Hi, I have Frontier FIOS and am currently using an ASA for my Internet router but want to use a PA-200 with a Cisco 891F behind it. The design looks like this: ISP(DHCP)----(e1/1)-PA-200-(e1/2)---891F (5 subnets) I set e1/1 untrust w/DHCP from the ISP and e1/2 trust w/static /30 to 891F. I also checked auto create default route to inject route from the ISP and setup Outbound NAT to any/any with no other security policies in place. I allowed ping on both interfaces for troubleshooting. I prefer not to use the PA-200 for DHCP, therefore, on the 891, I have multiple VLANs with DHCP processes doling out IP addresses/SM/GW/DNS. That works fine and all routing seems to be working, as well. Added a default route to exit the 891s interface connected to the PA-200. The PA-200 did acquire a DHCP address from the ISP. The trouble I'm having is that I cannot access the Internet from any deivce nor ping the untrusted interface ip. I am not using the ISPs router at all. I guess I am not sure if this is the best design to get this going so, if not, can someone point me in the right direction? I hope this makes sense. Thanks, Dan
... View more