Cisco Firewall :: ASA 5505 SLA Commands Not Working

Jan 28, 2013

I am trying to set up a SLA statement on an ASA 5505 version 8.2(5). When I enter the command "sla monitor schedule 1 life forever start-time now" I get a message stating "%Entry not configured."

View 1 Replies


ADVERTISEMENT

Cisco Firewall :: Multiple Route Commands On ASA 5505?

Jan 7, 2013

I want to know with an ASA 5505 w/ Security Plus License I get up to 20 VLANS/Named Interfaces.I have a customer that is getting a new subnet of external IP addresses from their service provider and a different default gateway to accomodate re-hosting their datacenter at their main office instead of at a Colo. My question, when building out their new DMZ, can I have multiple route 0.0.0.0 commands?
 
Example.
 
Current Default Gateway 1.1.1.X
 
Internal hosts 192.168.1.0 use and are natted to 1.1.1.X
 
New Default Gateway for DMZ Servers 2.2.2.x
 
Internal hosts still use 1.1.1.X, but server hosts in 192.168.1.3 should use 2.2.2.X -- there are also a bunch of pre-existing static NAT rules for these servers such as 2.2.2.30 translates to 192.168.1.30.
 
I think I would accomplish this by using the following:
 
route inside 0.0.0.0 0.0.0.0 1.1.1.X
route DMZ 0.0.0.0 0.0.0.0 2.2.2.x
 
Would this be correct?

View 2 Replies View Related

Cisco Firewall :: 5505 Cannot Type In Commands In Putty Or Hyper-terminal

May 5, 2013

I have a Cisco ASA 5505. This has been previously configured. I am trying to give it a factory reset and I am being able to connect via Putty and Hyper-terminal but I cannot enter anything. I am able to go into ROMMAN mode by using the esc key.

View 6 Replies View Related

Cisco Switching/Routing :: 2811 / IOS Firewall Commands Not Working?

Mar 8, 2013

I have a Cisco 2811 router and i want to experiment on the IOS firewall.The thing is, none of the commands that are proposed in online guides - like ip inspect, ip audit, etc. - seem to be working. I just get "unrecognized command" on a router that is supposed to support such features. I'm wondering if it has something to do with the IOS image.

My show version output is this:
 
Cisco IOS Software, 2800 Software (C2800NM-SPSERVICESK9-M), Version 12.3(11)T9, RELEASE SOFTWARE (fc3)
Technical Support: [URL]
Copyright (c) 1986-2005 by Cisco Systems, Inc.
Compiled Tue 13-Dec-05 08:24 by ccai

[code]....

View 5 Replies View Related

Cisco VPN :: ASA 5505 - Commands In Roman (8.4(4)1)

Nov 12, 2012

Any link to the commands in the Roman asa 55xx ? Did not find on Cisco's documents.
 
My small ASA 5505 crashed and comes up in Roman. Like to try get SW and Config back if possible.

View 4 Replies View Related

Cisco WAN :: 2911 - Ip Sla Monitor Commands Not Working

May 21, 2012

I have cisco 2911 with IOS-universalK9 mz.SPA.150.1.T, but that does not accept the ip sla monitor commands XX, XX or rtr ip sla XX. How active these commands in IOS or what you belong to?

View 1 Replies View Related

Cisco Firewall :: PoE On ASA 5505 Not Working (8.4)

Jun 2, 2012

I recently acquired a used ASA 5505 and have encountered issues with getting the PoE output on Ports 6 & 7 working. Theese two PoE ports are behaving like all the other ports (100mbit, Vlan 1). Per the best I could Google, I made sure the all relevant ports are set to "auto" for duplex and link speed. Again, the ports do work for data - just not PoE. The LEDs light up ok.
 
I've tested four different working devices that can be powered off PoE with it, and all failed to power up using a straight-thru Ethernet cable connected to ports 6 & 7.

Ubiquiti PicoStation M2
MikroTik OmniTik
MikroTik RB450G
MikroTik RB433
 
What should I do to get PoE working? Is it a defective unit?
 
: Saved
: Written by enable_15 at 18:56:43.926 CDT Sun Jun 3 2012
!
ASA Version 8.4(4)

[Code].....

View 1 Replies View Related

Cisco Firewall :: SSH Not Working In 5505?

May 20, 2013

i'm trying to setup my 5505 for SSH but it seem doesn't work. console and HTTPS/ASDM are working.
 
my teraterm is just stuck with the user/password screen. also tried using putty but still failed.
 
ciscoasa# exit 
Logoff 
Username: admin

[Code].....

View 2 Replies View Related

Cisco Firewall :: ASA 5505 Not Working?

Jul 2, 2012

When i install my ASA5505 i get the following message? "This platform has a Base license.
 
Encryption hardware device : Cisco ASA-5505 on-board accelerator (revision 0x0)
Boot microcode   :  CNlite-MC-Boot-Cisco-1.2
SSL/IKE microcode:  CNlite-MC-IPSEC-Admin-3.03
IPSec microcode  :  CNlite-MC-IPSECm-MAIN-2.05
i2c_write_byte_w_suspend() error, slot = 0x0, device = 0x40, address = 26 byte
count = 1. Reason: I2C_UNPOPULATED_ERROR"

View 5 Replies View Related

Cisco WAN :: Router Rip And No Shutdown Commands Not Working On 2621xm?

Jun 16, 2012

I have an old 2621xm router in CCIE lab at home. Only a week ago I started having issue on 2 of them. The problem is on one of them when I go under interface configuration and I type "no shut" nothing happens. Interface stays in administratively down status and when I check running config "shutdown" is still under interface.
 
On the other one the same problem but only with "router rip" command. I configure my rip routing but then when I check running config there is no rip section and also RIP is not running under "show ip protocols rip".These routers are connected to 2511 AccesServer. So I thought the issue might be communication from AccessServer to these devices. I connected a console cable straight to them and still the same problem. Everything else is working on these devices.

View 10 Replies View Related

Cisco Firewall :: Static 1 To 1 NAT Not Working On ASA 5505

Jan 28, 2013

i have 2 internal server sitting in inside interface
 
inside network vlan 1 ip address 192.168.0.20, and 192.168.0.22
 
i going to map 192.168.0.20 to public ip routable address 203.117.124.180 and 192.168.0.22 to public ip routable address 203.117.124.181
 
the purpose is to make those 2 server 192.168.0.20, and .22 to be able to access remotely using public routable ip address,
 
however, after done the configuration i still not able to ping or access the public IP Address mention above. my both server are turn on and can access internally.both server are also able to access internet. See below partial configuration retrieve from Show Run.
 
nat-control
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0
nat (Antlab) 1 0.0.0.0 0.0.0.0

[Code].....

View 2 Replies View Related

Cisco Firewall :: NAT Only Working For Some IP Addresses On 5505

Dec 16, 2011

I'm trying to get a new 5505 installed in our network to replace the 1841 that died over the past few days (memory issues).  One of the big pieces of functionality that the old router gave us was the ability to open certain ports to the outside world to let clients see web sites we were working on for them or let employees RDP in to their work machines.  I'm having trouble getting that working properly with the new device.
 
After a lot of trial and error, I finally got some ports working, but only for some IP addresses.  In theory, Comcast (our ISP) is routing 13 IP addresses to our device (a.b.c.177 through 189).  For historical reasons, the external IP of the device is .178.  Only those NAT entries for .177, .178 and .179 are currently working. I've attached the configuration of the ASA, as well as the configuration of the old 1841.  As far as I know, Comcast's equipment is doing its job, so I don't have a lot of reason to question that end of it.  And it was working with the 1841 in place before its untimely demise.
 
One note - I am also having trouble getting the VPNs working, so they are a work in progress.  That will account for some of the differences in the configs.

View 7 Replies View Related

Cisco Firewall :: ASA 5505 9.0(2) Traceroute Not Working

Apr 16, 2013

there is an issue with tracroute from ASA 5505 with 9.0(2) - here is the running configuration [code] with this running configuration - from the LAN tracerouet to public IP, it is working fine.  but once I traceroute from the LAN 192.168.225.x to the corporate networks via the IPSec l2l tunnel - it does not show any hop at all - even the inside interface of the ASA does not show in the traceroute. 

View 4 Replies View Related

Cisco Firewall :: ASA 5505 - 8.4(3) - PCTV Not Working?

Apr 1, 2012

I have an ASA 5505 running 8.4(3) at home and I'm banging my head against the wall trying to get the PCTV working from my local ISP.Basically I open a web page for the service and I can stream all the basic TV channels to my PC screen.
 
I just simply cant get this working through the ASA.. I know absolutely nothing about voice/video in networking.
  
My setup regarding ASA configurations are as follows
  
interface Vlan1
description LAN
nameif LAN
security-level 100
ip address 10.0.0.1 255.255.255.0
igmp forward interface WAN

[code....
 
I can get the PCTV working if i bypass the ASA. I can for example get the PCTV working on PC2 if I simply change the port Ethernet0/2 to access vlan 10. So theres just simply something that I havent configured on the ASA or the ASA doesnt support something?I took a capture from my PC2 just as I opened the browser and connected to the PCTV url (opens our local channe 1 right away)Only thing I can see in the capture at that point is:
 
- V2 Membership report / Join group 232.1.3.1

- Right after a remote host from the ISP networks starts sending the stream with the destination port udp/2000 with the destination address of 232.1.3.1
 
what I could check in my configuration? Or is there something that I have simply configured wrong already on the partial configuration shown above?

View 3 Replies View Related

Cisco WAN :: Route-map And IP SLA Monitor Commands Not Working On 1841 Router

Jun 11, 2013

There are no commands like route-map & ip sla monitor on my cisco 1841 router, its ios version is 12.4(T1). I have to configure load balancing and failover on this router but without these commands i cant do that.

View 3 Replies View Related

Cisco Firewall :: ASA 5505 Base License - How To Get AnyConnect Working

Mar 29, 2012

I have a base 5505 and would like to get AnyConnect working.  To do that, would I have to first purchase either an essentials or premium license and then purchase the AnyConnect Mobile license?

View 1 Replies View Related

Cisco Firewall :: ASA 8.4 What Commands Can Use To Verify Related Configuration On Firewall

Apr 7, 2013

We have an ASA with 8.4(5) version. we had detected that few ip's were getting shunned ,to overcome the problem no shun was used and the traffic normalised.But, the same problem re-occured a few days after that with logs showing traffic being shunned.
 
is there any fixed way to get rid of this. what commands can i use to verify related configuration on the firewall.

View 3 Replies View Related

Cisco Firewall :: ASA 8.4.2 NAT Commands

Jul 13, 2011

I try to get a ASA with the new software 8.4.2 running. On an old pix we had the nat command: static (inside,outside) tcp interface www 192.168.15.252 www netmask 255.255.255.255 0 0,In all the new documents about 8.4.2 I can find that it should work with something like:
 
object network web_host nat (inside,outside) static interface service tcp www www
 
I want to forward http traffic from the outside interface to this host. In the log I just get entries about blocking ACL - but both is allowed on the outside access-list - traffic to the inside IP and also to the outside interface IP.
 
I also tried it with "Public Server" - but when I try to use the Interface address I just get the message: Address x.x.x.x overlaps with outside interface address.

Is it still possible to do port forwarding on the outside interface?

View 5 Replies View Related

Cisco Firewall :: PIX 515 - How To Set NATing Up Or Commands

Oct 19, 2011

I have just received 4 static ip's from my isp, i want to be able to point these ip's at different services on my internal servers, for example: [code]. The firewall I have is Cisco PIX 515, how to set the NATing up or commands?

View 1 Replies View Related

Cisco Firewall :: ASA 5515 - CLI Commands Just Scroll

Dec 19, 2012

Why do my cli commands just scroll all the content rather than having to press space to show more?  It is hard to type sh run and the entire config flays past rather than being to inspect it page by page.

View 3 Replies View Related

Cisco Firewall :: ASA 5545 - Passwords To Allow All Show Commands

Mar 26, 2013

Currently have an ASA 5545. What I want to do is allow our support team to perform ALL show commands (up to and including show run) but not enable them to perform ANY configuration changes on the devices (not get into config t). This is to allow them to check ARP tables, routing protocol status, etc
 
i don't have access to the ASA at the moment and haven't been able to figure it out in IOS, i'm assuming its not too hard.

View 1 Replies View Related

Cisco Firewall :: ASA 5520 - Logging / Viewing Commands?

Sep 27, 2011

How to view  the commands that someone  changed the configurations in ASA 5520?

View 1 Replies View Related

Cisco VPN :: ASA 5505 - VPN Only Partially Working

May 9, 2012

I configured a VPN on my ASA5505 and it seems to be working just fine if I connect with my i Pad or iPhone.  But if I use the Cisco VPN Client, I can authenticate but can't get to any other the server that I can access just fine from my i Pad. 

I can RDP from my i Pad to servers but I can't RDP from my laptop to the same servers. 

View 4 Replies View Related

Cisco VPN :: ASA 5505 IPsec Not Working?

May 6, 2012

I have setup a ASA and everything but ipsec seems to be working. I was able to use the clientless ssl but I need ipsec working. I'm at a loss. config is a little sloppy and i will be cleaning it up but would like to get this working first.
 
Cisco Systems VPN Client Version 5.0.07.0290
Copyright (C) 1998-2010 Cisco Systems, Inc. All Rights Reserved.
Client Type(s): Windows, WinNT

[Code].....

View 3 Replies View Related

Cisco VPN :: AnyConnect With ASA 5505 Stopped Working

Sep 26, 2012

I was installing a IIS server to our client and created access - rules for http server and port translations. After that i noticed i lost local lan access trough vpn.  Anyconnect and ipsec vpn. No other changes made to asa than those access-rules and nat changes. I'm trying to find out what is wrong, vpn connects okay, i can ping ASA but nothing else on inside network (for example dns server). Dns is not either working. When i ping local server, i can see in log.

View 8 Replies View Related

Cisco Firewall :: Monitoring ASA 5505 Firewall Active / Standby Pair Using SNMP?

Sep 7, 2011

How I can actively monitor the interfaces and overall status of 2 x ASA 5500s in an Active/Standby configuration?
 
I can setup monitoring of the interfaces on the Active member but I'm not sure how to manage the Standby member?

View 1 Replies View Related

Cisco Firewall :: IOS Firewall Versus ASA (5505 / 5510) For Smaller Clients (less Than 50)?

Apr 24, 2012

We were having a discussion of ios firewall vs. asa for smaller clients(less than 50). On using ios firewall(zbf or cbac)and an asa 5505/5510.  One of the arguments brought up on using ios firewall on the router is that a router will do an ip sla failover.  I have configured a number of isr's for this and i know it works good. 

View 1 Replies View Related

Cisco Firewall :: Failover ASA 5505 - Setup Second Inside Interface On Firewall?

Feb 19, 2012

I have a Cisco ASA 5505 in our office. We are currently using Interface 0 for outside and 1 for inside. We only have 1 Vlan in our environment. We have two three switches behind the firewall. Today the uplink to Interface 1, to the firewall, on the switch went bad. I want to setup a second inside interface on the firewall and configure it as failover incase this happens again. I want to attach it to the other switch. Can I do this? If so, what do I need to do? would it only be a passive/standby interface?

View 1 Replies View Related

Cisco Firewall :: Setting Up ASA 5505 To Be Used As Firewall Between BT Internet And 3560 LAN Switch?

Aug 23, 2011

setting up an ASA 5505 to be used as a firewall between a BT internet router(BTNet service) and a Cisco 3560 Lan switch. BT have presented me with a cisco 3800 series router with the following details:

Network Address   Network Mask  BTnet NTE Router LAN Address
      
There are 2 Gigethernet ports on the back of the router port Ge0/0 is connected to the BT NTE and the status light is flashing green. Int ge0/1 is connected into port int e0/1 of the ASA but i am unable to get any connection.

View 21 Replies View Related

Cisco Firewall :: Upgrade From 5505 To 5520 On Network - ASA Firewall Throughput

Feb 27, 2013

I'd like to see some REAL LIFE comparisons of ASA firewall throughput (a bit like this one for ISR G2 Routers - [URL].
 
The reason I ask is that I recently upgraded a firewall from an ASA5505 to an ASA5520 on a small network where the only outside connectivity was a single 10meg Internet circuit with an IPSEC VPN (not landed on the firewall but on a router) to another site.
 
When I swapped out the firewall the users noticed a big improvement. The firewall is not doing anything out of the ordinary - no IPS or VPN, just standard state full inspection.

View 5 Replies View Related

Cisco :: 5505 Lost ICMP And ASDM Launcher / But ASA Is Still Working?

Sep 11, 2012

I was logged into our ASA 5505 via ASDM-IDM Launcher (everything was working) and when I tried to update a change later on today it was unable to send the request. I tried to ping the device and the request timed out. The internet is still working, the VPN connections are still up. But I cannot connect into it anymore.

View 4 Replies View Related

Cisco VPN :: ASA 5505 - Running Pair Of VPNs Working From Offsite

Dec 16, 2011

We're trying to get a new ASA 5505 put in place on our network after the untimely demise of our 1841 router.  One of the functions of the router that we need to get back up and running is a pair of VPNs to employees that we have working from offsite.  These are site-to-site VPNs.
 
They worked with the 1841 in place, so I know that the other end works.  I'm just having trouble configuring the ASA to match.  I've been through the wizard in ASDM a couple of times, but have yet to have any luck getting it to connect.
 
Attached are config files for the 1841 (with both VPNs) and the 5505 (with only 1 VPN in place).  What I may be missing in order to get this working?
 
One note - I am having some trouble with my NAT configurations (another post pending), but I think they are close enough that I hope it's not interfering with the VPNs.
 
If I can get one running, the other has a nearly identical set up, so I should be able to get the second pretty easily.

View 1 Replies View Related

Cisco Firewall :: 5505 - Setting Transparent Firewall Ip Address?

Dec 22, 2011

Trying to set up a asa 5505 in transparent firewall mode. I cannot set the management ip address:
 
ciscoasa> enable
Password:
ciscoasa# config term

[Code].....

View 7 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved