Solved

What command do I use to assign static IP to ASA interface

Posted on 2011-09-16
17
671 Views
Last Modified: 2012-05-12
My ASA outside interface is getting an address from the DHCP in a TELMEX DSL router.  I need to turn DHCP off.  How do I assign a static IP?  I need to know the commands.  Here is the interface config now with an address from DHCP.

Interface Vlan2 "outside", is up, line protocol is up
  Hardware is EtherSVI
      MAC address 0007.0e46.ad0d, MTU 1500
      IP address 192.168.1.101, subnet mask 255.255.255.0
  Traffic Statistics for "outside":
      16548 packets input, 23143012 bytes
      11208 packets output, 505824 bytes
      38 packets dropped
      1 minute input rate 208 pkts/sec,  293293 bytes/sec
      1 minute output rate 140 pkts/sec,  6077 bytes/sec
      1 minute drop rate, 0 pkts/sec
      5 minute input rate 0 pkts/sec,  0 bytes/sec
      5 minute output rate 0 pkts/sec,  0 bytes/sec
      5 minute drop rate, 0 pkts/sec
0
Comment
Question by:jtennyson
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 8
  • 8
17 Comments
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 36550156
Int vlan2
IP address x.x.x.x 255.255.255.x
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 36550177
Don't forget you'll need a default route as well then.

Route outside 0.0.0.0 0.0.0.0 x.x.x.y
The x.x.x.y should be the IP of internet router/modem.
0
 
LVL 30

Expert Comment

by:Randy Downs
ID: 36550207
http://www.cisco.com/en/US/docs/security/pix/pix63/command/reference/gl.html

 To reset the interface and delete the DHCP lease from PIX Firewall, configure a static IP address with the ip address if_name ip_address [netmask] or ip address if_name pppoe | dhcp [setroute] command, or use the clear ip command.

The ip address dhcp and pppoe command options are mutually exclusive.

0
Ready to trade in that old firewall?

Whether you need to trade-up to a shiny new Firebox or just ready to upgrade from whatever appliance you're using now, WatchGuard has the right appliance for you! Find your perfect Firebox today with appliance sizing tool!

 

Author Comment

by:jtennyson
ID: 36550229
The LAN address correct?
0
 

Author Comment

by:jtennyson
ID: 36550260
Erniebeek - I need to route to the routers inside LAN address correct.  192,168.1.254?
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 36550318
No, the pix needs a default gateway. If your provider gave you a static IP, he should have also have given you a gateway address. Did he?
0
 

Author Comment

by:jtennyson
ID: 36550402
The router does not have a static IP on the outside.  The gateway wouldn't be the static IP on the inside of the router?
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 36558611
Ehr, but the question was: 'how do I assign a static ip on the outside' was it?

So what we are discussing here is what to do when you are going to assign a static ip on the outside.

When using DHCP (as you are now), a default gateway will be assigned automatically.
0
 

Author Comment

by:jtennyson
ID: 36560137
No.  I want to assign a static IP on the  ASA wich connects to the DSL router.  It is on the inside.  connecting to 192.168.1.254.  I don't want to use DHCP on the router.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 36560262
Ok, getting confused here.

Could you try to describe this a bit more elaborate?
0
 

Author Comment

by:jtennyson
ID: 36560518
I am going to create a (very crude) diagram and upload it.
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 36560520
Please do :)
0
 

Author Comment

by:jtennyson
ID: 36560682
Maybe this helps.
Juarez-diagram.pdf
0
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 500 total points
ID: 36560735
Ah, I think I'm getting it :)

The ASA is on the inside of the router getting a DHCP addres on it's outside interface (from the router.

So you'll need:

Interface vlan2
IP address 192.168.1.x 255.255.255.0

For the x fill in the number you would like it to have.
And:
route outside 0.0.0.0 0.0.0.0 192.168.1.254

That should do the trick.
0
 

Author Comment

by:jtennyson
ID: 36560821
Thanks so much
0
 

Author Closing Comment

by:jtennyson
ID: 36560831
Thanks for the help.  I know I wasn't all that clear at the beginning
0
 
LVL 35

Expert Comment

by:Ernie Beek
ID: 36560848
:)
Well, eventually we got there, didn't we ;)

Thanks for the points.
0

Featured Post

IoT Devices - Fast, Cheap or Secure…Pick Two

The IoT market is growing at a rapid pace and manufacturers are under pressure to quickly provide new products. Can you be sure that your devices do what they're supposed to do, while still being secure?

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
On Feb. 28, Amazon’s Simple Storage Service (S3) went down after an employee issued the wrong command during a debugging exercise. Among those affected were big names like Netflix, Spotify and Expedia.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question