Moving the outside interface
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-13-2013 11:16 AM - edited 03-11-2019 06:00 PM
We moved the outside interface on an ASA5510 from a10/100 port to a 10/100/1000 port. The nameif and IP address from the old port were removed and added to the new port same security level. All the config that reference the nameif were added back in. We could hit the inside address of the FW but could not hit the internet. From the firewall we could ping the internet and the inside. What are we missing on the new port? We looked at all the obvious but had to move the cable back and reload the old config.
- Labels:
-
NGFW Firewalls
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-13-2013 11:44 AM
Hi,
First thing that came to mind was that perhaps it was an ARP issue related to the upstream router but as you say you were able to test connections to Internet (from ASA) it would seem its not the case.
Its pretty hard to say what the problem was.
Do you by any chance have the configuration from the time you had moved the interface configurations and could post both that and the current working one for comparison?
- Jouni
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-13-2013 12:24 PM
We did clear the ARP tables. I think we saved a copy of the new config and I'll post it. We did run a comparison of the changes we did to the original config and didn't see anything we missed.
