<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tracert and Ping to 8.8.8.8 works but cant access the Internet in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205846#M1116410</link>
    <description>&lt;P&gt;Please help. I have an ASA 5506-x connected to a 3750 swich. I cant ping 8.8.8.8 or anything external from the switch. I cant ping the other vlan subnets either ( the ASA has the route back to these). However, I can ping 8.8.8.8 and tracert successfully from client connected to the switch, but cant access the internet. What could be the problem?&lt;/P&gt;&lt;P&gt;ASA CONFIG&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/1&lt;BR /&gt;nameif OUTSIDE&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 154.113.70.206 255.255.255.252&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;nameif INSIDE&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.100.1 255.255.255.252&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/4&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/5&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/6&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/7&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/8&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management1/1&lt;BR /&gt;management-only&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;dns domain-lookup OUTSIDE&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;name-server 8.8.8.8&lt;BR /&gt;name-server 41.75.80.84&lt;BR /&gt;name-server 8.8.4.4&lt;BR /&gt;domain-name gaclos.local&lt;BR /&gt;object network obj_DATA_128&lt;BR /&gt;subnet 192.168.200.128 255.255.255.128&lt;BR /&gt;description DATA network&lt;BR /&gt;object network obj_VOICE_32&lt;BR /&gt;subnet 192.168.200.32 255.255.255.224&lt;BR /&gt;object network obj_PSEC_16&lt;BR /&gt;subnet 192.168.200.16 255.255.255.240&lt;BR /&gt;description PSEC network&lt;BR /&gt;object network obj_CUCME_0&lt;BR /&gt;subnet 192.168.200.0 255.255.255.248&lt;BR /&gt;description CUCME&lt;BR /&gt;object network obj_APAPA_44&lt;BR /&gt;subnet 10.251.44.0 255.255.255.0&lt;BR /&gt;description Apapa Mgmt&lt;BR /&gt;object network obj_APAPA_45&lt;BR /&gt;subnet 10.251.45.0 255.255.255.0&lt;BR /&gt;description Apapa CUCME&lt;BR /&gt;object network obj_APAPA_46&lt;BR /&gt;subnet 10.251.46.0 255.255.255.0&lt;BR /&gt;object network obj_APAPA_47&lt;BR /&gt;subnet 10.251.47.0 255.255.255.0&lt;BR /&gt;description Apapa WiFi&lt;BR /&gt;object network obj_APAPA_48&lt;BR /&gt;subnet 10.251.48.0 255.255.255.0&lt;BR /&gt;description Apapa LAN&lt;BR /&gt;object network obj_APAPA_49&lt;BR /&gt;subnet 10.251.49.0 255.255.255.0&lt;BR /&gt;description Apapa Voice&lt;BR /&gt;object network obj_APAPA_50&lt;BR /&gt;subnet 10.251.50.0 255.255.255.0&lt;BR /&gt;description Apapa Servers&lt;BR /&gt;object-group network GAC_PHC_NETWORK&lt;BR /&gt;description PHC_NETWORK&lt;BR /&gt;network-object 192.168.100.0 255.255.255.252&lt;BR /&gt;network-object object obj_CUCME_0&lt;BR /&gt;network-object object obj_DATA_128&lt;BR /&gt;network-object object obj_PSEC_16&lt;BR /&gt;network-object object obj_VOICE_32&lt;BR /&gt;object-group network GAC_APAPA_NETWORK&lt;BR /&gt;description APAPA Network&lt;BR /&gt;network-object object obj_APAPA_44&lt;BR /&gt;network-object object obj_APAPA_45&lt;BR /&gt;network-object object obj_APAPA_46&lt;BR /&gt;network-object object obj_APAPA_47&lt;BR /&gt;network-object object obj_APAPA_48&lt;BR /&gt;network-object object obj_APAPA_49&lt;BR /&gt;network-object object obj_APAPA_50&lt;BR /&gt;object-group service TCPUDP tcp&lt;BR /&gt;port-object eq 587&lt;BR /&gt;access-list OUTSIDE_cryptomap extended permit ip object-group GAC_PHC_NETWORK object-group GAC_APAPA_NETWORK&lt;BR /&gt;access-list INSIDE_access_in extended permit tcp any any eq domain&lt;BR /&gt;access-list INSIDE_access_in extended permit icmp any any&lt;BR /&gt;access-list INSIDE_access_in extended permit tcp any any eq www&lt;BR /&gt;access-list INSIDE_access_in extended permit tcp any any eq https&lt;BR /&gt;access-list INSIDE_access_in extended permit tcp any any eq 587&lt;BR /&gt;access-list INSIDE_access_in extended permit udp any any eq isakmp&lt;BR /&gt;access-list INSIDE_access_in extended permit tcp any any eq pop3&lt;BR /&gt;access-list OUTSIDE_access_in extended permit icmp any any&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any any&lt;BR /&gt;access-list INSIDE extended permit ip any any&lt;BR /&gt;pager lines 24&lt;BR /&gt;mtu OUTSIDE 1500&lt;BR /&gt;mtu INSIDE 1500&lt;BR /&gt;no failover&lt;BR /&gt;no monitor-interface service-module&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;arp rate-limit 16384&lt;BR /&gt;nat (INSIDE,OUTSIDE) source static GAC_PHC_NETWORK GAC_PHC_NETWORK destination static GAC_APAPA_NETWORK GAC_APAPA_NETWORK no-proxy-arp route-lookup&lt;BR /&gt;!&lt;BR /&gt;object network obj_DATA_128&lt;BR /&gt;nat (any,OUTSIDE) dynamic interface&lt;BR /&gt;object network obj_PSEC_16&lt;BR /&gt;nat (any,OUTSIDE) dynamic interface&lt;BR /&gt;access-group OUTSIDE_access_in in interface OUTSIDE&lt;BR /&gt;access-group INSIDE_access_in in interface INSIDE&lt;BR /&gt;route OUTSIDE 0.0.0.0 0.0.0.0 154.113.70.205 1&lt;BR /&gt;route INSIDE 192.168.200.0 255.255.255.248 192.168.100.2 1&lt;BR /&gt;route INSIDE 192.168.200.16 255.255.255.240 192.168.100.2 1&lt;BR /&gt;route INSIDE 192.168.200.32 255.255.255.224 192.168.100.2 1&lt;BR /&gt;route INSIDE 192.168.200.128 255.255.255.128 192.168.100.2 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;timeout conn-holddown 0:00:15&lt;BR /&gt;timeout igp stale-route 0:01:10&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;aaa authentication enable console LOCAL&lt;BR /&gt;aaa authentication http console LOCAL&lt;BR /&gt;aaa authentication serial console LOCAL&lt;BR /&gt;aaa authentication login-history&lt;BR /&gt;http server enable 8080&lt;BR /&gt;http 0.0.0.0 0.0.0.0 OUTSIDE&lt;BR /&gt;http 0.0.0.0 0.0.0.0 INSIDE&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;service sw-reset-button&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS esp-aes esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS esp-aes esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS esp-aes-192 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS esp-aes-192 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS esp-aes-256 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS esp-aes-256 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS esp-3des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS esp-3des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS esp-des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS esp-des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES256&lt;BR /&gt;protocol esp encryption aes-256&lt;BR /&gt;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES192&lt;BR /&gt;protocol esp encryption aes-192&lt;BR /&gt;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES&lt;BR /&gt;protocol esp encryption aes&lt;BR /&gt;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal 3DES&lt;BR /&gt;protocol esp encryption 3des&lt;BR /&gt;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal DES&lt;BR /&gt;protocol esp encryption des&lt;BR /&gt;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto map OUTSIDE_map 1 match address OUTSIDE_cryptomap&lt;BR /&gt;crypto map OUTSIDE_map 1 set peer 197.253.33.66&lt;BR /&gt;crypto map OUTSIDE_map 1 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map OUTSIDE_map interface OUTSIDE&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ikev2 policy 1&lt;BR /&gt;encryption aes-256&lt;BR /&gt;integrity sha&lt;BR /&gt;group 5 2&lt;BR /&gt;prf sha&lt;BR /&gt;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 10&lt;BR /&gt;encryption aes-192&lt;BR /&gt;integrity sha&lt;BR /&gt;group 5 2&lt;BR /&gt;prf sha&lt;BR /&gt;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 20&lt;BR /&gt;encryption aes&lt;BR /&gt;integrity sha&lt;BR /&gt;group 5 2&lt;BR /&gt;prf sha&lt;BR /&gt;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 30&lt;BR /&gt;encryption 3des&lt;BR /&gt;integrity sha&lt;BR /&gt;group 5 2&lt;BR /&gt;prf sha&lt;BR /&gt;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 40&lt;BR /&gt;encryption des&lt;BR /&gt;integrity sha&lt;BR /&gt;group 5 2&lt;BR /&gt;prf sha&lt;BR /&gt;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 enable OUTSIDE&lt;BR /&gt;crypto ikev1 enable OUTSIDE&lt;BR /&gt;crypto ikev1 policy 10&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption aes-256&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 20&lt;BR /&gt;authentication rsa-sig&lt;BR /&gt;encryption aes-256&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 40&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption aes-192&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 50&lt;BR /&gt;authentication rsa-sig&lt;BR /&gt;encryption aes-192&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 70&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption aes&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 80&lt;BR /&gt;authentication rsa-sig&lt;BR /&gt;encryption aes&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 100&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption 3des&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 110&lt;BR /&gt;authentication rsa-sig&lt;BR /&gt;encryption 3des&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 130&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption des&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 140&lt;BR /&gt;authentication rsa-sig&lt;BR /&gt;encryption des&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 OUTSIDE&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 INSIDE&lt;BR /&gt;ssh timeout 15&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;ssl cipher default custom "AES256-SHA:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA"&lt;BR /&gt;ssl cipher tlsv1 custom "AES256-SHA:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA"&lt;BR /&gt;ssl cipher dtlsv1 custom "AES256-SHA:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA"&lt;BR /&gt;group-policy GroupPolicy_197.253.33.66 internal&lt;BR /&gt;group-policy GroupPolicy_197.253.33.66 attributes&lt;BR /&gt;vpn-tunnel-protocol ikev1&lt;BR /&gt;group-policy GroupPolicy_41.75.82.94 internal&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;username mamoussou password $sha512$5000$+0/X7IbvSP+ZET/aSSnjXg==$2YHiAXAsFLlOsrbIte63lA== pbkdf2 privilege 15&lt;BR /&gt;tunnel-group 197.253.33.66 type ipsec-l2l&lt;BR /&gt;tunnel-group 197.253.33.66 general-attributes&lt;BR /&gt;default-group-policy GroupPolicy_197.253.33.66&lt;BR /&gt;tunnel-group 197.253.33.66 ipsec-attributes&lt;BR /&gt;ikev1 pre-shared-key *****&lt;BR /&gt;ikev2 remote-authentication pre-shared-key *****&lt;BR /&gt;ikev2 local-authentication pre-shared-key *****&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;no tcp-inspection&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect ftp&lt;BR /&gt;inspect h323 h225&lt;BR /&gt;inspect h323 ras&lt;BR /&gt;inspect ip-options&lt;BR /&gt;inspect netbios&lt;BR /&gt;inspect rsh&lt;BR /&gt;inspect rtsp&lt;BR /&gt;inspect skinny&lt;BR /&gt;inspect esmtp&lt;BR /&gt;inspect sqlnet&lt;BR /&gt;inspect sunrpc&lt;BR /&gt;inspect tftp&lt;BR /&gt;inspect sip&lt;BR /&gt;inspect xdmcp&lt;BR /&gt;inspect dns preset_dns_map&lt;BR /&gt;inspect icmp&lt;BR /&gt;policy-map type inspect dns migrated_dns_map_2&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;no tcp-inspection&lt;BR /&gt;policy-map type inspect dns migrated_dns_map_1&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;no tcp-inspection&lt;/P&gt;&lt;P&gt;ROUTES&lt;/P&gt;&lt;P&gt;nat (INSIDE,OUTSIDE) source static GAC_PHC_NETWORK GAC_PHC_NETWORK destination static GAC_APAPA_NETWORK GAC_APAPA_NETWORK no-proxy-arp route-lookup&lt;BR /&gt;route OUTSIDE 0.0.0.0 0.0.0.0 154.113.70.205 1&lt;BR /&gt;route INSIDE 192.168.200.0 255.255.255.248 192.168.100.2 1&lt;BR /&gt;route INSIDE 192.168.200.16 255.255.255.240 192.168.100.2 1&lt;BR /&gt;route INSIDE 192.168.200.32 255.255.255.224 192.168.100.2 1&lt;BR /&gt;route INSIDE 192.168.200.128 255.255.255.128 192.168.100.2 1&lt;BR /&gt;timeout igp stale-route 0:01:10&lt;/P&gt;&lt;P&gt;NAT and ACLs&lt;/P&gt;&lt;P&gt;sh nat&lt;BR /&gt;Manual NAT Policies (Section 1)&lt;BR /&gt;1 (INSIDE) to (OUTSIDE) source static GAC_PHC_NETWORK GAC_PHC_NETWORK destination static GAC_APAPA_NETWORK GAC_APAPA_NETWORK no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 8, untranslate_hits = 8&lt;/P&gt;&lt;P&gt;Auto NAT Policies (Section 2)&lt;BR /&gt;1 (any) to (OUTSIDE) source dynamic obj_PSEC_16 interface&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;2 (any) to (OUTSIDE) source dynamic obj_DATA_128 interface&lt;BR /&gt;translate_hits = 15217, untranslate_hits = 1081&lt;BR /&gt;&lt;BR /&gt;# sh access-list&lt;BR /&gt;access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 4096)&lt;BR /&gt;alert-interval 300&lt;BR /&gt;access-list OUTSIDE_cryptomap; 35 elements; name hash: 0x7d0700c2&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip object-group GAC_PHC_NETWORK object-group GAC_APAPA_NETWORK (hitcnt=3) 0xb50a5623&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.100.0 255.255.255.252 10.251.44.0 255.255.255.0 (hitcnt=0) 0xfdc1b3c4&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.100.0 255.255.255.252 10.251.45.0 255.255.255.0 (hitcnt=0) 0xe23249c8&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.100.0 255.255.255.252 10.251.46.0 255.255.255.0 (hitcnt=0) 0x1e0dfffc&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.100.0 255.255.255.252 10.251.47.0 255.255.255.0 (hitcnt=0) 0x4e8676cf&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.100.0 255.255.255.252 10.251.48.0 255.255.255.0 (hitcnt=0) 0xbd8d6abd&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.100.0 255.255.255.252 10.251.49.0 255.255.255.0 (hitcnt=0) 0xb361e7d4&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.100.0 255.255.255.252 10.251.50.0 255.255.255.0 (hitcnt=0) 0xa4061b7b&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.0 255.255.255.248 10.251.44.0 255.255.255.0 (hitcnt=0) 0xea33b872&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.0 255.255.255.248 10.251.45.0 255.255.255.0 (hitcnt=0) 0xc7e8b504&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.0 255.255.255.248 10.251.46.0 255.255.255.0 (hitcnt=0) 0xffbf71e6&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.0 255.255.255.248 10.251.47.0 255.255.255.0 (hitcnt=0) 0x95338c3e&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.0 255.255.255.248 10.251.48.0 255.255.255.0 (hitcnt=0) 0x73eca7c5&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.0 255.255.255.248 10.251.49.0 255.255.255.0 (hitcnt=0) 0x1bdc78e8&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.0 255.255.255.248 10.251.50.0 255.255.255.0 (hitcnt=0) 0x9d5e40a3&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.128 255.255.255.128 10.251.44.0 255.255.255.0 (hitcnt=0) 0x6b57bb41&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.128 255.255.255.128 