<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VLAN internet access via ASA 5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441219#M238340</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;Hopefully there are some ASA experts out there! I have been having an issue getting internet access working on VLANs and am literally tearing my hair out!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;Ok, just a quick summary of my environment. We have a 3750X cisco switch trunked over to an ASA 5510.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;Internet access is fine for the inside network but having no joy whatsoever with additional vlans and internet access. My steps so far have been:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;Create a VLAN2 on the 3750X - 10.10.20.250&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;Create subinterface on the ASA with same security level as inside network - IP of subinterface is 10.10.20.2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;From VLAN2 I can ping the ASA subinterface IP and all of the inside network except the ASA inside IP address. Maybe this is my problem??&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;I have inserted NAT statements for VLAN2 internet traffic.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;The inbuilt packet tracer from VLAN2 to outside is showing as ok.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;What am I missing? I can post the switch and ASA configs if anyone would like to help me out. ASA license is base and firewall mode is routed.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;Thanks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;Neill&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 04:13:15 GMT</pubDate>
    <dc:creator>neillradford</dc:creator>
    <dc:date>2019-03-12T04:13:15Z</dc:date>
    <item>
      <title>VLAN internet access via ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441219#M238340</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;Hopefully there are some ASA experts out there! I have been having an issue getting internet access working on VLANs and am literally tearing my hair out!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;Ok, just a quick summary of my environment. We have a 3750X cisco switch trunked over to an ASA 5510.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;Internet access is fine for the inside network but having no joy whatsoever with additional vlans and internet access. My steps so far have been:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;Create a VLAN2 on the 3750X - 10.10.20.250&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;Create subinterface on the ASA with same security level as inside network - IP of subinterface is 10.10.20.2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;From VLAN2 I can ping the ASA subinterface IP and all of the inside network except the ASA inside IP address. Maybe this is my problem??&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;I have inserted NAT statements for VLAN2 internet traffic.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;The inbuilt packet tracer from VLAN2 to outside is showing as ok.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;What am I missing? I can post the switch and ASA configs if anyone would like to help me out. ASA license is base and firewall mode is routed.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;Thanks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: verdana,geneva,sans-serif;"&gt;Neill&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:13:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441219#M238340</guid>
      <dc:creator>neillradford</dc:creator>
      <dc:date>2019-03-12T04:13:15Z</dc:date>
    </item>
    <item>
      <title>The ASA config would help, as</title>
      <link>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441220#M238345</link>
      <description>&lt;P&gt;The ASA config would help, as would the running-config and "show interface" for the switch interface connecting to the ASA.&lt;/P&gt;&lt;P&gt;You didn't mention where the interface connecting the switch to the ASA is configured as a trunk - i.e. "switchport mode trunk"&lt;/P&gt;</description>
      <pubDate>Tue, 20 May 2014 22:01:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441220#M238345</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-20T22:01:05Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin Thanks for replying</title>
      <link>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441221#M238349</link>
      <description>&lt;P&gt;Hi Marvin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for replying. Didn't want to post the config in my initial post as it would have saturated the query!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;See below, I've stripped out stuff that isn't relevant like VPN's etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;3750X Config&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/1&lt;/P&gt;&lt;P&gt;&amp;nbsp;description ASA 5510&lt;/P&gt;&lt;P&gt;&amp;nbsp;switchport trunk encapsulation dot1q&lt;/P&gt;&lt;P&gt;&amp;nbsp;switchport trunk allowed vlan 1,2&lt;/P&gt;&lt;P&gt;&amp;nbsp;switchport mode trunk&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/2&lt;/P&gt;&lt;P&gt;&amp;nbsp;description SSM Module&lt;/P&gt;&lt;P&gt;&amp;nbsp;switchport trunk encapsulation dot1q&lt;/P&gt;&lt;P&gt;&amp;nbsp;switchport trunk allowed vlan 1,2&lt;/P&gt;&lt;P&gt;&amp;nbsp;switchport mode trunk&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address 192.168.3.250 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt;&amp;nbsp;description Testing&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address 10.10.20.250 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip helper-address 192.168.3.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan5&lt;/P&gt;&lt;P&gt;&amp;nbsp;description Voice Vlan&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address 10.10.10.250 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip helper-address 192.168.3.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip http secure-server&lt;/P&gt;&lt;P&gt;&lt;U&gt;!&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;ASA Config&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 9.1(3)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ……..ASA&lt;/P&gt;&lt;P&gt;domain-name ………&lt;/P&gt;&lt;P&gt;enable password QnKyFyFK6LWudLeM encrypted&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any4 any4&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any4 any6&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any6 any4&lt;/P&gt;&lt;P&gt;xlate per-session deny tcp any6 any6&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any4 any4 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any4 any6 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any6 any4 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session deny udp any6 any6 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session permit tcp any4 any4&lt;/P&gt;&lt;P&gt;xlate per-session permit tcp any4 any6&lt;/P&gt;&lt;P&gt;xlate per-session permit tcp any6 any4&lt;/P&gt;&lt;P&gt;xlate per-session permit tcp any6 any6&lt;/P&gt;&lt;P&gt;xlate per-session permit udp any4 any4 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session permit udp any4 any6 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session permit udp any6 any4 eq domain&lt;/P&gt;&lt;P&gt;xlate per-session permit udp any6 any6 eq domain&lt;/P&gt;&lt;P&gt;passwd gerd0WPZAcHKQ1jK encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;ip local pool remotes 11.1.1.1-11.1.1.10 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;&amp;nbsp;nameif outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;security-level 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address x.x.x.x 255.255.255.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;&amp;nbsp;nameif inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;security-level 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address 192.168.3.2 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;description Test VLAN&lt;/P&gt;&lt;P&gt;&amp;nbsp;vlan 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;nameif VLAN2&lt;/P&gt;&lt;P&gt;&amp;nbsp;security-level 100&lt;/P&gt;&lt;P&gt;&amp;nbsp;ip address 10.10.20.2 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa913-k8.bin&lt;/P&gt;&lt;P&gt;boot system disk0:/asa846-5-k8.bin&lt;/P&gt;&lt;P&gt;boot system disk0:/asa842-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone GMT/BST 0&lt;/P&gt;&lt;P&gt;clock summer-time GMT/BDT recurring last Sun Mar 1:00 last Sun Oct 2:00&lt;/P&gt;&lt;P&gt;dns domain-lookup outside&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt;&amp;nbsp;name-server 8.8.8.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;domain-name xxxxxxxxx&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object network NETWORK_OBJ_11.1.1.0_28&lt;/P&gt;&lt;P&gt;&amp;nbsp;subnet 11.1.1.0 255.255.255.240&lt;/P&gt;&lt;P&gt;object network inside_network&lt;/P&gt;&lt;P&gt;&amp;nbsp;subnet 192.168.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network NETWORK_OBJ_192.168.3.0_24&lt;/P&gt;&lt;P&gt;&amp;nbsp;subnet 192.168.3.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object network module&lt;/P&gt;&lt;P&gt;&amp;nbsp;host 192.168.3.8&lt;/P&gt;&lt;P&gt;object network vlantest&lt;/P&gt;&lt;P&gt;&amp;nbsp;host 10.10.20.250&lt;/P&gt;&lt;P&gt;object network vlan2&lt;/P&gt;&lt;P&gt;&amp;nbsp;range 10.10.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_2 tcp&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq 3388&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq 4550&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq 5511&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq 5550&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq 5552&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq 5553&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq 5611&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq 6550&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq 81&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq 8554&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq 8866&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_3 tcp&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq pop3&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq smtp&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq www&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_4 tcp&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq www&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq pop3&lt;/P&gt;&lt;P&gt;&amp;nbsp;port-object eq smtp&lt;/P&gt;&lt;P&gt;object-group protocol TCPUDP&lt;/P&gt;&lt;P&gt;&amp;nbsp;protocol-object udp&lt;/P&gt;&lt;P&gt;&amp;nbsp;protocol-object tcp&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object exchange eq smtp&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any object exchangeportal eq https&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any4 object x.x.x.x eq smtp&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any4 object x.x.x.x eq 6521&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any4 object x.x.x.x eq pptp&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any4 object x.x.x.x object-group DM_INLINE_TCP_2&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any4 object x.x.x.x&lt;/P&gt;&lt;P&gt;access-list ACL_VLAN2 extended permit ip 10.10.20.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list acl_inside extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list acl_inside extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list global_mpc extended permit tcp any any object-group DM_INLINE_TCP_3&lt;/P&gt;&lt;P&gt;access-list inside_mpc extended permit tcp 192.168.3.0 255.255.255.0 x.x.x.x 255.255.255.240 object-group DM_INLINE_TCP_4&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging monitor informational&lt;/P&gt;&lt;P&gt;logging buffered debugging&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging from-address ASAalerts@.........&lt;/P&gt;&lt;P&gt;logging recipient-address …………. level errors&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu VLAN2 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp permit any VLAN2&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-714.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;no arp permit-nonconnected&lt;/P&gt;&lt;P&gt;nat (inside,outside) source static inside_network inside_network destination static NETWORK_OBJ_11.1.1.0_28 NETWORK_OBJ_11.1.1.0_28 no-proxy-arp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network inside_network&lt;/P&gt;&lt;P&gt;&amp;nbsp;nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;object network exchange&lt;/P&gt;&lt;P&gt;&amp;nbsp;nat (inside,outside) static interface service tcp smtp smtp&lt;/P&gt;&lt;P&gt;object network exchangeportal&lt;/P&gt;&lt;P&gt;&amp;nbsp;nat (inside,outside) static interface service tcp https https&lt;/P&gt;&lt;P&gt;object network vlan2&lt;/P&gt;&lt;P&gt;&amp;nbsp;nat (VLAN2,outside) dynamic interface&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 x.x.x.x&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;http server enable 444&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;ntp server x.x.x.x source outside prefer&lt;/P&gt;&lt;P&gt;tftp-server inside 192.168.3..x ASA5510.cfg&lt;/P&gt;&lt;P&gt;ssl trust-point ASDM_TrustPoint0 inside&lt;/P&gt;&lt;P&gt;ssl trust-point ASDM_TrustPoint0 outside&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;&amp;nbsp;port 444&lt;/P&gt;&lt;P&gt;&amp;nbsp;enable outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;enable inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-win-2.5.2014-k9.pkg 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-macosx-i386-2.4.1012-k9.pkg 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-linux-2.4.1012-k9.pkg 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;anyconnect image disk0:/anyconnect-wince-ARMv4I-2.4.1012-k9.pkg 4&lt;/P&gt;&lt;P&gt;&amp;nbsp;anyconnect enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;tunnel-group-list enable&lt;/P&gt;&lt;P&gt;group-policy DfltGrpPolicy attributes&lt;/P&gt;&lt;P&gt;&amp;nbsp;dns-server value 8.8.8.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;vpn-tunnel-protocol ssl-clientless&lt;/P&gt;&lt;P&gt;&amp;nbsp;default-domain value ………&lt;/P&gt;&lt;P&gt;&amp;nbsp;wins-server none&lt;/P&gt;&lt;P&gt;&amp;nbsp;dns-server value 192.168.3.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 ikev2 l2tp-ipsec ssl-client&lt;/P&gt;&lt;P&gt;&amp;nbsp;default-domain value …..&lt;/P&gt;&lt;P&gt;&amp;nbsp;address-pools value remotes&lt;/P&gt;&lt;P&gt;&amp;nbsp;webvpn&lt;/P&gt;&lt;P&gt;group-policy GroupPolicy1 internal&lt;/P&gt;&lt;P&gt;group-policy remotes internal&lt;/P&gt;&lt;P&gt;group-policy remotes attributes&lt;/P&gt;&lt;P&gt;&amp;nbsp;dns-server value 192.168.3.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;vpn-tunnel-protocol ikev1 ikev2 l2tp-ipsec ssl-client&lt;/P&gt;&lt;P&gt;&amp;nbsp;default-domain value ……..&lt;/P&gt;&lt;P&gt;&amp;nbsp;address-pool remotes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map global-class&lt;/P&gt;&lt;P&gt;&amp;nbsp;match access-list global_mpc&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp;parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp;class global-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; csc fail-close&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;smtp-server 192.168.3.x&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;call-home&lt;/P&gt;&lt;P&gt;&amp;nbsp;profile CiscoTAC-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no active&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination address email callhome@cisco.com&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination transport-method http&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;/P&gt;&lt;P&gt;Cryptochecksum:1f5c2e807da97877abac7e15bb5a5143&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-714.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2014 18:08:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441221#M238349</guid>
      <dc:creator>neillradford</dc:creator>
      <dc:date>2014-05-21T18:08:40Z</dc:date>
    </item>
    <item>
      <title>Your:    object network vlan2</title>
      <link>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441222#M238351</link>
      <description>&lt;P&gt;Your:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; object network vlan2&lt;BR /&gt;&amp;nbsp; &amp;nbsp; range 10.10.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt;is mis-formed. Try instead:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; object network vlan2&lt;BR /&gt;&amp;nbsp; &amp;nbsp; subnet 10.10.20.0 255.255.255.0&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2014 18:08:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441222#M238351</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-21T18:08:41Z</dc:date>
    </item>
    <item>
      <title>Hopefully thats what it is! I</title>
      <link>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441223#M238355</link>
      <description>&lt;P&gt;Hopefully thats what it is! I'll give that a go tomorrow and let you know if that resolved.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Marvin&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2014 20:57:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441223#M238355</guid>
      <dc:creator>neillradford</dc:creator>
      <dc:date>2014-05-21T20:57:15Z</dc:date>
    </item>
    <item>
      <title>Hi Marvin,Still no internet</title>
      <link>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441224#M238358</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Hi Marvin,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Still no internet access with the object change from range to subnet.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma, geneva, sans-serif; font-size: 11px;"&gt;Should I be able to ping the inside interface IP of 192.168.3.2 from VLAN2? At the moment I can't but I can ping everything else on the 192.168.3.x subnet.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;See below for output from the show nat command:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Auto NAT Policies (Section 2)&lt;BR /&gt;1 (inside) to (outside) source static exchange interface &amp;nbsp; service tcp smtp smtp &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; translate_hits = 0, untranslate_hits = 538&lt;BR /&gt;2 (inside) to (outside) source static exchangeportal interface &amp;nbsp; service tcp htt &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ps https&lt;BR /&gt;&amp;nbsp; &amp;nbsp; translate_hits = 0, untranslate_hits = 7319&lt;BR /&gt;3 (VLAN2) to (outside) source dynamic vlan2 interface&lt;BR /&gt;&amp;nbsp; &amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;BR /&gt;4 (inside) to (outside) source dynamic inside_network interface&lt;BR /&gt;&amp;nbsp; &amp;nbsp; translate_hits = 617483, untranslate_hits = 24596&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Show below for output from packet tracer ( I get exactly the same when tracing from an IP on the inside network)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;packet-tracer input vlan2 tcp 10.10.20.51 http 8.8.8.8 http&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Phase: 1&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;MAC Access list&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in &amp;nbsp; 0.0.0.0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.0.0.0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; outside&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Phase: 3&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;object network vlan2&lt;BR /&gt;&amp;nbsp;nat (VLAN2,outside) dynamic interface&lt;BR /&gt;Additional Information:&lt;BR /&gt;Dynamic translate 10.10.20.51/80 to x.x.x.x /80&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Phase: 4&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Phase: 5&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Phase: 6&lt;BR /&gt;Type: SSM-DIVERT&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Phase: 7&lt;BR /&gt;Type: SSM_SERVICE&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Phase: 8&lt;BR /&gt;Type: SSM_SERVICE&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Phase: 9&lt;BR /&gt;Type: NAT&lt;BR /&gt;Subtype: per-session&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Phase: 10&lt;BR /&gt;Type: IP-OPTIONS&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Phase: 11&lt;BR /&gt;Type: FLOW-CREATION&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;New flow created with id 639142, packet dispatched to next module&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Result:&lt;BR /&gt;input-interface: VLAN2&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: allow&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11px;"&gt;&lt;SPAN style="font-family:tahoma,geneva,sans-serif;"&gt;Any other thoughts on where I'm going wrong?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2014 21:26:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441224#M238358</guid>
      <dc:creator>neillradford</dc:creator>
      <dc:date>2014-05-22T21:26:49Z</dc:date>
    </item>
    <item>
      <title>From what host on VLAN 2 are</title>
      <link>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441225#M238360</link>
      <description>&lt;P&gt;From what host on VLAN 2 are you initiating the pings? Does that host have your ASA VLAN 2 interface set as the gateway?&lt;/P&gt;&lt;P&gt;I ask because your "show nat" output indicates no translate hits for traffic coming from VLAN 2:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-family: tahoma, geneva, sans-serif; font-size: 11px; background-color: rgb(247, 247, 247);"&gt;3 (VLAN2) to (outside) source dynamic vlan2 interface&lt;/SPAN&gt;&lt;BR style="color: rgb(119, 119, 119); font-family: tahoma, geneva, sans-serif; font-size: 11px; background-color: rgb(247, 247, 247);" /&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-family: tahoma, geneva, sans-serif; font-size: 11px; background-color: rgb(247, 247, 247);"&gt;&amp;nbsp; &amp;nbsp; translate_hits = 0, untranslate_hits = 0&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2014 22:06:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441225#M238360</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-22T22:06:57Z</dc:date>
    </item>
    <item>
      <title>The pings are initiated from</title>
      <link>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441226#M238364</link>
      <description>&lt;P&gt;The pings are initiated from a PC that has obtained an IP from the DHCP server.&lt;/P&gt;&lt;P&gt;The DHCP scope router for VLAN2 is configured as 10.10.20.250 which is the same gateway defined on the 3750 switch.&lt;/P&gt;&lt;P&gt;Should the DHCP scope router IP match the ASA sub interface IP of 10.10.20.2?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2014 22:06:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441226#M238364</guid>
      <dc:creator>neillradford</dc:creator>
      <dc:date>2014-05-22T22:06:58Z</dc:date>
    </item>
    <item>
      <title>Problem sorted! The issue was</title>
      <link>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441227#M238365</link>
      <description>&lt;P&gt;Problem sorted! The issue was with the router IP of the DHCP scope. One the gateway was changed to the sub interface VLAN2 IP address it worked.&lt;/P&gt;&lt;P&gt;Marvin - thanks for taking the time to read the config and give advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 May 2014 20:20:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441227#M238365</guid>
      <dc:creator>neillradford</dc:creator>
      <dc:date>2014-05-23T20:20:15Z</dc:date>
    </item>
    <item>
      <title>You're welcome.Glad to see my</title>
      <link>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441228#M238367</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;&lt;P&gt;Glad to see my analysis was correct. Thanks for the rating.&lt;/P&gt;</description>
      <pubDate>Fri, 23 May 2014 21:53:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vlan-internet-access-via-asa-5510/m-p/2441228#M238367</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-23T21:53:22Z</dc:date>
    </item>
  </channel>
</rss>

