Authenticate to a website from behind ASA

Unanswered Question

Hi,


I ran into a weird problem today. I am setting up ASA for a retail company. all the sales locations has ASA5505 version 7.2. A q-see webcam system is installed in each location. a manager at any location can monitor any remote one. the camera system is web based and uses the default port 80, connected directly to the Internet and is assigned a real IP address. Once a manager type in a camera address in his IE, he is prompt to enter his user name and password. Usually this is a straigh forward operation until I installed the ASA. Now, nothing


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
kicharle Wed, 09/30/2009 - 01:46
User Badges:

I hope, you would have connected the web camera to the inside interface and the outside interface to the outside world.


If that is so, have you configured an ACL to allow port 80 inbound to the outside interface.


Also, you have mentioned that is using real IP address.


You need to configure a static rule that translates to the same real IP address.


Hi Kicharle,

The cameras are connected directly to the internet and assigned a real IP adderss. I have no control over the way they are setup. managers used to authenticate correclty before I installed the ASA, now, when they try to connect, they still get the prompt for a user name and password but nothing happens after. I guess the ASA is blocking the reply from the camreas. here is the log



6 Sep 26 2009 20:10:07 302014 CameraLA4 TSinside Teardown TCP connection 4850 for outside:CameraLA4/80 to inside:TSinside/1476 duration 0:00:00 bytes 1850 TCP FINs



6 Sep 26 2009 20:10:07 302013 CameraLA4 TSinside Built outbound TCP connection 4851 for outside:CameraLA4/80 (CameraLA4/80) to inside:TSinside/1477 (76.x.x.1/4175)



6 Sep 26 2009 20:10:07 302013 CameraLA4 TSinside Built outbound TCP connection 4851 for outside:CameraLA4/80 (CameraLA4/80) to inside:TSinside/1477 (76.x.x.1/4175)



6 Sep 26 2009 20:10:07 305011 TSinside 76.x.x.1 Built dynamic TCP translation from inside:TSinside/1477 to outside:76.x.x.1/4175



Any ideas?


Actions

This Discussion