<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 7.0 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-7-0/m-p/1231284#M877511</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not sure I understand this but I am assuming you want your internal users and dmz users to access the Internet. I think for that all you need is:&lt;/P&gt;&lt;P&gt;nat (inside) 1 172.20.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (dmz) 1 192.168.4.0 255.255.255.0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;global (dmz) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also don't know why you would like DMZ devices to access the internal network but for that you will need to apply an ACL to dmz interface&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Jan 2009 20:53:45 GMT</pubDate>
    <dc:creator>Tshi M</dc:creator>
    <dc:date>2009-01-20T20:53:45Z</dc:date>
    <item>
      <title>ASA 7.0</title>
      <link>https://community.cisco.com/t5/network-security/asa-7-0/m-p/1231283#M877510</link>
      <description>&lt;P&gt;I had a post with a 6.3(4) referring to the same issue, so now Ive treid the same with an ASA.&lt;/P&gt;&lt;P&gt;My config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int inside&lt;/P&gt;&lt;P&gt;security 100&lt;/P&gt;&lt;P&gt;ip add 172.20.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int out&lt;/P&gt;&lt;P&gt;security 0&lt;/P&gt;&lt;P&gt;ip add 10.10.10.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int dmz&lt;/P&gt;&lt;P&gt;192.168.4.1&lt;/P&gt;&lt;P&gt;security 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (dmz) 1 192.168.4.0 255.255.255.0&lt;/P&gt;&lt;P&gt;global (inside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 2 172.20.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;global (outside) 2 10.10.10.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL's on inside and dmz permit ip any any and permit icmp any any&lt;/P&gt;&lt;P&gt;I want to be able to access inside&amp;amp;outside and I cant.Only one works at a time: either from dmz to inside or dmz from outside, depending on how you play with the NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Vlad &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS: Static is out of question as I have around 20-25 networks on the inside to be accessed  from the dmz.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-7-0/m-p/1231283#M877510</guid>
      <dc:creator>hunnetvl01</dc:creator>
      <dc:date>2019-03-11T14:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 7.0</title>
      <link>https://community.cisco.com/t5/network-security/asa-7-0/m-p/1231284#M877511</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not sure I understand this but I am assuming you want your internal users and dmz users to access the Internet. I think for that all you need is:&lt;/P&gt;&lt;P&gt;nat (inside) 1 172.20.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (dmz) 1 192.168.4.0 255.255.255.0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;global (dmz) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also don't know why you would like DMZ devices to access the internal network but for that you will need to apply an ACL to dmz interface&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Jan 2009 20:53:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-7-0/m-p/1231284#M877511</guid>
      <dc:creator>Tshi M</dc:creator>
      <dc:date>2009-01-20T20:53:45Z</dc:date>
    </item>
  </channel>
</rss>

