<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clients behind ASA 5505 cannot connect to internet in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359666#M308268</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could you add on the 2811:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 15.0.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also, kindly post &lt;STRONG&gt;show version&lt;/STRONG&gt; and &lt;STRONG&gt;show route&lt;/STRONG&gt; from the 5505.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Nov 2013 06:34:22 GMT</pubDate>
    <dc:creator>johnlloyd_13</dc:creator>
    <dc:date>2013-11-26T06:34:22Z</dc:date>
    <item>
      <title>Clients behind ASA 5505 cannot connect to internet</title>
      <link>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359665#M308267</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configure Router 2811 behind ASA 5505, ASA outside&amp;nbsp; interface can got ip address from ISP but clients in inside interface&amp;nbsp; cannot connect to internet, anyone can help me ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my network diagram :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet --- &amp;gt; (Outside)&amp;nbsp; ASA 5505&amp;nbsp;&amp;nbsp; (Inside)&amp;nbsp; ---&amp;gt;&amp;nbsp; R2811&amp;nbsp; --&amp;gt; Sw2950&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internet --- &amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ASA 5505&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; R2811&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --&amp;gt;&amp;nbsp; Sw2950&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------------&amp;nbsp; ----&lt;BR /&gt;&lt;STRONG&gt;ASA Configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.4(7)&lt;BR /&gt;!&lt;BR /&gt;hostname ciscoasa&lt;BR /&gt;domain-name bvn.local&lt;BR /&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;BR /&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt; switchport access vlan 3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt; switchport access vlan 12&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; nameif Management&lt;BR /&gt; security-level 100&lt;BR /&gt;ip address ..&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; pppoe client vpdn group DIALER-GROUP&lt;BR /&gt; ip address pppoe setroute&lt;BR /&gt;!&lt;BR /&gt;interface Vlan3&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 15.0.0.1 255.0.0.0&lt;BR /&gt;!&lt;BR /&gt;interface Vlan12&lt;BR /&gt; nameif DMZ&lt;BR /&gt; security-level 50&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa847-k8.bin&lt;BR /&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dns domain-lookup outside&lt;BR /&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;dns server-group DefaultDNS&lt;BR /&gt; name-server 8.8.8.8&lt;BR /&gt; name-server 8.8.4.4&lt;BR /&gt; domain-name bvn.local&lt;BR /&gt;&lt;BR /&gt;object network obj-network-R2811&lt;BR /&gt; host 15.0.0.2&lt;BR /&gt;&lt;BR /&gt;object network obj-Inside-Network&lt;BR /&gt; subnet 15.0.0.0 255.0.0.0&lt;BR /&gt;&lt;BR /&gt;object-group service obj-service-R2811&lt;BR /&gt; description "Services for Cisco R2811"&lt;BR /&gt; service-object tcp source range 55554 55559&lt;BR /&gt; service-object tcp source eq 3366&lt;BR /&gt;&lt;BR /&gt;access-list ACL-OUTSIDE-TO-INSIDE extended permit object-group obj-service-R2811 any object obj-network-R2811&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pager lines 24&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu Management 1500&lt;BR /&gt;mtu outside 1492&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu DMZ 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-714.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;!&lt;BR /&gt;&lt;STRONG&gt;object network obj-Inside-Network&lt;BR /&gt; nat (inside,outside) dynamic interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication enable console LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;http server enable&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh 192.168.10.0 255.255.255.0 Management&lt;BR /&gt;ssh timeout 60&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;console timeout 0&lt;BR /&gt;vpdn group DIALER-GROUP request dialout pppoe&lt;BR /&gt;vpdn group DIALER-GROUP localname xxxxxxxxxxxx&lt;BR /&gt;vpdn group DIALER-GROUP ppp authentication pap&lt;BR /&gt;vpdn username xxxxxxxxxx password ***** store-local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;tls-proxy maximum-session 