Brent,
Since I was accessing the ASA from remote ( had someone on sight allow a single specific IP on the outside for management) I accessed with ASDM web (java) interface. I used the embedded CLI tool and made my ACLs that way. Once i would exit out of the CLI the ASDM would do it's refresh...
David - Thanks for the heads Up, I'll have to knock it out by then, I guess if I don't it wouldn't hurt to learn all those new things, since wireless and IPv6 is where networking will end up eventually. I guess the down side is I'll have to re invest in the $40 a pop text books. Gotta spend...
David,
Thanks for your input and I don't think you were too harsh, I realize now that VPN/Pix was probobly a little deep to start. Randomly I found out today that the test center I was signed up for to test on Aug 2nd ended their relationship with Cisco as of 1 Aug. So I guess I have some time...
Also in searching around I learned about conduit commands. These are for earlier versions of the pix firmware right? not what I'm looking for here i think, but I wanted to ask.
-John
Brian/ Brent:
I took that static (that pointed to itself) out of there after posting the other day, that was one of those hey let's try this and see if it helps. It obviously didn't. I tried removing it and that didn't help either I'm still getting the ACL denied message in syslog.
Brent...
Brent,
OK those posted changes made complete sense. I tried them and I'm still getting ACL denied in the logging:
71003: TCP access denied by ACL from 123.456.123.456/3677 to outside 70.20.123.456/80
I'll post the running config agian, Thanks a ton for you help, I can't seem to understand...
Ok, That helped, in fact now dns translation is working. It's nice to see some favorable entries in the syslog.
alright, now i'm having problems forwarding www traffic to the www server. I'll post the config, but the problem according to syslogs is: tcp access denied by acl from...
I took out the static and that didn't seem to help. I noticed I already had a global (outside) 1 interface. I'm fairly certian that's what you were talking about adding correct? or am I still missign something fundemental?
Thanks for the help so far.
John
Latest running config...
I'm trying to setup an ASA 5510 on our exisiting network as the first step to establish an EasyVPN, NEM site to site type setup. This is kind of a lab exercise, I have my CCNA test coming up and I want to try to learn by doing so any help would be great (you may think this is beyond my level...
I'm trying to setup an ASA 5510 on our exisiting network as the first step to establish an EasyVPN, NEM site to site type setup. This is kind of a lab exercise, I have my CCNA test coming up and I want to try to learn by doing so any help would be great (you may think this is beyond my level...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.