) From the router, can you ping the server 192.168.2.x?&lt;/P&gt;&lt;P&gt;5) Since you can't even ping 10.252.126.1 from the router, you might want to check the Market WAN link, and see if it has routes back for 192.168.2.x back towards the router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 10:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-issue/m-p/1499273#M708316</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-28T10:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: Access Issue</title>
      <link>https://community.cisco.com/t5/network-security/access-issue/m-p/1499274#M708321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we need to check from sever (192.168.2.X) towards outside and need to access the ip 10.2.1.240.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now we have checked and are able to reach router(192.168.99.10) from the server (192.168.2.X) using traceroute of the ip 10.2.1.240 and it shows that it reaches router and after that showing "request timed out".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so we have to check the router configuration, which i have already provided to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if you need any further information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 11:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-issue/m-p/1499274#M708321</guid>
      <dc:creator>tuhinbhowmick</dc:creator>
      <dc:date>2010-06-28T11:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: Access Issue</title>
      <link>https://community.cisco.com/t5/network-security/access-issue/m-p/1499275#M708327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Base on the traceroute, it reaches the router. Next hop would be the firewall, that's why it's showing request time out. You would need to check if the firewall is receiving the packet and passing it to the next hop. I don't see issue with the router configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 11:19:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-issue/m-p/1499275#M708327</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-28T11:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: Access Issue</title>
      <link>https://community.cisco.com/t5/network-security/access-issue/m-p/1499276#M708332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i think i am not able to make you understand.........we are trying to reach&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have tested the traceroute from the server to 10.2.1.240...and here is the result for the same....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1st hop : 192.168.2.1 ----&amp;gt; Switch&lt;/P&gt;&lt;P&gt;2nd hop : 192.168.2.99 ----&amp;gt; Firewall&lt;/P&gt;&lt;P&gt;3rd hop : 192.168.99.10 ----&amp;gt; router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now after router it is showing "request timed out".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if you need any further clarification.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 12:30:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-issue/m-p/1499276#M708332</guid>
      <dc:creator>tuhinbhowmick</dc:creator>
      <dc:date>2010-06-28T12:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: Access Issue</title>
      <link>https://community.cisco.com/t5/network-security/access-issue/m-p/1499277#M708338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When I asked you earlier what is &lt;SPAN style="background-color: #f8fafd;"&gt;192.168.99.9, you advised that it is a firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there 2 firewalls in your network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the traceroute, it gave you a hop of the router, meaning it passes through the router OK, the next hop would be what is after the router interface of 192.168.99.10 (vlan 100). Base on the routing, it points to 192.168.99.9 which you advised earlier is a firewall. If it's not a firewall, please check what device it is, and what could be blocking it on that particular device.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jun 2010 12:41:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-issue/m-p/1499277#M708338</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-28T12:41:30Z</dc:date>
    </item>
  </channel>
</rss>

