<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Proxy/mail server -ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113955#M895484</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;internet-&amp;lt;-----ASAx.x.3.100--&amp;lt;-----x.x.3.99ProxyServer----&lt;LAN&gt;&lt;/LAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a) from Lan can you ping 192.168.3.100 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b)In the Access-list applied on outside interface, add the line, access-list &lt;NAME&gt; line 1 permit icmp any any&lt;/NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;c)Now, ping 4.2.2.2 from the LAN, turn on "debug icmp trace" do you see icmp packet reaching firewall ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible post your configuration here ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 04 Oct 2008 17:06:34 GMT</pubDate>
    <dc:creator>abinjola</dc:creator>
    <dc:date>2008-10-04T17:06:34Z</dc:date>
    <item>
      <title>Proxy/mail server -ASA</title>
      <link>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113954#M895481</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have proxy server and having two interface.One int face isconnected to Lan(192.168.*.*) and another 192.168.3.100 which is connected to my firwall.&lt;/P&gt;&lt;P&gt;I have configured in ASA,inside ip 192.168.3.99 and outside ip 192.168.4.2.All lan user using proxy for the internet.From ASA ,I can ping all interface.but i cant ping 192.168.3.99 from the proxy server and internet is also is not working.What would be the problem.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:53:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113954#M895481</guid>
      <dc:creator>CSCO10320953</dc:creator>
      <dc:date>2019-03-11T13:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy/mail server -ASA</title>
      <link>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113955#M895484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;internet-&amp;lt;-----ASAx.x.3.100--&amp;lt;-----x.x.3.99ProxyServer----&lt;LAN&gt;&lt;/LAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a) from Lan can you ping 192.168.3.100 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b)In the Access-list applied on outside interface, add the line, access-list &lt;NAME&gt; line 1 permit icmp any any&lt;/NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;c)Now, ping 4.2.2.2 from the LAN, turn on "debug icmp trace" do you see icmp packet reaching firewall ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible post your configuration here ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Oct 2008 17:06:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113955#M895484</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-10-04T17:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy/mail server -ASA</title>
      <link>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113956#M895492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All lan traffic is coming through the Proxy server IPs :lan 192.168.*.*.LAn and proxy server is in the same network.&lt;/P&gt;&lt;P&gt;Proxy Second ip 192.168.3.100 which is connected inside interface 192.168.3.99.Ouside ip 192.168.4.2 which is connectd to BSNL modem 192.168.4.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BMR1C#  sh run             &lt;/P&gt;&lt;P&gt;: Saved       &lt;/P&gt;&lt;P&gt;: &lt;/P&gt;&lt;P&gt;ASA Version 7.0(6)                  &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;                                       &lt;/P&gt;&lt;P&gt;      &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface Ethernet0/0                     &lt;/P&gt;&lt;P&gt; nameif inside              &lt;/P&gt;&lt;P&gt; security-level 100                   &lt;/P&gt;&lt;P&gt; ip address 192.168.3.99 255.255.255.0                                      &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface Ethernet0/0.1                       &lt;/P&gt;&lt;P&gt; shutdown         &lt;/P&gt;&lt;P&gt; no vlan        &lt;/P&gt;&lt;P&gt; no nameif          &lt;/P&gt;&lt;P&gt; no security-level                  &lt;/P&gt;&lt;P&gt; no ip address              &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface Ethernet0/0.2                       &lt;/P&gt;&lt;P&gt; shutdown         &lt;/P&gt;&lt;P&gt; no vlan        &lt;/P&gt;&lt;P&gt; no nameif          &lt;/P&gt;&lt;P&gt; no security-level                  &lt;/P&gt;&lt;P&gt; no ip address              &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface Ethernet0/1                     &lt;/P&gt;&lt;P&gt; shutdown         &lt;/P&gt;&lt;P&gt; no nameif          &lt;/P&gt;&lt;P&gt; no security-level                  &lt;/P&gt;&lt;P&gt; no ip address              &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface Ethernet0/2                     &lt;/P&gt;&lt;P&gt; nameif Outside               &lt;/P&gt;&lt;P&gt; security-level 0                 &lt;/P&gt;&lt;P&gt; ip address 192.168.4.2 255.255.255.0                  &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface Management0/0                       &lt;/P&gt;&lt;P&gt; nameif management                  &lt;/P&gt;&lt;P&gt; security-level 0                 &lt;/P&gt;&lt;P&gt; ip address *.*.*.* 255.255.255.128                                     &lt;/P&gt;&lt;P&gt; management-only                &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted                                 &lt;/P&gt;&lt;P&gt;ftp mode passive                &lt;/P&gt;&lt;P&gt;pager lines 24              &lt;/P&gt;&lt;P&gt;mtu inside 1500               &lt;/P&gt;&lt;P&gt;mtu Outside 1500                &lt;/P&gt;&lt;P&gt;mtu management 1500                   &lt;/P&gt;&lt;P&gt;no asdm history enable                      &lt;/P&gt;&lt;P&gt;arp timeout 14400                 &lt;/P&gt;&lt;P&gt;route inside 192.168.0.0 255.255.255.0 192.168.3.100 1                                                      &lt;/P&gt;&lt;P&gt;route Outside 0.0.0.0 0.0.0.0 192.168.4.1 1                                           &lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00                     &lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02                                                    &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;             &lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0                                                     &lt;/P&gt;&lt;P&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00                                                      &lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute                              &lt;/P&gt;&lt;P&gt;http server enable                  &lt;/P&gt;&lt;P&gt;management                                         &lt;/P&gt;&lt;P&gt;no snmp-server location                       &lt;/P&gt;&lt;P&gt;no snmp-server contact                      &lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart                                               &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;                       &lt;/P&gt;&lt;P&gt;telnet timeout 5                &lt;/P&gt;&lt;P&gt;ssh timeout 5             &lt;/P&gt;&lt;P&gt;console timeout 0                 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;class-map inspection_default                            &lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns maximum-length 512&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  inspect h323 h225&lt;/P&gt;&lt;P&gt;  inspect h323 ras&lt;/P&gt;&lt;P&gt;  inspect netbios&lt;/P&gt;&lt;P&gt;  inspect rsh&lt;/P&gt;&lt;P&gt;  inspect rtsp&lt;/P&gt;&lt;P&gt;  inspect skinny&lt;/P&gt;&lt;P&gt;  inspect esmtp&lt;/P&gt;&lt;P&gt;  inspect sqlnet&lt;/P&gt;&lt;P&gt;  inspect sunrpc&lt;/P&gt;&lt;P&gt;  inspect tftp&lt;/P&gt;&lt;P&gt;  inspect sip&lt;/P&gt;&lt;P&gt;  inspect xdmcp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;Cryptochecksum:2143d98d4cd9274aabcf7c7d19e73c7d&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;BMRC#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2008 05:56:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113956#M895492</guid>
      <dc:creator>CSCO10320953</dc:creator>
      <dc:date>2008-10-07T05:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy/mail server -ASA</title>
      <link>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113957#M895496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take care of following points :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have a ASA 5505 correct ? By default, port e0/0 is the outside Interface and rest 0/1-0/7 part of VLAN1 which is inside interface, but you have made e0/0 as inside, please make sure you have it assigned on VLAN 1 (inside) and e0/2 must be assigned in VLAN 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b)Remove the logical VLANs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no interface Ethernet0/0.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no interface Ethernet0/0.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;c)You never answered if you are able to ping inside interface from any inside LAN machine ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;d)On the Outside you have a private IP, who does the NATTing ? outside modem or ASA ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like you to add following commands &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default &lt;/P&gt;&lt;P&gt;inspect icmp &lt;/P&gt;&lt;P&gt;logg mon 7&lt;/P&gt;&lt;P&gt;term mon&lt;/P&gt;&lt;P&gt;logg on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now onc you have thess commands in place, ping 4.2.2.2 and collect the logs, paste it here  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2008 06:28:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113957#M895496</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-10-07T06:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy/mail server -ASA</title>
