<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: http access via PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/http-access-via-pix/m-p/49522#M728745</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying to access using the IP address....do I still need the DNS entry in the ACL??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Apr 2002 15:34:04 GMT</pubDate>
    <dc:creator>gcumarasamy</dc:creator>
    <dc:date>2002-04-29T15:34:04Z</dc:date>
    <item>
      <title>http access via PIX</title>
      <link>https://community.cisco.com/t5/network-security/http-access-via-pix/m-p/49520#M728739</link>
      <description>&lt;P&gt;I am trying to config my PIX 501 OS 6.1(1) to allow only http traffic to go out with the following acl and applied to the inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp x.x.x.x x.x.x.x eq www any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group acl_in in interface inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once I apply this acl, I can't seem to get to any websites. Am I doing anything wrong here or missing any acl entries?????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:02:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-access-via-pix/m-p/49520#M728739</guid>
      <dc:creator>gcumarasamy</dc:creator>
      <dc:date>2020-02-21T06:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: http access via PIX</title>
      <link>https://community.cisco.com/t5/network-security/http-access-via-pix/m-p/49521#M728742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;have u allowed ur dns queries out of ur inside LAN, if u have a DNS server &lt;/P&gt;&lt;P&gt;outside.(not in inside LAN). if not u can add an entry as below and check if it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_in permit udp any eq domain any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ashok Pawar H.S.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2002 03:09:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-access-via-pix/m-p/49521#M728742</guid>
      <dc:creator>ashokpawar</dc:creator>
      <dc:date>2002-04-29T03:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: http access via PIX</title>
      <link>https://community.cisco.com/t5/network-security/http-access-via-pix/m-p/49522#M728745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying to access using the IP address....do I still need the DNS entry in the ACL??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2002 15:34:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-access-via-pix/m-p/49522#M728745</guid>
      <dc:creator>gcumarasamy</dc:creator>
      <dc:date>2002-04-29T15:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: http access via PIX</title>
      <link>https://community.cisco.com/t5/network-security/http-access-via-pix/m-p/49523#M728746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Do you have NAT set up and a outside route?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Apr 2002 17:20:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-access-via-pix/m-p/49523#M728746</guid>
      <dc:creator>e-see</dc:creator>
      <dc:date>2002-04-29T17:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: http access via PIX</title>
      <link>https://community.cisco.com/t5/network-security/http-access-via-pix/m-p/49524#M728749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I do have a NAT/Global setup as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't have any outside route other than the default ststic route that was created during the initial setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks........&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Apr 2002 00:45:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-access-via-pix/m-p/49524#M728749</guid>
      <dc:creator>gcumarasamy</dc:creator>
      <dc:date>2002-04-30T00:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: http access via PIX</title>
      <link>https://community.cisco.com/t5/network-security/http-access-via-pix/m-p/49525#M728750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to allow DNS to pass through unless you are using an internal DNS. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Apr 2002 10:38:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-access-via-pix/m-p/49525#M728750</guid>
      <dc:creator>mike</dc:creator>
      <dc:date>2002-04-30T10:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: http access via PIX</title>
      <link>https://community.cisco.com/t5/network-security/http-access-via-pix/m-p/49526#M728753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First, I strongly recommend that you sit down and think about what you're trying to accomplish.  As was mentioned, DNS will almost certainly be required for most web applications and services.  You may want other services as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second, unless I'm missing something, I believe that your access list is incorrect.  Try something like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_in permit tcp x.x.x.x x.x.x.x any eq www &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The destination port is 80.  I believe that you have specified it as the source port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Apr 2002 14:04:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-access-via-pix/m-p/49526#M728753</guid>
      <dc:creator>mklaphek</dc:creator>
      <dc:date>2002-04-30T14:04:11Z</dc:date>
    </item>
  </channel>
</rss>

