Cisco :: Cannot Get Into ASA 5520

Jan 31, 2011

After having a hard time getting the VPN back to default, I logged into the ASDM and reset to factory defaults. After it reset, I logged in via the management port and configured everything to work. When I clicked on "apply", it gave an error saying that the inside interfaces, g0/1, IP address is on the same network as the management interface. When the ASA restarted, I am now unable to get into the unit via the management port or the inside interface.

I had set the management port to 10.0.1.254. WHen I connect an ethernet cable to it and place my mac on the the same network, I can ping the management interface, however I cannot SSH, Telnet or ASDM into it.

Here is the big problem, I don't have a console/rollover cable to connect to the console interface. Is there another way I can default the box? Maybe via the reset button on the back somehow? Or, is there a way to figure out the ip address of the inside interface? I'm assuming, since it did not take the IP I set, that it defaults to something right?

View 17 Replies


ADVERTISEMENT

Cisco Firewall :: Different Between ASA-5520-K9 And ASA-5520-K8

Nov 2, 2012

We were using ASA-5520-K9 with  ASA-SSM-AIP-20-K9 but recently found some hardware problem in our running ASA. Now cisco want to replace with ASA-5520-K8.

View 1 Replies View Related

Cisco :: ICMP Through ASA 5520?

Jan 26, 2012

I cannot seem to ping between devices on two networks hanging off a 5520 unless I use the same-security interface command. I have the relevant ACL's set up between the interfaces, but it just doesnt work unless I have that command in - if I use that command, it bypasses the ACL.

Config

interface GigabitEthernet0/0.224
description NMS
vlan 224
nameif NMS
security-level 100
ip address 10.11.120.225 255.255.255.240[code].....

View 8 Replies View Related

Cisco WAN :: ASA 5520 - Implement With A New ISP

Jul 31, 2011

We are attempting to implement an ASA 5520 with a new ISP.  Based on the limited routing needs, I believe we can use it as the router as well. I am familiar enough with routers, but the ASA is obviously a different thing.
 
The setup looks like:
 
ASA Version 8.2(1) !
host name Cisco
 interface GigabitEthernet0/0description Internet name if Outsidesecurity-level 0ip address 69.XX.46.1 255.255.255.252 !interface GigabitEthernet0/1
description DMZnameif DMZsecurity-level 0ip address 69.XX.56.1 255.255.255.240
!interface GigabitEthernet0/2description Localnameif Insidesecurity-level 15ip address 10.0.XX.XXX 255.255.252.0
[Code] .....

1) Outside 0/0 connects to MRV from service provider (Public)
2) DMZ 0/1  connects to outside switch with servers (Public)
3) Inside 0/2 is LAN (Private)
 
A) Based on a completely default config and aside from setting the routes to send traffic from inside to outside, and outside to DMZ, what is the next step?
 
B) What should the interface security levels be, I am unsure what they should be or why...?
 
Based on the initial config with interfaces set as above, I cannot move traffic through.

View 5 Replies View Related

Cisco VPN :: ASA 5520 - VPN With Two Devices

Jun 25, 2012

I got a VPN request form from one of our partners. On my side I have one ASA 5520 running 8.0(3) On their form, It says that their endpoints are two boxes, sitting on different cities, It also says that there is only one encryption domain, (actually just one IP) that I need to speficy on the VPN setting. It looks like they mean that you could access the same encryption domain from any of the two Boxes in different cities. This is strange to me, since every time I have set up VPN before, each endpoint has their own encryption domains.I never seen two enpoints with the same encryption domain behind, so Im confused wether it might be a mistake on their part, or this is expected.

View 1 Replies View Related

Cisco VPN :: Using RSA With Local AAA On Asa 5520?

Aug 23, 2012

Is it possable to use rsa token on the ASA without setting up any other server just using the ASA, out clients use the cisco vpn client version 5.0.07.0290 and IOS 8.3(1), How would this be done?

View 3 Replies View Related

Cisco VPN :: ASA 5520 SSL Using Different IP Than Public

Nov 6, 2012

I am trying to configure a SSL VPN on a Cisco ASA5520. Unfortunately the port 443 of the OUTSIDE interface of ASA is already in use by Microsoft Outlook Web Access and I cannot change the configuration of Outlook. This configuration already in place prevents me to use the public IP of the ASA as Cisco VPN ip address for the webpage. I don't either want to use a different port so to keep life easy for the users.I have some public IPs available that I can use so I wanted to use one of them instead of the ASA's OUTSIDE interface.

View 7 Replies View Related

Cisco WAN :: Asa 5520 The Vlan Going Up And Down

Dec 8, 2011

I have connected an ASA 5520 firewall DMZ to SERVER (17) vlan in core  switch and INSIDE is connected as trunk to the core switch (including  vlan 15,18). now the management ip of the switch is 10.xx.xx.126/25. and  the other vlans are showing "administratively down"..but if I enter to  any of the other vlans and do a "no shut", that particular vlan wil go  UP but the other 2 will go down..means only one vlan become up at a  time.

View 4 Replies View Related

Cisco VPN :: VTI Tunnel Using ASA 5520

Mar 4, 2013

Can i use at one site  ASA 5520 and another site Router to configure VTI tunnel with OSPF routing?

View 1 Replies View Related

Cisco VPN :: Get IP Address From ASA 5520

Apr 24, 2011

I have an iPAD.  It connects to my ASA5520 via IPSEC.  When it connects it gets an IP address from the ASA but it does not get any of the other stuff.  Specifically the DNS suffix.  How to correct it?

View 3 Replies View Related

Cisco VPN :: 5520 Get RRI To Work On

Jun 25, 2012

I have a L2L VPN tunnel on a Cisco ASA 5520 that I'm trying to get RRI to work on. On my cryptomap ACL I have defined a local object-group and a remote object-group, and I'm performing one-to-one NAT on the local group. I also have a route map configured that will take the static routes and redistribute them into my EIGRP AS. Two things I've noticed -1, I'm not seeing any static routes on my ASA that point to the remote subnets, and 2, the ACL that I've used in my route map definition is not getting any hits on it.

View 2 Replies View Related

Cisco VPN :: 5520 / 5550 - VPN Using Outside Ip With NAT?

Aug 13, 2012

I'm trying to setup a tunnel from our Cisco 5520 to a 5550 using one of our external ips natted through this tunnel. For some reason traffic that should hit this tunnel goes through global nat. Here is the configs I have for this tunnel:
 
access-list policy-nat extended permit ip host 66.77.88.170 host 1.2.3.4
access-list Outside_cryptomap_60 extended permit ip inside-network 255.255.254.0 host 1.2.3.4
access-list Outside_cryptomap_60 extended permit ip host 66.85.99.170 host 1.2.3.4

[code]...
 
If I ping 1.2.3.4 from a inside ip host I see in the logs that it uses 66.77.88.136 as the NAT and not 66.77.88.170. Do you see something wrong with this configuration?

View 10 Replies View Related

Cisco VPN :: 5520 Are There Any CPU Limitations In Going To 8.4

Nov 30, 2011

I'm currently running 8.3(2) on my 5520s in an active/standby config.  The 5520s have the 2GB RAM upgrade and 256MB flash card.  Are there any CPU limitations in going to 8.4?  I read the release notes but didn't seen anything about CPU.  I heard through the grapevine that a 64-bit processor may be needed. We currently have the Pentium 4 Celeron 2000 MHz CPU. 

View 1 Replies View Related

Cisco WAN :: 5520 Vlan Going Up And Down

Dec 8, 2011

I have connected an ASA 5520 firewall DMZ to SERVER (55) vlan in core switch and INSIDE is connected as trunk to the core switch (including vlan 66,77). now the management ip of the switch is 10.xx.xx.126/25. and the other vlans are showing "administratively down"..but if I enter to any of the other vlans and do a "no shut", that particular vlan wil go UP but the other 2 will go down..means only one vlan become up at a time.

View 1 Replies View Related

Cisco VPN :: ASA 5520 VPN To Outside Interface?

Mar 20, 2011

I have a 5520 VPN that is otherwise correctly configured for access (so I would say).  It is in test (external IP x.x.x.10/22) running parallel on an external switch to a Check Point (x.x.x.4/22) that is the live setup.
 
I can tunnel consistently to the outside interface on its external IP from inside the network, which is probably natural since I'm inside the network making the attempt; however...
 
When attempting connection from somewhere outside the network, I generally do not get response from the device.  If I connect/disconnect from the Check Point VPN first, then I can subsequently get a connection to the ASA.  I did actually have one instance of non-massaged connectivity to the ASA, but there was nothing that I did in the configs that would allow me to claim credit for that instance.
 
So here's the question:  Is there a timeout setting that makes the outside interface go to sleep or something?  I'm still at the developmental stage where settings that would be obvious trip me up for hours.  I verified the routes.  the timeout configs are below; I believe they are all default..

arp timeout 14400
!
timeout xlate 3:00:00timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolutetimeout tcp-proxy-reassembly 0:01:00

View 3 Replies View Related

Cisco VPN :: Routing With ASA 5520?

Apr 7, 2013

I have setup IPsec remote vpn users into the Cisco ASA 5520 using Radius into my main network. Works just fine. I have site to site tunnels from my Cisco ASA5520 going to other sites, some of the tunnels have Cisco ASA and some have SonicWalls. I would like my IPSec remote VPN users to be able to traverse into those site to site tunnels to access the remote subnets attached to those tunnels. Do I need to use a combination of routing and ACL's? Or do I just use ACL's only? Or do I just use routing only?

View 2 Replies View Related

Cisco WAN :: ASA 5520 Failover

May 7, 2013

When I try to put my ASAs in active/standby config here is the error I get.Warning: Failover message decryption failure. Pleas make sure both units have the same failover shared key and crypto license or the system is out of memory.

View 1 Replies View Related

Cisco VPN :: Dual ISP And SSL VPN On ASA 5520?

Dec 30, 2012

I configured dual ISP on ASA 5520 following cisco doc below. Now I would like to configure SSL VPN to work with this for failover? I tried to find an article regarding this but I could not. [URL]

View 3 Replies View Related

Cisco VPN :: 2 Licenses On ASA 5520?

Aug 19, 2012

Ive got a customer asking for 2 products to be installed on an ASA 5520?
 
ASA 5500 SSL VPN 10 Premium User License and AnyConnect Essentials VPN License - ASA 5520 (750 Users)?
 
Am i correct in saying only one of those licences will actually be active at any time?

View 3 Replies View Related

Cisco VPN :: ASA 5520 - AnyConnect 3 With ASA 8.4?

Jul 5, 2011

2 x ASA5520 with SSM20 . using AnyConnect 3 , users are not getting disconnected from ASA even after the vpn client is closed . Users would not be able to login from the same ip until the session is active. Manual clearing of the session enable the user to log back in .

View 1 Replies View Related

Cisco VPN :: ASA 5520 - Add 50 More Licenses?

Feb 4, 2013

We have a 5520 ASA with a 100 user ssl license. We need to increase this but 250 is overkill. Is there an option to just add 50 more licenses or do we have to go up to 250?

View 2 Replies View Related

Cisco VPN :: ASA-5520 / How To Implement DAP

Oct 21, 2011

Today we have a simple ASA-5520 SVC setup with just one connection profile and one group policy. Authentication (2 factor – AD + SMS) is performed by RADIUS. We would now like allow access to this VPN service only if you reside in a particular group in the MS AD. From what I understand this can be accomplished through DAP. Either by matching the LDAP attribute “memberOf” or RADIUS id 146. I’m I right? Can I still perform authentication using RADIUS and then DAP using LDAP or must I use DAP using RADIUS?

View 3 Replies View Related

Cisco VPN :: 5520 - SSL And PCI Compliance

Feb 1, 2012

I am installing a new 5520 with IPS for a client, and they were asking about the PCI compliance of the SSL(WebVPN) being self signed.  I am not sure what document to find this information from under the PCI DSS.  There was also mention about dual authentication being needed, but without seeing the actual requirements, I am just guessing at it.
 
What is required for making SSL PCI compliant.

View 5 Replies View Related

Cisco VPN :: To Generate CSR From ASA 5520 8.2(5)

Dec 11, 2012

We are already having a True business ID certificate from Geotrust for our SSL VPN on CISCO ASA 5510.this is working fine.
 
We are now changing our device from ASA 5510 to ASA5520 in failover setup. As we check with Geotrust they are asking us to create a new CSR with same parameters from new ASA5520 device and reissue the certificate from their site.In this context how to create a new CSR from ASA5520 8.2(5). create CSR from ASA 5520 8.2(5)

View 2 Replies View Related

Cisco :: Reset Old TCP Session On ASA 5520?

Jul 20, 2011

how to reset old TCP session on cisco ASA 5520?

View 2 Replies View Related

Cisco :: Setup A Juniper VPN Into ASA 5520

Jan 25, 2012

I have a ASA 5520 with a functional IPSEC VPN using the Cisco VPN client. This allows my remote users (Staff) using laptops to come in from anywhere on the Internet and tunnel in. Works great.Next, we need to stand up a VPN over a Juniper SSG5 so that when we have groups working outside of our network, they can tunnel back into our network. If they were going to be coming from a known, fixed IP, or even netblock, we'd probably use Route-based setup from a Juniper SSG5 into the ASA 5520. But they may very well be coming from any IP. I am thinking this leads us to Site-to-Site VPNs- it won't be Network Client access obviously, nor will it be Clientless (browser-based).

View 9 Replies View Related

Cisco :: Slow Connection With ASA 5520?

Oct 16, 2012

I have a really poor internet connection on ASA 5520 after creating a Redundant Interface with interfaces 2 and 3. As you can see, something is really weird:

Interface GigabitEthernet0/1 "", is up, line protocol is up
Hardware is i82546GB rev03, BW 1000 Mbps, DLY 10 usec
Auto-Duplex(Full-duplex), Auto-Speed(1000 Mbps)

[Code]....

View 9 Replies View Related

Cisco Firewall :: ASA 5520 CPU Utilization Is 100 %

Sep 27, 2011

We have configured 20 route in ASA 5520. The CPU usage goes to 100 % at the moment when we add a specific route.route inside 10.254.101.0 255. 255. 255.0 10.254.102.254 1.This is the same case when we add this route at the first cli or as the 10th cli or the 21 cli (errespective of the position of cli) There is an another route out of which 20 routes we have configured is route inside 10.254.103.0 255.255.255.0 10.254.102.254 1.The normal case if we dont add the problamatic route , then the CPU utilization is only 2 %.

View 1 Replies View Related

Cisco VPN :: 5510 / 5520 - 121 Ipec Vpn

Nov 1, 2012

I'm running into trouble with one of my l2l ipec vpn between a cisco 5510 and 5520 asa running version 8.2.2.
 
Our existing l2l vpns are connected fine and working fine. Currently SITE A (10.10.0.0/16) connects to SITE B (10.20.0.0/16). SITE A also connects to SITE C (10.100.8.0/21). These are OK.
 
What's failing is when I try to connect SITE B to SITE C. The tunnel does come up and phase 1 and 2 complete successfully. However while running: 'packet-tracer input inside icmp 10.20.8.2 8 0 10.100.8.1 detailed' i get the following:
 
Phase: 10
Type: VPN
Subtype: encrypt
Result: DROP
Config:

Additional Information:
Forward Flow based lookup yields rule:
out id=0xad1c4500, priority=70, domain=encrypt, deny=false
hits=609, user_data=0x0, cs_id=0xad1c2e10, reverse, flags=0x0, protocol=0
src ip=10.20.0.0, mask=255.255.0.0, port=0
dst ip=10.100.8.0, mask=255.255.248.0, port=0, dscp=0x0

I noticed when the tunnel came up, the 10.100.8.0/21 route was not added in the routing table and the cyrpto ACL was not applied on the remote ASA. I added the route manually but cant get the cryto ACL to apply.
 
More usefull info:
 
SITE C
object-group network NoNatDMZ-objgrp
network-object 10.10.0.0 255.255.0.0
network-object 10.10.12.0 255.255.255.0
network-object 10.20.0.0 255.255.0.0

[Code] ......

View 7 Replies View Related

Cisco Firewall :: ASA 5520 With Failover NAT With Two ISP?

Jun 20, 2011

Currently we have one ISP1 and all traffic goes to this way. Suppose our isp1 goes down, our outside user cant get the server. All servers are nated to this ISP1.We planned to purchase a another ISP2. Shall we Configure same inside server to map this ISP2? so that one primary ISP1 goes down it will take place the outside trafficISP2.

View 1 Replies View Related

Cisco Firewall :: ASA 5520 Nat Translation Max?

Aug 24, 2012

I am going with ASA 5520, know how many NAT translation is possible.

View 2 Replies View Related

Cisco VPN :: ASA 5520 - Number Of Licenses That Are Available?

Mar 6, 2011

Need to know the number of VPN licenses that is available,

1)  I have site to site vpn connections.
2) SSL VPn (browser)
3) IPsec  client vpn.

How many vpn connections are allowed? can multiple connections be made using the same username for IPsec VPn clients.?

View 2 Replies View Related

Cisco VPN :: Log Off Idle Users / ASA 5520

May 6, 2010

I'm using a Cisco ASA 5520 with IOS 8.2.2.  We have many remote users using the Cisco VPN client, but I have been asked can we logout idle users as we do hit our license limit and some users stay conenct for days.

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved