ASA 5512 Config question

I've configured an ASA 5512 and I'm not sure if the config is correct.  I wanted to see if anyone could glance at this config and see if they see any problems.  I'm in a situation where it needs to work immediately after it boots and I want to try to avoid any issues if I can.

I hope someone has a few minutes.  I really appreciate it.  Thanks.
ASA5512.txt
LVL 4
jplagensAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

fgasimzadeCommented:
It looks fine.. What exactly this ASA need to do?
0
pgolding00Commented:
dont know about:
route inside 68.65.151.0 255.255.255.0 192.168.10.10 1
because 192.168.10.0 is not attached to an interface. this would work on a router, but not so sure about recursive routing lookup on asa. you definitely cant source route, which is sort-of what this is trying to do. just use:
route inside 68.65.151.0 255.255.255.0 192.168.0.16
no question that this will work.

otherwise, as above, what are you trying to achieve with it?
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
jplagensAuthor Commented:
The issue was that this ASA 5512 was replacing an old Pix515e.  Due to the maintenance window I didn't have much time, so it was going to be pretty much unplug/unrack the Pix, put in the ASA, turn it on and it had to work.  I haven't done a lot of work with the new NAT commands in 8.3 or higher so I was stressing a little about it working.

I discovered that inside route to 192.168.10.10.1 wasn't needed.  No one new what it was so I removed it.

The only changes I made was that I added a new object:

object network OBJ_ANY
subnet 0.0.0.0 0.0.0.0
nat (inside,outside) dynamic interface

and I forgot to apply the access-list:

access-group inbound in interface outside
0
fgasimzadeCommented:
Yeah, I was just going to point out, that you will not be able to access Internet unless you configure dynamic NAT, what you have done.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Cisco

From novice to tech pro — start learning today.