<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Correction:  I just refreshed in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045678#M144955</link>
    <description>&lt;P&gt;Correction: &amp;nbsp;I just refreshed from the device, and was able to modify the Rules. &amp;nbsp;Am only seeing the new rule now. &amp;nbsp;But still I don't have internet. &amp;nbsp;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Apr 2017 13:14:02 GMT</pubDate>
    <dc:creator>fbrunell</dc:creator>
    <dc:date>2017-04-19T13:14:02Z</dc:date>
    <item>
      <title>5506 No internet access</title>
      <link>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045675#M144952</link>
      <description>&lt;P&gt;New to this, forgive me.&amp;nbsp; I'm trying to configure a new 5506 to firewall two internet connections into my existing network.&amp;nbsp; For testing, I have a laptop connected to the 5506 and a line from my cable internet connected as well.&amp;nbsp; Every time I try to change the inside network to our IP schema, I break it.&amp;nbsp; If I drop back to default mode,&amp;nbsp;internet works again.&amp;nbsp; I should add, that I was experiencing the same problem on an old&amp;nbsp;5505 I was playing around with before.&amp;nbsp; Trying to use the ASDM primarily for this.&amp;nbsp; Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:13:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045675#M144952</guid>
      <dc:creator>fbrunell</dc:creator>
      <dc:date>2019-03-12T09:13:58Z</dc:date>
    </item>
    <item>
      <title>Hi fbrunell@wfft.com,</title>
      <link>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045676#M144953</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://supportforums.cisco.com/users/fbrunellwfftcom" title="View user profile." class="username" lang="" about="/users/fbrunellwfftcom" typeof="sioc:UserAccount" property="foaf:name" datatype=""&gt;fbrunell@wfft.com&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I can definitely help you fixing this really quick by checking your current config through the outputs of the CLI, now if you are trying to learn through ASDM you can take a look to the following guide:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/ip/network-address-translation-nat/118996-config-asa-00.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope this info helps!!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rate if helps you!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-JP-&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 01:17:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045676#M144953</guid>
      <dc:creator>JP Miranda Z</dc:creator>
      <dc:date>2017-04-19T01:17:02Z</dc:date>
    </item>
    <item>
      <title>Thanks for getting back to me</title>
      <link>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045677#M144954</link>
      <description>&lt;P&gt;Thanks for getting back to me. &amp;nbsp;I was using dynamic PAT, but not in a specific manner like that. &amp;nbsp;I am still having a problem. &amp;nbsp;Right now I have 4 rules in the NAT rules table. &amp;nbsp;I've tried moving the new rule to the top of the list, and I've tried deleting the other rules, but neither command works. &amp;nbsp;It looks like the one&amp;nbsp;rule higher in the list is static, so I presume that rule would prevent my new rule from working.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 13:08:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045677#M144954</guid>
      <dc:creator>fbrunell</dc:creator>
      <dc:date>2017-04-19T13:08:56Z</dc:date>
    </item>
    <item>
      <title>Correction:  I just refreshed</title>
      <link>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045678#M144955</link>
      <description>&lt;P&gt;Correction: &amp;nbsp;I just refreshed from the device, and was able to modify the Rules. &amp;nbsp;Am only seeing the new rule now. &amp;nbsp;But still I don't have internet. &amp;nbsp;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 13:14:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045678#M144955</guid>
      <dc:creator>fbrunell</dc:creator>
      <dc:date>2017-04-19T13:14:02Z</dc:date>
    </item>
    <item>
      <title>Can share the configuration</title>
      <link>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045679#M144956</link>
      <description>&lt;P&gt;Can share the configuration you are trying to use?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you are sure the configuration is right will be necessary to get in to the ASA through the CLI and check a couple of commands:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;sh xlate&lt;/P&gt;
&lt;P&gt;packet-tracer input inside icmp &amp;lt;insideip&amp;gt; 8 0 4.2.2.2 detail&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope this info helps!!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rate if helps you!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-JP-&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 13:25:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045679#M144956</guid>
      <dc:creator>JP Miranda Z</dc:creator>
      <dc:date>2017-04-19T13:25:16Z</dc:date>
    </item>
    <item>
      <title>I'm not sure now much you</title>
      <link>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045680#M144957</link>
      <description>&lt;P&gt;I'm not sure now much you want to know about the config, but I have the following interfaces: outside (DHCP), &amp;nbsp;inside (not using, but enabled), insidemain (10.142.0.10), outside2 (DHCP, not connected yet but enabled). &amp;nbsp;I setup the NAT rule as directed under the PAT section with an IP of 10.142.0.0 255.255.0.0 and source interface of insidemain.&lt;/P&gt;
&lt;P&gt;And here are the CLI commands requested:&lt;/P&gt;
&lt;P&gt;inftwof1rtr010# sh xlate&lt;BR /&gt;0 in use, 1 most used&lt;/P&gt;
&lt;P&gt;inftwof1rtr010# packet-tracer input insidemain icmp 10.142.0.15 8 0 4.2.2.2 de$&lt;/P&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;found next-hop 10.1.10.1 using egress ifc outside&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;object network obj_10.142.0.0&lt;BR /&gt; nat (insidemain,outside) dynamic interface&lt;BR /&gt;Additional Information:&lt;BR /&gt;Dynamic translate 10.142.0.15/0 to 10.1.10.66/64682&lt;BR /&gt; Forward Flow based lookup yields rule:&lt;BR /&gt; in id=0x2aaac23aed40, priority=6, domain=nat, deny=false&lt;BR /&gt; hits=0, user_data=0x2aaac2360060, cs_id=0x0, flags=0x0, protocol=0&lt;BR /&gt; src ip/id=10.142.0.0, mask=255.255.0.0, port=0, tag=any&lt;BR /&gt; dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any, dscp=0x0&lt;BR /&gt; input_ifc=insidemain, output_ifc=outside&lt;/P&gt;
&lt;P&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt; Forward Flow based lookup yields rule:&lt;BR /&gt; in id=0x2aaac0ca6ff0, priority=0, domain=nat-per-session, deny=true&lt;BR /&gt; hits=65, user_data=0x0, cs_id=0x0, reverse, use_real_addr, flags=0x0, pr&lt;BR /&gt;otocol=0&lt;BR /&gt; src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any&lt;BR /&gt; dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any, dscp=0x0&lt;BR /&gt; input_ifc=any, output_ifc=any&lt;/P&gt;
&lt;P&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt; Forward Flow based lookup yields rule:&lt;BR /&gt; in id=0x2aaac17b4c20, priority=0, domain=inspect-ip-options, deny=true&lt;BR /&gt; hits=213, user_data=0x0, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;BR /&gt; src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any&lt;BR /&gt; dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any, dscp=0x0&lt;BR /&gt; input_ifc=insidemain, output_ifc=any&lt;/P&gt;
&lt;P&gt;Phase: 5&lt;BR /&gt;Type: INSPECT&lt;BR /&gt;Subtype: np-inspect&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt; Forward Flow based lookup yields rule:&lt;BR /&gt; in id=0x2aaac17b4430, priority=66, domain=inspect-icmp-error, deny=false&lt;BR /&gt; hits=2, user_data=0x2aaac17b39a0, cs_id=0x0, use_real_addr, flags=0x0, p&lt;BR /&gt;rotocol=1&lt;BR /&gt; src ip/id=0.0.0.0, mask=0.0.0.0, icmp-type=0, tag=any&lt;BR /&gt; dst ip/id=0.0.0.0, mask=0.0.0.0, icmp-code=0, tag=any, dscp=0x0&lt;BR /&gt; input_ifc=insidemain, output_ifc=any&lt;/P&gt;
&lt;P&gt;Phase: 6&lt;BR /&gt;Type: USER-STATISTICS&lt;BR /&gt;Subtype: user-statistics&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt; Forward Flow based lookup yields rule:&lt;BR /&gt; out id=0x2aaac228e960, priority=0, domain=user-statistics, deny=false&lt;BR /&gt; hits=27, user_data=0x2aaac1dc1450, cs_id=0x0, reverse, flags=0x0, protoc&lt;BR /&gt;ol=0&lt;BR /&gt; src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any&lt;BR /&gt; dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any, dscp=0x0&lt;BR /&gt; input_ifc=any, output_ifc=outside&lt;/P&gt;
&lt;P&gt;Phase: 7&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 146, packet dispatched to next module&lt;BR /&gt;Module information for forward flow ...&lt;BR /&gt;snp_fp_tracer_drop&lt;BR /&gt;snp_fp_inspect_ip_options&lt;BR /&gt;snp_fp_translate&lt;BR /&gt;snp_fp_adjacency&lt;BR /&gt;snp_fp_fragment&lt;BR /&gt;snp_ifc_stat&lt;/P&gt;
&lt;P&gt;Module information for reverse flow ...&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2017 13:59:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045680#M144957</guid>
      <dc:creator>fbrunell</dc:creator>
      <dc:date>2017-04-19T13:59:29Z</dc:date>
    </item>
    <item>
      <title>OK, I figured out that the</title>
      <link>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045681#M144958</link>
      <description>&lt;P&gt;OK, I figured out that the issue was with DNS. &amp;nbsp;If I turn on DHCP with auto-config from "outside" interface, it will work. &amp;nbsp;However, this is not how it will be setup in the working environment. &amp;nbsp;So, my question is perhaps more of a "best-practice" question. &amp;nbsp;Should I setup my existing DNS server with forwarding to the DNS server IPs from my ISP, or would I setup forwarding to the ASA and setup the DNS server list there?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 19:44:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045681#M144958</guid>
      <dc:creator>fbrunell</dc:creator>
      <dc:date>2017-04-21T19:44:48Z</dc:date>
    </item>
    <item>
      <title>So I got the DNS question</title>
      <link>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045682#M144959</link>
      <description>&lt;P&gt;So I got the DNS question resolved, I think. &amp;nbsp;I've setup my DNS server for forwarding. &amp;nbsp;Will find out for sure shortly when I deploy the ASA in my network. &amp;nbsp;I was having another issue getting my second ISP to work, that turned out to be a routing problem, solution here:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118962-configure-asa-00.html&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 16:51:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/5506-no-internet-access/m-p/3045682#M144959</guid>
      <dc:creator>fbrunell</dc:creator>
      <dc:date>2017-04-24T16:51:04Z</dc:date>
    </item>
  </channel>
</rss>