10.251.45.0 255.255.255.0 (hitcnt=0) 0x2a48cff0&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.128 255.255.255.128 10.251.46.0 255.255.255.0 (hitcnt=0) 0x346c1302&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.128 255.255.255.128 10.251.47.0 255.255.255.0 (hitcnt=15) 0x62fabae7&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.128 255.255.255.128 10.251.48.0 255.255.255.0 (hitcnt=0) 0x3da20527&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.128 255.255.255.128 10.251.49.0 255.255.255.0 (hitcnt=0) 0x6594c1b1&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.128 255.255.255.128 10.251.50.0 255.255.255.0 (hitcnt=0) 0x84c8e267&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.16 255.255.255.240 10.251.44.0 255.255.255.0 (hitcnt=0) 0x1ffd5f19&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.16 255.255.255.240 10.251.45.0 255.255.255.0 (hitcnt=0) 0xd79459ed&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.16 255.255.255.240 10.251.46.0 255.255.255.0 (hitcnt=0) 0x5991a0a3&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.16 255.255.255.240 10.251.47.0 255.255.255.0 (hitcnt=0) 0x392f79b2&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.16 255.255.255.240 10.251.48.0 255.255.255.0 (hitcnt=0) 0xf4de6d67&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.16 255.255.255.240 10.251.49.0 255.255.255.0 (hitcnt=0) 0x8befe92a&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.16 255.255.255.240 10.251.50.0 255.255.255.0 (hitcnt=0) 0x25c35164&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.32 255.255.255.224 10.251.44.0 255.255.255.0 (hitcnt=0) 0xc553a3ed&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.32 255.255.255.224 10.251.45.0 255.255.255.0 (hitcnt=0) 0x2d015abb&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.32 255.255.255.224 10.251.46.0 255.255.255.0 (hitcnt=0) 0x6de59669&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.32 255.255.255.224 10.251.47.0 255.255.255.0 (hitcnt=0) 0xd4fa270a&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.32 255.255.255.224 10.251.48.0 255.255.255.0 (hitcnt=0) 0x244acbba&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.32 255.255.255.224 10.251.49.0 255.255.255.0 (hitcnt=0) 0xf64c5a30&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.32 255.255.255.224 10.251.50.0 255.255.255.0 (hitcnt=0) 0x164acdcd&lt;BR /&gt;access-list INSIDE_access_in; 7 elements; name hash: 0xb71cec1d&lt;BR /&gt;access-list INSIDE_access_in line 1 extended permit tcp any any eq domain (hitcnt=10410) 0x6463e52f&lt;BR /&gt;access-list INSIDE_access_in line 2 extended permit icmp any any (hitcnt=1411) 0xbe2c8578&lt;BR /&gt;access-list INSIDE_access_in line 3 extended permit tcp any any eq www (hitcnt=179) 0xae7df53e&lt;BR /&gt;access-list INSIDE_access_in line 4 extended permit tcp any any eq https (hitcnt=3798) 0x44c047ca&lt;BR /&gt;access-list INSIDE_access_in line 5 extended permit tcp any any eq 587 (hitcnt=0) 0xefa402f4&lt;BR /&gt;access-list INSIDE_access_in line 6 extended permit udp any any eq isakmp (hitcnt=0) 0x02b7c7d8&lt;BR /&gt;access-list INSIDE_access_in line 7 extended permit tcp any any eq pop3 (hitcnt=0) 0x611278d2&lt;BR /&gt;access-list OUTSIDE_access_in; 2 elements; name hash: 0x766b1b32&lt;BR /&gt;access-list OUTSIDE_access_in line 1 extended permit icmp any any (hitcnt=108) 0x112340aa&lt;BR /&gt;access-list OUTSIDE_access_in line 2 extended permit ip any any (hitcnt=951) 0x482d024c&lt;BR /&gt;access-list INSIDE; 1 elements; name hash: 0xdedb237a&lt;BR /&gt;access-list INSIDE line 1 extended permit ip any any (hitcnt=0) 0x2a29f5f2&lt;/P&gt;&lt;P&gt;SWITCH CONFIG&lt;/P&gt;&lt;P&gt;Current configuration : 5924 bytes&lt;BR /&gt;!&lt;BR /&gt;version 12.2&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;no service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname GAC-PHC-SW1&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;enable secret 5 $1$11Wa$KoksYYu938zhv.kMZjYDd0&lt;BR /&gt;enable password N33d2kN0w#&lt;BR /&gt;!&lt;BR /&gt;username mamoussou privilege 15 password 0 mamoussou@123!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;system mtu routing 1500&lt;BR /&gt;ip routing&lt;BR /&gt;ip dhcp excluded-address 192.168.200.129 192.168.200.139&lt;BR /&gt;ip dhcp excluded-address 192.168.200.33 192.168.200.39&lt;BR /&gt;ip dhcp excluded-address 192.168.200.17 192.168.200.21&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool GAC-DATA&lt;BR /&gt;network 192.168.200.128 255.255.255.128&lt;BR /&gt;domain-name gaclos.local&lt;BR /&gt;default-router 192.168.200.129&lt;BR /&gt;dns-server 41.75.80.84 8.8.8.8&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool GAC-VOICE&lt;BR /&gt;network 192.168.200.32 255.255.255.224&lt;BR /&gt;domain-name gaclos.local&lt;BR /&gt;default-router 192.168.200.33&lt;BR /&gt;dns-server 41.75.80.84 8.8.8.8&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool GAC-PSEC&lt;BR /&gt;network 192.168.200.16 255.255.255.240&lt;BR /&gt;domain-name gaclos.local&lt;BR /&gt;default-router 192.168.200.17&lt;BR /&gt;dns-server 41.75.80.84 8.8.8.8&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki trustpoint TP-self-signed-4096251392&lt;BR /&gt;enrollment selfsigned&lt;BR /&gt;subject-name cn=IOS-Self-Signed-Certificate-4096251392&lt;BR /&gt;revocation-check none&lt;BR /&gt;rsakeypair TP-self-signed-4096251392&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki certificate chain TP-self-signed-4096251392&lt;BR /&gt;certificate self-signed 01&lt;BR /&gt;30820244 308201AD A0030201 02020101 300D0609 2A864886 F70D0101 04050030&lt;BR /&gt;31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274&lt;BR /&gt;69666963 6174652D 34303936 32353133 3932301E 170D3933 30333031 30303038&lt;BR /&gt;33375A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649&lt;BR /&gt;4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D34 30393632&lt;BR /&gt;35313339 3230819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281&lt;BR /&gt;8100A341 6B8C9394 C15A791F 54EC3D3B 05D1D8C7 059A1B20 EB17B504 86C9CD17&lt;BR /&gt;F2FDF78A 1279FDC0 8AE1FB27 36510CA3 465551EF 8ECFD28D 34F49412 F36C3332&lt;BR /&gt;55A2BBC0 9C378252 E9299A13 BD18A36F D56A0B9A 352C5089 0C20F883 E4B336D4&lt;BR /&gt;DCB5DD81 92F3B778 7FF5F3FB 8FA2A7E1 170F21B7 A9DEBA0B C72C3ED8 ABF605D9&lt;BR /&gt;4ED70203 010001A3 6C306A30 0F060355 1D130101 FF040530 030101FF 30170603&lt;BR /&gt;551D1104 10300E82 0C474143 2D504843 2D535731 2E301F06 03551D23 04183016&lt;BR /&gt;801434D0 32AF4F32 12CF6995 29122035 641FB29D 6C68301D 0603551D 0E041604&lt;BR /&gt;1434D032 AF4F3212 CF699529 12203564 1FB29D6C 68300D06 092A8648 86F70D01&lt;BR /&gt;01040500 03818100 500A61EC 4FCFEC83 1B99290C AD16F329 F9FEAAFB 8D9A4684&lt;BR /&gt;DBF9D2EE 0B463934 D86568EB F67E4073 834D04F0 CC83F211 BADDCD2C DB82BAC9&lt;BR /&gt;2984DDDD 45B0231D 553EF7A8 E79841D6 DC209DA8 4540A34F 75B993F0 AEB8ABB7&lt;BR /&gt;2EDEF3D4 D70ECA44 E2D1549C 5F505F1D 1DED7725 FB8F3A43 E79D0D84 A39DE80E&lt;BR /&gt;283F75D2 B6B051B8&lt;BR /&gt;quit&lt;BR /&gt;spanning-tree mode pvst&lt;BR /&gt;spanning-tree extend system-id&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;vlan internal allocation policy ascending&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/2&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/3&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/4&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/5&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/6&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/7&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/8&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/9&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/10&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/11&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/12&lt;BR /&gt;switchport access vlan 40&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;description ***TO FW**&lt;BR /&gt;no switchport&lt;BR /&gt;ip address 192.168.100.2 255.255.255.252&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;no ip address&lt;BR /&gt;no ip mroute-cache&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Vlan10&lt;BR /&gt;description GAC-CUCME&lt;BR /&gt;ip address 192.168.200.1 255.255.255.248&lt;BR /&gt;no ip redirects&lt;BR /&gt;no ip unreachables&lt;BR /&gt;no ip proxy-arp&lt;BR /&gt;no ip mroute-cache&lt;BR /&gt;!&lt;BR /&gt;interface Vlan20&lt;BR /&gt;description GAC-DATA&lt;BR /&gt;ip address 192.168.200.129 255.255.255.128&lt;BR /&gt;!&lt;BR /&gt;interface Vlan30&lt;BR /&gt;description GAC-VOICE&lt;BR /&gt;ip address 192.168.200.33 255.255.255.224&lt;BR /&gt;no ip redirects&lt;BR /&gt;no ip unreachables&lt;BR /&gt;no ip proxy-arp&lt;BR /&gt;!&lt;BR /&gt;interface Vlan40&lt;BR /&gt;description GAC-PSEC&lt;BR /&gt;ip address 192.168.200.17 255.255.255.240&lt;BR /&gt;no ip redirects&lt;BR /&gt;no ip unreachables&lt;BR /&gt;no ip proxy-arp&lt;BR /&gt;!&lt;BR /&gt;ip default-gateway 192.168.100.2&lt;BR /&gt;ip classless&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 192.168.100.1&lt;BR /&gt;ip http server&lt;BR /&gt;ip http secure-server&lt;BR /&gt;!&lt;BR /&gt;ip sla enable reaction-alerts&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;line vty 0 4&lt;BR /&gt;transport input ssh&lt;BR /&gt;transport output ssh&lt;BR /&gt;line vty 5 15&lt;BR /&gt;transport input ssh&lt;BR /&gt;transport output ssh&lt;/P&gt;&lt;P&gt;PING&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.100.1, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;BR /&gt;#ping 8.8.8.8&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:&lt;BR /&gt;.....&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;BR /&gt;#ping 192.168.200.129&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.200.129, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/8 ms&lt;BR /&gt;#ping 192.168.200.33&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.200.33, timeout is 2 seconds:&lt;BR /&gt;.....&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;BR /&gt;#ping 192.168.200.17&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.200.17, timeout is 2 seconds:&lt;BR /&gt;.....&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;/P&gt;&lt;P&gt;FROM SWITCH CONNECTED CLIENT&lt;/P&gt;&lt;P&gt;Tracing route to 8.8.8.8 over a maximum of 30 hops&lt;/P&gt;&lt;P&gt;1 2 ms 2 ms 3 ms 192.168.200.129&lt;BR /&gt;2 2 ms 2 ms 2 ms 154.113.70.205&lt;BR /&gt;3 19 ms 20 ms 19 ms 41.75.80.9&lt;BR /&gt;4 18 ms 17 ms 18 ms 41.75.80.9&lt;BR /&gt;5 16 ms 16 ms 16 ms 72.14.217.212&lt;BR /&gt;6 17 ms 17 ms 17 ms 192.178.106.187&lt;BR /&gt;7 18 ms 19 ms 18 ms 172.253.76.173&lt;BR /&gt;8 20 ms 20 ms 20 ms 8.8.8.8&lt;/P&gt;&lt;P&gt;Pinging 8.8.8.8 with 32 bytes of data:&lt;BR /&gt;Reply from 8.8.8.8: bytes=32 time=20ms TTL=119&lt;BR /&gt;Reply from 8.8.8.8: bytes=32 time=20ms TTL=119&lt;BR /&gt;Reply from 8.8.8.8: bytes=32 time=20ms TTL=119&lt;BR /&gt;Reply from 8.8.8.8: bytes=32 time=20ms TTL=119&lt;/P&gt;&lt;P&gt;C:\Users\martial.amoussou&amp;gt;ping google.com&lt;BR /&gt;Ping request could not find host google.com. Please check the name and try again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Oct 2024 14:59:41 GMT</pubDate>
    <dc:creator>mamoussou</dc:creator>
    <dc:date>2024-10-09T14:59:41Z</dc:date>
    <item>
      <title>Tracert and Ping to 8.8.8.8 works but cant access the Internet</title>
      <link>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205846#M1116410</link>
      <description>&lt;P&gt;Please help. I have an ASA 5506-x connected to a 3750 swich. I cant ping 8.8.8.8 or anything external from the switch. I cant ping the other vlan subnets either ( the ASA has the route back to these). However, I can ping 8.8.8.8 and tracert successfully from client connected to the switch, but cant access the internet. What could be the problem?&lt;/P&gt;&lt;P&gt;ASA CONFIG&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/1&lt;BR /&gt;nameif OUTSIDE&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 154.113.70.206 255.255.255.252&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;nameif INSIDE&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.100.1 255.255.255.252&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/4&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/5&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/6&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/7&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/8&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management1/1&lt;BR /&gt;management-only&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;dns domain-lookup OUTSIDE&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;name-server 8.8.8.8&lt;BR /&gt;name-server 41.75.80.84&lt;BR /&gt;name-server 8.8.4.4&lt;BR /&gt;domain-name gaclos.local&lt;BR /&gt;object network obj_DATA_128&lt;BR /&gt;subnet 192.168.200.128 255.255.255.128&lt;BR /&gt;description DATA network&lt;BR /&gt;object network obj_VOICE_32&lt;BR /&gt;subnet 192.168.200.32 255.255.255.224&lt;BR /&gt;object network obj_PSEC_16&lt;BR /&gt;subnet 192.168.200.16 255.255.255.240&lt;BR /&gt;description PSEC network&lt;BR /&gt;object network obj_CUCME_0&lt;BR /&gt;subnet 192.168.200.0 255.255.255.248&lt;BR /&gt;description CUCME&lt;BR /&gt;object network obj_APAPA_44&lt;BR /&gt;subnet 10.251.44.0 255.255.255.0&lt;BR /&gt;description Apapa Mgmt&lt;BR /&gt;object network obj_APAPA_45&lt;BR /&gt;subnet 10.251.45.0 255.255.255.0&lt;BR /&gt;description Apapa CUCME&lt;BR /&gt;object network obj_APAPA_46&lt;BR /&gt;subnet 10.251.46.0 255.255.255.0&lt;BR /&gt;object network obj_APAPA_47&lt;BR /&gt;subnet 10.251.47.0 255.255.255.0&lt;BR /&gt;description Apapa WiFi&lt;BR /&gt;object network obj_APAPA_48&lt;BR /&gt;subnet 10.251.48.0 255.255.255.0&lt;BR /&gt;description Apapa LAN&lt;BR /&gt;object network obj_APAPA_49&lt;BR /&gt;subnet 10.251.49.0 255.255.255.0&lt;BR /&gt;description Apapa Voice&lt;BR /&gt;object network obj_APAPA_50&lt;BR /&gt;subnet 10.251.50.0 255.255.255.0&lt;BR /&gt;description Apapa Servers&lt;BR /&gt;object-group network GAC_PHC_NETWORK&lt;BR /&gt;description PHC_NETWORK&lt;BR /&gt;network-object 192.168.100.0 255.255.255.252&lt;BR /&gt;network-object object obj_CUCME_0&lt;BR /&gt;network-object object obj_DATA_128&lt;BR /&gt;network-object object obj_PSEC_16&lt;BR /&gt;network-object object obj_VOICE_32&lt;BR /&gt;object-group network GAC_APAPA_NETWORK&lt;BR /&gt;description APAPA Network&lt;BR /&gt;network-object object obj_APAPA_44&lt;BR /&gt;network-object object obj_APAPA_45&lt;BR /&gt;network-object object obj_APAPA_46&lt;BR /&gt;network-object object obj_APAPA_47&lt;BR /&gt;network-object object obj_APAPA_48&lt;BR /&gt;network-object object obj_APAPA_49&lt;BR /&gt;network-object object obj_APAPA_50&lt;BR /&gt;object-group service TCPUDP tcp&lt;BR /&gt;port-object eq 587&lt;BR /&gt;access-list OUTSIDE_cryptomap extended permit ip object-group GAC_PHC_NETWORK object-group GAC_APAPA_NETWORK&lt;BR /&gt;access-list INSIDE_access_in extended permit tcp any any eq domain&lt;BR /&gt;access-list INSIDE_access_in extended permit icmp any any&lt;BR /&gt;access-list INSIDE_access_in extended permit tcp any any eq www&lt;BR /&gt;access-list INSIDE_access_in extended permit tcp any any eq https&lt;BR /&gt;access-list INSIDE_access_in extended permit tcp any any eq 587&lt;BR /&gt;access-list INSIDE_access_in extended permit udp any any eq isakmp&lt;BR /&gt;access-list INSIDE_access_in extended permit tcp any any eq pop3&lt;BR /&gt;access-list OUTSIDE_access_in extended permit icmp any any&lt;BR /&gt;access-list OUTSIDE_access_in extended permit ip any any&lt;BR /&gt;access-list INSIDE extended permit ip any any&lt;BR /&gt;pager lines 24&lt;BR /&gt;mtu OUTSIDE 1500&lt;BR /&gt;mtu INSIDE 1500&lt;BR /&gt;no failover&lt;BR /&gt;no monitor-interface service-module&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;arp rate-limit 16384&lt;BR /&gt;nat (INSIDE,OUTSIDE) source static GAC_PHC_NETWORK GAC_PHC_NETWORK destination static GAC_APAPA_NETWORK GAC_APAPA_NETWORK no-proxy-arp route-lookup&lt;BR /&gt;!&lt;BR /&gt;object network obj_DATA_128&lt;BR /&gt;nat (any,OUTSIDE) dynamic interface&lt;BR /&gt;object network obj_PSEC_16&lt;BR /&gt;nat (any,OUTSIDE) dynamic interface&lt;BR /&gt;access-group OUTSIDE_access_in in interface OUTSIDE&lt;BR /&gt;access-group INSIDE_access_in in interface INSIDE&lt;BR /&gt;route OUTSIDE 0.0.0.0 0.0.0.0 154.113.70.205 1&lt;BR /&gt;route INSIDE 192.168.200.0 255.255.255.248 192.168.100.2 1&lt;BR /&gt;route INSIDE 192.168.200.16 255.255.255.240 192.168.100.2 1&lt;BR /&gt;route INSIDE 192.168.200.32 255.255.255.224 192.168.100.2 1&lt;BR /&gt;route INSIDE 192.168.200.128 255.255.255.128 192.168.100.2 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;timeout conn-holddown 0:00:15&lt;BR /&gt;timeout igp stale-route 0:01:10&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;aaa authentication enable console LOCAL&lt;BR /&gt;aaa authentication http console LOCAL&lt;BR /&gt;aaa authentication serial console LOCAL&lt;BR /&gt;aaa authentication login-history&lt;BR /&gt;http server enable 8080&lt;BR /&gt;http 0.0.0.0 0.0.0.0 OUTSIDE&lt;BR /&gt;http 0.0.0.0 0.0.0.0 INSIDE&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;service sw-reset-button&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS esp-aes esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS esp-aes esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-128-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS esp-aes-192 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS esp-aes-192 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-192-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS esp-aes-256 esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS esp-aes-256 esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-AES-256-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS esp-3des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS esp-3des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-3DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS esp-des esp-sha-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-SHA-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS esp-des esp-md5-hmac&lt;BR /&gt;crypto ipsec ikev1 transform-set ESP-DES-MD5-TRANS mode transport&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES256&lt;BR /&gt;protocol esp encryption aes-256&lt;BR /&gt;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES192&lt;BR /&gt;protocol esp encryption aes-192&lt;BR /&gt;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal AES&lt;BR /&gt;protocol esp encryption aes&lt;BR /&gt;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal 3DES&lt;BR /&gt;protocol esp encryption 3des&lt;BR /&gt;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec ikev2 ipsec-proposal DES&lt;BR /&gt;protocol esp encryption des&lt;BR /&gt;protocol esp integrity sha-1 md5&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto map OUTSIDE_map 1 match address OUTSIDE_cryptomap&lt;BR /&gt;crypto map OUTSIDE_map 1 set peer 197.253.33.66&lt;BR /&gt;crypto map OUTSIDE_map 1 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5&lt;BR /&gt;crypto map OUTSIDE_map interface OUTSIDE&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ikev2 policy 1&lt;BR /&gt;encryption aes-256&lt;BR /&gt;integrity sha&lt;BR /&gt;group 5 2&lt;BR /&gt;prf sha&lt;BR /&gt;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 10&lt;BR /&gt;encryption aes-192&lt;BR /&gt;integrity sha&lt;BR /&gt;group 5 2&lt;BR /&gt;prf sha&lt;BR /&gt;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 20&lt;BR /&gt;encryption aes&lt;BR /&gt;integrity sha&lt;BR /&gt;group 5 2&lt;BR /&gt;prf sha&lt;BR /&gt;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 30&lt;BR /&gt;encryption 3des&lt;BR /&gt;integrity sha&lt;BR /&gt;group 5 2&lt;BR /&gt;prf sha&lt;BR /&gt;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 policy 40&lt;BR /&gt;encryption des&lt;BR /&gt;integrity sha&lt;BR /&gt;group 5 2&lt;BR /&gt;prf sha&lt;BR /&gt;lifetime seconds 86400&lt;BR /&gt;crypto ikev2 enable OUTSIDE&lt;BR /&gt;crypto ikev1 enable OUTSIDE&lt;BR /&gt;crypto ikev1 policy 10&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption aes-256&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 20&lt;BR /&gt;authentication rsa-sig&lt;BR /&gt;encryption aes-256&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 40&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption aes-192&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 50&lt;BR /&gt;authentication rsa-sig&lt;BR /&gt;encryption aes-192&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 70&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption aes&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 80&lt;BR /&gt;authentication rsa-sig&lt;BR /&gt;encryption aes&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 100&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption 3des&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 110&lt;BR /&gt;authentication rsa-sig&lt;BR /&gt;encryption 3des&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 130&lt;BR /&gt;authentication pre-share&lt;BR /&gt;encryption des&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;crypto ikev1 policy 140&lt;BR /&gt;authentication rsa-sig&lt;BR /&gt;encryption des&lt;BR /&gt;hash sha&lt;BR /&gt;group 2&lt;BR /&gt;lifetime 86400&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 OUTSIDE&lt;BR /&gt;ssh 0.0.0.0 0.0.0.0 INSIDE&lt;BR /&gt;ssh timeout 15&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;ssl cipher default custom "AES256-SHA:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA"&lt;BR /&gt;ssl cipher tlsv1 custom "AES256-SHA:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA"&lt;BR /&gt;ssl cipher dtlsv1 custom "AES256-SHA:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA"&lt;BR /&gt;group-policy GroupPolicy_197.253.33.66 internal&lt;BR /&gt;group-policy GroupPolicy_197.253.33.66 attributes&lt;BR /&gt;vpn-tunnel-protocol ikev1&lt;BR /&gt;group-policy GroupPolicy_41.75.82.94 internal&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;username mamoussou password $sha512$5000$+0/X7IbvSP+ZET/aSSnjXg==$2YHiAXAsFLlOsrbIte63lA== pbkdf2 privilege 15&lt;BR /&gt;tunnel-group 197.253.33.66 type ipsec-l2l&lt;BR /&gt;tunnel-group 197.253.33.66 general-attributes&lt;BR /&gt;default-group-policy GroupPolicy_197.253.33.66&lt;BR /&gt;tunnel-group 197.253.33.66 ipsec-attributes&lt;BR /&gt;ikev1 pre-shared-key *****&lt;BR /&gt;ikev2 remote-authentication pre-shared-key *****&lt;BR /&gt;ikev2 local-authentication pre-shared-key *****&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;no tcp-inspection&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect ftp&lt;BR /&gt;inspect h323 h225&lt;BR /&gt;inspect h323 ras&lt;BR /&gt;inspect ip-options&lt;BR /&gt;inspect netbios&lt;BR /&gt;inspect rsh&lt;BR /&gt;inspect rtsp&lt;BR /&gt;inspect skinny&lt;BR /&gt;inspect esmtp&lt;BR /&gt;inspect sqlnet&lt;BR /&gt;inspect sunrpc&lt;BR /&gt;inspect tftp&lt;BR /&gt;inspect sip&lt;BR /&gt;inspect xdmcp&lt;BR /&gt;inspect dns preset_dns_map&lt;BR /&gt;inspect icmp&lt;BR /&gt;policy-map type inspect dns migrated_dns_map_2&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;no tcp-inspection&lt;BR /&gt;policy-map type inspect dns migrated_dns_map_1&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;no tcp-inspection&lt;/P&gt;&lt;P&gt;ROUTES&lt;/P&gt;&lt;P&gt;nat (INSIDE,OUTSIDE) source static GAC_PHC_NETWORK GAC_PHC_NETWORK destination static GAC_APAPA_NETWORK GAC_APAPA_NETWORK no-proxy-arp route-lookup&lt;BR /&gt;route OUTSIDE 0.0.0.0 0.0.0.0 154.113.70.205 1&lt;BR /&gt;route INSIDE 192.168.200.0 255.255.255.248 192.168.100.2 1&lt;BR /&gt;route INSIDE 192.168.200.16 255.255.255.240 192.168.100.2 1&lt;BR /&gt;route INSIDE 192.168.200.32 255.255.255.224 192.168.100.2 1&lt;BR /&gt;route INSIDE 192.168.200.128 255.255.255.128 192.168.100.2 1&lt;BR /&gt;timeout igp stale-route 0:01:10&lt;/P&gt;&lt;P&gt;NAT and ACLs&lt;/P&gt;&lt;P&gt;sh nat&lt;BR /&gt;Manual NAT Policies (Section 1)&lt;BR /&gt;1 (INSIDE) to (OUTSIDE) source static GAC_PHC_NETWORK GAC_PHC_NETWORK destination static GAC_APAPA_NETWORK GAC_APAPA_NETWORK no-proxy-arp route-lookup&lt;BR /&gt;translate_hits = 8, untranslate_hits = 8&lt;/P&gt;&lt;P&gt;Auto NAT Policies (Section 2)&lt;BR /&gt;1 (any) to (OUTSIDE) source dynamic obj_PSEC_16 interface&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;2 (any) to (OUTSIDE) source dynamic obj_DATA_128 interface&lt;BR /&gt;translate_hits = 15217, untranslate_hits = 1081&lt;BR /&gt;&lt;BR /&gt;# sh access-list&lt;BR /&gt;access-list cached ACL log flows: total 0, denied 0 (deny-flow-max 4096)&lt;BR /&gt;alert-interval 300&lt;BR /&gt;access-list OUTSIDE_cryptomap; 35 elements; name hash: 0x7d0700c2&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip object-group GAC_PHC_NETWORK object-group GAC_APAPA_NETWORK (hitcnt=3) 0xb50a5623&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.100.0 255.255.255.252 10.251.44.0 255.255.255.0 (hitcnt=0) 0xfdc1b3c4&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.100.0 255.255.255.252 10.251.45.0 255.255.255.0 (hitcnt=0) 0xe23249c8&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.100.0 255.255.255.252 10.251.46.0 255.255.255.0 (hitcnt=0) 0x1e0dfffc&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.100.0 255.255.255.252 10.251.47.0 255.255.255.0 (hitcnt=0) 0x4e8676cf&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.100.0 255.255.255.252 10.251.48.0 255.255.255.0 (hitcnt=0) 0xbd8d6abd&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.100.0 255.255.255.252 10.251.49.0 255.255.255.0 (hitcnt=0) 0xb361e7d4&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.100.0 255.255.255.252 10.251.50.0 255.255.255.0 (hitcnt=0) 0xa4061b7b&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.0 255.255.255.248 10.251.44.0 255.255.255.0 (hitcnt=0) 0xea33b872&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.0 255.255.255.248 10.251.45.0 255.255.255.0 (hitcnt=0) 0xc7e8b504&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.0 255.255.255.248 10.251.46.0 255.255.255.0 (hitcnt=0) 0xffbf71e6&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.0 255.255.255.248 10.251.47.0 255.255.255.0 (hitcnt=0) 0x95338c3e&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.0 255.255.255.248 10.251.48.0 255.255.255.0 (hitcnt=0) 0x73eca7c5&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.0 255.255.255.248 10.251.49.0 255.255.255.0 (hitcnt=0) 0x1bdc78e8&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.0 255.255.255.248 10.251.50.0 255.255.255.0 (hitcnt=0) 0x9d5e40a3&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.128 255.255.255.128 10.251.44.0 255.255.255.0 (hitcnt=0) 0x6b57bb41&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.128 255.255.255.128 10.251.45.0 255.255.255.0 (hitcnt=0) 0x2a48cff0&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.128 255.255.255.128 10.251.46.0 255.255.255.0 (hitcnt=0) 0x346c1302&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.128 255.255.255.128 10.251.47.0 255.255.255.0 (hitcnt=15) 0x62fabae7&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.128 255.255.255.128 10.251.48.0 255.255.255.0 (hitcnt=0) 0x3da20527&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.128 255.255.255.128 10.251.49.0 255.255.255.0 (hitcnt=0) 0x6594c1b1&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.128 255.255.255.128 10.251.50.0 255.255.255.0 (hitcnt=0) 0x84c8e267&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.16 255.255.255.240 10.251.44.0 255.255.255.0 (hitcnt=0) 0x1ffd5f19&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.16 255.255.255.240 10.251.45.0 255.255.255.0 (hitcnt=0) 0xd79459ed&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.16 255.255.255.240 10.251.46.0 255.255.255.0 (hitcnt=0) 0x5991a0a3&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.16 255.255.255.240 10.251.47.0 255.255.255.0 (hitcnt=0) 0x392f79b2&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.16 255.255.255.240 10.251.48.0 255.255.255.0 (hitcnt=0) 0xf4de6d67&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.16 255.255.255.240 10.251.49.0 255.255.255.0 (hitcnt=0) 0x8befe92a&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.16 255.255.255.240 10.251.50.0 255.255.255.0 (hitcnt=0) 0x25c35164&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.32 255.255.255.224 10.251.44.0 255.255.255.0 (hitcnt=0) 0xc553a3ed&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.32 255.255.255.224 10.251.45.0 255.255.255.0 (hitcnt=0) 0x2d015abb&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.32 255.255.255.224 10.251.46.0 255.255.255.0 (hitcnt=0) 0x6de59669&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.32 255.255.255.224 10.251.47.0 255.255.255.0 (hitcnt=0) 0xd4fa270a&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.32 255.255.255.224 10.251.48.0 255.255.255.0 (hitcnt=0) 0x244acbba&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.32 255.255.255.224 10.251.49.0 255.255.255.0 (hitcnt=0) 0xf64c5a30&lt;BR /&gt;access-list OUTSIDE_cryptomap line 1 extended permit ip 192.168.200.32 255.255.255.224 10.251.50.0 255.255.255.0 (hitcnt=0) 0x164acdcd&lt;BR /&gt;access-list INSIDE_access_in; 7 elements; name hash: 0xb71cec1d&lt;BR /&gt;access-list INSIDE_access_in line 1 extended permit tcp any any eq domain (hitcnt=10410) 0x6463e52f&lt;BR /&gt;access-list INSIDE_access_in line 2 extended permit icmp any any (hitcnt=1411) 0xbe2c8578&lt;BR /&gt;access-list INSIDE_access_in line 3 extended permit tcp any any eq www (hitcnt=179) 0xae7df53e&lt;BR /&gt;access-list INSIDE_access_in line 4 extended permit tcp any any eq https (hitcnt=3798) 0x44c047ca&lt;BR /&gt;access-list INSIDE_access_in line 5 extended permit tcp any any eq 587 (hitcnt=0) 0xefa402f4&lt;BR /&gt;access-list INSIDE_access_in line 6 extended permit udp any any eq isakmp (hitcnt=0) 0x02b7c7d8&lt;BR /&gt;access-list INSIDE_access_in line 7 extended permit tcp any any eq pop3 (hitcnt=0) 0x611278d2&lt;BR /&gt;access-list OUTSIDE_access_in; 2 elements; name hash: 0x766b1b32&lt;BR /&gt;access-list OUTSIDE_access_in line 1 extended permit icmp any any (hitcnt=108) 0x112340aa&lt;BR /&gt;access-list OUTSIDE_access_in line 2 extended permit ip any any (hitcnt=951) 0x482d024c&lt;BR /&gt;access-list INSIDE; 1 elements; name hash: 0xdedb237a&lt;BR /&gt;access-list INSIDE line 1 extended permit ip any any (hitcnt=0) 0x2a29f5f2&lt;/P&gt;&lt;P&gt;SWITCH CONFIG&lt;/P&gt;&lt;P&gt;Current configuration : 5924 bytes&lt;BR /&gt;!&lt;BR /&gt;version 12.2&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;no service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname GAC-PHC-SW1&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;enable secret 5 $1$11Wa$KoksYYu938zhv.kMZjYDd0&lt;BR /&gt;enable password N33d2kN0w#&lt;BR /&gt;!&lt;BR /&gt;username mamoussou privilege 15 password 0 mamoussou@123!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;system mtu routing 1500&lt;BR /&gt;ip routing&lt;BR /&gt;ip dhcp excluded-address 192.168.200.129 192.168.200.139&lt;BR /&gt;ip dhcp excluded-address 192.168.200.33 192.168.200.39&lt;BR /&gt;ip dhcp excluded-address 192.168.200.17 192.168.200.21&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool GAC-DATA&lt;BR /&gt;network 192.168.200.128 255.255.255.128&lt;BR /&gt;domain-name gaclos.local&lt;BR /&gt;default-router 192.168.200.129&lt;BR /&gt;dns-server 41.75.80.84 8.8.8.8&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool GAC-VOICE&lt;BR /&gt;network 192.168.200.32 255.255.255.224&lt;BR /&gt;domain-name gaclos.local&lt;BR /&gt;default-router 192.168.200.33&lt;BR /&gt;dns-server 41.75.80.84 8.8.8.8&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool GAC-PSEC&lt;BR /&gt;network 192.168.200.16 255.255.255.240&lt;BR /&gt;domain-name gaclos.local&lt;BR /&gt;default-router 192.168.200.17&lt;BR /&gt;dns-server 41.75.80.84 8.8.8.8&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki trustpoint TP-self-signed-4096251392&lt;BR /&gt;enrollment selfsigned&lt;BR /&gt;subject-name cn=IOS-Self-Signed-Certificate-4096251392&lt;BR /&gt;revocation-check none&lt;BR /&gt;rsakeypair TP-self-signed-4096251392&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki certificate chain TP-self-signed-4096251392&lt;BR /&gt;certificate self-signed 01&lt;BR /&gt;30820244 308201AD A0030201 02020101 300D0609 2A864886 F70D0101 04050030&lt;BR /&gt;31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274&lt;BR /&gt;69666963 6174652D 34303936 32353133 3932301E 170D3933 30333031 30303038&lt;BR /&gt;33375A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649&lt;BR /&gt;4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D34 30393632&lt;BR /&gt;35313339 3230819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281&lt;BR /&gt;8100A341 6B8C9394 C15A791F 54EC3D3B 05D1D8C7 059A1B20 EB17B504 86C9CD17&lt;BR /&gt;F2FDF78A 1279FDC0 8AE1FB27 36510CA3 465551EF 8ECFD28D 34F49412 F36C3332&lt;BR /&gt;55A2BBC0 9C378252 E9299A13 BD18A36F D56A0B9A 352C5089 0C20F883 E4B336D4&lt;BR /&gt;DCB5DD81 92F3B778 7FF5F3FB 8FA2A7E1 170F21B7 A9DEBA0B C72C3ED8 ABF605D9&lt;BR /&gt;4ED70203 010001A3 6C306A30 0F060355 1D130101 FF040530 030101FF 30170603&lt;BR /&gt;551D1104 10300E82 0C474143 2D504843 2D535731 2E301F06 03551D23 04183016&lt;BR /&gt;801434D0 32AF4F32 12CF6995 29122035 641FB29D 6C68301D 0603551D 0E041604&lt;BR /&gt;1434D032 AF4F3212 CF699529 12203564 1FB29D6C 68300D06 092A8648 86F70D01&lt;BR /&gt;01040500 03818100 500A61EC 4FCFEC83 1B99290C AD16F329 F9FEAAFB 8D9A4684&lt;BR /&gt;DBF9D2EE 0B463934 D86568EB F67E4073 834D04F0 CC83F211 BADDCD2C DB82BAC9&lt;BR /&gt;2984DDDD 45B0231D 553EF7A8 E79841D6 DC209DA8 4540A34F 75B993F0 AEB8ABB7&lt;BR /&gt;2EDEF3D4 D70ECA44 E2D1549C 5F505F1D 1DED7725 FB8F3A43 E79D0D84 A39DE80E&lt;BR /&gt;283F75D2 B6B051B8&lt;BR /&gt;quit&lt;BR /&gt;spanning-tree mode pvst&lt;BR /&gt;spanning-tree extend system-id&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;vlan internal allocation policy ascending&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/2&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/3&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/4&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/5&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/6&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/7&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/8&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/9&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/10&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/11&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/12&lt;BR /&gt;switchport access vlan 40&lt;BR /&gt;switchport mode access&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;description ***TO FW**&lt;BR /&gt;no switchport&lt;BR /&gt;ip address 192.168.100.2 255.255.255.252&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;switchport access vlan 20&lt;BR /&gt;switchport mode access&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;no ip address&lt;BR /&gt;no ip mroute-cache&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Vlan10&lt;BR /&gt;description GAC-CUCME&lt;BR /&gt;ip address 192.168.200.1 255.255.255.248&lt;BR /&gt;no ip redirects&lt;BR /&gt;no ip unreachables&lt;BR /&gt;no ip proxy-arp&lt;BR /&gt;no ip mroute-cache&lt;BR /&gt;!&lt;BR /&gt;interface Vlan20&lt;BR /&gt;description GAC-DATA&lt;BR /&gt;ip address 192.168.200.129 255.255.255.128&lt;BR /&gt;!&lt;BR /&gt;interface Vlan30&lt;BR /&gt;description GAC-VOICE&lt;BR /&gt;ip address 192.168.200.33 255.255.255.224&lt;BR /&gt;no ip redirects&lt;BR /&gt;no ip unreachables&lt;BR /&gt;no ip proxy-arp&lt;BR /&gt;!&lt;BR /&gt;interface Vlan40&lt;BR /&gt;description GAC-PSEC&lt;BR /&gt;ip address 192.168.200.17 255.255.255.240&lt;BR /&gt;no ip redirects&lt;BR /&gt;no ip unreachables&lt;BR /&gt;no ip proxy-arp&lt;BR /&gt;!&lt;BR /&gt;ip default-gateway 192.168.100.2&lt;BR /&gt;ip classless&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 192.168.100.1&lt;BR /&gt;ip http server&lt;BR /&gt;ip http secure-server&lt;BR /&gt;!&lt;BR /&gt;ip sla enable reaction-alerts&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;line vty 0 4&lt;BR /&gt;transport input ssh&lt;BR /&gt;transport output ssh&lt;BR /&gt;line vty 5 15&lt;BR /&gt;transport input ssh&lt;BR /&gt;transport output ssh&lt;/P&gt;&lt;P&gt;PING&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.100.1, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;BR /&gt;#ping 8.8.8.8&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:&lt;BR /&gt;.....&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;BR /&gt;#ping 192.168.200.129&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.200.129, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/8 ms&lt;BR /&gt;#ping 192.168.200.33&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.200.33, timeout is 2 seconds:&lt;BR /&gt;.....&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;BR /&gt;#ping 192.168.200.17&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.200.17, timeout is 2 seconds:&lt;BR /&gt;.....&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;/P&gt;&lt;P&gt;FROM SWITCH CONNECTED CLIENT&lt;/P&gt;&lt;P&gt;Tracing route to 8.8.8.8 over a maximum of 30 hops&lt;/P&gt;&lt;P&gt;1 2 ms 2 ms 3 ms 192.168.200.129&lt;BR /&gt;2 2 ms 2 ms 2 ms 154.113.70.205&lt;BR /&gt;3 19 ms 20 ms 19 ms 41.75.80.9&lt;BR /&gt;4 18 ms 17 ms 18 ms 41.75.80.9&lt;BR /&gt;5 16 ms 16 ms 16 ms 72.14.217.212&lt;BR /&gt;6 17 ms 17 ms 17 ms 192.178.106.187&lt;BR /&gt;7 18 ms 19 ms 18 ms 172.253.76.173&lt;BR /&gt;8 20 ms 20 ms 20 ms 8.8.8.8&lt;/P&gt;&lt;P&gt;Pinging 8.8.8.8 with 32 bytes of data:&lt;BR /&gt;Reply from 8.8.8.8: bytes=32 time=20ms TTL=119&lt;BR /&gt;Reply from 8.8.8.8: bytes=32 time=20ms TTL=119&lt;BR /&gt;Reply from 8.8.8.8: bytes=32 time=20ms TTL=119&lt;BR /&gt;Reply from 8.8.8.8: bytes=32 time=20ms TTL=119&lt;/P&gt;&lt;P&gt;C:\Users\martial.amoussou&amp;gt;ping google.com&lt;BR /&gt;Ping request could not find host google.com. Please check the name and try again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 14:59:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205846#M1116410</guid>
      <dc:creator>mamoussou</dc:creator>
      <dc:date>2024-10-09T14:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert and Ping to 8.8.8.8 works but cant access the Internet</title>
      <link>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205850#M1116411</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/349133"&gt;@mamoussou&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Your problema seems to be related to DNS. Which DNS are you using on the PC? It is local DNS or are you using the google DNS?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 15:06:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205850#M1116411</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-10-09T15:06:38Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert and Ping to 8.8.8.8 works but cant access the Internet</title>
      <link>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205882#M1116413</link>
      <description>&lt;P&gt;You apply ACL on interface IN' add to this ACL line to permit DNS any any&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 16:00:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205882#M1116413</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-09T16:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert and Ping to 8.8.8.8 works but cant access the Internet</title>
      <link>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205977#M1116417</link>
      <description>&lt;P&gt;I am using ISP supplied DNS and google DNS&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 17:18:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205977#M1116417</guid>
      <dc:creator>mamoussou</dc:creator>
      <dc:date>2024-10-09T17:18:05Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert and Ping to 8.8.8.8 works but cant access the Internet</title>
      <link>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205978#M1116418</link>
      <description>&lt;P&gt;ok. will try that. but why cant I ping other inside subnets?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 17:19:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205978#M1116418</guid>
      <dc:creator>mamoussou</dc:creator>
      <dc:date>2024-10-09T17:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert and Ping to 8.8.8.8 works but cant access the Internet</title>
      <link>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205980#M1116419</link>
      <description>&lt;P&gt;In SW&lt;/P&gt;
&lt;P&gt;Show ip interface breif&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check if VLAN SVI is up or not&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 17:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205980#M1116419</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-09T17:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert and Ping to 8.8.8.8 works but cant access the Internet</title>
      <link>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205982#M1116420</link>
      <description>&lt;P&gt;Is this issue with switch and clients.&lt;/P&gt;
&lt;P&gt;Switch side make sure you configure DNS correctly and if you looking layer 3, then remove default-router config, make sure ip routing enabled on the switch.&lt;/P&gt;
&lt;P&gt;From client you not able to ping domain.com, seems to be resolution issue.&lt;/P&gt;
&lt;P&gt;from client can you post ipconfig /all&lt;/P&gt;
&lt;P&gt;nslookup google.com or cisco.com output.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 17:27:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205982#M1116420</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-10-09T17:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert and Ping to 8.8.8.8 works but cant access the Internet</title>
      <link>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205990#M1116421</link>
      <description>&lt;P&gt;But if you run "nslookup &lt;A href="http://www.google.com&amp;quot;" target="_blank"&gt;www.google.com"&lt;/A&gt; on your machine, what do you get?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 17:51:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5205990#M1116421</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-10-09T17:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert and Ping to 8.8.8.8 works but cant access the Internet</title>
      <link>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5206116#M1116426</link>
      <description>&lt;P&gt;Yes they are up.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 20:49:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5206116#M1116426</guid>
      <dc:creator>mamoussou</dc:creator>
      <dc:date>2024-10-09T20:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert and Ping to 8.8.8.8 works but cant access the Internet</title>
      <link>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5206118#M1116427</link>
      <description>&lt;P&gt;ipconfig /all shows dhcp IP, gateway and dns from swich. Able to ping up to ping and trace to 8.8.8.8 over 8 hops. however nslookup does not resolve.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 20:51:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5206118#M1116427</guid>
      <dc:creator>mamoussou</dc:creator>
      <dc:date>2024-10-09T20:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert and Ping to 8.8.8.8 works but cant access the Internet</title>
      <link>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5206130#M1116428</link>
      <description>&lt;P&gt;if you like further assitance like to see the output :&amp;nbsp; (if no nslookup done, then you use correct DNS resolver to get ping FQDN, some ISP do not allowed google DNS, so use ISP DNS configured on client side and test it)&lt;/P&gt;
&lt;P&gt;from client can you post ipconfig /all&lt;/P&gt;
&lt;P&gt;nslookup google.com or cisco.com output.&lt;/P&gt;
&lt;P&gt;Note : ping is to test reachability, does not resolve the issue of yours, you have IP connectiviyt for the Ping, do not have DNS lookup that where you need to focus.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 21:27:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5206130#M1116428</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-10-09T21:27:37Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert and Ping to 8.8.8.8 works but cant access the Internet</title>
      <link>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5206230#M1116432</link>
      <description>&lt;P&gt;Two issues here&lt;/P&gt;
&lt;P&gt;1- The VLAN SVI in SW' so check if ip routing comamnd is use or not in SW&lt;/P&gt;
&lt;P&gt;2- DNS issue' as I mention before your need add ACL in ASA allow traffic of dns between IN and OUT interface&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2024 04:29:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-and-ping-to-8-8-8-8-works-but-cant-access-the-internet/m-p/5206230#M1116432</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-10T04:29:11Z</dc:date>
    </item>
  </channel>
</rss>

