<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 8.4 Pat RPF-Check and HTTP Server in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863103#M459563</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okay so basically this is what you need: access the ASA using port 8080 And then be redirected to the internal host on port 80 right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network web03-p81&lt;/P&gt;&lt;P&gt; host 10.5.0.13&lt;/P&gt;&lt;P&gt;object service http-proxy&lt;/P&gt;&lt;P&gt; service tcp source eq 8080&lt;/P&gt;&lt;P&gt;object service http&lt;/P&gt;&lt;P&gt;service tcp source eq 80&lt;/P&gt;&lt;P&gt;object network internet.77&lt;/P&gt;&lt;P&gt; host 77.77.77.77&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outside ip is 77.77.77.77 and internal box is 10.5.0.13 right?&lt;/P&gt;&lt;P&gt;So lets do it like this: &lt;/P&gt;&lt;P&gt; nat (inside,outside) source static web03-p81 internet.77 service http http-proxy&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 10.5.0.13 eq 80&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Feb 2012 01:21:30 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2012-02-14T01:21:30Z</dc:date>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863092#M459552</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am moving all of my nat/pat from my 2800 series to my ASA.&amp;nbsp; I have a few things working including multiple outside ip addresses and dynamic nat, as well as outside access for a few servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My two probems are as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the life of me I cannot get pat working when I want to access and internal web server using a different port on the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example I have added this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;network object test.obj&lt;/P&gt;&lt;P&gt;host 192.168.184.11&lt;/P&gt;&lt;P&gt;nat (inside,outside) static outside-ip-100.1.1.1 8080 www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This adds the nat statments into the network object nat list and it all make sense.&amp;nbsp; Then I add the acl:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object test.obj eq http-81&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see no hits on the acl when I try from an outside device, and the packet-tracer keeps telling me I have a nat problem with the reverse path forwarding check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;xlate shows this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5520-fw# show xlate | i 100.1.1.1&lt;/P&gt;&lt;P&gt;TCP PAT from inside:192.168.184.11 80-80 to outside:100.1.1.1 81-81&lt;/P&gt;&lt;P&gt;NAT from inside:192.168.184.11 to outside:100.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have no idea why, I have followed many examples and I still get nothing.&amp;nbsp; I also get no access to the internet on the computer running the web server unless I add another dynamic nat statement pointing a different network object with the same host ip to the same outside ip address.&amp;nbsp; eg:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;network object test.obj-dynamic&lt;/P&gt;&lt;P&gt;host 192.168.184.11&lt;/P&gt;&lt;P&gt;nat (inside,outside) dynamic outside-ip-100.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still after that I get no connection from the outside to the web server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had moved our main web server over to the asa and access from the outside worked for a few minutes, I think, as I had hits on the acl.&amp;nbsp; Then it stopped working and the logs showed a huge list of teardowns and it looked like they were all dns requests.&amp;nbsp; I am assuming this is a problem with the virtual hosts on the web server and the dns inspection that the asa is doing.&amp;nbsp; So I added the dns command at the end of the nat command and it did not solve my problem.&amp;nbsp; So I am thinking the first problem with the RPF-check is related to this problem.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a couple of other web servers going through the asa with no problems but they are not running on apache and using virtual hosts, they are single stand alone web servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea what I am doing wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Dan.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863092#M459552</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2019-03-11T22:28:19Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863093#M459553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think there is some kind of bug in the ASA.&amp;nbsp; I setup a test web server (192.168.75.208), and I added two network objects&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network dan-laptop-pat&lt;/P&gt;&lt;P&gt; nat (inside,outside) static interface service tcp www www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network dan-laptop&lt;/P&gt;&lt;P&gt; nat (any,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the device can get out onto the internet because of the second statement and I can access it remotely because of the first statement.&amp;nbsp; So everything works fine.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when I use packet-tracer and I run a test it says it doesn't work!&amp;nbsp; Yet it actually works....&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/7/1/77176-working-not-working.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Proof from the log file that it works:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6|Feb 12 2012|08:59:11|302014|68.171.231.80|43273|192.168.75.208|80|Teardown TCP connection 28185054 for outside:68.171.231.80/43273 to inside:192.168.75.208/80 duration 0:00:01 bytes 5904 TCP FINs&lt;/P&gt;&lt;P&gt;6|Feb 12 2012|08:59:09|302013|68.171.231.80|43273|192.168.75.208|80|Built inbound TCP connection 28185054 for outside:68.171.231.80/43273 (68.171.231.80/43273) to inside:192.168.75.208/80 (217.77.77.77/80)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on what is happening?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 12 Feb 2012 15:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863093#M459553</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2012-02-12T15:01:38Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863094#M459554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeap, you are doing the packet tracer to the private ip address, you should do it to the public ip address of the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Feb 2012 01:57:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863094#M459554</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-13T01:57:36Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863095#M459555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the reply, I have been pulling my hair out on this one....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I use the public ip as you stated it all looks like it works fine in the packet tracer but in reality it does not work.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network dan-laptop&lt;/P&gt;&lt;P&gt; host 192.168.75.208&lt;/P&gt;&lt;P&gt;object network dan-laptop-pat&lt;/P&gt;&lt;P&gt; host 192.168.75.208&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This WORKS:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network laptop-pat&lt;/P&gt;&lt;P&gt; nat (inside,outside) static interface service tcp www www&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (inside,outside) after-auto source static laptop internet-75&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object http any object dan-laptop-pat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This DOES NOT WORK:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network laptop-pat&lt;/P&gt;&lt;P&gt; nat (inside,outside) static interface service tcp www 81&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (inside,outside) after-auto source static laptop internet-75&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object http-81 any object dan-laptop-pat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I doing the wrong kind of nat to make this work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Dan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Feb 2012 02:08:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863095#M459555</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2012-02-13T02:08:31Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863096#M459556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Found out it was a problem with the web server not accepting the request like that.&amp;nbsp; I tried a different web server and now the port translation works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Feb 2012 23:31:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863096#M459556</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2012-02-13T23:31:16Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863097#M459557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is correct, As I told you before the configuration its okay.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please mark the question as answered, so future users can learn from this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Feb 2012 23:36:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863097#M459557</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-13T23:36:04Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863098#M459558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry I spoke to soon this is not solved and still not working.&amp;nbsp; I cannot PAT anything on my asa using 8.4. Looks like this may be a bug because no scenario works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 00:36:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863098#M459558</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2012-02-14T00:36:42Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863099#M459559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you are saying your internal users cannot get PATeed to the outside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please provide sh run nat, then we will start working on captures if I do not see something strange.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 00:43:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863099#M459559</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-14T00:43:13Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863100#M459560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My issue is with outside access in.&amp;nbsp; Not inside access out, that seems to be fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example if I do this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network web03&lt;/P&gt;&lt;P&gt; host 10.5.0.13&lt;/P&gt;&lt;P&gt;object network web03-p81&lt;/P&gt;&lt;P&gt; host 10.5.0.13&lt;/P&gt;&lt;P&gt;object service http-proxy&lt;/P&gt;&lt;P&gt; service tcp destination eq 8080&lt;/P&gt;&lt;P&gt;object network internet.77&lt;/P&gt;&lt;P&gt; host 77.77.77.77&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network web03-p81&lt;/P&gt;&lt;P&gt; nat (inside,outside) static internet.77 service tcp www 8080&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (inside,outside) after-auto source static web03 internet.77&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object http-proxy any object web03-p81&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When trying to access the web server using &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://77.77.77.77:8080"&gt;http://77.77.77.77:8080&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; the log shows that the device is trying to access it using port 80???&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY style="border: inherit; border-color: inherit; border-width: inherit;"&gt;&lt;TR style="border: inherit; border-color: inherit; border-width: inherit;"&gt;&lt;TD style="border-color: inherit; border: inherit;"&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD style="border-color: inherit; border: inherit;"&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD style="border-color: inherit; border: inherit;"&gt;18:31:15&lt;/TD&gt;&lt;TD style="border-color: inherit; border: inherit;"&gt;106023&lt;/TD&gt;&lt;TD style="border-color: inherit; border: inherit;"&gt;68.121.131.81&lt;/TD&gt;&lt;TD style="border-color: inherit; border: inherit;"&gt;20347&lt;/TD&gt;&lt;TD style="border-color: inherit; border: inherit;"&gt;10.5.0.13&lt;/TD&gt;&lt;TD style="border-color: inherit; border: inherit;"&gt;80&lt;/TD&gt;&lt;TD style="border-color: inherit; border: inherit;"&gt;Deny tcp src outside:68.121.131.81/20347 dst inside:10.5.0.13/80 by access-group "outside_access_in" [0x0, 0x0]&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I add an access list that allows port 80 it all works, yet I am typing :8080 in the web address...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 00:49:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863100#M459560</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2012-02-14T00:49:57Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863101#M459561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;object service http-proxy&lt;/P&gt;&lt;P&gt;no service tcp destination eq 8080&lt;/P&gt;&lt;P&gt;service tcp source eq 8080&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then give it a try!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 01:00:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863101#M459561</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-14T01:00:05Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863102#M459562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still no go.&amp;nbsp; It is still hitting the box using port 80 instead of 8080 according to the logs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt;Feb 13 2012&lt;/TD&gt;&lt;TD&gt;19:04:43&lt;/TD&gt;&lt;TD&gt;106023&lt;/TD&gt;&lt;TD&gt;68.121.131.80&lt;/TD&gt;&lt;TD&gt;63464&lt;/TD&gt;&lt;TD&gt;10.5.0.13&lt;/TD&gt;&lt;TD&gt;80&lt;/TD&gt;&lt;TD&gt;Deny tcp src outside:68.121.131.80/63464 dst inside:10.5.0.13/80 by access-group "outside_access_in" [0x0, 0x0]&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried from a different external system and still same problem.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 01:14:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863102#M459562</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2012-02-14T01:14:50Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863103#M459563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okay so basically this is what you need: access the ASA using port 8080 And then be redirected to the internal host on port 80 right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network web03-p81&lt;/P&gt;&lt;P&gt; host 10.5.0.13&lt;/P&gt;&lt;P&gt;object service http-proxy&lt;/P&gt;&lt;P&gt; service tcp source eq 8080&lt;/P&gt;&lt;P&gt;object service http&lt;/P&gt;&lt;P&gt;service tcp source eq 80&lt;/P&gt;&lt;P&gt;object network internet.77&lt;/P&gt;&lt;P&gt; host 77.77.77.77&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outside ip is 77.77.77.77 and internal box is 10.5.0.13 right?&lt;/P&gt;&lt;P&gt;So lets do it like this: &lt;/P&gt;&lt;P&gt; nat (inside,outside) source static web03-p81 internet.77 service http http-proxy&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host 10.5.0.13 eq 80&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 01:21:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863103#M459563</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-14T01:21:30Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863104#M459565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Ok, so this works sort of....I can access the site using &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://77.77.77.77:8080"&gt;http://77.77.77.77:8080&lt;/A&gt;&lt;SPAN&gt; now, but I can still access the site using &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://77.77.77.77/"&gt;http://77.77.77.77/&lt;/A&gt;&lt;SPAN&gt;, but I don't want to be able to do that.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 01:37:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863104#M459565</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2012-02-14T01:37:59Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863105#M459566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So remove all you configured before related to that and left what I sent you, that is the only one that should work from an outside user!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 01:39:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863105#M459566</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-14T01:39:58Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863106#M459568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, everything was removed and I entered in what you sent&amp;nbsp; But I still can access it on port 80 and 8080 from the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 01:43:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863106#M459568</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2012-02-14T01:43:50Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863107#M459570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh wait, I forgot to remove one other thing.&amp;nbsp; That is the other nat statement that allowed the server to get out to the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without that the server could not get out.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 01:45:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863107#M459570</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2012-02-14T01:45:22Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863108#M459572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please post entire config, to see why is that happening!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 01:50:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863108#M459572</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-14T01:50:54Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863109#M459577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So your config you sent me works perfectly, but my server cannot get out onto the internet, I think I need another nat statement, but when I add another nat statement then i can access the server using port 80 from the outside, so I must be doing something wrong. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.4(3) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname gvsd-asa-5520-fw&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.10.10.10 255.255.255.252 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 77.77.77.70 255.255.255.192 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone CST -6&lt;/P&gt;&lt;P&gt;clock summer-time CDT recurring&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 172.16.0.102&lt;/P&gt;&lt;P&gt; name-server 172.16.0.101&lt;/P&gt;&lt;P&gt; domain-name domain.com&lt;/P&gt;&lt;P&gt;object network 10.20.10.1&lt;/P&gt;&lt;P&gt; host 10.20.10.1&lt;/P&gt;&lt;P&gt; description Astaro Web Filter&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;object network 172.16.0.0&lt;/P&gt;&lt;P&gt; range 172.16.0.0 172.16.254.254&lt;/P&gt;&lt;P&gt; description Data Network&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;object network 192.168.0.0&lt;/P&gt;&lt;P&gt; subnet 192.168.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;object network 10.10.10.1&lt;/P&gt;&lt;P&gt; host 10.10.10.1&lt;/P&gt;&lt;P&gt; description gw-2821-01&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;object network 10.10.10.9&lt;/P&gt;&lt;P&gt; host 10.10.10.9&lt;/P&gt;&lt;P&gt; description gw-2821-02&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;object network NETWORK_OBJ_10.250.0.0_28&lt;/P&gt;&lt;P&gt; subnet 10.250.0.0 255.255.255.240&lt;/P&gt;&lt;P&gt; description VPN Test&lt;/P&gt;&lt;P&gt;object network 172.16.187.0&lt;/P&gt;&lt;P&gt; subnet 172.16.187.0 255.255.255.0&lt;/P&gt;&lt;P&gt; description GVC Wifi&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;object network 10.7.0.0&lt;/P&gt;&lt;P&gt; subnet 10.7.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt; description Guest Network&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;object network 10.10.10.46&lt;/P&gt;&lt;P&gt; host 10.10.10.46&lt;/P&gt;&lt;P&gt; description astarogw&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;object network 10.11.0.0&lt;/P&gt;&lt;P&gt; subnet 10.11.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt; description GVSD I.T Network&lt;/P&gt;&lt;P&gt;object network 10.11.200.0&lt;/P&gt;&lt;P&gt; subnet 10.11.200.0 255.255.255.0&lt;/P&gt;&lt;P&gt; description DO I.T Network&lt;/P&gt;&lt;P&gt;object network merlin-67.75&lt;/P&gt;&lt;P&gt; host 77.77.77.75&lt;/P&gt;&lt;P&gt; description Merlin-67.75&lt;/P&gt;&lt;P&gt;object network helpdesk.domain.com&lt;/P&gt;&lt;P&gt; host 10.5.0.125&lt;/P&gt;&lt;P&gt; description Helpdesk Server for HTTP site&lt;/P&gt;&lt;P&gt;object network merlin-67.123&lt;/P&gt;&lt;P&gt; host 77.77.77.123&lt;/P&gt;&lt;P&gt;object network 10.5.0.0&lt;/P&gt;&lt;P&gt; subnet 10.5.0.0 255.255.255.0&lt;/P&gt;&lt;P&gt; description GVSD Server Network&lt;/P&gt;&lt;P&gt;object network intermapper.domain.com&lt;/P&gt;&lt;P&gt; host 10.5.0.150&lt;/P&gt;&lt;P&gt; description intermapper.domain.com&lt;/P&gt;&lt;P&gt;object network merlin-67.120&lt;/P&gt;&lt;P&gt; host 77.77.77.120&lt;/P&gt;&lt;P&gt;object network merlin-67.105&lt;/P&gt;&lt;P&gt; host 77.77.77.105&lt;/P&gt;&lt;P&gt;object network merlin-67.106&lt;/P&gt;&lt;P&gt; host 77.77.77.106&lt;/P&gt;&lt;P&gt;object network merlin-67.116&lt;/P&gt;&lt;P&gt; host 77.77.77.116&lt;/P&gt;&lt;P&gt;object network merlin-67.117&lt;/P&gt;&lt;P&gt; host 77.77.77.117&lt;/P&gt;&lt;P&gt;object network merlin-67.118&lt;/P&gt;&lt;P&gt; host 77.77.77.118&lt;/P&gt;&lt;P&gt;object network merlin-67.121&lt;/P&gt;&lt;P&gt; host 77.77.77.121&lt;/P&gt;&lt;P&gt;object network merlin-67.122&lt;/P&gt;&lt;P&gt; host 77.77.77.122&lt;/P&gt;&lt;P&gt;object network merlin-67.95&lt;/P&gt;&lt;P&gt; host 77.77.77.95&lt;/P&gt;&lt;P&gt;object network merlin-67.99&lt;/P&gt;&lt;P&gt; host 77.77.77.99&lt;/P&gt;&lt;P&gt;object network merlin-67.68&lt;/P&gt;&lt;P&gt; host 77.77.77.68&lt;/P&gt;&lt;P&gt;object network merlin-67.69&lt;/P&gt;&lt;P&gt; host 77.77.77.69&lt;/P&gt;&lt;P&gt;object network merlin-67.70&lt;/P&gt;&lt;P&gt; host 77.77.77.70&lt;/P&gt;&lt;P&gt;object network merlin-67.71&lt;/P&gt;&lt;P&gt; host 77.77.77.71&lt;/P&gt;&lt;P&gt;object network 172.16.187.22&lt;/P&gt;&lt;P&gt; host 172.16.187.22&lt;/P&gt;&lt;P&gt; description GVC Test Host&lt;/P&gt;&lt;P&gt;object network library.domain.com&lt;/P&gt;&lt;P&gt; host 10.5.0.85&lt;/P&gt;&lt;P&gt; description Library Server&lt;/P&gt;&lt;P&gt;object network netstorage.domain.com&lt;/P&gt;&lt;P&gt; host 10.5.0.35&lt;/P&gt;&lt;P&gt; description Netstorage server&lt;/P&gt;&lt;P&gt;object network sm.domain.com&lt;/P&gt;&lt;P&gt; host 10.5.0.87&lt;/P&gt;&lt;P&gt; description Sucess Maker Server&lt;/P&gt;&lt;P&gt;object network vibe.domain.com&lt;/P&gt;&lt;P&gt; host 10.5.0.27&lt;/P&gt;&lt;P&gt; description Vibe Server&lt;/P&gt;&lt;P&gt;object network mobilesync.domain.com&lt;/P&gt;&lt;P&gt; host 10.5.0.32&lt;/P&gt;&lt;P&gt; description Mobilesync Server&lt;/P&gt;&lt;P&gt;object network powerschool.domain.com&lt;/P&gt;&lt;P&gt; host 10.5.0.181&lt;/P&gt;&lt;P&gt; description PowerSchool Application Server&lt;/P&gt;&lt;P&gt;object service powerschool-5071&lt;/P&gt;&lt;P&gt; service tcp source eq 5071 destination eq 5071 &lt;/P&gt;&lt;P&gt;object service powerschool-7880&lt;/P&gt;&lt;P&gt; service tcp source eq 7880 destination eq 7880 &lt;/P&gt;&lt;P&gt;object service powerschool-7980&lt;/P&gt;&lt;P&gt; service tcp source eq 7980 destination eq 7980 &lt;/P&gt;&lt;P&gt;object network astaro-mail&lt;/P&gt;&lt;P&gt; host 10.30.10.2&lt;/P&gt;&lt;P&gt;object service http-81&lt;/P&gt;&lt;P&gt; service tcp destination eq 81 &lt;/P&gt;&lt;P&gt;object service http-82&lt;/P&gt;&lt;P&gt; service tcp destination eq 82 &lt;/P&gt;&lt;P&gt;object service http-83&lt;/P&gt;&lt;P&gt; service tcp destination eq 83 &lt;/P&gt;&lt;P&gt;object service http-84&lt;/P&gt;&lt;P&gt; service tcp destination eq 84 &lt;/P&gt;&lt;P&gt;object service http-85&lt;/P&gt;&lt;P&gt; service tcp destination eq 85 &lt;/P&gt;&lt;P&gt;object network merlin-67.77&lt;/P&gt;&lt;P&gt; host 77.77.77.77&lt;/P&gt;&lt;P&gt;object network dan-laptop&lt;/P&gt;&lt;P&gt; host 192.168.75.208&lt;/P&gt;&lt;P&gt;object service http-proxy&lt;/P&gt;&lt;P&gt; service tcp source eq 8080 &lt;/P&gt;&lt;P&gt;object