cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
642
Views
0
Helpful
2
Replies

VPN Web Access with ACL Firewall

Anthony W.
Level 1
Level 1

All,

I have a basic EZ VPN and my outside interface has a standard ACL firewall.  I can VPN into the system just fine and have access to all internal items but I have no internet access.  The router log shows:

003253: Aug 22 15:22:26.456 MDT: %SEC-6-IPACCESSLOGP: list FW_OUT denied tcp 74.125.225.199(80) -> 67.X.X.X (59480), 1 packet

But have an IP NAT transaiton for this request:

tcp 67.X.X.X.X:59480 172.25.0.68:59480  74.125.225.199:80  74.125.225.199:80

The ip address is in the NAT range.  Am I missing an IP inspect command? I am inspecting TCP and UDP.   Any ideas?

1 Accepted Solution

Accepted Solutions

Jeff Van Houten
Level 5
Level 5

Which direction is the inspect statement on the interface defined? It should be defined as out.

Sent from Cisco Technical Support iPad App

View solution in original post

2 Replies 2

Jeff Van Houten
Level 5
Level 5

Which direction is the inspect statement on the interface defined? It should be defined as out.

Sent from Cisco Technical Support iPad App

The incorrect way.  Thanks for helping me out!