External ACL does not increment for traffic allowed through the site to site VPN

Hi all, we have many site - to IPSEC VPNS that are sending traffic to us successfully - the largest part of this traffic is FTP or SFTP.

There is not configuration of the firewall of the SAA sysopt. Access lists have been configured on the external interface of the ASA to allow these VPN for FTP SFTP connections & - however, all counters are 0 when I do a 'show access-list internet-in' for FTP or SFTP.

There are general IP entries in list of FTP & SFTP natted access connected to the Internet addresses of these FTP servers and these are increment but then there are certain customers who use the internet to transfer files.

I guess what I was asking is ASA outside increment for traffic access lists allowed by VPN? The access list entries are for THEIRINTERNALIP to OURINTERNALIP (according to crypto card)

Just to add that these ACL is configured through groups of objects in the case that matters - also once again that they are correctly transfer files to us - only I don't get where they are allowed.

Thanks in advance

Mark

VPN traffic is flowing properly and there is no ACL allowing UDP 500 or ESP?

Can you post the output of "sh run all the sysopt"

Federico.

Tags: Cisco Security

Similar Questions

  • My master password does not ask for connection and all the site view saved passwords.

    On one of my computers when I open firefox the master connection requires me to type my password has disappeared. But when I go to one of my sites that passwords are used as if I had. This means that anyone with access to this computer can access my secure sites. How can I fix it.

    Thank you

    Install the master password again. Then restart Firefox.
    Is always the problem?

    You can use the same password that you had.

  • I have problems with the shopify widget in Muse. I have configured my shopify store, but when I placed the button 'buy' is didn't tell the product no availabe longer and does not appear when I'm writing the site.

    I have problems with the shopify widget in Muse. I have configured my shopify store, but when I placed the button 'buy' is didn't tell the product no availabe longer and does not appear when I'm writing the site.

    Please contact the original publisher of the widget.

    Thank you

    Sanjit

  • Scanner does not work for all users on the computer Windows 7

    Photosmart 7510 Scanner does not work.  My scanner has the habit of work.   Now it does not for one of the three users on my Windows 7 desktop.

    I spent over 3 hours on the phone with HP.   They had me restart the computer, Plug and unplug the printer, reinstall the software twice under different names. The software depending on what user id, it is installed under allows access to the scanner/printer to one or more users.  The scanner works with Windows Paint software for all three nicknames.

    HP response is that some user control prevents the scanner software, who used to work on all three nicknames on the computer, which now works on one or more of the users.  They couldn't tell me which user control need changing.

    The HP solution is to restore my system when I could scan for all users of three.   I don't want to do that.   Does anyone have a better solution?

    The real problem is HP error messages.   When I click on scan a document, there is no answer.  Nothing happened.

    Then I tried to scan using Windows Fax and Scan.   I got an error message which helped me locate the source of the error.   I was able to fix the problem without creating a new user account.  I had deleted bu error the file MY Document.   Restore this file fixes the problem.

  • Beta 4 - Momentics IDE seized semiautomatic does not work for Qt classes in the newly created projects?

    After you have uninstalled the Beta 3 Momentics IDE und install the new beta 4, I noticed that the autocompletion of the IDE not working anymore for Qt classes when I create a new project from a template (empty or non-empty). It seems that the IDE cannot find the Qt header files:

    But I can compile the project without problems.

    When I import my old projects created with the Beta 3 of the autocompletion also works for Qt classes. When I compared to them, I noticed that the Makefiles have changed completely.

    Of course I could stay with my old project structure, but the Release Notes for the Beta 4 mention something about the changes in the Qt libraries, pre-compiled headers and so on who might require changes in Beta 3 projects. To avoid problems, I thought I could just create new projects in Beta 4 and re-import my source files for my Beta 3 projects. But I want to keep the autocompletition for Qt classes.

    I guess it's just a problem in files created automatically from the project. Is there a way to remedy?

    Thanks for your replies. The trick to rebuild the index was useful, but does not solve the problem in itself.

    But comparing all files in some of my old projects of Cascades generated in Beta 3 and newly generated in Beta 4, I found that in the Beta 4 project files .cproject, missing several tags that setting the include path for Qt for the IDE headers. Note, I'm not referring to the railways include the settings of the compiler here. Just autocompletion and also the analysis of the code in the IDE has not worked.

    In any case, to solve this problem, I found the following solution:

    There are four instances of these tags in the file .cproject of a Cascades (beta 4) project:

    
    

    Where NNNNN is a number randomly. When I change all these 4 cases to:

    
    

    .. .then they review as they did in the Beta 3 and then refresh the project or restart the IDE autocompletion all started working again for new projects of Beta 4. When I then invoke Index-> reconstruction such as recommended in the other thread also the analysis of the C++ code for the work of syntax errors and semantics again (if you have enabled in the IDE).

    I suppose that these lines could also be included in the model files somewhere in the NDK of BB installation folder, but I didn't fix files it.

    I have submitted a new question here:
    https://www.BlackBerry.com/jira/browse/BBTEN-466

  • Headset does not work for phone calls on the iPhone 6 s with update of iOS 10

    Is there a way to solve this problem

    Go to settings > Bluetooth and turn Bluetooth off then turn it back on.

    If this does not help, the pair of UN then re pair the headset > Set install and use third-party Bluetooth - Apple Support Accessories

  • Key 3 C often does not work for several minutes after the start, the other keys work fine.

    I got am HP Pavilion 17-e049wm Notebook PC product #E0J75UAR for about 4 weeks now.  I bought it refurbished.  A week ago I started having this problem.  3, e, d and c keys do not work when I first start the computer all of the other keys work.  Nothing happens when they are pressed.   Sometimes I will restart the computer and they work again, other times they won't, but often will start working if I left the computer set for about five minutes after the start.

    The computer is spotlessly clean.  I've only used a dozen times or more.  Nothing has been spilled on the keyboard.

    Sounds like software for me, but what?

    I am running Windows 8.1 and no programs are running at startup, with the exception of a program start button, but the problem began weeks after installing that.

    Any ideas?

    FWIW, I called hp. They believed excluded material and had me do a full system restore. Problem persists... The things you own end up owning you they say... I guess it's doubly true if you own a hp laptop. Full day turned... One day closer to death. Thanks Obama.

  • The Extract function does not work for work plans in the last update CC?

    The functionality of the extract stops when I have a PSD with work plans. Does anyone else have this problem?

    I am pleased to say that work plans are now supported in excerpt on the site of creative cloud. Let us know how to find you and if there is anything we can improve!

  • Site Flash does not update unless I click off the site!

    Site Flash does not update unless I click outside of the site and then again on the site!

    My Flash website presents to the user a list of customers to select

    When the user selects a customer of the user is presented with a full discription of the customer

    But when usage goes back to the screen containing all customers and selects another client, the previous client is displayed ' until I have click out of the site, click back on the site ", then the customer profile automatically updated! which is not what I want as I want the customer info to display when the user clicks in the list!

    I have worked on this issue now for 3 weeks so if someone has something to say help please help

    Well, after searching for a month and thinking maybe flex was not capable for dynamic web sites, that I decided to start over with my search

    Turns out that the answer was really simple way just had to clear my mind and think about

    protected function itemrenderer1_mouseOverHandler(event:MouseEvent):void

    {

    Main.ClientData.ClientsID = clientIdNumber.text;

    ScrollPanelSkinClientScrollingContentSkin.getClientResult.token = ScrollPanelSkinClientScrollingContentSkin.customerService.getClient (Main.ClientData.Clien, tID);

    trace ("Trace one113" + Main.ClientData.ClientID);

    }

    As all ways, stupid I feel

  • Baffled: Remote Site is does not display pages, no update of the site?

    I'm totally baffled by Dreamweaver for a few days now. I can have a button somewhere, but here's what seems to happen:

    My site is online and all pages work online, but out of 1200 pages or if Dreamweaver only 80-90 pages on the server seesn remote. I did a "refresh all folders" on the server remote, all the image files are there, but I only see the same 80-90 html pages. There should be more than 1200 pages.

    I also looked on the site and created a new site and the folder. Same question.

    I checked the local site, everything is there, and Dreamweaver can clearly see all the.

    If I do a page edit and upload to the server, the change appears not live on the site

    BUT if I make a change to a page, it does not appear on the server. I have to go find the page on the remote server, and then download the remote page using DW, what changes is displayed correctly. But this is not live on the website.

    Everything is just too fast, usually when I download a page of 100K, it takes a second or two as DW did his thing FTP. Now it flashes only files to download for a nanosecond, I know DW says its download, but is apparently not.

    Or something on the side server is a problem, I can understand someday, but I'm now on day 3 with this question.

    DW4, Vista 64

    If you have solved the problem please mark this thread as answered, just let people know.

    http://www.helpvid.NET

  • Firefox does not work for multiple instances of the SAME user account on Windows Multipoint Server 2011

    We have a PC HP of MulitSeat MS6200
    It runs Microsoft Windows MultiPoint Server 2011 (which seems to be a twisted version of Windows 7)
    It is implemented in a laboratory of computer science and students connect you using their account for shared room - IE multiple instances of the same user accounts are currently running on the PC at the same time.
    The first student to run Firefox can work with it without a problem.
    However, when another student try to start firefox they get the following message:
    Firefox is already running but is not responding. To open a new window, you must first close the existing Firefox process, or restart your system.

    Cannot start Firefox using a profile that is already used by someone else.
    Each Firefox instance needs its own profile or you will get this error message.

    Use-no.-line switch remote control to open another instance of Firefox with its own profile and to different instances of Firefox running concurrently.

  • My application does not work for two days after the update

    ITI has been two days now my app is not workog knowing that I paid for a membership year after that I did the update it please help

    We will post updates on the installation of revel problem in the following thread:

    Problem installing Adobe Revel 2.3.2

  • Join does not work for NULL values on the join condition

    Hello

    I have the following problem.

    SQL > select * from a;

    X Y
    ---------- --------------------
    1
    2
    3
    4

    SQL > select * from b;

    A:
    ---------- --------------------
    1
    2



    SQL > select f.x, f.y, s.b in f, s b
    2 where f.x = s.b (+);
    X Y B
    ---------- -------------------- ----------
    1 1
    2 2
    4
    3




    SQL > select f.x, f.y, s.b in f, s b
    2 where f.x = s.b (+)
    3 and f.y = s.y;

    no selected line


    So now if I include a join condition more where null = null situation arises, it's working now.
    Just tell her not to treat (1 and null) (1 and null) are the same.
    What is the solution. This is an expected behavior.


    Thank you
    Pramod Garre

    Pramod salvation,

    Another way to use the outer join is,

    Select f.x, f.y, s.b
    of a, f, s b
    where f.x = s.b (+)
    and nvl(f.y,0) = nvl (s.y (+), 0);

    Hope this will help you.

    Thank you
    Amit

  • Delete record behavior does not wait for the "submit" button

    I have master / detail pages as a whole.  Of all the detail, there are links to delete or update a record.  When I click the link to delete the folder, it goes to the confirmation page with the correct record.  Now, when I add the behavior delete record server and a button "submit", it is what is happening.  As soon as I click on the link to access the Delete Confirm page, deletes the record and the page redirects to the page that I put in the server behavior.  It does not display the confirmation page and does not wait for me to hit the button confirm.  The page runs and removes the page from the database.

    How can I get to wait until I hit the submit button?

    You must surround your request deletion with an "If" statement seeking a confirmation variable, then when the user clicks the confirmation link, you can pass the necessary variable and the ID of the record that the delete request is pregnant.

    As an alternative, you can use a JS alert fuction to ask if they are sure they want to delete the folder, and then delet allwo runs after confirmation to the user. To do this, you can use code like this...


    onclick = "return ('are you SURE you want to DELETE this record? confirm")">

    --
    Lawrence * Adobe Community Expert *.
    www.Cartweaver.com
    All Shopping Cart Application for
    Dreamweaver, available in ASP, PHP and CF
    www.twitter.com/LawrenceCramer

  • PowerConnect 6200 ACL does not seem to work

    Hello

    I have a total of four 6248 s two groups at different locations that are configured with VRRP + OSPF.  I tried to set up a simple ACL on either a VLAN to allow a portion of the traffic and block everything else, but I can't make it work.  I have tried many combinations to try to get this working, but so far without success.  It's just a simple ACL, which should allow the web/http traffic on the 10.1.30.100 server and blocks everything else.

    The only type of ACE that seem to work are either a "deny ip any any" or "permit ip any any" If you try an ACE with a destination host and subnet mask 0.0.0.0 it's just all this blocking.  Has anyone else had problems of the ACL or is it just my incompetence in preventing me from getting the 6200 ACL work properly?  I didn't have this problem, get the ACL list to work on our Cisco 2811 routers, just at the moment where I tried on the PC6248s.

    1. config
    2. int vlan 720
    3. no ip-group vlan720-in in access
    4. output
    5. No list of access-vlan720-en
    6. access-list vlan720-in permit tcp any 10.1.30.100 0.0.0.0 eq 80
    7. int vlan 720
    8. IP access-group vlan720-in in
    9. output
    10. output
    11. copy, run start
    12. There

    Just an update on this issue.  I worked with Dell to determine why the ACL does not seem to work.  We discovered that the 6200 apply ACL to the traffic as a VLAN ACL Cisco card as opposed to a router ACL entry.  This causes the ACL to apply to not only routed or transferred but also traffic switched in the same VLAN.

    This has been the source of my problems that my traffic is not limited to a single 6200.  I developed a simple laboratory to check that the 6200 applied traffic switched in the same VLAN ACL.

    First the 6200 has one ACL applied to VLAN5 both PC1 and PC2 are in VLAN 5.  They are both on the same subnet 192.168.5.0/24.  The ACL has a statement of "permit icmp any one" but nothing else.  The PC1 and PC2 are running Windows XP Pro with IIS is installed for the test.  The firewall on both is disabled.

    PC #1 IP: 192.168.5.2/24
    PC #2 IP: 192.168.5.3/24

    [6200]
    |    |
    |    |
    |   [2950T #2] <-->[PC #2]
    |
    |
    [2950T #1] <-->[PC #1]

    In this scenario PC1 and PC2 can ping each other without problem because of the permit icmp any any statement, but you cannot access the IIS site on each of the other computers.

    Dell said that this is normal and if you want communication VLAN VLAN you 'license ip ' to make it work properly.  I also found that traffic back from other VLANs were also denied because of the ACL applied on all of the incoming traffic.  As a solution, the license statement should be included for ALL traffic back to the limited subnet other subnets.  So in this case "ip enable any ".

    I find it a bit annoying that ACL is applied in the form of maps of VLAN not like real incoming router ACL as they are on similar Cisco devices as the 3750.  So there is a work around.  I hope they can solve the problem in a future update, because I really think that the 6200 is a great device.

    Here you can see the difference between VLAN ACLs cards and router entry ACL where they are applied in what concerns local traffic to VLAN.
    http://www.Cisco.com/en/us/docs/switches/LAN/catalyst3750/software/release/12.2_25_see/configuration/guide/swacl.html#wp1572522

Maybe you are looking for

  • Tecra A4: coursor jumps while typing

    When you type on the keyboard, with no indication, the slider repositions to somewhere else. As I am a touch typist and not look at the keyboard or screen, it can cause me some problems of approximate return. Does anyone know a fix for this problem,

  • Where there is a way to make an image as a projection?

    I will be shooting my main character in front of a white wall. Is there a way to take some pictures and make it look like its projected on the wall behind the actor? I tried google search with keywords but not found anything useful. Has anyone tried

  • Satellite Pro A120: Keyboard permanently press down

    As soon as I start my laptop it automatically supports a reason any. The only way I can stop it is by pressing the tab key, and then it stops temporarily. But as soon as you press an arrow key that it is to the top, bottom, left or right the problem

  • Cannot update iTunes after the upgrade to Windows 10

    Any attempt to upgrade and/or uninstall to start a completely new download, which brings me to this error message: "the component you are trying to use is on a network unavailable resource. '" It seems that it does not find the iTunes files. Microsof

  • Camera memory card will not show a menu

    Hello, my computer is now not letting me store or even to open images from my camera or my daughters. We have all two nikon cameras. I used to get a menu asking me what I would do and what I wanted to use programs. I assume that it it the menu box. N