Cisco Firewall :: ASA Software 8.2 And Earlier Required
Jan 10, 2012
I'm in the process of migrating a rather big NAT configuration from a customer running pre 8.2 ASA software.The customer has 2 Dynamic Policy NAT configured which have overlapping source addressesOther Dynamic Policy NAT has the destination address of "any"
Other Dynamic Policy NAT has a single host address as destination address towards InternetThe Dynamic Policy NAT configured with the "any" destination is applied to all translations for the source host towards Internet
What I'm interested in is the following
Since both NAT statements are equal in a sense (because they are of same type) what is the next deciding factor for ASA decides which translation rule to use?
Does the "nat_id" parameter define which rule is checked first? Is the NAT rule with the lowest "nat_id" value used regardless what the order of the NAT rules is when you check them on the CLI? (with "show run global" and "show run nat")I'm just interested on how the NAT operates in this case, even though were generally using 8.4 at the moment.
View 6 Replies
ADVERTISEMENT
Jan 6, 2011
My problem is that when i try to use device manager it tells me mmc cannot run a version of internet explorer earlier than 5.5 and i have internet explorer 7. One thing is that we dont use interent explorer any more we use american online but we still have internet explorer. We got rid of it when we stopped wanting to pay for it. And if i try to hook up the modem for this the dsl light keeps flashing red and everything else is green i dont know why it is red i set up everything. i used the splitter and powered the modem and put the ethernet cord into the back of my xbox and then used the spiltter for the phone line thing and connected the phone line to the back of the computer to the phone thing on the splitter and then used the dsl cord to the back of the modem and on to the splitter.
View 1 Replies
View Related
Feb 9, 2011
My wife had someone at her school make changes to her laptop (she dosn't know what) so that she could use the school's network (it did not work). Now that she is at home the laptop will not connect to the wireless home network. Is there a way to restore the laptop to a date before the changes were made ?
View 1 Replies
View Related
Feb 27, 2012
I have a win 7 pc networked to several xp desktops and notebooks, nas, wired network printers, and all works well. Its no big deal but everything I look at to do with my network on my win7 pc says its network5. Is there a way to have this network 1 which I assume it was once? Does this mean that there is also junk hiding within my network as to the configuration of 4 earlier networks?
View 13 Replies
View Related
Nov 15, 2012
I am quite new to firewall, in my company one asa 5510 firewall is there.I configured inside, outside, dns, dhcp and nating.I need to config bandwidth limit (1Mbps) for inside port and I restruct like facebook, youtube and pornsites..And I heard that some subscription is required, really is it required?
View 1 Replies
View Related
Mar 31, 2013
I have one firewall need to be configured in transparent mode. I have inside and outside router. What is the configuration of transparent firewall ASA8.2. I didn't find the configuration on Cisco site.
View 17 Replies
View Related
Oct 18, 2011
I am very confused on how I setup a Pix 515 that I just got to route traffic out a cable modem. First, let me give you a little details on my current network setup and what I am trying to accomplish with this Pix 515. Currently all my users go out the proxy for any internet access, however I have certain users that need to go out the cable modem instead of the proxy server. Below is an example of the current IP setup of a user A:The cable modem that we currently have has DHCP so I would need the external PIX address to accept a DHCP address. I also don't really understand what else I need to setup so if I have say four users hitting the cable modem through the pix how do I direct their web traffic to the correct computer (NAT ?),I will be plugging the PIX into a cisco switch that all ports are in VLAN 48 so hopefully a static internal address on the pix of 10.24.48.254 will keep me from having to do any routes since all traffic will be originating from the 10.24.48.0 network.
View 1 Replies
View Related
Jun 14, 2011
I have two ASA 5510 with Security Plus license and Shared SSL VPN licensing enabled.
The problem is that the client get “Session could not be established: session limit of 25 reached” but ther is only 6 ssl vpn user connected with AnyConnect.The software on the firewall’s is 8.2(1)Is there any BUG in this software related to this problem?
View 1 Replies
View Related
Jun 6, 2012
We have purchased a new Websense 10000 Appliance and I'm not a hundred percent how to set this up. I see that URL Filtering is a possibility and WCCP, which way to move forward on implementing this?
View 4 Replies
View Related
Apr 19, 2011
I am trying to set up my Cisco 520 router with a firewall that will: Allow port 80 traffic to the vlan 20,Block all other incomming ports to vlan 20 (unless initalised from inside),Allow all outgoing ports on vlan 20,Block all access from vlan 20 to vlan 10 (unless initalised from vlan 10)
View 35 Replies
View Related
May 16, 2011
I upgraded my ASA 5520 with the latest image. Now I get an error upon launching ASDM.Your ASA image has a version number 7.2(4) which is not supported by ASDM 6.4(1), use Device Manager version 5.2(x)Continue Anyway?
What are the newest, recomended image versions of ASA and ASDM I should be using?I will also be using the SSM-20 module with this setup, so I would like to stay with a working version of ASDM.
View 1 Replies
View Related
Apr 29, 2013
I have a problem with the configuration of the ACL of my ASA 5505 router.However, the syntax seems okay,access-list 121 extended deny icmp 192.168.0.0 255.255.255.0 .
View 3 Replies
View Related
Jan 1, 2012
I am looking into buying an ASA5505 but I would like to know if it is going to work in my setup. I have an Internet connection and 2 seperate networks. I know that the ASA5505 has 8 ports and I would like to know if I can assign each port to a different network zone? I dont want to use VLAN but physical networks. I know it is possible with ASA5510 and above but I want to make sure I can do the same with a ASA5505 (Without the security upgrade). I want to get an ASA5505 unlimited users.
So an Internet connection (with multiple IPs), 2 seperate networks, I want to filter traffic between all 3 and route between them also.
View 2 Replies
View Related
Aug 17, 2011
I am looking at upgrading an HA pair of ASA5520's from 8.2(2) to 8.3(1), and am just wondering why the huge upgrade in memory is needed. How are Cisco justifying where the additional memory is going to? Are there supposed to be some massive improvements in performance?
View 2 Replies
View Related
Jul 13, 2011
I have existing Sonic FW in my company we are moving from sonic FW to ASA 5510 Security plus lice. I have two ISP currently connected to sonic Firewall I am planning to implement Dual ISP configuration on ASA5510.
View 12 Replies
View Related
Nov 27, 2011
I have an ASA 5501 running latest code. Per the article at [URL], I need to open the below ports. I have 5 Xboxes (when people come over) and they all have a static IP. My network is 192.168.0.x and is a /24 network.Xbox LIVE requires the following ports to be open: Port 88 (UDP)Port 3074 (UDP and TCP)Port 53 (UDP and TCP)Port 80 (TCP)port 1863 (UDP and TCP) (Kinnect) I defined the various network ports as a service and then created 5 hosts called xbox1, 2, etc with a static IP. I dont have access from the command line (forgot telnet and ssh passwords) , so from the gui, what do I do next?
View 7 Replies
View Related
Feb 27, 2012
I have a 5505 configured with a active/standby dual wan setup using the sla tracked connection settings. Is there a way to configure the ASA to stay on the backup connection after activating? We had a situation where the main T1 was bouncing, so the backup connection was being activated and deactivated very often. The problem is that there is an app being used that does not allow users to reconnect to dropped connections immediately, so every time the asa switches wan connections it causes a significant disruption.I should note that I already set monitor options frequency to 240 seconds. I could set it higher, but then we have a longer delay when the main connection dies.
View 2 Replies
View Related
Feb 24, 2011
Is there a Security Plus trial license available for the ASA 5500 series? I currently have one sitting around that I would like to use for testing, but it only has the base license.
View 2 Replies
View Related
Sep 20, 2012
I like to set up a pix and router for this network for a small buss, but I need to know what type of cable do I need to set this connection to work straight through or a cross over cable? also I need a subgestion if a nat would work better on the pix or leave it on the router?
View 4 Replies
View Related
Oct 16, 2012
I've gotten to the point where I can test against active directory and get in, also I can get AD groups from my server on the ASA. My problem, I can't connect in via my AnyConnect client on my Android. I immediately get a "log in failed" and I know I'm using the right username/pass. Doing a little troubleshooting, I have attached my AnyConnect debug log and the results of the "debug ldap 255" command on the ASA. Also, I've used ldp.exe to determine I can connect in with the username/password combo I'm using.Combing through the AnyConnect logs I see a few instances of "global error unexpected" but no Google searches have brought up anything useful.
View 7 Replies
View Related
Mar 10, 2012
I got a project where I have to provide NATTED addresses to cutomers for the internal servers and I found out that the outside address range /27 already in use. We are using 5510 with ver 8.1. We cant use PAT here.
View 1 Replies
View Related
Jan 20, 2013
My ASA 5505 getting pretty hot after a while and so I used a wattmeter to find out what´s happening.
260 watts is quite a lot if the device is running in idle mode and has no active device attached nor any config has been installed.
What's your experience of the ASA 5505 power consumption ?
View 1 Replies
View Related
Oct 1, 2012
Is it required for the 3des license upgrade for the asa5510 to reboot for the further configuration of site2site tunnels.
View 1 Replies
View Related
May 15, 2011
Due to a bug int the IOS (F4 loosing routing information) i needed to upgrade the IOS from 15.0.1-M4 to the latest one which is 15.1.Is it ok to do without valid Smartnet contract? Cisco website allowed me to download the IOS and then put it on the router.Due you need some sort of a license to upgrade the IOS?
View 3 Replies
View Related
Aug 14, 2011
I'm running LMS 4.0 as an evaluation and I'm only discovering 86 devices, using the auto discovery. I've added a seed and although it sees lots of neighbours on that seed it only goes on to discover devices off a particular range. All the devices are set up the same way (standard config) so it should see them as well.
I know it has a limit on the number of managed devices of 100, and I could understand if it hit 100 and then stopped. We have around 500 devices in total (not including phones, DMPs, etc).
I've just added the seed and selected cdp as discovery method and set the snmp target as *.*.*.*. Is there anything else I should be doing?
View 1 Replies
View Related
Jan 5, 2012
I have a customer that purchased an LMS 3.0 package and later upgraded it to LMS 3.2 using same license for 300 devices.Now the customer wants to upgrade to LMS 4.1 and is asking if they can get a similar free upgrade as before, especially since their current LMS is covered under an SP Base contract.
Do you know if the SP Base contract will qualify them for this? I have tried discussing it with a TAC licensing Engineer and the Local Accounts team both have not given me a solid answer.
View 3 Replies
View Related
Jul 9, 2012
I will attempt to explain the history of our wireless controller configurations as best I can. We are currently using a 4400 controller running 7.x software which authenticates to and ACS 4.1 appliance. All of this was set up prior to my arrival on the job and the previous engineers had already left with no documentation in place so I'm trying to piece it together. The ACS is setup to map to AD for specific groups.
In the controller we have an SSID called triton which is our corporate SSID that all internal users connect to. Three different interfaces have been defined, a general one for most users and two others( lets call them INT1 and INT2) that place users on separate ip networks. The reason for this is those ip networks can reach certain services that are not allowed for general users. ACS maps those users upon authentication to the Vlans associated with those separate ip networks.
Problem 1. When I first took this job, users could not map drives or any services because only user authentication was taking place..After some troubleshooting and realization that ACS was authenticating, placing the "Domain Computers" group as an ACS group mapping fixed that issue, allowing the computers to authenticate prior and therefore execute the login script
Problem 2. Recently it has come to my attention that some of the users on one of the other interfaces (INT1 and INT2) that should be placed in the vlans associated with their AD group mapping are not. Upon further investigation it was discovered that the reason they are not is that the authentication is not correct. When the computer first authenticates before the user logs on its shows in ACS as host/xxxxx.yyyy.org where the user authentication shows as xxxxx/username . So some of the computers never change from authenticating as a host to a user and the ip address ends up in the wrong vlan.
View 2 Replies
View Related
Sep 22, 2012
My main goal i want to filter certain sites including facebook not to be accessible within the network and block all torrets including maliciuos site. I was advised to get Cisco ASA 5505 which i already got a quote. But now i want to know if is the ASA 5505 good enough for this purpose, is there anything additional required to succesfully overcome my main goal?
View 5 Replies
View Related
Jan 10, 2010
setting up IPsec for a DMVPN between a 2811 and 2951s in a test lab. I have enabled IPsec on the hub (2811) but I am unable to do so on either of the 2951s. After researching, it seems that I may have the incorrect IOS for this, but I am at a loss which IOS I should be using. Currently the 2951s are on "c2951-universalk9-mz.SPA.151-2.T2.bin" and the only crypto options.
View 9 Replies
View Related
Jul 2, 2012
I have modified my radius accounting reports using "interactive viewer" and saved successfully but the exported report doesn't reflect these changes. I'm just wondering what's the point of being able to modify the reports if you can't export your changes or there is something I'm missing?
View 3 Replies
View Related
Sep 29, 2011
i have LMS 3.2 installed in my campus. i need the serial number of the LMS suite to open a service request with cisco. but unable to find the same. How to find the same.
View 1 Replies
View Related
May 20, 2012
I need my security key
View 1 Replies
View Related
Apr 10, 2012
I want to directly connect two Win XP machines together to transfer large files.Both have "Gigabit Ethernet".Its been years since I last did this, and used to need a special cable called a crossover cable to accomplish this, but reading up to refresh my memory I believe I no longer need the special cable, but can use the cable that now connects my cable modem to my computer, as the Gigabit specification eliminates the need for a crossover cable.
View 3 Replies
View Related