How to connect to the internet with ASA 5515 X?

Hi all:
I just got my new ASA 5515 X firewall and I got stuck in the first steps.
I can ping a public IP (8.8.8.8) from the device but I cannot ping it from my LAN.
I know I am missing either NAT rules or Access rules or maybe both, but I need some help, please.
Thank you.

ciscoasa# sho run
: Saved
ASA Version 9.1(2)
hostname ciscoasa
enable password djMW8L3Na14L7q2L encrypted
names
interface GigabitEthernet0/0
 nameif OUTSIDE
 security-level 0
 ip address 10.9.251.2 255.255.255.0
interface GigabitEthernet0/1
 nameif INSIDE
 security-level 100
 ip address 10.9.250.2 255.255.255.0
interface GigabitEthernet0/2
 shutdown
 no nameif
 no security-level
 no ip address
interface GigabitEthernet0/3
<--- More --->
 shutdown
 no nameif
 no security-level
 no ip address
interface GigabitEthernet0/4
 shutdown
 no nameif
 no security-level
 no ip address
interface GigabitEthernet0/5
 shutdown
 no nameif
 no security-level
 no ip address
interface Management0/0
 management-only
 nameif management
 security-level 100
 ip address 192.168.1.1 255.255.255.0
ftp mode passive
<--- More --->
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
object network inside_net
 subnet 10.9.250.0 255.255.255.0
pager lines 24
logging asdm informational
mtu OUTSIDE 1500
mtu INSIDE 1500
mtu management 1500
no failover
icmp unreachable rate-limit 1 burst-size 1
icmp permit any INSIDE
no asdm history enable
arp timeout 14400
no arp permit-nonconnected
object network inside_net
 nat (INSIDE,OUTSIDE) dynamic interface
route OUTSIDE 0.0.0.0 0.0.0.0 10.9.251.1 1
timeout xlate 3:00:00
timeout pat-xlate 0:00:30
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
<--- More --->
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00
dynamic-access-policy-record DfltAccessPolicy
user-identity default-domain LOCAL
http server enable
http 192.168.1.0 255.255.255.0 management
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart
crypto ipsec security-association pmtu-aging infinite
crypto ca trustpool policy
telnet timeout 5
ssh timeout 5
ssh key-exchange group dh-group1-sha1
console timeout 0
dhcpd address 192.168.1.2-192.168.1.254 management
dhcpd enable management
threat-detection basic-threat
threat-detection statistics access-list
no threat-detection statistics tcp-intercept
class-map inspection_default
<--- More --->
 match default-inspection-traffic
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum client auto
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect esmtp
  inspect sqlnet
  inspect skinny  
  inspect sunrpc
  inspect xdmcp
  inspect sip  
  inspect netbios
  inspect tftp
  inspect ip-options
<--- More --->
  inspect icmp
service-policy global_policy global
prompt hostname context
no call-home reporting anonymous
Cryptochecksum:d41d8cd98f00b204e9800998ecf8427e
: end
ciscoasa# sho runpacket-tracer input inside icmp 10.9.250.3 0 0 8.8.8.8 detailed
Phase: 1
Type: ROUTE-LOOKUP
Subtype: input
Result: ALLOW
Config:
Additional Information:
in   0.0.0.0         0.0.0.0         OUTSIDE
Phase: 2
Type: NAT
Subtype:
Result: ALLOW
Config:
object network inside_net
 nat (INSIDE,OUTSIDE) dynamic interface
Additional Information:
 Forward Flow based lookup yields rule:
 in  id=0x7fff293db020, priority=6, domain=nat, deny=false
    hits=22235, user_data=0x7fff2a6a3810, cs_id=0x0, flags=0x0, protocol=0
    src ip/id=10.9.250.0, mask=255.255.255.0, port=0, tag=0
    dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0, dscp=0x0
    input_ifc=INSIDE, output_ifc=OUTSIDE
Phase: 3
<--- More --->
Type: NAT
Subtype: per-session
Result: ALLOW
Config:
Additional Information:
 Forward Flow based lookup yields rule:
 in  id=0x7fff29b804b0, priority=0, domain=nat-per-session, deny=true
    hits=26730, user_data=0x0, cs_id=0x0, reverse, use_real_addr, flags=0x0, protocol=0
    src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0
    dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0, dscp=0x0
    input_ifc=any, output_ifc=any
Phase: 4
Type: IP-OPTIONS
Subtype:
Result: ALLOW
Config:
Additional Information:
 Forward Flow based lookup yields rule:
 in  id=0x7fff2a633a90, priority=0, domain=inspect-ip-options, deny=true
    hits=25709, user_data=0x0, cs_id=0x0, reverse, flags=0x0, protocol=0
    src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0
    dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0, dscp=0x0
    input_ifc=INSIDE, output_ifc=any
<--- More --->
Result:
input-interface: INSIDE
input-status: up
input-line-status: up
output-interface: OUTSIDE
output-status: up
output-line-status: up
Action: drop
Drop-reason: (nat-xlate-failed) NAT failed
ciscoasa#

Similar Messages

  • How do I connect to the internet with my new IPAD ?

    How do I connect to the internet with myt new Ipad

    See here for connecting to the Internet:
    http://support.apple.com/kb/HT1695
    If you have any problems there is troubleshooting advice here: http://www.apple.com/support/ipad/wifi/

  • How do i connect to the internet with my ipad?

    how do i connect to the internet with my ipad?

    Did you turn WiFi on in the Settings App? If WiFi is turned on, your iPad should be able to see any WiFi networks that you can connect to and you should be able to tap on one of those, enter a password if needed and then tap the join button.
    I get the feeling that you know this and the problem needs further explanation so ... Can you explain in more detail?

  • How do i connect to the internet with apple tv

    how do i connect to the internet with apple tv

    Ethernet cable from your router, or configure wifi in Settings.

  • WRT 120N- Cannot connect to the internet with more than one PC at a time.

    Before I went on a three month vacation,I could connect 3 or 4 PC's either wireless or wired to my router with no problems at all.I have a desk top and a laptop computer which I use at home.After I returned,I found that I could connect to the internet with only one PC at a time.
    If I was say,connected via my laptop,my desk top would continuously keep getting disconnected and vice versa.I have been reading the suggestions from experts here and have done a few checks based on them.I also cannot get to my router page which is 192.168.1.1 I keep getting a message that says "Problem Loading Page" and this happens with both,Firefox and Internet Explorer.I am running Windows 7 - 32 bit on my desk top and Vista Home Premium on my laptop.
    I have opened the "Command Prompt" dialogue and pinged 192.168.1.1 and thereafter I typed in "ipconfig".These are the results:
    Microsoft Windows [Version 6.0.6002]
    Copyright (c) 2006 Microsoft Corporation.  All rights reserved.
    C:\Users\Gordon>ping 192.168.1.1
    Pinging 192.168.1.1 with 32 bytes of data:
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=111
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=111
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=111
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=111
    Ping statistics for 192.168.1.1:
        Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 0ms, Maximum = 0ms, Average = 0ms
    C:\Users\Gordon>ipconfig
    Windows IP Configuration
    PPP adapter Brownwolf:
       Connection-specific DNS Suffix  . :
       IPv4 Address. . . . . . . . . . . : 92.98.42.65
       Subnet Mask . . . . . . . . . . . : 255.255.255.255
       Default Gateway . . . . . . . . . : 0.0.0.0
    Ethernet adapter Local Area Connection* 22:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
    Wireless LAN adapter Wireless Network Connection:
       Connection-specific DNS Suffix  . :
       IPv6 Address. . . . . . . . . . . : 2002:5c62:2a41:c:35a2:8753:8832:f494
       Site-local IPv6 Address . . . . . : fec0::c:35a2:8753:8832:f494%2
       IPv6 Address. . . . . . . . . . . : 2002:5661:4cc9:c:35a2:8753:8832:f494
       Temporary IPv6 Address. . . . . . : 2002:5661:4cc9:c:a408:59a3:918e:f0ab
       Temporary IPv6 Address. . . . . . : 2002:5c62:2a41:c:a408:59a3:918e:f0ab
       Link-local IPv6 Address . . . . . : fe80::35a2:8753:8832:f494%12
       IPv4 Address. . . . . . . . . . . : 192.168.0.1
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Default Gateway . . . . . . . . . :
    Ethernet adapter Local Area Connection:
       Connection-specific DNS Suffix  . :
       IPv6 Address. . . . . . . . . . . : 2002:5c62:2a41:c:413:cf4f:77af:474d
       Site-local IPv6 Address . . . . . : fec0::c:413:cf4f:77af:474d%1
       IPv6 Address. . . . . . . . . . . : 2002:5661:4cc9:c:413:cf4f:77af:474d
       Temporary IPv6 Address. . . . . . : 2002:5661:4cc9:c:1591:ad9:13da:8fea
       Temporary IPv6 Address. . . . . . : 2002:5c62:2a41:c:1591:ad9:13da:8fea
       Link-local IPv6 Address . . . . . : fe80::413:cf4f:77af:474d%11
       IPv4 Address. . . . . . . . . . . : 192.168.1.100
       Subnet Mask . . . . . . . . . . . : 255.255.255.0
       Default Gateway . . . . . . . . . : fe80::35a2:8753:8832:f494%11
                                           192.168.1.1
    Tunnel adapter Local Area Connection* 7:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
    Tunnel adapter Local Area Connection* 11:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
    Tunnel adapter Local Area Connection* 14:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
    Tunnel adapter Local Area Connection* 15:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
    Tunnel adapter Local Area Connection* 19:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
    Tunnel adapter Local Area Connection* 20:
       Connection-specific DNS Suffix  . :
       IPv6 Address. . . . . . . . . . . : 2002:5c62:2a41::5c62:2a41
       Default Gateway . . . . . . . . . : 2002:c058:6301::c058:6301
    Tunnel adapter Local Area Connection* 23:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
    Tunnel adapter Local Area Connection* 24:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
    Tunnel adapter Local Area Connection* 28:
       Media State . . . . . . . . . . . : Media disconnected
       Connection-specific DNS Suffix  . :
    I presume that this model is a modem **bleep** router as I do not have a separate modem with my system.I have a DSL connection and the firmware version of my router is ver.1.0.If I recall,I did upgrade to the next firmware upgrade a few months after I purchased the router but I am not sure.
    I use both my PC's to run a small business venture and I am worried that resetting the router may cause some other problems and will stop me from using the internet.
    The Command Prompt information above was taken from my laptop.
    Any help will be really appreciated.
    Gerard.
    Solved!
    Go to Solution.

    brownwolf66 wrote:
    No,I have a desk top and a laptop and I cannot access 192.168.1.1 on either of them.In my OP,I have used the Command Prompt dialogue on both computers to ping 192.168.1.1 and I have attached the results.This is what I got:
    Microsoft Windows [Version 6.0.6002]
    Copyright (c) 2006 Microsoft Corporation.  All rights reserved.
    C:\Users\Gordon>ping 192.168.1.1
    Pinging 192.168.1.1 with 32 bytes of data:
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=111
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=111
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=111
    Reply from 192.168.1.1: bytes=32 time<1ms TTL=111
    Ping statistics for 192.168.1.1:
        Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
    Approximate round trip times in milli-seconds:
        Minimum = 0ms, Maximum = 0ms, Average = 0ms
    The results I obtained using ipconfig in the command prompt have already been mentioned in my OP.
    I do not know if the above result is what it is supposed to be but I still cannot access my router's home page.How do I verify if there is a proxy server and if there is one,how do I disable it in my browsers?This problem occured suddenly as a few months earlier all was well.It's getting rather frustrating.
    I suggest resetting the router. Make sure firmware is updated. You can download it here - http://homesupport.cisco.com/en-us/support/routers/WRT120N. After firmware upgrade, reset and reconfigure. Just access the link below to guide you setting up the router.
    * Setting up a Linksys router for DSL Internet connection
    http://www6.nohold.net/Cisco2/ukp.aspx?vw=1&docid=20ee1457387f40178cd5f41d4b585db4_3687.xml&pid=80&r...
    * Setting up a Linksys router with Cable Internet service
    http://www6.nohold.net/Cisco2/ukp.aspx?vw=1&docid=0ff4c94586a345d082828ec2161aaecf_3686.xml&pid=80&r...

  • My imac and ipad2 will not connect to the internet with Windstream using an 2wire DSL modem.

    Help my brand new imac and ipad2 will not connect to the internet with Windstream using an "2WIRE" DSL modem.  Windstream tech service is useless.  i can connect with the built in router through Ethernet or wireless, but still no connecting to internet, help!  windstream said everything is working on their end, yea right.  What i do know is that both the mac and ipad work at other places and can connect with wireless connected to the internet, so i know it's not the apple products. 
    these are brand new machines with lion.
    This is my first mac, so I’m still new to how it works, which is not helping either so a detailed help would be great.  Please help before my wife losses it
    thanks

    There is a 2701HG-B, and a 2701HG-D.  If not labelled on the modem, ask Windstream which one they presently supply or how to tell the difference.
    By the way tell your wife it isn't that bad.  At least you have an ethernet DSL modem.  There were times where DSL modems had RJ-11, USB, and Ethernet, and all three were used to provide access.  At least now only the craziest DSL providers still use those modems.

  • Can no longer connect to the internet with the 580...

    Hi, my PC was able to connect to the internet with my 5800 via a USB cable.  Now, I can no longer connect to the internet with the 5800 via a USB cable. 
    I had never tried connecting the computer to the internet with the 5800 via Bluetooth prior to this incident, so I tried that.  Strangely, it works.  
    My question is how come I can no longer use the 5800 via USB as a modem, but how come the 5800 via Bluetooth still works as a working modem?
    Sorry, if my sentences are confusing.  I have a terrible headache at the moment.  While the Bluetooth connection works, I just feel better using the USB connection and knowing that my 5800 has a clean bill of health. 
    BTW, my PC is on Windows 7 Professional at the moment.  I've tried uninstalling the Ovi Suite and reinstalling it, but that didn't work.  I've also tried using PC suite instead of the Ovi Suite but that didn't work either.  What other options do I have, beside hard resetting the phone?  Thanks in advance.        
    Edit: BTW, the message shown when I tried to connect to the internet with the 5800 USB modem was "failed to establish a network connection". 
    Solved!
    Go to Solution.

    Hi,
    I am so  much tierd by trying to connect my phone to pc.
    I have nokia 5800,and I used to connect my phone to PC by USB cable.
    But from last 5 days I could not able to connect it.
    The problem is that,
    when I connect phone to pc,notification comes up that phone connected via ovi suit,but within  a minute or 2,
    "porable device" icon disappears from the task bar in the right hand corner,so connection could not proceed further.
    Please help me in this asap.
    I had tried following already:
    1.format my PC
    2.Installed new ovi suit
    now please give me a proper solution on that.
    thank you.

  • Mac OS 9.1 How to connect to the internet

    How do I connect to the Internet with PPP (dial-up access and a modem? What are the procedures. I am using a OS 9.1.
    Please help.

    Well, first you need an ISP=Internet Servce Provider to provide you with internet service.
    You can then go to your Mac OS Help Menu for detailed instructions. You will need to make the connection through your TCP/IP Control Panels.
    If you run into problem you can check Knowledge Base Article http://docs.info.apple.com/article.html?artnum=106871 Mac OS 8, Mac OS 9: Troubleshooting a Dial-Up/PPP Internet Connection.
    Post back if you run into any problems. Knowledgable users still using dialup service and/or know more about it than I do will be able to help you.
    Good luck!

  • Can't connect to the internet with airport or firewire

    I can't seem to connect to the internet with airport or firewire. I recently restored my old G4 mac mini PPC 1.42 (with airport and bluetooth) Tiger 10.4.8 with a new harddrive. I have it connected to my leopard mac pro, internet sharing is on (both computers), the systems are connected, however, the mini just can't connect to the internet. tried it also using airport, no go. network diagnosis seems to go in a constant loop.

    works ok with ethernet connection though.
    that'll work.

  • Can I connect to the internet with an Ipad in Santo Domingo, DR while I'm on vacation?

    Can I connect to the internet with an Ipad in Santo Domingo, DR while I'm on vacation?

    Lots of hotels in the DR have WiFi. And there is plenty of cellular coverage in Santo Domingo (and elsewhere).
    One thing to be careful of, the WiFi networks are usually not secured and are very vulnerable to people "listening" for passwords and user names, so don't do any financial transactions online and perhaps consider setting up some temporary passwords for the trip and changing them when you get home.
    -dan

  • Unable to connect to the internet with my Fujitsu ...

    Ive just got a Home Hub 4 and have connected it to my laptop, a Fujitsu Esprimo V5535. But it is only giving me Local Only Access. Which means I cant connect to the internet. The Home Hub is working fine as my netbook and other mobile devices are all connected ok but my laptop isnt.... Is there anything I can do to resolve this?

    Did it connect to the Internet with your old homehub?
    Make sure the network card drivers on the laptop are up to date using the manufacturers website rather than Windows which can be out of date. You will need to connect by Ethernet cable to download them or download them on another device and copy them over.

  • Why is it that every time I try to connect to the Internet with my Mac the whole Wi-Fi system comes down and it's only when I turn on my Mac

    Every time I try to connect to the Internet my Mac always makes the Wi-Fi turned off and we have lots of iPads and iPhones and they are fine when we try to use them but as soon as I my Mac it doesn't work. When we have a PC try to connect to the Internet nothing happens but when I try to connect to the Internet with my Mac the Internet turns off

    See:
    * http://kb.mozillazine.org/Firefox_crashes
    * [[Firefox crashes]]

  • No connection to the internet with MINI

    Hello from sunny Jerusalem.
    I got a problem - my IBook connects to the internet via ethernet jack from the router in the apartment next door .
    I had unplugged the IBook and plugged the same jack in the new MINI and there is no connection.
    http://discussions.apple.com/thread.jspa?threadID=578432&tstart=0
    all the advices lead me to beleive that i am an idiot !
    Posting this from work using my MINI which i had connected here.
    Any input anyone?
    be well and safe.
    MacMini DualCore 1,66 1G RAM 100G HD   Mac OS X (10.4.7)   Original Tangerine IBook G3 300Mhz ..OS9.2.2 and still kikkin..

    Since it works on the iBook, the check the network
    settings on the mini.
    System Preferences -- open Network -- check the
    settings on the Built in Ethernet Connection. You can
    compare it to the iBook. It should be configured to
    "Using DHCP".
    If it isn't a settings problem, and it works on the
    iBook, then you probably have a bad ethernet port on
    the mini.
    Hello from sunny Jerusalem !
    possibly ,sir,...you had not read the "posts" in full?
    here it is -
    Hello from sunny Jerusalem.
    I got a problem - my IBook connects to the internet via ethernet jack from the router in the apartment next door .
    I had unplugged the IBook and plugged the same jack in the new MINI and there is no connection.
    http://discussions.apple.com/thread.jspa?threadID=578432&tstart=0
    all the advices lead me to beleive that i am an idiot !
    Posting this from work using my MINI which i had connected here.
    Any input anyone?
    be well and safe.
    MacMini DualCore 1,66 1G RAM 100G HD Mac OS X (10.4.7) Original Tangerine IBook G3 300Mhz ..OS9.2.2 and still kikkin..
    Glenn Leblanc
    Posts: 218
    Registered: 09-Sep-2003
    New! Re: no connection to the internet with MINI
    Posted: 30-Jul-2006 07:58 in response to: gennady nogin Reply Email
    Since it works on the iBook, the check the network settings on the mini.
    System Preferences -- open Network -- check the settings on the Built in Ethernet Connection. You can compare it to the iBook. It should be configured to "Using DHCP".
    If it isn't a settings problem, and it works on the iBook, then you probably have a bad ethernet port on the mini.
    PowerMac G5 1.6 Mac OS X (10.4.6)
    You'd see that there i stated that i had taken the MINI to work and had internet connection there as well, which proves that the ethernet port is fine, also i had stated that the info from TCP/IP in the IBook i copied to the MINI's...
    but my poit is that i did not need to do anything at work with my MINI- just plug the ethernet and go !
    I shall go directly to the router when there is a chance.
    be safe and well.
    MacMini DualCore 1,66 1G RAM 100G HD   Mac OS X (10.4.7)   Original Tangerine IBook G3 300Mhz ..OS9.2.2 and still kikkin..

  • My ipod says the connection passcode for our internet is incorrect when the same passcode connects to the internet with our other electronic devices.

    my ipod has always been able to connect to the internet until this past month. i have the passcode for our internet written down but it says the passcode is incorrect. our other electronic devices work and connect to the internet with the same passcode. what should i do?

    Try the following:
    - Reset the iPOd. Nothing will be lost.
    Reset iPod touch:  Hold down the On/Off button and the Home button at the same time for at
    least ten seconds, until the Apple logo appears.
    - Power off and then back on your router
    - Reset network settings: Settings>General>Reset>Reset Network Settings
    - iPhone and iPod touch: Troubleshooting Wi-Fi networks and connections

  • How do I connect to the internet with Airport for the first time?

    I just got my Airport express and I've been trying to configure it to connect to the internet but it doesn't work and I can't find info on the configurations. I have an ethernet "modem" which I used to connect the cable coming from it to the computer and now I connect it to my Airport. Although the green light is on and in network preferences, it tells me I'm connected to the internet, I can't browse the internet with Safari, etc. I've been trying to find information on how to configure the base station in Airport Admin Utility but there is no specific information. Is there anyone who could help me telling me how to set up the IP adress, if I need one, DHCP, preferences in Airport Admin Utility?? If the ethernet cable is connected to the computer directly I don't need a user ID or anything... It's all setup automatically.

    As a minimum, in order to gain access to the Internet with an AirPort Express base station, you will need an Internet Service Provider (ISP) AND an Internet modem or gateway device.
    What is the make & model of the Internet modem or gateway device that you have the AirPort Express directly connected to by Ethernet? What exact model of Express do you have?

Maybe you are looking for