<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Question-Help needed in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-question-help-needed/m-p/1069453#M895115</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can make the configuration as simple,by controlling all the nat operation at the firewall and allow only routing in the router.It will make as simple the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Archana.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 21 Oct 2008 08:25:49 GMT</pubDate>
    <dc:creator>marchanamendon</dc:creator>
    <dc:date>2008-10-21T08:25:49Z</dc:date>
    <item>
      <title>ASA Question-Help needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-question-help-needed/m-p/1069448#M895094</link>
      <description>&lt;P&gt;I have configured and integrated an ASA to my network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside----ASA----ROUTER-----Internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 3 servers in my inside network,one of them is a proxy server which all other users use. The 3 servers have both public and private addresses.I have done two layers of nat,one on the ASA and the other on the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My inside users cannot ping the inside interface of the router neither can they browse.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the configs on the ASA and router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone please take a look at it and let me know where I got it wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:57:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-question-help-needed/m-p/1069448#M895094</guid>
      <dc:creator>sameoj1881</dc:creator>
      <dc:date>2019-03-11T13:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Question-Help needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-question-help-needed/m-p/1069449#M895098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some should please help me look into this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Oct 2008 16:07:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-question-help-needed/m-p/1069449#M895098</guid>
      <dc:creator>sameoj1881</dc:creator>
      <dc:date>2008-10-16T16:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Question-Help needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-question-help-needed/m-p/1069450#M895103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post a more complete asa sanatized config to get a better picture and see the nonat acls. You said that your inside users cannot get to the inside interface of the router facing asa outside interface and browse,  if this is so you simply need a nat statement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.i&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your asa already have this statement &lt;/P&gt;&lt;P&gt;global (outside) 1 interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do you have these ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside ) 1 &lt;INSIDE_SUBNET&gt;&lt;/INSIDE_SUBNET&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Oct 2008 19:13:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-question-help-needed/m-p/1069450#M895103</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-10-16T19:13:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Question-Help needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-question-help-needed/m-p/1069451#M895106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you are not filtering out that traffic on the router by the use of access control lists  ..?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps   ..  please rate helpful posts  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Oct 2008 20:49:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-question-help-needed/m-p/1069451#M895106</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2008-10-16T20:49:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Question-Help needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-question-help-needed/m-p/1069452#M895109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ASA Configs&lt;/P&gt;&lt;P&gt;static(inside,outside) x.x.103.5 x.x.101.5 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static(inside,outside) x.x.103.250 x.x.101.250 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;static(inside,outside) x.x.103.2 x.x.101.2 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 100 extended permit icmp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 100 extended permit tcp any host x.x.103.5 eq 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 100 extended permit tcp any host x.x.103.250 eq 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 100 extended permit tcp any host x.x.103.2 eq 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int e0/1&lt;/P&gt;&lt;P&gt;access-group 100 in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list NO-NAT extended permit ip x.x.101.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat(inside) 1 access-list NO-NAT&lt;/P&gt;&lt;P&gt;global(outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0. x.x.103.7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router Configs&lt;/P&gt;&lt;P&gt;access-list 10 permit x.x.103.0 0.0.0.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source list 10 interface fa0/0 overlaod&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp x.x.103.5 80 x.x.39.155 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp x.x.103.250 80 x.x.39.156 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp x.x.103.2 25 x.x.39.73 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int fa0/0&lt;/P&gt;&lt;P&gt;ip nat outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int fa0/1&lt;/P&gt;&lt;P&gt;ip nat inside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Oct 2008 08:22:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-question-help-needed/m-p/1069452#M895109</guid>
      <dc:creator>sameoj1881</dc:creator>
      <dc:date>2008-10-17T08:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Question-Help needed</title>
      <link>https://community.cisco.com/t5/network-security/asa-question-help-needed/m-p/1069453#M895115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can make the configuration as simple,by controlling all the nat operation at the firewall and allow only routing in the router.It will make as simple the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Archana.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Oct 2008 08:25:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-question-help-needed/m-p/1069453#M895115</guid>
      <dc:creator>marchanamendon</dc:creator>
      <dc:date>2008-10-21T08:25:49Z</dc:date>
    </item>
  </channel>
</rss>

