<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP Address assignment on LAN Interface ASDM /CLI in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4581183#M1088737</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/220490"&gt;@amh4y0001&lt;/a&gt; from the CLI just run the command "ping 8.8.8.8" and ensure you get a reply.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Mar 2022 14:32:02 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2022-03-29T14:32:02Z</dc:date>
    <item>
      <title>IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579857#M1088683</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Have Cisco Firepower 1200 /ASDM and inside Ethernet 2 (inside) has 192.168.1.x IP address by default for the management purposes.&lt;BR /&gt;Question:&lt;BR /&gt;a) Is this port (Ethernet 2) and remaining other ports (Ethernet 3 - Ethernet &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; belongs to same vLAN?&lt;BR /&gt;b) Can I leave Ethernet 2 (inside) as it is with it's default IP addressing scheme, or there is some other best practices?Firepower, Cisco Adaptive Security Appliance (ASA), Other Network Security Topics&lt;BR /&gt;c) How I can use Ethernet ports (3 - &lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; as LAN ports, same vLAN (but different from what Ethernet 2 belongs to) and IP address assignment etc.?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 18:13:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579857#M1088683</guid>
      <dc:creator>amh4y0001</dc:creator>
      <dc:date>2022-03-28T18:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579861#M1088684</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/220490"&gt;@amh4y0001&lt;/a&gt;&amp;nbsp;as default the ASA interfaces are unconfigured. Generally you assign the inside interface of the ASA with a dedicated /30 or /29 routed link to the connected core switch. You then define static routes on the ASA for the local networks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So you could continue to use eth2, just define static routes via the core switch for the connected vlans.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 18:31:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579861#M1088684</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-03-28T18:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579869#M1088686</link>
      <description>&lt;P&gt;It's OK for me to leave Eth2 as it is and continue to use eth3 -eth8 as LAN configuration.&amp;nbsp;&lt;BR /&gt;Can't I have /8 /16 or /24 network?&amp;nbsp;&lt;BR /&gt;How to achieve it using GUI and CLI, suggested guide?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 18:46:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579869#M1088686</guid>
      <dc:creator>amh4y0001</dc:creator>
      <dc:date>2022-03-28T18:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579870#M1088687</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/220490"&gt;@amh4y0001&lt;/a&gt;&amp;nbsp;the ASA is a firewall, not a switch. I wouldn't use such a large network. Use a dedicated vlan between the ASA and the switch, just to route the traffic.&amp;nbsp;Use multiple vlans on the switch, let the switch do the intervlan routing, with a default route via the ASA.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 18:52:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579870#M1088687</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-03-28T18:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579885#M1088688</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;thanks for reply. Agree, that a L2 switch should exist for best practice.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have mix scenarios, one of them requires only 2 LAN ports at the same time number of devices should not increase i.e. no L2 switch should be added, rather have to use 2 LAN ports from the ASA ... is it possible?&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 19:19:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579885#M1088688</guid>
      <dc:creator>amh4y0001</dc:creator>
      <dc:date>2022-03-28T19:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579890#M1088689</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/220490"&gt;@amh4y0001&lt;/a&gt; ok understand you may not have a switch. Perhaps you could use a BVI, this was supported on the older ASA 5506 hardware, not sure if it works on your firepower 1120 hardware though. &lt;A href="https://www.petenetlive.com/KB/Article/0001422" target="_self"&gt;Here&lt;/A&gt; is an example.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternatively you could just define 2 routed interfaces on the ASA.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 19:35:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579890#M1088689</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-03-28T19:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579900#M1088691</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Do you recommend any guide or example how to&amp;nbsp;&lt;SPAN&gt;define 2 routed interfaces on the ASA?&lt;BR /&gt;As I think in my situation it looks promising (so far at least).&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 20:00:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579900#M1088691</guid>
      <dc:creator>amh4y0001</dc:creator>
      <dc:date>2022-03-28T20:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579905#M1088695</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/220490"&gt;@amh4y0001&lt;/a&gt; they are just normal interfaces, here is an example:-&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;interface gigabitethernet 0/3&amp;nbsp;nameif INSIDE_1&amp;nbsp;ip address 192.168.11.1 255.255.255.0&amp;nbsp;no shut&amp;nbsp;security-level 100interface gigabitethernet 0/4&lt;BR /&gt;&amp;nbsp;nameif INSIDE_2&lt;BR /&gt;&amp;nbsp;ip address 192.168.12.1 255.255.255.0&lt;BR /&gt;&amp;nbsp;no shut&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;!&lt;BR /&gt;object network INSIDE-1&amp;nbsp;subnet 192.168.11.0 255.255.255.0&amp;nbsp;nat (inside_1,outside) dynamic interfaceobject network INSIDE-2&lt;BR /&gt; subnet 192.168.12.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;nat (inside_2,outside) dynamic interface&lt;/PRE&gt;
&lt;P&gt;Just plug in the endpoints to the interfaces, assign an IP address in the correct network range.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 20:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579905#M1088695</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-03-28T20:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579913#M1088697</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;I think that would be sufficient for my current task, thanks again for prompt reply and suggestions.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 20:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4579913#M1088697</guid>
      <dc:creator>amh4y0001</dc:creator>
      <dc:date>2022-03-28T20:14:46Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4580810#M1088719</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;In FP1200 ASA, is it NOT possible to have two ports in the same network (without having L2 switch).&lt;/P&gt;&lt;P&gt;In the above configuration, I am able to configure the interfaces as per your suggestion but:&lt;/P&gt;&lt;P&gt;1. Internet is not available when I connect end-point to Ethernet 3 and Eth 4.&lt;/P&gt;&lt;P&gt;2. I cannot ping from 192.168.11.x network to 192.168.12.x network (this is why I asked if it's possible to have two interface belonging to same network ...).&lt;/P&gt;&lt;P&gt;Note: Ethernet1 is connected to WAN and have assigned static IP address with security level 100, see screenshot, if that could explain why Internet is not available on LAN.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts would be appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 12:50:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4580810#M1088719</guid>
      <dc:creator>amh4y0001</dc:creator>
      <dc:date>2022-03-29T12:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4580833#M1088720</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/220490"&gt;@amh4y0001&lt;/a&gt; well ideally you'd use a switch but you can configure the command &lt;STRONG&gt;same-security-traffic permit&amp;nbsp;inter-interface.&lt;/STRONG&gt;&amp;nbsp;This command allows traffic to enter an interface of certain security level and then exit from another interface of the same security level. Therefore ensure both interfaces are configured with the same security level.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You'd have to provide your nat configuration to determine why you cannot access the internet.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 12:51:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4580833#M1088720</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-03-29T12:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4580857#M1088721</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Thanks, I have not configured NAT configuration other than you provided as below:&lt;/P&gt;&lt;PRE&gt;nat (inside_2,outside) &lt;/PRE&gt;&lt;PRE&gt;dynamic interface&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 12:58:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4580857#M1088721</guid>
      <dc:creator>amh4y0001</dc:creator>
      <dc:date>2022-03-29T12:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4580866#M1088722</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/220490"&gt;@amh4y0001&lt;/a&gt; please provide the output of "show nat detail" and "show run interfaces"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 12:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4580866#M1088722</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-03-29T12:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4580905#M1088723</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;, thanks&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ciscoasa# show nat detail&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Auto NAT Policies (Section 2)&lt;BR /&gt;1 (Site-A_LAN-P3) to (outside) source dynamic Site-A_LAN-P3 interface&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 192.168.11.0/24, Translated: X.Y.Z.40/28&lt;/P&gt;&lt;P&gt;2 (Site-A_LAN-P4) to (outside) source dynamic Site-A_LAN-P4 interface&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 192.168.12.0/24, Translated: X.Y.Z.40/28&lt;/P&gt;&lt;P&gt;3 (any) to (outside) source dynamic obj_any interface&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 0.0.0.0/0, Translated: X.Y.Z.40/28&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ciscoasa# sh run interface&lt;/STRONG&gt;&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/1&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address X.Y.Z.40 255.255.255.240&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/2&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/3&lt;BR /&gt;nameif Site-A_LAN-P3&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.11.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/4&lt;BR /&gt;nameif Site-A_LAN-P4&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.12.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/5&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/6&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/7&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/8&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/9&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/10&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/11&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/12&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management1/1&lt;BR /&gt;management-only&lt;BR /&gt;nameif management&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address dhcp setroute&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 13:07:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4580905#M1088723</guid>
      <dc:creator>amh4y0001</dc:creator>
      <dc:date>2022-03-29T13:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4580926#M1088725</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/220490"&gt;@amh4y0001&lt;/a&gt; you've got zero hits on all the of that nat rules, how are you testing?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Run packet-tracer from the CLI and provide the output for review. Example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;packet-tracer input Site-A_LAN-P3 tcp 192.168.11.10 3000 8.8.8.8 80&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 13:11:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4580926#M1088725</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-03-29T13:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4581013#M1088726</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;Thanks, see below. I was trying to ping 8.8.8.8 and even open a browser to see if I have internet access.&lt;BR /&gt;Have enabled ICMP Echo requests for IPv4 on both end-points.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ciscoasa# packet-tracer input Site-A_LAN-P3 tcp 192.168.11.10 3000 8.8.8.8 80&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: Site-A_LAN-P3&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (no-route) No route to host, Drop-location: frame 0x0000562d87f3ff8e flow (NA)/NA&lt;/P&gt;&lt;P&gt;------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;ciscoasa# packet-tracer input Site-A_LAN-P4 tcp 192.168.12.10 3000 8.8.8.8 80&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: Site-A_LAN-P4&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (no-route) No route to host, Drop-location: frame 0x0000562d87f3ff8e flow (NA)/NA&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 13:29:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4581013#M1088726</guid>
      <dc:creator>amh4y0001</dc:creator>
      <dc:date>2022-03-29T13:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4581026#M1088727</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/220490"&gt;@amh4y0001&lt;/a&gt; &lt;STRONG&gt;Drop-reason: (no-route) No route to host&lt;/STRONG&gt; - do you have a default route configured?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;route outside 0 0 &amp;lt;next hop ip address&amp;gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 13:31:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4581026#M1088727</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-03-29T13:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4581116#M1088729</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;my bad, I have not configured the default route. However, I have configured now, but still no internet access.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;ciscoasa# show nat detail&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Auto NAT Policies (Section 2)&lt;BR /&gt;1 (Site-A_LAN-P3) to (outside) source dynamic Site-A_LAN-P3 interface&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 192.168.11.0/24, Translated: X.Y.Z.40/28&lt;BR /&gt;2 (Site-A_LAN-P4) to (outside) source dynamic Site-A_LAN-P4 interface&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 192.168.12.0/24, Translated: X.Y.Z.40/28&lt;BR /&gt;3 (any) to (outside) source dynamic obj_any interface&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Source - Origin: 0.0.0.0/0, Translated: X.Y.Z.40/28&lt;BR /&gt;&lt;STRONG&gt;ciscoasa# packet-tracer input Site-A_LAN-P3 tcp 192.168.11.10 3000 8.8.8.8 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: INPUT-ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Found next-hop x.y.z.33 using egress ifc outside&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: Site-A_LAN-P3&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule, Drop-location: frame 0x0000562d87f37680 flow (NA)/NA&lt;BR /&gt;&lt;STRONG&gt;ciscoasa# packet-tracer input Site-A_LAN-P4 tcp 192.168.12.10 3000 8.8.8.8 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: INPUT-ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Found next-hop x.y.z.33 using egress ifc outside&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: Site-A_LAN-P4&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule, Drop-location: frame 0x0000562d87f37680 flow (NA)/NA&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 13:57:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4581116#M1088729</guid>
      <dc:creator>amh4y0001</dc:creator>
      <dc:date>2022-03-29T13:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4581136#M1088730</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/220490"&gt;@amh4y0001&lt;/a&gt; can you provide your full configuration, remove confidential information (change public IP addresses etc).&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 13:59:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4581136#M1088730</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-03-29T13:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: IP Address assignment on LAN Interface ASDM /CLI</title>
      <link>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4581160#M1088731</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;&amp;nbsp;do you mean contents of &lt;STRONG&gt;"show running-config"?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 14:07:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ip-address-assignment-on-lan-interface-asdm-cli/m-p/4581160#M1088731</guid>
      <dc:creator>amh4y0001</dc:creator>
      <dc:date>2022-03-29T14:07:57Z</dc:date>
    </item>
  </channel>
</rss>

