05-08-2015 07:05 AM - last edited on 03-25-2019 05:55 PM by ciscomoderator
in ASA access rule
Rule 1 deny any source address to destination 192.168.1.254
Rule 2 permit any source address to destination 192.168.1.0/24
why it can still surf internet when it deny from outside to gateway ?
why there is rule 2? doesn't all traffic meet rule 1 ?
i am confused about this setting when troubleshooting apple tv can not watch or Buy with UDP
05-08-2015 08:08 AM
Hi,
This set of 2 rules simply allows access to all ip addresses in 192.168.1.0/24 subnet except 192.168.1.254.
"why it can still surf internet when it deny from outside to gateway ?"
for this you have paste ur config here. normally surfing internet should mean "to outside" not from outside.
"why there is rule 2? doesn't all traffic meet rule 1 ?"
check first line.
It'll be helpful you could elaborate your scenario.
Thanks,
Rohit
05-08-2015 06:39 PM
After search,router do not edit source ip address and port
then this make me understand why it can go to rule 2
but i am confused which outside port it use to come back
does it mean that the gateway only use inside port, not include outside port?
if so, this make sense
does it mean that the udp traffic can come back from another different outside port ,not from the original outside port which initial apple tv?
does it mean to use another different inside port to send udp traffic?
so that the path go out and go in are actually two different path?
so conclusion is that asa is not the device to block the traffic of apple tv?
what security reason to make it to deny any ip address ip protocol traffic to 192.168.1.254 ?
05-09-2015 10:02 AM
Hi,
Its very diffilcult to understand your problem here.
Is ASA the default gateway for your internal network?
Or there is a router connected to outside interface of ASA?
Can you define your network diagram here?
Also, it would be helpful if you paste ASA config here.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: