<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No internet access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201943#M1065358</link>
    <description>&lt;P&gt;Where is&amp;nbsp;&lt;SPAN&gt;192.168.60.254 in physical relation to the 3850 and the ASA?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 19 Oct 2017 19:22:38 GMT</pubDate>
    <dc:creator>Dean Romanelli</dc:creator>
    <dc:date>2017-10-19T19:22:38Z</dc:date>
    <item>
      <title>No internet access</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201898#M1065353</link>
      <description>&lt;P&gt;hi friends, my ASA 5580 has an INSIDE interface with 192.168.62.254 ip add. and that interf. is connected to a Switch through vlan62 with 192.168.62.253 ip addr. When I connect a PC to vlan62 with a static ip add. (192.168.62.40) and set GW as 192.168.62.253 or 192.168.62.254 for the PC in both cases I can access the internet without any problem. So far so good....&lt;/P&gt;
&lt;P&gt;Now I'm trying to do the same with another interface but I can't. The other inter. has 192.168.51.254 ip add and is connected to Swich through vlan51 with 192.168.51.253 ip add. When I use GW 192.168.51.254 in the PC I can access internet without problem, but when I use 192.168.51.253 as GW I can't...and the problem is that I need to use 192.168.51.253 as GW...can anybody help me please??? is this a conf. problem on the ASA ??? Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:32:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201898#M1065353</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2020-02-21T14:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: No internet access</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201903#M1065354</link>
      <description>&lt;P&gt;Could you post your ASA configs for us please?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 18:20:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201903#M1065354</guid>
      <dc:creator>Dean Romanelli</dc:creator>
      <dc:date>2017-10-19T18:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: No internet access</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201912#M1065355</link>
      <description>&lt;P&gt;here it is:&lt;/P&gt;
&lt;P&gt;ASA5580# sh running-config &lt;BR /&gt;: Saved&lt;BR /&gt;: &lt;BR /&gt;: Serial Number: USE00&lt;BR /&gt;: Hardware:&amp;nbsp;&amp;nbsp; ASA5580-20, 8192 MB RAM, CPU AMD Opteron 2600 MHz, 2 CPUs (4 cores)&lt;BR /&gt;:&lt;BR /&gt;ASA Version 9.1(7)19 &lt;BR /&gt;!&lt;BR /&gt;hostname ASA5580&lt;BR /&gt;enable password TFyi2xrxZ encrypted&lt;BR /&gt;xlate per-session deny tcp any4 any4&lt;BR /&gt;xlate per-session deny tcp any4 any6&lt;BR /&gt;xlate per-session deny tcp any6 any4&lt;BR /&gt;xlate per-session deny tcp any6 any6&lt;BR /&gt;xlate per-session deny udp any4 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any4 any6 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any6 eq domain&lt;BR /&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;BR /&gt;names&lt;BR /&gt;ip local pool pool-vpn-prueba 192.168.239.1-192.168.239.100 mask 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;&amp;nbsp;nameif management&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 192.168.0.44 255.255.255.0 &lt;BR /&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;interface Management0/1&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet3/0&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet3/1&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet3/2&lt;BR /&gt;&amp;nbsp;nameif CARRIERS&lt;BR /&gt;&amp;nbsp;security-level 30&lt;BR /&gt;&amp;nbsp;ip address 10.227.224.3 255.255.252.0 &lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet3/3&lt;BR /&gt;&amp;nbsp;nameif INSIDE_Prueba&lt;BR /&gt;&amp;nbsp;security-level 40&lt;BR /&gt;&amp;nbsp;ip address 192.168.62.254 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface TenGigabitEthernet5/0&lt;BR /&gt;&amp;nbsp;nameif CMTS&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 192.168.61.9 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface TenGigabitEthernet5/1&lt;BR /&gt;&amp;nbsp;nameif FTTH&lt;BR /&gt;&amp;nbsp;security-level 50&lt;BR /&gt;&amp;nbsp;ip address 192.168.51.254 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface TenGigabitEthernet7/0&lt;BR /&gt;&amp;nbsp;nameif OUTSIDE&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 170.X.X.2 255.255.255.240 &lt;BR /&gt;!&lt;BR /&gt;interface TenGigabitEthernet7/1&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;&amp;nbsp;no nameif&lt;BR /&gt;&amp;nbsp;no security-level&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;boot system disk0:/asa917-19-smp-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CST -6&lt;BR /&gt;clock summer-time CDT recurring 1 Sun Apr 2:00 last Sun Oct 2:00&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network 10.19.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.19.0.0 255.255.0.0&lt;BR /&gt;object network 170.X.X.3&lt;BR /&gt;&amp;nbsp;host 170.X.X.3&lt;BR /&gt;object network 170.X.X.4&lt;BR /&gt;&amp;nbsp;host 170.X.X.4&lt;BR /&gt;object network 170.X.X.5&lt;BR /&gt;&amp;nbsp;host 170.X.X.5&lt;BR /&gt;object network 170.X.X.6&lt;BR /&gt;&amp;nbsp;host 170.X.X.6&lt;BR /&gt;object network 170.X.X.7&lt;BR /&gt;&amp;nbsp;host 170.X.X.7&lt;BR /&gt;object network 170.X.X.8&lt;BR /&gt;&amp;nbsp;host 170.X.X.8&lt;BR /&gt;object network 170.X.X.9&lt;BR /&gt;&amp;nbsp;host 170.X.X.9&lt;BR /&gt;object network 170.X.X.10&lt;BR /&gt;&amp;nbsp;host 170.X.X.10&lt;BR /&gt;object network 170.X.X.11&lt;BR /&gt;&amp;nbsp;host 170.X.X.11&lt;BR /&gt;object network 170.X.X.12&lt;BR /&gt;&amp;nbsp;host 170.X.X.12&lt;BR /&gt;object network 170.X.X.13&lt;BR /&gt;&amp;nbsp;host 170.X.X.13&lt;BR /&gt;object network 170.X.X.14&lt;BR /&gt;&amp;nbsp;host 170.X.X.14&lt;BR /&gt;object network 10.27.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.27.0.0 255.255.0.0&lt;BR /&gt;object network 10.25.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.25.0.0 255.255.0.0&lt;BR /&gt;object network 10.9.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.9.0.0 255.255.0.0&lt;BR /&gt;object network 10.39.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.39.0.0 255.255.0.0&lt;BR /&gt;object network 10.11.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.11.0.0 255.255.0.0&lt;BR /&gt;object network 10.35.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.35.0.0 255.255.0.0&lt;BR /&gt;object network 10.33.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.33.0.0 255.255.0.0&lt;BR /&gt;object network 10.13.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.13.0.0 255.255.0.0&lt;BR /&gt;object network 10.17.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.17.0.0 255.255.0.0&lt;BR /&gt;object network 10.37.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.37.0.0 255.255.0.0&lt;BR /&gt;object network 10.41.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.41.0.0 255.255.0.0&lt;BR /&gt;object network 10.45.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.45.0.0 255.255.0.0&lt;BR /&gt;object network 170.X.X.16&lt;BR /&gt;&amp;nbsp;host 170.X.X.16&lt;BR /&gt;object network 170.X.X.17&lt;BR /&gt;&amp;nbsp;host 170.X.X.17&lt;BR /&gt;object network 170.X.X.18&lt;BR /&gt;&amp;nbsp;host 170.X.X.18&lt;BR /&gt;object network 170.X.X.19&lt;BR /&gt;&amp;nbsp;host 170.X.X.19&lt;BR /&gt;object network 170.X.X.20&lt;BR /&gt;&amp;nbsp;host 170.X.X.20&lt;BR /&gt;object network 170.X.X.21&lt;BR /&gt;&amp;nbsp;host 170.X.X.21&lt;BR /&gt;object network 170.X.X.22&lt;BR /&gt;&amp;nbsp;host 170.X.X.22&lt;BR /&gt;object network 170.X.X.23&lt;BR /&gt;&amp;nbsp;host 170.X.X.23&lt;BR /&gt;object network 170.X.X.24&lt;BR /&gt;&amp;nbsp;host 170.X.X.24&lt;BR /&gt;object network 170.X.X.25&lt;BR /&gt;&amp;nbsp;host 170.X.X.25&lt;BR /&gt;object network 10.47.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.47.0.0 255.255.0.0&lt;BR /&gt;object network 170.X.X.26&lt;BR /&gt;&amp;nbsp;host 170.X.X.26&lt;BR /&gt;object network 170.X.X.27&lt;BR /&gt;&amp;nbsp;host 170.X.X.27&lt;BR /&gt;object network 170.X.X.28&lt;BR /&gt;&amp;nbsp;host 170.X.X.28&lt;BR /&gt;object network 170.X.X.29&lt;BR /&gt;&amp;nbsp;host 170.X.X.29&lt;BR /&gt;object network 170.X.X.30&lt;BR /&gt;&amp;nbsp;host 170.X.X.30&lt;BR /&gt;object network 170.X.X.31&lt;BR /&gt;&amp;nbsp;host 170.X.X.31&lt;BR /&gt;object network 10.49.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.49.0.0 255.255.0.0&lt;BR /&gt;object network Prueba-10.227.225.210&lt;BR /&gt;&amp;nbsp;host 10.227.225.210&lt;BR /&gt;object network 10.227.225.210&lt;BR /&gt;&amp;nbsp;host 10.227.225.210&lt;BR /&gt;object network 172.16.99.0&lt;BR /&gt;&amp;nbsp;subnet 172.16.99.0 255.255.255.0&lt;BR /&gt;object network 172.16.99.22&lt;BR /&gt;&amp;nbsp;host 172.16.99.22&lt;BR /&gt;object network 10.50.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.50.0.0 255.255.0.0&lt;BR /&gt;object network 10.51.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.51.0.0 255.255.0.0&lt;BR /&gt;object network 10.227.225.20&lt;BR /&gt;&amp;nbsp;host 10.227.225.20&lt;BR /&gt;object network CentroValle_1930&lt;BR /&gt;&amp;nbsp;host 10.227.225.20&lt;BR /&gt;object network CentroValle_1946&lt;BR /&gt;&amp;nbsp;host 10.227.225.20&lt;BR /&gt;object network 170.X.X.2&lt;BR /&gt;&amp;nbsp;host 170.X.X.2&lt;BR /&gt;object network Stgo4646_3050&lt;BR /&gt;&amp;nbsp;host 10.44.0.130&lt;BR /&gt;object network 10.44.0.130&lt;BR /&gt;&amp;nbsp;host 10.44.0.130&lt;BR /&gt;object network 192.168.199.0&lt;BR /&gt;&amp;nbsp;subnet 192.168.199.0 255.255.255.0&lt;BR /&gt;object network 10.227.225.41&lt;BR /&gt;&amp;nbsp;host 10.227.225.41&lt;BR /&gt;object network Administracion_FTTH_NuevoIdeal&lt;BR /&gt;&amp;nbsp;subnet 10.16.10.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;description Administracion FTTH Nuevo Ideal&lt;BR /&gt;object network 10.228.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.228.0.0 255.255.240.0&lt;BR /&gt;&amp;nbsp;description 10.228.0.0&lt;BR /&gt;object network 192.168.239.0&lt;BR /&gt;&amp;nbsp;subnet 192.168.239.0 255.255.255.128&lt;BR /&gt;&amp;nbsp;description 192.168.239.0&lt;BR /&gt;object network NETWORK_OBJ_192.168.239.0_25&lt;BR /&gt;&amp;nbsp;subnet 192.168.239.0 255.255.255.128&lt;BR /&gt;object network pool-vpn-prueba&lt;BR /&gt;&amp;nbsp;subnet 192.168.239.0 255.255.255.128&lt;BR /&gt;object network Pool_CMTS_Stgo&lt;BR /&gt;&amp;nbsp;range 170.X.X.8 170.X.X.9&lt;BR /&gt;object network 10.227.225.12&lt;BR /&gt;&amp;nbsp;host 10.227.225.12&lt;BR /&gt;object network AutopartesStgo_Suc_NI_81&lt;BR /&gt;&amp;nbsp;host 10.227.225.12&lt;BR /&gt;object network AutopartesStgo_Suc_NI_554&lt;BR /&gt;&amp;nbsp;host 10.227.225.12&lt;BR /&gt;object network AutopartesStgo_Suc_NI_8000&lt;BR /&gt;&amp;nbsp;host 10.227.225.12&lt;BR /&gt;object network 10.227.225.31&lt;BR /&gt;&amp;nbsp;host 10.227.225.31&lt;BR /&gt;object network Ferrepisos_NI_3389&lt;BR /&gt;&amp;nbsp;host 10.227.225.31&lt;BR /&gt;object network Ferrepisos_NI_8081&lt;BR /&gt;&amp;nbsp;host 10.227.225.31&lt;BR /&gt;object network 10.227.225.21&lt;BR /&gt;&amp;nbsp;host 10.227.225.21&lt;BR /&gt;object network 10.227.225.22&lt;BR /&gt;&amp;nbsp;host 10.227.225.22&lt;BR /&gt;object network 170.X.X.80&lt;BR /&gt;&amp;nbsp;host 170.X.X.80&lt;BR /&gt;object network 170.X.X.81&lt;BR /&gt;&amp;nbsp;host 170.X.X.81&lt;BR /&gt;object network 170.X.X.82&lt;BR /&gt;&amp;nbsp;host 170.X.X.82&lt;BR /&gt;object network 10.227.225.29&lt;BR /&gt;&amp;nbsp;host 10.227.225.29&lt;BR /&gt;object network 10.227.225.39&lt;BR /&gt;&amp;nbsp;host 10.227.225.39&lt;BR /&gt;object network 170.X.X.83&lt;BR /&gt;&amp;nbsp;host 170.X.X.83&lt;BR /&gt;object network 170.X.X.84&lt;BR /&gt;&amp;nbsp;host 170.X.X.84&lt;BR /&gt;object network 170.X.X.85&lt;BR /&gt;&amp;nbsp;host 170.X.X.85&lt;BR /&gt;object network 192.168.199.29&lt;BR /&gt;&amp;nbsp;host 192.168.199.29&lt;BR /&gt;&amp;nbsp;description Gaspar&lt;BR /&gt;object network 10.227.224.11&lt;BR /&gt;&amp;nbsp;host 10.227.224.11&lt;BR /&gt;&amp;nbsp;description CACTI_Carrier&lt;BR /&gt;object network CACTI_Carrier&lt;BR /&gt;&amp;nbsp;host 10.227.224.11&lt;BR /&gt;object network 10.227.224.0&lt;BR /&gt;&amp;nbsp;subnet 10.227.224.0 255.255.252.0&lt;BR /&gt;object network ALTAI&lt;BR /&gt;&amp;nbsp;host 172.16.99.22&lt;BR /&gt;object network VPN-POOL&lt;BR /&gt;&amp;nbsp;range 192.168.239.1 192.168.239.100&lt;BR /&gt;object network Pool_CMTS_Victoria&lt;BR /&gt;&amp;nbsp;range 170.X.X.11 170.X.X.12&lt;BR /&gt;object network INSIDE-TEST&lt;BR /&gt;&amp;nbsp;subnet 192.168.62.0 255.255.255.0&lt;BR /&gt;object network Servidor_Comcast&lt;BR /&gt;&amp;nbsp;host 192.168.51.100&lt;BR /&gt;object network FTTH-network&lt;BR /&gt;&amp;nbsp;subnet 192.168.51.0 255.255.255.0&lt;BR /&gt;object network 10.30.0.0&lt;BR /&gt;&amp;nbsp;subnet 10.30.0.0 255.255.0.0&lt;BR /&gt;&amp;nbsp;description 10.30.0.0&lt;BR /&gt;object-group network redvpn&lt;BR /&gt;&amp;nbsp;network-object object 192.168.199.0&lt;BR /&gt;access-list CARRIERS_access_in extended permit ip 10.227.224.0 255.255.252.0 any4 &lt;BR /&gt;access-list CARRIERS_access_out extended permit ip any4 10.227.224.0 255.255.252.0 &lt;BR /&gt;access-list CARRIERS_access_out extended permit ip 192.168.199.0 255.255.255.0 10.227.224.0 255.255.252.0 &lt;BR /&gt;access-list OUTSIDE_access_in remark ALTAI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any4 object 172.16.99.22 &lt;BR /&gt;access-list OUTSIDE_access_in remark Centro Valle&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any4 object 10.227.225.20 eq 1930 &lt;BR /&gt;access-list OUTSIDE_access_in remark Centro Valle&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any4 object 10.227.225.20 eq 1946 &lt;BR /&gt;access-list OUTSIDE_access_in remark Stgo Contrato 4646&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any4 object 10.44.0.130 eq 3050 &lt;BR /&gt;access-list OUTSIDE_access_in remark Prueba&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any4 object 10.227.225.210 &lt;BR /&gt;access-list OUTSIDE_access_in remark Gasolinera Holanda&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any4 object 10.227.225.41 &lt;BR /&gt;access-list OUTSIDE_access_in remark AutopartesStgo_Suc_NI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any4 object 10.227.225.12 eq 81 &lt;BR /&gt;access-list OUTSIDE_access_in remark AutopartesStgo_Suc_NI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any4 object 10.227.225.12 eq rtsp &lt;BR /&gt;access-list OUTSIDE_access_in remark AutopartesStgo_Suc_NI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any4 object 10.227.225.12 eq 8000 &lt;BR /&gt;access-list OUTSIDE_access_in remark Ferrepisos_NI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any4 object 10.227.225.31 eq 3389 &lt;BR /&gt;access-list OUTSIDE_access_in remark Ferrepisos_NI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any4 object 10.227.225.31 eq 8081 &lt;BR /&gt;access-list OUTSIDE_access_in remark Gasolinera Samantha&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any4 object 10.227.225.21 &lt;BR /&gt;access-list OUTSIDE_access_in remark Gasolinera CM&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any4 object 10.227.225.22 &lt;BR /&gt;access-list OUTSIDE_access_in remark Farmacia Economica NI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any4 object 10.227.225.39 &lt;BR /&gt;access-list OUTSIDE_access_in remark Caja Hipodromo NI&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any4 object 10.227.225.29 &lt;BR /&gt;access-list OUTSIDE_access_in remark CACTI_Carrier&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any4 object 10.227.224.11 &lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any4 any4 &lt;BR /&gt;access-list INSIDE_Prueba_access_in extended permit ip 192.168.62.0 255.255.255.0 any4 &lt;BR /&gt;access-list INSIDE_Prueba_access_in extended permit ip object 172.16.99.0 any4 &lt;BR /&gt;access-list INSIDE_Prueba_access_in extended permit ip object 192.168.199.0 any4 &lt;BR /&gt;access-list INSIDE_Prueba_access_in extended permit ip object 10.228.0.0 any4 &lt;BR /&gt;access-list INSIDE_Prueba_access_in extended permit ip 10.227.224.0 255.255.252.0 192.168.199.0 255.255.255.0 &lt;BR /&gt;access-list INSIDE_Prueba_access_in extended permit ip 192.168.199.0 255.255.255.0 192.168.239.0 255.255.255.128 &lt;BR /&gt;access-list ACL-tunel-vpn-prueba standard permit 192.168.199.0 255.255.255.0 &lt;BR /&gt;access-list ACL-tunel-vpn-prueba standard permit 192.168.239.0 255.255.255.0 &lt;BR /&gt;access-list ACL-tunel-vpn-prueba standard permit 192.168.62.0 255.255.255.0 &lt;BR /&gt;access-list INSIDE_Prueba_access_out extended permit ip 10.227.224.0 255.255.252.0 any4 &lt;BR /&gt;access-list INSIDE_Prueba_access_out extended permit ip 192.168.199.0 255.255.255.0 any4 &lt;BR /&gt;access-list INSIDE_Prueba_access_out extended permit ip any4 object 172.16.99.0 &lt;BR /&gt;access-list INSIDE_Prueba_access_out extended permit ip 192.168.239.0 255.255.255.128 192.168.199.0 255.255.255.0 &lt;BR /&gt;access-list TEST extended permit ip 192.168.199.0 255.255.255.0 192.168.239.0 255.255.255.128 &lt;BR /&gt;access-list TEST extended permit ip 192.168.239.0 255.255.255.128 192.168.199.0 255.255.255.0 &lt;BR /&gt;access-list FTTH_access_in extended permit ip 192.168.51.0 255.255.255.0 any4 &lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu management 1500&lt;BR /&gt;mtu CARRIERS 1500&lt;BR /&gt;mtu INSIDE_Prueba 1500&lt;BR /&gt;mtu CMTS 1500&lt;BR /&gt;mtu OUTSIDE 1500&lt;BR /&gt;mtu FTTH 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;icmp permit any CARRIERS&lt;BR /&gt;icmp permit any echo CARRIERS&lt;BR /&gt;icmp permit any echo-reply CARRIERS&lt;BR /&gt;icmp permit any OUTSIDE&lt;BR /&gt;asdm image disk0:/asdm-762-150.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.19.0.0 170.X.X.16&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.27.0.0 pat-pool Pool_CMTS_Victoria&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.25.0.0 170.X.X.18&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.39.0.0 170.X.X.20&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.35.0.0 170.X.X.22&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.33.0.0 170.X.X.23&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.13.0.0 170.X.X.13&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.17.0.0 170.X.X.25&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.37.0.0 170.X.X.26&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.41.0.0 170.X.X.27&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.33.0.0 170.X.X.29&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.47.0.0 170.X.X.21&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.49.0.0 170.X.X.24&lt;BR /&gt;nat (CARRIERS,OUTSIDE) source static 10.227.225.210 170.X.X.3&lt;BR /&gt;nat (CARRIERS,OUTSIDE) source static 10.227.225.41 170.X.X.82 description Gasolinera Holanda&lt;BR /&gt;nat (INSIDE_Prueba,OUTSIDE) source dynamic 10.228.0.0 170.X.X.10&lt;BR /&gt;nat (CMTS,OUTSIDE) source dynamic 10.51.0.0 pat-pool Pool_CMTS_Stgo&lt;BR /&gt;nat (CARRIERS,OUTSIDE) source static 10.227.225.21 170.X.X.80 description Gasolinera Samantha&lt;BR /&gt;nat (CARRIERS,OUTSIDE) source static 10.227.225.22 170.X.X.81 description Gasolinera CM&lt;BR /&gt;nat (CARRIERS,OUTSIDE) source static 10.227.225.39 170.X.X.83&lt;BR /&gt;nat (CARRIERS,OUTSIDE) source static 10.227.225.29 170.X.X.84&lt;BR /&gt;nat (INSIDE_Prueba,OUTSIDE) source static INSIDE-TEST INSIDE-TEST destination static NETWORK_OBJ_192.168.239.0_25 NETWORK_OBJ_192.168.239.0_25 no-proxy-arp route-lookup&lt;BR /&gt;nat (INSIDE_Prueba,OUTSIDE) source static redvpn redvpn destination static pool-vpn-prueba pool-vpn-prueba no-proxy-arp route-lookup&lt;BR /&gt;nat (OUTSIDE,OUTSIDE) source static pool-vpn-prueba pool-vpn-prueba destination static pool-vpn-prueba pool-vpn-prueba no-proxy-arp route-lookup&lt;BR /&gt;nat (FTTH,OUTSIDE) source dynamic any 170.X.X.10&lt;BR /&gt;nat (FTTH,OUTSIDE) source dynamic 10.30.0.0 170.X.X.10&lt;BR /&gt;!&lt;BR /&gt;object network CentroValle_1930&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static interface service tcp 1930 11930 &lt;BR /&gt;object network CentroValle_1946&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static interface service tcp 1946 11946 &lt;BR /&gt;object network Stgo4646_3050&lt;BR /&gt;&amp;nbsp;nat (CMTS,OUTSIDE) static 170.X.X.28 service tcp 3050 13050 &lt;BR /&gt;object network AutopartesStgo_Suc_NI_81&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static interface service tcp 81 10081 &lt;BR /&gt;object network AutopartesStgo_Suc_NI_554&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static interface service tcp rtsp 10554 &lt;BR /&gt;object network AutopartesStgo_Suc_NI_8000&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static interface service tcp 8000 18000 &lt;BR /&gt;object network Ferrepisos_NI_3389&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static interface service tcp 3389 13389 &lt;BR /&gt;object network Ferrepisos_NI_8081&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static interface service tcp 8081 18081 &lt;BR /&gt;object network CACTI_Carrier&lt;BR /&gt;&amp;nbsp;nat (CARRIERS,OUTSIDE) static 170.X.X.6&lt;BR /&gt;object network ALTAI&lt;BR /&gt;&amp;nbsp;nat (INSIDE_Prueba,OUTSIDE) static 170.X.X.4&lt;BR /&gt;!&lt;BR /&gt;nat (CARRIERS,OUTSIDE) after-auto source dynamic any interface&lt;BR /&gt;nat (INSIDE_Prueba,OUTSIDE) after-auto source dynamic any interface&lt;BR /&gt;nat (CMTS,OUTSIDE) after-auto source dynamic 10.45.0.0 170.X.X.28&lt;BR /&gt;nat (OUTSIDE,OUTSIDE) after-auto source static pool-vpn-prueba interface no-proxy-arp&lt;BR /&gt;access-group CARRIERS_access_in in interface CARRIERS&lt;BR /&gt;access-group CARRIERS_access_out out interface CARRIERS&lt;BR /&gt;access-group INSIDE_Prueba_access_out out interface INSIDE_Prueba&lt;BR /&gt;access-group OUTSIDE_access_in in interface OUTSIDE&lt;BR /&gt;route OUTSIDE 0.0.0.0 0.0.0.0 170.X.X.1 1 &lt;BR /&gt;route CMTS 10.8.0.0 255.255.0.0 192.168.61.102 1 &lt;BR /&gt;route CMTS 10.9.0.0 255.255.0.0 192.168.61.102 1 &lt;BR /&gt;route CMTS 10.10.0.0 255.255.0.0 192.168.61.101 1 &lt;BR /&gt;route CMTS 10.11.0.0 255.255.0.0 192.168.61.101 1 &lt;BR /&gt;route CMTS 10.12.0.0 255.255.0.0 192.168.61.114 1 &lt;BR /&gt;route CMTS 10.13.0.0 255.255.0.0 192.168.61.114 1 &lt;BR /&gt;route CMTS 10.16.0.0 255.255.0.0 192.168.61.112 1 &lt;BR /&gt;route CMTS 10.17.0.0 255.255.0.0 192.168.61.112 1 &lt;BR /&gt;route CMTS 10.18.0.0 255.255.0.0 192.168.61.111 1 &lt;BR /&gt;route CMTS 10.19.0.0 255.255.0.0 192.168.61.111 1 &lt;BR /&gt;route CMTS 10.24.0.0 255.255.0.0 192.168.61.122 1 &lt;BR /&gt;route CMTS 10.25.0.0 255.255.0.0 192.168.61.122 1 &lt;BR /&gt;route CMTS 10.26.0.0 255.255.0.0 192.168.61.123 1 &lt;BR /&gt;route CMTS 10.27.0.0 255.255.0.0 192.168.61.123 1 &lt;BR /&gt;route FTTH 10.30.0.0 255.255.0.0 192.168.51.50 1 &lt;BR /&gt;route CMTS 10.32.0.0 255.255.0.0 192.168.61.130 1 &lt;BR /&gt;route CMTS 10.33.0.0 255.255.0.0 192.168.61.130 1 &lt;BR /&gt;route CMTS 10.34.0.0 255.255.0.0 192.168.61.131 1 &lt;BR /&gt;route CMTS 10.35.0.0 255.255.0.0 192.168.61.131 1 &lt;BR /&gt;route CMTS 10.36.0.0 255.255.0.0 192.168.61.132 1 &lt;BR /&gt;route CMTS 10.37.0.0 255.255.0.0 192.168.61.132 1 &lt;BR /&gt;route CMTS 10.38.0.0 255.255.0.0 192.168.61.133 1 &lt;BR /&gt;route CMTS 10.39.0.0 255.255.0.0 192.168.61.133 1 &lt;BR /&gt;route CMTS 10.40.0.0 255.255.0.0 192.168.61.134 1 &lt;BR /&gt;route CMTS 10.41.0.0 255.255.0.0 192.168.61.134 1 &lt;BR /&gt;route CMTS 10.44.0.0 255.255.0.0 192.168.61.135 1 &lt;BR /&gt;route CMTS 10.45.0.0 255.255.0.0 192.168.61.135 1 &lt;BR /&gt;route CMTS 10.46.0.0 255.255.0.0 192.168.61.137 1 &lt;BR /&gt;route CMTS 10.47.0.0 255.255.0.0 192.168.61.137 1 &lt;BR /&gt;route CMTS 10.48.0.0 255.255.0.0 192.168.61.138 1 &lt;BR /&gt;route CMTS 10.49.0.0 255.255.0.0 192.168.61.138 1 &lt;BR /&gt;route CMTS 10.50.0.0 255.255.0.0 192.168.61.139 1 &lt;BR /&gt;route CMTS 10.51.0.0 255.255.0.0 192.168.61.139 1 &lt;BR /&gt;route INSIDE_Prueba 10.228.0.0 255.255.0.0 192.168.62.253 1 &lt;BR /&gt;route INSIDE_Prueba 172.16.99.0 255.255.255.0 192.168.62.253 1 &lt;BR /&gt;route INSIDE_Prueba 192.168.199.0 255.255.255.0 192.168.62.253 1 &lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;aaa authentication enable console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.0.0 255.255.255.0 management&lt;BR /&gt;snmp-server host management 192.168.0.2 community ***** udp-port 161&lt;BR /&gt;snmp-server location Site-Dg&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server community *****&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac &lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac &lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map OUTSIDE_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP&lt;BR /&gt;crypto map OUTSIDE_map interface OUTSIDE&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ikev1 enable OUTSIDE&lt;BR /&gt;crypto ikev1 policy 10&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 20&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 30&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption aes-256&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 40&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 50&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 60&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption aes-192&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 70&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 80&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 90&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption aes&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 100&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 110&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 120&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption 3des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 130&lt;BR /&gt;&amp;nbsp;authentication crack&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 140&lt;BR /&gt;&amp;nbsp;authentication rsa-sig&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 150&lt;BR /&gt;&amp;nbsp;authentication pre-share&lt;BR /&gt;&amp;nbsp;encryption des&lt;BR /&gt;&amp;nbsp;hash sha&lt;BR /&gt;&amp;nbsp;group 2&lt;BR /&gt;&amp;nbsp;lifetime 86400&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 192.168.0.0 255.255.255.0 management&lt;BR /&gt;ssh 192.168.0.0 255.255.255.0 INSIDE_Prueba&lt;BR /&gt;ssh 200.Y.Y.3 255.255.255.255 OUTSIDE&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;BR /&gt;management-access INSIDE_Prueba&lt;BR /&gt;!&lt;BR /&gt;tls-proxy maximum-session 1000&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;group-policy DfltGrpPolicy attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 ikev2 ssl-clientless&lt;BR /&gt;group-policy policiy-tunel-vpn-prueba-all internal&lt;BR /&gt;group-policy policiy-tunel-vpn-prueba-all attributes&lt;BR /&gt;&amp;nbsp;dns-server value 209.244.0.3 209.244.0.4&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 ssl-clientless&lt;BR /&gt;&amp;nbsp;split-tunnel-policy tunnelall&lt;BR /&gt;group-policy policiy-tunel-vpn-prueba-split internal&lt;BR /&gt;group-policy policiy-tunel-vpn-prueba-split attributes&lt;BR /&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 &lt;BR /&gt;&amp;nbsp;split-tunnel-policy tunnelspecified&lt;BR /&gt;&amp;nbsp;split-tunnel-network-list value ACL-tunel-vpn-prueba&lt;BR /&gt;username fermin password vWzyma2s encrypted privilege 15&lt;BR /&gt;username gaspar password uFhUHyhgi encrypted privilege 15&lt;BR /&gt;username extra password Mgi9n5y3x encrypted privilege 15&lt;BR /&gt;tunnel-group tunel-vpn-prueba type remote-access&lt;BR /&gt;tunnel-group tunel-vpn-prueba general-attributes&lt;BR /&gt;&amp;nbsp;address-pool pool-vpn-prueba&lt;BR /&gt;&amp;nbsp;default-group-policy policiy-tunel-vpn-prueba-split&lt;BR /&gt;tunnel-group tunel-vpn-prueba ipsec-attributes&lt;BR /&gt;&amp;nbsp;ikev1 pre-shared-key *****&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum client auto&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect ip-options &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect skinny &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;&amp;nbsp; inspect sip &amp;nbsp;&lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt;&amp;nbsp;profile CiscoTAC-1&lt;BR /&gt;&amp;nbsp; no active&lt;BR /&gt;&amp;nbsp; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;BR /&gt;&amp;nbsp; destination transport-method http&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly 7&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly 7&lt;BR /&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:a33559ffa672a6fb650&lt;BR /&gt;: end&lt;BR /&gt;ASA5580#&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 18:35:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201912#M1065355</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2017-10-19T18:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: No internet access</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201925#M1065356</link>
      <description>&lt;P&gt;Does your switch have any static routes configured? I suspect I may know the issue.&lt;/P&gt;
&lt;P&gt;Could you please port the output of the following command from your switch:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;show run | section ip route&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 18:54:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201925#M1065356</guid>
      <dc:creator>Dean Romanelli</dc:creator>
      <dc:date>2017-10-19T18:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: No internet access</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201934#M1065357</link>
      <description>&lt;P&gt;Sorry, I forgot to mention that both interfaces are connected to diffrent switches, INSIDE is connected to 3750 Switch and FFTH is connected to 3850 Switch. Supposing you want me to run the command in 3850 here you go:&lt;/P&gt;
&lt;P&gt;SW3850_Core#show run | section ip route&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 192.168.60.254&lt;BR /&gt;ip route 10.26.0.0 255.255.0.0 192.168.61.123&lt;BR /&gt;ip route 10.27.0.0 255.255.0.0 192.168.61.123&lt;BR /&gt;ip route 172.16.8.0 255.255.255.0 192.168.60.254&lt;BR /&gt;ip route 172.30.0.0 255.255.254.0 192.168.60.254&lt;BR /&gt;ip route 192.168.61.0 255.255.255.0 192.168.61.254&lt;BR /&gt;ip route 192.168.62.0 255.255.255.0 192.168.20.223&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 19:10:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201934#M1065357</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2017-10-19T19:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: No internet access</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201943#M1065358</link>
      <description>&lt;P&gt;Where is&amp;nbsp;&lt;SPAN&gt;192.168.60.254 in physical relation to the 3850 and the ASA?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 19:22:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201943#M1065358</guid>
      <dc:creator>Dean Romanelli</dc:creator>
      <dc:date>2017-10-19T19:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: No internet access</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201947#M1065359</link>
