New Type of Firewall Config (for me)

OK - this is a different type of config for me so I am reaching out for  some advise / help.  I manage many cisco asa 5520's and I am in the  process of converting one asa from a block of 30 outside addresses of to  a 50 Meg Cox cable modem with a block of 30 cidr addresses.
Normally  I would just reference an outside address and bingo, things would work  right.  In this case I found out so far that I could only get internet  access through this cable modem by setting up the outside interface of  the asa with dhcp - then it grabbed a public wan address, added a route  to the asa 5520 and then I had internet access out through the cable  modem.
My question / problem / nuance to me is when I reference /  assign  one of our cidr addresses to a device (like a server) and that  is natted from the dmz to the outside address I don't get access to the  device.
I'm thinking I have to do something special to set up  these cidr addresses but having never done this before I am reaching out  for some advise.
my outside dhcp assigned wan address is 70.168.x.1xx with a gateway of 70.168.x.1
The cidr block I have been assigned from the cable company is
184.185.x.x/27
The  cable company also has suggested a default gateway address withing the  cidr block and a first useable and last useable address.
I must say that I usually look to over complicate things by thinking things are more difficult than they really are.
Can  anyone get me pointed in the right direction so I know how to assign  these cidr addresses and have then accessable from the outside???
Thanks in advance
Paul

Hi,
So from what I understand you should have your own public IP address range of /27 usable through your current connection. Yet it only works with setting the ASA outside to use DHCP and doesnt work when you staticly assign an IP address from the /27 address range and set the default route.
If the above is the case I'm kinda wondering why you are even getting IP address with DHCP from the ISP if you are supposed to have your own public address block.
You sure the ISP has its side configured correctly?
- Jouni

Similar Messages

  • Post new artwork and screenshots/configs for Alopex (formerly ttwm)

    Post your screenshots and configs for Alopex here:
    .ttwm_config.h - edit: (this is old so I deleted it and I won't change it here)  My alopex configs are in my configs in my signature.
    On my netbook HP mini
    Edit:  config.h change--see sig link--this wm changes config.h like I change my underwear--just a sign that it's under active development.
    Last edited by bgc1954 (2013-05-04 14:24:40)

    Hey all!
    Here are my custom config.h and icons.h.
    Background is Fedora 11's King Concept. My status bar is being run by conky (conkyrc linked). And the programs featured on the cluttered image are dwb, htop and alsi (with a customized Arch logo) running in termite, and interrobang at the bottom (custom interrobangrc can be found here).
    [Edit]: Removed embedded custom config.h ('twas out-of-date; see new link for updated version), and updated picture links for 404s.
    [Edit2]: Updated links for name change.
    All the best,
    -HG
    Last edited by HalosGhost (2013-05-01 19:04:49)

  • Definition of a new type of invoice for Evaluated Receipt Settlemen (ERS)

    Hello,
    I need to define a new type of invoice for Evaluated Receipt Settlemen (ERS). Is it possible? What should i do to configure the system?
    Thanks in advance,
    Luis Álvarez.

    Hi,
    ERS is used for invoice plan & invoicing plan for leasing agreements like, aim to considerably reduce the manual data entry effort in the purchasing and invoice verification (A/P) department.
    The invoicing plan enables you to schedule the desired dates for the creation of invoices relating to the planned procurement of materials or services independently of the actual receipt of the goods or actual performance of the services. It list the dates on which you wish to create and then pay the invoices.
    The steps are,
    1.XK02: In Purchasing Data tick the check box of AutoEvalGRSetmt Del,
    2.ME12: Should not select No ERS check box,
    3.ME21N: Create PO,
    4.MIGO: Receive Goods,
    5.MRRL: Evaluated Receipt Settlement
    Link may be useful.
    http://help.sap.com/saphelp_srm30/helpdata/en/fb/8dec38574c2661e10000000a114084/content.htm

  • New Mac Pro - Config for graphics?

    Looking to purchase a new 6-Core Mac Pro for high end photo retouching & 3D modeling/rendering. I would love to be able to afford the la$t of each option for CPU, memory, storage, graphics, etc. But this would immediately push the price tag over $10K -which is way beyond my intended general price point.
    I've been using Macs professionally since 1987, and tradionally options like ram and displays are more economically purchased from other vendors. I know from my last Macbook Pro purchase that some options are permanent and can't be upgraded. I'm tempted to go with the stock config here, with the intention of adding ram and a new display as needed.
    Can the flash storage be upgraded later? 256Gb seems like barely enough for OS and a few apps. I currently keep my itunes library on my boot drive, but that won't fly with 256Gb. Can the itunes library reside on the non boot drive or would that have to be iCloud?
    $1500 for the next bump up in CPU is steep. You can never have enough raw power for 3D rendering, but this is another option I would like to upgrade later as needed. Is this possible?
    I would like to keep the purchase price close to the base cost, but would be prepared to pay upgrades that offer major productivity boosts, or any components that can't be upgraded later (but perhaps the latter is a moot qhestion)
    I know I can get answers to these questions from Apple sales, but am hoping to get suggestions from tech savvy users who employ a similar workflow, and preferably have experience with the NEW HARDWARE.
    thanks

    The expectation is that the Built-in SSD is the Boot Drive, and that User files and work files will go into Thunderbolt-to-something external enclosure(s), the number of which, and specifications of which, are your choice.
    The 6-core is a sweet spot, giving you more cores with a still fast base CPU speed for less than half the price of an additional complete unit.
    There is a knee in the RAM upgrade curve. Using today's modules, the 16GB modules are RDIMMs, and do not play nice with ANY other sizes.There are four independent memory channels, that can be locked into pairs.  I have not read anything definitive about why/why not to upgrade DIMMs by the each (except that by example Apple has demonstrated that three modules in the four slots works fine).

  • Configure of New Release strategy in PR for ERSA Mat type

    Dear Friends,
    Pl provide me the solution for configure of New Release strategy in PR for ERSA Mat type with the approval of GE with a characterstic value of MRP Controller.
    Regards,
    Ask

    ashokkumardash wrote:>
    > Dear Friends,
    >
    > Pl provide me the solution for configure of New Release strategy in PR for ERSA Mat type with the approval of GE with a characterstic value of MRP Controller.
    Hi,
    Create Characteristic for Material type and Communication structure CEBAN and a create class with 023 and assign character to class and create Release group and code for MRP controller and finally assign this particulate role to the MRP controller User ID and he release the same.

  • Profit center config for new Division

    Hi SAP Experts,
    I need guidance for new Division implementation for our client.
    my client started a new branch its like a existing company but not separate a legal entity,requirement is they need every thing P and L ,Balance sheet for new branch.
    how to do profit center wise config for the same.
    i require profit center document for the same.
    what are prerequisites and detail steps of config.
    Thanks in Advance
    Sumaira
    Moderator: Please, read and respect SDN rules

    I suppose you are implementing Classic PCA in CO.
    The transportation can be done thru
    SPRO - Controlling - Profit Center Accounting - Tools - Transport Customizing Settings
    Enjoy.
    Venkat.

  • Adding new object type (field BKPF-AWKEY) for BAPI posting

    Hi everyone,
    I am posting to SAP GL using an input file to read the data and transfer it to BKPF and BSEG tables.
    The problem is I have to use BAPI_ACC_DOCUMENT_POST, and it expects values for OBJ_KEY and OBJ_TYPE.. For now, OBJ_TYPE creates a problem, because if I use BKPF, it says it cannot post using this object type, as it is for SAP internal use only.
    Does anyone know how to add a new object type for the customer namespace, which can be manually used for this kind of posting? I know that the new entry must be made in tables TTYP, TTYPT, and possibly TTYPV, for which the maintainence view exists: V_TTYPV.
    How to add an entry here, or where can I find it in customizing?
    All helpful answers will be awarded.
    Thank you very much
    Srdjan

    perform fill_internal_tables.
    if check_l = 'X'.
      call function 'BAPI_ACC_DOCUMENT_CHECK'
           destination dest
           exporting
                documentheader    = gd_documentheader
                customercpd       = gd_customercpd
                contractheader    = gd_fica_hd
           tables
                accountgl         = it_accountgl
                accountreceivable = it_accountreceivable
                accountpayable    = it_accountpayable
                accounttax        = it_accounttax
               currencyamount    = it_currencyamount
                criteria          = it_criteria
                valuefield        = it_valuefield
                extension1        = it_ext
                return            = it_return
                paymentcard       = it_paymentcard
                contractitem      = it_fica_it.
               extension2        = it_ext2
               realestate        = it_re.
      write: / 'Result of check lines:'.                        "#EC NOTEXT
      perform show_messages.
    endif.
    if check_a = 'X'.
      call function 'BAPI_ACC_DOCUMENT_CHECK'
        destination dest
        exporting
          documentheader    = gd_documentheader
          customercpd       = gd_customercpd
          contractheader    = gd_fica_hd
        tables
          accountgl         = it_accountgl
          accountreceivable = it_accountreceivable
          accountpayable    = it_accountpayable
          accounttax        = it_accounttax
          currencyamount    = it_currencyamount
          criteria          = it_criteria
          valuefield        = it_valuefield
          extension1        = it_ext
          return            = it_return
          paymentcard       = it_paymentcard
          contractitem      = it_fica_it.
         extension2        = it_ext2
         realestate        = it_re.
      write: / 'Result of check all:'.                          "#EC NOTEXT
      perform show_messages.
    endif.
    if post = 'X'.
      data: l_type like gd_documentheader-obj_type,
            l_key  like gd_documentheader-obj_key,
            l_sys  like gd_documentheader-obj_sys.
      if dest = space or
         dest = gd_documentheader-obj_sys.
       post synchron
        call function 'BAPI_ACC_DOCUMENT_POST'
          exporting
            documentheader    = gd_documentheader
            customercpd       = gd_customercpd
            contractheader    = gd_fica_hd
          importing
            obj_type          = l_type
            obj_key           = l_key
            obj_sys           = l_sys
          tables
            accountgl         = it_accountgl
            accountreceivable = it_accountreceivable
            accountpayable    = it_accountpayable
            accounttax        = it_accounttax
            currencyamount    = it_currencyamount
            criteria          = it_criteria
            valuefield        = it_valuefield
            extension1        = it_ext
            return            = it_return
            paymentcard       = it_paymentcard
            contractitem      = it_fica_it.
           extension2        = it_ext2
           realestate        = it_re.
        write: / 'Result of post:'.                             "#EC NOTEXT
        perform show_messages.
      else.
      create Idoc
        it_receivers-logsys = dest.
        append it_receivers.
        call function 'ALE_ACC_DOCUMENT_POST'
          exporting
            documentheader    = gd_documentheader
            customercpd       = gd_customercpd
            contractheader    = gd_fica_hd
          tables
            accountgl         = it_accountgl
            accountreceivable = it_accountreceivable
            accountpayable    = it_accountpayable
            accounttax        = it_accounttax
            currencyamount    = it_currencyamount
            criteria          = it_criteria
            valuefield        = it_valuefield
            extension1        = it_ext
            paymentcard       = it_paymentcard
            contractitem      = it_fica_it
           extension2        = it_ext2
           realestate        = it_re
            receivers         = it_receivers
          COMMUNICATION_DOCUMENTS =
          APPLICATION_OBJECTS     =
          exceptions
            error_creating_idocs    = 1
            others                  = 2  .
        if sy-subrc = 0.
          write: / 'IDoc created'.                              "#EC NOTEXT
        else.
          write: sy-msgid.
        endif.
      endif.
    endif.
    if rev_p = 'X' or rev_c = 'X'.
      data: rev like bapiacrev,
            rev_key like ref_key.
      rev_key       = ref_key.
      rev_key(1)    = 'R'.
      rev-obj_type  = gd_documentheader-obj_type.
      rev-obj_key   = rev_key.
      rev-obj_sys   = gd_documentheader-obj_sys.
      rev-obj_key_r = ref_key.
      if rev_c is initial.
        if dest = space or
           dest = gd_documentheader-obj_sys.
          call function 'BAPI_ACC_DOCUMENT_REV_POST'
            exporting
              reversal = rev
              bus_act  = gd_documentheader-bus_act
            tables
              return   = it_return.
        else.
          it_receivers-logsys = dest.
          append it_receivers.
          call function 'ALE_ACC_DOCUMENT_REV_POST'
            exporting
              reversal                      = rev
              busact                        = gd_documentheader-bus_act
            OBJ_TYPE                      = 'BUS6035'
            SERIAL_ID                     = '0'
            tables
              receivers                     = it_receivers
            COMMUNICATION_DOCUMENTS       =
            APPLICATION_OBJECTS           =
            exceptions
              error_creating_idocs          = 1
              others                        = 2
          if sy-subrc <> 0.
            message id sy-msgid type sy-msgty number sy-msgno
                    with sy-msgv1 sy-msgv2 sy-msgv3 sy-msgv4.
          else.
            write: / 'IDoc created'.                            "#EC NOTEXT
          endif.
        endif.
      else.
        call function 'BAPI_ACC_DOCUMENT_REV_CHECK'
          exporting
            reversal = rev
            bus_act  = gd_documentheader-bus_act
          tables
            return   = it_return.
      endif.
      write: / 'Result of Reversal Posting:'.                   "#EC NOTEXT
      perform show_messages.
    endif.
    commit work.
    chk this
    Give points if useful

  • [svn] 3662: + add throttle configs for new and improved policy and other throttle features

    Revision: 3662
    Author: [email protected]
    Date: 2008-10-15 13:01:21 -0700 (Wed, 15 Oct 2008)
    Log Message:
    + add throttle configs for new and improved policy and other throttle features
    Modified Paths:
    blazeds/trunk/qa/apps/qa-regress/WEB-INF/flex/messaging-config.mods.xml

    How about the random pausing when streaming a movie from itunes that was converted from a DVD? I know myself, and, a few others from what i can see are experiencing this same issue. Anyone else?

  • Config for Cucle Count method by storage type

    Hi All,
    We wanted to activate teh cycle counting inevnetory for some storage types. The pre-requisite is that assign the Inventory method ( ST, PZ etc.) to teh storage type. We are in ECC 6.0 and I don't see any indicator which I can assign to teh storage type. We do see only ST, PZ or blank i.e. no inventory.
    Can anybody please help that where we can add the inventory method for cycle count so that we can assign it to the storage type?
    Tahnks inadvance for any help.
    regards,
    KHAN

    Hi,
    Flag the box  at the header leval i.e. cycle count
    regards

  • Config for Dispatch Intrastat

    Hello Experts,
    Our client has a manufacturing plant in France which is already in SAP. Now they are planning to come up with another plant in France. We will be creating a new Company Code and Sales Org. My question is that since France is already in SAP and uses Intrastat reporting so do we need to make any config for new Plant/Sales Org or is the Intrastat setting defined at country level only.
    Regards,
    Karan

    Hello Karan,
    We are going to create a new Plant as well as a new Sales Organisation. In Intrastat there is one setting where we assign Business Transaction Type to Sales Org/Item Category combination. For the reference Sales Org this setting is already in place so do we need to do this setting for new Sales Org also or does it get copied when we create new sales org with reference to existing sales org?
    In my view on the current set up which you are incorporating for new plant at France, there is no need to have new Company Code and Sales organization unless and untill there is some legal requirement at EU(If export process needs to be triggered). There is not much information available on Intrastat functionality but as i understand from you, you create Business transaction type at Intrastat, and then assign business transaction type to Sales organization, My suggestion would be :- most likely you would have to extend and include the newly created Sales Organization for Business transaction type.
    Thanks,
    Sarthak

  • Firewall-config cannot change firewall zones of NetworkManager conns

    I have been playing around with firewalld and firewall-config recently to try to harden up my laptop.
    My regular user account is in group wheel, and I have polkit set up.  So, any administrative tasks prompt me for my password.  I can configure networks with NetworkManager (and even set a firewall zone from within NetworkManager).  And with a password, I can modify firewalld rules.
    However, if I attempt to change the firewall zone of a network connection (either under Options > Change Zones of Connections... or by left-clicking on firewall-applet), I get the following stackdump:
    Traceback (most recent call last):
      File "/usr/bin/firewall-config", line 1007, in change_zone_connection_editor
        editor.run()
      File "/usr/bin/firewall-config", line 5301, in run
        settings = connection_obj.GetSettings()
      File "/usr/lib/python3.4/site-packages/dbus/proxies.py", line 70, in __call__
        return self._proxy_method(*args, **keywords)
      File "/usr/lib/python3.4/site-packages/slip/dbus/proxies.py", line 51, in __call__
        return dbus.proxies._ProxyMethod.__call__(self, *args, **kwargs)
      File "/usr/lib/python3.4/site-packages/dbus/proxies.py", line 145, in __call__
        **keywords)
      File "/usr/lib/python3.4/site-packages/dbus/connection.py", line 651, in call_blocking
        message, timeout)
    dbus.exceptions.DBusException: org.freedesktop.DBus.Error.AccessDenied: Rejected send message, 8 matched rules; type="method_call", sender=":1.78" (uid=2290 pid=4997 comm="/usr/bin/python -Es /usr/bin/firewall-config ") interface="(unset)" member="GetSettings" error name="(unset)" requested_reply="0" destination=":1.6" (uid=0 pid=1461 comm="/usr/bin/NetworkManager --no-daemon ")
    So, it is some permission problem.  If I run firewall-config as root and try again, everything works as intended.  So, I think this is DBUS or Polkit configuration problem.  Is there some way to determine why access is denied or what DBUS call is being attempted?  I have tried dbus-monitor and d-feet, but I still can't find the call the fails.  (I have never had to troubleshoot DBUS calls before, so I'm quite confused as is.)
    What's weird is I can change the firewall zone of the network configuration using nm-connection-editor.  So is this bug in how firewall-config and NetworkManager communicate?
    Any advice on which permissions to check would be greatly appreciated.

    Hi Kristian.
    The problem in my case was the RRAS/Gateway system was no longer available.  Unfortunately, VMM still "wanted" to connect to it to complete the removal; regardless of the dependency order.  (BTW, I was trying to remove objects in the
    correct order.)
    I expect VMM should be enhanced to allow objects, such as the ones I had, to be removed if the communication with the backing system fails.  Say, a warning/confirmation/force popup with the GUI, or something somilar for the various PowerShell cmdlets.
    - Mark

  • Proper TLS Config for IronPort C170

    I inherited an infrastructure a little bit ago that uses an IronPort C170 cluster for email security. I have been tasked with configuring TLS connections with our new medical benefits provider and have some issues doing so. We have 3 MX records, let's call them mail1, mail2 and mail3. Mail1 and mail2 are configured normally on our firewall to pass SMTP traffic on port 25 to the MailListener port on the IronPort which is 25. Mail3, however, is configured on the firewall to translate SMTP traffic on port 25 to port 3600 which is sent to the TLS Listener port 3600 on the IronPort. The IronPort MailInterfaces are configured as such (25,3600) Reverse configuration on the firewall takes any port 3600 traffic from the IronPort and translates it to port 25 traffic for the rest of the world.
    I configured the IronPort with a new Sender Group named TLS_ACCEPT,  added all the medical provider domain names/IPs to it and assigned it to  the ACCEPTED Mail Flow Policy where TLS is set to Required. Likewise,  for outgoing, I specified the same domain names/IPs within the  Destination Controls to require TLS for sending purposes.
    I replaced the guy who originally configured this so I am not too sure how it is setup on the other end for TLS connections already established. We do have a few in place that are active. I am assuming that the other end is configured to send email only to the mail3 MX record. This configuration, however, is not possible with our medical provider so I need an alternative. They have verified that they cannot contact us on mail1 or mail2 via TLS but can with mail3.
    The obvious problem is if a sender from these new domains tries to send TLS_required emails to us over the mail1 and mail2 MX IPs, they will receive an NDR. If I configure the firewall to translate mail1 and mail2 incoming connections from port 25 to 3600, any email sent with TLS not prefered/required will get an NDR. This was actually tested and domains like Yahoo and Hotmail could not send to us.
    Are there any options for me on the IronPort to allow these connections to be sent from all our MX IPs without having to translate the ports? If not, what would happen if I changed the TLS Listener port on the IronPort to 25 instead of 3600 and disabled all the NAT rules on the firewall for mail3? I am only to assume this translation was another security step added by the previous admin here but am not too sure what would happen if I eliminated it.
    Any advice, help, questions, assistance or fun-poking would be greatly appreciated!! Thank you in advance!

    Kevin,
    OMG there's so much unneeded complication here...You can totally ditch the port translation
    Here's what I did:
    Under Network/IP interfaces, I have 3 interfaces:  managment, Public, Private.
         Public is exposed to the net, only port 25 allowed in/out, with 1 A  record for a Domain1 which I have a certificate for.
    Under Network/Listener I have 2 Listeners: 
         Outbound on the Private interface not really relavent for the rest of this discussion
         Inbound on the Public interface
              listening on port 25
              using an Accept query pointed at my Active Directory (all the various email domains in 1 AD)
              using a cert that matches the hostname on the Public interface
              Mail flow polices in HAT all set to TLS preferred with an address list configed for the "required" ones
    Mail Policies/Destination Controls to force sending as TLS
    In my external DNS
         Domain1
              A  mail.domain1.com  x.x.x.
              mx domain1.com  mail.domain1.com pref 10 weight 10 TTL 86400
         Domain2-10
              mx domain2.com mail.domain1.com
              mx domain3.com mail.domain1.com
         etc....
    Hope that helps...
    Ken    

  • Training and event management - create new type of attendee

    Hi all,
    For training and event management, I have to create a new type of attendee besides sap existing attendee type such as company, contact person, customer, external person and so on.
    Via IMG -> Training and event management -> basic settings -> object type modeling enhancement -> object type -> define object types, then how can I define OrgObj Type for new object type I want to create?
    Thanks & regards,
    WCC

    S_AHR_61016216 - Cancellations per Attendee , i think there is no standard report for cencelation of business events, type and group.
    for cancellations per attendee reports is available in the system.
    good luck
    Devi

  • Config for Production client

    Dear all,
    I'm a new basis and now I'm working in big project ERP. I have a disturbed about config for Production client.
    In scc4 we must set client role is Production and No change allowed for Objects. But in production some time we need do Open and Close Period, or change following business requirement, ... This is not allowed to do in Production client.
    How do we config for Production client to cover this requirements ?
    Do we need a config client for maintain Production client ? Example: Production client is 500, Config client is 100. When we need Open or Close Period or change anything, we do in 100 and transfer request to 500.
    Thank you very much.
    Regards,
    Thanh.
    Do not use text message language, the next time your thread will be deleted.
    Read the "Rules of Engagement"
    Edited by: Juan Reyes on Dec 1, 2010 11:06 AM

    You can customize transaction to be executable although the setting in SCC4 is "productive", this is accomplished by using transaction SOBJ:
    Note 1497640 - Open and close periods in productive client
    You can theoretically put every customizing view there and make it "executable" in a production system.
    Markus

  • What brands and type can I use for my iMac 20" internal Hard Drive?

    what brands and type can I use for my iMac 20" aluminium internal Hard Drive?
    can I use WD caviar black?
    is it too hot?

    If you are replacing the drive because the existing one is faulty, that's one thing. If you just want more space, you should take advantage of having a decently fast and relatively small capacity drive in there now (instead of a huge drive). Get an external FireWire drive and off-load most of your user data there. Make your internal drive dedicated to mostly your OS and app files, with plenty of free space. That setup will make your iMac run more efficiently. I won't go into more detail, because I'm not answered your specific question... You can post back with any questions, if interested...
    To answer your questions...
    You should be able to use any SATA 3.5-inch drive internally, but you should probably keep it at or under 1TB. The main concerns are power usage and heat dissipation. A drive like the WD Caviar Green would be ideal in terms of power and heat, but they do have slower (or variable) spin rate. I have one as an external drive (750GB) and it is amazingly quiet and cool. If I had to replace the internal drive because the current drive failed, I'd put it inside. I'll trade a bit of pure performance for the efficiency (including low noise), and these drives are more advanced with higher data density and larger cache, so the trade-off from slower spin rate may not be so bad.
    You can check your current drive's model number (which is shown in System Profiler) to get the specs online. The stock drive in my old +Late 2006+ iMac is a 7200 RPM drive. The Caviar Black is a 7200 RPM drive, with a newer design. So if you want to use a Caviar Black in there, I think it would be OK.

Maybe you are looking for