<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need Help getting Outside network to talk to DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170668#M875950</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;np - glad to help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 23 Feb 2009 19:56:23 GMT</pubDate>
    <dc:creator>andrew.prince</dc:creator>
    <dc:date>2009-02-23T19:56:23Z</dc:date>
    <item>
      <title>Need Help getting Outside network to talk to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170658#M875928</link>
      <description>&lt;P&gt;I'm in the testing phase of setting up an ASA 5520 and I'm having some issues getting the Outside network to talk to the DMZ. I set up a test using a web server on 172.20.175.110 (SCADADEV01) and I thought I had it NATed correctly and had the right ACL but I cannot seemed to get to from the test computer 10.80.1.16. Can you give me a little help. Attached is the config file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:55:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170658#M875928</guid>
      <dc:creator>tharris</dc:creator>
      <dc:date>2019-03-11T14:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help getting Outside network to talk to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170659#M875929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your NAT is incorrect, and your outside acl is incorrect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would configure something like - for testing:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ,outside) tcp interface www 172.20.175.110 www netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then write the acl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any interface outside eq 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 15:18:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170659#M875929</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-02-23T15:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help getting Outside network to talk to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170660#M875930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I simplified the config and tried your suggestion. But no joy. Attached is the modified config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 16:02:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170660#M875930</guid>
      <dc:creator>tharris</dc:creator>
      <dc:date>2009-02-23T16:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help getting Outside network to talk to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170661#M875932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK - when you say it did not work, how did you test it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What debugging did you have enabled?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 16:09:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170661#M875932</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-02-23T16:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help getting Outside network to talk to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170662#M875934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I simply opened up a browser on the outside client computer (10.80.1.16) and typed in the url 172.20.175.110 and it timed out. Doing this same test from a computer on the inside network works fine. How do you suggest I debug this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 16:39:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170662#M875934</guid>
      <dc:creator>tharris</dc:creator>
      <dc:date>2009-02-23T16:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help getting Outside network to talk to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170663#M875937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK - firstly,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are typing the wrong IP address. You are natting on the firewall - so you will not be able to connect to the DMZ IP address, as this is not know on the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test again using the IP address "10.80.1.15"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly - enable logging, then check the logs.  You can also check to see if your access is being hit - show access-list.  The you should check connectivity locally from a device in the DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 16:44:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170663#M875937</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-02-23T16:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help getting Outside network to talk to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170664#M875941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, typing in 10.80.1.15 was successful from the outside client copmputer. I apologize for how green I am in doing this. Thanks for your patience. I will also follow your other suggestions. I think I can use the web example to fix the other connectivity problems I'm having. I appreciate the help. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 16:57:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170664#M875941</guid>
      <dc:creator>tharris</dc:creator>
      <dc:date>2009-02-23T16:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help getting Outside network to talk to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170665#M875943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I simply opened up a browser on the outside client computer (10.80.1.16) and typed in the url 172.20.175.110 and it timed out. Doing this same test from a computer on the inside network works fine. How do you suggest I debug this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 16:59:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170665#M875943</guid>
      <dc:creator>tharris</dc:creator>
      <dc:date>2009-02-23T16:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help getting Outside network to talk to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170666#M875945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Should I ignore this post? As I think I have already answered it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 17:09:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170666#M875945</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-02-23T17:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help getting Outside network to talk to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170667#M875948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. Ignor it. Not sure how it got sent.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 17:28:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170667#M875948</guid>
      <dc:creator>tharris</dc:creator>
      <dc:date>2009-02-23T17:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Need Help getting Outside network to talk to DMZ</title>
      <link>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170668#M875950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;np - glad to help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 19:56:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-help-getting-outside-network-to-talk-to-dmz/m-p/1170668#M875950</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-02-23T19:56:23Z</dc:date>
    </item>
  </channel>
</rss>

