<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5520 configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856698#M954950</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you provide more details on the interfaces configuration, are they trusted inside interfaces? 1st thing comes to mind is if  the interfaces are configured with same security level and are to be trusted meaning you do not want acls between them, if this is the case try adding this statement. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;same-security-traffic permit inter-interface&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 17 Feb 2008 00:26:44 GMT</pubDate>
    <dc:creator>JORGE RODRIGUEZ</dc:creator>
    <dc:date>2008-02-17T00:26:44Z</dc:date>
    <item>
      <title>ASA 5520 configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856697#M954949</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We just bought an ASA 5520 firewall. We configured two interfaces in different subnets. Because the 5520 is a router it must be possible two ping interfaces in different subnets. I cannot get it to work in our ASA 5520. Anybody knows how to configure this? &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:03:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856697#M954949</guid>
      <dc:creator>ict</dc:creator>
      <dc:date>2019-03-11T12:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856698#M954950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you provide more details on the interfaces configuration, are they trusted inside interfaces? 1st thing comes to mind is if  the interfaces are configured with same security level and are to be trusted meaning you do not want acls between them, if this is the case try adding this statement. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;same-security-traffic permit inter-interface&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Feb 2008 00:26:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856698#M954950</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-02-17T00:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856699#M954951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the ASA5520 is *not* a router.  And it is *not* possible to ping an ASA interface other than the one which is closest to you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Feb 2008 12:47:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856699#M954951</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2008-02-17T12:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856700#M954952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steven, I disagree with you on " it is *not* possible to ping an ASA interface other than the one which is closest to you".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps I am missunderstanding it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For instance, you may have two same security level interaces under two difference subnets and be able to ping accross each other including their respective physical interfaces in the case of implementing same-security-traffic permit inter-interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s1_72.html#wp1289167" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/s1_72.html#wp1289167&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 17 Feb 2008 18:20:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856700#M954952</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-02-17T18:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856701#M954953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much for your input. I have configured the ASA with two interfaces. I have set the interfaces within the same trusted level (100). And I checked the radiobutton that the firewall can accept traffic through interfaces that have the same security level. The configuration of the interfaces is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface 1:&lt;/P&gt;&lt;P&gt;IP:   192.168.1.1&lt;/P&gt;&lt;P&gt;Mask: 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface 2:&lt;/P&gt;&lt;P&gt;IP:   172.16.1.1&lt;/P&gt;&lt;P&gt;Mask: 255.255.240.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my test environment. I only configured the interfaces, not rules or anything like that. A ping command within the same subnet is possible but from one interface to the other is not possible. I want to create a DMZ with the ASA as frontend firewall and an ISA server as backend firewall. This means that the interfaces must communicate in order to send traffic from the internet to DMZ to LAN and the other way around.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2008 10:26:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856701#M954953</guid>
      <dc:creator>ict</dc:creator>
      <dc:date>2008-02-18T10:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856702#M954954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Lets put aside for a minute pinging interfaces accross, do you have vlans for each of these networks configured on your inside switch? can a host from 192.168.1.x net  freely  ping another host on 172.16.1.x network and vice versa?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2008 19:41:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856702#M954954</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-02-18T19:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856703#M954955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't configured vlans. Is that a requirement to ping from one interface to the other? At the moment it is not possible to ping from one host in 192.168.1.x to a host on 172.16.1.x and vice versa. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2008 13:17:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856703#M954955</guid>
      <dc:creator>ict</dc:creator>
      <dc:date>2008-02-19T13:17:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856704#M954956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you need to separate the networks with respective VLANS.. where does your ASA interfaces currently connects to in respect to your inside interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA_firewall&lt;/P&gt;&lt;P&gt;Interface ethernet2-or-gigabit&lt;/P&gt;&lt;P&gt;nameif VLAN2&lt;/P&gt;&lt;P&gt;security-level 0  &lt;/P&gt;&lt;P&gt;ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface ethernet3-or-gigabit&lt;/P&gt;&lt;P&gt;nameif VLAN3&lt;/P&gt;&lt;P&gt;security-level 0 &lt;/P&gt;&lt;P&gt;ip address 172.16.1.1 255.255.240.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface &lt;/P&gt;&lt;P&gt;global (outside) 1 interface &lt;/P&gt;&lt;P&gt;nat(VLAN2) 1 192.168.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;nat(VLAN3) 1 172.16.1. 255.255.255.240&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;e.g on switch similar config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch: &lt;/P&gt;&lt;P&gt;vlan database &lt;/P&gt;&lt;P&gt;vtp transparent &lt;/P&gt;&lt;P&gt;vtp domain test_lab &lt;/P&gt;&lt;P&gt;vtp password cisco &lt;/P&gt;&lt;P&gt;vlan 2 name net_192.168.1.0/24 &lt;/P&gt;&lt;P&gt;vlan 3 name net_172.16.1.0/28 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface fastethernet0/1&lt;/P&gt;&lt;P&gt;Description ASA_Ethernet2_Connection&lt;/P&gt;&lt;P&gt;switchport access vlan 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface fastethernet0/2&lt;/P&gt;&lt;P&gt;Description ASA_Ethernet3_Connection&lt;/P&gt;&lt;P&gt;switchport access vlan 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface fastethernet0/4&lt;/P&gt;&lt;P&gt;Description HOST_192.168.1.100&lt;/P&gt;&lt;P&gt;switchport access vlan 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface fastethernet0/5&lt;/P&gt;&lt;P&gt;Description HOST_172.16.1.10&lt;/P&gt;&lt;P&gt;switchport access vlan 3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with this simple config you should be able to ping/reach hosts without acls, if you cannot please look at asa logs to see what the problem could be, post results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2008 04:12:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856704#M954956</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-02-20T04:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856705#M954957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much. I will try this configuration. I will let you know if this configuration has worked for me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2008 13:43:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856705#M954957</guid>
      <dc:creator>ict</dc:creator>
      <dc:date>2008-02-20T13:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856706#M954958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, have your test being successfull let me know what the update is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2008 17:18:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856706#M954958</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-02-21T17:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856707#M954959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Me and my colleague are gonna start monday with the initial installation. I will let you know somewhere next week if the configuration has worked. Thank you very much!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Martijn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2008 15:03:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856707#M954959</guid>
      <dc:creator>ict</dc:creator>
      <dc:date>2008-02-22T15:03:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856708#M954961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Martijn,  not problem  we are  here to help you in this issue , I'll keep my eyes opened. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2008 23:45:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-configuration/m-p/856708#M954961</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-02-22T23:45:17Z</dc:date>
    </item>
  </channel>
</rss>

