Resolution of conflicts between the external Web application port of ASA Firewall and the default audit protocol

Source: Internet
Author: User
Tags firewall

I. Overview:

Today QQ received a friend's help, the following environment, looked at the ASA configuration, the strategy is full pass, incredibly unable to access, but also puzzled.

If the use of GNS3 to build environmental testing, on both sides of the firewall grab packet, found that TCP three times handshake normal, but located inside the firewall issued by the HTTP GET packet is the firewall discarded, with Google input keyword: ASA TCP 2000 Search to the following links:

http://blog.csdn.net/yangcage/article/details/1787558

Http://www.petenetlive.com/KB/Article/0000027.htm

Finally understand: is because ASA to access the external HTTP TCP 2000 port traffic as the skinny protocol traffic, but the actual HTTP traffic, because the data structure of the two protocol traffic is certainly different, all when the TCP three handshake completes, after the HTTP application of the packet is discarded. For further testing, the test is divided into three different situations:

The first is that the ports of the external Web application are not listed by default, such as TCP 8080;

The second is the port of the external Web application is under review, but the actual application does not have such traffic, such as TCP 2000;

The third is the port of the external Web application is reviewed, and the default review protocol needs to be opened.

Two. Test topology:

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.