<?xml version="1.0" encoding="koi8-r"?>
<rss version="0.91">
<channel>
    <title>OpenForum RSS: Cisco ASA 5540 Drop на NATe из outside в inside</title>
    <link>https://opennet.ru/openforum/vsluhforumID6/17992.html</link>
    <description>Добрый день. Помогите. Не могу пустить трафик из outside в inside. &lt;br&gt;&lt;br&gt;ASA Version 7.2(1) &lt;br&gt;!&lt;br&gt;hostname ciscoasa&lt;br&gt;domain-name xxx.ru&lt;br&gt;enable password J3QefryiQ9zlWmPY encrypted&lt;br&gt;names&lt;br&gt;dns-guard&lt;br&gt;!&lt;br&gt;interface GigabitEthernet0/0&lt;br&gt; nameif outside&lt;br&gt; security-level 0&lt;br&gt; ip address x.x.12.162 255.255.255.248 &lt;br&gt;!&lt;br&gt;interface GigabitEthernet0/1&lt;br&gt; nameif inside&lt;br&gt; security-level 100&lt;br&gt; ip address 10.2.1.254 255.255.255.0 &lt;br&gt;!&lt;br&gt;interface GigabitEthernet0/2&lt;br&gt; shutdown&lt;br&gt; nameif dmz&lt;br&gt; security-level 50&lt;br&gt; no ip address&lt;br&gt;!  &lt;br&gt;interface GigabitEthernet0/3&lt;br&gt; shutdown&lt;br&gt; nameif backup&lt;br&gt; security-level 0&lt;br&gt; no ip address&lt;br&gt;!&lt;br&gt;interface Management0/0&lt;br&gt; shutdown&lt;br&gt; no nameif&lt;br&gt; no security-level&lt;br&gt; no ip address&lt;br&gt; management-only&lt;br&gt;!&lt;br&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;br&gt;boot system disk1:/asa721-k8.bin&lt;br&gt;ftp mode passive&lt;br&gt;dns server-group DefaultDNS&lt;br&gt; domain-name xxx.ru&lt;br&gt;&lt;br&gt;object-group network local-net&lt;br&gt; network-object 10.2.3.0 255.255.255.0&lt;br&gt; network-object 10.2.6.0 255.255.255.0&lt;br&gt; network-object 10.2.7.0 255.255.255.0&lt;br&gt; network-object 10.2</description>

<item>
    <title>Cisco ASA 5540 Drop на NATe из outside в inside (Юрий)</title>
    <link>https://opennet.ru/openforum/vsluhforumID6/17992.html#2</link>
    <pubDate>Fri, 16 Jan 2009 12:21:00 GMT</pubDate>
    <description>Отключи nat-control&lt;br&gt;</description>
</item>

<item>
    <title>Cisco ASA 5540 Drop на NATe из outside в inside (ilya)</title>
    <link>https://opennet.ru/openforum/vsluhforumID6/17992.html#1</link>
    <pubDate>Tue, 13 Jan 2009 07:21:12 GMT</pubDate>
    <description>может быть в асл out надо указать не адрес из сети 10.0 о которой никто не знает, а адрес из статики? x.x.12.164 &lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;gt;&#091;оверквотинг удален&#093;&lt;br&gt;&amp;gt;input-line-status: up &lt;br&gt;&amp;gt;output-interface: inside &lt;br&gt;&amp;gt;output-status: up &lt;br&gt;&amp;gt;output-line-status: up &lt;br&gt;&amp;gt;Action: drop &lt;br&gt;&amp;gt;Drop-reason: (acl-drop) Flow is denied by configured rule &lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;&lt;br&gt;&amp;gt;&lt;br&gt;&lt;br&gt;</description>
</item>

</channel>
</rss>
