<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can not browse duckduckgo in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751705#M1013163</link>
    <description>&lt;P&gt;I can send you tonight&lt;/P&gt;
&lt;P&gt;is it that i use wrong subnet ?&lt;/P&gt;
&lt;P&gt;because class B is above 128&lt;/P&gt;
&lt;P&gt;i use class A with class B subnet&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Nov 2018 00:21:57 GMT</pubDate>
    <dc:creator>Maivoko</dc:creator>
    <dc:date>2018-11-23T00:21:57Z</dc:date>
    <item>
      <title>Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751308#M1012954</link>
      <description>&lt;P&gt;I remove firepower service policy at outside&lt;/P&gt;
&lt;P&gt;and only apply at inside4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Allow country United States&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Traditional ASA itself inside4 allow UDP 53 and TCP 53 and any IP address with TCP 443 and 80&lt;/P&gt;
&lt;P&gt;but can not browse duckduckgo&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attached setting&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 14:06:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751308#M1012954</guid>
      <dc:creator>Maivoko</dc:creator>
      <dc:date>2019-03-12T14:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751330#M1013149</link>
      <description>&lt;P&gt;Even though duckduckgo is US-based, it (and most other globally accessed services) is served up by regional content providers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For instance, when I do an nslookup on it from my home in Malaysia, I get:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;Name:    duckduckgo.com
Addresses:  54.254.135.186
	  46.51.219.131
&lt;/PRE&gt;
&lt;P&gt;A whois search reveals those two addresses to be in Japan and Europe.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2018 10:06:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751330#M1013149</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-11-22T10:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751332#M1013150</link>
      <description>&lt;P&gt;correct me if i am wrong in your setup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your remove the access-list for inspection (firepower from outside) and applied it to inside4 which i assume is your inside network with security level 100.&lt;/P&gt;
&lt;P&gt;for example&lt;/P&gt;
&lt;P&gt;Interface gigX/X&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nameif inside4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;security level 100&lt;/P&gt;
&lt;P&gt;&amp;nbsp;ip address x.x.x.x x.x.x.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no shut&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;object network inside4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;subnet x.x.x.x x.x.x.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat (inside4,outside) dynamic interface dns&lt;/P&gt;
&lt;P&gt;if this is the case than you dont need the access-list as dynamic nat will take care of nat.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;could you please run a command&lt;/P&gt;
&lt;P&gt;packet tracer input tcp inside x.x.x.x 12345 duck.com 443 detail&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;duck.com just put the ip address of duckduck&lt;/P&gt;
&lt;P&gt;once you provide the output we have an understanding what happening here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2018 10:10:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751332#M1013150</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2018-11-22T10:10:01Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751343#M1013151</link>
      <description>&lt;P&gt;Which United States search engine do not have content providers? And IP address is fixed at United States?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if have content provider, country option will select more countries, it force me to use protect license to use IPS policy and application level Filter&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if not use protect license, country filter is useless in base license&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;moreover I find default ssl policy , will it have influence to it? can it decrpt google https?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2018 10:28:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751343#M1013151</guid>
      <dc:creator>Maivoko</dc:creator>
      <dc:date>2018-11-22T10:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751346#M1013152</link>
      <description>&lt;P&gt;ssl decryption on ASA model are not recommended. as it consume a lot of cpu of the box. if you have FTD 900 on ward yes. but i guess this is not the case for you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2018 10:32:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751346#M1013152</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2018-11-22T10:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751355#M1013153</link>
      <description>&lt;P&gt;Country filters are mostly useful for incoming traffic. They are not an effective way to get around any local or regionally-hosted search engines.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SSL decryption is increasingly not useful of outbound communications. Many web sites (especially Google, iTunes, Dropbox etc.) actively take measures to prevent man-in-the-middle decryption. Even when they do not you have to setup a PKI and distribute trust of the root CA to all your clients.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SSL decryption is mostly useful when you are decrypting incoming traffic to a server whose private key you control.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2018 10:46:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751355#M1013153</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-11-22T10:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751368#M1013154</link>
      <description>&lt;P&gt;Which web site is fixed IP address in United States for testing connection?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if not using country filter,&lt;/P&gt;
&lt;P&gt;is application filter useful for google and google drive and google email and amazon cloud only at home ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;because I can press cache link in google web to indirectly browse web&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2018 11:16:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751368#M1013154</guid>
      <dc:creator>Maivoko</dc:creator>
      <dc:date>2018-11-22T11:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751374#M1013155</link>
      <description>&lt;P&gt;What is your goal?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want a US-only website then don't try with a globally-used search engine or other software as a service. Instead use something like a US-based university (something US-based with .edu domain) .&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2018 11:26:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751374#M1013155</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-11-22T11:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751430#M1013156</link>
      <description>&lt;P&gt;Attached screen capture&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2018 13:25:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751430#M1013156</guid>
      <dc:creator>Maivoko</dc:creator>
      <dc:date>2018-11-22T13:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751454#M1013158</link>
      <description>&lt;P&gt;Though dhcp and NAT to access point is subnet different from 192.168.1.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but access point itself dhcp is using 192.168.1.0&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;will it conflict with inside itself?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;should I change access point dhcp address ?&lt;/P&gt;
&lt;P&gt;i discover ASDM not sync with console configuration&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my product is made in Mexico , do it have problem?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2018 13:56:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751454#M1013158</guid>
      <dc:creator>Maivoko</dc:creator>
      <dc:date>2018-11-22T13:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751538#M1013161</link>
      <description>nothing to worry if the product is made in Mexico. this is normal.&lt;BR /&gt;could you send me you nat rules.&lt;BR /&gt;&lt;BR /&gt;show run nat&lt;BR /&gt;show run nat detail&lt;BR /&gt;and also show us what is the interface setting of inside6&lt;BR /&gt;!&lt;BR /&gt;i noted access-list is dropping the packet. we need to understand what config you have made up for inside6</description>
      <pubDate>Thu, 22 Nov 2018 15:44:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751538#M1013161</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2018-11-22T15:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751705#M1013163</link>
      <description>&lt;P&gt;I can send you tonight&lt;/P&gt;
&lt;P&gt;is it that i use wrong subnet ?&lt;/P&gt;
&lt;P&gt;because class B is above 128&lt;/P&gt;
&lt;P&gt;i use class A with class B subnet&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Nov 2018 00:21:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751705#M1013163</guid>
      <dc:creator>Maivoko</dc:creator>
      <dc:date>2018-11-23T00:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751712#M1013165</link>
      <description>&lt;P&gt;Inside 7 use wrong subnet class B&lt;/P&gt;
&lt;P&gt;but I can connect to remote Amazon host&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;then i do similar at inside6 but can not surf internet&lt;/P&gt;</description>
      <pubDate>Fri, 23 Nov 2018 00:55:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3751712#M1013165</guid>
      <dc:creator>Maivoko</dc:creator>
      <dc:date>2018-11-23T00:55:59Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3752261#M1013168</link>
      <description>&lt;P&gt;I can surf internet now&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but I discover two wrong things&lt;/P&gt;
&lt;P&gt;first can not use tcp and UDP Tag together In ASA access policy , so I separate rules to google dns&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;second . I need to remove service policy of firepower at inside_6&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another thing is I used packet tracer to test it, it always show drop packet at access policy even if I can surf internet and can connect internet but why the test is wrong?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Nov 2018 01:00:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3752261#M1013168</guid>
      <dc:creator>Maivoko</dc:creator>
      <dc:date>2018-11-25T01:00:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3753537#M1013170</link>
      <description>seems like your access group is wrong you mind to send the config</description>
      <pubDate>Tue, 27 Nov 2018 13:45:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3753537#M1013170</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2018-11-27T13:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3753548#M1013172</link>
      <description>&lt;P&gt;you have configured&lt;/P&gt;
&lt;P&gt;/////////////////////////////////////////////////////////////////////////////////////&lt;/P&gt;
&lt;P&gt;access-group inside_6_access_in_1 in interface inside_6&lt;/P&gt;
&lt;P&gt;access-list inside_6_access_in_in extended deny ip any any log&lt;/P&gt;
&lt;P&gt;////////////////////////////////////////////////////////////////////////////////////&lt;/P&gt;
&lt;P&gt;what is inside_6, what address it has?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 13:54:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3753548#M1013172</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2018-11-27T13:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can not browse duckduckgo</title>
      <link>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3754051#M1013173</link>
      <description>&lt;P&gt;inside6 is NAT address, subnet for wireless access point to get ip address at WAN point&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and DHCP the above subnet&lt;SPAN&gt;&amp;nbsp;for wireless access point to get ip address at WAN point&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Nov 2018 03:48:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-not-browse-duckduckgo/m-p/3754051#M1013173</guid>
      <dc:creator>Maivoko</dc:creator>
      <dc:date>2018-11-28T03:48:58Z</dc:date>
    </item>
  </channel>
</rss>

