Cisco Support Community
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

ASA5510 setup

hi there

i have an ASA5510 with the following setup:

e0 - outside interface-212.188.x.x/28

e1 - inside if - 192.168.3.x/24 into 2960sw pport 10 vlan 1-switchport access

e2 - dmz if - 172.16.x.x/24 into port 14 vlan 40 switchport access.

linux server plugged into port 14 vlan40 ip 172.16.x.x/24 g/w dmz interface.

windows server plugged into port 15 vlan1 ip 192.16.3.x/24. g/w inside interface

both the windows server and linux server can ping their default gateways but i cant seem to ping each server across the network or establish an ssh connection to the liinux box.

the sh route command on the asa shows the 3 connected n/w (outside,inside&dmz).

I can get to the internet fromt the inside thatis ok

when i try to ping the windows erver from the linuxbox i get network unreachable. below are the access lists:

access-list 106 line 1 extended permit tcp host 192.168.3.x host 172.16.10.x eq ssh (hitcnt=9)

access-list 106 line 2 extended permit icmp any any (hitcnt=148)

access-list 106 line 3 extended permit ip any any (hitcnt=122)

access-group 106 in interface inside

Any ideas? Plese help as im really baffled.



Re: ASA5510 setup

Try adding...

static (inside,dmz) netmask

You will also need an acl applied into the dmz interface to allow the icmp reply traffic, or to initiate communication from the dmz to the inside.

access-list dmz extended permit icmp any

access-list dmz extended deny ip any

access-list dmz permit ip any any

access-group dmz in interface dmz

Hope that helps.

Community Member

Re: ASA5510 setup

thanks for your reply.

it was more to do with the linux box rather than the asa. sorted out after i had to add a static route for the connected nw and also a default route

CreatePlease to create content