Cisco Firewall :: 5505 Copy Ftp Fails?

Mar 28, 2011

The FTP server log shows no hits, from 192.168.1.4 I can telnet to 5505 no problem.
 
Doing everything on inside interface eth0/1, ftp server  shows up and arp table of 5505 has correct mac for 192.168.1.4
 
ciscoasa# copy ftp://bob@192.168.1.4/asa841-k8.bin disk0:
Address or name of remote host [192.168.1.4]?
Source username [bob]?

[Code]...

View 2 Replies


ADVERTISEMENT

Cisco Firewall :: 5505 ASDM 7.1 Fails To Start On MacOS

Feb 6, 2013

I have an ASA-5505 which I have been managing using ASDM from a PC and a Mac.I just happens that the Mac has not been used in a little while and when I tried to use ASDM on it, it fails.I've had a trawl through various posts and release notes (after updating various components in the process, incl Java with all the diabling/security updates of late) but am still having the problem and this is where I'm at:

- the ASA runs v8.4(2) and ASDM 7.1(1)52
- release notes state that ASDM 7.1 should work on Java 7 on Windows 7 and MacOS 10.7
- ASDM starts fine on my Windows 7 PC running Java 1.7.0_13
- I am also running Java 1.7.0_13 on MacOS 10.7.5
- on MacOS, ASDM starts, asks for credentials, download/refreshes the cached app... and then crashes with the following exception message:
 
The root cause of the issue seems to be that a Java class called apple.laf.AquaTableHeaderUI is not found..Now, I don't know much about Java, but that seems to be an Apple UI related class - I presume that it would be good to use this to give ASDM a more native look and feel, but why on earth is there no fallback? or am I missing something?

View 4 Replies View Related

Cisco VPN :: Copy And Paste Config To New ASA 5505?

May 26, 2013

I have a new ASA 5505  we have in production  the same model.
 
So I copy and paste the same config  bot ASA have the same IOS version 8.4(3)
 
But the VPN is not working. is because of this ? ikev1 pre-shared-key *****
 
When I copy paste the  config  the pass  is still like this ****.
 
How can I copy  my  config to the new device withouth introduce the pass again.

View 6 Replies View Related

Cisco VPN :: ASA 5505 - S2S VPN Tunnel Fails After Upgrade 8.3 To 8.4

Jun 6, 2012

I upgraded an ASA 5505 from 8.3(2) to 8.4(4) this evening.  The 5505 is a backup and used to perform testing prior to production changes. After the upgrade was complete, a VPN tunnel began to fail.  I did a limited search online to see if this was a known issue or something new.  I also reviewed the release notes but did not see anything that matched the issue I received.
 
My concern is that this tunnel configuration is scheduled to be deployed to the production firewalls next week after their upgrade.  But if it failed on the upgraded test unit, it may fail on the production units.
 
I downgraded the backup unit to 8.3(1) and verified that the tunnel indeed worked at that level.

View 2 Replies View Related

Cisco Firewall :: 5520 - Copy Configured ASA To New One?

Aug 7, 2011

I have seen similar questions but with not a lot of answers for the ASA platform. As the title states, What procedures can I use to copy a pre-existing configured CISCO ASA 5520 to a brand new CISCO ASA 5520. I have found a URL that seems to answer some questions but not all. [URL]
 
The URL talks more about the PIX's than the ASA
 
Is there any documentation or shorter procedures for product specific on the 5520?

View 1 Replies View Related

Cisco Firewall :: ASA 5550 - Cannot Copy IOS From Flash To PC

Jan 8, 2013

I just got a brand new ASA 5550, i configured the port g0/0  on asa with an ip address 192.168.10.1 then configure my computer with ip 192.168.10.2 and default gateway is 192.168.10.1. I'm able to ping the asa from my computer. I remote to ASA thru the console port  and try to copy iOS from flash to my pc but it doesn't work.
 
Cisco asa# copy flash tftp://192.168.10.2/asa804-k8.bin
Source file name []? asa804-k8.bin
Address or name of remote host [192.168.10.2]?
Destination file name [asa804-k8.bin]?
 Writing file tftp://192.168.10.2/asa804-k8.bin...
!%Error writing tftp://192.168.10.2/asa804-k8.bin (Timed out attempting to connect)
Cisco asa#

View 3 Replies View Related

Cisco Firewall :: Copy Files Between Failover ASA 5520?

Oct 29, 2012

I made an ASDM upgrade for one of my two CISCO ASA 5520. If I copy a file to the primary ASA's flash, is there any command I can  run on the primary ASA to copy a file to the secondary ASA?

View 1 Replies View Related

Cisco Firewall :: Use USB Ports On ASA 5510s To Copy Files Onto Flash?

Nov 9, 2011

Is it possible to use the USB ports on a ASA5510's to copy files onto the flash?
 
I have not been able to find any ionfo on this in the users guides ?

View 2 Replies View Related

Cisco Firewall :: 5520 - Upgrade From 8.3.1 To 8.3.2 / Unable To Copy Via TFTP

Aug 16, 2011

I was trying to upgrade from 8.3.1 to 8.3.2. but I am unable to copy via tftp to the ASA flash or disk0:
 
ASA5520# copy tftp: flash:
 Address or name of remote host []? 10.88.127.153
 Source filename []? asa831-k8.bin
 Destination filename [asa831-k8.bin]?

[code]....
 
Half way thru writing to the disk, it goes for a reboot. There is more than enought space on the disk0. I tried copying via a Compact Flash, but the ASA is not detecting the Compact Flash (which I thinks should be disk1). I tried copying a asdm file, even that also went for a reboot.I am stuck now, unable to upgrade

View 12 Replies View Related

Cisco Firewall :: File Transfer Using Secure Copy Server On ASA 5510?

Nov 13, 2008

I have SSH and SCP enabled on the ASA 5510.  I can SSH fine into the device. However, I cannot copy files to the device usng WinSCP.  Used all options but nothign seems to work.  I see the log authentication successful, but then WinSCP reports no response from ASA.

View 5 Replies View Related

Cisco Firewall :: ASA 55xx (8.0.3) Failover When IPS SSM Fails

Aug 27, 2008

Is there a way to trigger stateful (or stateless) failover on ASA 55xx (8.0.3) when there's a failure on the IPS unit?  I understand the fail open/fail close and its application on a single firewall, but the better solution for an IPS failure in a redundant pair would seem to be a stateful failover to the other ASA, and I don't see that as a documented feature.

View 8 Replies View Related

Cisco Firewall :: ASA 5510 Fails To Boot

Apr 10, 2013

I have a Cisco ASA 5510 with a strange issue. When I power it ON, the following is the status of the front panel LED:
 
Power is OFF
Status is Amber
Active is Amber
VPN is Green
Flash is OFF
 
Also nothing comes up on the console. I suspected a Power supply issue and replaced it, but still it doesn't seem to work.I cant open up a TAC as I do not have a Smart Net contract.

View 2 Replies View Related

Cisco Firewall :: ASA5505 SNMP Polling Fails?

May 31, 2012

I am having issues with monitoring our Cisco ASA5505 devices with "SolarWinds Orion NPM 10.2" through the use of SNMPv2. On some devices we see that SNMP polling stops and that the ASA's interfaces would show up as unknown - usually when the link to the device goes down/up or after a random ammount of time. At that point SNMP polling data is no longer updated and all we can rely on is ICMP for device status. I can resolve the issue by restarting the remote ASA OR restarting the SolarWinds server after which polling resumes. We are only seeing this behaviour with our remote ASA's.
 
Our setup is as follows:
Head End: Cisco ASA 5520 [ASA 8.3(2)]
Remote: Cisco ASA 5505 [ASA 8.3(2)] 
 
I have found a SolarWinds article listed below that possibly identifies the issue that we are having but am not sure where to start.
 
[URL]

View 8 Replies View Related

Cisco Firewall :: Fails To Download File Through ASA5540

Dec 12, 2011

We have ASA 5540 with 8.2 SW. We are trying to download a file (3 MB pdf)  from https session which fails if done behind the firewall. In case, the client bypasses firewall, the file gets downloaded as usuall. Interesting thing here to note is that when client is behind the firewall, its takes a long time to download the file and the file size always 312 Bytes, of course its a corrupt file.

View 3 Replies View Related

Cisco :: ASA5510 - Event Primary Firewall Fails

Jun 6, 2011

The client is only interested to have one-WAN(MPLS) and One internet circuit with Dual ASA5510 primary/failover configuration. In the event primary firewall fails, there is no direct WAN/internet connection to failover firewall. I beleived that  to mitigate the issue,  I needed to add a layer 3 switch , and have each circuit (MPLS/Internet) or (modems/routers) connect to a L3 switch. L3 switch will do the vlan based routing based on the state of firewall. ? am i correct?  The client want automatic failover to secondary firewall in the event the actual firewall failed without impacting the day to day business.

View 3 Replies View Related

Cisco Firewall :: Pix 525 - Config To NvRAM Fails / No Memory Available

Nov 6, 2012

I have CISCO pix, version 525, today while trying to save the config, I am getting below error

GPRS-PIX# wrBuilding configuration...no memory available

Error executing command

[FAILED]

Cisco PIX Security Appliance Software Version 8.0(4)Device Manager Version 6.1(5)51

Compiled on Thu 07-Aug-08 19:42 by buildersSystem image file is "flash:/pix804.bin"

[Code]....

View 4 Replies View Related

Cisco Firewall :: ASA5510 Any Way For Users To Not Get Disconnected / When One Device Fails

Jul 8, 2012

I want to set-up a HA for ASA5510. I wanted to design the network to achieve HA. I am attaching the present set-up of the network. At present, I have 2 ISPs connections terminating in ASA5510. The configuration is done for failover in ASA5510.I have another ASA5510 and want to use it for HA. I needed to know the design for the set-up. I want a stateless failover since the amount of traffic is less. I don't have any ISP routers in the present network. I suppose I need 2 routers for HA and couple of switches. One more question is that, as there are SSL VPN users, is there any way for the users to not get disconnected when one device fails.

View 5 Replies View Related

Cisco Firewall :: ASA 5520 - Verifying Flash Image Fails?

Nov 1, 2011

I have an ASA 5520, currently running version 7.25-k8. I'm preparing for an upgrade to version 7.25(4), so I transferred the software code (obtained via Cisco download) to the firewall vis SCP. I then issued the "verify flash:asa725-k8.bin" and it fails. It comes back with the error that the CRC did not verify, Data Integrity has been compromised". My first thought was the image did not copy correctly, so I deleted it and transferred it again. I got the same error. Then I decided to run a verify against the actual current code that was running on the firewall, and it came back with the same error. I don't understand what the problem is. I don't tend to think it's an SSH key related problem, as the method I use to access the firewall is via SSH and I have no problems. Worth noting,this firewall is part of an active/standby pair, and I observe the same behavior on the failover unit, it fails to verify.

View 3 Replies View Related

Cisco Firewall :: ASA 8.4 - Connection Fails When Host On Inside Tries To Connect To Server On Outside

Mar 9, 2011

We are using an ASA with 8.4 in transparent mode. Connection fails when a host on inside tries to connect to a server on outside. This server uses mac-address 0100.5E00.0000 to load balance but replies with real mac-address.Firewall logs "Deny TCP".ARP inspection is disabled.

View 2 Replies View Related

Cisco :: Copy Tftp Flash And Copy Flash Tftp Not Working?

Jul 19, 2011

I am using TFTPD32 to upgrade the IOS on a router. When I type in the commands copy tftp flash and enter all the necessary information, the router sits for a minute or so and then times out. There is no entry made in the log when it times out. copy flash tftp yields the same result. The fa 0/0 interface and the TFTP server are both on the same subnet and can successfully ping one anothe

View 16 Replies View Related

Cisco Firewall :: ASA 5510 - FTPS Explicit Client Fails At Init TLS Stage

Feb 11, 2013

I have a problem when trying to access from a workstation on the internal network to an external FTP server using Explicit FTPS. After the server requires the client TLS Authentication the client inits TLS but the connection is closed by timeout.
 
I have disabled the FTP inspection on the firewall and I have opened some high ports from the Internet to the test workstation (ACL and NAT rules), but without results.
 
If I try to connect from a workstation to the FTP server using a direct Internet connection I can access the FTP server without problems, so I think the problem is in the ASA.

View 6 Replies View Related

Linksys Wireless Router :: EA4500 FTP Server Remote Access Fails With Firewall

Sep 1, 2012

I tried to remotely access my disk connected to the USB port of the EA4500 and it failed until I disabled the IPv4/IPv6 SPI Firewall options. Surely, the firewall should not block the router's own FTP server!

View 8 Replies View Related

Cisco Firewall :: Monitoring ASA 5505 Firewall Active / Standby Pair Using SNMP?

Sep 7, 2011

How I can actively monitor the interfaces and overall status of 2 x ASA 5500s in an Active/Standby configuration?
 
I can setup monitoring of the interfaces on the Active member but I'm not sure how to manage the Standby member?

View 1 Replies View Related

Cisco Firewall :: IOS Firewall Versus ASA (5505 / 5510) For Smaller Clients (less Than 50)?

Apr 24, 2012

We were having a discussion of ios firewall vs. asa for smaller clients(less than 50). On using ios firewall(zbf or cbac)and an asa 5505/5510.  One of the arguments brought up on using ios firewall on the router is that a router will do an ip sla failover.  I have configured a number of isr's for this and i know it works good. 

View 1 Replies View Related

Cisco Firewall :: Failover ASA 5505 - Setup Second Inside Interface On Firewall?

Feb 19, 2012

I have a Cisco ASA 5505 in our office. We are currently using Interface 0 for outside and 1 for inside. We only have 1 Vlan in our environment. We have two three switches behind the firewall. Today the uplink to Interface 1, to the firewall, on the switch went bad. I want to setup a second inside interface on the firewall and configure it as failover incase this happens again. I want to attach it to the other switch. Can I do this? If so, what do I need to do? would it only be a passive/standby interface?

View 1 Replies View Related

Cisco Firewall :: Setting Up ASA 5505 To Be Used As Firewall Between BT Internet And 3560 LAN Switch?

Aug 23, 2011

setting up an ASA 5505 to be used as a firewall between a BT internet router(BTNet service) and a Cisco 3560 Lan switch. BT have presented me with a cisco 3800 series router with the following details:

Network Address   Network Mask  BTnet NTE Router LAN Address
      
There are 2 Gigethernet ports on the back of the router port Ge0/0 is connected to the BT NTE and the status light is flashing green. Int ge0/1 is connected into port int e0/1 of the ASA but i am unable to get any connection.

View 21 Replies View Related

Cisco Firewall :: Upgrade From 5505 To 5520 On Network - ASA Firewall Throughput

Feb 27, 2013

I'd like to see some REAL LIFE comparisons of ASA firewall throughput (a bit like this one for ISR G2 Routers - [URL].
 
The reason I ask is that I recently upgraded a firewall from an ASA5505 to an ASA5520 on a small network where the only outside connectivity was a single 10meg Internet circuit with an IPSEC VPN (not landed on the firewall but on a router) to another site.
 
When I swapped out the firewall the users noticed a big improvement. The firewall is not doing anything out of the ordinary - no IPS or VPN, just standard state full inspection.

View 5 Replies View Related

Cisco Firewall :: 5505 - Setting Transparent Firewall Ip Address?

Dec 22, 2011

Trying to set up a asa 5505 in transparent firewall mode. I cannot set the management ip address:
 
ciscoasa> enable
Password:
ciscoasa# config term

[Code].....

View 7 Replies View Related

Cisco Firewall :: ASA 5505 Creating Interface Vlan In Firewall

May 3, 2011

I have been working with ASA 5510,20,40,80 but not with 5505 this vlan and its interfaces are quite confusing.Just want to know how it works and its connectivity to Cisco Switch.Do i have to put the interface of the switch in the same vlan as i am creating the interface vlan in firewall ?Now the switch port connecting to this Eth1 interface should also be in the same vlan ? i.e vlan3 ?? or it will be in trunk ? The default configuration shows the eth0 with no access vlan and interface eth1 with access vlan 2... does it mean the eth0 is in vlan1 ? (Nativ Vlan ) ???

View 4 Replies View Related

Cisco Firewall :: ASA 5505 Firewall To Filter HTTPS Websites?

May 28, 2012

I have a cisco asa 5505 firewall. Is it possible to block secure websites in it like [URL]? I have already tried regular expression filtering but it filters only http traffic.

View 4 Replies View Related

Cisco Firewall :: ASA 5505 - Can't Reach FTP Site While Inside Firewall?

Feb 26, 2011

I am trying to configure our ASA 5505 so that our users can access our ftp site using [URL] while inside the firewall. Our ftp site is setup so that you can reach it by either browsing to the above url or by browsing to ftp://99.23.119.78 but we are unable to access our ftp site from either route while inside the firewall. We can access our ftp site using the internal ip address of 192.168.1.3.
 
Here is our current confguration:
 
Result of the command: "show running-config"
: Saved:ASA Version 8.2(1) !hostname ciscoasaenable password qVQaNBP31RadYDLM encryptedpasswd 2KFQnbNIdI.2KYOU encryptednames!interface Vlan1nameif insidesecurity-level 100ip address 192.168.1.1 255.255.255.0 !interface Vlan2nameif ATTsecurity-level 0pppoe client vpdn group ATTip address pppoe setroute !interface Ethernet0/0switchport access vlan 2!interface Ethernet0/1!interface Ethernet0/2!interface Ethernet0/3!interface Ethernet0/4!interface Ethernet0/5!interface Ethernet0/6!interface Ethernet0/7!ftp mode passiveobject-group service DM_INLINE_TCP_1 tcpport-object eq ftpport-object eq ftp-dataport-object eq wwwaccess-list ATT_access_in extended permit tcp any host 99.23.119.78 object-group DM_INLINE_TCP_1 access-list ATT_access_in extended permit tcp any interface ATT eq ftp access-list ATT_access_in extended permit tcp any interface ATT eq ftp-data access-list ATT_access_in extended permit tcp any interface ATT eq www access-list 100 extended permit tcp any interface ATT eq ftp

[code]....

View 6 Replies View Related

Cisco Firewall :: 5505 PAT With Single Public IP And Several Servers Behind Firewall

Nov 21, 2012

New to the ASA 5505 8.4 software version, but here is what I'm trying to do:
 
-Single static public IP:  16.2.3.4
-Need to PAT several ports to three separate servers behind firewall
-One server houses email, pptp server, ftp server and web services: 10.1.20.91
-One server houses drac management (port 445): 10.1.20.92
-One server is the IP phone server using a range of ports: 10.1.20.156
 
Basically, need to PAT the ports associated with each server to the respective servers behind the ASA 5505.  Is anything missing from this config? Do I need to include a global policy for PPTP and SMTP? [code]

View 11 Replies View Related

Cisco Firewall :: ASA 5505 Transparent Firewall With Web Sense Integration

Apr 27, 2011

I'm integrating a Cisco ASA5505 with a Websense proxy. I have a configuration setup where we have four routers which are used for Internet access. There are two VLAN's - Guest and Private. What I would like to achieve is making the use of available bandwidth by load distribution via GLBP, and filtering users web traffic. Two routers will be used for a GLBP group in one VLAN, and the other two routers will be used for GLBP in another VLAN.The users are connected to a Cisco 2960 switch and are in their respective VLAN's. I'm planning a 802.1q trunk to a Cisco ASA from the 2960 switch, carrying both VLAN's.What I would like to know is if there is a CSC module (or similar) which has Websense installed on it, and if it is possible to setup the ASA5505 in transparent mode to filter the traffic in this way? Hopefully this would allow multiple users to take advantage of the additional bandwidth, and not be restricted by using a traditional proxy setup which where all web traffic would be originating from a single MAC address.

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved