Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

ASA5505 problem

I have a strange problem with ASA5505.

Some times iam not able to ping the outside interface from Internet and the VPN tunnels goes down.

If i reboot the ASA box i will be able to ping the outside interface and the VPN tunnels comes up.

#sh ver

Cisco Adaptive Security Appliance Software Version 7.2(2)

Device Manager Version 5.2(1)

Compiled on Wed 22-Nov-06 14:16 by builders

System image file is "disk0:/asa722-k8.bin"

Config file at boot was "startup-config"

BAR-ASA5505-01 up 1 hour 24 mins

Hardware: ASA5505, 256 MB RAM, CPU Geode 500 MHz

Internal ATA Compact Flash, 128MB

BIOS Flash LHF00L47 @ 0xffe00000, 1024KB

Encryption hardware device : Cisco ASA-5505 on-board accelerator (revision 0x0)

Boot microcode : CNlite-MC-Boot-Cisco-1.2

SSL/IKE microcode: CNlite-MC-IPSEC-Admin-3.03

IPSec microcode : CNlite-MC-IPSECm-MAIN-2.04

0: Int: Internal-Data0/0 : address is 0019.0724.9ee3, irq 11

1: Ext: Ethernet0/0 : address is 0019.0724.9edb, irq 255

2: Ext: Ethernet0/1 : address is 0019.0724.9edc, irq 255

3: Ext: Ethernet0/2 : address is 0019.0724.9edd, irq 255

4: Ext: Ethernet0/3 : address is 0019.0724.9ede, irq 255

5: Ext: Ethernet0/4 : address is 0019.0724.9edf, irq 255

6: Ext: Ethernet0/5 : address is 0019.0724.9ee0, irq 255

7: Ext: Ethernet0/6 : address is 0019.0724.9ee1, irq 255

8: Ext: Ethernet0/7 : address is 0019.0724.9ee2, irq 255

9: Int: Internal-Data0/1 : address is 0000.0003.0002, irq 255

10: Int: Not used : irq 255

11: Int: Not used : irq 255

Licensed features for this platform:

Maximum Physical Interfaces : 8

VLANs : 3, DMZ Restricted

Inside Hosts : Unlimited

Failover : Disabled

VPN-DES : Enabled

VPN-3DES-AES : Enabled

VPN Peers : 10

WebVPN Peers : 2

Dual ISPs : Disabled

VLAN Trunk Ports : 0

This platform has a Base license.

Serial Number: xxxx

Running Activation Key: xxx

Configuration register is 0x1

Configuration has not been modified since last system restart.

Can somebody tell me what could be the reason?

I have attached the config file.

New Member

Re: ASA5505 problem

Any body has any suggestions?

Cisco Employee

Re: ASA5505 problem

What kind of Internet connection do you have?

When you said you cant ping from the outside, is there a next hop router that you have access to which can ping the outside IP address.

Or if you can get into the console during that time the interface is un-responsive are you able to see any kind of errors on the interface "sh interface vlan 2" & sh interface e0/0"

This should start you in the direction to troubleshoot the problem.



New Member

Re: ASA5505 problem

We do not have next hop router.

The connection is direct ethernet hand off and terminating in ASA 5505 box.

When i connect thro console i do not see any errors int interface vlan 2 & e0/0

If i reboot the ASA the connection comes back and tunnels also.



New Member

Re: ASA5505 problem

I am still getting familiar with ASA or version 7.x software, but I don't see how the ACL allow_in is applied to the outside interface. Are the loss of pings and the dropping of the VPN tunnels happening at the same time? That would seem to be an ISP problem.