<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I see.Do you think this is in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-drop-on-outside-interfce/m-p/2604282#M198179</link>
    <description>&lt;P&gt;I see.&lt;/P&gt;&lt;P&gt;Do you think this is the issue?&lt;/P&gt;&lt;P&gt;For how long does the issue remains?&lt;/P&gt;&lt;P&gt;Can you please a capture and verify the source mac address? I would like to know who is sending the traffic back to the ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jan 2015 23:15:35 GMT</pubDate>
    <dc:creator>Maykol Rojas</dc:creator>
    <dc:date>2015-01-05T23:15:35Z</dc:date>
    <item>
      <title>ACL drop on outside interfce</title>
      <link>https://community.cisco.com/t5/network-security/acl-drop-on-outside-interfce/m-p/2604281#M198178</link>
      <description>&lt;P&gt;I have a ASA 5515X running 8.6 code&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On my internal network, I have a couple subnets that connect through the ASA to the Internet. I also have&amp;nbsp; DMZ with some servers on it that are reachable from the Internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These internal subnets are off different interfaces on the ASA, and my NAT rules are set up like this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object-group network DEFAULT-PAT-SOURCE&lt;BR /&gt;network-object object obj-172.25.36.30&lt;BR /&gt;network-object object obj-192.168.221.0&lt;BR /&gt;network-object object obj-172.23.120.250&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;nat (Guestnet,outside) after-auto source dynamic DEFAULT-PAT-SOURCE interface&lt;BR /&gt;nat (NETWORK2,outside) after-auto source dynamic DEFAULT-PAT-SOURCE interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;BR /&gt;description Guestnet&lt;BR /&gt;nameif Guestnet&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 192.168.221.4 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/5&lt;BR /&gt;nameif NETWORK2&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 172.23.120.129 255.255.255.128&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is an ACL applied to the outside interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Periodically, I have had an issue where the outbound/inbound traffic slows to a crawl on the Guestnet network, and I see a weird message in the logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jan 05 2015 07:30:40: %ASA-3-710003: TCP access denied by ACL from 192.168.221.51/52108 to Guestnet:&amp;lt;outside interface IP&amp;gt;/80&lt;BR /&gt;Jan 05 2015 07:30:40: %ASA-3-710003: TCP access denied by ACL from 192.168.221.51/52106 to Guestnet:&amp;lt;outside interface IP&amp;gt;/443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why does the ASA think traffic is coming inbound from an IP that is on the internal network? (the Guestnet network). It is almost like a spoofing situation, but the IP 192.168.221.51 was my laptop IP I was testing from.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there something wrong with this configuration? What could be the issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-drop-on-outside-interfce/m-p/2604281#M198178</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2019-03-12T05:18:07Z</dc:date>
    </item>
    <item>
      <title>I see.Do you think this is</title>
      <link>https://community.cisco.com/t5/network-security/acl-drop-on-outside-interfce/m-p/2604282#M198179</link>
      <description>&lt;P&gt;I see.&lt;/P&gt;&lt;P&gt;Do you think this is the issue?&lt;/P&gt;&lt;P&gt;For how long does the issue remains?&lt;/P&gt;&lt;P&gt;Can you please a capture and verify the source mac address? I would like to know who is sending the traffic back to the ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jan 2015 23:15:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-drop-on-outside-interfce/m-p/2604282#M198179</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2015-01-05T23:15:35Z</dc:date>
    </item>
  </channel>
</rss>

