<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Basic conf ASA 5505 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137325#M878878</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Pascal,&lt;/P&gt;&lt;P&gt;   Please do the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Assuming that NAT for internet connection etc does not take place in router for 192.168.1.0/24 network)&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; security 0&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;no same-security-traffic permit inter-interface &lt;/P&gt;&lt;P&gt;no same-security-traffic permit intra-interface &lt;/P&gt;&lt;P&gt;no access-list inside_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;no access-list outside_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;no access-group inside_access_in in interface inside &lt;/P&gt;&lt;P&gt;no access-group outside_access_in in interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;   class inspection_default&lt;/P&gt;&lt;P&gt;      inspect icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Dec 2008 17:33:46 GMT</pubDate>
    <dc:creator>Alan Huseyin Kayahan</dc:creator>
    <dc:date>2008-12-12T17:33:46Z</dc:date>
    <item>
      <title>Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137317#M878865</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm a newbie on ASA, I need some assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have this schema.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Host 192.168.1.0/ ---&amp;gt; ASA INSIDE -----&amp;gt;ASA OUTSIDE ------&amp;gt; to my interface router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From  host 192.168.1.0/24 I can ping INSIDE interface from my ASA but I cannot ping interface OUTISIDE and no interface from my router at this address 172.16.0.5/252&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under my conf.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 7.2(4)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;enable password 1I5BT/dHhpGbnQvr encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt;nameif outside&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 172.16.0.6 255.255.255.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt;domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-524.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 172.16.0.5 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.2-192.168.1.33 inside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username admin password p1ClWSkbSujddlxc encrypted&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;inspect ftp&lt;/P&gt;&lt;P&gt;inspect h323 h225&lt;/P&gt;&lt;P&gt;inspect h323 ras&lt;/P&gt;&lt;P&gt;inspect rsh&lt;/P&gt;&lt;P&gt;inspect rtsp&lt;/P&gt;&lt;P&gt;inspect esmtp&lt;/P&gt;&lt;P&gt;inspect sqlnet&lt;/P&gt;&lt;P&gt;inspect skinny&lt;/P&gt;&lt;P&gt;inspect sunrpc&lt;/P&gt;&lt;P&gt;inspect xdmcp&lt;/P&gt;&lt;P&gt;inspect sip&lt;/P&gt;&lt;P&gt;inspect netbios&lt;/P&gt;&lt;P&gt;inspect tftp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;Cryptochecksum:885202205e413b4a47e7f59d572ef3d7&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:25:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137317#M878865</guid>
      <dc:creator>p.maillot</dc:creator>
      <dc:date>2019-03-11T14:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137318#M878866</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the inside host you are not allowed to ping the outside interface (that's part of the security of the firewall). From the router you should be able to ping the outside IP though. Try adding this line-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try pinging and if it fails, take a look at the log &lt;B&gt;show logging buff | inc ICMP&lt;/B&gt; and see where it's failing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 16:26:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137318#M878866</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-12-12T16:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137319#M878867</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank Collin but no change with&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp permit any outside and icmp permit any inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This command don't exist show logging buff | inc ICMP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can do only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# sh logging ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  asdm     Show ASDM syslog buffer content&lt;/P&gt;&lt;P&gt;  message  Show enabled and disabled messages at non-default level&lt;/P&gt;&lt;P&gt;  queue    Show syslog queue&lt;/P&gt;&lt;P&gt;  setting  Show syslog setting&lt;/P&gt;&lt;P&gt;  |        Output modifiers&lt;/P&gt;&lt;P&gt;  &lt;CR&gt;&lt;/CR&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 16:41:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137319#M878867</guid>
      <dc:creator>p.maillot</dc:creator>
      <dc:date>2008-12-12T16:41:43Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137320#M878869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try access-list outside_access_in extended permit icmp any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Francisco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 16:48:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137320#M878869</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2008-12-12T16:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137321#M878871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, &lt;B&gt;show logging&lt;/B&gt; is correct.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 16:56:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137321#M878871</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-12-12T16:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137322#M878873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Always same problem with&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And after sh logging?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# sh logging&lt;/P&gt;&lt;P&gt;Syslog logging: disabled&lt;/P&gt;&lt;P&gt;    Facility: 20&lt;/P&gt;&lt;P&gt;    Timestamp logging: disabled&lt;/P&gt;&lt;P&gt;    Standby logging: disabled&lt;/P&gt;&lt;P&gt;    Deny Conn when Queue Full: disabled&lt;/P&gt;&lt;P&gt;    Console logging: disabled&lt;/P&gt;&lt;P&gt;    Monitor logging: disabled&lt;/P&gt;&lt;P&gt;    Buffer logging: disabled&lt;/P&gt;&lt;P&gt;    Trap logging: disabled&lt;/P&gt;&lt;P&gt;    History logging: disabled&lt;/P&gt;&lt;P&gt;    Device ID: disabled&lt;/P&gt;&lt;P&gt;    Mail logging: disabled&lt;/P&gt;&lt;P&gt;    ASDM logging: level informational, 0 messages logged&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 17:10:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137322#M878873</guid>
      <dc:creator>p.maillot</dc:creator>
      <dc:date>2008-12-12T17:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137323#M878876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in  permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list outside_access_in  permit icmp any any source-quench &lt;/P&gt;&lt;P&gt;access-list outside_access_in  permit icmp any any unreachable  &lt;/P&gt;&lt;P&gt;access-list outside_access_in  permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 17:18:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137323#M878876</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2008-12-12T17:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137324#M878877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same problem with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any source-quench&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any unreachable&lt;/P&gt;&lt;P&gt;access-list outside_access_in permit icmp any any time-exceeded &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 17:30:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137324#M878877</guid>
      <dc:creator>p.maillot</dc:creator>
      <dc:date>2008-12-12T17:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137325#M878878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Pascal,&lt;/P&gt;&lt;P&gt;   Please do the following&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(Assuming that NAT for internet connection etc does not take place in router for 192.168.1.0/24 network)&lt;/P&gt;&lt;P&gt;nat (inside) 1 0 0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; security 0&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;no same-security-traffic permit inter-interface &lt;/P&gt;&lt;P&gt;no same-security-traffic permit intra-interface &lt;/P&gt;&lt;P&gt;no access-list inside_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;no access-list outside_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;no access-group inside_access_in in interface inside &lt;/P&gt;&lt;P&gt;no access-group outside_access_in in interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;   class inspection_default&lt;/P&gt;&lt;P&gt;      inspect icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 17:33:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137325#M878878</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-12-12T17:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137326#M878880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;nat (inside) 1 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 17:35:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137326#M878880</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-12-12T17:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137327#M878881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;now why didnt i though of that &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good job jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 17:36:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137327#M878881</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2008-12-12T17:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137328#M878883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same problem. See my last conf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 7.2(4)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;enable password 1I5BT/dHhpGbnQvr encrypted&lt;/P&gt;&lt;P&gt;passwd 2KFQnbNIdI.2KYOU encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 172.16.0.6 255.255.255.252&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt; domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any source-quench&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any unreachable&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-524.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 172.16.0.5 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.1.2-192.168.1.33 inside&lt;/P&gt;&lt;P&gt;dhcpd enable inside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username admin password p1ClWSkbSujddlxc encrypted&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  inspect h323 h225&lt;/P&gt;&lt;P&gt;  inspect h323 ras&lt;/P&gt;&lt;P&gt;  inspect rsh&lt;/P&gt;&lt;P&gt;  inspect rtsp&lt;/P&gt;&lt;P&gt; inspect esmtp&lt;/P&gt;&lt;P&gt;  inspect sqlnet&lt;/P&gt;&lt;P&gt;  inspect skinny&lt;/P&gt;&lt;P&gt;  inspect sunrpc&lt;/P&gt;&lt;P&gt;  inspect xdmcp&lt;/P&gt;&lt;P&gt;  inspect sip&lt;/P&gt;&lt;P&gt;  inspect netbios&lt;/P&gt;&lt;P&gt;  inspect tftp&lt;/P&gt;&lt;P&gt;  inspect icmp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;Cryptochecksum:885202205e413b4a47e7f59d572ef3d7&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;ciscoasa(config)#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 18:04:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137328#M878883</guid>
      <dc:creator>p.maillot</dc:creator>
      <dc:date>2008-12-12T18:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137329#M878885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;use "sh logg | inc icmp" under CLI and post outout. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 18:16:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137329#M878885</guid>
      <dc:creator>francisco_1</dc:creator>
      <dc:date>2008-12-12T18:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137330#M878886</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Config looks OK, now please explain the problem in details. Please keep in mind that by default, you can NOT! ping the inside interface of ASA from your router connected to outside interface. And with this configuration, you can NOT! ping hosts in 192.168.1.0/24 on their actual IPs since they are NATed. If you describe what you exactly want to achieve, then we will advise accordingly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 18:21:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137330#M878886</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-12-12T18:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137331#M878887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When I use "sh logg | inc icmp" under CLI, nothing appears. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 18:22:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137331#M878887</guid>
      <dc:creator>p.maillot</dc:creator>
      <dc:date>2008-12-12T18:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137332#M878888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From my host 192.168.1.2 I want to ping interface of my routeur 172.16.0.5/30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my host to ASA Inside interface = OK&lt;/P&gt;&lt;P&gt;From my host to ASA Outiside interface = NOK&lt;/P&gt;&lt;P&gt;From my router to ASA Outiside interface = OK&lt;/P&gt;&lt;P&gt;From my router to my Host = NOK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 18:31:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137332#M878888</guid>
      <dc:creator>p.maillot</dc:creator>
      <dc:date>2008-12-12T18:31:01Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137333#M878889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"From my host to ASA Outiside interface = NOK "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the default non-changeable behaviour which has no affect on your network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"From my router to my Host = NOK "&lt;/P&gt;&lt;P&gt;To achieve this, do the following modification&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound permit ip 192.168.1.0 255.255.255.0 172.16.0.4 255.255.255.252&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"From my host 192.168.1.2 I want to ping interface of my routeur 172.16.0.5/30 "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be able to be doing this right now, check your host if it has the default gateway of 192.168.1.1. !If windows firewall is enabled, and you have an exception added for PING, keep in mind that the exceptions work only for same subnet, so you wont be able to receive ping replies from another subnet like our router's interface. So either manually enter exception for 172 subnet or temporarily disable the windows firewall for testing purposes!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 18:33:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137333#M878889</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-12-12T18:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137334#M878890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you a lot husycisco.........&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now from host I can ping my router but why from my router I cannot ping the host?&lt;/P&gt;&lt;P&gt;It's normal?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 18:49:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137334#M878890</guid>
      <dc:creator>p.maillot</dc:creator>
      <dc:date>2008-12-12T18:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137335#M878891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try this,&lt;/P&gt;&lt;P&gt;  In router, just type ping then press enter. Enter the destination address, then press enter to accept defaults for other settings untill extended options which states [n]. Press y when extended options is asked, it will ask you "source interface", type in 172.16.0.5, then press enter for all other options and see if ping is successfull&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 18:52:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137335#M878891</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-12-12T18:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: Basic conf ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137336#M878892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pascal,&lt;/P&gt;&lt;P&gt;   Any update?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Please rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 20:21:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/basic-conf-asa-5505/m-p/1137336#M878892</guid>
      <dc:creator>Alan Huseyin Kayahan</dc:creator>
      <dc:date>2008-12-12T20:21:39Z</dc:date>
    </item>
  </channel>
</rss>

