Cisco Firewall :: 5520 - How To Check Vulnerability On ASA IOS Image

Feb 28, 2012

i am using asa821-k8.bin image, in my cisco 5520, How can i check if my IOS is vulnerable ?

View 4 Replies


Cisco Firewall :: How To Check Functions Included For ASA Image NCI-ASA5520-BUN-K9

Jan 13, 2013

May I have to know how to check functions included for asa image NCI-ASA5520-BUN-K9?

View 2 Replies View Related

Cisco Firewall :: 5520 - How To Check Hits On Particular Allowed IP

Aug 10, 2011

i allowed one of internal ip using static nat and public ip is and i want to check which IP  are  hit this public ip ?Is there is any command to check which ip is hitting I have the cisco 5520 asa firewall.

View 6 Replies View Related

Cisco Firewall :: ASA 5520 - Check Which IPs Hitting On Particular Interface

Sep 23, 2012

I have a cisco asa 5520 and suddendley in my Network Monitor tool,(using SNMP)  asa's DMZ interface traffic is showing arround 90000 Kbit/s .
i want to check which traffic is flowing throgh this interface.(Ip address details)
Note : There is no impact on asa CPU usage.

View 4 Replies View Related

Cisco Firewall :: Command To Check ASA 5520 Is Passing Traffic

May 14, 2012

how can i check that ASA is passing traffic? Also what command we can use to make sure VPN is working fine.

View 2 Replies View Related

Cisco Firewall :: Command To Check IPSEC Tunnel On ASA 5520?

Jan 7, 2013

Need to check how many tunnels IPSEC are running over ASA 5520.Tried commands which we use on Routers no luck?

View 6 Replies View Related

Cisco Firewall :: ASA 5520 / SSM-20 Password Recovery With 5.0 Image Running

Jun 3, 2012

The customer forgot the password for the ASA SSM-20 ips module installed in ASA 5520 module in customer FW shows it up state. I brought it to our office teat bed. here it show

ASA1# sh module
 Mod Card Type                                    Model              Serial No.
--- -------------------------------------------- ------------------ -----------
  0 ASA 5520 Adaptive Security Appliance         ASA5520-K8         JMX1022K03A
  1 ASA 5500 Series Security Services Module-20  ASA-SSM-20         JAB101003C2
 Mod MAC Address Range                 Hw Version   Fw Version   Sw Version    


what to do with  this module in my test bed.I have to take it back to the customer site to use it in their ASA itself to troubleshoot.There it the status is up and i did use all the hw-module option but no use. The version is 5.0. This module is more than 5 years old and so far no one upgrade the image. ASA 5520 running 8.2.5.

View 8 Replies View Related

Cisco Firewall :: ASA 5520 - Verifying Flash Image Fails?

Nov 1, 2011

I have an ASA 5520, currently running version 7.25-k8. I'm preparing for an upgrade to version 7.25(4), so I transferred the software code (obtained via Cisco download) to the firewall vis SCP. I then issued the "verify flash:asa725-k8.bin" and it fails. It comes back with the error that the CRC did not verify, Data Integrity has been compromised". My first thought was the image did not copy correctly, so I deleted it and transferred it again. I got the same error. Then I decided to run a verify against the actual current code that was running on the firewall, and it came back with the same error. I don't understand what the problem is. I don't tend to think it's an SSH key related problem, as the method I use to access the firewall is via SSH and I have no problems. Worth noting,this firewall is part of an active/standby pair, and I observe the same behavior on the failover unit, it fails to verify.

View 3 Replies View Related

Cisco Firewall :: What Is The Vulnerability Impact Of Using SSH V1 On An ASA 8.4

Dec 9, 2012

if SSH v1 is considered vulnerable why is it still enabled by default on the ASA 8.4 by default?What is the vulnerability impact of using SSH v1 on an ASA?

View 1 Replies View Related

Cisco Firewall :: ASA 8.4.1 SSH Timeout Vulnerability?

Feb 20, 2013

Faced this recent vulnerability?

My understanding is that for ASA 8.4.1 and prior, there's a vulnerability that opening many ssh sessions and one of them times out, the firewalls crashes! 
As we have many customers with ASA using 8.2.5(26) (for example) I'd like a confirmation that for fixing that bug I need to upgrade my ASA image to at least 8.4.x.Case that, I believe that all the former firewall configuration must be reviewed because 8.2.x version has many different commands that 8.4.x (for example, NAT)

View 19 Replies View Related

Cisco Firewall :: ASA5510 Device Manager Image Set But Not A Valid Image File

Feb 9, 2012

I'm have upgraded our ASA5510's from 7.0.8 to 8.4.3 and now I just need to do the ASDM, but get this error?  The bin file has been uploaded: [code] Device Manager image set, but not a valid image file disk0:/asdm-647.bin.

View 3 Replies View Related

Cisco VPN :: ASA 5520 - AnyConnect Check Endpoint Attributes Not Working

Mar 12, 2013

While user's connecting through AnyConnect, AnyConnect doesn`t check endpoint attributes. I've configured checking process  of "notepad.exe", but it doesn`t work. There is no checking process of  "notepad.exe" in output debug dab trace (see attach).

ASA 5520 ver 8.4(1)
AnyConnect 3.1.02040
HostScan     3.1.02043
CSD            3.6.6234

View 16 Replies View Related

Cisco Firewall :: NAT RPF Check Failure PIX 8.2 OS

May 2, 2013

i know in Cisco PIX til 8.2 OS, if i have Nat control disabled and ACL permitting connection from Low Secirity ( DMZ ) to High Secuurity (INSIDE) then connectino should be successful, and i dont need any STATIC identity nat of inside IP to be created.

But i have Cisco PIX 525 with  Version 7.2(2) Which is not allowing connection from DMZ to INSIDE , although nat control is disabled. and giving RFP check failure, any thought?

PIT525PIXINET# sh running-config nat-control no nat-cont
packet-tracer input dmZ  tcp 65000 3389
Phase: 1
Result: ALLOW

View 6 Replies View Related

Cisco :: Software To Check Most Used Website Through Firewall

Mar 1, 2012

know software that can show us software that shows most used websites through particular firewall?

View 8 Replies View Related

Cisco Firewall :: ASA 8.2(5) / UDP Reverse Path Check

Jun 15, 2012

ASA running 8.2(5).When I enable ip spoofing on my network interfaces I see this getting logged:

Deny UDP reverse path check from to on interface SPECTRA-LAN
This is because interface SPECTRA-LAN (VLAN50) is the interface connected to the network with ip but the interface do not have a ip address so it does not exist in the routing table I believe?However interface INTERN do also belong to network which also is the management interface and the default route for hosts in network, but has no vlan. 

1. move the management0/0 to SPECTRA-LAN and give SPECTRA-LAN ip

2. give SPECTRA-LAN a ip address in the range?

My routing table and interface list is:

Current available interface(s):
  DATA-BACKUP     Name of interface Redundant1.10
  DMZ             Name of interface Redundant1.900
  GUEST           Name of interface Redundant1.990
  HOSTING         Name of interface Redundant1.100
  Infrastruktur   Name of interface Redundant1.20


View 3 Replies View Related

Cisco Firewall :: ASA 8.4.3 - Does It Check DNS Source IP Address

Oct 29, 2012

Does ASA 8.4.3 check the source IP address of  a DNS reply and drop it if the reply address is different to that in the query?
Customers DNS server does this due to a recent change, their server now has a virtual address, but replies are sent from its physcial address. This is temporary. Their PIX is happy with this.
Replace the PIX with the ASA, DNS fails, the only reason I can see is due to the way their internal DNS operates.

View 1 Replies View Related

Cisco Firewall :: Way To Check Hardware Status Of ASA 5505?

Nov 22, 2012

Is there a way to check the hardware status of an ASA 5505 ? I am thinking of a command or a script to execute.

View 3 Replies View Related

Cisco Firewall :: 12697 FWSM Shows TCP Check-sum Incorrect

Jun 13, 2012

When we setup a connection between two hosts we receive the message "TCP checksum incorrect" , This is  between a settop box on the outside and a server inside the firewall. This STB used to communicate with the server on port 443 which is NAT-en to port 12697.With a new settop box image which uses on the inside and outside port 12697 we receive this TCP checksum incorrect on the Firewall with wireshark.
Strange is that on the outside of the firewall we see an MSS of 1460 and on the inside it is 1380 (don't know if there is a relation with this and the issue we have)

View 1 Replies View Related

Cisco Firewall :: ASA 8.4 Newer Check Point Conversion Tool?

Feb 8, 2012

Is there a newer tool for current versions of Checkpoint to ASA 8.4?  I notice a lot of similarity between checkpoint and 8.4 now, but I still have to do it all line by line which has become a PITA.

View 1 Replies View Related

Cisco Infrastructure :: Where To Check License Details - ASR 1000 Firewall

Mar 13, 2011

I am looking for for details meaning of license because I cannot found the details install.  The license call
that is used to enable the firewall function in ASR 1000 series.  But I don't clear about what feature inside, it is because it only show the "firewall" from website.  Is that same as IOS firewall?

View 1 Replies View Related

Cisco :: Any Vulnerability Scan Tool Recommended For It?

Mar 16, 2012

I would like to perform vulnerability scan on Cisco switch and router.Is there any free vulnerability scan tool recommended for Cisco device ?

View 2 Replies View Related

Cisco WAN :: ASR1002 Running SubPackages And IOS Vulnerability?

Apr 19, 2012

We have ASR1002 routers configured to run individual SubPackages, at this point everything is operating without problems.We just received a Cisco Security Advisory informing us SSHv2 is vulnerable in our version of router code.We have to upgrade to the recommended stable release, so we downloaded, installed and expanded the IOS to expose the SubPackages on the ASR routers bootflash.

Since we are running SubPackages, do we need to upgrade all SubPackages (I.E. complete IOS upgrade) of can we just upgrade the vulnerable SubPackage? How do you determine which SubPackage contains the SSHv2 application?

View 2 Replies View Related

Cisco Firewall :: ASA5510 Will Not Load New Image

Aug 4, 2011

i have an ASA 5510. it was running asa708-k8.bin and i have attempted to install asa821-k8.bin. i have done this on many ASAs before effortlessly.this time i have had an issue. the ASA will not load the new image, and for some reason will not even load the old.the ASA seems to just keep crashing. i have erased disk0 (advised in forum): and attempted to load the image from tftp. please see below. i know i need to re-formaet the flash, but cannot get into the ASA at all to complete this. [code]

View 2 Replies View Related

Cisco Firewall :: PIX 501 Upgrade To Have ASDM Image On It

Mar 29, 2011

I got a PIX 501 off ebay and im trying to upgrade it to have an ASDM image on it.Ive downloaded every copy of the ASDM image i can get my hands on, and when i transfer it to the PIX when its up and running i get out of memory, If i do it through monitor mode, i get the error "bad magic number" no matter what i transfer to itI can transfer a new image to the PIX (a non asdm one through monitor mode.

View 3 Replies View Related

Cisco Firewall :: Need Image File Install On Pix 515

Aug 28, 2011

I have a pix 515, time to time the firewall start rebooting with invalid flash error I found erasedisk.bin in internet, after that i cant load pix532.bin ios file and others pix***.bin are not workingThe only file i am able to load is pix508.bin it,s start asking me activatin number before install I have a previous activation number ios version 5.3.2 but this number is not correct.

View 1 Replies View Related

Cisco Firewall :: Tell If PIX515e Image Is Genuine?

Aug 28, 2011

I just bought a used PIX515e. It is running version 8.0(3) and ASDM 6.1.5  Because I do not know the history of the unit, how can I tell if the image used came from cisco and not some download site?  I guess I should've thought about this before buying it but hindsight know. Worse case is that the person who had it before me dl the software that was infected with a backdoor or something else. I don't have a service contract so I'm kinda stuck.
Can I download the image from the firewall flash and compare a MD5SUM?

View 12 Replies View Related

Cisco Firewall :: ASA 5500 - Upgrade Image To 8.4(3)?

Apr 3, 2012

We are now using image 8.0(4) for my ASA 5510. Later on, I would like to upgrade the image to 8.4(3).May I have to know what difference for those images, what should I take care of the script?

View 1 Replies View Related

Cisco Firewall :: ASA5520 Best Image To Use Required

May 16, 2011

 I upgraded my ASA 5520 with the latest image. Now I get an error upon launching ASDM.Your ASA image has a version number 7.2(4) which is not supported by ASDM 6.4(1), use Device Manager version 5.2(x)Continue Anyway?
What are the newest, recomended image versions of ASA and ASDM I should be using?I will also be using the SSM-20 module with this setup, so I would like to stay with a working version of ASDM.

View 1 Replies View Related

Cisco Firewall :: How To Upgrade Fwsm Image From 3.1(10) To 4.0(8)

Jan 11, 2010

I need to upgrade the fwsm image from 3.1(10) to 4.0(8). Can i do it directly from 3.1(10) to 4.0(8) ?Do i need to upgrade other image also along with Firewall version 4.0(8)?

View 5 Replies View Related

Cisco Switching/Routing :: Switch 3750-X Vulnerability

Jul 19, 2012

I had a bad expirience with Switch 3750-X. Because of an auditing security processess, my customer ran a software called "Nessus" to do a scanning of vulnerability on the network. When this software is point to switch, the process of the switch will next to 100% and reset. The software only do a listening on the ports to see what ports are opened and the switch should not reset because this. Bellow is the log os switch on the moment of test; we note that the processess 'HTTP' rise moments before the switch reset. I disable the HTTP service on switch but the problem persist. The test was made only one machine connected to switch.

View 4 Replies View Related

Cisco Firewall :: 5510 - How To Roll Back ASA Image

Mar 17, 2012

I downloaded a new image to my ASA 5510 and found out up on reboot that the ASA doesn't have enough memory so I am booting to the "ciscoasa" prompt with no config. I still have my old image in disk0:. How do I roll back to this old image?

View 1 Replies View Related

Cisco Firewall :: Upload New Image To Standby ASA5520?

Nov 30, 2011

I have a pair of asa5520's in active/standby configuration.  I plan on ugrading the asa/asdm images to 8.4 shortly (currently on 8.0) and would like to do this with zero downtime.  Specifically, I would like to upload the new software to the standby unit, upgrade it, swap standby/active units and then upgrade what will become the standby after the swap.The problem I'm having is getting the new images uploaded onto the standby unit.  I've read that the routing table is not shared from the primary and the USB ports are "for future use".  I have no problem uploading the new images to the active unit via tftp...but can't do the same to the standby.

View 5 Replies View Related

Cisco Firewall :: How To Change Which Image Is Booted On ASA5510

Mar 18, 2011

I am wondering how to change which image is loaded by default on an ASA5510.  I have two image files stored in the flash memory on disk0:/ but need to change which one is loaded on boot.  I used the command "boot system disk0:/asa722-12-k8.bin" which completed successfully, but when the system starts it says two images exist and the default is 1, loading the previous file.  Is there a command to change the order that is used?

View 2 Replies View Related

Copyrights 2005-15, All rights reserved