<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unfortunately still learning in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615534#M197075</link>
    <description>&lt;P&gt;Unfortunately still learning the ASA so no to the PAT piece&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 14 Feb 2015 14:04:33 GMT</pubDate>
    <dc:creator>Dave Kozlowski</dc:creator>
    <dc:date>2015-02-14T14:04:33Z</dc:date>
    <item>
      <title>Cannot connect  ASA interfaces</title>
      <link>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615528#M197069</link>
      <description>&lt;P&gt;Having a problem&amp;nbsp; Trying to setup an 5520 ASA&lt;/P&gt;&lt;P&gt;I can get the static route 0.0.0.0 thru the external interface to work fine. System accepts it with no errors&lt;/P&gt;&lt;P&gt;When I try to setup other routes,&amp;nbsp; say a route to my lan side network, I keep getting the error&amp;nbsp;&amp;nbsp; " Cannot add route, connected route exist&lt;/P&gt;&lt;P&gt;Seems line the wan and lan interfaces aren't communicating to each other.&lt;/P&gt;&lt;P&gt;I can ping out via my wan interface but not my lan interface.&lt;/P&gt;&lt;P&gt;Help is appreciated.&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:30:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615528#M197069</guid>
      <dc:creator>Dave Kozlowski</dc:creator>
      <dc:date>2019-03-12T05:30:10Z</dc:date>
    </item>
    <item>
      <title>DaveThat usually means you</title>
      <link>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615529#M197070</link>
      <description>&lt;P&gt;Dave&lt;/P&gt;&lt;P&gt;That usually means you are adding a route for a subnet that the ASA has an IP from on one of it's interfaces.&lt;/P&gt;&lt;P&gt;What route are you trying to add and what does the routing table look like on the ASA ?&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Sat, 14 Feb 2015 12:57:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615529#M197070</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-02-14T12:57:55Z</dc:date>
    </item>
    <item>
      <title>Here is what I haveWan</title>
      <link>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615530#M197071</link>
      <description>&lt;P&gt;Here is what I have&lt;/P&gt;&lt;P&gt;Wan interface &amp;nbsp;50.206.215.130 &amp;nbsp;other side 50.206.215.129&lt;/P&gt;&lt;P&gt;Routing 0.0.0.0 thru 50.206.215.129 works fine. &amp;nbsp;I can ping outside (8.8.8.8)&lt;/P&gt;&lt;P&gt;Lan interface 17216.100.251 other side switch 172.16.100.250&lt;/P&gt;&lt;P&gt;From this interface I can ping inside the switch. &amp;nbsp;&lt;/P&gt;&lt;P&gt;But if I use the Wan interface I cannot inside the switch&lt;/P&gt;&lt;P&gt;Also from the lan interface I cannot pintg out (8.8.8.8)&lt;/P&gt;&lt;P&gt;Tried to setup a route 172.16.100.0/24 using the 172.16.100.250 gateway and I get an error.&lt;/P&gt;&lt;P&gt;Hope this makes sense.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Sat, 14 Feb 2015 13:11:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615530#M197071</guid>
      <dc:creator>Dave Kozlowski</dc:creator>
      <dc:date>2015-02-14T13:11:34Z</dc:date>
    </item>
    <item>
      <title>DaveYou can't add that route</title>
      <link>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615531#M197072</link>
      <description>&lt;P&gt;Dave&lt;/P&gt;&lt;P&gt;You can't add that route because the ASA inside interface is already in that IP subnet so it doesn't need a route.&lt;/P&gt;&lt;P&gt;I also don't think you can ping from the WAN interface to the switch because the ASA doesn't allow that or at least the versions I worked on didn't.&lt;/P&gt;&lt;P&gt;If you want to test connectivity don't use the ASA interfaces, use the switch and try to ping out.&lt;/P&gt;&lt;P&gt;Have you setup NAT for the 172.16.100.0/24 subnet ?&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Sat, 14 Feb 2015 13:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615531#M197072</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-02-14T13:16:41Z</dc:date>
    </item>
    <item>
      <title>from switch I can only ping</title>
      <link>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615532#M197073</link>
      <description>&lt;P&gt;from switch I can only ping the lan interface 172.16.100.251&lt;/P&gt;&lt;P&gt;Haven't setup anything with NAT yet.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Feb 2015 13:24:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615532#M197073</guid>
      <dc:creator>Dave Kozlowski</dc:creator>
      <dc:date>2015-02-14T13:24:46Z</dc:date>
    </item>
    <item>
      <title>Okay when testing from the</title>
      <link>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615533#M197074</link>
      <description>&lt;P&gt;Okay when testing from the switch don't try and ping the outside interface of the ASA as it won't work. Ping an IP beyond the ASA.&lt;/P&gt;&lt;P&gt;So you will need to setup -&lt;/P&gt;&lt;P&gt;1) dynamic PAT if you are translating all internal IPs to the outside interface IP of your ASA&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;2) if you are using ping to test then you need either -&lt;/P&gt;&lt;P&gt;i)&amp;nbsp; ICMP inspection&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;ii) an acl on the outside interface allowing ICMP back in&lt;/P&gt;&lt;P&gt;do you know how to set this up ?&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Sat, 14 Feb 2015 13:29:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615533#M197074</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-02-14T13:29:23Z</dc:date>
    </item>
    <item>
      <title>Unfortunately still learning</title>
      <link>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615534#M197075</link>
      <description>&lt;P&gt;Unfortunately still learning the ASA so no to the PAT piece&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Feb 2015 14:04:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615534#M197075</guid>
      <dc:creator>Dave Kozlowski</dc:creator>
      <dc:date>2015-02-14T14:04:33Z</dc:date>
    </item>
    <item>
      <title>Add this to your ASA -object</title>
      <link>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615535#M197076</link>
      <description>&lt;P&gt;Add this to your ASA -&lt;/P&gt;&lt;P&gt;object network PAT&lt;BR /&gt;subnet 172.16.100.0 255.255.255.0&lt;BR /&gt;nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp; class inspection_default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;Note the above is a basic configuration to get you going.&lt;/P&gt;&lt;P&gt;There are other ways to do the NAT depending on what your other NAT requirements are.&lt;/P&gt;&lt;P&gt;See this document for 8.3 NAT onwards written by Jouni Forss. It's one of the best documents on this site in my opinion.&lt;/P&gt;&lt;P&gt;He normally configures dynamic PAT in section 3 using the after-auto option but I have given you just a basic example using object NAT.&lt;/P&gt;&lt;P&gt;If you read the doc you'll understand what I am talking about and it is worth reading to get a better understanding of how it all works -&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportforums.cisco.com/document/132066/asa-nat-83-nat-operation-and-configuration-format-cli"&gt;https://supportforums.cisco.com/document/132066/asa-nat-83-nat-operation-and-configuration-format-cli&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Any problems with the config above let me know.&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Sat, 14 Feb 2015 15:19:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-connect-asa-interfaces/m-p/2615535#M197076</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2015-02-14T15:19:53Z</dc:date>
    </item>
  </channel>
</rss>

