<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Https rules in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/https-rules/m-p/1598785#M604519</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please apply captures on the outside and inside and of the asa and also the PC this will give us some ideas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let us see where it is feeling&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807c35e7.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807c35e7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this will help you applying captures&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Feb 2011 14:54:16 GMT</pubDate>
    <dc:creator>Jitendriya Athavale</dc:creator>
    <dc:date>2011-02-22T14:54:16Z</dc:date>
    <item>
      <title>Https rules</title>
      <link>https://community.cisco.com/t5/network-security/https-rules/m-p/1598784#M604518</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're experiëncing some difficulties with our ASA 5505.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;When we want to visit &lt;A href="https://portal.example.com" target="_blank"&gt;https://portal.example.com&lt;/A&gt; the pc doesn't go to that website. However, when we visit a different portal, it goes right ahead. When we remove the ASA 5505 out of the network we can vizit &lt;A href="https://portal.example.com" target="_blank"&gt;https://portal.example.com&lt;/A&gt; just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I uploaded the firewall rules just in case. I didn't think there's anything wrong with those but I uploaded them anyway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone experienced the same kind of incidents?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stijn&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:54:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-rules/m-p/1598784#M604518</guid>
      <dc:creator>Stijntacken</dc:creator>
      <dc:date>2019-03-11T19:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Https rules</title>
      <link>https://community.cisco.com/t5/network-security/https-rules/m-p/1598785#M604519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;please apply captures on the outside and inside and of the asa and also the PC this will give us some ideas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let us see where it is feeling&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807c35e7.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807c35e7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this will help you applying captures&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Feb 2011 14:54:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-rules/m-p/1598785#M604519</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2011-02-22T14:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: Https rules</title>
      <link>https://community.cisco.com/t5/network-security/https-rules/m-p/1598786#M604520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you might also want to take a look at this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804c8b9f.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a00804c8b9f.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Feb 2011 15:08:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-rules/m-p/1598786#M604520</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2011-02-22T15:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: Https rules</title>
      <link>https://community.cisco.com/t5/network-security/https-rules/m-p/1598787#M604521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume that "portal.example.com" is just a placeholder for the real server you try to access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some things to verify (because "PC doesn't go to that website" is not very precise):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you resolve the name on the PC in question with nslookup?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you establish a telnet session to the resolved IP address, port 443?&lt;/P&gt;&lt;P&gt;(you might want to do that test from "server" because it's the only one permitted https to the outside)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A packet-tracer is always recommended to verify if something is wrong with the firewall config (but in that case I don't think its the config).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is "server" functioning as a https-proxy for the inside PCs? If so, can the server itself open the website?&lt;/P&gt;&lt;P&gt;If "server" is a https-proxy could be something wrong with the server policies, like black-list or something wrong with the certificate of "portal.example.com"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In some rare cases a server can redirect the clients to a different port with "content location changed" (vulgo "http redirect").&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just a few things that might be worth trying to drill down into the cause of the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MiKa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Feb 2011 20:54:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-rules/m-p/1598787#M604521</guid>
      <dc:creator>m.kafka</dc:creator>
      <dc:date>2011-02-22T20:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Https rules</title>
      <link>https://community.cisco.com/t5/network-security/https-rules/m-p/1598788#M604522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These answers put me on the right track.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had t change the MMS value in the ASA. After that it worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you all!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greets,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stijn Tacken&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Mar 2011 14:09:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/https-rules/m-p/1598788#M604522</guid>
      <dc:creator>Stijntacken</dc:creator>
      <dc:date>2011-03-01T14:09:18Z</dc:date>
    </item>
  </channel>
</rss>

