Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA Issues

I am new to configuring ASA firewall.

 

Currently what I am struggling with is having inside interface being able to ping external sources. I can do this on the outside interface but not the inside interface.

 


ASA Version 9.0(3)


xlate per-session deny tcp any4 any4
xlate per-session deny tcp any4 any6
xlate per-session deny tcp any6 any4
xlate per-session deny tcp any6 any6
xlate per-session deny udp any4 any4 eq domain
xlate per-session deny udp any4 any6 eq domain
xlate per-session deny udp any6 any4 eq domain
xlate per-session deny udp any6 any6 eq domain
names
dns-guard
!
interface GigabitEthernet0/0
 nameif Inside
 security-level 100
 ip address 10.X.X.X 255.X.X.X.X
!
interface GigabitEthernet0/1
 nameif Outside
 security-level 0
ip address X.X.X.X X.X.X.X
!
boot system disk0:/asa903-k8.bin
ftp mode passive
dns server-group DefaultDNS

object network obj-X.X.X.X - X.X.X.X
 range X.X.X.X-X.X.X.X
object network NAT
 subnet 10.X.X.X X.X.X.X
object network any_subnet
 subnet 0.0.0.0 0.0.0.0
object network all_nat
object network NETWORK_SUBNET
 subnet 10.X.X.X 255.X.X.X
object network any_obj
 subnet 0.0.0.0 0.0.0.0
object-group icmp-type ALLOW_ICMP
 icmp-object echo-reply
 icmp-object echo
 icmp-object unreachable
 icmp-object traceroute
 icmp-object time-exceeded
object-group network obj_any
access-list SSH extended permit tcp host 10.X.X.X eq ssh host 10.X.X.X
access-list ICMP extended permit icmp any any object-group ALLOW_ICMP
access-list ICMP extended permit icmp 10.X.X.X 255.X.X.X any
pager lines 24
mtu Inside 1500
mtu Outside 1500
no failover
icmp unreachable rate-limit 1 burst-size 1
icmp permit any Inside
icmp permit any Outside
asdm image disk0:/asdm-507.bin
no asdm history enable
arp timeout 14400
no arp permit-nonconnected
nat (Inside,Outside) source dynamic any interface
nat (Inside,Outside) source static any interface
!
object network NETWORK_SUBNET
 nat (Inside,Outside) dynamic interface
object network any_obj
 nat (Inside,Outside) dynamic interface
access-group ICMP in interface Outside
route Outside 0.0.0.0 0.0.0.0 X.X.X.X
timeout xlate 3:00:00
timeout pat-xlate 0:00:30
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00
dynamic-access-policy-record DfltAccessPolicy
user-identity default-domain LOCAL
aaa authentication enable console LOCAL
aaa authentication ssh console LOCAL
aaa authentication telnet console LOCAL
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec security-association pmtu-aging infinite
crypto ca trustpool policy
telnet timeout 5
ssh timeout 5
console timeout 0
threat-detection basic-threat
threat-detection statistics access-list
no threat-detection statistics tcp-intercept

class-map inspection_default
 match default-inspection-traffic
!
!
policy-map type inspect dns migrated_dns_map_1
 parameters
  message-length maximum client auto
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns migrated_dns_map_1
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect netbios
  inspect rsh
  inspect rtsp
  inspect skinny
  inspect esmtp
  inspect sqlnet
  inspect sunrpc
  inspect tftp
  inspect sip
  inspect xdmcp
  inspect icmp
  inspect icmp error
  inspect ip-options
!

: end
 

Can someone point me in the right direction?

  • Small Business Routers
Everyone's tags (1)
32
Views
0
Helpful
0
Replies
This widget could not be displayed.