Cisco Firewall :: ASA 5515 Failover Does Not Work Anymore
Aug 12, 2012
I have two ASA 5515 configured as active / standby. I configured the failover and I checked for proper operation. But when I configured access rules and NAT, I realized that the failover does not work anymore: two interfaces, inside and outside, are "Unknow (Waiting)". The other LAN interface and management are "Normal (Monitored)." [code] It is possible that some access rule deny the communication between the two asa?
View 9 Replies
ADVERTISEMENT
Apr 17, 2011
I am having ASA 5520 with active/standby configured. Around 2 days ago, the ASA stopped responding & all of my websites stopped working. when i checked the failover status it said that failover is off. I had to manually turn the failover to start my traffic flow.During this time my secondary ASA was not responding. After some time, the primary stopped responding & secondary became active......to solve this i had to make the secondary unit as failover unit primary & the primary unit as failover unit secondary. i did get a log on ASA :-
“(Primary) Disabling Failover” with error message no.105001 which states the below:-
Error Message %PIX|ASA-1-105001: (Primary) Disabling failover.
Explanation In version 7.x and later, this message may indicate the following: failover has been automatically disabled because of a mode mismatch (single or multiple), a license mismatch (encryption or context), or a hardware difference (one unit has an IPS SSM installed, and its peer has a CSC SSM installed).(Primary) can also be listed as (Secondary) for the secondary unit.
View 1 Replies
View Related
Jul 25, 2011
I have a W7 PC 64 bit system and I've been trying to port forward the port 25565 for my Minecraft server. However for some reason (even after port forwarding the right one) people still can't connect. When I check on Open Port Check Tool - Test Port Forwarding on Your Router It still says that the port 25565 is closed!I've even created an Inbound and Outbound rule in the Windows Firewall advanced settings. I use Avira Anti-vir fyi..
View 19 Replies
View Related
Nov 8, 2012
I just upgraded my dell inspiron r15 to windows 8.my bluetooth does not work any more I tried updating the driver it shows Activate bluetooth using wireless switch even tough its on....
View 1 Replies
View Related
Apr 21, 2009
I have a 3845 running 12.4.13a which I want to upgrade to 12.4.24.After upgrade one of the interface that is configured for frame relay doesn't work anymore.In fact is the "service-module t1 timeslots" commands that can not be executed and the router throws that error.I tested this behaviour on two 3845s and the result is the same.Is this a bug or is an workaround for it?
View 3 Replies
View Related
Jul 18, 2011
Comcast sent out a new modem a few days ago. The reason for this was our internet had gone out for a while, they came in and said our modem was fried. I have internet access by directly wiring from the modem to my computer.My router doesn't work anymore. I have a local network, but no internet access. I'm using a Linksys WRT54G, and I don't really know what to do.As far as I remember, setting everything to defaults and factory settings was how I set up my router in the first place and it just worked.
View 11 Replies
View Related
Jan 12, 2012
I had the website filter ON and it was working very well to block a few websites on a schedule. And after a few month, it doesn't work any more. While it is possible that I scewed up the setting , I have tried so many settings.
So:DIR655 fw 1.32NA,hw A3,"Enable access control" is on with the desktop MAC address (used copy this MAC)(I have also tried my laptop MAC),web site filter is set to "deny",the router time is set using NTP dlink server,
View 3 Replies
View Related
May 17, 2011
I have several ports opened on my DIR-655 A3, pointing to specific ports on a NAS server i have on my network.
I've already try this:
- Reboot the router
- Erase all Virtual Server Settings and try open only one port
- Re-flash the router with latest European firmware - 1.34b05EU
View 11 Replies
View Related
Mar 5, 2013
I am currently migrating a netscreen firewall to a asa 5515 version 8.6 The issue is setting up the management connectivity.
basically the management IP of the cisco asa is not advertised. But, we want to route a management IP through the management interface to interface Gi0/2.
so IP of management interface is say - 216.10.100.10. and the IP of the inside interface is say - 198.1.1.10/24 on our router we have a static route sending 198.1.1.0/24 to next hop of 216.10.100.10 (management interface of cisco asa).
On the Cisco ASA can I send the traffic to the inside interface and manage the firewall via ssh that way?
View 4 Replies
View Related
Aug 29, 2012
I have a ASA 5515-X-IPS firewall and I want to communicate firewall through ASDM-IDM. Already done the below procedure;
•1. Connect cable to Management port.
•2. Open browser and type https://192.168.1.1/asdmin and download the ASDM-IDM Launcher v1.5(55) and install my laptop(OS: windows 7)
•3. Connect asdm-idm launcher we put IP Address: 192.168.1.1 and username, password enter.
Just whenever we login the wizard then the message shown “ Unable to connect the asdm manager”For your kind information we already setup jre6u7 java software.
View 1 Replies
View Related
Sep 16, 2012
A customer contacted us that he can't connect his devices via web since he changed the IP address. Ok, big laugh "type the correct IP" but no. Even if you use the correct IP, no user can't connect anymore to the device. Also via CLI!The only thing that worked was the password recovery procedure. After that everything worked fine.The customer and me tried it again with another 2960, maybe there went something wrong when he did it last time and it was an accident. Nice thought but no: another device same error, no login possible.
View 1 Replies
View Related
Oct 28, 2012
Is there a way through the CLI to have the ASA 5515-x power back on after a power failure? Currently, the only way to restore power is to press the power button. The X series does not have a power switch the same as the 5500 series.
View 1 Replies
View Related
Mar 29, 2013
I am trying to connect 2 VMWARE servers directly to my 5515-X firewall. [code]ASDM will not let me assign the same VLAN to both Gi0/2 and Gi0/3. I dont want to connect my VMWARE servers to a switch first (that just adds one more component that can fail).
View 4 Replies
View Related
Apr 22, 2013
We are trying to get Teamviewer to work on our WAN, from the log traffic from the PC's to our Cisco IronPort Web Filter it looks like the ASA Firewall is blocking the traffic. We have opened everything we can open on our Cisco IronPort Web Filter and I have a Cisco TAC case open and they said it appears the ASA Firewall must be blocking the traffic.
View 3 Replies
View Related
Oct 10, 2012
i need to configure a new ASA 5515-X with a 3 trunk port for vlans that become from switch, but i need turn on IPS in in-line mode, somebody has an example and limitations for this configuration type?
View 3 Replies
View Related
Oct 22, 2012
i would like to use ASA 5515-k9 with Antivirus and antispam but i don't know the part number that support this and how it process .
View 3 Replies
View Related
Mar 18, 2013
I´m triing to setup a QoS policy on ASA 5515, i read several pages, but my questions are, how setup the real BW?, or is not necessary to do this?
View 7 Replies
View Related
Mar 23, 2013
Recently we migrated our network to ASA 5515, since we had configured nat pool overload on our existing router the users are able to translated their ip's outside. Right now my issue was when I use the existing NAT configured to our router into firewall, it seems that the translation was not successful actually I used Dynamic NAT. When I use the Dynamic PAT(Hide) all users are able to translated to the said public IP's. I know that PAT is Port address translation but when I use static nat for specific server. The Static NAT was not able to translated. Any conflict whit PAT to Static NAT?
View 3 Replies
View Related
May 5, 2013
We have one Cisco ASA5515 firewall, I configured ftp mode to passive, inspect ftp in service, use anoother public to do NAT with ftp server, and also configued ACL in outside interface, but I failed to access the ftp server from internet use that public ip address, no problem to acces the ftp server use its inside address in LAN.
View 9 Replies
View Related
Apr 21, 2013
I've got a little problem with my ASA 5515-X after upgrade from version 8.6 to 9.1.
I've got two 5515-X in A/S-mode and upgraded both as described on cisco's website (first standby-unit, failover, etc.). Everything worked just fine except pinging the ASA-interfaces themselfes. Before upgrade it was possible to ping from any subnet to the internal interface, but now it's not. If I'm on the router next to the ASA I'm able to ping, but every ping from behind that router fails. The ICMP-packets get into the ASA (counter on ACL raises up), but no reply is getting into the source.
The configuration fir ICMP was not changed and says "permit 0.0.0.0 0.0.0.0" for any ICMP on the internal interface. The router betwenn my subnet and the ASA has no ACL installed and - as said above - the ICMP gets obviously to the ASA but doesn't come back!?
View 4 Replies
View Related
May 12, 2013
I was purchase ASA5515-K9 (Without IPS Edition) firewall and this is run smoothly our network. But right now i want to IPS facilities. Can i have any licnese purchase and upgrade from ASA5515-K9 to ASA5515-IPS-K9 abd use IPS edition ?
View 1 Replies
View Related
Dec 5, 2012
I am working on translating configuration from a firewall named Joe box to ASA 5515. On Joe box, it has 5 continuous public IP addresses (xx.xx.xx.73 -77/29), first one as interface IP and others as alias, on the Internet-facing interface. I need to configure ASA 5515 in the same way, however it seems not simple.
- The way to configure sub interfaces on 5515 is by configuring V LAN.
- The interface can hold xx.xx.xx.73/29 without a problem.
- The first sub interface can have IP address xx.xx.xx.74 however with different mask(/16), as it doesn’t allow /29.
- The second sub interface doesn’t allow to enter IP xx.xx.xx.75, saying "Failed to apply IP address to interface GigabitEthernet0.x, as the network overlaps with interface GigabitEthernet0. Two interfaces cannot be in the same sub net."
View 6 Replies
View Related
May 17, 2013
im changing the firewall 5510 to 5515, with ASA5510 the incoming and outgoing calls work perfectly, but when i active the 5515 the outgoing calls doesnt work, only the incoming calls work.
As you see on the topology,the flow of calls happens this way:
In the outgoing calls the phone forward the call to the PABX(172.17.3.4), and the PABX forward the call through the ISP LINK to SIP SERVER (10.140.131.208). The incoming calls occur in the reverse path.
ASA 5510 config:
ASA Version 7.0(8)
name 172.17.3.4 PABX
dns-guard
!
!
interface Ethernet0/1
[Code]...
View 1 Replies
View Related
Jan 8, 2012
Im changing the firewall 5510 to 5515, with ASA5510 the incoming and outgoing calls work perfectly, but when i active the 5515 the outgoing calls doesnt work, only the incoming calls work.
As you see on the topology,the flow of calls happens this way: In the outgoing calls the phone forward the call to the PABX(172.17.3.4), and the PABX forward the call through the ISP LINK to SIP SERVER (10.140.131.208). The incoming calls occur in the reverse path.
ASA 5510 config:
ASA Version 7.0(8)
name 172.17.3.4 PABX
dns-guard
!
!
interface Ethernet0/1
description ***ISP SIP Network***
[Code]....
View 1 Replies
View Related
Apr 14, 2013
I'm starting my configuration and i created a test environment side by side with my production. i just run startup config and connected my ad-test.com AD host to it. i can ping ad-test.com from console, ok. but it can't get internet from inside environment
here's the config..............................
: Saved
: Written by enable_15 at 07:56:40.638 UTC Mon Apr 15 2013
!
ASA Version 8.6(1)2
[Code].....
View 8 Replies
View Related
Dec 19, 2012
Why do my cli commands just scroll all the content rather than having to press space to show more? It is hard to type sh run and the entire config flays past rather than being to inspect it page by page.
View 3 Replies
View Related
Feb 27, 2013
I just would like to know if possible to block the multiplayer games?? I'm using ASA 5515-X.
View 2 Replies
View Related
Mar 24, 2013
The datasheet contains the following regarding rails and brackets:
Cisco ASA 5512-X, 5515-X, 5525-X, 5545-X, 5555-X spare rail kit - ASA-RAILS=
Cisco ASA 5512-X, 5515-X, 5525-X brackets for rack mounting - ASA-BRACKETS=
The word spare seems to imply that it comes with a set of rails. Does the ASA-5515-X come with rails and brackets, or must both of these be ordered?
[URL]
View 4 Replies
View Related
Apr 15, 2013
I have a 5515 ASA that has the webVPN configured on it and it is using active directory to authenticate. The client would like to set up groups in active directory and restrict access to those groups when they are connected to the webVPN. For example, they have a group in active directory that they only want to access their "web" interface. What is the best way to configure this on the asa?
View 2 Replies
View Related
Nov 25, 2012
I am moving from ASA 5505 to ASA 5515 because we are maxing out the number of connections that the 5505 can handle. The 5515 runs version ASA 8.6(1)2 and ASDM 6.6(1) and the 5505 version is ASA 8.2(5) ASDM 6.4(5). On the 5505 I used e0/0, 0/2, 0/4 and 0/5 as outside port with teh switch ports feature but there is no switch port feature on the 5515. I have tried to set the ports individually to numerous public IP addresses that I have but I get an error that they subnet is already associated with another interface. How do I replicate the same setup on the 5515?
View 3 Replies
View Related
Aug 7, 2012
where I can find detailed documentation on these two products. Particularly, I am looking for high availability capabilities and any license requirements.
View 1 Replies
View Related
Jun 3, 2013
Worried about denial-of-service attacks. They have 11 vm's that share a connection and want to set it up so that there is a maximum amount of traffic allowed to hit each vm, so if there is a DDoS attack it will only affect that one VM instead of all the VM's on the same connection.
What is the best way to go about this from the ASA? This is behind a 5515 with asa code version 8.6. Is there a way to rate-limit by ip address?
View 1 Replies
View Related
Apr 17, 2013
We installed a new ASA 5515 about a month ago for the corporate office we also have 40 branch locations that feedback VOIP, camera, and Citrix to the corp location. Each of the branch locations have a separate DSL connection with a local provider and all of them are dynamic IP addresses.
The problem I have is that I cannot figure out a access rule to make the voip traffic work 100% of the time what ends up happening is five or six random locations change IP address's every day and I could not figure out how to create a access rule for that so I create a static route with that dynamic IP and then it will change a week or so later. That's a horrible security risk and a lot of manual work.
View 4 Replies
View Related