service http-proxy-2&lt;/P&gt;&lt;P&gt; service tcp destination eq 8080 &lt;/P&gt;&lt;P&gt;object network web03-p8080&lt;/P&gt;&lt;P&gt; host 10.5.0.13&lt;/P&gt;&lt;P&gt;object service http-8080&lt;/P&gt;&lt;P&gt; service tcp source eq 8080 &lt;/P&gt;&lt;P&gt;object service www&lt;/P&gt;&lt;P&gt; service tcp source eq www &lt;/P&gt;&lt;P&gt;object-group service ff-system udp&lt;/P&gt;&lt;P&gt; description ff system management&lt;/P&gt;&lt;P&gt; port-object eq 1091&lt;/P&gt;&lt;P&gt;object-group service http-81-1 tcp&lt;/P&gt;&lt;P&gt; port-object eq 81&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object http-81 any object dan-laptop &lt;/P&gt;&lt;P&gt;access-list outside_access_in remark helpdesk webiste&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object helpdesk.domain.com eq www &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object library.domain.com eq www &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object netstorage.domain.com eq https &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object sm.domain.com eq www &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object sm.domain.com eq https inactive &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object mobilesync.domain.com eq https &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object powerschool.domain.com eq www &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object powerschool.domain.com eq https &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object powerschool-5071 any object powerschool.domain.com &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object powerschool-7880 any object powerschool.domain.com &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object powerschool-7980 any object powerschool.domain.com &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object astaro-mail eq smtp inactive &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object vibe.domain.com eq https &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object intermapper.domain.com eq www &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 10.5.0.13 eq www &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended deny ip object 172.16.187.22 any inactive &lt;/P&gt;&lt;P&gt;access-list inside_access_in remark blsd - web accesss&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp object 10.7.0.0 any eq 88 &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended deny udp object 10.7.0.0 range 1 65535 any range 1 65535 &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended deny tcp object 10.7.0.0 range 1 65535 any range 1 65535 &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list inside_access_out extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list outside_access_out extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list netflow-hosts extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list http-s extended permit tcp any any eq www inactive &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;flow-export destination inside 10.11.200.104 2055&lt;/P&gt;&lt;P&gt;flow-export destination inside 10.11.200.193 2055&lt;/P&gt;&lt;P&gt;flow-export template timeout-rate 1&lt;/P&gt;&lt;P&gt;flow-export delay flow-create 30&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;ip local pool VPN-L2TP-IPSEC-POOL 10.250.0.4-10.250.0.14 mask 255.255.255.224&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface outside&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-647.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static web03-p8080 merlin-67.77 service www http-8080&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network 172.16.0.0&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;object network 10.10.10.1&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;object network 10.10.10.9&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;object network 10.7.0.0&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;object network 10.10.10.46&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;object network 10.11.0.0&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;object network helpdesk.domain.com&lt;/P&gt;&lt;P&gt; nat (any,any) static merlin-67.123&lt;/P&gt;&lt;P&gt;object network intermapper.domain.com&lt;/P&gt;&lt;P&gt; nat (any,any) static merlin-67.120&lt;/P&gt;&lt;P&gt;object network library.domain.com&lt;/P&gt;&lt;P&gt; nat (any,any) static merlin-67.121&lt;/P&gt;&lt;P&gt;object network netstorage.domain.com&lt;/P&gt;&lt;P&gt; nat (any,any) static merlin-67.122&lt;/P&gt;&lt;P&gt;object network sm.domain.com&lt;/P&gt;&lt;P&gt; nat (any,any) static merlin-67.116&lt;/P&gt;&lt;P&gt;object network vibe.domain.com&lt;/P&gt;&lt;P&gt; nat (any,any) static merlin-67.117&lt;/P&gt;&lt;P&gt;object network mobilesync.domain.com&lt;/P&gt;&lt;P&gt; nat (any,any) static merlin-67.118&lt;/P&gt;&lt;P&gt;object network powerschool.domain.com&lt;/P&gt;&lt;P&gt; nat (any,any) static merlin-67.106&lt;/P&gt;&lt;P&gt;object network