<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 not allowing some https traffic in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-some-https-traffic/m-p/2605284#M202040</link>
    <description>&lt;P&gt;I have 2 ASA 5510's in a failover bundle. &amp;nbsp;I have a weird issue right now, where a site (https) is apparently getting blocked behind the firewall. &amp;nbsp;If I browse to the site, it just spins, then says the page could not be displayed. &amp;nbsp;I can ping the IP address, and I can browse to the http version of the page, but I cannot browse to the https site. &amp;nbsp;If I plug into the DMZ on the outside of the firewall, I can see the page no problem. There is something in the ASA that is blocking it. &amp;nbsp;We certainly allow 443 out, and use https heavily, all the time. &amp;nbsp;It's just this one site, which is weird, because I know ASA's don't do deep packet inspection. &amp;nbsp;Can anyone think of what would be causing this?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 05:14:45 GMT</pubDate>
    <dc:creator>Jake Pratt</dc:creator>
    <dc:date>2019-03-12T05:14:45Z</dc:date>
    <item>
      <title>ASA 5510 not allowing some https traffic</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-some-https-traffic/m-p/2605284#M202040</link>
      <description>&lt;P&gt;I have 2 ASA 5510's in a failover bundle. &amp;nbsp;I have a weird issue right now, where a site (https) is apparently getting blocked behind the firewall. &amp;nbsp;If I browse to the site, it just spins, then says the page could not be displayed. &amp;nbsp;I can ping the IP address, and I can browse to the http version of the page, but I cannot browse to the https site. &amp;nbsp;If I plug into the DMZ on the outside of the firewall, I can see the page no problem. There is something in the ASA that is blocking it. &amp;nbsp;We certainly allow 443 out, and use https heavily, all the time. &amp;nbsp;It's just this one site, which is weird, because I know ASA's don't do deep packet inspection. &amp;nbsp;Can anyone think of what would be causing this?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:14:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-some-https-traffic/m-p/2605284#M202040</guid>
      <dc:creator>Jake Pratt</dc:creator>
      <dc:date>2019-03-12T05:14:45Z</dc:date>
    </item>
    <item>
      <title>Well, we figured this out.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-some-https-traffic/m-p/2605285#M202041</link>
      <description>&lt;P&gt;Well, we figured this out. &amp;nbsp;It actually wasn't the firewall. &amp;nbsp;It was DNS resolution. &amp;nbsp;This particular site's DNS was all messed up. &amp;nbsp;When I was on the DMZ, I changed to another DNS server, which hadn't updated yet. &amp;nbsp;External DNS tests were all returning either no records or just the generic Network Solutions IP, which would give you a landing page. &amp;nbsp;We used the hosts file to get around it until they fixed their DNS pointers.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Dec 2014 19:35:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-some-https-traffic/m-p/2605285#M202041</guid>
      <dc:creator>Jake Pratt</dc:creator>
      <dc:date>2014-12-18T19:35:04Z</dc:date>
    </item>
  </channel>
</rss>

