Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA 5520 Configuration for Internet Access from Different VLAN


Hi All,

I'm new in ASA configuration, please help me out for my requirement in Campus LAN internet access from different VLAN ( Defalt VLAN 1, is down in all Cisco Switch for security reason, starting from Vlan 2 and so on near about 40 VLANS are there )

I have attached my Network Arch for your ready reference. The brief scionarion are as follows:-

1. In Core Switch 1 ( VTP Server ) all 40 VLANs are created, Core Switch 2 is in standy by ( VTP Mode Client )

2. ASA Outside interface connecetd with Internet Router's Fa0/1, I don't know what IP should I give in both of the Router & ASA interface.

3. Internet Router Fa0/0 ( ) connected with ISP 3 MB Internet link, Gateway Next Hop

4. ISP has given me 6 more Public IP for my Web Server in DMZ Lan, out of 6 I need atleast 4 ip for those server, maximum 2 I can use for any other purpose like if required in ASA & Router Interface or Nat pooling etc. The segment is

5. ISP provided me the Public DNS as & 181

6. Core1 connected to Firewall with a /30 IP, Core switch side and ASA inside interface

7. The DMZ switch is L2 Cisco switch 2960 with no IP address, ASA Outside interface

8. All the DMZ server IP in segment

9. All VLANs are Routed through Inter VLAN routing in L3 Switch ( IP Routing ) dynamic routing used.

10. The Inside (,, ) LAN and DMZ ( ) are configured and working fine with required NAT, Access Rule, Routing etc....

11. The current ASA configuration is also attached for your ready ref.

12. The Core switch VLAN segments like as below:----


    Interface VLAN 1 is DOWN, - 45.0/24,,,,,

My Requirements:- Please help me with your kind expert advice to configure the following scinario.

1st which is required immediate....

# I need to configure my ASA, Router & L3 in such a way that Internet should be accessed from End user PC, that means from end user PC only the public DNS can be resolved without any Proxy.

2nd which is required later.....

# I will install a Proxy server also Local DNS with in next 30 days, so that user have to use internet thriugh Proxy & URL filtering will be activated, at the same time DNS request will come to Local DNS and then it will get resolved by Public DNS

3rd which is also require ASAP

# The DMZ server can also reach Internet as well from Internet user can get into DMZ server.

Everyone's tags (6)
New Member

Re: ASA 5520 Configuration for Internet Access from Different VL

What a surprise...!!!!! Not a single answer....May be I asked very critical or so simple.......or may the information I put here...are too long to any one read the entire....Ami I right...????

Any way...I have solved the problem as per my 1st requirement MOSTLY.........

# From Campuls LAN any VLAN I can ping my Public DNS, but internet still not working as may be its is not getting the http request from Public DNS...any one can help in this regards......??

Cisco Employee

Re: ASA 5520 Configuration for Internet Access from Different VL

I guess it is all of it Added to that it is Thanks Giving Weekend (major holiday like Diwali in India) here in the U.S. So, the responses may be delayed.

let me read your (long) post and try to answer.


Cisco Employee

Re: ASA 5520 Configuration for Internet Access from Different VL

This is initial ASA5510 config. Pls. refer this link:

You may not need the dhcpd config. You can skip that part in the above link.

Also, read Shyam's reponse in this thread:

You mentioned you need this done ASAP, you may want to open a TAC case if you run into issues while configuring or the configuration does not work as expected.

If you need to see samples on here is the link:

We have samples for many scenarios.