      <link>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113958#M895503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C.NO &lt;/P&gt;&lt;P&gt;d.Nat ASA I&lt;/P&gt;&lt;P&gt;BMRC# debug icmp trace&lt;/P&gt;&lt;P&gt;debug icmp trace enabled at level 1&lt;/P&gt;&lt;P&gt;BMRC# ping 4.2.2.2&lt;/P&gt;&lt;P&gt;                  ICMP echo request from 192.168.4.2 to 4.2.2.2 ID=4388 seq=4838&lt;/P&gt;&lt;P&gt;4 len=72&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 4.2.2.2, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;ICMP echo reply from 4.2.2.2 to 192.168.4.2 ID=4388 seq=48384 len=72&lt;/P&gt;&lt;P&gt;!ICMP echo request from 192.168.4.2 to 4.2.2.2 ID=4388 seq=48384 len=72&lt;/P&gt;&lt;P&gt;!ICMP echo reply from 4.2.2.2 to 192.168.4.2 ID=4388 seq=48384 len=72&lt;/P&gt;&lt;P&gt;ICMP echo request from 192.168.4.2 to 4.2.2.2 ID=4388 seq=48384 len=72&lt;/P&gt;&lt;P&gt;ICMP echo reply from 4.2.2.2 to 192.168.4.2 ID=4388 seq=48384 len=72&lt;/P&gt;&lt;P&gt;!ICMP echo request from 192.168.4.2 to 4.2.2.2 ID=4388 seq=48384 len=72&lt;/P&gt;&lt;P&gt;!ICMP echo reply from 4.2.2.2 to 192.168.4.2 ID=4388 seq=48384 len=72&lt;/P&gt;&lt;P&gt;ICMP echo request from 192.168.4.2 to 4.2.2.2 ID=4388 seq=48384 len=72&lt;/P&gt;&lt;P&gt;ICMP echo reply from 4.2.2.2 to 192.168.4.2 ID=4388 seq=48384 len=72&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2008 08:59:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113958#M895503</guid>
      <dc:creator>CSCO10320953</dc:creator>
      <dc:date>2008-10-07T08:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy/mail server -ASA</title>
      <link>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113959#M895511</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;add&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2008 09:05:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113959#M895511</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-10-07T09:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy/mail server -ASA</title>
      <link>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113960#M895517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not able to ping 192.168.3.99&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route Outside 0.0.0.0 0.0.0.0 192.168.4.1 1&lt;/P&gt;&lt;P&gt;route inside 192.168.0.0 255.255.255.0 192.168.3.99 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2008 09:13:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113960#M895517</guid>
      <dc:creator>CSCO10320953</dc:creator>
      <dc:date>2008-10-07T09:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy/mail server -ASA</title>
      <link>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113961#M895526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list outacc extended permit icmp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outacc in interface Outside&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2008 09:25:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113961#M895526</guid>
      <dc:creator>CSCO10320953</dc:creator>
      <dc:date>2008-10-07T09:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy/mail server -ASA</title>
      <link>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113962#M895533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;from the firewall are you able to ping proxy 3.99 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from the proxy ping 4.2.2.2 and turn on &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logg on&lt;/P&gt;&lt;P&gt;logg mon 7&lt;/P&gt;&lt;P&gt;term mon&lt;/P&gt;&lt;P&gt;debug icmp trace&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;send me the above outputs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Oct 2008 09:30:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxy-mail-server-asa/m-p/1113962#M895533</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-10-07T09:30:20Z</dc:date>
    </item>
  </channel>
</rss>

