<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5515 help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970620#M1106475</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/230473"&gt;@coreillycisco&lt;/a&gt; reconfigure your interface Gi0/4 and set the new default route.&lt;/P&gt;
&lt;PRE&gt;interface GigabitEthernet0/4&lt;BR /&gt;&amp;nbsp;nameif Flexential&lt;BR /&gt;&amp;nbsp;security-level 0&lt;BR /&gt;&amp;nbsp;ip address 72.15.233.&lt;STRONG&gt;228&lt;/STRONG&gt; 255.255.255.248 &lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;route Flexential 0 0 72.15.233.225&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;Remove you other default route via the incorrect next hop.&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 03 Dec 2023 17:56:31 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2023-12-03T17:56:31Z</dc:date>
    <item>
      <title>ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970415#M1106447</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Moved cisco firewall to new location and now cannot connect to the VPN, Does anyone know how to fix this issue? In down state now. I still have to clean configs, but wanted to get this in place. So I moved the firewall from Atlanta Georgia to Jacksonville Florida into a Colo. I switched IP addresses and still cannot connect to VPN. I am new to this and not sure what I am doing.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Dec 2023 23:51:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970415#M1106447</guid>
      <dc:creator>coreillycisco</dc:creator>
      <dc:date>2023-12-02T23:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970417#M1106448</link>
      <description>&lt;P&gt;Vpn s2s or anyconnect ?&lt;/P&gt;
&lt;P&gt;Can you share config?&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 02 Dec 2023 23:53:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970417#M1106448</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-12-02T23:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970418#M1106449</link>
      <description>&lt;P&gt;Anyconnect. Here is the running config. Still messy but I will clean it up.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Dec 2023 23:59:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970418#M1106449</guid>
      <dc:creator>coreillycisco</dc:creator>
      <dc:date>2023-12-02T23:59:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970424#M1106451</link>
      <description>&lt;P&gt;You have vti and ipsec vpn' many command lines you have.&lt;/P&gt;
&lt;P&gt;But let start from basic&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you check reachability' since I think public IP of outside interface change?&lt;/P&gt;
&lt;P&gt;Do you modify peer config to match your IP change?&lt;/P&gt;
&lt;P&gt;Try clear crypto (for ipsec s2s vpn)&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 01:08:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970424#M1106451</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-12-03T01:08:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970425#M1106452</link>
      <description>&lt;P&gt;I can ping the IP 72.15.233.225. I do not know where peer config is. I am using ASDM. How do I clear crypto with ASDM?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 01:17:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970425#M1106452</guid>
      <dc:creator>coreillycisco</dc:creator>
      <dc:date>2023-12-03T01:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970427#M1106453</link>
      <description>&lt;P&gt;In the ASDM&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Go to Monitoring, then select VPN from the list of Interfaces&lt;/LI&gt;
&lt;LI&gt;Then expand VPN statistics and click on Sessions.&lt;/LI&gt;
&lt;LI&gt;Choose the type of tunnel you're looking for from the drop-down at the right (IPSEC Site-To-Site for example.)&lt;/LI&gt;
&lt;LI&gt;Click on the tunnel you wish to reset and then click Logout in order to reset the tunnel.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Sun, 03 Dec 2023 01:31:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970427#M1106453</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-12-03T01:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970429#M1106454</link>
      <description>&lt;P&gt;When doing so there are no sessions there. See attachment. Is this an issue?&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 01:37:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970429#M1106454</guid>
      <dc:creator>coreillycisco</dc:creator>
      <dc:date>2023-12-03T01:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970568#M1106459</link>
      <description>&lt;P&gt;Tunnel Manager has failed to establish an L2L SA. All configured IKE versions failed to establish the tunnel.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 15:25:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970568#M1106459</guid>
      <dc:creator>coreillycisco</dc:creator>
      <dc:date>2023-12-03T15:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970569#M1106460</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/230473"&gt;@coreillycisco&lt;/a&gt; you do not appear to have a default route via your outside interface "Flexential" in your configuration and the error from your debugs below confirms it failed to find the next hop address:&lt;/P&gt;
&lt;PRE class="bp-text bp-text-plain hljs bp-is-scrollable" tabindex="0"&gt;&lt;CODE class="bp-text-code txt"&gt;6|Dec 03 2023|10:19:27|110003|Ifc||40.70.3.44|62465|&lt;STRONG&gt;Routing failed to locate next hop&lt;/STRONG&gt; for udp from NP Identity Ifc:72.15.233.225/62465 to Flexential:40.70.3.44/62465
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;Create a default route, example:-&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;route Flexential 0 0 &amp;lt;next hop ip address&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 15:31:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970569#M1106460</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-12-03T15:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970582#M1106461</link>
      <description>&lt;P&gt;I am new to cisco and using what they have. They use ASDM. And I am not sure what next hop ip i need to be using. The ones I try say cannot be routed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 16:21:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970582#M1106461</guid>
      <dc:creator>coreillycisco</dc:creator>
      <dc:date>2023-12-03T16:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970584#M1106462</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/230473"&gt;@coreillycisco&lt;/a&gt; you need to use the IP address of the upstream router (your ISP) as the next hop. The only usable IP addresses in the public network of the Flexential interface are - 72.15.233.225 - 72.15.233.230, so it's either .226, .227, .228, .229 or .230 &lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 16:26:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970584#M1106462</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-12-03T16:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970586#M1106463</link>
      <description>&lt;P&gt;Would this be to my Internal subnet? Such as: route Flexential 0.0.0.0 0.0.0.0 10.1.3.1 1&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 16:30:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970586#M1106463</guid>
      <dc:creator>coreillycisco</dc:creator>
      <dc:date>2023-12-03T16:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970590#M1106464</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/230473"&gt;@coreillycisco&lt;/a&gt; no, 10.1.3.1 1 isn't even in the same network as the Flexential interface (Gi0/4) .You need a default route to the internet via the Flexential interface - which is in the 72.15.233.225/28 network, therefore the next hop is either .226, .227, .228, .229 or .230. &lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 16:34:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970590#M1106464</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-12-03T16:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970591#M1106465</link>
      <description>&lt;P&gt;Ok, Yeah I see what you are saying. Been a long week. I will add that route.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 16:35:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970591#M1106465</guid>
      <dc:creator>coreillycisco</dc:creator>
      <dc:date>2023-12-03T16:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970593#M1106466</link>
      <description>&lt;P&gt;So I now have the route as:&amp;nbsp;route Flexential 0.0.0.0 0.0.0.0 72.15.233.226 1&lt;/P&gt;&lt;P&gt;Is there somewhere else I have to change for anyconnect?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 16:43:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970593#M1106466</guid>
      <dc:creator>coreillycisco</dc:creator>
      <dc:date>2023-12-03T16:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970597#M1106467</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/230473"&gt;@coreillycisco&lt;/a&gt; are you sure it's .226? Can you ping it from the ASA itself? I cannot ping that IP address but I can ping .227&lt;/P&gt;
&lt;P&gt;Have you tried accessing the internet from the &lt;U&gt;ASA&lt;/U&gt;? Ping something (i.e. 8.8.8.8), does it work? If not AnyConnect will not work, nor will anything else.&lt;/P&gt;
&lt;P&gt;If AnyConnect was pre-configured to use a DNS hostname and that resolved to the old IP address (the one you changed) you will also need to update the DNS entry in the public DNS or use the IP address of the ASA (72.15.233.225) instead - you will get a certificate error though.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 16:52:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970597#M1106467</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-12-03T16:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970602#M1106468</link>
      <description>&lt;P&gt;Yeah i changed that in our DNS. I can ping .226, but .227 is: Reply from 72.15.233.227: Destination net unreachable.&lt;/P&gt;&lt;P&gt;&amp;gt;ping 72.15.233.227&lt;/P&gt;&lt;P&gt;Pinging 72.15.233.227 with 32 bytes of data:&lt;BR /&gt;Reply from 72.15.233.227: Destination net unreachable.&lt;BR /&gt;Reply from 72.15.233.227: Destination net unreachable.&lt;BR /&gt;Reply from 72.15.233.227: Destination net unreachable.&lt;BR /&gt;Reply from 72.15.233.227: Destination net unreachable.&lt;/P&gt;&lt;P&gt;Ping statistics for 72.15.233.227:&lt;BR /&gt;Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),&lt;/P&gt;&lt;P&gt;&amp;gt;ping 72.15.233.226&lt;/P&gt;&lt;P&gt;Pinging 72.15.233.226 with 32 bytes of data:&lt;BR /&gt;Reply from 72.15.233.226: bytes=32 time=317ms TTL=240&lt;BR /&gt;Reply from 72.15.233.226: bytes=32 time=22ms TTL=240&lt;BR /&gt;Reply from 72.15.233.226: bytes=32 time=22ms TTL=240&lt;BR /&gt;Reply from 72.15.233.226: bytes=32 time=21ms TTL=240&lt;/P&gt;&lt;P&gt;Ping statistics for 72.15.233.226:&lt;BR /&gt;Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),&lt;BR /&gt;Approximate round trip times in milli-seconds:&lt;BR /&gt;Minimum = 21ms, Maximum = 317ms, Average = 95ms&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 17:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970602#M1106468</guid>
      <dc:creator>coreillycisco</dc:creator>
      <dc:date>2023-12-03T17:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970604#M1106469</link>
      <description>&lt;P&gt;Oh sorry. Ping from ASA is timing out.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 17:10:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970604#M1106469</guid>
      <dc:creator>coreillycisco</dc:creator>
      <dc:date>2023-12-03T17:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970607#M1106470</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/230473"&gt;@coreillycisco&lt;/a&gt; I assume you pinged an IP address such as 8.8.8.8 and not a DNS name? If you cannot ping from the ASA to an IP address on the internet then routing is still not working. Run a ping and traceroute from the ASA to 8.8.8.8 and provide the output.&lt;/P&gt;
&lt;P&gt;Confirm with your ISP what their router IP address is.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 17:17:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970607#M1106470</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-12-03T17:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5515 help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970611#M1106471</link>
      <description>&lt;P&gt;Yes, I pinged 8.8.8.8. Here is the traceroute from the ASA:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Dec 2023 17:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5515-help/m-p/4970611#M1106471</guid>
      <dc:creator>coreillycisco</dc:creator>
      <dc:date>2023-12-03T17:38:17Z</dc:date>
    </item>
  </channel>
</rss>

