<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Internal Web Server Not Reachable By Internal Users in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/internal-web-server-not-reachable-by-internal-users/m-p/2237219#M350902</link>
    <description>&lt;P&gt;Device Type:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASA5505&lt;/P&gt;&lt;P&gt;ASA Version:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8.2(5) &lt;/P&gt;&lt;P&gt;ASDM Version:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6.4(5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The web server behind the firewall is unavailable to internal users.&lt;/P&gt;&lt;P&gt;If I connect to the web server, login and run the web browser, the web site is unavailable.&lt;/P&gt;&lt;P&gt;Help greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the firewall configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;ASA Version 8.2(5) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;terminal width 511&lt;/P&gt;&lt;P&gt;hostname asa5505&lt;/P&gt;&lt;P&gt;domain-name nnnn.mmmmmmm.net&lt;/P&gt;&lt;P&gt;enable password QQQQQQQQQQQQ encrypted&lt;/P&gt;&lt;P&gt;passwd QQQQQQQQQQQ encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;BR /&gt;switchport access vlan 2&lt;BR /&gt;speed 100&lt;BR /&gt;duplex full&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;BR /&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;BR /&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;BR /&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;BR /&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.0.0.254 255.255.255.0 &lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 208.109.184.27 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;BR /&gt;domain-name&amp;nbsp; nnnn.mmmmmmm.net&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq ftp-data &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq ftp &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq ssh &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 42 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp any any eq nameserver &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq domain &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp any any eq domain &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq www &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq pop3 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq https &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 465 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 587 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 995 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 993 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 3389 &lt;BR /&gt;access-list outside_access_in extended permit tcp any any eq 8443 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 2006 &lt;BR /&gt;access-list outside_access_in extended permit tcp any any eq 8447 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 9999 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 2086 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 2087 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 2082 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 2083 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 2096 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 2095 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 8880 &lt;BR /&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq telnet &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq smtp &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq imap4 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq 1433 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq 3306 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq 9080 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq 9090 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any source-quench &lt;BR /&gt;access-list outside_access_in extended permit icmp any any unreachable &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any time-exceeded &lt;/P&gt;&lt;P&gt;access-list inside_access_in&amp;nbsp; extended permit ip any any &lt;/P&gt;&lt;P&gt;no pager&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging buffered warnings&lt;/P&gt;&lt;P&gt;logging history warnings&lt;/P&gt;&lt;P&gt;logging asdm notifications&lt;/P&gt;&lt;P&gt;logging queue 500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface outside&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm history enable&lt;BR /&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (outside,inside) 10.0.0.2 208.109.186.139 &lt;BR /&gt;netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) 208.109.186.139 10.0.0.2 &lt;BR /&gt;netmask 255.255.255.255 &lt;BR /&gt;static (outside,inside) 10.0.0.3 208.109.186.154 &lt;BR /&gt;netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) 208.109.186.154 10.0.0.3 &lt;BR /&gt;netmask 255.255.255.255 &lt;BR /&gt;static (outside,inside) 10.0.0.1 208.109.184.134 &lt;BR /&gt;netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) 208.109.184.134 10.0.0.1 &lt;BR /&gt;netmask 255.255.255.255 &lt;BR /&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 208.109.184.254 1&lt;BR /&gt;route outside 0.0.0.0 255.255.255.0 208.109.184.254 1&lt;/P&gt;&lt;P&gt;route outside 192.168.101.3 255.255.255.255 208.109.184.254 1&lt;/P&gt;&lt;P&gt;route outside 192.168.105.3 255.255.255.255 208.109.184.254 1&lt;/P&gt;&lt;P&gt;route outside 192.168.109.3 255.255.255.255 208.109.184.254 1&lt;/P&gt;&lt;P&gt;route outside 208.109.96.4&amp;nbsp; 255.255.255.255 208.109.184.254 1&lt;/P&gt;&lt;P&gt;route outside 208.109.188.4 255.255.255.255 208.109.184.254 1&lt;/P&gt;&lt;P&gt;route outside 216.69.160.4&amp;nbsp; 255.255.255.255 208.109.184.254 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record Dflt&lt;BR /&gt;AccessPolicy&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;http 10.0.0.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community *****&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;sysopt noproxyarp inside&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;management-access outside&lt;BR /&gt;d&lt;BR /&gt;hcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;username XXXXXXXXXXX password QQQQQQQQQQQQ encrypted privilege 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameters&lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class inspection_default&lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;BR /&gt;no call-home &lt;BR /&gt;reporting anonymous&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 01:35:49 GMT</pubDate>
