troubleshooting Question

High range ports and ASA inspection ?

Avatar of orus
orus asked on
CiscoRoutersHardware Firewalls
7 Comments2 Solutions548 ViewsLast Modified:
We have an ASA5505 with inside, dmz and outside interface. I cannot get outside connections to come in.

We normally allow outside traffic into the dmz like this: (ip addresses have been changed)

access-list outside-in extended permit tcp any host 77.1.1.80 eq 80
access-list outside-in extended permit tcp any host 77.1.1.80 range 60000 64999
static (dmz,outside) 77.1.1.80  10.10.10.12 netmask 255.255.255.255

All DMZ hosts have full access to anything (except internal network)

The issue we are having is, no traffic is hitting 10.10.10.12 from the outside. I even did a permit ip any host 77.1.1.80 and still nothing.  If we access 77.1.1.80  from 77.1.1.50,(one of our own public IPs) it works. But no other outside users can access it
ASKER CERTIFIED SOLUTION
Pete Long
Solutions Architect
Join our community to see this answer!
Unlock 2 Answers and 7 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 2 Answers and 7 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros