<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Axelilly's Ponderings</title>
	<atom:link href="http://axelilly.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://axelilly.wordpress.com</link>
	<description>Just my thoughts and notes on various topics.</description>
	<lastBuildDate>Tue, 03 Jan 2012 21:44:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='axelilly.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Axelilly's Ponderings</title>
		<link>http://axelilly.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://axelilly.wordpress.com/osd.xml" title="Axelilly&#039;s Ponderings" />
	<atom:link rel='hub' href='http://axelilly.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Can&#8217;t mount a Windows 2008 share?</title>
		<link>http://axelilly.wordpress.com/2011/09/27/cant-mount-a-windows-2008-share/</link>
		<comments>http://axelilly.wordpress.com/2011/09/27/cant-mount-a-windows-2008-share/#comments</comments>
		<pubDate>Tue, 27 Sep 2011 14:34:18 +0000</pubDate>
		<dc:creator>axelilly</dc:creator>
				<category><![CDATA[linux]]></category>
		<category><![CDATA[TechTips]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://axelilly.wordpress.com/?p=178</guid>
		<description><![CDATA[If you are trying to mount a Windows 2008 (or potentially other versions of windows) share using mount.cifs and you keep getting an input/output error like the one below, then read on. [jason@superfreak ~]$ sudo mount //powerhouse-smb.mydomain.com/LogFiles /mnt/ecomm/ -tcifs -orw,username=doctor Password: mount error 5 = Input/output error Refer to the mount.cifs(8) manual page (e.g.man mount.cifs) [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=178&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>If you are trying to mount a Windows 2008 (or potentially other versions of windows) share using mount.cifs and you keep getting an input/output error like the one below, then read on.</p>
<p>[jason@superfreak ~]$ sudo mount //powerhouse-smb.mydomain.com/LogFiles /mnt/ecomm/ -tcifs -orw,username=doctor<br />
Password:<br />
mount error 5 = Input/output error<br />
Refer to the mount.cifs(8) manual page (e.g.man mount.cifs)</p>
<p>The error reporting that is provided by mount.cifs is really not that good.  That input/output error could really mean anything.  Let&#8217;s use smbclient to attempt a connection to the share.  smbclient is sort of like a FTP client, but used to connect to a SMB share.  However, the real reason why we are using it is because it gives much more detailed error reporting by default.  Also, you could increase the debug level to some truly insane detail.</p>
<p>[jason@superfreak ~]$ smbclient //powerhouse-smb.mydomain.com/LogFiles -U doctor<br />
Enter doctor&#8217;s password:<br />
Domain=[POWERHOUSE] OS=[Windows Server 2008 R2 Standard 7601 Service Pack 1] Server=[Windows Server 2008 R2 Standard 6.1]<br />
tree connect failed: NT_STATUS_DUPLICATE_NAME</p>
<p>Finally, some more detail.  The error message &#8216;NT_STATUS_DUPLICATE_NAME&#8217; indicates that the connection was denied by the windows server because the destination host name that I provided was different then the computer name set on the actual destination server.  This is a security feature in Windows Server 2008 (and likely other versions of Windows).  In my case this is because I access the server through a load balancer.  There is a special virtual service on the load balancer to allow the SMB connection into the server.  However, for you the mismatch might be caused by a alias in your hosts file, bad DNS entry or simply even a mistype.</p>
<p>Now try the mount operation using the IP addresses instead of the hostname.  Using just the IP address will not cause that security check to trip.  Now it should work with no issues.</p>
<p>Happy Hacking.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/axelilly.wordpress.com/178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/axelilly.wordpress.com/178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/axelilly.wordpress.com/178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/axelilly.wordpress.com/178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/axelilly.wordpress.com/178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/axelilly.wordpress.com/178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/axelilly.wordpress.com/178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/axelilly.wordpress.com/178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/axelilly.wordpress.com/178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/axelilly.wordpress.com/178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/axelilly.wordpress.com/178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/axelilly.wordpress.com/178/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/axelilly.wordpress.com/178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/axelilly.wordpress.com/178/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=178&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://axelilly.wordpress.com/2011/09/27/cant-mount-a-windows-2008-share/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0d0afaebdcff6a0581f567fd6c7f8a40?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">axelilly</media:title>
		</media:content>
	</item>
		<item>
		<title>View the contents of a SSL cert.</title>
		<link>http://axelilly.wordpress.com/2011/09/14/view-the-contents-of-a-ssl-cert/</link>
		<comments>http://axelilly.wordpress.com/2011/09/14/view-the-contents-of-a-ssl-cert/#comments</comments>
		<pubDate>Wed, 14 Sep 2011 17:45:36 +0000</pubDate>
		<dc:creator>axelilly</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[openssl]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://axelilly.wordpress.com/?p=175</guid>
		<description><![CDATA[Did you just find a thisserver.crt file on your machine and you want to check the details of what it&#8217;s for? In other words you have a SSL certificate that you want to decode. You need to be on Linux and have OpenSSL installed. Then use the x509 module: openssl x509 -text -in thisserver.crt Enjoy!<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=175&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Did you just find a thisserver.crt file on your machine and you want to check the details of what it&#8217;s for?  In other words you have a SSL certificate that you want to decode.</p>
<p>You need to be on Linux and have OpenSSL installed.  Then use the x509 module:</p>
<p>openssl x509 -text -in thisserver.crt</p>
<p>Enjoy!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/axelilly.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/axelilly.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/axelilly.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/axelilly.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/axelilly.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/axelilly.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/axelilly.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/axelilly.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/axelilly.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/axelilly.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/axelilly.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/axelilly.wordpress.com/175/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/axelilly.wordpress.com/175/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/axelilly.wordpress.com/175/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=175&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://axelilly.wordpress.com/2011/09/14/view-the-contents-of-a-ssl-cert/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0d0afaebdcff6a0581f567fd6c7f8a40?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">axelilly</media:title>
		</media:content>
	</item>
		<item>
		<title>Add and remove SCSI hot to linux.</title>
		<link>http://axelilly.wordpress.com/2011/08/04/add-and-remove-scsi-hot-to-linux/</link>
		<comments>http://axelilly.wordpress.com/2011/08/04/add-and-remove-scsi-hot-to-linux/#comments</comments>
		<pubDate>Thu, 04 Aug 2011 15:24:35 +0000</pubDate>
		<dc:creator>axelilly</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://axelilly.wordpress.com/?p=173</guid>
		<description><![CDATA[I do file restores from snapshots using a linux server.  In my case it&#8217;s Centos. I do this by creating a disk resource from a snapshot on my IPStor SAN.  Then I assign the new resource to all nodes of my HQ VMWare cluster. Create a disk resource from a snapshot on my IPStor SAN. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=173&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I do file restores from snapshots using a linux server.  In my case it&#8217;s Centos.</p>
<p>I do this by creating a disk resource from a snapshot on my IPStor SAN.  Then I assign the new resource to all nodes of my HQ VMWare cluster.</p>
<ol>
<li>Create a disk resource from a snapshot on my IPStor SAN.</li>
<li>Assign the new resource to all nodes of my HQ VMWare cluster.</li>
<li>In VMWare, set the path settings for the new FC resource to round robin.  (Do this on each node in the cluster.)</li>
<li>Add the resource to the restore linux server as a Raw Device Mappings.</li>
<li>SSH into Linux server used for doing restores.</li>
<li>Rescan the SCSI bus in order to make the new device available for mount.     Replace the &#8220;X&#8221; with the proper host number.</li>
</ol>
<p>echo &#8220;- &#8211; - &#8221; &gt; /sys/class/scsi_host/hostX/scan</p>
<ul>
<li>View the /var/log/messages file in order to determine what block device ID this resource has showed up as. In the example output, you will notice in green that this resource is registered as block device sdb1.  Look for some output like this:</li>
</ul>
<pre>Aug  4 10:48:28 zenoss ntfs-3g[7273]: Unmounting /dev/sdb1 (Users)
Aug  4 11:06:22 zenoss kernel:   Vendor: VMware    Model: Virtual disk      Rev: 1.0
Aug  4 11:06:22 zenoss kernel:   Type:   Direct-Access                      ANSI SCSI revision: 02
Aug  4 11:06:22 zenoss kernel:  target0:0:1: Beginning Domain Validation
Aug  4 11:06:22 zenoss kernel:  target0:0:1: Domain Validation skipping write tests
Aug  4 11:06:22 zenoss kernel:  target0:0:1: Ending Domain Validation
Aug  4 11:06:22 zenoss kernel:  target0:0:1: FAST-40 WIDE SCSI 80.0 MB/s ST (25 ns, offset 127)
Aug  4 11:06:22 zenoss kernel: SCSI device sdb: 1572864000 512-byte hdwr sectors (805306 MB)
Aug  4 11:06:22 zenoss kernel: sdb: Write Protect is off
Aug  4 11:06:22 zenoss kernel: sdb: cache data unavailable
Aug  4 11:06:22 zenoss kernel: sdb: assuming drive cache: write through
Aug  4 11:06:22 zenoss kernel: SCSI device sdb: 1572864000 512-byte hdwr sectors (805306 MB)
Aug  4 11:06:22 zenoss kernel: sdb: Write Protect is off
Aug  4 11:06:22 zenoss kernel: sdb: cache data unavailable
Aug  4 11:06:22 zenoss kernel: sdb: assuming drive cache: write through
Aug  4 11:06:22 zenoss kernel:  sdb: <span style="color:#008080;">sdb1</span>
Aug  4 11:06:22 zenoss kernel: sd 0:0:1:0: Attached scsi disk sdb
Aug  4 11:06:22 zenoss kernel: sd 0:0:1:0: Attached scsi generic sg1 type 0</pre>
<ul>
<li>Make sure that you can see the new resource.</li>
</ul>
<p>cat /proc/scsi/scsi</p>
<ul>
<li>Mount the new resource to a available mount spot.</li>
</ul>
<pre>mount /dev/sdb1 /mnt/recover1</pre>
<ul>
<li>Do your restore by copying off the files that you need&#8230;.yada yada yada</li>
<li>Now it is time to unmount and disconnect the restore resource.</li>
<li>unmount the block device:</li>
</ul>
<p>umount /dev/sdb1 /mnt/recover1</p>
<ul>
<li>Delete the SCSI resource from the SCSI bus:</li>
</ul>
<blockquote><p>echo &#8220;scsi remove-single-device a b c d&#8221; &gt; /proc/scsi/scsi<br />
a == hostadapter id (first one being 0)<br />
b == SCSI channel on hostadapter (first one being 0)<br />
c == ID<br />
d == LUN (first one being 0)</p></blockquote>
<ul>
<li>Make sure the resource is gone.</li>
</ul>
<p>cat /proc/scsi/scsi</p>
<ul>
<li>Now remove the RDM from the virtual host.</li>
<li>Remove SAN assignment of the snapshot resource from VMWare cluster.</li>
<li>Have vmware hosts rescan their FC connectsions.</li>
<li>Delete snap shot resource from SAN.</li>
<li>You are done.</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/axelilly.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/axelilly.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/axelilly.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/axelilly.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/axelilly.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/axelilly.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/axelilly.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/axelilly.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/axelilly.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/axelilly.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/axelilly.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/axelilly.wordpress.com/173/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/axelilly.wordpress.com/173/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/axelilly.wordpress.com/173/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=173&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://axelilly.wordpress.com/2011/08/04/add-and-remove-scsi-hot-to-linux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0d0afaebdcff6a0581f567fd6c7f8a40?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">axelilly</media:title>
		</media:content>
	</item>
		<item>
		<title>Empathy needs a OTR plugin.</title>
		<link>http://axelilly.wordpress.com/2011/07/25/empathy-needs-a-otr-plugin/</link>
		<comments>http://axelilly.wordpress.com/2011/07/25/empathy-needs-a-otr-plugin/#comments</comments>
		<pubDate>Mon, 25 Jul 2011 15:37:18 +0000</pubDate>
		<dc:creator>axelilly</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://axelilly.wordpress.com/?p=168</guid>
		<description><![CDATA[I just switched over to using Empathy for my IM client. I really like it better then Pidgin because it has much smoother integration with GNOME3 and is slicker looking. However, one of the things that it is really lacking is the fact that it doesn&#8217;t have plugins. Since it doesn&#8217;t have plugins, I can&#8217;t [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=168&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I just switched over to using Empathy for my IM client.  I really like it better then Pidgin because it has much smoother integration with GNOME3 and is slicker looking.  However, one of the things that it is really lacking is the fact that it doesn&#8217;t have plugins.  Since it doesn&#8217;t have plugins, I can&#8217;t use encryption such as OTR (Off The Record).  </p>
<p>I hope the Empathy fairies here this and that OTR gets added some time. </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/axelilly.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/axelilly.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/axelilly.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/axelilly.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/axelilly.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/axelilly.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/axelilly.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/axelilly.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/axelilly.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/axelilly.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/axelilly.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/axelilly.wordpress.com/168/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/axelilly.wordpress.com/168/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/axelilly.wordpress.com/168/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=168&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://axelilly.wordpress.com/2011/07/25/empathy-needs-a-otr-plugin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0d0afaebdcff6a0581f567fd6c7f8a40?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">axelilly</media:title>
		</media:content>
	</item>
		<item>
		<title>TFTP new software onto ASA from a TFTP server on other side of VPN tunnel.</title>
		<link>http://axelilly.wordpress.com/2011/07/22/tftp-new-software-onto-asa-from-a-tftp-server-on-other-side-of-vpn-tunnel/</link>
		<comments>http://axelilly.wordpress.com/2011/07/22/tftp-new-software-onto-asa-from-a-tftp-server-on-other-side-of-vpn-tunnel/#comments</comments>
		<pubDate>Fri, 22 Jul 2011 17:49:57 +0000</pubDate>
		<dc:creator>axelilly</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[asa]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[TFTP]]></category>

		<guid isPermaLink="false">http://axelilly.wordpress.com/?p=166</guid>
		<description><![CDATA[If you need to TFTP new software (or any other file for that fact) onto a ASA from a TFTP server that is on the other side of a VPN tunnel, you will need to specify the source interface for the TFTP client to use. The easiest way to do this, is to specify it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=166&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>If you need to TFTP new software (or any other file for that fact) onto a ASA from a TFTP server that is on the other side of a VPN tunnel, you will need to specify the source interface for the TFTP client to use.</p>
<p>The easiest way to do this, is to specify it inline with the copy command:</p>
<pre>
 copy tftp://192.168.1.30/ASA/asa842-k8.bin;int=INSIDE-management disk0:/asa842-k8.bin</pre>
<p>Where, 192.168.1.30 is the IP of the TFTP server. INSIDE-management should be replaced with whatever interface you want to use as source.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/axelilly.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/axelilly.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/axelilly.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/axelilly.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/axelilly.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/axelilly.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/axelilly.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/axelilly.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/axelilly.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/axelilly.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/axelilly.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/axelilly.wordpress.com/166/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/axelilly.wordpress.com/166/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/axelilly.wordpress.com/166/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=166&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://axelilly.wordpress.com/2011/07/22/tftp-new-software-onto-asa-from-a-tftp-server-on-other-side-of-vpn-tunnel/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0d0afaebdcff6a0581f567fd6c7f8a40?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">axelilly</media:title>
		</media:content>
	</item>
		<item>
		<title>No security exception for SSL EV certificates in Fire Fox 3.6.17</title>
		<link>http://axelilly.wordpress.com/2011/05/18/no-security-exception-for-ssl-ev-certificates-in-fire-fox-3-6-17/</link>
		<comments>http://axelilly.wordpress.com/2011/05/18/no-security-exception-for-ssl-ev-certificates-in-fire-fox-3-6-17/#comments</comments>
		<pubDate>Wed, 18 May 2011 14:05:12 +0000</pubDate>
		<dc:creator>axelilly</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://axelilly.wordpress.com/?p=162</guid>
		<description><![CDATA[Today I learned something new about Fire Fox 3.6.17. I was migrating a SSL EV certificate from a IIS server onto a Virtual Server that is located on a KEMP LoadMaster. This test server on the LM is running a prototype/test site. Therefore, the domain name doesn&#8217;t match the domain name that the SSL cert [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=162&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Today I learned something new about Fire Fox 3.6.17. I was migrating a SSL EV certificate from a IIS server onto a Virtual Server that is located on a KEMP LoadMaster. This test server on the LM is running a prototype/test site. Therefore, the domain name doesn&#8217;t match the domain name that the SSL cert was created for. This normally will create a SSL name mismatch error in the web browser. This error normally can then be bypassed by the user, this process is called &#8220;Security Exception&#8221; in Fire Fox. I went to add this exception and found that Fire Fox wouldn&#8217;t allow me to add it. What&#8217;s interesting is that the exception window tells you that the identification of the certificate is so positive that there is no reason for you to add an exception.<br />
<code><br />
This site provides valid, verified identification. There is no need to add an exception.</code></p>
<p>I think this is a good thing.  It really helps make the EV certificates more strong and adds value to them.  I guess I&#8217;ll go back to using a self signed certificate for testing.</p>
<div id="attachment_163" class="wp-caption aligncenter" style="width: 310px"><a href="http://axelilly.files.wordpress.com/2011/05/screenshot-addsecurityexception.png"><img class="size-medium wp-image-163" title="Screenshot-AddSecurityException" src="http://axelilly.files.wordpress.com/2011/05/screenshot-addsecurityexception.png?w=300&#038;h=287" alt="" width="300" height="287" /></a><p class="wp-caption-text">No security exception.</p></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/axelilly.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/axelilly.wordpress.com/162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/axelilly.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/axelilly.wordpress.com/162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/axelilly.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/axelilly.wordpress.com/162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/axelilly.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/axelilly.wordpress.com/162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/axelilly.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/axelilly.wordpress.com/162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/axelilly.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/axelilly.wordpress.com/162/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/axelilly.wordpress.com/162/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/axelilly.wordpress.com/162/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=162&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://axelilly.wordpress.com/2011/05/18/no-security-exception-for-ssl-ev-certificates-in-fire-fox-3-6-17/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0d0afaebdcff6a0581f567fd6c7f8a40?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">axelilly</media:title>
		</media:content>

		<media:content url="http://axelilly.files.wordpress.com/2011/05/screenshot-addsecurityexception.png?w=300" medium="image">
			<media:title type="html">Screenshot-AddSecurityException</media:title>
		</media:content>
	</item>
		<item>
		<title>suid, sgid, sticky bit</title>
		<link>http://axelilly.wordpress.com/2010/12/15/suid-sgid-sticky-bit/</link>
		<comments>http://axelilly.wordpress.com/2010/12/15/suid-sgid-sticky-bit/#comments</comments>
		<pubDate>Wed, 15 Dec 2010 16:38:03 +0000</pubDate>
		<dc:creator>axelilly</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[bash]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[permissions]]></category>

		<guid isPermaLink="false">http://axelilly.wordpress.com/?p=159</guid>
		<description><![CDATA[Great quick reference article on suid, sguid and sticky bit. http://www.zzee.com/solutions/linux-permissions.shtml<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=159&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Great quick reference article on suid, sguid and sticky bit.</p>
<p>http://www.zzee.com/solutions/linux-permissions.shtml</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/axelilly.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/axelilly.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/axelilly.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/axelilly.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/axelilly.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/axelilly.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/axelilly.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/axelilly.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/axelilly.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/axelilly.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/axelilly.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/axelilly.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/axelilly.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/axelilly.wordpress.com/159/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=159&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://axelilly.wordpress.com/2010/12/15/suid-sgid-sticky-bit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0d0afaebdcff6a0581f567fd6c7f8a40?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">axelilly</media:title>
		</media:content>
	</item>
		<item>
		<title>What do the &#8216;ls&#8217; colors mean in BASH?</title>
		<link>http://axelilly.wordpress.com/2010/12/15/what-do-the-ls-colors-mean-in-bash/</link>
		<comments>http://axelilly.wordpress.com/2010/12/15/what-do-the-ls-colors-mean-in-bash/#comments</comments>
		<pubDate>Wed, 15 Dec 2010 16:27:35 +0000</pubDate>
		<dc:creator>axelilly</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[bash]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">http://axelilly.wordpress.com/?p=157</guid>
		<description><![CDATA[Ever wonder what all the default colors outputed by ls in BASH mean? These are some of the common default ones: Executable files: Green * Normal file : Normal * Directory: Blue * Symbolic link : Cyan * Pipe: Yellow * Socket: Magenta * Block device driver: Bold yellow foreground, with black background * Character [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=157&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Ever wonder what all the default colors outputed by ls in BASH mean?  These are some of the common default ones:</p>
<p>Executable files: Green<br />
* Normal file : Normal<br />
* Directory: Blue<br />
* Symbolic link : Cyan<br />
* Pipe: Yellow<br />
* Socket: Magenta<br />
* Block device driver: Bold yellow foreground, with black background<br />
* Character device driver: Bold yellow foreground, with black background<br />
* Orphaned syminks : Blinking Bold white with red background<br />
* Missing links ( &#8211; and the files they point to) : Blinking Bold white with red background<br />
* Archives or compressed : Red (.tar, .gz, .zip, .rpm)<br />
* Image files : Magenta (.jpg, gif, bmp, png, tif)</p>
<p>Ganked from: http://www.cyberciti.biz/tips/where-is-color-of-ls-command-defined.html</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/axelilly.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/axelilly.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/axelilly.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/axelilly.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/axelilly.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/axelilly.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/axelilly.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/axelilly.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/axelilly.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/axelilly.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/axelilly.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/axelilly.wordpress.com/157/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/axelilly.wordpress.com/157/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/axelilly.wordpress.com/157/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=157&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://axelilly.wordpress.com/2010/12/15/what-do-the-ls-colors-mean-in-bash/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0d0afaebdcff6a0581f567fd6c7f8a40?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">axelilly</media:title>
		</media:content>
	</item>
		<item>
		<title>Ping inside interface of ASA accross a VPN tunnel.</title>
		<link>http://axelilly.wordpress.com/2010/10/14/ping-inside-interface-of-asa-accross-a-vpn-tunnel/</link>
		<comments>http://axelilly.wordpress.com/2010/10/14/ping-inside-interface-of-asa-accross-a-vpn-tunnel/#comments</comments>
		<pubDate>Thu, 14 Oct 2010 16:15:09 +0000</pubDate>
		<dc:creator>axelilly</dc:creator>
				<category><![CDATA[TechTips]]></category>
		<category><![CDATA[asa]]></category>
		<category><![CDATA[cisco]]></category>

		<guid isPermaLink="false">http://axelilly.wordpress.com/?p=155</guid>
		<description><![CDATA[Do you need to ping the inside interface of a ASA across a VPN tunnel? Maybe you need to do this for monitoring purposes, or whatever. Allow access of ICMP to the inside interface: icmp permit host 192.168.1.10 inside Monitoring station &#8212;&#62; 192.168.1.10 Inside interface &#8212;&#62; inside<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=155&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Do you need to ping the inside interface of a ASA across a VPN tunnel?<br />
Maybe you need to do this for monitoring purposes, or whatever.</p>
<p>Allow access of ICMP to the inside interface:<br />
icmp permit host 192.168.1.10 inside</p>
<p>Monitoring station &#8212;&gt; 192.168.1.10<br />
Inside interface &#8212;&gt; inside</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/axelilly.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/axelilly.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/axelilly.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/axelilly.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/axelilly.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/axelilly.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/axelilly.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/axelilly.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/axelilly.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/axelilly.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/axelilly.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/axelilly.wordpress.com/155/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/axelilly.wordpress.com/155/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/axelilly.wordpress.com/155/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=155&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://axelilly.wordpress.com/2010/10/14/ping-inside-interface-of-asa-accross-a-vpn-tunnel/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0d0afaebdcff6a0581f567fd6c7f8a40?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">axelilly</media:title>
		</media:content>
	</item>
		<item>
		<title>Notes on ASA 8.3 NAT</title>
		<link>http://axelilly.wordpress.com/2010/10/13/notes-on-asa-8-3-nat/</link>
		<comments>http://axelilly.wordpress.com/2010/10/13/notes-on-asa-8-3-nat/#comments</comments>
		<pubDate>Wed, 13 Oct 2010 15:19:04 +0000</pubDate>
		<dc:creator>axelilly</dc:creator>
				<category><![CDATA[TechTips]]></category>
		<category><![CDATA[asa]]></category>
		<category><![CDATA[cisco]]></category>

		<guid isPermaLink="false">http://axelilly.wordpress.com/?p=146</guid>
		<description><![CDATA[Cisco ASA 8.3 has introduced major changes in how NAT is configured and operates. This video is a excellent resource for a basic introduction to NAT on ASA 8.3 software: https://supportforums.cisco.com/docs/DOC-12324 Here are some quick notes that I have gathered for my reference.  Feel free to post any additional comments and notes you may have [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=146&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Cisco ASA 8.3 has introduced major changes in how NAT is configured and operates.</p>
<p>This video is a excellent resource for a basic introduction to NAT on ASA 8.3 software:</p>
<p>https://supportforums.cisco.com/docs/DOC-12324</p>
<p><span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='495' height='309' src='http://www.youtube.com/embed/REGJodyLJEU?version=3&amp;rel=1&amp;fs=1&amp;showsearch=0&amp;showinfo=1&amp;iv_load_policy=1&amp;wmode=transparent' frameborder='0'></iframe></span><br />
Here are some quick notes that I have gathered for my reference.  Feel free to post any additional comments and notes you may have to share:</p>
<p><span style="text-decoration:underline;"><strong>COMMANDS</strong></span></p>
<pre>show run objects</pre>
<p>(Displays network and service objects that are in the running confg)</p>
<pre>show run object id</pre>
<p>(Displays a specific object)</p>
<pre>show run nat</pre>
<p>(Displays running config NAT configurations)</p>
<pre>show nat</pre>
<p>(Displays NAT policies and counters)</p>
<p><span style="text-decoration:underline;"><strong>Use packet-tracer for testing NAT (and other things)</strong></span></p>
<pre>packet-tracer input inside tcp 10.0.0.40 4444 198.133.219.25 80</pre>
<p><strong> </strong></p>
<ul> <strong>Configure Auto-NAT: </strong></ul>
<p><strong> </strong></p>
<pre>object network inside
   subnet 192.168.1.0 255.255.255.0
   nat (inside,outside) dynamic interface</pre>
<p>Note:  This will configure PAT onto the outside interface for the inside subnet, while at the same time configuring the network object for the inside subnet.</p>
<p><strong>
<ul>
Configure Twice(manual) NAT:<br />
</strong></ul>
<pre>
nat (inside,outside) source dynamic inside-net translated-ip destination static cisco-dot-com cisco-dot-com
</pre>
<p>Note:  You must first define the network objects for the source and destination before configuring manual NAT.  In this example, the source IP address of the inside host is translated to &#8220;translated-ip&#8221; only when the dynamic host is sending a packet that is destined to &#8220;cisco-dot-com&#8221;.  cisco-dot-com is entered twice because we are not translating the destination.  If we wanted to translate the destination, we would do it here.</p>
<p><strong>
<ul>
Exempt subnets from NAT because of VPN tunnel:<br />
</strong></ul>
<pre>
nat (inside,outside) static inside-net inside-net destination static vpn-subnets vpn-subnets
</pre>
<p>This statement will catch traffic on the inside trying to go to the outside.  Traffic that matches the source and destination is operated on but no change is made.</p>
<p><strong> </strong></p>
<ul><strong>General Notes:</strong></ul>
<p>ASA 8.3 has two types of NAT: Auto-NAT and Twice (manual) NAT.  You can use Auto-NAT for most NAT/PAT operations, except for ones that need to make a decision based upon the destination address of a packet.</p>
<p>With ASA 8.3, a new change called &#8220;Real IP&#8221; was introduced.  Real IP means that NAT translation happens BEFORE a ACL is checked.  Therefore ACLs must contain the real IP address of the host that the inbound packet is headed towards.  In other words, do not write the ACL to match on the &#8220;mapped&#8221; IP address.  The real IP address is normally a non-routable IP address.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/axelilly.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/axelilly.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/axelilly.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/axelilly.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/axelilly.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/axelilly.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/axelilly.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/axelilly.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/axelilly.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/axelilly.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/axelilly.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/axelilly.wordpress.com/146/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/axelilly.wordpress.com/146/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/axelilly.wordpress.com/146/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=axelilly.wordpress.com&amp;blog=1791500&amp;post=146&amp;subd=axelilly&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://axelilly.wordpress.com/2010/10/13/notes-on-asa-8-3-nat/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/0d0afaebdcff6a0581f567fd6c7f8a40?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96" medium="image">
			<media:title type="html">axelilly</media:title>
		</media:content>
	</item>
	</channel>
</rss>
