<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What am I missing - ASA 5520 basic config? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836202#M492279</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I tried to add&lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit ip any any&lt;/P&gt;&lt;P&gt;but this did not help..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Nov 2011 14:26:00 GMT</pubDate>
    <dc:creator>torleif</dc:creator>
    <dc:date>2011-11-30T14:26:00Z</dc:date>
    <item>
      <title>What am I missing - ASA 5520 basic config?</title>
      <link>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836200#M492277</link>
      <description>&lt;P&gt;I am trying to make a basic config on my 5520. The first goal is to make trafic from inside to outside.&lt;/P&gt;&lt;P&gt;The internet address is 64.28.29.200 and the default internet gw is 64.28.20.193&lt;/P&gt;&lt;P&gt;What am I missing since I can not get trafic from inside to the internet?&lt;/P&gt;&lt;P&gt;Any help would be appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.2(5)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname asatest&lt;/P&gt;&lt;P&gt;domain-name test.net&lt;/P&gt;&lt;P&gt;enable password xxx&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif Outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 64.28.29.200 255.255.255.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; nameif Inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.59.64.50 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;boot system disk0:/asa825-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name test.net&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list inside_acl extended permit ip any any&lt;/P&gt;&lt;P&gt;global (Outside) 1 64.28.29.202&lt;/P&gt;&lt;P&gt;nat (Inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;access-group outside_acl in interface Outside&lt;/P&gt;&lt;P&gt;access-group inside_acl in interface Inside&lt;/P&gt;&lt;P&gt;route Outside 0.0.0.0 0.0.0.0 64.28.29.193 1&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:56:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836200#M492277</guid>
      <dc:creator>torleif</dc:creator>
      <dc:date>2019-03-11T21:56:15Z</dc:date>
    </item>
    <item>
      <title>What am I missing - ASA 5520 basic config?</title>
      <link>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836201#M492278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The first issue that I notice is this&lt;/P&gt;&lt;P&gt;access-group outside_acl in interface Outside&lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit icmp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so you are not allowing anything but ICMP inbound on the outside interface. that makes it very difficult for things like DNS to work, which then impacts many other things that depend on DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Nov 2011 22:01:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836201#M492278</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2011-11-28T22:01:04Z</dc:date>
    </item>
    <item>
      <title>What am I missing - ASA 5520 basic config?</title>
      <link>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836202#M492279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I tried to add&lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit ip any any&lt;/P&gt;&lt;P&gt;but this did not help..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Nov 2011 14:26:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836202#M492279</guid>
      <dc:creator>torleif</dc:creator>
      <dc:date>2011-11-30T14:26:00Z</dc:date>
    </item>
    <item>
      <title>What am I missing - ASA 5520 basic config?</title>
      <link>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836203#M492280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;access-list outside_acl extended permit icmp any any&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;access-list inside_acl extended permit ip any any&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;global (Outside) 1 64.28.29.202&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;nat (Inside) 1 0.0.0.0 0.0.0.0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;access-group outside_acl in interface Outside&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;access-group inside_acl in interface Inside&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;route Outside 0.0.0.0 0.0.0.0 64.28.29.193 1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) remove both ACLs and the access-groups commands&lt;/P&gt;&lt;P&gt;2) change global(outside) command to&amp;nbsp; &lt;STRONG&gt;global (Outside) 1 interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;3) enable icmp inspection:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;policy-map global_policy&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;class inspection_default&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;inspect icmp &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Nov 2011 14:59:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836203#M492280</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-11-30T14:59:52Z</dc:date>
    </item>
    <item>
      <title>What am I missing - ASA 5520 basic config?</title>
      <link>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836204#M492281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you for your suggestions.&lt;/P&gt;&lt;P&gt;I got the following error messages while configuring:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asatest(config)# policy-map global_policy&lt;/P&gt;&lt;P&gt;asatest(config-pmap)# class inspection_default&lt;/P&gt;&lt;P&gt;ERROR: % class-map inspection_default not configured&lt;/P&gt;&lt;P&gt;asatest(config-pmap)# inspect icmp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;/P&gt;&lt;P&gt;ERROR: % Invalid input detected at '^' marker.&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;asatest(config)# policy-map global_policy&lt;/P&gt;&lt;P&gt;asatest(config-pmap)# class inspection_default&lt;/P&gt;&lt;P&gt;ERROR: % class-map inspection_default not configured&lt;/P&gt;&lt;P&gt;asatest(config-pmap)# inspect icmp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;/P&gt;&lt;P&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The changes did not seem to solve my problem.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Torleif&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Dec 2011 13:31:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836204#M492281</guid>
      <dc:creator>torleif</dc:creator>
      <dc:date>2011-12-01T13:31:16Z</dc:date>
    </item>
    <item>
      <title>What am I missing - ASA 5520 basic config?</title>
      <link>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836205#M492282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;post entire config.&lt;/P&gt;&lt;P&gt;can you ping your internet gateway from inside ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Dec 2011 13:41:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836205#M492282</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-12-01T13:41:53Z</dc:date>
    </item>
    <item>
      <title>What am I missing - ASA 5520 basic config?</title>
      <link>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836206#M492283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For basic config, as Rich and Alain mentioned, remove the ACLs.Once web access work, you can add addl security.&lt;/P&gt;&lt;P&gt; Also, if you see no issues in reaching the gateway, try using global (Outside) 1 interface. See if that works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Dec 2011 18:31:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836206#M492283</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2011-12-01T18:31:34Z</dc:date>
    </item>
    <item>
      <title>What am I missing - ASA 5520 basic config?</title>
      <link>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836207#M492284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the inside network I am only able to ping the inside interface. I am not able to ping the outside interface nor the outside gateway from the inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here comes the entire config.&lt;/P&gt;&lt;P&gt;Thx for your help.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Torleif&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.4(2)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname asatest&lt;/P&gt;&lt;P&gt;domain-name test.net&lt;/P&gt;&lt;P&gt;enable password xxx encrypted&lt;/P&gt;&lt;P&gt;passwd xxx encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;dns-guard&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif Outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 64.28.29.200 255.255.255.240&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; nameif Inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.59.64.50 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt; nameif DMZ&lt;/P&gt;&lt;P&gt; security-level 50&lt;/P&gt;&lt;P&gt; ip address 192.168.3.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.59.60.50 255.255.255.0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa842-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name test.net&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; subnet 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list inside_acl extended permit ip any any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;mtu Outside 1500&lt;/P&gt;&lt;P&gt;mtu Inside 1500&lt;/P&gt;&lt;P&gt;mtu DMZ 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;failover polltime unit 15 holdtime 45&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-645-206.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; nat (Inside,Outside) dynamic 64.28.29.202&lt;/P&gt;&lt;P&gt;access-group outside_acl in interface Outside&lt;/P&gt;&lt;P&gt;access-group inside_acl in interface Inside&lt;/P&gt;&lt;P&gt;route Outside 0.0.0.0 0.0.0.0 64.28.29.193 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 10.59.64.0 255.255.255.0 Inside&lt;/P&gt;&lt;P&gt;http 10.59.60.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community *****&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;call-home&lt;/P&gt;&lt;P&gt; profile CiscoTAC-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no active&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination address http &lt;/P&gt;&lt;P&gt;&lt;A href="https://tools.cisco.com/its/service/oddce/services/DDCEService"&gt;https://tools.cisco.com/its/service/oddce/services/DDCEService&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination address email &lt;/P&gt;&lt;P&gt;&lt;A href="mailto:callhome@cisco.com"&gt;callhome@cisco.com&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; destination transport-method http&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group diagnostic&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group environment&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group inventory periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group configuration periodic monthly&lt;/P&gt;&lt;P&gt;&amp;nbsp; subscribe-to-alert-group telemetry periodic daily&lt;/P&gt;&lt;P&gt;Cryptochecksum:434092a6461c0571570d49af38b17c46&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;asatest#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Dec 2011 08:08:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836207#M492284</guid>
      <dc:creator>torleif</dc:creator>
      <dc:date>2011-12-02T08:08:24Z</dc:date>
    </item>
    <item>
      <title>What am I missing - ASA 5520 basic config?</title>
      <link>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836208#M492285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove your inside ACL it's not necessary. then look at this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt; nameif Outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address&lt;STRONG&gt; 64.28.29.200&lt;/STRONG&gt; 255.255.255.240&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object network obj_any&lt;/P&gt;&lt;P&gt; nat (Inside,Outside) dynamic &lt;STRONG&gt;64.28.29.202&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try the &lt;STRONG&gt;nat(Inside,Outside) dynamic interface &lt;/STRONG&gt;I suggested, remove the inside ACL and then first try a ping to your gateway then to 8.8.8.8 and then do the same from an inside host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Dec 2011 08:56:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836208#M492285</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-12-02T08:56:32Z</dc:date>
    </item>
    <item>
      <title>What am I missing - ASA 5520 basic config?</title>
      <link>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836209#M492286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you all for your suggestions and your time!&lt;/P&gt;&lt;P&gt;Alains changes made this work!&lt;/P&gt;&lt;P&gt;Now I have a working config and can work on with my needs..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Torleif&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Dec 2011 09:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836209#M492286</guid>
      <dc:creator>torleif</dc:creator>
      <dc:date>2011-12-02T09:21:19Z</dc:date>
    </item>
    <item>
      <title>What am I missing - ASA 5520 basic config?</title>
      <link>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836210#M492287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Alain / Rich,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you shed some light on why the ASA does not work when mapping static ip (global (Outside) 1 x.x.x.x) when compared to dynamic mapping with public ip subnet /28?&amp;nbsp; I had similar issue previously on 8.0 and when changed the config to global (Outside) 1 interface- it worked fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The static ip mapping config worked fine for me with public subnets /24 and /27. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ms&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Dec 2011 14:29:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-am-i-missing-asa-5520-basic-config/m-p/1836210#M492287</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2011-12-02T14:29:10Z</dc:date>
    </item>
  </channel>
</rss>

