<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: publish web site in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324974#M858247</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tested it from inside and 2 x outside locations but still no luck. I will check the NAT/ACL again.&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 18 Aug 2009 10:59:12 GMT</pubDate>
    <dc:creator>jaimewalker</dc:creator>
    <dc:date>2009-08-18T10:59:12Z</dc:date>
    <item>
      <title>publish web site</title>
      <link>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324966#M858229</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;I am trying to publish a web site on 80.2.100.85/80 and access it from 78.109.177.183. when I try to access the server on port 80, I get the following log message: Deny tcp src WAN:78.109.177.183/64679 dst PRG_LAN:80.2.100.85/80 by access-group "PRG_WAN_access_in" but the config looks right to me. can anybody help?&lt;/P&gt;&lt;P&gt;config below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (WAN) 2 80.2.100.75-80.2.100.87 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;global (WAN) 1 interface&lt;/P&gt;&lt;P&gt;static (PRG_LAN,WAN) tcp 80.2.100.85 www 192.168.123.34 www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-list PRG_WAN_access_in extended permit tcp any host 82.2.100.74 eq ssh&lt;/P&gt;&lt;P&gt;access-list PRG_WAN_access_in extended permit tcp any host 82.2.100.84 eq www &lt;/P&gt;&lt;P&gt;access-list PRG_WAN_access_in extended permit tcp any host 82.2.100.85 eq www &lt;/P&gt;&lt;P&gt;access-group PRG_WAN_access_in in interface WAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:06:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324966#M858229</guid>
      <dc:creator>jaimewalker</dc:creator>
      <dc:date>2019-03-11T16:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: publish web site</title>
      <link>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324967#M858233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;issue on the cli "clear xlate" and try again, also put a line at the bottom of the acl:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list PRG_WAN_access_in extended deny ip any any log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then check your logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Aug 2009 09:18:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324967#M858233</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-08-18T09:18:55Z</dc:date>
    </item>
    <item>
      <title>Re: publish web site</title>
      <link>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324968#M858235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;unfortunatly clear xlate didn't help&lt;/P&gt;&lt;P&gt;and the log information is not showing me anything else.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Aug 2009 10:08:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324968#M858235</guid>
      <dc:creator>jaimewalker</dc:creator>
      <dc:date>2009-08-18T10:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: publish web site</title>
      <link>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324969#M858238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;post the output from:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show xlate&lt;/P&gt;&lt;P&gt;show access-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Aug 2009 10:08:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324969#M858238</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-08-18T10:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: publish web site</title>
      <link>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324970#M858239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;attachment added with output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Aug 2009 10:16:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324970#M858239</guid>
      <dc:creator>jaimewalker</dc:creator>
      <dc:date>2009-08-18T10:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: publish web site</title>
      <link>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324971#M858241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK - my ovbservations:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) you did get a hit for the http acl for the web server - check your server is actaully listening on tcp port 80&lt;/P&gt;&lt;P&gt;2) You are getting alog of denies - are you trying to access the website via DNS or direct IP&lt;/P&gt;&lt;P&gt;3) Is by DNS check the IP address the url is resolving to is the same as the acl &amp;amp; static nat&lt;/P&gt;&lt;P&gt;4) Try changing the PAT to a NAT:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;remove&lt;/P&gt;&lt;P&gt;static (PRG_LAN,WAN) tcp 80.2.100.85 www 192.168.123.34 www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;replace&lt;/P&gt;&lt;P&gt;static (PRG_LAN,WAN) 80.2.100.85 192.168.123.34 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And re-test.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Aug 2009 10:19:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324971#M858241</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-08-18T10:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: publish web site</title>
      <link>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324972#M858243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;I can successfully telnet 192.168.123.34 80 so I believe the server is listening on port 80&lt;/P&gt;&lt;P&gt;My test is to telnet 80.2.100.85 80 rather than use DNS&lt;/P&gt;&lt;P&gt;I have done a NAT translation as advised but still no look&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Aug 2009 10:30:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324972#M858243</guid>
      <dc:creator>jaimewalker</dc:creator>
      <dc:date>2009-08-18T10:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: publish web site</title>
      <link>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324973#M858245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where are you testing from, the inside or the outside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check your NAT/ACL again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Aug 2009 10:50:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324973#M858245</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-08-18T10:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: publish web site</title>
      <link>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324974#M858247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tested it from inside and 2 x outside locations but still no luck. I will check the NAT/ACL again.&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Aug 2009 10:59:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324974#M858247</guid>
      <dc:creator>jaimewalker</dc:creator>
      <dc:date>2009-08-18T10:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: publish web site</title>
      <link>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324975#M858248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;wood for the trees....&lt;/P&gt;&lt;P&gt;the problem was a typo in the ACL. I was putting 82 instead of 80 in the first octet.&lt;/P&gt;&lt;P&gt;sorry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Aug 2009 06:44:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324975#M858248</guid>
      <dc:creator>jaimewalker</dc:creator>
      <dc:date>2009-08-19T06:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: publish web site</title>
      <link>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324976#M858249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;np - glad to help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Aug 2009 07:42:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publish-web-site/m-p/1324976#M858249</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-08-19T07:42:31Z</dc:date>
    </item>
  </channel>
</rss>

