Error portmap translation creation failed

I am conf. thru ASDM for ASA 5550.
I have two zones  : ITZONE  & USERZONE.
ITZONE  - 192.168.1.0/24
USERZONE - 192.168.200.0/26

POlicy created as ITZONE  192.168.1.100/24 to USERZONE 192.168.200.15/26 PORT 3389.

When trying to access i am getting error.
portmap translation creation failed for tcp src ITZONE :192.168.1.100/2195 dst USERZONE:192.168.200.15/3389
vkraamanAsked:
Who is Participating?
 
qbakiesCommented:
You need to allow interfaces with the same security level to communicate.  Use this command:

same-security-traffic permit inter-interface
0
 
Istvan KalmarHead of IT Security Division Commented:
Hi,

Did you enabled nonat between zones? Did you enabled on lowers security interface with ACL this traffic?

Please show us the config


Best regards,
Istvan
0
 
vkraamanAuthor Commented:
interface Management0/0
 description ***ip address 172.29.100.7 255.255.254.0 standby 172.29.100.9***
 shutdown
 nameif management
 security-level 100
 no ip address
 management-only
!
interface GigabitEthernet1/1
 description ***USERZONE - KK***
 nameif USERZONE
 security-level 100
 ip address 192.168.200.1 255.255.255.192 standby 192.168.200.2
fwconf-ee.txt
0
KuppingerCole Reviews AlgoSec in Executive Report

Leading analyst firm, KuppingerCole reviews AlgoSec's Security Policy Management Solution, and the security challenges faced by companies today in their Executive View report.

 
vkraamanAuthor Commented:
interface GigabitEthernet0/1
 description ***ITZONE NETWORK***
 nameif ITZONE
 security-level 100
 ip address 192.168.1.100 255.255.255.0 standby 192.168.1.50
!
interface Management0/0
 description ***ip address 172.29.100.7 255.255.254.0 standby 172.29.100.9***
 shutdown
 nameif management
 security-level 100
 no ip address
 management-only
!
interface GigabitEthernet1/1
 description ***USERZONE - KK***
 nameif USERZONE
 security-level 100
 ip address 192.168.200.1 255.255.255.192 standby 192.168.200.2
!
0
 
vkraamanAuthor Commented:
Thanks but
interface GigabitEthernet0/1
 description ***ITZONE NETWORK***
 nameif ITZONE
 security-level 100
 ip address 192.168.1.100 255.255.255.0 standby 192.168.1.50
!
interface GigabitEthernet1/1
 description ***USERZONE - KK***
 nameif USERZONE
 security-level 100
 ip address 192.168.200.1 255.255.255.192 standby 192.168.200.2
!
both interfaces are  security-level 100
0
 
LingerLongerCommented:
Right, so you must enter the command suggested by qbakies to get the two interfaces to talk. Despite being the same security level, they will not talk between each other without that command.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.