<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cannot access secure web with site-to-site vpn in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3374311#M960923</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I change the Default Action in Access Control to 'Intrusion Prevention: Connectivity Over Security' from 'Access Control: Block All Traffic'. after the changed secure webpage &lt;A href="https://10.60.76.31" target="_blank"&gt;https://10.60.76.31&lt;/A&gt; can be loaded in the client machine 192.168.1.163. how do i check from here if i would to use 'Access Control: Block All Traffic' as default Action.&lt;/P&gt;</description>
    <pubDate>Fri, 27 Apr 2018 06:59:52 GMT</pubDate>
    <dc:creator>kenjitkc185</dc:creator>
    <dc:date>2018-04-27T06:59:52Z</dc:date>
    <item>
      <title>cannot access secure web with site-to-site vpn</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3373478#M960915</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm using Cisco FTD 2120 and managed by FMC. I have site-to-site VPN between two sites. Site A(10.60.76.0) is an HQ and Site B(192.168.1.0) is a branch. In Site B i can ssh to Site A server IP address 10.60.76.31 but i cannot access secure web server ip 10.60.76.31. how to i capture the packet to find out any drop in FTD? or anything i can do to trace or find out the packet had being dropped.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Kenji Tan&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:40:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3373478#M960915</guid>
      <dc:creator>kenjitkc185</dc:creator>
      <dc:date>2020-02-21T15:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access secure web with site-to-site vpn</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3373482#M960916</link>
      <description>&lt;P&gt;on your ftd go to analysis&amp;gt;connections&amp;gt;events and do a search based on initiator or responder IP&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 08:28:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3373482#M960916</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2018-04-26T08:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access secure web with site-to-site vpn</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3373671#M960917</link>
      <description>&lt;P&gt;Hi Dennis&lt;/P&gt;
&lt;P&gt;I put in initiator ip address 192.168.1.163 and responder ip address 10.60.76.31. There are no blocking between this two device but the page still not loaded. Any else to check.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 12:13:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3373671#M960917</guid>
      <dc:creator>kenjitkc185</dc:creator>
      <dc:date>2018-04-26T12:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access secure web with site-to-site vpn</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3373693#M960918</link>
      <description>&lt;P&gt;Ok so you know the tunnel is up, you see the remote traffic coming in. I d spin up wireshark on your webserver or run a tcpdump other wise and see if the traffic is actually reaching the web server on port 443&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 12:51:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3373693#M960918</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2018-04-26T12:51:29Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access secure web with site-to-site vpn</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3374020#M960919</link>
      <description>&lt;P&gt;Could also configure a debug or capture at the HQ to see if the traffic is leaving the inside interface.&lt;/P&gt;
&lt;P&gt;FTD CLI issue the command &lt;STRONG&gt;system support firewall-engine-debug&lt;/STRONG&gt;&amp;nbsp;enter ther server IP and client IP leave the protocol blank unless you really need to be that specific.&amp;nbsp; then run a test. and see if there is any output on the debug.&amp;nbsp; You might be hitting a rule in Security Intelligence which will be shown here.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also go into &lt;STRONG&gt;system support diagnostic-cli&lt;/STRONG&gt; and run a capture between the two IPs.&amp;nbsp; This will not show the Snort actions as the debug command will.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 19:58:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3374020#M960919</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2018-04-26T19:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access secure web with site-to-site vpn</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3374249#M960920</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i issued the '&lt;STRONG&gt;system support firewall-engine-debug' with server IP 10.60.76.31 and client IP 192.168.1.163 with protocol I leave it blank. I also ran the 'system support diagnostic-cli' with 'capture cap1 interface Internal match ip host 10.60.76.31 host 192.168.1.163'. I still not able to find out where the issue. the page is still not loaded in client machine 192.168.1.163.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Thanks&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 05:13:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3374249#M960920</guid>
      <dc:creator>kenjitkc185</dc:creator>
      <dc:date>2018-04-27T05:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access secure web with site-to-site vpn</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3374298#M960921</link>
      <description>&lt;P&gt;In the packet capture we see traffic flowing in both directs and nothing in the debug indicates a drop on the FTD either.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the URL you are trying to access the website with?&lt;/P&gt;
&lt;P&gt;Are you able to access this URL from a PC on the same subnet as the webserver?&lt;/P&gt;
&lt;P&gt;What device is used to terminate the VPN at the remote site?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 06:25:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3374298#M960921</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2018-04-27T06:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access secure web with site-to-site vpn</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3374305#M960922</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is the URL you are trying to access the website with?&lt;/P&gt;
&lt;P&gt;i'm using the ip address "&lt;A href="https://10.60.76.31" target="_blank"&gt;https://10.60.76.31&lt;/A&gt;" which is a Cisco FMC using the browser (IE, chrome).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you able to access this URL from a PC on the same subnet as the webserver?&lt;/P&gt;
&lt;P&gt;i have no issue to access from Server "10.60.76.28" to the Cisco FMC "10.60.76.31"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What device is used to terminate the VPN at the remote site?&lt;/P&gt;
&lt;P&gt;is a Watchguard M200&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 06:49:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3374305#M960922</guid>
      <dc:creator>kenjitkc185</dc:creator>
      <dc:date>2018-04-27T06:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access secure web with site-to-site vpn</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3374311#M960923</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I change the Default Action in Access Control to 'Intrusion Prevention: Connectivity Over Security' from 'Access Control: Block All Traffic'. after the changed secure webpage &lt;A href="https://10.60.76.31" target="_blank"&gt;https://10.60.76.31&lt;/A&gt; can be loaded in the client machine 192.168.1.163. how do i check from here if i would to use 'Access Control: Block All Traffic' as default Action.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 06:59:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-secure-web-with-site-to-site-vpn/m-p/3374311#M960923</guid>
      <dc:creator>kenjitkc185</dc:creator>
      <dc:date>2018-04-27T06:59:52Z</dc:date>
    </item>
  </channel>
</rss>

