[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now


Cisco ASA 5505 PPPOE configuration

Posted on 2014-02-02
Medium Priority
Last Modified: 2014-03-29
Hi Experts
I was given a PPPOE was modem on which I had to configure the ASA 5505 , While following below steps .. I could not establish the PPOE connection ...

I followed the below link .. but I couldnt create  PPPOE connection .


it explains for below step which is meant to be created on eth port . but when I issue this command , it gives error to supply this command in Vlan interface ...

hostname(config)# interface gigabitethernet 0/0
hostname(config-if)# ip address pppoe

Also below command is both can be issued on Global config mode and vlan interface mode

Step 1      Enable the PPPoE client by entering the following command from interface configuration mode:

hostname(config-if)# ip address pppoe [setroute]

any quick tip what can be missing in the config , I am not able to paste the config as i am not sitting with device ??

the only difference I am encountering is .. guide does not explain to define vlan configurations and setting interface as outside , and I am not able to config eth0/0 and only can work on vlan2 .

and also I assigned  vlan 2 to the eth 0/0  with switchport access valn 2 command ..
Question by:annasad
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
LVL 57

Assisted Solution

by:Pete Long
Pete Long earned 2000 total points
ID: 39829743

Author Comment

ID: 39830200
well , I did the same configuration ...

what I extra did is  ... to create eth 0/0 to under Vlan 2 . because I believed that if I am doing interface mode commands on vlan 2 , then I have to assign ethernet 0/0 to vlan 2 and for this i supplied below command on eth 0/0  

switchport mode acces vlan 2  

now I am not sure if I have to do this or not , but I just thought to associate logical interface to port because how vlan 2 wil map the config on eth 0/0 ??

and also I dont need to supply any commands on eth 0/0 ??

I am not clear whats the difference here in eth 0/0 and vlan2 and their relationship
LVL 57

Accepted Solution

Pete Long earned 2000 total points
ID: 39832273
OK, with an ASA 5505 you DO NOT configure the physical ethernet ports (as far as IP addresses go anyway) you configure VLANS, typically VLAN1 is inside and VLAN2 is outside.

The only thing you do with the physical ethernet ports is add then to the vlans, by default ethernet0/0 is usually the outside one and the others are the inside ones. Because VLAN1 is the default vlan (in cisco world), you dont have to 'tag' ports into VLAN1 you only have to 'tag' ports into to other vlans (in your case VLAN2).

So your physical ports are usually configured like so
interface Ethernet0/0
 switchport access vlan 2
interface Ethernet0/1
interface Ethernet0/2
interface Ethernet0/3
interface Ethernet0/4
interface Ethernet0/5
interface Ethernet0/6
interface Ethernet0/7

Open in new window

Your VLAN Ports are configured like so (this is for DHCP PPPoe)
interface Vlan1
 nameif inside
 security-level 100
 ip address 
interface Vlan2
 nameif outside
 security-level 0
 pppoe client vpdn group PNL-DIALER-GROUP
 ip address pppoe setroute 

Open in new window

Your PPPoE Dialer group is set up like this;
vpdn group PNL-DIALER-GROUP request dialout pppoe
vpdn group PNL-DIALER-GROUP localname username@petenetlive.net.uk
vpdn group PNL-DIALER-GROUP ppp authentication chap
vpdn username username@petenetlive.net.uk password Password123 store-local

Open in new window

Your internal Traffic will need NAT like so;
object network obj_any
 nat (inside,outside) dynamic interface

Open in new window

That should be all you need to do


Author Comment

ID: 39842818
thanks PL

above is useful , however  I believe the sequence of entering these commands is very essential
specially when you issue command ,

ip address setroute

that should be the last command on vlan2 interface , any chunk missing or adding after this command does not let you establish the PPPOE connection

but I thought may be that can be mixed by restarting the firewall , but I think I was wrong , it did not help me , untill i spent it doing again and again

but I have not configured the internet on this ... So in order to enable internet running

do I need below three commands only ?

object network obj_any
 nat (inside,outside) dynamic interface

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

There’s a movement in Information Technology (IT), and while it’s hard to define, it is gaining momentum. Some call it “stream-lined IT;” others call it “thin-model IT.”
This article is in regards to the Cisco QSFP-4SFP10G-CU1M cables, which are designed to uplink/downlink 40GB ports to 10GB SFP ports. I recently experienced this and found very little configuration documentation on how these are supposed to be confi…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question