<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active Directory issues and ASA 5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/active-directory-issues-and-asa-5510/m-p/1041056#M914920</link>
    <description>&lt;P&gt;We are running an ASA 5510 w/ 8.0(3) code that is isolating vendor systems from our network. We have an enterprise AD structure and the vendor has an internal AD structure for their system. Their systems exist on our network in a non-routed VLAN and the ASA has an interface inside that VLAN for traffic. If I disable the ASA interface, all connectivity within the VLAN functions normally (and I stress within the VLAN). If I enable the interface, the devices can no longer authenticate nor map network shares within the VLAN. A packet capture finds master browser elections that no one answers while the interface is enabled but the AD server answers when the interface is off. I have tried denying all traffic across the interface and even allowing all traffic. NETBIOS inspect, DNS inspect are turned on in the default inspect policy. Yes, the allow traffic between hosts on the same interface is enable as well. All the devices are physically connected to the same switch and exists in the same VLAN. Please forgive the lack of logs at this moment, I can't access them from home but will add in another post tomorrow. Any guidance or suggestions to look for is appreciated.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 13:28:12 GMT</pubDate>
    <dc:creator>vhabilthornc</dc:creator>
    <dc:date>2019-03-11T13:28:12Z</dc:date>
    <item>
      <title>Active Directory issues and ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/active-directory-issues-and-asa-5510/m-p/1041056#M914920</link>
      <description>&lt;P&gt;We are running an ASA 5510 w/ 8.0(3) code that is isolating vendor systems from our network. We have an enterprise AD structure and the vendor has an internal AD structure for their system. Their systems exist on our network in a non-routed VLAN and the ASA has an interface inside that VLAN for traffic. If I disable the ASA interface, all connectivity within the VLAN functions normally (and I stress within the VLAN). If I enable the interface, the devices can no longer authenticate nor map network shares within the VLAN. A packet capture finds master browser elections that no one answers while the interface is enabled but the AD server answers when the interface is off. I have tried denying all traffic across the interface and even allowing all traffic. NETBIOS inspect, DNS inspect are turned on in the default inspect policy. Yes, the allow traffic between hosts on the same interface is enable as well. All the devices are physically connected to the same switch and exists in the same VLAN. Please forgive the lack of logs at this moment, I can't access them from home but will add in another post tomorrow. Any guidance or suggestions to look for is appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:28:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-directory-issues-and-asa-5510/m-p/1041056#M914920</guid>
      <dc:creator>vhabilthornc</dc:creator>
      <dc:date>2019-03-11T13:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory issues and ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/active-directory-issues-and-asa-5510/m-p/1041057#M914930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First regarding AD, i have had more than my share of this lately with my clients &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please explain more about the relationship with the AD connections?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are your servers multi-homed in their DMZ with dual-nics?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could their be a simple IP conflict between the ASA (include nat's as ARP plays into this) and their servers? How have  you checked this? look at arp -a on the servers... make sure you dont have arp entries for servers coming back to the ASA's mac address...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;have you setup a trust between your servers? one-way? two-way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does eventvwr show? who error messages?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please give us these answers and we can continue helping  you solve this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you be open to me coming in with you on webex and helping you solve this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Aug 2008 01:17:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-directory-issues-and-asa-5510/m-p/1041057#M914930</guid>
      <dc:creator>joe19366</dc:creator>
      <dc:date>2008-08-08T01:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory issues and ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/active-directory-issues-and-asa-5510/m-p/1041058#M914940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the response Joe..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The two AD's mentioned are completely seperate, no trusts, no DMZ, no nothing. Their AD is in place to authenticate their workstations to their db server. Another system within their setup sends data to two specific systems on the private side of our network. I haven't looked at the arps' on their server but I can and will. We assigned the ip range for their systems and we check for duplicates before assigning them, but who knows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The vendor server (and workstations) event logs sho very generic and non-descript error messages relating to SMB errors. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sadly, the powers that be in my workplace do not allow Webex unless it is written in as support on a contract &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you again for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chuck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Aug 2008 12:30:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-directory-issues-and-asa-5510/m-p/1041058#M914940</guid>
      <dc:creator>vhabilthornc</dc:creator>
      <dc:date>2008-08-08T12:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory issues and ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/active-directory-issues-and-asa-5510/m-p/1041059#M914942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There was a duplicate arp entry on the server.I deleted it and am awaiting the results. Thanks again for the info.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chuck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Aug 2008 19:19:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/active-directory-issues-and-asa-5510/m-p/1041059#M914942</guid>
      <dc:creator>vhabilthornc</dc:creator>
      <dc:date>2008-08-08T19:19:53Z</dc:date>
    </item>
  </channel>
</rss>

