cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1718
Views
0
Helpful
2
Replies

ACL not working in ASA 8.4

rehan_uet
Level 1
Level 1

An ACL has been applied on the inside interface to of the ASA 8.4 but it is not working. The aim of this list to allow only a few host for outside access and deny rest of the hosts for outside access. The syntex of the access list is

access-list ACL-Inside extended permit ip host 192.168.100.101 any

access-list ACL-Inside extended permit ip host 192.168.100.108 any

access-list ACL-Inside extended permit ip host 192.168.100.109 any

access-list ACL-Inside extended permit ip host 192.168.100.243 any

access-list ACL-Inside extended permit ip host 192.168.100.241 any

access-group ACL-Inside in interface inside

2 Replies 2

Maykol Rojas
Cisco Employee
Cisco Employee

Hello,

Can you run a packet tracer?

packet-tracer inpunt inside tcp 192.168.100.241 1025 4.2.2.2 80

Send us the output.

Mike

Mike

siddhartham
Level 4
Level 4

Did you configure the NAT statement for the inside hosts to be mapped to a public IP? The below config will NAT 192.168.100.0 -100.254 to outside interface and the access-list you defined only allow those hosts to go out.

object network Inside_Net

subnet 192.168.100.0 255.255.255.0

nat  (inside, outside)  dynamic interface

If you alread did the above config please send us the packet capture as Mike requested.

Siddhartha
Review Cisco Networking for a $25 gift card