<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thank you - sorry the DNS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-access-internet-with-asa-5505/m-p/2769667#M171176</link>
    <description>&lt;P&gt;Thank you - sorry the DNS server wasn't properly set to process DNS, and the PCs weren't picking up the firewall as the gateway properly - were trying to jump straight to the router (as when it was setup originally to test, without the firewall). That's sorted now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Have a lot of Cisco studying to do!!! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Nov 2015 20:54:58 GMT</pubDate>
    <dc:creator>ZF XCX</dc:creator>
    <dc:date>2015-11-04T20:54:58Z</dc:date>
    <item>
      <title>Can't access internet with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-internet-with-asa-5505/m-p/2769662#M171171</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Feel really silly with this, I'm sure I've followed so many guides, and literally stuck with the default configuration (factory resetting numerous times!) but still can't connect out.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I've been given a LAN IP Range, with /29 address. I've been told that x.x.x.16 is network address, .17 is router address &amp;amp; default gateway, .18-.22 useable.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If I connect a network cable straight to the router they supply, and do manual IP config (as DHCP etc is disabled) with those values and their DNS servers, I can access the net fine.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As soon as I connect ASA 5505 the troubles begin!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My private network IP range is 192.168.128.1-255. I've set the Cisco ASA 5505 to 192.168.128.9, and got a DHCP server up and running, assigning&amp;nbsp;IPs etc (from .50 upwards). The DNS i've tried setting but none of the IPs given by my ISP will resolve, presumably due to firewall connectivity issues. For default gateway I've tried my public IP as given by ISP x.x.x.17, and I've also tried 192.168.128.9 as suggested on some other sites (I believe this to be the correct config now too, but it still won't work)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I can ping&amp;nbsp;192.168.128.9, but can't ping anything on the internet. Trying to connect to site just gives me DNS errors and 'resolving host' or waiting for host etc.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I've also got the following line in my logs - but not sure why as I wasn't trying to connect to google or use their DNS!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;4&lt;SPAN class="Apple-tab-span"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Oct 28 2015&amp;nbsp;&lt;SPAN class="Apple-tab-span"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;21:47:04&lt;/P&gt;
&lt;P&gt;192.168.128.50&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="Apple-tab-span"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;63110&lt;SPAN class="Apple-tab-span"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;8.8.4.4&lt;SPAN class="Apple-tab-span"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;53&lt;SPAN class="Apple-tab-span"&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Deny&amp;nbsp;udp&lt;/P&gt;
&lt;P&gt;src inside:192.168.128.50/63110&lt;/P&gt;
&lt;P&gt;dst outside:8.8.4.4/53 by access-group "inside_access_in" [0x0, 0x0]&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What's this "inside_access_in"?! I only have inside and outside. I've tried to&amp;nbsp;access IPs&amp;nbsp;from ASDM troubleshooter, but I get blocked by rule - there is an implicit Deny rule, but I haven't set up any deny rules - I've put some allow outs (as in guides I've seen). Ahhh help!?!?! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is the config - haven't done very much at all as I literally want to get on the internet and save it, then care about the rest! This is my first cisco config so I want to learn... but it's also becoming mission critical that the new internet is up ASAP.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;: Written by enable_15 at 21:22:45.339 UTC Wed Oct 28 2015&lt;BR /&gt;!&lt;BR /&gt;ASA Version 9.0(1)&lt;BR /&gt;!&lt;BR /&gt;hostname cisco1234&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.128.9 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address x.x.x.19 (ISP public address - is this supposed to be another 192.168.128.x address!? DHCP on the outside interface won't work either - it will on inside, but I want static).&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network obj_any&lt;BR /&gt; subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object-group service DM_INLINE_SERVICE_1&lt;BR /&gt; service-object ip&lt;BR /&gt; service-object icmp&lt;BR /&gt; service-object udp&lt;BR /&gt; service-object tcp&lt;BR /&gt; service-object tcp destination eq www&lt;BR /&gt; service-object tcp destination eq https&lt;BR /&gt;object-group service DM_INLINE_SERVICE_2&lt;BR /&gt; service-object ip&lt;BR /&gt; service-object udp&lt;BR /&gt; service-object tcp&lt;BR /&gt; service-object tcp destination eq www&lt;BR /&gt; service-object tcp destination eq https&lt;BR /&gt;object-group service DM_INLINE_SERVICE_3&lt;BR /&gt; service-object ip&lt;BR /&gt; service-object icmp&lt;BR /&gt; service-object udp&lt;BR /&gt; service-object tcp&lt;BR /&gt; service-object tcp destination eq www&lt;BR /&gt; service-object tcp destination eq https&lt;BR /&gt; service-object udp destination eq www&lt;BR /&gt;access-list outside_access_in extended permit object-group DM_INLINE_SERVICE_1 a&lt;BR /&gt;ny interface outside&lt;BR /&gt;access-list global_access extended permit object-group DM_INLINE_SERVICE_2 any i&lt;BR /&gt;nterface outside&lt;BR /&gt;access-list inside_access_in extended permit object-group DM_INLINE_SERVICE_3 an&lt;BR /&gt;y interface outside&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;access-group inside_access_in in interface inside&lt;BR /&gt;access-group outside_access_in in interface outside&lt;BR /&gt;access-group global_access global&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 &lt;EM&gt;ISPGATEWAY (x.x.x.17)&lt;/EM&gt;&amp;nbsp;1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside&lt;BR /&gt;http 0.0.0.0 0.0.0.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;/P&gt;
&lt;P&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;/P&gt;
&lt;P&gt;dhcpd auto_config outside&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt; message-length maximum client auto&lt;BR /&gt; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt; inspect dns preset_dns_map&lt;BR /&gt; inspect ftp&lt;BR /&gt; inspect h323 h225&lt;BR /&gt; inspect h323 ras&lt;BR /&gt; inspect rsh&lt;BR /&gt; inspect rtsp&lt;BR /&gt; inspect esmtp&lt;BR /&gt; inspect sqlnet&lt;BR /&gt; inspect skinny&lt;BR /&gt; inspect sunrpc&lt;BR /&gt; inspect xdmcp&lt;BR /&gt; inspect sip&lt;BR /&gt; inspect netbios&lt;BR /&gt; inspect tftp&lt;BR /&gt; inspect ip-options&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:48:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-internet-with-asa-5505/m-p/2769662#M171171</guid>
      <dc:creator>ZF XCX</dc:creator>
      <dc:date>2019-03-12T06:48:21Z</dc:date>
    </item>
    <item>
      <title>Hi ZF XCX,</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-internet-with-asa-5505/m-p/2769663#M171172</link>
      <description>&lt;P&gt;Hi ZF XCX,&lt;/P&gt;
&lt;P&gt;Uf you have not configured below access-list then you have not performed the factory default properly. Below are the access-list present on ASA:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;access-list outside_access_in extended permit object-group DM_INLINE_SERVICE_1 a&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ny interface outside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;access-list global_access extended permit object-group DM_INLINE_SERVICE_2 any i&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;nterface outside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;access-list inside_access_in extended permit object-group DM_INLINE_SERVICE_3 an&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;y interface outside&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;These access-list might be the reason you are being denied to go out.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;If you wish to remove all the configuration then perform 'clear configuration all' on configuration termial mode.&lt;/P&gt;
&lt;P&gt;If you do not wish to clear all the configuration, then remove the access-list from interfaces with below commands:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;no access-group inside_access_in in interface inside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;no access-group outside_access_in in interface outside&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;no access-group global_access global&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Also you do not have any NAT&amp;nbsp;configured on ASA. To allow communication between private to public, you need NAT. Please perform the below commands:&lt;/P&gt;
&lt;P&gt;object network obj-any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;subnet 0 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;/P&gt;
&lt;P&gt;This would PAT your all the internal subnet to outside interface IP address.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is a very basic setup. No need of access-list on any interface. This would enable internet connectivity through your ASA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 02:04:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-internet-with-asa-5505/m-p/2769663#M171172</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-10-29T02:04:11Z</dc:date>
    </item>
    <item>
      <title>Hi Akshay</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-internet-with-asa-5505/m-p/2769664#M171173</link>
      <description>&lt;P&gt;Hi Akshay&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Many thanks for your reply. After performing these my computer says 'internet' but I still can't do anything. With asdm I have an implicit deny global ip rule - Is that right, I can't get rid of it&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 10:23:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-internet-with-asa-5505/m-p/2769664#M171173</guid>
      <dc:creator>ZF XCX</dc:creator>
      <dc:date>2015-10-29T10:23:34Z</dc:date>
    </item>
    <item>
      <title>Can you ping an internet IP</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-internet-with-asa-5505/m-p/2769665#M171174</link>
      <description>&lt;P&gt;Can you&amp;nbsp;ping an internet IP from the firewall itself ?&lt;/P&gt;
&lt;P&gt;How are you testing internet access from the PC ?&lt;/P&gt;
&lt;P&gt;If it is with trying to connect to a web server does your PC have a DNS server ?&lt;/P&gt;
&lt;P&gt;If it is with ping you need to add something to your configuration.&lt;/P&gt;
&lt;P&gt;Can you answer the above and if you can ping from the firewall itself can you post your latest configuration.&lt;/P&gt;
&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 12:22:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-internet-with-asa-5505/m-p/2769665#M171174</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-10-29T12:22:38Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-internet-with-asa-5505/m-p/2769666#M171175</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Can we have teamviewer session and fix your issue ?&lt;/P&gt;
&lt;P&gt;Ping me on Skype : mshareef2833&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;@Mohammed&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2015 00:14:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-internet-with-asa-5505/m-p/2769666#M171175</guid>
      <dc:creator>Mohammed Ismail Shareef</dc:creator>
      <dc:date>2015-10-30T00:14:31Z</dc:date>
    </item>
    <item>
      <title>Thank you - sorry the DNS</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-internet-with-asa-5505/m-p/2769667#M171176</link>
      <description>&lt;P&gt;Thank you - sorry the DNS server wasn't properly set to process DNS, and the PCs weren't picking up the firewall as the gateway properly - were trying to jump straight to the router (as when it was setup originally to test, without the firewall). That's sorted now &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Have a lot of Cisco studying to do!!! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 20:54:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-internet-with-asa-5505/m-p/2769667#M171176</guid>
      <dc:creator>ZF XCX</dc:creator>
      <dc:date>2015-11-04T20:54:58Z</dc:date>
    </item>
  </channel>
</rss>

