<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5510 Access-List Problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-access-list-problem/m-p/1011532#M941350</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems your routing is not correct for the destination network:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result: &lt;/P&gt;&lt;P&gt;input-interface: outside &lt;/P&gt;&lt;P&gt;output-interface: outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 08 Mar 2008 00:01:19 GMT</pubDate>
    <dc:creator>brettmilborrow</dc:creator>
    <dc:date>2008-03-08T00:01:19Z</dc:date>
    <item>
      <title>ASA 5510 Access-List Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-access-list-problem/m-p/1011529#M941344</link>
      <description>&lt;P&gt;My ASA 5510 is intermittently denying access form my ISP's mail server to our internal SMTP gatway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The acl applied to the outside interface of the firewall allows tcp any any to the smtp server on port 25. There is no access-list applied to inside interface. A packet trace yeilds the following result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: FLOW-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Found no matching flow, creating a new flow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: UN-NAT&lt;/P&gt;&lt;P&gt;Subtype: static&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;static (inside,outside) 193.201.254.66 128.1.100.199 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;  match ip inside host 128.1.100.199 outside any&lt;/P&gt;&lt;P&gt;    static translation to 193.201.254.66&lt;/P&gt;&lt;P&gt;    translate_hits = 1584262, untranslate_hits = 7749710&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;NAT divert to egress interface inside&lt;/P&gt;&lt;P&gt;Untranslate 193.201.254.66/0 to 128.1.100.199/0 using netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in   0.0.0.0         0.0.0.0         outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: DROP&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt; Forward Flow based lookup yields rule:&lt;/P&gt;&lt;P&gt; in  id=0x47de0a0, priority=11, domain=permit, deny=true&lt;/P&gt;&lt;P&gt;	hits=7928006, user_data=0x5, cs_id=0x0, flags=0x0, protocol=0&lt;/P&gt;&lt;P&gt;	src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/P&gt;&lt;P&gt;	dst ip=0.0.0.0, mask=0.0.0.0, port=0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: outside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: drop&lt;/P&gt;&lt;P&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The packet is being dropped by an implicit rule?  Any ideas.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:13:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-access-list-problem/m-p/1011529#M941344</guid>
      <dc:creator>dasgill</dc:creator>
      <dc:date>2019-03-11T12:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Access-List Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-access-list-problem/m-p/1011530#M941346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you post your acl?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should be...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list name extended permit tcp any host 193.201.254.66 eq 25&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2008 16:21:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-access-list-problem/m-p/1011530#M941346</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-03-07T16:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Access-List Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-access-list-problem/m-p/1011531#M941349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list outside_acl extended permit tcp any host 193.201.254.66 eq smtp &lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit tcp any object-group web-servers object-group web-ports-tcp &lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit tcp any object-group dmz-servers eq www &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2008 16:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-access-list-problem/m-p/1011531#M941349</guid>
      <dc:creator>dasgill</dc:creator>
      <dc:date>2008-03-07T16:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Access-List Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-access-list-problem/m-p/1011532#M941350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems your routing is not correct for the destination network:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result: &lt;/P&gt;&lt;P&gt;input-interface: outside &lt;/P&gt;&lt;P&gt;output-interface: outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Mar 2008 00:01:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-access-list-problem/m-p/1011532#M941350</guid>
      <dc:creator>brettmilborrow</dc:creator>
      <dc:date>2008-03-08T00:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Access-List Problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-access-list-problem/m-p/1011533#M941351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What version are you running? I'm getting the exact output your getting with a trace - looks like my issue could be related to bug ID CSCsj31537 however. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 20:51:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-access-list-problem/m-p/1011533#M941351</guid>
      <dc:creator>valconix</dc:creator>
      <dc:date>2008-03-11T20:51:21Z</dc:date>
    </item>
  </channel>
</rss>

