cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
335
Views
0
Helpful
3
Replies

A new question about ASA5510

miregistrocisco
Level 1
Level 1

Hi again! I've got an ASA5510 firewall and I want to allow only http requests from the inside network. I have tried the following access-lists without success:

access-list 200 extended permit tcp any any eq http

access-group 200 in interface inside

and

access-list 200 extended deny any any neq http

access-group 200 in interface inside

any suggestions?

3 Replies 3

Hi,

by without success what do you mean exactly? did inside network access http and everything or inside network couldn't access any thing at all???

Tha access list is right. you may check your NAT, Global configuration.

B.Regards,

Mohammed Moustafa.

the inside network can access everything, including http. Still a NAT failure?

Sorry, I mistook posting the second access-list, here is the right one:

access-list 200 extended deny tcp any any neq http

access-group 200 in interface inside

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card