Cisco Firewall :: ASA5500 Add A Second Outside Connection With Second Provider
Feb 24, 2013
ASA-5510, inside, outside, and some DMZ.Some services published with Static NAT - no problem.Now we need to add a second outside connection, with a second provider.Internet navigation only through the first provider (default gateway to the provider router "A").I need to publish some services ALSO through the second provider, ensuring the accessibility of both public IP addresses.I can set up the second NAT on the second interface, but the answer is ONLY to the first IP (the ISP "A", where I have the default gateway).By Cisco manual, it seems that there is a "lookup route" automatic with the return route of NAT, but it does not work.
View 6 Replies
ADVERTISEMENT
Mar 3, 2013
Does any one advise the current ASA 5510 is going to EOS ?
View 1 Replies
View Related
Oct 31, 2011
Using any computer and AnyConnect, I can connect to our network via ASA5500. But when I use Cius or iPAD, I always get a No License error message.
View 3 Replies
View Related
May 5, 2013
Should we active IPS feature in ASA 5500-x by useing license?in the 5500-x ordering guide:IPS is only sold as ASA-IPS combo SKUs i.e., one cannot add IPS service as an option on top of ASA SKU. For example, if IPS service is desired on ASA 5515-X appliance, the relevant SKU is ASA5515-IPS-K8 or ASA5515-IPS-K9.But my customer has actived it by using the ASA5525-IPS-SSP on ASA5525-K9.
View 2 Replies
View Related
Feb 4, 2012
Recently i have configured ASA5550 with 2 Contexts in Transparent mode. Traffic can pass through a single Firewall context but through both contexts it couldn't.
View 0 Replies
View Related
Mar 2, 2012
I would like to schedule automatic backups of our ASA5500's OoO-hours:
1. SSH from secure server and create _FULL_ backup - what would be the CLI command(s) ?
2. SCP from secure server and retreive file(s) - what is the location of the file(s) ?
View 12 Replies
View Related
Jul 17, 2012
It's a problem about access ASA5500 Firewall mangement port. The customer request access ASA5500 by entering the default IP address https://192.168.1.1 to monitor data tracffic in Windows 7. But after entering the default IP in IE, no any page appear.
But that way can access ASA5500 magement port successfully in Windows XP. What the different between Windows 7 and Windows XP? Is there any way or any patch can access ASA5500 manemeng port in Windows 7?
View 4 Replies
View Related
Dec 26, 2011
I have a large quantity of ASA5520's and ASA5540's that need to be quickly assessed and RTV'd (if need be) if they are found to be upgraded ASA5510's.
My concern is because of this recent release-note by Cisco: [URL]
Is there a way to check the amount of DIMM slots on a unit through console or do I have to physically check each and every one?
View 2 Replies
View Related
Sep 19, 2011
I was wondering if it is needed to license the IPsec VPN clients in the ASA5500 firewalls...I know that you have license the SSL VPN peers (AnyConnect). I am almost sure that for the IPsec you don't have to.
View 1 Replies
View Related
Jan 10, 2012
I am attempting to port-forward on an ASA 5500 to internal host .100. The outside interface recieves its IP via DHCP. Packets are being denied so I ran packet-tracer and get the following error from outside to ssh port on internal host.
#packet-tracer input outside tcp 79.x.x.x 1025 71.x.x.x ssh
Phase: 1
Type: ACCESS-LIST
Subtype:
Result: ALLOW
Config:
[Code]...
View 7 Replies
View Related
Sep 20, 2012
I would like to know about asa 5500-x. Does it supports application visibility and granular control for different applications. Moreover bandwidth control based on different users and different applications
View 1 Replies
View Related
Nov 16, 2012
who to connect two dsl connection with two different provider
View 1 Replies
View Related
Mar 6, 2011
We have ASA5500's deployed for remote access concentration.We use Cisco IPsec vpn client with a group policy the chacks for Network ICE BlackIce ersonal firewall.The powers-that-be wish to change to McAfee presonal Firewall ok..Now the Group Policy allows you to check for several pre- configured Firewalls, Cisco Integrated, Sygate, Zone Labs etc.So as McAfee are no listed then I am to assume we go for "Custom Firewall" and this is where I am struggling.To configure checking for a Custom Firewall I must have the Vendor ID and the Product ID.McAfee haven't the faintest idea what we're talking about when we ask them for these details.Or is there a way to extract them from the registry of a machine with the McAfee product installed?
View 3 Replies
View Related
Jul 9, 2012
I have currently a Cisco 3600 router, it has three interfaces (all ethernet interfaces only).We being a client, our requirement is, we want two links one being the primary and one secondary for the fail over.My ISP has done certain configurations, but I am so puzzled what really has been done. I asked with them and they told that they have provided us one public IP 202.166.217.248 via Fibre--> Media Converter-->Ethernet 0/0.At the same time, they have given us a pool of addresses of the network 202.166.216.48/29 through the interface Ethernet 2/1.And we have used all the available public IPs in the server farm.They have told that, for the failover purpose via wireless, they have even used an IP address 202.166.213.114/25.
Now, where my confusion lies is, cant they provide the pool address via fibre? What is the significance of the ip that has been provided via fibre? What actually is its purpose? Isn't it consuming an extra interface ?Cant we have both the primary and secondary link excluding that one additional process?Or, am not understanding the real working mechanism how ISP distribute the internet?
View 1 Replies
View Related
Jan 11, 2011
we are charter High speed customers and just recently upgraded are connection speedHowever today my sisters netbook wireless connection stopped working. My DS wifi connection is also dead now In the past the the wireless network name was wifi-****** but now its called wireless and the wep key no longer works
View 5 Replies
View Related
May 22, 2012
We are connected to 2 different providers (PROV01 and PROV02) with eBGP full internet tables. PROV01 routes have higher local preference over PROV02.
We are having problems with our provider and would like your expertise. PROV01, higher preference has been having trouble with their router. The BGP remains up but the router stops forwarding traffic. as a resulta we lose connection to the internet but our traffic never goes to PROV02 since PROV01 BGP remains up announcing the 400K routes to us.
Is there a way to test internet connection though PROV01 and as the "internet is DOWN" automatically change traffic to PROV02? Can BGP parameters changes be triggered by IP SLA? Our router is an ASR1006 RP2.
View 11 Replies
View Related
Aug 28, 2012
My modem with single network connectivity (Type I) works fine. I tried to replace with Type II modem (with wifi- and 4 or more ports) for connectivity. I could not establish connection with the server of the service provider. I tried to replace with a different type of typeII modem. Still the same. What could be the reason?I connected the same in a different workplace to a different PC.
View 1 Replies
View Related
Apr 9, 2012
ok when i'm playing my xbox 360 my brothers sister and my dad are on computers playing games and watching netflix and i lagg alot is there any way i can get my own network connection my internet provider is century link.
View 3 Replies
View Related
Jul 6, 2011
in a week or two we are going to put in a secondary internet connection. Is there a way on a pix 515E to have one internet provider be preferred over the other and if the primary fails then the secondary will take over?
View 3 Replies
View Related
Oct 11, 2011
I have a dual wan router with a main cable modem for high speed and a backup adsl modem hooked just in case. The problem is that quite often it seems that my ISP loose his connection to the internet but communication is not lost between my ISP and my modem and router. Because of this, my router doesn´t do the automatic changeover from my WAN 1 to my WAN 2 hooked slower ADSL modem. My router has the ping to keep alive option checked on the WAN 1 setings using my Cable ISP provided IP address.How can I force my router to notice that my cable ISP lost his connection to the internet and do right away the changeover from his WAN 1 to his WAN 2 input?
View 1 Replies
View Related
Aug 7, 2011
We are using several Cisco ASA 5505 with the 8.05 OS on it. The problem is that the SMTP traffic of my ISP(Telenet) isn't passtrough the ASA, I'm using outlook 2010. Before there was also a problem with our local exchange server but I solved this by disabling ESMTP checking in the policies, but it didn't worked for my local ISP.
View 4 Replies
View Related
Sep 7, 2011
What are my best options to secure branch office connection to HQ over Provider MPLS cloud. Our existing Setup
<<HeadQuarter>> :: DataCenter hosting Email, ERP, Intranet, Voice Services 10mb link to Service Provider over MPLS CloudMPLS is terminated on a 3825 Router running advance Services
<<BrancOffice>>::Total 10 In Country Branch Offices2mb Link to Service Provider over MPLS CloudTotal users in each branch : 20 MPLS is terminated on a 2811 Router running advance Services
View 1 Replies
View Related
Feb 5, 2013
I have an issue with Netflow that I have been unable to solve. I have an ASA5510 that is sending netflow data to a FogLight NMS and it works fine until I reboot the server. After the server is rebooted, the flows no longer are received until I reload the ASA. Once the ASA is rebooted, flows work fine. I can remove and reconfigure the netflow configuration on the ASA and that will start the netflow again, but that is painful.
Is there any way to easily stop/restart or re-initiate the netflow from the ASA easily?
View 2 Replies
View Related
Oct 16, 2012
Is Cisco secure desktop free and available for download on Cisco's download site? Is host scan part of the package? I just purchased an AnyConnect license for my ASA (ASA5500-SSL-250=) and would like to know how to get Cisco Secure desktop and more specifically if host scan comes with CSD.
View 1 Replies
View Related
Oct 1, 2012
What benefits does the Cisco Secure Desktop bring to customers running ASA5500-SSL-250= user license on the ASA? This is not Anyconnect. This is just regular clientless SSL VPN. I am particularly interested in anti-virus/anti-spyware compliance. Is this available with the base version of CSD? How does this endpoint control work? Can endpoint control detect that an O/S antivirus is not up to date and then block this device from accessing the VPN? If it can, how is this configured? note I am not asking about the additional Advanced endpoint control license. Just basic Cisco Secure Desktop download.
View 1 Replies
View Related
Apr 10, 2011
I am trying to configure ASA to assign same static ip address to certain user(User1) every time when he connect to network via AnyConnect client. We have Windows AD and use LDAP AAA server for authentication of VPN Remote Access users. I found in document "Cisco ASA 5500 Series Configuration Guide using the CLI, 8.2" in section "Configuring an External Server for Security Appliance User Authorization" explanation and configured ASA and User Properties in AD on exectly same way:First, I assigned static ip address in properties menu(dial in section) of User1 in Active Directory. Then I created ldap attribute map where I mapped msRADIUSFrameIPAddressattribute to IETF-Radius-Framed-IP-Address attribute. At the end I applied this ldap attribute map to AAA server group LDAP.
Although I set this up, whenever I connect using User1 credentials from AD I still get ip address from vpn pool instead static ip address that I configured. In output of debug ldap 255 command I found line "msRADIUSFramedIPAddress: value = -1062718956" but not any line that prove mapping above mentioned attributes.It seems like mapping is not working.All AnyConnect users get parameters from defined internal group policy on ASA,including addresses form pool,dns server etc. I want that User1 get static ip address and inherit all other parameters from group policy.
View 4 Replies
View Related
Feb 27, 2011
I am trying to configure ACS 5.1 to authenticate SSL VPNs on an ASA5500 and aslo to provide admin access to the ASA5500 both via radius.I want to authenticate the VPN against a SeureID appliance and the admin login against a different database (using internal for testing but will use LDAP in the end).I cant seem to get the ACS to distinguish between the two authentication types. If I create a rule that says match protocol radius I can point that at either database but if I try saying match radius and service type 5 it doesnt match the VPN and falls through to the default authentication service. I have also tried matching service type 6 for admin and that doesnt seem to work either.In the end what I want to acheive is to authenticate teh ASA5500 VPN against the SecureID appliance and then admin access to all devices on teh newtork (a mixture of Cisco, F5 and Juniper) to active directory via LDAP where if the user is a member of the "admin" group they get access.I was intending to use specific devices for the ASA5500s (there aretwo) and then creat a device group based on IP address range for everything else.
View 4 Replies
View Related
Jul 24, 2012
I am designing wireless controller solution for one of our customer network with Cisco 5500 series controller, wireless client authentication part.
1. There are 25 departments around the campus, each will be given one or two access points.
2. One Cisco AIR-CT5508-50-K9 Controller shall be used.
3. Single SSID/ VLAN shall be used for entire campus.
4. Wireless Authentication credentials used by one department shouldn’t work for other department
View 7 Replies
View Related
Jun 27, 2011
I am using ASA5500 series box which has a site to site tunnel terminated on it.Is there any command by which we can check the up time of the tunnel.
ASA# sh isakmp sa
Active SA: 1 Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)Total IKE SA: 1
1 IKE Peer: x.x.x.x Type : L2L Role : responder Rekey : no State : MM_ACTIVE
View 2 Replies
View Related
Mar 9, 2011
I have configured Remote Access VPN on an ASA5500 Firewall. I am able to login normally and Ping Internal servers on the LAN. However, The servers cannot ping my IP address that i am taking from the RAVPN Pool. So it is a one way communication.
View 2 Replies
View Related
Jun 20, 2012
I currently have a problem with connecting to some CIFS shares on a EMC NAS. I have created some bookmarks for those shares to be used via the client less SSL VPN portal. I have also setup SSO which works properly for web-bookmarks and RDP stuff but not for the CIFS shares.
When I try to access those shares I'll always get a "authentication failed" error message. Afterwards a new log in-box is displayed. I have been able to log in to those shares by using the user-ID prefixed with the domain name [URL]. Log in fails when using only the user-ID or for example DOMAIN user-ID. I have also tried with a share on a different Server (windows2008 R2) which works without any problems.
View 1 Replies
View Related
Feb 6, 2012
We have problems on central firewall with restricting traffic coming from remote office from IPsec. (The network sheme is attached) All branch offices are connected to central asa though IPsec. The main aim is to rule access from branch offices only on the central firewall, NOT on each IPsec tunnel According to the sheme:172.16.1.0/24 is on of the branch office LANs10.1.1.0/24 and 10.2.2.0/24 are central office LANThe crypto ACL looks like permit ip 172.16.1.0/24 10.0.0.0/8 the aim is to restrict access from 172.16.1.0/24 to 10.1.1.0/24 When packets are generated from host 10.1.1.10 to 172.16.1.0/24 all is ok - they are dropped by acl2 When packets are generated from 172.16.1.0/24 to 10.1.1.10 they are not dropped by any ACL - the reason is stateful firewall - traffic bypasses all access lists on a back path I thought that TCP State Bypass feature can solve this problem and disable stateful firewall inspection for traffic coming from 172.16.1.0/24 to 10.1.1.0/24, but it didn't work.The central asa 5500 is configured according to cisco doc [URL]
access-list tcp_bypass_acl extended permit tcp 172.16.1.0 255.255.255.0 10.1.1.0 255.255.255.0
!
class-map tcp_bypass_map
description "TCP traffic that bypasses stateful firewall"
match access-list tcp_bypass_acl
[code].....
View 4 Replies
View Related
Feb 28, 2012
I would like to configure the below setup:
End user client (Cisco Any connect/VPN client) -> ASA 5500 (AAA client) -> ACS server -> External RADIUS database.
Here ACS server would send the authentication requests to External RADIUS server.So, i have added the external user database (RADIUS token server) in ACS under External databases.I have added AAA client in Network configuration (selected authenticate using RADIUS(VPN 3000/ASA/PIX 7.0) from the drop down.
Here how do i make ASA recognize that it has to send the request to ACS server. Normally when you use ACS as RADIUS server you can add an AAA server in ASA and test it.But here we are using an external RADIUS server which has been configured in ACS, so how do i make ASA to send the requests to ACS server?
View 6 Replies
View Related