<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Communication between two DMZ segments in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/communication-between-two-dmz-segments/m-p/818969#M969838</link>
    <description>&lt;P&gt;Hi friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a firewall with inside, outside + 2 DMZ's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to talk to the DMZ's from inside and outside interfaces but inter-MZ communication or communication between two DMZ's is not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have all the static translations and routing in place but still it doesn't work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also enabled same security traffic permit inter-interface and intra-interface. Is there any inherent limitation in ASA 5540 for this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;Gautam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:08:22 GMT</pubDate>
    <dc:creator>gautamzone</dc:creator>
    <dc:date>2019-03-11T11:08:22Z</dc:date>
    <item>
      <title>Communication between two DMZ segments</title>
      <link>https://community.cisco.com/t5/network-security/communication-between-two-dmz-segments/m-p/818969#M969838</link>
      <description>&lt;P&gt;Hi friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a firewall with inside, outside + 2 DMZ's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to talk to the DMZ's from inside and outside interfaces but inter-MZ communication or communication between two DMZ's is not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have all the static translations and routing in place but still it doesn't work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also enabled same security traffic permit inter-interface and intra-interface. Is there any inherent limitation in ASA 5540 for this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;Gautam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:08:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/communication-between-two-dmz-segments/m-p/818969#M969838</guid>
      <dc:creator>gautamzone</dc:creator>
      <dc:date>2019-03-11T11:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Communication between two DMZ segments</title>
      <link>https://community.cisco.com/t5/network-security/communication-between-two-dmz-segments/m-p/818970#M969839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just wanted to add that Syslog reports the following message for communication between two DMZ's:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-6-110001: No route to 10.0.3.10 from 10.1.20.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2007 21:21:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/communication-between-two-dmz-segments/m-p/818970#M969839</guid>
      <dc:creator>gautamzone</dc:creator>
      <dc:date>2007-09-07T21:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: Communication between two DMZ segments</title>
      <link>https://community.cisco.com/t5/network-security/communication-between-two-dmz-segments/m-p/818971#M969840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please post the relevant parts of the config?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2007 21:38:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/communication-between-two-dmz-segments/m-p/818971#M969840</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-09-07T21:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: Communication between two DMZ segments</title>
      <link>https://community.cisco.com/t5/network-security/communication-between-two-dmz-segments/m-p/818972#M969841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure, the configs are as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no nat-control&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0&lt;/P&gt;&lt;P&gt; nameif SA&lt;/P&gt;&lt;P&gt; security-level 30&lt;/P&gt;&lt;P&gt; ip address 10.0.3.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/2&lt;/P&gt;&lt;P&gt; nameif WAN&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.0.4.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (WAN,SA) 10.1.20.0 10.1.20.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list SA extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list WAN extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list WAN extended permit icmp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group SA in interface SA&lt;/P&gt;&lt;P&gt;access-group WAN in interface WAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Output of show route WAN on ASA&lt;/P&gt;&lt;P&gt;--------------------------------&lt;/P&gt;&lt;P&gt;O IA 10.1.20.0 255.255.255.0 [110/11123] via 10.0.4.3, 0:47:31, WAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Output of show route SA on ASA&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;C    10.0.3.0 255.255.255.0 is directly connected, SA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Output of show run router&lt;/P&gt;&lt;P&gt;-------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router ospf 100&lt;/P&gt;&lt;P&gt; network 10.0.3.0 255.255.255.0 area 20&lt;/P&gt;&lt;P&gt; network 10.0.4.0 255.255.255.0 area 20&lt;/P&gt;&lt;P&gt; network 10.0.5.0 255.255.255.0 area 20&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;The routers 10.0.4.3 and 10.1.20.1 have OSPF advertised routes for 10.0.3.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: An interesting thing is that when i turn on capture for packets from 10.1.20.2 towards 10.0.3.10, i am seeing echo requests being sent thru but no echo replies from 10.0.3.10!!!. Also, if i ping the other way (10.0.3.10--&amp;gt;10.1.20.2), i am seeing echo requests being sent and echo replies being received too but firewall seems to drop them!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2007 22:21:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/communication-between-two-dmz-segments/m-p/818972#M969841</guid>
      <dc:creator>gautamzone</dc:creator>
      <dc:date>2007-09-07T22:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Communication between two DMZ segments</title>
      <link>https://community.cisco.com/t5/network-security/communication-between-two-dmz-segments/m-p/818973#M969842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you use "nat-control" or "no nat-control"?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Sep 2007 07:18:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/communication-between-two-dmz-segments/m-p/818973#M969842</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2007-09-08T07:18:55Z</dc:date>
    </item>
    <item>
      <title>Re: Communication between two DMZ segments</title>
      <link>https://community.cisco.com/t5/network-security/communication-between-two-dmz-segments/m-p/818974#M969843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I use no nat-control now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Sep 2007 18:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/communication-between-two-dmz-segments/m-p/818974#M969843</guid>
      <dc:creator>gautamzone</dc:creator>
      <dc:date>2007-09-08T18:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Communication between two DMZ segments</title>
      <link>https://community.cisco.com/t5/network-security/communication-between-two-dmz-segments/m-p/818975#M969844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you needn't have static.&lt;/P&gt;&lt;P&gt;But another static entry in you config can break communication between two interfaces with the same security level. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Sep 2007 11:29:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/communication-between-two-dmz-segments/m-p/818975#M969844</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2007-09-09T11:29:19Z</dc:date>
    </item>
  </channel>
</rss>

