<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help Require - Security Context issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/help-require-security-context-issues/m-p/933960#M938640</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the information Jorge.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i removed global commands and do static NAT on both the contexts for internal subnets, the ICMP between both the contexts started.and i have to extended my NAT translation on ISP routers. i.e,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Admin Context:static (inside,outside) 10.126.1.0 10.126.1.0 netmask 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Admin context are having all our servers like Active directory, File server, Internal DNS, Mail, etc... so it is a requirement to access of admin context from the CustA context. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The objective behind implementing contexts is to segregate one Inside VLAN traffic from other network VLANs. However we want to access  admin contexts from other contexts so that we can have the access of all the servers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 27 Apr 2008 11:23:13 GMT</pubDate>
    <dc:creator>jszinzuwadia</dc:creator>
    <dc:date>2008-04-27T11:23:13Z</dc:date>
    <item>
      <title>Help Require - Security Context issues</title>
      <link>https://community.cisco.com/t5/network-security/help-require-security-context-issues/m-p/933958#M938635</link>
      <description>&lt;P&gt;Hi Techies,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been assigned project for setting up the security contexts on PIX firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see the below tech details:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created two contexts i.e. Admin &amp;amp; CustA. I have decided to share the Outside interface between two contexts. I have enabled 'mac-address auto' on PIX firewall to avoid conflicting between ARP requests.Also both the physical ports on L2 switches are configured into Trunk mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sh run for Admin Context:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface inside&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.126.1.17 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface outside&lt;/P&gt;&lt;P&gt;nameif outside&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 10.10.10.200 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.126.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 10.10.10.2 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sh run for CustA Context:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nterface E_inside&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.126.6.250 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface E_outside&lt;/P&gt;&lt;P&gt;nameif outside&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 10.10.10.201 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.126.6.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 10.10.10.2 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problems:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to ping 10.126.1.X network from CustA context. However, not able to ping 10.126.6.X network from Admin Context.&lt;/P&gt;&lt;P&gt;I am able to surf the Internet from Admin Context i.e. from 10.126.1.X network. However, the DNS server resides on 10.126.1.X network and hence not able to resolve DNS requests from CustA context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could someone please help me to resolve the above mentioned problem? Let me know if anybody requires any additional information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JBP&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:37:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-require-security-context-issues/m-p/933958#M938635</guid>
      <dc:creator>jszinzuwadia</dc:creator>
      <dc:date>2019-03-11T12:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: Help Require - Security Context issues</title>
      <link>https://community.cisco.com/t5/network-security/help-require-security-context-issues/m-p/933959#M938638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think your problem relies on how you are implementing or allowing icmp in each context, can you go over these two links, I beieve once you read it will help in solving some of your icmp issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa icmp functionality&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#req" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#req&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;inspect icmp&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/i2_72.html#wp1665749" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/i2_72.html#wp1665749&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the dns part there could be couple of things that may be in the way, first of all can you from CustA context ping by ip a public IP address to deternmined if you have outbound connectivity, try pinging &lt;A class="jive-link-custom" href="http://www.yahoo.com" target="_blank"&gt;www.yahoo.com&lt;/A&gt; by ip 69.147.114.210,if you get replies we know there is connectivity.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you have the DNS server on admin context inside LAN I would assumed that you will need to NAT the DNS server and permit DNS port because you are comming from CustA context to Admin context for DNS queries but while the forum here tries to help here in your dns issue you could use in the meantime public DNS servers for CustA context. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Apr 2008 20:20:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-require-security-context-issues/m-p/933959#M938638</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-04-26T20:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: Help Require - Security Context issues</title>
      <link>https://community.cisco.com/t5/network-security/help-require-security-context-issues/m-p/933960#M938640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the information Jorge.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i removed global commands and do static NAT on both the contexts for internal subnets, the ICMP between both the contexts started.and i have to extended my NAT translation on ISP routers. i.e,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Admin Context:static (inside,outside) 10.126.1.0 10.126.1.0 netmask 255.255.255.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Admin context are having all our servers like Active directory, File server, Internal DNS, Mail, etc... so it is a requirement to access of admin context from the CustA context. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The objective behind implementing contexts is to segregate one Inside VLAN traffic from other network VLANs. However we want to access  admin contexts from other contexts so that we can have the access of all the servers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Apr 2008 11:23:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/help-require-security-context-issues/m-p/933960#M938640</guid>
      <dc:creator>jszinzuwadia</dc:creator>
      <dc:date>2008-04-27T11:23:13Z</dc:date>
    </item>
  </channel>
</rss>

