Help adding additional external Ip's to Cisco ASA 5505

Posted on 2007-10-18
Last Modified: 2011-10-03
Hi all, basically I have run out of External ip's and I need to know how to add the new block I ip's I received to my Cisco ASA 5505.  I have a  /28 block that I would like to start using but I don't know how to add it to my current config or if it's even possible?  
We'll say my new block looks as follows:  .2 is the default gateway (.3-17 useable, .18 broadcast) I need to add this to my current config:

: Saved
ASA Version 8.0(2)
enable password names
name 72.x.x.x appserver-ext description External Add
name 192.168.0.x appserver_int description Parlay Games
name 72.x.x.x oracle_db-ext description External Add
name 192.168.0.x oracle_db_int description Oracle / MySql
name 72.x.x.x webserver-ext description External Add
name 192.168.0.x webserver_int description Apache / PHP
name 72.x.x.x Lotto_Site-ext
name 192.168.0.x Lotto_Site-int
interface Vlan1
 nameif inside
 security-level 50
 ip address 192.168.0.x
interface Vlan2
 nameif outside
 security-level 0
 ip address 72.x.x.x
interface Ethernet0/0
 switchport access vlan 2
interface Ethernet0/1
interface Ethernet0/2
interface Ethernet0/3
interface Ethernet0/4
interface Ethernet0/5
interface Ethernet0/6
interface Ethernet0/7
ftp mode passive
clock timezone EST -5
clock summer-time EDT recurring
dns server-group DefaultDNS
object-group network Blink_Servers_int
 network-object host oracle_db_int
 network-object host webserver_int
 network-object host appserver_int
 network-object host Lotto_Site-int
object-group network My_Sql
 network-object host Parlay_Network
 network-object host Trent_Sschwartz
object-group network SSH
 network-object host Parlay_Network
 network-object host Trent_Sschwartz
object-group protocol TCPUDP
 protocol-object udp
 protocol-object tcp
object-group service MySql tcp
 port-object eq 3306
object-group service Parlay_Chat tcp
 port-object eq 2156
object-group service Tomcat tcp
 port-object eq 8080
object-group service Parlay_Services tcp
 group-object Parlay_Chat
 group-object Tomcat
 port-object eq www
 port-object eq https
object-group network Blink_Servers_ext
 network-object host oracle_db-ext
 network-object host webserver-ext
 network-object host appserver-ext
 network-object host Lotto_Site-ext
pager lines 24
logging enable
logging asdm informational
mtu inside 1500
mtu outside 1500
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-602.bin
no asdm history enable
arp timeout 14400
global (outside) 1 interface
static (inside,outside) oracle_db-ext oracle_db_int netmask
static (inside,outside) webserver-ext webserver_int netmask
static (inside,outside) appserver-ext appserver_int netmask
static (inside,outside) Lotto_Site-ext Lotto_Site-int netmask
access-group inside_access_in in interface inside
access-group outside_access_in in interface outside
route outside 72.x.x.x 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout uauth 0:05:00 absolute
dynamic-access-policy-record DfltAccessPolicy
http server enable
http 192.168.0.x inside
http Parlay_Network outside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
no crypto isakmp nat-traversal
telnet Parlay_Network outside
telnet timeout 5
ssh timeout 5
console timeout 0

threat-detection basic-threat
threat-detection statistics access-list
class-map inspection_default
 match default-inspection-traffic
policy-map type inspect dns preset_dns_map
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect esmtp
  inspect sqlnet
  inspect skinny  
  inspect sunrpc
  inspect xdmcp
  inspect sip  
  inspect netbios
  inspect tftp
service-policy global_policy global
prompt hostname context
: end
asdm image disk0:/asdm-602.bin
no asdm history enable
Question by:parlay_user
    LVL 79

    Expert Comment

    The ISP has to route the new block to your outside IP address. Then you can use all of the IP's from .1 -.14 with .15 as the broadcast and nothing reserved as a gateway.

    Then, just create new statics using the new IPs.

    Author Comment

    When you say outside IP address, would that be the ip of the firewall interface?
    LVL 79

    Expert Comment

    Yes. The ISP must route the new block of IP's to  ip address 72.x.x.x

    Author Comment

    Ok, the isp has routed to 72.x.x.x.  So your saying all I have to do is create new nats using the new ips and I'm good to go?
    LVL 79

    Accepted Solution


    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Find Ransomware Secrets With All-Source Analysis

    Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

    Suggested Solutions

    This article assumes you have at least one Cisco ASA or PIX configured with working internet and a non-dynamic, public, address on the outside interface. If you need instructions on how to enable your device for internet, or basic configuration info…
    Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
    Migrating to Microsoft Office 365 is becoming increasingly popular for organizations both large and small. If you have made the leap to Microsoft’s cloud platform, you know that you will need to create a corporate email signature for your Office 365…
    In this sixth video of the Xpdf series, we discuss and demonstrate the PDFtoPNG utility, which converts a multi-page PDF file to separate color, grayscale, or monochrome PNG files, creating one PNG file for each page in the PDF. It does this via a c…

    759 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    11 Experts available now in Live!

    Get 1:1 Help Now