Posted: Sat Jan 12, 2008 12:50 pm Post subject: Cisco ASA 5505 - Problem to access Internet from Inside host
Hi All,
I have a problem to access Internet from inside host, even I have configured all neccessary ACL for the firewall. The internet connection is PPPoe (Wimax), and it can ping outside directly from the firewall, but if I tried to ping the outside url from inside host, it does not reply.
The following is my configuration of the firewall:
ASA Version 7.2(3)
May anyone please check what could be the error with my configuration? I have tried to reconfigure the firewall for so many times since last year December, but without any success.
Joined: Jun 25, 2006 Posts: 65 Location: Buffalo, NY
Posted: Sun Jan 13, 2008 2:02 am Post subject:
I have only configured the simple things on the ASA before, but I think your default route is what is making your inside host not be able to get out. What is the ip of your default gateway of your pppoe connection? Thats what your going to want to put in where you have 192.168.x.x You could also load ASDM and watch the firewall logs to see what is going on. If your not sure how to connect to ASDM here is your url for it on the inside https://192.168.2.1
Posted: Tue Jan 15, 2008 10:10 am Post subject: Default route
I have configured without the default route before, and then it does not have a static route to the ISP when I do show route. The only problem is that only the interface outside can talk to dns server, but not the interface inside. The problem is that the interface inside cannot communicate to the interface outside. That's the only problem that I need to solve now, therefore I can access the Internet.
Joined: Aug 10, 2006 Posts: 1387 Location: GT Manchester, UK
Posted: Tue Jan 15, 2008 3:31 pm Post subject:
Hi there,
Can you confirm, are you trying to ping the External interface from the Internal Interface (or viceversa) ? _________________ Wayne Murphy
Firewall.cx Team Member
www.firewall.cx
Now working for a Security Company called Sec-1 Ltd in the UK, for any
Penetration Testing work visit www.sec-1.com or PM me for details.
I tried to ping the external interface from internal interface. Internal -> External. The packet is always deny by implicit ACL, when I did packet trace from ASDM.
View next topic View previous topic
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You can attach files in this forum You can download files in this forum