<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Server cannot browse to own websites in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786882#M494260</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, last update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem solved for one server using these lines:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;nat (inside,inside) source dynamic any interface &lt;STRONG&gt;Destination&lt;/STRONG&gt; static public_ip private_ip&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 remaining questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Can I change Public_IP and Private_IP to object groups?&lt;/P&gt;&lt;P&gt;2) Do I need sysopt noproxyarp inside?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Nov 2011 14:20:16 GMT</pubDate>
    <dc:creator>KingPrawns</dc:creator>
    <dc:date>2011-11-07T14:20:16Z</dc:date>
    <item>
      <title>Server cannot browse to own websites</title>
      <link>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786874#M494238</link>
      <description>&lt;P&gt;I've currently got a set of servers that all go through a switch and out via an asa firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know there isn't a problem with port 80 as the servers can navigate to external sites such as google.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a result of a packet-trace:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: monospace; white-space: pre;"&gt;bt(config)# packet-tracer input inside tcp 10.20.3.148 www 10.20.3.148 www detailed&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: CAPTURE&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt; Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt; in&amp;nbsp; id=0xca88f500, priority=13, domain=capture, deny=false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=37877223, user_data=0xca88f400, cs_id=0x0, l3_type=0x0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src mac=0000.0000.0000, mask=0000.0000.0000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst mac=0000.0000.0000, mask=0000.0000.0000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input_ifc=inside, output_ifc=any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt; Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt; in&amp;nbsp; id=0xcabe35b8, priority=1, domain=permit, deny=false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=18614673, user_data=0x0, cs_id=0x0, l3_type=0x8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src mac=0000.0000.0000, mask=0000.0000.0000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst mac=0000.0000.0000, mask=0100.0000.0000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input_ifc=inside, output_ifc=any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 10.20.3.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt; Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt; in&amp;nbsp; id=0xcabe4508, priority=111, domain=permit, deny=true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=0, user_data=0x0, cs_id=0x0, flags=0x4000, protocol=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src ip/id=0.0.0.0, mask=0.0.0.0, port=0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; input_ifc=inside, output_ifc=inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: inside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt; I'm not 100% sure I got that trace correct, should it be inside ip to inside ip or inside ip to outside (or vice versa) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got the following access-lists in and tried to run a capture but got nothing with regards to serving internal/external ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;access-list cap extended permit ip any host 195.171.9.148
access-list cap extended permit ip host 195.171.9.148 any
access-list cap extended permit ip any host 10.20.3.148
access-list cap extended permit ip host 10.20.3.148 any

&lt;/PRE&gt;&lt;P&gt;Am I missing a rule in the access lists?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:45:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786874#M494238</guid>
      <dc:creator>KingPrawns</dc:creator>
      <dc:date>2019-03-11T21:45:23Z</dc:date>
    </item>
    <item>
      <title>Server cannot browse to own websites</title>
      <link>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786875#M494240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Wez,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what it looks like is you are trying to do u-turning on ASA, use this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,inside) 10.20.3.148 10.20.3.148&lt;/P&gt;&lt;P&gt;nat (inside) 5 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;global (inside) 5 interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;sysopt noproxyarp inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to access the server on public ip, then remove the above static and add this:&lt;/P&gt;&lt;P&gt;static (inside,inside) 195.171.9.148 10.20.3.148&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Nov 2011 11:13:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786875#M494240</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-11-02T11:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: Server cannot browse to own websites</title>
      <link>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786876#M494242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Getting the following error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bt(config)# nat (inside) 5 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;ERROR: This syntax of nat command has been deprecated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're on version 8.4, sorry should have said that before. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think it's arguing with "5". Is that translated to "static/dynamic"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, I tried adding it as a nat rule to "object network" and that overwrote my inside/outside nat. Do I need to add it somewhere different?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example (post change):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;object network Ras
nat (inside,outside) static Ras_Outside&amp;nbsp; (correct)
object network Dev1
nat (inside,inside) static Dev1&amp;nbsp;&amp;nbsp; (no longer pointing outside?)&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Nov 2011 11:25:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786876#M494242</guid>
      <dc:creator>KingPrawns</dc:creator>
      <dc:date>2011-11-02T11:25:08Z</dc:date>
    </item>
    <item>
      <title>Server cannot browse to own websites</title>
      <link>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786877#M494244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Wez,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i guess you are using 8.3 or above code, if thats the case use this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network public_ip&lt;/P&gt;&lt;P&gt; host 195.171.9.148 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network private_ip&lt;/P&gt;&lt;P&gt; host 10.20.3.148&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside,inside) source dynamic any interface source static public_ip private_ip &lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;sysopt noproxyarp inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Nov 2011 11:41:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786877#M494244</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-11-02T11:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: Server cannot browse to own websites</title>
      <link>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786878#M494246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still having problems with the nat rule. where is the config hierarchy should I be putting it? &lt;/P&gt;&lt;PRE&gt;(config)# nat (inside,inside) source dynamic any interface source static Dev1_Outside Dev1
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^

ERROR: % Invalid input detected at '^' marker.
&lt;/PRE&gt;&lt;P&gt; Will I have to add this rule for every server?&amp;nbsp;&amp;nbsp; Just found another issue, it seems that the servers on this .3. subnet can't browse to any of the websites on servers in the same subnet (not just themselves).&amp;nbsp; Is this now a routing issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Wez Morris
(formatting)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Nov 2011 11:59:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786878#M494246</guid>
      <dc:creator>KingPrawns</dc:creator>
      <dc:date>2011-11-02T11:59:09Z</dc:date>
    </item>
    <item>
      <title>Server cannot browse to own websites</title>
      <link>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786879#M494255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please share your config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Nov 2011 12:06:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786879#M494255</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-11-02T12:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Server cannot browse to own websites</title>
      <link>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786880#M494257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sent you a PM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Nov 2011 12:20:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786880#M494257</guid>
      <dc:creator>KingPrawns</dc:creator>
      <dc:date>2011-11-02T12:20:39Z</dc:date>
    </item>
    <item>
      <title>Server cannot browse to own websites</title>
      <link>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786881#M494258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Still having trouble with this issue. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anybody recommend a way of debugging the problem? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need a server to access websites that it hosts, but I can't work out the traceroute/packet-trace&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 11:04:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786881#M494258</guid>
      <dc:creator>KingPrawns</dc:creator>
      <dc:date>2011-11-07T11:04:18Z</dc:date>
    </item>
    <item>
      <title>Server cannot browse to own websites</title>
      <link>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786882#M494260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, last update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem solved for one server using these lines:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;nat (inside,inside) source dynamic any interface &lt;STRONG&gt;Destination&lt;/STRONG&gt; static public_ip private_ip&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 remaining questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Can I change Public_IP and Private_IP to object groups?&lt;/P&gt;&lt;P&gt;2) Do I need sysopt noproxyarp inside?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 14:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786882#M494260</guid>
      <dc:creator>KingPrawns</dc:creator>
      <dc:date>2011-11-07T14:20:16Z</dc:date>
    </item>
    <item>
      <title>Server cannot browse to own websites</title>
      <link>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786883#M494261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the server are not in the directly connected subnet of the ASA, then you mght need to add the sysopt command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you can chnage the Private and Public to object-groups, no issues with it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Nov 2011 14:24:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/server-cannot-browse-to-own-websites/m-p/1786883#M494261</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-11-07T14:24:25Z</dc:date>
    </item>
  </channel>
</rss>

