Link to home
Start Free TrialLog in
Avatar of Daniel Booker
Daniel BookerFlag for United States of America

asked on

Cisco ASA5506w-x first time setup

I have a cisco asa 5506 running version asdm 7.4 and asa 9.4. I am trying to set it for the first time and I'm not familiar at all with this. I can setup a basic router for a static WAN IP but have no clue on setup for this box. I have reset the box to factory defaults and have interfaced into the box on Ethernet1/2 "inside" on and I am in the box using the ASDM. (Also I have verified the cable I am using does work for internet by setting up a router on the same static WAN to verify)

I am looking to setup this as a router replacing a home Linksys router. We have a Comcast box in passthrough/bridged.

1. How do I set ethernet1/1 for "outside" static WAN IP address given my ISP? I believe the Comcast box LAN ip is so do I set the outside IP to and use a static route or use the WAN IP (not actual IP)

2. I guess once I have internet how do I do a basic port forwards like rdp 3389 to local LAN
Avatar of Benjamin Van Ditmars
Benjamin Van Ditmars
Flag of Netherlands image

Link to home
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Daniel Booker


I'm not at the office anymore so i'll be sure to try this tomorrow.

I'm interested in "Option 1 static IP address" the most because I would like this to be our router.

opion 1static ip address

and set youre static ip address. you alse need to add a rourte. from the outside to and fill in the ip address of the gateway of youre provider.

I have set my external "outside" security to 0.

I think i remember reading what you are talking about, about setting a route it is just kind of foreign to me because i have never done it. I'll look into what you are talking about I think i might know how to now from playing around most of the day. (Was able to get option 2 to work, but still want to just use only option 1)

2. Make a nat rule
I'll need to see this because i have no looked at this part yet because it took me a good while to figure out on how just to get on the internet.
it al depends on what youre provider is giving to you ;) in holland we are lucky to have almost in every private house an optic connection up to 500/500 mbit with more then one ip

the routing part you can find in device setup -> Routing -> Static routing. and then just press the add button say interface outside, network and then youre gateway ip and youre all set

let me know if you need more help

I swear I did all of what you said before, but now it works!

I tried then go add a firewall and create a "access rule" and seemingly I do not have internet access anymore. I tried to delete the rule I just setup and still can not get to the internet. I was unsure on how to do exactly what you were saying and found this page.
I wouldn't suppose I could grab your help to remote into my PC to help me get the basic idea of what is going?

I reset my box back to factory using the CLI
1. ena
2. config t
3. config factory-default
4. reload save-config noconfirm

I ran back through the the device setup > launch setup wizard. And configured it again for how it had worked just a little bit ago with using a static wan IP and setting up a nat (any) and used the gateway of the static IP, but not getting internet.
ok lets test some stuff.
from the asdm tools -> ping
and ping from this tool youre external IP, GW Ip and

let see how for you come.
oke let's do a factory reset

conf t
config factory-default {youre internal network addres}
do a write mem and reload.
don't do a restore of youre config

what kinda ip do you get from youre provider static/dhcp ? or are you still behind a nat ?
No I am not able to ping
I get a static IP I am not behind a NAT.
ok can you ping youre gateway ?
I just did what you said and waiting for it to reload now.
The gateway meaning the asa box? If so then yes.
Do you use Skype if so I am willing to paypal you some money for compensation for your time.
after factory reset let's do this

1. setup Outside interface.
device setup -> Interfaces

select interface
interface name Outside
check box interface enabled
select static ip
enter ip address and subnet mask

press ok button

2. make our default route
device setup -> Routing - Static Routes
Add new route like this

interface outside
gateway ip {youre provider gateway ip}

press ok button to save

3. add dynamic nat policy for lan to wan

go to Firewall -> Nat Rules

press the down arrow on the add button en select Add "network object" nat rule

Name {LAN Network}
type network
Ip address youre local network like
select correct Netmask

set the box Add Automatic Adress Transport Rules
type Dynamic PAT (Hide)
Translated addr: Outside

now test if you can ping youre provider gateway, and some public address like

if this works

add an Access control list to allow ping reply to come back

Firewall -> Access Rules

interface outside

action permit
source any
destination any
service icmp

now you should be able to ping from youre client

last thing is dns. but try this first
No need to send some money, this forum is all about it people to help the other :)
No, it did not work. I am sure that the IP for the static wan for my ISP is correct because I setup a home router and had to tested before plugging in the asa box.
I just realized that while we were configuring this we did not setup a DNS for the DHCP. Let me set a static IP on my notebook .
Do you get reply from youre provider gateway ip ?
Still not working :(
no I do not. 50.199.---.--- request time out.
I am able to ping that gateway from a different PC on different network that has a different static IP.

what is youre subnet mask at Outside interface
send me info to my email

because i have the feeling the problem is here

network address
broadcast address
and gateway address
Generating server: ------
 #554 5.4.4 SMTPSEND.DNS.NonExistentDomain; nonexistent domain ##
Thanks for the detailed description and troubleshooting with me.

Also interesting to find out my ISP box arp table held onto a another device trying to use that same static IP when I flip between my home router and asa box and that would explain another reason why I was not able to get it to work at first.