<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Http Connection inside Lan in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/http-connection-inside-lan/m-p/1694555#M561011</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am configuring a new ASA 5510 to replace a SonicWall and I have a problem with an HTTP Connection inside my LAN.&lt;/P&gt;&lt;P&gt;PC from the LAN ( using ASA LAN interface as gateway) can't Connect to a Camera video Web Server (192.168.4.20) on Port 80 whereas I can Ping it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ADSM logs show :&lt;/P&gt;&lt;P&gt;106015# Deny TCP (no connection) from ip1 to ip2 Flags RST on Interface LAN.&lt;BR /&gt;The adaptive security appliance discarded a TCP Packet that has no Associated connection in the adaptive security appliance Connection table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- I Enabled command "same-security-traffic permit intra-interface" &lt;/P&gt;&lt;P&gt;- HTTP inspection is disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used Capture feature on the Ingress Interface, I joined the Logs and a part of my ASA Running Config.&lt;/P&gt;&lt;P&gt;Any Ideas? Thank You&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 20:43:43 GMT</pubDate>
    <dc:creator>beaujoire</dc:creator>
    <dc:date>2019-03-11T20:43:43Z</dc:date>
    <item>
      <title>Http Connection inside Lan</title>
      <link>https://community.cisco.com/t5/network-security/http-connection-inside-lan/m-p/1694555#M561011</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am configuring a new ASA 5510 to replace a SonicWall and I have a problem with an HTTP Connection inside my LAN.&lt;/P&gt;&lt;P&gt;PC from the LAN ( using ASA LAN interface as gateway) can't Connect to a Camera video Web Server (192.168.4.20) on Port 80 whereas I can Ping it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ADSM logs show :&lt;/P&gt;&lt;P&gt;106015# Deny TCP (no connection) from ip1 to ip2 Flags RST on Interface LAN.&lt;BR /&gt;The adaptive security appliance discarded a TCP Packet that has no Associated connection in the adaptive security appliance Connection table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- I Enabled command "same-security-traffic permit intra-interface" &lt;/P&gt;&lt;P&gt;- HTTP inspection is disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used Capture feature on the Ingress Interface, I joined the Logs and a part of my ASA Running Config.&lt;/P&gt;&lt;P&gt;Any Ideas? Thank You&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-connection-inside-lan/m-p/1694555#M561011</guid>
      <dc:creator>beaujoire</dc:creator>
      <dc:date>2019-03-11T20:43:43Z</dc:date>
    </item>
    <item>
      <title>Http Connection inside Lan</title>
      <link>https://community.cisco.com/t5/network-security/http-connection-inside-lan/m-p/1694556#M561015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (lan) 1 Interface &lt;/P&gt;&lt;P&gt;static (lan,lan) 192.168.4.20 192.168.4.20 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers &lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 17:12:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-connection-inside-lan/m-p/1694556#M561015</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-06-09T17:12:49Z</dc:date>
    </item>
    <item>
      <title>Http Connection inside Lan</title>
      <link>https://community.cisco.com/t5/network-security/http-connection-inside-lan/m-p/1694557#M561018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok but Can I remove NAT exemption now ? ( I used it to avoid&amp;nbsp; the dynamic nat : "Global (WAN) 1 interface" ) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="line-height: normal; margin-bottom: 0pt;"&gt;object-group network DM_INLINE_NETWORK_21&lt;/P&gt;&lt;P style="line-height: normal; margin-bottom: 0pt;"&gt;network-object 192.168.2.0 255.255.255.0&lt;/P&gt;&lt;P style="line-height: normal; margin-bottom: 0pt;"&gt;network-object 192.168.3.0 255.255.255.0&lt;/P&gt;&lt;P style="line-height: normal; margin-bottom: 0pt;"&gt;network-object 192.168.5.0 255.255.255.0&lt;/P&gt;&lt;P style="line-height: normal; margin-bottom: 0pt;"&gt;network-object 192.168.4.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="line-height: normal; margin-bottom: 0pt;"&gt;access-list LAN_nat0_outbound extended permit ip 192.168.0.0 255.255.248.0 object-group DM_INLINE_NETWORK_21 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="line-height: normal; margin-bottom: 0pt;"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jun 2011 16:31:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-connection-inside-lan/m-p/1694557#M561018</guid>
      <dc:creator>beaujoire</dc:creator>
      <dc:date>2011-06-16T16:31:46Z</dc:date>
    </item>
    <item>
      <title>Http Connection inside Lan</title>
      <link>https://community.cisco.com/t5/network-security/http-connection-inside-lan/m-p/1694558#M561022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not quite sure if it is going to break any other configuration that you may have (VPN, access to another interface etc), so lets just disable the exeption just for the source host in question. Do the following: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list LAN_nat0_outbound line 1 deny ip 192.168.1.x host 192.168.4.20 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The x represents the host from where you want to reach the camera server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jun 2011 05:43:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-connection-inside-lan/m-p/1694558#M561022</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-06-17T05:43:08Z</dc:date>
    </item>
  </channel>
</rss>

