We help IT Professionals succeed at work.

We've partnered with Certified Experts, Carl Webster and Richard Faulkner, to bring you a podcast all about Citrix Workspace, moving to the cloud, and analytics & intelligence. Episode 2 coming soon!Listen Now

x

Restore implicit rule to permit to any less secure network

Medium Priority
4,694 Views
Last Modified: 2012-05-06
I have been setting up an ASA 5505 using mostely the ASDM (dont know much about command line). I did load a config from a previous setup that worked well and everything was great except I can not web browse.  I looked at the two configs and can not see any major differences. When I look in the security section of the ASDM I do see that the one that works has an implicit rule to permit access to any less secure network.  This is missing from the one I loaded the config to.  I dont see any way to add this rule in the ASDM and can not even find it looking at the configs from a sh run.  I am open to either path to add this back.  I like the ASDM but I know the more command line time I get the better.
Comment
Watch Question

Top Expert 2009

Commented:
Can you post a "show run"?
Commented:
The implicit rule to permit access to any less secure network is should be active by default. This is because inside interface has higher security level and lower on the outside interface.

If you'd like to allow browsing through the clients on the inside interface, make sure you have nat and acl, will be something like:

nat (inside) 1 0.0.0.0 0.0.0.0
nat (inside) 1 0.0.0.0 0.0.0.0 (allow inside clients to use outside interface when go out to internet)

also acl on outside interface
access-list outside_access_in extended permit ip any outside/24



Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.