?
Solved

Cisco ASA5505 Firewall Issue

Posted on 2011-03-05
7
Medium Priority
?
780 Views
Last Modified: 2012-05-11
Dear Experts

I need your help I have an issue with my Cisco ASA5505 firewall.

Basically I can't get any web page to work through the firewall.

All pages just eventually time out I just can't seem to work out what the issue is!!!

Any assistance would be greatly appreciated

Copied below is the config I am currently using

0
Comment
Question by:Robert_Rayworth
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
7 Comments
 

Author Comment

by:Robert_Rayworth
ID: 35045099
This is my current config ExpertsExchange-Config.txt
0
 
LVL 3

Assisted Solution

by:chouckham
chouckham earned 668 total points
ID: 35046191
Hi Robert,

Few things zou need to let us know:
++ Is your Outside IP address issued by DHCP?
++ Does this connection also provide you with DNS resolution?

I have noticed your default route outside is set as: "route outside 0.0.0.0 0.0.0.0 192.168.1.254 1" Which is the Internal IP address of your Firewall to the LAN. This should be set to your ISP's DF Gateway address or if its your lan, your next hop...
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 332 total points
ID: 35046854
>route outside 0.0.0.0 0.0.0.0 192.168.1.254 1
You must remove this entry so that DHCP will learn the default route
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 

Author Comment

by:Robert_Rayworth
ID: 35056050
Thanks for responding I am going to try out what Irmoore suggest which makes sense.

You don't know how long this has been driving me mad!!!

Message for Chouckham yes my outside address is issued by DHCP. Vlan 2 is plugged into a cable modem which doesn't have a fixed IP address. And that DHCP address does get DNS resolution.

I did also notice that I wasn't able to get an IP address from connecting switch port 0 directly into the cable modem. After quite a bit of fault finding I discovered the issue to be with Cisco using a very long Vlan2
Ethernet 0/0
Client-ID:      cisco-1cdf.0f5c.61e7-outside-ASA-5505
I managed to get round this by setting up client id to use a MAC address the cable modem was use to speaking to.

This however never got me to a place to open web pages.

I am hoping by removing this entry it will

I will post back nad let you know if its a winner!!!
0
 
LVL 3

Assisted Solution

by:chouckham
chouckham earned 668 total points
ID: 35056467
Exactly as both Irmoore and I pointed out the "route outside 0.0.0.0 0.0.0.0 192.168.1.254 1" is incorrect and should be removed.

Please let us know the outcome.
0
 

Author Comment

by:Robert_Rayworth
ID: 35071814
Hi guys basically what you both suggested was correct so how do you want me to award the points.
I have to admit the user Chouckham suggestion was clearer in that he told me exactly what to do so would it be fair to split the points????
0
 
LVL 3

Expert Comment

by:chouckham
ID: 35072279
I don't mind Robert. Split sounds good to me.
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
Imagine you have a shopping list of items you need to get at the grocery store. You have two options: A. Take one trip to the grocery store and get everything you need for the week, or B. Take multiple trips, buying an item at a time, to achieve t…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month10 days, 14 hours left to enroll

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question