<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I found Internet Issue with ASA5515 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4189639#M1076185</link>
    <description>&lt;P&gt;5515 should be capable of handling the information your provided. do you have any other Addons enabled Like IPS ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you post show version as requested along with your config and translation to understand the issue ?&amp;gt;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Nov 2020 11:14:25 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2020-11-27T11:14:25Z</dc:date>
    <item>
      <title>I found Internet Issue with ASA5515</title>
      <link>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4189576#M1076175</link>
      <description>&lt;P&gt;I used ASA5515 and I found problem with Internet Connection lost.&lt;/P&gt;&lt;P&gt;For example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm able to access the internet and sometime I found internet has lost.&lt;/P&gt;&lt;P&gt;Please find the details below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can ping ASA5515&lt;/P&gt;&lt;P&gt;I can remote to ASA5515&lt;/P&gt;&lt;P&gt;I can ping LAN (inside) interface of ASA5515&lt;/P&gt;&lt;P&gt;I can ping LAN network from ASA5515&lt;/P&gt;&lt;P&gt;I can ping 8.8.8.8 from ASA5515&lt;/P&gt;&lt;P&gt;but&lt;BR /&gt;I can't ping 8.8.8.8 from Client&lt;BR /&gt;&lt;BR /&gt;And next 5 minutes I can access internet.&lt;BR /&gt;I can ping 8.8.8.8 from my laptop.&lt;BR /&gt;I don't know what's happened.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 08:39:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4189576#M1076175</guid>
      <dc:creator>pichai-chai</dc:creator>
      <dc:date>2020-11-27T08:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: I found Internet Issue with ASA5515</title>
      <link>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4189613#M1076181</link>
      <description>&lt;P&gt;This could you be your NAt issue where this was translating.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what kind of bandwidth and how many Clients. have you looked at the NAT translation and Logs in ASA at the time of Loss ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;provide from ASA&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show version&lt;/P&gt;
&lt;P&gt;other information related to translation&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 10:07:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4189613#M1076181</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-11-27T10:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: I found Internet Issue with ASA5515</title>
      <link>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4189622#M1076184</link>
      <description>&lt;P&gt;bandwidth = 200 Mbps&lt;/P&gt;&lt;P&gt;Client = 50 users&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.1(2)&lt;BR /&gt;Device Manager Version 7.1(3)&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 10:41:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4189622#M1076184</guid>
      <dc:creator>pichai-chai</dc:creator>
      <dc:date>2020-11-27T10:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: I found Internet Issue with ASA5515</title>
      <link>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4189639#M1076185</link>
      <description>&lt;P&gt;5515 should be capable of handling the information your provided. do you have any other Addons enabled Like IPS ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;can you post show version as requested along with your config and translation to understand the issue ?&amp;gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 11:14:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4189639#M1076185</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-11-27T11:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: I found Internet Issue with ASA5515</title>
      <link>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4189952#M1076200</link>
      <description>&lt;P&gt;Yes, I think it's enough performance for our internet usage.&lt;BR /&gt;I've no IPS on this firewall.&lt;/P&gt;&lt;P&gt;Please find attached for the config below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;============&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 10.61.x.x 255.255.254.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;nameif outside&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address xxx.xxx.xxx.xxx 255.255.255.248&lt;/P&gt;&lt;P&gt;object network Internal&lt;/P&gt;&lt;P&gt;subnet 10.61.0.0 255.255.0.0&lt;/P&gt;&lt;P&gt;access-list inside_to_outside extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list inside_to_outside extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list inside_to_outside extended permit udp any any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;no arp permit-nonconnected&lt;/P&gt;&lt;P&gt;object network Internal&lt;/P&gt;&lt;P&gt;nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;access-group inside_to_outside in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 xxx.xxx.xxx.xxx 1&lt;/P&gt;&lt;P&gt;route inside 10.61.0.0 255.255.0.0 10.xx.xx.247 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2020 00:20:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4189952#M1076200</guid>
      <dc:creator>pichai-chai</dc:creator>
      <dc:date>2020-11-28T00:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: I found Internet Issue with ASA5515</title>
      <link>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4189989#M1076201</link>
      <description>&lt;P&gt;Are you using separate physical interfaces for inside and outside interfaces or is it a port-channel?&lt;/P&gt;
&lt;P&gt;Have you check the logs on the ASA and the switch it connects to?&lt;/P&gt;
&lt;P&gt;Next time the issue occurs, also check the connection table (show conn).&amp;nbsp; The output can be big so make sure your terminal emulator buffer is large enough to handle it.&amp;nbsp; Check that, for example, when pinging 8.8.8.8 from a client, the connection is between inside and outside interface and not being sent to another interface or being black-holed.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2020 08:13:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4189989#M1076201</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-11-28T08:13:45Z</dc:date>
    </item>
    <item>
      <title>Re: I found Internet Issue with ASA5515</title>
      <link>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4189992#M1076202</link>
      <description>&lt;P&gt;&lt;SPAN&gt;as requested before pleas post - can you post show version as requested along with your config and translation to understand the issue ?&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also for testing, if you can arrange a device to bypass FW and check if you have an issue, on that PC to eliminate what causing the issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;there is couple issue i can think of now - may be your TCP multiplexing conn overflow, so no NAT taking place. this may be due to any device compromised network and sending huge traffic out or randomly&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2020 08:35:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4189992#M1076202</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-11-28T08:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: I found Internet Issue with ASA5515</title>
      <link>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4190198#M1076221</link>
      <description>&lt;P&gt;Hi Bud&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've one lan cable is connect from L3 to ASA, no etherchannel function.&lt;/P&gt;&lt;P&gt;========================================&lt;/P&gt;&lt;P&gt;I took the step when I found the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ping asa from client = okay&lt;/P&gt;&lt;P&gt;ping 8.8.8.8 from client = not okay&lt;/P&gt;&lt;P&gt;telnet asa from client = okay&lt;/P&gt;&lt;P&gt;ping 8.8.8.8 from asa = okay&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think this is a ASA issue but I don't know what's happened?&lt;/P&gt;&lt;P&gt;sometime internet is work fine all day but sometime the internet is loss in 15 minutes or every 1 hour.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2020 00:27:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4190198#M1076221</guid>
      <dc:creator>pichai-chai</dc:creator>
      <dc:date>2020-11-29T00:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: I found Internet Issue with ASA5515</title>
      <link>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4190199#M1076222</link>
      <description>&lt;P&gt;Dear Bud&lt;/P&gt;&lt;P&gt;When I found the issue I do telnet to ASA and I've ping to 8.8.8.8 from ASA, yes I can ping but the client can not ping 8.8.8.8.&lt;/P&gt;&lt;P&gt;I agreed with you about NAT translation and TCP multiplexing conn overflow but how I can prove this issue?&lt;/P&gt;&lt;P&gt;Please advise me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2020 00:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4190199#M1076222</guid>
      <dc:creator>pichai-chai</dc:creator>
      <dc:date>2020-11-29T00:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: I found Internet Issue with ASA5515</title>
      <link>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4190212#M1076224</link>
      <description>&lt;P&gt;Do you only have that NAT rule applied to the ASA? if not, can you please post the output of the &lt;STRONG&gt;sh run nat&lt;/STRONG&gt; command for review?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2020 03:27:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4190212#M1076224</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-11-29T03:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: I found Internet Issue with ASA5515</title>
      <link>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4190228#M1076226</link>
      <description>&lt;P&gt;here is the step by step instructions :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/116388-technote-nat-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/116388-technote-nat-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since you have an issue to resolve i also suggest to setup an SYSLOG Server for some time or Long Term send the Logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Make some script as soon as you hit the connection limit or any other issue you get an email from out of the box monitor system.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can use EEM script example :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://thwack.solarwinds.com/t5/NPM-Discussions/Monitoring-Cisco-router-NAT-translations/m-p/246895" target="_blank"&gt;https://thwack.solarwinds.com/t5/NPM-Discussions/Monitoring-Cisco-router-NAT-translations/m-p/246895&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2020 07:13:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4190228#M1076226</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-11-29T07:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: I found Internet Issue with ASA5515</title>
      <link>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4193301#M1076409</link>
      <description>&lt;P&gt;No, I have not.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 09:05:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4193301#M1076409</guid>
      <dc:creator>pichai-chai</dc:creator>
      <dc:date>2020-12-04T09:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: I found Internet Issue with ASA5515</title>
      <link>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4193303#M1076410</link>
      <description>&lt;P&gt;I found this issue when I've changed the firewall to Fortigate. It's the same.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 09:06:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/i-found-internet-issue-with-asa5515/m-p/4193303#M1076410</guid>
      <dc:creator>pichai-chai</dc:creator>
      <dc:date>2020-12-04T09:06:11Z</dc:date>
    </item>
  </channel>
</rss>

