<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5505 &amp;quot;outside_access_in&amp;quot; blocking UDP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/875996#M956737</link>
    <description>&lt;P&gt;Greetings all!  This is sort of elementary for everyone (and may be silly, once you hear what I'm doing...) but I'm stumped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's what I've got:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- ASA5505&lt;/P&gt;&lt;P&gt;- Xbox LIVE service:  88 UDP &amp;amp; 3074 TCP-UDP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've searched around these forums and found help, but they were geared more towards the PIX 501.  Anyways, here's what I've done:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- setup my xbox to a static IP (192.168.1.200)&lt;/P&gt;&lt;P&gt;- entered a service group with the above mentioned ports for both UDP and TCP&lt;/P&gt;&lt;P&gt;- created 3 NAT rules for those ports to go straight to the Xbox.&lt;/P&gt;&lt;P&gt;- added the xbox to a ACL so that those ports come into the Xbox&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I get, when testing, is this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4	Jan 18 2008	20:01:18	106023	65.59.234.162	72.12.119.218	 Deny udp src outside:65.59.234.162/55619 dst inside:72.12.119.218/3074 by access-group "outside_access_in" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the "outside_access_in" group, I have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1	True	any	Xbox360	Xbox_LIVE	Permit	Default		&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure why, but the packets, when coming back inside, are being denied.  I'm using ASDM to set this up and I know a lot of you like the command line.  If any of you can offer any help, I can run a command using command line and give you any outputs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help my friends.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CH&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:50:32 GMT</pubDate>
    <dc:creator>interknox</dc:creator>
    <dc:date>2019-03-11T11:50:32Z</dc:date>
    <item>
      <title>ASA5505 "outside_access_in" blocking UDP</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/875996#M956737</link>
      <description>&lt;P&gt;Greetings all!  This is sort of elementary for everyone (and may be silly, once you hear what I'm doing...) but I'm stumped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's what I've got:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- ASA5505&lt;/P&gt;&lt;P&gt;- Xbox LIVE service:  88 UDP &amp;amp; 3074 TCP-UDP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've searched around these forums and found help, but they were geared more towards the PIX 501.  Anyways, here's what I've done:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- setup my xbox to a static IP (192.168.1.200)&lt;/P&gt;&lt;P&gt;- entered a service group with the above mentioned ports for both UDP and TCP&lt;/P&gt;&lt;P&gt;- created 3 NAT rules for those ports to go straight to the Xbox.&lt;/P&gt;&lt;P&gt;- added the xbox to a ACL so that those ports come into the Xbox&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I get, when testing, is this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4	Jan 18 2008	20:01:18	106023	65.59.234.162	72.12.119.218	 Deny udp src outside:65.59.234.162/55619 dst inside:72.12.119.218/3074 by access-group "outside_access_in" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the "outside_access_in" group, I have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1	True	any	Xbox360	Xbox_LIVE	Permit	Default		&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure why, but the packets, when coming back inside, are being denied.  I'm using ASDM to set this up and I know a lot of you like the command line.  If any of you can offer any help, I can run a command using command line and give you any outputs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help my friends.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CH&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:50:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/875996#M956737</guid>
      <dc:creator>interknox</dc:creator>
      <dc:date>2019-03-11T11:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 "outside_access_in" blocking UDP</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/875997#M956739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;post a...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show run nat&lt;/P&gt;&lt;P&gt;show run access-list outside_access_in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jan 2008 02:22:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/875997#M956739</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-01-19T02:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 "outside_access_in" blocking UDP</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/875998#M956741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;show run nat:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"nat (inside) 1 0.0.0.0 0.0.0.0"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show run access-list outside_access_in:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"access-list outside_access_in extended permit object-group Xbox_LIVE any host Xbox360"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jan 2008 02:40:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/875998#M956741</guid>
      <dc:creator>interknox</dc:creator>
      <dc:date>2008-01-19T02:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 "outside_access_in" blocking UDP</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/875999#M956743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry I meant show run static. Why don't you just post a sanitized/cleaned config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show run&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jan 2008 13:55:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/875999#M956743</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-01-19T13:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 "outside_access_in" blocking UDP</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/876000#M956745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;show run static:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 3074 Xbox360 3074 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) udp interface 3074 Xbox360 3074 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) udp interface 88 Xbox360 88 netmask 255.255.255.255  dns &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show run:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.0(3) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname greylock&lt;/P&gt;&lt;P&gt;domain-name ch.local&lt;/P&gt;&lt;P&gt;enable password RONX1BXdqaFcKwP9 encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 192.168.1.200 Xbox360&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.169 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; pppoe client vpdn group DSL&lt;/P&gt;&lt;P&gt; ip address pppoe setroute &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;boot system disk0:/newstuff/asa803.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns domain-lookup outside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 208.67.222.222&lt;/P&gt;&lt;P&gt; name-server 208.67.220.220&lt;/P&gt;&lt;P&gt; domain-name interknox.net&lt;/P&gt;&lt;P&gt;object-group service Xbox_LIVE&lt;/P&gt;&lt;P&gt; service-object udp source eq 88 eq 88 &lt;/P&gt;&lt;P&gt; service-object tcp-udp source eq 3074 eq 3074 &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip host Xbox360 any &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group Xbox_LIVE any host Xbox360 &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm warnings&lt;/P&gt;&lt;P&gt;logging from-address &lt;A href="mailto:email@interknox.net"&gt;email@interknox.net&lt;/A&gt;&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp deny any outside&lt;/P&gt;&lt;P&gt;asdm image disk0:/newstuff/asdm-603.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 3074 Xbox360 3074 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) udp interface 3074 Xbox360 3074 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) udp interface 88 Xbox360 88 netmask 255.255.255.255  dns &lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 68.152.211.86 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;vpdn group DSL request dialout pppoe&lt;/P&gt;&lt;P&gt;vpdn group DSL localname my dsl email&lt;/P&gt;&lt;P&gt;vpdn group DSL ppp authentication pap&lt;/P&gt;&lt;P&gt;vpdn username my email password ********* &lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.125-192.168.1.150 inside&lt;/P&gt;&lt;P&gt;dhcpd dns 208.67.222.222 208.67.220.220 interface inside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics port&lt;/P&gt;&lt;P&gt;threat-detection statistics protocol&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;ntp server 131.107.13.100 source outside&lt;/P&gt;&lt;P&gt;ntp server 129.6.15.29 source outside&lt;/P&gt;&lt;P&gt;ntp server 129.6.15.28 source outside prefer&lt;/P&gt;&lt;P&gt;username chris password TYGBt4.L24KH1.mU encrypted privilege 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;  inspect rtsp &lt;/P&gt;&lt;P&gt;  inspect esmtp &lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;  inspect skinny  &lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt;  inspect sip  &lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;Cryptochecksum:1d79690fe1b4b7246c3a87153b23040b&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE: I cut out some of the "interfaces" because of message length restrictions on the forums.  Other interfaces aren't in use, FYI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jan 2008 14:21:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/876000#M956745</guid>
      <dc:creator>interknox</dc:creator>
      <dc:date>2008-01-19T14:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 "outside_access_in" blocking UDP</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/876001#M956747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your access list is not correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group Xbox_LIVE any host Xbox360 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;should be...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group Xbox_LIVE any interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group Xbox_LIVE any host &lt;OUTSIDE.IP.ADDRESS&gt;&lt;/OUTSIDE.IP.ADDRESS&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jan 2008 14:42:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/876001#M956747</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-01-19T14:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 "outside_access_in" blocking UDP</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/876002#M956749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay, using ASDM, it went from this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group Xbox_LIVE any host Xbox360 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit object-group Xbox_LIVE any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and it still blocks UDP ports (from log):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4	Jan 19 2008	09:48:27	106023	65.59.234.162	72.12.119.28	 Deny udp src outside:65.59.234.162/43971 dst inside:72.12.119.28/3074 by access-group "outside_access_in" [0x0, 0x0]&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jan 2008 14:57:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/876002#M956749</guid>
      <dc:creator>interknox</dc:creator>
      <dc:date>2008-01-19T14:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 "outside_access_in" blocking UDP</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/876003#M956751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have the source ip's of xbox live?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, the Xbox_LIVE object group needs to be the destination port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended  permit udp any interface outside eq 88&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended  permit udp any interface outside eq 3074&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended  permit tcp any interface outside eq 3074&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jan 2008 15:07:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/876003#M956751</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-01-19T15:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 "outside_access_in" blocking UDP</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/876004#M956754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay, it's working now and I found that there were 2 problems.  One problem ended up being that the Xbox_Live group's ports had the source/destination as the same thing, instead of "default" for the source.  For instance, I had:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;destination: udp 3074&lt;/P&gt;&lt;P&gt;source:  udp 3074&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When in fact, Xbox LIVE service doesn't use those ports at the source, so the ACL was blocking it.  I changed it do:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;destination:  udp 3074&lt;/P&gt;&lt;P&gt;source:  default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second, like you said, my outside_access_in group listed my destination as my Xbox360, when in fact that won't work, as that device is using a private IP, behind the firewall.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I changed both these things and it now works like a champ!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for all your help.  I'll be sure to rate/vote whatever for you anytime.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jan 2008 15:52:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/876004#M956754</guid>
      <dc:creator>interknox</dc:creator>
      <dc:date>2008-01-19T15:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 "outside_access_in" blocking UDP</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/876005#M956759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Happy gaming!~&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jan 2008 17:58:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-quot-outside-access-in-quot-blocking-udp/m-p/876005#M956759</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-01-19T17:58:03Z</dc:date>
    </item>
  </channel>
</rss>

