<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5505 Help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-help/m-p/1074054#M418483</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so the mailserver is also serving as dhcp server for the inside clients, which is why i turned off DHCP on the router.  i have decided that i need to work on this in person - it's difficult to truobleshoot something that isn't plugged in.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  so i'm trying to arrange to make the trek to my client's sit on monday.  once I figure out what's wrong I will post it here for future reference.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 20 Dec 2008 16:32:07 GMT</pubDate>
    <dc:creator>wendigoulette</dc:creator>
    <dc:date>2008-12-20T16:32:07Z</dc:date>
    <item>
      <title>ASA 5505 Help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-help/m-p/1074050#M418479</link>
      <description>&lt;P&gt;I am configuring an ASA 5505 for a small business client to replace Linksys router, and I am having some trouble with it.  Any help would be greatly appreciated.  Here is my config:&lt;/P&gt;&lt;P&gt;sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 7.2(4) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 192.168.32.5 mailserver&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.32.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address xx.xx.215.35 255.255.255.224 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;object-group service DM_INLINE_TCP_1 tcp&lt;/P&gt;&lt;P&gt; port-object eq www&lt;/P&gt;&lt;P&gt; port-object eq https&lt;/P&gt;&lt;P&gt; port-object eq smtp&lt;/P&gt;&lt;P&gt; port-object eq 444&lt;/P&gt;&lt;P&gt; port-object eq imap4&lt;/P&gt;&lt;P&gt; port-object eq 4125&lt;/P&gt;&lt;P&gt; port-object eq pptp&lt;/P&gt;&lt;P&gt; port-object eq ftp&lt;/P&gt;&lt;P&gt; port-object eq 3389&lt;/P&gt;&lt;P&gt; port-object eq pop3&lt;/P&gt;&lt;P&gt; port-object eq 995&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any host mailserver object-group DM_INLINE_TCP_1 &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging buffered informational&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface ftp mailserver ftp netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface https mailserver https netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface smtp mailserver smtp netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 444 mailserver 444 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface imap4 mailserver imap4 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 4125 mailserver 4125 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface pptp mailserver pptp netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 3389 mailserver 3389 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 995 mailserver 995 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface www mailserver www netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;static (inside,outside) interface mailserver netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 xx.xx.215.33 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.32.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;  inspect rtsp &lt;/P&gt;&lt;P&gt;  inspect esmtp &lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;  inspect skinny &lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt;  inspect sip &lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;Cryptochecksum:916a58426e2cb7b4d44cdbc0446fcfad&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;ciscoasa#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the routing table (nothing plugged in right now other than console):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway of last resort is not set&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C    127.0.0.0 255.255.255.0 is directly connected, _internal_loopback&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I have the client connect the asa, no connectivity in or out works.  They have two layer 2 switches, no routers.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:10:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-help/m-p/1074050#M418479</guid>
      <dc:creator>wendigoulette</dc:creator>
      <dc:date>2020-02-21T11:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-help/m-p/1074051#M418480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;B&gt;Here is the routing table (nothing plugged in right now other than console): &lt;/B&gt;&lt;/P&gt;&lt;P&gt;Gateway of last resort is not set &lt;/P&gt;&lt;P&gt;C 127.0.0.0 255.255.255.0 is directly connected, _internal_loopback&amp;lt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 xx.xx.215.33 1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi Wendi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to start making the physical connection in your inside switch  and outside interfaces first before atempting to connect to internet or from outside internet to inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show route does not indicate any physical connectivity to anything .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Dec 2008 04:43:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-help/m-p/1074051#M418480</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-12-20T04:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-help/m-p/1074052#M418481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, thank you for your reply.  I noted in my post that when it IS plugged in, nothing works.  I am very aware that connectivity to anywhere will not work without a physical connection.  &lt;span class="lia-unicode-emoji" title=":monkey_face:"&gt;🐵&lt;/span&gt;&lt;/P&gt;&lt;P&gt;My concern is mostly my config - I'm looking for any suggestions on what I may have configured incorrectly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oh, one other note - shouldn't my static default route be displayed in the routing table whether it is connected or not?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 xx.xx.215.33 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Dec 2008 14:42:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-help/m-p/1074052#M418481</guid>
      <dc:creator>wendigoulette</dc:creator>
      <dc:date>2008-12-20T14:42:51Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-help/m-p/1074053#M418482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Wendy,  the default route will show up in routing table once the upstream router is reachable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I meant also to repost my answer few minutes later thinking that you must have placed back the linksys router becuase connectivity to internet was not happening, my apologies for that, I would have done exactly the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you connect back the firewall connections to inside and outside from firewall itself try pinging your defalt route to confirm you can reach that upstream router. The access from inside to outside by default is permited but you will need some dns configuration for the PC inside to  DNS query  weblinks.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you could try dhcp address for inside interfaces if you don't have dhcp server and use a public opened DNS servers 208.67.222.222,208.67.220.220&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and have this be automatically given to inside hosts dynamically&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dhcpd dns 208.67.222.222 208.67.220.220&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.32.10-192.168.32.100 inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for the acl to get access to inside mailserver I would try :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any interface outside object-group DM_INLINE_TCP_1&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but...I would recommend to change the acl name instead of the " inside_access_in " to sort of distinguish what comes from outside to inside within acl names, like  &lt;B&gt;outside_access_in&lt;/B&gt; gives clear picture for your outside interface acls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit tcp any interface outside object-group DM_INLINE_TCP_1&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;remove old one&lt;/P&gt;&lt;P&gt;no access-list inside_access_in extended permit tcp any host mailserver object-group DM_INLINE_TCP_1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Dec 2008 16:11:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-help/m-p/1074053#M418482</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-12-20T16:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-help/m-p/1074054#M418483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so the mailserver is also serving as dhcp server for the inside clients, which is why i turned off DHCP on the router.  i have decided that i need to work on this in person - it's difficult to truobleshoot something that isn't plugged in.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  so i'm trying to arrange to make the trek to my client's sit on monday.  once I figure out what's wrong I will post it here for future reference.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Dec 2008 16:32:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-help/m-p/1074054#M418483</guid>
      <dc:creator>wendigoulette</dc:creator>
      <dc:date>2008-12-20T16:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-help/m-p/1074055#M418484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Wendi, just touching base to learn if you have any issues or is all ok?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Dec 2008 18:25:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-help/m-p/1074055#M418484</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-12-22T18:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 Help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-help/m-p/1074056#M418485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I haven't been able to coordinate a time to visit the customer until now - I will be going over there tomorrow evening.  Will post the results here.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Dec 2008 16:30:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-help/m-p/1074056#M418485</guid>
      <dc:creator>wendigoulette</dc:creator>
      <dc:date>2008-12-29T16:30:12Z</dc:date>
    </item>
  </channel>
</rss>

