05-04-2017 08:10 AM - edited 03-12-2019 02:19 AM
Hi,
New to Cisco so sorry if these are basic questions..Recently received an ASA5510 that was setup with a single IP subnet from our ISP fiber modem and worked fine. We've just added a second block of IPs (different subnet/gateway) that I'm having issues being able to access. Both blocks are sent to the ASA over a single interface from the fiber modem. I've tried several different configurations and have succeeded in confusing myself at this point. I'm hoping there is a simple way to accomplish this that this forum can point me to. Thanks very much for any direction/information.
05-04-2017 09:14 AM
If I am understanding the post correctly then your ISP has provided a second block of IP addresses. The most common way to use these is to create address translation that uses these new addresses for translation. There is no need to assign the new IPs to interfaces, but just use for translation.
HTH
Rick
05-04-2017 10:08 AM
And not to forget "arp permit-nonconnected" which is needed in this scenario.
05-05-2017 11:46 AM
Thanks for the information. We are currently running 9.1.7 on our 5510 which I've read may have an issue with the arp permit-nonconnected feature. Can anyone confirm this? If this is an issue, would rolling back to 9.1.6 be a good next step? Thanks again.
05-05-2017 04:34 PM
What problems should that be? And you should better upgrade to the newest 9.1(7) interims-version.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide