<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 No Internet Connection on the inside Interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846658#M489455</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh yess, definitely, thanks. I jsut didnt see any nat statement in there, n might have overlooked the one you specified &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 04 Jan 2012 17:37:25 GMT</pubDate>
    <dc:creator>varrao</dc:creator>
    <dc:date>2012-01-04T17:37:25Z</dc:date>
    <item>
      <title>ASA 5510 No Internet Connection on the inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846655#M489452</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so i have a ASA 5510.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA is Connect with the Internet through PPOE DSL MODEM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The outside Interface get an IP&lt;/P&gt;&lt;P&gt;The Inside Interface get through DHCP from the ASA the Internet DNS SERVER (T-Online)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the HOST do not connect to the Internet because the DNS Server is timed out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here my Config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa&amp;gt; ena&lt;/P&gt;&lt;P&gt;Password: *******&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# show run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.4(2) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;enable password xxx&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; pppoe client vpdn group T-Online&lt;/P&gt;&lt;P&gt; ip address pppoe setroute &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.20.0.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 217.5.100.185&lt;/P&gt;&lt;P&gt; name-server 217.5.100.186&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;access-list inside_in extended permit ip any any &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;&amp;lt;--- More ---&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 &amp;lt;ip of the outside interface&amp;gt; 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;http 172.20.0.0 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;&amp;lt;--- More ---&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;vpdn group T-Online request dialout pppoe&lt;/P&gt;&lt;P&gt;vpdn group T-Online localname &amp;lt;t-online username&amp;gt;&lt;/P&gt;&lt;P&gt;vpdn group T-Online ppp authentication pap&lt;/P&gt;&lt;P&gt;vpdn username &amp;lt;t-online username&amp;gt; password xxx&lt;/P&gt;&lt;P&gt;dhcpd address 172.20.0.100-172.20.0.200 inside&lt;/P&gt;&lt;P&gt;dhcpd dns 217.5.100.185 217.5.100.186 interface inside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.2-192.168.1.254 management&lt;/P&gt;&lt;P&gt;dhcpd enable management&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;lt;--- More ---&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;Cryptochecksum:b28f45c98568fb8d01293cf71256fa82&lt;/P&gt;&lt;P&gt;&amp;lt;--- More ---&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa#&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I Think this must be a NAT/ACL Problem but when i configure nat the same Problem still exists&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CAn someone Help me ?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:09:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846655#M489452</guid>
      <dc:creator>Philipp Hoeffker</dc:creator>
      <dc:date>2019-03-11T22:09:57Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 No Internet Connection on the inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846656#M489453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Philipp,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It definitely seems to be a NAT issue, you would need to add this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it still does not work, please reboot the modem and the ASA once and then check again.\&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jan 2012 16:26:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846656#M489453</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-01-04T16:26:57Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 No Internet Connection on the inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846657#M489454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess you oversighted that ASA version is 8.4 :-).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Philipp,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the new version try this...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; subnet 0.0.0.0 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --&amp;gt; You can replace 0/0 with your internal subnet.&lt;BR /&gt;&amp;nbsp;&amp;nbsp; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more information on pre/post 8.3 syntax changes, refer the below link...