cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6263
Views
0
Helpful
2
Replies

ASA 5512-X no route to host to default gateway and any other hosts

Steve Block
Level 1
Level 1

Hi,

Can someone help me with the following?

I am working on an ASA 5512-x at the moment.

I just returned to the factory default I started to set the IP of inside and outside interface and after this I set the default gateway, but ASA don't use it.

I cannot ping the default gateway neither. I got "No route to host"  message.

Can someone have any idea what can I do, what did I wrong?

This is my really basic config:

: Saved

:

ASA Version 9.1(1)

!

hostname ciscoasa

enable password 8Ry2YjIyt7RRXU24 encrypted

passwd 2KFQnbNIdI.2KYOU encrypted

names

!

interface GigabitEthernet0/0

nameif OUTSIDE

security-level 0

ip address 58.143.244.170 255.255.255.248

!

interface GigabitEthernet0/1

shutdown

nameif inside

security-level 100

ip address 10.0.0.10 255.255.255.0

!

interface GigabitEthernet0/2

shutdown

no nameif

no security-level

no ip address

!

interface GigabitEthernet0/3

shutdown

no nameif

no security-level

no ip address

!

interface GigabitEthernet0/4

shutdown

no nameif

no security-level

no ip address

!

interface GigabitEthernet0/5

shutdown

no nameif

no security-level

no ip address

!

interface Management0/0

management-only

nameif management

security-level 100

ip address 192.168.1.1 255.255.255.0

!

boot system disk0:/asa911-smp-k8.bin

ftp mode passive

pager lines 24

logging asdm informational

mtu OUTSIDE 1500

mtu management 1500

mtu inside 1500

icmp unreachable rate-limit 1 burst-size 1

no asdm history enable

arp timeout 14400

no arp permit-nonconnected

route OUTSIDE 0.0.0.0 0.0.0.0 58.143.244.169 1

route OUTSIDE 8.8.8.8 255.255.255.255 58.143.244.169 1

timeout xlate 3:00:00

timeout pat-xlate 0:00:30

timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02

timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00

timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00

timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute

timeout tcp-proxy-reassembly 0:01:00

timeout floating-conn 0:00:00

dynamic-access-policy-record DfltAccessPolicy

user-identity default-domain LOCAL

http server enable

http 192.168.1.0 255.255.255.0 management

no snmp-server location

no snmp-server contact

snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart

crypto ipsec security-association pmtu-aging infinite

crypto ca trustpool policy

telnet timeout 5

ssh timeout 5

console timeout 0

dhcpd address 192.168.1.2-192.168.1.254 management

dhcpd enable management

!

threat-detection basic-threat

threat-detection statistics access-list

no threat-detection statistics tcp-intercept

!

class-map inspection_default

match default-inspection-traffic

!

!

policy-map type inspect dns preset_dns_map

parameters

  message-length maximum client auto

  message-length maximum 512

policy-map global_policy

class inspection_default

  inspect dns preset_dns_map

  inspect ftp

  inspect h323 h225

  inspect h323 ras

  inspect rsh

  inspect rtsp

  inspect esmtp

  inspect sqlnet

  inspect skinny

  inspect sunrpc

  inspect xdmcp

  inspect sip

  inspect netbios

  inspect tftp

  inspect ip-options

!

service-policy global_policy global

prompt hostname context

no call-home reporting anonymous

Cryptochecksum:7ea5c3b31f8ca799c909fa7985c06e5d

: end

ciscoasa# ping 8.8.8.8

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 8.8.8.8, timeout is 2 seconds:

No route to host 8.8.8.8

Success rate is 0 percent (0/1)

ciscoasa# sh route

Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP

       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area

       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2

       E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP

       i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area

       * - candidate default, U - per-user static route, o - ODR

       P - periodic downloaded static route

Gateway of last resort is not set

ciscoasa#

ciscoasa# ping 58.143.244.169

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 58.143.244.169, timeout is 2 seconds:

No route to host 58.143.244.169

Success rate is 0 percent (0/1)

Thank you for all your help.

2 Replies 2

Steve Block
Level 1
Level 1

cancel it, i was wrong

Istvan kelemen
Level 1
Level 1

Hello,

You need to inspect icmp.

add this: inspect icmp
Isnpect icmp error
Under:
class inspection_default


Sent from Cisco Technical Support Android App

Review Cisco Networking products for a $25 gift card