Cisco Firewall :: ASA 5510 / 8.0 - Capture Type ASP Drop Entries With No Reason?

Dec 4, 2011

I have a capture set up of type "asp-drop all", and I am capturing certain packets with no indicated ASP drop reason.  See output below (ASA 5510 with 8.0(5)23 code):asa5510-8.0#  show capture, capture ASP type asp-drop all buffer 15000 circular-buffer [Capturing - 14912 bytes]

View 2 Replies


ADVERTISEMENT

Cisco Firewall :: ASA 5510 / 4GE SSM - FP L2 Rule Drop

Nov 10, 2011

ASA 5510 running without issues for a while but we needed extra port so added a 4GE SSM.
 
Having installed the 4GE SSM we had some issues with the card not liking a connection to our switches and only working by plugging directly from the server into the firewall, not great as we wanted extra servers on the line in the future.  So we upgraded the firmware and no are at an impasse.
 
We have upgraded to 8.0(4)3 and now we cannot get any traffic through the port, we can't even connect to an external DNS server.  Running a packet trace I get an immediate error on the first step '(l2_acl) FP L2 rule drop', and it appears as though the outside connection is down.
 
I have some experience on setting up basic port forwarding and NAT for internet access, webservers, mail but this has thrown me. 

View 28 Replies View Related

Cisco Firewall :: ASA 5510 High Drop Count On Management Interface

Sep 4, 2012

I have a 5510 FW in multi-context mode that is showing a high drop count on the Management interface in the Admin context.

View 1 Replies View Related

Cisco Firewall :: Allow / Block Any Type Of Services From ASA 5510 Extended

Jul 25, 2012

I have created Different extended access-list which allow/block some specific services like IP,TCP,UDP ,ICMP etc for certain source and destination . But now I have to allow/Block all/any type of services to a certain host from a extended access-list . How can I do it ?

View 4 Replies View Related

Cisco WAN :: Enable IP Accounting Or Capture Packets In ASA 5510?

Sep 3, 2012

Enabling IP Accounting or capture packets in Cisco ASA 5510 ( 8.2 ).

View 2 Replies View Related

Cisco VPN :: RDP Connection Drop When Working Via WebVPN ASA 5510

Nov 21, 2010

I have a customer using the RDP plugin via WebVPN on an ASA 5510 (running 8.2.2).They are complaining that after ten minutes or so, the RDP connection drops. Sometimes they can connect again straight away, other times they even have to re-login the ASA WebVPN again.I can't find any logging which explains what is going on.

View 5 Replies View Related

Cisco Firewall :: PIX 515e Reason To Upgrade To ASA Cluster

Feb 24, 2011

Just looking for some good reasons why I should upgrade a Cisco PIX 515e cluster to an ASA Cluster to present to the business.

View 1 Replies View Related

Cisco Firewall :: Failover On ASA5510 - Reason Of Interface Tests

Jun 24, 2011

Do I correctly understand that when two ASA 5510 are in fail over pair, the switchover from primary to secondary if one interface of primary goes down shall happen ONLY if failover link is up? So when the fail over link is down and one interface on primary got down also,  interface tests between the two ASAs still are being done , but secondary SHALL NEVER try to become active.

In this case why to make  tests on data interfaces ? What is the reason to make them? If the knowledge of that some interfaces  of primary became down comes through failover link - no need to make additional interface tests - primary will tell about the failure to secondary. If so should run no monitor-interface  if name command to dis load devices and network by foolish  tests?

View 5 Replies View Related

Cisco Firewall :: 15.2 / How To Interpret IOS Log Entries

Oct 12, 2011

how to read some of these log entries I see on the IOS 15.2 router I'm working with.  I'm fairly new to this stuff.  My understanding is that the first socket (123.123.123.123:port#) is the originating one, and the 2nd socket is the receiving or destination.  This makes sense when I see an entry like:
 
01043: *Nov 21 2012 10:28:34.323 PCTime: %FW-6-DROP_PKT: Dropping tcp session xx.xx.241.163:39557 192.168.xx.xx:80  due to  RST inside current window with ip ident 0
 
The internal IP is our email server inside the LAN, the first IP is some IP in a foreign country, so someobody visited our web interface for the email server, obviously trying to breach or recon the interface but whatever.  Then I see an (unrelated) entry like this elsewhere in the logs:
 
001095: *Nov 21 2012 25:56:03.531 PCTime: %FW-6-DROP_PKT: Dropping tcp session xx.xx.178.210:25 192.168.xx.xx:47343 on zone-pair inside-outside class INSIDE-OUTSIDE due to  Stray Segment with ip ident 0
 
What this latter entry tells me is that the Internet host sent data FROM port 25 to what I am guessing is the open port our internal email server must have originated some other communication from.  However we do not accept incoming port 25 mail from anywhere but a designated IP so this "send" is not supposed ot occur.  So first off, am I reading that correctly?  Is the first IP the sending system, and the second IP the receiver?   there are no other entries in the logs between these two hosts, so either the logs have truncated with oldest entries removed (log buffer is set to 51200), or that outside host is sending, hoping to get our mail server to respond?  BTW, the outside host WHOIS's to Microsoft's IP range, Block 1. 

View 8 Replies View Related

Cisco Firewall :: ASA 5505 - Capture AOL Instant Messenger Traffic?

Feb 11, 2013

I have an ASA 5505 and I setup a port with a PC connected to monitor the LAN interface. I see all the traffic from the LAN  going out and traffic coming back in no problem. What I do not see the the AOL Instant Messenger traffic at all. I have WireShark on the PC and I filter for AIM traffic and I see nothing.

View 5 Replies View Related

Cisco Firewall :: ASA 5520 With 9.0.1 IOS - Capture To Inside Interface Not Supported

Dec 9, 2012

I recently upgraded my 5520 to 9.0.1 IOS.  Today I tried to apply a capture to my inside interface referencing a simple ACL and I get this error.
 
ERROR: Capture doesn't support access-list <capin> containing mixed policies
 
I also created a capture for the outside interface with a similar ACL and it worked just fine.  I can't seem to find anything on the web that gives me a clue to resolving the error above. 

View 7 Replies View Related

Cisco Firewall :: ASA 5505 - How To Store Show Capture Word Output

Apr 16, 2011

I have a cisco ASA 5505 . I need to store " show capture 'word' ( where is a variable) output  to syslog server for analyzing packet and port  .

View 2 Replies View Related

Cisco Firewall :: Cannot View Permit Entries In The Log On ASA 5520

Apr 6, 2011

I can not seem to view my "permit" entries in the log on my ASA 5520. I set up logging-lists, changed the level to 3 on  the logging statement, and simply can't find it anywhere.
 
Partial config:
 
logging enabled
logging timestamp
logging JC-L3 level errors
logging monitor JC-L3
logging buffered JC-L3
logging trap notifications

[code]....

View 6 Replies View Related

Cisco Firewall :: How Many Route Entries Can ASA5520 (8.2.1-k8) Support

Sep 24, 2011

how many route entries can ASA5520 (8.2.1-k8) support?

View 2 Replies View Related

Cisco Firewall :: ASA 5505 Using Logging & Packet-capture To Locate Virus Infected PC

Aug 2, 2011

ATT notified my company we have a virus infected pc on one our networks which sits behind a Cisco ASA 5505 running 7.2(4). The set up is a basic inside/outside NAT configuration. They gave us the destination ip address and port which the our pc is contacting.  I have been tasked to track down the infected pc.  I created the following access-list and applied to the inside interface:
 
access-list VIRUS extended permit TCP ANY host x.x.x.x EQ YYYYY log debugging interval 600 access-group VIRUS in interface inside
 
I enable logging to the console whose output did not list the IP address of the infected pc, only the ip address of the DNS servers we were using. I then used the following capture commands to try locate the internal ip address of the infected pc:
 
capture in-cap interface inside access-list VIRUS-CAP buffer 1000000 packet 1522 capture in-cap access-list VIRUS-CAP interface inside
 
Neither step worked and the resulting console output overwhelmed the firewall in a very short period of time. Before attempting this task again, I would like to know if I am going about this the right way or if there is a better methodology?

View 24 Replies View Related

Cisco Firewall :: 6552 Static Entries With Same Ip Address But Different Ports

Sep 15, 2011

Our proxy/anti-smap/IPS box called PROXY is behind our Cisco ASA firewall. The PROXY is set in transparent mode.The PROXY internal ip is 1.1.1.1 (internal ip)We have the MX record for mail.domain.com with public ip 9.2.7.5 (public ip as we entered with ISP public DNS)What happens now is that the emails that come through get "caught" by the PROXY and then we setup a thing whereby the emails are then forwarded from PROXY to our mail.domain.com server. Also, we made a static entry in PROXY whereby we can https to our email server for the outlook web access from outside of work therefore allowing for users to see the outlook web access web page.On the Cisco firewall, we put the static entry that 9.2.7.5 is mapped to 1.1.1.1 thus the mail server public ip is mapped to the PROXY.
 
Now, the box has this thing whereby it sends an email to all staff once a day telling them how many mails are legit, how many rejected and how many are spam - the spam emails are listed within the email and staff can at a click of a release button next to each spam email release a particular email from the PROXY box and make it to into their inbox.  This works fine from the inside network, but I have issues from the outside due to the DNS and other things.I also put in the PROXY that any network can release spam and that our staff vlan can release emails. Also, on the inside of the firewall we did an access list that computers from staff vlan can access 1.1.1.1 on port 6552 (Which is the release spam port).Hence, we can release emails from internal network through the Microsoft Outlook.
 
On the outside network, we cannot release emails when using outlook web access.The host name for the PROXY release spam is proxy.domain.com so what we did also today is ask "ISP" to make an A record entry for another public ip which is 9.2.7.6 for proxy.domain.com.We meanwhile made an entry on the access list that comptuers from outside can access 9.2.7.6 on port 6552 (which is the release port).Now the only question is in regards to the static entries:
 
1. do we (and can we?) static map 9.2.7.6 to 1.1.1.1 through a port 3840 on the Cisco ASA (although we have already mapped 1.1.1.1 to 9.2.7.5 - I have a doubt here as this might mean we might not get emails? Or would we have to do the static again for this one specifcying the 9.2.7.5 as an smtp entry and the 9.2.7.6 as a release button?

2. have I made a mistake in general and should I have just told the ISP to make a CNAME entry for proxy.domain.com with the public ip 9.2.7.5 (which is the public ip for MX record?)?

View 9 Replies View Related

Cisco Firewall :: 5580 To Create Syslog Entries When Someone Connects Via HTTPS / SSH

Mar 13, 2011

Is it possible for a Cisco ASA 5580 to create Syslog entries when someone connects via HTTPS or SSH to it. I need to obtain information from Syslog when someone does this.

View 5 Replies View Related

Cisco Firewall :: Maximum Number Of 1-1 Static Nat Entries On ASA 5515X Or 5525X?

Aug 7, 2012

I have a FWSM cluster that I exceeded the maximum number of static nat entries on.  i migrated the connectivity off to a pair of PIX 535's that seem to be handling the adderess translation needs.  however the number of NAT entries being required is increasing and being the PIX series wal EOL'd several years back..I need to replace them..  The static 1-1 nat entries cannot be summarized into network as the hosts that are being nat'd are scattered all over various micro subnets in the all 3 rfc1918 ipv4 address ranges and they are being manged directly by snmp and SNMP-trap and other services that prohibit the use of many-to-one nat.   Is there a mknown maximum number of static 1-1 nat entries that can be defined on the ASA 5515-x, 5525=x and higher ASA firewalls?  Say I wanted to be able to grow to 2500 or more static 1-1 nat entries.  I am currently running 2010 1-1 static host nats currently.

View 1 Replies View Related

Cisco Firewall :: 5585x - Threat Detection Log Entries In Multi Context Mode

Dec 29, 2012

We have a 5585X running in multi context mode, and we are getting log entries for scanning threat detection, such as:
 
%ASA-4-733100: [ Scanning] drop rate-1 exceeded. Current burst rate is 2 per second, max configured rate is 10; Current average rate is 5 per second, max configured rate is 5; Cumulative total count is 3116
 
Threat detection is not supported in multi context mode so I cannot tune the thresholds, is there any way that I can get rid of this outside of messing about with logging levels/message IDs?

View 2 Replies View Related

Cisco WAN :: How To Convert From LSA Type 5 To Type 3 And Reverse

Nov 28, 2012

I have some LSA type 5, I want to change it from type 5 to type 3 before send to another Area, How can i do it?

View 1 Replies View Related

Cisco Firewall :: ASA5520 With Different CPU Type?

May 16, 2011

We want to use ASA5520 but both Firewall have different CPU. One has CPU Pentium 4 2400 MHz and another has Pentium 4 Celeron 2000 MHz. Can it be configured for replica / failover?

View 5 Replies View Related

Cisco Firewall :: AnyConnect 3.0 Profile Drop-down List

May 2, 2012

Working as a consultant I find it annoying I cannot see a drop-down list in the AnyConnect client as you can with the traditional IPSEC VPN client with multiple profiles. How to modify the default profile to list multiple entries?

View 5 Replies View Related

Cisco Firewall :: 887VA-W Keep Getting Drop Packet Error Message

Jul 13, 2012

I have an 887VA-w connected at home. I am using ip virtual-reassembly an all interfaces (dialer and all internal VLANs), I am also using CBAC (currently setting up ZBF). The issue I am having is that I keep getting drop packet error messages and the reasons can differ. Below are some of the outputs I recieve: [code] I have done a show ip virtual-reassembly on all the interfaces and the counter is shown as 0.

View 6 Replies View Related

Cisco Firewall :: Drop Rate-1 ASA 5505 Web Server Not Accessible

May 8, 2012

My web server was down for the day now it's back on but the ASA not accessible with error drop rate-1 exceed

View 3 Replies View Related

Cisco Firewall :: Resolving Drop During Port Forwarding On ASA5500

Jan 10, 2012

I am attempting to port-forward on an ASA 5500 to internal host .100. The outside interface recieves its IP via DHCP. Packets are being denied so I ran packet-tracer and get the following error from outside to ssh port on internal host.
 
#packet-tracer input outside tcp 79.x.x.x 1025 71.x.x.x ssh
 Phase: 1
Type: ACCESS-LIST
Subtype:
Result: ALLOW
Config:
[Code]...

View 7 Replies View Related

Cisco Firewall :: ASA 5550 Proxy Inspector Drop Reset

Dec 19, 2012

Outside users with certain public ip addresses are not able to access our website.  Below is a log from our ASA 5550 8.2(5)  on one of the clients that's being dropped.  Packet trace result shows that the outside public addresses are allowed.  We do have a TAC case open.

View 1 Replies View Related

Cisco Firewall :: Remote VPN User Client Type On ASA 8.3?

Jun 21, 2011

It seemed that show vpn-sessiondb ra-ikev1-ipsec will not provide the client type of the remote vpn user as show vpn-sessiondb remote did before.
 
Is there a way to find it out on ASA running 8.3?

View 1 Replies View Related

Cisco Firewall :: ASA5510-BUN-K9 / Find Out Rate-limit Drop Source Ip?

Nov 22, 2011

I have two ASA5510-BUN-K9 Fws and I am planning to buy 2 x L-ASA5510-SEC-PL= to put them in HA.I was wondering if the support contract that I curently have for the two ASAs is still valid or do I have to buy any support upgrade?

View 1 Replies View Related

Cisco Firewall :: How To Configure ASA 8.2(4) Not To Drop Packets With IP Option 7 (record Route)

Oct 21, 2012

How to configure ASA not to drop packets with ip option 7 (record route)?  According to the docs, ip inspect ip option will drop all ip option packets except 0,1,and 20 (EOOL, NOP, or RTRALT):
 
"If an IP header contains additional options other than EOOL, NOP, or RTRALT, regardless of whether the ASA is configured to allow these options, the ASA will drop the packet. "
 
Also, policy-map type inspect ip-options treats only these 3.

View 1 Replies View Related

Cisco Firewall :: PIX 506E With 2620 Which Type Of Cable Is Required

Sep 20, 2012

I like to set up a pix and router for this network for a small buss, but I need to know what type of cable do I need to set this connection to work straight through or a cross over cable?   also I need a subgestion if a nat would work better on the pix or leave it on the router?

View 4 Replies View Related

Cisco Firewall :: 5505 Cannot Type In Commands In Putty Or Hyper-terminal

May 5, 2013

I have a Cisco ASA 5505. This has been previously configured. I am trying to give it a factory reset and I am being able to connect via Putty and Hyper-terminal but I cannot enter anything. I am able to go into ROMMAN mode by using the esc key.

View 6 Replies View Related

Cisco Firewall :: ASA 5550 Switch - Change Media Type Command On Interface

Oct 12, 2011

I am switching a switch connecting to the ASA5550 tomorrow. My current switch is using fiber connecting to the ASA. The new one only support copper. If I switch between fiber to copper on the ASA (change media-type command on interface) will it cause a down time? I have VPN tunnel on the ASA and don't want the session to reset.

View 2 Replies View Related

Cisco WAN :: Way To Capture Packets Getting Punted To CPU In NPE-G2?

Jan 10, 2011

While troubleshooting high cpu due to interrupts on platforms like 6500 or 7600 we can capture the packets getting punted to the CPU using netdr or on 4500 I think we can even use monitor session. But is there a way where we can capture/sniff packets reaching the CPU on a 7206vxr with NPE-G2?

View 6 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved