Cisco AAA/Identity/Nac :: 5505 - ACS 5.2 With ASA Firewalls

Dec 16, 2010

I am trying to setup a Cisco ACS 5.2 for both login and enable authentication to asa 5505s, 5510s, and catalyst switches. I am testing with an ASA 5505. The initial authentication to the firewall works, but when I try to enter privileged exec mode using the enable command, it doesn't work. I have the user setup on the ACS with a password and an enable password and privilege level 15, I have the device setup on the ACS, I have the tacacs+ server setup on the firewall and pointed to the correct server address, and the AAA commands for telnet, ssh, and enable.

View 9 Replies


ADVERTISEMENT

Cisco Firewall :: ASA 5505 Voice Platform - Firewalls

Apr 23, 2012

I  am currently working on our Cisco voice platform at work.
 
Our Cisco  firewall engineer has left and I have been given the task of looking  after the firewalls as our Chief Exec seems to think that Cisco Voice is  similar to Cisco ASA firewalls,
 
Are there any books/videos out that you can recommend to learn the about firewalls quickly.

View 1 Replies View Related

Cisco Firewall :: 5510 / Adding AIP Firewalls To Existing CSC Firewalls Setup?

Mar 3, 2011

I have a customer with active/standby on a pair of 5510's with the CSC modules. They were inquiring about the AIP/ASA, and since this would NOT work in their current setup, would getting a pair of 5510/AIP configured for transparent failover work placed in front fo the existing units? Would I need to have a switch placed between the AIP and CSC ASA's?  Or would I setup the ASA's for context based Active/Active failover to interconnect the ASA's to the existing units, but I still see a need for a switch.

View 1 Replies View Related

Cisco VPN :: 5505 - Two Site To Site To Same ASA Firewalls

Nov 6, 2012

I have a scenario whereby I need to add a second VPN tunnel to a Cisco ASA, however its peer address will be on the outside2 interface on the remote firewall. 
 
we have ASA1-HQ 5505
 
Inside address - 172.16.20.0
 
Outside1 - 1.1.1.1
Outside 2 - 2.2.2.1
 
ASA2-DC 5510
 
Inside Address- 172.16.30.0
Outside1 - 3.3.3.1
Outside2 - 4.4.4.1
 
There is currently a VPN tunnel between 1.1.1.1 and 3.3.3.1. I need to add a 2nd VPN tunnel utilising outside2 addresses 2.2.2.1 & 4.4.4.1 respectively.
 
I have labbed this out, however i cannot get traffic going down to the 2nd VPN tunnel. I have created the following routes on each firewall
 
ASA1-HQ
 
Outside1 0.0.0.0 0.0.0.0 1.1.1.2 (metric 1) (Next hop for outside1 interface)
 
Outside2 4.4.4.1 255.255.255.255 2.2.2.2 (metric 1) Peer address of 2nd vpn tunnel)
 
ASA2-DC
 
Outside1 0.0.0.0 0.0.0.0 3.3.3.2 (metric 1) (Next hop for outside1 interface)
 
Outside2 2.2.2.1 255.255.255.255 4.4.4.2 (metric 1) Peer address of 2nd vpn tunnel)
  
I have tried adjusting the Crypto map Priority values however this has made no difference. One theory I have is the local addresses potentially would need to be on a separate network in order for traffic to traverse the 2nd VPN tunnel.
 
the crypto maps i have created are:
 
ASA1-HQ
 
Outside1 (Priority10)  S 172.16.20.0 /24 D 172.16.30.0/24 Protect ESP-3DES-SHA Peer 3.3.3.1 (Nat T Enabled)
Outside2 (Priority 1)  S 172.16.20.50 /32 D 172.16.30.50/32 Protect ESP-3DES-SHA Peer 4.4.4.1 (Nat T Enabled)
 
ASA2-DC
 
Outside1 (Priority10) S 172.16.30.0 /24 D 172.16.20.0/24 Protect ESP-3DES-SHA Peer 1.1.1.1 (Nat T Enabled)
Outside2 (Priority1)  S 172.16.30.50 /32 D 172.16.20.50/32 Protect ESP-3DES-SHA Peer 2.2.2.1 (Nat T Enabled)
 
Is what I am attempting feasible?

View 6 Replies View Related

Cisco AAA/Identity/Nac :: PIX / ACS AAA Authorization On 5505

Jul 24, 2012

i have create a one profile on PIX/ASA Command Authorization Sets & MAP with Group & Ldap with My AD. but authentication is not done as per the set parameter on command authorization in ACS.i am using Cisco ASA 5505 & ACS 4.2.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ASA 5505 Cut Through Proxy And Redirection After Login

Jun 17, 2012

I have successfully set up a 5505 as a cut-through proxy so that wireless users are required to log in when they open a browser to access the Internet.   Is there a way to take them to the original page they requested after the login is complete, rather than having it sit at the screen where it is says they are logged in?                  

View 1 Replies View Related

AAA/Identity/Nac :: Possible To Send VSA From Radius Server To ASA-5505

Oct 26, 2009

Wondering if it's possible to send a VSA from my radius server to my ASA-5505 that will instruct the ASA to use one of several split tunnel lists I have created, based on the user name supplied in the Radius request.For example, I can send a VSA of "ip:inacl#1=permit ..." and the ASA will dynamically create an access-list for that user.Is there a similar VSA for split tunnel?

View 8 Replies View Related

Cisco AAA/Identity/Nac :: To Configure ASA 5505 Running 8.3 To Allow A Priv15 Local User

Apr 28, 2011

I am trying to configure an ASA 5505 running 8.3 to allow a priv 15 local user to be able to ssh into the device and be placed into priv 15 mode without having to execute the enable command and type the enable password.Right now when you log in as a priv 15 user you still have to execute the enable command and type the enable password to get to priv 15.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ASA 5505 Does Some LDAP Attribute Mapping To Get Group Membership For DAP

Dec 21, 2012

I have a working ASA 5505 that is used for remote access.  It authenticates users via RADIUS (Microsoft AD using two IAS servers), it also authorises users via LDAP and it does some LDAP attribute mapping to get group membership for DAP.  This is all working fine however recently I enabled IPv6 to do some testing.  I have a /126 subnet on the Inside interface (maps to its equivalent /30 IPv4 subnet) and OSPFv3 running so the ASA has visibility of the internal IPv6 networks.  DNS client is enabled in the ASA and all the authentication servers are entered as hostnames.  The two RADIUS servers only have A records and the two LDAP servers (Windows DC's) have both A and AAAA records.  My plan was to begin test IPv6 on the AnyConnect VPN clients (once I was happy the ASA was working fine with IPv6).

When I initially enabled IPv6 everything continued to work as before, however I had to reboot the ASA today and after it all came back up authorisation stopped working.  I did a bit of troubleshooting and the ASA is complaining of not being able to resolve the addresses of the two LDAP servers.  From the CLI I can ping the hostnames and the LDAP servers resolve to IPv6 addresses and the RADIUS servers resolve to IPv4 addresses.  When I issue the command 'show aaa-server LDAP' (LDAP is the name of the group) I see the servers listed but the address displays 0.0.0.0:
 
Prior to the reboot both the LDAP servers were showing thier addresses (IPv4) correctly.  I can workaround it by disabling IPv6 on the ASA, letting it lookup the (IPv4) addresses of the LDAP servers (so they appear in the 'Server Address:' field above) and then re-enabling IPv6.  Strangely deleting and re-adding the servers just with their IPv4 addresses also fails but I haven't fully tested this.  I don't know but I think I would have the same behaviour if the RADIUS servers also had AAAA records.
 
I assume when IPv6 is enabled on the ASA it will perform AAAA lookups as well as A lookups but the LDAP client cannot use IPv6?  Just guessing at the moment as I haven't managed to get a LAN capture. [code]

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Use Radius On ASA 5505 To Block Outgoing User Access By Username In Group

Jan 15, 2012

Can I use AAA Radius on a ASA 5505 to block outgoing user access by user name in a group?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ASA 5505 - Procedure For Monitoring Site-to-site VPN Tunnel?

Apr 30, 2012

Need to know the step by step procedure for monitoring site-to-site VPN tunnel (up/down) using SNMP on Cisco ASA 5505. 

View 1 Replies View Related

Cisco :: Discovery ASA Firewalls In LMS 4.0

Feb 16, 2012

I have a problem discovering some ASA firewalls on a network. I have several ASA firewalls on this /24 network, but some of them I can't discover e.g 149.x.x.107 is discovered ok, but 149.x.x.20 I can't discover. It seems that it's not even trying to discover the devices I have problems with. Nothing is shown in the discovery log.

View 11 Replies View Related

Firewalls Over TCP / IP Stack

Jun 25, 2011

For protection of any network architecture,use of firewalls (either hardware or software) only at Network ,Transport and Application Layers of TCP/IP stack. Why not at remaining layers?

View 1 Replies View Related

Cisco :: Upgrading Software On ASA Firewalls?

Feb 13, 2012

Am I able to legally download and upgrade software versions still on ASA firewalls?I have not had an issue in the past as this has not effected the license.I cant find anything online saying that you cant due to Cisco's new Software license policy changes.

View 1 Replies View Related

Cisco VPN :: Setting Up VPN Through 2 ASA 5510 Firewalls

Jan 10, 2012

'm trying to set up a vpn connection through two ASA 5510 firewalls.My network is as follows:
 
PC | FW A | Internet |FW B| - lan |
 
I am trying to achieve the following:
 
PC | FW A | Internet |FW B| - | DMZ | - | FW C| - | lan |
 
However, I am not sure where the VPNs will need to terminate and how I will achieve this taking into account the WAN IPs.

View 1 Replies View Related

Security / Firewalls :: What Can The Other Computers See

Feb 13, 2012

I opened my iTunes program today and noticed a roommate's MP3 files were picked up on my network. I think the name of the program is Rocket Tube MP3. Anyway, I came on here because our computers use a Wi-Fi internet connection and I was wondering how much of my web activity (history, cookies, temporary files, etc) he could see from my laptop if his computer was a desktop downstairs. He's very tech-savvy (a former IT guy) and I don't want him snooping through my personal records.

View 2 Replies View Related

Security / Firewalls :: Using NAT With Cisco ASA 5510 Firewall?

Mar 25, 2011

I was under the impression that those global addresses that we used with NAT were from the outside IP addresses range?Lets say my outside IP address is idk 192.112.40.11 /30 and I only had two usable IPs (since you can't use network and broadcast IPs) so how would I set up NAT for a couple of Inside addresses with a shorting of addresses like this? Idk if that makes sense what I'm trying to say

View 3 Replies View Related

Cisco :: 2 WLC 2504 With Two Firewalls - Backup Port

Apr 24, 2012

I have a question about 2504 deployment.Two WLC's , one will be acting as primary controller, second as secondary controller.
 
There will be two firewalls with High Availability between them. Ok, if primary controller will go down, we would need to wait about 2minutes, and AP's would join secondary controller.
 
But  if there is a problem with firewall? Etc. FW 1 goes down. Is it  possible with WLC 2504 to use it's second port as backup port ? And use  the same IP address between them?
 
Because if we configure the second port with different IP address, we would need to wait  about 2minutes, because AP's is in "rejoining" mode )(To  use second port as backup, but have the same IP address on it ( like  put these two interfaces into the same "vlan") , because this would be  really great, if one Firewall goes down, we would still will be using  the same wireless controller.)

View 3 Replies View Related

Cisco :: ASA 5510 / Upgrade All Firewalls To Security Plus?

Sep 21, 2011

I am trying to upgrade all my firewalls to Security Plus but I am not sure what firewalls are needing the upgrade.  Is there a SNMP pull I can do to see what license is on my firewall?  example: "This platform has an ASA 5510 Security Plus license." via SNMP

View 1 Replies View Related

Cisco Firewall :: ASA 5510 - Speed Through 2 Firewalls

Jun 5, 2012

We have a configuration where we go through a firewall (ASA 5510) to a router, which decides if it is internet traffic or another network used for colleges etc in Canada called SR Net. If it is internet traffic it then goes through another ASA 5510 to the internet.
 
When we tested we were not seeing the speed of our internet (about 1/10th). We tested by putting the laptop before the internet firewall and we get the throughput. We also threw the test laptop before the router and we got the throughput expected. But when the test laptop is before the internal (first) firewall we get about 1/10th the speed. We are Nating on both firewalls, so from the inside we are going from a private IP to a Public IP (so it can go to SR Net is need be), then Nating again to the internet IP on the second firewall.

View 2 Replies View Related

Security / Firewalls :: How To Protect Network

Nov 29, 2011

We are a non-profit organization that is heavily reliant on interns that use their own laptops a lot here. My concern is they come in and connect to our wireless network with no supervision or anything else. I am worried they will introduce a virus, trojan, or something to our network. What the best way to keep them from introducing unwanted malware from a thumb drive, virus in email, or something to that effect shy of standing over them while they install and run an antivirus software?

View 7 Replies View Related

Security / Firewalls :: Lan To Lan Vpn Tunnel Is Not Working

Feb 12, 2012

I have problem with the Lan-to-Lan VPN tunnel.the VPN working fines since 9 months ago without any problems.Suddenly got the problem!,In last two days we faced problem the VPN down.in first time the problem in phase-2.. but after that in phase-1... in latest no data packet received to their side.

View 1 Replies View Related

Security / Firewalls :: Static IP Will Be Changing With The New ISP?

Apr 27, 2011

I am looking for some resources on what steps would be involved in configuring a Cisco ASA 5500 when obtaining a new ISP. Since our static IP will be changing with the new ISP, just need to know what configurations changes will need to take place. We currently have a working config with DSL, but are switching to cable. We are using a DMZ configuration, and are going to try using ASDM first since that should be easier

View 3 Replies View Related

Security / Firewalls :: Port Scanning On LAN

Jul 24, 2012

There are three Win 7 laptops on the LAN trying to connect to the ASA5500 Firewall. They generate a Severity Level 3 alert and try the same port three times then move to the next numerical port and try that three times. Is this a malicious Hack.

View 5 Replies View Related

Security / Firewalls :: Possible To Change Nat Type

May 22, 2012

can i change my nat type from type 3 to type 1

View 19 Replies View Related

Security / Firewalls :: Why Can't Get Into Specific Website

Dec 6, 2011

I have been trying to get into one website (url)The world's best online marketplace, List free Classifieds,buy and sell - auction,post a job and get hire from over 1 million top professionals. | Wanaifieds.com and I can't get into the site from my home I can get into the site everywhere else but here I called the service provider and their telling me it's not them they don't block website and the IP is not stationary so their nothing wrong with their end I called the hosting company of the website and they told me they don't block any IP's I don't know what to do I do remember when it was working about 4 days ago I tried something o the site and I messed up and I clicked back instead of putting my password a little box poped up and said something about a certificate or something but I just clicked off and when I tried to get back on the site.

View 6 Replies View Related

Security / Firewalls :: Some Of IP Address Is Shunned?

Aug 26, 2012

I'm working with Cisco ASDM 6.1 for pix. I want some of ip addresses are not shunned thus provide a list of addresses which should not be shunned in threat detection, but some of ip addresses are shunned yet.

View 1 Replies View Related

Security / Firewalls :: How To Block Website

May 20, 2012

I want to block 10.0.0.1 and 192.168.1.1 but my router says invalid domain so if will the guess network be able to go to page 10.0.0.1 and 192.168.1.1 even though I don't block it? I have a bypass account but don't want anyone else to access 10.0.0.1 and 192.168.1.1. Also can you tell me some proxy sites I can block?

View 11 Replies View Related

Security / Firewalls :: Associated Service Not Running

Nov 30, 2011

Windows firewall settings cannot be displayed because the associated service is not running

View 4 Replies View Related

Security / Firewalls :: How To Turn Off Firewall

Apr 20, 2012

I'm not sure how I turn off my firewall

View 4 Replies View Related

Security / Firewalls :: Difference Between NMS And SIEM?

Dec 8, 2011

Finding the difference nms and SIEM. But I couldn't find until now.

View 3 Replies View Related

Security / Firewalls :: How To Block Traffic From A Lan Ip

Jan 16, 2013

when I run nestat -b command. I always see a lan ip sending TCP traffic to my computer with state syn_receivedProto >> Lan Address >> Foreign Address >> state >> Process idTCP >> (my ip) >> 192.168.2.222(lan ip) >> syn_received >> 4

View 6 Replies View Related

Use GNS3 For ASA 5500 Firewalls Along With ASDM?

Jan 3, 2012

How many of you use GNS3 for ASA 5500 Firewalls along with ASDM? While I am on the subject of GNS3 I had a questions about the new version and the capture feature. I installed the latest version last night with the new live capture features but it seems to be only one way capture. T Is there a way to fix this?

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved