<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Ahmed, the ISP's default in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957678#M161380</link>
    <description>&lt;P&gt;Hi Ahmed, the ISP's default gateway is 12.3.4.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;ASA-Lab01# sh nat&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Auto NAT Policies (Section 2)&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;1 (Inside) to (Outside) source dynamic net-192.168.1 interface&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt; translate_hits = 106, untranslate_hits = 87&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;ASA-Lab01#&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;ASA-Lab01# sh xlate&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;0 in use, 101 most used&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;ASA-Lab01#&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi Marvin, I thought the Comcast router was having issue early today too so I setup a router with IP 12.3.4.9&amp;nbsp;as its outside interface, the route is working fine with the internet. My router can ping the ISP gateway and 8.8.8.8 and I can ping the ASA 12.3.4.5 and vice versa. I think I'm going to reboot the comcast router to see if it would help. I'll update you guys&amp;nbsp;later. thanks.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 30 Jul 2016 04:13:55 GMT</pubDate>
    <dc:creator>tinhnho123</dc:creator>
    <dc:date>2016-07-30T04:13:55Z</dc:date>
    <item>
      <title>ASA 5540 question</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957671#M161360</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a ASA 5540 that I'd like to configure for my brand office. Below my network topology:&lt;/P&gt;
&lt;P&gt;Comcast----&amp;gt;Cisco ASA 5540 ----&amp;gt; L3 switch----&amp;gt; PC.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ASA 5540 is reset to factory default setting. The goal is that I'd like to get my PCs online from this brand office.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The ASA has code version 9.1(5). Here is what I've configured so far:&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet0/0&lt;BR /&gt; speed 1000&lt;BR /&gt; duplex full&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 12.3.4.5&amp;nbsp;255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt; speed 1000&lt;BR /&gt; duplex full&lt;BR /&gt; nameif Inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;object network net-192.168.1&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;subnet 192.168.1.0 255.255.255.0&lt;/P&gt;
&lt;P&gt;object network net-192.168.1&lt;BR /&gt;&amp;nbsp; &amp;nbsp;nat (Inside,Outside) dynamic interface&lt;BR /&gt;route Outside 0.0.0.0 0.0.0.0 &lt;SPAN&gt;12.3.4.1&lt;/SPAN&gt;&amp;nbsp;1&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I connected my PC to the L3 switch, I can ping the &lt;SPAN&gt;192.168.1.1 (ASA inside) but unable to ping the outside and also can't get online while using google DNS 8.8.8.8 for my PC.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Any ideas why it doesn't work? Thanks.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:03:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957671#M161360</guid>
      <dc:creator>tinhnho123</dc:creator>
      <dc:date>2019-03-12T08:03:19Z</dc:date>
    </item>
    <item>
      <title>To get ping working you'll</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957672#M161363</link>
      <description>&lt;P&gt;To get ping working you'll probably need to add something like:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt; message-length maximum client auto&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt; inspect ftp &lt;BR /&gt; inspect h323 h225 &lt;BR /&gt; inspect h323 ras &lt;BR /&gt; inspect ip-options &lt;BR /&gt; inspect netbios &lt;BR /&gt; inspect rsh &lt;BR /&gt; inspect rtsp &lt;BR /&gt; inspect skinny &lt;BR /&gt; inspect sqlnet &lt;BR /&gt; inspect sunrpc &lt;BR /&gt; inspect tftp &lt;BR /&gt; inspect sip &lt;BR /&gt; inspect xdmcp &lt;BR /&gt;&lt;STRONG&gt; inspect icmp &lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt; inspect icmp error &lt;/STRONG&gt;&lt;BR /&gt; inspect pptp &lt;BR /&gt; inspect dns preset_dns_map&lt;/PRE&gt;</description>
      <pubDate>Sat, 23 Jul 2016 13:54:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957672#M161363</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-07-23T13:54:09Z</dc:date>
    </item>
    <item>
      <title>Philip is correct regarding</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957673#M161366</link>
      <description>&lt;P&gt;Philip is correct regarding ping.&lt;/P&gt;
&lt;P&gt;I would also advise that ping is a poor tool for troubleshooting. More useful would be packet-tracer. It has both a GUI (ASDM) and cli version.&lt;/P&gt;
&lt;P&gt;For instance:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;packet-tracer input inside &amp;lt;tcp or udp&amp;gt; &amp;lt;source ip&amp;gt; &amp;lt;source port&amp;gt; &amp;lt;destination ip&amp;gt; &amp;lt;destination port&amp;gt;&lt;/PRE&gt;
&lt;P&gt;...will show you the logic the ASA uses for a given packet with the specified 5-tuple (protocol, source ip, source port, destination ip, destination port).&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2016 14:21:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957673#M161366</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-07-23T14:21:15Z</dc:date>
    </item>
    <item>
      <title>hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957674#M161369</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;is there a typo? make sure the NAT statements coincides with the nameif given.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt; &amp;nbsp;nat (Inside,&lt;SPAN style="color: #ff0000;"&gt;o&lt;/SPAN&gt;utside) dynamic interface&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;could you post &lt;STRONG&gt;show int ip brief&lt;/STRONG&gt; and ping 8.8.8.8 from the ASA?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2016 06:40:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957674#M161369</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2016-07-25T06:40:24Z</dc:date>
    </item>
    <item>
      <title>Hi Guys,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957675#M161371</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Sorry I was out of town and just got back today.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Below are the results which you guys asked me to run on the ASA&lt;/P&gt;
&lt;P&gt;ASA-Lab01# packet-tracer input inside tcp 12.3.4.5 80 8.8.8.8 80&lt;/P&gt;
&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/P&gt;
&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in 0.0.0.0 0.0.0.0 Outside&lt;/P&gt;
&lt;P&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 4&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 5&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 6&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;
&lt;P&gt;Phase: 7&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 57580, packet dispatched to next module&lt;/P&gt;
&lt;P&gt;Result:&lt;BR /&gt;input-interface: Inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: Outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;
&lt;P&gt;ASA-Lab01#&lt;BR /&gt;========================&lt;/P&gt;
&lt;P&gt;ASA-Lab01# sh int ip br&lt;BR /&gt;Interface IP-Address OK? Method Status Protocol&lt;BR /&gt;GigabitEthernet0/0 12.3.4.5 YES manual up up&lt;BR /&gt;GigabitEthernet0/1 192.168.1.1 YES manual up up&lt;BR /&gt;GigabitEthernet0/2 unassigned YES unset administratively down up&lt;BR /&gt;GigabitEthernet0/3 unassigned YES unset administratively down down&lt;BR /&gt;Management0/0 172.20.16.10 YES manual up up&lt;BR /&gt;ASA-Lab01#&lt;BR /&gt;=========================&lt;BR /&gt;Ping 8.8.8.8&lt;BR /&gt;ASA-Lab01# ping 8.8.8.8&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:&lt;BR /&gt;?????&lt;BR /&gt;Success rate is 0 percent (0/5)&lt;BR /&gt;ASA-Lab01#&lt;BR /&gt;========================&lt;BR /&gt;Ping ISP's gateway:&lt;BR /&gt;ASA-Lab01# ping 12.3.4.9&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to &lt;SPAN&gt;12.3.4.9&lt;/SPAN&gt;, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;BR /&gt;ASA-Lab01#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I still can't get to the internet and also can't ping any public IP either.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2016 01:11:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957675#M161371</guid>
      <dc:creator>tinhnho123</dc:creator>
      <dc:date>2016-07-30T01:11:25Z</dc:date>
    </item>
    <item>
      <title>Hi;</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957676#M161373</link>
      <description>&lt;P&gt;Hi;&lt;/P&gt;
&lt;P&gt;What is you ISP&amp;nbsp;gateway is 12.3.4.9 or 12.3.4.1?&lt;/P&gt;
&lt;P&gt;If its 12.3.4.9 then please modify you static route (&lt;SPAN&gt;route Outside 0 0&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;12.3.4.9) and verify.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If not can you also share the output of show nat &amp;amp; show xlate command.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks &amp;amp; Best regards;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2016 01:11:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957676#M161373</guid>
      <dc:creator>ahmedshoaib</dc:creator>
      <dc:date>2016-07-30T01:11:26Z</dc:date>
    </item>
    <item>
      <title>Ditto to what ahmed suggested</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957677#M161377</link>
      <description>&lt;P&gt;Ditto to what ahmed suggested.&lt;/P&gt;
&lt;P&gt;Packet-tracer confirms the ASA setup is OK. You have an issue with / getting past the upstream gateway (Comcast router).&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2016 02:57:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957677#M161377</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-07-30T02:57:17Z</dc:date>
    </item>
    <item>
      <title>Hi Ahmed, the ISP's default</title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957678#M161380</link>
      <description>&lt;P&gt;Hi Ahmed, the ISP's default gateway is 12.3.4.1.&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;ASA-Lab01# sh nat&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Auto NAT Policies (Section 2)&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;1 (Inside) to (Outside) source dynamic net-192.168.1 interface&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt; translate_hits = 106, untranslate_hits = 87&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;ASA-Lab01#&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;ASA-Lab01# sh xlate&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;0 in use, 101 most used&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;ASA-Lab01#&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi Marvin, I thought the Comcast router was having issue early today too so I setup a router with IP 12.3.4.9&amp;nbsp;as its outside interface, the route is working fine with the internet. My router can ping the ISP gateway and 8.8.8.8 and I can ping the ASA 12.3.4.5 and vice versa. I think I'm going to reboot the comcast router to see if it would help. I'll update you guys&amp;nbsp;later. thanks.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2016 04:13:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957678#M161380</guid>
      <dc:creator>tinhnho123</dc:creator>
      <dc:date>2016-07-30T04:13:55Z</dc:date>
    </item>
    <item>
      <title>Hi, </title>
      <link>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957679#M161383</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You see the both output packet tracer and show nat both shows that its not a nat issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mostprobably it's router issue.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2016 07:51:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5540-question/m-p/2957679#M161383</guid>
      <dc:creator>ahmedshoaib</dc:creator>
      <dc:date>2016-07-30T07:51:55Z</dc:date>
    </item>
  </channel>
</rss>

