<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot create new Rule on ASA - HELP - HELP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-create-new-rule-on-asa-help-help/m-p/2122293#M394953</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to leave the "deny ip any any" ACL rule there, then yes, you can just move the 2 rules before that "deny" rule and those should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Nov 2012 16:58:18 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2012-11-29T16:58:18Z</dc:date>
    <item>
      <title>Cannot create new Rule on ASA - HELP - HELP</title>
      <link>https://community.cisco.com/t5/network-security/cannot-create-new-rule-on-asa-help-help/m-p/2122289#M394916</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to configure my Cisco ASA firewall to allow outside access to my new webserver which is hosting inside the company network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The number 47 &amp;amp; 48 from image below are my new access rules.&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/5/1/3/116315-1.jpg" alt="1.jpg" class="jive-image-thumbnail jive-image" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From ouside I can ping to it by using name or IP but when I try to access the website using web browser, I got the page can't display. Yes, my web page is working fine when access using internal network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I replace the Destination on #35 with #47 (replace TTCHR2Outside with Dealer.Nittotire) then I can access the website from outside OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would anyone please tell me what I did wrong and how to fix it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks inadvance.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:30:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-create-new-rule-on-asa-help-help/m-p/2122289#M394916</guid>
      <dc:creator>Minh Vu</dc:creator>
      <dc:date>2019-03-12T00:30:03Z</dc:date>
    </item>
    <item>
      <title>Cannot create new Rule on ASA - HELP - HELP</title>
      <link>https://community.cisco.com/t5/network-security/cannot-create-new-rule-on-asa-help-help/m-p/2122290#M394927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Line 39 has a rule that blocks ALL TCP/UDP traffic from "any" to "any"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see, no rule after line 39 has even gotten 1 hitcount.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to remove the current line 39 configuration for any of the latter ones to apply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 16:51:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-create-new-rule-on-asa-help-help/m-p/2122290#M394927</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-11-29T16:51:26Z</dc:date>
    </item>
    <item>
      <title>Cannot create new Rule on ASA - HELP - HELP</title>
      <link>https://community.cisco.com/t5/network-security/cannot-create-new-rule-on-asa-help-help/m-p/2122291#M394932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; JouniForss,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your quick reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I just move line 47 &amp;amp; 48 up to before 39 without removing 39?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 16:54:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-create-new-rule-on-asa-help-help/m-p/2122291#M394932</guid>
      <dc:creator>Minh Vu</dc:creator>
      <dc:date>2012-11-29T16:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create new Rule on ASA - HELP - HELP</title>
      <link>https://community.cisco.com/t5/network-security/cannot-create-new-rule-on-asa-help-help/m-p/2122292#M394943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember that every single ACL ends with an "Implicit Deny" (I guess it should show on ASDM side) which basically blocks all the traffic that hasnt matched any previous ACL rule line.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Making a Deny rule in the middle of an ACL only makes sense when you specily a network/host address regarding either the source or destination of the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"deny ip any any" doesnt make any sense in the middle of an ACL as it makes the lines after that useless.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 16:55:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-create-new-rule-on-asa-help-help/m-p/2122292#M394943</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-11-29T16:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot create new Rule on ASA - HELP - HELP</title>
      <link>https://community.cisco.com/t5/network-security/cannot-create-new-rule-on-asa-help-help/m-p/2122293#M394953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to leave the "deny ip any any" ACL rule there, then yes, you can just move the 2 rules before that "deny" rule and those should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 16:58:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-create-new-rule-on-asa-help-help/m-p/2122293#M394953</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-11-29T16:58:18Z</dc:date>
    </item>
    <item>
      <title>Cannot create new Rule on ASA - HELP - HELP</title>
      <link>https://community.cisco.com/t5/network-security/cannot-create-new-rule-on-asa-help-help/m-p/2122294#M394960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; So, any line below "Deny" will be blocked, right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 16:58:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-create-new-rule-on-asa-help-help/m-p/2122294#M394960</guid>
      <dc:creator>Minh Vu</dc:creator>
      <dc:date>2012-11-29T16:58:51Z</dc:date>
    </item>
    <item>
      <title>Cannot create new Rule on ASA - HELP - HELP</title>
      <link>https://community.cisco.com/t5/network-security/cannot-create-new-rule-on-asa-help-help/m-p/2122295#M394966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you very much for your quick answer on this matter, yes, I am able to acces my website from outside now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 17:00:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-create-new-rule-on-asa-help-help/m-p/2122295#M394966</guid>
      <dc:creator>Minh Vu</dc:creator>
      <dc:date>2012-11-29T17:00:26Z</dc:date>
    </item>
  </channel>
</rss>

