<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5512 outside can not access ACS server through HTTPS in DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3314199#M997244</link>
    <description>1025 is just random source port you can take any port above 1024</description>
    <pubDate>Fri, 19 Jan 2018 02:46:50 GMT</pubDate>
    <dc:creator>Pawan Raut</dc:creator>
    <dc:date>2018-01-19T02:46:50Z</dc:date>
    <item>
      <title>ASA 5512 outside can not access ACS server through HTTPS in DMZ</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3313459#M997143</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;Hello,there may be some problems with the ASA's config, but I can find where are the problems.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Below is the basic config for this ASA:&lt;/P&gt;
&lt;P&gt;DMZ&amp;nbsp;ip address :　192.168.3.254/24&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Outside ip address: &amp;nbsp;125.35.20.188/26&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;acs server ip address:&amp;nbsp; 192.168.3.240/24 &amp;nbsp;acs server version 5.2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; DMZ &amp;nbsp; access ACS server through HTTPS https:// 192.168.3.240/acsadmin&amp;nbsp; successfully&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Outside &amp;nbsp;access ACS server through HTTPS https:// 192.168.3.240/acsadmin&amp;nbsp;&amp;nbsp;failed&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;https:// 125.35.20.145/acsadmin &amp;nbsp;failed&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;where are the problems.thanks!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please get the detailed config in the attached file&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:09:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3313459#M997143</guid>
      <dc:creator>supermanwwc</dc:creator>
      <dc:date>2020-02-21T15:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5512 outside can not access ACS server through HTTPS in DMZ</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3313554#M997144</link>
      <description>&lt;P&gt;Can you enable traffic from the lower security level to high security level and try it again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 10:43:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3313554#M997144</guid>
      <dc:creator>denilson.mota</dc:creator>
      <dc:date>2018-01-18T10:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5512 outside can not access ACS server through HTTPS in DMZ</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3313590#M997145</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The config looks okay, can you please take syslogs on ASA and attach here.&lt;/P&gt;
&lt;P&gt;Also, could be an issue over internet routing for the NAT ip address 125.35.20.145.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can take a capture:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;capture capo interface outside match tcp any host 125.35.20.145&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;then initiate traffic from outside and take output of 'show cap capo'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please take syslogs and attach these outputs. Same Security commands is not required since the security level is different for these interfaces.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 11:29:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3313590#M997145</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-01-18T11:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5512 outside can not access ACS server through HTTPS in DMZ</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3313922#M997146</link>
      <description>&lt;P&gt;Can you check you have proper ACL and NAT rule on ASA. Could you do packet-tracer on ASA&lt;/P&gt;
&lt;P&gt;packet-tracer input outside&amp;nbsp; tcp &amp;lt;sourec ip&amp;gt; 1025 &amp;lt;ACS IP address&amp;gt; 443 de&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 18:35:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3313922#M997146</guid>
      <dc:creator>Pawan Raut</dc:creator>
      <dc:date>2018-01-18T18:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5512 outside can not access ACS server through HTTPS in DMZ</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3314179#M997147</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank you very much for your advice。&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I didn't change any configuration，I tried again today，only this command to collect logs （capture capo interface outside match tcp any host 125.35.20.145&amp;nbsp;）。&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://125.35.20.145/acsadmin/login.jsp&amp;nbsp;&amp;nbsp;successfully" target="_blank"&gt;https://125.35.20.145/acsadmin/login.jsp&amp;nbsp;&amp;nbsp;successfully&lt;/A&gt; from Outside.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Please see the attached document，THAK YOUR VERY MUCH AGAIN.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 02:02:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3314179#M997147</guid>
      <dc:creator>supermanwwc</dc:creator>
      <dc:date>2018-01-19T02:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5512 outside can not access ACS server through HTTPS in DMZ</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3314181#M997241</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank you very much for your help.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;but&amp;nbsp;security level is different。&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 02:05:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3314181#M997241</guid>
      <dc:creator>supermanwwc</dc:creator>
      <dc:date>2018-01-19T02:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5512 outside can not access ACS server through HTTPS in DMZ</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3314183#M997242</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank you very much for your help.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;packet-tracer input outside&amp;nbsp; tcp &amp;lt;sourec ip&amp;gt; 1025 &amp;lt;ACS IP address&amp;gt; 443 ，Why is the 1025 port？&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 02:13:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3314183#M997242</guid>
      <dc:creator>supermanwwc</dc:creator>
      <dc:date>2018-01-19T02:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5512 outside can not access ACS server through HTTPS in DMZ</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3314199#M997244</link>
      <description>1025 is just random source port you can take any port above 1024</description>
      <pubDate>Fri, 19 Jan 2018 02:46:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3314199#M997244</guid>
      <dc:creator>Pawan Raut</dc:creator>
      <dc:date>2018-01-19T02:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5512 outside can not access ACS server through HTTPS in DMZ</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3315223#M997246</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From what I can tell, this is purely client-server issue and not a firewall issue. I checked the captures you attached, and:&lt;/P&gt;
&lt;P&gt;-There is clearly a 3-way handshake done successfully&lt;/P&gt;
&lt;P&gt;-There is a reset then sent from&amp;nbsp;218.247.232.86 at a certain time, could be the application specific traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Couple of more things to figure out the issue:&lt;/P&gt;
&lt;P&gt;1. Is the same traffic working from behind the firewall&lt;/P&gt;
&lt;P&gt;2. Is there a WAF (Web Application Firewall) or any other appliance that could be causing this issue&lt;/P&gt;
&lt;P&gt;3. There could be an IPS issue as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-HTH&lt;/P&gt;
&lt;P&gt;AJ&lt;/P&gt;</description>
      <pubDate>Sun, 21 Jan 2018 04:53:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3315223#M997246</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2018-01-21T04:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5512 outside can not access ACS server through HTTPS in DMZ</title>
      <link>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3315581#M997248</link>
      <description>&lt;UL&gt;
&lt;LI&gt;
&lt;H1 class="keyword"&gt;Thank your for your suggestion. It is very useful for us.&lt;/H1&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 22 Jan 2018 02:25:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5512-outside-can-not-access-acs-server-through-https-in-dmz/m-p/3315581#M997248</guid>
      <dc:creator>supermanwwc</dc:creator>
      <dc:date>2018-01-22T02:25:56Z</dc:date>
    </item>
  </channel>
</rss>

