<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Failed to access web server on inside through ASA5505 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/failed-to-access-web-server-on-inside-through-asa5505/m-p/2434459#M269292</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So are you saying that there is only the connected network behind &lt;STRONG&gt;"outside"&lt;/STRONG&gt; interface? I can only see a default route that is pointing towards &lt;STRONG&gt;"inside"&lt;/STRONG&gt;? Or is there an error on the default route as in a typical setup you would have it towards &lt;STRONG&gt;"outside"&lt;/STRONG&gt; or is this ASA somewhere else than the edge of the internal/external network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see from the logs the connection is allowed through the ASA but it ends with SYN Timeout. It either means the server does not reply or the server (and/or devices between it and the ASA) dont have a route towards the &lt;STRONG&gt;"outside"&lt;/STRONG&gt; network of the ASA pointing towards ASA so the return traffic for the connection doesnt go where it needs to go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Feb 2014 07:25:52 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2014-02-20T07:25:52Z</dc:date>
    <item>
      <title>Failed to access web server on inside through ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/failed-to-access-web-server-on-inside-through-asa5505/m-p/2434458#M269290</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hello, I have a very simple issue need your kindly helps! I need to access from outside a web server (192.18.81.13)&amp;nbsp; through ASA5505, and I used static nat to map it to the intreface outside IP,198.18.81.232. Everything seemed OK but I failed to access it through &lt;A href="http://192.18.81.232/" target="_blank"&gt;http://192.18.81.232&lt;/A&gt;, from the Real-time Log Viewer I found no problems. Attached please find my config. Any suggestions? Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:47:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failed-to-access-web-server-on-inside-through-asa5505/m-p/2434458#M269290</guid>
      <dc:creator>nathen121203</dc:creator>
      <dc:date>2019-03-12T03:47:52Z</dc:date>
    </item>
    <item>
      <title>Failed to access web server on inside through ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/failed-to-access-web-server-on-inside-through-asa5505/m-p/2434459#M269292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So are you saying that there is only the connected network behind &lt;STRONG&gt;"outside"&lt;/STRONG&gt; interface? I can only see a default route that is pointing towards &lt;STRONG&gt;"inside"&lt;/STRONG&gt;? Or is there an error on the default route as in a typical setup you would have it towards &lt;STRONG&gt;"outside"&lt;/STRONG&gt; or is this ASA somewhere else than the edge of the internal/external network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see from the logs the connection is allowed through the ASA but it ends with SYN Timeout. It either means the server does not reply or the server (and/or devices between it and the ASA) dont have a route towards the &lt;STRONG&gt;"outside"&lt;/STRONG&gt; network of the ASA pointing towards ASA so the return traffic for the connection doesnt go where it needs to go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Feb 2014 07:25:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failed-to-access-web-server-on-inside-through-asa5505/m-p/2434459#M269292</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-02-20T07:25:52Z</dc:date>
    </item>
    <item>
      <title>Failed to access web server on inside through ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/failed-to-access-web-server-on-inside-through-asa5505/m-p/2434460#M269294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; My host is connected directly to ASA, and Web server is through a switch. The actual topology is as below,&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/7/2/9/180927-firewall.jpg" alt="firewall.jpg" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Feb 2014 08:30:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failed-to-access-web-server-on-inside-through-asa5505/m-p/2434460#M269294</guid>
      <dc:creator>nathen121203</dc:creator>
      <dc:date>2014-02-20T08:30:48Z</dc:date>
    </item>
    <item>
      <title>Failed to access web server on inside through ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/failed-to-access-web-server-on-inside-through-asa5505/m-p/2434461#M269297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well according to the logs it seems to me that the clients have correct network configurations as they forward the connection to the ASA. The ASA also seems to have a correct configuration as it builds the connection through the ASA but the connection never fully forms between client and server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest checking the network settings of the server to confirm that it has its default gateway set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that is fine then I would confim that the service itself is running on the server and no software firewall is blocking the connection attempts. You could naturally test the connectivity with some other TCP based service through the ASA though you would have to configure the same type of Static PAT (Port Forward) and make the ACL rule addition.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Feb 2014 08:39:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failed-to-access-web-server-on-inside-through-asa5505/m-p/2434461#M269297</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-02-20T08:39:29Z</dc:date>
    </item>
    <item>
      <title>Failed to access web server on inside through ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/failed-to-access-web-server-on-inside-through-asa5505/m-p/2434462#M269299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Checking the gateway sounds very reasonable,&amp;nbsp; I will check next week, no time in this week. Thank you!&lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon" height="1" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" width="1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Feb 2014 08:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failed-to-access-web-server-on-inside-through-asa5505/m-p/2434462#M269299</guid>
      <dc:creator>nathen121203</dc:creator>
      <dc:date>2014-02-20T08:56:07Z</dc:date>
    </item>
    <item>
      <title>Failed to access web server on inside through ASA5505</title>
      <link>https://community.cisco.com/t5/network-security/failed-to-access-web-server-on-inside-through-asa5505/m-p/2434463#M269301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; It was really the gateway to blame. I set the server's default gateway to firewall's inside IP then all was OK. &lt;SPAN __jive_emoticon_name="laugh" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon" height="1" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" width="1"&gt;&lt;/SPAN&gt; To my knowledage there is no need to set gateway since they are connected by a switch, it is strange to me, anyway, it was OK now. Thank you very much!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Feb 2014 01:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/failed-to-access-web-server-on-inside-through-asa5505/m-p/2434463#M269301</guid>
      <dc:creator>nathen121203</dc:creator>
      <dc:date>2014-02-25T01:16:08Z</dc:date>
    </item>
  </channel>
</rss>

