<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5505 Slow Internet/Strict Nat/Settings in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-slow-internet-strict-nat-settings/m-p/3074010#M145684</link>
    <description>&lt;P&gt;I've been scratching my head on this one for the past few days. I cannot figure it out and I'm sure it's something I'm missing. I could really use somebody's help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So I recently installed a Cisco ASA 5505 and finally got it configured and up and running. I have internet access. However, it's extremely flakey and slow. Before hand I was getting 90~down and 25~up. Now it's 20~down (maybe) and 5~up. Also getting a STRICT NAT on my Xbox One.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here's my network setup to kind of paint a picture.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;------------------------------------------------------------------------------------------&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;ISP--&amp;gt; MODEM --&amp;gt; ASA 5505 --&amp;gt; PATCH PANEL --&amp;gt; CATALYST 3550 SWITCH&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;------------------------------------------------------------------------------------------&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So the ISP goes to Modem, Modem goes into the ASA, the ASA goes into the Patch panel, then Patch panel to Cisco Switch. The other machines in the house go into the patch panel and then into the switch.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also, my neighbor is our DHCP server. A CAT6 cable is running from his house to ours and plugs directly into the switch. That's never been an issue though.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline; font-size: 18pt;"&gt;&lt;STRONG&gt;Here's the Running-Config on the Catalyst 3550 Switch:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Current configuration : 4455 bytes&lt;BR /&gt;!&lt;BR /&gt;version 12.2&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname bmasswitch&lt;BR /&gt;!&lt;BR /&gt;enable secret 5 XXX.&lt;BR /&gt;!&lt;BR /&gt;no aaa new-model&lt;BR /&gt;ip subnet-zero&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki trustpoint TP-self-signed-4155860992&lt;BR /&gt; enrollment selfsigned&lt;BR /&gt; subject-name cn=IOS-Self-Signed-Certificate-4155860992&lt;BR /&gt; revocation-check none&lt;BR /&gt; rsakeypair TP-self-signed-4155860992&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki certificate chain TP-self-signed-4155860992&lt;BR /&gt; certificate self-signed 01&lt;BR /&gt; 30820243 308201AC A0030201 02020101 300D0609 2A864886 F70D0101 04050030&lt;BR /&gt; 31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274&lt;BR /&gt; 69666963 6174652D 34313535 38363039 3932301E 170D3933 30333031 30303031&lt;BR /&gt; 30355A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649&lt;BR /&gt; 4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D34 31353538&lt;BR /&gt; 36303939 3230819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281&lt;BR /&gt; 8100C442 B3578F33 2B8941B1 BCF4D4E5 A09A926E D176104C 81B3E6E3 A21CB279&lt;BR /&gt; 5EB9BC87 2222CE2A 8B41EAFB 26E7F85B 40EEA546 3298DE98 DC162E41 A4C2583B&lt;BR /&gt; F63EA522 10B0DADD D58770FC 6F50C04F 975FD969 E1D07F94 EB60E24B E9F0BC2D&lt;BR /&gt; 9A3E1477 71751A25 DF6D6788 3299840E 5E4201FD E11139E5 FF2194E5 10296F15&lt;BR /&gt; 04170203 010001A3 6B306930 0F060355 1D130101 FF040530 030101FF 30160603&lt;BR /&gt; 551D1104 0F300D82 0B626D61 73737769 7463682E 301F0603 551D2304 18301680&lt;BR /&gt; 14EF6569 8BFEAD3C 68F6CFA6 1A40A0B9 EE795FEA AE301D06 03551D0E 04160414&lt;BR /&gt; EF65698B FEAD3C68 F6CFA61A 40A0B9EE 795FEAAE 300D0609 2A864886 F70D0101&lt;BR /&gt; 04050003 81810080 01862D72 83EC7319 59922A94 F46203F2 DF640071 C1A9F280&lt;BR /&gt; 86C646FF 45AB7D14 9C13F10F 7149EDEF 9486602F 841864D8 DA683335 E0C80E3B&lt;BR /&gt; 03A172EC 6DB665E1 5CCDA8BF 20B3176D B90EF134 B1288E3D FF693850 DCC3D8E2&lt;BR /&gt; 5BB66523 889C7197 E0151357 85A3EA7A 1E48A2CB 24CF6A4E 8C7AFC7E 2A5C13F3&lt;BR /&gt; F10E3115 0F9282&lt;BR /&gt; quit&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;spanning-tree mode pvst&lt;BR /&gt;spanning-tree extend system-id&lt;BR /&gt;!&lt;BR /&gt;vlan internal allocation policy ascending&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/2&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/3&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/4&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/5&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/6&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/7&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/8&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/9&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/10&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/11&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/12&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/13&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/14&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/15&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/16&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/17&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/18&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/19&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/20&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/21&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/22&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/23&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/24&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; no ip address&lt;BR /&gt; shutdown&lt;BR /&gt;!&lt;BR /&gt;ip default-gateway XX.XX.XX.XX&lt;BR /&gt;ip classless&lt;BR /&gt;ip http server&lt;BR /&gt;ip http secure-server&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;control-plane&lt;BR /&gt;!&lt;BR /&gt;banner motd ^Coto&lt;/P&gt;
&lt;P&gt;***************************************************&lt;/P&gt;
&lt;P&gt;UNAUTHORIZED ACCESS IS PROHIBITED!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;***************************************************^C&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt; exec-timeout 30 0&lt;BR /&gt; password 7 XXX&lt;BR /&gt; logging synchronous&lt;BR /&gt; login&lt;BR /&gt;line vty 0 4&lt;BR /&gt; exec-timeout 30 0&lt;BR /&gt; password 7 XXX&lt;BR /&gt; logging synchronous&lt;BR /&gt; login&lt;BR /&gt;line vty 5 15&lt;BR /&gt; login&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline; font-size: 18pt;"&gt;&lt;STRONG&gt;Running-Config on the ASA 5505:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA Version 8.2(5)&lt;BR /&gt;!&lt;BR /&gt;hostname bmas&lt;BR /&gt;domain-name nd.local&lt;BR /&gt;enable password XXX encrypted&lt;BR /&gt;passwd XXX encrypted&lt;BR /&gt;names&lt;BR /&gt;name XX.XX.XX.XX Xbox1 description Kevins Xbox&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; switchport access vlan 11&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address XXX.XXX.XXX.XXX 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan11&lt;BR /&gt; nameif Outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address dhcp setroute&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone EST -5&lt;BR /&gt;clock summer-time EDT recurring&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt; domain-name nd.local&lt;BR /&gt;object-group protocol TCPUDP&lt;BR /&gt; protocol-object udp&lt;BR /&gt; protocol-object tcp&lt;BR /&gt;access-list Outside_access_in extended permit udp any host Xbox1 eq isakmp&lt;BR /&gt;access-list Outside_access_in extended permit udp any host Xbox1 eq 88&lt;BR /&gt;access-list Outside_access_in extended permit object-group TCPUDP any host Xbox1 eq 3074&lt;BR /&gt;access-list Outside_access_in extended permit object-group TCPUDP any host Xbox1 eq domain&lt;BR /&gt;access-list Outside_access_in extended permit tcp any host Xbox1 eq www&lt;BR /&gt;access-list Outside_access_in extended permit udp any host Xbox1 eq 3544&lt;BR /&gt;access-list Outside_access_in extended permit udp any host Xbox1 eq 4500&lt;BR /&gt;pager lines 24&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu Outside 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;nat-control&lt;BR /&gt;global (Outside) 101 interface&lt;BR /&gt;nat (inside) 101 0.0.0.0 0.0.0.0&lt;BR /&gt;static (inside,Outside) udp interface isakmp Xbox1 isakmp netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) udp interface 88 Xbox1 88 netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) tcp interface 3074 Xbox1 3074 netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) udp interface 3074 Xbox1 3074 netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) tcp interface domain Xbox1 domain netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) udp interface domain Xbox1 domain netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) tcp interface www Xbox1 www netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) udp interface 3544 Xbox1 3544 netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) udp interface 4500 Xbox1 4500 netmask 255.255.255.255&lt;BR /&gt;access-group Outside_access_in in interface Outside&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;http server enable&lt;BR /&gt;http XXX.XXX.XX.XX 255.255.255.255 inside&lt;BR /&gt;http XXX.XXX.XX.XX 255.255.255.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcp-client client-id interface Outside&lt;/P&gt;
&lt;P&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;webvpn&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt; message-length maximum client auto&lt;BR /&gt; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt; inspect dns preset_dns_map&lt;BR /&gt; inspect ftp&lt;BR /&gt; inspect h323 h225&lt;BR /&gt; inspect h323 ras&lt;BR /&gt; inspect ip-options&lt;BR /&gt; inspect netbios&lt;BR /&gt; inspect rsh&lt;BR /&gt; inspect rtsp&lt;BR /&gt; inspect skinny&lt;BR /&gt; inspect esmtp&lt;BR /&gt; inspect sqlnet&lt;BR /&gt; inspect sunrpc&lt;BR /&gt; inspect tftp&lt;BR /&gt; inspect sip&lt;BR /&gt; inspect xdmcp&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt; profile CiscoTAC-1&lt;BR /&gt; no active&lt;BR /&gt; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt; destination address email callhome@cisco.com&lt;BR /&gt; destination transport-method http&lt;BR /&gt; subscribe-to-alert-group diagnostic&lt;BR /&gt; subscribe-to-alert-group environment&lt;BR /&gt; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt; subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:36b0759fec664b1a3323dcfc1e968d89&lt;BR /&gt;: end&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline; font-size: 18pt;"&gt;&lt;STRONG&gt;Here's the Interfaces on the ASA 5505:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/0 "", is up, line protocol is up&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex(Full-duplex), 100 Mbps(100 Mbps)&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 13914825 packets input, 15692491670 bytes, 0 no buffer&lt;BR /&gt; Received 1775589 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 104840 switch ingress policy drops&lt;BR /&gt; 5194165 packets output, 617637394 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/1 "", is down, line protocol is down&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex, 100 Mbps&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 switch ingress policy drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/2 "", is down, line protocol is down&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex, 100 Mbps&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 switch ingress policy drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/3 "", is up, line protocol is up&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex(Full-duplex), 100 Mbps(100 Mbps)&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 5913814 packets input, 777750420 bytes, 0 no buffer&lt;BR /&gt; Received 473595 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 14889 switch ingress policy drops&lt;BR /&gt; 12050570 packets output, 15565319160 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/4 "", is down, line protocol is down&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex, 100 Mbps&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 switch ingress policy drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/5 "", is down, line protocol is down&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex, 100 Mbps&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 switch ingress policy drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/6 "", is down, line protocol is down&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex, 100 Mbps&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 switch ingress policy drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/7 "", is down, line protocol is down&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex, 100 Mbps&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 switch ingress policy drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I apologize for the huge post but I'm trying to be thorough in hopes that someone out there can help me out.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you all for reading.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 09:05:11 GMT</pubDate>
    <dc:creator>Kevin Ware</dc:creator>
    <dc:date>2019-03-12T09:05:11Z</dc:date>
    <item>
      <title>ASA 5505 Slow Internet/Strict Nat/Settings</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-slow-internet-strict-nat-settings/m-p/3074010#M145684</link>
      <description>&lt;P&gt;I've been scratching my head on this one for the past few days. I cannot figure it out and I'm sure it's something I'm missing. I could really use somebody's help.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So I recently installed a Cisco ASA 5505 and finally got it configured and up and running. I have internet access. However, it's extremely flakey and slow. Before hand I was getting 90~down and 25~up. Now it's 20~down (maybe) and 5~up. Also getting a STRICT NAT on my Xbox One.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here's my network setup to kind of paint a picture.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;------------------------------------------------------------------------------------------&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;ISP--&amp;gt; MODEM --&amp;gt; ASA 5505 --&amp;gt; PATCH PANEL --&amp;gt; CATALYST 3550 SWITCH&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;------------------------------------------------------------------------------------------&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So the ISP goes to Modem, Modem goes into the ASA, the ASA goes into the Patch panel, then Patch panel to Cisco Switch. The other machines in the house go into the patch panel and then into the switch.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also, my neighbor is our DHCP server. A CAT6 cable is running from his house to ours and plugs directly into the switch. That's never been an issue though.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline; font-size: 18pt;"&gt;&lt;STRONG&gt;Here's the Running-Config on the Catalyst 3550 Switch:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Current configuration : 4455 bytes&lt;BR /&gt;!&lt;BR /&gt;version 12.2&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname bmasswitch&lt;BR /&gt;!&lt;BR /&gt;enable secret 5 XXX.&lt;BR /&gt;!&lt;BR /&gt;no aaa new-model&lt;BR /&gt;ip subnet-zero&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki trustpoint TP-self-signed-4155860992&lt;BR /&gt; enrollment selfsigned&lt;BR /&gt; subject-name cn=IOS-Self-Signed-Certificate-4155860992&lt;BR /&gt; revocation-check none&lt;BR /&gt; rsakeypair TP-self-signed-4155860992&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki certificate chain TP-self-signed-4155860992&lt;BR /&gt; certificate self-signed 01&lt;BR /&gt; 30820243 308201AC A0030201 02020101 300D0609 2A864886 F70D0101 04050030&lt;BR /&gt; 31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274&lt;BR /&gt; 69666963 6174652D 34313535 38363039 3932301E 170D3933 30333031 30303031&lt;BR /&gt; 30355A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649&lt;BR /&gt; 4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D34 31353538&lt;BR /&gt; 36303939 3230819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281&lt;BR /&gt; 8100C442 B3578F33 2B8941B1 BCF4D4E5 A09A926E D176104C 81B3E6E3 A21CB279&lt;BR /&gt; 5EB9BC87 2222CE2A 8B41EAFB 26E7F85B 40EEA546 3298DE98 DC162E41 A4C2583B&lt;BR /&gt; F63EA522 10B0DADD D58770FC 6F50C04F 975FD969 E1D07F94 EB60E24B E9F0BC2D&lt;BR /&gt; 9A3E1477 71751A25 DF6D6788 3299840E 5E4201FD E11139E5 FF2194E5 10296F15&lt;BR /&gt; 04170203 010001A3 6B306930 0F060355 1D130101 FF040530 030101FF 30160603&lt;BR /&gt; 551D1104 0F300D82 0B626D61 73737769 7463682E 301F0603 551D2304 18301680&lt;BR /&gt; 14EF6569 8BFEAD3C 68F6CFA6 1A40A0B9 EE795FEA AE301D06 03551D0E 04160414&lt;BR /&gt; EF65698B FEAD3C68 F6CFA61A 40A0B9EE 795FEAAE 300D0609 2A864886 F70D0101&lt;BR /&gt; 04050003 81810080 01862D72 83EC7319 59922A94 F46203F2 DF640071 C1A9F280&lt;BR /&gt; 86C646FF 45AB7D14 9C13F10F 7149EDEF 9486602F 841864D8 DA683335 E0C80E3B&lt;BR /&gt; 03A172EC 6DB665E1 5CCDA8BF 20B3176D B90EF134 B1288E3D FF693850 DCC3D8E2&lt;BR /&gt; 5BB66523 889C7197 E0151357 85A3EA7A 1E48A2CB 24CF6A4E 8C7AFC7E 2A5C13F3&lt;BR /&gt; F10E3115 0F9282&lt;BR /&gt; quit&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;spanning-tree mode pvst&lt;BR /&gt;spanning-tree extend system-id&lt;BR /&gt;!&lt;BR /&gt;vlan internal allocation policy ascending&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/2&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/3&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/4&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/5&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/6&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/7&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/8&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/9&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/10&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/11&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/12&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/13&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/14&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/15&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/16&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/17&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/18&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/19&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/20&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/21&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/22&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/23&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/24&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/2&lt;BR /&gt; switchport mode dynamic desirable&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; no ip address&lt;BR /&gt; shutdown&lt;BR /&gt;!&lt;BR /&gt;ip default-gateway XX.XX.XX.XX&lt;BR /&gt;ip classless&lt;BR /&gt;ip http server&lt;BR /&gt;ip http secure-server&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;control-plane&lt;BR /&gt;!&lt;BR /&gt;banner motd ^Coto&lt;/P&gt;
&lt;P&gt;***************************************************&lt;/P&gt;
&lt;P&gt;UNAUTHORIZED ACCESS IS PROHIBITED!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;***************************************************^C&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt; exec-timeout 30 0&lt;BR /&gt; password 7 XXX&lt;BR /&gt; logging synchronous&lt;BR /&gt; login&lt;BR /&gt;line vty 0 4&lt;BR /&gt; exec-timeout 30 0&lt;BR /&gt; password 7 XXX&lt;BR /&gt; logging synchronous&lt;BR /&gt; login&lt;BR /&gt;line vty 5 15&lt;BR /&gt; login&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline; font-size: 18pt;"&gt;&lt;STRONG&gt;Running-Config on the ASA 5505:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA Version 8.2(5)&lt;BR /&gt;!&lt;BR /&gt;hostname bmas&lt;BR /&gt;domain-name nd.local&lt;BR /&gt;enable password XXX encrypted&lt;BR /&gt;passwd XXX encrypted&lt;BR /&gt;names&lt;BR /&gt;name XX.XX.XX.XX Xbox1 description Kevins Xbox&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; switchport access vlan 11&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt; speed 100&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address XXX.XXX.XXX.XXX 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan11&lt;BR /&gt; nameif Outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address dhcp setroute&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone EST -5&lt;BR /&gt;clock summer-time EDT recurring&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt; domain-name nd.local&lt;BR /&gt;object-group protocol TCPUDP&lt;BR /&gt; protocol-object udp&lt;BR /&gt; protocol-object tcp&lt;BR /&gt;access-list Outside_access_in extended permit udp any host Xbox1 eq isakmp&lt;BR /&gt;access-list Outside_access_in extended permit udp any host Xbox1 eq 88&lt;BR /&gt;access-list Outside_access_in extended permit object-group TCPUDP any host Xbox1 eq 3074&lt;BR /&gt;access-list Outside_access_in extended permit object-group TCPUDP any host Xbox1 eq domain&lt;BR /&gt;access-list Outside_access_in extended permit tcp any host Xbox1 eq www&lt;BR /&gt;access-list Outside_access_in extended permit udp any host Xbox1 eq 3544&lt;BR /&gt;access-list Outside_access_in extended permit udp any host Xbox1 eq 4500&lt;BR /&gt;pager lines 24&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu Outside 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;nat-control&lt;BR /&gt;global (Outside) 101 interface&lt;BR /&gt;nat (inside) 101 0.0.0.0 0.0.0.0&lt;BR /&gt;static (inside,Outside) udp interface isakmp Xbox1 isakmp netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) udp interface 88 Xbox1 88 netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) tcp interface 3074 Xbox1 3074 netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) udp interface 3074 Xbox1 3074 netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) tcp interface domain Xbox1 domain netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) udp interface domain Xbox1 domain netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) tcp interface www Xbox1 www netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) udp interface 3544 Xbox1 3544 netmask 255.255.255.255&lt;BR /&gt;static (inside,Outside) udp interface 4500 Xbox1 4500 netmask 255.255.255.255&lt;BR /&gt;access-group Outside_access_in in interface Outside&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;http server enable&lt;BR /&gt;http XXX.XXX.XX.XX 255.255.255.255 inside&lt;BR /&gt;http XXX.XXX.XX.XX 255.255.255.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcp-client client-id interface Outside&lt;/P&gt;
&lt;P&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;webvpn&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt; message-length maximum client auto&lt;BR /&gt; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt; inspect dns preset_dns_map&lt;BR /&gt; inspect ftp&lt;BR /&gt; inspect h323 h225&lt;BR /&gt; inspect h323 ras&lt;BR /&gt; inspect ip-options&lt;BR /&gt; inspect netbios&lt;BR /&gt; inspect rsh&lt;BR /&gt; inspect rtsp&lt;BR /&gt; inspect skinny&lt;BR /&gt; inspect esmtp&lt;BR /&gt; inspect sqlnet&lt;BR /&gt; inspect sunrpc&lt;BR /&gt; inspect tftp&lt;BR /&gt; inspect sip&lt;BR /&gt; inspect xdmcp&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt; profile CiscoTAC-1&lt;BR /&gt; no active&lt;BR /&gt; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt; destination address email callhome@cisco.com&lt;BR /&gt; destination transport-method http&lt;BR /&gt; subscribe-to-alert-group diagnostic&lt;BR /&gt; subscribe-to-alert-group environment&lt;BR /&gt; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt; subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:36b0759fec664b1a3323dcfc1e968d89&lt;BR /&gt;: end&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-decoration: underline; font-size: 18pt;"&gt;&lt;STRONG&gt;Here's the Interfaces on the ASA 5505:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/0 "", is up, line protocol is up&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex(Full-duplex), 100 Mbps(100 Mbps)&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 13914825 packets input, 15692491670 bytes, 0 no buffer&lt;BR /&gt; Received 1775589 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 104840 switch ingress policy drops&lt;BR /&gt; 5194165 packets output, 617637394 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/1 "", is down, line protocol is down&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex, 100 Mbps&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 switch ingress policy drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/2 "", is down, line protocol is down&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex, 100 Mbps&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 switch ingress policy drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/3 "", is up, line protocol is up&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex(Full-duplex), 100 Mbps(100 Mbps)&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 5913814 packets input, 777750420 bytes, 0 no buffer&lt;BR /&gt; Received 473595 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 14889 switch ingress policy drops&lt;BR /&gt; 12050570 packets output, 15565319160 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/4 "", is down, line protocol is down&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex, 100 Mbps&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 switch ingress policy drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/5 "", is down, line protocol is down&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex, 100 Mbps&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 switch ingress policy drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/6 "", is down, line protocol is down&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex, 100 Mbps&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 switch ingress policy drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;Interface Ethernet0/7 "", is down, line protocol is down&lt;BR /&gt; Hardware is 88E6095, BW 100 Mbps, DLY 100 usec&lt;BR /&gt; Auto-Duplex, 100 Mbps&lt;BR /&gt; Input flow control is unsupported, output flow control is unsupported&lt;BR /&gt; Available but not configured via nameif&lt;BR /&gt; MAC address XXXX, MTU not set&lt;BR /&gt; IP address unassigned&lt;BR /&gt; 0 packets input, 0 bytes, 0 no buffer&lt;BR /&gt; Received 0 broadcasts, 0 runts, 0 giants&lt;BR /&gt; 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort&lt;BR /&gt; 0 pause input, 0 resume input&lt;BR /&gt; 0 L2 decode drops&lt;BR /&gt; 0 switch ingress policy drops&lt;BR /&gt; 0 packets output, 0 bytes, 0 underruns&lt;BR /&gt; 0 pause output, 0 resume output&lt;BR /&gt; 0 output errors, 0 collisions, 0 interface resets&lt;BR /&gt; 0 late collisions, 0 deferred&lt;BR /&gt; 0 rate limit drops&lt;BR /&gt; 0 switch egress policy drops&lt;BR /&gt; 0 input reset drops, 0 output reset drops&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I apologize for the huge post but I'm trying to be thorough in hopes that someone out there can help me out.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you all for reading.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:05:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-slow-internet-strict-nat-settings/m-p/3074010#M145684</guid>
      <dc:creator>Kevin Ware</dc:creator>
      <dc:date>2019-03-12T09:05:11Z</dc:date>
    </item>
  </channel>
</rss>

