Solved

Can't Get to a Website

Posted on 2011-09-07
13
420 Views
Last Modified: 2012-06-27
Cisco ASA.  The website we want to get to (www.fixme.com) resolves to 77.77.77.116
The ASA has an IP of 88.88.88.141
An internal PC has the IP of 192.168.12.57

I find these lines in the ASA:

access-list capin extended permit ip host 192.168.12.57 host 77.77.77.116
access-list capin extended permit ip host 77.77.77.116 host 192.168.12.57
access-list capout extended permit ip host 88.88.88.141 host 77.77.77.116
access-list capout extended permit ip host 77.77.77.116 host 88.88.88.141

Even if I remove all these lines, a ping of www.fixme.com resolves properly (77.77.77.116) but the pings are not answered.

Any ideas?
0
Comment
Question by:dougp23
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
  • 3
  • +1
13 Comments
 
LVL 10

Expert Comment

by:CSIPComputing
ID: 36495411
Funny, that's not the ip address I get for www.fixme.com, and you're correct, you can't get a ping response from 77.77.77.116:

ping 77.77.77.116

Pinging 77.77.77.116 with 32 bytes of data:
Reply from 77.77.64.106: Destination host unreachable.
Reply from 77.77.64.106: Destination host unreachable.

ping www.fixme.com

Pinging fixme.com [209.81.96.132] with 32 bytes of data:
Reply from 209.81.96.132: bytes=32 time=140ms TTL=117
Reply from 209.81.96.132: bytes=32 time=139ms TTL=117
Reply from 209.81.96.132: bytes=32 time=139ms TTL=117
Reply from 209.81.96.132: bytes=32 time=138ms TTL=117

Was Fixme.com an example, or is your DNS screwed?
0
 
LVL 1

Author Comment

by:dougp23
ID: 36495461
I should have clarified!  fixme.com is an example.
The website resolves properly and answers pings outside the firewall (i.e. from public hotspots, home, library, etc.) so it has to be something with my ASA...
0
 
LVL 10

Expert Comment

by:CSIPComputing
ID: 36495479
Sorry, 77.77.77.116 isn't reachable from my connection....  See my original post.

Is 77.77.77.116 also an example?
0
Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 1

Author Comment

by:dougp23
ID: 36495569
Yes, the IPs and all are examples.  I try to avoid posting real IPs as malware and spam harvesters love to find them and then do bad things to them!
0
 
LVL 10

Expert Comment

by:CSIPComputing
ID: 36495644
OK, apologies.  Thought we may have a simple problem of incorrect DNS etc.  That's not the case.  As I don't do ASA, I'll stand down, and apologise for jumping in.
0
 
LVL 6

Expert Comment

by:JRoyse
ID: 36495913
add
access-list capout extended permit ip host 192.168.12.57 host 77.77.77.116
0
 
LVL 3

Expert Comment

by:Mystique_87
ID: 36497042
I am guessing that the access-list on the external interface is capout. Add the following entry:

access-list capout ext permit ip host 77.77.77.116 host <external_ip_of_PC>
0
 
LVL 1

Author Comment

by:dougp23
ID: 36497762
JRoyse, I tried your suggestion and still no go.

Mystique, the external IP is 77.77.77.116, so I think you may have meant for the same exact setup as JRoyse.

Here's what's weird...there is no need for those 4 lines in the ASA config.  This domain should be resolved and loaded the same as any other.  Yet it won't load inside the building. Once you get on a network outside the building, it comes right up.  
Is there any kind of testing I can do from the ASA?  Even a ping of the IP from within the ASA fails....
0
 
LVL 3

Accepted Solution

by:
Mystique_87 earned 500 total points
ID: 36501445
Try the packet-tracer from the ASA:
packet-tracer in <input_interface> tcp <source_ip> 4444 <website_ip> 80

Do paste the output of this command. Also you could try applying captures on the input interface and the output interface to check if the ASA is infact sending the request out of the ASA. If so, is the website's response coming back.
Here is how you can apply captures:
http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a0080a9edd6.shtml
0
 
LVL 3

Expert Comment

by:Mystique_87
ID: 36501455
Put in the private Ip of the source in the packet tracer command
0
 
LVL 1

Author Comment

by:dougp23
ID: 36503304
Mystique, it all looks good (I think).  Before I paste in the output, see if this causes you to think of something else:

If I run a traceroute from off the network, I get all the way there.  The second to last hop is liquidweb, the very last hop is host.ez2ba.com.  If I run the traceroute internally, I get to liquidweb, then it just starts timing out, it never does that final hop to host.ez2ba.com.
Maybe the ASA views this as some sort of redirect and doesn't like it?  Maybe the webhost at host.ez2ba.com for some reason is denying my IP?

Anyway, here's the output:  (I changed one or 2 IPs to protect things):

Phase: 1
Type: ACCESS-LIST
Subtype:
Result: ALLOW
Config:
Implicit Rule
Additional Information:
MAC Access list

Phase: 2
Type: FLOW-LOOKUP
Subtype:
Result: ALLOW
Config:
Additional Information:
Found no matching flow, creating a new flow

Phase: 3
Type: ROUTE-LOOKUP
Subtype: input
Result: ALLOW
Config:
Additional Information:
in   0.0.0.0         0.0.0.0         outside
             
Phase: 4
Type: IP-OPTIONS
Subtype:
Result: ALLOW
Config:
Additional Information:

Phase: 5
Type: NAT
Subtype:
Result: ALLOW
Config:
nat (inside) 1 0.0.0.0 0.0.0.0
  match ip inside any outside any
    dynamic translation to pool 1 (74.74.186.151 [Interface PAT])
    translate_hits = 344516, untranslate_hits = 9350
Additional Information:
Dynamic translate 192.168.12.74/4444 to 74.74.186.151/60234 using netmask 255.255.255.255

Phase: 6
Type: NAT
Subtype: host-limits
Result: ALLOW
Config:
nat (inside) 1 0.0.0.0 0.0.0.0
  match ip inside any inside any
    dynamic translation to pool 1 (No matching global)
    translate_hits = 0, untranslate_hits = 0
Additional Information:

Phase: 7
Type: IP-OPTIONS
Subtype:
Result: ALLOW
Config:
Additional Information:

Phase: 8
Type: FLOW-CREATION
Subtype:
Result: ALLOW
Config:
Additional Information:
New flow created with id 347622, packet dispatched to next module

Result:
input-interface: inside
input-status: up
input-line-status: up
output-interface: outside
output-status: up
output-line-status: up
Action: allow

0
 
LVL 3

Expert Comment

by:Mystique_87
ID: 36506287
Its all looking good here. I am not sure about the traceroute. What about the captures? Did you get to try that?
0
 
LVL 1

Author Closing Comment

by:dougp23
ID: 36524843
The capture was able to show me that the webhoster was blocking my public NAT address.  Once I inquired as to why, and got them to unblock it, life is good.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Botnet detection help me please 21 156
Palo Alto Networks: Truly No Hit Count? 2 139
Resource timeout across a VPN 9 63
SSL-VPN 1 88
We sought a budget ($5,000) firewall solution that would provide all the performance we needed with no single point of failure.  Hosting a SAAS web application in our datacenter, it was critical that we find a way to keep connectivity up and inbound…
I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
A short tutorial showing how to set up an email signature in Outlook on the Web (previously known as OWA). For free email signatures designs, visit https://www.mail-signatures.com/articles/signature-templates/?sts=6651 If you want to manage em…
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question