<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Publidhing Web Server in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018794#M919644</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Huseyin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. Need  to know that why &lt;/P&gt;&lt;P&gt;i should use this command&lt;/P&gt;&lt;P&gt;static (dmz,outside) publicip webserverip netmask 255.255.255.255 dns &lt;/P&gt;&lt;P&gt;because i just want to publish webserver so y in this we should mention dns.&lt;/P&gt;&lt;P&gt;other thing i want to ask shouldn't i use&lt;/P&gt;&lt;P&gt;conduit permit tcp host webserverip eq www any&lt;/P&gt;&lt;P&gt;instead of access-list because it is mentioned in cisco website that for lower security level to higher security level we should use conduit command. and to allow access for my internal user to website i should use nat &amp;amp; global commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 24 May 2008 07:23:45 GMT</pubDate>
    <dc:creator>kashifashraf</dc:creator>
    <dc:date>2008-05-24T07:23:45Z</dc:date>
    <item>
      <title>Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018792#M919642</link>
      <description>&lt;P&gt;I have a PIX 515e. My company wants to launch the web site which will serve Internet users as well as internal users. In my web server i have two network cards. My firewall has 3 network interface one is inside, other is outside network and the third one i want to configure as a dmz in which the webserver will reside. how should i configure my firewall to publish webserver. should i connect dmz with one network card of webserver for internet users and the other network card to connect to my local netwrok for internal users.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:49:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018792#M919642</guid>
      <dc:creator>kashifashraf</dc:creator>
      <dc:date>2019-03-11T12:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018793#M919643</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kashif&lt;/P&gt;&lt;P&gt;  I would recommend using only 1 NIC with webserver, place it into DMZ. then create the following static rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) publicip webserverip netmask 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit tcp any host publicip eq www&lt;/P&gt;&lt;P&gt;static (dmz,inside) webserverip webserverip netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   If your domain is same with your external domain, create a host record with www in DNS and point it to webserverip not the publicip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2008 16:38:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018793#M919643</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-05-23T16:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018794#M919644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Huseyin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. Need  to know that why &lt;/P&gt;&lt;P&gt;i should use this command&lt;/P&gt;&lt;P&gt;static (dmz,outside) publicip webserverip netmask 255.255.255.255 dns &lt;/P&gt;&lt;P&gt;because i just want to publish webserver so y in this we should mention dns.&lt;/P&gt;&lt;P&gt;other thing i want to ask shouldn't i use&lt;/P&gt;&lt;P&gt;conduit permit tcp host webserverip eq www any&lt;/P&gt;&lt;P&gt;instead of access-list because it is mentioned in cisco website that for lower security level to higher security level we should use conduit command. and to allow access for my internal user to website i should use nat &amp;amp; global commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 May 2008 07:23:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018794#M919644</guid>
      <dc:creator>kashifashraf</dc:creator>
      <dc:date>2008-05-24T07:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018795#M919645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"dns" switch at the end enables dns doctoring for that specific entry. If you dont do dns doctoring, whenever an inside user tries to reach &lt;A class="jive-link-custom" href="http://www.youwebsite.com," target="_blank"&gt;www.youwebsite.com,&lt;/A&gt; your Public address will be returned and this will create a U turn traffic which will result with a drop. In DNS doctoring, If the specified traffic is met (an inside host tries to reach &lt;A class="jive-link-custom" href="http://www.yourwebsite.com," target="_blank"&gt;www.yourwebsite.com,&lt;/A&gt; ) that static with DNS command will re-write the DNS query by putting the private ip of Web server in DMZ instead public IP and you will reach webserver directly. But If you have a DNS server locally that all clients pointed to that and you can create a host record for www in yourwebsite.com domain, dns doctoring wont be needed at all, but just in case, I put it there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conduit statement is depreceated, it was used before 6.3 IOS it is no longer supported. You have to use ACLs instead. You have an IOS greater than 6.3 in PIX 515E correct ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and for your clients located in inside interface to be able to connect dmz, second static command is necessary. It will make the webserver located in DMZ not to be translated in NAT and reached directly. You wont need further NAT&amp;amp;Global commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 May 2008 13:10:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018795#M919645</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-05-24T13:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018796#M919646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Very Much i will try this scenerio and i will inform u. Also yes my Pix515e software version is 6.3(4).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 May 2008 12:55:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018796#M919646</guid>
      <dc:creator>kashifashraf</dc:creator>
      <dc:date>2008-05-25T12:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018797#M919647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are welcome kashif, looking forward to hear from you about the progress. I suggest you to upgrade your IOS to at least 6.3(5), and my recommendation is 7.2(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 May 2008 14:02:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018797#M919647</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-05-25T14:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018798#M919648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear husycisco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have cnfigure my firewall for inbound access but in my log it shows &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;deny tcp src outside:ipaddress dst dmz:ipaddress/80 by access-group "inbound"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have attached my config file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can u please help me and tell me what mistake i am doing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 May 2008 09:40:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018798#M919648</guid>
      <dc:creator>kashifashraf</dc:creator>
      <dc:date>2008-05-30T09:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018799#M919649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;  Hi Kashif,&lt;/P&gt;&lt;P&gt;   I assume your code 6.3(4) is still running with conduits. Please add the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no access-list inbound permit tcp any host 91.140.255.220 eq www &lt;/P&gt;&lt;P&gt;no access-group inbound in interface outside&lt;/P&gt;&lt;P&gt;conduit permit tcp host 91.140.255.220 eq www any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 May 2008 10:31:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018799#M919649</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-05-30T10:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018800#M919650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I tried these commands also but its not working still. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also in syslog i didnt get any error message i rechecked the conectivity of my firewall to internet and its ok. i can use vpn connection from my home.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but still i cant access the website.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 May 2008 14:12:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018800#M919650</guid>
      <dc:creator>kashifashraf</dc:creator>
      <dc:date>2008-05-31T14:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018801#M919651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kashif,&lt;/P&gt;&lt;P&gt;  Run "clear arp" and "clear xlate".&lt;/P&gt;&lt;P&gt;  Make sure web server's default gateway is 172.16.4.1&lt;/P&gt;&lt;P&gt;  Make sure there is no software firewall or HIPS runnin on web server. If running, then modify the exceptions scope to accept www traffic from any.&lt;/P&gt;&lt;P&gt;  Please post your latest config with conduit added.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 May 2008 16:03:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018801#M919651</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-05-31T16:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018802#M919652</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear husycisco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for your advise . after putting the default gateway i can access my website from internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;other thing i want to ask u how i can publish the website for internal users. before u suggest me to use static command with access-list now but my firewall ios version is 6.3 so i can use cnduit command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so how i can publish my website for internal users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank u very very much for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2008 11:27:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018802#M919652</guid>
      <dc:creator>kashifashraf</dc:creator>
      <dc:date>2008-06-02T11:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018803#M919653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;dear husycisco &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have change my configuration from conduit command to access-list and it is working fine also.&lt;/P&gt;&lt;P&gt;i think before i didnt succed becz the gateway was not configured to web server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now i want to give access to internal users to the web site so what should i configure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also to manage the webiste i want to give access to developers internal network so they can connect through remote desktop to web server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2008 15:02:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018803#M919653</guid>
      <dc:creator>kashifashraf</dc:creator>
      <dc:date>2008-06-02T15:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018804#M919654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kashif,&lt;/P&gt;&lt;P&gt;  You are welcome &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Add the following&lt;/P&gt;&lt;P&gt; static (dmz,inside) webserver webserver netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-list hadi line 2 permit 200.200.200.0 255.255.255.0 host webserver eq 80&lt;/P&gt;&lt;P&gt;access-list hadi line 3 permit developersnetwork developersnetmask host webserver eq 3389&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2008 16:21:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018804#M919654</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-06-02T16:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018805#M919655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear husycisco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the static command was accecepted by the firewall but i wasnt able to access the website from internal user, i tried to access with the ip address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;both access-list command was not accepted by the firewall and i couldn configure it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it seems like some parameter was missing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2008 16:58:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018805#M919655</guid>
      <dc:creator>kashifashraf</dc:creator>
      <dc:date>2008-06-02T16:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018806#M919656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm, try this&lt;/P&gt;&lt;P&gt;access-list hadi line 2 permit ip 200.200.200.0 255.255.255.0 host webserver eq 80 &lt;/P&gt;&lt;P&gt;access-list hadi line 3 permit ip developersnetwork developersnetmask host webserver eq 3389 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2008 17:19:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018806#M919656</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-06-02T17:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018807#M919657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried this also but firewall still not accepting this command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i tried to use "any" instead of host, firewall accepted the command but i wasnt able to connect to webserver.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also i configured &lt;/P&gt;&lt;P&gt;static (dmz,inside) webserver webserver netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;but still my internal users were not able to access website i check in syslog i got this error message&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regular translation creation failed for tcp src inside ***ipaddress*** dst dmz webserver&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2008 19:34:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018807#M919657</guid>
      <dc:creator>kashifashraf</dc:creator>
      <dc:date>2008-06-02T19:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: Publidhing Web Server</title>
      <link>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018808#M919658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I advise BS like that when I dont get enough sleep sorry for that &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; nothing exists like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list hadi line 2 permit ip 200.200.200.0 255.255.255.0 host webserver eq 80 &lt;/P&gt;&lt;P&gt;access-list hadi line 3 permit ip developersnetwork developersnetmask host webserver eq 3389 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;should be&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list hadi line 2 permit tcp 200.200.200.0 255.255.255.0 host webserver eq 80 &lt;/P&gt;&lt;P&gt;access-list hadi line 3 permit tcp developersnetwork developersnetmask host webserver eq 3389 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The point here is, above ACEs should be placed before the deny any any statement you provided. Or simply remove deny statement, add above ACEs without line command then place dny any any in the end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also try the following static&lt;/P&gt;&lt;P&gt;static (inside,dmz) 200.200.200.0 200.200.200.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after entering the static command, run clear xlate that should handle regular trans crea fail. If all still the same, post your latest config and the regular translation creation failed syslog exactly with IP addresses&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2008 00:45:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/publidhing-web-server/m-p/1018808#M919658</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-06-03T00:45:11Z</dc:date>
    </item>
  </channel>
</rss>

