<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM:Allowing HTTP on another port:Inspection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-allowing-http-on-another-port-inspection/m-p/1232599#M860187</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check the security level of the interfaces. Traffic does not go through the FWSM from a higher security interface to a lower security interface. You did not apply an access list to the higher security interface to allow traffic through. Unlike the PIX firewall, the FWSM does not automatically allow traffic to pass between interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apply an access list to the source interface to allow traffic through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 May 2009 12:35:29 GMT</pubDate>
    <dc:creator>sadbulali</dc:creator>
    <dc:date>2009-05-08T12:35:29Z</dc:date>
    <item>
      <title>FWSM:Allowing HTTP on another port:Inspection</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-allowing-http-on-another-port-inspection/m-p/1232598#M860183</link>
      <description>&lt;P&gt;hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet ---- FWSM (ver 3.2(8)) ---Serverfarm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have a server which has an application that listens on port 55005.The way the appliction is accessed is by &lt;A class="jive-link-custom" href="http://public-ip:55005" target="_blank"&gt;http://public-ip:55005&lt;/A&gt;. I have opened port 55005 on the fwsm and the static and access-lists are as follows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmzSERVER,OUTSIDE) public-ip private-ip netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list FR_OUTSIDE extended permit tcp any host public-ip eq 55005 &lt;/P&gt;&lt;P&gt;access-group FR_OUTSIDE in int OUTSIDE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is that i get the login page.As soon as enter the username and password and hit enter it says page cannot be displayed. On logging the FWSM i cannot find anything being dropped. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried application inspection for http using the following configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map HTTP&lt;/P&gt;&lt;P&gt; match port tcp eq 55005&lt;/P&gt;&lt;P&gt;policy-map HTTP&lt;/P&gt;&lt;P&gt; class HTTP&lt;/P&gt;&lt;P&gt;  inspect http &lt;/P&gt;&lt;P&gt;service-policy HTTP interface OUTSIDE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now when the outside user tries &lt;A class="jive-link-custom" href="http://public-ip:55005" target="_blank"&gt;http://public-ip:55005&lt;/A&gt; i can see that there are hits for the above inspection and that nothing is dropped.But still after supplying the username and password we still get page cannot be displayed. I havent tried with an HTTp map though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe this has got something to do with http traffic going on port 55005. locally everything works OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if any one has some ideas regarding this please help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mannyD&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:27:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-allowing-http-on-another-port-inspection/m-p/1232598#M860183</guid>
      <dc:creator>MannyD123</dc:creator>
      <dc:date>2019-03-11T15:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM:Allowing HTTP on another port:Inspection</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-allowing-http-on-another-port-inspection/m-p/1232599#M860187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check the security level of the interfaces. Traffic does not go through the FWSM from a higher security interface to a lower security interface. You did not apply an access list to the higher security interface to allow traffic through. Unlike the PIX firewall, the FWSM does not automatically allow traffic to pass between interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apply an access list to the source interface to allow traffic through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 May 2009 12:35:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-allowing-http-on-another-port-inspection/m-p/1232599#M860187</guid>
      <dc:creator>sadbulali</dc:creator>
      <dc:date>2009-05-08T12:35:29Z</dc:date>
    </item>
  </channel>
</rss>

