Wolfmansb's profile

Contributor

 • 

2 Messages

Monday, November 3rd, 2014 9:45 PM

NVG589 with Public IP's and Cisco ASA

I got my static ip range today and was able to assign one of those IP Addresses to my 5505 ASA. When i try to establish my Site to site vpn with my Work 5520 ASA the IKE traffic does not appear to be making it back to my internal ASA on the newly assigned public IP's. All firewall options are off and i am not using pass through mode on the ATT gateway. If i use the pass through mode  and change my endpoint to reflect the modems external adress the vpn will .connect without incident. (defeats the purpose of getting static IP's)  Anyone have a ny good ideas? AT&T support does not know why it's blocking the IKE traffic or how to fix it.

Thanks in advance for anyone that has a helpful idea..

 

 

ACE - Expert

 • 

35K Messages

9 years ago

Is the IPSEC tunnel the first thing you're trying to do with your new static subnet on the Cisco ASA?  Have you successfully tested such mundane things as PING to and from the ASA?

 

How did you set up the static subnet on the Residential Gateway?  Did you manually set one of the available addresses on the external interface of the ASA?

 

Contributor

 • 

2 Messages

9 years ago

I can browse the internet, stream video and ping to my hearts content. but unless i use the DHCP from the NVG589 to assign the ip address, the ipsec traffic will not flow. I just used the dhcp to assign a public ip to my ASA and the tunnel comes up without issue. Problem is i do not want other devices being handed public ip addresses. When i turn off the public assign of the ip addresses i cannot use the IP Allocate tab to assign the public ip to the ASA. I get error " A required setting is empty" when i try. Suggestions?

Community Support

 • 

6.7K Messages

9 years ago

Hi @Wolfmansb,

 

There is a workaround on this. It sounds like you need the passthrough setup so certain traffic is not blocked. If you set it up using DHCPS:fixed and put in the MAC address to your ASA, it will passthrough the traffic to that device. After that, you want to hard code your ASA with one of the static IPs in your block. That way, it should passthrough the traffic, and it will be to one of your static IPs.

 

Hope this helps.

 

-David T

Not finding what you're looking for?
New to AT&T Community?
New to the AT&T Community? Start by visiting the Community How-To.
New to the AT&T Community?
Visit the Community How-To.