Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Cisco ASA5505 Firewall Issue

Posted on 2011-03-05
7
Medium Priority
?
781 Views
Last Modified: 2012-05-11
Dear Experts

I need your help I have an issue with my Cisco ASA5505 firewall.

Basically I can't get any web page to work through the firewall.

All pages just eventually time out I just can't seem to work out what the issue is!!!

Any assistance would be greatly appreciated

Copied below is the config I am currently using

0
Comment
Question by:Robert_Rayworth
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
7 Comments
 

Author Comment

by:Robert_Rayworth
ID: 35045099
This is my current config ExpertsExchange-Config.txt
0
 
LVL 3

Assisted Solution

by:chouckham
chouckham earned 668 total points
ID: 35046191
Hi Robert,

Few things zou need to let us know:
++ Is your Outside IP address issued by DHCP?
++ Does this connection also provide you with DNS resolution?

I have noticed your default route outside is set as: "route outside 0.0.0.0 0.0.0.0 192.168.1.254 1" Which is the Internal IP address of your Firewall to the LAN. This should be set to your ISP's DF Gateway address or if its your lan, your next hop...
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 332 total points
ID: 35046854
>route outside 0.0.0.0 0.0.0.0 192.168.1.254 1
You must remove this entry so that DHCP will learn the default route
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 

Author Comment

by:Robert_Rayworth
ID: 35056050
Thanks for responding I am going to try out what Irmoore suggest which makes sense.

You don't know how long this has been driving me mad!!!

Message for Chouckham yes my outside address is issued by DHCP. Vlan 2 is plugged into a cable modem which doesn't have a fixed IP address. And that DHCP address does get DNS resolution.

I did also notice that I wasn't able to get an IP address from connecting switch port 0 directly into the cable modem. After quite a bit of fault finding I discovered the issue to be with Cisco using a very long Vlan2
Ethernet 0/0
Client-ID:      cisco-1cdf.0f5c.61e7-outside-ASA-5505
I managed to get round this by setting up client id to use a MAC address the cable modem was use to speaking to.

This however never got me to a place to open web pages.

I am hoping by removing this entry it will

I will post back nad let you know if its a winner!!!
0
 
LVL 3

Assisted Solution

by:chouckham
chouckham earned 668 total points
ID: 35056467
Exactly as both Irmoore and I pointed out the "route outside 0.0.0.0 0.0.0.0 192.168.1.254 1" is incorrect and should be removed.

Please let us know the outcome.
0
 

Author Comment

by:Robert_Rayworth
ID: 35071814
Hi guys basically what you both suggested was correct so how do you want me to award the points.
I have to admit the user Chouckham suggestion was clearer in that he told me exactly what to do so would it be fair to split the points????
0
 
LVL 3

Expert Comment

by:chouckham
ID: 35072279
I don't mind Robert. Split sounds good to me.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question