<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA ACL problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851171#M490479</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yes it's my public IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see in the log that the ASA really identified it as the source IP trying to connect to it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 21 Dec 2011 18:05:32 GMT</pubDate>
    <dc:creator>Jean-Francois Gagnon</dc:creator>
    <dc:date>2011-12-21T18:05:32Z</dc:date>
    <item>
      <title>ASA ACL problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851169#M490475</link>
      <description>&lt;P&gt;I don't know what's wrong with this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Doing &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any interface outside eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is working but this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp 172.12.33.0 255.255.255.0 interface outside eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've double checked the ip and I can even see it as the source ip in the log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why is the ASA do not recognise this ACL when the source ip is written?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:04:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851169#M490475</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2019-03-11T22:04:52Z</dc:date>
    </item>
    <item>
      <title>ASA ACL problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851170#M490477</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jean,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is 172.12.33.0 subnet reachable for the ASA via the outside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Dec 2011 17:24:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851170#M490477</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-21T17:24:55Z</dc:date>
    </item>
    <item>
      <title>ASA ACL problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851171#M490479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yes it's my public IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can see in the log that the ASA really identified it as the source IP trying to connect to it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Dec 2011 18:05:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851171#M490479</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2011-12-21T18:05:32Z</dc:date>
    </item>
    <item>
      <title>ASA ACL problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851172#M490480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jean,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok, so can you share your configuration so I can let you know why this is now working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Dec 2011 18:07:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851172#M490480</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-21T18:07:56Z</dc:date>
    </item>
    <item>
      <title>ASA ACL problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851173#M490481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; It's only working with ANY source in the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if I put in my IP, it's not working. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I'm truly sure the IP is good.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Dec 2011 19:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851173#M490481</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2011-12-21T19:28:35Z</dc:date>
    </item>
    <item>
      <title>ASA ACL problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851174#M490482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jean,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post the running-configuration ( With some changes due to your own newtork security) We need to see what you want to acomplish, check the nat statements, access-group,complete ACLs,etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok so the network 172.12.33.0 /16 on the outside security zone is trying to access on port 80 the outside interface and its not working unless you configure the ACL with the tcp any interface outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you also share the following packet-tracer output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input outside tcp 172.12.33.15 1025 x.x.x.x (outside ip address) 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Dec 2011 19:43:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851174#M490482</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-21T19:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ACL problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851175#M490483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'll give you the part you'd need. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp host 102.51.88.50 host 201.223.12.226 eq www&amp;nbsp; &amp;lt;-- This won't work&lt;BR /&gt;access-list outside_access_in extended permit tcp host 102.251.177.74 host 201.223.12.226 eq www&amp;nbsp; &amp;lt;- This won'T work&lt;BR /&gt;access-list outside_access_in extended permit tcp host 51.231.212.98 host 201.223.12.226 eq www&amp;nbsp; &amp;lt;- THis won't work&lt;BR /&gt;access-list outside_access_in extended permit tcp host 211.222.31.194 host 201.223.12.226 eq www &amp;lt;-- This won't work&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;access-list outside_access_in extended permit tcp 23.111.101.0 255.255.255.0 host 201.223.12.226 eq www&amp;nbsp; &amp;lt;-- This won't work&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;access-list outside_access_in extended permit tcp any host 201.223.12.226 eq www&amp;nbsp; &amp;lt;-- This work correctly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface www PBX www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I only put the ACL that does'nt work, it jumps directly to the "access-list outside_access_in extended deny"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Dec 2011 21:36:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851175#M490483</guid>
      <dc:creator>Jean-Francois Gagnon</dc:creator>
      <dc:date>2011-12-29T21:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ACL problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851176#M490485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Okay, lets do the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets leave just the ACL withouth the tcp any any.&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp 23.111.101.0 255.255.255.0 host 201.223.12.226 eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets create a capture ( For that you will need to generate some traffic from 23.111.101.x host)&lt;/P&gt;&lt;P&gt;access-list&amp;nbsp; capout permit tcp host 23.111.101.x host 201.223.12.226 eq 80&lt;/P&gt;&lt;P&gt;access-list capout permit tcp host 201.223.12.223 eq 80 host 23.111.101.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list capin permit tcp host 23.111.101.x host PBX eq 80&lt;/P&gt;&lt;P&gt;access-list capin permit tcp host PBX eq 80 host 23.111.101.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture capin access-list capin interface inside&lt;/P&gt;&lt;P&gt;capture capout access-list capout interface outside&lt;/P&gt;&lt;P&gt;capture asp type asp-drop all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now generate the traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then provide the following data&lt;/P&gt;&lt;P&gt;sh asp | include 23.11.101.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Go to a browser : &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://inside_interface_ip_address/capture/capin/pcap"&gt;https://inside_interface_ip_address/capture/capin/pcap&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://inside_interface_ip_address/capture/capout/pcap"&gt;https://inside_interface_ip_address/capture/capout/pcap&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And upload to this discussion the files&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Dec 2011 22:23:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-acl-problem/m-p/1851176#M490485</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-29T22:23:39Z</dc:date>
    </item>
  </channel>
</rss>

