We are setting up an ASA 5505 we cannot open access to the outside (internet) can ping external gateway but cannot ping outside address. can not access any internet addresses. Get the foillowing error returned..
portmap translation creation failed for icmp src inside:test dst inside:192.168.11.1 (type 8, code 0)
the settings are:
: Saved
:
ASA Version 8.0(2)
!
hostname JASVPN
domain-name JASMfg.Internal
enable password 4hnySGSCciSYd4NZ encrypted
names
name 74.218.127.165 PUBLIC_IP_01
name 192.168.1.3 test
!
interface Vlan1
nameif inside
security-level 100
ip address 192.168.1.1 255.255.255.0
ospf cost 10
!
interface Vlan2
nameif outside
security-level 0
ip address 74.218.127.166 255.255.255.252
ospf cost 10
!
interface Ethernet0/0
switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
passwd 2KFQnbNIdI.2KYOU encrypted
boot system disk0:/asa802-k8.bin
boot config disk0:/asa8-k8.bin
ftp mode passive
clock timezone EST -5
clock summer-time EDT recurring
dns server-group DefaultDNS
domain-name JASMfg.Internal
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
object-group network AllowAll
description ACL
network-object 0.0.0.0 0.0.0.0
object-group service TCP_Ports tcp
description Special Ports
port-object range 125 145
port-object range 1433 1433
port-object range smtp www
port-object range ldap ldap
port-object range 4000 4300
port-object range https 450
port-object range 8000 9100
object-group service TCP_Services tcp
description Service to be used
port-object eq aol
port-object eq finger
port-object eq ftp
port-object eq ftp-data
port-object eq www
port-object eq https
port-object eq kerberos
port-object eq ldap
port-object eq pop3
port-object eq pptp
port-object eq sip
port-object eq smtp
port-object eq telnet
port-object eq uucp
object-group service UDP_Services udp
description Allow these UDP Services
port-object eq domain
port-object eq www
port-object eq isakmp
port-object eq kerberos
port-object eq nameserver
port-object eq netbios-dgm
port-object eq netbios-ns
port-object eq radius
port-object eq radius-acct
port-object eq rip
port-object eq secureid-udp
port-object eq sip
port-object eq snmp
port-object eq snmptrap
port-object eq tftp
port-object eq time
port-object eq who
object-group icmp-type PingTest
icmp-object alternate-address
icmp-object conversion-error
icmp-object echo
icmp-object echo-reply
icmp-object information-reply
icmp-object information-request
icmp-object mask-reply
icmp-object mask-request
icmp-object mobile-redirect
icmp-object parameter-problem
icmp-object redirect
icmp-object router-advertisement
icmp-object router-solicitation
icmp-object source-quench
icmp-object time-exceeded
icmp-object timestamp-reply
icmp-object timestamp-request
icmp-object traceroute
icmp-object unreachable
object-group service AllServiceAllow
description AllowEvery
service-object icmp
service-object udp
service-object esp
service-object tcp
service-object eigrp
service-object ospf
service-object icmp echo
service-object icmp echo-reply
service-object icmp information-reply
service-object icmp information-request
service-object icmp mask-reply
service-object icmp mask-request
service-object tcp-udp eq domain
service-object tcp-udp eq www
service-object tcp-udp eq sip
service-object tcp-udp eq sunrpc
service-object tcp-udp eq tacacs
service-object tcp-udp eq talk
service-object tcp eq domain
service-object tcp eq echo
service-object tcp eq ftp
service-object tcp eq www
service-object tcp eq https
service-object tcp eq pop3
service-object tcp eq pptp
service-object tcp eq smtp
service-object tcp eq sqlnet
service-object tcp eq telnet
service-object tcp eq uucp
service-object icmp traceroute
service-object udp eq echo
service-object udp eq nameserver
service-object udp eq netbios-dgm
service-object udp eq netbios-ns
service-object udp eq pcanywhere-status
service-object udp eq rip
service-object udp eq secureid-udp
service-object udp eq sip
service-object udp eq snmp
service-object udp eq snmptrap
service-object udp eq tacacs
service-object udp eq tftp
service-object icmp unreachable
service-object ip
service-object pim
service-object pcp
service-object snp
service-object igmp
service-object ipinip
service-object gre
service-object ah
service-object icmp6
service-object igrp
service-object nos
service-object icmp alternate-address
service-object icmp conversion-error
service-object icmp mobile-redirect
service-object icmp parameter-problem
service-object icmp redirect
service-object icmp router-advertisement
service-object icmp router-solicitation
service-object icmp source-quench
service-object tcp-udp eq cifs
service-object tcp-udp eq discard
service-object tcp-udp eq echo
service-object tcp-udp eq kerberos
service-object tcp-udp eq pim-auto-rp
service-object tcp eq aol
service-object tcp eq bgp
service-object tcp eq chargen
service-object tcp eq cifs
service-object tcp eq citrix-ica
service-object tcp eq ctiqbe
service-object tcp eq daytime
service-object tcp eq discard
service-object tcp eq exec
service-object tcp eq finger
service-object tcp eq ftp-data
service-object tcp eq gopher
service-object tcp eq h323
service-object tcp eq hostname
service-object tcp eq ident
service-object tcp eq imap4
service-object tcp eq irc
service-object tcp eq kerberos
service-object tcp eq klogin
service-object tcp eq kshell
service-object tcp eq ldap
service-object tcp eq ldaps
service-object tcp eq login
service-object tcp eq lotusnotes
service-object tcp eq lpd
service-object tcp eq netbios-ssn
service-object tcp eq nntp
service-object tcp eq pcanywhere-data
service-object tcp eq pim-auto-rp
service-object tcp eq pop2
service-object tcp eq rsh
service-object tcp eq rtsp
service-object tcp eq sip
service-object tcp eq ssh
service-object tcp eq sunrpc
service-object tcp eq tacacs
service-object tcp eq talk
service-object tcp eq whois
service-object icmp time-exceeded
service-object icmp timestamp-reply
service-object icmp timestamp-request
service-object udp eq biff
service-object udp eq cifs
service-object udp eq discard
service-object udp eq dnsix
service-object udp eq domain
service-object udp eq www
service-object udp eq isakmp
service-object udp eq kerberos
service-object udp eq mobile-ip
service-object udp eq ntp
service-object udp eq pim-auto-rp
service-object udp eq radius
service-object udp eq radius-acct
service-object udp eq sunrpc
service-object udp eq syslog
service-object udp eq talk
service-object udp eq time
service-object udp eq who
object-group service Test
group-object AllServiceAllow
object-group service DM_INLINE_SERVICE_1
service-object icmp
service-object icmp alternate-address
service-object icmp echo
service-object icmp echo-reply
group-object AllServiceAllow
object-group service DM_INLINE_SERVICE_2
service-object icmp
group-object AllServiceAllow
service-object icmp alternate-address
service-object icmp conversion-error
service-object icmp echo
service-object icmp echo-reply
service-object icmp information-reply
service-object icmp information-request
object-group service DM_INLINE_SERVICE_3
service-object icmp
group-object AllServiceAllow
service-object icmp echo
service-object icmp echo-reply
object-group service DM_INLINE_SERVICE_4
service-object ip
service-object icmp
group-object AllServiceAllow
service-object icmp echo
service-object icmp echo-reply
object-group service let
service-object ip
service-object icmp
service-object pim
service-object pcp
service-object snp
service-object udp
service-object igmp
service-object ipinip
service-object gre
service-object esp
service-object ah
service-object icmp6
service-object tcp
service-object eigrp
service-object ospf
service-object igrp
service-object nos
service-object icmp alternate-address
service-object icmp conversion-error
service-object icmp echo
service-object icmp echo-reply
service-object icmp information-reply
service-object icmp information-request
service-object icmp mask-reply
service-object icmp mask-request
service-object icmp mobile-redirect
service-object icmp parameter-problem
service-object icmp redirect
service-object icmp router-advertisement
service-object icmp router-solicitation
service-object icmp source-quench
service-object tcp-udp eq cifs
service-object tcp-udp eq discard
service-object tcp-udp eq domain
service-object tcp-udp eq echo
service-object tcp-udp eq www
service-object tcp-udp eq kerberos
service-object tcp-udp eq pim-auto-rp
service-object tcp-udp eq sip
service-object tcp-udp eq sunrpc
service-object tcp-udp eq tacacs
service-object tcp-udp eq talk
service-object tcp eq aol
service-object tcp eq bgp
service-object tcp eq chargen
service-object tcp eq cifs
service-object tcp eq citrix-ica
service-object tcp eq ctiqbe
service-object tcp eq daytime
service-object tcp eq discard
service-object tcp eq domain
service-object tcp eq echo
service-object tcp eq exec
service-object tcp eq finger
service-object tcp eq ftp
service-object tcp eq ftp-data
service-object tcp eq gopher
service-object tcp eq h323
service-object tcp eq hostname
service-object tcp eq www
service-object tcp eq https
service-object tcp eq ident
service-object tcp eq imap4
service-object tcp eq irc
service-object tcp eq kerberos
service-object tcp eq klogin
service-object tcp eq kshell
service-object tcp eq ldap
service-object tcp eq ldaps
service-object tcp eq login
service-object tcp eq lotusnotes
service-object tcp eq lpd
service-object tcp eq netbios-ssn
service-object tcp eq nntp
service-object tcp eq pcanywhere-data
service-object tcp eq pim-auto-rp
service-object tcp eq pop2
service-object tcp eq pop3
service-object tcp eq pptp
service-object tcp eq rsh
service-object tcp eq rtsp
service-object tcp eq sip
service-object tcp eq smtp
service-object tcp eq sqlnet
service-object tcp eq ssh
service-object tcp eq sunrpc
service-object tcp eq tacacs
service-object tcp eq talk
service-object tcp eq telnet
service-object tcp eq uucp
service-object tcp eq whois
service-object icmp time-exceeded
service-object icmp timestamp-reply
service-object icmp timestamp-request
service-object icmp traceroute
service-object udp eq biff
service-object udp eq bootpc
service-object udp eq bootps
service-object udp eq cifs
service-object udp eq discard
service-object udp eq dnsix
service-object udp eq domain
service-object udp eq echo
service-object udp eq www
service-object udp eq isakmp
service-object udp eq kerberos
service-object udp eq mobile-ip
service-object udp eq nameserver
service-object udp eq netbios-dgm
service-object udp eq netbios-ns
service-object udp eq ntp
service-object udp eq pcanywhere-status
service-object udp eq pim-auto-rp
service-object udp eq radius
service-object udp eq radius-acct
service-object udp eq rip
service-object udp eq secureid-udp
service-object udp eq sip
service-object udp eq snmp
service-object udp eq snmptrap
service-object udp eq sunrpc
service-object udp eq syslog
service-object udp eq tacacs
service-object udp eq talk
service-object udp eq tftp
service-object udp eq time
service-object udp eq who
service-object udp eq xdmcp
service-object icmp unreachable
access-list global_mpc extended permit object-group AllServiceAllow any any log disable
access-list inside_access_in extended permit object-group DM_INLINE_SERVICE_3 any any
access-list outside_access_in extended permit object-group DM_INLINE_SERVICE_2 any any log
access-list outside_access_in extended permit object-group AllServiceAllow 74.218.127.164 255.255.255.252 192.168.1.0 255.255.255.0
access-list outside_access_out extended permit object-group DM_INLINE_SERVICE_4 any any log
access-list inside_access_out_1 extended permit object-group DM_INLINE_SERVICE_1 any any
access-list JASVPN1_splitTunnelAcl standard permit any
access-list inside_cryptomap extended permit object-group AllServiceAllow 192.168.1.0 255.255.255.0 74.218.127.164 255.255.255.252
pager lines 24
logging enable
logging asdm informational
mtu inside 1500
mtu outside 1500
ip local pool JAS 192.168.1.100-192.168.1.11
0 mask 255.255.255.0
ip audit info action
ip audit attack action
ip audit signature 1103 disable
ip audit signature 2000 disable
ip audit signature 2001 disable
ip audit signature 2002 disable
ip audit signature 2003 disable
ip audit signature 2004 disable
ip audit signature 2005 disable
ip audit signature 2006 disable
ip audit signature 2007 disable
ip audit signature 2008 disable
ip audit signature 2009 disable
ip audit signature 2010 disable
ip audit signature 2151 disable
icmp unreachable rate-limit 1 burst-size 1
icmp permit any inside
icmp permit any outside
asdm image disk0:/asdm-602.bin
no asdm history enable
arp timeout 14400
nat-control
global (inside) 1 test-192.168.1.99 netmask 255.255.255.0
global (outside) 1 PUBLIC_IP_01 netmask 255.0.0.0
global (outside) 101 interface
nat (inside) 101 0.0.0.0 0.0.0.0
access-group inside_access_in in interface inside
access-group inside_access_out_1 out interface inside
access-group outside_access_in in interface outside
access-group outside_access_out out interface outside
route outside 0.0.0.0 0.0.0.0 192.168.1.1 1
route inside 192.168.0.0 255.255.0.0 PUBLIC_IP_01 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:25:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout uauth 0:05:00 absolute uauth 0:10:00 inactivity
dynamic-access-policy-reco
rd DfltAccessPolicy
aaa authorization command LOCAL
aaa authorization exec authentication-server
http server enable
http 192.168.1.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac
crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac
crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac
crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac
crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac
crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac
crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac
crypto ipsec transform-set TRANS_ESP_3DES_MD5 esp-3des esp-md5-hmac
crypto ipsec transform-set TRANS_ESP_3DES_MD5 mode transport
crypto dynamic-map outside_dyn_map 20 set pfs
crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-SHA TRANS_ESP_3DES_MD5
crypto dynamic-map outside_dyn_map 40 set pfs
crypto dynamic-map outside_dyn_map 40 set transform-set ESP-3DES-SHA
crypto dynamic-map JASVPN2 1 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5
crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map
crypto map outside_map interface outside
crypto map inside_map0 1 ipsec-isakmp dynamic JASVPN2
crypto map inside_map0 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
crypto map inside_map0 interface inside
crypto isakmp enable inside
crypto isakmp enable outside
crypto isakmp policy 10
authentication pre-share
encryption 3des
hash sha
group 2
lifetime 86400
crypto isakmp policy 30
authentication pre-share
encryption 3des
hash md5
group 2
lifetime 86400
no crypto isakmp nat-traversal
vpn-sessiondb max-session-limit 10
telnet 192.168.1.0 255.255.255.0 inside
telnet timeout 5
ssh 192.168.1.0 255.255.255.0 inside
ssh timeout 60
console timeout 0
management-access inside
dhcpd auto_config outside
!
dhcpd address test-192.168.1.33 inside
dhcpd dns 192.168.1.1 74.218.127.166 interface inside
dhcpd ping_timeout 32 interface inside
dhcpd domain jasmfg.internal interface inside
dhcpd enable inside
!
no threat-detection basic-threat
threat-detection statistics
!
class-map global-class
match any
!
!
policy-map type inspect dns preset_dns_map
parameters
message-length maximum 512
policy-map global-policy
class global-class
inspect icmp
set connection conn-max 2 embryonic-conn-max 2 per-client-max 2 per-client-embryonic-max 2
set connection decrement-ttl
!
service-policy global-policy global
tftp-server inside test /
ssl encryption 3des-sha1 aes256-sha1 aes128-sha1 rc4-sha1 rc4-md5 des-sha1
webvpn
enable inside
enable outside
group-policy DfltGrpPolicy attributes
vpn-tunnel-protocol IPSec l2tp-ipsec svc webvpn
group-policy JASVPN1 internal
group-policy JASVPN1 attributes
split-tunnel-policy tunnelspecified
split-tunnel-network-list value JASVPN1_splitTunnelAcl
group-policy JAS internal
group-policy JAS attributes
wins-server value 192.168.1.1
dns-server value 192.168.1.1
username user5 password 6rSaocMqc/FtCD1T encrypted privilege 0
username user5 attributes
vpn-group-policy JAS
username user4 password 6rSaocMqc/FtCD1T encrypted privilege 0
username user4 attributes
vpn-group-policy JAS
username user1 password 6rSaocMqc/FtCD1T encrypted privilege 0
username user1 attributes
vpn-group-policy JAS
username user3 password 6rSaocMqc/FtCD1T encrypted privilege 0
username user3 attributes
vpn-group-policy JAS
username user2 password 6rSaocMqc/FtCD1T encrypted privilege 0
username user2 attributes
vpn-group-policy JAS
tunnel-group DefaultL2LGroup ipsec-attributes
pre-shared-key *
tunnel-group DefaultRAGroup general-attributes
address-pool JAS
tunnel-group DefaultRAGroup ipsec-attributes
pre-shared-key *
tunnel-group DefaultRAGroup ppp-attributes
authentication pap
authentication ms-chap-v2
authentication eap-proxy
tunnel-group JAS type remote-access
tunnel-group JAS general-attributes
address-pool JAS
default-group-policy JAS
tunnel-group JAS ipsec-attributes
pre-shared-key *
tunnel-group JASVPN1 type remote-access
tunnel-group JASVPN1 general-attributes
address-pool JAS
authorization-server-group
LOCAL
default-group-policy JASVPN1
tunnel-group JASVPN1 webvpn-attributes
hic-fail-group-policy JASVPN1
tunnel-group JASVPN1 ipsec-attributes
pre-shared-key *
tunnel-group JASVPN2 type ipsec-l2l
tunnel-group JASVPN2 ipsec-attributes
pre-shared-key *
privilege cmd level 3 mode exec command perfmon
privilege cmd level 3 mode exec command ping
privilege cmd level 3 mode exec command who
privilege cmd level 3 mode exec command logging
privilege cmd level 3 mode exec command failover
privilege show level 5 mode exec command import
privilege show level 5 mode exec command running-config
privilege show level 3 mode exec command reload
privilege show level 3 mode exec command mode
privilege show level 3 mode exec command firewall
privilege show level 3 mode exec command interface
privilege show level 3 mode exec command clock
privilege show level 3 mode exec command dns-hosts
privilege show level 3 mode exec command access-list
privilege show level 3 mode exec command logging
privilege show level 3 mode exec command ip
privilege show level 3 mode exec command failover
privilege show level 3 mode exec command asdm
privilege show level 3 mode exec command arp
privilege show level 3 mode exec command route
privilege show level 3 mode exec command ospf
privilege show level 3 mode exec command aaa-server
privilege show level 3 mode exec command aaa
privilege show level 3 mode exec command eigrp
privilege show level 3 mode exec command crypto
privilege show level 3 mode exec command vpn-sessiondb
privilege show level 3 mode exec command ssh
privilege show level 3 mode exec command dhcpd
privilege show level 3 mode exec command vpnclient
privilege show level 3 mode exec command vpn
privilege show level 3 mode exec command blocks
privilege show level 3 mode exec command wccp
privilege show level 3 mode exec command webvpn
privilege show level 3 mode exec command uauth
privilege show level 3 mode exec command compression
privilege show level 3 mode configure command interface
privilege show level 3 mode configure command clock
privilege show level 3 mode configure command access-list
privilege show level 3 mode configure command logging
privilege show level 3 mode configure command ip
privilege show level 3 mode configure command failover
privilege show level 5 mode configure command asdm
privilege show level 3 mode configure command arp
privilege show level 3 mode configure command route
privilege show level 3 mode configure command aaa-server
privilege show level 3 mode configure command aaa
privilege show level 3 mode configure command crypto
privilege show level 3 mode configure command ssh
privilege show level 3 mode configure command dhcpd
privilege show level 5 mode configure command privilege
privilege clear level 3 mode exec command dns-hosts
privilege clear level 3 mode exec command logging
privilege clear level 3 mode exec command arp
privilege clear level 3 mode exec command aaa-server
privilege clear level 3 mode exec command crypto
privilege cmd level 3 mode configure command failover
privilege clear level 3 mode configure command logging
privilege clear level 3 mode configure command arp
privilege clear level 3 mode configure command crypto
privilege clear level 3 mode configure command aaa-server
prompt hostname context
Cryptochecksum:fa67ff496b2
2636eadd59
0a2c6377de
a
: end
asdm image disk0:/asdm-602.bin
no asdm history enable
Thanks, desperate for help
Start Free Trial