<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: newbie question, cannot make ASA5510 up running... in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875589#M491209</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i tried a laptop connecting to the broadband modem directly using the public ip and gateway , the internet works, the gateway is pingable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now the asa5510 is directly connecting with the broadband modem, the gateway 202.105.56.33 is not pingable......&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Dec 2011 10:13:55 GMT</pubDate>
    <dc:creator>sc.bill.lee</dc:creator>
    <dc:date>2011-12-15T10:13:55Z</dc:date>
    <item>
      <title>newbie question, cannot make ASA5510 up running...</title>
      <link>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875583#M491198</link>
      <description>&lt;P&gt;hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I follow the steps according to the basic settings provided by Cisco Support forum, but still failed to access the internet,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would you advise anything I missed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV align="left" dir="ltr"&gt;&lt;SPAN style="color: #0000ff; font-family: 新細明體; font-size: 10pt;"&gt;ASA5510# sh run&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version&amp;nbsp; 8.2(1)&lt;BR /&gt;!&lt;BR /&gt;hostname ASA5510&lt;BR /&gt;domain-name xxx.com&lt;BR /&gt;enable&amp;nbsp; password &lt;BR /&gt;passwd &lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; nameif&amp;nbsp; outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address x.x.x.x&amp;nbsp; 255.255.255.248&lt;BR /&gt; ospf cost 10&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt; nameif&amp;nbsp; inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 10.161.9.14 255.255.255.0&lt;BR /&gt; ospf&amp;nbsp; cost 10&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no&amp;nbsp; ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt; no nameif&lt;BR /&gt; no&amp;nbsp; security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt; description&amp;nbsp; Management interface&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip&amp;nbsp; address&lt;BR /&gt;!&lt;BR /&gt;ftp&amp;nbsp; mode passive&lt;BR /&gt;dns domain-lookup outside&lt;BR /&gt;dns domain-lookup inside&lt;BR /&gt;dns&amp;nbsp; server-group DefaultDNS&lt;BR /&gt; name-server x.x.x.x&lt;BR /&gt; name-server x.x.x.x&lt;BR /&gt; domain-name starcruises.com&lt;BR /&gt;object-group network&amp;nbsp; Internet-User&lt;BR /&gt; network-object 10.0.0.0 255.0.0.0&lt;BR /&gt;access-list&amp;nbsp; inside_access_in extended permit ip object-group Internet-User any&lt;BR /&gt;pager&amp;nbsp; lines 24&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;icmp unreachable rate-limit 1&amp;nbsp; burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;route outside&amp;nbsp; 0.0.0.0 0.0.0.0 202.105.56.33 1&lt;BR /&gt;route inside 10.0.0.0 255.0.0.0 10.161.19.2&amp;nbsp; 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp&amp;nbsp; 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp&amp;nbsp; 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite&amp;nbsp; 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth&amp;nbsp; 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly&amp;nbsp; 0:01:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;no snmp-server&amp;nbsp; location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp&amp;nbsp; authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association&amp;nbsp; lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes&amp;nbsp; 4608000&lt;BR /&gt;telnet 10.0.0.0 255.0.0.0 inside&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout&amp;nbsp; 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection&amp;nbsp; statistics access-list&lt;BR /&gt;no threat-detection statistics&amp;nbsp; tcp-intercept&lt;BR /&gt;username admin password Jato7oimyIarVvyI&amp;nbsp; encrypted&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match&amp;nbsp; default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns&amp;nbsp; preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map&amp;nbsp; global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map&lt;BR /&gt;&amp;nbsp;&amp;nbsp; inspect ftp&lt;BR /&gt;&amp;nbsp; inspect h323 h225&lt;BR /&gt;&amp;nbsp; inspect h323 ras&lt;BR /&gt;&amp;nbsp; inspect&amp;nbsp; netbios&lt;BR /&gt;&amp;nbsp; inspect rsh&lt;BR /&gt;&amp;nbsp; inspect rtsp&lt;BR /&gt;&amp;nbsp; inspect skinny&lt;BR /&gt;&amp;nbsp; inspect&amp;nbsp; esmtp&lt;BR /&gt;&amp;nbsp; inspect sqlnet&lt;BR /&gt;&amp;nbsp; inspect sunrpc&lt;BR /&gt;&amp;nbsp; inspect tftp&lt;BR /&gt;&amp;nbsp; inspect&amp;nbsp; sip&lt;BR /&gt;&amp;nbsp; inspect xdmcp&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt&amp;nbsp; hostname context&lt;BR /&gt;Cryptochecksum:d110aabfe29f038d89965851f2dbcd92&lt;BR /&gt;:&amp;nbsp; end&lt;BR /&gt;ASA5510#&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:01:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875583#M491198</guid>
      <dc:creator>sc.bill.lee</dc:creator>
      <dc:date>2019-03-11T22:01:47Z</dc:date>
    </item>
    <item>
      <title>newbie question, cannot make ASA5510 up running...</title>
      <link>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875584#M491200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Add this and it shoudl work perfect after that:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Dec 2011 10:13:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875584#M491200</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-12-14T10:13:42Z</dc:date>
    </item>
    <item>
      <title>newbie question, cannot make ASA5510 up running...</title>
      <link>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875585#M491202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apply your access-list inside_access_in as access-group on interface inside in "in"direction.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Dec 2011 10:39:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875585#M491202</guid>
      <dc:creator>andrey.dugin</dc:creator>
      <dc:date>2011-12-14T10:39:52Z</dc:date>
    </item>
    <item>
      <title>newbie question, cannot make ASA5510 up running...</title>
      <link>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875586#M491204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Access-list is not really required on any interface for the internet access, what is missing from the config is the translation for the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Dec 2011 10:50:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875586#M491204</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-12-14T10:50:58Z</dc:date>
    </item>
    <item>
      <title>newbie question, cannot make ASA5510 up running...</title>
      <link>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875587#M491205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i did adding "&lt;SPAN style="font-family: Arial, verdana, sans-serif; font-size: 12px; background-color: #f7fafb;"&gt;nat (inside) 1 0.0.0.0 0.0.0.0" and "&lt;/SPAN&gt;&lt;SPAN style="font-family: Arial, verdana, sans-serif; font-size: 12px; background-color: #f7fafb;"&gt;global (outside) 1 interface"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px; font-family: Arial, verdana, sans-serif; "&gt;but seems still not working, one more stupid question:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how can I verify if the ASA is successfully connected to the internet without connecting a PC for browsing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is that the gateway of the public IP should be pingable by the ASA if the configuration is fine?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Dec 2011 03:54:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875587#M491205</guid>
      <dc:creator>sc.bill.lee</dc:creator>
      <dc:date>2011-12-15T03:54:05Z</dc:date>
    </item>
    <item>
      <title>newbie question, cannot make ASA5510 up running...</title>
      <link>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875588#M491207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bill,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As soon as you provide a public ip address to the outside interface of the ASA and you set a route to the oustide you should be able to ping any host on the outside ( Please try4.2.2.2 from the ASA), unless the border router blocks that traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And by the way you should be able to ping this host 202.105.56.33 if you cannot ping it the ASA will not be able to go to the outside&amp;nbsp; ( if they are directly connected ) that means there might be a problem at the phisical layer, if there is a switch in the middle please give a look.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Dec 2011 05:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875588#M491207</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-15T05:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: newbie question, cannot make ASA5510 up running...</title>
      <link>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875589#M491209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i tried a laptop connecting to the broadband modem directly using the public ip and gateway , the internet works, the gateway is pingable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now the asa5510 is directly connecting with the broadband modem, the gateway 202.105.56.33 is not pingable......&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Dec 2011 10:13:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875589#M491209</guid>
      <dc:creator>sc.bill.lee</dc:creator>
      <dc:date>2011-12-15T10:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: newbie question, cannot make ASA5510 up running...</title>
      <link>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875590#M491210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bill,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is the problem.....Seems to be an arp issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try to do a clear arp, clear local-host, clear xlate and then try to ping the modem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that does not help, please provide another ip address to the outside interface and then put the old one back.&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;nterface Ethernet0/0&lt;/P&gt;&lt;P&gt;ip address x.x.x.y&amp;nbsp; 255.255.255.248&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface Ethernet 0/0&lt;/P&gt;&lt;P&gt;ip address x.x.x.x&amp;nbsp; 255.255.255.248&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please verify the ASA is connected to the modem (modem got to be connected to por 0/0 on the ASA)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Dec 2011 17:29:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875590#M491210</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-15T17:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: newbie question, cannot make ASA5510 up running...</title>
      <link>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875591#M491212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks, i did it, i can ping the ISP now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;may I know what is the purpose of "clear arp, clear local-host, clear xlate"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Dec 2011 01:27:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875591#M491212</guid>
      <dc:creator>sc.bill.lee</dc:creator>
      <dc:date>2011-12-16T01:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: newbie question, cannot make ASA5510 up running...</title>
      <link>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875592#M491214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bill,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the clear arp solved the problem! Great to hear that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This commands are going to clear the entries on the ASA tables (Xlate[translation table},Local-host and arp table).&lt;/P&gt;&lt;P&gt;Seems like the router has an invalid entry of the ASA mac address so when we clear the arp we force the ASA to send a gratitious arp to the directly connected router so it learns the right mac address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Dec 2011 01:50:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/newbie-question-cannot-make-asa5510-up-running/m-p/1875592#M491214</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2011-12-16T01:50:49Z</dc:date>
    </item>
  </channel>
</rss>

