Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

asa 5505 no internet connection, first time setup

Status
Not open for further replies.

onlyalex

Technical User
Feb 20, 2009
3
SE
Hi first time here. Have read around the topics here but could not find anything that helped me so here comes my post.

Im new to cisco but will try keeping it simple. This is my hardware

DSL modem "Bridge" --> ASA 5505 --> My computer

I have static ip assigned by my isp. When i plug my computer into modem i get an public ip. I have done the config wizard but i cant get an public ip to the asa, no internet connection. Any help would be most appriciated. Here is my config from "show run" command

Result of the command: "show run"

: Saved
:
ASA Version 7.2(4)
!
hostname ciscoasa
domain-name default.domain.invalid
enable password jwWParBBHK8Ey3Ud encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
names
!
interface Vlan1
nameif inside
security-level 100
ip address 192.168.10.253 255.255.255.0
!
interface Vlan2
nameif outside
security-level 0
ip address dhcp
!
interface Vlan3
shutdown
no forward interface Vlan1
nameif dmz
security-level 50
no ip address
!
interface Ethernet0/0
switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
ftp mode passive
dns server-group DefaultDNS
domain-name default.domain.invalid
pager lines 24
logging asdm informational
mtu inside 1500
mtu outside 1500
mtu dmz 1500
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-524.bin
no asdm history enable
arp timeout 14400
nat (inside) 1 0.0.0.0 0.0.0.0
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
http server enable
http 192.168.10.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
telnet timeout 5
ssh 192.168.10.0 255.255.255.0 inside
ssh timeout 5
console timeout 0
dhcpd auto_config outside
!
dhcpd address 192.168.10.1-192.168.10.30 inside
dhcpd enable inside
!

!
class-map inspection_default
match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
parameters
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
!
service-policy global_policy global
prompt hostname context
Cryptochecksum:32824354006006a28638ecaa0381c166
: end
 
Does your provider require authentication??
I have static ip assigned by my isp
But you have your outside interface (vlan2) set for dhcp. If you truly have a static ip you'll do this
1) issue no dhcpd auto_config outside
2) go under your vlan 2 svi and do this:
asa(config)# int vlan 2
asa(config-if)# ip add <static ip> <subnet mask>

You should have a global statement: global (outside) 1 interface

You will need a default route: route outside 0.0.0.0 0.0.0.0 interface

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
Hi thanks for you reply. I might hade wronge info in my first post. I get dynamic ip from my isp. When i plug in my computer i get an ip adress assaigned.

Since this is my first cisco im not so well known with the commands. I fired up an terminal to my asa with the console cable. And runned this

ciscoasa# issue no dhcpd auto_config outside
^
ERROR: % Invalid input detected at '^' marker.


I tried this command to
route outside 0.0.0.0 0.0.0.0 interface
i get
Invalid input detected at '^' marker.

I dont know relly what to do now. Any help is appriciated.
 
ok, so before we proceed any further, you need to tell me if your provider requires any authentication. If it does require authentication we'll need to configure a vpdn group and change how the outside interface obtains its ip address.

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
Hello i think that this problem has come to an end. I tried another internet connection, from another modem and that worked fine. So no i have got myself a new modem and did a reset of the asa and i worked right away. No i can focus on howto get the ssl vpn up...

This thread is now solved.
Thanks for great help
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top