Access between 2 vlans

felipesch used Ask the Experts™
From wireless interface ( I can access the host on server farm ( But I can't access on DMZ ( Can we explain why?

My config:

: Saved
ASA Version 8.0(4)28 
hostname ciscoasa
enable password 8Ry2YjIyt7RRXU24 encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
interface Vlan1
 nameif serverfarm
 security-level 100
 ip address 
interface Vlan2
 nameif outside
 security-level 0
 pppoe client vpdn group brt
 ip address pppoe setroute 
interface Vlan12
 nameif dmz
 security-level 50
 ip address 
interface Vlan22
 nameif wireless
 security-level 100
 ip address 
interface Vlan32
 nameif media
 security-level 90
 ip address 
interface Ethernet0/0
 switchport access vlan 2
interface Ethernet0/1
interface Ethernet0/2
 switchport access vlan 12
interface Ethernet0/3
 switchport access vlan 22
interface Ethernet0/4
 switchport access vlan 32
interface Ethernet0/5
interface Ethernet0/6
interface Ethernet0/7
ftp mode passive
clock timezone BRT -3
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
access-list wireless_nat0_outbound extended permit ip 
access-list wireless_nat0_outbound extended permit ip 
access-list wireless_nat0_outbound extended permit ip 
access-list serverfarm_nat0_outbound extended permit ip 
access-list dmz_nat0_outbound extended permit ip 
pager lines 24
logging enable
logging asdm informational
mtu serverfarm 1500
mtu outside 1500
mtu dmz 1500
mtu wireless 1500
mtu media 1500
no failover
icmp unreachable rate-limit 1 burst-size 1
no asdm history enable
arp timeout 14400
global (outside) 1 interface
nat (serverfarm) 0 access-list serverfarm_nat0_outbound
nat (serverfarm) 1
nat (dmz) 0 access-list dmz_nat0_outbound
nat (dmz) 1
nat (wireless) 0 access-list wireless_nat0_outbound
nat (wireless) 1
nat (media) 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
dynamic-access-policy-record DfltAccessPolicy
http server enable
http wireless
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
telnet timeout 5
ssh timeout 5
console timeout 0
vpdn group brt request dialout pppoe
vpdn group brt localname xx@localturbo
vpdn group brt ppp authentication pap
vpdn username xx@localturbo password ********* store-local
dhcpd auto_config outside
dhcpd auto_config outside interface serverfarm
dhcpd address wireless
dhcpd auto_config outside interface wireless
dhcpd enable wireless
dhcpd address media
dhcpd auto_config outside interface media
dhcpd enable media

threat-detection basic-threat
threat-detection statistics access-list
no threat-detection statistics tcp-intercept
class-map inspection_default
 match default-inspection-traffic
policy-map type inspect dns preset_dns_map
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map 
  inspect ftp 
  inspect h323 h225 
  inspect h323 ras 
  inspect rsh 
  inspect rtsp 
  inspect esmtp 
  inspect sqlnet 
  inspect skinny  
  inspect sunrpc 
  inspect xdmcp 
  inspect sip  
  inspect netbios 
  inspect tftp 
service-policy global_policy global
prompt hostname context 
: end
no asdm history enable

Open in new window

Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Top Expert 2012
You need to change this line

access-list dmz_nat0_outbound extended permit ip

To this

access-list dmz_nat0_outbound extended permit ip
Istvan KalmarHead of IT Security Division
Top Expert 2010

This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial