[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

ASA 5512 Config question

Posted on 2013-02-05
4
Medium Priority
?
1,199 Views
Last Modified: 2013-03-14
I've configured an ASA 5512 and I'm not sure if the config is correct.  I wanted to see if anyone could glance at this config and see if they see any problems.  I'm in a situation where it needs to work immediately after it boots and I want to try to avoid any issues if I can.

I hope someone has a few minutes.  I really appreciate it.  Thanks.
ASA5512.txt
0
Comment
Question by:jplagens
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 18

Expert Comment

by:fgasimzade
ID: 38858870
It looks fine.. What exactly this ASA need to do?
0
 
LVL 8

Accepted Solution

by:
pgolding00 earned 1500 total points
ID: 38859377
dont know about:
route inside 68.65.151.0 255.255.255.0 192.168.10.10 1
because 192.168.10.0 is not attached to an interface. this would work on a router, but not so sure about recursive routing lookup on asa. you definitely cant source route, which is sort-of what this is trying to do. just use:
route inside 68.65.151.0 255.255.255.0 192.168.0.16
no question that this will work.

otherwise, as above, what are you trying to achieve with it?
0
 
LVL 4

Author Comment

by:jplagens
ID: 38859712
The issue was that this ASA 5512 was replacing an old Pix515e.  Due to the maintenance window I didn't have much time, so it was going to be pretty much unplug/unrack the Pix, put in the ASA, turn it on and it had to work.  I haven't done a lot of work with the new NAT commands in 8.3 or higher so I was stressing a little about it working.

I discovered that inside route to 192.168.10.10.1 wasn't needed.  No one new what it was so I removed it.

The only changes I made was that I added a new object:

object network OBJ_ANY
subnet 0.0.0.0 0.0.0.0
nat (inside,outside) dynamic interface

and I forgot to apply the access-list:

access-group inbound in interface outside
0
 
LVL 18

Expert Comment

by:fgasimzade
ID: 38859816
Yeah, I was just going to point out, that you will not be able to access Internet unless you configure dynamic NAT, what you have done.
0

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
During and after that shift to cloud, one area that still poses a struggle for many organizations is what to do with their department file shares.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question