2 Replies Latest reply: Jun 20, 2012 7:31 AM by Eminence_Front RSS

    i cannot access to internet behind asa


      hello for all

      i bought cisco asa 5540
      i have cisco router 2811 with static ip
      and make nat to conected to internet pat nat
      and have for exchange server


      i want to confiure asa behind router
      i mean leave all configure on cisco router
      when i make out side and inside lan all is ok
      but all pc conected on inside interface of asa 5540 cannot access to internet
      and also cannot ping from pc ip on interface outside i permet icmp in servise poilcy and incpection icmp
      but i mean no conection not ping only
      my senaro

      lan------------------ asa -------------------- cisco router ----------internet


      i will post configration for asa

      ASA Version 8.4(2)
      hostname ciscoasa
      enable password 8Ry2YjIyt7RR24 encrypted


      interface GigabitEthernet0/0
      nameif outside
      security-level 0
      ip address
      interface GigabitEthernet0/1
      nameif inside
      security-level 100
      ip address
      interface GigabitEthernet0/2
      no nameif
      no security-level
      no ip address
      interface GigabitEthernet0/3
      no nameif
      no security-level
      no ip address
      interface Management0/0
      nameif management
      security-level 100
      ip address
      same-security-traffic permit inter-interface
      same-security-traffic permit intra-interface
      access-list OUTSIDE extended permit ip any any
      access-list inside_access_in extended permit ip any any
      access-list cap extended permit icmp any host
      access-list cap extended permit icmp host any
      access-group OUTSIDE in interface outside
      access-group inside_access_in in interface inside
      route inside 1




      policy-map global_policy
      class inspection_default
      inspect dns preset_dns_map
      inspect ftp
      inspect h323 h225
      inspect h323 ras
      inspect rsh
      inspect rtsp
      inspect esmtp
      inspect sqlnet
      inspect skinny
      inspect sunrpc
      inspect xdmcp
      inspect sip
      inspect netbios
      inspect tftp
      inspect ip-options
      inspect icmp
      inspect icmp error
      my router access to internet and all lan access to intenet without asa

      so what is missing or wrong conigration to access to internet

      best regards

        • 1. Re: i cannot access to internet behind asa
          Scott Morris - CCDE/4xCCIE/2xJNCIE

          On your firewall there, you are using private addresses for inside and outside...


          You don't appear to have any NAT configuration or statics.  The ASA needs to have an xlate table entry one way or the other, even if things aren't changing.


          Try upping your logging to debug and see what errors are popping up on the ASA as you try to move traffic through, that will likely help you!



          • 2. Re: i cannot access to internet behind asa

            Missing NAT config (which version Code, on ASA, and we can help you ?)


            2.) need a return route on the Router, telling internet sourced traffic how to reach hosts behind ASA. (e.g. if you're going to NAT the Exchange behind a pub IP on the ASA< you need to make ASA next hop inbound, in your Router, for that Network / Host-IP)


            You need




            pubIP--<Inside-192>--->--->(NAT) ASA---<natted_IP>---> ((INET_Router)pub_Internet


            upon return, it looks like this


            INET-HOST--->"Some-Pub-IP"---<<your router>>-->-->--(where do i go?)--|<ASA>>|--192-lan