cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
162
Views
0
Helpful
5
Replies
ravi mishra
Beginner

unable to access website (natting, route,accesslist??)

We are unable to access a website from our network A.It can be accessed from other networks globally. while pinging it (the websites ip) from router i can ping it but from ASA or switches or end devices, i am not able to ping it.

This website is a part of another system who is in another network B configured with other ISP.

while doing traceroute from my device it is reaching my isp then other isp and to the i/f of the other network B router and getting lost.

There in other network B, it has been natted with a local ip and no access lists are defined for the interface.

5 REPLIES 5
mvsheik123
Rising star

Hi Ravi,

Traceroute (udp) and ping (icmp) uses different type of packets. If your ASA filtering echo-reply, you will not be able to ping the website ip. Unable to access website from inside only (accessible globally)   a).Filtering on other side  b) May be your DNS somehow resolving website ip to different IP? 

Thx

MS

When i checked the log on the router B by sh ip nat translation, i am getting hits from the network A natted global ip and there is no filtering added in the router B. access list permits any ip to that website global ip in the external interface.

While doing traceroute from end device of network A i am able to reach the router of network B and getting lost.

I can ping the website ip from my router but not from internal devices. suppose for Network B, router global i/f is 100.29.226.163 then for the website its .162 and this i/f access list permits any ip to .162 and .163

> On the Target check the application logs or install wireshark and see if your requests are reaching the server and server responding.

> If server replying back, check the next hop (router??) if they are reaching that router and hten move on to next hop.

You need to look into this step by step.

Thx

MS

solved.Added a nat rule in Checkpoint utm internally and it worked!!!

Georg Pauwen
VIP Master

Hello,

this is just one specific website ? Usually the problem is MTU size. Which website is it (URL) ?