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-9129"&gt;https://supportforums.cisco.com/docs/DOC-9129&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jan 2012 17:03:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846657#M489454</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2012-01-04T17:03:41Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 No Internet Connection on the inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846658#M489455</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh yess, definitely, thanks. I jsut didnt see any nat statement in there, n might have overlooked the one you specified &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jan 2012 17:37:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846658#M489455</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-01-04T17:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 No Internet Connection on the inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846659#M489456</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK i see it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But when i config this the Problem still exist &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;New Config:&lt;/P&gt;&lt;P&gt;iscoasa# show run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.4(2) &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;enable password xxx&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; pppoe client vpdn group T-Online&lt;/P&gt;&lt;P&gt; ip address pppoe setroute &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.20.0.1 255.255.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0 &lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; name-server 217.5.100.185&lt;/P&gt;&lt;P&gt; name-server 217.5.100.186&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;object network Testpc&lt;/P&gt;&lt;P&gt; host 172.20.100.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_in extended permit ip any interface outside &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip 172.20.0.0 255.255.0.0 interface outside &lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip object Testpc interface outside &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 87.139.227.44 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;http 172.20.0.0 255.255.0.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;vpdn group T-Online request dialout pppoe&lt;/P&gt;&lt;P&gt;vpdn group T-Online localname &lt;USERNAME t-online=""&gt;&lt;/USERNAME&gt;&lt;/P&gt;&lt;P&gt;vpdn group T-Online ppp authentication pap&lt;/P&gt;&lt;P&gt;vpdn username &lt;USERNAME t-online=""&gt; password xxx &lt;/USERNAME&gt;&lt;/P&gt;&lt;P&gt;dhcpd address 172.20.100.1-172.20.100.200 inside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.2-192.168.1.254 management&lt;/P&gt;&lt;P&gt;dhcpd enable management&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;Cryptochecksum:3b1058e17ecd9f9dd895841e0cdf9688&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The new acls are a try to solve this output from the ASDM Logging:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;P&gt;443&amp;nbsp;&amp;nbsp;&amp;nbsp; Deny TCP (no connection) from 172.20.100.1/50142 to 172.20.0.1/443 flags FIN ACK&amp;nbsp; on interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Update: &lt;/P&gt;&lt;P&gt;I have remove the acls so that only "Lower Interface" rule is working&lt;/P&gt;&lt;P&gt;It seems that the connection to the DNS Server is established but than theconnection is closed&amp;nbsp; with "Teardown" befor the information is transmittet.&lt;/P&gt;&lt;P&gt;All packets are translatet but is not working&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Log Entrys:&lt;/P&gt;&lt;P&gt;217.100.5.185|&amp;nbsp;&amp;nbsp; 53|172.20.100.1 |63320|Teardown UDP connection 1552 for outside:217.100.5.185/53 to inside:172.20.100.1/63320 duration 0:02:07 bytes 129&lt;/P&gt;&lt;P&gt;217.100.5.186|&amp;nbsp;&amp;nbsp; 53|172.20.100.1 |63320|Teardown UDP connection 1551 for outside:217.100.5.186/53 to inside:172.20.100.1/63320 duration 0:02:08 bytes 172&lt;/P&gt;&lt;P&gt;172.20.100.1 |54829|217.100.5.186|&amp;nbsp;&amp;nbsp; 53|Built outbound UDP connection 1562 for outside:217.100.5.186/53 (217.100.5.186/53) to inside:172.20.100.1/54829 (ISP given IP/29049)&lt;/P&gt;&lt;P&gt;172.20.100.1 |54829|217.100.5.185|&amp;nbsp;&amp;nbsp; 53|Built outbound UDP connection 1561 for outside:217.100.5.185/53 (217.100.5.185/53) to inside:172.20.100.1/54829 (ISP given IP/29049)&lt;/P&gt;&lt;P&gt;172.20.100.1 |54829|87.139.227.44|29049|Built dynamic UDP translation from inside:172.20.100.1/54829 to ISP given IP/29049&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2012 09:14:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846659#M489456</guid>
      <dc:creator>Philipp Hoeffker</dc:creator>
      <dc:date>2012-01-05T09:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 No Internet Connection on the inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846660#M489457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Problem is caused @ the outside Interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Incomming Packtes ar droped through an outside acl.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The packet flows is broken @ an acl from the outside to the inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i openthe wall the nat drop the packet -.........&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2012 15:58:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846660#M489457</guid>
      <dc:creator>Philipp Hoeffker</dc:creator>
      <dc:date>2012-01-05T15:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 No Internet Connection on the inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846661#M489458</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Philiopp,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please add the following access-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_in line 1 permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then provide me the following outputs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- packet-tracer input inside tcp 172.20.1.15 1025 4.2.2.2 80&lt;/P&gt;&lt;P&gt;- fixup protocol icmp&lt;/P&gt;&lt;P&gt;-Try to ping from the PC 87.139.227.44 and let me know the result&lt;/P&gt;&lt;P&gt;-Ping for the ASA to 4.2.2.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2012 17:17:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846661#M489458</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-01-05T17:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 No Internet Connection on the inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846662#M489459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here the Output you need:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)#packet-tracer input inside Tcp 172.10.1.15 1025 4.2.2.2 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 1&lt;/P&gt;&lt;P&gt;Type: ROUTE-LOOKUP&lt;/P&gt;&lt;P&gt;Subtype: input&lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;in&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 2&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 3&lt;/P&gt;&lt;P&gt;Type: NAT&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; nat (inside,outside) dynamic interface&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Dynamic translate 172.10.1.15/1025 to 87.139.227.44/22793&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 4&lt;/P&gt;&lt;P&gt;Type: IP-OPTIONS&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phase: 5&lt;/P&gt;&lt;P&gt;Type: FLOW-CREATION&lt;/P&gt;&lt;P&gt;Subtype: &lt;/P&gt;&lt;P&gt;Result: ALLOW&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;P&gt;Additional Information:&lt;/P&gt;&lt;P&gt;New flow created with id 294, packet dispatched to next module&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result:&lt;/P&gt;&lt;P&gt;input-interface: inside&lt;/P&gt;&lt;P&gt;input-status: up&lt;/P&gt;&lt;P&gt;input-line-status: up&lt;/P&gt;&lt;P&gt;output-interface: outside&lt;/P&gt;&lt;P&gt;output-status: up&lt;/P&gt;&lt;P&gt;output-line-status: up&lt;/P&gt;&lt;P&gt;Action: allow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# ping 4.2.2.2&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 4.2.2.2, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;!!!!!&lt;/P&gt;&lt;P&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 60/68/70 ms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-----------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Ping from PC:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Microsoft Windows [Version 6.1.7601]&lt;/P&gt;&lt;P&gt;Copyright (c) 2009 Microsoft Corporation. Alle Rechte vorbehalten.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\Users\Technik&amp;gt;ping 87.139.227.44&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ping wird ausgeführt für 87.139.227.44 mit 32 Bytes Daten:&lt;/P&gt;&lt;P&gt;Zeitüberschreitung der Anforderung.&lt;/P&gt;&lt;P&gt;Zeitüberschreitung der Anforderung.&lt;/P&gt;&lt;P&gt;Zeitüberschreitung der Anforderung.&lt;/P&gt;&lt;P&gt;Zeitüberschreitung der Anforderung.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ping-Statistik für 87.139.227.44:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Pakete: Gesendet = 4, Empfangen = 0, Verloren = 4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; (100% Verlust),&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\Users\Technik&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2012 08:52:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846662#M489459</guid>
      <dc:creator>Philipp Hoeffker</dc:creator>
      <dc:date>2012-01-06T08:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 No Internet Connection on the inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846663#M489460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So the ASA does have internet connectivity..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you add the command fixup protocol ICMP??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2012 17:39:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846663#M489460</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-01-06T17:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 No Internet Connection on the inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846664#M489461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, i have enter this command but nothing chnage. I have activate vpn over ssl as a test, it works fine but the inside host has no connection to the outside.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jan 2012 16:19:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846664#M489461</guid>
      <dc:creator>Philipp Hoeffker</dc:creator>
      <dc:date>2012-01-07T16:19:31Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 No Internet Connection on the inside Interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846665#M489462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The new config you posted- ASA missing DNS IPs for hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dhcpd dns 217.5.100.185 217.5.100.186 interface inside&amp;nbsp; --&amp;gt; Add this to ASA &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, remove access-group inside_access_in in interface inside&amp;nbsp; (you add later if required)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try with this and see how it goes. If any issues, try to browse using IP instead of DNS name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jan 2012 16:47:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-no-internet-connection-on-the-inside-interface/m-p/1846665#M489462</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2012-01-07T16:47:31Z</dc:date>
    </item>
  </channel>
</rss>

