<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA5520 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5520/m-p/857460#M960324</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a Deny farther up the ACL? Any hit counts on the ACL for SSH? Can you post the entire log message (minus the IPs)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Nov 2007 19:47:57 GMT</pubDate>
    <dc:creator>Collin Clark</dc:creator>
    <dc:date>2007-11-20T19:47:57Z</dc:date>
    <item>
      <title>ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/asa5520/m-p/857459#M960322</link>
      <description>&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having trouble with a security policy rule that is denying outbound connections.  I am trying to allow outbound SSH connections to specific IP addresses.  Therefore, I added a rule on the inside incoming interface that allows tcp source 192.168.0.0/24 dest ip-group tcp-service group.  The ip-group consists of 3 IP addresses of servers.  The TCP service group consists of tcp ports 902, 9999, ftp, ftp-data, and ssh.  902, 9999, ftp, ftp-data work fine, but the SSH does not work.  I get a message in the log deny tcp src 192.168.0.x to x.x.x.x:22 on the internal access list.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a NAT rule for these connections, but it looks like the firewall denies it before the NAT rule takes affect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if anyone has any suggestions.  Thanks,&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:33:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520/m-p/857459#M960322</guid>
      <dc:creator>sweigle</dc:creator>
      <dc:date>2019-03-11T11:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/asa5520/m-p/857460#M960324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a Deny farther up the ACL? Any hit counts on the ACL for SSH? Can you post the entire log message (minus the IPs)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2007 19:47:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520/m-p/857460#M960324</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2007-11-20T19:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/asa5520/m-p/857461#M960326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks, you were right, there was something farther up the ACL that was denying thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Nov 2007 22:50:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520/m-p/857461#M960326</guid>
      <dc:creator>sweigle</dc:creator>
      <dc:date>2007-11-20T22:50:29Z</dc:date>
    </item>
  </channel>
</rss>

