<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SOLVED: ASA5506 - Internal network not routed via public PPPoE interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/solved-asa5506-internal-network-not-routed-via-public-pppoe/m-p/3884710#M5901</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;we're having a problem with out ASA5506.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The public interface "outsideSub" has internet connection via PPPoE.&lt;/P&gt;&lt;P&gt;The ping test to a public DNS server from the outsideSub iface is successful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the package trace shows that TCP packets are blocket using an ACL.&lt;/P&gt;&lt;P&gt;Also, hosts in the internal subnet do not have internet connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the current config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;BR /&gt;: Serial Number: JAD211802J4&lt;BR /&gt;: Hardware: ASA5506, 4096 MB RAM, CPU Atom C2000 series 1250 MHz, 1 CPU (4 cores)&lt;BR /&gt;: Written by admin at 12:07:48.259 CEDT Thu Jul 4 2019&lt;BR /&gt;!&lt;BR /&gt;ASA Version 9.6(1)&lt;BR /&gt;!&lt;BR /&gt;hostname firewall&lt;BR /&gt;enable password WHzrdccdxogzFJXY encrypted&lt;BR /&gt;names&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;interface GigabitEthernet1/1&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/1.100&lt;BR /&gt;nve-only&lt;BR /&gt;vlan 7&lt;BR /&gt;nameif outsideSub&lt;BR /&gt;security-level 0&lt;BR /&gt;pppoe client vpdn group telekom&lt;BR /&gt;ip address pppoe&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address dhcp&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;nameif DMZ&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 192.168.3.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/4&lt;BR /&gt;nameif guest&lt;BR /&gt;security-level 1&lt;BR /&gt;ip address 192.168.5.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/5&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/6&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/7&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/8&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management1/1&lt;BR /&gt;management-only&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;ip address dhcp&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CEST 1&lt;BR /&gt;clock summer-time CEDT recurring last Sun Mar 2:00 last Sun Oct 3:00&lt;BR /&gt;dns domain-lookup outsideSub&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;name-server 217.69.169.25 outsideSub&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network obj_any&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network insideSub&lt;BR /&gt;object network WWW-EXT&lt;BR /&gt;host 87.140.26.169&lt;BR /&gt;object network WWW-INT&lt;BR /&gt;host 192.168.3.2&lt;BR /&gt;object service https&lt;BR /&gt;service tcp source range 0 1024 destination eq https&lt;BR /&gt;object network internal-webserver&lt;BR /&gt;host 192.168.3.2&lt;BR /&gt;object network dect-gateway&lt;BR /&gt;host 192.168.178.15&lt;BR /&gt;object service http&lt;BR /&gt;service tcp source eq www destination eq www&lt;BR /&gt;description http&lt;BR /&gt;object-group service DM_INLINE_SERVICE_1&lt;BR /&gt;service-object tcp-udp destination eq sip&lt;BR /&gt;service-object tcp destination eq www&lt;BR /&gt;service-object tcp destination eq https&lt;BR /&gt;object-group service DM_INLINE_SERVICE_2&lt;BR /&gt;service-object udp&lt;BR /&gt;service-object tcp destination eq sip&lt;BR /&gt;service-object udp destination eq sip&lt;BR /&gt;service-object tcp destination eq 5090&lt;BR /&gt;service-object tcp destination eq https&lt;BR /&gt;service-object tcp destination eq www&lt;BR /&gt;service-object udp destination range 30000 31000&lt;BR /&gt;service-object udp destination eq 3478&lt;BR /&gt;service-object udp destination eq 3479&lt;BR /&gt;service-object udp destination range 40000 41000&lt;BR /&gt;object-group service DM_INLINE_SERVICE_3&lt;BR /&gt;service-object udp&lt;BR /&gt;service-object tcp destination eq sip&lt;BR /&gt;service-object udp destination eq sip&lt;BR /&gt;service-object tcp destination eq https&lt;BR /&gt;service-object tcp destination eq 5090&lt;BR /&gt;service-object udp destination range 30000 30900&lt;BR /&gt;service-object udp destination range 40000 40900&lt;BR /&gt;service-object udp destination eq 5070&lt;BR /&gt;service-object udp destination eq 5080&lt;BR /&gt;object-group service DM_INLINE_SERVICE_6&lt;BR /&gt;service-object tcp destination eq https&lt;BR /&gt;service-object tcp-udp destination eq domain&lt;BR /&gt;service-object tcp destination eq www&lt;BR /&gt;object-group service DM_INLINE_TCP_1 tcp&lt;BR /&gt;port-object eq www&lt;BR /&gt;port-object eq https&lt;BR /&gt;object-group service DM_INLINE_TCP_2 tcp&lt;BR /&gt;port-object eq www&lt;BR /&gt;port-object eq https&lt;BR /&gt;access-list inside_access_in extended permit ip any any&lt;BR /&gt;access-list inbound extended permit tcp any object internal-webserver object-group DM_INLINE_TCP_2 log debugging&lt;BR /&gt;access-list inbound extended permit object-group DM_INLINE_SERVICE_2 any object dect-gateway log debugging inactive&lt;BR /&gt;access-list DMZ_access_in extended permit tcp any object internal-webserver object-group DM_INLINE_TCP_1&lt;BR /&gt;access-list DMZ_access_in extended permit object-group DM_INLINE_SERVICE_6 object internal-webserver any&lt;BR /&gt;access-list DMZ_access_in extended permit ip any any inactive&lt;BR /&gt;access-list inside_access_in_1 extended permit ip any any&lt;BR /&gt;access-list inside_access_in_1 extended permit object-group DM_INLINE_SERVICE_3 any object dect-gateway log debugging inactive&lt;BR /&gt;access-list guest_access_in extended permit ip any interface outsideSub&lt;BR /&gt;access-list telefon_access_in extended permit object-group DM_INLINE_SERVICE_1 any any&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu outside 1492&lt;BR /&gt;mtu outsideSub 1492&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu DMZ 1500&lt;BR /&gt;mtu guest 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;!&lt;BR /&gt;object network obj_any&lt;BR /&gt;nat (any,outsideSub) dynamic interface&lt;BR /&gt;object network internal-webserver&lt;BR /&gt;nat (DMZ,outsideSub) static interface service tcp https https&lt;BR /&gt;!&lt;BR /&gt;nat (inside,outsideSub) after-auto source dynamic any interface&lt;BR /&gt;nat (DMZ,outsideSub) after-auto source dynamic any interface&lt;BR /&gt;nat (guest,outsideSub) after-auto source dynamic any interface&lt;BR /&gt;access-group inbound in interface outsideSub&lt;BR /&gt;access-group inside_access_in_1 in interface inside&lt;BR /&gt;access-group DMZ_access_in in interface DMZ&lt;BR /&gt;route outsideSub 0.0.0.0 0.0.0.0 87.140.26.169 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.178.0 255.255.255.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;service sw-reset-button&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto ca trustpoint ASDM_Launcher_Access_TrustPoint_0&lt;BR /&gt;enrollment self&lt;BR /&gt;fqdn none&lt;BR /&gt;subject-name CN=192.168.178.1,CN=firewall&lt;BR /&gt;keypair ASDM_LAUNCHER&lt;BR /&gt;crl configure&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ca certificate chain ASDM_Launcher_Access_TrustPoint_0&lt;BR /&gt;certificate 213f335c&lt;BR /&gt;308202d2 308201ba a0030201 02020421 3f335c30 0d06092a 864886f7 0d010105&lt;BR /&gt;0500302b 3111300f 06035504 03130866 69726577 616c6c31 16301406 03550403&lt;BR /&gt;130d3139 322e3136 382e3137 382e3130 1e170d31 39303231 31303831 3332345a&lt;BR /&gt;170d3239 30323038 30383133 32345a30 2b311130 0f060355 04031308 66697265&lt;BR /&gt;77616c6c 31163014 06035504 03130d31 39322e31 36382e31 37382e31 30820122&lt;BR /&gt;300d0609 2a864886 f70d0101 01050003 82010f00 3082010a 02820101 00b8ce18&lt;BR /&gt;cf8bf6f6 dd3ee4fb a4dfe76c 4fe03a80 f81cd905 e46d54f9 f012b3ef a7b1b18e&lt;BR /&gt;986a25c1 72e2958e 358069bc 19cb4f82 6c64ae3e 093c5728 d459f866 6f96236a&lt;BR /&gt;510542c1 31fa49da 3abda6f9 9fd94928 f50cd6e4 0efd84e7 347f347b 599cffe4&lt;BR /&gt;ffc329ab 20e73469 4eea0f70 eccbbfe9 8b836d74 308d2726 141b774e bfc67f7b&lt;BR /&gt;01fd29f3 95270e96 1f772697 f860eb11 7e0686a7 d3a67ddf 1bc9d1f1 dfd8e56b&lt;BR /&gt;0dd0383b 77450eae d40e73b1 42eaa054 bdf1df88 bce74fa3 786577f4 761e2bb5&lt;BR /&gt;a7a64f7f bd438ccd a17fb35c 2259eb15 6e7fae71 41f7a8f2 1bcf7de0 1d681b31&lt;BR /&gt;67c3accc 8f335083 c1c785aa 287efa1b 001f9364 9ca24063 1df21744 0d020301&lt;BR /&gt;0001300d 06092a86 4886f70d 01010505 00038201 010005c6 2bb39f28 b70fc7f0&lt;BR /&gt;a36607a8 2548e727 f15ac207 fb9158dc 2d40b205 01bbdfca a400a80d f7ceddf9&lt;BR /&gt;9e970bb2 1ea6f27c 5abf5213 36c6e0bb da17f51f 11b57d6a 1a23d549 1da464b0&lt;BR /&gt;4eb0b2a9 8930c91d c4cab838 0467fe35 222fe4b1 8b1341a6 ea83f447 f415300e&lt;BR /&gt;c1d4307e 3ae79b83 99800943 6a1dfd1c 22f3313b cc16ad04 852268b0 d028aa16&lt;BR /&gt;b50ce50a bc6b7060 db1e01c4 c76395b4 cdfee801 a1d3a9f4 74398b92 cba196cf&lt;BR /&gt;8fca0659 305b10f7 fee4e90a 00ec7220 6401044c c20cd391 74cd12db acc1427f&lt;BR /&gt;d6d5f324 f5b15a43 b97eb21e 07fac702 81aed9a9 1828acae 91702b57 994e3618&lt;BR /&gt;3c2e2e50 55bb0fc3 18da4c73 399d0c17 830a9389 b679&lt;BR /&gt;quit&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 192.168.178.0 255.255.255.0 inside&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh key-exchange group dh-group14-sha1&lt;BR /&gt;console timeout 0&lt;BR /&gt;vpdn group telekom request dialout pppoe&lt;BR /&gt;vpdn group telekom ppp authentication pap&lt;/P&gt;&lt;P&gt;dhcpd dns 217.69.169.25&lt;BR /&gt;dhcpd auto_config inside&lt;BR /&gt;dhcpd option 3 ip 192.168.5.1&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 192.168.5.2-192.168.5.254 guest&lt;BR /&gt;dhcpd dns 217.69.169.25 interface guest&lt;BR /&gt;dhcpd enable guest&lt;BR /&gt;!&lt;BR /&gt;ntp server 188.68.54.53 source outsideSub&lt;BR /&gt;ssl trust-point ASDM_Launcher_Access_TrustPoint_0&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;username admin password WRN6n6ecK1px5qbL encrypted privilege 15&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect dns preset_dns_map&lt;BR /&gt;inspect ftp&lt;BR /&gt;inspect h323 h225&lt;BR /&gt;inspect h323 ras&lt;BR /&gt;inspect rsh&lt;BR /&gt;inspect rtsp&lt;BR /&gt;inspect esmtp&lt;BR /&gt;inspect sqlnet&lt;BR /&gt;inspect skinny&lt;BR /&gt;inspect sunrpc&lt;BR /&gt;inspect xdmcp&lt;BR /&gt;inspect sip&lt;BR /&gt;inspect netbios&lt;BR /&gt;inspect tftp&lt;BR /&gt;inspect ip-options&lt;BR /&gt;inspect icmp&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;Cryptochecksum:2e518b4508919eb399ce4cb4eae31eca&lt;BR /&gt;: end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are two screenshots to clearify the problem/configuration:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bildschirmfoto 2019-07-03 um 15.47.36.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/40115iD64391B47358DFA2/image-size/large?v=v2&amp;amp;px=999" role="button" title="Bildschirmfoto 2019-07-03 um 15.47.36.png" alt="Bildschirmfoto 2019-07-03 um 15.47.36.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bildschirmfoto 2019-07-03 um 15.53.04.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/40116iA984E48F40DE7047/image-size/large?v=v2&amp;amp;px=999" role="button" title="Bildschirmfoto 2019-07-03 um 15.53.04.png" alt="Bildschirmfoto 2019-07-03 um 15.53.04.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The NAT rules or routes were not changed explicitly!&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only change that has been done was changing the internalSub PPPoE setting to "use a static IP".&lt;/P&gt;&lt;P&gt;We did not have internet connection with the static IP, so we switched the iface setting back to PPPoE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ever since, the NATing/routing problem exists.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, there are no configuration backups and the config was written to flash...&lt;/P&gt;&lt;P&gt;We'd really appreciate your help!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EDIT: The issue was that "VTEP source interface" was checked in the virtual interface settings.&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 17:16:41 GMT</pubDate>
    <dc:creator>rfzt</dc:creator>
    <dc:date>2020-02-21T17:16:41Z</dc:date>
    <item>
      <title>SOLVED: ASA5506 - Internal network not routed via public PPPoE interface</title>
      <link>https://community.cisco.com/t5/network-security/solved-asa5506-internal-network-not-routed-via-public-pppoe/m-p/3884710#M5901</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;we're having a problem with out ASA5506.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The public interface "outsideSub" has internet connection via PPPoE.&lt;/P&gt;&lt;P&gt;The ping test to a public DNS server from the outsideSub iface is successful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the package trace shows that TCP packets are blocket using an ACL.&lt;/P&gt;&lt;P&gt;Also, hosts in the internal subnet do not have internet connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the current config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;BR /&gt;: Serial Number: JAD211802J4&lt;BR /&gt;: Hardware: ASA5506, 4096 MB RAM, CPU Atom C2000 series 1250 MHz, 1 CPU (4 cores)&lt;BR /&gt;: Written by admin at 12:07:48.259 CEDT Thu Jul 4 2019&lt;BR /&gt;!&lt;BR /&gt;ASA Version 9.6(1)&lt;BR /&gt;!&lt;BR /&gt;hostname firewall&lt;BR /&gt;enable password WHzrdccdxogzFJXY encrypted&lt;BR /&gt;names&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;interface GigabitEthernet1/1&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/1.100&lt;BR /&gt;nve-only&lt;BR /&gt;vlan 7&lt;BR /&gt;nameif outsideSub&lt;BR /&gt;security-level 0&lt;BR /&gt;pppoe client vpdn group telekom&lt;BR /&gt;ip address pppoe&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/2&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address dhcp&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/3&lt;BR /&gt;nameif DMZ&lt;BR /&gt;security-level 50&lt;BR /&gt;ip address 192.168.3.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/4&lt;BR /&gt;nameif guest&lt;BR /&gt;security-level 1&lt;BR /&gt;ip address 192.168.5.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/5&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/6&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/7&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/8&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management1/1&lt;BR /&gt;management-only&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;ip address dhcp&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CEST 1&lt;BR /&gt;clock summer-time CEDT recurring last Sun Mar 2:00 last Sun Oct 3:00&lt;BR /&gt;dns domain-lookup outsideSub&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt;name-server 217.69.169.25 outsideSub&lt;BR /&gt;same-security-traffic permit inter-interface&lt;BR /&gt;same-security-traffic permit intra-interface&lt;BR /&gt;object network obj_any&lt;BR /&gt;subnet 0.0.0.0 0.0.0.0&lt;BR /&gt;object network insideSub&lt;BR /&gt;object network WWW-EXT&lt;BR /&gt;host 87.140.26.169&lt;BR /&gt;object network WWW-INT&lt;BR /&gt;host 192.168.3.2&lt;BR /&gt;object service https&lt;BR /&gt;service tcp source range 0 1024 destination eq https&lt;BR /&gt;object network internal-webserver&lt;BR /&gt;host 192.168.3.2&lt;BR /&gt;object network dect-gateway&lt;BR /&gt;host 192.168.178.15&lt;BR /&gt;object service http&lt;BR /&gt;service tcp source eq www destination eq www&lt;BR /&gt;description http&lt;BR /&gt;object-group service DM_INLINE_SERVICE_1&lt;BR /&gt;service-object tcp-udp destination eq sip&lt;BR /&gt;service-object tcp destination eq www&lt;BR /&gt;service-object tcp destination eq https&lt;BR /&gt;object-group service DM_INLINE_SERVICE_2&lt;BR /&gt;service-object udp&lt;BR /&gt;service-object tcp destination eq sip&lt;BR /&gt;service-object udp destination eq sip&lt;BR /&gt;service-object tcp destination eq 5090&lt;BR /&gt;service-object tcp destination eq https&lt;BR /&gt;service-object tcp destination eq www&lt;BR /&gt;service-object udp destination range 30000 31000&lt;BR /&gt;service-object udp destination eq 3478&lt;BR /&gt;service-object udp destination eq 3479&lt;BR /&gt;service-object udp destination range 40000 41000&lt;BR /&gt;object-group service DM_INLINE_SERVICE_3&lt;BR /&gt;service-object udp&lt;BR /&gt;service-object tcp destination eq sip&lt;BR /&gt;service-object udp destination eq sip&lt;BR /&gt;service-object tcp destination eq https&lt;BR /&gt;service-object tcp destination eq 5090&lt;BR /&gt;service-object udp destination range 30000 30900&lt;BR /&gt;service-object udp destination range 40000 40900&lt;BR /&gt;service-object udp destination eq 5070&lt;BR /&gt;service-object udp destination eq 5080&lt;BR /&gt;object-group service DM_INLINE_SERVICE_6&lt;BR /&gt;service-object tcp destination eq https&lt;BR /&gt;service-object tcp-udp destination eq domain&lt;BR /&gt;service-object tcp destination eq www&lt;BR /&gt;object-group service DM_INLINE_TCP_1 tcp&lt;BR /&gt;port-object eq www&lt;BR /&gt;port-object eq https&lt;BR /&gt;object-group service DM_INLINE_TCP_2 tcp&lt;BR /&gt;port-object eq www&lt;BR /&gt;port-object eq https&lt;BR /&gt;access-list inside_access_in extended permit ip any any&lt;BR /&gt;access-list inbound extended permit tcp any object internal-webserver object-group DM_INLINE_TCP_2 log debugging&lt;BR /&gt;access-list inbound extended permit object-group DM_INLINE_SERVICE_2 any object dect-gateway log debugging inactive&lt;BR /&gt;access-list DMZ_access_in extended permit tcp any object internal-webserver object-group DM_INLINE_TCP_1&lt;BR /&gt;access-list DMZ_access_in extended permit object-group DM_INLINE_SERVICE_6 object internal-webserver any&lt;BR /&gt;access-list DMZ_access_in extended permit ip any any inactive&lt;BR /&gt;access-list inside_access_in_1 extended permit ip any any&lt;BR /&gt;access-list inside_access_in_1 extended permit object-group DM_INLINE_SERVICE_3 any object dect-gateway log debugging inactive&lt;BR /&gt;access-list guest_access_in extended permit ip any interface outsideSub&lt;BR /&gt;access-list telefon_access_in extended permit object-group DM_INLINE_SERVICE_1 any any&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu outside 1492&lt;BR /&gt;mtu outsideSub 1492&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu DMZ 1500&lt;BR /&gt;mtu guest 1500&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;no arp permit-nonconnected&lt;BR /&gt;!&lt;BR /&gt;object network obj_any&lt;BR /&gt;nat (any,outsideSub) dynamic interface&lt;BR /&gt;object network internal-webserver&lt;BR /&gt;nat (DMZ,outsideSub) static interface service tcp https https&lt;BR /&gt;!&lt;BR /&gt;nat (inside,outsideSub) after-auto source dynamic any interface&lt;BR /&gt;nat (DMZ,outsideSub) after-auto source dynamic any interface&lt;BR /&gt;nat (guest,outsideSub) after-auto source dynamic any interface&lt;BR /&gt;access-group inbound in interface outsideSub&lt;BR /&gt;access-group inside_access_in_1 in interface inside&lt;BR /&gt;access-group DMZ_access_in in interface DMZ&lt;BR /&gt;route outsideSub 0.0.0.0 0.0.0.0 87.140.26.169 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout pat-xlate 0:00:30&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;timeout floating-conn 0:00:00&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.178.0 255.255.255.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;service sw-reset-button&lt;BR /&gt;crypto ipsec security-association pmtu-aging infinite&lt;BR /&gt;crypto ca trustpoint ASDM_Launcher_Access_TrustPoint_0&lt;BR /&gt;enrollment self&lt;BR /&gt;fqdn none&lt;BR /&gt;subject-name CN=192.168.178.1,CN=firewall&lt;BR /&gt;keypair ASDM_LAUNCHER&lt;BR /&gt;crl configure&lt;BR /&gt;crypto ca trustpool policy&lt;BR /&gt;crypto ca certificate chain ASDM_Launcher_Access_TrustPoint_0&lt;BR /&gt;certificate 213f335c&lt;BR /&gt;308202d2 308201ba a0030201 02020421 3f335c30 0d06092a 864886f7 0d010105&lt;BR /&gt;0500302b 3111300f 06035504 03130866 69726577 616c6c31 16301406 03550403&lt;BR /&gt;130d3139 322e3136 382e3137 382e3130 1e170d31 39303231 31303831 3332345a&lt;BR /&gt;170d3239 30323038 30383133 32345a30 2b311130 0f060355 04031308 66697265&lt;BR /&gt;77616c6c 31163014 06035504 03130d31 39322e31 36382e31 37382e31 30820122&lt;BR /&gt;300d0609 2a864886 f70d0101 01050003 82010f00 3082010a 02820101 00b8ce18&lt;BR /&gt;cf8bf6f6 dd3ee4fb a4dfe76c 4fe03a80 f81cd905 e46d54f9 f012b3ef a7b1b18e&lt;BR /&gt;986a25c1 72e2958e 358069bc 19cb4f82 6c64ae3e 093c5728 d459f866 6f96236a&lt;BR /&gt;510542c1 31fa49da 3abda6f9 9fd94928 f50cd6e4 0efd84e7 347f347b 599cffe4&lt;BR /&gt;ffc329ab 20e73469 4eea0f70 eccbbfe9 8b836d74 308d2726 141b774e bfc67f7b&lt;BR /&gt;01fd29f3 95270e96 1f772697 f860eb11 7e0686a7 d3a67ddf 1bc9d1f1 dfd8e56b&lt;BR /&gt;0dd0383b 77450eae d40e73b1 42eaa054 bdf1df88 bce74fa3 786577f4 761e2bb5&lt;BR /&gt;a7a64f7f bd438ccd a17fb35c 2259eb15 6e7fae71 41f7a8f2 1bcf7de0 1d681b31&lt;BR /&gt;67c3accc 8f335083 c1c785aa 287efa1b 001f9364 9ca24063 1df21744 0d020301&lt;BR /&gt;0001300d 06092a86 4886f70d 01010505 00038201 010005c6 2bb39f28 b70fc7f0&lt;BR /&gt;a36607a8 2548e727 f15ac207 fb9158dc 2d40b205 01bbdfca a400a80d f7ceddf9&lt;BR /&gt;9e970bb2 1ea6f27c 5abf5213 36c6e0bb da17f51f 11b57d6a 1a23d549 1da464b0&lt;BR /&gt;4eb0b2a9 8930c91d c4cab838 0467fe35 222fe4b1 8b1341a6 ea83f447 f415300e&lt;BR /&gt;c1d4307e 3ae79b83 99800943 6a1dfd1c 22f3313b cc16ad04 852268b0 d028aa16&lt;BR /&gt;b50ce50a bc6b7060 db1e01c4 c76395b4 cdfee801 a1d3a9f4 74398b92 cba196cf&lt;BR /&gt;8fca0659 305b10f7 fee4e90a 00ec7220 6401044c c20cd391 74cd12db acc1427f&lt;BR /&gt;d6d5f324 f5b15a43 b97eb21e 07fac702 81aed9a9 1828acae 91702b57 994e3618&lt;BR /&gt;3c2e2e50 55bb0fc3 18da4c73 399d0c17 830a9389 b679&lt;BR /&gt;quit&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 192.168.178.0 255.255.255.0 inside&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh key-exchange group dh-group14-sha1&lt;BR /&gt;console timeout 0&lt;BR /&gt;vpdn group telekom request dialout pppoe&lt;BR /&gt;vpdn group telekom ppp authentication pap&lt;/P&gt;&lt;P&gt;dhcpd dns 217.69.169.25&lt;BR /&gt;dhcpd auto_config inside&lt;BR /&gt;dhcpd option 3 ip 192.168.5.1&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 192.168.5.2-192.168.5.254 guest&lt;BR /&gt;dhcpd dns 217.69.169.25 interface guest&lt;BR /&gt;dhcpd enable guest&lt;BR /&gt;!&lt;BR /&gt;ntp server 188.68.54.53 source outsideSub&lt;BR /&gt;ssl trust-point ASDM_Launcher_Access_TrustPoint_0&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;username admin password WRN6n6ecK1px5qbL encrypted privilege 15&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;parameters&lt;BR /&gt;message-length maximum client auto&lt;BR /&gt;message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;inspect dns preset_dns_map&lt;BR /&gt;inspect ftp&lt;BR /&gt;inspect h323 h225&lt;BR /&gt;inspect h323 ras&lt;BR /&gt;inspect rsh&lt;BR /&gt;inspect rtsp&lt;BR /&gt;inspect esmtp&lt;BR /&gt;inspect sqlnet&lt;BR /&gt;inspect skinny&lt;BR /&gt;inspect sunrpc&lt;BR /&gt;inspect xdmcp&lt;BR /&gt;inspect sip&lt;BR /&gt;inspect netbios&lt;BR /&gt;inspect tftp&lt;BR /&gt;inspect ip-options&lt;BR /&gt;inspect icmp&lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context&lt;BR /&gt;no call-home reporting anonymous&lt;BR /&gt;Cryptochecksum:2e518b4508919eb399ce4cb4eae31eca&lt;BR /&gt;: end&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are two screenshots to clearify the problem/configuration:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bildschirmfoto 2019-07-03 um 15.47.36.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/40115iD64391B47358DFA2/image-size/large?v=v2&amp;amp;px=999" role="button" title="Bildschirmfoto 2019-07-03 um 15.47.36.png" alt="Bildschirmfoto 2019-07-03 um 15.47.36.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bildschirmfoto 2019-07-03 um 15.53.04.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/40116iA984E48F40DE7047/image-size/large?v=v2&amp;amp;px=999" role="button" title="Bildschirmfoto 2019-07-03 um 15.53.04.png" alt="Bildschirmfoto 2019-07-03 um 15.53.04.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The NAT rules or routes were not changed explicitly!&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only change that has been done was changing the internalSub PPPoE setting to "use a static IP".&lt;/P&gt;&lt;P&gt;We did not have internet connection with the static IP, so we switched the iface setting back to PPPoE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ever since, the NATing/routing problem exists.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately, there are no configuration backups and the config was written to flash...&lt;/P&gt;&lt;P&gt;We'd really appreciate your help!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;EDIT: The issue was that "VTEP source interface" was checked in the virtual interface settings.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/solved-asa5506-internal-network-not-routed-via-public-pppoe/m-p/3884710#M5901</guid>
      <dc:creator>rfzt</dc:creator>
      <dc:date>2020-02-21T17:16:41Z</dc:date>
    </item>
  </channel>
</rss>

