<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for jklogic.net</title>
	<atom:link href="http://jklogic.net/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://jklogic.net</link>
	<description>logical reality</description>
	<lastBuildDate>Thu, 29 Apr 2010 12:15:20 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Unable to download NAT policy for ACE by David</title>
		<link>http://jklogic.net/unable-to-download-nat-policy-for-ace/comment-page-1/#comment-3527</link>
		<dc:creator>David</dc:creator>
		<pubDate>Thu, 29 Apr 2010 12:15:20 +0000</pubDate>
		<guid isPermaLink="false">http://jklogic.net/unable-to-download-nat-policy-for-ace/#comment-3527</guid>
		<description>Thanks for the tip.
Fixed my NAT issue 8.2(1)- wish saw this post yesterday</description>
		<content:encoded><![CDATA[<p>Thanks for the tip.<br />
Fixed my NAT issue 8.2(1)- wish saw this post yesterday</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cisco ASA and ICMP Configurations by Abhishek Paul</title>
		<link>http://jklogic.net/cisco-asa-and-icmp-configurations/comment-page-2/#comment-3495</link>
		<dc:creator>Abhishek Paul</dc:creator>
		<pubDate>Tue, 20 Apr 2010 15:32:29 +0000</pubDate>
		<guid isPermaLink="false">http://jklogic.net/cisco-asa-and-icmp-configurations/#comment-3495</guid>
		<description>Hi James 

I built my internal web application be accessible from the Internet using a Public IP, and it works, I can see the web site from Internet using the Public IP, But I can not use the same public IP to connect to the site from inside. How can I use the public IP even from inside?

Same problem for Ping, the  ping command works from outside but not from inside.

I am using an ASA 5510.

Thanks a lot in advance.

Abhishek</description>
		<content:encoded><![CDATA[<p>Hi James </p>
<p>I built my internal web application be accessible from the Internet using a Public IP, and it works, I can see the web site from Internet using the Public IP, But I can not use the same public IP to connect to the site from inside. How can I use the public IP even from inside?</p>
<p>Same problem for Ping, the  ping command works from outside but not from inside.</p>
<p>I am using an ASA 5510.</p>
<p>Thanks a lot in advance.</p>
<p>Abhishek</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cisco ASA and ICMP Configurations by Ryan</title>
		<link>http://jklogic.net/cisco-asa-and-icmp-configurations/comment-page-2/#comment-3251</link>
		<dc:creator>Ryan</dc:creator>
		<pubDate>Tue, 09 Mar 2010 02:16:37 +0000</pubDate>
		<guid isPermaLink="false">http://jklogic.net/cisco-asa-and-icmp-configurations/#comment-3251</guid>
		<description>Hi James,

Thanks for a great post!  I&#039;m trying to follow option 3 from your original post.  I&#039;ve got an ASA 5505 ASA Version 8.2(1).  I&#039;ve looked at the global_policy and icmp/icmp error are already defined as inspected traffic types, but traceroute does not work (ping works fine).  Here is a snippet from my config.

policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map dynamic-filter-snoop 
  inspect esmtp 
  inspect ftp 
  inspect h323 h225 
  inspect h323 ras 
  inspect icmp 
  inspect icmp error 
  inspect netbios 
  inspect pptp 
  inspect rsh 
  inspect rtsp 
  inspect sip  
  inspect skinny  
  inspect sqlnet 
  inspect sunrpc 
  inspect tftp 
  inspect xdmcp 

Do I still need to enable the ACLs mentioned in option 1 because although ping was working fine, traceroute was not.  Was there another step that I am missing.  I&#039;m using the ASDM.

Thanks.</description>
		<content:encoded><![CDATA[<p>Hi James,</p>
<p>Thanks for a great post!  I&#8217;m trying to follow option 3 from your original post.  I&#8217;ve got an ASA 5505 ASA Version 8.2(1).  I&#8217;ve looked at the global_policy and icmp/icmp error are already defined as inspected traffic types, but traceroute does not work (ping works fine).  Here is a snippet from my config.</p>
<p>policy-map global_policy<br />
 class inspection_default<br />
  inspect dns preset_dns_map dynamic-filter-snoop<br />
  inspect esmtp<br />
  inspect ftp<br />
  inspect h323 h225<br />
  inspect h323 ras<br />
  inspect icmp<br />
  inspect icmp error<br />
  inspect netbios<br />
  inspect pptp<br />
  inspect rsh<br />
  inspect rtsp<br />
  inspect sip<br />
  inspect skinny<br />
  inspect sqlnet<br />
  inspect sunrpc<br />
  inspect tftp<br />
  inspect xdmcp </p>
<p>Do I still need to enable the ACLs mentioned in option 1 because although ping was working fine, traceroute was not.  Was there another step that I am missing.  I&#8217;m using the ASDM.</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cisco ASA and ICMP Configurations by G-man</title>
		<link>http://jklogic.net/cisco-asa-and-icmp-configurations/comment-page-2/#comment-3206</link>
		<dc:creator>G-man</dc:creator>
		<pubDate>Thu, 25 Feb 2010 17:32:16 +0000</pubDate>
		<guid isPermaLink="false">http://jklogic.net/cisco-asa-and-icmp-configurations/#comment-3206</guid>
		<description>Hi James,

   I&#039;m having an issue.  I have a Cisco ASA 5510 and I can ping the inside our network and I can ping from outside to in.  However I cannot ping from inside to my outside interface.  Any suggestions?</description>
		<content:encoded><![CDATA[<p>Hi James,</p>
<p>   I&#8217;m having an issue.  I have a Cisco ASA 5510 and I can ping the inside our network and I can ping from outside to in.  However I cannot ping from inside to my outside interface.  Any suggestions?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cisco ASA and ICMP Configurations by Adam</title>
		<link>http://jklogic.net/cisco-asa-and-icmp-configurations/comment-page-2/#comment-3205</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Thu, 25 Feb 2010 02:25:13 +0000</pubDate>
		<guid isPermaLink="false">http://jklogic.net/cisco-asa-and-icmp-configurations/#comment-3205</guid>
		<description>James,

I&#039;m having an issue.  local hosts that use our Global Dynamic NAT to reach outside hosts can not run traceroutes (i can see the hops on LAN between host and ASA, but nothing outside of ASA.  These same Static NAT hosts can not access remote (outside) TFTP servers.  

However, a static NAT LAN host can successfully run traceroutes and access TFTP servers.

Other services like http, etc are working perfectly fine regardless of the type of NAT used.  Any help would be appreciated.</description>
		<content:encoded><![CDATA[<p>James,</p>
<p>I&#8217;m having an issue.  local hosts that use our Global Dynamic NAT to reach outside hosts can not run traceroutes (i can see the hops on LAN between host and ASA, but nothing outside of ASA.  These same Static NAT hosts can not access remote (outside) TFTP servers.  </p>
<p>However, a static NAT LAN host can successfully run traceroutes and access TFTP servers.</p>
<p>Other services like http, etc are working perfectly fine regardless of the type of NAT used.  Any help would be appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cisco ASA iPhone VPN Config by Kablooie</title>
		<link>http://jklogic.net/cisco-asa-iphone-vpn-config/comment-page-1/#comment-3134</link>
		<dc:creator>Kablooie</dc:creator>
		<pubDate>Thu, 11 Feb 2010 19:17:51 +0000</pubDate>
		<guid isPermaLink="false">http://jklogic.net/?p=23#comment-3134</guid>
		<description>I have no problems with a similar conf on my asa5510 except the internal dns lookup does not work.</description>
		<content:encoded><![CDATA[<p>I have no problems with a similar conf on my asa5510 except the internal dns lookup does not work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cisco ASA and ICMP Configurations by Charlie</title>
		<link>http://jklogic.net/cisco-asa-and-icmp-configurations/comment-page-2/#comment-3131</link>
		<dc:creator>Charlie</dc:creator>
		<pubDate>Tue, 09 Feb 2010 02:33:22 +0000</pubDate>
		<guid isPermaLink="false">http://jklogic.net/cisco-asa-and-icmp-configurations/#comment-3131</guid>
		<description>Thanks James.</description>
		<content:encoded><![CDATA[<p>Thanks James.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Unable to download NAT policy for ACE by DC</title>
		<link>http://jklogic.net/unable-to-download-nat-policy-for-ace/comment-page-1/#comment-3122</link>
		<dc:creator>DC</dc:creator>
		<pubDate>Fri, 05 Feb 2010 21:06:12 +0000</pubDate>
		<guid isPermaLink="false">http://jklogic.net/unable-to-download-nat-policy-for-ace/#comment-3122</guid>
		<description>Confirmed, happens to me on 8.2(1) as well.

Thanks for this great tip, really saves a lot of trouble (and some downtime) by not having to do a reload.</description>
		<content:encoded><![CDATA[<p>Confirmed, happens to me on 8.2(1) as well.</p>
<p>Thanks for this great tip, really saves a lot of trouble (and some downtime) by not having to do a reload.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cisco ASA and ICMP Configurations by James</title>
		<link>http://jklogic.net/cisco-asa-and-icmp-configurations/comment-page-2/#comment-3119</link>
		<dc:creator>James</dc:creator>
		<pubDate>Thu, 04 Feb 2010 18:54:12 +0000</pubDate>
		<guid isPermaLink="false">http://jklogic.net/cisco-asa-and-icmp-configurations/#comment-3119</guid>
		<description>Charlie,

This is the normal operation for the ASA.  You will not be able to ping the DMZ or Outside interface from and inside host.</description>
		<content:encoded><![CDATA[<p>Charlie,</p>
<p>This is the normal operation for the ASA.  You will not be able to ping the DMZ or Outside interface from and inside host.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Cisco ASA iPhone VPN Config by Magnus</title>
		<link>http://jklogic.net/cisco-asa-iphone-vpn-config/comment-page-1/#comment-3111</link>
		<dc:creator>Magnus</dc:creator>
		<pubDate>Sat, 30 Jan 2010 22:15:33 +0000</pubDate>
		<guid isPermaLink="false">http://jklogic.net/?p=23#comment-3111</guid>
		<description>Nope didn&#039;t work, but a nice initiative.</description>
		<content:encoded><![CDATA[<p>Nope didn&#8217;t work, but a nice initiative.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
