cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5272
Views
5
Helpful
40
Replies

Unable to use internet via Cisco asa 5505 firewall

andywilkie1981
Level 1
Level 1

Hi I have an asus ac68u router connected to a cisco asa 5505 firewall I can see the router fine and I have internet access via the AP aka the router and firewall but unable to do anything my ISP is plus net please help

 

Thank You

40 Replies 40

hi i must of forgot to turn on logging, but now when i try and download asdm it tells me my computer settings are correct but the device is 192.168.0.1 is not responding and security/firewall may be blocking connection.

From the CLI, try show log asdm

Hi it shows nothing at all

OK, adds these to the config:

!
logging enable
logging buffered info
logging buffer-size 500000
!

...wait a few minutes for your ASA to connect to the PPPoE and get disconnected. Confirm that you have an internet connection during this time. Then share the output of sh logging

 

Hi,

it is no longer connecting to the internet this is the output from sh logging

ciscoasa(config)# sh logging
Syslog logging: enabled
    Facility: 20
    Timestamp logging: disabled
    Standby logging: disabled
    Debug-trace logging: disabled
    Console logging: disabled
    Monitor logging: disabled
    Buffer logging: level informational, 217 messages logged
    Trap logging: disabled
    Permit-hostdown logging: disabled
    History logging: disabled
    Device ID: disabled
    Mail logging: disabled
    ASDM logging: disabled
%ASA-5-111008: User 'Config' executed the 'object  network INSIDE_NETWORK' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'object  network INSIDE_NETWORK'
%ASA-5-111008: User 'Config' executed the 'nat inside outside dynamic interface' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'nat inside outside dynamic interface'
%ASA-5-111008: User 'Config' executed the 'dynamic-access-policy-record DfltAccessPolicy' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'dynamic-access-policy-record DfltAccessPolicy'
%ASA-5-111008: User 'Config' executed the 'user-identity default-domain LOCAL' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'user-identity default-domain LOCAL'
%ASA-5-111008: User 'Config' executed the 'no snmp-server location' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'no snmp-server location'
%ASA-5-111008: User 'Config' executed the 'no snmp-server contact' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'no snmp-server contact'
%ASA-5-111008: User 'Config' executed the 'snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart'
%ASA-5-111008: User 'Config' executed the 'crypto ipsec security-association pmtu-aging infinite' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'crypto ipsec security-association pmtu-aging infinite'
%ASA-5-111008: User 'Config' executed the 'crypto ca trustpoint _SmartCallHome_ServerCA' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'crypto ca trustpoint _SmartCallHome_ServerCA'
%ASA-5-111008: User 'Config' executed the 'crl configure' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'crl configure'
%ASA-5-111008: User 'Config' executed the 'crypto ca trustpool policy' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'crypto ca trustpool policy'
%ASA-5-111008: User 'Config' executed the 'crypto ca certificate chain _SmartCallHome_ServerCA' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'crypto ca certificate chain _SmartCallHome_ServerCA'
%ASA-5-111008: User 'Config' executed the 'certificate ca' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'certificate ca'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the '<cr>' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed '<cr>'
%ASA-5-111008: User 'Config' executed the 'quit' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'quit'
%ASA-5-111008: User 'Config' executed the 'console timeout 0' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'console timeout 0'
%ASA-5-111008: User 'Config' executed the 'vpdn username <username>jackbarley@plusdsl.net password *' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'vpdn username <username>jackbarley@plusdsl.net password *'
%ASA-5-111008: User 'Config' executed the 'vpdn username jackbarley@plusdsl.net password *' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'vpdn username jackbarley@plusdsl.net password *'
%ASA-5-111008: User 'Config' executed the 'threat-detection basic-threat' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'threat-detection basic-threat'
%ASA-5-111008: User 'Config' executed the 'threat-detection statistics access-list' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'threat-detection statistics access-list'
%ASA-5-111008: User 'Config' executed the 'no threat-detection statistics tcp-intercept' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'no threat-detection statistics tcp-intercept'
%ASA-5-111008: User 'Config' executed the 'prompt hostname context' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'prompt hostname context'
%ASA-5-120008: Call-Home client Configuration was activated.
%ASA-5-120008: Call-Home client Inventory was activated.
%ASA-5-120008: Call-Home client Crashinfo was activated.
%ASA-5-120008: Call-Home client Failover was activated.
%ASA-5-120008: Call-Home client Minidump was activated.
%ASA-5-111008: User 'Config' executed the 'call-home reporting anonymous' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'call-home reporting anonymous'
%ASA-5-111008: User 'Config' executed the 'call-home' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'call-home'
%ASA-5-111008: User 'Config' executed the 'profile CiscoTAC-1' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'profile CiscoTAC-1'
%ASA-5-111008: User 'Config' executed the 'no active' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'no active'
%ASA-5-111008: User 'Config' executed the 'destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService'
%ASA-5-111008: User 'Config' executed the 'destination address email callhome@cisco.com' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'destination address email callhome@cisco.com'
%ASA-5-111008: User 'Config' executed the 'destination transport-method http' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'destination transport-method http'
%ASA-5-111008: User 'Config' executed the 'subscribe-to-alert-group diagnostic' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'subscribe-to-alert-group diagnostic'
%ASA-5-111008: User 'Config' executed the 'subscribe-to-alert-group environment' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'subscribe-to-alert-group environment'
%ASA-5-111008: User 'Config' executed the 'subscribe-to-alert-group inventory periodic monthly' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'subscribe-to-alert-group inventory periodic monthly'
%ASA-5-111008: User 'Config' executed the 'subscribe-to-alert-group configuration periodic monthly' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'subscribe-to-alert-group configuration periodic monthly'
%ASA-5-111008: User 'Config' executed the 'subscribe-to-alert-group telemetry periodic daily' command.
%ASA-5-111010: User 'Config', running 'N/A' from IP 0.0.0.0, executed 'subscribe-to-alert-group telemetry periodic daily'
%ASA-4-411003: Interface Ethernet0/0, changed state to administratively up
%ASA-4-411003: Interface Ethernet0/1, changed state to administratively up
%ASA-4-411003: Interface Ethernet0/2, changed state to administratively up
%ASA-4-411003: Interface Ethernet0/3, changed state to administratively up
%ASA-4-411003: Interface Ethernet0/4, changed state to administratively up
%ASA-4-411003: Interface Ethernet0/5, changed state to administratively up
%ASA-4-411003: Interface Ethernet0/6, changed state to administratively up
%ASA-4-411003: Interface Ethernet0/7, changed state to administratively up
%ASA-6-720002: (VPN-Secondary) Starting VPN Stateful Failover Subsystem...
%ASA-6-720003: (VPN-Secondary) Initialization of VPN Stateful Failover Component completed successfully
%ASA-6-720004: (VPN-Secondary) VPN failover  main thread started.
%ASA-6-720005: (VPN-Secondary) VPN failover timer thread started.
%ASA-6-720006: (VPN-Secondary) VPN failover sync thread started.
%ASA-6-721001: (WebVPN-Secondary) WebVPN Failover SubSystem started successfully.
%ASA-4-411001: Line protocol on Interface Ethernet0/0, changed state to up
%ASA-4-713903: IKE reserved IPSec UDP port 10000 on interface outside successfully
%ASA-4-411001: Line protocol on Interface Ethernet0/1, changed state to up
%ASA-4-713903: IKE reserved IPSec UDP port 10000 on interface inside successfully
%ASA-6-199002: Startup completed.  Beginning operation.
%ASA-5-120001: Call-Home Module started.
%ASA-6-120003: Call-Home is processing configuration event ASA Configuration.
%ASA-6-120003: Call-Home is processing inventory event ASA Inventory.
%ASA-4-120011: To ensure Smart Call Home can properly communicate with Cisco, use the command "dns name-server" to configure at least one DNS server.
%ASA-6-302015: Built outbound UDP connection 1 for inside:255.255.255.255/67 (255.255.255.255/67) to identity:192.168.1.1/68 (192.168.1.1/68)
%ASA-4-120006: Call-Home configuration message to https://tools.cisco.com/its/service/oddce/services/DDCEService failed. Reason: NO_ROUTE
%ASA-4-120011: To ensure Smart Call Home can properly communicate with Cisco, use the command "dns name-server" to configure at least one DNS server.
%ASA-4-120006: Call-Home inventory message to https://tools.cisco.com/its/service/oddce/services/DDCEService failed. Reason: NO_ROUTE
%ASA-4-120011: To ensure Smart Call Home can properly communicate with Cisco, use the command "dns name-server" to configure at least one DNS server.
%ASA-4-120006: Call-Home configuration message to https://tools.cisco.com/its/service/oddce/services/DDCEService failed. Reason: NO_ROUTE
%ASA-4-120011: To ensure Smart Call Home can properly communicate with Cisco, use the command "dns name-server" to configure at least one DNS server.
%ASA-4-120006: Call-Home inventory message to https://tools.cisco.com/its/service/oddce/services/DDCEService failed. Reason: NO_ROUTE
%ASA-4-120011: To ensure Smart Call Home can properly communicate with Cisco, use the command "dns name-server" to configure at least one DNS server.
%ASA-4-120006: Call-Home configuration message to https://tools.cisco.com/its/service/oddce/services/DDCEService failed. Reason: NO_ROUTE
%ASA-4-120011: To ensure Smart Call Home can properly communicate with Cisco, use the command "dns name-server" to configure at least one DNS server.
%ASA-4-120006: Call-Home inventory message to https://tools.cisco.com/its/service/oddce/services/DDCEService failed. Reason: NO_ROUTE
%ASA-4-120011: To ensure Smart Call Home can properly communicate with Cisco, use the command "dns name-server" to configure at least one DNS server.
%ASA-4-120006: Call-Home configuration message to https://tools.cisco.com/its/service/oddce/services/DDCEService failed. Reason: NO_ROUTE
%ASA-4-120005: Call-Home configuration message to https://tools.cisco.com/its/service/oddce/services/DDCEService was dropped. Reason: EXCEED_LIMIT
%ASA-4-120011: To ensure Smart Call Home can properly communicate with Cisco, use the command "dns name-server" to configure at least one DNS server.
%ASA-6-302015: Built outbound UDP connection 2 for inside:192.168.1.2/53 (192.168.1.2/53) to identity:192.168.1.1/9019 (192.168.1.1/9019)
%ASA-4-120006: Call-Home inventory message to https://tools.cisco.com/its/service/oddce/services/DDCEService failed. Reason: NO_ROUTE
%ASA-4-120005: Call-Home inventory message to https://tools.cisco.com/its/service/oddce/services/DDCEService was dropped. Reason: EXCEED_LIMIT
%ASA-6-302016: Teardown UDP connection 1 for inside:255.255.255.255/67 to identity:192.168.1.1/68 duration 0:05:09 bytes 4384
%ASA-6-302016: Teardown UDP connection 2 for inside:192.168.1.2/53 to identity:192.168.1.1/9019 duration 0:02:01 bytes 33
%ASA-6-302010: 0 in use, 2 most used
%ASA-5-502103: User priv level changed: Uname: enable_15 From: 1 To: 15
%ASA-5-111008: User 'enable_1' executed the 'enable' command.
%ASA-5-111007: Begin configuration: console reading from terminal
%ASA-5-111008: User 'enable_15' executed the 'configure terminal' command.
%ASA-5-111010: User 'enable_15', running 'CLI' from IP 0.0.0.0, executed 'configure terminal'
ciscoasa(config)#

Hi ping now says " General Failure "

C:\Users\linux>ping 192.168.0.1

Pinging 192.168.0.1 with 32 bytes of data:
General failure.
General failure.
General failure.
General failure.

Ping statistics for 192.168.0.1:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

C:\Users\linux>

Hi,

The error message "General failure"  noticed while your NIC card is not connected or you don't have a valid IP or Gateway on the machine.

 

Regards,
Deepak Kumar,
Don't forget to vote and accept the solution if this comment will help you!

Hi,

while my NIC is not connected

Hi,

 

I have just notice some of the problem is my internet has been down since 6 am yesterday morning and forgot i was connecting via my phone. I am still waiting for my isp to be back up, its now 4:42 AM GMT .

OK, once your ISP is back up, give the PPPoE client a chance to connect and then share the log buffer.

Hi,

My power cable for the asa just died although its suppose to be a new asa, i will have to buy a new power plug for it now.