<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Static bypassing ACL inside? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/static-bypassing-acl-inside/m-p/1062136#M913862</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Adam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Must be going alzheimers already &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Aug 2008 17:26:59 GMT</pubDate>
    <dc:creator>azore2007</dc:creator>
    <dc:date>2008-08-27T17:26:59Z</dc:date>
    <item>
      <title>Static bypassing ACL inside?</title>
      <link>https://community.cisco.com/t5/network-security/static-bypassing-acl-inside/m-p/1062134#M913853</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to double-check packet traversal in a pix 6.3(5)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have  webserver on the inside with public IP's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The acl-inside is limiting access from passing the firewall towards the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Webserver has the static (inside,outside) 1.1.1.1 1.1.1.1 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL-outside has a  permit ip any host 1.1.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, to my problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought you needed to add access for the webserver (1.1.1.1) to respond back?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So acl-inside need the acl rule "permit ip host 1.1.1.1 any"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE, i have a "deny ip any any" at the bottom of my ACL-inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;need som clarification thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:36:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-bypassing-acl-inside/m-p/1062134#M913853</guid>
      <dc:creator>azore2007</dc:creator>
      <dc:date>2019-03-11T13:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: Static bypassing ACL inside?</title>
      <link>https://community.cisco.com/t5/network-security/static-bypassing-acl-inside/m-p/1062135#M913858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You do not have to allow the return traffic from the webserver in the inside acl. This is the whole point of a stateful firewall. You do however need to allow any traffic that will be initiated from the webserver through the inside interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Aug 2008 15:08:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-bypassing-acl-inside/m-p/1062135#M913858</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-08-27T15:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: Static bypassing ACL inside?</title>
      <link>https://community.cisco.com/t5/network-security/static-bypassing-acl-inside/m-p/1062136#M913862</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Adam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Must be going alzheimers already &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Aug 2008 17:26:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/static-bypassing-acl-inside/m-p/1062136#M913862</guid>
      <dc:creator>azore2007</dc:creator>
      <dc:date>2008-08-27T17:26:59Z</dc:date>
    </item>
  </channel>
</rss>

