<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The subnet/vlan not able to in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5525-configuration/m-p/2720883#M193387</link>
    <description>&lt;P&gt;The subnet/vlan not able to access internet is:&lt;/P&gt;&lt;P&gt;object network NETWORK_OBJ_VLAN25&lt;BR /&gt;&amp;nbsp;subnet 192.168.100.0 255.255.255.254&lt;/P&gt;&lt;P&gt;description VLAN25&lt;/P&gt;&lt;P&gt;This config was entered by me:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ASA1(config)# object network NETWORK_OBJ_VLAN24&amp;#8; &amp;#8;5&lt;/P&gt;&lt;P&gt;ASA1(config-network-object)# subnet 192.168.100.0 255.255.254.0&lt;/P&gt;&lt;P&gt;ASA1(config-network-object)# description VLAN 25&lt;/P&gt;&lt;P&gt;ASA1(config-network-object)# END&lt;/P&gt;&lt;P&gt;ASA1# conf t&lt;/P&gt;&lt;P&gt;ASA1(config)# route inside 192.168.100.0 255.255.254.0 XX.XX.XX.X 1&lt;/P&gt;&lt;P&gt;ASA1(config)# end&lt;/P&gt;&lt;P&gt;These are the commands for nating in the firewall&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static VPN-xxxxxxx-NETWORKS destination static VPN-XXXXXXXXno-proxy-arp route-lookup&lt;BR /&gt;nat (inside,outside) source static any any destination static NETWORK_OBJ_10.255.255.0_24 NETWORK_OBJ_10.255.255.0_24&lt;BR /&gt;!&lt;BR /&gt;object network INSIDE&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 25 Jul 2015 19:59:15 GMT</pubDate>
    <dc:creator>dallewis1</dc:creator>
    <dc:date>2015-07-25T19:59:15Z</dc:date>
    <item>
      <title>ASA 5525 configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-configuration/m-p/2720881#M193382</link>
      <description>&lt;P&gt;Need help in configuring internet access for a particular sub-net on an ASA 5525 firewall.&lt;/P&gt;&lt;P&gt;I am pretty new to ASA.&amp;nbsp; From the configuration, all sub-nets are in a separate vlan and all the vlans configured have internet access.&amp;nbsp; I introduced a new vlan and there is no internet access for devices in that vlan.&lt;/P&gt;&lt;P&gt;A portion of my ASA config is as follows:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;object network INSIDE&lt;BR /&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network obj-XX.XXX.XXX..0&lt;BR /&gt;&amp;nbsp;subnet XX.XXX.XXX.0 XXX.XXX.XXX.0&lt;BR /&gt;object network NETWORK_OBJ_XX.XXX.XX.XX_24&lt;BR /&gt;&amp;nbsp;subnet XX.XXX.XXX.0 XXX.255.255.0&lt;BR /&gt;&amp;nbsp;description&lt;BR /&gt;object network NETWORK_OBJ_&lt;BR /&gt;&amp;nbsp;subnet XX.XX.XXX.0 XXX.XXX.XX.0&lt;BR /&gt;&amp;nbsp;description VPN&lt;BR /&gt;object network NETWORK_OBJ_VLAN&lt;BR /&gt;&amp;nbsp;subnet XXX.XX.XX.0 XX.XX.252.0&lt;BR /&gt;&amp;nbsp;description VLAN20&lt;BR /&gt;object network NETWORK_OBJ_VLAN60&lt;BR /&gt;&amp;nbsp;subnet XXX.XXX.XXX.0 XXX.XXX.XXX.0&lt;BR /&gt;&amp;nbsp;description VLAN60&lt;BR /&gt;object network NETWORK_OBJ_VLAN62&lt;BR /&gt;&amp;nbsp;subnet XXX.XXX.XXX.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;description VLAN62&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:19:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-configuration/m-p/2720881#M193382</guid>
      <dc:creator>dallewis1</dc:creator>
      <dc:date>2019-03-12T06:19:59Z</dc:date>
    </item>
    <item>
      <title>Please share which subnet</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-configuration/m-p/2720882#M193385</link>
      <description>&lt;P&gt;Please share which subnet/vlan is not able to access internet and also share the natting rules configured on the firewall.&lt;BR /&gt;&lt;BR /&gt;Regards.&lt;BR /&gt;Dinesh Moudgil&lt;BR /&gt;&lt;BR /&gt;P.S. Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jul 2015 15:58:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-configuration/m-p/2720882#M193385</guid>
      <dc:creator>Dinesh Moudgil</dc:creator>
      <dc:date>2015-07-25T15:58:56Z</dc:date>
    </item>
    <item>
      <title>The subnet/vlan not able to</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-configuration/m-p/2720883#M193387</link>
      <description>&lt;P&gt;The subnet/vlan not able to access internet is:&lt;/P&gt;&lt;P&gt;object network NETWORK_OBJ_VLAN25&lt;BR /&gt;&amp;nbsp;subnet 192.168.100.0 255.255.255.254&lt;/P&gt;&lt;P&gt;description VLAN25&lt;/P&gt;&lt;P&gt;This config was entered by me:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ASA1(config)# object network NETWORK_OBJ_VLAN24&amp;#8; &amp;#8;5&lt;/P&gt;&lt;P&gt;ASA1(config-network-object)# subnet 192.168.100.0 255.255.254.0&lt;/P&gt;&lt;P&gt;ASA1(config-network-object)# description VLAN 25&lt;/P&gt;&lt;P&gt;ASA1(config-network-object)# END&lt;/P&gt;&lt;P&gt;ASA1# conf t&lt;/P&gt;&lt;P&gt;ASA1(config)# route inside 192.168.100.0 255.255.254.0 XX.XX.XX.X 1&lt;/P&gt;&lt;P&gt;ASA1(config)# end&lt;/P&gt;&lt;P&gt;These are the commands for nating in the firewall&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static VPN-xxxxxxx-NETWORKS destination static VPN-XXXXXXXXno-proxy-arp route-lookup&lt;BR /&gt;nat (inside,outside) source static any any destination static NETWORK_OBJ_10.255.255.0_24 NETWORK_OBJ_10.255.255.0_24&lt;BR /&gt;!&lt;BR /&gt;object network INSIDE&lt;BR /&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jul 2015 19:59:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-configuration/m-p/2720883#M193387</guid>
      <dc:creator>dallewis1</dc:creator>
      <dc:date>2015-07-25T19:59:15Z</dc:date>
    </item>
    <item>
      <title>Are you using subinterfaces</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-configuration/m-p/2720884#M193388</link>
      <description>&lt;P&gt;Are you using subinterfaces on the ASA to connect to the VLANs / subnets on the local LAN or is it just a single routed interface between the ASA and a layer 3 swith or router on the LAN?&lt;/P&gt;&lt;P&gt;could you post the output of show int ip brief. &amp;nbsp;Remember to remove any public IPs from the configuration that you post.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jul 2015 20:14:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-configuration/m-p/2720884#M193388</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2015-07-25T20:14:19Z</dc:date>
    </item>
    <item>
      <title>I believe there are</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-configuration/m-p/2720885#M193390</link>
      <description>&lt;P&gt;I believe there are subinterfaces on the ASA to connect to the VLANS.&amp;nbsp; ASA is directly connected to a 3560 switch and config is as follows:&lt;/P&gt;&lt;P&gt;interface Port-channel30&lt;BR /&gt;&amp;nbsp;description po towards Firewall-1&lt;BR /&gt;&amp;nbsp;switchport trunk encapsulation dot1q&lt;BR /&gt;&amp;nbsp;switchport trunk allowed vlan 300,666&lt;BR /&gt;&amp;nbsp;switchport mode trunk&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;/P&gt;&lt;P&gt;inside interface config on the ASA is as follows:&lt;/P&gt;&lt;P&gt;interface Port-channel1.300&lt;BR /&gt;&amp;nbsp;vlan 300&lt;BR /&gt;&amp;nbsp;nameif inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;/P&gt;&lt;P&gt;I dont have access to the ASA right now to display the output of the sh int ip brief.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Jul 2015 21:29:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-configuration/m-p/2720885#M193390</guid>
      <dc:creator>dallewis1</dc:creator>
      <dc:date>2015-07-25T21:29:19Z</dc:date>
    </item>
    <item>
      <title>Since you are using</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525-configuration/m-p/2720886#M193392</link>
      <description>&lt;P&gt;Since you are using subinterfaces on the ASA for your VLANs you would just need to create a new subinterface and configure it to be in the new VLAN along with a security-level, interface name, and an IP address...also remember to issue the no shutdown command.&lt;/P&gt;&lt;P&gt;Then make sure that the switch at the other end is allowing that VLAN over the trunk link.&lt;/P&gt;&lt;P&gt;interface Port-channel30&lt;/P&gt;&lt;P&gt;&amp;nbsp; switchport trunk allowed vlan add &amp;lt;VLAN number&amp;gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jul 2015 17:13:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525-configuration/m-p/2720886#M193392</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2015-07-26T17:13:17Z</dc:date>
    </item>
  </channel>
</rss>

