Solved

Cisco ASA5505 Firewall Issue

Posted on 2011-03-05
7
775 Views
Last Modified: 2012-05-11
Dear Experts

I need your help I have an issue with my Cisco ASA5505 firewall.

Basically I can't get any web page to work through the firewall.

All pages just eventually time out I just can't seem to work out what the issue is!!!

Any assistance would be greatly appreciated

Copied below is the config I am currently using

0
Comment
Question by:Robert_Rayworth
  • 3
  • 3
7 Comments
 

Author Comment

by:Robert_Rayworth
ID: 35045099
This is my current config ExpertsExchange-Config.txt
0
 
LVL 3

Assisted Solution

by:chouckham
chouckham earned 167 total points
ID: 35046191
Hi Robert,

Few things zou need to let us know:
++ Is your Outside IP address issued by DHCP?
++ Does this connection also provide you with DNS resolution?

I have noticed your default route outside is set as: "route outside 0.0.0.0 0.0.0.0 192.168.1.254 1" Which is the Internal IP address of your Firewall to the LAN. This should be set to your ISP's DF Gateway address or if its your lan, your next hop...
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 83 total points
ID: 35046854
>route outside 0.0.0.0 0.0.0.0 192.168.1.254 1
You must remove this entry so that DHCP will learn the default route
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 

Author Comment

by:Robert_Rayworth
ID: 35056050
Thanks for responding I am going to try out what Irmoore suggest which makes sense.

You don't know how long this has been driving me mad!!!

Message for Chouckham yes my outside address is issued by DHCP. Vlan 2 is plugged into a cable modem which doesn't have a fixed IP address. And that DHCP address does get DNS resolution.

I did also notice that I wasn't able to get an IP address from connecting switch port 0 directly into the cable modem. After quite a bit of fault finding I discovered the issue to be with Cisco using a very long Vlan2
Ethernet 0/0
Client-ID:      cisco-1cdf.0f5c.61e7-outside-ASA-5505
I managed to get round this by setting up client id to use a MAC address the cable modem was use to speaking to.

This however never got me to a place to open web pages.

I am hoping by removing this entry it will

I will post back nad let you know if its a winner!!!
0
 
LVL 3

Assisted Solution

by:chouckham
chouckham earned 167 total points
ID: 35056467
Exactly as both Irmoore and I pointed out the "route outside 0.0.0.0 0.0.0.0 192.168.1.254 1" is incorrect and should be removed.

Please let us know the outcome.
0
 

Author Comment

by:Robert_Rayworth
ID: 35071814
Hi guys basically what you both suggested was correct so how do you want me to award the points.
I have to admit the user Chouckham suggestion was clearer in that he told me exactly what to do so would it be fair to split the points????
0
 
LVL 3

Expert Comment

by:chouckham
ID: 35072279
I don't mind Robert. Split sounds good to me.
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
small, multi network, problem 3 79
Network Infrastructure for Branch Office 16 87
WAN Site Edge Routers 15 49
Some issue on SecurityCRT 5 24
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

947 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now