WEB ACLs is not working properly after upgrading ASA from 8.0.4 to 8.2.3

Unanswered Question
Aug 13th, 2010
User Badges:

Hi all, i'm just upragde my ASA 5510 from 8.0.4 to 8.2.3 and find out that can't access

bookmarked resources trough clientless webvpn. When i click on link it's show me window that access is denied, and i see denied string in syslog that access to resource was denied http://10.16.9.17....


but i have WEB ACL

access-list DVI webtype permit url http://10.16.9.17/* log default


which is permit access to http://10.16.9.17/* and it's working well before


now i'm add to web acl string

access-list DVI webtype permit tcp host 10.16.9.17 log disable


and only after that access was restored, why?


thank you.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Jennifer Halim Sat, 08/14/2010 - 20:01
User Badges:
  • Cisco Employee,

It should work just fine. I would suggest that you configure a new webtype ACL with a new name with the URL that you have configured earlier and assign this new webtype ACL to the VPN group. Let us know if that works. If it still doesn't, then you might want to open a TAC case to get it investigated further.

Actions

This Discussion