<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5505 with Comcast in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982736#M155532</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I was hoping someone had some input here. &amp;nbsp;I have an SBG6580 modem/router in bridge mode with a router to it so I can use my own router (AE Extreme). &amp;nbsp;Anyway, I have port 0/0 into the modem, and have AE Extreme into port 0/1 of the ASA. &amp;nbsp;I have tried multiple setups. &amp;nbsp;Setup static routes inside any to modem gateway. &amp;nbsp;My biggest confusion on the ASA in how the inside/outside interface should be properly setup. &amp;nbsp;Should I need static routes? If you need more detail, please let me know. &amp;nbsp;Please advise if anyone has any tips.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 08:31:48 GMT</pubDate>
    <dc:creator>austingndr1</dc:creator>
    <dc:date>2019-03-12T08:31:48Z</dc:date>
    <item>
      <title>ASA 5505 with Comcast</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982736#M155532</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I was hoping someone had some input here. &amp;nbsp;I have an SBG6580 modem/router in bridge mode with a router to it so I can use my own router (AE Extreme). &amp;nbsp;Anyway, I have port 0/0 into the modem, and have AE Extreme into port 0/1 of the ASA. &amp;nbsp;I have tried multiple setups. &amp;nbsp;Setup static routes inside any to modem gateway. &amp;nbsp;My biggest confusion on the ASA in how the inside/outside interface should be properly setup. &amp;nbsp;Should I need static routes? If you need more detail, please let me know. &amp;nbsp;Please advise if anyone has any tips.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:31:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982736#M155532</guid>
      <dc:creator>austingndr1</dc:creator>
      <dc:date>2019-03-12T08:31:48Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982737#M155533</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I hope you are fine, you will need to have a default route configured in the ASA to point to your ISP, also you will need have nat rules to translate the traffic and allow the connections to go through. Could you kindly please send the configuration that you have built in the asa?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2016 03:38:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982737#M155533</guid>
      <dc:creator>Kornelia Gutierrez</dc:creator>
      <dc:date>2016-11-15T03:38:08Z</dc:date>
    </item>
    <item>
      <title>Ok, I have setup up the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982738#M155534</link>
      <description>&lt;P&gt;Ok, I have setup up the static route to point to the comcast default gateway which is 68.44.xxx.x. Sorry, I am not home at the moment and forgot the rest. &amp;nbsp;My local default gateway is 192.168.0.1. &amp;nbsp;I have set static route to "any" to the above 68.44.xxx.x default gateway address supplied by comcast, but still a no-go. &amp;nbsp;Should the static route be the public IP from comcast, or the public default gateway from comcast, or neither? &amp;nbsp;I do not have any NAT rules at the moment, but what would I setup for that. &amp;nbsp;Once I get home, I will try to send the config over. &amp;nbsp;Thanks&amp;nbsp;in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2016 16:07:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982738#M155534</guid>
      <dc:creator>austingndr1</dc:creator>
      <dc:date>2016-11-15T16:07:34Z</dc:date>
    </item>
    <item>
      <title>Hello Kornelia,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982739#M155535</link>
      <description>&lt;P&gt;Hello Kornelia,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please see running config below. &amp;nbsp;Please let me know where I'm off, or need to add. &amp;nbsp;Thanks Again.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;interface Ethernet0/0&lt;BR /&gt; switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.0.200 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address dhcp &lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa924-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone EST -5&lt;BR /&gt;clock summer-time EDT recurring&lt;BR /&gt;dns domain-lookup inside&lt;BR /&gt;dns domain-lookup outside&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt; name-server 75.75.75.75&lt;BR /&gt; name-server 75.75.76.76&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;pager lines 24&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-761.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;route inside 0.0.0.0 0.0.0.0 68.44.142.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.0.0 255.255.255.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 192.168.0.0 255.255.255.0 inside&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;/P&gt;
&lt;P&gt;dhcp-client client-id interface outside&lt;BR /&gt;dhcpd auto_config outside interface inside&lt;BR /&gt;!&lt;BR /&gt;dhcprelay timeout 60&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;!&lt;BR /&gt;class-map global-class&lt;BR /&gt; match any&lt;BR /&gt;class-map type regex match-any DomainBlockList&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt; message-length maximum client auto&lt;BR /&gt; message-length maximum 512&lt;BR /&gt;policy-map global-policy&lt;BR /&gt; class global-class&lt;BR /&gt; inspect icmp &lt;BR /&gt;!&lt;BR /&gt;service-policy global-policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt; profile CiscoTAC-1&lt;BR /&gt; no active&lt;BR /&gt; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt; destination address email callhome@cisco.com&lt;BR /&gt; destination transport-method http&lt;BR /&gt; subscribe-to-alert-group diagnostic&lt;BR /&gt; subscribe-to-alert-group environment&lt;BR /&gt; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt; subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:f2d985662b1f026da56db69f82700817&lt;BR /&gt;: end&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2016 22:55:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982739#M155535</guid>
      <dc:creator>austingndr1</dc:creator>
      <dc:date>2016-11-15T22:55:02Z</dc:date>
    </item>
    <item>
      <title>Hi Austin,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982740#M155536</link>
      <description>&lt;P&gt;Hi Austin,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I hope you are fine, thanks for the configuration, you will need to add a nat rule in order to allow the traffic reach the internet. Please try to add the following:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you are running ASA on code 9.2.4&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;nat (inside,outside) source dynamic any interface&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you are running ASA &amp;nbsp;on software version 8.2:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;
&lt;P&gt;global (outside) 1 interface&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Let me know how it goes!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2016 00:55:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982740#M155536</guid>
      <dc:creator>Kornelia Gutierrez</dc:creator>
      <dc:date>2016-11-16T00:55:36Z</dc:date>
    </item>
    <item>
      <title>Unfortunately, still no luck.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982741#M155537</link>
      <description>&lt;P&gt;Unfortunately, still no luck. &amp;nbsp;I feel that I am close. &amp;nbsp;Please see config below. &amp;nbsp;Im on 924&lt;/P&gt;
&lt;P&gt;interface Ethernet0/0&lt;BR /&gt; switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.0.200 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address dhcp setroute &lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa924-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone EST -5&lt;BR /&gt;clock summer-time EDT recurring&lt;BR /&gt;dns domain-lookup inside&lt;BR /&gt;dns domain-lookup outside&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt; name-server 75.75.75.75&lt;BR /&gt; name-server 75.75.76.76&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;object service RDP&lt;BR /&gt; service tcp source eq 3389 destination eq 3389 &lt;BR /&gt; description RDP&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-761.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;nat (inside,outside) source dynamic any interface&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 68.44.142.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.0.0 255.255.255.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 192.168.0.0 255.255.255.0 inside&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;BR /&gt; &lt;BR /&gt;dhcp-client client-id interface outside&lt;BR /&gt;dhcpd auto_config outside interface inside&lt;BR /&gt;!&lt;BR /&gt;dhcprelay timeout 60&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;&lt;BR /&gt;class-map global-class&lt;BR /&gt; match any&lt;BR /&gt;class-map type regex match-any DomainBlockList&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt; message-length maximum client auto&lt;BR /&gt; message-length maximum 512&lt;BR /&gt;policy-map global-policy&lt;BR /&gt; class global-class&lt;BR /&gt; inspect icmp &lt;BR /&gt;!&lt;BR /&gt;service-policy global-policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt; profile CiscoTAC-1&lt;BR /&gt; no active&lt;BR /&gt; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt; destination address email callhome@cisco.com&lt;BR /&gt; destination transport-method http&lt;BR /&gt; subscribe-to-alert-group diagnostic&lt;BR /&gt; subscribe-to-alert-group environment&lt;BR /&gt; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt; subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:318eae64f41e53c8e50a83793aaf547c&lt;BR /&gt;: end&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2016 03:03:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982741#M155537</guid>
      <dc:creator>austingndr1</dc:creator>
      <dc:date>2016-11-16T03:03:54Z</dc:date>
    </item>
    <item>
      <title>Hi Austin,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982742#M155538</link>
      <description>&lt;P&gt;Hi Austin,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I hope you are fine, there is something I noticed with the routing that you have set up in the last configuration the following default route:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;route outside 0.0.0.0 0.0.0.0 68.44.142.1 1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Which is ok to configure a default route, but my concern is that the outside interface is provided with a dhcp address, &amp;nbsp;the default gateway for the default route should be provided with dhcp as well.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would like you to try the following:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-From the ASA ping the&amp;nbsp;68.44.142.1 (your ISP Gateway). If the ping is sucessfull, please run a packet tracer like the one below:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;packet-tracer input inside tcp &lt;SPAN&gt;192.168.0.10 1024 8.8.8.8 80&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;And let me know the output.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;-If the ping does not work, kindly please add the following configuration and test:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;no&amp;nbsp;route outside 0.0.0.0 0.0.0.0 68.44.142.1 1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;The key in here is that you have already the setroute keyword, this should let the asa to learn its default gateway and install the route by dhcp. Since you have the following:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;interface Vlan2&lt;BR /&gt;&lt;SPAN&gt;nameif outside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;security-level 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ip address dhcp &lt;STRONG&gt;setroute &amp;nbsp;--&amp;gt; setroute learns by dhcp the ip address of the gateway and installs the route on the table&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 00:33:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982742#M155538</guid>
      <dc:creator>Kornelia Gutierrez</dc:creator>
      <dc:date>2016-11-17T00:33:12Z</dc:date>
    </item>
    <item>
      <title>Note:</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982743#M155539</link>
      <description>&lt;P&gt;Note:&lt;/P&gt;
&lt;P&gt;Here is a little document where I base my suggestion, you can take a look if you want&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/70391-pix-asa-dhcp-svr-client.html#client&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 00:34:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982743#M155539</guid>
      <dc:creator>Kornelia Gutierrez</dc:creator>
      <dc:date>2016-11-17T00:34:21Z</dc:date>
    </item>
    <item>
      <title>Unfortunately still no luck.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982744#M155540</link>
      <description>&lt;P&gt;Unfortunately still no luck. &amp;nbsp;Please see below config. &amp;nbsp;Could DNS have any issue why the connection fails. &amp;nbsp;I currently have 0/0 set as DHCP and no static routes. &amp;nbsp;Also does it matter what the inside interface IP is. &amp;nbsp;Should this be my internal router IP? &amp;nbsp;I set it as .200 just so I could easily remember it, but no device on my network is set at .200. &amp;nbsp;Just mentioning some more details. &amp;nbsp;Let me know you thoughts. &amp;nbsp;Thanks.&lt;/P&gt;
&lt;P&gt;ciscoasa# show running-config&lt;BR /&gt;: Saved&lt;BR /&gt;: &lt;BR /&gt;: Serial Number: JMX1235Z20W&lt;BR /&gt;: Hardware: ASA5505, 256 MB RAM, CPU Geode 500 MHz&lt;BR /&gt;:&lt;BR /&gt;ASA Version 9.2(4) &lt;BR /&gt;!&lt;BR /&gt;hostname ciscoasa&lt;BR /&gt;xlate per-session deny tcp any4 any4&lt;BR /&gt;xlate per-session deny tcp any4 any6&lt;BR /&gt;xlate per-session deny tcp any6 any4&lt;BR /&gt;xlate per-session deny tcp any6 any6&lt;BR /&gt;xlate per-session deny udp any4 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any4 any6 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any4 eq domain&lt;BR /&gt;xlate per-session deny udp any6 any6 eq domain&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.0.200 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address dhcp setroute &lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa924-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone EST -5&lt;BR /&gt;clock summer-time EDT recurring&lt;BR /&gt;dns domain-lookup inside&lt;BR /&gt;dns domain-lookup outside&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt; name-server 75.75.75.75&lt;BR /&gt; name-server 75.75.76.76&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;object service RDP&lt;BR /&gt; service tcp source eq 3389 destination eq 3389 &lt;BR /&gt; description RDP&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-761.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;nat (inside,outside) source dynamic any interface&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.0.0 255.255.255.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 192.168.0.0 255.255.255.0 inside&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;/P&gt;
&lt;P&gt;dhcp-client client-id interface outside&lt;BR /&gt;dhcpd auto_config outside interface inside&lt;BR /&gt;!&lt;BR /&gt;dhcprelay timeout 60&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;!&lt;BR /&gt;class-map global-class&lt;BR /&gt; match any&lt;BR /&gt;class-map type regex match-any DomainBlockList&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt; message-length maximum client auto&lt;BR /&gt; message-length maximum 512&lt;BR /&gt;policy-map global-policy&lt;BR /&gt; class global-class&lt;BR /&gt; inspect icmp &lt;BR /&gt;!&lt;BR /&gt;service-policy global-policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt; profile CiscoTAC-1&lt;BR /&gt; no active&lt;BR /&gt; destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt; destination address email callhome@cisco.com&lt;BR /&gt; destination transport-method http&lt;BR /&gt; subscribe-to-alert-group diagnostic&lt;BR /&gt; subscribe-to-alert-group environment&lt;BR /&gt; subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt; subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt; subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:b9045a9bb35d6559f7be379677bf1504&lt;BR /&gt;: end&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2016 01:47:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-with-comcast/m-p/2982744#M155540</guid>
      <dc:creator>austingndr1</dc:creator>
      <dc:date>2016-11-18T01:47:52Z</dc:date>
    </item>
  </channel>
</rss>

