ā12-14-2011 02:10 AM - edited ā03-11-2019 03:01 PM
hi there,
I follow the steps according to the basic settings provided by Cisco Support forum, but still failed to access the internet,
Would you advise anything I missed?
Solved! Go to Solution.
ā12-14-2011 02:13 AM
Add this and it shoudl work perfect after that:
nat (inside) 1 0.0.0.0 0.0.0.0
global (outside) 1 interface
cheers,
Varun
ā12-15-2011 09:29 AM
Hello Bill,
That is the problem.....Seems to be an arp issue
Can you try to do a clear arp, clear local-host, clear xlate and then try to ping the modem.
If that does not help, please provide another ip address to the outside interface and then put the old one back.
Example:
nterface Ethernet0/0
ip address x.x.x.y 255.255.255.248
Interface Ethernet 0/0
ip address x.x.x.x 255.255.255.248
Please verify the ASA is connected to the modem (modem got to be connected to por 0/0 on the ASA)
Please rate helpful posts.
Regards,
Julio
ā12-14-2011 02:13 AM
Add this and it shoudl work perfect after that:
nat (inside) 1 0.0.0.0 0.0.0.0
global (outside) 1 interface
cheers,
Varun
ā12-14-2011 02:39 AM
Apply your access-list inside_access_in as access-group on interface inside in "in"direction.
ā12-14-2011 02:50 AM
Access-list is not really required on any interface for the internet access, what is missing from the config is the translation for the traffic.
Varun
ā12-14-2011 07:54 PM
i did adding "nat (inside) 1 0.0.0.0 0.0.0.0" and "global (outside) 1 interface"
but seems still not working, one more stupid question:
how can I verify if the ASA is successfully connected to the internet without connecting a PC for browsing?
is that the gateway of the public IP should be pingable by the ASA if the configuration is fine?
ā12-14-2011 09:05 PM
Hello Bill,
As soon as you provide a public ip address to the outside interface of the ASA and you set a route to the oustide you should be able to ping any host on the outside ( Please try4.2.2.2 from the ASA), unless the border router blocks that traffic.
And by the way you should be able to ping this host 202.105.56.33 if you cannot ping it the ASA will not be able to go to the outside ( if they are directly connected ) that means there might be a problem at the phisical layer, if there is a switch in the middle please give a look.
Please rate helpful posts.
Julio,
ā12-15-2011 02:13 AM
i tried a laptop connecting to the broadband modem directly using the public ip and gateway , the internet works, the gateway is pingable
now the asa5510 is directly connecting with the broadband modem, the gateway 202.105.56.33 is not pingable......
ā12-15-2011 09:29 AM
Hello Bill,
That is the problem.....Seems to be an arp issue
Can you try to do a clear arp, clear local-host, clear xlate and then try to ping the modem.
If that does not help, please provide another ip address to the outside interface and then put the old one back.
Example:
nterface Ethernet0/0
ip address x.x.x.y 255.255.255.248
Interface Ethernet 0/0
ip address x.x.x.x 255.255.255.248
Please verify the ASA is connected to the modem (modem got to be connected to por 0/0 on the ASA)
Please rate helpful posts.
Regards,
Julio
ā12-15-2011 05:27 PM
thanks, i did it, i can ping the ISP now.
may I know what is the purpose of "clear arp, clear local-host, clear xlate"
ā12-15-2011 05:50 PM
Hello Bill,
So the clear arp solved the problem! Great to hear that.
This commands are going to clear the entries on the ASA tables (Xlate[translation table},Local-host and arp table).
Seems like the router has an invalid entry of the ASA mac address so when we clear the arp we force the ASA to send a gratitious arp to the directly connected router so it learns the right mac address.
Please rate helpful posts.
Regards,
Julio
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide