12-08-2023 05:29 AM
Web server connected to outside router, outside router connected to ASA5506, ASA5506 connected to inside router and inside router connected to PC.
Is it normal when I send message from outside router to inside router failed, but inside router to outside router successfully and able to browse the web in PC. if not, what the solution to solve it?
12-08-2023 05:36 AM
It secuirty level issue
If ASA secuirty of interface connect to Web is less than connect to NAT then you need access list to allow traffic
If the ASA secuirty is same then you need
Same secuirty traffic permit intra/inter interface
If it low then traffic allow by defualt except if there is ACL apply to Web interface deny traffic.
For NAT I need to see topolgy and NAT you use
12-08-2023 05:38 AM
yes that situation ok
Most cases
ISP--Router--FW--Switch--PC (may be your case instead of switch it was router)
yes the traffic leaving from Inside to ourside NATtted and working as expected.
From outside to inside default rule deny, until any specifically allowed in the ASA FW.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide