07-20-2019 08:31 AM - edited 07-20-2019 10:02 AM
Hi ,
I have been provided with 5 usable ip's x.x.x.x/29 from the ISP
I need to assign 5 public ips to my ASA using VLANS
How do i go about configuring the outside interface?
Currently WAN connection goes to int 0/0 and I have assigned that an IP address provided -81.209.115.101 I would like to assign the second IP on 0/0.200 another available ip -81.209.115.102
Inside network is not yet ready -- but assume there is one ( how would the NAT /ACL's be done in this situation)
Please can someone advice me on this configuration...
Thanks:)
07-25-2019 05:54 AM
Hi , I have enabled ICMP inspection I might have deleted the config line beofre posting it here..
When I Run this with echo-reply or information-request - its fails with the NAT error
packet-tracer input GUEST icmp 192.168.80.1 0 1 8.161.119.238 xml
When done with just echo everything shows a tick on the packet tracer..
07-25-2019 07:56 AM
Echo reply would not work as a synthetic packet as is used by packet-tracer since there is no record of the echo request having been in through the device.
Again, I highly recommend to use tcp as a test through the firewall and in a way that matches real world traffic flows.
07-25-2019 08:07 AM
07-25-2019 08:20 PM
At a quick glance they appear correct otherwise.
07-29-2019 02:01 AM - edited 07-29-2019 02:02 AM
@Marvin Rhoads Thank you for you r continued help , I found out the issue and what fixed it was I needed to put the nat after auto source dynamic and now traffic is flowing :)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide