Asa Aha
|
Firewall(config)# interface if name Firewall(config-if)# ip address pppoe [setroute] |
The firewall sends PPPoE requests on its outside interface to authenticate and obtain an IP address and subnet mask from the ISP. If the default gateway that is returned should be used as the firewall's default route, add the setroute keyword. Otherwise, a default route must be configured manually on the firewall.
You can renegotiate the address parameters with the ISP by entering this configuration command again.
If you already have a static IP address assigned by the ISP, you can use an alternative command:
Firewall(config)# ip address outside ip-address netmask pppoe [setroute]
Here, the IP address and netmask are already known. The firewall still authenticates with the ISP through PPPoE, but it uses these values rather than negotiating them.
As an example of PPPoE interface configuration, the following commands can be used to define a VPDN group for one ISP that can be used by the firewall:
Firewall(config)# vpdn username JohnDoe password JDsecret Firewall(config)# vpdn group ISP1 localname JohnDoe Firewall(config)# vpdn group ISP1 ppp authentication chap Firewall(config)# vpdn group ISP1 request dialout pppoe Firewall(config)# ip address outside pppoe setroute
4. Test the interface:
a. Verify the IP address:
Firewall# show ip or
Firewall# show ip if name {dhcp | pppoe}
b. Ping the next-hop gateway address:
Firewall# ping [if name] ip address
You can send ICMP echo requests to the next-hop gateway or a host located on the same subnet as the firewall interface. You can specify which firewall interface name to use with if_name, but this is not required. The target is at ip_address.
If ICMP replies are received, they are reported along with the round-trip time, as in this example:
Firewall# ping 192.168.199.4
192.168.199.4 response received 192.168.199.4 response received 192.168.199.4 response received Firewall#
c. Verify PPPoE operation:
As soon as the PPPoE client is configured and the interface is connected and is operational, the firewall automatically attempts to bring up the PPPoE connection. You can see the status with the following command:
Firewall# show vpdn session
For example, if the PPPoE client has negotiated its connection, you might see the following output:
Firewall# show vpdn session
PPPoE Session Information (Total tunnels=1 sessions=1) Remote Internet Address is 192.168.11.1 Session state is SESSION_UP
Time since event change 10002 secs, interface outside PPP interface id is 1
36 packets sent, 36 received, 1412 bytes sent, 0 received Firewall#
If the PPPoE connection does not come up normally, you can use the debug pppoe event command to see PPPoE negotiation events as they occur.
Interface Configuration Examples
A firewall has three interfaces:
• inside (gb-ethernet0)
• outside (gb-ethernet1)
These interfaces have IP addresses 172.16.1.1, 172.17.1.1, and 172.18.1.1, respectively. The configuration commands needed are as follows, for both PIX 6.3 and ASA releases:
Continue reading here: Configuring IPv6 on an Interface
Was this article helpful?