<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Simple HTTPS Access (Intranet) not so simple in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/simple-https-access-intranet-not-so-simple/m-p/3414381#M951057</link>
    <description>&lt;P&gt;&lt;SPAN&gt;xx.xx.xx.151 - iam guessing this is public internet&amp;nbsp;routeble IP, is this correct ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do you have NAT rule for your internal IP ? (172.25.205.5-172.25.205.250).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;RFC 1918 - can not go directly to internet, you need to do NAT in the WAN end router/or device.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;if you can show the network topo, we can suggest much better.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;BB&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Jul 2018 00:35:46 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2018-07-12T00:35:46Z</dc:date>
    <item>
      <title>Simple HTTPS Access (Intranet) not so simple</title>
      <link>https://community.cisco.com/t5/network-security/simple-https-access-intranet-not-so-simple/m-p/3414374#M951056</link>
      <description>&lt;P&gt;A company that we've been talking to via HTTPS over our Internet connection wants us to&lt;BR /&gt;run this HTTPS connection via our Internal Network which we connect to on our core Network &lt;BR /&gt;just fine but can't access via our remote vpn sites.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Remote VPN sites are all connected to a 5510 that can reach&lt;SPAN&gt;&amp;nbsp;xx.xx.xx.151 just fine.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The VPN connection on the remote ends are odd, they have a working IPSEC Tunnel but they actually connect to the&amp;nbsp;&lt;SPAN&gt;xx.xx.xx.151 website&lt;/SPAN&gt; via Cisco AnyConnect VPN clients. When they log into the AnyConnect they're given a Pool IP&amp;nbsp;172.25.205.5-172.25.205.250&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note: We can reach other internal servers but not the xx.xx.xx.151&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've ran a packet capture but I don't think I'm doing it right.&lt;/P&gt;
&lt;P&gt;Packet-tracer input inside tcp 172.25.205.1 1025 xx.xx.xx.151 443 DETAIL &lt;BR /&gt;&amp;nbsp; &amp;nbsp; Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;
&lt;P&gt;show run access-group&lt;BR /&gt;&amp;nbsp; &amp;nbsp; access-group out_in in interface outside&lt;/P&gt;
&lt;P&gt;show config | inc out_in&lt;BR /&gt;&amp;nbsp; &amp;nbsp; access-list out_in extended permit ip any any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help on this would be greatly appreciated like I said various people have been trying to get it to work for 9 months.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:58:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-https-access-intranet-not-so-simple/m-p/3414374#M951056</guid>
      <dc:creator>ixholla69</dc:creator>
      <dc:date>2020-02-21T15:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: Simple HTTPS Access (Intranet) not so simple</title>
      <link>https://community.cisco.com/t5/network-security/simple-https-access-intranet-not-so-simple/m-p/3414381#M951057</link>
      <description>&lt;P&gt;&lt;SPAN&gt;xx.xx.xx.151 - iam guessing this is public internet&amp;nbsp;routeble IP, is this correct ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do you have NAT rule for your internal IP ? (172.25.205.5-172.25.205.250).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;RFC 1918 - can not go directly to internet, you need to do NAT in the WAN end router/or device.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;if you can show the network topo, we can suggest much better.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;BB&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 00:35:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-https-access-intranet-not-so-simple/m-p/3414381#M951057</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-07-12T00:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: Simple HTTPS Access (Intranet) not so simple</title>
      <link>https://community.cisco.com/t5/network-security/simple-https-access-intranet-not-so-simple/m-p/3414401#M951058</link>
      <description>&lt;P&gt;Here's a quick map.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 01:46:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-https-access-intranet-not-so-simple/m-p/3414401#M951058</guid>
      <dc:creator>ixholla69</dc:creator>
      <dc:date>2018-07-12T01:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Simple HTTPS Access (Intranet) not so simple</title>
      <link>https://community.cisco.com/t5/network-security/simple-https-access-intranet-not-so-simple/m-p/3414448#M951059</link>
      <description>&lt;P&gt;Can I apply the same ANY ANY ACL to this to the INSIDE Interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show run access-group&lt;BR /&gt;&amp;nbsp; &amp;nbsp; access-group out_in in interface outside&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;------Current&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-group out_in in interface INSIDE&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;-----Add to INSIDE interface?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is that possible? I don't usually do Access-Groups so not sure if it's possible, would that allow the ANY ANY traffic to hit the INSIDE as well?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 03:57:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/simple-https-access-intranet-not-so-simple/m-p/3414448#M951059</guid>
      <dc:creator>ixholla69</dc:creator>
      <dc:date>2018-07-12T03:57:47Z</dc:date>
    </item>
  </channel>
</rss>

