<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ClaytonYou won't be able to in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769494#M192697</link>
    <description>&lt;P&gt;Clayton&lt;/P&gt;&lt;P&gt;You won't be able to route between vlans without setting up NAT between the interfaces ie.&lt;/P&gt;&lt;P&gt;static (inside,ipcamera) 192.168.11.0 192.168.11.0 255.255.255.0&lt;BR /&gt;static (ipcamera,inside) 192.168.12.0 192.168.12.0 255.255.255.0&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
    <pubDate>Tue, 18 Aug 2015 14:20:34 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2015-08-18T14:20:34Z</dc:date>
    <item>
      <title>No Internet for Multiple VLANS</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769484#M192687</link>
      <description>&lt;P&gt;On an ASA 5505 Ver 8.2(5) I have the ability to access internet from primary vlan. &amp;nbsp;However, when I added an additional vlan I'm not able to access the internet from that vlan. &amp;nbsp;I'm able to get out to internet on VLAN1. &amp;nbsp;However, I'm not on VLAN12. &amp;nbsp;I have the security plus license for this appliance. &amp;nbsp;Any assistance I can get with this is greatly appreciated.&lt;/P&gt;&lt;P&gt;--Clayton&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:26:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769484#M192687</guid>
      <dc:creator>claytonp</dc:creator>
      <dc:date>2019-03-12T06:26:45Z</dc:date>
    </item>
    <item>
      <title>ClaytonYou need to add "nat</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769485#M192688</link>
      <description>&lt;P&gt;Clayton&lt;/P&gt;&lt;P&gt;You need to add either "nat (ipcamera) 1 0.0.0.0 0.0.0.0"&amp;nbsp;or "nat (ipcamera) 1&amp;nbsp;192.168.12.0 255.255.255.0" &amp;nbsp;to your configuration.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2015 21:16:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769485#M192688</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-08-17T21:16:19Z</dc:date>
    </item>
    <item>
      <title>Hello Jon!  I've tried both</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769486#M192689</link>
      <description>&lt;P&gt;Hello Jon! &amp;nbsp;I've tried both with no success.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2015 23:50:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769486#M192689</guid>
      <dc:creator>claytonp</dc:creator>
      <dc:date>2015-08-17T23:50:15Z</dc:date>
    </item>
    <item>
      <title>Can you post output of -</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769487#M192690</link>
      <description>&lt;P&gt;Can you post output of -&lt;/P&gt;&lt;P&gt;"packet-tracer input inside tcp&amp;nbsp;192.168.12.10 12345 8.8.8.8 www"&lt;/P&gt;&lt;P&gt;From the ASA can you ping a 192.168.12.x client ?&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 11:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769487#M192690</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-08-18T11:11:03Z</dc:date>
    </item>
    <item>
      <title>Here you go! Result of the</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769488#M192691</link>
      <description>&lt;P&gt;Here you go!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result of the command: "packet-tracer input inside tcp 192.168.12.10 12345 8.8.8.8 www"&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in &amp;nbsp; 0.0.0.0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.0.0.0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; outside&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&amp;nbsp;&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 3&lt;BR /&gt;Type: NAT-EXEMPT&lt;BR /&gt;Subtype:&amp;nbsp;&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;&amp;nbsp; match ip inside 192.168.12.0 255.255.255.0 outside any&lt;BR /&gt;&amp;nbsp; &amp;nbsp; NAT exempt&lt;BR /&gt;&amp;nbsp; &amp;nbsp; translate_hits = 1, untranslate_hits = 0&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 4&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&amp;nbsp;&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp; match ip inside any outside any&lt;BR /&gt;&amp;nbsp; &amp;nbsp; dynamic translation to pool 1 (65.114.22.82 [Interface PAT])&lt;BR /&gt;&amp;nbsp; &amp;nbsp; translate_hits = 266513, untranslate_hits = 168014&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 5&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: host-limits&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;&amp;nbsp; match ip inside any inside any&lt;BR /&gt;&amp;nbsp; &amp;nbsp; dynamic translation to pool 1 (No matching global)&lt;BR /&gt;&amp;nbsp; &amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 6&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&amp;nbsp;&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Phase: 7&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&amp;nbsp;&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 1441990, packet dispatched to next module&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am able to ping a 192.168.12.x client from the ASA&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 12:38:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769488#M192691</guid>
      <dc:creator>claytonp</dc:creator>
      <dc:date>2015-08-18T12:38:52Z</dc:date>
    </item>
    <item>
      <title>Not sure what is happening</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769489#M192692</link>
      <description>&lt;P&gt;Not sure what is happening here.&lt;/P&gt;&lt;P&gt;The output suggests you are matching the "ip nat (inside) 1 0.0.0.0 0.0.0.0" entry but you shouldn't be.&lt;/P&gt;&lt;P&gt;So is the client port on the switch in vlan 12 and how is the switch connected to the ASA ie. what is the configuration on the port on the switch that connects to e0/7 on your ASA ?&lt;/P&gt;&lt;P&gt;Also can you attach the configuration you are currently working with ?&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 12:51:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769489#M192692</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-08-18T12:51:06Z</dc:date>
    </item>
    <item>
      <title>The client port on the switch</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769490#M192693</link>
      <description>&lt;P&gt;The client port on the switch is in vlan 12. &amp;nbsp;Port e0/7 connects to switch which is also on vlan 12 in access mode.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 13:41:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769490#M192693</guid>
      <dc:creator>claytonp</dc:creator>
      <dc:date>2015-08-18T13:41:04Z</dc:date>
    </item>
    <item>
      <title>The client port on the switch</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769491#M192694</link>
      <description>&lt;P&gt;The client port on the switch is in vlan 12. &amp;nbsp;Port e0/7 connects to switch which is also on vlan 12 in access mode.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 13:41:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769491#M192694</guid>
      <dc:creator>claytonp</dc:creator>
      <dc:date>2015-08-18T13:41:11Z</dc:date>
    </item>
    <item>
      <title>You have this line -access</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769492#M192695</link>
      <description>&lt;P&gt;You have this line -&lt;/P&gt;&lt;P&gt;&lt;EM&gt;access-list inside_nat0_outbound extended permit ip 192.168.12.0 255.255.255.0 any &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;and the NAT exemption ie. "nat (inside) 0 access-list &amp;lt;acl name&amp;gt;" takes precedence if I remember correctly.&lt;/P&gt;&lt;P&gt;If that line is for VPN then you need to make the destination the same as the other line ie. 192.168.5.0 255.255.255.0 but you can't use any because that includes internet.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 13:47:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769492#M192695</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-08-18T13:47:35Z</dc:date>
    </item>
    <item>
      <title>Seems to be working now.</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769493#M192696</link>
      <description>&lt;P&gt;Seems to be working now. &amp;nbsp;Below is what I changed:&lt;/P&gt;&lt;P&gt;no&amp;nbsp;access-list inside_nat0_outbound extended permit ip 192.168.12.0 255.255.255.0 any&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 192.168.12.0 255.255.255.0 192.168.5.0 255.255.255.0&lt;/P&gt;&lt;P&gt;The 192.168.12.X is able to get to internet now. &amp;nbsp;&lt;/P&gt;&lt;P&gt;Last issue is I'm not able to route between these two vlans. &amp;nbsp;Should I create another discussion for this issue?&lt;/P&gt;&lt;P&gt;--Clayton&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 14:11:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769493#M192696</guid>
      <dc:creator>claytonp</dc:creator>
      <dc:date>2015-08-18T14:11:58Z</dc:date>
    </item>
    <item>
      <title>ClaytonYou won't be able to</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769494#M192697</link>
      <description>&lt;P&gt;Clayton&lt;/P&gt;&lt;P&gt;You won't be able to route between vlans without setting up NAT between the interfaces ie.&lt;/P&gt;&lt;P&gt;static (inside,ipcamera) 192.168.11.0 192.168.11.0 255.255.255.0&lt;BR /&gt;static (ipcamera,inside) 192.168.12.0 192.168.12.0 255.255.255.0&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 14:20:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769494#M192697</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-08-18T14:20:34Z</dc:date>
    </item>
    <item>
      <title>Can this be accomplished</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769495#M192698</link>
      <description>&lt;P&gt;Can this be accomplished without the connection to the switch not being a trunk?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 15:03:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769495#M192698</guid>
      <dc:creator>claytonp</dc:creator>
      <dc:date>2015-08-18T15:03:09Z</dc:date>
    </item>
    <item>
      <title>It shouldn't make any</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769496#M192699</link>
      <description>&lt;P&gt;It shouldn't make any difference whether you use a trunk or not.&lt;/P&gt;&lt;P&gt;Your question is slightly unclear, what exactly do you want to do ?&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 15:09:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769496#M192699</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-08-18T15:09:20Z</dc:date>
    </item>
    <item>
      <title>I just want to be able to</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769497#M192700</link>
      <description>&lt;P&gt;I just want to be able to pass traffic between the two vlans.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 15:12:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769497#M192700</guid>
      <dc:creator>claytonp</dc:creator>
      <dc:date>2015-08-18T15:12:23Z</dc:date>
    </item>
    <item>
      <title>Then you should be fine with</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769498#M192701</link>
      <description>&lt;P&gt;Then you should be fine with what you have as long as you add those NAT statements.&lt;/P&gt;&lt;P&gt;Is everything working now ?&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 15:13:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769498#M192701</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-08-18T15:13:38Z</dc:date>
    </item>
    <item>
      <title>I get the following error</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769499#M192702</link>
      <description>&lt;P&gt;I get the following error message when applying those statements:&lt;/P&gt;&lt;P&gt;Result of the command: "static (inside,ipcamera) 192.168.11.0 192.168.11.0 255.255.255.0"&lt;/P&gt;&lt;P&gt;static (inside,ipcamera) 192.168.11.0 192.168.11.0 255.255.255.0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Result of the command: "static (ipcamera,inside) 192.168.12.0 192.168.12.0 255.255.255.0"&lt;/P&gt;&lt;P&gt;static (ipcamera,inside) 192.168.12.0 192.168.12.0 255.255.255.0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 15:18:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769499#M192702</guid>
      <dc:creator>claytonp</dc:creator>
      <dc:date>2015-08-18T15:18:50Z</dc:date>
    </item>
    <item>
      <title>Sorry I missed out the</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769500#M192703</link>
      <description>&lt;P&gt;Sorry I missed out the "netmask" keyword, they should be -&lt;/P&gt;&lt;P&gt;static (inside,ipcamera) 192.168.11.0 192.168.11.0 netmask 255.255.255.0&lt;BR /&gt;static (ipcamera,inside) 192.168.12.0 192.168.12.0 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 15:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769500#M192703</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-08-18T15:33:48Z</dc:date>
    </item>
    <item>
      <title>AWESOME!!!!   It's working.</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769501#M192704</link>
      <description>&lt;P&gt;AWESOME!!!! &amp;nbsp; It's working. &amp;nbsp;Thanks a million. &amp;nbsp;I learned from&amp;nbsp;this session.&lt;/P&gt;&lt;P&gt;--Clayton&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 15:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769501#M192704</guid>
      <dc:creator>claytonp</dc:creator>
      <dc:date>2015-08-18T15:36:20Z</dc:date>
    </item>
    <item>
      <title>No problem, glad you got it</title>
      <link>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769502#M192705</link>
      <description>&lt;P&gt;No problem, glad you got it working.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 15:43:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-internet-for-multiple-vlans/m-p/2769502#M192705</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-08-18T15:43:46Z</dc:date>
    </item>
  </channel>
</rss>

