Assist , how do i allow hosts in inside segment to reach out segment and vice versa taking into account the security levels

ASA Version 7.0(8)
hostname BUJ-IT-ASA-LAN-2
domain-name leo.bi
enable password MgKXXPviZgW4zhKc encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
names
dns-guard
interface Ethernet0/0
description connects ucom lan
nameif inside
security-level 100
ip address 192.168.0.13 255.255.248.0
interface Ethernet0/1
description out interface
nameif outside
security-level 0
ip address 192.168.254.1 255.255.255.0
interface Ethernet0/2
shutdown
no nameif   
no security-level
no ip address
interface Ethernet0/3
shutdown
no nameif
no security-level
no ip address
interface Management0/0
shutdown
nameif management
security-level 100
ip address 192.168.1.1 255.255.255.0
management-only
ftp mode passive
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
pager lines 24
logging asdm informational
mtu management 1500
mtu inside 1500
mtu outside 1500
no failover
asdm image disk0:/asdm-508.bin
no asdm history enable
arp timeout 14400
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00
timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
username UcomIT password Tx95VR7l4gIiavnh encrypted
aaa authentication ssh console LOCAL
http server enable
http 192.168.1.0 255.255.255.0 management
http 192.168.0.0 255.255.248.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
telnet timeout 5
ssh 192.168.0.0 255.255.248.0 inside
ssh timeout 5
ssh version 2
console timeout 0
dhcpd address 192.168.1.2-192.168.1.254 management
dhcpd lease 3600
dhcpd ping_timeout 50
dhcpd enable management
class-map inspection_default
match default-inspection-traffic
policy-map global_policy
class inspection_default
  inspect dns maximum-length 512
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect esmtp
  inspect sqlnet
  inspect skinny
  inspect sunrpc
  inspect xdmcp
  inspect sip
  inspect netbios
  inspect tftp
  inspect icmp
service-policy global_policy global
Cryptochecksum:ba068a6f85d256ce9351d903c60873e5
: end

Hi,
Its success really depends on the rest of the network that I dont know about.
If you hosts that you are using to PING/ICMP through the ASA are connected to the same network as the ASAs interface then you will have to make sure that the hosts both have routes towards the other network.
Also if on the "outside" of the ASA there are additional networking devices then you have to configure default route on the ASA also as mentioned in the other discussion.
route outside 0.0.0.0 0.0.0.0
The above replys ACL was just an example of the configuration format. If you wanted to allow ICMP then you would also have to allow ICMP
access-list OUTSIDE-IN permit icmp 192.168.254.0 255.255.255.0 192.168.0.0 255.255.248.0 echo
I dont see anything else wrong with the ASA configuration related to ICMP other than possibly the lacking of default route and allowing the ICMP from the "outside" with the ACL "OUTSIDE-IN".
Go through the network setup from one host to the other. On each step confirm that that device has route towards both of the networks. Otherwise the devices will naturally not be able to forward the ICMP messages from end to end.
- Jouni

Similar Messages

  • How to change manual segment management to automatic? and vice versa

    how to change manual segment management to automatic? and vice versa
    i can't find any option for that in EM
    Thanks

    Paolo Marin,
    The original wants to change from Freelist management to Automatic Segment Space management - the URL you supplied is about converting from Dictionary Managed tablespaces (DMT) to Locally Managed tablespaces (LMT).
    In passing - the article you reference says: First, MAKE sure to take a full backup of the tablespace and all related tablespaces (inter-tablespace referential integrity) before running this procedure:. There's no such thing as 'tablespace referential integrity', but (a) it would be a good idea to make sure that no-one else is using the database whilst you do a conversion, and (b) it's the system tablespace that holds the data dictionary so that's the one other (really important) tablespace you have to back up before starting.
    There is a very old note about the limitations of doing the DMT -> LMT conversion here: http://www.jlcomp.demon.co.uk/book_8i/ch_08.html#Extent%20Management
    Regards
    Jonathan Lewis
    http://jonathanlewis.wordpress.com
    https://www.jlcomp.demon.co.uk

  • How do I get my iPad to show iMessages from my iPhone, and vice versa?

    My iPad used to show the same iMessages as on my iPhone, and vice versa...and now it doesn't.  I don't know whether it was an iOS upgrade that fouled it up or what, but I'd like to restore the convenience of seeing and responding to iMessages on either device.  They both send and receive iMessages, but one begun on one device does not appear on the other.
    Fred

    Using FaceTime http://support.apple.com/kb/ht4319
    Troubleshooting FaceTime http://support.apple.com/kb/TS3367
    The Complete Guide to FaceTime + iMessage: Setup, Use, and Troubleshooting
    http://tinyurl.com/a7odey8
    Troubleshooting FaceTime and iMessage activation
    http://support.apple.com/kb/TS4268
    Using FaceTime and iMessage behind a firewall
    http://support.apple.com/kb/HT4245
    iOS: About Messages
    http://support.apple.com/kb/HT3529
    Set up iMessage
    http://www.apple.com/ca/ios/messages/
    Troubleshooting Messages
    http://support.apple.com/kb/TS2755
    Troubleshooting iMessage Issues: Some Useful Tips You Should Try
    http://www.igeeksblog.com/troubleshooting-imessage-issues/
    Setting Up Multiple iOS Devices for iMessage and Facetime
    http://macmost.com/setting-up-multiple-ios-devices-for-messages-and-facetime.htm l
    FaceTime and iMessage not accepting Apple ID password
    http://www.ilounge.com/index.php/articles/comments/facetime-and-imessage-not-acc epting-apple-id-password/
    Unable to use FaceTime and iMessage with my apple ID
    https://discussions.apple.com/thread/4649373?tstart=90
    For non-Apple devices, check out the TextFree app https://itunes.apple.com/us/app/text-free-textfree-sms-real/id399355755?mt=8
    How to Send SMS from iPad
    http://www.iskysoft.com/apple-ipad/send-sms-from-ipad.html
     Cheers, Tom

  • How do I get iTunes on Windows to talk to my iphone and vice versa?

    Problems occurred after iTunes 1.11.4 update on my Windows 7 desktop..  I seem to be missing the Apple Mobile Devise Service and the USB driver.  I have meticulously followed the Apple support instructions for uninstalling and reinstalling iTunes to no avail.  In summary, I uninstalled the required Apple programs (note, AMDS was missing before the uninstalls), including icloud control panel and Tuneup.  I restarted.  I still had some remaining folders after restarting.  I deleted them and restarted.  I deleted the Temp folder under my User name/AppData/Local, and emptied the recycle bin.  I restarted my computer. I ran CCleaner Registry Cleaner and removed numerous Apple registry items.  I restarted my computer.  I downloaded the most recent iTunes 1.11.4.62, which was just released January 28th to fix the update issues.  I installed iTunes.  Everything seems to work in iTunes... the store, etc.. My iPhone 4s with the latest OS still does not connect/ is not recognized.  I get an unknown device in Device Manager still and AMDS still isn't present in the program control panel.  All other programs are there and seem to be working.
    Note... I started this process because I originally received error messages involving MSVCR80.dll being missing.  After my first try at reinstalling iTunes all messages went away but my iphone would not connect.  By the way, my wife has a desktop with Windows 7 and the same thing occurred.  I followed the Apple support suggestions and everything was fixed perfectly... her iphone now connects using AMDS and USB drivers were automatically installed.
    I have been working on this for more hours than I would like to admit.  Please Help.

    Update:  I performed a repair of the OS in place, sometimes called a Windows 7 no-reformat, nondestructive reinstall.  This took several hours, but my system was then fixed so I was able to follow Apple's iTunes reinstall procedure and bring iTunes/iPhone interface back to life.  This was my last resort and one should not start with a Windows 7 reinstall.  Problem solved and all programs and data remained in place.

  • How do I sync my event colors from treo 650 to iCal and vice versa?

    heres the deal:
    in using iCal and my Treo 650 (Verizon), I have been iSyncing the two together. While all the data and calendar events, contacts from Address book, tasks from task list transfer no problem, none of the event colors sync up. If an event from iCal is marked red, it moves to the Treo in "unfiled" gray. If the event is on the Treo and moves to the iCal, it is automatically shuffled under the default color code in the Options category.
    If the event is on both the Treo and iCal as red, and I edit the iCal version and then sync the two, it changes the Treo version back to "gray", even though both tools have the same color options and the same categorizations. although this sounds like a small glitch, I run a tour guiding business with multiple tour guides and the color coding is crucial to my PDA, so its driving me absolutely crazy. I bought my Treo with the promise that everything would sync up with the iCal, and it wont.
    What do I do?

    The behavior you describe is a characteristic limitation of the iSync Palm Conduit.
    The Missing Sync for Palm OS from Mark/Space supports categories and groups, and therefore—on advanced Palm OS devices like your Treo 650 smartphone—calendar colors. You can learn more about this application here:
    http://www.markspace.com/missingsync_palmos.php
    The Mark/Space Knowledge Base says this about categorization:
    Calendars and Categories
    • iCal events are assigned to a Palm category with the same name as the calendar they are part of. If the category does not exist on the Palm device, the Events conduit creates a category with the calendar name and assigns the event to that category. If that category cannot be added—due to space limitation—the event is added to Unfiled.
    • Palm events/tasks that are in a specific category are sent to that calendar in iCal only if a calendar with the same name as the category exists. If the calendar does not exist, the record will be sent to the calendar that is chosen in the conduit configuration sheet. If the calendar is read only, the event/task will be ignored.
    • On the first synchronization of read-only calendars, the items are properly assigned to the correct category on the device. If any edit is made to an item in a read-only calendar the change is ignored but will persist on the device until something forces it to be overwritten by data from the desktop, for example: if the read-only item was updated. If an item is assigned to a read-only calendar it will be switched to the calendar you have selected in your preferences.
    • Calendars listed in the conduit settings are pulled from Sync Services, meaning that if iCal has not finished synchronizing with Sync Services the full list of calendars may not be read.

  • Since the last iOS update, my calls come in on my phone and my wife's, and vice versa. How do I unlink them?

    I upgraded to the new IOS last week and since then anytime my wife and I are in the house at the same time, all our calls come in on both phones. My calls ring on her phone as well as mine, and vice versa. She has the 6 and I have the 4S. Not sure if that matters.
    I don't know how this happened, but how do we fix it?

    Settings > Facetime > Turn off Cellular Calls

  • On back up assistant, how do I adjust it not to back up my pictures, videos, and documents?

    On back up assistant, how do I adjust it not to back up my pictures, videos, and documents?
    The cloud back up keeps getting full because of these items, that I back up another way already...

        Joe.A.Rose
    Excellent question.  When you open the Verizon Cloud app you will see the menu option in the top left hand corner.  It consists of 4 vertical lines. Then you will select Settings and chose What to Backup. When it backs up the videos are you connected to wifi?
    EmmaM_VZW
    Follow us on Twitter @VZWsupport

  • How to sync my iPhone to my MacBook Pro and vice versa as it no longer seems to be doing?

    How to sync my iphone to my MacBook Pro and vice versa as it no longer seems to be doing? When I initially set up everything it worked fine; however, now my contacts are not syncing between devices?
    I have Icloud and even paid for ectra storage to see if this was the issue but it doesnt seems to be.  When I try and view devices on my itunes to sync it will not allow - blank option?
    If anyone could please help it would be really appreciated- thanks in advance:)

    I don't know how you got to your current position, but you might want to start by replacing your calendar with your MacBook Pro calendar if it is correct (if it isn't, skip this):  first disable calendar syncing on your phone (Settings>iCloud>Calendars set to OFF), then prior to syncing open iTunes on your computer and disable automatic syncing (under Preferences>Devices>Disable...from syncing automatically syncing).  Next connect your phone and set your sync settings on the Info tab to Syc Calendars with iCal, and below under Advanced choose "Replace Information on this iPhone" and check Calendars.  Now sync and this will hopefully replicate your MacBook calendar on your iPhone.
    Next, carefully review this to see that you have correctly set up iCloud on both your phone and your MacBook: http://www.apple.com/icloud/setup/, and that your meet the minimum system requirements (latest version of iOS on your phone, latest version of iTunes, OSX Lion 10.7.2 or later).

  • My family of four (2 iPhones, 2 iPods) all share the same iTunes account.  Many text messages sent to or from mine or my husband's phones are also received on my daughter's iPod, and vice versa. How do I fix this?

    How can I keep text messages sent from my or husband's phone from being received on daughter's iPod, and vice versa? We have five devices on one iTunes account - 2 iPhones, 2 iPods and an iPad.

    Hello Hrd1977,
    This is typically caused by both devices sharing an Apple ID for iMessage and FaceTime.  I would recommend signing out of iMessage on your daughter's device.  Go to Settings > Messages > Send & Receive, tap your Apple ID, and select Sign Out. Then sign in with the desired Apple ID.
    iOS: Troubleshooting FaceTime and iMessage activation
    http://support.apple.com/kb/TS4268
    Cheers,
    Allen

  • I recently purchased a book and according to my bank account the payment went through buy now when I try to download anything iTunes says there was a problem with my last purchase and won't let me download how do I fix this please?? Do I have to pay again

    I Recently purchased a book from iTunes and according to my bank account the payment was successfull but now when I try to sownload anything it says there was a payment issue with my last purchase! How do I fix this? Do I have to pay again??

    Contact the store support staff at: http://www.apple.com/emea/support/itunes/contact.html for help.

  • My nephew and I use the same iTunes account and when I add an app it is loaded on to his iPhone and vice versa... How do I make that stop?

    My nephew and I use the same iTunes account and when I add an app it is loaded on to his iPhone and vice versa... How do I make that stop? I have already unchecked the "Auto Update Apps" button. It happens with all purchases in the app store and on iTunes. HELP!

    I also think separate accounts is the way to go....if he is over 13yrs also remember if you do make an account for him and use your bank card all purchases will be charged to your card.

  • HT1766 Hi, I share an iTunes account with my wife. Sometimes she gets my iMessages and I don't and vice versa. Also if people face time me it goes to her phone. How can I stop this from happening?

    Hi, I share an iTunes account with my wife. Sometimes she gets my iMessages and I don't and vice versa. Also if people face time me it goes to her phone. How can I stop this from happening?

    You can share the same Apple ID in
    Settings > iTunes & App Store > Apple ID: here
    But for all other Apple services like:
    FaceTime, iMessage, iCloud, etc, one of you should use a different Apple ID.

  • How do I move an icon from the second page of my home screen to the first page  and vice versa?

    How do I move an icon from the second page of my home screen to the first page and vice versa?

    Hold an icon down until they all wiggle.
    Drag it wherever you want it.

  • For some reason when my daughter sends a text to someone else I get it and vice versa.  Also, when I send a text to her the text comes to me as well.  How do I stop this from happening?

    For some reason when my daughter sends a text to someone else I get it and vice versa.  Also, when I send a text to her the text comes to me as well.  How do I stop this from happening?

    This is iMessages, not an SMS/MMS, and this means the same Apple ID is registered for iMessage on each iPhone.
    You or your daughter need to activate your own Apple ID for iMessage and FaceTime. The same Apple ID can continue to be shared for iTunes store downloads - for music and apps.
    On the iPhone, go to Settings > Messages > Send & Receive.   Select the Apple ID at the top and sign out.   Sign in with the new Apple ID.
    Make sure the same email address is not available below You can be reached by iMessage at on each iPhone.

  • How to connect an non-hana-ewm with an Hana-ECC and vice versa

    Hello,
    for our migration project planning I am wondering how to connect EWM on SAP with ECC on Hana and vice versa.
    As it is, both systems are (productive) on non - hana with actual SAP-Release and have to be migrated.
    The background of my question: we may be not able do the "big bang" thing to migrate ERP ECC607 and EWM (with special Add-Ons) at one point to Hana (DMO) and therefore may need an interim solution. I checked ETL and LTS as "connectors" but they - from my point of view -  are one-way solutions from EWM to ECC/Hana -not bidirectional.I Found some questions concerning the same theme in the net but no solution at all till now..
    How about BODS ? (Didnt work with it yet)
    Best regards,
       Ronald

    Great. So I have to either install OS X, or buy a new mcahine. Can OS X run on a G3 without grinding to a halt?
    By the way, I cannot get the iPod to even mount when connected via firewire. The USB/firewire PCMCIA card does not have drivers for OS 9. I thought that this support was built into OS 9. The USB port works (although the iPod will not mount when connected via USB either). Any ideas?
    Thanks

Maybe you are looking for

  • How to handle sessions with two severs on one machine?

    All, I am having a problem with session cookies being overwritten when I host two apps on one machine running WebLogic 8.1 The apps are http://myserver:7300/app1 and http://myserver:7400/app2, and each runs in its own server. Users will often access

  • ISG does not send Access-Request to download service definition

    Hi guys,  I got these configs on my ISG and when I see the packets between AAA and ISG router, there's no access-request for downloading the service definition!  policy-map type control PPPoE_MAIN_POLICY  class type control always event session-start

  • Why are you not restoring previous session

    Up to a week or go tabs were restored - now they are not. I have followed all instructions. One problem - when I go to privacy options and select custom settings the next time I go there is is unselected. I want tabs restored. Please help

  • Bridge CS6 download function freezes.

    What is causing the Bridge download function in my CS 6 to freeze up?  Bridge in my CS 5 continues to work properly.  How to resolve?

  • HT1766 iPOD Apps to other PC for easy synch.

    I scare that i lose my paid programs, i can load free softwares again but i wont pay again thoes softwares what i already have paid.. So please tell me how i copy them to other computer.. Problem: I have been use to load my musics and softwares to iP