<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New Subnet Requiring Internet Access via ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455064#M680887</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post up a new copy of your configuration of your firewall please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will help us help you with the changes needed to get the internet working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kimberly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 May 2010 14:03:56 GMT</pubDate>
    <dc:creator>Kimberly Adams</dc:creator>
    <dc:date>2010-05-14T14:03:56Z</dc:date>
    <item>
      <title>New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455050#M680873</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our current network only has a handful of vlans with vlan1 with an ip range for PC's and servers of 10.255.0.0 255.255.0.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have started to create new Vlans and our first test one is VLAN2 with an IP address range of 10.254.25.0/24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a new 6500 switch and the subnet and dhcp is created on that with a static default gateway set to our firewall of 10.255.251.211.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the firewall for testing purposes has an any any rule allowing everyone internally access out to the internet (or so I thought)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently anyone on the 10.255.0.0 range has internet access, those on the 10.254.25.0 range don't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have I missed something on the firewall config for this new subnet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:44:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455050#M680873</guid>
      <dc:creator>drikilbride</dc:creator>
      <dc:date>2019-03-11T17:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455051#M680874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;drikilbride wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our current network only has a handful of vlans with vlan1 with an ip range for PC's and servers of 10.255.0.0 255.255.0.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have started to create new Vlans and our first test one is VLAN2 with an IP address range of 10.254.25.0/24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a new 6500 switch and the subnet and dhcp is created on that with a static default gateway set to our firewall of 10.255.251.211.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the firewall for testing purposes has an any any rule allowing everyone internally access out to the internet (or so I thought)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently anyone on the 10.255.0.0 range has internet access, those on the 10.254.25.0 range don't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have I missed something on the firewall config for this new subnet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need a route added so the firewall knows how to send the return traffic back ie.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 10.254.0.0 255.255.255.0&amp;nbsp; &lt;VLAN 1="" interface="" ip="" on="" the="" 6500="" ie.="" 10.255.x.x=""&gt;&lt;/VLAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 May 2010 09:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455051#M680874</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-05-12T09:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455052#M680875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I would need to add&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 10.254.0.0 255.255.255..0 10.255.250.51&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a mil!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 May 2010 09:48:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455052#M680875</guid>
      <dc:creator>drikilbride</dc:creator>
      <dc:date>2010-05-12T09:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455053#M680876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;drikilbride wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I would need to add&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 10.254.0.0 255.255.255..0 10.255.250.51&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a mil!&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;If 10.255.250.51 is the vlan 1 interface IP on the switch then yes that should do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 May 2010 10:05:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455053#M680876</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-05-12T10:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455054#M680877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried that but still no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the 10.254.25.0/24 network I can ping my firewall. I just cant get internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In under routing I had one route set there from before all of this for my old network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was simply and outside rule&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;outside 0.0.0.0 0.0.0.0 77.75.x.x 255 (metric)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought this rule sends everything internal out through my ISP gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added the inside rule also but this isnt working. Maybe I have missed something silly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again, your help is much appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 May 2010 15:00:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455054#M680877</guid>
      <dc:creator>drikilbride</dc:creator>
      <dc:date>2010-05-12T15:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455055#M680878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First off can you ping the next hop outside of the ASA from the network in question?&amp;nbsp; Also, I am just wondering why would you set a metric of 255 on the default route out to the Internet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kimberly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 May 2010 15:27:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455055#M680878</guid>
      <dc:creator>Kimberly Adams</dc:creator>
      <dc:date>2010-05-12T15:27:38Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455056#M680879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kimberly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No I cant ping the next hop which is the ISP's gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im actually not sure why the lads set the metric to 255, have just changed it back to 1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a mil!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 May 2010 15:31:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455056#M680879</guid>
      <dc:creator>drikilbride</dc:creator>
      <dc:date>2010-05-12T15:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455057#M680880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Metric of 1 for the default route is usually best and signifies that it is one hop away.&amp;nbsp; From the network in question are you able to ping anything outside of the ASA?&amp;nbsp; Some good tests to run would be run a continuous ping to 4.2.2.2 and then telnet/ssh into the ASA and see if you are hitting the xlate table or connection table. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;commands would be:&lt;/P&gt;&lt;P&gt;show xlate | include [your systems ip here]&lt;/P&gt;&lt;P&gt;show conn | include [your systems ip here]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is just another test to see what the ASA is doing.&amp;nbsp; By the way, what is the default gateway of the subnet that cannot get to the internet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kimberly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 May 2010 15:38:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455057#M680880</guid>
      <dc:creator>Kimberly Adams</dc:creator>
      <dc:date>2010-05-12T15:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455058#M680881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now here lies the problem.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our new subnets are being created by a third party engineer and he is the one who is saying I need to make changes on my firewall although he cant tell me what.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The subnet he has created has the following dgw 10.254.25.3. This subnet has been created on a 6500 switch which has a dgw set to 10.255.250.39&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I ping 4.2.2.2 from the pc on the new subnet i get the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;reply from 10.254.25.2 (which is the DHCP Server on the new 6500 Switch)...destination host unreachable&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 May 2010 15:47:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455058#M680881</guid>
      <dc:creator>drikilbride</dc:creator>
      <dc:date>2010-05-12T15:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455059#M680882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am assuming there is a route somewhere on your network that points to the ASA for Internet.&amp;nbsp; At this time I am not seeing where that would be coming from.&amp;nbsp; Can you please provide a little more information on the routing on your LAN and if you can get to the ASA at all?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kimberly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 May 2010 16:01:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455059#M680882</guid>
      <dc:creator>Kimberly Adams</dc:creator>
      <dc:date>2010-05-12T16:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455060#M680883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;drikilbride wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now here lies the problem.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our new subnets are being created by a third party engineer and he is the one who is saying I need to make changes on my firewall although he cant tell me what.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The subnet he has created has the following dgw 10.254.25.3. This subnet has been created on a 6500 switch which has a dgw set to 10.255.250.39&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I ping 4.2.2.2 from the pc on the new subnet i get the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;reply from 10.254.25.2 (which is the DHCP Server on the new 6500 Switch)...destination host unreachable&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why is the DHCP server coming back with a destination host unreachable message ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the 6500 routing for the vlans ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is 10.254.25.3, is this the L3 vlan interface on the 6500 switch ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 6500 has a default-gateway ?? - is the 6500 routing or simply acting as a L2 switch.&amp;nbsp; The dgw of 10.255.250.39, what exactly is that device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As Kimberly says, if the 6500 is responsible for routing the vlans then you need a default-route (not default-gateway) pointing to the ASA. But it sounds like it is a bit more complicated than this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 May 2010 17:47:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455060#M680883</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-05-12T17:47:37Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455061#M680884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have managed to persuade the third party engineer to add a default route on his 6500 to the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So now instead of getting destination host unreachable I am getting the normal request timed out when I ping an external IP Address so I now suspect it must be an access rule issue on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like my ping is getting out but just not being returned to the new vlan 10.254.25.0/24. Is there anything additional I can add in on the firewall to test this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 May 2010 13:16:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455061#M680884</guid>
      <dc:creator>drikilbride</dc:creator>
      <dc:date>2010-05-14T13:16:58Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455062#M680885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the firewall, you may need a route inside statement that would look like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 10.254.25.0 255.255.255.0 [IP of your 6500]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See if this helps the traffic come back to your new network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Kimberly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 May 2010 13:51:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455062#M680885</guid>
      <dc:creator>Kimberly Adams</dc:creator>
      <dc:date>2010-05-14T13:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455063#M680886</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kimberly&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfort I already have that route added.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still no internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 May 2010 14:01:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455063#M680886</guid>
      <dc:creator>drikilbride</dc:creator>
      <dc:date>2010-05-14T14:01:03Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455064#M680887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post up a new copy of your configuration of your firewall please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will help us help you with the changes needed to get the internet working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kimberly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 May 2010 14:03:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455064#M680887</guid>
      <dc:creator>Kimberly Adams</dc:creator>
      <dc:date>2010-05-14T14:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455065#M680888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I wanted to test a ping from 10.254.25.42 to 208.67.222.222 what rule would I add to accomplish this?I have tried a few but have had no luck with&lt;/P&gt;&lt;P&gt;it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already have an outside rule with the source being 208.67.222 and destination any and this allows pings to work from my old network out and back in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just no luck with the new subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still feel there could be an issue on the 6500 but its hard to prove as the engineer feels its all firewall and I cant access the config of it!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 May 2010 14:04:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455065#M680888</guid>
      <dc:creator>drikilbride</dc:creator>
      <dc:date>2010-05-14T14:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455066#M680889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the updated config!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 May 2010 14:16:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455066#M680889</guid>
      <dc:creator>drikilbride</dc:creator>
      <dc:date>2010-05-14T14:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455067#M680890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your config shows a NAT statement for users in the 10.255.x.x subnet- nat (inside) 1 10.255.0.0 255.255.0.0, but this does not cover the users in the new subnet, 10.254.25.0.&amp;nbsp; I would remove the current nat (inside) command and add the following line- nat (inside) 1 0.0.0.0 0.0.0.0 - this command will cover all of your internal subnets and will PAT them to the outside interface. &lt;/P&gt;&lt;P&gt;Please let me know if this works for you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 May 2010 15:57:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455067#M680890</guid>
      <dc:creator>Scott Conklin</dc:creator>
      <dc:date>2010-05-14T15:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455068#M680891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've looked at your configuration and Scott Conklin is right. You are lacking a NAT statement for your new subnet. Using packet-tracer would have revealed this for you though as you would have seen the flow being created and no NAT rule matching.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 May 2010 18:33:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455068#M680891</guid>
      <dc:creator>Kent Heide</dc:creator>
      <dc:date>2010-05-14T18:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: New Subnet Requiring Internet Access via ASA</title>
      <link>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455069#M680892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added that NAT command but still no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for all your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 May 2010 09:40:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/new-subnet-requiring-internet-access-via-asa/m-p/1455069#M680892</guid>
      <dc:creator>drikilbride</dc:creator>
      <dc:date>2010-05-17T09:40:23Z</dc:date>
    </item>
  </channel>
</rss>

