I don't know where's the problem !!!

Hello ,
I spend 3 days trying to ping or to reach anything from
192.168.14.1    to      192.168.21.1
And it’s not working, can anyone help
Thanks
ASA Version 8.2(2)16
hostname ASA
domain-name corp.local
names
dns-guard
interface Ethernet0/0
nameif outside
security-level 0
ip address 1.1.1.2  255.255.255.252
interface Ethernet0/1
no nameif
security-level 50
no ip address
interface Ethernet0/1.20
vlan 20
nameif DMZ
security-level 50
ip address 192.168.20.1 255.255.255.0
interface Ethernet0/1.21
vlan 21
nameif DMZ2
security-level 50
ip address 192.168.21.1 255.255.255.0
interface Ethernet0/2
shutdown
no nameif
no security-level
no ip address
interface Ethernet0/3
nameif inside
security-level 100
ip address 192.168.14.2 255.255.255.0
interface Management0/0
shutdown
nameif management
security-level 100
ip address 192.168.1.1 255.255.255.0
management-only
boot system disk0:/asa822-16-k8.bin
ftp mode passive
clock timezone GST 4
dns domain-lookup inside
dns server-group DefaultDNS
name-server DC01-inside-10.11
name-server DC02-inside-10.12
domain-name corp.local
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
object-group network Corp-Domains
network-object host DC01-inside-10.11
network-object host DC02-inside-10.12
object-group network Users
network-object Wireless-Users-13 255.255.255.0
network-object Wired-users-14 255.255.255.0
object-group network DC-DNS
network-object host DC01-inside-10.11
network-object host DC02-inside-10.12
access-list inside_access_in extended permit ip any any inactive
access-list inside_access_in extended deny udp object-group Users host Etisalat-DNS eq domain
access-list inside_access_in extended permit udp any any eq domain
access-list inside_access_in extended permit icmp object-group Users any
access-list inside_access_in extended permit ip 192.168.50.0 255.255.255.0 any
access-list inside_access_in extended permit tcp object-group Users any eq www
access-list inside_access_in extended permit tcp object-group Users any eq 666
access-list inside_access_in extended permit tcp Server-Farm-10 255.255.255.0 any eq 8080
access-list inside_access_in extended permit tcp object-group Users any eq https
access-list inside_access_in extended permit tcp object-group Users any eq 8080
access-list inside_access_in extended permit tcp object-group Users any eq ssh
access-list inside_access_in extended permit icmp Server-Farm-10 255.255.255.0 any
access-list inside_access_in extended permit tcp Server-Farm-10 255.255.255.0 any eq www
access-list inside_access_in extended permit tcp Server-Farm-10 255.255.255.0 any eq https
access-list inside_access_in extended permit tcp host 192.168.10.15 host 192.168.20.11 eq smtp
access-list inside_access_in extended permit tcp host 192.168.10.16 host 192.168.21.16 eq 5062
access-list inside_access_in extended permit tcp host 192.168.10.16 host 192.168.21.16 eq 8057
access-list inside_access_in extended permit tcp host 192.168.10.15 host 192.168.20.11 eq 50636
access-list inside_access_in extended permit tcp host 192.168.10.16 host 192.168.21.16 eq 4443
access-list inside_access_in extended permit tcp host 192.168.10.16 host 192.168.21.16 eq 5061
access-list inside_access_in extended permit tcp any any eq 3389
access-list DMZ_access_in extended permit tcp host 192.168.20.13 Server-Farm-10 255.255.255.0 eq 3389
access-list fromout extended permit icmp any any
access-list fromdmz extended permit udp any host DC01-inside-10.11 eq domain
access-list fromdmz extended permit udp any host DC02-inside-10.12 eq domain
access-list fromdmz extended permit tcp 192.168.20.0 255.255.255.0 any eq www
access-list fromdmz extended permit tcp 192.168.20.0 255.255.255.0 any eq https
access-list fromdmz extended permit icmp 192.168.20.0 255.255.255.0 any
access-list fromdmz extended permit tcp 192.168.20.0 255.255.255.0 any eq smtp
access-list fromdmz extended permit udp 192.168.20.0 255.255.255.0 any eq domain
access-list fromdmz extended permit ip any any
access-list DMZ_access_in_1 extended permit ip any any inactive
access-list DMZ_access_in_1 extended permit tcp any any eq pptp
access-list DMZ_access_in_1 extended permit icmp any any
access-list DMZ_access_in_1 extended permit tcp any any eq smtp
access-list DMZ_access_in_1 extended permit udp any any eq domain
access-list DMZ_access_in_1 extended permit tcp any any eq www
access-list DMZ_access_in_1 extended permit tcp any any eq https
access-list DMZ_access_in_1 extended permit tcp any any eq ssh
access-list DMZ2_access_in extended permit ip any any inactive
access-list DMZ2_access_in extended permit ip 192.168.21.0 255.255.255.0 Server-Farm-10 255.255.255.0 inactive
access-list DMZ2_access_in extended permit ip 192.168.21.0 255.255.255.0 Wireless-Users-13 255.255.255.0 inactive
access-list DMZ2_access_in extended permit ip host 192.168.21.12 host DC01-inside-10.11
access-list DMZ2_access_in extended permit ip host 192.168.21.12 host DC02-inside-10.12
access-list DMZ2_access_in extended permit udp host 192.168.21.16 host Etisalat-DNS eq domain
access-list DMZ2_access_in extended permit tcp 192.168.21.0 255.255.255.0 object-group Users eq 3389 inactive
access-list DMZ2_access_in extended permit udp host 192.168.21.10 host DC01-inside-10.11 eq domain
access-list DMZ2_access_in extended permit udp host 192.168.21.10 host DC02-inside-10.12 eq domain
access-list to-out extended permit ip any any inactive
access-list to-out extended permit tcp any any eq 3389
access-list to-out extended permit tcp any any eq pptp
access-list to-out extended permit icmp any any
access-list to-out extended permit udp any any eq domain
access-list to-out extended permit tcp any any eq 8080 inactive
access-list to-out extended permit tcp any any eq https
access-list to-out extended permit tcp any any eq www
access-list to-out extended permit tcp any any eq smtp
access-list inside_nat0_outbound extended permit ip Server-Farm-10 255.255.255.0 192.168.50.0 255.255.255.0
access-list inside_nat0_outbound extended permit ip 192.168.12.0 255.255.255.0 192.168.50.0 255.255.255.0
access-list outside_nat0_outbound extended permit ip 192.168.50.0 255.255.255.0 any
access-list splitt-tunnel standard permit Server-Farm-10 255.255.255.0
access-list splitt-tunnel standard permit 192.168.20.0 255.255.255.0
access-list splitt-tunnel standard permit 192.168.21.0 255.255.255.0
access-list splitt-tunnel standard permit 192.168.12.0 255.255.255.0
access-list DMZ_nat0_outbound extended permit ip 192.168.50.0 255.255.255.0 any
pager lines 24
logging enable
logging trap emergencies
logging asdm informational
mtu outside 1500
mtu DMZ 1500
mtu DMZ2 1500
mtu inside 1500
mtu management 1500
ip local pool VPN-Users 192.168.50.10-192.168.50.245 mask 255.255.255.0
ip verify reverse-path interface outside
icmp unreachable rate-limit 1 burst-size 1
icmp permit any outside
icmp permit any DMZ
icmp permit any DMZ2
icmp permit any inside
asdm image disk0:/asdm-647.bin
no asdm history enable
arp timeout 14400
global (outside) 1 1.1.1.1. netmask 255.0.0.0
nat (outside) 0 access-list outside_nat0_outbound
nat (DMZ) 0 access-list DMZ_nat0_outbound
nat (inside) 0 access-list inside_nat0_outbound
nat (inside) 1 Server-Farm-10 255.255.255.0
nat (inside) 1 Wireless-Users-13 255.255.255.0
nat (inside) 1 Wired-users-14 255.255.255.0
static (inside,DMZ) Wired-users-14 Wired-users-14 netmask 255.255.255.0
static (inside,DMZ) Wireless-Users-13 Wireless-Users-13 netmask 255.255.255.0
static (inside,DMZ) Server-Farm-10 Server-Farm-10 netmask 255.255.255.0
static (inside,DMZ2) Server-Farm-10 Server-Farm-10 netmask 255.255.255.0
static (inside,DMZ2) Wireless-Users-13 Wireless-Users-13 netmask 255.255.255.0
access-group fromout in interface outside
access-group to-out out interface outside
access-group DMZ_access_in_1 in interface DMZ
access-group DMZ2_access_in in interface DMZ2
access-group inside_access_in in interface inside
route outside 0.0.0.0 0.0.0.0 3.3.3.3 1
route inside Server-Farm-10 255.255.255.0 192.168.10.1 1
route inside 192.168.12.0 255.255.255.0 192.168.12.1 1
route inside Wireless-Users-13 255.255.255.0 192.168.13.1 1

Hi
First of all why are implementing 192.168.14.2 as the interface on the ASA ? all of the other interfaces are .1 ?
And Also why are you trying to reach something on the ASA interface ip address ?
Second thing, what exactly are you trying to make happen here ?
What is the purpose ?
The third thing you can do is to use Packet tracer to let you see where the packets fail.
In your case that would be to start the cli
packet-tracer input inside tcp 192.168.14.1 1025 192.168.21.1 80
as an example

Similar Messages

  • HT1476 I have a big problem in my phone charger . I have Iphone 5s . I don't know what is the problem but the bettery is not working true . A decrease in the battery very quickly and then turns off the machine . Please, I want to address this problem quic

    I have a big problem in my phone charger . I have Iphone 5s . I don't know what is the problem but the bettery is not working true . A decrease in the battery very quickly and then turns off the machine . Please, I want to address this problem quickly .

    http://osxdaily.com/2013/09/19/ios-7-battery-life-fix/

  • 47 gigas of "other memory" I don't know where is the "other memory"

    I have a MacBook Air 11" with only 64 GB of memory. I go to
    "About This Mac" and says...
    Audio - 2 GB
    Movies - 48.7 MB
    Photos - 418.3 MB
    Apps - 7.01 GB
    Backup - Zero KB
    Other - 42 GB
    Other - 42 GB ??????????
    I don't know where are the archives of "Other"
    I have used the premiere pro and I know that uses memory to convert videos and stuff
    but I have deleted all that memory

    One suggestion would be to post in the iPad forum.  This is the iPhone fourm.
    D'oh!

  • I don't know what is the problem..

    I have a CISCO6506-E, with Sup II with PFC and an 8-Port GBIC connected to a 4506 on GBIC.
    I have tagged the vlan, configure the trunk but I cannot ping the 4506 from the 6506. The 6506-E is just a forwarding switch (L2). What coud be the problem. I have check the status, no vlan mismatch, trunk is good, CDP is good.

    Hi H,
    I do not think there is an command like "set trunk negotiate disable" I think you might have given command "set trunk nonegotiate" and it should not create any problem as it just bring the trunk up without sending any DTP packet.
    You cannot put negotiate on both sides and that is the probable reason trunk is going down. Negotiate keyword is just to let the switch know what is the encapsulation cofnigured on other side i.e isl or dot1q and it will work accordingly.
    Can you please explain what have you configured as trunk mode on other side? I think we are lacking in some config if you just post the related config it will be of help.
    Regards,
    Ankur

  • HT201401 After changing the sincard I cannot dile any number and I get a message " call failed " I don't know what is the problem

    The simcard  have been changed twice by the carrier VODAFONE but still the problem exist

    hello flabs, this is likely caused by an outdated extension. in case you have the social fixer addon installed, please update it to the latest version that is available at http://socialfixer.com/blog/category/releasenotes/.

  • I've just upgrade my ios 5.1 to ios 6 but my ipod is now hanging up and i cannot turn it off even i follow the troubleshooting procedures. What should I do? I don't know what is the problem.

    I have problem with my Ipod touch when I upgrade it with ios 6. I cannot turn it off. I have alrealy followed the troubleshooting instructions to press both the off/sleep button and the home button but still it will not turn off. I cannot use my ipod anymore for it is just hanging up.

    Try:
    - iOS: Not responding or does not turn on
    - Also try DFU mode after try recovery mode
    How to put iPod touch / iPhone into DFU mode « Karthik's scribblings
    - If not successful and you can't fully turn the iPod fully off, let the battery fully drain. After charging for an least an hour try the above again.
    - If still not successful that indicates a hardware problem and an appointment at the Genius Bar of an Apple store is in order.
    Apple Retail Store - Genius Bar

  • HT4914 I can't update the apps! It ask me to change back to macau store , but I don't know where's the setting!

    Every time it want to update or buy a new apps by my 4s. But the apps system ask me that to change back to Macao store in the settings,but I can't find out the setting! Pls help and let me know how to do ! Thx

    You can create an account without a credit card, check here:
    Creating an iTunes Store, App Store, iBooks Store, and Mac App Store account without a credit card

  • I can't sync my iPad to the iTunes it's give me an unknown error  message 0xe8000012 I don't know how to fix it and where is the problem could be need format or the problem is in the charging port please can any one help me

    I can't sync my iPad to the iTunes it's give me an unknown error  message 0xe8000012 I don't know how to fix it and where is the problem could be need format or the problem is in the charging port please can any one help me

    Unknown Error containing "0xE" when restoring
    To resolve this issue, follow the steps in iPhone, iPad, iPod touch: Unknown error containing '0xE' when connecting. If you have a Windows computer with an Intel® 5 series/3400 series chipset, you may need updates for your chipset drivers. See iTunes for Windows: Issues syncing iOS devices with P55 and related Intel Chipsets for more information.
    From Here  >  http://support.apple.com/kb/TS3694

  • I use CS5 and all of a sudden I am getting a notification that says there is an error with my icons. It's telling me to contact support or reinstall. The problem is I don't know where my disks are to re-install. Any suggestions?

    I use CS5 and all of a sudden I am getting a notification that says there is an error with my icons. It's telling me to contact support or reinstall. The problem is I don't know where my disks are to re-install. Any suggestions?

    doodlebug,
    Am I just out of luck until I find those?
    You may try Adobe Support (phone),
    http://helpx.adobe.com/adobe-connect/adobe-connect-phone-numbers.html
    and talk to them about your registration, but I am unsure whether they can help you with anything pre CC (There was a Customer Care option with chat which seems to have stopped working).
    If you are still out of luck, please report back, and I will try to ask someone to find the right someone to help you.

  • I bought i pad 3 in canada 4 months ago but i think it's got problem with battery .i live in germany i don't know where to send it

    i bought i pad 3 in canada 4 months ago but i think it's got problem with battery .i live in germany i don't know where to send it

    Not quite what I heard when I went into the Apple Store in Hong Kong yesterday.
    I have just bought an iPad in Hong Kong but will eventually be travelling back to the UK.
    Louis in the Apple Store told me that iPads without cellular have international warranty but those with cellular do not (as there are slightly different models for different carriers).
    But he was pretty cagey and essentially couldn't give a clear, straightforward answer. Which most Apple employees can't.
    It is now a grey area, at the discrection of each local Apple Store & is subject, it seems, to you paying the import duty as a possible get out clause.
    Look carefully but do tell us if you got this iPad reapired. Thanks.

  • Don't know where the error is!!!

    hi again
    i wrote the code for the add button ,, but when i enter the path of the .au(eg a:\piano.au) in the text field and click add it will be added to my database and the .au file will be saved as a long binary data in the db,, when i come to search for it in my application i get in the voice text field something like that 61003A005C007000690061006E006F002E0061007500 not(a:\piano.au), i don't get the path so when i come to play it it will not play i don't know where the problem is ..
    this is the code:
    if(e.getSource()==vadd)
    //User has not populated all the input fields.
    if(vname.getText().equals("")|| vaddress.getText().equals("")|| vphone.getText().equals("")|| vsex.getText().equals("")|| vdob.getText().equals("")|| vtemplate.getText().equals("")|| vvoice.getText().equals(""))
    JOptionPane.showMessageDialog(null, "Please fill in all the fields","Missing Fields",JOptionPane.INFORMATION_MESSAGE);
    }//if
    else
    // save the new customer:
    try
    //1. take the customer's data:
    int vuserId = Integer.parseInt(vid.getText());
    String vuserName = vname.getText();
    String vuserAddress = vaddress.getText();
    String vuserPhone = vphone.getText();
    String vuserSex = vsex.getText();
    String vuserDateBirth = vdob.getText();
    String vuserTemplate = vtemplate.getText();
    String vuserVoice=vvoice.getText();
    File file = new File(vuserVoice);
    int fileLength = (int)file.length();
    if(fileLength > 0)
    fis = new FileInputStream(file);
    String query = " INSERT INTO voice VALUES('"+vuserId+"', '"+vuserName+"', '"+vuserAddress+"', '"+vuserPhone+"', '"+vuserSex+"', '"+vuserDateBirth+"', '"+vuserTemplate+"', ? ) ";
    PreparedStatement pstmt = conn.prepareStatement(query);
    pstmt.setBinaryStream(1, fis, fileLength);
    pstmt.executeUpdate();
    else
    String query = " INSERT INTO voice VALUES('"+vuserId+"', '"+vuserName+"', '"+vuserAddress+"', '"+vuserPhone+"', '"+vuserSex+"', '"+vuserDateBirth+"', '"+vuserTemplate+"',?) ";
    stat.executeUpdate(query);
    /*String query = " INSERT INTO voice VALUES('"+vuserId+"', '"+vuserName+"', '"+vuserAddress+"', '"+vuserPhone+"', '"+vuserSex+"', '"+vuserDateBirth+"', '"+vuserTemplate+"', '"+vuserVoice+"') ";
    stat.executeUpdate(query);*/
    vupdateTable();
    } //try
    catch (Exception ev)
    System.out.println("Caught exception in add action: " + ev);
    } //catch
    }//else
    }//else if
    So plzz can some one help..

    The characters you get is just the (reversed) unicode representation of the string you want:
    class Printit{
    // this shows the two representations are equal:
    public static void main(String [] args){
         String tu = "" + '\u0061' + '\u003A' + '\\' /*'\u005C'*/
                           + '\u0070' + '\u0069'
                           + '\u0061' + '\u006E' + '\u006F'
                           + '\u002E'
                           + '\u0061' + '\u0075';
         System.out.println(tu);
    }shows this - well the '\' is only allowed escaped, so I may not use '\005C' directly.
    I suppose the field in DB has a wrong format or you do not read it the right way. The writing seems OK to me.

  • I have an older airport express but don't know where to look to find its model number.  The version number is airport utility 6.3.4 (634.17).  Can anyone point me in the right direction?  Thanks.

    I have an older airport express, but don't know where to look to find its model number. 
    The version number is airport utility 6.3.4 (634.17). 
    Can anyone point me in the right direction?  Thanks.

    Hard to see it's so teeny. I needed a magnifying glass.
    FWIW, you should not mark your reply as Solved because you did not solve your question. Helpful and Solved are used to reward the user who help you or solved your problem.

  • I changed my iPhone lately but i can't restore my last backup since it keeps saying "itunes could not restore backup because the password was incorrect" but I don't know where to put the password to make it happen... Any suggestions?

    Hey guys,
    I just bought a new iPhone but i can't restore my backup files beacuse it keeps saying "itunes could not restore backup because the password was incorrect" but I really don't know where to put the password to restore it. I really have some files that are meaningful for me so I really need help. Any suggestions anyone?

    Select your iDevice in the iTunes.
    Choose the Summary screen (tab) and scroll to the bottom of the screen.
    Then un-select Encrypt iPhone backup.
    iTunes will then prompt you to “Enter the password to unlock your iPhone backup”, enter the password you set originally.

  • I have a 2009 A6 with a 5th Gen. iPod. I mostly listen to audio bks, not a lot of music. Often, the MMI starts on the first song on my iPod, therefore I don't know where I stopped in my 4-6 hr book.  How can I get MMI to start where I left off?

    I have a 2009 A6 with a 5th Gen. iPod pluggedinto the MMI.  I mostly  listen to audio books, not a lot ofmusic.  The books are 4-6 hours long, vs 4-6minutes with a song.  Often, but not always, when I start my A6, the MMI starts on the first song on my iPod, thereforeI don't know where I stopped in my 4-6 hour book.  How can I get the interface to stay stopped where I left off?  I have gone into iTunes and placed my current book as the first "song" on my iPod for ease of finding it, but often the MMI starts it over at the beginning.  Thank you if anyone has any experience with this.  My dealer in San Rafael, CA says they've never heard of this issue. 

    I think my iPod, which is an iPod touch 3rd generation , which is a lot different from a nano, which really makes it almost impossible for me to help you, which is why I suggested that you post your question in the iPod nano community.  Your first post says that your product is an iPod nano. I think the people who answer those questions would be most likely to help you. If yours isn't a nano then you can pick the right community from here. This community is really to answer questions about this forum, or issues that don't fit anywhere else.
    laverne's mom
    Message was edited by: laverne's mom

  • HT1222 I just updated iTunes to the latest version and now I can't play more than have of my songs.  Says it can find it and then leasds me to locate it.  I don't know where to look.  Help!!!

    I just updated iTunes to the latest version and now I can't play more than half of my songs.  When I click on a song it comes back and states that it can't find it and prompts me to try and locate it.  I don't know where to look.  Help!!!!

    Hi ldhong,
    There are a few ideas in this article on how and where to look for missing iTunes media:
    iTunes: Finding lost media and downloads
    http://support.apple.com/kb/TS1408
    Hope this helps!
    - Ari

Maybe you are looking for