Should we always need a static st. combined with ACL when connection is initiated from inside network.
For example if am initiating a http connection from inside network then for the response http traffic should i need a static+ACL st.
For a connection that is initiated from the inside to outside, you do not need to permit the response. PIX being a stateful firewall will keep a track of the connection information and will allow the return packets after it checks the state table and sees that the response is coming because the request was done from inside.
---Pls rate if useful---
In this case you need open ACL for this traffic...
The rule mentioned above is for default firewall settings (without restrictive ACL)
In you case ACL blocks traffic se you need open ACL for outbound http request
Hope that helps rate if it does