Core issue
One of the reasons that this problem can occur is due to the incorrect order of access-lists. The PIX/ASA applies the access rules, which depends on the order.
Resolution
In order to allow traffic to pass through the PIX/ASA, you can create access-lists and apply them to a specific interface with the help of the access-groups command.
- Access-lists are executed in a top-to-down fashion.
- Access-lists can be given preference with the help of access-list line number.
- The correct order of access-lists applied on an interface is also essential as the traffic can be interrupted due to incorrect sequence.
- You can put all the permit statements first and then set the access-lists to deny undesired traffic.