<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: another ASA question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/another-asa-question/m-p/1297629#M826384</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"11. If there is one DMZ, does the extra default route (item a) need to be configured for the DMZ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a. route dmz 0.0.0.0 0.0.0.0 210.1.3.1 (for DMZ) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b. route outside 0.0.0.0 0.0.0.0 210.1.3.1 (for outbound traffic to Internet) "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NO. 210.1.3.1 exists on the outside interface, not the DMZ.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 19 Sep 2009 14:29:44 GMT</pubDate>
    <dc:creator>acomiskey</dc:creator>
    <dc:date>2009-09-19T14:29:44Z</dc:date>
    <item>
      <title>another ASA question</title>
      <link>https://community.cisco.com/t5/network-security/another-asa-question/m-p/1297628#M826354</link>
      <description>&lt;P&gt;Hi expert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Grateful if the expert could advise on it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;11. If there is one DMZ, does the extra default route (item a) need to be configured for the DMZ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a. route dmz 0.0.0.0 0.0.0.0 210.1.3.1 (for DMZ)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b. route outside 0.0.0.0 0.0.0.0 210.1.3.1 (for outbound traffic to Internet)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;12 how do I defind the "CHK_attack" object if the command is configured as below?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip audit interface inside CHK_attack&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;13. The decription from the command reference is obscure, grateful if you could advise on the "LOCAL". what user account to be auth? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record InControlPolicy&lt;/P&gt;&lt;P&gt;aaa authentication enable console LOCAL &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;14 if the enable password is not configured but the enable secret was confiured, what will happen if the command is configured as below?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication http console&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;15. Following is the default policy to be configured from the cisco web site. What happen if those commands are removed? what is the different between command "ip audit interface outside CHK_attack"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!            &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rdgs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:17:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/another-asa-question/m-p/1297628#M826354</guid>
      <dc:creator>anitachoi3</dc:creator>
      <dc:date>2019-03-11T16:17:30Z</dc:date>
    </item>
    <item>
      <title>Re: another ASA question</title>
      <link>https://community.cisco.com/t5/network-security/another-asa-question/m-p/1297629#M826384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"11. If there is one DMZ, does the extra default route (item a) need to be configured for the DMZ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a. route dmz 0.0.0.0 0.0.0.0 210.1.3.1 (for DMZ) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b. route outside 0.0.0.0 0.0.0.0 210.1.3.1 (for outbound traffic to Internet) "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NO. 210.1.3.1 exists on the outside interface, not the DMZ.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Sep 2009 14:29:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/another-asa-question/m-p/1297629#M826384</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2009-09-19T14:29:44Z</dc:date>
    </item>
    <item>
      <title>Re: another ASA question</title>
      <link>https://community.cisco.com/t5/network-security/another-asa-question/m-p/1297630#M826404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any idea regarding item 12 - 15 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rdgs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Sep 2009 15:54:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/another-asa-question/m-p/1297630#M826404</guid>
      <dc:creator>anitachoi3</dc:creator>
      <dc:date>2009-09-19T15:54:39Z</dc:date>
    </item>
  </channel>
</rss>

