<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 config help in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749681#M495341</link>
    <description>&lt;P&gt;My ASA5510 is connected to a time capsule (Apple router). Its configuratin is as follow:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ethernet0/0&amp;nbsp; interface &lt;STRONG&gt;Outside&lt;/STRONG&gt; with security level 0. It is configured to get ip adr from dhcp. (It gets ip adr from Time Capsule)&lt;/P&gt;&lt;P&gt;Ethernet0/1&amp;nbsp; interface &lt;STRONG&gt;Inside&lt;/STRONG&gt; with security level 100. IP adr is 192.168.10.1 255.255.255.0 . DHCP server is enabled on interface &lt;STRONG&gt;Inside&lt;/STRONG&gt; (192.168.10.2-192.168.10.254). I did that so my computer could get ip adr from ASA instead of TimeCapsule. Also autoconfiguration is enabled on interface &lt;STRONG&gt;Outside&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;PAT is enabled (Use the ip adr on the &lt;STRONG&gt;Outside&lt;/STRONG&gt; interface.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the basic info from setup wizard. There is no other additional configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA is wired into TimeCapsule on Ethernet0/0 and my pc is connected to ethernet0/1 of ASA. My pc gets ip adr (192.168.10.2) from ASA but not able to connect to the internet. When run Windows TS wizard the msg I get is "Windows can not communicate with the device/resource (Primary DNS Server)"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cany any body tell me what I am doing wrong? I believe I am missing some crucial config setting at ASA but can't figure it out. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any kind of help will be highly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;ImranN&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:39:26 GMT</pubDate>
    <dc:creator>Narmi2000</dc:creator>
    <dc:date>2019-03-11T21:39:26Z</dc:date>
    <item>
      <title>ASA 5510 config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749681#M495341</link>
      <description>&lt;P&gt;My ASA5510 is connected to a time capsule (Apple router). Its configuratin is as follow:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ethernet0/0&amp;nbsp; interface &lt;STRONG&gt;Outside&lt;/STRONG&gt; with security level 0. It is configured to get ip adr from dhcp. (It gets ip adr from Time Capsule)&lt;/P&gt;&lt;P&gt;Ethernet0/1&amp;nbsp; interface &lt;STRONG&gt;Inside&lt;/STRONG&gt; with security level 100. IP adr is 192.168.10.1 255.255.255.0 . DHCP server is enabled on interface &lt;STRONG&gt;Inside&lt;/STRONG&gt; (192.168.10.2-192.168.10.254). I did that so my computer could get ip adr from ASA instead of TimeCapsule. Also autoconfiguration is enabled on interface &lt;STRONG&gt;Outside&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;PAT is enabled (Use the ip adr on the &lt;STRONG&gt;Outside&lt;/STRONG&gt; interface.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the basic info from setup wizard. There is no other additional configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA is wired into TimeCapsule on Ethernet0/0 and my pc is connected to ethernet0/1 of ASA. My pc gets ip adr (192.168.10.2) from ASA but not able to connect to the internet. When run Windows TS wizard the msg I get is "Windows can not communicate with the device/resource (Primary DNS Server)"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cany any body tell me what I am doing wrong? I believe I am missing some crucial config setting at ASA but can't figure it out. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any kind of help will be highly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;ImranN&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:39:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749681#M495341</guid>
      <dc:creator>Narmi2000</dc:creator>
      <dc:date>2019-03-11T21:39:26Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749682#M495342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In your DHCP config are you handing out a valid DNS server ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is a DNS server problem then can you try connecting to a website using an IP address rather than a URL ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Oct 2011 16:59:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749682#M495342</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2011-10-18T16:59:30Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749683#M495343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your help Jon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have enabled DHCP server on Inside interface with the pool (192.168.10.2-192.168.10.254) so my pc could get&lt;/P&gt;&lt;P&gt;ip adr from there and it does. Also I have enabled auto-configuration from interface Outside (This setting&lt;/P&gt;&lt;P&gt;is part of setup wizard). It means DHCP server should automatically configure DNS, WINS and domain name.&lt;/P&gt;&lt;P&gt;According to the ipv4 settings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My pc's ip adr is&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.10.2 (Getting from interface Inside which is configured as DHCP) &lt;/P&gt;&lt;P&gt;Default gateway is&amp;nbsp;&amp;nbsp; 192.168.10.1 (IP adr of interface Inside)&lt;/P&gt;&lt;P&gt;DHCP serveris&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.10.1 (IP adr of interface Inside where DHCP server is enabled)&lt;/P&gt;&lt;P&gt;DNS server is&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.1&amp;nbsp; (Internal IP adr of the router ie TimeCapsule)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cant use IP adr to conenct to a web site because my pc is not connecting to internet. (In Network and Sharing Center I have a red X on internet.). In other words I dont have internet connectivity. It probably means packets are not allowed to leave ASA. That is why probably some misconfiguration. The error I get is (Your computer appears to be correctly configured but the device or resource (DNS Server) is not responding)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Btw, the ip subnet at interface Inside is 192.168.10.0 and the ip adr ASA gets from router is from the subnet of 192.168.1.0. On the other hand management interface has ip adr of 192.168.1.1. Does it make and difference?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other suggestion?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;ImraN&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Oct 2011 18:39:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749683#M495343</guid>
