cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
553
Views
0
Helpful
4
Replies

ASA can't get to the internet HTTP but can ICMP.

kevin.cooke
Level 1
Level 1

I have to have lost my mind.  I had a firewall setup with the wizard defaults and it worked just fine.  Late a co-worker tried to get a ste to site vpn working and the internet access has been gone since.  I just can't fine the problem.  Can someone look at my config and see what is wrong?

Result of the command: "show run"

: Saved
:
ASA Version 8.6(1)2
!
hostname OCFASA01
enable password yz8p/OLZUxxi0WVC encrypted
passwd j/IegePBFbt/dIRI encrypted
names
!
interface GigabitEthernet0/0
nameif outside
security-level 0
ip address XXX.XXX.XXX.XXX 255.255.255.240
!
interface GigabitEthernet0/1
shutdown
no nameif
no security-level
no ip address
!
interface GigabitEthernet0/2
shutdown
no nameif
no security-level
no ip address
!
interface GigabitEthernet0/3
shutdown
no nameif
no security-level
no ip address
!
interface GigabitEthernet0/4
shutdown
no nameif
no security-level
no ip address
!
interface GigabitEthernet0/5
nameif inside
security-level 100
ip address 10.62.1.9 255.255.255.252
!
interface Management0/0
nameif management
security-level 99
ip address 10.62.250.42 255.255.255.0
management-only
!
boot system disk0:/asa861-2-smp-k8.bin
ftp mode passive
same-security-traffic permit inter-interface
object network AllInside
subnet 10.0.0.0 255.0.0.0
pager lines 24
logging enable
logging buffered debugging
logging asdm informational
logging host inside 10.60.54.78
mtu outside 1500
mtu inside 1500
mtu management 1500
no failover
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-66114.bin
no asdm history enable
arp timeout 14400
!
nat (inside,outside) after-auto source dynamic any interface
route outside 0.0.0.0 0.0.0.0 174.77.235.33 1
route inside 10.0.0.0 255.0.0.0 10.62.1.10 1
route management 10.60.6.31 255.255.255.255 10.62.250.1 1
route management 10.60.54.0 255.255.255.0 10.62.250.1 1
route management 10.60.90.100 255.255.255.255 10.62.250.1 1
route management 10.60.182.0 255.255.255.0 10.62.250.1 1
route management 10.61.90.100 255.255.255.255 10.62.250.1 1
route management 10.62.54.0 255.255.255.0 10.62.250.1 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00
dynamic-access-policy-record DfltAccessPolicy
aaa-server ACS protocol tacacs+
aaa-server ACS (management) host 10.60.90.100
timeout 3
key *****
aaa-server ACS (management) host 10.61.90.100
key *****
no user-identity enable
user-identity default-domain LOCAL
aaa authentication enable console ACS LOCAL
aaa authentication http console ACS LOCAL
aaa authentication ssh console ACS LOCAL
aaa accounting enable console ACS
http server enable
http 10.60.54.0 255.255.255.0 inside
http 10.60.54.0 255.255.255.0 management
http 10.62.54.0 255.255.255.0 inside
http 10.62.54.0 255.255.255.0 management
http 10.60.182.0 255.255.255.0 management
http 10.60.6.31 255.255.255.255 management
http 10.61.54.0 255.255.255.0 management
snmp-server host inside 10.60.6.136 community *****
snmp-server host inside 10.60.6.31 community *****
no snmp-server location
no snmp-server contact
snmp-server community *****
snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart
no sysopt connection permit-vpn
crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac
crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac
crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac
crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac
crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac
crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac
crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac
crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac
crypto ipsec ikev2 ipsec-proposal AES256
protocol esp encryption aes-256
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal AES192
protocol esp encryption aes-192
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal AES
protocol esp encryption aes
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal 3DES
protocol esp encryption 3des
protocol esp integrity sha-1 md5
crypto ipsec ikev2 ipsec-proposal DES
protocol esp encryption des
protocol esp integrity sha-1 md5
telnet timeout 3
ssh 10.62.54.0 255.255.255.0 management
ssh 10.60.54.0 255.255.255.0 management
ssh 10.61.54.0 255.255.255.0 management
ssh 10.60.182.0 255.255.255.0 management
ssh 10.60.6.31 255.255.255.255 management
ssh timeout 5
console timeout 30
management-access management
threat-detection basic-threat
threat-detection statistics access-list
no threat-detection statistics tcp-intercept
ssl encryption rc4-md5
webvpn
!
class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
parameters
  message-length maximum 512
policy-map global_policy
class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect esmtp
  inspect sqlnet
  inspect skinny 
  inspect sunrpc
  inspect xdmcp
  inspect sip 
  inspect netbios
  inspect tftp
  inspect ip-options
  inspect icmp
  inspect http
!
service-policy global_policy global
prompt hostname context
no call-home reporting anonymous
Cryptochecksum:1b40776e13f77a4a6e287d8209f7e5ea
: end

            

Pings go through and you get a reply.  Thanks for you help!

4 Replies 4

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

On a quick look I cant find any specific problem.

Provided that all your hosts are behind the "inside" interface?

You seem to have a lot of networks behind the "management" interface. Though your Management interface is configured with the "management-only" setting so it wont pass any traffic through it. It will only allow management connections to the actual interface.

Though it doesnt really make sense if you can ping hosts on the Internet but cant connect to them?

Is there a chance that there is some problem with DNS?

Give an example IP address of a host that cant connect to Internet.

You can also test firewall rules with command "packet-tracer"

packet-tracer input inside tcp 12345 1.2.3.4 80

Just as an example command. It will tell what the firewall would do to the above HTTP connection to IP 1.2.3.4

- Jouni

Thats the wierd part the packet trace is good.  DNS is fine that was the first thing I checked.  Its all just very odd.

When I ping it resolves to 8.8.8.8.  All I'm trying to get to on the web is www.google.com or ipchicken.com. 

This is baffling!

Thanks

Hi,

Can you take the output of a "packet-tracer" command using some source and destination IP address related to what you are actually testing and copy/paste the output here just to confirm that the ASA configuration isnt problematic.

You can also remove the "inspect http" if you want to test that but to be honest I have never run into problem with it.

- Jouni

OK problem found!! Obviously when Cox Cable shuts off service for billing the just shut off HTTP/HTTPS and leave ICMP and DNS working.  This was the strangest problem ever.  Thanks for all the help.

Review Cisco Networking products for a $25 gift card