<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DMZ Deployment problems in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075082#M878596</link>
    <description>&lt;P&gt;have to configure a cisco ASA 5510 for my web server, i did all the config by the manual, but typeing my outside ip i get page could not be found,&lt;/P&gt;&lt;P&gt;i enabled and configured a DMZ interface where i connected my web server, (interface ip 10.0.10.1)&lt;/P&gt;&lt;P&gt;1. I added a NAT rule between DMZ and inside interface ex.: (10.0.10.30 -&amp;gt;78.52.39.51) with enabled PAT port 80&lt;/P&gt;&lt;P&gt;2. A NAT rule betwen the inside and DMZ interfaces (10.0.10.0 -&amp;gt; 10.0.10.0)&lt;/P&gt;&lt;P&gt;3. Address translation rule betwen the outside and DMZ interfaces that translates its public ip of the DMZ to its privat ip, ex.: (75.52.39.51 -&amp;gt; 10.10.10.30)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ interface IP:10.0.10.1&lt;/P&gt;&lt;P&gt;Web_Server IP:10.0.10.5&lt;/P&gt;&lt;P&gt;Local network IP:198.162.0.1 -&amp;gt;&lt;/P&gt;&lt;P&gt;Static outside ip: ex.: 75.52.39.51&lt;/P&gt;&lt;P&gt;Help please&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 14:28:06 GMT</pubDate>
    <dc:creator>adem.zuberi</dc:creator>
    <dc:date>2019-03-11T14:28:06Z</dc:date>
    <item>
      <title>DMZ Deployment problems</title>
      <link>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075082#M878596</link>
      <description>&lt;P&gt;have to configure a cisco ASA 5510 for my web server, i did all the config by the manual, but typeing my outside ip i get page could not be found,&lt;/P&gt;&lt;P&gt;i enabled and configured a DMZ interface where i connected my web server, (interface ip 10.0.10.1)&lt;/P&gt;&lt;P&gt;1. I added a NAT rule between DMZ and inside interface ex.: (10.0.10.30 -&amp;gt;78.52.39.51) with enabled PAT port 80&lt;/P&gt;&lt;P&gt;2. A NAT rule betwen the inside and DMZ interfaces (10.0.10.0 -&amp;gt; 10.0.10.0)&lt;/P&gt;&lt;P&gt;3. Address translation rule betwen the outside and DMZ interfaces that translates its public ip of the DMZ to its privat ip, ex.: (75.52.39.51 -&amp;gt; 10.10.10.30)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ interface IP:10.0.10.1&lt;/P&gt;&lt;P&gt;Web_Server IP:10.0.10.5&lt;/P&gt;&lt;P&gt;Local network IP:198.162.0.1 -&amp;gt;&lt;/P&gt;&lt;P&gt;Static outside ip: ex.: 75.52.39.51&lt;/P&gt;&lt;P&gt;Help please&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:28:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075082#M878596</guid>
      <dc:creator>adem.zuberi</dc:creator>
      <dc:date>2019-03-11T14:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Deployment problems</title>
      <link>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075083#M878598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adem, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Review DMZ implementation, visit this link&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/getting_started/asa5500/quick/guide/dmz.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/getting_started/asa5500/quick/guide/dmz.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it could be something simple to correct, make sure your webserver is indeed listening on port 80, also look at ASDM real time log while trying to access webserver from outside, log can provide information usefull for troubleshooting the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If still issues  PLS post the firewall configuration .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Dec 2008 22:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075083#M878598</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-12-20T22:14:00Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Deployment problems</title>
      <link>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075084#M878600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I configured the asa according to:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/getting_started/asa5500/quick/guide/dmz.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/getting_started/asa5500/quick/guide/dmz.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but no success.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Running config:&lt;/P&gt;&lt;P&gt;ASA Version 8.0(3)6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 10.1.1.0 adrespul&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.0.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 10&lt;/P&gt;&lt;P&gt; ip address 10.30.30.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 212.xxx.xxx.xxx 255.255.255.248&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;access-list nadvor_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list nadvor_access_in extended permit tcp any eq www host 212.xxx.xxx.xxx&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-603.bin&lt;/P&gt;&lt;P&gt;asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 10.1.1.15-10.1.1.253 netmask 255.0.0.0&lt;/P&gt;&lt;P&gt;global (outside) 101 interface&lt;/P&gt;&lt;P&gt;global (DMZ) 200 interface&lt;/P&gt;&lt;P&gt;nat (inside) 101 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (DMZ,outside) tcp interface www 10.30.30.30 www netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (DMZ,inside) 10.30.30.30 xxx.xxx.xxx.xxx netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static (inside,DMZ) interface 10.30.30.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-group nadvor_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 xxx.xxx.xxx.xxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SYSLOG MESSAGE:&lt;/P&gt;&lt;P&gt;conn from inside:&lt;/P&gt;&lt;P&gt;3 Feb 24 2008	23:38:50	710003	192.168.0.8	212.xxx.xxx.xxx	 TCP access denied by ACL from 192.168.0.8/3764 to inside:212.xxx.xxx.xxx/80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Conn from outside:&lt;/P&gt;&lt;P&gt;4	Feb 24 2008	23:41:12	106023	 Deny tcp src outside:77.xxx.xxx.xxx/64589 dst DMZ:212.xxx.xxx.xxx/80 by access-group "nadvor_access_in" [0x0, 0x0]&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Dec 2008 12:13:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075084#M878600</guid>
      <dc:creator>adem.zuberi</dc:creator>
      <dc:date>2008-12-21T12:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Deployment problems</title>
      <link>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075085#M878602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;B&gt;Conn from outside: &lt;/B&gt;&lt;/P&gt;&lt;P&gt;4 Feb 24 2008 23:41:12 106023 Deny tcp src outside:77.xxx.xxx.xxx/64589 dst DMZ:212.xxx.xxx.xxx/80 by access-group "nadvor_access_in" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;remove&lt;/P&gt;&lt;P&gt;no access-list nadvor_access_in extended permit tcp any eq www host 212.xxx.xxx.xxx &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;add &lt;/P&gt;&lt;P&gt;access-list nadvor_access_in extended permit tcp any interface outside eq www log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;conn from inside: &lt;/B&gt;&lt;/P&gt;&lt;P&gt;3 Feb 24 2008 23:38:50 710003 192.168.0.8 212.xxx.xxx.xxx TCP access denied by ACL from 192.168.0.8/3764 to inside:212.xxx.xxx.xxx/80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This one is trikie as you are tryng U-turn or better said hairpining  using outside interface IP address,  not a  spared public IP per say.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can try  if your web server is 10.30.30.30 in DMZ.&lt;/P&gt;&lt;P&gt;    &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ,DMZ) 212.xxx.xxx.xxx 10.30.30.30 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PLS  try and  post results&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Dec 2008 15:43:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075085#M878602</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-12-21T15:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Deployment problems</title>
      <link>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075086#M878603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply it works from outside after i did as u suggested, but not from inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Dec 2008 17:10:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075086#M878603</guid>
      <dc:creator>adem.zuberi</dc:creator>
      <dc:date>2008-12-21T17:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Deployment problems</title>
      <link>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075087#M878604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post the logs from when you try connecting from inside to 212.xxx.xxx.xxx, is the log same as before?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Dec 2008 18:44:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075087#M878604</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-12-21T18:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Deployment problems</title>
      <link>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075088#M878605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I Have tested your configuration .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PLS remove this static - but  you can leave as is if any host from DMZ tries accessing 10.30.30.30 through public IP&lt;/P&gt;&lt;P&gt;static (DMZ,DMZ) 212.xxx.xxx.xxx 10.30.30.30 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From inside to DMZ to access 10.30.30.30 via public IP you need this nat entry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ,inside) 212.xxx.xxx.xxx  10.30.30.30 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;PLS rate post if it helps&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Dec 2008 21:08:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075088#M878605</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-12-21T21:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Deployment problems</title>
      <link>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075089#M878606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adem, could specify whether the solution worked or not to assist you fruther, if worked PLS rate post as resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Dec 2008 23:44:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075089#M878606</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-12-21T23:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ Deployment problems</title>
      <link>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075090#M878607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it did work thanks for your time and klonedge.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Dec 2008 07:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-deployment-problems/m-p/1075090#M878607</guid>
      <dc:creator>adem.zuberi</dc:creator>
      <dc:date>2008-12-22T07:40:55Z</dc:date>
    </item>
  </channel>
</rss>

