An outside user attempts to access an inside host – Cisco ASA 5505 User Manual
Page 193
 
4-21
Cisco ASA 5500 Series Configuration Guide using the CLI
Chapter 4 Configuring the Transparent or Routed Firewall
Firewall Mode Examples
5.
The ASA forwards the packet to the inside user.
An Outside User Attempts to Access an Inside Host
shows an outside user attempting to access the inside network.
Figure 4-6
Outside to Inside
The following steps describe how data moves through the ASA (see
1.
A user on the outside network attempts to reach an inside host (assuming the host has a routable 
IP address).
If the inside network uses private addresses, no outside user can reach the inside network without 
NAT. The outside user might attempt to reach an inside user by using an existing NAT session.
2.
The ASA receives the packet and because it is a new session, the ASA verifies if the packet is 
allowed according to the security policy (access lists, filters, AAA).
3.
The packet is denied, and the ASA drops the packet and logs the connection attempt.
If the outside user is attempting to attack the inside network, the ASA employs many technologies 
to determine if a packet is valid for an already established session.
www.example.com
User
10.1.2.27
209.165.201.2
10.1.1.1
10.1.2.1
Outside
Inside
DMZ
92407