      <dc:creator>Narmi2000</dc:creator>
      <dc:date>2011-10-18T18:39:49Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749684#M495345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post config of ASA ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Oct 2011 21:35:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749684#M495345</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2011-10-18T21:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749685#M495347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the configuration detail of ASA5510. I have attached screen shots.&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/1/1/65110-ASA%20config%201.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/1/1/65111-ASA%20config%202.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/1/1/65112-ASA%20config%203.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/1/1/65113-ASA%20config%204.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;Moreover I have run ping test from my pc. My pc is connected to interface Inside and interface Outside is connected to TimeCapsule router. &lt;/P&gt;&lt;P&gt;I can ping to the interface I am connected to but can't ping the other interface (Outside). It means somehow both interfaces are not comunicating.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;ImraN&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Oct 2011 14:12:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749685#M495347</guid>
      <dc:creator>Narmi2000</dc:creator>
      <dc:date>2011-10-19T14:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749686#M495348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;I can ping to the interface I am connected to but can't ping the other interface (Outside).&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's normal you cant ping outside interface from inside on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your ACl screenshot you have implicit deny all inbound on outside but if you want to ping from inside to the router on outside then you must put an explicit rule stating you accept icmp echo-replies on this interface inbound or enable icmp inspection.&lt;/P&gt;&lt;P&gt;I can't only give you a CLI config but you can paste it in ASDM:&lt;/P&gt;&lt;P&gt;the most secure way for me is to inspect icmp so here it is&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;policy-map global_policy&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;class inspection_default&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;inspect icmp &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This way you can ping your router IP address from a PC on inside.&lt;/P&gt;&lt;P&gt;what does a ping to router WAN address give?&lt;/P&gt;&lt;P&gt;if you connect a PC&amp;nbsp; directly on the router, does it work and then have you got connectivity with internet? ping 8.8.8.8 is successful from PC?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you post a show run from the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Oct 2011 15:29:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749686#M495348</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-10-19T15:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749687#M495349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks you so much for helping me out Alain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is show running-config command out put on my ASA5510&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JASA&amp;gt; en&lt;/P&gt;&lt;P&gt;Password:&lt;/P&gt;&lt;P&gt;JASA# show run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.2(5)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname JASA&lt;/P&gt;&lt;P&gt;enable password y2YjIyt7RRXU24 encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; nameif JOutside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address dhcp setroute&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; nameif JInside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.10.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&amp;lt;--- More ---&amp;gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no nameif&lt;/P&gt;&lt;P&gt; no security-level&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt; nameif management&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt; management-only&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;access-list JOutside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu JOutside 1500&lt;/P&gt;&lt;P&gt;mtu JInside 1500&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;nat (JInside) 0 0.0.0.0 0.0.0.0 norandomseq&lt;/P&gt;&lt;P&gt;access-group JOutside_access_in in interface JOutside&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config JOutside&lt;/P&gt;&lt;P&gt;dhcpd update dns&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.10.2-192.168.10.254 JInside&lt;/P&gt;&lt;P&gt;dhcpd auto_config JOutside interface JInside&lt;/P&gt;&lt;P&gt;dhcpd enable JInside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.2-192.168.1.254 management&lt;/P&gt;&lt;P&gt;dhcpd enable management&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;Cryptochecksum:0504ad33009162ea950248812eba1ffc&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;JASA#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I changed the network on the router. Now its using 172.16.0.0 network instead of 192.168.1.0. After doing that now in ASDM interface Outside also shows the ip adr its getting from the router where it was not showing any ip adr before (see screenshot).&amp;nbsp; Anyways, nothing eles has been changed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/4/2/65249-ASA%20conf%2020Oct%201.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My pc is connected to interface outside with ethernet cable and interface Inside is connected to the router. LAN config of my nic is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ip adr:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.10.2&lt;/P&gt;&lt;P&gt;Default gateway: 192.168.10.1&lt;/P&gt;&lt;P&gt;DHCP server:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.10.1&lt;/P&gt;&lt;P&gt;DNS server :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.1.1 (Internal ip adr of the router)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cant ping Outside interface of ASA. Host is unreachable. The traffic from high security interface to low security interface is allowed by default. If this is correct then I must have internet connection. Even though two different networks are setup on inside and outside interfaces, should ASA by default not do NAT?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have internet connected while directly connected to my router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Regards,&lt;/P&gt;&lt;P&gt;ImraN&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 22:05:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749687#M495349</guid>
      <dc:creator>Narmi2000</dc:creator>
      <dc:date>2011-10-20T22:05:47Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749688#M495353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;My pc is connected to interface outside with ethernet cable and&amp;nbsp; interface Inside is connected to the router. LAN config of my nic is:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Ip adr:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.10.2&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Default gateway: 192.168.10.1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;DHCP server:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.10.1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;DNS server :&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.1.1 (Internal ip adr of the router)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)&amp;nbsp; PC should be connected to interface INSIDE and router to interface OUTSIDE and it is as you have received a DHCP address&amp;nbsp; &lt;STRONG&gt;so point 1 is ok&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2) so to ping your router interface on OUTSIDE or any address on OUTSIDE you must either:&lt;/P&gt;&lt;P&gt;- inspect ICMP as I explained above and that's the most secure way&lt;/P&gt;&lt;P&gt;-create an ACL permitting ICMP echo-replies from any to your PC an apply it inbound on interface OUTSIDE&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;this is ok but the way you do it is very insecure&lt;/STRONG&gt; .&lt;/P&gt;&lt;P&gt;3) verify you have a default route on ASA for OUTSIDE pointing to 172.16.1.1 ---&amp;gt; &lt;STRONG&gt;show route&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; if it is not the case then create one: &lt;STRONG&gt;route outside 0 0 172.16.1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;4) the router needs a route to 192.168.10.0/24 network&amp;nbsp; &lt;STRONG&gt;no need to from 6 output&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;5) As as I said in previous post you can't ping ASA outside interface from inside so don't worry about this.&lt;/P&gt;&lt;P&gt;6) whether your ASA should be doing NAT or not depends if nat-control is enabled or not ---&amp;gt; &lt;STRONG&gt;show run nat-control&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if it is enabled then it is mandatory to do NAT from inside to outside communication to work. If it is the case then point 4 is not mandatory anymore.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;7) from 6 you must be doing NAT and this is where there is a problem in your config:&lt;/P&gt;&lt;P&gt;do this:&lt;/P&gt;&lt;P&gt;- no nat (JInside) 0 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;-nat(inside) 1 0 0&lt;/P&gt;&lt;P&gt;-global(outside) 1 interface JOutside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I said above concerning the ACL&amp;nbsp; when you've verified all is ok then remove it and inspect icmp instead &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Oct 2011 09:08:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749688#M495353</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-10-21T09:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749689#M495358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Alain for all your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried the config you provided but for some reason it CLI does not accept &lt;/P&gt;&lt;P&gt;-global(outside) 1 interface JOutside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So after many fruitless tries, I set the firewall to factory default. Connected it directly to the internet connection and configured it. I did work. I will look into other configuration some other time just for my own knowledge. I still greatly&lt;/P&gt;&lt;P&gt;appreciate all your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Nov 2011 14:38:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749689#M495358</guid>
      <dc:creator>Narmi2000</dc:creator>
      <dc:date>2011-11-08T14:38:13Z</dc:date>
    </item>
    <item>
      <title>ASA 5510 config help</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749690#M495361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;happy to know it is working now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I gave you a wrong command it should have been &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-nat(Jinside) 1 0 0&lt;/P&gt;&lt;P&gt;-global(Joutside) 1 interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Nov 2011 20:59:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-config-help/m-p/1749690#M495361</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-11-08T20:59:56Z</dc:date>
    </item>
  </channel>
</rss>

