<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DMZ access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dmz-access/m-p/973741#M918305</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot, i will implement the config as you said n try to ping from outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Jun 2008 09:19:55 GMT</pubDate>
    <dc:creator>dinesh.das</dc:creator>
    <dc:date>2008-06-17T09:19:55Z</dc:date>
    <item>
      <title>DMZ access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-access/m-p/973734#M918278</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not able to access DMZ from outside. Attached the running config of firewall.&lt;/P&gt;&lt;P&gt;I think it might be some routing issue, any suggestions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:00:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-access/m-p/973734#M918278</guid>
      <dc:creator>dinesh.das</dc:creator>
      <dc:date>2019-03-11T13:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-access/m-p/973735#M918280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Some questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Did you try to ping from outside your host in DMZ?&lt;/P&gt;&lt;P&gt;- When you try to access to host in DMZ do you see log messages on firewall?&lt;/P&gt;&lt;P&gt;- Did you set up the defaul gateway on host in DMZ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;Massimiliano.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 08:34:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-access/m-p/973735#M918280</guid>
      <dc:creator>massimiliano.serafino</dc:creator>
      <dc:date>2008-06-17T08:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-access/m-p/973736#M918284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. i am not able to ping from out side to DMZ nat ip.&lt;/P&gt;&lt;P&gt;2. no&lt;/P&gt;&lt;P&gt;3. Yes &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 08:49:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-access/m-p/973736#M918284</guid>
      <dc:creator>dinesh.das</dc:creator>
      <dc:date>2008-06-17T08:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-access/m-p/973737#M918288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;- From outside did you ping the ip address of the firewall's interface outside?&lt;/P&gt;&lt;P&gt;- From host in DMZ did you have access to hosts in Internet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 08:58:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-access/m-p/973737#M918288</guid>
      <dc:creator>massimiliano.serafino</dc:creator>
      <dc:date>2008-06-17T08:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-access/m-p/973738#M918295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First of all your access-list is wrong:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ1_access_in extended permit ip host 1.1.27.113 any&lt;/P&gt;&lt;P&gt;access-list DMZ1_access_in extended permit icmp host 1.1.27.113 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 1.1.27.113 will never be seen on the DMZ side, it will only see the pre-nat local IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly one of your static's is incorrect:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 1.1.27.101 192.168.5.101 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should be 192.168.1.101  OR &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ1,outside) 1.1.27.101 192.168.5.101 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thirdly, why have you put two default routes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 09:06:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-access/m-p/973738#M918295</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-17T09:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-access/m-p/973739#M918300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;all global ip are responding from out side, except DMZ NAT IP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 09:09:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-access/m-p/973739#M918300</guid>
      <dc:creator>dinesh.das</dc:creator>
      <dc:date>2008-06-17T09:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-access/m-p/973740#M918302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean this IP? 1.1.27..113&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to add this in your DMZ ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ1_access_in extended permit ip host 192.168.5.111 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can make it more secure after doing the initial testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Secondly fix your static as per my last post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 09:16:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-access/m-p/973740#M918302</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-17T09:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-access/m-p/973741#M918305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot, i will implement the config as you said n try to ping from outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 09:19:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-access/m-p/973741#M918305</guid>
      <dc:creator>dinesh.das</dc:creator>
      <dc:date>2008-06-17T09:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-access/m-p/973742#M918307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Just do some logging and icmp debugging in ASA then post it here.&lt;/P&gt;&lt;P&gt;did u try a telnet to a server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 09:25:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-access/m-p/973742#M918307</guid>
      <dc:creator>nomair_83</dc:creator>
      <dc:date>2008-06-17T09:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-access/m-p/973743#M918308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Omair the issue is with the ACL and the static.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 09:30:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-access/m-p/973743#M918308</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-17T09:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-access/m-p/973744#M918310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Agreed but I hope that he changed the config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jun 2008 09:51:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-access/m-p/973744#M918310</guid>
      <dc:creator>nomair_83</dc:creator>
      <dc:date>2008-06-17T09:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: DMZ access</title>
      <link>https://community.cisco.com/t5/network-security/dmz-access/m-p/973745#M918315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Farrukh, it is working now. I think the only problem was ACL_DMZ and that is what it was not comming out of the FW.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jun 2008 03:16:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dmz-access/m-p/973745#M918315</guid>
      <dc:creator>dinesh.das</dc:creator>
      <dc:date>2008-06-18T03:16:22Z</dc:date>
    </item>
  </channel>
</rss>

