<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot access outside from guestwifi (dmz) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715696#M194159</link>
    <description>&lt;P&gt;Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to create a guestwifi, but it does not seem to work, i will post my configurations below. Please let me know any additional information.&lt;/P&gt;&lt;P&gt;ASA Version 8.2(1)&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;BR /&gt;&amp;nbsp;nameif guestwifi&lt;BR /&gt;&amp;nbsp;security-level 5&lt;BR /&gt;&amp;nbsp;ip address 192.168.175.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;global (guestwifi) 1 interface&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;dhcpd dns 8.8.8.8 8.8.4.4&lt;BR /&gt;dhcpd lease 86400&lt;BR /&gt;dhcpd option 3 ip 192.168.175.1&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 192.168.175.10-192.168.175.253 guestwifi&lt;BR /&gt;dhcpd enable guestwifi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MonogramASA# packet-tracer input guestwifi icmp 192.168.175.12 0 0 216.58.216.110&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;MAC Access list&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: FLOW-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Found no matching flow, creating a new flow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 10836954, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: guestwifi&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 06:13:02 GMT</pubDate>
    <dc:creator>Chad Campbell</dc:creator>
    <dc:date>2019-03-12T06:13:02Z</dc:date>
    <item>
      <title>Cannot access outside from guestwifi (dmz)</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715696#M194159</link>
      <description>&lt;P&gt;Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to create a guestwifi, but it does not seem to work, i will post my configurations below. Please let me know any additional information.&lt;/P&gt;&lt;P&gt;ASA Version 8.2(1)&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;BR /&gt;&amp;nbsp;nameif guestwifi&lt;BR /&gt;&amp;nbsp;security-level 5&lt;BR /&gt;&amp;nbsp;ip address 192.168.175.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;global (guestwifi) 1 interface&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;dhcpd dns 8.8.8.8 8.8.4.4&lt;BR /&gt;dhcpd lease 86400&lt;BR /&gt;dhcpd option 3 ip 192.168.175.1&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 192.168.175.10-192.168.175.253 guestwifi&lt;BR /&gt;dhcpd enable guestwifi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MonogramASA# packet-tracer input guestwifi icmp 192.168.175.12 0 0 216.58.216.110&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ACCESS-LIST&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Implicit Rule&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;MAC Access list&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: FLOW-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Found no matching flow, creating a new flow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: INSPECT&lt;/P&gt;&lt;P&gt;Subtype: np-inspect&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Phase: 6&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype:&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 10836954, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: guestwifi&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:13:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715696#M194159</guid>
      <dc:creator>Chad Campbell</dc:creator>
      <dc:date>2019-03-12T06:13:02Z</dc:date>
    </item>
    <item>
      <title>HI,Need more infor on your</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715697#M194160</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;Need more infor on your configuration. is the wireless access point configuration okay? Do you have a NAT device between Internet and firewall and is it configure okay?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2015 23:29:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715697#M194160</guid>
      <dc:creator>johnd2310</dc:creator>
      <dc:date>2015-07-02T23:29:12Z</dc:date>
    </item>
    <item>
      <title>Thanks John, The devices</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715698#M194161</link>
      <description>&lt;P&gt;Thanks John, The devices connects to the AP and gets a DHCP&amp;nbsp;address successfully from the ASA, but are not able to access the internet through the outside interface. What do you mean do I have a NAT device?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2015 23:39:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715698#M194161</guid>
      <dc:creator>Chad Campbell</dc:creator>
      <dc:date>2015-07-02T23:39:19Z</dc:date>
    </item>
    <item>
      <title>Hi,Is the firewall connected</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715699#M194162</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is the firewall connected to the Internet or do you have another device between the firewall and the Internet?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2015 23:42:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715699#M194162</guid>
      <dc:creator>johnd2310</dc:creator>
      <dc:date>2015-07-02T23:42:29Z</dc:date>
    </item>
    <item>
      <title>The firewall is directly</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715700#M194163</link>
      <description>&lt;P&gt;The firewall is directly connected to the internet.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2015 23:43:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715700#M194163</guid>
      <dc:creator>Chad Campbell</dc:creator>
      <dc:date>2015-07-02T23:43:54Z</dc:date>
    </item>
    <item>
      <title>Hi,IS this correct global</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715701#M194164</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;IS this correct&amp;nbsp;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;global (guestwifi) 1 interface? Where is the NAT&amp;nbsp;&amp;nbsp;config for the&amp;nbsp;192.168.175.0/24 network?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;John&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2015 23:58:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715701#M194164</guid>
      <dc:creator>johnd2310</dc:creator>
      <dc:date>2015-07-02T23:58:40Z</dc:date>
    </item>
    <item>
      <title>John, I did not include 1, I</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715702#M194165</link>
      <description>&lt;P&gt;John,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did not include 1, I thought the global nat statement would have covered the NAT (i guess not), but I do no have a NAT config for that network, can you give me a simple command to show me what it should look like?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2015 00:06:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715702#M194165</guid>
      <dc:creator>Chad Campbell</dc:creator>
      <dc:date>2015-07-03T00:06:00Z</dc:date>
    </item>
    <item>
      <title>Do you have something like</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715703#M194166</link>
      <description>&lt;P&gt;Do you have something like global (outside) 1 interface? If so, then the NAT statement would be&amp;nbsp;&lt;/P&gt;&lt;P&gt;nat(guestwifi)1 192.168.175.0 255.255.255.0&amp;nbsp;&lt;/P&gt;&lt;P&gt;i don't this you need&amp;nbsp;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;global (guestwifi) 1 interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2015 00:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715703#M194166</guid>
      <dc:creator>johnd2310</dc:creator>
      <dc:date>2015-07-03T00:20:48Z</dc:date>
    </item>
    <item>
      <title>Thanks John, I did see that</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715704#M194167</link>
      <description>&lt;P&gt;Thanks John, I did see that and I just entered the command you recommended, I will have my team to test, while I wait I am going to find some videos about natting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will let you know, thanks again.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2015 00:26:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715704#M194167</guid>
      <dc:creator>Chad Campbell</dc:creator>
      <dc:date>2015-07-03T00:26:32Z</dc:date>
    </item>
    <item>
      <title>Thanks John this work!</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715705#M194168</link>
      <description>&lt;P&gt;Thanks John this work!&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2015 16:10:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-outside-from-guestwifi-dmz/m-p/2715705#M194168</guid>
      <dc:creator>Chad Campbell</dc:creator>
      <dc:date>2015-07-03T16:10:57Z</dc:date>
    </item>
  </channel>
</rss>

