<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The Routed_Lan wont need a in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796401#M173280</link>
    <description>&lt;P&gt;The Routed_Lan wont need a gateway on the ASA, it will use the default route for the ASA to your ISP. &amp;nbsp;Your ISP will need to route 3.3.3.0/29 via 2.2.2.2.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For a server plugged into the Route_Lan segment its gateway will be that of the ASA, 3.3.3.1.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Your new config will work perfectly.&lt;/P&gt;</description>
    <pubDate>Sat, 23 Jan 2016 17:52:46 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2016-01-23T17:52:46Z</dc:date>
    <item>
      <title>ASA5510 Public Pool IP Address Assignment on LAN Server</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796392#M173271</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a requirement where i can assign the Public Pool IP Address to my LAN Server. &amp;nbsp;I don't want to do one to one NAT.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ISP IP Address:&amp;nbsp;2.2.2.1 /30&lt;/P&gt;
&lt;P&gt;ASA IP Address:&amp;nbsp;2.2.2.2 /30&lt;/P&gt;
&lt;P&gt;ASA DGW:&amp;nbsp;2.2.2.1&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Public IP Pool from ISP:&amp;nbsp;3.3.3.0 3.3.3.7/29&lt;/P&gt;
&lt;P&gt;I want to assign one of the Public Pool IP Address directly to my Server, e.g.&amp;nbsp;3.3.3.1&lt;/P&gt;
&lt;P&gt;Question:&lt;/P&gt;
&lt;P&gt;What will be the ASA Configuration&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What will be the Gateway of Server&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have also attached the topology I am looking for.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks and regards&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:09:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796392#M173271</guid>
      <dc:creator>faiqmahdi</dc:creator>
      <dc:date>2019-03-12T07:09:18Z</dc:date>
    </item>
    <item>
      <title>More than likely you wont be</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796393#M173272</link>
      <description>&lt;P&gt;More than likely you wont be able to make this work. &amp;nbsp;You need to figure out another way of doing this.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jan 2016 19:16:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796393#M173272</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-01-17T19:16:01Z</dc:date>
    </item>
    <item>
      <title>That's really weird, If ASA</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796394#M173273</link>
      <description>&lt;P&gt;That's really weird, If ASA does not support this. &amp;nbsp;I am really expecting more in ASA. &amp;nbsp;Let's hope for the best. &amp;nbsp;If i get someone who has done similarly earlier.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jan 2016 20:34:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796394#M173273</guid>
      <dc:creator>faiqmahdi</dc:creator>
      <dc:date>2016-01-17T20:34:51Z</dc:date>
    </item>
    <item>
      <title>This is not an ASA issue.</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796395#M173274</link>
      <description>&lt;P&gt;This is not an ASA issue. &amp;nbsp;This is a fundamental and basic networking concept to do with IP routing. &amp;nbsp;You have a fundamental issue with your network design preventing this configuration.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jan 2016 20:37:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796395#M173274</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-01-17T20:37:33Z</dc:date>
    </item>
    <item>
      <title>Customer has already the same</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796396#M173275</link>
      <description>&lt;P&gt;Customer has already the same implementation with DrayTek Router and we are going to replace the DrayTek with ASA. &amp;nbsp;If ASA does not support the same feature, probably we have to stick with DrayTek just because of this feature.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 08:15:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796396#M173275</guid>
      <dc:creator>faiqmahdi</dc:creator>
      <dc:date>2016-01-18T08:15:33Z</dc:date>
    </item>
    <item>
      <title>Without NAT the only way to</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796397#M173276</link>
      <description>&lt;P&gt;Without NAT the only way to make this work is with a routed subnet to the server. &amp;nbsp;I suspect things are not working as you think.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 08:21:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796397#M173276</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-01-18T08:21:47Z</dc:date>
    </item>
    <item>
      <title>Here is the link, that's</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796398#M173277</link>
      <description>&lt;P&gt;Here is the link, that's exactly how we configured the DrayTek. &amp;nbsp;Similar behavior customer is looking for ASA.&lt;/P&gt;
&lt;P&gt;http://www.draytek.com/index.php?option=com_k2&amp;amp;view=item&amp;amp;id=5660&amp;amp;Itemid=293&amp;amp;lang=en&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 08:25:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796398#M173277</guid>
      <dc:creator>faiqmahdi</dc:creator>
      <dc:date>2016-01-18T08:25:28Z</dc:date>
    </item>
    <item>
      <title>It looks to me like it is</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796399#M173278</link>
      <description>&lt;P&gt;It looks to me like it is setting up a routed /30 subnet.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;An easier config would be to create a DMZ and put&amp;nbsp;&lt;SPAN&gt;3.3.3.0/29 on it. &amp;nbsp;Then put the servers you want to have public IP addresses directly into the DMZ with real IP addresses on them. &amp;nbsp;Then no NAT for servers. &amp;nbsp;Users can be NATed to the outside IP address of the ASA and life will be simple.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 08:37:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796399#M173278</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-01-18T08:37:03Z</dc:date>
    </item>
    <item>
      <title>Hi Philip</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796400#M173279</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Hi Philip&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I am giving a shot as you mentioned.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;interface Ethernet0/3&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt; nameif Routed_LAN&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt; security-level 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt; ip address 3.3.3.1 255.255.255.248&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Two Questions:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;1st Question: What will be the Internet Route for this Interface. &amp;nbsp;I tried to add two Routes but no benefit:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;route Routed_LAN 0.0.0.0 0.0.0.0 2.2.2.1 (ISP Gateway)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;ERROR: Cannot add route entry, conflict with existing routes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;route Routed_LAN 0.0.0.0 0.0.0.0 2.2.2.2 (ASA IP Address)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;%Invalid next hop address, it belongs to one of our interfaces&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;ASA Configuration:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;!&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;interface Ethernet0/0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt; nameif OUTSIDE&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt; security-level 0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt; ip address 2.2.2.2 255.255.255.252&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;route OUTSIDE 0.0.0.0 0.0.0.0 2.2.2.1 1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;2nd Question:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-size: 10pt;"&gt;What will be the Gateway of Server in Routed_LAN Subnet&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 17:49:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796400#M173279</guid>
      <dc:creator>faiqmahdi</dc:creator>
      <dc:date>2016-01-23T17:49:11Z</dc:date>
    </item>
    <item>
      <title>The Routed_Lan wont need a</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796401#M173280</link>
      <description>&lt;P&gt;The Routed_Lan wont need a gateway on the ASA, it will use the default route for the ASA to your ISP. &amp;nbsp;Your ISP will need to route 3.3.3.0/29 via 2.2.2.2.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For a server plugged into the Route_Lan segment its gateway will be that of the ASA, 3.3.3.1.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Your new config will work perfectly.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 17:52:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796401#M173280</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-01-23T17:52:46Z</dc:date>
    </item>
    <item>
      <title>I don't have any Server plug</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796402#M173281</link>
      <description>&lt;P&gt;I don't have any Server plug at the moment with Routed_LAN but I will give a try tomorrow. &amp;nbsp;I am trying to configure it remotely. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have enabled SSH for Routed_LAN Interface but I am not able to connect remotely:&lt;/P&gt;
&lt;P&gt;ssh 0.0.0.0 0.0.0.0 &lt;SPAN&gt;Routed_LAN&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I tried the following and here is the result:&lt;/P&gt;
&lt;P&gt;MyFW# ping tcp &lt;SPAN&gt;Routed_LAN&lt;/SPAN&gt; 8.8.8.8 53&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;No source specified. Pinging from identity interface.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;Sending 5 TCP SYN requests to 8.8.8.8 port 53&lt;BR /&gt;from &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;2.2.2.2&lt;/STRONG&gt;&lt;/SPAN&gt;, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 5/6/6 ms&lt;BR /&gt;&lt;SPAN&gt;MyFW&lt;/SPAN&gt;#&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 18:04:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796402#M173281</guid>
      <dc:creator>faiqmahdi</dc:creator>
      <dc:date>2016-01-23T18:04:31Z</dc:date>
    </item>
    <item>
      <title>Routed_Lan is not your</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796403#M173282</link>
      <description>&lt;P&gt;Routed_Lan is not your connection to your ISP, correct? &amp;nbsp;Your ISP connects via your Outside IP address&lt;SPAN&gt;&amp;nbsp;2.2.2.0 /30&lt;/SPAN&gt;, correct?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you want to connect to the ASA from the Routed_Lan then use:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;ssh 0.0.0.0 0.0.0.0 &lt;/SPAN&gt;&lt;SPAN&gt;Routed_LAN&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;If you want to connect from the outside world then use:&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;If you want to connect from inside of the network then use:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;The interface says where the SSH traffic must come in from.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 18:19:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796403#M173282</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-01-23T18:19:25Z</dc:date>
    </item>
    <item>
      <title>You can not get to 8.8.8.8</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796404#M173283</link>
      <description>&lt;P&gt;You can not get to 8.8.8.8 via Routed_Lan. &amp;nbsp;Routed_Lan only has 3.3.3.0/29 on it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You get to 8.8.8.8 via your outside interface - the connection to your ISP.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;A host in Routed_Lan will send its traffic to 3.3.3.1, the ASA, which will then forward it to your ISP. &amp;nbsp;The ISP traffic will come in over the outside interface 2.2.2.2 and then the ASA will forward it to Routed_Lan.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 18:21:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796404#M173283</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-01-23T18:21:39Z</dc:date>
    </item>
    <item>
      <title>Hi Philip</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796405#M173284</link>
      <description>&lt;P&gt;Hi Philip&lt;/P&gt;
&lt;P&gt;Routed_LAN is not my connection to ISP. &amp;nbsp;ISP connects via Outside IP Address 2.2.2.0/30.&lt;/P&gt;
&lt;P&gt;I will give a shot tomorrow by connecting the server with Routed_LAN. &amp;nbsp;Thanks for all your sincere help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2016 18:25:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796405#M173284</guid>
      <dc:creator>faiqmahdi</dc:creator>
      <dc:date>2016-01-23T18:25:41Z</dc:date>
    </item>
    <item>
      <title>Hi Philip</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796406#M173285</link>
      <description>&lt;P&gt;Hi Philip&lt;/P&gt;
&lt;P&gt;I connected a Server and everything worked like a charm. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot and really appreciate all your sincere help.&lt;/P&gt;
&lt;P&gt;Stay blessed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2016 06:24:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796406#M173285</guid>
      <dc:creator>faiqmahdi</dc:creator>
      <dc:date>2016-01-24T06:24:24Z</dc:date>
    </item>
    <item>
      <title>You're welcome.  I hope you</title>
      <link>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796407#M173286</link>
      <description>&lt;P&gt;You're welcome. &amp;nbsp;I hope you'll enjoy your change to the ASA platform. &amp;nbsp;It is a much nicer config having it work this way as well.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jan 2016 06:45:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5510-public-pool-ip-address-assignment-on-lan-server/m-p/2796407#M173286</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2016-01-24T06:45:29Z</dc:date>
    </item>
  </channel>
</rss>

