<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: asa firewall issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408631#M723945</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&amp;nbsp; i checked the asa inside and outside nat and default route.all are correct.I have attached the firewall config(asa).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Jan 2010 05:19:09 GMT</pubDate>
    <dc:creator>manivelengg</dc:creator>
    <dc:date>2010-01-22T05:19:09Z</dc:date>
    <item>
      <title>asa firewall issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408629#M723943</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Im using ASA firewall behind cisco series 3640 router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Complete setup:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Internet---- cisco router------firewall---coreswitch-----lan users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; whenever the lanusers trying to browse the internet,they can not able to do it but all the logs are showing in asa(inside and outside) but they cant do it.What may be the problem.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:59:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408629#M723943</guid>
      <dc:creator>manivelengg</dc:creator>
      <dc:date>2019-03-11T16:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: asa firewall issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408630#M723944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:manivelengg@gmail.com"&gt;manivelengg@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Im using ASA firewall behind cisco series 3640 router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Complete setup:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Internet---- cisco router------firewall---coreswitch-----lan users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; whenever the lanusers trying to browse the internet,they can not able to do it but all the logs are showing in asa(inside and outside) but they cant do it.What may be the problem.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could be any number of things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First thing to check is are your clients using private addressing and if so are you Natting their private addresses to a public IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the outside interface of the ASA has a public IP then the usual method to do this is -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also check you have a default-route on the ASA ie.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route (outside) 0.0.0.0 0.0.0.0&amp;nbsp; &amp;lt;3640 IP address of interface facing ASA&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Jan 2010 12:36:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408630#M723944</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-01-21T12:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: asa firewall issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408631#M723945</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&amp;nbsp; i checked the asa inside and outside nat and default route.all are correct.I have attached the firewall config(asa).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jan 2010 05:19:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408631#M723945</guid>
      <dc:creator>manivelengg</dc:creator>
      <dc:date>2010-01-22T05:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: asa firewall issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408632#M723946</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is network that is not able to get out to the internet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you ping one of the hosts on that network from the ASA? If not, you may need a route back from the ASA.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;And vice-versa, can you ping from a host to the ASA's interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you ping your ASAs default gateway from the host? (100.100.100.1)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jan 2010 06:08:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408632#M723946</guid>
      <dc:creator>August Ritchie</dc:creator>
      <dc:date>2010-01-22T06:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: asa firewall issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408633#M723947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="text-align: left;"&gt;hi&lt;/P&gt;&lt;P style="text-align: left;"&gt;&amp;nbsp;&amp;nbsp; we cant able to reach the internet from all the networks.Below lan networks are&lt;/P&gt;&lt;P style="text-align: left;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (192.168.100.0,192.168.103.0,192.168.104.0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;all the networks are pinging from asa(firewall)&amp;nbsp; as well as we are pinging from lan networks to asa which has not issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt; At the same time we are pinging from host to default gateway(100.100.100.1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;but the internet websites are not pinging from hosts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jan 2010 08:03:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408633#M723947</guid>
      <dc:creator>manivelengg</dc:creator>
      <dc:date>2010-01-22T08:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: asa firewall issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408634#M723948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:manivelengg@gmail.com"&gt;manivelengg@gmail.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;hi&lt;/P&gt;&lt;P style="text-align: left;"&gt;&amp;nbsp;&amp;nbsp; we cant able to reach the internet from all the networks.Below lan networks are&lt;/P&gt;&lt;P style="text-align: left;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (192.168.100.0,192.168.103.0,192.168.104.0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;all the networks are pinging from asa(firewall)&amp;nbsp; as well as we are pinging from lan networks to asa which has not issue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt; At the same time we are pinging from host to default gateway(100.100.100.1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;but the internet websites are not pinging from hosts.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your ASA config you haven't actually applied any of the access-list to any of the interfaces. To get ping working add this to your config -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jan 2010 10:20:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408634#M723948</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-01-22T10:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: asa firewall issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408635#M723949</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well the fact that you can ping the host (100.100.100.1) from the hosts means that traffic is going out of the ASA and returning correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This generally means it's not an ASA problem. If you can ping the ASAs default gateway then we know that you must be natting out and that traffic knows how to get back to you from 100.100.100.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question now is can you ping from your ASA to 4.2.2.2?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jan 2010 13:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408635#M723949</guid>
      <dc:creator>August Ritchie</dc:creator>
      <dc:date>2010-01-22T13:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: asa firewall issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408636#M723950</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;im extremely sorry for the troule bacause the lan users not able to ping 100.100.100.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They are pinging inside interface of the asa firewall inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;plz suggest me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jan 2010 15:17:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408636#M723950</guid>
      <dc:creator>manivelengg</dc:creator>
      <dc:date>2010-01-22T15:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: asa firewall issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408637#M723951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try this. Do this capture and post the results back. The ip provided is a test site called gizmodo.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list capture permit ip any host 69.60.7.199&lt;/P&gt;&lt;P&gt;access-list capture permit ip host 69.60.7.199 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;capture capin access-list capture interface inside&lt;/P&gt;&lt;P&gt;capture capout access-list capture interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then initiate the connection from a PC that doesn't work by putting 69.60.7.199 in your browser.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue a 'show cap capin' and 'show cap capout'&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jan 2010 15:32:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408637#M723951</guid>
      <dc:creator>August Ritchie</dc:creator>
      <dc:date>2010-01-22T15:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: asa firewall issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408638#M723952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; i tried this capture command in asa firwall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the mentioned ip address is pinging in firewall at the same time the i tried both website name and ip but not pinging from our pc(lan networks)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;meanwhile i intimate you all the websites are pinging from firewall point of view but the browsing(http) is not happening from all the networks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Jan 2010 06:10:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-issue/m-p/1408638#M723952</guid>
      <dc:creator>manivelengg</dc:creator>
      <dc:date>2010-01-23T06:10:31Z</dc:date>
    </item>
  </channel>
</rss>

