cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1036
Views
0
Helpful
5
Replies

Routing

atulpal singh
Level 1
Level 1

i am not able to ping the server having the config 200.0.0.4 . can any body help ? please find the diagram here attached 

 

 

hostname ciscoasa

names

!

interface GigabitEthernet1/1

nameif inside

security-level 100

ip address 192.168.1.1 255.255.255.0

!

interface GigabitEthernet1/2

nameif outside

security-level 0

ip address 200.0.0.2 255.255.255.0

!

interface GigabitEthernet1/3

no nameif

security-level 100

no ip address

!

interface GigabitEthernet1/4

no nameif

no security-level

no ip address

shutdown

!

interface GigabitEthernet1/5

no nameif

no security-level

no ip address

shutdown

!

interface GigabitEthernet1/6

no nameif

no security-level

no ip address

shutdown

!

interface GigabitEthernet1/7

no nameif

no security-level

no ip address

shutdown

!

interface GigabitEthernet1/8

no nameif

no security-level

no ip address

shutdown

!

interface Management1/1

management-only

no nameif

no security-level

no ip address

!

object network internal

subnet 192.168.1.0 255.255.255.0

object-group service port1 tcp

port-object eq 59443

object-group service port2 tcp-udp

port-object range 333 555

port-object range 333 555

object network test

host 192.168.1.2

object network test1

host 192.168.1.3

object-group service test4 udp

port-object range 11 50

!

route outside 0.0.0.0 0.0.0.0 200.0.0.4 1

!

access-list per extended permit tcp host 200.0.0.1 host 192.168.1.2 eq 59443

access-list norm extended permit ip 192.168.1.0 255.255.255.0 any

!

!

object network internal

nat (inside,outside) dynamic interface

!

 

 

5 Replies 5

Alan Ng'ethe
Level 3
Level 3
In your diagram, which server has the IP 200.0.0.4? If it is the server in the diagram then you don't really need the default route since the ASA sees the network 200.0.0.0/24 as an directly connected network. Additionally you need access-list 'norm' applied in the inbound direction to the inside interface. Though you could also do without it because of the existing security levels.
Remember to rate helpful posts and/or mark as a solution if your issue is resolved.

Leo Laohoo
Hall of Fame
Hall of Fame
Please contact your instructor.
This thread is obviously (glaring) a school/homework.
Be warned that by helping, you may GET A FAILING GRADE because our answers (no matter how "helpful") may not be what the instructor wants to see.
One of the role of the instructor is look out for students who are "lost" or "confused" and steer them into the right direction.

I agree, study and review your school material and practice on PT

this is not a homework.. i was confused on some point , which you can be too on some other case .. instead of writing garbage , u could have given straight answer . if you dont know then shut up

this is not a homework.. i was confused on some point , which you can be too on some other case .. instead of writing garbage , u could have given straight answer .
Review Cisco Networking products for a $25 gift card