<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA ISP CIDR Setup in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194446#M1065680</link>
    <description>&lt;P&gt;Hello all!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have recently acquired a new block of CIDR IP addresses from my ISP and I don't understand how to get it setup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WAN address: 68.x.x.232&lt;/P&gt;
&lt;P&gt;WAN gateway: 68.x.x.225&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CIDR network: 70.y.y.112/28&lt;/P&gt;
&lt;P&gt;Usable addresses: 70.y.y.114 - .126&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do I get this to work on an ASA 5512-X? Any help would be appreciated. Thanks!&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 14:26:34 GMT</pubDate>
    <dc:creator>tylerphillippe</dc:creator>
    <dc:date>2020-02-21T14:26:34Z</dc:date>
    <item>
      <title>ASA ISP CIDR Setup</title>
      <link>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194446#M1065680</link>
      <description>&lt;P&gt;Hello all!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have recently acquired a new block of CIDR IP addresses from my ISP and I don't understand how to get it setup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;WAN address: 68.x.x.232&lt;/P&gt;
&lt;P&gt;WAN gateway: 68.x.x.225&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CIDR network: 70.y.y.112/28&lt;/P&gt;
&lt;P&gt;Usable addresses: 70.y.y.114 - .126&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How do I get this to work on an ASA 5512-X? Any help would be appreciated. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194446#M1065680</guid>
      <dc:creator>tylerphillippe</dc:creator>
      <dc:date>2020-02-21T14:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ISP CIDR Setup</title>
      <link>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194454#M1065681</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry i read the question a bit fast&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just use the block for the service you need, for example new rules. The ISP points the block to your existing setup.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Martin&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 16:33:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194454#M1065681</guid>
      <dc:creator>mfilipovski</dc:creator>
      <dc:date>2017-10-05T16:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ISP CIDR Setup</title>
      <link>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194474#M1065682</link>
      <description>&lt;P&gt;That statement makes literally no sense.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need help getting this setup from scratch.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 16:47:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194474#M1065682</guid>
      <dc:creator>tylerphillippe</dc:creator>
      <dc:date>2017-10-05T16:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ISP CIDR Setup</title>
      <link>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194480#M1065683</link>
      <description>&lt;P&gt;Sorry,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What i meant was that your provider points the new block of address to the existing configuration in their router. So basically you can start using them right away, for example configure a new static nat rule with one of the new IP´s.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;edit: you mean that you want to start using the extra block you aquired from the provider?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 16:56:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194480#M1065683</guid>
      <dc:creator>mfilipovski</dc:creator>
      <dc:date>2017-10-05T16:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ISP CIDR Setup</title>
      <link>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194483#M1065684</link>
      <description>&lt;P&gt;Your WAN block is of course a standard setting that you would configure under your interface connected to your ISP. For instance:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;int gi0/1&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;nameif outside&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;ip address &lt;SPAN&gt;68.x.x.232&lt;/SPAN&gt; &amp;lt;netmask&amp;gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;!&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;route 0 0 &lt;SPAN&gt;68.x.x.225&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The CIDR block would be used for statc or dynamic NAT of your internal hosts. For example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;nat (inside,outside) source static&amp;nbsp;&amp;lt;private address&amp;gt; &lt;SPAN&gt;70.y.y.114&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;SPAN&gt;(Best practice would be to use objects with more human-readable names vs raw addresses in your NAT statements.)&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 17:02:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194483#M1065684</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-10-05T17:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ISP CIDR Setup</title>
      <link>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194485#M1065685</link>
      <description>&lt;P&gt;Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think I understand setting the outside facing port to the given address and then setting the route. I have seen online that I need to set the inside facing port to one of the CIDR addresses, for example 70.y.y.114. Is this correct?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 17:02:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194485#M1065685</guid>
      <dc:creator>tylerphillippe</dc:creator>
      <dc:date>2017-10-05T17:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ISP CIDR Setup</title>
      <link>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194508#M1065686</link>
      <description>&lt;P&gt;Before this change, we just had five separate routable addresses. We bought a CIDR block of 13 and everything has changed.&lt;BR /&gt;&lt;BR /&gt;We never had a CIDR block to begin with, so that's why I don't understand how to make it work.&lt;BR /&gt;&lt;BR /&gt;I understand the port connected to the modem needs to be the WAN address and I think another port for the LAN needs to be one of the CIDR addresses. But, that is as much as I understand.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can't even get the LAN port to ping the WAN port on the ASA, states there is no route even though they are both directly connected...&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 17:43:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194508#M1065686</guid>
      <dc:creator>tylerphillippe</dc:creator>
      <dc:date>2017-10-05T17:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ISP CIDR Setup</title>
      <link>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194727#M1065687</link>
      <description>&lt;P&gt;I'm not sure exactly what you're asking when you say "&lt;SPAN&gt;set the inside facing port to one of the CIDR addresses&lt;/SPAN&gt;". A NAT rule such as I cited earlier suffices. Routing-wise the upstream provider router sends that traffic to your ASA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the traffic is initiated from inside, the NAT plus the upstream provider's return path routing suffice to allow a flow and connection to establish.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the traffic is initiated from outside, the NAT rule and provider routing plus an access list allowing the traffic inbound will be needed.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2017 02:25:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194727#M1065687</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-10-06T02:25:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA ISP CIDR Setup</title>
      <link>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194756#M1065688</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Do you want to set the ASA in routed mode or transparent mode?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please advise your network considerations and goals.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Kias&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2017 04:45:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-isp-cidr-setup/m-p/3194756#M1065688</guid>
      <dc:creator>Kias</dc:creator>
      <dc:date>2017-10-06T04:45:09Z</dc:date>
    </item>
  </channel>
</rss>

