<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, The configuration seems in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sub-interface-not-connection-to-internet/m-p/2522467#M236471</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The configuration seems kinda strange. I mean the fact that you have configured IP address under the actual physical interface but also configured subinterface for the physical interface. Typically when you configure a Trunk you leave the physical interface configurations blank other than set the duplex/speed and description configurations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How is the switchport connected to this ASA configured?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT: Just to add. I presume that if your &lt;STRONG&gt;"inside"&lt;/STRONG&gt; users are in Vlan 1 of the switched network then this is probably understandable that is works as the traffic comes to the ASA probably untagged.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want&amp;nbsp; to test the ASA configurations then you can use the command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input IOS_DC tcp 10.10.2.100 12345 8.8.8.8 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The above IPs are just chosen by me randomly. The output of the above command should show you what rules such a packet would match on the ASA. We could for example see if the traffic is even allowed and if its allowed does it have proper NAT configurations and so on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
    <pubDate>Fri, 18 Jul 2014 07:35:32 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2014-07-18T07:35:32Z</dc:date>
    <item>
      <title>Sub_interface not connection to internet</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-not-connection-to-internet/m-p/2522464#M236468</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a sub-interface 'on' the inside (see below) and setup the VLAN ID &amp;nbsp;--&amp;gt; Connected the VLAN to the SWITCH and &amp;nbsp;routed to the PORT. &amp;nbsp;The Server(s) recognize the 'new' VLAN / IPs; but do not have connectivity to the internet.&amp;nbsp;&lt;BR /&gt;My assumption is it's at the gateway? Also; I can ping an IP on the inside interface from the VLAN, but not the inside interface itself.&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;interface GigabitEthernet0/1&lt;BR /&gt;&amp;nbsp;speed 100&lt;BR /&gt;&amp;nbsp;duplex full&lt;BR /&gt;&amp;nbsp;nameif Inside&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.10.10.1 255.255.255.0&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/1.20&lt;BR /&gt;&amp;nbsp;vlan 20&lt;BR /&gt;&amp;nbsp;nameif IOS_DC&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address 10.10.2.1 255.255.255.0&amp;nbsp;&lt;BR /&gt;!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:29:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-not-connection-to-internet/m-p/2522464#M236468</guid>
      <dc:creator>IOS_support</dc:creator>
      <dc:date>2019-03-12T04:29:23Z</dc:date>
    </item>
    <item>
      <title>Hi, I am attaching a screen</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-not-connection-to-internet/m-p/2522465#M236469</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am attaching a screen shot which is config for sub interface generally implemented in the shown manner.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/sub_interface_0.png" class="migrated-markup-image" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anim Saxena&lt;/P&gt;&lt;P&gt;Community Manager (Security)&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2014 07:07:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-not-connection-to-internet/m-p/2522465#M236469</guid>
      <dc:creator>Anim Saxena</dc:creator>
      <dc:date>2014-07-18T07:07:14Z</dc:date>
    </item>
    <item>
      <title>Hi, I don think so your</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-not-connection-to-internet/m-p/2522466#M236470</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don think so your configuration has problems from interface perspective. But make sure that you have all the settings defined below.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) You switch has the VLAN 20 and you are trying to access internet from VLAN 20 connected machine.&lt;/P&gt;&lt;P&gt;2) Make sure that you have access-list binded to the subinterface in case if you have anything such.... say&lt;/P&gt;&lt;P&gt;access-list ios-dc permit tcp 0.10.2.0 255.255.255.0 any www&lt;/P&gt;&lt;P&gt;access-list ios-dc permit tcp 0.10.2.0 255.255.255.0 any https&lt;/P&gt;&lt;P&gt;access-list ios-dc permit udp 0.10.2.0 255.255.255.0 any domain&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-group ios-dc in interface IOS_DC&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;3) Make sure that NAT/PAT is configured for this...&lt;/P&gt;&lt;P&gt;nat (IOS_DC,Outside) dynamic interface -- In new version&lt;/P&gt;&lt;P&gt;if it is old version&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.10.2.0 255.255.255.0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Set your default gateway for VLAN 20 PC machine to 10.10.2.1... you should be able to reach that.... if it is trunked and connected to FW......&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If all this things are there... then you should be able to get to internet...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2014 07:35:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-not-connection-to-internet/m-p/2522466#M236470</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2014-07-18T07:35:30Z</dc:date>
    </item>
    <item>
      <title>Hi, The configuration seems</title>
      <link>https://community.cisco.com/t5/network-security/sub-interface-not-connection-to-internet/m-p/2522467#M236471</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The configuration seems kinda strange. I mean the fact that you have configured IP address under the actual physical interface but also configured subinterface for the physical interface. Typically when you configure a Trunk you leave the physical interface configurations blank other than set the duplex/speed and description configurations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How is the switchport connected to this ASA configured?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT: Just to add. I presume that if your &lt;STRONG&gt;"inside"&lt;/STRONG&gt; users are in Vlan 1 of the switched network then this is probably understandable that is works as the traffic comes to the ASA probably untagged.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you want&amp;nbsp; to test the ASA configurations then you can use the command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;packet-tracer input IOS_DC tcp 10.10.2.100 12345 8.8.8.8 80&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The above IPs are just chosen by me randomly. The output of the above command should show you what rules such a packet would match on the ASA. We could for example see if the traffic is even allowed and if its allowed does it have proper NAT configurations and so on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2014 07:35:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sub-interface-not-connection-to-internet/m-p/2522467#M236471</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-07-18T07:35:32Z</dc:date>
    </item>
  </channel>
</rss>

