<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5505 outside implicit rule in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5505-outside-implicit-rule/m-p/831997#M960512</link>
    <description>&lt;P&gt;I can't seem to get incoming traffic pass the implicit outside rule. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've configured the below static route and access-list which I hope means anything source tcp address can get through the outside interface on port 1997 only and the static NAT sends the traffic to an IP in the DMZ zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) 192.168.18.5 192.168.2.2 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 192.168.18.5 eq 1997&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However I can't seem to get through. When I run packet filter it gets stopped by the outside implicit deny all rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logging shows the below:- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-7-710005: TCP request discarded from 192.168.18.254/3049 to outside:192.168.18.5/1997&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And as you can see from my access-list, my explicit configured rules are getting zero hit counts as all seems to be getting caught by the implicit deny rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mipsasa01# show access-list&lt;/P&gt;&lt;P&gt;access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 4096)&lt;/P&gt;&lt;P&gt;            alert-interval 300&lt;/P&gt;&lt;P&gt;access-list outside_access_in; 1 elements&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 1 extended permit tcp any host 192.168.18.5 eq 1997 (hitcnt=0) 0xdea97d0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why is all outside traffic hitting the explicit deny rule instead of my explicit permit rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In despair I changed my access rule to permit all tcp traffic on all ports and it still didn't get through. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packetnet dropped the packet with the implicit deny rule and logging showed the discarded message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas at all would be appreciated.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:31:59 GMT</pubDate>
    <dc:creator>starkhorn</dc:creator>
    <dc:date>2019-03-11T11:31:59Z</dc:date>
    <item>
      <title>ASA5505 outside implicit rule</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-outside-implicit-rule/m-p/831997#M960512</link>
      <description>&lt;P&gt;I can't seem to get incoming traffic pass the implicit outside rule. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've configured the below static route and access-list which I hope means anything source tcp address can get through the outside interface on port 1997 only and the static NAT sends the traffic to an IP in the DMZ zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) 192.168.18.5 192.168.2.2 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any host 192.168.18.5 eq 1997&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However I can't seem to get through. When I run packet filter it gets stopped by the outside implicit deny all rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logging shows the below:- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-7-710005: TCP request discarded from 192.168.18.254/3049 to outside:192.168.18.5/1997&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And as you can see from my access-list, my explicit configured rules are getting zero hit counts as all seems to be getting caught by the implicit deny rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mipsasa01# show access-list&lt;/P&gt;&lt;P&gt;access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 4096)&lt;/P&gt;&lt;P&gt;            alert-interval 300&lt;/P&gt;&lt;P&gt;access-list outside_access_in; 1 elements&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 1 extended permit tcp any host 192.168.18.5 eq 1997 (hitcnt=0) 0xdea97d0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why is all outside traffic hitting the explicit deny rule instead of my explicit permit rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In despair I changed my access rule to permit all tcp traffic on all ports and it still didn't get through. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Packetnet dropped the packet with the implicit deny rule and logging showed the discarded message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas at all would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:31:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-outside-implicit-rule/m-p/831997#M960512</guid>
      <dc:creator>starkhorn</dc:creator>
      <dc:date>2019-03-11T11:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 outside implicit rule</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-outside-implicit-rule/m-p/831998#M960514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is 192.168.18.5 the outside interface ip address? If so try this...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) interface 192.168.2.2 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2007 14:01:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-outside-implicit-rule/m-p/831998#M960514</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-11-16T14:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 outside implicit rule</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-outside-implicit-rule/m-p/831999#M960516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for that. Yeah 192.168.18.5 is the outside interface address. I've tried the above and I still get the same message when I do show log. There must be something fairly obvious that I'm doing incorrectly. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would the entire config of my ASA help?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Nov 2007 05:46:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-outside-implicit-rule/m-p/831999#M960516</guid>
      <dc:creator>starkhorn</dc:creator>
      <dc:date>2007-11-18T05:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 outside implicit rule</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-outside-implicit-rule/m-p/832000#M960517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok I stand corrected. I used the ASDM GUI and changed to use interface instead of 192.168.18.5....and it didn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I then tried it again but this time I used the CLI and now it works. I can only think that I forgot to press APPLY when using the GUI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway how it gets through with no problems. I don't get it though. 192.168.18.5 is the interface ip address so shouldn't that have worked?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Nov 2007 21:34:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-outside-implicit-rule/m-p/832000#M960517</guid>
      <dc:creator>starkhorn</dc:creator>
      <dc:date>2007-11-18T21:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 outside implicit rule</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-outside-implicit-rule/m-p/832001#M960519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is a feature in pix that you have to use the interface keyword when configuring Static if you want the traffic to hit the outside IP and get translated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SNIP&gt; You must use the interface keyword instead of specifying the actual IP address when you want to include the IP address of a PIX Firewall interface in a static PAT entry&lt;/SNIP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer the below URL for details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/s.html#wp1026694" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/s.html#wp1026694&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Nov 2007 22:00:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-outside-implicit-rule/m-p/832001#M960519</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2007-11-18T22:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5505 outside implicit rule</title>
      <link>https://community.cisco.com/t5/network-security/asa5505-outside-implicit-rule/m-p/832002#M960521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Arul, that clearly explains it. Many thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 18 Nov 2007 22:05:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5505-outside-implicit-rule/m-p/832002#M960521</guid>
      <dc:creator>starkhorn</dc:creator>
      <dc:date>2007-11-18T22:05:08Z</dc:date>
    </item>
  </channel>
</rss>

