Costum service traffic inspection

Hi,
I need to do costum service traffic inspection to a SQL server inside interface communicate with the dmz interface server.
I need INSIDE useres access(http/https and other site in port 100) my web server(DMZ) which have a service that accesses the SQL server to autheticate in port  tcp 1433 and the SQL server responde in a dynamic port.
How can I inspect this traffic do this maintaing the default inspection to the inside interface?
Kind Regards,
AS

Hi,
You say that the following happen in your case
Internal host contacts DMZ server
DMZ server initiates connection to Internal server
Internal server initiates connection to DMZ server
I can't comment much on how the actual Web server and SQL server operate but the connections formed between them should be possible by simply making sure that the ACLs allow the traffic and there is nothing else preventing these connections from forming on the firewall.
I am not sure though why the Web server forms a connection to the SQL server and then the SQL server opens a new connection to the Web server?
What is the device you are using as a firewall? Is it a Cisco ASA5505 perhaps? On ASA5505 having only Base License would mean that you would be allowed to have only 3 Vlans one of which would be limited from connecting to one of the 2 other Vlans with the command "no forward interface interface Vlanx"
If you are using ASA5505 then the above thing might be preventing the DMZ from contacting the Internal network. But its a bit far fetched but thought I'd point it out.
I dont think you can use the MPF on the ASA to affect what is allowed between your 2 different network segments. To my understanding it is used to modify already allowed connections like changing timeouts and connection limits.
If you have problem with connectivity between different ASA firewall interfaces I would suggest first opening up the ASDM monitoring view with appropriate logging level and then attempting these connections and see what is failing according to the logs.
- Jouni

Similar Messages

  • Open Box Warranty Issues and Poor Lenovo Malaysia Costumer Service

    Dear Sir,
    My name is Azri. I just bought a new free DOS Lenovo G400S from your authorize dealer in penang on 31th March 2014 around 6pm. Since  the unit was a free dos unit, I just brought that laptop home without opening the box for inspection due to the shop will close at 7pm. Upon arriving at my house I unbox the unit to install the OS. On first start, I notice there was an obvious one big death pixel underneath of LENOVO logo. Since it was free dos, I thought it might be the dos issues, so I boot it with linux live CD. After finish booting, I do several test and notice that the dot is really a death pixel. I pack it up and brought back to authorize dealer on 1st of April. Authorize dealer are keen to replace one to one to me as this is open box issues. How ever they need the clearance from lenovo penang for that. I leave that faulty unit with their RMA department and follow up the next day via phone. Upon follow up they inform me that Lenovo penang request the unit to be evaluate at their center. I had to wait for a few days.  On friday the authorize dealer call me and inform that the conclusion will be given by lenovo penang by monday. On Monday I went to authorize dealer again to ask for status. Again lenovo penang decline to give statement. Frustrated I called them  and after a while they inform me that my claim was rejected due to insufficient  number of death pixel. I really frustrated with lenovo service. I never use that unit and the screen already faulty when I open the box.I  hope you could resolve my problem as this unit is my costumer unit. This problem had tarnish the image of Lenovo as your unit with QC passed mark actually don't pass the mark.
    Below are details of the product with attached information:
    Product Model: Lenovo Ideapad G400s
    Serial Number: 1S59392001CBxxxxxxxx
    Date of purchase: 31th March 2014 at 6.00pm
    Date return to reseller: 1 April 2014 at 1.00pm
    Lenovo Penang service report number: 252130 (D014-052)
    I went to penang service center and explain my situation. They just asked me to call Lenovo Malaysia to get the authorization for them. So I call Lenovo malaysia on every single day since then. After long arguing they only gave me the reference number that is:
    SR : 8002963510 **MYR**
    Even though I call the Lenovo Malaysia on every single day, they keep on giving excuse and the agent seem don't know or notified about my problem. When i push them harder they rejected my request for LCD replacement by qouting the US site Term and condition.
    I got angry and scold them by comparing their service againts other company such HP. After that they escalate my case to their supervisor. Still after almost a month they didnt want to replace the faulty LCD, They keep delaying the answer to replace my faulty LCD. I dont know where to complain anymore. Plese lenovo help me. I was a victim of your poor support and costumer service. How do you dare to put the QC passed sticker on your machine while your machine are faulty.
    Please help me lenovo International. This is machine information.
    Type & Model:Lenovo Ideapad G400s(59392001)
    Serial number:CBxxxxxxxx
    Monitor type/SL# (if it is a monitor pbm):-
    Problem Details:Blue Dot(Dead Pixel)Center Of The Display 
    Service Providers Nameith Computer Sdn Bhd
    Remarks if anyOA Claim(One to one exchange or LCD replacement)
    Machine  Information
    Serial Number :    Idea CBxxxxxxxx (e.g: Think RX-12345 & Idea EB12345678)
    Machine Type :       Idea G400s   (e.g: Think 0829-AB1 & Idea Z450)
    Problem Description : Blue Dot(Deal Pixel)Center Of The Display   (e.g: Machine
    I Hope you all could replace the unit as soon as possible as i need to send to costumer and costumer already piss off with me. If this thing unresolve, I shall take this case to court for reimbursement.
    Thanks in Advance,
    Azri
    Moderator Note; s/n edited

    Also forgot to add, but it cannot be very hard for Lenovo to send me a black/purple hairline cover for the laptop. Surely they can be taken off and put on somewhat easily.

  • Using JAX-RPC handlers to proxy web service traffic

    Hi,
    I want to use JAX-RPC handlers to proxy web service traffic. In some instances the handler should modifiy / verify the message before forwarding the request to the remote web service end-point. Hence, the handler should forward the call by invoking the remote web service. In some cases the result from invoking the remove service should be post-processed by another proxy handler. To ensure that the result from invoking the remote service is available for post-processing I assume that the handler invoking the remote service must add the response message to the message context ( e g setProperty method) in the handler. Is this correctly understood?
    I would like to understand that this is a technically feasible and reasonable approach of using JAX-RPC. I'd really appreciate some feedback here.
    Many thanks,
    Tom

    Hi Eric,
    Thanks for your response. we are trying to access WSRR( manages end point urls for 7 different environments) and generate the end point dynamically at the design time. As we figured out WSRR is not compatible with OSB we are trying to implement these client side (OSB Proxy service) handlers which would get the dynamic endpoint depending on the environment used. I was able to create the handlers for this and set the jar in the classpath but the client service which should be using these handlers have to have these handlers defined in the deployment descriptor(web.xml) which am unable to see with a OSB project.
    Will there be a deployment descriptor(web.xml/webservices.xml) associated with Proxy services on OSB? Or Is there any other way to add custom JAX-RPC Handlers to a proxy service? Or is there any way to connect to WSRR directly?
    Thanks,
    Swetha

  • Security Deposit - Horrible Costumer service

    Let me tell about my horrible story in with verizon Service.
    I have taken verizon triple play two year plan and cancelled my service within 1 month of satisfaction period and it has been two months and i have not recieved my security deposit i have paid.  i have been contacting the costumer service departments and been transferred one to other departments from months on and nothing has happend. 
    Did anyone faced the similar issues?

    Hello oneselfdenied-
    I apologize for the lateness of this reply; we have been extremely backlogged through the holidays and are trying to get caught up.  I can certainly understand your frustration at being on hold with our Destin, FL store for so long, only to be hung up on.  Once is bad enough, but for it to happen a second time would certainly have my blood boiling.
    While the stores can definitely be extremely busy at times, we do expect our stores to make every effort to answer their phones in a timely manner.  I sincerely apologize that this was not your experience and I will be providing this feedback to the stores upper management for their review.
    If I may make a suggestion for the future, you do also have the option to check BestBuy.com for product availability at a specific store and may even be able to place an order for in-store pickup to ensure that you have it ready to go for you when you get to the store.  This may help you avoid some of this potential frustration with any future items you wish to check the availability on in our stores.
    I hope that this helps and thanks for posting!
    Bill|Senior Social Media Specialist | Best Buy® Corporate
     Private Message

  • I have an iPhone 5 unlocked. I have been using it for few weeks but 4 days ago I turned it off and in the morning it had NoService. Called tmobile and apple costumer services no one helped. Did any one had this issue and solved it?

    I have an iPhone 5 unlocked. I have been using it for few weeks but 4 days ago I turned it off and in the morning it had NoService. Called tmobile and apple costumer services no one helped. Did any one had this issue

    If you got the Unlocked message it means it was successfully unlocked by AT&T.  Apple will not relock or block it.  They have no objections to it being used on T-Mobile.  It is still under warrantee.  Take to an Apple store.  They can test it with a SIM from AT&T.  If that doesn't work have them replace the phone.  Have them verify that the new phone is unlocked.  If it does work with the AT&T card then it is a T_Mobile problem.

  • Why am being charged when i didnt even have a spotify account. I need costumer service.

    Im having trouble getting a hold of costumer service. I had to sign up this app just to find help. Im getting charged over $300 when i dont even own this app. I need to get my money refund asap.This is **bleep**en stupid. All in one day. I didnt even know what the **bleep** was this app till now. I need costumer service. Somebody needs to refund my money.

    Hello.
    Please contact customer support.
    https://www.spotify.com/about-us/contact/contact-spotify-support/?contact
    or Twitter
    If support replies you to check community for a solution or if you received your case number (#XXXXXXXX), please reply back even if there is "no reply" tag and tell that you still need help. If your inbox is empty please check spam.
    Support usually replies within 24-48 hours.

  • HT4061 How do you unlock your AppStore Lock, seriously this is bugging me because the App Store costumer service is down , APPLE HELP ME!!!

    How do you unlock your AppStore Lock, seriously this is bugging me because the App Store costumer service is down , APPLE HELP ME!!!

    You posted in the iPad forum instead of the iPhone forum. To get answers to your question, next time post in the proper forum. See https://discussions.apple.com/index.jspa  I'll request that Apple relocate your post.
     Cheers, Tom

  • How do I send an email to apple costumer service?

    how do I send an email to apple costumer service?

    Apple
    1 Infinite Loop
    Cupertino, CA 95014
    Write to that address.

  • Nokai costumer service

    I have called the Nokai costumer service in USA and had a bad experience. who is the next level up that I can talk to?
    the manager told me that there are no hire levels.
    Solved!
    Go to Solution.

    You need to stop trying to speak to people, and write a formal letter to Nokia's nearest corporate head office (either Texas or New York).
    http://www.nokia.com/A4126577
    Include the two managers' names.
    Be professional, polite and diplomatic if you want to achieve a favourable result.

  • Costumer service

    What is the costumer service number

    Dear All,
    Here is the link to use to contact Skype Customer Service: contact customer service
    Copied from the website page:
    Skype offers help and support through:
    The Skype Support website
    The Support Network
    The Heartbeat blog
    Skype blogs
    Email - follow the steps below to submit your support request to us by email
    Live chat for eligible customers
    We don’t currently offer telephone support.
    If you are a Skype customer, you can contact Skype Customer Service as follows:
    Click this link and sign in with your Skype Name and password.
    Select the topic you need help with and the problem you are having. Some information is displayed that might help with your problem.
    If the information doesn’t help, click Continue support request.
    Select your contact method.
    If you chose email, enter your details, describe your problem, and then click Send support request. We'll get back to you as fast as we can.
    Regards,
    Elaine
    Was your question answered? Please click on the Accept as a Solution link so everyone can quickly find what works! Like a post or want to say, "Thank You" - ?? Click on the Kudos button!
    Trustworthy information: Brian Krebs: 3 Basic Rules for Online Safety and Consumer Reports: Guide to Internet Security Online Safety Tip: Change your passwords often!

  • Costumer service complaint

    Hi,
    Where can I file a complaint I have regarding apple's costumer service? and service I got from apple support online?
    Thanks

    I was an internet only customer and I asked to add a phone line. The total bill came out to $135 which is $40 more than the cost of the "triple play" package. Just adding TV saved me a lot of money. Did they mention this to me? NO... I had to find out for myself.
    All of the reps are poorly trained

  • Were Can i Get The Ipod Number For costumer service

    Does any bodhave the costumer service number to apple? any help[[ wouold be reallly appriciated thnks Appe.

    http://www.apple.com/contact/phone_contacts.html
    Cheers!
    -Bryan

  • VERY BAD COSTUMER SERVICE

    I HAVE A NOTE BOOK AND IT'S BATTERY IS NOT WORKING PROPERLY WHILE IT IS IN WARRENTY PERIOD,BUT HP SERVICE CENTER IS NOT READY TO LISTEN ANY COMPLAIN WHICH MAKE ME VERY DISAPPOINTING.  FOR REPLACING LAPTOP'S BATTERY  AND  HP CONTAIN WORST BATTERY IN THEIR PRODUCT

    Did you just want to vent a bit or did you have a question? What is wrong with the battery and what kind of laptop is it? We are listening. I cannot guarantee a solution but we will try to help.

  • I need a phone number to talk to someone in costumer service

    I need a phone number to talk directly to costumer service

    Phone support | Orders, returns exchanges
    http://helpx.adobe.com/x-productkb/global/phone-support-orders.html

  • My terrible experience with Apple's costumer service (PLEASE READ)

    I have been a loyal customer with Apple and iTunes for about 6 years now. Being a lover of music I always tried to avoid downloading it off the Internet because I believed in supporting the artists and supporting things like iTunes for selling their music in a fast convenientway. About 2 months ago my younger brother wanted to start buying content off of iTunes on our family account, but couldn't because there were already 5 computers authorized on it even though there should only be 4. We looked through all of our old computers but couldn't find the one that was still authorized and not being used. We tried to de-authorize all the computers on the account but we're told that we had to wait a year before doing so (which by the way is extremely inconvenient and completely pointless in my opinion). In order to fix this problem I decided to create my own account so that my brother could take my place on the family one. After a couple of days of buying/listening to music on my new account I ran into a problem. About 500 of my songs plus a lot of other content could no longer be used because I was no longer authorized on the account that I bought them on. Being an optimistic person I assumed that Apple/iTunes customer support/service would be able to fix the problem easily. I went to the site and found it difficult to find any information relating to my problem or to find a number I could call. When I finally found a number I called it and to my surprise found myself having to speak commands to a machine (which by the way is the last thing people want to deal with when they need assistance, and it is very frustrating). It took me 7 tries to finally get through to someone because the machine had no idea what I wanted and kept hanging up on me. I talked with a customer service representative and explained the situation to him. I then asked him if he could possibly de-authorize all the computers on our family account, and he said that he could not and provided no explanation as to why. So then I asked him if he could transfer the content that I paid for on the family account to my new account and he said no. Finally I asked him if there was anything he or I could do to fix the problem and the only thing he suggested was that I'll just have to buy all the content again on my new account. I told him that was about 500 songs, 10 TV series, 10 movies, 9 audio books, and about 25 apps, which would probably cost around $1000. But he just repeated that there was nothing he could do. I was so disappointed with the lack of helpfulness from their customer service and with the way I was treated that I will no longer purchase music, movies, TV series, or anything that isn't an app from the iTunes store. I spent about 5 days replacing every song I could no longer listen to by downloading off the Internet. I even had to delete some of the songs because I could not find a downloadable version. They have officially lost a loyal iTunes customer and I hope this complaint will open their eyes a little. Thank you for taking the time to read this.

    I realize the number I called was not for iTunes store support, but I thought that they would at least be able to help me or point me in the right direction.
    Sorry, you knew that the number you called was not for iTunes Store support, but then you got upset because they couldn't help you? That seems rather unfair of you in my view. Not being party to the conversation and hearing what was said, I can't address the second issue of why they weren't able to point you to the form. Perhaps they did and you just missed it.
    Again, this post will convey nothing to anyone who can do anything about it. If you just want to comment to Apple, use their feedback pages:
    http://www.apple.com/feedback
    If you want actual assistance from the iTunes Store, contact them via the form I linked to above. There is, again, no phone support for the iTunes Store. You can express your desire for such phone service to Apple via the feedback page, but it's highly unlikely that Apple will ever find it cost-effective to provide that.
    Regards.

Maybe you are looking for

  • My iPhone 4 iOS 6 just froze, powered off, and wont turn on or charge.

    so ive just come in from school, loaded facebook. typed a message and pressed send, phone made a strange noise and now wont turn back on or charge. what can i do?

  • Error in Select single statement

    Hi All, Following is the statement and error message im getting: Can anyone help me with this. I am not able to figure out whats wrong with this. <b>select SINGLE *   from  vbrk where  vbeln eq iv_billno.</b> <u>Error:</u> The INTO clause is missing

  • Movies fail to load and playback in web browsers

    I can't seem to load and playback what appear to be QT movies in Safari, Chrome , or Firefox. A black window sits there and all I get is a spinning blue circle in the middle of the screen for a long time. I have a 2.66 Ghz intel imac with 2 gigs of R

  • Backup and Restore - WSUS

    Friends, I will format a Windows Server 2008 server running WSUS 3.0, then I will install Windows Server 2008 again and will install WSUS 3.0 again, do not want to lose WSUS settings and folders updates. If I follow the procedure to do the full backu

  • CCX 8

    I have installed ccx 8.0.2 in cluster (pub and sub). I changed application user and password via CLI, it seems the process goes good but when I tried to get access to ccx editor, rtmt or other application I get a mistake (wrong user or password) and