A new question about ASA5510

Unanswered Question
Sep 2nd, 2008
User Badges:

Hi again! I've got an ASA5510 firewall and I want to allow only http requests from the inside network. I have tried the following access-lists without success:


access-list 200 extended permit tcp any any eq http

access-group 200 in interface inside


and


access-list 200 extended deny any any neq http

access-group 200 in interface inside


any suggestions?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
mohammed_moustafa Tue, 09/02/2008 - 00:43
User Badges:

Hi,


by without success what do you mean exactly? did inside network access http and everything or inside network couldn't access any thing at all???


Tha access list is right. you may check your NAT, Global configuration.


B.Regards,

Mohammed Moustafa.

miregistrocisco Tue, 09/02/2008 - 01:13
User Badges:

the inside network can access everything, including http. Still a NAT failure?

miregistrocisco Tue, 09/02/2008 - 01:34
User Badges:

Sorry, I mistook posting the second access-list, here is the right one:


access-list 200 extended deny tcp any any neq http

access-group 200 in interface inside

Actions

This Discussion