01-22-2017 03:02 PM - edited 03-12-2019 01:48 AM
I just purchased a 5506-x for a non-profit organization I am trying to support. I have been able to get the firewall installed and users are able to access the internet ok thru the firewall. Next, I want to enable remote web access via https (port 443) to the server at IP address 192.168.1.3 but am running into problems getting the config correct.
I issued the following commands:
object network remote-web-access-https
host 192.168.1.3
object network remote-web-access-https
nat (TVLCNetwork,SimplyBits) static interface service tcp 443 443
access-list outside_access_in extended permit tcp any object remote-web-access-https eq 443
What am I missing (full config) below?
Result of the command: "show running-config"
: Saved
:
: Serial Number: JAD2033078J
: Hardware: ASA5506, 4096 MB RAM, CPU Atom C2000 series 1250 MHz, 1 CPU (4 cores)
:
ASA Version 9.6(1)
!
hostname TVLCfirewall
domain-name local.tvlc.org
enable password U69ecSZ2fQ8jrQp1 encrypted
names
!
interface GigabitEthernet1/1
nameif SimplyBits
security-level 0
ip address 64.119.46.197 255.255.255.248
!
interface GigabitEthernet1/2
nameif TVLCNetwork
security-level 100
ip address 192.168.1.1 255.255.255.0
!
interface GigabitEthernet1/3
shutdown
no nameif
no security-level
no ip address
!
interface GigabitEthernet1/4
shutdown
no nameif
no security-level
no ip address
!
interface GigabitEthernet1/5
shutdown
no nameif
no security-level
no ip address
!
interface GigabitEthernet1/6
shutdown
no nameif
no security-level
no ip address
!
interface GigabitEthernet1/7
shutdown
no nameif
no security-level
no ip address
!
interface GigabitEthernet1/8
shutdown
no nameif
no security-level
no ip address
!
interface Management1/1
management-only
no nameif
no security-level
no ip address
!
ftp mode passive
clock timezone MST -7
dns server-group DefaultDNS
domain-name local.tvlc.org
object network obj_any
subnet 0.0.0.0 0.0.0.0
object network remote-web-access-https
host 192.168.1.3
access-list outside_access_in extended permit tcp any object remote-web-access-https eq https
pager lines 24
logging asdm informational
mtu SimplyBits 1500
mtu TVLCNetwork 1500
icmp unreachable rate-limit 1 burst-size 1
no asdm history enable
arp timeout 14400
no arp permit-nonconnected
!
object network obj_any
nat (any,SimplyBits) dynamic interface
object network remote-web-access-https
nat (TVLCNetwork,SimplyBits) static interface service tcp https https
!
nat (TVLCNetwork,SimplyBits) after-auto source dynamic any interface
route SimplyBits 0.0.0.0 0.0.0.0 64.119.46.193 1
timeout xlate 3:00:00
timeout pat-xlate 0:00:30
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00
user-identity default-domain LOCAL
http server enable
http 192.168.1.0 255.255.255.0 TVLCNetwork
no snmp-server location
no snmp-server contact
service sw-reset-button
crypto ipsec security-association pmtu-aging infinite
crypto ca trustpoint _SmartCallHome_ServerCA
no validation-usage
crl configure
