ASA 5515-x Vpn And HP Pro-curve Vlans

Jan 22, 2013

I have a Cisco ASA 5515-x, setup as my router with a split-tunnel SSL VPN for remote users.. It works great, except when connected via VPN I can only access the same subnet the ASA and HP switch reside on. My VLANs provided via my core HP 5406zl L3 switch are inaccessible. This must just be a simple routing issue, but between Cisco and HP I can not wrap my head around it.

Comcast---> Cisco ASA (VPN) 10.20.28.1 ---> HP (vlans)-----> VLAN 1 10.20.28.254 (Works fine over VPN), VLAN 45 -10.20.45.254 (No access over vpn), VLAN 99- 10.20.99.254 (No access over vpn)

Intervlan routing works great, I can access VLAN 99 from VLAN 1 and vise-versa. I have a route on the HP switch for 0.0.0.0 0.0.0.0 10.20.28.1 for internet access. On the Cisco I have a static route of 10.20.0.0 255.255.0.0 10.20.28.254. I believe my issue is that the HP requires your default gateway to be your VLAN IP for the intervlan routing to work. With my split tunnel SSL VPN, I do not believe it uses the correct routes.

Where and what routes do I need to add so that I can access the other VLANs when connected via VPN?I have a test environment setup and I am going to start testing by disabling split tunneling to see if I can access the other VLANs.

View 6 Replies


ADVERTISEMENT

Cisco Firewall :: Configuring VLANs On 5515-X Is It Possible

Mar 29, 2013

I am trying to connect 2 VMWARE servers directly to my 5515-X firewall. [code]ASDM will not let me assign the same VLAN to both Gi0/2 and Gi0/3. I dont want to connect my VMWARE servers to a switch first (that just adds one more component that can fail).

View 4 Replies View Related

HP Pro-Curve SNMP Link Aggregation Configuration

Aug 7, 2012

I am looking after a mixed collection of Cisco and HP switches and use a Perl script to extract configuration data.I use the ifStackStatus table (OID: 1.3.6.1.2.1.31.1.2.1.3) from RFC1573 to sucesfully obtain the EtherChannel data from the Cisco switches but, though I do obtain data from the same table from the Procurve switches it seems to bear no resemblance to Link Agregation. I could look at other tables and may have to - but would like to use this one in order to simplify the code.

View 2 Replies View Related

Determine Why HP Pro-curve Switch Randomly Faults?

Feb 8, 2012

How to determine why my HP Pro-curve switch randomly faults and resets during the day, about 3 to 5 times?

View 5 Replies View Related

HP Pro Curve 2650 And 2610 VLAN Infrastructure?

Mar 3, 2013

I have 2 Procuve Switches one is 2650 were all the Department PC's & Wireless access points connected & second one is 2610 were i have the firewall connected,Active Directory & Windows DHCP Server

Switch 1- 2650
Ports
Port 1-16 is used by HR Department
Port17-32 is used by Finanace Department
Port 33-34 is used by Access Points
Port 41-48 is used by Users

Port 50 is used to uplink to switch 2610.What i wanted to achive is Isolcate Departments & Users & Access Points through VLAN from each other but they should be able to hit our Active directory for authentication, Firewall for internet & DHCP Server for IP's.

View 3 Replies View Related

Daisy Chain 2 Pro-curve 1810g 8 Port Switches

Jan 8, 2012

i am trying to daisy chain 2 pro-curve 1810g 8 port switches.i got the cable i need to connect them but i just want to know what kind of settings i have to change on the switches to have it run as best as it can.

View 17 Replies View Related

Why Blackberry Curve 9300 3g Wifi Doesn't Find Pc Wireless

Sep 27, 2011

why my Blackberry wifi doesnt find my pc wireless. I have Blackberry curve 9300 3G. OS 6

View 1 Replies View Related

Protocols / Routing :: Connect Two Asterisk Server On A HP Pro Curve 2626 Switch

Apr 11, 2013

I am trying to connect two Asterisk Server (with DHCP server enabled on both) on a HP Pro Curve 2626 switch. Server A has IP address 192.168.2.1 and Server B has IP address 192.168.3.1. I created a two new VLAN on switch, VLAN2 for 192.168.2.0 network and VLAN3 for 192.168.3.1 network. I put the command "ip routing" on the switch. My goal is to be able to ping ip address from PC 1(VLAN2) to PC 2(VLAN3) and vice versa... I'm not sure what I am missing... By the way, there is NO ROUTER involved on this set up. I tried to Google and it says HP ProCurve 2626 is a Layer 3 switch so IP routing should be possible.

View 4 Replies View Related

Cisco Firewall :: To Deploy ASA5585 In Between User Vlans And Server Vlans

Jun 1, 2012

WE have to deploy ASA5585 in between User vlans & server vlans. we have to find all the ports that needs to be opened on firewall. any tools to do same.

View 2 Replies View Related

Cisco VPN :: ASA 5515 With 8.6 - Blocking VPN

Jan 29, 2013

We just upgraded our ASA here at work to a new ASA5515-x with 8.6 (used to have a ASA5510). We used the VPN wizard to create a generic VPN Profile and Group. The profile works with split tunneling just fine from outside our network. But when I go home, I have an ASA5505 with 8.4. When i connect to work using the VPN Client on windows, it connects and gets the appropriate IP but i am not able to get to anything on our work network. When i try and connect using the built-in client on Mac OS X (10.5, 10.6, 10.7 or 10.8) using IP Sec, it comes back and says "Remote server did not respond". If i look at my console on the Mac, it shows it connected, built the first tunnel, then it sits. if i watch the logs on our 5515, it shows the same. But it will not authenticate the local user past the group. The Cisco VPN Client on the mac wont even attempt to connect, it just flashes connecting to x.x.x.x and disconnects about a second later.
 
Is there a setting that i am missing on my 5505 to allow VPN out? Is there a setting were missing on our 5515 that might not be allowing the VPN clients to connect from certain networks? 

View 2 Replies View Related

Cisco Firewall :: ASA 5515-x Self Power On?

Oct 28, 2012

Is there a way through the CLI to have the ASA 5515-x power back on after a power failure? Currently, the only way to restore power is to press the power button. The X series does not have a power switch the same as the 5500 series.

View 1 Replies View Related

Cisco VPN :: ASA 5515 - AnyConnect VPN Configuration

Jul 17, 2012

I'm trying to configure Any connect SSL RA VPN. I have followed the config guide for 8.4 & 8.6 but can't even get the Any connect page to load. I'm pasting the config below. Pl check and let me know what I have missed. Objectives are:
 
1. The user simply opens https://<outside-ip> and is prompted to install the any connect vpn client.
2. Is able to access internal LAN resources and browse the internet simultaneously (is split-tunneling required?)
  
ASA Version 8.6(1)
hostname Harpoon
domain-name xxxxx.com
enable password xxxxxxxxxx encrypted
passwd xxxxxxxxxxxx encrypted
names
[code]....

View 1 Replies View Related

Cisco Firewall :: Teamviewer Being Blocked By ASA 5515?

Apr 22, 2013

We are trying to get Teamviewer to work on our WAN, from the log traffic from the PC's to our Cisco IronPort Web Filter it looks like the ASA Firewall is blocking the traffic. We have opened everything we can open on our Cisco IronPort Web Filter and I have a Cisco TAC case open and they said it appears the ASA Firewall must be blocking the traffic.

View 3 Replies View Related

Cisco Firewall :: ASA 5515-X Vlan And IPS Configuration?

Oct 10, 2012

i need to configure a new ASA 5515-X with a 3 trunk port for vlans that become from switch, but i need turn on IPS in in-line mode, somebody has an example and limitations for this configuration type?

View 3 Replies View Related

Cisco Firewall :: Not Clear ASA 5515-k9 With Antivirus Or Not?

Oct 22, 2012

i would like to use ASA 5515-k9 with Antivirus and antispam but i don't know the part number that support this and how it process .

View 3 Replies View Related

Cisco Firewall :: Setup QoS Policy On ASA 5515?

Mar 18, 2013

I´m triing to setup a QoS policy on ASA 5515, i read several pages, but my questions are, how setup the real BW?, or is not necessary to do this?

View 7 Replies View Related

Cisco Firewall :: Dynamic PAT And Static NAT ASA 5515

Mar 23, 2013

Recently we migrated our network to ASA 5515, since we had configured nat pool overload on our existing router the users are able to translated their ip's outside. Right now my issue was when I use the existing NAT configured to our router into firewall, it seems that the translation was not successful actually I used Dynamic NAT. When I use the Dynamic PAT(Hide) all users are able to translated to the said public IP's. I know that PAT is Port address translation but when I use static nat for specific server. The Static NAT was not able to translated. Any conflict whit PAT to Static NAT?

View 3 Replies View Related

Cisco Firewall :: Configure ASA 5515 To Allow FTP Server Behind It?

May 5, 2013

We have one Cisco ASA5515 firewall, I configured ftp mode to passive, inspect ftp in service, use anoother public to do NAT with ftp server, and also configued ACL in outside interface, but I failed to access the ftp server from internet use that public ip address, no problem to acces the ftp server use its inside address in LAN.

View 9 Replies View Related

Cisco Firewall :: ASA 5515-X - After Upgrade From 8.6 To 9.1 No Ping?

Apr 21, 2013

I've got a little problem with my ASA 5515-X after upgrade from version 8.6 to 9.1.
 
I've got two 5515-X in A/S-mode and upgraded both as described on cisco's website (first standby-unit, failover, etc.). Everything worked just fine except pinging the ASA-interfaces themselfes. Before upgrade it was possible to ping from any subnet to the internal interface, but now it's not. If I'm on the router next to the ASA I'm able to ping, but every ping from behind that router fails. The ICMP-packets get into the ASA (counter on ACL raises up), but no reply is getting into the source.
 
The configuration fir ICMP was not changed and says "permit 0.0.0.0 0.0.0.0" for any ICMP on the internal interface. The router betwenn my subnet and the ASA has no ACL installed and - as said above - the ICMP gets obviously to the ASA but doesn't come back!?

View 4 Replies View Related

Cisco Firewall :: ASA5515-k9 Upgrade To ASA 5515-IPS-K9?

May 12, 2013

I was purchase ASA5515-K9 (Without IPS Edition) firewall and this is run smoothly our network. But right now i want to IPS facilities. Can i have any licnese purchase and upgrade from ASA5515-K9 to ASA5515-IPS-K9 abd use IPS edition ?

View 1 Replies View Related

Cisco Firewall :: ASA 5515 - Two Interfaces Cannot Be In Same Subnet

Dec 5, 2012

I am working on translating configuration from a firewall named Joe box to ASA 5515. On Joe box, it has 5 continuous public IP addresses (xx.xx.xx.73 -77/29), first one as interface IP and others as alias, on the Internet-facing interface. I need to configure ASA 5515 in the same way, however it seems not simple.

- The way to configure sub interfaces on 5515 is by configuring V LAN.
- The interface can hold xx.xx.xx.73/29 without a problem.
- The first sub interface can have IP address xx.xx.xx.74 however with different mask(/16), as it doesn’t allow /29.
- The second sub interface doesn’t allow to enter IP xx.xx.xx.75, saying "Failed to apply IP address to interface GigabitEthernet0.x, as the network overlaps with interface GigabitEthernet0. Two interfaces cannot be in the same sub net."

View 6 Replies View Related

Cisco Firewall :: Voip ASA 5515 Version 9.1

May 17, 2013

im changing the firewall 5510 to 5515, with ASA5510 the incoming and outgoing calls work perfectly, but when i active the 5515 the outgoing calls doesnt work, only the incoming calls work.
 
As you see on the topology,the flow of calls happens this way:

In the outgoing calls the phone forward the call to the PABX(172.17.3.4), and the PABX forward the call through the ISP LINK to SIP SERVER (10.140.131.208). The incoming calls occur in the reverse path.

ASA 5510 config:
ASA Version 7.0(8)
name 172.17.3.4 PABX
dns-guard
!
!
interface Ethernet0/1
[Code]...

View 1 Replies View Related

Cisco Firewall :: Voip ASA 5515 Version 9.1.1

Jan 8, 2012

Im changing the firewall 5510 to 5515, with ASA5510 the incoming and outgoing calls work perfectly, but when i active the 5515 the outgoing calls doesnt work, only the incoming calls work.

As you see on the topology,the flow of calls happens this way: In the outgoing calls the phone forward the call to the PABX(172.17.3.4), and the PABX forward the call through the ISP LINK to SIP SERVER (10.140.131.208). The incoming calls occur in the reverse path.
 
ASA 5510 config:
 
ASA Version 7.0(8)
name 172.17.3.4 PABX
dns-guard
!
!
interface Ethernet0/1
description ***ISP SIP Network***
[Code]....

View 1 Replies View Related

Cisco Firewall :: Starting ASA 5515-x Configuration

Apr 14, 2013

I'm starting my configuration and i created a test environment side by side with my production.  i just run startup config and connected my ad-test.com AD host to it. i can ping ad-test.com from console, ok.  but it can't get internet from inside environment
 
here's the config..............................
 
: Saved
: Written by enable_15 at 07:56:40.638 UTC Mon Apr 15 2013
!
ASA Version 8.6(1)2

[Code].....

View 8 Replies View Related

Cisco Firewall :: ASA 5515 - CLI Commands Just Scroll

Dec 19, 2012

Why do my cli commands just scroll all the content rather than having to press space to show more?  It is hard to type sh run and the entire config flays past rather than being to inspect it page by page.

View 3 Replies View Related

Cisco Firewall :: ASA 5515-X / How To Block The Multiplayer Games

Feb 27, 2013

I just would like to know if possible to block the multiplayer games?? I'm using ASA 5515-X.

View 2 Replies View Related

Cisco Firewall :: Does ASA 5515-X Include Rails And Brackets

Mar 24, 2013

The datasheet contains the following regarding rails and brackets:
 
Cisco ASA 5512-X, 5515-X, 5525-X, 5545-X, 5555-X spare rail kit - ASA-RAILS=
Cisco ASA 5512-X, 5515-X, 5525-X brackets for rack mounting - ASA-BRACKETS=
 
The word spare seems to imply that it comes with a set of rails.  Does the ASA-5515-X come with rails and brackets, or must both of these be ordered?
 
[URL]

View 4 Replies View Related

Cisco Firewall :: 5515 Web VPN Using Active Directory To Authenticate

Apr 15, 2013

I have a 5515 ASA that has the webVPN configured on it and it is using active directory to authenticate. The client would like to set up groups in active directory and restrict access to those groups when they are connected to the webVPN. For example, they have a group in active directory that they only want to access their "web" interface. What is the best way to configure this on the asa?

View 2 Replies View Related

Cisco Firewall :: ASA 5515 Failover Does Not Work Anymore

Aug 12, 2012

I have two ASA 5515 configured as active / standby. I configured the failover and I checked for proper operation. But when I configured access rules and NAT, I realized that the failover does not work anymore: two interfaces, inside and outside, are "Unknow (Waiting)". The other LAN interface and management are "Normal (Monitored)." [code] It is possible that some access rule deny the communication between the two asa?

View 9 Replies View Related

Cisco VPN :: ASA 5515 / VPN Users Cannot Communicate With The Internal Network

Aug 12, 2012

I have two ASA 5515 configured in failover (active / standby).I used the ASDM wizard to create connections through ipsec cisco client.Currently users are able to connect but can not do a ping to anywhere inside the network.
 
The ping request is received from the internal client but the internal client can not communicate with the remote user.The ping fail also directly from the ASA.
 
When the remote client is connected an entry is added to the routing table:

S 192.168.10.130 255 255 255 255 [1/0] via <ip of the ISP>, "WAN"

as if that IP was reachable directly from the Internet.I tried changing the settings of the NAT but in no way I can make them communicate.The ultimate goal would be to create different users with different access permissions to the LAN and the other subnets in the company.

View 2 Replies View Related

Cisco Firewall :: Configure ASA 5515 Switch Ports

Nov 25, 2012

I am moving from ASA 5505 to ASA 5515 because we are maxing out the number of connections that the 5505 can handle. The 5515 runs version ASA 8.6(1)2 and ASDM 6.6(1) and the 5505 version is ASA 8.2(5) ASDM 6.4(5). On the 5505 I used e0/0, 0/2, 0/4 and 0/5 as outside port with teh switch ports feature but there is no switch port feature on the 5515. I have tried to set the ports individually to numerous public IP addresses that I have but I get an error that they subnet is already associated with another interface. How do I replicate the same setup on the 5515?

View 3 Replies View Related

Cisco Firewall :: Detailed Documentation On ASA 5512-x And 5515-x?

Aug 7, 2012

where I can find detailed documentation on these two products. Particularly, I am looking for high availability capabilities and any license requirements. 

View 1 Replies View Related

Cisco Firewall :: 5515 - Way To Rate-limit By IP Address?

Jun 3, 2013

Worried about denial-of-service attacks. They have 11 vm's that share a connection and want to set it up so that there is a maximum amount of traffic allowed to hit each vm, so if there is a DDoS attack it will only affect that one VM instead of all the VM's on the same connection.

What is the best way to go about this from the ASA? This is behind a 5515 with asa code version 8.6. Is there a way to rate-limit by ip address?

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved