[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

07/05/2009 at 05:34PM PDT, ID: 24545351
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

7.1

Networker 7.4.2 through a Cisco ASA5510

Asked by daveyp32 in Backup & Restore Software, Miscellaneous Networking

Tags: Networker 7.4.2, Cisco ASA5510

We have an ASA5510 that seperates 2 environments. The Client that we are trying to backup is in a DMZ. The Backup server sits in the Inside trusted network.
When we initiate the backups they do not complete and there are constant denies seen on the Firewall:
%ASA-6-106015: Deny TCP (no connection) from ausbps-meap02/2066 to ausbps-backup01/9544 flags RST on interface DMZ

We have open TCP rules between these 2 servers as seen in the config snipits seen below.
Are there any reasons that the backup client will send TCP FIN message within such a short period of time?
1:
2:
3:
4:
5:
6:
7:
8:
9:
10:
11:
12:
13:
14:
15:
16:
17:
18:
19:
20:
21:
22:
23:
24:
25:
26:
27:
28:
29:
30:
31:
32:
33:
34:
35:
36:
37:
38:
39:
40:
41:
42:
43:
44:
45:
46:
Firewall config:
interface Ethernet0/2.10
 vlan 10
 nameif DMZ#1
 security-level 50
 ip address 172.20.228.1 255.255.255.240 
!
 
interface Ethernet0/0
 nameif EPN-INSIDE
 security-level 100
 ip address 172.20.227.10 255.255.255.0 
!
!
name 172.20.228.5 ausbps-meap02
name 172.21.223.20 Hobbit-Monitor
name 172.20.223.11 ausbps-backup02 description EPN Backup Server
name 172.21.223.11 ausbps-backup01 description EPN Backup Server
 
object-group network BPS-EPN-Backup-Servers
 network-object host ausbps-backup02
 network-object host ausbps-backup01
!
object-group network BPS-EPN-Shared-Services
 network-object 172.20.223.0 255.255.255.224
 network-object 172.21.223.0 255.255.255.224
!
object-group network BPS-EPN-Management-and-Backup
 network-object host ausbps-backup02
 network-object host ausbps-backup01
 network-object host Hobbit-Monitor
!
 
 
access-list  DMZ#1_access_in extended permit tcp host ausbps-meap02 object-group BPS-EPN-Backup-Servers 
access-group  DMZ#1_access_in in interface SAI-DMZ
!
 
access-list EPN-INSIDE_access_in extended permit tcp object-group BPS-EPN-Management-and-Backup 172.20.228.0 255.255.255.240 
access-group EPN-INSIDE_access_in in interface EPN-INSIDE
!
 
 
access-list EPN-INSIDE_nat0_outbound extended permit ip object-group BPS-EPN-Shared-Services 172.20.228.0 255.255.255.240
nat (EPN-INSIDE) 0 access-list EPN-INSIDE_nat0_outbound
!
[+][-]07/05/09 06:51 PM, ID: 24782064

View this solution now by starting your 30-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Backup & Restore Software, Miscellaneous Networking
Tags: Networker 7.4.2, Cisco ASA5510
Sign Up Now!
Solution Provided By: meyersd
Participating Experts: 1
Solution Grade: B
 
 
 
Loading Advertisement...
20091028-EE-VQP-87 - Hierarchy / EE_QW_4_20070622