<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 - outside and inside can not access web server in DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538266#M705952</link>
    <description>&lt;P&gt;Hello, there may be some problems with the ASA's config, but I can find where are the problems.&lt;/P&gt;&lt;P&gt;Below is the basic config for this ASA:&lt;/P&gt;&lt;P&gt;Inside ip address :　192.168.10.1/24&lt;/P&gt;&lt;P&gt;Outside ip address:&amp;nbsp; 120.195.153.151/26&lt;/P&gt;&lt;P&gt;DMZ ip address:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.30.1/24&lt;/P&gt;&lt;P&gt;Web server ip address:&amp;nbsp; 192.168.30.5/24&lt;/P&gt;&lt;P&gt;I wanna complete the tasks , the status of which are as below:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Inside ping Web server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; successfully&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Inside ping &lt;A href="http://www.cisco.com" target="_blank"&gt;www.cisco.com&lt;/A&gt;&amp;nbsp; successfully&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; DMZ&amp;nbsp;&amp;nbsp; ping&amp;nbsp; &lt;A href="http://www.cisco.com" target="_blank"&gt;www.cisco.com&lt;/A&gt;&amp;nbsp; successfully&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; Inside access web sites in web server through &lt;A href="http://192.168.30.5" target="_blank"&gt;http://192.168.30.5&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; failed&lt;/P&gt;&lt;P&gt;5.&amp;nbsp; Outside access web sites in web server through &lt;A href="http://120.195.153.151" target="_blank"&gt;http://120.195.153.151&lt;/A&gt; failed&lt;/P&gt;&lt;P&gt;Please get the detailed config in the attached file, and kindly help have a check to find where are the problems.thanks!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 18:45:32 GMT</pubDate>
    <dc:creator>cole xu</dc:creator>
    <dc:date>2019-03-11T18:45:32Z</dc:date>
    <item>
      <title>ASA 5510 - outside and inside can not access web server in DMZ</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538266#M705952</link>
      <description>&lt;P&gt;Hello, there may be some problems with the ASA's config, but I can find where are the problems.&lt;/P&gt;&lt;P&gt;Below is the basic config for this ASA:&lt;/P&gt;&lt;P&gt;Inside ip address :　192.168.10.1/24&lt;/P&gt;&lt;P&gt;Outside ip address:&amp;nbsp; 120.195.153.151/26&lt;/P&gt;&lt;P&gt;DMZ ip address:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.30.1/24&lt;/P&gt;&lt;P&gt;Web server ip address:&amp;nbsp; 192.168.30.5/24&lt;/P&gt;&lt;P&gt;I wanna complete the tasks , the status of which are as below:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Inside ping Web server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; successfully&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Inside ping &lt;A href="http://www.cisco.com" target="_blank"&gt;www.cisco.com&lt;/A&gt;&amp;nbsp; successfully&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; DMZ&amp;nbsp;&amp;nbsp; ping&amp;nbsp; &lt;A href="http://www.cisco.com" target="_blank"&gt;www.cisco.com&lt;/A&gt;&amp;nbsp; successfully&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; Inside access web sites in web server through &lt;A href="http://192.168.30.5" target="_blank"&gt;http://192.168.30.5&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; failed&lt;/P&gt;&lt;P&gt;5.&amp;nbsp; Outside access web sites in web server through &lt;A href="http://120.195.153.151" target="_blank"&gt;http://120.195.153.151&lt;/A&gt; failed&lt;/P&gt;&lt;P&gt;Please get the detailed config in the attached file, and kindly help have a check to find where are the problems.thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:45:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538266#M705952</guid>
      <dc:creator>cole xu</dc:creator>
      <dc:date>2019-03-11T18:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538267#M705954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You would need to remove the following line as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no static (inside,DMZ) 192.168.30.0 192.168.10.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Replace with the following:&lt;/P&gt;&lt;P&gt;static (inside,DMZ) 192.168.10.0 192.168.10.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you would need to "clear xlate" to clear existing translation.&lt;/P&gt;&lt;P&gt;The above will fix issue# 4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following will fix issue# 5:&lt;/P&gt;&lt;P&gt;static (DMZ,outside) tcp interface 80 192.168.30.5 80 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you would need to "clear xlate" to clear existing translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Sep 2010 09:18:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538267#M705954</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-27T09:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538268#M705956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Jennifer&lt;/P&gt;&lt;P&gt;Thanks for your helps, now the issue #4 was fixed, but issue #5 still exists. need your kindly help to check again. thanks!&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Inside ping Web server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; successfully&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; Inside ping &lt;A class="jive-link-external-small" href="http://www.cisco.com"&gt;&lt;SPAN style="color: #2f6681;"&gt;www.cisco.com&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp; successfully&lt;/P&gt;&lt;P&gt;3.&amp;nbsp; DMZ&amp;nbsp;&amp;nbsp; ping&amp;nbsp; &lt;A class="jive-link-external-small" href="http://www.cisco.com"&gt;&lt;SPAN style="color: #2f6681;"&gt;www.cisco.com&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp; successfully&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; Inside access web sites in web server through &lt;A class="jive-link-external-small" href="http://192.168.30.5"&gt;&lt;SPAN style="color: #2f6681;"&gt;http://192.168.30.5&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; successfully&lt;/P&gt;&lt;P&gt;5.&amp;nbsp; Outside access web sites in web server through &lt;A class="jive-link-external-small" href="http://120.195.153.151"&gt;&lt;SPAN style="color: #2f6681;"&gt;http://120.195.153.151&lt;/SPAN&gt;&lt;/A&gt; failed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Sep 2010 09:57:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538268#M705956</guid>
      <dc:creator>cole xu</dc:creator>
      <dc:date>2010-09-27T09:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538269#M705958</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you try using a different public ip address (public ip address that has not been used elsewhere) instead?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove the existing translation first:&lt;/P&gt;&lt;P&gt;no static (dmz,outside) tcp interface www 192.168.30.5 www netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then add the following line with the spare public ip address:&lt;/P&gt;&lt;P&gt;static (dmz,outside) 120.195.153.x 192.168.30.5 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then "clear xlate". You might also want to "clear arp" on both the ASA, and the upstream router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Sep 2010 10:06:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538269#M705958</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-27T10:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538270#M705960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm sorry to say that ISP only assigned one public ip address for me, I can not use any other address. &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Sep 2010 10:22:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538270#M705960</guid>
      <dc:creator>cole xu</dc:creator>
      <dc:date>2010-09-27T10:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538271#M705962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Really? your outside subnet is /26, doesn't that mean you have the whole /26 subnet to use?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, in that case, let's continue to use the ASA interface ip address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To troubleshoot further, please configure the following ACL line:&lt;/P&gt;&lt;P&gt;access-list 102 line 1 extended permit tcp any host 120.195.153.151 eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then try to access it from the outside again, and then issue "show access-list 102", and check if you have any hitcount on the first line.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Sep 2010 10:34:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538271#M705962</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-27T10:34:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538272#M705964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for the late reply, I've tried to add the command as you advised, but still no luck.&lt;/P&gt;&lt;P&gt;Below is the output of 'sh access-list 102', quantity of hit count is no zero.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# sh access-list 102&lt;BR /&gt;access-list 102; 4 elements&lt;BR /&gt;access-list 102 line 1 extended permit tcp any host 120.195.153.151 eq www (hitc&lt;BR /&gt;nt=4)&lt;BR /&gt;access-list 102 line 2 extended permit icmp any any (hitcnt=682)&lt;BR /&gt;access-list 102 line 3 extended permit ip any any (hitcnt=145)&lt;BR /&gt;access-list 102 line 4 extended permit tcp any any eq www (hitcnt=0)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Sep 2010 12:37:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538272#M705964</guid>
      <dc:creator>cole xu</dc:creator>
      <dc:date>2010-09-27T12:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538273#M705966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you share the output of "sh conn | i 192.168.30.5" as soon as you tried to access it from the outside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Sep 2010 13:39:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538273#M705966</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-27T13:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538274#M705968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, please refer to the following output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# sh conn | i 192.168.30.5&lt;BR /&gt;UDP out 117.85.147.201:1316 in 192.168.30.5:2792 idle 0:00:00 bytes 1014585 flag&lt;BR /&gt;s -&lt;BR /&gt;TCP out 114.243.120.255:5938 in 192.168.30.5:2790 idle 0:00:40 bytes 458 flags U&lt;BR /&gt;IO&lt;BR /&gt;TCP out 117.85.147.201:1378 in 192.168.30.5:80 idle 0:00:11 bytes 0 flags aB&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Sep 2010 13:48:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538274#M705968</guid>
      <dc:creator>cole xu</dc:creator>
      <dc:date>2010-09-27T13:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538275#M705970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, looking at this line:&lt;/P&gt;&lt;P&gt;TCP out 117.85.147.201:1378 in 192.168.30.5:80 idle 0:00:11 bytes 0 &lt;STRONG&gt;flags aB&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Flags of &lt;STRONG&gt;aB &lt;/STRONG&gt;means that ASA is receiving SYN packet from outside host towards the DMZ server, however, it never receives the SYN-ACK back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you check what is the default gateway on the DMZ server (pls make sure that it's the ASA DMZ interface ip address).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 04:47:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538275#M705970</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-28T04:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538276#M705971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The default gateway of DMZ server is 192.168.30.1 , which is the ip address of DMZ interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 05:03:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538276#M705971</guid>
      <dc:creator>cole xu</dc:creator>
      <dc:date>2010-09-28T05:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538277#M705972</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please run a packet capture on the outside and dmz interface of the ASA to see where the traffic breaks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, if you can run the packet tracer on the ASA from the outside towards the dmz server public ip address and make sure that it passes through OK.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 05:24:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538277#M705972</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-28T05:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538278#M705973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jennifer,&lt;/P&gt;&lt;P&gt;Sorry for butting in but I'm curious. Do the following configuration mentioned above also applicable for ASA5510 with IOS version of 8.0 or 8.2?&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 06:26:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538278#M705973</guid>
      <dc:creator>rjpselguera</dc:creator>
      <dc:date>2010-09-28T06:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538279#M705974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've runned the following commands:&lt;/P&gt;&lt;P&gt;1. capture outside inter outside&lt;/P&gt;&lt;P&gt;2. capture dmz inter dmz&lt;/P&gt;&lt;P&gt;and get the below output, seems no traffic breaks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture outside type raw-data interface outside [Capturing - 330602 bytes]&lt;BR /&gt;capture dmz type raw-data interface dmz [Capturing - 465476 bytes]&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 06:38:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538279#M705974</guid>
      <dc:creator>cole xu</dc:creator>
      <dc:date>2010-09-28T06:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538280#M705975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please remove the existing capture first:&lt;/P&gt;&lt;P&gt;no capture outside type raw-data interface outside&lt;BR /&gt;no capture dmz type raw-data interface dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please make it more specific so we can capture only the specific information:&lt;/P&gt;&lt;P&gt;(NB: assuming that you are testing from ip address: 117.85.147.201)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list cap-out permit tcp host 117.85.147.201 host 120.195.153.151&lt;/P&gt;&lt;P&gt;access-list cap-out permit tcp host 120.195.153.151 host 117.85.147.201&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;access-list cap-dmz permit tcp host 117.85.147.201 host 192.168.30.5&lt;/P&gt;&lt;P&gt;access-list cap-dmz permit tcp host 192.168.30.5 host 117.85.147.201&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture cap-out access-list cap-out interface outside&lt;/P&gt;&lt;P&gt;capture cap-dmz access-list cap-dmz interface dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then test accessing the website from 117.85.147.201.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then gather the output:&lt;/P&gt;&lt;P&gt;show cap cap-out&lt;/P&gt;&lt;P&gt;show cap cap-dmz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 10:23:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538280#M705975</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-28T10:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538281#M705976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, jennifer&lt;/P&gt;&lt;P&gt;Thanks a lot for your help . I think I have found where is the problem , just got reply from telecom company, the port 80 is blocked by them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 04:39:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538281#M705976</guid>
      <dc:creator>cole xu</dc:creator>
      <dc:date>2010-09-30T04:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538282#M705977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great, and thanks for the update.&lt;/P&gt;&lt;P&gt;Pls kindly mark the post as answered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 04:42:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538282#M705977</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-30T04:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 - outside and inside can not access web server in D</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538283#M705978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 04:49:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-outside-and-inside-can-not-access-web-server-in-dmz/m-p/1538283#M705978</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-30T04:49:38Z</dc:date>
    </item>
  </channel>
</rss>

