<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Okay, I didn't know that. I in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-internet-access/m-p/3061054#M135728</link>
    <description>&lt;P&gt;Okay, I didn't know that. I tried pinging from the router connected to the ASA (10.1.0.2)&lt;/P&gt;
&lt;TABLE style="width: 100%;"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 10.1.0.1, timeout is 2 seconds:&lt;BR /&gt;Packet sent with a source address of 10.1.0.2&lt;BR /&gt;.!!!!&lt;BR /&gt;Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms&lt;BR /&gt;WAN_Router#ping 8.8.8.8 source 10.1.0.2&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:&lt;BR /&gt;Packet sent with a source address of 10.1.0.2&lt;BR /&gt;.....&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It couldn't even talk to the DNS server (8.8.8.8), which I am assuming because it cannot get out past the ASA.&lt;/P&gt;</description>
    <pubDate>Wed, 10 May 2017 02:34:27 GMT</pubDate>
    <dc:creator>Shawnw4401</dc:creator>
    <dc:date>2017-05-10T02:34:27Z</dc:date>
    <item>
      <title>ASA Internet Access</title>
      <link>https://community.cisco.com/t5/network-security/asa-internet-access/m-p/3061052#M135726</link>
      <description>&lt;P&gt;Can someone please help me with this ASA? I'm new to working on ASAs and trying to learn more about them. This is just a test lab ASA for home environment purposes. Security practices aren't my main concern right now. I am just trying to learn how to configure it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Right now, I have a pretty much a blank ASA, aside from my interfaces and NATreferences.&amp;nbsp;&lt;/P&gt;
&lt;TABLE style="width: 100%; padding-left: 30px;"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;interface Ethernet0/0&lt;BR /&gt;description To &lt;G class="gr_ gr_487 gr-alert gr_gramm gr_inline_cards gr_run_anim Grammar multiReplace" id="487" data-gr-id="487"&gt;Internet&lt;/G&gt;&lt;BR /&gt;&lt;G class="gr_ gr_482 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="482" data-gr-id="482"&gt;nameif&lt;/G&gt; Outside&lt;BR /&gt;security-level 0&lt;BR /&gt;&lt;G class="gr_ gr_483 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="483" data-gr-id="483"&gt;ip&lt;/G&gt; address &lt;G class="gr_ gr_484 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="484" data-gr-id="484"&gt;dhcp&lt;/G&gt;&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;description To Secondary_LAN_Router&lt;BR /&gt;&lt;G class="gr_ gr_488 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="488" data-gr-id="488"&gt;nameif&lt;/G&gt; Secondary_LAN&lt;BR /&gt;security-level 100&lt;BR /&gt;&lt;G class="gr_ gr_489 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="489" data-gr-id="489"&gt;ip&lt;/G&gt; address 10.2.0.1 255.255.255.252&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;description To Primary_LAN_Router&lt;BR /&gt;&lt;G class="gr_ gr_492 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="492" data-gr-id="492"&gt;nameif&lt;/G&gt; Primary_LAN&lt;BR /&gt;security-level 100&lt;BR /&gt;&lt;G class="gr_ gr_481 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="481" data-gr-id="481"&gt;ip&lt;/G&gt; address 10.1.0.1 255.255.255.252&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;description To Honeypot&lt;BR /&gt;&lt;G class="gr_ gr_485 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="485" data-gr-id="485"&gt;nameif&lt;/G&gt; Honeypot&lt;BR /&gt;security-level 0&lt;BR /&gt;&lt;G class="gr_ gr_486 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="486" data-gr-id="486"&gt;ip&lt;/G&gt; address 192.168.0.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;management-only&lt;BR /&gt;&lt;G class="gr_ gr_490 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="490" data-gr-id="490"&gt;nameif&lt;/G&gt; management&lt;BR /&gt;security-level 100&lt;BR /&gt;&lt;G class="gr_ gr_491 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="491" data-gr-id="491"&gt;ip&lt;/G&gt; address 192.168.100.2 255.255.255.0&lt;/P&gt;
&lt;P&gt;object network Permit_Secondary_LAN&lt;BR /&gt;subnet 10.2.0.0 255.255.255.252&lt;BR /&gt;object network Permit_Primary_LAN&lt;BR /&gt;subnet 10.1.0.0 255.255.255.252&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging &lt;G class="gr_ gr_807 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="807" data-gr-id="807"&gt;asdm&lt;/G&gt; informational&lt;BR /&gt;&lt;G class="gr_ gr_808 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="808" data-gr-id="808"&gt;mtu&lt;/G&gt; management 1500&lt;BR /&gt;&lt;G class="gr_ gr_809 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="809" data-gr-id="809"&gt;mtu&lt;/G&gt; Outside 1500&lt;BR /&gt;&lt;G class="gr_ gr_810 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="810" data-gr-id="810"&gt;mtu&lt;/G&gt; Secondary_LAN 1500&lt;BR /&gt;&lt;G class="gr_ gr_811 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="811" data-gr-id="811"&gt;mtu&lt;/G&gt; Primary_LAN 1500&lt;BR /&gt;&lt;G class="gr_ gr_812 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="812" data-gr-id="812"&gt;mtu&lt;/G&gt; Honeypot 1500&lt;BR /&gt;no failover&lt;BR /&gt;&lt;G class="gr_ gr_813 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="813" data-gr-id="813"&gt;icmp&lt;/G&gt; unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no &lt;G class="gr_ gr_814 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="814" data-gr-id="814"&gt;asdm&lt;/G&gt; history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;nat &lt;G class="gr_ gr_816 gr-alert gr_gramm gr_inline_cards gr_run_anim Style replaceWithoutSep" id="816" data-gr-id="816"&gt;(Secondary_LAN,Outside)&lt;/G&gt; source dynamic Permit_Secondary_LAN pat-pool interface&lt;BR /&gt;nat &lt;G class="gr_ gr_817 gr-alert gr_gramm gr_inline_cards gr_run_anim Style replaceWithoutSep" id="817" data-gr-id="817"&gt;(Primary_LAN,Outside)&lt;/G&gt; source dynamic Permit_Primary_LAN pat-pool interface&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please let me know if I am missing anything. Right now I cannot ping the internet from an inside interface, but I can from my outside.&lt;/P&gt;
&lt;TABLE style="width: 100%;"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;G class="gr_ gr_2406 gr-alert gr_spell gr_inline_cards gr_run_anim ContextualSpelling ins-del multiReplace" id="2406" data-gr-id="2406"&gt;ciscoasa&lt;/G&gt;(config)# ping Outside google.com&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 24.220.112.147, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 20/20/20 ms&lt;BR /&gt;ciscoasa(config)# ping Pri&lt;BR /&gt;ciscoasa(config)# ping Primary_LAN google.com&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 24.220.112.147, timeout is 2 seconds:&lt;BR /&gt;?????&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ciscoasa(config)# show nat&lt;BR /&gt;Manual NAT Policies (Section 1)&lt;BR /&gt;1 (Secondary_LAN) to (Outside) source dynamic Permit_Secondary_LAN pat-pool interface&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;2 (Primary_LAN) to (Outside) source dynamic Permit_Primary_LAN pat-pool interface&lt;BR /&gt;translate_hits = 0, untranslate_hits = 0&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;All help is greatly appreciated. Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:20:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-internet-access/m-p/3061052#M135726</guid>
      <dc:creator>Shawnw4401</dc:creator>
      <dc:date>2019-03-12T09:20:12Z</dc:date>
    </item>
    <item>
      <title>you can't ping internet from</title>
      <link>https://community.cisco.com/t5/network-security/asa-internet-access/m-p/3061053#M135727</link>
      <description>&lt;P&gt;you can't ping internet from inside interface, If you want to test internet connectivity connect a PC behind&amp;nbsp;&lt;SPAN&gt;Primary_LAN interface you should be able to ping/access internet sites.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 01:47:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-internet-access/m-p/3061053#M135727</guid>
      <dc:creator>Ashish Jhaldiyal</dc:creator>
      <dc:date>2017-05-10T01:47:45Z</dc:date>
    </item>
    <item>
      <title>Okay, I didn't know that. I</title>
      <link>https://community.cisco.com/t5/network-security/asa-internet-access/m-p/3061054#M135728</link>
      <description>&lt;P&gt;Okay, I didn't know that. I tried pinging from the router connected to the ASA (10.1.0.2)&lt;/P&gt;
&lt;TABLE style="width: 100%;"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 10.1.0.1, timeout is 2 seconds:&lt;BR /&gt;Packet sent with a source address of 10.1.0.2&lt;BR /&gt;.!!!!&lt;BR /&gt;Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/1 ms&lt;BR /&gt;WAN_Router#ping 8.8.8.8 source 10.1.0.2&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:&lt;BR /&gt;Packet sent with a source address of 10.1.0.2&lt;BR /&gt;.....&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It couldn't even talk to the DNS server (8.8.8.8), which I am assuming because it cannot get out past the ASA.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 02:34:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-internet-access/m-p/3061054#M135728</guid>
      <dc:creator>Shawnw4401</dc:creator>
      <dc:date>2017-05-10T02:34:27Z</dc:date>
    </item>
    <item>
      <title>Shawn,</title>
      <link>https://community.cisco.com/t5/network-security/asa-internet-access/m-p/3061055#M135729</link>
      <description>&lt;P&gt;Shawn,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I see some issue with NAT, Do you want to translate LAN subnets with&amp;nbsp;&lt;SPAN&gt;pat-pool or Outside interface IP?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;you can try this&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;nat (Secondary_LAN,Outside) source dynamic Permit_Secondary_LAN interface&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;nat (Primary_LAN,Outside) source dynamic Permit_Primary_LAN interface&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 02:45:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-internet-access/m-p/3061055#M135729</guid>
      <dc:creator>Ashish Jhaldiyal</dc:creator>
      <dc:date>2017-05-10T02:45:57Z</dc:date>
    </item>
    <item>
      <title>Ashish,</title>
      <link>https://community.cisco.com/t5/network-security/asa-internet-access/m-p/3061056#M135730</link>
      <description>&lt;P&gt;Ashish,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Changing the NAT statement didn't change anything. What I am trying to do is equivalent to the router side when putting in a nat translation [ip nat inside source list &lt;I&gt;access-list&lt;/I&gt; &lt;G class="gr_ gr_695 gr-alert gr_gramm gr_inline_cards gr_run_anim Style only-del replaceWithoutSep" id="695" data-gr-id="695"&gt;interface&amp;nbsp;&lt;/G&gt;&lt;EM&gt;&lt;G class="gr_ gr_695 gr-alert gr_gramm gr_inline_cards gr_disable_anim_appear Style only-del replaceWithoutSep" id="695" data-gr-id="695"&gt;interface&lt;/G&gt; &lt;/EM&gt;overload].&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2017 23:10:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-internet-access/m-p/3061056#M135730</guid>
      <dc:creator>Shawnw4401</dc:creator>
      <dc:date>2017-05-10T23:10:42Z</dc:date>
    </item>
    <item>
      <title>Make sure you have an access</title>
      <link>https://community.cisco.com/t5/network-security/asa-internet-access/m-p/3061057#M135731</link>
      <description>&lt;P dir="ltr"&gt;Make sure you have an access list that allows icmp reply, because by default ASA doesn't inspect icmp packets. By default Asa only inspects TCP and udp. You can create an access list allowing icmp and apply it to ASAs outside interface.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can use packet tracer utility to check where the packet is dropping.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;packet-tracer input secondary_lan icmp x.x.x.x 8 0 8.8.8.8&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;replace x.x.x.x with source address&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;also so if you are trying to ping an outside address like Google DNS from a device that's behind the firewall just make sure that device has a default gateway configured&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2017 00:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-internet-access/m-p/3061057#M135731</guid>
      <dc:creator>cofee</dc:creator>
      <dc:date>2017-05-11T00:04:20Z</dc:date>
    </item>
  </channel>
</rss>