24&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;webvpn&lt;BR /&gt; anyconnect-essentials&lt;BR /&gt;username admin password J.TJIa8ig6Y7fCBj encrypted privilege 15&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt; message-length maximum client auto&lt;BR /&gt; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt; inspect dns preset_dns_map&lt;BR /&gt; inspect ftp&lt;BR /&gt; inspect h323 h225&lt;BR /&gt; inspect h323 ras&lt;BR /&gt; inspect rsh&lt;BR /&gt; inspect rtsp&lt;BR /&gt; inspect esmtp&lt;BR /&gt; inspect sqlnet&lt;BR /&gt; inspect skinny&lt;BR /&gt; inspect sunrpc&lt;BR /&gt; inspect xdmcp&lt;BR /&gt; inspect sip&lt;BR /&gt; inspect netbios&lt;BR /&gt; inspect tftp&lt;BR /&gt; inspect ip-options&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;Cryptochecksum:1f99c5818d8fbc47e40068c4568fa911&lt;BR /&gt;: end&lt;BR /&gt;ciscoasa#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;R2811 Configuration&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R2811#show run&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 9145 bytes&lt;BR /&gt;!&lt;BR /&gt;! Last configuration change at 10:35:58 gmt Tue Nov 26 2013 by admin&lt;BR /&gt;! NVRAM config last updated at 09:50:24 gmt Tue Nov 26 2013 by admin&lt;BR /&gt;!&lt;BR /&gt;version 12.4&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;no service password-encryption&lt;BR /&gt;service sequence-numbers&lt;BR /&gt;!&lt;BR /&gt;hostname R2811&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot system flash:/c2800nm-advipservicesk9-mz.124-15.T17.bin&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;logging buffered 4096&lt;BR /&gt;no logging console&lt;BR /&gt;no logging monitor&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default group radius local&lt;BR /&gt;aaa authorization exec default group radius local if-authenticated&lt;BR /&gt;aaa authorization network default group radius local if-authenticated&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;clock timezone gmt 7&lt;BR /&gt;dot11 syslog&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip cef&lt;BR /&gt;ip dhcp database flash:/dhcp_binding write-delay 60 timeout 10&lt;BR /&gt;&lt;SPAN&gt;ip dhcp database t&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://192.168.30.200/dhcp_binding" target="_blank"&gt;ftp://192.168.30.200/dhcp_binding&lt;/A&gt;&lt;SPAN&gt; write-delay 60 timeout 10&lt;/SPAN&gt;&lt;BR /&gt;no ip dhcp use vrf connected&lt;BR /&gt;ip dhcp excluded-address 192.168.10.200 192.168.10.254&lt;BR /&gt;ip dhcp excluded-address 192.168.20.200 192.168.20.254&lt;BR /&gt;ip dhcp excluded-address 192.168.30.200 192.168.30.254&lt;BR /&gt;ip dhcp excluded-address 192.168.20.1 192.168.20.10&lt;BR /&gt;ip dhcp excluded-address 192.168.10.1 192.168.10.100&lt;BR /&gt;ip dhcp excluded-address 192.168.30.1 192.168.30.100&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool VLAN30&lt;BR /&gt; network 192.168.30.0 255.255.255.0&lt;BR /&gt; default-router 192.168.30.1&lt;BR /&gt; dns-server 8.8.8.8&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool default&lt;BR /&gt; network 192.168.10.0 255.255.255.0&lt;BR /&gt; default-router 192.168.10.1&lt;BR /&gt; dns-server 8.8.8.8&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool VLAN20&lt;BR /&gt; network 192.168.20.0 255.255.255.0&lt;BR /&gt; default-router 192.168.20.1&lt;BR /&gt; dns-server 8.8.8.8&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool VLAN50&lt;BR /&gt; network 192.168.50.0 255.255.255.0&lt;BR /&gt; default-router 192.168.50.1&lt;BR /&gt; dns-server 8.8.8.8&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip domain name bvn.local&lt;BR /&gt;&lt;STRONG&gt;ip name-server 8.8.8.8&lt;/STRONG&gt;&lt;BR /&gt;!&lt;BR /&gt;multilink bundle-name authenticated&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki trustpoint my-trustpoint&lt;BR /&gt; enrollment selfsigned&lt;BR /&gt; subject-name O=IT,CN=&lt;A href="http://www.bvn.local" target="_blank"&gt;www.bvn.local&lt;/A&gt;&lt;BR /&gt; revocation-check crl&lt;BR /&gt; rsakeypair my-rsa-keys&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki certificate chain my-trustpoint&lt;BR /&gt; certificate self-signed 02&lt;BR /&gt; 3082026F 308201D8 A0030201 02020102 300D0609 2A864886 F70D0101 04050030&lt;BR /&gt; 45311630 14060355 0403130D 7777772E 62766E2E 6C6F6361 6C310B30 09060355&lt;BR /&gt; 040A1302 4954311E 301C0609 2A864886 F70D0109 02160F52 32383131 2E62766E&lt;BR /&gt; 2E6C6F63 616C301E 170D3133 31313137 30343535 34345A17 0D323030 31303130&lt;BR /&gt; 30303030 305A3045 31163014 06035504 