Cisco Firewall :: ASA 8.4 NAT Command Selection

Jul 4, 2011

I am designing a new NAT configuration for an ASA 8.4
 
On my PIX 8.0 configuration I needed to allow bidirectional traffic between interfaces with different security levels.  For example, Inside at 100 and dmz at 50.To accomplish this in 8.0 I used a static NAT command along with any necessary ACLs.

 I now need to apply this same 8.0 config for 8.4.  With the static command not availablein 8.4 I am unsure of which NAT commands to use to achieve the bidirectional traffic.

View 1 Replies


ADVERTISEMENT

Cisco Firewall :: ASA 5510 Model Selection

May 4, 2011

Our company is in the process of replacing our old firewall with a Cisco ASA since our old firewall can handle only 170 concurrent users and we are expanding fast. Can I know what are the considerations when selecting from the different models of ASA currently we are debating if we should buy a 5510 or a 5520 also can I know if cisco ASA also have a limitations on concurrent users online in a lan like our old firewall. By the way we are a Call Center company(going 500 seats) so we are using VOIP(Asterisk using SIP and IAX).

View 1 Replies View Related

Cisco Firewall :: NAT Command Conversion PIX 6.3 To ASA 8.4(2)

Dec 28, 2011

I am in the process of migrating a production firewall from PIX 6.3 to ASA 8.4(2). This is going to be a complete firewall rebuild and I will not be upgrading the configs because they have become out of date and very bloated. I am in the process of converting the NAT commands.[code] I am hoping these commands would be enough to replicate the previous functionality. I removed all the static identity NATs because NAT control is no longer in place so those rules are not required. Additionally I didn't re-create the rules that had NAT ID 0 or 1 because it didn't look like they were doing anything. correct way to do the static NAT commands at the bottom.

View 3 Replies View Related

Cisco Firewall :: What New Command Is For NAT In Version 8.3

May 29, 2013

what the new command is for NAT in version 8.3?The config i have is from Version 7.2 and doesnt work on 8.3. [code]

View 12 Replies View Related

Cisco Firewall :: 5505 - Command Changes From 7.2 To 8.6

Mar 10, 2013

I'm coming from a 5505/5510 ASA to a 5512x. I see the following 7.2 commands are now set with the NAT command in 8.6:
 
-------------begin 7.2 commands---------------------
global (outside) 1 interfaceglobal (inside) 10 interfaceglobal (wireless) 1 interfacenat (inside) 0 access-list nonatnat (inside) 1 192.168.3.0 255.255.255.0static (inside,outside) tcp interface www 192.168.3.114 www netmask 255.255.255.255static (inside,outside) udp interface 5008 192.168.3.117 5008 netmask 255.255.255.255static (inside,outside) tcp interface 3390 192.168.3.101 3389 netmask 255.255.255.255static (inside,outside) tcp interface h323 192.168.3.118 h323 netmask 255.255.255.255
--------------end 7.2 commands----------------------

View 10 Replies View Related

Cisco :: Command To List Firewall Rules?

May 17, 2012

Boss wants a listing of the firewall rules only. What's a command I can run that will give me a listing of this?If I can get an output of firewall rules only, via GUI, that'll work too. It just needs to end up with a printout on a piece of paper telling me what the firewall is doing.

View 17 Replies View Related

Cisco Firewall :: ASA 8.4 - New Configuration To Replace Old NAT 0 Command

Jan 15, 2012

What is the new configuration in ASA 8.4 to replace the old "nat 0" command.

View 1 Replies View Related

Cisco Firewall :: Command For Configuring NAT On ASA5505?

Dec 5, 2012

want to know the command for configuring NAT on My ASA5505.

Local IP - 192.168.1.0/241

Public IP - 182.73.109.118 255.255.255.252

View 4 Replies View Related

Cisco Firewall :: Need Pix 506E Version 4.3 Command

Nov 19, 2012

I have a PIX506E that was resently reset and it has version PIX Version 7.1(2) .  It either uses some different commands or I am not using them correctly. [code]

View 2 Replies View Related

Cisco Firewall :: ASA 5580 Command Itself Is No Longer Used

Mar 5, 2011

i'm new with the asa's...i'm familiar with the FWSM's on 6500's and pix..I'm running Version 8.3(2) and i wanted to setup nat-control and use of identify nats for advertising inside subnets to my outside networks.
 
the old command was static(inside,outside) 10.x.x.x 10.x.x.x netmask 255.255.255.x i'm having a little difficulty decyphering the pdf about the static nat...the command itself is no longer used, nat-control is no longer used, but i'm not quite sure what the equivalent nat command is that equates to the old static inside,outside command.

View 8 Replies View Related

Cisco Firewall :: Save Command Output To Flash On ASA 8.4?

May 28, 2012

How do you save the command output from the CLI  to a file on flash?
 
With IOS, I would normally use a pipe command to redirect to tftp, but the ASA doesn't support this as far as I can tell. As a work around I was thinking I could save the output to flash and then tftp that file off the ASA.

View 5 Replies View Related

Cisco WAN :: 2921 How To Access Firewall From Command Line

Jun 11, 2012

we just bought a 2921 with the following modules: 4 port clear channel T1/E1 HWICSM-ES3G-24-P: EtherSwitch.I read some CISCO documents, and not be able to find what I need. I would prefer all instructions from you are for CLI interface.This is my first time to deal directly with T1, WIC and 2921 etc. The following is what I get from ATT, IP masked IP Address Block IP Address: 20.20.20.136/29 WAN Link Details: WAN Link IP Address:13.13.13.92 AR Serial INT IP Address:13.13.13.93 CR Serial INT IP Address:13.13.13.94 WAN Link Subnet Mask:255.255.255.252
 
A: how do I configure T1, what does "AR, CR" stands for, and do I need to use both IP addresses? What is the WAN Link IP for?
 
B: We have two T1 lines, so I should plug them both to the WIC, say port 0 and port 1, how to configure them?
 
C: how do I access the firewall from the command line?
 
D: I followed T1/E1 HWIC installation guide, and as soon as I add channel-group to the controller t1, the serial interface went down?

View 2 Replies View Related

Cisco Firewall :: 5580 Do Static Command Needed

Oct 3, 2011

The firewall is running version #8.2 on ASA 5580. Address translation is not needed on Inside network and Outside network.But the customer has hundreds of static command as below.. [code] Can they all be removed and replace with one single command as below? 

View 1 Replies View Related

Cisco Firewall :: Asa 722 Asdm Location Command After Upgrade

Sep 3, 2008

Before running firmware asa722-k8.bin and asdm-522.bin ASDM "asdm location" config lines were created when we created a network object. After the upgrade to asa722-k8.bin and asdm-522.bin this dissapeared.We recently upgraded to asa724-k8.bin and asdm-524.bin which brought those config lines back.So if "asdm location" is needed, if not can we make sure those lines wont pollute the config file?

View 3 Replies View Related

Cisco Firewall :: 5520 - ASA 8.6.1 Shape Command Invalid

Jul 9, 2012

Tried setting up a Shape Policy and it states its invalid.  Worked fine on my 5520, just curious to know why its coming as invalid now                  
      
ciscoasa(config-pmap-c)# shape
^
ERROR: % Invalid input detected at '^' marker.
ciscoasa(config-pmap-c)# shape ?
ERROR: % Unrecognized command

View 11 Replies View Related

Cisco Firewall :: ASA 5520 Cancel / Abort Command

Jan 23, 2012

So, I made the fatal mistake while consoled in to do a "Show Run". Now, it is just stuck in that cycle. I tried the usual "Ctrl+Shift+6" command, and even the "Ctrl+6" with no success.

View 5 Replies View Related

Cisco Firewall :: SSH Run Command Output Stuck In ASA 5540

Mar 1, 2010

We have an ASA 5540 failover bundle working in Active/Standby mode. On our active asa 5540 when the sh run command is issued it gets stuck and displays the output after more than 15-20 mins.. and it takes another 10-15 mins to get back to the prompt..
 
However on the standby asa 5540 if the sh run command is issued, it displays the ouput and comes back to the prompt (even though this also takes 2-3 seconds)
 
I have tried rebooting the active asa 5540.We are running asa version 8.2.2.

View 8 Replies View Related

Cisco Firewall :: Cannot Specify RO On Snmp-server Command With Older Pix 501 6.3

Oct 23, 2012

i am wanting to open up snmp on a pix 501 6.3 version.  I am planning on doing it with the following configuration: [code]

I noticed you cannot specify RO on the snmp-server command with the older pix.  I don't want this configuration to open up any write access to the pix.  Is there a way to specify only read only for snmp

View 1 Replies View Related

Cisco Firewall :: CLI Command To Open Ports 80 / 443 And 1882

Aug 23, 2012

I need top open ports 80, 443 and 1882 to a specific external client (IP address).

View 8 Replies View Related

Cisco Firewall :: ASA 8.4 Port Forward Command Request?

May 7, 2013

i can't do it with ASDM and try to use command but still fail
 
nat (inside,outside) source static inside-10.18.20.162 4F-1.1.1.2
 
it is working fine for the above command if there is more than one public ip, in case 1.1.1.1 is for firewall interface public ip?if i have only one public ip and i would like to forward http traffic to my internal network? how can i use command to do that?

View 8 Replies View Related

Cisco Firewall :: IPTables Command Translated ASA 5540 Ver 9.0

Nov 19, 2012

I would like to have these commands on our Firewall to avoid at least several students to use this service. How to translate this? It's apparently working great if I will use an Linux box or another firewall compatible with iptables.
 
iptables -I INPUT -s hotspotshield.com -j REJECT
iptables -I INPUT -s hotspotshield.net -j REJECT
iptables -I INPUT -s anchorfree.com -j REJECT
iptables -I INPUT -s anchorfree.net -j REJECT
iptables -I INPUT -s openvpn.net -j REJECT
 
iptables -I OUTPUT -d hotspotshield.com -j REJECT
iptables -I OUTPUT -d hotspotshield.net -j REJECT
iptables -I OUTPUT -d anchorfree.com -j REJECT
iptables -I OUTPUT -d anchorfree.net -j REJECT
iptables -I OUTPUT -d openvpn.net -j REJECT

View 1 Replies View Related

Cisco Firewall :: Command Authorization In ASA 8.4 For Object Network

Apr 28, 2012

I just tried to do a quick privilege level setup for a user to limit access to asa. User should be able to add nat's to configuration.ASA 8.4 is in question and trying the following does not seem to work:

privilege configure level 3 command object,gives me ,ERROR: specified command 'object' not found in any mode.It looks like localy this cannot be done or I am doing something wrong?

View 1 Replies View Related

Cisco Firewall :: ASA 5500 - Command For Creating Read Only User

Jan 13, 2009

What is the command for creating a user on an ASA 5500 running 7.2(3) that can only view the config but not make any changes?

View 8 Replies View Related

Cisco Firewall :: Command To Check ASA 5520 Is Passing Traffic

May 14, 2012

how can i check that ASA is passing traffic? Also what command we can use to make sure VPN is working fine.

View 2 Replies View Related

Cisco Firewall :: ASA5585 - Debug Command Stops After Exiting

Oct 19, 2011

We are experiencing intermittent issues with the IPS on our ASA5585 vs 8.4(2). Probably something with the dataplane. So I want to keep debug cplane 255 activated and logged with log debug-trace setting to syslog server. But when session times out the debug command is cleared so the output stops. Since it is a intermittent issue I want to keep debug activated...Totally different behaviour then with routers which keeps it activated. how to keep debug activated on a ASA.

View 1 Replies View Related

Cisco Firewall :: Command To Check IPSEC Tunnel On ASA 5520?

Jan 7, 2013

Need to check how many tunnels IPSEC are running over ASA 5520.Tried commands which we use on Routers no luck?

View 6 Replies View Related

Cisco Firewall :: ASA5510 - Applying Static Command / Not Found Error

Apr 3, 2011

I have Cisco ASA5510 OS version 8.4(1), when i try to apply static command, this command is not found, the NAT issues used nat(inside,outside).

So why i can't found this command ?

View 1 Replies View Related

Cisco Firewall :: Cannot Access FWSM Via Session Command In 6513 (VSS Enabled)

Apr 24, 2012

Today i received FWSM from cisco (RMA), I need to configure it as standby unit for existing FWSM active/standby setup.
 
IOS on RMAed FWSM is 2.3.4 and  cisco VSS supports FWSM IOS 4.0.4 and later.My issue is, I cannot access FWSM (IOS 2.3.4) via session command from cisco 6513 but could successfully consoled it without any problem. I have reloaded it twice and also tried to disable and enable power on it.
 
VSS#sh module switch 2
 Switch Number:     2   Role:  Virtual Switch Standby
Mod Ports Card Type                              Model              Serial No.
--- ----- -------------------------------------- ------------------ -----------
   2    6  Firewall Module                        WS-SVC-FWM-1  -----------

[code]....

why I cannot access FWSM through session command ?Whether this is because of older IOS ? If yes then how to upgrade its IOS ?Is it possible to upgrade IOS via FWSM console ? if yes, Do i need to test on different slot ? 

View 2 Replies View Related

Cisco Firewall :: ASA 5550 Switch - Change Media Type Command On Interface

Oct 12, 2011

I am switching a switch connecting to the ASA5550 tomorrow. My current switch is using fiber connecting to the ASA. The new one only support copper. If I switch between fiber to copper on the ASA (change media-type command on interface) will it cause a down time? I have VPN tunnel on the ASA and don't want the session to reset.

View 2 Replies View Related

Cisco WAN :: BGP Route Selection On 65001

Sep 7, 2011

I have a router with 2 WAN (MPLS) connections to two different IPSs.One connection is a 3mbs MLPPP connection and the other is a 10mbs MetroEthernet connection.Both use BGP to peer up with the ISP with private AS numbers (65001, 65002, etc)I want the router to always prefer (use) the BGP connection through the 10mbs link, but here are my considerations:I can't change the prefix length for the peers. In other words, BGP 65001 is going to advertise 192.168.21.0 /24 to its peer, and BGP 65002 is going to advertise the same network with the same mask.What is the best way to make sure the 10mbs link is always preferred? Can I do local preference?

View 6 Replies View Related

Cisco :: LMS 4.2 Sub-interface Not Available In Instance Selection

Apr 26, 2013

I have sub-interfaces created on the switch and are in active(up/up) state,but these sub-interface not available for selection in the instance window while creating the poller, and am not able to monitor the traffic on these sub interface in the performance management.
 
LMS will not display the interfaces in the instance selection window if they are not active, but here the sub-interface are in active state but these are not available.

View 1 Replies View Related

Cisco WAN :: 6509e BGP Outbound Path Selection

Sep 20, 2012

I multi homed to dual ISPs using a single 6509e. Currently, I am only receiving a default from wash ISP and marking one with a higher local pref. most of my traffic flow is inbound, so this config meets my need. The issue I have: if either ISP has has an outage upstream from my directly connected peer, my router does not detect that and continues to send traffic out thru that provider only to be black holed. My 6509 will only support 256k routes, so full route tables isn't an option. I could receive partials from each ISP. Is there any other method to detecting this upstream ISP issue and then adjusting my local pref on my default to use the alternate provider path?

View 3 Replies View Related

Cisco WAN :: 6509E - BGP Outbound Path Selection

Mar 4, 2013

I  multi homed to dual ISPs using a single 6509e. Currently, I am only receiving a default from wash ISP and marking one with a higher local pref. most of my traffic flow is inbound, so this config meets my need. The issue I have: if either ISP has has an outage upstream from my directly connected peer, my router does not detect that and continues to send traffic out thru that provider only to be black holed. My 6509 will only support 256k routes, so full route tables isn't an option. I could receive partials from each ISP. Is there any other method to detecting this upstream ISP issue and then adjusting my local pref on my default to use the alternate provider path?

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved