Cisco CCNP Security Core (SCOR) 350-701Visibility and EnforcementMedium

A network administrator is troubleshooting an issue where users are unable to access internal web applications hosted on a server behind a Cisco ASA firewall. The ASA is configured with NAT and access rules. Upon reviewing the firewall logs, the administrator observes denied connections with the reason 'Deny inbound UDP from 1.1.1.1/32 to 10.0.0.10/32 on interface outside'. Which of the following is the most likely cause of this issue?

  1. AThe web server is not listening on the correct port.
  2. BAn access control list (ACL) on the outside interface is blocking UDP traffic.
  3. CThe NAT configuration is incorrect for the web server.
  4. DThe web application requires TCP, but the firewall is observing UDP.
Show answer & explanation

Correct answer: D. The web application requires TCP, but the firewall is observing UDP.

The log message explicitly states 'Deny inbound UDP' while the problem describes 'internal web applications'. Web applications typically use TCP (HTTP/HTTPS). The firewall is observing UDP traffic, which is likely not what the web application expects, indicating a mismatch in the expected protocol.

Why the other options are wrong

  • A. If the server wasn't listening, the firewall would likely still permit the traffic but the connection would fail at the server, not be denied by the firewall for the wrong protocol.
  • B. While an ACL could block UDP, the core issue is that web applications use TCP, so UDP traffic is unexpected and implies a misconfiguration elsewhere, or a client attempting the wrong protocol.
  • C. Incorrect NAT would typically result in a 'no route' or 'translation failed' type of error, not a protocol mismatch 'Deny inbound UDP'.

Web Application Protocols

Web applications primarily use the Hypertext Transfer Protocol (HTTP) and Hypertext Transfer Protocol Secure (HTTPS), both of which are built on top of the Transmission Control Protocol (TCP) for reliable data transfer.

  • HTTP and HTTPS use TCP as their transport layer protocol.
  • Common TCP ports are 80 (HTTP) and 443 (HTTPS).
  • UDP is typically used for connectionless services like DNS or VoIP, not standard web browsing.

Memory trick: Logs tell a story; read the protocol for the real plot twist.

More Visibility and Enforcement questions