Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

A new question about ASA5510

Hi again! I've got an ASA5510 firewall and I want to allow only http requests from the inside network. I have tried the following access-lists without success:

access-list 200 extended permit tcp any any eq http

access-group 200 in interface inside

and

access-list 200 extended deny any any neq http

access-group 200 in interface inside

any suggestions?

3 REPLIES
New Member

Re: A new question about ASA5510

Hi,

by without success what do you mean exactly? did inside network access http and everything or inside network couldn't access any thing at all???

Tha access list is right. you may check your NAT, Global configuration.

B.Regards,

Mohammed Moustafa.

New Member

Re: A new question about ASA5510

the inside network can access everything, including http. Still a NAT failure?

New Member

Re: A new question about ASA5510

Sorry, I mistook posting the second access-list, here is the right one:

access-list 200 extended deny tcp any any neq http

access-group 200 in interface inside

90
Views
0
Helpful
3
Replies
CreatePlease login to create content