04-28-2016 01:40 AM - edited 03-12-2019 12:40 AM
Here is my Putty log:
ASA Version 9.2
!
!
<--- More --->
<--- More ---> security-level 100
<--- More --->
<--- More
<--- More ---> interface GigabitEthernet0/4
<--- More --->
<--- More ---> security-level 80
<--- More --->
<--- More
<--- More ---> interface GigabitEthernet0/5
<--- More ---> shutdown
<--- More ---> no
<--- More ---> no security-level
<--- More ---> no
<--- More
<--- More ---> interface Management0/0
<--- More ---> management-only
<--- More --->
<--- More ---> security-level 100
<--- More --->
<--- More --->
<--- More ---> object network CC-Camera-subnet
<--- More ---> subnet 10.10.20.0 255.255.255.0
<--- More ---> object network Computer-Lab
<--- More ---> subnet 10.10.21.0 255.255.255.0
<--- More ---> object network Private-LAN
<--- More ---> subnet 10.10.22.0 255.255.255.0
<--- More ---> object network Wireless
<--- More ---> subnet 10.10.23.0 255.255.255.0
<--- More ---> access-list CC-Camera_access_in extended permit
<--- More ---> access-list CC-Camera_access_in extended permit
<--- More ---> access-list Public-IP_access_in extended permit
<--- More ---> pager lines 24
<--- More ---> logging asdm informational
<--- More --->
<--- More --->
<--- More --->
<--- More --->
<--- More --->
<--- More --->
<--- More ---> no failover
<--- More ---> icmp unreachable rate-limit 1 burst-size 1
<--- More --->
<--- More ---> no asdm history enable
<--- More --->
<--- More ---> no
<--- More
<--- More ---> object network CC-Camera-subnet
<--- More --->
<--- More ---> object network Computer-Lab
<--- More --->
<--- More ---> object network Private-LAN
<--- More --->
<--- More ---> object network Wireless
<--- More --->
<--- More ---> access-group Public-IP_access_in in interface Public-IP
<--- More ---> access-group CC-Camera_access_in in interface CC-Camera
<--- More ---> route Public-IP 0.0.0.0 0.0.0.0 202.79.23.1 1
<--- More ---> timeout xlate 3:00:00
<--- More ---> timeout pat-
<--- More ---> timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
<--- More ---> timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
<--- More ---> timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
<--- More ---> timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
<--- More ---> timeout
<--- More ---> timeout floating-conn 0:00:00
<--- More ---> dynamic-access-policy-record DfltAccessPolicy
<--- More ---> user-identity default-domain LOCAL
<--- More ---> http server
<--- More ---> http 192.168.1.0 255.255.255.0 management
<--- More ---> no snmp-server location
<--- More ---> no snmp-server contact
<--- More ---> crypto ipsec security-association
<--- More ---> crypto
<--- More --->
<--- More ---> no ssh
<--- More ---> ssh timeout 5
<--- More ---> ssh key-exchange group
<--- More ---> console timeout 0
<--- More --->
<--- More --->
<--- More
<--- More ---> threat-detection basic-threat
<--- More ---> threat-detection statistics access-list
<--- More ---> no threat-detection statistics
<--- More ---> ssl encryption rc4-sha1 aes128-sha1 aes256-sha1 3des-sha1
<--- More
<--- More ---> class-map inspection_default
<--- More ---> match default-inspection-traffic
<--- More
<--- More
<--- More ---> policy-map type inspect
<--- More ---> parameters
<--- More ---> message-length maximum client auto
<--- More ---> message-length maximum 512
<--- More ---> policy-map global_policy
<--- More ---> class inspection_default
<--- More ---> inspect
<--- More ---> inspect
<--- More ---> inspect h323 h225
<--- More ---> inspect h323 ras
<--- More ---> inspect
<--- More ---> inspect
<--- More ---> inspect
<--- More ---> inspect sqlnet
<--- More ---> inspect skinny
<--- More ---> inspect
<--- More ---> inspect
<--- More ---> inspect sip
<--- More ---> inspect
<--- More ---> inspect
<--- More ---> inspect
<--- More
<--- More ---> service-policy global_policy global
<--- More ---> prompt hostname context
<--- More ---> no call-home reporting anonymous
<--- More ---> Cryptochecksum:577fdb160dccc7796f9a682bda7dbeef
<--- More ---
Here
NAT is not working
I tried to make the port 0/0 to communicate with 0/1 using two way policy and that didn't work either
I am using the ASDM to configure it. Since it is my first time with ASA so
My client wants Facebook,
04-28-2016 03:33 AM
1. NAT from where to where is not working?
2. What exactly do you want to communicate between these two interfaces? Which IP addresses?
3. Do you have Firepower in this ASA? That is the best way. Failing that check out this article:
https://www.fir3net.com/Firewalls/Cisco/cisco-asa-domain-fqdn-based-acls.html
04-28-2016 03:50 AM
Hi Philip,
I mean NAT from my private IP to public IP
Since the NAT didn't work so
When
Thank you.
04-28-2016 03:52 AM
Start by changing the security level of CC camera from 0 to anything else, like 10. Then reboot. Then see how many problems resolve themself. Let me know what is left that is broken.
04-28-2016 04:01 AM
Actually,
How do you communicate two
What we did at
Philip is my
Thank you.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide