<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACL question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acl-question/m-p/742015#M982838</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Or apply the acl in interface inside instead.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Aug 2007 15:24:03 GMT</pubDate>
    <dc:creator>acomiskey</dc:creator>
    <dc:date>2007-08-08T15:24:03Z</dc:date>
    <item>
      <title>ACL question</title>
      <link>https://community.cisco.com/t5/network-security/acl-question/m-p/742008#M982831</link>
      <description>&lt;P&gt;I have an acl to get all users out to the internet- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Internet_access_out tcp_group_internet_access&lt;/P&gt;&lt;P&gt;access-list Internet_access_out extended permit tcp any any object-group internet_test &lt;/P&gt;&lt;P&gt;access-list Internet_access_out extended permit tcp any any eq www &lt;/P&gt;&lt;P&gt;access-list Internet_access_out extended permit tcp any any eq domain &lt;/P&gt;&lt;P&gt;access-list Internet_access_out extended permit tcp any any eq https &lt;/P&gt;&lt;P&gt;access-list Internet_access_out extended permit tcp any any eq ftp &lt;/P&gt;&lt;P&gt;access-list Internet_access_out extended permit tcp any any eq citrix-ica &lt;/P&gt;&lt;P&gt;access-list Internet_access_out extended permit tcp any any range 2095 2095 &lt;/P&gt;&lt;P&gt;access-list Internet_access_out extended permit tcp any any range 9100 9100 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I change the source (any) to the ip address of the proxy server, I get an error message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4	Aug 08 2007	09:25:29	106023	10.132.129.30	65.54.152.126	 Deny tcp src inside:10.132.129.30/50285 dst outside:65.54.152.126/80 by access-group "Internet_access_out" [0x0, 0x0]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would appreciate any help. Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 10:55:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-question/m-p/742008#M982831</guid>
      <dc:creator>mike.feeney</dc:creator>
      <dc:date>2019-03-11T10:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: ACL question</title>
      <link>https://community.cisco.com/t5/network-security/acl-question/m-p/742009#M982832</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you made it like this...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Internet_access_out extended permit tcp host 10.132.129.30 any eq www &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and you receive the Deny message above?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2007 14:43:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-question/m-p/742009#M982832</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-08-08T14:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: ACL question</title>
      <link>https://community.cisco.com/t5/network-security/acl-question/m-p/742010#M982833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2007 14:49:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-question/m-p/742010#M982833</guid>
      <dc:creator>mike.feeney</dc:creator>
      <dc:date>2007-08-08T14:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: ACL question</title>
      <link>https://community.cisco.com/t5/network-security/acl-question/m-p/742011#M982834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well that doesn't make sense does it? Sure that you put "host 10.132.129.30 any" and not "any host 10.132.129.30"? How is the acl applied?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2007 14:54:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-question/m-p/742011#M982834</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-08-08T14:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: ACL question</title>
      <link>https://community.cisco.com/t5/network-security/acl-question/m-p/742012#M982835</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just changed it to this-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Internet_access_out extended permit tcp host 10.132.129.30 any eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the error message- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4	Aug 08 2007	12:08:26	106023	10.132.129.30	199.181.132.250	 Deny tcp src inside:10.132.129.30/52112 dst outside:199.181.132.250/80 by access-group "Internet_access_out" [0x0, 0x0] &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2007 15:06:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-question/m-p/742012#M982835</guid>
      <dc:creator>mike.feeney</dc:creator>
      <dc:date>2007-08-08T15:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: ACL question</title>
      <link>https://community.cisco.com/t5/network-security/acl-question/m-p/742013#M982836</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A little more info-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TFBPCiscoASA(config)# sh run access-g&lt;/P&gt;&lt;P&gt;access-group dbadirect_tunnel1_acl in interface outside&lt;/P&gt;&lt;P&gt;access-group Internet_access_out out interface outside&lt;/P&gt;&lt;P&gt;TFBPCiscoASA(config)# sh run static&lt;/P&gt;&lt;P&gt;static (inside,outside) x.x.x.207 10.132.129.30 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The static for the proxy is not the outside interface address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2007 15:16:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-question/m-p/742013#M982836</guid>
      <dc:creator>mike.feeney</dc:creator>
      <dc:date>2007-08-08T15:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: ACL question</title>
      <link>https://community.cisco.com/t5/network-security/acl-question/m-p/742014#M982837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What happens if you use the Natted address in your access-list ie x.x.x.207 instead of the 10.132.29.30 address ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2007 15:18:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-question/m-p/742014#M982837</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-08-08T15:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: ACL question</title>
      <link>https://community.cisco.com/t5/network-security/acl-question/m-p/742015#M982838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Or apply the acl in interface inside instead.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2007 15:24:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-question/m-p/742015#M982838</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-08-08T15:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: ACL question</title>
      <link>https://community.cisco.com/t5/network-security/acl-question/m-p/742016#M982839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you both for your help. Changing the acl to use the natted address worked. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Aug 2007 15:28:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acl-question/m-p/742016#M982839</guid>
      <dc:creator>mike.feeney</dc:creator>
      <dc:date>2007-08-08T15:28:28Z</dc:date>
    </item>
  </channel>
</rss>

