Cisco Firewall :: ASA5505 - Setting Up For Home DSL Use?

Mar 4, 2012

I have a cisco asa 5505 firewall, and I have a normal home ADSL broadband router, the router currently connects via wireless to my pc.What I would like to do is basically connect the asa to my pc, then my router to my firewall.what the best thing to do here, run the aa in transparent mode, OR routed mode and do NAT on the firewall to the private ip address range of my router. 
OR, would it be possible to get the outside interface of my asa to get DHCP from my broadband router so it will use a 192.168.1.x address on the outside, and then turn NAT off?

View 2 Replies


Cisco Firewall :: Installing ASA5505 On Home Network For VPN Connection?

Feb 25, 2013

I have been asked to install a ASA5505 on a home network. The home network has a home broadband connection which the ISP provider supplies with an IP address. This is only for 6 weeks until the new line comes in. I know this is going to cause problems but we have no choice but to impletment this.
My questions are below.
1, We have a home hub supplied by the ISP which is configured by an IP address which is NOT static. Can we not use the ASA 5505 instead. I know that if our ISP change the IP address we have to change the IP address on the 5505.
2, Will we be able to use the home network broadband to create a secure connection?

View 1 Replies View Related

Cisco Firewall :: ASA5505 - Can't Get Home Webserver Published To Outside Interface

Aug 17, 2011

I've tried to get my head around this but beeing used to Juniper and Watchguard devices I just can't get my home webserver published to the outside interface.I have a ASA5505 with ASA version 8.4 and ASDM version 6.4 and the basic license.

Outside interface is X.X.X.32/ so I have 5 static IP:s on my external interface, .34 is in use for the outside interface.

I have a webserver in DMZ located at and would like to publish it to the external IP X.X.X.35.I've tried to make the static NAT but every time I do either nothing goes in or out of the DMZ zone or you can't access the webserver from the outside interface.Right now I deleted all trials since none of them work so only the basic config is applied. Everything get's NAT:ed to the external interface .34 IP.

View 4 Replies View Related

Setting Web / FTP Home Server With Netgear DGN2200 And Zyxel USG100 With Firewall

Jun 15, 2013

I want to public to the internet a web + ftp server, all running in the same machine that now is a performance pc, in the future will be a qnap nas ts-220. I don't need extreme performance so my ISP gives me only 12 Mb down and 0,8 Mb up. I will use the nas as download station, ftp server and a web server when I'll public a personal site.

this is the config:

-modem/router adsl2+ that connects to the internet. ISP gives me dynamic ip! it has ip and I think it cannot be changed.

-a firewall hardware zyxel usg 100 with all active UTM services. it has default ip the netgear in the "attached devices" see the zyxel as, the same ip zyxel says to the wan1 port.

-a pc or, in the future, a nas that now has automatically assigned ip

I must use a free or paied service as dyndns or something else. If the solution to retrieve everytime the dynamic ip is to set the ddns only in the router/modem netgear then it can only use or .com or .it with the dns of the associated ddns service. For example: if I set a account in the netgear I must set also the dns provided by because if I set google dns or something else the service cannot work.At the moment I tested only with a filezilla server running on the pc directly connected to the netgear, no zyxel in this test.

The config is:

netgear with ddns service provided by, activated with the username and password, in the wan I setup the dmz as, in the adsl settings setup the IPs. in the services of the netgear also provided a custom service with ports from 60000 to 60050 and created two rules one for outbound and one for inbound where I let data pass from the wan to the server in the lan

filezilla running on the pc with windows 7 x64 with lan ip mask as th3 netgear and gateway of course the netgear dns servers same as provided by filezilla configured with only one anonym user without password for testing, default listening port is 60000, passive mode active with range 60000-60050 and for retrieving IP I set default, no host cause it will not work.

So configured it works fine!problem is when I connect the zyxel between the netgear and the change the default ip of zyxel? in configuration - ethernet - lan port is correct to set there the default and static ip to there are many options! same as dmz you can set there the static ip and what ip?also when you want to public a server zyxel don't say nothing about port-forwarding. it says only create two address objects one with ip of the netgear and one with the ip of the dmz port then create a rule in the firewall section where you set wan to dmz and destination and origin ip selecting the two address objects previously created then you are, really no! and the ip of the firewall rules in the netgear? which ip do you must set? or if you set it up in the dmz port of the zyxel? no, it is a conflict so you must set another set correctly the server to be visible in the internet with the netgear + zyxel usg 100?

View 5 Replies View Related

Cisco VPN :: ASA5505 - Bad Cryptochecksum Ignored And Setting Default Startup Configuration

Jan 9, 2012

There are two issues which are testing my resolve.
1) Bad Cryptochecksum Ignored error
2) Unable to boot to a save startup-config file.
I want to take the configuration from one ASA 5505 and move it to another ASA 5505. I copied the startup-config file from an ASA 5505 running asa821-k8.bin to an ASA running 8.222-k8 to flash using tftp. I set the boot config parameter on the new asa to flash:/startup-config which is the location of the startup file. If I use copy run start command, I over write the startup file. When I copy the startup configuration to the running configuration I get a Bad Cryptochecksum Ignored error and the startup file does not copy over to the running file. How can I resolve this issue?

View 1 Replies View Related

Cisco WAN :: ASA5505 / Setting Access Policies Dual Internet Connections

Jun 7, 2011

I'm trying to set up a S2S VPN between two ASA5505 SP units running ASA Version 8.2(1). I've ordered additional ADSL2 lines to handle this traffic and I'm having troubles with the configuration for the additional PPPoE connection. Here is are extracts from my current config; First the interface vlans
interface Vlan1
nameif inside
security-level 100
ip address

The result being that I can ping the OUTSIDE interface, but get no reply from the VPN interface. I've checked ADSL lines, they are up. The two PPPoE sessions are logged in and active. I can even see the ICMP packets hit the VPN interface, but there is no reply.

View 1 Replies View Related

Cisco :: Want To Setup A ASA5505 To Comcast Home Mode?

Feb 5, 2013

New to Cisco but learning some. Needing to know what I should code into CLI on my ASA5505 to make it work with comcast modem which uses DHCP for it's addressing from Comcast proper.

View 2 Replies View Related

Cisco VPN :: ASA5505 - Can't Make Tunnel Connection From LAN Home Side

Oct 6, 2011

I have an ASA 5505 with Base license and a vpn client. The scenario is like this: LAN -- ASA 5505 -- ISP DSL Router---( Internet ) -- Home DSL Router --- LAN -- VPN CLient, The ISP DSL Router gets a public IP address and the ASA gets a private IP address (ISP DSL router doing NAT) and I cant reach the internet with no problem from the LAN´s ASA side but I cant make the vpn tunnel connection from the LAN´s Home side so I told the provider to bridge the ISP DSL Router, to the ASA so the ASA could get the public IP but in order to do that the provider told me to do MAC clonning on the ASA 5505 which I did putting the ISP DSL Router MAC on the ASA. Now the ASA gets the public IP on the outside vlan by DHCP but when I try to make the VPN tunnel I just cannt. I can reach the public IP by ping on the ASA and I can see the pings coming in using debug but I just cant make the vpn client work.

View 2 Replies View Related

Cisco VPN :: Connecting To ASA5505 From Home To Head-office Using L2TP VPN

Jul 16, 2012

I am connecting to a ASA5505 at from home to the head-office using L2TP VPN.
Head-office then has a connection to other-office via a site-to-site IPSEC tunnel.
When in the head-office ( I can ping/access remote-office ( OK.
When connected remotely to head-office, I can ping/access head-office OK from the road-warrior laptop.
My problem is that when connected remotely from home to the head-office I cannot ping/access the other-office subnet.
On the home laptop the L2TP VPN connection is set to route all traffic to the VPN connection using the HQ as the internet gateway I can confirm this works.
I cant do traceroute (I get timeouts) as my policy doesnt allow and not sure how to enable this properly on the ASA.

name othersite
interface Vlan1
nameif inside
security-level 100


View 1 Replies View Related

Home Network :: Setting Up A VPN

Jun 17, 2011

I want to setup a VPN, probally more just for the experiance and to learn how to etc, but i also print remotely and view cameras remotely etc and i though it might be safer then port forwarding hundreds of different ports.First question, would it be better or safer to set it up in Windows XP or windows Server as i would have to purchase windows server. I have XP and windows 7. and, what exactly is a VPN. I have done some reading up, but was woundering how exacly i would for instance, remotely view my DVR (cameras) over a VPN. Also, i want the server to be a remote HDD to store and access all data remotely, Backing up etc. This i think VPN is more made for right?And, i will need a server (computer running at all times) to setup a VPN right? as where the router is always on and accessable. I can acheive this and i think this is what i need.So there it is, im new to this side of things done about all i can with the old router and looking at extending my knowledge. Also i wouldnt mind it being SAFE.

