07-31-2010 08:23 AM - edited 03-11-2019 11:19 AM
H
ello everyone,
My friend's small medical building's firewall guy got sick and is in the hospital. They moved into a new building and thy have a brand new Cisco 5505 unlimited license. They have Time Warner Biz Class 35meg down/10 up with a cable modem and 5 static ips.
I was trying t oconfigure this for them because biz is opening Monday. I set the inside interface on vlan1 with ip address 192.168.10.1 and the outside interface on e0/0 with one of the static ips. i also set a route for 0.0.0.0 0.0.0.0 outside interface 1.
i can ping external ips form the asa but i cannot get out to the internet from th einside network ( workstations etc.). Do i need to nat/pat or both? also can someone help me with the correct commands? i am researching as we speak.
thanks for any iinput.
Bob
07-31-2010 08:38 AM
Hello,
To start, please try the following commands:
int vlan 2
nameif outside
security-level 0
ip address
access-group outside_access_in in interface outside
Hope this helps.
Regards,
NT
07-31-2010 08:43 AM
thanks! I will be onsite in 90 minutes. i still think i need to set up NAT. am
i wrong?
07-31-2010 08:46 AM
Hello,
Yu are right. You need to setup NAT. The commands I included in my earlier
post (global/NAT) achieve the same.
Hope this helps.
Regards,
NT
07-31-2010 08:52 AM
great i
will give it a shot. thanks!
07-31-2010 12:37 PM
07-31-2010 12:52 PM
Hello,
Please try the following:
no nat (inside,outside) source dynamic any interface
object network LAN
subnet 192.168.10.0 255.255.255.0
nat (inside,outside) dynamic interface dns
Hope this helps.
Regards,
NT
07-31-2010 02:39 PM
Thanks greatly apprciated...works great..tomorrow I need to do ipsec vpn for a few users...I might hit you up again..
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: