<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA WAN &amp; LAN Configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027401#M918682</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will not be able to ping the 'outside' interface itself when sourcing your pings from the 'inside'. This is not allowed by the PIX/ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try to ping any public IP addresses from the PIX itself?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also when you initiate traffic to the internet from inside, what do you see in the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show xlate&lt;/P&gt;&lt;P&gt;show conn det&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Jun 2008 07:37:13 GMT</pubDate>
    <dc:creator>Farrukh Haroon</dc:creator>
    <dc:date>2008-06-16T07:37:13Z</dc:date>
    <item>
      <title>ASA WAN &amp; LAN Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027395#M918672</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;I am Newbee to ASA configuration. recently we brought one ASA5505 i tried my level best to configure the ASA we are getiing PPPOE IP from ISP. after PC are not able to browse. from ASA i am able to ping the outside network. can any one please help me how to configure ASA . &lt;/P&gt;&lt;P&gt; please find the current configuration/&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# sh  run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 7.2(3)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;domain-name cisco.com&lt;/P&gt;&lt;P&gt;enable password xxx&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt;nameif outside&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;pppoe client vpdn group ADSLGROUP&lt;/P&gt;&lt;P&gt;ip address pppoe setroute&lt;/P&gt;&lt;P&gt;ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.31.215 255.255.255.0&lt;/P&gt;&lt;P&gt;ospf cost 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;switchport access vlan 11&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;switchport access vlan 11&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt;domain-name cisco.com&lt;/P&gt;&lt;P&gt;access-list inside_access_out extended permit ip any interface outside&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any eq www any eq www&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list outside_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list outside_in extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any interface outside&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any interface inside&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging debug-trace&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface outside&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-523.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 192.168.31.0-192.168.31.255 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp 192.168.31.0 smtp 59.93.112.10 smtp netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 59.93.122.1 1&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 59.93.112.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 192.168.31.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;http 192.168.31.0 255.255.255.0 outside&lt;/P&gt;&lt;P&gt;http authentication-certificate outside&lt;/P&gt;&lt;P&gt;http authentication-certificate inside&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;vpdn group ADSLGrouP request dialout pppoe&lt;/P&gt;&lt;P&gt;vpdn group ADSLGrouP localname AdslLocalName&lt;/P&gt;&lt;P&gt;vpdn group ADSLGrouP ppp authentication chap&lt;/P&gt;&lt;P&gt;vpdn username ADSLUSENAME password ****** store-local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt; !&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  inspect h323 h225&lt;/P&gt;&lt;P&gt;  inspect h323 ras&lt;/P&gt;&lt;P&gt;  inspect rsh&lt;/P&gt;&lt;P&gt;  inspect rtsp&lt;/P&gt;&lt;P&gt;  inspect esmtp&lt;/P&gt;&lt;P&gt;  inspect sqlnet&lt;/P&gt;&lt;P&gt;  inspect skinny&lt;/P&gt;&lt;P&gt;  inspect sunrpc&lt;/P&gt;&lt;P&gt;  inspect xdmcp&lt;/P&gt;&lt;P&gt;  inspect sip&lt;/P&gt;&lt;P&gt;  inspect netbios&lt;/P&gt;&lt;P&gt;  inspect tftp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;username user1 password xxx encrypted&lt;/P&gt;&lt;P&gt; prompt hostname context&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxx&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:57:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027395#M918672</guid>
      <dc:creator>rsjavahar</dc:creator>
      <dc:date>2019-03-11T12:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA WAN &amp; LAN Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027396#M918673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are missing a 'nat' statement. Also your 'global' statement is incorrect'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat = what IP Addresses(s) to translate&lt;/P&gt;&lt;P&gt;global = Translate IPs mentioned in 'Nat' statement into WHICH public IP Addresses(s)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The nat and global statements should share the same sequence number (in your case 1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.31.0-192.168.31.255 netmask 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jun 2008 07:11:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027396#M918673</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-10T07:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: ASA WAN &amp; LAN Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027397#M918674</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also the following is recommend for PPPoE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mtu outside 1492&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jun 2008 07:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027397#M918674</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-10T07:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA WAN &amp; LAN Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027398#M918675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you get this working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jun 2008 18:07:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027398#M918675</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-10T18:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA WAN &amp; LAN Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027399#M918677</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Where is nat:) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 Jun 2008 11:58:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027399#M918677</guid>
      <dc:creator>nomair_83</dc:creator>
      <dc:date>2008-06-15T11:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA WAN &amp; LAN Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027400#M918680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI &lt;/P&gt;&lt;P&gt; i added the NAT statements but its not working .. from PC i can ping to Inside IP address but not able to ping to the Outside interface . Browsing is not working &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please do the need .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2008 06:39:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027400#M918680</guid>
      <dc:creator>rsjavahar</dc:creator>
      <dc:date>2008-06-16T06:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA WAN &amp; LAN Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027401#M918682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will not be able to ping the 'outside' interface itself when sourcing your pings from the 'inside'. This is not allowed by the PIX/ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try to ping any public IP addresses from the PIX itself?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also when you initiate traffic to the internet from inside, what do you see in the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show xlate&lt;/P&gt;&lt;P&gt;show conn det&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2008 07:37:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027401#M918682</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-16T07:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA WAN &amp; LAN Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027402#M918685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;Please find the current config . i am not able to browse internet , &lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 7.2(3) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname ciscoasa&lt;/P&gt;&lt;P&gt;domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;enable password xxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ip address 192.168.31.215 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; pppoe client vpdn group pppoex&lt;/P&gt;&lt;P&gt; ip address pppoe setroute &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;passwd xxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; domain-name default.domain.invalid&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_out extended permit ip any interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any eq www any eq www &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in extended permit icmp any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in extended permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any interface inside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mtu outside 1492&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-523.bin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.31.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 59.93.112.1 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http 192.168.31.10 255.255.255.255 inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vpdn group pppoex request dialout pppoe&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vpdn group pppoex localname ABCDEFGHI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vpdn group pppoex ppp authentication mschap&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vpdn username ABCDEFGHIK password ********  &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  message-length maximum 512&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  inspect ftp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  inspect h323 h225 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  inspect h323 ras &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  inspect netbios &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  inspect rsh &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  inspect rtsp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  inspect skinny &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  inspect esmtp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  inspect sqlnet &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  inspect sunrpc &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  inspect tftp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  inspect sip &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  inspect xdmcp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cryptochecksum:xxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)#       &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2008 07:52:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027402#M918685</guid>
      <dc:creator>rsjavahar</dc:creator>
      <dc:date>2008-06-16T07:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA WAN &amp; LAN Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027403#M918687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you try to ping any public IP addresses from the PIX itself? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also when you initiate traffic to the internet from inside, what do you see in the following: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show xlate &lt;/P&gt;&lt;P&gt;show conn det &lt;/P&gt;&lt;P&gt;show route (important)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems you have assigned a 'default gateway' to some IP, what IP is this? You already have 'setroute' option in PPP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2008 08:47:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027403#M918687</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-16T08:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA WAN &amp; LAN Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027404#M918688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;did you enable vpdn on the firewall?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2008 08:50:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027404#M918688</guid>
      <dc:creator>liaqath2k7</dc:creator>
      <dc:date>2008-06-16T08:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA WAN &amp; LAN Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027405#M918690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI  &lt;/P&gt;&lt;P&gt;I didn't add any Static IP in the configuration here find the output for the commands you asked &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh nat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NAT policies on Interface inside:&lt;/P&gt;&lt;P&gt;  match ip inside 192.168.31.0 255.255.255.0 outside any&lt;/P&gt;&lt;P&gt;    dynamic translation to pool 1 (95.93.117.66 [Interface PAT])&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip inside 192.168.31.0 255.255.255.0 inside any&lt;/P&gt;&lt;P&gt;    dynamic translation to pool 1 (No matching global)&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;  match ip inside 192.168.31.0 255.255.255.0 _internal_loopback any&lt;/P&gt;&lt;P&gt;    dynamic translation to pool 1 (No matching global)&lt;/P&gt;&lt;P&gt;    translate_hits = 0, untranslate_hits = 0&lt;/P&gt;&lt;P&gt;ciscoasa(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh run access-list&lt;/P&gt;&lt;P&gt;access-list inside_access_out extended permit ip any interface outside&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any eq www any eq www&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list outside_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list outside_in extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any interface outside&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit ip any interface inside&lt;/P&gt;&lt;P&gt;ciscoasa(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP&lt;/P&gt;&lt;P&gt;       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area&lt;/P&gt;&lt;P&gt;       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2&lt;/P&gt;&lt;P&gt;       E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP&lt;/P&gt;&lt;P&gt;       i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area&lt;/P&gt;&lt;P&gt;       * - candidate default, U - per-user static route, o - ODR&lt;/P&gt;&lt;P&gt;       P - periodic downloaded static route&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway of last resort is 95.93.112.1 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C    192.168.31.0 255.255.255.0 is directly connected, inside&lt;/P&gt;&lt;P&gt;C    127.1.0.0 255.255.0.0 is directly connected, _internal_loopback&lt;/P&gt;&lt;P&gt;S*   0.0.0.0 0.0.0.0 [1/0] via 95.93.112.1, outside&lt;/P&gt;&lt;P&gt;ciscoasa(config)#&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh conn detail&lt;/P&gt;&lt;P&gt;0 in use, 32 most used&lt;/P&gt;&lt;P&gt;Flags: A - awaiting inside ACK to SYN, a - awaiting outside ACK to SYN,&lt;/P&gt;&lt;P&gt;       B - initial SYN from outside, C - CTIQBE media, D - DNS, d - dump,&lt;/P&gt;&lt;P&gt;       E - outside back connection, F - outside FIN, f - inside FIN,&lt;/P&gt;&lt;P&gt;       G - group, g - MGCP, H - H.323, h - H.225.0, I - inbound data,&lt;/P&gt;&lt;P&gt;       i - incomplete, J - GTP, j - GTP data, K - GTP t3-response&lt;/P&gt;&lt;P&gt;       k - Skinny media, M - SMTP data, m - SIP media, O - outbound data,&lt;/P&gt;&lt;P&gt;       P - inside back connection, q - SQL*Net data, R - outside acknowledged FI&lt;/P&gt;&lt;P&gt;N,&lt;/P&gt;&lt;P&gt;       R - UDP SUNRPC, r - inside acknowledged FIN, S - awaiting inside SYN,&lt;/P&gt;&lt;P&gt;       s - awaiting outside SYN, T - SIP, t - SIP transient, U - up, W - WAAS,&lt;/P&gt;&lt;P&gt;       X - inspected by service module&lt;/P&gt;&lt;P&gt;ciscoasa(config)#&lt;/P&gt;&lt;P&gt;ciscoasa(config)# sh xlate&lt;/P&gt;&lt;P&gt;0 in use, 0 most used&lt;/P&gt;&lt;P&gt;ciscoasa(config)#&lt;/P&gt;&lt;P&gt;ciscoasa(config)# ping 209.85.153.104&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 209.85.153.104, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;!!!!!&lt;/P&gt;&lt;P&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 80/80/80 ms&lt;/P&gt;&lt;P&gt;ciscoasa(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2008 10:25:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027405#M918690</guid>
      <dc:creator>rsjavahar</dc:creator>
      <dc:date>2008-06-16T10:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA WAN &amp; LAN Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027406#M918692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes i got IP from the Service provider .. is it possible can i take your help through IM .. please &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2008 10:45:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027406#M918692</guid>
      <dc:creator>rsjavahar</dc:creator>
      <dc:date>2008-06-16T10:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA WAN &amp; LAN Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027407#M918694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt; I think the problem of internet browsing here is in the access list entry:&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any eq www any eq www &lt;/P&gt;&lt;P&gt;because the source port will not be www(80), it will be a random number above 1024, and the destination port will be www(80). so, to solve this problem just remove this entry,  the other commands in this ACL is enough to enable internet browsing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2008 12:12:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027407#M918694</guid>
      <dc:creator>alanajjar</dc:creator>
      <dc:date>2008-06-16T12:12:34Z</dc:date>
    </item>
    <item>
      <title>Re: ASA WAN &amp; LAN Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027408#M918696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That should not be a problem because the next line is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2008 12:53:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027408#M918696</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-16T12:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: ASA WAN &amp; LAN Configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027409#M918698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt; You are right, I thought it is deny statement. &lt;/P&gt;&lt;P&gt;with regards &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jun 2008 13:27:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-wan-lan-configuration/m-p/1027409#M918698</guid>
      <dc:creator>alanajjar</dc:creator>
      <dc:date>2008-06-16T13:27:50Z</dc:date>
    </item>
  </channel>
</rss>

