It was a dark, cold night in late December, and Bob, (the optimistic firewall technician), had a single ASA to deploy before going home for the holidays.  The requirements for the firewall were simple.   Bob read them slowly as follows:

  1. R1 should be able to ping the server "" by name.
  2. PC should be able to ping the server "" by name.

Bob also read the background information to see if this was something he could finish before leaving the office.   Bob read the following:

DNS Server is mapping to the global address of
All devices have appropriate routes in place.
R1 and the PC are both configured to use the DNS server at
DNS Server, PC, R1  and supporting L2 switchports for the ASA are configured correctly.

Bob also looked at the diagram:

Bob's Quick Installation Gone Wrong

Bob put the following together in notepad, and then quickly pasted it into the ASA using Secure CRT:

!************ begin ASA configuration ************


conf  t
clear config all

no nat-control
hostname ASA1
interface Ethernet0/0
nameif outside
ip address
interface Ethernet0/1
nameif inside
ip address
interface Ethernet0/2
nameif dmz
ip address
nat (inside) 1
nat (dmz) 1
global (outside) 1 interface
access-list outside permit tcp any host eq www
access-list outside permit icmp any host echo
access-group outside in interface outside
static (dmz,outside)


!************end ASA configuration*************

After waiting a few moments, Bob went to R1, issued the following command and hoped for the best:


The ping failed.    He tried the same ping from the PC which also failed.    As much as Bob “hoped” it would work, it didn’t, and Bob secretly wished he had the skills and knowledge of a Security CCIE that would allow him to quickly solve the configuration problem so he could go home for the holidays.

My fellow CCIE bloggers and INE fans, your mission, should you choose to accept it, is to identify the missing and/or incorrect elements that need to be in place for successful pings to from the PC and R1.

There is more than 1 way to solve this, and there are between 5 and 7 corrections that need to take place.

Will you assist BOB?

About INE

INE is the premier provider of technical training for the IT industry. INE is revolutionizing the digital learning industry through the implementation of adaptive technologies and a proven method of hands on training experiences. Our portfolio of trainings is built for all levels of technical learning, specializing in advanced networking technologies, next generation security and infrastructure programming and development. Want to talk to a training advisor about our course offerings and training plans? Give us a call at 877-224-8987 or email us at

Subscribe to INE Blog Updates

New Blog Posts!