troubleshooting Question

Cisco ASA NAT not working???

Avatar of huffmana
huffmanaFlag for United States of America asked on
* ASACiscoNetworking
17 Comments1 Solution137 ViewsLast Modified:
I can't get my ASA NAT to work.  I'm testing to configure the firewall for our shop by simulating it on our local network.  The ISP router is at 192.168.168.1.  The ASA can ping out to the internet but the PC can't.

The PC picks up DHCP OK and can ping 192.168.171.1 (ASA GigabitEthernet0/1), but it can't ping the default gateway ASA 192.168.168.233 (ASA GigabitEthernet0/0) or beyond.

<------------------ASA-------------->
!
interface GigabitEthernet0/0
 nameif outside
 security-level 0
 ip address 192.168.168.233 255.255.255.0
!
interface GigabitEthernet0/1
 nameif inside
 security-level 100
 ip address 192.168.171.1 255.255.255.0
!
interface GigabitEthernet0/3
 nameif mngt
 security-level 0
 ip address 10.10.10.13 255.255.255.224
!
 icmp permit any mngt
 icmp permit any inside
 icmp permit any outside
!
object network INSIDE-SUBNET
 subnet 192.168.171.0 255.255.255.0
nat (inside,outside) source dynamic INSIDE-SUBNET interface
route outside 0.0.0.0 0.0.0.0 192.168.168.1 5

  dhcpd address 192.168.171.3 - 192.167.171.63 inside
  dhcpd address 192.168.171.3-192.167.171.63 inside
  dhcpd address 192.168.171.3-192.168.171.63 inside
  dhcp dns 192.168.168.1
  dhcpd dns 192.168.168.1
  dhcpd lease 3000
  dhcpd domain cortana.com
  dhcpd ping_timeout 20
  dhcpd option 3 192.168.171.1
  dhcpd option 3 ip 192.168.171.1
  dhcpd enable inside
  dhcpd option 2 ascii dhcpd_option_2_ascii_examplestring_HERE

<-----------------SWITCH------------------>
---- ASA GigabitEthernet0/1 -> switch on inside of the ASA ----
!
interface FastEthernet0/1
des to_ASA_GigabitEthernet0/1_inside
 switchport trunk encapsulation dot1q
 switchport trunk native vlan 200
 switchport trunk allowed vlan 1,200
 switchport mode trunk
!
----PC -> witch on inside of the ASA ----
interface FastEthernet0/2
 des PC_to_Switch_on_the_inside_of_ASA
 switchport access vlan 200
 switchport mode access
ASKER CERTIFIED SOLUTION
Pete Long
Solutions Architect
Join our community to see this answer!
Unlock 1 Answer and 17 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 17 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros