<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CBAC Difficults with Web page Viewing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cbac-difficults-with-web-page-viewing/m-p/806204#M1007933</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using CBAC on an 877w and get to this site fine. What I think is that you aren't letting out other things that the website might be using. My CBAC inspection list includes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND http&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND https&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND ftp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND icmp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND dns&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND echo&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND finger&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND imap&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND imap3&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND irc&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND isakmp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND nntp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND ntp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND pop3&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND realaudio&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND snmp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND smtp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND telnet&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND tftp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND time&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND udp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND tcp router-traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember for CBAC to work properly you should be denying inbound traffic. So you permit what you want out on the outbound access-list and deny the traffic on the inbound access-list and CBAC will generate the return ACE's automatically. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See how you go with this - if not post your config and I'll have a squiz and see what I can see. Actually here is a default config (working) for ya &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 08 Apr 2007 11:10:07 GMT</pubDate>
    <dc:creator>mightymouse2045</dc:creator>
    <dc:date>2007-04-08T11:10:07Z</dc:date>
    <item>
      <title>CBAC Difficults with Web page Viewing</title>
      <link>https://community.cisco.com/t5/network-security/cbac-difficults-with-web-page-viewing/m-p/806203#M1007932</link>
      <description>&lt;P&gt;I recently installed an 837 w/ CBAC (12.4) at a small office.  I have enabled inspection for DNS, HTTP and HTTPS.  I have found that most web pages display without trouble but a couple of sites are giving me trouble (&lt;A href="http://www.usatoday.com" target="_blank"&gt;www.usatoday.com&lt;/A&gt;).  The page never displays and doesn't seem to timeout either.  The CBAC audit logs haven't indicated that anything is being blocked or denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ideas?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-difficults-with-web-page-viewing/m-p/806203#M1007932</guid>
      <dc:creator>rmeans</dc:creator>
      <dc:date>2019-03-11T09:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: CBAC Difficults with Web page Viewing</title>
      <link>https://community.cisco.com/t5/network-security/cbac-difficults-with-web-page-viewing/m-p/806204#M1007933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using CBAC on an 877w and get to this site fine. What I think is that you aren't letting out other things that the website might be using. My CBAC inspection list includes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND http&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND https&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND ftp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND icmp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND dns&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND echo&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND finger&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND imap&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND imap3&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND irc&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND isakmp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND nntp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND ntp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND pop3&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND realaudio&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND snmp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND smtp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND telnet&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND tftp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND time&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND udp&lt;/P&gt;&lt;P&gt;ip inspect name INBOUND tcp router-traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember for CBAC to work properly you should be denying inbound traffic. So you permit what you want out on the outbound access-list and deny the traffic on the inbound access-list and CBAC will generate the return ACE's automatically. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See how you go with this - if not post your config and I'll have a squiz and see what I can see. Actually here is a default config (working) for ya &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Apr 2007 11:10:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-difficults-with-web-page-viewing/m-p/806204#M1007933</guid>
      <dc:creator>mightymouse2045</dc:creator>
      <dc:date>2007-04-08T11:10:07Z</dc:date>
    </item>
  </channel>
</rss>