      <description>&lt;P&gt;is in another ASA (5540)...&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 19:27:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201947#M1065359</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2017-10-19T19:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: No internet access</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201977#M1065360</link>
      <description>&lt;P&gt;Is that ASA 5540 in between the core switch and the ASA 5580?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 20:04:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201977#M1065360</guid>
      <dc:creator>Dean Romanelli</dc:creator>
      <dc:date>2017-10-19T20:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: No internet access</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201986#M1065361</link>
      <description>&lt;P&gt;not between, is connected to another port in 3850, like the 5580...&lt;/P&gt;
&lt;P&gt;5540 is in port g1/0/1 and 5580 in port t1/1/3....&lt;/P&gt;
&lt;P&gt;besides that, I ran some test in the 5580:&lt;/P&gt;
&lt;P&gt;ASA5580# packet-tracer input ftTH tcp 192.168.51.40 1024 8.8.8.8 3389&lt;BR /&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;BR /&gt;&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OUTSIDE&lt;BR /&gt;&lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (FTTH,OUTSIDE) source dynamic any 170.X.X.10&lt;BR /&gt;Additional Information:&lt;BR /&gt;Dynamic translate 192.168.51.40/1024 to 170.X.X.10/1024&lt;BR /&gt;&lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 5&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 6&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: rpf-check&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (FTTH,OUTSIDE) source dynamic any 170.X.X.10&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 8&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;&lt;BR /&gt;Phase: 9&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 2128048568, packet dispatched to next module&lt;BR /&gt;&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: FTTH&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: OUTSIDE&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;
&lt;P&gt;and in the way around:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;ASA5580# packet-tracer input ouTSIDE tcp 8.8.8.8 12345 170.X.X.10 80&lt;BR /&gt;&lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype: &lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;BR /&gt;&lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; 170.X.X.0&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.240 OUTSIDE&lt;BR /&gt;&lt;BR /&gt;Result:&lt;BR /&gt;input-interface: OUTSIDE&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: OUTSIDE&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop &amp;nbsp;&lt;BR /&gt;Drop-reason: (nat-no-xlate-to-pat-pool) Connection to PAT address without pre-existing xlate&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2017 20:15:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3201986#M1065361</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2017-10-19T20:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: No internet access</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3202193#M1065362</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Looks like the 5580 is working as expected, but you are default routing everything to the 5540 in the 3850. &lt;BR /&gt;Is that what you want?&lt;BR /&gt;If so the problem is probably in the 5540 and not in the 5580.&lt;BR /&gt;If you do a packet capture on the 5540, do you see the client traffic there?&lt;BR /&gt;&lt;BR /&gt;# to capture traffic, need to change X to correct interface.&lt;BR /&gt;capture A interface X match ip host 192.168.51.40 host 8.8.8.8&lt;BR /&gt;# to see the capture&lt;BR /&gt;show capture A&lt;BR /&gt;&lt;BR /&gt;br, Micke&lt;BR /&gt;</description>
      <pubDate>Fri, 20 Oct 2017 08:07:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3202193#M1065362</guid>
      <dc:creator>mikael.lahtela</dc:creator>
      <dc:date>2017-10-20T08:07:01Z</dc:date>
    </item>
    <item>
      <title>Re: No internet access</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3202414#M1065363</link>
      <description>&lt;P&gt;thanks my friend, I solved already.... Just added a route to the 5580 and now everything is ok.&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 20 Oct 2017 14:12:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-access/m-p/3202414#M1065363</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2017-10-20T14:12:20Z</dc:date>
    </item>
  </channel>
</rss>

