Cisco ASA 5505 PPPOE configuration

Posted on 2014-02-02
Last Modified: 2014-03-29
Hi Experts
I was given a PPPOE was modem on which I had to configure the ASA 5505 , While following below steps .. I could not establish the PPOE connection ...

I followed the below link .. but I couldnt create  PPPOE connection .

it explains for below step which is meant to be created on eth port . but when I issue this command , it gives error to supply this command in Vlan interface ...

hostname(config)# interface gigabitethernet 0/0
hostname(config-if)# ip address pppoe

Also below command is both can be issued on Global config mode and vlan interface mode

Step 1      Enable the PPPoE client by entering the following command from interface configuration mode:

hostname(config-if)# ip address pppoe [setroute]

any quick tip what can be missing in the config , I am not able to paste the config as i am not sitting with device ??

the only difference I am encountering is .. guide does not explain to define vlan configurations and setting interface as outside , and I am not able to config eth0/0 and only can work on vlan2 .

and also I assigned  vlan 2 to the eth 0/0  with switchport access valn 2 command ..
Question by:annasad
  • 2
  • 2
LVL 57

Assisted Solution

by:Pete Long
Pete Long earned 500 total points
ID: 39829743

Author Comment

ID: 39830200
well , I did the same configuration ...

what I extra did is  ... to create eth 0/0 to under Vlan 2 . because I believed that if I am doing interface mode commands on vlan 2 , then I have to assign ethernet 0/0 to vlan 2 and for this i supplied below command on eth 0/0  

switchport mode acces vlan 2  

now I am not sure if I have to do this or not , but I just thought to associate logical interface to port because how vlan 2 wil map the config on eth 0/0 ??

and also I dont need to supply any commands on eth 0/0 ??

I am not clear whats the difference here in eth 0/0 and vlan2 and their relationship
LVL 57

Accepted Solution

Pete Long earned 500 total points
ID: 39832273
OK, with an ASA 5505 you DO NOT configure the physical ethernet ports (as far as IP addresses go anyway) you configure VLANS, typically VLAN1 is inside and VLAN2 is outside.

The only thing you do with the physical ethernet ports is add then to the vlans, by default ethernet0/0 is usually the outside one and the others are the inside ones. Because VLAN1 is the default vlan (in cisco world), you dont have to 'tag' ports into VLAN1 you only have to 'tag' ports into to other vlans (in your case VLAN2).

So your physical ports are usually configured like so
interface Ethernet0/0
 switchport access vlan 2
interface Ethernet0/1
interface Ethernet0/2
interface Ethernet0/3
interface Ethernet0/4
interface Ethernet0/5
interface Ethernet0/6
interface Ethernet0/7

Open in new window

Your VLAN Ports are configured like so (this is for DHCP PPPoe)
interface Vlan1
 nameif inside
 security-level 100
 ip address 
interface Vlan2
 nameif outside
 security-level 0
 pppoe client vpdn group PNL-DIALER-GROUP
 ip address pppoe setroute 

Open in new window

Your PPPoE Dialer group is set up like this;
vpdn group PNL-DIALER-GROUP request dialout pppoe
vpdn group PNL-DIALER-GROUP localname
vpdn group PNL-DIALER-GROUP ppp authentication chap
vpdn username password Password123 store-local

Open in new window

Your internal Traffic will need NAT like so;
object network obj_any
 nat (inside,outside) dynamic interface

Open in new window

That should be all you need to do


Author Comment

ID: 39842818
thanks PL

above is useful , however  I believe the sequence of entering these commands is very essential
specially when you issue command ,

ip address setroute

that should be the last command on vlan2 interface , any chunk missing or adding after this command does not let you establish the PPPOE connection

but I thought may be that can be mixed by restarting the firewall , but I think I was wrong , it did not help me , untill i spent it doing again and again

but I have not configured the internet on this ... So in order to enable internet running

do I need below three commands only ?

object network obj_any
 nat (inside,outside) dynamic interface

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Every server (virtual or physical) needs a console: and the console can be provided through hardware directly connected, software for remote connections, local connections, through a KVM, etc. This document explains the different types of consol…
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now