<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Am I in over my head...... in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516737#M626423</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no worries, even i learnt it by questioning, it&lt;/P&gt;&lt;P&gt;feels good when one tries to learn rather than just implement what one says&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anyways coming back,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;teh default gateway still looks incorrect because it looks like you have given the internal loopback ip address as default gateway&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your default gateway would be the ip address of the interface on isp router which is connected to asa, if you are unsure you can conatct the isp guys and they will help you figure that out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also other option is see if you can configure it as pppoe server or dhcp server so that we can configure asa to get ip address and default gateway from the modem itself&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Sep 2010 16:31:10 GMT</pubDate>
    <dc:creator>Jitendriya Athavale</dc:creator>
    <dc:date>2010-09-29T16:31:10Z</dc:date>
    <item>
      <title>Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516723#M626405</link>
      <description>&lt;P&gt;I have read a ton of stuff on this forum....WOW....great work by everyone contributing...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My initial question is how should I go about learning/familiarizing myself on how to properly configure cisco products?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what I want to do with what I have.&lt;/P&gt;&lt;P&gt;I have a one asa 5510 and three asa 5505.&amp;nbsp; The goal is to have the asa 5510 at our main office then the 5505 at each remote office.&amp;nbsp; Then establish a vpn connection to the server at the main office. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I HAVE ZERO cisco experience.....and only know the basics in network.&amp;nbsp; So am I way in over my head or can make this happen????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far I have bridged my isp provided modem to my asa 5510.&amp;nbsp; On the asa 5510 I have established my outside and inside interfaces.&amp;nbsp; But I have not been able to establish a simple internet connection thru the asa 5510.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help and suggestions is greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:43:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516723#M626405</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2019-03-11T18:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516724#M626406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;toddyboman wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have read a ton of stuff on this forum....WOW....great work by everyone contributing...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My initial question is how should I go about learning/familiarizing myself on how to properly configure cisco products?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what I want to do with what I have.&lt;/P&gt;&lt;P&gt;I have a one asa 5510 and three asa 5505.&amp;nbsp; The goal is to have the asa 5510 at our main office then the 5505 at each remote office.&amp;nbsp; Then establish a vpn connection to the server at the main office. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I HAVE ZERO cisco experience.....and only know the basics in network.&amp;nbsp; So am I way in over my head or can make this happen????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far I have bridged my isp provided modem to my asa 5510.&amp;nbsp; On the asa 5510 I have established my outside and inside interfaces.&amp;nbsp; But I have not been able to establish a simple internet connection thru the asa 5510.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help and suggestions is greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, there is a ton of documentation avaailable on the Cisco site especially for VPNs that give step by step config guides so we can point you to those when you want to setup the VPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But first we need to get your ASAs setup so you have internet access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So a few questions -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) can you post config of ASA 5510 and remove any sensitive info ie. public IP addresses etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) how are you testing internet connectivity ie. what is the source IP and where is it in relation to the ASA and what is the destination IP and are you using ping or trying to connect to a web site etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) From the ASA itself can you ping the ISP gateway&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Sep 2010 10:17:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516724#M626406</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-09-23T10:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516725#M626407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First to set up the internet connectivity :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you configured the nat rules and the route commands ?&lt;/P&gt;&lt;P&gt;Nat rules would like (assuming you are translating all the inside ip to the outside interface ip) :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510(config)# global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510(config)# nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also you need to point the default gateway to the isp :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5510(config)# route outside 0.0.0.0 0.0.0.0 &lt;ISP ip=""&gt;&lt;/ISP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do tell me how it goes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rahul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Sep 2010 13:01:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516725#M626407</guid>
      <dc:creator>rmavila</dc:creator>
      <dc:date>2010-09-23T13:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516726#M626408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you both for a prompt reply!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would love to post my configurations.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but its all gone......I had my inside/outside/mgmt/ nat and routes all set up last night.....&lt;/P&gt;&lt;P&gt;NO everything wasn't functioning properly but I had it all set.......now I log in this morning and its like I am logging in the first time.....The only interface I have is mgmt.&amp;nbsp; What did I do wrong???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My set up is as follows...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;internet............isp given modem.......asa5510........basic switch/hub.......all office pc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I currently have been doing all my setup/configurations through the ASDM launcher.&amp;nbsp; However I see almost everyone used the command line.......Why?&amp;nbsp; How can I properly connect to the asa and use the command line features?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Sep 2010 16:06:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516726#M626408</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-09-23T16:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516727#M626409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;here is the link to setup vpn ising asdm&lt;/P&gt;&lt;P&gt;since this is a new setup i would suggest setup the vpn using the wizard it will take you 1 to 2 mins to setup vpn on both ends&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now regarding initial config for your asa box, here is a example config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is for asa 5505&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 11pt; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; color: #1f497d;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt;ExampleASA(config)# username example password example privilege 15 &lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN class="postbody"&gt;ExampleASA(config)#&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt;ExampleASA(config)# interface vlan 1 &lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN class="postbody"&gt;ExampleASA(config-if)# ip address 192.168.1.1 255.255.255.0 &lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN class="postbody"&gt;ExampleASA(config-if)# nameif inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt;ExampleASA(config)# interface vlan 2 &lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN class="postbody"&gt;ExampleASA(config-if)# ip address 212.115.192.x 255.255.255.248 &lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN class="postbody"&gt;ExampleASA(config-if)# nameif outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt;ExampleASA(config-if)# exit &lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN class="postbody"&gt;ExampleASA(config)# route outside 0.0.0.0 0.0.0.0 212.115.192.y&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt;ExampleASA(config)# interface ethernet0/0 &lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN class="postbody"&gt;ExampleASA(config-if)# switchport access vlan 2 &lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN class="postbody"&gt;ExampleASA(config-if)# no shutdown&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt;ExampleASA(config)# interface ethernet0/1 &lt;/SPAN&gt;&lt;BR /&gt; &lt;SPAN class="postbody"&gt;ExampleASA(config-if)# no shutdown&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt;ExampleASA(config)# nat (inside) 10 192.168.1.0 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt;ExampleASA(config)# global (outside) 10 interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;if you are getting ip via dhcp then instead of giving ip address on asa give the following command&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;ip address dhcp set route&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;for asa 5510 only thing that is different is that you will be entering the ip address commands on interface and not on vlans as they have L3 ports, for example&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;int e0/0&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;ip address x.x.x.x y.y.y.y&lt;/P&gt;&lt;P class="MsoNormal"&gt;nameif inside&lt;/P&gt;&lt;P class="MsoNormal"&gt;no shut&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;for asdm and ssh access&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN class="postbody"&gt;ExampleASA(config)# crypto key generate rsa&amp;nbsp; modulus 1024&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE align="center" border="0" cellpadding="3" cellspacing="1" width="90%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="code"&gt;ExampleASA(config)#&amp;nbsp; aaa authentication ssh console LOCAL&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE align="center" border="0" cellpadding="3" cellspacing="1" style="width: 788px; height: 87px;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="code"&gt;&lt;P&gt;&lt;SPAN class="postbody"&gt;ExampleASA(config)# ssh 192.168.1.0 255.255.255.0&amp;nbsp; inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="postbody"&gt;ExampleASA(config)# http server enable&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN class="postbody"&gt;ExampleASA(config)# aaa authentication http&amp;nbsp; console LOCAL &lt;BR /&gt; ExampleASA(config)# http 192.168.1.0 255.255.255.0 inside&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Sep 2010 16:37:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516727#M626409</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-09-23T16:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516728#M626410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a sample LAN-to-LAN VPN configuration, which it seems is what you are trying to configure:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/products/ps6120/products_configuration_example09186a0080950890.shtml"&gt;http://www.cisco.com/en/US/partner/products/ps6120/products_configuration_example09186a0080950890.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To save your configuration, you have to issue the command "write memory" or "copy run start".&amp;nbsp; This will save the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Sep 2010 17:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516728#M626410</guid>
      <dc:creator>Allen P Chen</dc:creator>
      <dc:date>2010-09-23T17:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516729#M626411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks everyone for the replies......as always other "stuff" came up to fix so this was put aside for a few days.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is was my current configs........Still no connection to the Internet......So what all am I missing....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-508.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 7.0(8) &lt;BR /&gt;!&lt;BR /&gt;hostname L&lt;BR /&gt;domain-name default.domain.invalid&lt;BR /&gt;enable password ml encrypted&lt;BR /&gt;passwd 2 encrypted&lt;BR /&gt;names&lt;BR /&gt;dns-guard&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 111.111.111.11 255.255.255.252 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.10.1 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt; nameif management&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.1.5 255.255.255.0 &lt;BR /&gt; management-only&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu management 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;no failover&lt;BR /&gt;monitor-interface management&lt;BR /&gt;monitor-interface outside&lt;BR /&gt;monitor-interface inside&lt;BR /&gt;asdm image disk0:/asdm-508.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 111.1111.111.11 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00&lt;BR /&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;BR /&gt;timeout uauth 0:05:00 absolute&lt;BR /&gt;username admin password vx8BkOWfWwvYuBKw encrypted&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 management&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd address 192.168.1.6-192.168.1.254 management&lt;BR /&gt;dhcpd address 192.168.10.10-192.168.10.200 inside&lt;BR /&gt;dhcpd dns 200.200.200.10 &lt;BR /&gt;dhcpd lease 3600&lt;BR /&gt;dhcpd ping_timeout 50&lt;BR /&gt;dhcpd enable management&lt;BR /&gt;dhcpd enable inside&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns maximum-length 512 &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;Cryptochecksum: e&lt;BR /&gt;: end&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 05:57:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516729#M626411</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-09-28T05:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516730#M626412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;firstly your default gateway is wrong&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you have given it to be the same as your outside or external interface ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 111.1111.111.11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;secondly how are you testing internet connetivity if you are doing a ping test to internet it will not work bcoz you are not inspoecting icmp&lt;/P&gt;&lt;P&gt;try to browse or add this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and ping 4.2.2.2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 06:14:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516730#M626412</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-09-28T06:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516731#M626413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does your ISP require authentication to connect? Noticed you are bridging your DSL to your Firewall, so you probably need some PPOE config on your firewall:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080ab7ce9.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080ab7ce9.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Sep 2010 08:55:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516731#M626413</guid>
      <dc:creator>Brian O'Flynn</dc:creator>
      <dc:date>2010-09-29T08:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516732#M626414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Brian -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am confused and questioning my setup......&lt;/P&gt;&lt;P&gt;Do I have to bridge my router or not?&amp;nbsp; Should I bridge it to make the asa connect to the internet......or can I just simple let my isp given modem acquire my internet connection and then connect my asa to that and allow all stuff to run through the asa?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Sep 2010 15:24:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516732#M626414</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-09-29T15:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516733#M626415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can do the second alternative, use the isp given modem and&lt;/P&gt;&lt;P&gt; connect asa behind it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but the point we r getting to is how is your isp router set, if it is bridge mode you might have to set it up a different way and similarly if you have it i router mode we would look at it from a different point of view&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;may be this is confusing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in any case, can you please check the default gateway as per my previous post&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Sep 2010 15:37:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516733#M626415</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-09-29T15:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516734#M626416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can set the ips given modem either way......either bridge it or not.....Which way should I set it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Won't the default gateway depends on which way I set the modem???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Sep 2010 15:40:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516734#M626416</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-09-29T15:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516735#M626417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well you are rihgt it does depend, but the default gateway cannot be your self in any case and it is set that way currently your default gateway is your ip itself&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Sep 2010 15:49:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516735#M626417</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-09-29T15:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516736#M626418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry I am making this so challenging........I am learning a lot as I go.....So thanks so much for your time and help!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ok.....if I don't bridge my isp router......and go into my ips router settings.....I can find:&lt;/P&gt;&lt;P&gt;network routing tables and host routing tables.....both providing different gateways.... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my latest config....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-508.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 7.0(8) &lt;BR /&gt;!&lt;BR /&gt;hostname L&lt;BR /&gt;domain-name default.domain.invalid&lt;BR /&gt;enable password m encrypted&lt;BR /&gt;passwd m encrypted&lt;BR /&gt;names&lt;BR /&gt;dns-guard&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 111.111.111.11 255.255.255.252 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.10.1 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt; nameif management&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.1.5 255.255.255.0 &lt;BR /&gt; management-only&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu management 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;no failover&lt;BR /&gt;monitor-interface management&lt;BR /&gt;monitor-interface outside&lt;BR /&gt;monitor-interface inside&lt;BR /&gt;asdm image disk0:/asdm-508.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 127.0.0.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00&lt;BR /&gt;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;BR /&gt;timeout uauth 0:05:00 absolute&lt;BR /&gt;username 12 password v encrypted&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 management&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd address 192.168.1.6-192.168.1.254 management&lt;BR /&gt;dhcpd address 192.168.10.10-192.168.10.200 inside&lt;BR /&gt;dhcpd dns 200.200.200.10 &lt;BR /&gt;dhcpd lease 3600&lt;BR /&gt;dhcpd ping_timeout 50&lt;BR /&gt;dhcpd enable management&lt;BR /&gt;dhcpd enable inside&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns maximum-length 512 &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;&amp;nbsp; inspect icmp &lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;Cryptochecksum:f&lt;BR /&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Sep 2010 16:24:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516736#M626418</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-09-29T16:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516737#M626423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no worries, even i learnt it by questioning, it&lt;/P&gt;&lt;P&gt;feels good when one tries to learn rather than just implement what one says&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anyways coming back,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;teh default gateway still looks incorrect because it looks like you have given the internal loopback ip address as default gateway&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your default gateway would be the ip address of the interface on isp router which is connected to asa, if you are unsure you can conatct the isp guys and they will help you figure that out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also other option is see if you can configure it as pppoe server or dhcp server so that we can configure asa to get ip address and default gateway from the modem itself&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Sep 2010 16:31:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516737#M626423</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-09-29T16:31:10Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516738#M626425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sounds good....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the default gateway for my isp router is 192.168.1.1.&amp;nbsp; So this should be the default gateway i should input?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for configuring dhcp or ppoe I would set this on the outside interface or configure a new interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I set up ppoe with my verison of asa......My asa version is 7.0(8).......I thought I read somewhere I could only do ppoe for 8.X????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Sep 2010 16:52:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516738#M626425</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-09-29T16:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516739#M626427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;since it is a new setup i would recommend you go to the atleast 8.x code, bcoz 7.08 is ancient &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;coming back to the default gateway question let m egive you an example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if this is your interface ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;asa55(config-if)# ip address 212.115.192.x 255.255.255.248&lt;BR /&gt;asa55(config-if)# nameif outside&lt;BR /&gt;INFO: Security level for "outside" set to 0 by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;asa55(config-if)# exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your default gateway would be the following (basically in the same subnet)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;asa5505(config)# route outside 0.0.0.0 0.0.0.0 212.115.192.y&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from what you have sent me it looks like your modem has an internal ip in 192.168.1.x range and it is doing natting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so you need to put an ip to the outside interface in the same subnet and give it as the default gateway&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa-----------------------------isp modem/router--------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.x&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; public ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;correct me if this setup is wrong&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 00:21:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516739#M626427</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-09-30T00:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516740#M626428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;jathaval wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;since it is a new setup i would recommend you go to the atleast 8.x code, bcoz 7.08 is ancient &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WHY did i not do this update earlier......WOW.&amp;nbsp; &lt;SPAN __jive_emoticon_name="shocked" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="1" src="https://community.cisco.com/images/emoticons/shocked.gif" width="1"&gt;&lt;/SPAN&gt;&lt;SPAN __jive_emoticon_name="laugh" __jive_macro_name="emoticon" class="jive_macro jive_emote" height="1" src="https://community.cisco.com/images/emoticons/laugh.gif" width="1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;jathaval wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;coming back to the default gateway question let m egive you an example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if this is your interface ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;asa55(config-if)# ip address 212.115.192.x 255.255.255.248&lt;BR /&gt;asa55(config-if)# nameif outside&lt;BR /&gt;INFO: Security level for "outside" set to 0 by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;asa55(config-if)# exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your default gateway would be the following (basically in the same subnet)&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;asa5505(config)# route outside 0.0.0.0 0.0.0.0 212.115.192.y&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from what you have sent me it looks like your modem has an internal ip in 192.168.1.x range and it is doing natting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so you need to put an ip to the outside interface in the same subnet and give it as the default gateway&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa-----------------------------isp modem/router--------------------------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.x&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; public ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;correct me if this setup is wrong&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;YES my asa is 192.168.1.x&lt;/P&gt;&lt;P&gt;Yes my isp/modem/router is 192.168.1.1&lt;/P&gt;&lt;P&gt;Then my isp has provided me with 2 static ips......we will call them 111.111.111.111 and 222.222.222.222&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WOW really missing the boat on this default gateway.......&lt;/P&gt;&lt;P&gt;BEFORE I started this project a simple ipconfig on any machine shows a default gateway of 192.168.1.1....which is the ip of my isp/modem/router......&lt;/P&gt;&lt;P&gt;My isp guys say that gateway is my first static ip.........so IF i configure my outside interface as a ppoe and make it obtain an IP using ppoe then will I make my gateway my first static ip (111.111.111.111).......&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 03:42:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516740#M626428</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-09-30T03:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516741#M626429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you configure your asa to get ip from pppoe you can also configure it such that it gets its default gateway from th eisp rputer&lt;/P&gt;&lt;P&gt;so we wont have to bother about default gateway as the modem is going to puch it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you using static's ip's (which is the current setup), then change the default gateway to 192.168.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and you should be up and running&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also when you say you connect your PC to this mdem your PC gets an ip with defaukt gateway as 192.168.1.1, it gives me a feeling that your modem is behaving like a dhcp server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 03:49:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516741#M626429</guid>
      <dc:creator>Jitendriya Athavale</dc:creator>
      <dc:date>2010-09-30T03:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: Am I in over my head......</title>
      <link>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516742#M626430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks again for all your help.......&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;jathaval wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also when you say you connect your PC to this mdem your PC gets an ip with defaukt gateway as 192.168.1.1, it gives me a feeling that your modem is behaving like a dhcp server&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My modem does have a dhcp option.....should this be diabled?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is my current config......with my router NOT bridged........giving my asa outside interface a static IP.......no PPOE configurations on my ASA.........&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 8.0(5) &lt;BR /&gt;!&lt;BR /&gt;hostname L&lt;BR /&gt;domain-name default.domain.invalid&lt;BR /&gt;enable password m encrypted&lt;BR /&gt;passwd U encrypted&lt;BR /&gt;names&lt;BR /&gt;dns-guard&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 111.111.111.111 255.255.255.252 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.10.1 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt; nameif management&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.1.5 255.255.255.0 &lt;BR /&gt; management-only&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CST -6&lt;BR /&gt;clock summer-time CDT recurring&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt; domain-name default.domain.invalid&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu management 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-631.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 192.168.1.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 management&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd dns 192.168.10.1&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 192.168.10.5-192.168.10.25 inside&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 192.168.1.6-192.168.1.10 management&lt;BR /&gt;dhcpd enable management&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;username admin password vx8BkOWfWwvYuBKw encrypted&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns migrated_dns_map_1&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns migrated_dns_map_1 &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;&amp;nbsp; inspect icmp &lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;Cryptochecksum:6db9429f9cba9424fccd50647514ae9a&lt;BR /&gt;: end&lt;BR /&gt;asdm image disk0:/asdm-631.bin&lt;BR /&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to the ARP table on the ASDM some of my office pc's where connected to the mgmt interface.....and not the inside interface.&amp;nbsp; (Which I thought was odd?)&amp;nbsp; ........but those pc's couldn't establish an internet connection.....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Sep 2010 14:35:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/am-i-in-over-my-head/m-p/1516742#M626430</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-09-30T14:35:09Z</dc:date>
    </item>
  </channel>
</rss>

