02-28-2011 09:35 PM - edited 03-11-2019 12:58 PM
I set up an ASA 5505 at home through PPPOE connection. The ASA seems to obtain an IP address correctly.
and I can ping a public ip address using the outside nic, but not the inside nic. I saw the error message
when I ping: No route to ff0213 from fe801bc2b1288cd5bc1. As a result, I cannot connect to the Internet.
Help!
02-28-2011 10:50 PM
Ok so inside hosts cannot access the Internet - can you post your configuration so we can take a look?
03-01-2011 12:23 AM
Sounds like you are missing the default route...something like:
route outside 0.0.0.0 0.0.0.0 x.x.x.x 1
But as Allan said, if you can post the config we can take a look.
Regards,
Ian
03-01-2011 08:05 AM
03-01-2011 08:06 AM
Thanks for reply. configuration file has attached
03-01-2011 08:48 AM
Who is assigning IP Addresses to the hosts? What is your DNS set to for the hosts? Can you ping out to the internet, just not browse?
03-01-2011 09:04 AM
I can add the following command lines, but makes no differences
dhcpd address 10.40.1.11-10.40.1.33 inside
dhcpd dns 64.83.1.10 64.83.0.10
dhcpd enable inside
Thanks for your input!!
03-01-2011 09:16 AM
you shouldn't have to do this but, just for fun add these lines:
access-list inside-out permit ip any any
access-group inside-out in interface inside
03-01-2011 09:20 AM
OK, thanks.
I will try it later. BTW, the host is obtaining the ip address through PPPOE connection.
03-01-2011 04:36 PM
can you do this?:
Your inside network is as follows: 10.40.1.0 255.255.255.0
can you configure a host with an ip under this range and set up its default gateway to be 10.40.1.10 (ASA). Once this is done try to ping the firewall inside IP address -> 10.40.1.10
If you are succesfull then ping a host on the internet like 4.2.2.2 --> make sure you add a ACL on the outside interface to permit the echo reply back.
If succesfull you should be able to browse.
Also, a good idea is to enable the debug for ICMP: debug icmp trace
Also enable logging to see any important logs:
If you are logged in via telnet:
logging monitor 7
logg on
term mon
term no mon -> to disable this
If you are logged in via console:
Logg console 7
logg on
no logg on -> to disable it
To disbale the debug icmp trace debug:
und all
Let us know!
03-01-2011 06:13 PM
What does a packet tracer say?
packet-tracer input inside tcp 10.40.1.5 12345 198.133.219.25 80 detail
Best Regards,
-jb
03-02-2011 07:08 AM
I would like to thank all of you giving me good suggestions on this problem.
It was Windows Vista problem. Windows Network Diagnostics tool automatically
repaired Internet connection problem by resetting DNS commmunication.
Sincerely,
David Wu
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide