cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1499
Views
20
Helpful
20
Replies

Issue with ASA 5510

John Huthmaker
Level 4
Level 4

Hello Everyone,

I want to first say that this is my first time ever working on an ASA, so I appologize for the elementary questions.  My task today is allow incoming HTTP, and HTTPS traffic to my internal IP Address.

Currently this firewall is up, and working great.  There are several internal servers, and every service they are presenting to the internet are working fine.  Im using the graphic interface.  I added my server under the "Public Servers" like all of the other objects.  I can see it created the appropriate NAT statement, and access rule.  I applied my change, and saved the settings to flash.

The problem I'm having is the internal server is now essentially cut off from the internet.  I obviously cant access HTTP or HTTPS from the internet, but that server cant get from the lan to the internet either.  Every other server is working fine though.  I checked the order of how the nat rule and access rule are being applied, and I think they're fine.

The only thing I can think of is I need to restart the ASA, but that really surprises me.  I would think that adding a statement in an ASA would just work without a reboot.

Any thoughts?  I can provide screen shots of my Access Rules, NAT rules, and Public Servers list if it helps.

Thank you in advance.  I need to get this fixed asap.

20 Replies 20

Weird, so everything appears to be fine then?

Alright, I'll contact my isp.  Do I need to turn off that catpure?

Hello John.

If you want, yes.

no capture capin

no capture capout

That should do it!

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Thanks very much for your help

Hello John,

My pleasure, let me know if you have any problem with the ISP.

Regards,

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

You've been very very helpful.  Rather than reinventing the wheel, I chose a different IP address I had available.  Everything is working perfect.

Hello John,

Sure, It was a pleasure to work on this with you.

Please mark the question as answered so future users can learn from this.

Regards,

Julio!!

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Review Cisco Networking for a $25 gift card