<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi , You need to request in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506626#M235334</link>
    <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;You need to request&amp;nbsp;additional IP address from your service provider , or if your WAN IP address of your router is going to constant /permanent&amp;nbsp;for your connection . You can do static NAT for ASA outside IP address on port 443 (SSL VPN&amp;nbsp;) /&amp;nbsp;ISAKMP&amp;nbsp;&amp;nbsp;(IPSEC VPN)and you can configure for Remote access VPN on your ASA&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Sandy&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly rate for helpful post&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Aug 2014 15:54:04 GMT</pubDate>
    <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
    <dc:date>2014-08-25T15:54:04Z</dc:date>
    <item>
      <title>internet access issue asa5505 security plus</title>
      <link>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506619#M235327</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I'm new in configuration Cisco firewall.and I can't get internet access on the inside LAN.&lt;/P&gt;&lt;P&gt;Architecture :&lt;/P&gt;&lt;P&gt;Router ISP (local IP : 192.168.1.1 / IP fixe : 81.xx.xx.xx)---&amp;gt;ASA5505 Security plus---&amp;gt;VLAN1 (inside : 10.10.10.1 / VLAN 2 Outside : I puted IP fixe of ISP router :81.xx.xx.xx)&lt;/P&gt;&lt;P&gt;so I have created two VLAN : VLAN 1---&amp;gt;inside and VLAN 2 (outside)&lt;/P&gt;&lt;P&gt;when I use DHCP on the outside interface , I can get internet on the computer connected to ETH0/1 but when I use IP fixe : 81.xx.xx.xx , I can't get the internet .&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;PS :&lt;/STRONG&gt; I put ISP DNS on the ASA ( 62.251.229.237 62.251.229.223 )&lt;/P&gt;&lt;P&gt;my client computer has automatically : IP Address : 10.10.10.10 netmask : 255.255.255.0 Gateway : 10.10.10.1 (ASA) ,DNS1:62.251.229.237 DNS2 :62).251.229.223&lt;/P&gt;&lt;P&gt;I can't ping from the computer connected to ETH 0/1 : IP fixe (81.xx.xx.xx) ,8.8.8.8 (google) and I can't browse the internet&lt;/P&gt;&lt;P&gt;hereafter my configuration if you can please take a look at this and help me to solve this issue , thanks in advance:&lt;/P&gt;&lt;P&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 8.2(5)&lt;BR /&gt;!&lt;BR /&gt;hostname ciscoasa&lt;BR /&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;BR /&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;shutdown&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 10.10.10.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address 81.xx.xx.xx 255.0.0.0&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 81.xx.xx.xx 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;aaa authentication http console LOCAL&lt;BR /&gt;http server enable&lt;BR /&gt;http 10.10.10.0 255.255.255.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd dns 62.251.229.237 62.251.229.223&lt;BR /&gt;dhcpd auto_config outside&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 10.10.10.10-10.10.10.20 inside&lt;BR /&gt;dhcpd enable inside&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;webvpn&lt;BR /&gt;username mysuername password mypassword encrypted privilege 15&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect dns preset_dns_map&lt;BR /&gt;inspect ftp&lt;BR /&gt;inspect h323 h225&lt;BR /&gt;inspect h323 ras&lt;BR /&gt;inspect ip-options&lt;BR /&gt;inspect netbios&lt;BR /&gt;inspect rsh&lt;BR /&gt;inspect rtsp&lt;BR /&gt;inspect skinny&lt;BR /&gt;inspect esmtp&lt;BR /&gt;inspect sqlnet&lt;BR /&gt;inspect sunrpc&lt;BR /&gt;inspect tftp&lt;BR /&gt;inspect sip&lt;BR /&gt;inspect xdmcp&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;call-home&lt;BR /&gt;profile CiscoTAC-1&lt;BR /&gt;no active&lt;BR /&gt;destination address http &lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService" target="_blank"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt;&lt;BR /&gt;destination address email &lt;A href="mailto:callhome@cisco.com" rel="nofollow" target="_blank"&gt;callhome@cisco.com&lt;/A&gt;&lt;BR /&gt;destination transport-method http&lt;BR /&gt;subscribe-to-alert-group diagnostic&lt;BR /&gt;subscribe-to-alert-group environment&lt;BR /&gt;subscribe-to-alert-group inventory periodic monthly&lt;BR /&gt;subscribe-to-alert-group configuration periodic monthly&lt;BR /&gt;subscribe-to-alert-group telemetry periodic daily&lt;BR /&gt;Cryptochecksum:76bb15d8918d0e91f499c0ae2754eea8&lt;BR /&gt;: end&lt;BR /&gt;no asdm history enable&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:40:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506619#M235327</guid>
      <dc:creator>informaticien9</dc:creator>
      <dc:date>2019-03-12T04:40:26Z</dc:date>
    </item>
    <item>
      <title>Hi ,Check your sub-net mask</title>
      <link>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506620#M235328</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;Check your sub-net mask for outside VLAN/outside sub-net , it cant be &amp;nbsp;255.0.0.0&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;ip address 81.xx.xx.xx 255.0.0.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;Sandy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2014 13:44:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506620#M235328</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-08-25T13:44:27Z</dc:date>
    </item>
    <item>
      <title>Hi Sandy,First of all ,</title>
      <link>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506621#M235329</link>
      <description>&lt;P&gt;Hi Sandy,&lt;/P&gt;&lt;P&gt;First of all , thanks for your hepl appreciated,&lt;/P&gt;&lt;P&gt;For information&amp;nbsp;, I got automatically&amp;nbsp;this sub-net from the my ISP router , please see the attached file and let me know please what can i edit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks again&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2014 13:52:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506621#M235329</guid>
      <dc:creator>informaticien9</dc:creator>
      <dc:date>2014-08-25T13:52:37Z</dc:date>
    </item>
    <item>
      <title>Hi , Where you are</title>
      <link>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506622#M235330</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Where you are configuring PPOE on router ?? or your ASA . &amp;nbsp;How is your internet router is connected to service provider ??&lt;/P&gt;&lt;P&gt;Can you share me your internet router config .when you connect laptop directly to your internet router what is the ip address getting assigned to the laptop/ you assign IP address statically to your laptop ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Sandy&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2014 14:13:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506622#M235330</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-08-25T14:13:34Z</dc:date>
    </item>
    <item>
      <title>Hi Sandy, PPPOE is configured</title>
      <link>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506623#M235331</link>
      <description>&lt;P&gt;Hi Sandy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PPPOE is configured automatically on the internet&amp;nbsp;router&amp;nbsp;when I purshased a fixed IP address (81.xxx.xxx.17) as shown on my last file sent.when I connect my laptop directly to my internet router , the IP address is assigned automatically by DHCP of the internet router : Address ip :192.168.1.10 netmask : 255.255.255.0 ,Gatway : 192.168.1.1 (IP of my internet router) , DNS: 192.168.1.1 WINS : 192.168.1.1&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2014 14:24:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506623#M235331</guid>
      <dc:creator>informaticien9</dc:creator>
      <dc:date>2014-08-25T14:24:42Z</dc:date>
    </item>
    <item>
      <title>Hi , You cant Purchase single</title>
      <link>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506624#M235332</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;You cant Purchase single public IP address from your Internet service provider , it must be block IP address like x.x.x.x/30 or x.x.x.x/29&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once you gain block of IP address , you need to assign one IP address on your router LAN interface and another IP address for your connected host ( in our scenario its ASA ) . Both should be on same LAN segment , Default route for&amp;nbsp;your connected host must be IP address assigned on to router LAN interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On your topology , router LAN interface IP address is assigned&amp;nbsp;with 192.168.1.1 subnet and it release IP address for connected host from same subnet , But you have connected your ASA to same interface and have you configured Public IP address (&lt;SPAN style="background-color: rgb(247, 247, 247);"&gt;&lt;FONT color="#777777"&gt;&lt;SPAN style="font-size: 14px;"&gt;81.xx.xx.xx 255.0.0.0) &amp;nbsp;where there wont be any network&amp;nbsp;connectivity&amp;nbsp;.&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;Presently from your connectvity from your ASA you cant ping to router LAN interface .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me if you need any support&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Sandy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2014 14:51:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506624#M235332</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-08-25T14:51:32Z</dc:date>
    </item>
    <item>
      <title>Hi Sandy,Thanks for your</title>
      <link>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506625#M235333</link>
      <description>&lt;P&gt;Hi Sandy,&lt;/P&gt;&lt;P&gt;Thanks for your explanation , I appreciate it very much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;However I don't know unfortunatly how to solve my issue if you can help more please&lt;/P&gt;&lt;P&gt;For information when I use dhcp on ETH 0/0 ,&amp;nbsp;I can access well to internet on my inside hosts&amp;nbsp;:&lt;/P&gt;&lt;P&gt;ciscoasa(configif)#interface vlan 2&lt;BR /&gt;ciscoasa(configif)#nameif outside&lt;BR /&gt;INFO: Security level for "outside" set to 0 by default.&lt;BR /&gt;ciscoasa(configif)#ip address dhcp&lt;/P&gt;&lt;P&gt;Why I want to use the single public IP address ? because I'll need it to setup up VPN remote access .&lt;/P&gt;&lt;P&gt;so I should find the solution to use a single public IP Address on outside&amp;nbsp; interface (eth0/0) on ASA5505.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think my router is configured with bridge mode&lt;/P&gt;&lt;P&gt;LAN bridge: 192.168.1.1 - 255.255.255.0&lt;/P&gt;&lt;P&gt;WAN Bridge : 81.xx.xx.17 255.0.0.0 - Gatway 41.140.0.1( I see it"s dynamic gatway,and it change)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you please tell me what can i do to access internet on inside LAN using IP public on outside interface ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for your time and support&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2014 15:05:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506625#M235333</guid>
      <dc:creator>informaticien9</dc:creator>
      <dc:date>2014-08-25T15:05:12Z</dc:date>
    </item>
    <item>
      <title>Hi , You need to request</title>
      <link>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506626#M235334</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;You need to request&amp;nbsp;additional IP address from your service provider , or if your WAN IP address of your router is going to constant /permanent&amp;nbsp;for your connection . You can do static NAT for ASA outside IP address on port 443 (SSL VPN&amp;nbsp;) /&amp;nbsp;ISAKMP&amp;nbsp;&amp;nbsp;(IPSEC VPN)and you can configure for Remote access VPN on your ASA&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Sandy&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly rate for helpful post&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Aug 2014 15:54:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/internet-access-issue-asa5505-security-plus/m-p/2506626#M235334</guid>
      <dc:creator>SANTHOSHKUMAR SARAVANAN</dc:creator>
      <dc:date>2014-08-25T15:54:04Z</dc:date>
    </item>
  </channel>
</rss>