crypto ca trustpoint ASDM_Launcher_Access_TrustPoint_0
enrollment self
fqdn none
subject-name CN=192.168.1.1,CN=TVLCfirewall
keypair ASDM_LAUNCHER
crl configure
crypto ca trustpoint ASDM_Launcher_Access_TrustPoint_1
enrollment self
fqdn none
subject-name CN=192.168.1.1,CN=TVLCfirewall
keypair ASDM_LAUNCHER
crl configure
crypto ca trustpool policy
crypto ca certificate chain _SmartCallHome_ServerCA
certificate ca 6ecc7aa5a7032009b8cebcf4e952d491
308205ec 308204d4 a0030201 0202106e cc7aa5a7 032009b8 cebcf4e9 52d49130
0d06092a 864886f7 0d010105 05003081 ca310b30 09060355 04061302 55533117
30150603 55040a13 0e566572 69536967 6e2c2049 6e632e31 1f301d06 0355040b
13165665 72695369 676e2054 72757374 204e6574 776f726b 313a3038 06035504
0b133128 63292032 30303620 56657269 5369676e 2c20496e 632e202d 20466f72
20617574 686f7269 7a656420 75736520 6f6e6c79 31453043 06035504 03133c56
65726953 69676e20 436c6173 73203320 5075626c 69632050 72696d61 72792043
65727469 66696361 74696f6e 20417574 686f7269 7479202d 20473530 1e170d31
30303230 38303030 3030305a 170d3230 30323037 32333539 35395a30 81b5310b
30090603 55040613 02555331 17301506 0355040a 130e5665 72695369 676e2c20
496e632e 311f301d 06035504 0b131656 65726953 69676e20 54727573 74204e65
74776f72 6b313b30 39060355 040b1332 5465726d 73206f66 20757365 20617420
68747470 733a2f2f 7777772e 76657269 7369676e 2e636f6d 2f727061 20286329
3130312f 302d0603 55040313 26566572 69536967 6e20436c 61737320 33205365
63757265 20536572 76657220 4341202d 20473330 82012230 0d06092a 864886f7
0d010101 05000382 010f0030 82010a02 82010100 b187841f c20c45f5 bcab2597
a7ada23e 9cbaf6c1 39b88bca c2ac56c6 e5bb658e 444f4dce 6fed094a d4af4e10
9c688b2e 957b899b 13cae234 34c1f35b f3497b62 83488174 d188786c 0253f9bc
7f432657 5833833b 330a17b0 d04e9124 ad867d64 12dc744a 34a11d0a ea961d0b
15fca34b 3bce6388 d0f82d0c 948610ca b69a3dca eb379c00 48358629 5078e845
63cd1941 4ff595ec 7b98d4c4 71b350be 28b38fa0 b9539cf5 ca2c23a9 fd1406e8
18b49ae8 3c6e81fd e4cd3536 b351d369 ec12ba56 6e6f9b57 c58b14e7 0ec79ced
4a546ac9 4dc5bf11 b1ae1c67 81cb4455 33997f24 9b3f5345 7f861af3 3cfa6d7f
81f5b84a d3f58537 1cb5a6d0 09e4187b 384efa0f 02030100 01a38201 df308201
db303406 082b0601 05050701 01042830 26302406 082b0601 05050730 01861868
7474703a 2f2f6f63 73702e76 65726973 69676e2e 636f6d30 12060355 1d130101
ff040830 060101ff 02010030 70060355 1d200469 30673065 060b6086 480186f8
45010717 03305630 2806082b 06010505 07020116 1c687474 70733a2f 2f777777
2e766572 69736967 6e2e636f 6d2f6370 73302a06 082b0601 05050702 02301e1a
1c687474 70733a2f 2f777777 2e766572 69736967 6e2e636f 6d2f7270 61303406
03551d1f 042d302b 3029a027 a0258623 68747470 3a2f2f63 726c2e76 65726973
69676e2e 636f6d2f 70636133 2d67352e 63726c30 0e060355 1d0f0101 ff040403
02010630 6d06082b 06010505 07010c04 61305fa1 5da05b30 59305730 55160969
6d616765 2f676966 3021301f 30070605 2b0e0302 1a04148f e5d31a86 ac8d8e6b
c3cf806a d448182c 7b192e30 25162368 7474703a 2f2f6c6f 676f2e76 65726973
69676e2e 636f6d2f 76736c6f 676f2e67 69663028 0603551d 11042130 1fa41d30
1b311930 17060355 04031310 56657269 5369676e 4d504b49 2d322d36 301d0603
551d0e04 1604140d 445c1653 44c1827e 1d20ab25 f40163d8 be79a530 1f060355
1d230418 30168014 7fd365a7 c2ddecbb f03009f3 4339fa02 af333133 300d0609
2a864886 f70d0101 05050003 82010100 0c8324ef ddc30cd9 589cfe36 b6eb8a80
4bd1a3f7 9df3cc53 ef829ea3 a1e697c1 589d756c e01d1b4c fad1c12d 05c0ea6e
b2227055 d9203340 3307c265 83fa8f43 379bea0e 9a6c70ee f69c803b d937f47a
6decd018 7d494aca 99c71928 a2bed877 24f78526 866d8705 404167d1 273aeddc
481d22cd 0b0b8bbc f4b17bfd b499a8e9 762ae11a 2d876e74 d388dd1e 22c6df16
b62b8214 0a945cf2 50ecafce ff62370d ad65d306 4153ed02 14c8b558 28a1ace0
5becb37f 954afb03 c8ad26db e6667812 4ad99f42 fbe198e6 42839b8f 8f6724e8
6119b5dd cdb50b26 058ec36e c4c875b8 46cfe218 065ea9ae a8819a47 16de0c28
6c2527b9 deb78458 c61f381e a4c4cb66
quit
crypto ca certificate chain ASDM_Launcher_Access_TrustPoint_0
certificate 2e3d8358
308202d6 308201be a0030201 0202042e 3d835830 0d06092a 864886f7 0d010105
0500302d 31153013 06035504 03130c54 564c4366 69726577 616c6c31 14301206
03550403 130b3139 322e3136 382e312e 31301e17 0d313730 31323131 31343933
335a170d 32373031 31393131 34393333 5a302d31 15301306 03550403 130c5456
4c436669 72657761 6c6c3114 30120603 55040313 0b313932 2e313638 2e312e31
30820122 300d0609 2a864886 f70d0101 01050003 82010f00 3082010a 02820101
00cb3dfe a9756877 b0980e45 760679e1 61325d77 d8d4439c 3fb7b1e7 ab715031
d2aa653a 1c3b837a 6098360e 06e34694 154440ce 4cc2258a 36e2f646 09749abc
48f19bba 8b0fa746 05688674 f411a102 049ad9cc 8b9a3cd4 2147609b a409b6d0
25aac99d e8892284 94919b5b fc79782c 21f94a97 2b90345a 0a4e26a3 4f711cee
028df0c8 53301798 3d869f8c ba18bf47 e07ef6e3 6eb34a2d a9549d37 6b099556
9c8213fe 7e2306b8 2e33bb23 982f479c 951d9fab 2230d43e f9285cae e7d82c16
cbce31ce 49cd534d 19a3ee08 20af7f60 00105c52 56aeacc9 3b21484a 67396995
34fb6d3d 73d8b178 b0e3e25e b6acc6cb c252210c 10028669 b276fca2 756d5219
39020301 0001300d 06092a86 4886f70d 01010505 00038201 01006f37 1f6d0146
5d05a821 01b3228a e9f5eaa7 317fba8d 8010b53f 7bc129a8 bd6f6b98 7c4c22ca
29ce396b f16dced4 b2e628d1 30c55491 8785d332 03185817 003fd456 68f275dd
5e756ebf 8181df48 f1bc0d95 054b1300 027bc83a d576b04a 211fc67c ae131663
5d09f820 6830fb2d 1e09cd78 7a962f8d 27688313 2976435d fc1e04de 8a9310a6
7befec63 d31b9d64 4f12a9f2 101fd5ae baaa02c6 666fed60 e47b604c 9324033d
7aac4006 7120130e d56fde27 c86bc173 90fd74ff 58983e5e 27a77c7a cadd1f2b
3b49abed 6700c2b9 86489fac ca3a85b7 8b242d5f e578ff1c acac5c92 99dba1c0
419459f7 4766b66e 45d4cc21 4e83a985 2c15946e 5b9f01e3 fb32
quit
crypto ca certificate chain ASDM_Launcher_Access_TrustPoint_1
certificate 2f3d8358
308202d6 308201be a0030201 0202042f 3d835830 0d06092a 864886f7 0d010105
0500302d 31153013 06035504 03130c54 564c4366 69726577 616c6c31 14301206
03550403 130b3139 322e3136 382e312e 31301e17 0d313730 31323131 31353230
395a170d 32373031 31393131 35323039 5a302d31 15301306 03550403 130c5456
4c436669 72657761 6c6c3114 30120603 55040313 0b313932 2e313638 2e312e31
30820122 300d0609 2a864886 f70d0101 01050003 82010f00 3082010a 02820101
00cb3dfe a9756877 b0980e45 760679e1 61325d77 d8d4439c 3fb7b1e7 ab715031
d2aa653a 1c3b837a 6098360e 06e34694 154440ce 4cc2258a 36e2f646 09749abc
48f19bba 8b0fa746 05688674 f411a102 049ad9cc 8b9a3cd4 2147609b a409b6d0
25aac99d e8892284 94919b5b fc79782c 21f94a97 2b90345a 0a4e26a3 4f711cee
028df0c8 53301798 3d869f8c ba18bf47 e07ef6e3 6eb34a2d a9549d37 6b099556
9c8213fe 7e2306b8 2e33bb23 982f479c 951d9fab 2230d43e f9285cae e7d82c16
cbce31ce 49cd534d 19a3ee08 20af7f60 00105c52 56aeacc9 3b21484a 67396995
34fb6d3d 73d8b178 b0e3e25e b6acc6cb c252210c 10028669 b276fca2 756d5219
39020301 0001300d 06092a86 4886f70d 01010505 00038201 010094ee de64f0ed
056a6250 b28f3fcf 35d8be9e a5317be2 b61a189d 1789a02c f46aac17 5feb85c5
2ce8f4c2 9b212bb0 34561c0f 2e11761b c9ee542f d9eff6ba b5ded023 894d98b9
ccd34a4c 409ca1dc 98c4f795 6196c6d4 050f268e d8640ca2 ac979cbc 790634fb
68b6c340 86428831 33bb7c29 5c6d1dd4 a81cb243 d34d2853 9ecd425a 43628ab7
fc7be61d 814aacf1 20ade1ee be2e3c26 6d8c45fc d5b4ea11 a5b06687 16d826a8
f149a33e dd37672c 7181cb47 3687b7f9 c172c5fe b7fe7dee 031d50ed b5a13924
2dcf82cb a5541d17 d17dca3f 19116e89 449c2344 9a7bf72c b484bcf1 54193bcc
918babd2 fd06ffbd 4b98cb05 0ec59a72 0baa8fcf cffa8def 2071
quit
telnet timeout 5
no ssh stricthostkeycheck
ssh timeout 5
ssh key-exchange group dh-group1-sha1
console timeout 0
dhcpd auto_config SimplyBits
!
dhcpd address 192.168.1.5-192.168.1.254 TVLCNetwork
dhcpd dns 64.119.32.100 64.119.32.101 interface TVLCNetwork
dhcpd enable TVLCNetwork
!
ssl trust-point ASDM_Launcher_Access_TrustPoint_1 TVLCNetwork
ssl trust-point ASDM_Launcher_Access_TrustPoint_1 TVLCNetwork vpnlb-ip
dynamic-access-policy-record DfltAccessPolicy
!
class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
parameters
message-length maximum client auto
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect ip-options
inspect icmp
!
service-policy global_policy global
prompt hostname context
call-home reporting anonymous
Cryptochecksum:c652fb544aba9bf8aa0d6b59402fceba
: end
01-22-2017 03:16 PM
That config is correct. Are you sure the server is listening on port 443? Is the default gateway of the server pointing to the firewall, and can the server access the Internet?
Is the server blocking the access itself, such as via Windows Firewall?
01-23-2017 07:19 AM
Yes, I have verified the server is listening and the server gateway is pointing to the firewall. I can access the web page internally on the 192.186.1.x subnet via the URL: https://192.186.1.3/remote
01-23-2017 05:45 AM
I dont see an access-group applied. Could you please add it and see if it works.
HTH
-
AJ
01-23-2017 07:17 AM
Can you help with the format of the access-group command which should be applied?
01-23-2017 07:23 AM
access-group outside_access_in in interface SimplyBits
Please try and let me know if it works.
-
AJ
01-23-2017 05:40 PM
Thank you, that did it.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide