<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco Asa 5520 no internet.Please help. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209695#M1116612</link>
    <description>&lt;P&gt;ciscoasa# show run&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 8.0(5)&lt;BR /&gt;!&lt;BR /&gt;hostname ciscoasa&lt;BR /&gt;domain-name wonderland&lt;BR /&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;BR /&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;duplex full&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address dhcp setroute&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;duplex full&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.1.1.2 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;nameif manage&lt;BR /&gt;security-level 0&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;boot config disk0:/startup.cfg&lt;BR /&gt;ftp mode passive&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;domain-name wonderland&lt;BR /&gt;object-group network inside&lt;BR /&gt;object-group network inside-subnet&lt;BR /&gt;pager lines 24&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu manage 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-623.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;http server enable&lt;BR /&gt;http 10.1.1.1 255.255.255.255 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd dns 208.67.222.222 208.67.220.220&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 10.1.1.32-10.1.1.63 inside&lt;BR /&gt;dhcpd enable inside&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;username whiterabbit password HNOnJ3mP3F2wbi2O encrypted&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;prompt hostname context&lt;BR /&gt;Cryptochecksum:19c704489de6a0d92207d9d87c33f164&lt;BR /&gt;: end&lt;BR /&gt;ciscoasa#&lt;/P&gt;</description>
    <pubDate>Wed, 16 Oct 2024 15:15:25 GMT</pubDate>
    <dc:creator>antrikos_kal</dc:creator>
    <dc:date>2024-10-16T15:15:25Z</dc:date>
    <item>
      <title>Cisco Asa 5520 no internet.Please help.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209695#M1116612</link>
      <description>&lt;P&gt;ciscoasa# show run&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 8.0(5)&lt;BR /&gt;!&lt;BR /&gt;hostname ciscoasa&lt;BR /&gt;domain-name wonderland&lt;BR /&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;BR /&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/0&lt;BR /&gt;duplex full&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address dhcp setroute&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;duplex full&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.1.1.2 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/3&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;nameif manage&lt;BR /&gt;security-level 0&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;boot config disk0:/startup.cfg&lt;BR /&gt;ftp mode passive&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;domain-name wonderland&lt;BR /&gt;object-group network inside&lt;BR /&gt;object-group network inside-subnet&lt;BR /&gt;pager lines 24&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu manage 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-623.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;http server enable&lt;BR /&gt;http 10.1.1.1 255.255.255.255 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd dns 208.67.222.222 208.67.220.220&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 10.1.1.32-10.1.1.63 inside&lt;BR /&gt;dhcpd enable inside&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;username whiterabbit password HNOnJ3mP3F2wbi2O encrypted&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;prompt hostname context&lt;BR /&gt;Cryptochecksum:19c704489de6a0d92207d9d87c33f164&lt;BR /&gt;: end&lt;BR /&gt;ciscoasa#&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 15:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209695#M1116612</guid>
      <dc:creator>antrikos_kal</dc:creator>
      <dc:date>2024-10-16T15:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Asa 5520 no internet.Please help.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209705#M1116613</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/431646"&gt;@antrikos_kal&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;You need route and you probably need NAT&lt;/P&gt;
&lt;P&gt;&lt;STRONG class="cBold"&gt;route&lt;/STRONG&gt;&amp;nbsp;outside&amp;nbsp; 0.0.0.0 0.0.0.0 &lt;EM class="cEmphasis"&gt; gateway_ip&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM class="cEmphasis"&gt;nat (inside,outside) source dynamic any outside&amp;nbsp; &lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 15:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209705#M1116613</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-10-16T15:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Asa 5520 no internet.Please help.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209714#M1116614</link>
      <description>&lt;P&gt;You should get the default route from the ISP via DHCP, however, please check if that is the case with the command "sh route" or by pinging a public IP on the internet such as 8.8.8.8 or similar. If the default route is not getting injected by the ISP then as&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp;suggested please add the default route manually.&lt;/P&gt;
&lt;P&gt;Regarding NAT, you would need to create a dynamic PAT similar to this:&lt;/P&gt;
&lt;P&gt;object network LAN&lt;BR /&gt;&amp;nbsp; &amp;nbsp;subnet&amp;nbsp;&lt;SPAN&gt;10.1.1.0 255.255.255.0&lt;BR /&gt;&amp;nbsp; &amp;nbsp;nat (inside,outside) dynamic interface&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 15:25:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209714#M1116614</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-10-16T15:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Asa 5520 no internet.Please help.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209722#M1116615</link>
      <description>&lt;P&gt;ciscoasa(config-if)# sh route&lt;/P&gt;&lt;P&gt;Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP&lt;BR /&gt;D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;BR /&gt;N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;BR /&gt;E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP&lt;BR /&gt;i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area&lt;BR /&gt;* - candidate default, U - per-user static route, o - ODR&lt;BR /&gt;P - periodic downloaded static route&lt;/P&gt;&lt;P&gt;Gateway of last resort is not set&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 15:37:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209722#M1116615</guid>
      <dc:creator>antrikos_kal</dc:creator>
      <dc:date>2024-10-16T15:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Asa 5520 no internet.Please help.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209723#M1116616</link>
      <description>&lt;P&gt;ciscoasa(config-if)# sh route&lt;/P&gt;&lt;P&gt;Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP&lt;BR /&gt;D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;BR /&gt;N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;BR /&gt;E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP&lt;BR /&gt;i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area&lt;BR /&gt;* - candidate default, U - per-user static route, o - ODR&lt;BR /&gt;P - periodic downloaded static route&lt;/P&gt;&lt;P&gt;Gateway of last resort is not set&lt;/P&gt;&lt;P&gt;it doesnt accept nat(inside,outside) dynamic interface wrong cmnd.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 15:38:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209723#M1116616</guid>
      <dc:creator>antrikos_kal</dc:creator>
      <dc:date>2024-10-16T15:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Asa 5520 no internet.Please help.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209724#M1116617</link>
      <description>&lt;P&gt;if someone can connect via teamviewer i'd appreciate it.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 15:38:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209724#M1116617</guid>
      <dc:creator>antrikos_kal</dc:creator>
      <dc:date>2024-10-16T15:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Asa 5520 no internet.Please help.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209732#M1116618</link>
      <description>&lt;P&gt;Yes, I could see on the running-config that you have no route and that´s what I am suggesting.You need to identify which is your gateway and add the default route&lt;/P&gt;
&lt;P&gt;You can try to identify the gateway by running the command "show arp" and "show ip arp"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG class="cBold"&gt;route&lt;/STRONG&gt;&amp;nbsp;outside&amp;nbsp; 0.0.0.0 0.0.0.0 &lt;EM class="cEmphasis"&gt; gateway_ip&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;The NAT may be required may not, it will depend on how the ISP is handling this. They can be doing NAT for you already.&lt;/P&gt;
&lt;P&gt;But, you need to have route.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 15:53:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209732#M1116618</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2024-10-16T15:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Asa 5520 no internet.Please help.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209738#M1116620</link>
      <description>&lt;P&gt;The NAT command I shared must be issued under the object network, not in global config.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=1BW-h6X7Uuo" target="_blank"&gt;Configuring PAT on an ASA (youtube.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;But as&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/178747"&gt;@Flavio Miranda&lt;/a&gt;&amp;nbsp;mentioned, you might not need it if the ISP is doing NAT for you although I don't think they do because they wouldn't have any visibility of your internal network. Also, if the ISP is doing NAT for your inside network when you add extra networks behind the firewall you either need to ask the ISP to NAT those ones as well or apply NAT on the firewall which I recommend.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 16:02:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209738#M1116620</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-10-16T16:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Asa 5520 no internet.Please help.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209759#M1116624</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/431646"&gt;@antrikos_kal&lt;/a&gt; you appear to be running ASA Version 8.0(5) which has completely different NAT syntax to the modern ASA. Refer to the Dynamic PAT example &lt;A href="https://community.cisco.com/t5/security-knowledge-base/asa-pre-8-3-to-8-3-nat-configuration-examples/ta-p/3116375" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/asa-pre-8-3-to-8-3-nat-configuration-examples/ta-p/3116375&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Your outside interface is configured to receive an IP address and the default route via DHCP, I assume you get a DHCP address on the outside interface? You haven't received the default route (via setroute command), so you'd still need the static default route as already mentioned.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 16:35:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209759#M1116624</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-10-16T16:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Asa 5520 no internet.Please help.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209763#M1116626</link>
      <description>&lt;P&gt;Very good spot&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2024 16:40:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5209763#M1116626</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-10-16T16:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Asa 5520 no internet.Please help.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5211163#M1116732</link>
      <description>&lt;P&gt;Hi thank you all you guys my greetings from Greece, i recently lost my dad who was electronic engineer and was working in the national tv and the antennas.unfortunately he got cancer, but thank god he didn't have on bones or brain he died peacefuly on his sleep by cardiac arrest.When i will get better pshycologicaly i will try all the notes you gave me.God bless you all and away the sicknessess from you and your families.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 13:55:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5211163#M1116732</guid>
      <dc:creator>antrikos_kal</dc:creator>
      <dc:date>2024-10-18T13:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Asa 5520 no internet.Please help.</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5211187#M1116734</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/431646"&gt;@antrikos_kal&lt;/a&gt;, sorry to hear this, and my deepest condolences for you and your family's loss.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 14:41:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-no-internet-please-help/m-p/5211187#M1116734</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-10-18T14:41:14Z</dc:date>
    </item>
  </channel>
</rss>

