<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Inside Network Cant Access Internet ASA 5506 || Packet Tracer Lab || in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/inside-network-cant-access-internet-asa-5506-packet-tracer-lab/m-p/4135157#M1072951</link>
    <description>&lt;P&gt;I have a simple topology where two inside VLANS have HSRP Gateways needs to access Internet through ASA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can ping the inside Interface of ASA 5506 (Packet Tracer Simulator) from PC/Laptop but cant able to ping the Internet Router. Can any one share the valid solution with explanation for ASA config as i possibly think its a NAT issue.&amp;nbsp;&lt;BR /&gt;Screenshot+ ASA Config attached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SharedScreenshot.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/81405i9BDDE8F5DD172B4D/image-size/large?v=v2&amp;amp;px=999" role="button" title="SharedScreenshot.jpg" alt="SharedScreenshot.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SharedScreenshot2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/81406i6CE260B841EBC2DC/image-size/large?v=v2&amp;amp;px=999" role="button" title="SharedScreenshot2.jpg" alt="SharedScreenshot2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Aug 2020 09:33:50 GMT</pubDate>
    <dc:creator>Abdul Mateen</dc:creator>
    <dc:date>2020-08-13T09:33:50Z</dc:date>
    <item>
      <title>Inside Network Cant Access Internet ASA 5506 || Packet Tracer Lab ||</title>
      <link>https://community.cisco.com/t5/network-security/inside-network-cant-access-internet-asa-5506-packet-tracer-lab/m-p/4135157#M1072951</link>
      <description>&lt;P&gt;I have a simple topology where two inside VLANS have HSRP Gateways needs to access Internet through ASA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can ping the inside Interface of ASA 5506 (Packet Tracer Simulator) from PC/Laptop but cant able to ping the Internet Router. Can any one share the valid solution with explanation for ASA config as i possibly think its a NAT issue.&amp;nbsp;&lt;BR /&gt;Screenshot+ ASA Config attached.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SharedScreenshot.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/81405i9BDDE8F5DD172B4D/image-size/large?v=v2&amp;amp;px=999" role="button" title="SharedScreenshot.jpg" alt="SharedScreenshot.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SharedScreenshot2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/81406i6CE260B841EBC2DC/image-size/large?v=v2&amp;amp;px=999" role="button" title="SharedScreenshot2.jpg" alt="SharedScreenshot2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 09:33:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-network-cant-access-internet-asa-5506-packet-tracer-lab/m-p/4135157#M1072951</guid>
      <dc:creator>Abdul Mateen</dc:creator>
      <dc:date>2020-08-13T09:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: Inside Network Cant Access Internet ASA 5506 || Packet Tracer Lab ||</title>
      <link>https://community.cisco.com/t5/network-security/inside-network-cant-access-internet-asa-5506-packet-tracer-lab/m-p/4135168#M1072953</link>
      <description>Hi,&lt;BR /&gt;In order to ping through your ASA, you either need to permit the return icmp traffic or enable ICMP inspection. Run the command "fixup protocol icmp" to enable ICMP inspection.&lt;BR /&gt;&lt;BR /&gt;NAT your traffic behind the ASA's interface, amend your existing NAT to "nat (inside2,outside) dynamic interface"</description>
      <pubDate>Thu, 13 Aug 2020 09:41:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-network-cant-access-internet-asa-5506-packet-tracer-lab/m-p/4135168#M1072953</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-08-13T09:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Inside Network Cant Access Internet ASA 5506 || Packet Tracer Lab ||</title>
      <link>https://community.cisco.com/t5/network-security/inside-network-cant-access-internet-asa-5506-packet-tracer-lab/m-p/4135177#M1072955</link>
      <description>Thanks for your reply.&lt;BR /&gt;&lt;BR /&gt;I am untouch from ASA quite long.&lt;BR /&gt;I would be glad if you please enlighten me a bit about NAT (Static &amp;amp;&lt;BR /&gt;Dynamic) operation in ASA in and exact commands to make it work.&lt;BR /&gt;Also fixup protocol icmp is not working in ASA Packet Tracer.&lt;BR /&gt;[image: image.png]&lt;BR /&gt;</description>
      <pubDate>Thu, 13 Aug 2020 09:57:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-network-cant-access-internet-asa-5506-packet-tracer-lab/m-p/4135177#M1072955</guid>
      <dc:creator>Abdul Mateen</dc:creator>
      <dc:date>2020-08-13T09:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: Inside Network Cant Access Internet ASA 5506 || Packet Tracer Lab ||</title>
      <link>https://community.cisco.com/t5/network-security/inside-network-cant-access-internet-asa-5506-packet-tracer-lab/m-p/4135183#M1072956</link>
      <description>The image is not displayed, does packet tracer no like the command? &lt;BR /&gt;Amend you not NAT like below.&lt;BR /&gt;&lt;BR /&gt;object network inside_inet&lt;BR /&gt; no (inside2,outside) static 172.16.10.0&lt;BR /&gt; nat (inside2,outside) dynamic interface&lt;BR /&gt;&lt;BR /&gt;You NAT assumes that traffic is coming via "inside2" interface, you also have "inside" interface and would need a NAT rule for that.</description>
      <pubDate>Thu, 13 Aug 2020 10:10:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-network-cant-access-internet-asa-5506-packet-tracer-lab/m-p/4135183#M1072956</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2020-08-13T10:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Inside Network Cant Access Internet ASA 5506 || Packet Tracer Lab ||</title>
      <link>https://community.cisco.com/t5/network-security/inside-network-cant-access-internet-asa-5506-packet-tracer-lab/m-p/4137284#M1073079</link>
      <description>ciscoasa#sh run&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 9.6(1)&lt;BR /&gt;!&lt;BR /&gt;hostname ciscoasa&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/1&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.50.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;no nameif&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address dhcp&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 172.16.30.2 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/4&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/5&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/6&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/7&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/8&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Management1/1&lt;BR /&gt;management-only&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;object network inside_inet&lt;BR /&gt;subnet 192.168.50.0 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 172.16.30.1 1&lt;BR /&gt;route inside 172.16.10.0 255.255.255.0 192.168.50.2 1&lt;BR /&gt;route inside 192.168.10.0 255.255.255.0 192.168.50.2 1&lt;BR /&gt;route inside 192.168.20.0 255.255.255.0 192.168.50.2 1&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;object network inside_inet&lt;BR /&gt;nat (inside,outside) dynamic interface&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;class-map C1&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;policy-map P1&lt;BR /&gt;class C1&lt;BR /&gt;inspect icmp&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ciscoasa#</description>
      <pubDate>Tue, 18 Aug 2020 07:37:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-network-cant-access-internet-asa-5506-packet-tracer-lab/m-p/4137284#M1073079</guid>
      <dc:creator>Abdul Mateen</dc:creator>
      <dc:date>2020-08-18T07:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: Inside Network Cant Access Internet ASA 5506 || Packet Tracer Lab ||</title>
      <link>https://community.cisco.com/t5/network-security/inside-network-cant-access-internet-asa-5506-packet-tracer-lab/m-p/4137294#M1073081</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I have modified&amp;nbsp;a little in the topology and add a L3 Switch before ASA.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;I can now ping ASA internal interface from desktop computer but cant be able to reach the internet.&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;ASA config attached.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SharedScreenshot.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/81730i139B102CD7ECC008/image-size/large?v=v2&amp;amp;px=999" role="button" title="SharedScreenshot.jpg" alt="SharedScreenshot.jpg" /&gt;&lt;/span&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 18 Aug 2020 07:54:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/inside-network-cant-access-internet-asa-5506-packet-tracer-lab/m-p/4137294#M1073081</guid>
      <dc:creator>Abdul Mateen</dc:creator>
      <dc:date>2020-08-18T07:54:04Z</dc:date>
    </item>
  </channel>
</rss>

