asa5512 V8.6 nat web server cannot access

Hi all

asa5512 V8.6 nat web server cannot access.

my home pc can access www.cisco.com, but external client cannot access my web server inside...

all of my config, I do not know what is wrong.

Thank youe help.

ciscoasa #.

See the ciscoasa # running

ciscoasa # show running-config

: Saved

:

ASA 1.0000 Version 2

!

ciscoasa hostname

activate 2KFQnbNIdI.2KYOU encrypted password

2KFQnbNIdI.2KYOU encrypted passwd

names of

!

interface GigabitEthernet0/0

nameif outside

security-level 0

address IP XXX1 255.255.255.240

!

interface GigabitEthernet0/1

Shutdown

No nameif

no level of security

no ip address

!

interface GigabitEthernet0/2

Shutdown

No nameif

no level of security

no ip address

!

interface GigabitEthernet0/3

Description link to 3560 G0/1

Speed 1000

full duplex

nameif inside

security-level 100

192.168.1.13 IP address 255.255.255.0

!

interface GigabitEthernet0/4

Shutdown

No nameif

no level of security

no ip address

!

interface GigabitEthernet0/5

Shutdown

No nameif

no level of security

no ip address

!

interface Management0/0

nameif management

security-level 100

IP 192.168.100.1 address 255.255.255.0

!

!

time-range k3used

absolute starting 08:00 January 1, 2008

daily periodical 0:00 to 23:59

periodical daily 09:00-18:00

!

passive FTP mode

clock timezone BeiJing 8

network object obj - 192.168.1.0

subnet 192.168.1.0 255.255.255.0

network object obj - 192.168.200.0

192.168.200.0 subnet 255.255.255.0

network object obj - 192.168.1.2

host 192.168.1.2

network object obj - 192.168.1.2 - 01

host 192.168.1.2

network object obj - 192.168.1.19

Home 192.168.1.19

network object obj - 192.168.1.20

host 192.168.1.20

network object obj - 192.168.1.88

Home 192.168.1.88

network object obj - 192.168.1.1

host 192.168.1.1

network object obj - 192.168.1.2 - 02

host 192.168.1.2

network object obj - 192.168.1.6

host 192.168.1.6

object obj - X.X.X.3 network

Home X.X.X.3

object obj-tcp-source-eq-25 service

tcp source eq smtp service

obj-tcp-source-eq-110 service object

tcp source eq Microsoft pop3 service

object obj - X.X.X.10 network

Home X.X.X.10

obj-tcp-source-eq-8086 service object

tcp source eq 8086 service

obj-tcp-source-eq-80 service object

tcp source eq www service

network object obj - 192.168.1.1 - 01

host 192.168.1.1

obj-tcp-source-eq-3389 service object

source eq 3389 tcp service

obj-tcp-source-eq-9877 service object

tcp source eq 9877 service

obj-tcp-source-eq-21 service object

tcp source eq ftp service

object obj-tcp-source-eq-20 service

tcp source eq ftp service - data

network object obj - 192.168.2.88

Home 192.168.2.88

network object obj - 192.168.2.88 - 01

Home 192.168.2.88

network object obj - 192.168.2.88 - 02

Home 192.168.2.88

network object obj - 192.168.1.19 - 01

Home 192.168.1.19

network object obj - 192.168.2.2

host 192.168.2.2

network object obj - 192.168.2.2 - 01

host 192.168.2.2

network object obj - 192.168.2.2 - 02

host 192.168.2.2

network object obj - 192.168.3.2

host 192.168.3.2

network object obj - 192.168.3.2 - 01

host 192.168.3.2

network object obj - 192.168.3.2 - 02

host 192.168.3.2

object obj - X.X.X.9 network

Home X.X.X.9

obj-tcp-source-eq-8087 service object

tcp source eq 8087 service

network object obj - 192.168.1.200

host 192.168.1.200

network object obj - 192.168.1.200 - 01

host 192.168.1.200

network object obj - 192.168.1.30

host 192.168.1.30

network object obj - 192.168.1.30 - 01

host 192.168.1.30

network object obj - 192.168.1.1 - 02

host 192.168.1.1

object obj - X.X.X.6 network

Home X.X.X.6

obj-tcp-source-eq-8088 service object

tcp source eq 8088 service

network object obj - 192.168.3.5

Home 192.168.3.5

network object obj - 192.168.3.5 - 01

Home 192.168.3.5

network object obj - 192.168.3.5 - 02

Home 192.168.3.5

network object obj - 192.168.3.5 - 03

Home 192.168.3.5

network object obj - 192.168.3.5 - 04

Home 192.168.3.5

network object obj - 192.168.2.0

Subnet 192.168.2.0 255.255.255.0

network object obj - 192.168.3.0

subnet 192.168.3.0 255.255.255.0

network object obj - 192.168.4.0

subnet 192.168.4.0 255.255.255.0

network object obj - 192.168.5.0

192.168.5.0 subnet 255.255.255.0

network object obj - 192.168.6.0

192.168.6.0 subnet 255.255.255.0

network object obj - 192.168.7.0

192.168.7.0 subnet 255.255.255.0

network object obj - 192.168.8.0

192.168.8.0 subnet 255.255.255.0

vpn_list to access ip 192.168.1.0 scope list allow 255.255.255.0 192.168.200.0 255.255.255.0

vpn_list to access extended list ip 192.168.200.0 allow 255.255.255.0 192.168.1.0 255.255.255.0

access-list 101 extended deny ip any host 58.215.78.113

access-list 101 extended deny ip any host 61.139.126.81

access-list 101 extended deny ip any host 61.152.94.154

access-list 101 extended allow host ip 192.168.4.2 all

access-list 101 extended allow host ip 192.168.4.3 all

access-list 101 extended allow host ip 192.168.4.4 all

access-list 101 extended allow host ip 192.168.4.5 all

access-list 101 extended allow host ip 192.168.4.7 everything

access-list 101 extended permit ip host 192.168.4.8 all

access-list 101 extended permit ip host 192.168.4.9 all

access-list 101 extended permit ip host 192.168.4.10 all

access-list 101 extended allow host ip 192.168.4.11 all

access-list 101 extended allow host ip 192.168.4.12 all

access-list 101 extended allow host ip 192.168.4.13 all

access-list 101 extended allow host ip 192.168.4.14 all

access-list 101 extended allow host ip 192.168.4.15 all

access-list 101 extended allow host ip 192.168.4.16 all

access-list 101 extended allow host 192.168.4.18 ip everything

access-list 101 extended allow host ip 192.168.4.19 all

access-list 101 extended allow host ip 192.168.4.20 all

access-list 101 extended allow host ip 192.168.4.180 all

access-list 101 extended deny ip 192.168.4.0 255.255.255.0 any

access-list 101 extended allow host ip 192.168.2.176 all

access-list 101 extended allow icmp a whole

access-list 101 extended allow host ip 192.168.2.3 everything

access-list 101 extended allow host ip 192.168.2.164 all

access-list 101 extended allow host ip 192.168.2.171 all

access-list 101 extended allow host ip 192.168.2.142 all

access-list 101 extended allow host ip 192.168.2.180 all

access-list 101 extended allow host ip 192.168.2.149 all

access-list 101 extended allow host ip 192.168.2.201 all

access-list 101 extended allow host ip 192.168.2.170 all

access-list 101 extended allow host ip 192.168.2.168 all

access-list 101 extended allow host ip 192.168.2.103 everything

access-list 101 extended allow host ip 192.168.2.34 all

access-list 101 extended allow host ip 192.168.2.174 all

access-list 101 extended allow host ip 192.168.2.199 all

access-list 101 extended allow host ip 192.168.2.253 everything

access-list 101 extended allow host ip 192.168.2.236 all

access-list 101 extended allow host ip 192.168.2.214 all

access-list 101 extended allow host ip 192.168.2.110 everything

access-list 101 extended allow host ip 192.168.2.127 all

access-list 101 extended allow host ip 192.168.2.178 all

access-list 101 extended allow host ip 192.168.2.21 all

access-list 101 extended allow host ip 192.168.2.24 all

access-list 101 extended allow host ip 192.168.2.251 all

access-list 101 extended allow host ip 192.168.2.33 all

access-list 101 extended allow host ip 192.168.2.120 all

access-list 101 extended allow host ip 192.168.2.85 all

access-list 101 extended allow host ip 192.168.2.137 all

access-list 101 extended allow host ip 192.168.2.113 all

access-list 101 extended allow ip 192.168.2.20 host everything

access-list 101 extended allow host ip 192.168.2.101 everything

access-list 101 extended allow host ip 192.168.2.106 all

access-list 101 extended allow host ip 192.168.2.140 all

access-list 101 extended allow host ip 192.168.2.215 all

access-list 101 extended allow host ip 192.168.2.107 all

access-list 101 extended allow host ip 192.168.2.234 all

access-list 101 extended allow host ip 192.168.2.15 all

access-list 101 extended allow host ip 192.168.2.55 all

access-list 101 extended allow host ip 192.168.2.41 all

access-list 101 extended permit ip host 192.168.2.13 all

access-list 101 extended allow host ip 192.168.2.133 everything

access-list 101 extended allow host ip 192.168.2.73 all

access-list 101 extended allow host ip 192.168.2.172 all

access-list 101 extended allow host ip 192.168.2.175 all

access-list 101 extended allow host ip 192.168.2.88 all

access-list 101 extended allow host ip 192.168.2.188 all

access-list 101 extended allow host ip 192.168.2.136 all

access-list 101 extended allow host ip 192.168.2.74 all

access-list 101 extended allow host ip 192.168.2.12 everything

access-list 101 extended allow host ip 192.168.2.100 everything

access-list 101 extended allow host ip of 192.168.2.102 everything

access-list 101 extended allow host ip 192.168.2.152 all

access-list 101 extended allow ip 192.168.2.4 host everything

access-list 101 extended allow host ip 192.168.2.5 everything

access-list 101 extended allow host ip 192.168.2.6 everything

access-list 101 extended allow host ip 192.168.2.14 all

access-list 101 extended allow host ip 192.168.2.19 all

access-list 101 extended permit ip host 192.168.2.16 all

access-list 101 extended allow host ip 192.168.2.17 all

access-list 101 extended allow host ip 192.168.2.18 all

access-list 101 extended allow host ip 192.168.2.22 all

access-list 101 extended allow host ip 192.168.2.23 all

access-list 101 extended allow host ip 192.168.2.115 all

access-list 101 extended allow host ip 192.168.2.116 all

access-list 101 extended allow host ip 192.168.2.117 all

access-list 101 extended allow host ip 192.168.2.118 all

access-list 101 extended allow host ip 192.168.2.119 all

access-list 101 extended allow host ip 192.168.2.150 all

access-list 101 extended allow host ip 192.168.2.128 all

access-list 101 extended deny ip 192.168.2.0 255.255.255.0 any

access-list 101 extended allow ip 192.168.3.2 host everything

access-list 101 extended allow host ip 192.168.3.3 everything

access-list 101 extended permit ip host 192.168.3.4 everything

access-list 101 extended allow host ip 192.168.3.5 all

access-list 101 extended allow host ip 192.168.3.6 all

access-list 101 extended allow host ip 192.168.3.7 all

access-list 101 extended allow host ip 192.168.3.8 all

access-list 101 extended allow host ip 192.168.3.9 all

access-list 101 extended allow host ip 192.168.3.10 everything

access-list 101 extended allow host ip 192.168.3.11 all

access-list 101 extended allow host ip 192.168.3.12 all

access-list 101 extended allow host ip 192.168.3.13 all

access-list 101 extended allow host ip 192.168.3.14 all

access-list 101 extended allow host ip 192.168.3.15 everything

access-list 101 extended allow host ip 192.168.3.16 all

access-list 101 extended allow host ip 192.168.3.17 everything

access-list 101 extended allow host ip 192.168.3.18 all

access-list 101 extended allow host ip 192.168.3.19 all

access-list 101 extended allow host ip 192.168.3.20 everything

access-list 101 extended permit ip host 192.168.3.21 all

access-list 101 extended allow host ip 192.168.3.22 all

access-list 101 extended allow host ip 192.168.3.23 all

access-list 101 extended allow host ip 192.168.3.24 everything

access-list 101 extended allow host ip 192.168.3.25 all

access-list 101 extended allow host ip 192.168.3.26 all

access-list 101 extended allow host ip 192.168.3.27 all

access-list 101 extended allow host ip 192.168.3.28 all

access-list 101 extended allow host ip 192.168.3.29 all

access-list 101 extended allow host ip 192.168.3.30 all

access-list 101 extended allow host ip 192.168.3.31 all

access-list 101 extended allow host ip 192.168.3.32 all

access-list 101 extended allow host ip 192.168.3.33 all

access-list 101 extended allow host ip 192.168.3.34 all

access-list 101 extended allow host ip 192.168.3.35 all

access-list 101 extended allow host ip 192.168.3.36 all

access-list 101 extended allow host ip 192.168.3.37 all

access-list 101 extended allow host ip 192.168.3.38 all

access-list 101 extended allow host ip 192.168.3.39 all

access-list 101 extended allow host ip 192.168.3.40 all

access-list 101 extended allow host ip 192.168.3.41 all

access-list 101 extended allow host ip 192.168.3.42 all

access-list 101 extended allow host ip 192.168.3.43 all

access-list 101 extended allow host ip 192.168.3.86 all

access-list 101 extended allow host ip 192.168.3.88 all

access-list 101 extended allow host ip 192.168.3.89 all

access-list 101 extended allow host ip 192.168.3.56 all

access-list 101 extended allow host ip 192.168.3.55 all

access-list 101 extended allow host ip 192.168.3.96 all

access-list 101 extended allow host ip 192.168.3.97 all

access-list 101 extended allow host ip 192.168.3.98 all

access-list 101 extended allow host ip 192.168.3.116 all

access-list 101 extended allow host ip 192.168.3.111 all

access-list 101 extended allow host ip 192.168.3.175 all

access-list 101 extended allow host ip 192.168.3.176 all

access-list 101 extended allow host ip 192.168.3.201 all

access-list 101 extended allow host ip 192.168.3.202 all

access-list 101 extended allow host ip 192.168.3.203 all

access-list 101 extended allow host ip 192.168.3.204 all

access-list 101 extended allow host ip 192.168.3.205 all

access-list 101 extended allow host ip 192.168.3.206 all

access-list 101 extended allow host ip 192.168.3.207 all

access-list 101 extended allow host ip 192.168.3.208 all

access-list 101 extended allow host ip 192.168.3.209 all

access-list 101 extended allow host ip 192.168.3.210 all

access-list 101 extended allow host ip 192.168.3.213 all

access-list 101 extended allow host ip 192.168.3.214 all

access-list 101 extended allow host ip 192.168.3.215 all

access-list 101 extended allow host ip 192.168.3.101 all

access-list 101 extended allow host ip 192.168.3.102 all

access-list 101 extended allow host ip 192.168.3.103 all

access-list 101 extended allow host ip 192.168.3.106 all

access-list 101 extended allow host ip 192.168.3.107 all

access-list 101 extended allow host ip 192.168.3.152 all

access-list 101 extended allow host ip 192.168.3.151 all

access-list 101 extended allow host ip 192.168.3.153 all

access-list 101 extended allow host ip 192.168.3.195 all

access-list 101 extended allow host ip 192.168.3.45 all

access-list 101 extended allow host ip 192.168.3.46 all

access-list 101 extended allow host ip 192.168.3.199 all

access-list 101 extended allow host ip 192.168.3.157 all

access-list 101 extended refuse 192.168.3.0 ip 255.255.255.0 any

access-list 101 extended allow tcp a whole

access list 101 scope ip allow a whole

vpnclient_splitTunnelAcl list standard access allowed 192.168.1.0 255.255.255.0

2 extended access-list permit ip 192.168.2.0 255.255.255.0 any

3 extended access-list allow ip 192.168.3.0 255.255.255.0 any

4 extended access-list allow ip 192.168.4.0 255.255.255.0 any

access-list extended 500 k permit ip host XXX1 everything

access-list extended 500 k allow icmp host XXX1 everything

access-list 102 extended allow host ip 192.168.1.6 everything

access-list extended 100 permit tcp any host 192.168.1.1 eq www

access-list extended 100 permit tcp any host 192.168.1.1 eq 8080

access-list extended 100 permit tcp any host X.X.X.4

access-list extended 100 permit ip any host X.X.X.4

access-list extended 100 permit icmp any host X.X.X.4

access-list extended 100 permit tcp any host 192.168.1.6 eq smtp

access-list extended 100 permit tcp any host 192.168.1.6 eq pop3

access-list extended 100 permit tcp any host 192.168.1.6 eq www

access-list extended 100 permit tcp any host 192.168.1.6

access-list 100 scope ip allow any host 192.168.1.6

access-list extended 100 permit icmp any host 192.168.1.6

access-list extended 100 permit tcp any host 192.168.1.19 eq 3389

access-list extended 100 permit tcp any host 192.168.1.20 eq 3389

access-list extended 100 permit tcp any host 192.168.1.88 eq 3389

access-list extended 100 permit tcp any host X.X.X.12

access-list extended 100 permit ip any host X.X.X.12

access-list extended 100 permit icmp any host X.X.X.12

access-list extended 100 permit tcp any host 192.168.1.6 eq 8086

access-list extended 100 permit tcp any host 192.168.1.1 eq 3389

access-list extended 100 permit tcp any host 192.168.1.6 eq 3389

access-list extended 100 permit tcp any host 192.168.1.6 eq ftp

access-list extended 100 permit tcp any host 192.168.1.6 eq ftp - data

access-list extended 100 permit tcp any host 192.168.2.88 eq 3389

access-list extended 100 permit tcp any host 192.168.2.88 eq 12172

access-list extended 100 permit tcp any host 192.168.2.2 eq 3389

access-list extended 100 permit tcp any host 192.168.2.2 eq 9116

access-list extended 100 permit tcp any host 192.168.3.2 eq 25243

access-list extended 100 permit tcp any host 192.168.3.2 eq 3389

access-list extended 100 permit tcp any host 192.168.1.200 eq www

access-list extended 100 permit tcp any host 192.168.1.200 eq 12001

access-list extended 100 permit tcp any host 192.168.1.30 eq 3389

access-list extended 100 permit tcp any host 192.168.3.5 eq 4160

access-list extended 100 permit tcp any host 192.168.3.5 eq 11111

access-list extended 100 permit tcp any host 192.168.3.5 eq 3389

access-list extended 100 permit tcp any host X.X.X.10

access-list extended 100 permit udp any host 192.168.2.88 eq 12172

access-list extended 100 permit udp any host 192.168.2.2 eq 9116

access-list extended 100 permit udp any host 192.168.3.2 eq 25243

access-list extended 100 permit udp any host 192.168.3.5 eq 4170

access-list extended 100 permit udp any host 192.168.3.5 eq 11111

access-list extended 100 permit ip any host X.X.X.10

access-list extended 100 permit tcp any host 192.168.1.6 eq 8087

access-list extended 100 permit tcp any host X.X.X.9

access-list extended 100 permit ip any host X.X.X.9

access-list extended 100 permit tcp any host 192.168.1.30 eq www

access-list extended 100 permit tcp any host X.X.X.5

access-list extended 100 permit ip any host X.X.X.5

access-list extended 100 permit icmp a whole

access-list extended 100 permit tcp any host 192.168.1.6 eq 8088

access-list extended 100 permit ip any host X.X.X.6

access-list extended 100 permit tcp any host X.X.X.6

access list extended 100 permit tcp host 61.186.169.129 host 192.168.1.2 eq 5872 times-range k3used

access list extended 100 permit tcp host 61.186.169.129 host 192.168.1.2 eq 8088 times-range k3used

access list extended 100 permit tcp host 61.186.169.129 host 192.168.1.2 eq 3389 times-range k3used

allowed extended access list 100 tcp host 61.186.169.129 host 192.168.1.19 eq www time-range k3used

access-list extended 100 permit tcp host 61.186.169.129 X.X.X.2 time-range k3used

access list extended 100 permit tcp host 61.186.169.130 host 192.168.1.2 eq 5872 times-range k3used

access list extended 100 permit tcp host 61.186.169.130 host 192.168.1.2 eq 8088 times-range k3used

access list extended 100 permit tcp host 61.186.169.130 host 192.168.1.2 eq 3389 times-range k3used

allowed extended access list 100 tcp host 61.186.169.130 host 192.168.1.19 eq www time-range k3used

access-list extended 100 permit tcp host 61.186.169.130 X.X.X.2 time-range k3used

access list extended 100 permit tcp host 61.186.169.131 host 192.168.1.2 eq 5872 times-range k3used

access list extended 100 permit tcp host 61.186.169.131 host 192.168.1.2 eq 8088 times-range k3used

access list extended 100 permit tcp host 61.186.169.131 host 192.168.1.2 eq 3389 times-range k3used

allowed extended access list 100 tcp host 61.186.169.131 host 192.168.1.19 eq www time-range k3used

access-list extended 100 permit tcp host 61.186.169.131 X.X.X.2 time-range k3used

access list extended 100 permit tcp host 61.186.169.132 host 192.168.1.2 eq 5872 times-range k3used

access list extended 100 permit tcp host 61.186.169.132 host 192.168.1.2 eq 8088 times-range k3used

access list extended 100 permit tcp host 61.186.169.132 host 192.168.1.2 eq 3389 times-range k3used

allowed extended access list 100 tcp host 61.186.169.132 host 192.168.1.19 eq www time-range k3used

access-list extended 100 permit tcp host 61.186.169.132 X.X.X.2 time-range k3used

access list extended 100 permit tcp host 61.186.169.133 host 192.168.1.2 eq 5872 times-range k3used

access list extended 100 permit tcp host 61.186.169.133 host 192.168.1.2 eq 8088 times-range k3used

access list extended 100 permit tcp host 61.186.169.133 host 192.168.1.2 eq 3389 times-range k3used

allowed extended access list 100 tcp host 61.186.169.133 host 192.168.1.19 eq www time-range k3used

access-list extended 100 permit tcp host 61.186.169.133 X.X.X.2 time-range k3used

access-list extended 100 permit ip host 61.186.169.129 X.X.X.2 time-range k3used

access-list extended 100 permit ip host 61.186.169.130 X.X.X.2 time-range k3used

access-list extended 100 permit ip host 61.186.169.131 X.X.X.2 time-range k3used

access-list extended 100 permit ip host 61.186.169.132 X.X.X.2 time-range k3used

access-list extended 100 permit ip host 61.186.169.133 X.X.X.2 time-range k3used

access-list extended 100 permit icmp host 61.186.169.129 X.X.X.2 time-range k3used

access-list extended 100 permit icmp host 61.186.169.130 X.X.X.2 time-range k3used

access-list extended 100 permit icmp host 61.186.169.131 X.X.X.2 time-range k3used

access-list extended 100 permit icmp host 61.186.169.132 X.X.X.2 time-range k3used

access-list extended 100 permit icmp host 61.186.169.133 X.X.X.2 time-range k3used

access list extended 100 permit tcp host 183.64.106.194 host 192.168.1.2 eq 5872 times-range k3used

access list extended 100 permit tcp host 183.64.106.194 host 192.168.1.2 eq 8088 times-range k3used

access list extended 100 permit tcp host 183.64.106.194 host 192.168.1.2 eq 3389 times-range k3used

allowed extended access list 100 tcp host 183.64.106.194 host 192.168.1.19 eq www time-range k3used

access-list extended 100 permit tcp host 183.64.106.194 X.X.X.2 time-range k3used

access-list extended 100 permit ip host 183.64.106.194 X.X.X.2 time-range k3used

access-list extended 100 permit icmp host 183.64.106.194 X.X.X.2 time-range k3used

access list extended 100 permit tcp host 183.64.106.195 host 192.168.1.2 eq 5872 times-range k3used

access list extended 100 permit tcp host 183.64.106.195 host 192.168.1.2 eq 8088 times-range k3used

access list extended 100 permit tcp host 183.64.106.195 host 192.168.1.2 eq 3389 times-range k3used

allowed extended access list 100 tcp host 183.64.106.195 host 192.168.1.19 eq www time-range k3used

access-list extended 100 permit tcp host 183.64.106.195 X.X.X.2 time-range k3used

access-list extended 100 permit ip host 183.64.106.195 X.X.X.2 time-range k3used

access-list extended 100 permit icmp host 183.64.106.195 X.X.X.2 time-range k3used

access list extended 100 permit tcp host 14.107.162.32 host 192.168.1.2 eq 5872 times-range k3used

access list extended 100 permit tcp host 14.107.162.32 host 192.168.1.2 eq 8088 times-range k3used

access list extended 100 permit tcp host 14.107.162.32 host 192.168.1.2 eq 3389 times-range k3used

allowed extended access list 100 tcp host 14.107.162.32 host 192.168.1.19 eq www time-range k3used

access-list extended 100 permit tcp host 14.107.162.32 X.X.X.2 time-range k3used

access-list extended 100 permit ip host 14.107.162.32 X.X.X.2 time-range k3used

access-list extended 100 permit icmp host 14.107.162.32 X.X.X.2 time-range k3used

access list extended 100 permit tcp host 14.107.247.121 host 192.168.1.2 eq 5872 times-range k3used

access list extended 100 permit tcp host 14.107.247.121 host 192.168.1.2 eq 8088 times-range k3used

access list extended 100 permit tcp host 14.107.247.121 host 192.168.1.2 eq 3389 times-range k3used

allowed extended access list 100 tcp host 14.107.247.121 host 192.168.1.19 eq www time-range k3used

access-list extended 100 permit tcp host 14.107.247.121 X.X.X.2 time-range k3used

access-list extended 100 permit ip host 14.107.247.121 X.X.X.2 time-range k3used

access-list extended 100 permit icmp host 14.107.247.121 X.X.X.2 time-range k3used

access list extended 100 permit tcp host 61.128.208.106 host 192.168.1.2 eq 5872 times-range k3used

access list extended 100 permit tcp host 61.128.208.106 host 192.168.1.2 eq 8088 times-range k3used

access list extended 100 permit tcp host 61.128.208.106 host 192.168.1.2 eq 3389 times-range k3used

allowed extended access list 100 tcp host 61.128.208.106 host 192.168.1.19 eq www time-range k3used

access-list extended 100 permit tcp host 61.128.208.106 X.X.X.2 time-range k3used

access-list extended 100 permit ip host 61.128.208.106 X.X.X.2 time-range k3used

access-list extended 100 permit icmp host 61.128.208.106 X.X.X.2 time-range k3used

access-list 100 extended tcp refuse any host 192.168.1.2 eq 5872

access-list 100 extended tcp refuse any host 192.168.1.2 eq 8088

access-list 100 extended tcp refuse any host 192.168.1.2 eq 3389

access-list 100 extended tcp refuse any host 192.168.1.19 eq www

access-list 100 extended tcp refuse any host X.X.X.2

access-list extended 100 deny ip any host X.X.X.2

access-list extended 100 refuse icmp any host X.X.X.2

pager lines 24

Outside 1500 MTU

Within 1500 MTU

management of MTU 1500

IP local pool 192.168.200.1 - 192.168.200.20 mask 255.255.255.0 vpn_pool

ICMP unreachable rate-limit 1 burst-size 1

don't allow no asdm history

ARP timeout 14400

NAT (inside, all) source static obj - obj - 192.168.1.0 destination 192.168.1.0 static obj - 192.168.200.0 obj - 192.168.200.0 non-proxy-arp

NAT (inside, all) source static obj - 192.168.200.0 obj - 192.168.200.0 destination static obj - 192.168.1.0 obj - 192.168.1.0 non-proxy-arp

NAT (inside, outside) source static obj - 192.168.1.6 obj - X.X.X.3 service obj-tcp-source-eq-25 obj-tcp-source-eq-25

NAT (inside, outside) source static obj - 192.168.1.6 obj - X.X.X.3 service obj-tcp-source-eq-110 obj-tcp-source-eq-110

NAT (inside, outside) source static obj - 192.168.1.6 obj - X.X.X.10 service obj-tcp-source-eq-8086 obj-tcp-source-eq-80

NAT (inside, outside) source static obj - 192.168.1.6 obj - X.X.X.10 service obj-tcp-source-eq-3389 obj-tcp-source-eq-9877

NAT (inside, outside) source static obj - 192.168.1.6 obj - X.X.X.10 service obj-tcp-source-eq-21 obj-tcp-source-eq-21

NAT (inside, outside) source static obj - 192.168.1.6 obj - X.X.X.10 service obj-tcp-source-eq-20 obj-tcp-source-eq-20

NAT (inside, outside) source static obj - 192.168.1.6 obj - X.X.X.9 service obj-tcp-source-eq-8087 obj-tcp-source-eq-80

NAT (inside, outside) source static obj - 192.168.1.6 obj - X.X.X.6 service obj-tcp-source-eq-8088 obj-tcp-source-eq-80

NAT (inside, outside) source static obj - 192.168.1.6 obj - X.X.X.3 service obj-tcp-source-eq-80 obj-tcp-source-eq-80

NAT (inside, outside) source dynamic obj - 192.168.1.6 obj - X.X.X.3

!

network object obj - 192.168.1.0

NAT dynamic interface (indoor, outdoor)

network object obj - 192.168.200.0

NAT dynamic interface (indoor, outdoor)

network object obj - 192.168.1.2

NAT (inside, outside) Static X.X.X.2 5872 5872 tcp service

network object obj - 192.168.1.2 - 01

NAT (inside, outside) Static X.X.X.2 8088 8088 tcp service

network object obj - 192.168.1.19

NAT (inside, outside) Static X.X.X.12 tcp 3389 8001 service

network object obj - 192.168.1.20

NAT (inside, outside) Static X.X.X.12 tcp 3389 8002 service

network object obj - 192.168.1.88

NAT (inside, outside) Static X.X.X.12 tcp 3389 12345 service

network object obj - 192.168.1.1

NAT (inside, outside) Static X.X.X.4 tcp www www service

network object obj - 192.168.1.2 - 02

NAT (inside, outside) Static X.X.X.2 service tcp 3389 8005

network object obj - 192.168.1.1 - 01

NAT (inside, outside) Static X.X.X.10 tcp 3389 9876 service

network object obj - 192.168.2.88

NAT (inside, outside) Static X.X.X.10 tcp 3389 3129 service

network object obj - 192.168.2.88 - 01

NAT (inside, outside) Static X.X.X.10 12172 12172 tcp service

network object obj - 192.168.2.88 - 02

NAT (inside, outside) Static X.X.X.10 service udp 12172 12172

network object obj - 192.168.1.19 - 01

NAT (inside, outside) Static X.X.X.2 service tcp www 8056

network object obj - 192.168.2.2

NAT (inside, outside) Static X.X.X.10 3389 3128 tcp service

network object obj - 192.168.2.2 - 01

NAT (inside, outside) Static X.X.X.10 9116 9116 tcp service

network object obj - 192.168.2.2 - 02

NAT (inside, outside) Static X.X.X.10 service udp 9116 9116

network object obj - 192.168.3.2

NAT (inside, outside) Static X.X.X.10 25243 25243 tcp service

network object obj - 192.168.3.2 - 01

NAT (inside, outside) Static X.X.X.10 service udp 25243 25243

network object obj - 192.168.3.2 - 02

NAT (inside, outside) Static X.X.X.10 tcp 3389 3130 service

network object obj - 192.168.1.200

NAT (inside, outside) Static X.X.X.10 service tcp www 1114

network object obj - 192.168.1.200 - 01

NAT (inside, outside) Static X.X.X.10 12001 12001 tcp service

network object obj - 192.168.1.30

NAT (inside, outside) Static X.X.X.5 tcp www www service

network object obj - 192.168.1.30 - 01

NAT (inside, outside) Static X.X.X.10 tcp 3389 9878 service

network object obj - 192.168.1.1 - 02

NAT (inside, outside) Static X.X.X.4 8080 8080 tcp service

network object obj - 192.168.3.5

NAT (inside, outside) Static X.X.X.10 4160 4160 tcp service

network object obj - 192.168.3.5 - 01

NAT (inside, outside) Static X.X.X.10 service udp 4170 4170

network object obj - 192.168.3.5 - 02

NAT (inside, outside) Static X.X.X.10 11111 11111 tcp service

network object obj - 192.168.3.5 - 03

NAT (inside, outside) Static X.X.X.10 tcp 3389 3127 service

network object obj - 192.168.3.5 - 04

NAT (inside, outside) Static X.X.X.10 11111 11111 udp service

network object obj - 192.168.2.0

NAT dynamic interface (indoor, outdoor)

network object obj - 192.168.3.0

NAT dynamic interface (indoor, outdoor)

network object obj - 192.168.4.0

NAT dynamic interface (indoor, outdoor)

network object obj - 192.168.5.0

NAT dynamic interface (indoor, outdoor)

network object obj - 192.168.6.0

NAT dynamic interface (indoor, outdoor)

network object obj - 192.168.7.0

NAT dynamic interface (indoor, outdoor)

network object obj - 192.168.8.0

NAT dynamic interface (indoor, outdoor)

Access-group 100 in external interface

Access-group 101 in the interface inside

Route outside 0.0.0.0 0.0.0.0 X.X.X.14 1

Route inside 192.168.2.0 255.255.255.0 192.168.1.12 1

Route inside 192.168.3.0 255.255.255.0 192.168.1.12 1

Route inside 192.168.4.0 255.255.255.0 192.168.1.12 1

Route inside 192.168.5.0 255.255.255.0 192.168.1.12 1

Route inside 192.168.6.0 255.255.255.0 192.168.1.12 1

Timeout xlate 03:00

Timeout conn 01:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02

Sunrpc timeout 0:10:00 h323 0:05:00 h225 mgcp from 01:00 0:05:00 mgcp-pat 0:05:00

Sip timeout 0:30:00 sip_media 0:02:00 prompt Protocol sip-0: 03:00 sip - disconnect 0:02:00

Timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute

timeout tcp-proxy-reassembly 0:01:00

Floating conn timeout 0:00:00

dynamic-access-policy-registration DfltAccessPolicy

identity of the user by default-domain LOCAL

Enable http server

No snmp server location

No snmp Server contact

Server enable SNMP traps snmp authentication linkup, linkdown warmstart of cold start

Crypto ipsec transform-set esp - esp-md5-hmac ikev1 vpn_set

Crypto-map dynamic vpn_map 10 set transform-set vpn_set ikev1

Crypto-map dynamic vpn_map 10 the value reverse-road

vpnmap 10 card crypto ipsec-isakmp dynamic vpn_map

vpnmap interface card crypto outside

Crypto ikev1 allow outside

IKEv1 crypto policy 1

preshared authentication

the Encryption

md5 hash

Group 2

life 86400

IKEv1 crypto policy 65535

preshared authentication

3des encryption

sha hash

Group 2

life 86400

Telnet 0.0.0.0 0.0.0.0 inside

Telnet 192.168.1.0 255.255.255.0 inside

Telnet timeout 5

SSH 0.0.0.0 0.0.0.0 outdoors

SSH timeout 30

SSH version 1

Console timeout 0

a basic threat threat detection

Statistics-list of access threat detection

no statistical threat detection tcp-interception

Server NTP 192.43.244.18

internal group vpnclient strategy

vpnclient group policy attributes

value of server DNS 61.128.128.68

Ikev1 VPN-tunnel-Protocol

Split-tunnel-policy tunnelspecified

value of Split-tunnel-network-list vpnclient_splitTunnelAcl

cisco 3USUcOPFUiMCO4Jk encrypted password username

type tunnel-group vpn_group remote access

tunnel-group vpn_group General-attributes

address vpn_pool pool

Group Policy - by default-vpnclient

vpn_group group of tunnel ipsec-attributes

IKEv1 pre-shared-key *.

!

class-map 500 k

matches the access list 500 k

class-map inspection_default

match default-inspection-traffic

class-map 2

matches the access list 2

PAM-class 3

matches the access list 3

class-map 4

corresponds to the list of access-4

!

!

type of policy-card inspect dns preset_dns_map

parameters

maximum message length automatic of customer

message-length maximum 512

Policy-map global_policy

class inspection_default

inspect the preset_dns_map dns

inspect the ftp

inspect h323 h225

inspect the h323 ras

Review the ip options

inspect the netbios

inspect the rsh

inspect the rtsp

inspect the skinny

inspect esmtp

inspect sqlnet

inspect sunrpc

inspect the tftp

inspect the sip

inspect xdmcp

Policy-map 500 k

500 k class

Policy-map 2

class 2

class 3

class 4

!

global service-policy global_policy

context of prompt hostname

remote anonymous reporting call invites 2

call-home

Profile of CiscoTAC-1

no active account

http https://tools.cisco.com/its/service/oddce/services/DDCEService destination address

email address of destination [email protected] / * /

destination-mode http transport

Subscribe to alert-group diagnosis

Subscribe to alert-group environment

Subscribe to alert-Group 13 monthly periodic inventory

Subscribe to alert-group configuration periodic monthly 13

daily periodic subscribe to alert-group telemetry

Cryptochecksum:ecead54d7c85807eb47c7cdaf7d7e82a

: end

ciscoasa#                                                                     $

ciscoasa #.

ciscoasa #.

Hello

You have changed the source IP address of the order I suggested?

There is no reason to use the 192.168.1.1 IP address as the source of this command "packet - trace" that the source will NEVER be this IP address, because it is a private IP not routable on the public Internet.

Then you can try with the order I suggested.

entry Packet-trace out tcp 1.1.1.1 12345 61.186.236.4 80

I guess that the above command / test failed because you were using the real server IP address as the IP source for the test.

-Jouni

Tags: Cisco Security

Similar Questions

  • Windows Server cannot access the folder

    Windows Server 2008 R2 SP1 Standard, I have a folder that I created.  I can access the folder if I go through the C:\ drive, but can't if I try UNC \\ServerName\ or \\IPAddress\ and receive a

    Windows cannot access \\ServerName\...
    You are not allowed to access \\ServerName\... Contact your network administrator to request access.

    but when I check the permissions on the folder, I'm registered and received a control total change, read & execute, display the contents of the folder, read, write.

    I need to be able to assign the UNC path to a database, and it is a failure because of this problem.

    Anyone have any ideas?

    QuestionBoy

    You will need to create a new post on the TechNet forums for assistance with Windows Server:
    http://social.technet.Microsoft.com/forums/en-us/category/WindowsServer

  • sites Web/flash cannot access camera xoom

    Adobe Flash recognizes no built-in camera (s).  When I try to connect my xoom to a video chat website I do not get the FlashDrive asobe familiar settings dialog asking me if I want to allow the site to access my camera and a microphone.  Will flash I would like to receive the video, but won't allow me to send video footage.

    If I try were:

    http://www.testwebcam.com/

    or

    http://www.sillywebcam.com/others/?demo=test-your-webcam

    the Xoom does not give me the flash player settings dialog which is necessary to allow the site to take camera to my xoom from adobe.

    and the second site gives me the message: "it takes a camera for this demonstration."

    Is there a way to allow Web sites to access the photo/video camera feeds flash?

    Thank you

    Jim camp

    Jim,

    There was a gmanapps response that explains why the camera may not work through web sites, here are the other related thread:

    https://supportforums.Motorola.com/thread/47936?TSTART=0

  • BI SampleAppFiles Server cannot access the correct file

    Hello experts,

    Part of my project is creation of KPIs for my clients. Before doing all this, I'm trying to create a KPI sample and see if it works well.   It is using 11g (1.1.7).

    Here's the problem: I created the sample KPI without problem; However, when I try to open the report I get an error that

    State: HY000. Code: 10058. [NQODBC] [SQL_STATE: HY000] [nQSError: 10058] A general error occurred. [nQSError: 43113] The message returned by OBIS. [nQSError: 64023] Cannot access the E:\BIHOME\instances\instance1\bifoundation\OracleBIServerComponent\coreapplication_obis1/sample/SampleAppFiles/Data/SAMP_REVENUE_A.xml: no such file or directory for table SAMP_REVENUE_A (HY000)

    The path is correct, except instead (E:\), it should be (C:\).  Does anyone know how to change this? Help, please.

    I don't have a 'E' drive in my system. This forum works on windows

    Help, please

    Hello

    In the sample OBIEE, you have a variable called BI_EE_HOME with this path

    To change this, open your SPR (online mode) and then change repository variable BI_EE_HOME

    We call this variable in your connection pool (you can change this path directly on the connection pool too)

    Felipe Idalgo

  • Cannot start web server on the executable file

    Hello

    We have a problem with a Web server - we cannot get to initialize the help of nodes of property or the ini on a compiled executable file.

    As part of our application, we are starting the Web server to publish a status page to be read remotely. This works very well when we are running in the development environment and also when we run an executable a PC with installed development environment, however it will not boot on a PC with just the runtime installed.

    I have attached some of the code that functionally does exactly the same thing in our main application. I used this as my Tester code and built in an exe while trying a lot of different things to fix.

    When executing:

    • The code will sit in the while loop until I press stop.
    • Web server: Active Server = FALSE
    • Out error = ERROR No.

    In the full application the while loop waits a few seconds before throw an error if the server is not started. In this example, I can let the loop running for awhile without leave. Normally, the boot time is<50ms when="">

    It's the ini file to the executable file:

    [WebTest]
    server.app.propertiesEnabled = True
    Server.OLE.Enabled = True
    server.tcp.serviceName = "My Server computer/VI"
    server.vi.propertiesEnabled = True
    WebServer.Enabled = True
    WebServer.TcpAccess = "' + * '"
    WebServer.ViAccess = "' + * '"
    DebugServerEnabled = False
    DebugServerWaitOnLaunch = False

    And it is the Web server configuration file:

    ErrorLog "$LVSERVER_ROOT/logs/error.log".
    LogLevel 3
    The default server name
    DocumentRoot "$LVSERVER_ROOT /... /.. '. "/ www".
    Listen 8000
    ThreadLimit 10
    TypesConfig "$LVSERVER_ROOT/mime.types»
    DirectoryIndex index.html
    LoadModulePath "$LVSERVER_ROOT/modules '" $LVSERVER_ROOT/LVModules "" $LVSERVER_ROOT /... ".
    LoadModule LVAuth lvauthmodule
    LoadModule LVSnapshot lvsnapshotmodule
    LoadModule LVRFP lvrfpmodule
    LoadModule dir libdirModule
    LoadModule copy libcopyModule

    AddHandler LVAuthHandler
    AddHandler LVSnapshotHandler .snap
    AddHandler LVRFPHandler

    AddHandler dirHandler
    AddHandler copyHandler

    "CustomLog"$LVSERVER_ROOT/logs/access.log"'%%u %t \"%r\ hour' % > s %b.
    KeepAlive on
    KeepAliveTimeout 60
    Timeout 60

    As can side note, anyone tell me where the $LVSERVER_ROOT variable is configured?

    I tried the things:

    • Copy a new default configuration file before the entry into force
    • Writing a predefined file (encoded) before initializing config
    • Definition to root before initializing directory (it actually generates an error because the server is not active...)
    • Set WebServer.Active = TRUE several times inside the while loop
    • Toggle the web server in the ini file

    System:

    • LabVIEW 2010
    • PC with Windows 7 running

    Thanks for any help, because it makes me crazy slow!

    Ben

    Hi Marco, thanks for the reply.

    I have this guide was reviewed previously and had done all that he but a small section who gave me a hint of something to try and I have solved my problem, so thank you!

    If anyone is interested, here's the problem:

    The directive DocumentRoot folder in the config must exist or the Web server cannot be started. So basically, make sure that the file points to a folder that exists!

    This leaves two small annoying problems if - you can't see if the file exists (and then create it) before starting the Web server, because you can not query the path to the folder without the Web server running.

    AND

    You can't really define the configuration programmatically file as parameters from the file are responsible for execution, not on the start Web server.

    The result of this is that the config file and the folder root document should be created (and corresponding of course...) when the executable is built / installed on the system. Not a massive headache, but it means do not forget to put things in the build specification and do not rely on software to do the job at startup

  • Printer Officejet Pro 8620: How to reset the Server Web integrated (built-in web server) on the printer Officejet Pro 8620 Pro?

    The password has been reset, but we cannot go beyond the server request the user name and password to change the other settings.  We have not had any problems to set up the printer to the computer and we are able to print and use the printer.  We just need to find EWS to change other settings.  We use Windows 7.

    Hi there @Mariko23

    Welcome to the forums,

    I understand the SAP you request a user name and password and you're looking to reset the built-in Web server to access accordingly.

    I suggest try to restore default network settings on the device, which should help you.

    On the printer, select Setup, network configuration, network by default, Yes, restart the printer.

    Good luck, I hope this helps

  • Server cannot connect to the https

    I found the installation of software that our main server cannot access any site that requires https. I checked using Internet explore and firefox and no work. We have a Sonicwall firewall but can't find anything obvious here.

    Please contact a forum that manages your server product. If it is Windows server, then check on http://social.technet.microsoft.com/Forums/

    You can also add more details when reposting here, as the description above is not much information about the problem.

  • CF2016 - Alias/cf_scripts / scripts on the built-in Web server

    I am following the guide lockdown here:

    http://wwwimages.Adobe.com/content/dam/ACOM/en/products/ColdFusion/PDFs/ColdFusion-2016-Lo ckdown - guide.pdf

    The guide proposes to move/cf_scripts/scripts directory, I did.

    The guide also offers using only the web server integrated access to the ColdFusion administrator, this is how I put it in place.

    The guide also indicates that you need to create an alias for the directory moved to the built-in web server.  See page 58 of the PDF.

    If you plan to use the built-in web server to access the ColdFusion administrator, you may need to create an alias for/cf_scripts/scripts if you have changed the default Script Src in ColdFusion administrator.

    To create a new Alias for/cf_scripts/scripts on the built-in web server

    If you plan to use the web server to access the ColdFusion administrator, then you must also add an alias by adding a tag context inside the tag of the located server.xml file host: /opt/cf11/cfusion/runtime/conf/server.xml

    < context path = ' / '.

    docBase = "/ opt/cf11/cfusion/wwwroot".

    Workie = "/ opt/cf11/fusion/runtime/cone/Catalina/localhost/tamp.

    alias = "/ coscripts = / opt/cf11/fusion/wwwroot/CFIDE/scripts" / >

    Restart ColdFusion, and then test by visiting /cfscripts/cfform.js on your server of builtin.

    There are a ton of typos in the present (Workie vs WorDir, vs conf cone, Pack vs coscripts vs cfscripts, tmp, etc..

    This also seems to be referencing the paths cf11 (CFIDE/scripts vs /cfscripts/cfform.js vs cf_scripts/scripts/cfform.js and cf_scripts/scripts).

    In addition, coldfusion - error.log notes the following:

    WARNING: A context path should be an empty string or start with a ' / ' and do not end with a ' / '. [The path [/] does not satisfy these criteria and has been replaced by]

    WARNING: [SetPropertiesRule] {Server/Service/engine/host/context} setting property 'alias' to ' / cf_scripts/scripts = / cf_scripts/test_scripts "did not find a corresponding property.

    The first line is not a problem, but the second line is.  alias is not a valid property of the context.

    The server.xml file is an example, and it is as follows:

    "< context path =" "docBase =" < cf_home > / wwwroot "WorkDir =" "< cf_home > / runtime/conf/Catalina/localhost/tmp" > "

    < resources >

    < base preResources = "docBase1" className = "org.apache.catalina.webresources.DirResourceSet" webAppMount ="/ aliasPath1" / > "

    < base preResources = "docBase2" className = "org.apache.catalina.webresources.DirResourceSet" webAppMount ="/ aliasPath2" / > "

    < / resource >

    < / context >

    It aligns with the Apache docs.

    I have CF installed on Windows, to F:\CF_2016\.  That's what I did to alias the directory of scripts (renamed to test_scripts for testing) for the built-in web server:

    < context path = "/" docBase = "F:/CF_2016/cfusion/wwwroot" WorkDir = "F:/CF_2016/cfusion/runtime/conf/Catalina/localhost/tmp" >

    < resources >

    < base preResources = className "F:/CF_2016/cfusion/wwwroot/cf_scripts/test_scripts" = "org.apache.catalina.webresources.DirResourceSet" webAppMount = "/ cf_scripts/scripts" / > "

    < / resource >

    < / context >

    It seems to work.  Is this correct? Wouldn't be an alias as \Scripts or /cfscripts instead of/cf_scripts/scripts?

    Why exactly should I alias this to the administrator?

    Thank you

    Hello

    I was in the same boat (we are defining a profile secure for testing) and I see no one answered you so I want to offer what we were doing.

    webAppMount = "/ {NEW_CFSCRIPTS_VIRTUAL_DIRTORYNAME" / >} "

    You see, I believe the problem you had previously was that the base should be the physical directory and the webAppMount should be the virtual directory.

    You were correct about the typos in the "official" document

    I don't know if it's important or not, but we have also created the directory "tmp" (quoted above) within the "{YOUR_DRIVE} :/. "{CFROOT} / cfusion/runtime/conf/Catalina/localhost / ' because it is not there by default.

    Kind regards
    David

  • No NAT DMZ web server when you access by internal users

    How can I create an exception to allow users to access a web server on port 80 in the demilitarized zone inside? They cannot do that now because, in my view, the server goes through a NAT the public address, so how can I set up where a request from inside on port 80 on this server will not translate the IP of the server to a public IP address (via NAT)?

    static (i, dmz) internal_net internal_net /xx

    The CCIE Security

  • Cannot access the Web server in the DMZ from the inside using IP global

    Hi all

    I hope it's a very simple question.

    I'm running a PIX 515 firewall v6.3. I set up a Web server in my DMZ and use static NAT for re-branded it overall static IP address. Access from the outside of the demilitarized zone works remarkably well. I can access inside the interface Web site using the internal IP, but I can't access it from inside interface using the global IP are entrusted to him.

    Is there a particular reason why this would not be allowed? My feeling was that the request would be forwarded via the external interface (as it is a global IP address) and then be bounced back by my sense of the ISP the request would come to the new external interface (as the static NAT is applied to the external interface).

    However if I try and access the global IP from my inside interface, then the browser can not find the server.

    can someone explain why this is so? Any information would be appreciated.

    see you soon,

    Wayne

    ---------------------------------

    6.3 (3) version PIX

    interface ethernet0 100full

    interface ethernet1 100full

    interface ethernet2 100full

    ethernet0 nameif outside security0

    nameif ethernet1 inside the security100

    nameif dmz security50 ethernet2

    hostname helmsdeep

    domain p2h.com.sg

    fixup protocol dns-length maximum 512

    fixup protocol ftp 21

    fixup protocol h323 h225 1720

    fixup protocol h323 ras 1718-1719

    fixup protocol http 80

    fixup protocol they 389

    no correction protocol rsh 514

    fixup protocol rtsp 554

    fixup protocol sip 5060

    fixup protocol sip udp 5060

    fixup protocol 2000 skinny

    fixup protocol smtp 25

    No fixup protocol sqlnet 1521

    fixup protocol tftp 69

    names of

    acl_out list access permit tcp any host 203.169.113.110 eq www

    access-list 90 allow the host tcp 10.1.1.27 all

    pager lines 24

    debug logging in buffered memory

    Outside 1500 MTU

    Within 1500 MTU

    MTU 1500 dmz

    IP address outside pppoe setroute

    IP address inside 192.168.1.1 255.255.255.0

    dmz 10.1.1.1 IP address 255.255.255.0

    no failover

    failover timeout 0:00:00

    failover poll 15

    No IP failover outdoors

    No IP failover inside

    no failover ip address dmz

    location of PDM 202.164.169.42 255.255.255.255 inside

    location of PDM 202.164.169.42 255.255.255.255 dmz

    location of PDM 10.1.1.26 255.255.255.255 dmz

    location of PDM 10.1.1.26 255.255.255.255 outside

    location of PDM 172.16.16.20 255.255.255.255 outside

    location of PDM 192.168.1.222 255.255.255.255 inside

    history of PDM activate

    ARP timeout 14400

    Global 1 interface (outside)

    Global (dmz) 1 10.1.1.101 - 10.1.1.125

    NAT (inside) 1 0.0.0.0 0.0.0.0 0 0

    NAT (dmz) 0-list of access 90

    NAT (dmz) 1 0.0.0.0 0.0.0.0 0 0

    static (dmz, external) 203.169.113.110 10.1.1.27 netmask 255.255.255.255 0 0

    Access-group acl_out in interface outside

    Timeout xlate 03:00

    Timeout conn 01:00 half-closed 0:10:00 udp 0: CPP 02:00 0:10:00 01:00 h225

    H323 timeout 0:05:00 mgcp 0: sip from 05:00 0:30:00 sip_media 0:02:00

    Timeout, uauth 0:05:00 absolute

    GANYMEDE + Protocol Ganymede + AAA-server

    RADIUS Protocol RADIUS AAA server

    AAA-server local LOCAL Protocol

    Enable http server

    http 192.168.1.222 255.255.255.255 inside

    enable floodguard

    string fragment 1

    Console timeout 0

    Terminal width 80

    Code v6 pix or less don't let you have traffic "back" or return flow via the same interface on which it was sent. Having also your bounce back off of an external server traffic is never a good idea, because you won't be able to distinguish which and rogue attacks by spoofing someone outside your network.

    Since you are using pix 6.3 code, you may be able to outside the NAT. Add this static to your config:

    static (dmz, upside down) 203.169.113.110 10.1.1.27 netmask 255.255.255.255 0 0

    You may need to run a clear xlate after adding the new static statement. Note that the interfaces: it's demilitarized zone, inside inside, dmz.

    I would like to know if it works.

  • I'm in the Mexico and can browse the web but cannot get the roadrunner site to open the webmail server to allow access to e-mail.

    I'm in the Mexico and can browse the web but cannot get the roadrunner site to open the webmail server to allow access to e-mail. I worked around it through another proxy server, but navigation is a pain. does anyone know a solution to this problem? Roadrunner denies that it doesn't clog and so did the modem service here which is telmex?

    [moved]

    I had the same problem 2 weeks while in the Mexico.  I contacted the support TWC and the person to whom I spoke said he had to unlock something.  When he did, all my mail came in Outlook in the spam folder.  It was OK because I got my mail.

    I moved to a different House and now have the same problem again.  I've contacted support TWC and not had much luck. The second level support person and I spent more than an hour, the call of the Mexico using Vontage.  He has not found anything by the previous call that guided him by setting this time.  He said that he would open a ticket and call me in the next 24 to 48 hours.

    Is it reminds and solves the problem, I'll post how it was corrected.

    Amigos audio!

  • OfficeJet 8500 has Premium: cannot access any embedded web server...

    I'm changing the address of electronic mail (from a previous owner of the printer) by going to "scan to e-mail" settings in the HP utility and by hitting the link to enter the integrated Web server.  I was able to access the built-in Web server (despite receives a lot of restricted warnings) in typing the IP address 192.168.1.6 for a brief period, but I still couldn't change the e-mail settings as kepyt I get access denied the warnings.  Then I can I have messed up it by checking the Https redirection feature and now can not access EWS for all.  Is there a way to return to the main page of the EWS?  Now, all I get is a blank page when I click on go to EWS in the utility section of HP.    I would like to modify the e-mail settings which I believe have been implemented by the former owner.  I have restored the default settings of the network twice and nothing has changed.  Any help would be greatly appreciated that I use an older printer without help of the guarantee.

    Thank you

    Hi sojoey,

    I recommend you try a different browser than the one you are using. You can try Firefox, Google Chrome, etc. If you get pop-ups about certificates for HTTPS, click on continue anyway.

    We'll see what happens!

  • Built-in web server I cannot access the settings HP Officejet 6600 CZ155A tab

    HP Officejet 6600 CZ155A regarding:

    I had access to the embedded on my iMac on OSX 10.8.2 computer.  It did not work so I did an uninstall and then reinstall the HP software.  This is the latest version.  I did also some Apple software updates as requested.  The e-print emial account works when I send a message with a document and prints.  But when I try to enter in additional features in the web server, I can not go beyond the window with the IP address and "admin" displays as well.  I have some information in my file with the name wireless live - but it does not work either.

    Suggestions or comments?

    Thank you.  I contacted HP Support and it took a few calls but it is fixed.  The problem was with the IP addresses.  We emptied the printer.  Assigned to a correct IP and it worked perfectly.  Thanks again for your advice.

  • N600 ea2700 cannot access internal Web sites

    I have a new router, n600 ea2700, replace a wrt54g2 for this.

    I have an internal Web server configuration, with port 80 redirection http to my iis7 Web with a server static ip address

    I can access my areas outside my internal network (IE my cell phone), but when I type in www.mydomain(s).com (one of them) in my browser on a wired computer or internal wireless I get "cannot display this page".

    I can ping the www.my... and get an answer to my router static ip (internet provider)

    I can type in my static ip of the Web server and get my splash screen for iis7

    I of the wrong with linksys phone and they could not understand, basically saying take the router at staples and get a different model.

    I think I'll ask here before I do it.  I would add that if I put the old wrt back I can't access no problem.

    Any ideas?

    Thank you!

    Sorry I misunderstood your OP.

    This is called "NAT Loopback" and is not available on the Smart Wifi routers.

    Honestly the firmware of the Wifi chip is not designed for custom networks from servers or DNS requirements.

  • Cannot connect to the integrated Web server

    I have a HP p1606dn printer I need to change the IP address. I can't connect to SAP by using the IP address of the printer configuration page. I also tried on a work of the same model printer and cannot connect. I can't understand what I'm doing wrong. I type in xxx.xxx.xx.xxx in the address bar in Internet Explorer which is supposed to be an approved browser. Thank you!

    If the Web integrated printer server does not load when the IP address is entered, then means generally is not a direct path between the printer and the computer is trying to access.

    You mentioned that you must change the IP address.  What is the reason for this change?  The network IP addressing scheme changed so that the PC and the printer may appear as on different networks?

    I don't know if it will work in your particular situation, because it depends on whether or not it has access to an Ethernet connection.  You could try the connected printer to an Ethernet port which would be on the same network as the PC and then access it by IP addressed assigned to the Ethernet address.  Once the integrated Web server load, you can manually set the wifi information and then return to the wifi.

Maybe you are looking for