<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Based on the log, the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587586#M198012</link>
    <description>&lt;P&gt;Based on the log, the webserver sends an HTTP-redirect to the port 445. But for this port you don't have a translation and also no access-rule.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Jan 2015 15:34:12 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2015-01-12T15:34:12Z</dc:date>
    <item>
      <title>How to correct: TCP access denied by ACL</title>
      <link>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587585#M198011</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;I seem to have stumbled into a problem I am not sure how to correct. &amp;nbsp;I have a web server on a DMZ (10.1.10.5) that works correctly for all sites housed on it with the exception of one. &amp;nbsp;The server serves up the login page but upon trying to login the following message is received:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color:#A52A2A;"&gt;TCP access denied by ACL from 10.1.10.5/53346 to dmz: xx.xx.xx.xx/445 (where x is the public IP)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have tried creating an ACL that allows the two to communicate. &amp;nbsp;Even then I get a message that the ASA has detected IP Spoofing and it blocks it.&lt;/P&gt;&lt;P&gt;I am attaching my config. &amp;nbsp;Note there are some rules there to allow the staff on the inside to access the sites using public URLs instead of server IPs. &amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is how can I allow this authentication traffic to be passed?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:19:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587585#M198011</guid>
      <dc:creator>alafever1</dc:creator>
      <dc:date>2019-03-12T05:19:54Z</dc:date>
    </item>
    <item>
      <title>Based on the log, the</title>
      <link>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587586#M198012</link>
      <description>&lt;P&gt;Based on the log, the webserver sends an HTTP-redirect to the port 445. But for this port you don't have a translation and also no access-rule.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2015 15:34:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587586#M198012</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2015-01-12T15:34:12Z</dc:date>
    </item>
    <item>
      <title>Thanks for your response.I</title>
      <link>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587587#M198013</link>
      <description>&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;I have added:&lt;BR /&gt;object network WEBSERVER-TCP445&lt;BR /&gt;host 10.1.10.5&lt;BR /&gt;nat (DMZ,outside) static interface service tcp 445 445&lt;BR /&gt;access-list outside_acl extended permit tcp any object WEBSERVER-TCP445 eq 445&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appear to still be receiving the message. &amp;nbsp;New config attached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jan 2015 15:47:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587587#M198013</guid>
      <dc:creator>alafever1</dc:creator>
      <dc:date>2015-01-12T15:47:30Z</dc:date>
    </item>
    <item>
      <title>Any other ideas?  Seems weird</title>
      <link>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587588#M198014</link>
      <description>&lt;P&gt;Any other ideas? &amp;nbsp;&lt;/P&gt;&lt;P&gt;Seems weird that the 10.1.10.5 (which is inside the DMZ) is being blocked to the DMZ public IP. &amp;nbsp;I've tried several configurations...some remove the error the the site still does not function.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2015 19:46:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587588#M198014</guid>
      <dc:creator>alafever1</dc:creator>
      <dc:date>2015-01-14T19:46:42Z</dc:date>
    </item>
    <item>
      <title>can u please confirmed</title>
      <link>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587589#M198015</link>
      <description>&lt;P&gt;can u please confirmed weather xxx ip is at outside or at dmz side. can u provide asa log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color:#A52A2A"&gt;TCP access denied by ACL from 10.1.10.5/53346 &lt;STRONG&gt;to dmz: xx.xx.xx.xx/445&lt;/STRONG&gt; (where x is the public IP)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2015 20:38:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587589#M198015</guid>
      <dc:creator>jeevak mukadam</dc:creator>
      <dc:date>2015-01-16T20:38:55Z</dc:date>
    </item>
    <item>
      <title>xxx IP is the Outside</title>
      <link>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587590#M198016</link>
      <description>&lt;P&gt;xxx IP is the Outside interface public facing address. &amp;nbsp;I was a little confused about the message because 10.1.10.5 is in the DMZ and is the webserver that the public IP sends that traffic to. &amp;nbsp;&lt;/P&gt;&lt;P&gt;What kind of log can I provide for you? &amp;nbsp;I am not very familiar with the logging settings. &amp;nbsp;If you tell me how to get it I'll post it for you.&lt;/P&gt;&lt;P&gt;Really appreciate the response. &amp;nbsp;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2015 21:24:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587590#M198016</guid>
      <dc:creator>alafever1</dc:creator>
      <dc:date>2015-01-16T21:24:51Z</dc:date>
    </item>
    <item>
      <title>Hi,can post real time logs</title>
      <link>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587591#M198017</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;can post real time logs generated by firewall. sh logging&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or print screen of real time logs via asdm.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;JEEVAK,&lt;/P&gt;</description>
      <pubDate>Sat, 17 Jan 2015 03:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587591#M198017</guid>
      <dc:creator>jeevak mukadam</dc:creator>
      <dc:date>2015-01-17T03:09:05Z</dc:date>
    </item>
    <item>
      <title>The logs have my public IP</title>
      <link>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587592#M198018</link>
      <description>&lt;P&gt;The logs have my public IP address plastered all over them. &amp;nbsp;I wouldn't feel comfortable posting them here. Other than the one TCP denied message there doesn't seem to be any other entries related to the login request. &amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any particular tests I may be able to run to help give you information that might be useful?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jan 2015 19:36:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-correct-tcp-access-denied-by-acl/m-p/2587592#M198018</guid>
      <dc:creator>alafever1</dc:creator>
      <dc:date>2015-01-19T19:36:36Z</dc:date>
    </item>
  </channel>
</rss>

