<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic cannot access the internet router through ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005298#M916438</link>
    <description>&lt;P&gt;Dear all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have an ASA in the main site , the users in this site can access internet properly without any problems.&lt;/P&gt;&lt;P&gt;But after installing the firewall between the internet router and the BB switch , i cannot ping nor telnet on the internet router from my pc in the LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a WAN router connected to a dmz interface on the ASA ( its name is wan ) . From the LAN , i can ping &amp;amp; telnet on the wan router but i cannot do that on the internet router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;routing on the internet router:&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.82.212.169&lt;/P&gt;&lt;P&gt;ip route 10.1.0.0 255.255.0.0 82.35.212.169&lt;/P&gt;&lt;P&gt;ip route 172.18.100.0 255.255.255.0 82.35.212.169&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;82.35.212.169 is the outside interface of the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please find the attached files for the topology and the ASA configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please i need your advice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 13:16:54 GMT</pubDate>
    <dc:creator>mohamed_makled</dc:creator>
    <dc:date>2019-03-11T13:16:54Z</dc:date>
    <item>
      <title>cannot access the internet router through ASA</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005298#M916438</link>
      <description>&lt;P&gt;Dear all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have an ASA in the main site , the users in this site can access internet properly without any problems.&lt;/P&gt;&lt;P&gt;But after installing the firewall between the internet router and the BB switch , i cannot ping nor telnet on the internet router from my pc in the LAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a WAN router connected to a dmz interface on the ASA ( its name is wan ) . From the LAN , i can ping &amp;amp; telnet on the wan router but i cannot do that on the internet router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;routing on the internet router:&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.82.212.169&lt;/P&gt;&lt;P&gt;ip route 10.1.0.0 255.255.0.0 82.35.212.169&lt;/P&gt;&lt;P&gt;ip route 172.18.100.0 255.255.255.0 82.35.212.169&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;82.35.212.169 is the outside interface of the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please find the attached files for the topology and the ASA configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please i need your advice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:16:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005298#M916438</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2019-03-11T13:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access the internet router through ASA</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005299#M916439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you ping the inet router from the asa?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what default gateway do you have on PC?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jul 2008 16:55:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005299#M916439</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2008-07-19T16:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access the internet router through ASA</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005300#M916440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear a.alekseev&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply . form the ASA i can ping the internet router . Also i can ping my pc from the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the internet router i can ping the outside interface of the ASA .&lt;/P&gt;&lt;P&gt;But when trying to ping my pc from the internet router i cannot &amp;amp; the following log appears on the ASA :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-3-305005 : No translation group found for icmp src outside:82.35.212.172 dst inside:10.1.2.48(type8,code0).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default gateway on my pc (10.1.2.48) is the interface vlan on the BB switch (10.1.2.1) .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my pc i can ping my gateway , the inside interface of the ASA and the outside interface of the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jul 2008 17:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005300#M916440</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2008-07-19T17:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access the internet router through ASA</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005301#M916441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you may need couple of things in your config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in global policy add inspec icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i.e&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;inspect icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;even though you have nat (inside) 1 0.0, you may need to explitcitly specify 10.1.0.0/16 network seating behind another L3 device behind asa in nat.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you could get  10.1.0.0/16 nated through outside interface to get to internet router using outside interface as PAT , try. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.1.0.0  255.255.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you may also do a no nat acl to connect to internet router but preferrabe do it through interface PAT.. try that.. this would also include get you outbound internet via PAT for the 10.1.0.0/16 network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jul 2008 17:51:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005301#M916441</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-07-19T17:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access the internet router through ASA</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005302#M916442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply . i will do that and feed back you again but i need to remind you that i can ping the wan router interface from my pc which is connected to the ASA , also i can telnet on this router , why i cannot do that for the internet router???&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jul 2008 18:02:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005302#M916442</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2008-07-19T18:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access the internet router through ASA</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005303#M916443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does the BB switch have a route to 82.35.212.172 or it's default route is pointing to the inside address of the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the existing configuration you won't be able to ping from outside to inside PC. However, the configuration looks good and you should be able to ping from inside to outside as long as routing on your inside is good to the ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried doing a 'clear xlate' in the ASA and test connectivity from inside to the Inetneret router?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jul 2008 18:07:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005303#M916443</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2008-07-19T18:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access the internet router through ASA</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005304#M916444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear sundar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply . on the BB switch there is a default route to the inside interface of the ASA only . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 172.18.100.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i do clear xlate on the ASA many times but i am still facing the same problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jul 2008 18:15:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005304#M916444</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2008-07-19T18:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access the internet router through ASA</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005305#M916445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do a 'debug ip icmp' on the Internet router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to ping from your PC and see if the echo packets are making it to the router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jul 2008 18:19:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005305#M916445</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2008-07-19T18:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access the internet router through ASA</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005306#M916446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear sundar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ok i will do that and feedback you again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jul 2008 18:24:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005306#M916446</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2008-07-19T18:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access the internet router through ASA</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005307#M916447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sundar , long time .. greedings!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Momahed is geting bellow message, it seems from begining of the post he is trying to ping from internet router to pc inside subnet 10.1.0.0/16,yet there is not static nat for 10.1.0.0/16 hosts nor specific rule for this. If we observe the nat statement in config for WAN router that works we see the difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-3-305005 : No translation group found for icmp src outside:82.35.212.172 dst inside:10.1.2.48(type8,code0). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can do debug ip icmp as suggested , but I believe the issue is the nating , first to ping from outide ASA to inside you need some form of NATing and access rules as traffic from outside to inside is denied but in his case he is permiting icmp but there is no translations happening from outside to inside 10.1.0.0/16.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ON the other hand, local to ASA firewall it is aware of 10.1.0.0/16 but it does not know  how to translate to outside when traffic is going outside internet router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just a thought.. do the changes step at a time..  as suggested   debug ip icmp will help to see whats happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jul 2008 18:42:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005307#M916447</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-07-19T18:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access the internet router through ASA</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005308#M916448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;I&gt;But when trying to ping my pc from the internet router i cannot &amp;amp; the following log appears on the ASA : &lt;/I&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%ASA-3-305005 : No translation group found for icmp src outside:82.35.212.172 dst inside:10.1.2.48(type8,code0). &lt;/P&gt;&lt;P&gt;This is normal.&lt;/P&gt;&lt;P&gt;You cannot ping internal hosts from outside because you are doing PAT.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jul 2008 18:58:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005308#M916448</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2008-07-19T18:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access the internet router through ASA</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005309#M916449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mohammed, any update with your problem? is it resolved, pls let us know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 Jul 2008 21:34:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005309#M916449</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-07-20T21:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access the internet router through ASA</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005310#M916450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is solved now and every thing is ok . The situation before the firewall that the BB switch is connected directly to the internet router , so it was must to create interface vlan on the BB for internet , it was 82.35.212.169.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After installing the firewall between the BB switch and the internet router , we must delete the above interface vlan on the BB.&lt;/P&gt;&lt;P&gt;now after deleting it , i can ping and telnet on the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i would like to thank you jorge and everyone for helping me in this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jul 2008 11:41:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005310#M916450</guid>
      <dc:creator>mohamed_makled</dc:creator>
      <dc:date>2008-07-21T11:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: cannot access the internet router through ASA</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005311#M916451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for updating us.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That makes sense as it was a LAN routing issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jul 2008 13:37:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-the-internet-router-through-asa/m-p/1005311#M916451</guid>
      <dc:creator>sundar.palaniappan</dc:creator>
      <dc:date>2008-07-21T13:37:37Z</dc:date>
    </item>
  </channel>
</rss>

