<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks for replying. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920171#M155289</link>
    <description>&lt;P&gt;Thanks for replying.&lt;/P&gt;
&lt;P&gt;The weirdest thing happened with my ASA firewall and I don't know if it should have happened this way.&lt;/P&gt;
&lt;P&gt;I rewrote the configuration and this time I only configured the interfaces and the natting. And to my surprise the PC is now connected to the internet with no access-list.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is that supposed to happen? Shouldn't the firewall block everything unless I permit a certain ip?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I protect my PC form the "dangers" of the Internet using my Firewall?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Thu, 31 Mar 2016 06:57:07 GMT</pubDate>
    <dc:creator>anthony_chedid1</dc:creator>
    <dc:date>2016-03-31T06:57:07Z</dc:date>
    <item>
      <title>How to connect an ASA Firewall to the internet?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920165#M155283</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;In my topology (attached), I am simply trying to connect a PC to the internet through an ASA Firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the ASA configuration:&lt;/P&gt;
&lt;P&gt;hostname Firewall&lt;BR /&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;BR /&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.3.254 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address dhcp setroute&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet2&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet3&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;object network local&lt;BR /&gt; subnet 192.168.3.0 255.255.255.0&lt;BR /&gt;access-list out-in extended permit tcp any 192.168.3.0 255.255.255.0 eq www&lt;BR /&gt;access-list out-in extended permit tcp any 192.168.3.0 255.255.255.0 eq https&lt;BR /&gt;access-list out-in extended permit ip any 192.168.3.0 255.255.255.0&lt;BR /&gt;pager lines 24&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;!&lt;BR /&gt;object network local&lt;BR /&gt; nat (inside,outside) dynamic interface&lt;BR /&gt;access-group out-in in interface outside&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;------------------------------------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;Both the Firewall and the PC are able to ping 8.8.8.8 but I can't surf the web on the PC which means in a way it is not connected to the internet.&lt;/P&gt;
&lt;P&gt;So what should I change or do ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:33:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920165#M155283</guid>
      <dc:creator>anthony_chedid1</dc:creator>
      <dc:date>2019-03-12T07:33:04Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920166#M155284</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What is the IP of the PC ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It should have an IP of the same&amp;nbsp;&lt;SPAN&gt;192.168.3.0 255.255.255.0 range and default gateway as 192.168.3.254.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;G class="gr_ gr_87 gr-alert gr_gramm undefined Punctuation multiReplace" id="87" data-gr-id="87"&gt;Also&lt;/G&gt; use the command fixup protocol &lt;G class="gr_ gr_92 gr-alert gr_spell undefined ContextualSpelling ins-del multiReplace" id="92" data-gr-id="92"&gt;icmp&lt;/G&gt; on ASA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2016 12:49:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920166#M155284</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-03-29T12:49:54Z</dc:date>
    </item>
    <item>
      <title>hi,</title>
      <link>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920167#M155285</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;try adding DNS IP 8.8.8.8 on your PC's TCP/IPv4 settings and try again.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2016 13:26:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920167#M155285</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2016-03-29T13:26:10Z</dc:date>
    </item>
    <item>
      <title>I already added this DNS IP</title>
      <link>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920168#M155286</link>
      <description>&lt;P&gt;I already added this DNS IP and it didn't make any difference.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 06:40:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920168#M155286</guid>
      <dc:creator>anthony_chedid1</dc:creator>
      <dc:date>2016-03-30T06:40:11Z</dc:date>
    </item>
    <item>
      <title>My PC's IP is 192.168.3.10</title>
      <link>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920169#M155287</link>
      <description>&lt;P&gt;My PC's IP is 192.168.3.10 and the gateway's IP is 192.168.3.254.&lt;/P&gt;
&lt;P&gt;I used the command you mentioned and it didn't make any difference.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I was hoping someone would find what's wrong in the ASA configuration. Maybe the nat command is wrong or the access list.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 06:43:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920169#M155287</guid>
      <dc:creator>anthony_chedid1</dc:creator>
      <dc:date>2016-03-30T06:43:25Z</dc:date>
    </item>
    <item>
      <title>A helpful tool to use is</title>
      <link>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920170#M155288</link>
      <description>&lt;P&gt;A helpful tool to use is packet-tracer, it will tell whats happening at each stage of the packet processing.&amp;nbsp;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;packet-tracer input inside tcp 192.168.3.10 1234 8.8.8.8 80&lt;/PRE&gt;
&lt;P&gt;Try this and then use packet tracer again:&lt;/P&gt;
&lt;PRE class="prettyprint" style="padding-left: 30px;"&gt;access-list in-out permit ip 192.168.3.0 255.255.255.0 any&lt;BR /&gt;access-group in-out in interface inside&lt;/PRE&gt;
&lt;P&gt;Your existing ACL is permitting traffic in the outside interface, so toward your inside network &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 21:52:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920170#M155288</guid>
      <dc:creator>james.tucker</dc:creator>
      <dc:date>2016-03-30T21:52:32Z</dc:date>
    </item>
    <item>
      <title>Thanks for replying.</title>
      <link>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920171#M155289</link>
      <description>&lt;P&gt;Thanks for replying.&lt;/P&gt;
&lt;P&gt;The weirdest thing happened with my ASA firewall and I don't know if it should have happened this way.&lt;/P&gt;
&lt;P&gt;I rewrote the configuration and this time I only configured the interfaces and the natting. And to my surprise the PC is now connected to the internet with no access-list.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is that supposed to happen? Shouldn't the firewall block everything unless I permit a certain ip?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I protect my PC form the "dangers" of the Internet using my Firewall?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2016 06:57:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920171#M155289</guid>
      <dc:creator>anthony_chedid1</dc:creator>
      <dc:date>2016-03-31T06:57:07Z</dc:date>
    </item>
    <item>
      <title>In this case you are relying</title>
      <link>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920172#M155290</link>
      <description>&lt;P dir="ltr"&gt;In this case you are relying on the interface security levels to permit the traffic to the Internet. Traffic will flow from higher to lower security level interfaces (no ACL needed to permit) but not the other way round - here you would need an ACL that will define which ports you would need to permit into your network.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2016 21:32:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-connect-an-asa-firewall-to-the-internet/m-p/2920172#M155290</guid>
      <dc:creator>james.tucker</dc:creator>
      <dc:date>2016-03-31T21:32:42Z</dc:date>
    </item>
  </channel>
</rss>

