<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA: no internet connection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644619#M1091618</link>
    <description>&lt;P&gt;I noticed from my monitoring that PRTG flags as the link up.&lt;BR /&gt;Apparently the ASA is not going out through the backup link as the main one is active, even though I force the ping through the backup interface.&lt;BR /&gt;I'll check a good time to take the main link down to confirm if the backup will take over by the ASA.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jul 2022 21:33:16 GMT</pubDate>
    <dc:creator>patricia.quintao</dc:creator>
    <dc:date>2022-07-05T21:33:16Z</dc:date>
    <item>
      <title>ASA: no internet connection</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644128#M1091585</link>
      <description>&lt;P&gt;I have a problem that I don't know what else to do. Can you help me?&lt;/P&gt;&lt;P&gt;In my environment I have 2 ISP links, the main one and redundancy.&lt;BR /&gt;I changed the operator of the redundancy link.&lt;BR /&gt;I connected the router to the ASA, deletes the old routes from this interface, changed the name, IP and mask. Then I created the static route again with the new gateway.&lt;/P&gt;&lt;P&gt;Through ASDM &amp;gt; Tools &amp;gt; Ping, on this ISP's interface I can ping the router, but I don't have an output for 8.8.8.8.&lt;BR /&gt;I put a notebook directly on the router and the ping is ok, but apparently the ASA is not coming out.&lt;/P&gt;&lt;P&gt;The NAT rules I didn't change because there was no change. But the thing is, not even the ASA itself is going out through this ISP&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 14:54:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644128#M1091585</guid>
      <dc:creator>patricia.quintao</dc:creator>
      <dc:date>2022-07-05T14:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: no internet connection</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644132#M1091586</link>
      <description>&lt;P&gt;if you changed interface names, IP addresses too, better check NAT configurations again.&lt;/P&gt;
&lt;P&gt;also share some screen captures of routing and NAT to get an idea.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 15:00:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644132#M1091586</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2022-07-05T15:00:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: no internet connection</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644136#M1091588</link>
      <description>&lt;P&gt;friend&amp;nbsp;&lt;BR /&gt;after you check the ACL and NAT "in NAT please add route-lockup" if not success then&amp;nbsp;&lt;BR /&gt;you need floating timeout command to add, please see below link.&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113592-udp-traffic-fails-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113592-udp-traffic-fails-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 15:02:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644136#M1091588</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-07-05T15:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: no internet connection</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644242#M1091590</link>
      <description>&lt;P&gt;I redid the NAT rule, but still no success.&lt;BR /&gt;I only have one route using this interface.&lt;BR /&gt;I am attaching the two images&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 15:53:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644242#M1091590</guid>
      <dc:creator>patricia.quintao</dc:creator>
      <dc:date>2022-07-05T15:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: no internet connection</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644275#M1091591</link>
      <description>&lt;P&gt;your captures seems ok. but i noticed 2 points.&lt;/P&gt;
&lt;P&gt;1. your route priority is 100. check if you have any other default routes with less priority than 100. if so you need to make sure primary ISP have lower priority than backup ISP.&lt;/P&gt;
&lt;P&gt;2. there is a more NAT statements in background. check if your packet hits top NATs before hit correct one.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also use packet tracer option to simulate traffic and see whether traffic is blocking by ALC or any other step.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 16:03:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644275#M1091591</guid>
      <dc:creator>Kasun Bandara</dc:creator>
      <dc:date>2022-07-05T16:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: no internet connection</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644278#M1091592</link>
      <description>&lt;P&gt;How would I check the ACL?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My case was with the backup link, so the route metric was the highest.&lt;BR /&gt;From what I understand in that link you shared, it would be for the lowest metric routes.. isn't that it?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 16:05:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644278#M1091592</guid>
      <dc:creator>patricia.quintao</dc:creator>
      <dc:date>2022-07-05T16:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: no internet connection</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644313#M1091593</link>
      <description>&lt;P&gt;as mention above since the config of route is OK still you need NAT&amp;nbsp;&lt;BR /&gt;please select "object network" NAT rule&amp;nbsp;&lt;BR /&gt;and then config dynamic NAT&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NAT.jpg" style="width: 800px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/155197i9FDD7C30447FD3CF/image-size/large?v=v2&amp;amp;px=999" role="button" title="NAT.jpg" alt="NAT.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 16:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644313#M1091593</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-07-05T16:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: no internet connection</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644384#M1091600</link>
      <description>&lt;P&gt;Can you share cli config?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 17:33:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644384#M1091600</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-07-05T17:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: no internet connection</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644492#M1091601</link>
      <description>&lt;P&gt;I redid the NAT rule the way you instructed but nothing changed.&lt;BR /&gt;The ASA shouldn't be able to PING it out even without the NAT rule (if it was a NAT problem)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;using packet capture for the interface I can see some requests. I contacted the ISP operator and they manage to ping the IP I put. So it looks like the configuration from outside to ASA is ok.&lt;/P&gt;&lt;P&gt;It seems to me that something was tied up but I can't identify what it is.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 19:01:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644492#M1091601</guid>
      <dc:creator>patricia.quintao</dc:creator>
      <dc:date>2022-07-05T19:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: no internet connection</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644494#M1091602</link>
      <description>&lt;P&gt;what would be the best way to do this?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 19:02:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644494#M1091602</guid>
      <dc:creator>patricia.quintao</dc:creator>
      <dc:date>2022-07-05T19:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: no internet connection</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644530#M1091612</link>
      <description>&lt;P&gt;you need talent to ASA to access and cli&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also&lt;/P&gt;&lt;P&gt;this link helpful for you&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=_0D8DlkdRRA" target="_blank"&gt;https://www.youtube.com/watch?v=_0D8DlkdRRA&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 20:09:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644530#M1091612</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-07-05T20:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: no internet connection</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644619#M1091618</link>
      <description>&lt;P&gt;I noticed from my monitoring that PRTG flags as the link up.&lt;BR /&gt;Apparently the ASA is not going out through the backup link as the main one is active, even though I force the ping through the backup interface.&lt;BR /&gt;I'll check a good time to take the main link down to confirm if the backup will take over by the ASA.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 21:33:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644619#M1091618</guid>
      <dc:creator>patricia.quintao</dc:creator>
      <dc:date>2022-07-05T21:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: no internet connection</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644635#M1091621</link>
      <description>&lt;P&gt;Yes but for TEST only change the metric of primary route to be higher than the backup route.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 22:09:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4644635#M1091621</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-07-05T22:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA: no internet connection</title>
      <link>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4645297#M1091655</link>
      <description>&lt;P&gt;Confirmed. The ASA does not communicate over another internet interface when the main one has a lower metric. That's why the ping test through the backup interface didn't work.&lt;BR /&gt;Thanks for the support.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 18:17:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-no-internet-connection/m-p/4645297#M1091655</guid>
      <dc:creator>patricia.quintao</dc:creator>
      <dc:date>2022-07-06T18:17:15Z</dc:date>
    </item>
  </channel>
</rss>

