<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Beginner needs help - ASA 5510 Configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896374#M958716</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's backwards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first host or network is always the source, the second is the destination. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the access list is applied into the outside interface, people from the internet will be the source and your mail server is the destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list External_access_in extended permit tcp &lt;SOURCE&gt; &lt;DESTINATION&gt; eq &lt;DESTINATION port=""&gt;&lt;/DESTINATION&gt;&lt;/DESTINATION&gt;&lt;/SOURCE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the statment below&lt;/P&gt;&lt;P&gt;&lt;SOURCE&gt; = any&lt;/SOURCE&gt;&lt;/P&gt;&lt;P&gt;&lt;DESTINATION&gt; = host 64.179.53.30&lt;/DESTINATION&gt;&lt;/P&gt;&lt;P&gt;&lt;DESTINATION port=""&gt; = smtp&lt;/DESTINATION&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list External_access_in extended permit tcp any host 64.179.53.30 eq smtp&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Dec 2007 23:13:47 GMT</pubDate>
    <dc:creator>acomiskey</dc:creator>
    <dc:date>2007-12-14T23:13:47Z</dc:date>
    <item>
      <title>Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896359#M958701</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok...I'm struggling here.  I have always used Watchguard products, and decided to step up and buy my first Cisco.  I'm finding that the configuration is not quite as easy, and would love to get some help.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a very simple setup.  I need to setup my internal interface, external interface, NAT for 2 addresses (OWA and Exchange),No DMZ, no web server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I took a crack at the configuration using ASDM 5.0 and the Startup Wizard and failed. questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)  Does the external ethernet port have to be ethernet port 0?  Right now my internal port is port 0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2)  How are security levels used? How do I need to use them in my setup?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3)  Should I be able to use ASDM for all of my setup?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4)  Do I need to use DHCP on the ASA?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5)  Next steps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;info:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;External IP: 64.179.10.28&lt;/P&gt;&lt;P&gt;Gateway IP: 64.179.10.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internal interface IP: 192.168.0.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SMTP IP: 64.179.10.29 (NAT to 192.168.0.x)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OWA IP:  64.179.10.32 (NAT to 192.168.0.x)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone see what I've done wrong?  Any help would be appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "show running-config"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 7.0(7) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;Hostname test&lt;/P&gt;&lt;P&gt;domain-name test.net&lt;/P&gt;&lt;P&gt;enable password xxx&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; nameif Internal&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.0.x 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; nameif External&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 64.x.x.28 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;access-list Internal_access_in remark WWW&lt;/P&gt;&lt;P&gt;access-list Internal_access_in extended permit tcp host 192.168.0.0 eq www interface External eq www &lt;/P&gt;&lt;P&gt;access-list External_access_in remark SMTP&lt;/P&gt;&lt;P&gt;access-list External_access_in extended permit tcp host 64.179.10.29 eq smtp host 192.168.0.53 eq smtp &lt;/P&gt;&lt;P&gt;access-list External_access_out remark HTTP&lt;/P&gt;&lt;P&gt;access-list External_access_out extended permit tcp 64.179.10.22 255.255.255.240 eq www any eq www &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu Internal 1500&lt;/P&gt;&lt;P&gt;mtu External 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-507.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (External) 10 64.179.10.29-64.179.10.32 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (Internal) 10 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;nat (management) 0 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (External,Internal) 192.168.0.x 64.179.10.29 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (External,Internal) 192.168.0.x 64.179.10.32 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-group Internal_access_in in interface Internal&lt;/P&gt;&lt;P&gt;access-group External_access_in in interface External&lt;/P&gt;&lt;P&gt;access-group External_access_out out interface External&lt;/P&gt;&lt;P&gt;route External 0.0.0.0 0.0.0.0 63.179.53.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00&lt;/P&gt;&lt;P&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.0.x 255.255.255.255 Internal&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.2-192.168.1.254 management&lt;/P&gt;&lt;P&gt;dhcpd lease 3600&lt;/P&gt;&lt;P&gt;dhcpd ping_timeout 50&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns maximum-length 512 &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;  inspect rtsp &lt;/P&gt;&lt;P&gt;  inspect esmtp &lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;  inspect skinny &lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt;  inspect sip &lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:50:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896359#M958701</guid>
      <dc:creator>tsherven1</dc:creator>
      <dc:date>2019-03-13T00:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896360#M958702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. No.&lt;/P&gt;&lt;P&gt;2. More secure interface (inside) will have a higher level than lower security (outside). 100 for inside and 0 for outside is what you want.&lt;/P&gt;&lt;P&gt;3. Yes, but you should learn the cli. &lt;/P&gt;&lt;P&gt;4. No.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (Internal,External) 64.179.10.29 192.168.0.x netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (Internal,External) 64.179.10.32 192.168.0.x netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list External_access_in extended permit tcp any host 64.179.10.29 eq smtp &lt;/P&gt;&lt;P&gt;access-list External_access_in extended permit tcp any host 64.179.10.32 eq www&lt;/P&gt;&lt;P&gt;access-group External_access_in in interface External &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list Internal_access_in remark WWW &lt;/P&gt;&lt;P&gt;no access-list Internal_access_in extended permit tcp host 192.168.0.0 eq www interface External eq www &lt;/P&gt;&lt;P&gt;no access-group Internal_access_in in interface Internal&lt;/P&gt;&lt;P&gt;no access-list External_access_out remark HTTP &lt;/P&gt;&lt;P&gt;no access-list External_access_out extended permit tcp 64.179.10.22 255.255.255.240 eq www any eq www &lt;/P&gt;&lt;P&gt;no access-group External_access_out out interface External &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2007 19:44:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896360#M958702</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-12-13T19:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896361#M958703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how do I make the changes that you listed?  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2007 20:16:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896361#M958703</guid>
      <dc:creator>tsherven1</dc:creator>
      <dc:date>2007-12-13T20:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896362#M958704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Via the ASDM, console, ssh, telnet...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "no" statements are easy via the asdm as they just need to be removed. The others may be trial and error via the asdm til you get it to look right. That's why it's good to learn the cli.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa71/configuration/guide/start.html#wp1039724" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa71/configuration/guide/start.html#wp1039724&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2007 20:23:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896362#M958704</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-12-13T20:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896363#M958705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your help!  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm making progress.  I figured out this section:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (Internal,External) 64.179.10.29 192.168.0.x netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (Internal,External) 64.179.10.32 192.168.0.x netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list External_access_in extended permit tcp any host 64.179.10.29 eq smtp &lt;/P&gt;&lt;P&gt;access-list External_access_in extended permit tcp any host 64.179.10.32 eq www &lt;/P&gt;&lt;P&gt;access-group External_access_in in interface External &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I can't figure out this section:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list Internal_access_in remark WWW &lt;/P&gt;&lt;P&gt;no access-list Internal_access_in extended permit tcp host 192.168.0.0 eq www interface External eq www &lt;/P&gt;&lt;P&gt;no access-group Internal_access_in in interface Internal &lt;/P&gt;&lt;P&gt;no access-list External_access_out remark HTTP &lt;/P&gt;&lt;P&gt;no access-list External_access_out extended permit tcp 64.179.10.22 255.255.255.240 eq www any eq www &lt;/P&gt;&lt;P&gt;no access-group External_access_out out interface External &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I do this through ASDM?  Can you give me a specific example?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2007 22:14:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896363#M958705</guid>
      <dc:creator>tsherven1</dc:creator>
      <dc:date>2007-12-13T22:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896364#M958706</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just select the entries and delete them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2007 23:14:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896364#M958706</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-12-13T23:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896365#M958707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok...I'm going to be really stupid here...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you say "just select the entries and delete them".  Can you give me more detail?  If I'm in ASDM, do I go under Configuration --&amp;gt; Security Policy?  Where in the GUI do I find the items to delete (which screen)?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2007 23:26:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896365#M958707</guid>
      <dc:creator>tsherven1</dc:creator>
      <dc:date>2007-12-13T23:26:23Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896366#M958708</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that's the screen I believe. You should see some under the inside interface and some under the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or go up to Tools -&amp;gt; Command line interface, select multiple lines and copy and paste the following and hit send.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;config t&lt;/P&gt;&lt;P&gt;no access-group Internal_access_in in interface Internal &lt;/P&gt;&lt;P&gt;no access-group External_access_out out interface External &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2007 23:47:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896366#M958708</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-12-13T23:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896367#M958709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can understand most of the commands in the CLI, but can you tell me what this means (or actually does)?  Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;config t &lt;/P&gt;&lt;P&gt;no access-group Internal_access_in in interface Internal &lt;/P&gt;&lt;P&gt;no access-group External_access_out out interface External &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2007 14:04:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896367#M958709</guid>
      <dc:creator>tsherven1</dc:creator>
      <dc:date>2007-12-14T14:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896368#M958710</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have created access lists, Internal_access_in and External_access_out. These are not necessary and if you even did want them, the statements you have defined for them don't make sense and are not correct. Config t allow you to enter the configuration mode of the cli. The access-group command ties the access list to an interface. Since you don't want them, adding "no" before the command will remove it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2007 14:21:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896368#M958710</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-12-14T14:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896369#M958711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no access-group Internal_access_in in interface Internal &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It means that you are taking out all the access-lists named Internal_access_in, which apply from your internal network, going toward to your ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-group External_access_out out interface External &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It means that you are taking out all the access-lists named External_access_out, which apply from the external network (internet), going toward to your ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2007 14:34:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896369#M958711</guid>
      <dc:creator>vvii</dc:creator>
      <dc:date>2007-12-14T14:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896370#M958712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-group External_access_out out interface External &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;would apply to traffic leaving the External interface outbound away from the ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2007 14:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896370#M958712</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-12-14T14:41:18Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896371#M958713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is my configuration...Does this make sense? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "show running-config"&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 7.0(7) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname MCD&lt;/P&gt;&lt;P&gt;domain-name mcd.net&lt;/P&gt;&lt;P&gt;enable password xxx&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; nameif Internal&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.0.x 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; nameif External&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 64.x.x.28 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;access-list Internal_access_in remark WWW&lt;/P&gt;&lt;P&gt;access-list Internal_access_in extended permit tcp host 192.168.0.0 eq www interface External eq www &lt;/P&gt;&lt;P&gt;access-list External_access_in remark SMTP&lt;/P&gt;&lt;P&gt;access-list External_access_in extended permit tcp host 64.179.10.29 eq smtp host 192.168.0.x eq smtp &lt;/P&gt;&lt;P&gt;access-list External_access_out remark HTTP&lt;/P&gt;&lt;P&gt;access-list External_access_out extended permit tcp 64.179.10.32 255.255.255.240 eq www any eq www &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu Internal 1500&lt;/P&gt;&lt;P&gt;mtu External 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-507.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (External) 10 64.179.10.29-64.179.10.32 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;nat (Internal) 10 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;nat (management) 0 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (External,Internal) 192.168.0.x 64.179.10.29 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (External,Internal) 192.168.0.x 64.179.10.32 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-group External_access_in in interface External&lt;/P&gt;&lt;P&gt;route External 0.0.0.0 0.0.0.0 63.179.10.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00&lt;/P&gt;&lt;P&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.0.x 255.255.255.255 Internal&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.2-192.168.1.254 management&lt;/P&gt;&lt;P&gt;dhcpd lease 3600&lt;/P&gt;&lt;P&gt;dhcpd ping_timeout 50&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns maximum-length 512 &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;  inspect rtsp &lt;/P&gt;&lt;P&gt;  inspect esmtp &lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;  inspect skinny &lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt;  inspect sip &lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2007 21:52:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896371#M958713</guid>
      <dc:creator>tsherven1</dc:creator>
      <dc:date>2007-12-14T21:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896372#M958714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list External_access_in extended permit tcp host 64.179.10.29 eq smtp host 192.168.0.x eq smtp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;should be...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list External_access_in extended permit tcp any host 64.179.10.29 eq smtp&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2007 22:00:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896372#M958714</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-12-14T22:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896373#M958715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this the same thing, or is it backwards?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list External_access_in extended permit tcp host 64.179.53.39 eq smtp any&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2007 22:20:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896373#M958715</guid>
      <dc:creator>tsherven1</dc:creator>
      <dc:date>2007-12-14T22:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner needs help - ASA 5510 Configuration</title>
      <link>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896374#M958716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's backwards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first host or network is always the source, the second is the destination. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the access list is applied into the outside interface, people from the internet will be the source and your mail server is the destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list External_access_in extended permit tcp &lt;SOURCE&gt; &lt;DESTINATION&gt; eq &lt;DESTINATION port=""&gt;&lt;/DESTINATION&gt;&lt;/DESTINATION&gt;&lt;/SOURCE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the statment below&lt;/P&gt;&lt;P&gt;&lt;SOURCE&gt; = any&lt;/SOURCE&gt;&lt;/P&gt;&lt;P&gt;&lt;DESTINATION&gt; = host 64.179.53.30&lt;/DESTINATION&gt;&lt;/P&gt;&lt;P&gt;&lt;DESTINATION port=""&gt; = smtp&lt;/DESTINATION&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list External_access_in extended permit tcp any host 64.179.53.30 eq smtp&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2007 23:13:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-needs-help-asa-5510-configuration/m-p/896374#M958716</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-12-14T23:13:47Z</dc:date>
    </item>
  </channel>
</rss>