    <dc:creator>douglasbrantley</dc:creator>
    <dc:date>2019-03-12T01:35:49Z</dc:date>
    <item>
      <title>Internal Web Server Not Reachable By Internal Users</title>
      <link>https://community.cisco.com/t5/network-security/internal-web-server-not-reachable-by-internal-users/m-p/2237219#M350902</link>
      <description>&lt;P&gt;Device Type:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASA5505&lt;/P&gt;&lt;P&gt;ASA Version:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8.2(5) &lt;/P&gt;&lt;P&gt;ASDM Version:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6.4(5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The web server behind the firewall is unavailable to internal users.&lt;/P&gt;&lt;P&gt;If I connect to the web server, login and run the web browser, the web site is unavailable.&lt;/P&gt;&lt;P&gt;Help greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the firewall configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;ASA Version 8.2(5) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;terminal width 511&lt;/P&gt;&lt;P&gt;hostname asa5505&lt;/P&gt;&lt;P&gt;domain-name nnnn.mmmmmmm.net&lt;/P&gt;&lt;P&gt;enable password QQQQQQQQQQQQ encrypted&lt;/P&gt;&lt;P&gt;passwd QQQQQQQQQQQ encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;BR /&gt;switchport access vlan 2&lt;BR /&gt;speed 100&lt;BR /&gt;duplex full&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;BR /&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;BR /&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;BR /&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;BR /&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.0.0.254 255.255.255.0 &lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 208.109.184.27 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;BR /&gt;domain-name&amp;nbsp; nnnn.mmmmmmm.net&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq ftp-data &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq ftp &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq ssh &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 42 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp any any eq nameserver &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq domain &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit udp any any eq domain &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq www &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq pop3 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq https &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 465 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 587 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 995 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 993 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 3389 &lt;BR /&gt;access-list outside_access_in extended permit tcp any any eq 8443 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 2006 &lt;BR /&gt;access-list outside_access_in extended permit tcp any any eq 8447 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 9999 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 2086 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 2087 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 2082 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 2083 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 2096 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 2095 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any any eq 8880 &lt;BR /&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq telnet &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq smtp &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq imap4 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq 1433 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq 3306 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq 9080 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended deny&amp;nbsp;&amp;nbsp; tcp any any eq 9090 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any source-quench &lt;BR /&gt;access-list outside_access_in extended permit icmp any any unreachable &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any time-exceeded &lt;/P&gt;&lt;P&gt;access-list inside_access_in&amp;nbsp; extended permit ip any any &lt;/P&gt;&lt;P&gt;no pager&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging buffered warnings&lt;/P&gt;&lt;P&gt;logging history warnings&lt;/P&gt;&lt;P&gt;logging asdm notifications&lt;/P&gt;&lt;P&gt;logging queue 500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface outside&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm history enable&lt;BR /&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (outside,inside) 10.0.0.2 208.109.186.139 &lt;BR /&gt;netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) 208.109.186.139 10.0.0.2 &lt;BR /&gt;netmask 255.255.255.255 &lt;BR /&gt;static (outside,inside) 10.0.0.3 208.109.186.154 &lt;BR /&gt;netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) 208.109.186.154 10.0.0.3 &lt;BR /&gt;netmask 255.255.255.255 &lt;BR /&gt;static (outside,inside) 10.0.0.1 208.109.184.134 &lt;BR /&gt;netmask 255.255.255.255 &lt;BR /&gt;static (inside,outside) 208.109.184.134 10.0.0.1 &lt;BR /&gt;netmask 255.255.255.255 &lt;BR /&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 208.109.184.254 1&lt;BR /&gt;route outside 0.0.0.0 255.255.255.0 208.109.184.254 1&lt;/P&gt;&lt;P&gt;route outside 192.168.101.3 255.255.255.255 208.109.184.254 1&lt;/P&gt;&lt;P&gt;route outside 192.168.105.3 255.255.255.255 208.109.184.254 1&lt;/P&gt;&lt;P&gt;route outside 192.168.109.3 255.255.255.255 208.109.184.254 1&lt;/P&gt;&lt;P&gt;route outside 208.109.96.4&amp;nbsp; 255.255.255.255 208.109.184.254 1&lt;/P&gt;&lt;P&gt;route outside 208.109.188.4 255.255.255.255 208.109.184.254 1&lt;/P&gt;&lt;P&gt;route outside 216.69.160.4&amp;nbsp; 255.255.255.255 208.109.184.254 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record Dflt&lt;BR /&gt;AccessPolicy&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;http 10.0.0.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community *****&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;sysopt noproxyarp inside&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;management-access outside&lt;BR /&gt;d&lt;BR /&gt;hcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;username XXXXXXXXXXX password QQQQQQQQQQQQ encrypted privilege 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameters&lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class inspection_default&lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;BR /&gt;no call-home &lt;BR /&gt;reporting anonymous&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:35:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internal-web-server-not-reachable-by-internal-users/m-p/2237219#M350902</guid>
      <dc:creator>douglasbrantley</dc:creator>
      <dc:date>2019-03-12T01:35:49Z</dc:date>
    </item>
    <item>
      <title>Internal Web Server Not Reachable By Internal Users</title>
      <link>https://community.cisco.com/t5/network-security/internal-web-server-not-reachable-by-internal-users/m-p/2237220#M350903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First off, static NAT's are bi-directional. So, please modify your static NAT config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syntax is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (real_int,mapped_int) mapped_ip real_ip netmask x.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, remove following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no static (outside,inside) 10.0.0.2 208.109.186.139 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;no static (outside,inside) 10.0.0.3 208.109.186.154 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;no static (outside,inside) 10.0.0.1 208.109.184.134 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You only need these:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 208.109.186.139 10.0.0.2 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) 208.109.186.154 10.0.0.3 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) 208.109.184.134 10.0.0.1 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now,&amp;nbsp; if you are able to connect to server and get to login, your static NAT&amp;nbsp; and inbound acl is fine. You might need to get captures on inside and&amp;nbsp; outside interface for traffic flow to web server to further investigate&amp;nbsp; this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the procedure to do it:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-1222" rel="nofollow"&gt;https://supportforums.cisco.com/docs/DOC-1222&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Doesn't sound like an ASA issue, but captures should help figure this out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Sourav&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 May 2013 13:33:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internal-web-server-not-reachable-by-internal-users/m-p/2237220#M350903</guid>
      <dc:creator>sokakkar</dc:creator>
      <dc:date>2013-05-01T13:33:21Z</dc:date>
    </item>
    <item>
      <title>Internal Web Server Not Reachable By Internal Users</title>
      <link>https://community.cisco.com/t5/network-security/internal-web-server-not-reachable-by-internal-users/m-p/2237221#M350904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I fixed the problem but did not use a firewall configuration change to enable the fix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While the installation of the Cisco ASA 5505 caused the problem,&lt;/P&gt;&lt;P&gt;I decided not to focus on the firewall configuration.&lt;/P&gt;&lt;P&gt;I dug deep into the web application for the failure points.&lt;/P&gt;&lt;P&gt;This pointed me to name resolution and DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I installed the Windows Server 2003 DNS Server.&lt;/P&gt;&lt;P&gt;Created a Zone for the server and A Records.&lt;/P&gt;&lt;P&gt;The DNS only resolves for DNS queries made from within the server.&lt;/P&gt;&lt;P&gt;All of the A Records point to the Inside IP Addresses for the Host names.&lt;/P&gt;&lt;P&gt;.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.1&lt;/P&gt;&lt;P&gt;wwww&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.1&lt;/P&gt;&lt;P&gt;www&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.1&lt;/P&gt;&lt;P&gt;ww&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.1&lt;/P&gt;&lt;P&gt;w&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The web application is working great.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;db&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 18:49:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internal-web-server-not-reachable-by-internal-users/m-p/2237221#M350904</guid>
      <dc:creator>douglasbrantley</dc:creator>
      <dc:date>2013-05-08T18:49:40Z</dc:date>
    </item>
    <item>
      <title>Internal Web Server Not Reachable By Internal Users</title>
      <link>https://community.cisco.com/t5/network-security/internal-web-server-not-reachable-by-internal-users/m-p/2237222#M350905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Douglas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems you are accessing the servers from internal users. And now that you've configured your DNS server to resolve the request to internal IP's, thsi traffic will be handled internally and not through ASA (which makes sense as client and server are behind same interface of ASA so it doesn't make sense to send this communication through ASA anyways).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above information I provided was targetting users from internet accessing your web server. If you wish to allow access to your servers from outside as well, above changes will be needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Sourav&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 18:58:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internal-web-server-not-reachable-by-internal-users/m-p/2237222#M350905</guid>
      <dc:creator>sokakkar</dc:creator>
      <dc:date>2013-05-08T18:58:23Z</dc:date>
    </item>
  </channel>
</rss>

