Solved

asa config

Posted on 2013-11-08
4
420 Views
Last Modified: 2013-11-08
I updated my firewall 5505 version and edited the config from the old version to new version. I just noticed that new version outside route is .142 and the old version outside route is .141 - while the outside interface is .142

I thought the route outside has to look at the outside interface, so how was it working in the old version? I might have made a typing error on the new versionand should have put .141


new version is:
object network obj_any
 nat (inside,outside) dynamic interface
access-group outside_access_in in interface outside
route outside 0.0.0.0 0.0.0.0 75.22.180.142 1

old version is:
access-group outside_access_in in interface outside
route outside 0.0.0.0 0.0.0.0 75.22.180.141 1

the outside interface is:
75.22.180.142
0
Comment
Question by:tolinrome
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 57

Accepted Solution

by:
Pete Long earned 500 total points
ID: 39634096
?

The Route Outside command points to the IP address of the ROUTER supplied by your ISP it DOES NOT point to the outside interface IP address.

If you think yours DID then your are incorrect, or the config you are looking at is incorrect (or has been changed).

Traffic would never go outbound if the ASA looked at itself for its default route.


PL
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 39634103
And OLD and NEW (i.e. pre and post version 8.3) the route command has not changed.
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 39634107
>>route outside 0.0.0.0 0.0.0.0  75.22.180.142 1

If your outside IP is 75.22.180.142 then the above was NOT your route stement
0
 
LVL 7

Author Closing Comment

by:tolinrome
ID: 39634732
yes, that was the problem. thanks.
0

Featured Post

Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

When it comes to security, there are always trade-offs between security and convenience/ease of administration. This article examines some of the main pros and cons of using key authentication vs password authentication for hosting an SFTP server.
Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question