Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member



Please find the attached file ASA configuration on ASA we getting internet but local network not getting internet .

Hall of Fame Super Silver

The config looks pretty basic

The config looks pretty basic and mostly OK.

Please tell us what your local network host configuration and test is - i.e are you getting a DHCP address from the ASA, is the gateway being set to the ASA inside interface, what's your IP address and what test are you using to check Internet connectivity?

New Member

Dear Mr.Marvin Rhoads ,Thanks

Dear Mr.Marvin Rhoads ,

Thanks for your replay as per enclosed config on interface GigabitEthernet0/1 we connected directly to one system and given lan ip dhcp on systems dhcp ip is resolved from system we able to ping to ASA geteway ip but from system we are not getting internet.we are not  configured any host .

We have fortigate firewall find the enclosed FG configure we want to replace FG to ASA5525-SSD120-K9 please suggest me how to configure on ASA.

Hall of Fame Super Silver

What test are you using to

What test are you using to "get Internet"?

I would suggest you do the following to clean up the config:

1. remove the global ACL allowing ip any-any

2. remove the application of outside service-policy and

3. add the icmp inspection to the global policy.

conf t

no access-group 101 global

no service-policy outside-policy interface outside

policy-map global_policy
class inspection_default
  inspect icmp

wr mem

Then provide output of the following commands from the ASA:


packet-tracer input inside icmp 0 0 detailed
New Member

Dear Sir,Please give me basic

Dear Sir,

Please give me basic commands for 5525X for inter net configuration to local system.

On 5510 if i given these commands i getting internet to local systems, but same commands not allowed to 5525X suggested me commands on Version 9.1(3) 

global (outside) 1 interface
nat (inside) 0 access-list nonat
nat (inside) 1
route outside x.x.x.x 1.

New Member

 We have lic file how can i


We have lic file how can i get licence to asa we need key for activate the license.

Hall of Fame Super Silver

When you say license file

When you say license file what type of license are you talking about?

There is an ASA feature license and an ASA CX Net Generation Firewall subscription license file.

The ASA feature license is delivered in the for of a Product Activation Key (PAK) which you use to get an activation-key for the ASA. You can go to to obtain that activation-key.

If you have an NGFW license file you install and activate that using the PRSM interface.

New Member


On i done the register licence for 



Follow these steps to install your ASA-CX license file:

1.       Select Administration > Licenses.
2.       Select I want to > Upload License File.
3.       In the Upload License File panel, click Browse and select the license file from your workstation or network drive.
4.       Click Upload.

where can  i found the step 1

1.       Select Administration > Licenses.

please suggest me


Hall of Fame Super Silver

Did you try the commands I

Did you try the commands I already gave you earlier?

The ones you listed above (nat-control etc.) are old style Pix / pre 8.3 syntax. The ones in the initial configuration you posted look OK with the changes I suggested already.

VIP Green

As Marvin has mentioned, your

As Marvin has mentioned, your config looks fine for access to the internet.

could you please run a packet tracer which might shed some light on what is happening:

packet-tracer input inside tcp 12345 80 detail

Post the output here.


Please remember to select a correct answer and rate helpful posts


Please remember to rate and select a correct answer
CreatePlease login to create content