03130D77 77772E62 766E2E6C 6F63616C&lt;BR /&gt; 310B3009 06035504 0A130249 54311E30 1C06092A 864886F7 0D010902 160F5232&lt;BR /&gt; 3831312E 62766E2E 6C6F6361 6C30819F 300D0609 2A864886 F70D0101 01050003&lt;BR /&gt; 818D0030 81890281 81008C50 B07554E2 256C1E2D F4DBA9B1 45CCE4CD 7A469780&lt;BR /&gt; A4A50706 50A24300 CD1CA5A7 B9388ACD AE9A1D66 1EA5FEA6 A26E48DC 7D06E733&lt;BR /&gt; E554146D 64E22EB5 30750CEB 67C0286A 12FBEFE5 BEF2BEBC E6849354 C31AF749&lt;BR /&gt; 729BFA77 F081A88E E2420DC9 0BB0E827 CF6B885C 6DA8BEB8 002BBE30 76E134FB&lt;BR /&gt; BB5DADA7 455687AE 4B4F0203 010001A3 6F306D30 0F060355 1D130101 FF040530&lt;BR /&gt; 030101FF 301A0603 551D1104 13301182 0F523238 31312E62 766E2E6C 6F63616C&lt;BR /&gt; 301F0603 551D2304 18301680 14ECF478 D7A73A3C 3DB4A58F 072FD138 72A95737&lt;BR /&gt; 9F301D06 03551D0E 04160414 ECF478D7 A73A3C3D B4A58F07 2FD13872 A957379F&lt;BR /&gt; 300D0609 2A864886 F70D0101 04050003 8181002B 810C5936 F1C79ABE F58C6ACE&lt;BR /&gt; 5CA04136 AF768927 CB2DC3F8 CBFA1A68 87054270 3557400C 47B0BB99 42A98A57&lt;BR /&gt; 43202C33 89E06619 F527CDD4 029AA76B A8631AE7 65059A62 BDD1289D C1B83FFD&lt;BR /&gt; 02432B90 E5671FBB ABE3F5E1 39D4B707 D8580226 E6C60148 2D22A5C4 40FA7809&lt;BR /&gt; 151D66D3 497CE907 E62FA8CC A59A2645 D3D7CD&lt;BR /&gt; quit&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;archive&lt;BR /&gt; log config&lt;BR /&gt; hidekeys&lt;BR /&gt;&lt;SPAN&gt; path t&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://192.168.30.200/CiscoArchive" target="_blank"&gt;ftp://192.168.30.200/CiscoArchive&lt;/A&gt;&lt;BR /&gt; write-memory&lt;BR /&gt; time-period 1440&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip ftp username abc&lt;BR /&gt;ip ftp password 123&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface Loopback1&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/0&lt;BR /&gt; description CONNECT to ASA&lt;BR /&gt; ip address 15.0.0.2 255.0.0.0&lt;BR /&gt; ip nat outside&lt;BR /&gt; ip virtual-reassembly&lt;BR /&gt; duplex full&lt;BR /&gt; speed auto&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1&lt;BR /&gt; description LAN&lt;BR /&gt; no ip address&lt;BR /&gt; duplex full&lt;BR /&gt; speed auto&lt;BR /&gt; no cdp enable&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1.1&lt;BR /&gt; description DEFAULT&lt;BR /&gt; encapsulation dot1Q 1 native&lt;BR /&gt; ip address 192.168.10.1 255.255.255.0&lt;BR /&gt; ip nat inside&lt;BR /&gt; ip virtual-reassembly&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1.2&lt;BR /&gt; description FINANCE_DEPT&lt;BR /&gt; encapsulation dot1Q 20&lt;BR /&gt; ip address 192.168.20.1 255.255.255.0&lt;BR /&gt; ip nat inside&lt;BR /&gt; ip virtual-reassembly&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1.3&lt;BR /&gt; description IT_DEPT&lt;BR /&gt; encapsulation dot1Q 30&lt;BR /&gt; ip address 192.168.30.1 255.255.255.0&lt;BR /&gt; ip helper-address 192.168.10.10&lt;BR /&gt; ip nat inside&lt;BR /&gt; ip virtual-reassembly&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1.4&lt;BR /&gt; description HR_DEPT&lt;BR /&gt; encapsulation dot1Q 40&lt;BR /&gt; ip address 192.168.40.1 255.255.255.0&lt;BR /&gt; ip helper-address 192.168.10.10&lt;BR /&gt; ip nat inside&lt;BR /&gt; ip virtual-reassembly&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0/1.5&lt;BR /&gt; encapsulation dot1Q 50&lt;BR /&gt; ip address 192.168.50.1 255.255.255.0&lt;BR /&gt; ip access-group 101 in&lt;BR /&gt; ip nat inside&lt;BR /&gt; ip virtual-reassembly&lt;BR /&gt;!&lt;BR /&gt;interface Dialer0&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip forward-protocol nd&lt;BR /&gt;no ip forward-protocol udp tftp&lt;BR /&gt;no ip forward-protocol udp netbios-ns&lt;BR /&gt;no ip forward-protocol udp netbios-dgm&lt;BR /&gt;no ip forward-protocol udp tacacs&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip http server&lt;BR /&gt;ip http authentication local&lt;BR /&gt;ip http secure-server&lt;BR /&gt;ip nat inside source static tcp 192.168.20.254 3366 interface&amp;nbsp; FastEthernet0/0&amp;nbsp; 3366&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip nat inside source list 101 interface FastEthernet0/0 overload&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging facility local6&lt;BR /&gt;logging 192.168.30.200&lt;BR /&gt;access-list 101 permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;radius-server host 192.168.10.11 auth-port 1645 acct-port 1646&lt;BR /&gt;radius-server key 123456&lt;BR /&gt;!&lt;BR /&gt;control-plane&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;banner exec ^C&lt;BR /&gt;Session established to $(hostname) on line $(line)^C&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt; exec-timeout 0 0&lt;BR /&gt;line aux 0&lt;BR /&gt;line vty 0 4&lt;BR /&gt; access-class abc in&lt;BR /&gt; exec-timeout 0 0&lt;BR /&gt; privilege level 15&lt;BR /&gt; logging synchronous&lt;BR /&gt; transport input telnet ssh&lt;BR /&gt;line vty 5 15&lt;BR /&gt; access-class abc in&lt;BR /&gt; exec-timeout 0 0&lt;BR /&gt; logging synchronous&lt;BR /&gt; transport input telnet ssh&lt;BR /&gt;!&lt;BR /&gt;no scheduler allocate&lt;BR /&gt;ntp clock-period 17180068&lt;BR /&gt;ntp update-calendar&lt;BR /&gt;ntp server 14.0.18.136&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R2811#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------------&amp;nbsp; ----&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:09:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359665#M308267</guid>
      <dc:creator>bvn63</dc:creator>
      <dc:date>2019-03-12T03:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: Clients behind ASA 5505 cannot connect to internet</title>
      <link>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359666#M308268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could you add on the 2811:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 15.0.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also, kindly post &lt;STRONG&gt;show version&lt;/STRONG&gt; and &lt;STRONG&gt;show route&lt;/STRONG&gt; from the 5505.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Nov 2013 06:34:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359666#M308268</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2013-11-26T06:34:22Z</dc:date>
    </item>
    <item>
      <title>Clients behind ASA 5505 cannot connect to internet</title>
      <link>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359667#M308269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi johnlloyd,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank for your replying.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I put route command (ip route 0.0.0.0 0.0.0.0 15.0.0.1) on R2811 but clients can't connect to internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my ASA information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ciscoasa# show route&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * - candidate default, U - per-user static route, o - ODR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; P - periodic downloaded static route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway of last resort is 123.28.28.1 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 15.0.0.0 255.0.0.0 is directly connected, inside&lt;/P&gt;&lt;P&gt;S*&amp;nbsp;&amp;nbsp; 0.0.0.0 0.0.0.0 [1/0] via 123.20.27.1, outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ciscoasa# show ver&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 8.4(7) &lt;/P&gt;&lt;P&gt;Device Manager Version 7.1(4)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Compiled on Fri 30-Aug-13 19:48 by builders&lt;/P&gt;&lt;P&gt;System image file is "disk0:/asa847-k8.bin"&lt;/P&gt;&lt;P&gt;Config file at boot was "startup-config"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa up 22 hours 52 mins&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hardware:&amp;nbsp;&amp;nbsp; ASA5505, 512 MB RAM, CPU Geode 500 MHz&lt;/P&gt;&lt;P&gt;Internal ATA Compact Flash, 128MB&lt;/P&gt;&lt;P&gt;BIOS Flash M50FW016 @ 0xfff00000, 2048KB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Encryption hardware device : Cisco ASA-5505 on-board accelerator (revision 0x0)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Boot microcode&amp;nbsp;&amp;nbsp; : CN1000-MC-BOOT-2.00 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSL/IKE microcode: CNLite-MC-SSLm-PLUS-2.03&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IPSec microcode&amp;nbsp; : CNlite-MC-IPSECm-MAIN-2.06&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of accelerators: 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 0: Int: Internal-Data0/0&amp;nbsp;&amp;nbsp;&amp;nbsp; : address is 2894.0f0f.34de, irq 11&lt;/P&gt;&lt;P&gt; 1: Ext: Ethernet0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : address is 2894.0f0f.34d6, irq 255&lt;/P&gt;&lt;P&gt; 2: Ext: Ethernet0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : address is 2894.0f0f.34d7, irq 255&lt;/P&gt;&lt;P&gt; 3: Ext: Ethernet0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : address is 2894.0f0f.34d8, irq 255&lt;/P&gt;&lt;P&gt; 4: Ext: Ethernet0/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : address is 2894.0f0f.34d9, irq 255&lt;/P&gt;&lt;P&gt; 5: Ext: Ethernet0/4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : address is 2894.0f0f.34da, irq 255&lt;/P&gt;&lt;P&gt; 6: Ext: Ethernet0/5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : address is 2894.0f0f.34db, irq 255&lt;/P&gt;&lt;P&gt; 7: Ext: Ethernet0/6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : address is 2894.0f0f.34dc, irq 255&lt;/P&gt;&lt;P&gt; 8: Ext: Ethernet0/7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : address is 2894.0f0f.34dd, irq 255&lt;/P&gt;&lt;P&gt; 9: Int: Internal-Data0/1&amp;nbsp;&amp;nbsp;&amp;nbsp; : address is 0000.0003.0002, irq 255&lt;/P&gt;&lt;P&gt;10: Int: Not used&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : irq 255&lt;/P&gt;&lt;P&gt;11: Int: Not used&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : irq 255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Licensed features for this platform:&lt;/P&gt;&lt;P&gt;Maximum Physical Interfaces&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 8&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;VLANs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DMZ Unrestricted&lt;/P&gt;&lt;P&gt;Dual ISPs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;VLAN Trunk Ports&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 8&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;Inside Hosts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Unlimited&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;Failover&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Active/Standby perpetual&lt;/P&gt;&lt;P&gt;VPN-DES&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;VPN-3DES-AES&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;AnyConnect Premium Peers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;AnyConnect Essentials&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 25&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;Other VPN Peers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 25&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;Total VPN Peers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 25&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;Shared License&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;AnyConnect for Mobile&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;AnyConnect for Cisco VPN Phone&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;Advanced Endpoint Assessment&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;UC Phone Proxy Sessions&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;Total UC Proxy Sessions&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;Botnet Traffic Filter&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Enabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;Intercompany Media Engine&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : Disabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; perpetual&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This platform has an ASA 5505 Security Plus license.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- After I changing network-group service and put access-list into interface vlan2 as follows :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group service obj-service-R2811&lt;/P&gt;&lt;P&gt; description "Services for Cisco R2811"&lt;/P&gt;&lt;P&gt; service-object tcp source eq 3389 &lt;/P&gt;&lt;P&gt; service-object tcp source eq 3366 &lt;/P&gt;&lt;P&gt; service-object tcp source eq 3377 &lt;/P&gt;&lt;P&gt; service-object tcp source eq 3399 &lt;/P&gt;&lt;P&gt; service-object tcp source eq 51413 &lt;/P&gt;&lt;P&gt; service-object tcp source range 55554 55559 &lt;/P&gt;&lt;P&gt; service-object tcp source eq 8080 &lt;/P&gt;&lt;P&gt; service-object icmp &lt;/P&gt;&lt;P&gt; service-object tcp source eq domain &lt;/P&gt;&lt;P&gt; service-object udp source eq domain &lt;/P&gt;&lt;P&gt; service-object tcp source eq www &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ACL-OUTSIDE-TO-INSIDE extended permit object-group obj-service-R2811 any object obj-network-R2811 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 2&lt;/P&gt;&lt;P&gt; access-group ACL-OUTSIDE-TO-INSIDE in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- on R2811 can ping to any domain and ip address but clients can only ping to 8.8.8.8 and can't web page access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Nov 2013 08:14:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359667#M308269</guid>
      <dc:creator>bvn63</dc:creator>
      <dc:date>2013-11-26T08:14:32Z</dc:date>
    </item>
    <item>
      <title>Clients behind ASA 5505 cannot connect to internet</title>
      <link>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359668#M308270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there a reason you are doing NAT at the router and at the firewall?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Nov 2013 10:10:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359668#M308270</guid>
      <dc:creator>rfalconer.sffcu</dc:creator>
      <dc:date>2013-11-26T10:10:28Z</dc:date>
    </item>
    <item>
      <title>Clients behind ASA 5505 cannot connect to internet</title>
      <link>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359669#M308271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check logs on the ASA and see if the connection from your client is getting to the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Nov 2013 14:52:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359669#M308271</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-26T14:52:50Z</dc:date>
    </item>
    <item>
      <title>Clients behind ASA 5505 cannot connect to internet</title>
      <link>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359670#M308272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Why you are NATing in Router and then firewall. In router you can add one default route to firewall and from firewall you add return Route to router interface for all the INSIDE network Subnets.&lt;/P&gt;&lt;P&gt;Then in firewall Create one object group and add all the inside subnets and do NAT for that group and try.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Nov 2013 18:35:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359670#M308272</guid>
      <dc:creator>SHIBI V DEV</dc:creator>
      <dc:date>2013-11-26T18:35:47Z</dc:date>
    </item>
    <item>
      <title>Clients behind ASA 5505 cannot connect to internet</title>
      <link>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359671#M308273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you check logs as indicated????&lt;SPAN __jive_emoticon_name="plain" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Value our effort and rate the assistance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Nov 2013 04:30:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359671#M308273</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-11-27T04:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: Clients behind ASA 5505 cannot connect to internet</title>
      <link>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359672#M308274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good day,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;SPAN class="active_link"&gt;johnlloyd&lt;/SPAN&gt;, Robert, Shibi, jumora.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As SHIBI's suggest, I have configured route on router R2811 and ASA, It's working now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here my configuration after I changing route command on R2811 and ASA 5505&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;R2811&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname R2811&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot system flash:/c2800nm-advipservicesk9-mz.124-15.T17.bin&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;logging buffered 4096&lt;/P&gt;&lt;P&gt;no logging console&lt;/P&gt;&lt;P&gt;no logging monitor&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group radius local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group radius local if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization network default group radius local if-authenticated &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;clock timezone gmt 7&lt;/P&gt;&lt;P&gt;dot11 syslog&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip cef&lt;/P&gt;&lt;P&gt;ip dhcp database flash:/dhcp_binding write-delay 60 timeout 10&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ip dhcp database t&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://192.168.30.200/dhcp_binding" rel="nofollow"&gt;ftp://192.168.30.200/dhcp_binding&lt;/A&gt;&lt;SPAN&gt; write-delay 60 timeout 10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;no ip dhcp use vrf connected&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.10.200 192.168.10.254&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.20.200 192.168.20.254&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.30.200 192.168.30.254&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.20.1 192.168.20.10&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.10.1 192.168.10.100&lt;/P&gt;&lt;P&gt;ip dhcp excluded-address 192.168.30.1 192.168.30.100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool VLAN30&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; network 192.168.30.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; default-router 192.168.30.1 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; dns-server 8.8.8.8 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; network 192.168.10.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; default-router 192.168.10.1 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; dns-server 8.8.8.8 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool VLAN20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; network 192.168.20.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; default-router 192.168.20.1 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; dns-server 8.8.8.8 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip dhcp pool VLAN50&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; network 192.168.50.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; default-router 192.168.50.1 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; dns-server 8.8.8.8 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip domain name bvn.local&lt;/P&gt;&lt;P&gt;ip name-server 8.8.8.8&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;multilink bundle-name authenticated&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto pki trustpoint my-trustpoint&lt;/P&gt;&lt;P&gt; enrollment selfsigned&lt;/P&gt;&lt;P&gt; subject-name O=IT,CN=www.bvn.local&lt;/P&gt;&lt;P&gt; revocation-check crl&lt;/P&gt;&lt;P&gt; rsakeypair my-rsa-keys&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto pki certificate chain my-trustpoint&lt;/P&gt;&lt;P&gt; certificate self-signed 02&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3082026F 308201D8 A0030201 02020102 300D0609 2A864886 F70D0101 04050030 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 45311630 14060355 0403130D 7777772E 62766E2E 6C6F6361 6C310B30 09060355 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 040A1302 4954311E 301C0609 2A864886 F70D0109 02160F52 32383131 2E62766E &lt;/P&gt;&lt;P&gt;&amp;nbsp; 2E6C6F63 616C301E 170D3133 31313137 30343535 34345A17 0D323030 31303130 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 30303030 305A3045 31163014 06035504 03130D77 77772E62 766E2E6C 6F63616C &lt;/P&gt;&lt;P&gt;&amp;nbsp; 310B3009 06035504 0A130249 54311E30 1C06092A 864886F7 0D010902 160F5232 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 3831312E 62766E2E 6C6F6361 6C30819F 300D0609 2A864886 F70D0101 01050003 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 818D0030 81890281 81008C50 B07554E2 256C1E2D F4DBA9B1 45CCE4CD 7A469780 &lt;/P&gt;&lt;P&gt;&amp;nbsp; A4A50706 50A24300 CD1CA5A7 B9388ACD AE9A1D66 1EA5FEA6 A26E48DC 7D06E733 &lt;/P&gt;&lt;P&gt;&amp;nbsp; E554146D 64E22EB5 30750CEB 67C0286A 12FBEFE5 BEF2BEBC E6849354 C31AF749 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 729BFA77 F081A88E E2420DC9 0BB0E827 CF6B885C 6DA8BEB8 002BBE30 76E134FB &lt;/P&gt;&lt;P&gt;&amp;nbsp; BB5DADA7 455687AE 4B4F0203 010001A3 6F306D30 0F060355 1D130101 FF040530 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 030101FF 301A0603 551D1104 13301182 0F523238 31312E62 766E2E6C 6F63616C &lt;/P&gt;&lt;P&gt;&amp;nbsp; 301F0603 551D2304 18301680 14ECF478 D7A73A3C 3DB4A58F 072FD138 72A95737 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 9F301D06 03551D0E 04160414 ECF478D7 A73A3C3D B4A58F07 2FD13872 A957379F &lt;/P&gt;&lt;P&gt;&amp;nbsp; 300D0609 2A864886 F70D0101 04050003 8181002B 810C5936 F1C79ABE F58C6ACE &lt;/P&gt;&lt;P&gt;&amp;nbsp; 5CA04136 AF768927 CB2DC3F8 CBFA1A68 87054270 3557400C 47B0BB99 42A98A57 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 43202C33 89E06619 F527CDD4 029AA76B A8631AE7 65059A62 BDD1289D C1B83FFD &lt;/P&gt;&lt;P&gt;&amp;nbsp; 02432B90 E5671FBB ABE3F5E1 39D4B707 D8580226 E6C60148 2D22A5C4 40FA7809 &lt;/P&gt;&lt;P&gt;&amp;nbsp; 151D66D3 497CE907 E62FA8CC A59A2645 D3D7CD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; quit&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Loopback1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; description CONNECT to ASA&lt;/P&gt;&lt;P&gt; ip address 15.0.0.2 255.0.0.0&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt; description LAN&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1.1&lt;/P&gt;&lt;P&gt; description DEFAULT&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 1 native&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1.2&lt;/P&gt;&lt;P&gt; description FINANCE_DEPT&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 20&lt;/P&gt;&lt;P&gt; ip address 192.168.20.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1.3&lt;/P&gt;&lt;P&gt; description IT_DEPT&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 30&lt;/P&gt;&lt;P&gt; ip address 192.168.30.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1.4&lt;/P&gt;&lt;P&gt; description HR_DEPT&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 40&lt;/P&gt;&lt;P&gt; ip address 192.168.40.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1.5&lt;/P&gt;&lt;P&gt; encapsulation dot1Q 50&lt;/P&gt;&lt;P&gt; ip address 192.168.50.1 255.255.255.0&lt;/P&gt;&lt;P&gt; ip virtual-reassembly&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip forward-protocol nd&lt;/P&gt;&lt;P&gt;no ip forward-protocol udp tftp&lt;/P&gt;&lt;P&gt;no ip forward-protocol udp netbios-ns&lt;/P&gt;&lt;P&gt;no ip forward-protocol udp netbios-dgm&lt;/P&gt;&lt;P&gt;no ip forward-protocol udp tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip route 0.0.0.0 0.0.0.0 15.0.0.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip http authentication local&lt;/P&gt;&lt;P&gt;ip http secure-server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;=================================&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.4(7) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;domain-name bvn.local&lt;/P&gt;&lt;P&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; switchport access vlan 3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt; switchport access vlan 12&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif Management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; pppoe client vpdn group DIALER-GROUP&lt;/P&gt;&lt;P&gt; ip address pppoe setroute &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan3&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 15.0.0.1 255.0.0.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan12&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa847-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 8.8.8.8&lt;/P&gt;&lt;P&gt; name-server 8.8.4.4&lt;/P&gt;&lt;P&gt; domain-name bvn.local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network obj-Inside-Network&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; subnet 192.168.0.0 255.255.0.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu Management 1500&lt;/P&gt;&lt;P&gt;mtu outside 1492&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu test 1500 &lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-714.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;no arp permit-nonconnected&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;object network obj-Inside-Network&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; nat (inside,outside) dynamic interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route inside 192.168.0.0 255.255.0.0 15.0.0.2 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication enable console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 60&lt;/P&gt;&lt;P&gt;ssh version 2&lt;/P&gt;&lt;P&gt;ssh key-exchange group dh-group1-sha1&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;vpdn group DIALER-GROUP request dialout pppoe&lt;/P&gt;&lt;P&gt;vpdn group DIALER-GROUP localname xxxxx&lt;/P&gt;&lt;P&gt;vpdn group DIALER-GROUP ppp authentication pap&lt;/P&gt;&lt;P&gt;vpdn username xxxxx password ***** store-local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tls-proxy maximum-session 24&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;webvpn&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt; anyconnect-essentials&lt;/P&gt;&lt;P&gt;username admin password J.TJIa8ig6Y7fCBj encrypted privilege 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;Cryptochecksum:7473f9d7099ca0380fac148a144c7030&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Nov 2013 05:15:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/clients-behind-asa-5505-cannot-connect-to-internet/m-p/2359672#M308274</guid>
      <dc:creator>bvn63</dc:creator>
      <dc:date>2013-11-27T05:15:21Z</dc:date>
    </item>
  </channel>
</rss>

