<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't Connect to Internet through ASA 5510.... in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542411#M635889</link>
    <description>&lt;P&gt;Any help would be great......I have made several changes but can't seem to connect to the internet......&lt;/P&gt;&lt;P&gt;I am very new to the cisco and asa world....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;SPAN __jive_emoticon_name="cool" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/cool.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my config file...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 8.0(5) &lt;BR /&gt;!&lt;BR /&gt;hostname asa&lt;BR /&gt;enable password m encrypted&lt;BR /&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address dhcp setroute &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.10.1 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;nameif management&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.1.5 255.255.255.0 &lt;BR /&gt;management-only&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa805-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CST -6&lt;BR /&gt;clock summer-time CDT recurring&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu management 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-631.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (inside) 101 interface&lt;BR /&gt;global (outside) 1 111.111.111.11&lt;BR /&gt;nat (inside) 1 192.168.10.0 255.255.255.0&lt;BR /&gt;nat (inside) 101 0.0.0.0 0.0.0.0&lt;BR /&gt;nat (outside) 101 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 192.168.10.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 management&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd address 192.168.1.6-192.168.1.254 management&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 192.168.10.2-192.168.10.30 inside&lt;BR /&gt;dhcpd enable inside&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;username asa password v encrypted&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;Cryptochecksum:6f11e3619456492d465bbbec26ff930d&lt;BR /&gt;: end&lt;BR /&gt;asdm image disk0:/asdm-631.bin&lt;BR /&gt;no asdm history enable&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 18:52:03 GMT</pubDate>
    <dc:creator>toddyboman</dc:creator>
    <dc:date>2019-03-11T18:52:03Z</dc:date>
    <item>
      <title>Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542411#M635889</link>
      <description>&lt;P&gt;Any help would be great......I have made several changes but can't seem to connect to the internet......&lt;/P&gt;&lt;P&gt;I am very new to the cisco and asa world....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;SPAN __jive_emoticon_name="cool" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/cool.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my config file...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 8.0(5) &lt;BR /&gt;!&lt;BR /&gt;hostname asa&lt;BR /&gt;enable password m encrypted&lt;BR /&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt;nameif outside&lt;BR /&gt;security-level 0&lt;BR /&gt;ip address dhcp setroute &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;nameif inside&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.10.1 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;shutdown&lt;BR /&gt;no nameif&lt;BR /&gt;no security-level&lt;BR /&gt;no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt;nameif management&lt;BR /&gt;security-level 100&lt;BR /&gt;ip address 192.168.1.5 255.255.255.0 &lt;BR /&gt;management-only&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa805-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CST -6&lt;BR /&gt;clock summer-time CDT recurring&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu management 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-631.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (inside) 101 interface&lt;BR /&gt;global (outside) 1 111.111.111.11&lt;BR /&gt;nat (inside) 1 192.168.10.0 255.255.255.0&lt;BR /&gt;nat (inside) 101 0.0.0.0 0.0.0.0&lt;BR /&gt;nat (outside) 101 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 192.168.10.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 management&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd address 192.168.1.6-192.168.1.254 management&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 192.168.10.2-192.168.10.30 inside&lt;BR /&gt;dhcpd enable inside&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;username asa password v encrypted&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt;parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;Cryptochecksum:6f11e3619456492d465bbbec26ff930d&lt;BR /&gt;: end&lt;BR /&gt;asdm image disk0:/asdm-631.bin&lt;BR /&gt;no asdm history enable&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:52:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542411#M635889</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2019-03-11T18:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542412#M635890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please remove the following as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no global (inside) 101 interface&lt;BR /&gt;no global (outside) 1 111.111.111.11&lt;BR /&gt;no nat (inside) 1 192.168.10.0 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;no nat (outside) 101 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;no route outside 0.0.0.0 0.0.0.0 192.168.10.1 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And add the following:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;global (outside) 101 interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After the above changes, please "clear xlate".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the output of "show route" and makes sure that you have default gateway set by your ISP via the DHCP setroute command on the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 03:57:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542412#M635890</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-10-08T03:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542413#M635891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok I made those changes.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I enter the &lt;STRONG&gt;show route &lt;/STRONG&gt;I recieve the following....&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Gateway of last resort is not set&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;c&amp;nbsp; 192.168.10.0 255.255.255.0 is directly connected, inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;c&amp;nbsp; 192.168.1.0&amp;nbsp;&amp;nbsp; 255.255.255.0 is directly connected, management&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 04:09:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542413#M635891</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-10-08T04:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542414#M635892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, that means your outside interface doesn't seem to get the default gateway from your ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How is the connection to the ISP? is it supposed to be DHCP assigned address? Are you getting IP Address on the outside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check "show interface" to see if you are getting ip address on the Outside interface.&lt;/P&gt;&lt;P&gt;If not, please try shut/unshut the interface:&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; shut&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; no ip address&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ip address dhcp setroute&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And check the interface again and route.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 04:14:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542414#M635892</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-10-08T04:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542415#M635893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My connection is.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP provided dsl modem &amp;lt;-------&amp;gt; asa outside interface&lt;/P&gt;&lt;P&gt;asa inside interface &amp;lt;------------&amp;gt; internal switch&lt;/P&gt;&lt;P&gt;internal switch &amp;lt;--------------&amp;gt; office pc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DHCP is how my isp provide modem is currently set.......I can change it and will change it to whatever will make it work. &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I made the changes as you suggested and recieved the following...&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show route &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Gateway of last resort is not set&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.10.0 255.255.255.0 is directly connected, inside&lt;BR /&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.0 255.255.255.0 is directly connected, management&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 04:22:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542415#M635893</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-10-08T04:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542416#M635894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Why dont you try and set a static route in asa pointing towards the dsl modem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Raja&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 04:44:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542416#M635894</guid>
      <dc:creator>lalarajaraman1985</dc:creator>
      <dc:date>2010-10-08T04:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542417#M635895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post a : show inter ip brie&lt;/P&gt;&lt;P&gt;and debug dhcpc event&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for the debug you must add first :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging buffered 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 04:54:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542417#M635895</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2010-10-08T04:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542418#M635896</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;show inter ip brie.......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP-Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK? Method Status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Protocol&lt;BR /&gt;Ethernet0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES DHCP&amp;nbsp;&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;Ethernet0/1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.10.1&amp;nbsp;&amp;nbsp;&amp;nbsp; YES manual up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;Ethernet0/2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; administratively down down&lt;BR /&gt;Ethernet0/3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; administratively down down&lt;BR /&gt;Management0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.1.5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES CONFIG up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 12:56:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542418#M635896</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-10-08T12:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542419#M635897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you know from what class should you receive the dynamic IP ( the problem might be that&lt;/P&gt;&lt;P&gt;you should receive an IP from 192.168.1 or 192.168&lt;BR /&gt;.10 ) because the interface configuration is ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any logs like : Failed to apply IP address to&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW enable your logging &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 13:05:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542419#M635897</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2010-10-08T13:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542420#M635898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;dancicioiu wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and debug dhcpc event&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for the debug you must add first :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging buffered 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can't seem to make this command work......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa(config)# debug dhcpc event&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;BR /&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 13:23:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542420#M635898</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-10-08T13:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542421#M635899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug dhcpc detail&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 13:24:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542421#M635899</guid>
      <dc:creator>Dan-Ciprian Cicioiu</dc:creator>
      <dc:date>2010-10-08T13:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542422#M635900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;asa(config)# debug dhcpc detail&lt;/P&gt;&lt;P&gt;debug dhcpc detail enabled at level 1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 13:29:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542422#M635900</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-10-08T13:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542423#M635901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i'm starting to wonder if there isn't something configured/set up wrong within my ISP provided modem.......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently I have done nothing differently with it.....except hook the asa into it.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I change something within it?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I have conntacted my isp so I do have my static IP but I have not done anything with them......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for everyone's help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Oct 2010 13:34:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542423#M635901</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-10-08T13:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542424#M635902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you received static IP address from your ISP, you should just configure the static ip address on your ASA outside interface instead of DHCP.&lt;/P&gt;&lt;P&gt;Then you would also need to configure default route on the ASA to point to your ISP IP address. Internet should work after that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 09 Oct 2010 00:26:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542424#M635902</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-10-09T00:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542425#M635903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry was a long holiday weekend......and I elected to take the entire weekend off.......&lt;SPAN __jive_emoticon_name="cool" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/cool.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Back to work now.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my running config.......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something still isn't quite right........&lt;/P&gt;&lt;P&gt;I have a feeling it has to do with my my configuration of my route to point to my ISP IP address........&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.0(5) &lt;BR /&gt;!&lt;BR /&gt;hostname l&lt;BR /&gt;enable password l encrypted&lt;BR /&gt;passwd 2 encrypted&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 111.111.111.11 255.255.255.252 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.10.1 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt; nameif management&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.1.5 255.255.255.0 &lt;BR /&gt; management-only&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa805-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CST -6&lt;BR /&gt;clock summer-time CDT recurring&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging buffered alerts&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu management 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-631.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 101 interface&lt;BR /&gt;nat (inside) 101 0.0.0.0 0.0.0.0&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 192.168.10.1 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 management&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd address 192.168.1.6-192.168.1.254 management&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 192.168.10.2-192.168.10.30 inside&lt;BR /&gt;dhcpd enable inside&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;username admin password vx8BkOWfWwvYuBKw encrypted&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;Cryptochecksum:270ddeeb0289103b45bfa08f20419bba&lt;BR /&gt;: end&lt;BR /&gt;asdm image disk0:/asdm-631.bin&lt;BR /&gt;no asdm history enable&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Oct 2010 21:18:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542425#M635903</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-10-12T21:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542426#M635904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great to hear you are enjoying your weekend &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default gateway for the ASA is incorrect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems incorrect that your outside interface ip addres is 111.111.111.11 (with a /30 mask, 111.111.111.11 would be a broadcast address). Can you please double check with your ISP the actual ip address? Unless you are masking the ip address for privacy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following default gateway configured is incorrect:&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 192.168.10.1 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;192.168.10.1 is your ASA inside interface. By configuring default gateway towards the ASA inside interface, the traffic will not go out to the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need to remove the above, and configure the next hop ip address towards your ISP (would be in the same subnet as your ASA outside interface given by your ISP). Please check with your ISP what should be the ASA default gateway, then configure the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 &lt;ISP-IP-ADDRESS&gt;&lt;/ISP-IP-ADDRESS&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Oct 2010 23:50:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542426#M635904</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-10-12T23:50:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542427#M635905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I did mask my ISP given static ip for privacy reason.....so the 111.111.111.11 is fake ip......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They have given me 2 static ip addresses.....for privacy purposes I will use&lt;/P&gt;&lt;P&gt;111.111.111.11 and 222.222.222.22.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So are you saying my outsider interface should read&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface Ethernet0/0&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 111.111.111.11 255.255.255.252&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then my route will read the following.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;route outside 0.0.0.0 0.0.0.0 111.111.111.11 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to my ISP my default gateway is my First Static IP so using the a fake static ip's from above my default gateway would be 111.111.111.11.....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Oct 2010 03:29:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542427#M635905</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-10-13T03:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542428#M635906</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Oct 2010 14:41:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542428#M635906</guid>
      <dc:creator>Rudresh Veerappaji</dc:creator>
      <dc:date>2010-10-13T14:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542429#M635907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Consider the below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;111.111.111.12&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ------&amp;gt; ip address of the Gateway (i.e ISP router ip address,) and&lt;/P&gt;&lt;P&gt;111.111.111.11&amp;nbsp;&amp;nbsp; --------&amp;gt; ip address that needs to be assigned to the ASA,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internal network-------(inside)ASA(outside)-------------------------(111.111.111.12 )ISP Router----------INTERNET&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (111.111.111.11)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the above is the setup, you need the following configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;interface Ethernet0/0&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address &lt;/STRONG&gt;111.111.111.11&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp; &lt;STRONG&gt;255.255.255.252&amp;nbsp; &lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;STRONG&gt;route outside 0.0.0.0 0.0.0.0 111.111.111.12 1&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this works,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Rudresh V&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Oct 2010 14:43:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542429#M635907</guid>
      <dc:creator>Rudresh Veerappaji</dc:creator>
      <dc:date>2010-10-13T14:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Connect to Internet through ASA 5510....</title>
      <link>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542430#M635908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;do I need to configure my outside interface to accept or handle a ppoe connection.....since that is what my current isp provided modem/router does?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so I would assume I need to bridge my ISP provided router.....then add the static ip and my ppoe configurations to my outside interface....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe I do have those configurations.......I changed it to that way last night.......&lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;However I still can't connected.....&lt;SPAN __jive_emoticon_name="cry" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/cry.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my config file......&amp;nbsp; I obviously have hidden my static ips.....but I have 2 one is xxx.xxx.xxx.13 and the other is xxx.xxx.xxx.14 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 8.0(5) &lt;BR /&gt;!&lt;BR /&gt;hostname x&lt;BR /&gt;enable password mrNAzLB3WoDGll7l encrypted&lt;BR /&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address xxx.xxx.xxx.14 255.255.255.252 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.10.1 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt; nameif management&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.1.5 255.255.255.0 &lt;BR /&gt; management-only&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa805-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone CST -6&lt;BR /&gt;clock summer-time CDT recurring&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging enable&lt;BR /&gt;logging buffered alerts&lt;BR /&gt;logging asdm informational&lt;BR /&gt;logging debug-trace&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu management 1500&lt;BR /&gt;no failover&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-631.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 101 interface&lt;BR /&gt;nat (inside) 101 0.0.0.0 0.0.0.0&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 xxx.xxx.xxx.13 1&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;timeout tcp-proxy-reassembly 0:01:00&lt;BR /&gt;dynamic-access-policy-record DfltAccessPolicy&lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;http server enable&lt;BR /&gt;http 192.168.1.0 255.255.255.0 management&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd address 192.168.10.2-192.168.10.30 inside&lt;BR /&gt;dhcpd enable inside&lt;BR /&gt;!&lt;BR /&gt;dhcpd address 192.168.1.6-192.168.1.47 management&lt;BR /&gt;!&lt;BR /&gt;threat-detection basic-threat&lt;BR /&gt;threat-detection statistics access-list&lt;BR /&gt;no threat-detection statistics tcp-intercept&lt;BR /&gt;username admin password vx8BkOWfWwvYuBKw encrypted&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;Cryptochecksum:411b6627479dcd14b847fdf03cf5b90f&lt;BR /&gt;: end&lt;BR /&gt;asdm image disk0:/asdm-631.bin&lt;BR /&gt;no asdm history enable&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Oct 2010 15:01:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-connect-to-internet-through-asa-5510/m-p/1542430#M635908</guid>
      <dc:creator>toddyboman</dc:creator>
      <dc:date>2010-10-13T15:01:25Z</dc:date>
    </item>
  </channel>
</rss>

