<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firstly, you should know that in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955189#M150447</link>
    <description>&lt;P&gt;Firstly, you should know that the ip default-gateway has no effect at all when ip routing is enabled. The command is used when the switch operates at layer2 only. Basically the command does exactly the same as ip route 0.0.0.0 0.0.0.0 so they would be in conflict with each other.&lt;/P&gt;
&lt;P&gt;The new default route you have configure will cause all traffic which is routed in the switch to be forwarded on vlan 800, is that what you want?&lt;/P&gt;
&lt;P&gt;You broke the management since all traffic from the switch now is routed through vlan 800. You will need a route for the network where your management station is located pointning to 192.168.20.254, i.e. if your management station is located in the 172.16.10.0/24 subnet the route would look like this:&lt;/P&gt;
&lt;P&gt;ip route 172.16.10.0 255.255.255.0 192.168.20.254&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;SL&lt;/P&gt;</description>
    <pubDate>Fri, 26 Aug 2016 20:07:17 GMT</pubDate>
    <dc:creator>S-Lemming</dc:creator>
    <dc:date>2016-08-26T20:07:17Z</dc:date>
    <item>
      <title>ASA 5520 internet access problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955184#M150435</link>
      <description>&lt;P&gt;Hello, I have a problem with an ASA 5520. The thing is that in one of the interfaces I have connected a switch 3750 and connected to the switch a PC. This PC is in the same network that the ASA interface (10.229.0.0/24 and the switch is serving DHCP for the PC). That PC have full acess to the internet. So far no problem. Now I need to add another network to the switch (let's say 10.229.2.0/24) through a vlan, connect a PC to that network and give it access to the internet through the same interface, but the problem is that the PC doesn't reach the internet in any way. I've been trying for several days and several solutions but there's no possible way for me to do this. Can anybody helpme please??? At this point I'm very desperate. Here is some things that maybe help you to understand what I'm talking about:&lt;BR /&gt;&lt;BR /&gt;ASA interface ip: 10.229.0.1/24 connected directly to the 3750&lt;BR /&gt;ASA interface name: FTTH&lt;BR /&gt;Switch 3750 vlan800 ip: 10.229.0.2/24&lt;BR /&gt;&amp;nbsp;&amp;nbsp; ip dhcp pool FTTH-0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network 10.229.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; dns-server X.X.X.X &lt;BR /&gt;&amp;nbsp;&amp;nbsp; default-router 10.229.0.1 &lt;BR /&gt;Switch 3750 vlan802 ip: 10.229.2.2/24&lt;BR /&gt;&amp;nbsp;&amp;nbsp; ip dhcp pool FTTH-2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network 10.229.2.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; dns-server X.X.X.X &lt;BR /&gt;&amp;nbsp;&amp;nbsp; default-router 10.229.2.2 &lt;BR /&gt;ASA static route: route FTTH 10.229.2.0 255.255.255.0 10.229.0.2&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Need something else??? please let me know. Thank you very much in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:11:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955184#M150435</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2019-03-12T08:11:33Z</dc:date>
    </item>
    <item>
      <title>For traffic on vlan 802 to be</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955185#M150438</link>
      <description>&lt;P&gt;For traffic on vlan 802 to be able to reach vlan 800 where the ASA is you need to enable ip routing on the switch. Also you will need a default route looking like this: ip route 0.0.0.0 0.0.0.0 10.229.0.1.&lt;/P&gt;
&lt;P&gt;Another option is to set up vlan subinterfaces on the ASA so the firewall will do the routing. In that case you would need to configure the physical interface as a trunk on both ends.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;SL&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 09:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955185#M150438</guid>
      <dc:creator>S-Lemming</dc:creator>
      <dc:date>2016-08-26T09:32:25Z</dc:date>
    </item>
    <item>
      <title>Hi S-Lemming, from vlan 802 I</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955186#M150440</link>
      <description>&lt;P&gt;Hi &lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;A href="https://supportforums.cisco.com/users/s-lemming" title="View user profile." class="username" lang="" about="/users/s-lemming" typeof="sioc:UserAccount" property="foaf:name" datatype=""&gt;S-Lemming&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;, from vlan 802 I can ping 10.229.0.1 (ASA interface ip add.) so I think routing it's fine. Here are the basics of 3750:&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Sw3750-Site2#show running-config &lt;BR /&gt;Building configuration...&lt;BR /&gt;&lt;BR /&gt;Current configuration : 5256 bytes&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;version 12.2&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug uptime&lt;BR /&gt;service timestamps log uptime&lt;BR /&gt;service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname Sw3750-Site2&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;switch 1 provision ws-c3750g-12s&lt;BR /&gt;system mtu routing 1500&lt;BR /&gt;ip subnet-zero&lt;BR /&gt;ip routing&lt;BR /&gt;ip domain-name somosggl.com&lt;BR /&gt;ip dhcp excluded-address 10.229.0.1 10.229.0.10&lt;BR /&gt;ip dhcp excluded-address 10.229.2.1 10.229.2.10&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool FTTH-0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network 10.229.0.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; dns-server X.X.X.X &lt;BR /&gt;&amp;nbsp;&amp;nbsp; default-router 10.229.0.1 &lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool FTTH-2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network 10.229.2.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; dns-server X.X.X.X &lt;BR /&gt;&amp;nbsp;&amp;nbsp; default-router 10.229.2.2 &lt;BR /&gt;!&lt;BR /&gt;ip multicast-routing distributed&lt;BR /&gt;ip multicast multipath&lt;BR /&gt;ip ssh version 2&lt;BR /&gt;ip igmp snooping querier&lt;BR /&gt;ip igmp snooping vlan 69 mrouter learn cgmp&lt;BR /&gt;ip igmp profile 1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; range X.X.X.X X.X.X.X&lt;BR /&gt;ip igmp ssm-map enable&lt;BR /&gt;!&lt;BR /&gt;mvr vlan 69&lt;BR /&gt;mvr&lt;BR /&gt;mvr mode dynamic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;no file verify auto&lt;BR /&gt;spanning-tree mode pvst&lt;BR /&gt;spanning-tree extend system-id&lt;BR /&gt;!&lt;BR /&gt;vlan internal allocation policy ascending&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/1&lt;BR /&gt;&amp;nbsp;switchport trunk encapsulation dot1q&lt;BR /&gt;&amp;nbsp;switchport trunk allowed vlan 1,2,10,15,19,20,25,30,50,69,70,81,100,110,130&lt;BR /&gt;&amp;nbsp;switchport trunk allowed vlan add 140,150,160,170,180,190,200,230,450,700,800&lt;BR /&gt;&amp;nbsp;switchport trunk allowed vlan add 802,900&lt;BR /&gt;&amp;nbsp;switchport mode trunk&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/2&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/3&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/4&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;interface GigabitEthernet1/0/5&lt;BR /&gt;&amp;nbsp;description *** red FTTH ***&lt;BR /&gt;&amp;nbsp;switchport access vlan 800&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport nonegotiate&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/6&lt;BR /&gt;&amp;nbsp;description ** clientes carriers **&lt;BR /&gt;&amp;nbsp;switchport access vlan 900&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport nonegotiate&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/7&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/8&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;interface GigabitEthernet1/0/9&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;interface GigabitEthernet1/0/10&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/11&lt;BR /&gt;&amp;nbsp;!&lt;BR /&gt;interface GigabitEthernet1/0/12&lt;BR /&gt;&amp;nbsp;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan10&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan15&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan19&lt;BR /&gt;&amp;nbsp; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan20&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan25&lt;BR /&gt;&amp;nbsp; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan30&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan50&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan69&lt;BR /&gt;&amp;nbsp; no ip address&lt;BR /&gt;&amp;nbsp;ip pim dense-mode&lt;BR /&gt;&amp;nbsp;ip igmp static-group *&lt;BR /&gt;!&lt;BR /&gt;interface Vlan70&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;interface Vlan110&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan230&lt;BR /&gt;&amp;nbsp;ip address 192.168.20.223 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan450&lt;BR /&gt;&amp;nbsp; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan700&lt;BR /&gt;&amp;nbsp; ip address 10.211.0.11 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan800&lt;BR /&gt;&amp;nbsp;description *** red FTTH-0 ***&lt;BR /&gt;&amp;nbsp;ip address 10.229.0.2 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan802&lt;BR /&gt;&amp;nbsp;description *** red FTTH-2 ***&lt;BR /&gt;&amp;nbsp;ip address 10.229.2.2 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan803&lt;BR /&gt;&amp;nbsp;description *** red FTTH-3 ***&lt;BR /&gt;&amp;nbsp;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Vlan900&lt;BR /&gt;&amp;nbsp;description ** clientes carriers **&lt;BR /&gt;&amp;nbsp;ip address 10.227.224.2 255.255.252.0&lt;BR /&gt;!&lt;BR /&gt;ip default-gateway 192.168.200.254&lt;BR /&gt;ip classless&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 192.168.20.254&lt;BR /&gt;ip http server&lt;BR /&gt;ip http secure-server&lt;BR /&gt;!&lt;BR /&gt;ip pim autorp listener&lt;BR /&gt;ip pim accept-rp auto-rp&lt;BR /&gt;!&lt;BR /&gt;ip access-list standard ELCACTI&lt;BR /&gt;!&lt;BR /&gt;logging 192.168.0.3&lt;BR /&gt;snmp-server community sw3750 RO ELCACTI&lt;BR /&gt;snmp-server enable traps license&lt;BR /&gt;radius-server source-ports 1645-1646&lt;BR /&gt;!&lt;BR /&gt;control-plane&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What do you think? &lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 14:50:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955186#M150440</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2016-08-26T14:50:23Z</dc:date>
    </item>
    <item>
      <title>You are using a different</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955187#M150443</link>
      <description>&lt;P&gt;You are using a different default gateway in your routing.&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN style="font-size: 12.0pt; font-family: 'Times New Roman',serif;"&gt;ip route 0.0.0.0 0.0.0.0 192.168.20.254&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;This is your problem. Any packets destined for unknown addresses (as in IP addresses your 3750 does not have a specific route for) will hit this route. So the traffic from vlan 802 will be routed here.&lt;/P&gt;
&lt;P&gt;You have two options, either configure vlan 802 as an interface in the ASA and let it do all the routing for the vlan or you can configure policy based routing in the 3750. What this does is allow you to set up rules for how traffic is routed.&lt;/P&gt;
&lt;P&gt;It would like this:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;access-list 10 permit 10.229.2.0 0.0.0.255 &amp;lt;- Create access-list to match for traffic&lt;BR /&gt;&lt;BR /&gt;route-map Policy-route permit 10 &amp;lt;- Create route map to define policy route&lt;BR /&gt;&lt;BR /&gt;match ip address 10 &amp;lt;- Match address based on access-list 10&lt;BR /&gt;&lt;BR /&gt;set ip next-hop 10.229.0.1 &amp;lt;- Set default gateway&lt;BR /&gt;&lt;BR /&gt;interface vlan 802 &lt;BR /&gt;ip policy route-map Policy-route &amp;lt;- Apply route map to interface&lt;/PRE&gt;
&lt;P&gt;Traffic on vlan 802 with a source IP in the 10.229.2.0 subnet will match and that will set the default gateway to 10.229.0.1.&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;SL&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 15:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955187#M150443</guid>
      <dc:creator>S-Lemming</dc:creator>
      <dc:date>2016-08-26T15:43:11Z</dc:date>
    </item>
    <item>
      <title>Hi SL, first of all thank you</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955188#M150446</link>
      <description>&lt;P&gt;Hi SL, first of all thank you very much for your help.&lt;/P&gt;
&lt;P&gt;Configure vlan in the ASA is not an option, since I don't want to force the ASA to work harder.&lt;/P&gt;
&lt;P&gt;About routing in the 3750 I made it simple:&lt;/P&gt;
&lt;P&gt;ip default-gateway 192.168.20.254&lt;BR /&gt;ip classless&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 10.229.0.1&lt;BR /&gt;ip http server&lt;BR /&gt;ip http secure-server&lt;BR /&gt;&lt;BR /&gt;and now vlan 802 reach internet perfectly!! &lt;/P&gt;
&lt;P&gt;but I lost access to the 3750 through vlan230 (ip 192.168.20.223) and that's the one I use for management... Is any way to correct this???&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 18:23:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955188#M150446</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2016-08-26T18:23:31Z</dc:date>
    </item>
    <item>
      <title>Firstly, you should know that</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955189#M150447</link>
      <description>&lt;P&gt;Firstly, you should know that the ip default-gateway has no effect at all when ip routing is enabled. The command is used when the switch operates at layer2 only. Basically the command does exactly the same as ip route 0.0.0.0 0.0.0.0 so they would be in conflict with each other.&lt;/P&gt;
&lt;P&gt;The new default route you have configure will cause all traffic which is routed in the switch to be forwarded on vlan 800, is that what you want?&lt;/P&gt;
&lt;P&gt;You broke the management since all traffic from the switch now is routed through vlan 800. You will need a route for the network where your management station is located pointning to 192.168.20.254, i.e. if your management station is located in the 172.16.10.0/24 subnet the route would look like this:&lt;/P&gt;
&lt;P&gt;ip route 172.16.10.0 255.255.255.0 192.168.20.254&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;SL&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 20:07:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955189#M150447</guid>
      <dc:creator>S-Lemming</dc:creator>
      <dc:date>2016-08-26T20:07:17Z</dc:date>
    </item>
    <item>
      <title>Hi SL, I understood perfectly</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955190#M150448</link>
      <description>&lt;P&gt;Hi SL, I understood perfectly. Now my problem is solved and I learned something new. Thank you very much&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 23:12:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955190#M150448</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2016-08-26T23:12:40Z</dc:date>
    </item>
    <item>
      <title>Hi again SL,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955191#M150449</link>
      <description>&lt;P&gt;Hi again SL,&lt;/P&gt;
&lt;P&gt;I was thinking, I would get same result if I do:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ip route 0.0.0.0 0.0.0.0 192.168.20.254&lt;/P&gt;
&lt;P&gt;ip route 10.229.2.0 255.255.255.0 10.229.0.1&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;??? Thanks again&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Aug 2016 23:16:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955191#M150449</guid>
      <dc:creator>gasparmenendez</dc:creator>
      <dc:date>2016-08-26T23:16:52Z</dc:date>
    </item>
    <item>
      <title>No that would not work. What</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955192#M150450</link>
      <description>&lt;P&gt;No that would not work. What the ip route command does is tell the router how to send packets to a network which it does not know about.&lt;/P&gt;
&lt;P&gt;Here's how it works:&lt;/P&gt;
&lt;P&gt;ip route 0.0.0.0 0.0.0.0 192.168.20.254 &amp;lt;- This tells the router that for any packet with a destination address it does not know about (by having it in its routing table) should be forwarded to 192.168.20.254.&lt;/P&gt;
&lt;P&gt;ip route 10.229.2.0 255.255.255.0 10.229.0.1 &amp;lt;- This tells the router that packets with a destination address of 10.229.2.0/24 should be sent to 10.229.0.1, which is not what you want. However, because the switch has an interface in the 10.229.2.0/24 network (10.229.2.2) it is a connected network and in the routing table a connected network always "wins" over a configured route. This basically means that the route you have configured never will exist in the routing table as long as the switch has vlan interface 802.&lt;/P&gt;
&lt;P&gt;If you want to have the default route pointing to 192.168.20.254 you need to use policy-based routing like I suggested earlier.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Aug 2016 14:24:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-internet-access-problem/m-p/2955192#M150450</guid>
      <dc:creator>S-Lemming</dc:creator>
      <dc:date>2016-08-28T14:24:13Z</dc:date>
    </item>
  </channel>
</rss>