astaro-mail&lt;/P&gt;&lt;P&gt; nat (any,any) static merlin-67.106&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;nat (inside,outside) after-auto source static dan-laptop merlin-67.75&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group inside_access_out out interface inside&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;access-group outside_access_out out interface outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;router eigrp 100&lt;/P&gt;&lt;P&gt; no auto-summary&lt;/P&gt;&lt;P&gt; eigrp stub receive-only&lt;/P&gt;&lt;P&gt; network 10.10.10.8 255.255.255.252&lt;/P&gt;&lt;P&gt; passive-interface outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 77.77.77.65 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;snmp-server host inside 10.5.0.150 community public version 2c udp-port 161&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map type regex match-any http&lt;/P&gt;&lt;P&gt; match regex youtube&lt;/P&gt;&lt;P&gt;class-map type inspect http match-any http_inspect_regex&lt;/P&gt;&lt;P&gt; match request uri regex class http&lt;/P&gt;&lt;P&gt;class-map http-s&lt;/P&gt;&lt;P&gt; match access-list http-s&lt;/P&gt;&lt;P&gt;class-map type regex match-any URLBlockList&lt;/P&gt;&lt;P&gt; description Match Traffic for Inspection&lt;/P&gt;&lt;P&gt; match regex Torrent-Info_Hash&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all asdm_medium_security_methods&lt;/P&gt;&lt;P&gt; match not request method head&lt;/P&gt;&lt;P&gt; match not request method post&lt;/P&gt;&lt;P&gt; match not request method get&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;class-map netflow-traffic&lt;/P&gt;&lt;P&gt; match access-list netflow-hosts&lt;/P&gt;&lt;P&gt;class-map type regex match-any class-limit&lt;/P&gt;&lt;P&gt; match regex dropbox&lt;/P&gt;&lt;P&gt;class-map type inspect http match-all BlockURLsClass&lt;/P&gt;&lt;P&gt; match request uri regex class URLBlockList&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect http URL&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt; match request uri regex dropbox&lt;/P&gt;&lt;P&gt;&amp;nbsp; reset&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class http-s&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect http URL &lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns &lt;/P&gt;&lt;P&gt; class netflow-traffic&lt;/P&gt;&lt;P&gt;&amp;nbsp; flow-export event-type all destination 10.11.200.104&lt;/P&gt;&lt;P&gt;policy-map type inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map test_pol&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;smtp-server 10.5.0.20&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;call-home&lt;/P&gt;&lt;P&gt; profile CiscoTAC-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no active&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address http &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://tools.cisco.com/its/service/oddce/services/DDCEService"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; destination address email &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:callhome@cisco.com"&gt;callhome@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination transport-method http&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;/P&gt;&lt;P&gt;hpm topN enable&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 01:58:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863109#M459577</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2012-02-14T01:58:28Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863110#M459580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I have it figured out now.&amp;nbsp; I guess I deleted too many things.&amp;nbsp; I added the nat statement back for the orginal object and now I can get out to the internet again and I can only access the server using port 8080.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network web03.domain.com&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic internet.77&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without this the server could not get out onto the internet.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for your time, this has helped me very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 02:12:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863110#M459580</guid>
      <dc:creator>dan.letkeman</dc:creator>
      <dc:date>2012-02-14T02:12:05Z</dc:date>
    </item>
    <item>
      <title>ASA 8.4 Pat RPF-Check and HTTP Server</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863111#M459586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;I think I have it figured out now&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sure, glad I could help¨&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Feb 2012 02:42:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-4-pat-rpf-check-and-http-server/m-p/1863111#M459586</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-14T02:42:49Z</dc:date>
    </item>
  </channel>
</rss>

