<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Beginner ASA5500 setup help. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422265#M739010</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;svaish wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you have an internal DHCP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is your DHCP server and the clients behind the same interfave or in same Vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If yes then are the clients able to get the ip address and other parameters from the DHCP servere.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, the clients and DHCP server are behind the same interface, my "inside" interface.&amp;nbsp;&amp;nbsp; Currently the DHCP clients are not able to recieve the proper information from the server.&amp;nbsp; When manually configured they work and access the internet just fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 10 Jan 2010 04:45:22 GMT</pubDate>
    <dc:creator>Kyle_McIver</dc:creator>
    <dc:date>2010-01-10T04:45:22Z</dc:date>
    <item>
      <title>Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422261#M738977</link>
      <description>&lt;P&gt;I hate to be that guy begging for help, but this is absolutley the first time I have worked on firewalling &amp;amp; routing at all so I guess it is what it is.&amp;nbsp; Please forgive my excessive lack of knowledge on the subject.&amp;nbsp; I have an ASA5505 that I am having a difficult time getting to do what I want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i turn DHCP server on in my ISP router and plug a single workstation into the ASA where the workstation recieves a DHCP address from the firewall (or any combination of static IP addresses within this range so long as the inside interface is not changed from the default 192.168.x.x) the out of the box config will work and the workstation can access the internet in this manner:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP router -&amp;gt; ASA -&amp;gt; workstation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this scenario the ISP router is performing the NAT from internal to public IP.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;As soon as I start doing anything else to try to configure the device to fit into my internal IP scheme nothing works right.&amp;nbsp; I am trying to reconfigure the "inside" interface to the IP addressing scheme I already have setup and set the outside interface to something between the ASA and the ISP router.A simple single switched internal network gaining internet access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could just reconfigure my DHCP server to make everything inside work with the cisco out of the box config or let the ASA do the DHCP for the network, but at this point I want to actually learn how to manipulate this device correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've found a basic config guide from Cisco and the network diagram here is pretty much what I want:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080094768.shtml#configs" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080094768.shtml#configs&lt;/A&gt;&lt;IMG alt="http://www.cisco.com/image/gif/paws/10136/19a_update.gif" class="jive-image" src="http://www.cisco.com/image/gif/paws/10136/19a_update.gif" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have set the firewall up this way on a couple occasions with no success thus far. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need to to setup the ISP firewall in a pass through mode and let the ASA do the NAT translation?&amp;nbsp; Is there something else I am missing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any help is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;McIver&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:55:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422261#M738977</guid>
      <dc:creator>Kyle_McIver</dc:creator>
      <dc:date>2019-03-11T16:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422262#M738980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would sayy that you can do a clear config all on the ASA&lt;/P&gt;&lt;P&gt;save it and reload the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One interface on ASA can be in server mode or client mode for DHCP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to use your ISP router to provide ip addresses to the internal clents use then you need to configure DHCP relay&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/dhcp.html#wp1041663"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/dhcp.html#wp1041663&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is the link&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now after you do all that you need to configure a siomple translation rule for your inside network as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you are using ASA5505 please take care of the VLAN concept and adhere to the license feature installed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Jan 2010 04:24:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422262#M738980</guid>
      <dc:creator>svaish</dc:creator>
      <dc:date>2010-01-10T04:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422263#M738990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't want either of them providing DHCP. I have a dhcp server setup on my internal network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since my OP I have been able to configure both my internal and external interfaces with static IP's and I can connect to the internet with all my servers that have static IP configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently none of my workstations that up my internal DHCP server will connect to any part of the network - will not log into active directory or access the intnernet.&amp;nbsp; They act as normal if i log in locally and configure a static IP, DNS and default gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This must have something to do with the way I am handling DHCP across the firewall?&amp;nbsp; Or do I need to give a static route or entry in the ACL?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've got a static route for my inside interface 0.0.0.0&amp;nbsp; 0.0.0.0 &lt;FIREWALL&gt;&lt;/FIREWALL&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Jan 2010 04:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422263#M738990</guid>
      <dc:creator>Kyle_McIver</dc:creator>
      <dc:date>2010-01-10T04:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422264#M739003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you have an internal DHCP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is your DHCP server and the clients behind the same interfave or in same Vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If yes then are the clients able to get the ip address and other parameters from the DHCP servere.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Jan 2010 04:41:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422264#M739003</guid>
      <dc:creator>svaish</dc:creator>
      <dc:date>2010-01-10T04:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422265#M739010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;svaish wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you have an internal DHCP server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is your DHCP server and the clients behind the same interfave or in same Vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If yes then are the clients able to get the ip address and other parameters from the DHCP servere.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, the clients and DHCP server are behind the same interface, my "inside" interface.&amp;nbsp;&amp;nbsp; Currently the DHCP clients are not able to recieve the proper information from the server.&amp;nbsp; When manually configured they work and access the internet just fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Jan 2010 04:45:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422265#M739010</guid>
      <dc:creator>Kyle_McIver</dc:creator>
      <dc:date>2010-01-10T04:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422266#M739021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if the ip address assignment process is going through the firewall then we need to check this on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So is the DHCP request and Reply going through the firewall or is it going through some router on the internal network,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the request and reply is not going through the firewall then it is not a problem with the firewall at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if the request or reply is going through the firewall or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Jan 2010 04:50:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422266#M739021</guid>
      <dc:creator>svaish</dc:creator>
      <dc:date>2010-01-10T04:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422267#M739024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the request/reply should not be going through the firewall.&amp;nbsp; I have the network configured like is pictured in the graphic in my first post with an internal router in between the Cisco device and my internal clents.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is why I am puzzled.&amp;nbsp; As soon as I got everything setup and in and out access to my servers, my wrk stations would no longer recieve DHCP data, but I've made no changes to the router....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Jan 2010 04:54:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422267#M739024</guid>
      <dc:creator>Kyle_McIver</dc:creator>
      <dc:date>2010-01-10T04:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422268#M739028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;kyle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please post your config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;have you turned off DHCP within the ASA?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i gues the the inside interface IP is set within the DHCP reservation list with your DHCP server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i wouldnt think you would need to worry about acl's for the DCHP request and reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the ASA config would be a great help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jan 2010 11:59:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422268#M739028</guid>
      <dc:creator>SOL10</dc:creator>
      <dc:date>2010-01-11T11:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422269#M739033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;solpandor wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;kyle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please post your config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;have you turned off DHCP within the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i gues the the inside interface IP is set within the DHCP reservation list with your DHCP server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i wouldnt think you would need to worry about acl's for the DCHP request and reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the ASA config would be a great help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;solpandor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have turned off DHCP within the ASA and the inside interface IP is within the DHCP reservation list on nmy DHCP server.&amp;nbsp; Below is my running configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kyle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 7.2(4) &lt;BR /&gt;!&lt;BR /&gt;hostname ciscoasa&lt;BR /&gt;domain-name default.domain.invalid&lt;BR /&gt;enable password 8Ry2YjIyt7RRXU24 encrypted&lt;BR /&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; nameif inside&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 10.10.1.10 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address 10.10.3.1 255.255.255.0 &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; switchport access vlan 2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/4&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/5&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/6&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/7&lt;BR /&gt;!&lt;BR /&gt;ftp mode passive&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt; domain-name default.domain.invalid&lt;BR /&gt;pager lines 24&lt;BR /&gt;logging asdm informational&lt;BR /&gt;mtu inside 1500&lt;BR /&gt;mtu outside 1500&lt;BR /&gt;no failover&lt;BR /&gt;monitor-interface inside&lt;BR /&gt;monitor-interface outside&lt;BR /&gt;icmp unreachable rate-limit 1 burst-size 1&lt;BR /&gt;asdm image disk0:/asdm-524.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;arp timeout 14400&lt;BR /&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;BR /&gt;route outside 0.0.0.0 0.0.0.0 10.10.3.254 2&lt;BR /&gt;timeout xlate 3:00:00&lt;BR /&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;BR /&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;BR /&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;BR /&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;BR /&gt;http server enable&lt;BR /&gt;http 10.10.1.0 255.255.255.0 inside&lt;BR /&gt;http 192.168.1.0 255.255.255.0 inside&lt;BR /&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;BR /&gt;telnet timeout 5&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;console timeout 0&lt;BR /&gt;dhcpd auto_config outside&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map type inspect dns preset_dns_map&lt;BR /&gt; parameters&lt;BR /&gt;&amp;nbsp; message-length maximum 512&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns preset_dns_map &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;!&lt;BR /&gt;service-policy global_policy global&lt;BR /&gt;prompt hostname context &lt;BR /&gt;Cryptochecksum:c78aad4983316f1ac1f4e22fd4ff5f6e&lt;BR /&gt;: end&lt;BR /&gt;asdm image disk0:/asdm-524.bin&lt;BR /&gt;no asdm history enable&lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jan 2010 15:53:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422269#M739033</guid>
      <dc:creator>Kyle_McIver</dc:creator>
      <dc:date>2010-01-11T15:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422270#M739062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All I have done thus far from the out of the box config is the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Set static IP on outside interface&lt;/P&gt;&lt;P&gt;2) Add a static route for the outside interface of 0.0.0.0 0.0.0.0 with the internal IP of my ISP's router&lt;/P&gt;&lt;P&gt;3)Change inside IP interface to static IP address on my private network &amp;amp; add that network to the device access list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At that point I solved my original problem of not being able to reach the internet from mmy private network.&amp;nbsp; At that time I learned that anything on my network that was supposed to recieve a DHCP assignment was not contacting the server and needed to be manually configured.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jan 2010 15:59:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422270#M739062</guid>
      <dc:creator>Kyle_McIver</dc:creator>
      <dc:date>2010-01-11T15:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422271#M739063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;kyle&lt;/P&gt;&lt;P&gt;ok couple of things -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) are you letting your ISP's router/modem assign the IP to your ASA's outside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the reason i ask is ) that you have set your outside Interfafce to get its IP from the upstream router using the "dhcpd auto_config outside" (experts pls feel free to correct) but at the same time you have assigned it a static IP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you are getting the outside interface IP assigned by the ISP's router then remove the IP from the outside interface, then go under the outside interface and enter the command&amp;nbsp; "ip address dhcp setroute."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also, remove the static route you entered&amp;nbsp; route outside 0.0.0.0 0.0.0.0&amp;nbsp; 10.10.3.254&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; as the&amp;nbsp; "ip address dhcp setroute" command will get the route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;apart from this - the config looks fine to me&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me know how you get on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jan 2010 16:16:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422271#M739063</guid>
      <dc:creator>SOL10</dc:creator>
      <dc:date>2010-01-11T16:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422272#M739069</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;solpandor wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;kyle&lt;/P&gt;&lt;P&gt;ok couple of things -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) are you letting your ISP's router/modem assign the IP to your ASA's outside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the reason i ask is ) that you have set your outside Interfafce to get its IP from the upstream router using the "dhcpd auto_config outside" (experts pls feel free to correct) but at the same time you have assigned it a static IP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you are getting the outside interface IP assigned by the ISP's router then remove the IP from the outside interface, then go under the outside interface and enter the command&amp;nbsp; "ip address dhcp setroute."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also, remove the static route you entered&amp;nbsp; route outside 0.0.0.0 0.0.0.0&amp;nbsp; 10.10.3.254&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; as the&amp;nbsp; "ip address dhcp setroute" command will get the route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;apart from this - the config looks fine to me&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me know how you get on.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hmm...I know the default config has the outside IP set to recieve DHCP.&amp;nbsp; I do not want this to happen.&amp;nbsp; It is supposed to be statically assigned.&amp;nbsp; So I would need to turn the "dhcp auto_config outside" off.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want the ISP's router doing as little as possible as it is a POS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jan 2010 16:34:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422272#M739069</guid>
      <dc:creator>Kyle_McIver</dc:creator>
      <dc:date>2010-01-11T16:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422273#M739078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kyle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you want to assign a static IP then (depending on your country, ISP and their router) you can enable the Pass through feature on some ISP routers ( BT business hub here in the UK is one of them) and then assign a static IP from your block of IP's to the outside interface of the ASA,&amp;nbsp; but you will still need those commands in there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i configured an ASA5505 at our Spanish office i had to use PPPOE commands on the ASA to set the outside interface to have a static IP (we only had one IP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so I guess you might need the assistance of your ISP, unless the router is very straightforward to set up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jan 2010 16:46:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422273#M739078</guid>
      <dc:creator>SOL10</dc:creator>
      <dc:date>2010-01-11T16:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422274#M739084</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The static IP I have set on nthe outside interface of the ASA is a private IP on a subnet between my ISP router and the ASA.&amp;nbsp; The ISP router is handling NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;solpandor wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kyle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you want to assign a static IP then (depending on your country, ISP and their router) you can enable the Pass through feature on some ISP routers ( BT business hub here in the UK is one of them) and then assign a static IP from your block of IP's to the outside interface of the ASA,&amp;nbsp; but you will still need those commands in there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i configured an ASA5505 at our Spanish office i had to use PPPOE commands on the ASA to set the outside interface to have a static IP (we only had one IP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so I guess you might need the assistance of your ISP, unless the router is very straightforward to set up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jan 2010 17:06:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422274#M739084</guid>
      <dc:creator>Kyle_McIver</dc:creator>
      <dc:date>2010-01-11T17:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422275#M739090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I still have no idea why my work stations don't receive DHCP from the server on the same network segment.&amp;nbsp; Everything is running manually configured.&amp;nbsp; It works, but it's annoying.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It doesn't look like I posted it before, but from some of the responses it looks like it needs to be said.&amp;nbsp; I am using the ASDM console to manage this thing.&amp;nbsp; It appears that entering some of the stuff into the ASDM does not have the complete desired effect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jan 2010 06:17:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422275#M739090</guid>
      <dc:creator>Kyle_McIver</dc:creator>
      <dc:date>2010-01-13T06:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422276#M739092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kyle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is very strange. Have you ran ethereal on your segment to see the DHCP request and replies? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a long shot - but, could it be an arp issue (if you;ve changed IP's of the inside interface of the firewall to be one of the DHCP server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im guessing you now have internet connectivity?&amp;nbsp; - the DHCP request should not be getting as far the ASA - so to me it looks like an issue on the server side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jan 2010 09:54:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422276#M739092</guid>
      <dc:creator>SOL10</dc:creator>
      <dc:date>2010-01-13T09:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422277#M739093</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kyle,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried to turn off or disable the ASA, then test DHCP?&amp;nbsp; If it still doesn't work, you'll know for sure it's not a firewall issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jan 2010 16:17:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422277#M739093</guid>
      <dc:creator>JEFF SPRADLING</dc:creator>
      <dc:date>2010-01-13T16:17:49Z</dc:date>
    </item>
    <item>
      <title>Re: Beginner ASA5500 setup help.</title>
      <link>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422278#M739100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;jspradling wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kyle,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried to turn off or disable the ASA, then test DHCP?&amp;nbsp; If it still doesn't work, you'll know for sure it's not a firewall issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;I just did this this morning when a room mate was keeping me up @ 4am.&amp;nbsp; bypassed the asa and there was no change.&amp;nbsp; &lt;SPAN dir="ltr" id=":1dw"&gt;now i am thoroughly confused.&amp;nbsp; The company has been running on that DHCP for over a year with zero problems, save for when my domain contoller accidently got set to recieve a DHCP address. lol, oops.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible that it coincidently went out the same day I put the firewall in?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The DHCP is on nthe same box as my secondary domain controller and primary DNS and both of those are working as they should.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jan 2010 20:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/beginner-asa5500-setup-help/m-p/1422278#M739100</guid>
      <dc:creator>Kyle_McIver</dc:creator>
      <dc:date>2010-01-13T20:05:09Z</dc:date>
    </item>
  </channel>
</rss>