View 7 Replies View Related

Home Network :: Setting Up VPN?

May 5, 2012

I want to set up VPN at home so my friends can access network shares on my LAN and stuff. I have used this tutorial:(url) ?v=1s5JxMG06L4&feature=related so users are set up, and port forwarding on router is done as well. I am using Windows 7 Ultimate, and VPN is set up on this machine. The issue is that my friends cannot connect to my VPN from another Windows machine. When they try to connect it is asking them for user and password but later on after authentication they receive error 720 which says connection could not be established. When I went to the network connections and then to the properties of VPN (incoming connections) it says no hardware capable of accepting calls is installed.

View 11 Replies View Related

Setting Up Home LAN Network?

Jun 28, 2011

(i have 2 PCs (1 desktop and 1 laptop) both running Windows XP connected to my modem/router. the desktop is connected through a wireless adapter, and the laptop is connected directly using an ethernet cable. i have run Windows "Network Setup Wizard" on both PCs and they are part of the same workgroup with File and Printer Sharing enabled. this is as far as I've gone in setting up my LAN and everything works fine. i am able to see both PCs under My Network Neighbourhood and can access files from either PC just fine. both PCs are also able to ping each other by IP address and comptuer name.the problem is this only lasts temporarily. for some reason, after a random amount of time (anywhere between 1 hour to a few days) the desktop will "drop off" from My Network Neighborhood on the laptop. when i try to click on the desktop or workgroup in Network Neighbourhood i suddenly get the error "You might not have permission to use this network resource. Contact the administrator of this server to find out if you have permissions. The network Path was not found." after this happens i am no longer able to ping the desktop from the laptop either by the IP address or computer name.however I am still able to ping the laptop from the desktop by IP address and computer name, although in Network Neighbourhood the laptop can no longer be seen as part of the workgroup. I am still able access the laptop and its files from the desktop using the \*computer name* command and this will bring up the laptop name again in Network more thing i noticed is, once I've pinged the laptop from the desktop i found that i can again ping the desktop from the laptop, but only with the IP address. If I try to ping the desktop by computer name it still times out. oweer, this also lasts temporarily... after a while, the laptop is also not able to ping the desktop IP address again.the only solution so far is to restart the router. once the router restarts and both PCs reconnect to it, then the LAN is working fine again... that is, until the problem above starts up once again! cry.gifmy modem/router model is D-Link DSL-2640B.some additional info:

- i've assigned static IPs to both PCs so they always have the same IP address from the router.

- i've tried disabling the built-in Windows firewall on both PCs but the problem remains.

- i do not have any other anti-virus or firewall programs installed.

- i've disabled "Computer Browser" service on the laptop so that the desktop is always the Master Browser.

View 5 Replies View Related

Setting Up Multiple Home Pages On AOL 9.1?

Feb 11, 2011

I am running AOL Desktop 9.1. When ever I start up it loads multiple home pages. How can I prevent this from happening?

View 3 Replies View Related

Setting Up A DNS Server On Home Network

Jan 18, 2011

I have a small home network. My goal is to use Windows Server 2003 R2 to setup a DNS Server that can create a few simple names for some devices on my LAN, such as my printer. My DNS server will forward other inquiries (like to OpenDNS. Additionally, I don't want to setup a domain controller for my network. I wish to continue using workgroups,how to setup a Windows DNS Server on a workgroup. My biggest confusion is the FQDN of my name server. By default, it's setup as "server.", where 'server' is the name of my Windows Server 2003 machine. My workgroup is named 'Home'. So I tried 'server.home', but this does not resolve. What DNS suffix do my other machines on the network use by default? Is my domain name on the network really my workgroup name? Another thing I want to avoid is configuring a DNS Suffix for every single client machine on my network in their NIC properties for IPv4. I have a D-Link router, and if I do an "ipconfig /all" on my machine, I see that my DNS suffix is 'router', which is the name of my D-Link router. I try setting my DNS Server FQDN as 'server.router' and that doesn't work either, so I'm out of ideas.

View 1 Replies View Related

Setting Up Home Network With 2 Routers?

Nov 30, 2012

I recently signed up for Centurylink Prism TV and internet, they use a Cisco DDR2200 (modem+wireless router combo) which I've come to realize is only a "g" router, so I purchased a cheap Belkin N150 (which I intend to use as my main router). I've turned the wireless function off on the Cisco and have an ethernet cable running from a LAN port on the Cisco to the internet port on the Belkin.

The issue I'm having is how do I set up the IP addresses/DHCP servers for both routers? By default, the Cisco's IP address is (I know, weird right?) with a DHCP range of - Whereas the Belkin's IP address is . I guess I'm sort of at a loss on how to set this up to optimize my network.

View 5 Replies View Related

Home Network :: Setting Up Open VPN On OVH

Aug 14, 2012

I want to start using a VPN and would rather have my own server for it so was going to buy a kimsufi 2g with ubuntu installed on it, Have been looking on the openvpn website but cant find any tutorials on how to setup openvpn on ubuntu.

View 1 Replies View Related

Setting Up The Wireless Modem At Home

Mar 29, 2011

I can't get traditional broadband services, so I've been making due with Verizon's Mobile Broadband service. Problem is, it's expensive and has a 5GB cap per month. I read about powerline networking and thought it sounded good, so I bought all the adapters and a router. Problem is, I didn't have the prior knowledge to realize I also needed a modem as well. How or if I'd be able to set up any sort of modem in my home, considering services like Verizon can't reach me?

View 3 Replies View Related

Setting Up Wireless Home Network?

Feb 12, 2013

I want to set up my own home wireless network for the first time. Also this is the first time I'm using wireless router.nd trying to set up the network.Currently, I have ADSL+ router device that is configured in route mode and it has PPPoE credentials stored, so until now, I use ethernet cable to connect it to the ADSl router and everything works fine (Automatic IP, DHCP on notebook). Notebook also has wireless adapter, so I bought asus wireles router.This was supposed to be an easy install. According to the instructions all I need is to use this ethernet cable to connect to WAn port on wireless router and to follow Quick set up instruction. But this quick installation procedure fails.When I try to figure out why, I came accross to the fact that existing ADSl router has and this new asus WiFi has also

View 5 Replies View Related

Setting Up Small Home Network

Mar 4, 2012

I am buying a router with wireless soon and i am setting up an ADSL account.I only have one computer that will connect to this router.The router will be based in the living room area where the phone line is.My room (where the computer is situated) is quite far from the living room and i am not keen to drilling holes through roofs to wire some LAN cable.My plan is to use a wireless dongle in my pc to connect to the router for internet. Will this affect the speed of my downloads off the internet at all? will it be the same as if i was using a lan cable?I know file sharing over the network via WAN is slow but will my internet be?

View 1 Replies View Related

Home Network :: Setting Up Static IPs?

May 28, 2012

So I have AT&T U-verse and am teaching myself networking and am wanting to mess around in creating my home network and set up static IPs for my devices. I know how to set them up, but I guess AT&T is saying that they have to allocate the static IPs....pretty much they are saying I have to pay them so they can say ok I can use the IP addresses from xxx-xxx-x-10 to and then depnding on how many I want to have depends on how much I pay. This makes no sense to me. Why should I have to pay my ISP for static IP address, from my understanding those are things

View 3 Replies View Related

Setting Up A Large Home Network?

Jan 16, 2013

Im trying to rebuilt my parents home network. This is the general layout of what Im trying to go for when everyting is said and done.

l l l l l l l l l l l l-direct-tv box
l l l l l l l l l l l-blu-ray player
l l l l l l l l l l-xbox 360
l l l l l l l l l


and i dont know what switch 2 is yet because my dad ordered it and it has come it yet, all i know is its a linksys Now the big problem I keep having is keeping everything up and running for more than a day. Ive already configured router 2 to a staic ip address of and disabled DHSP server thing which cleared up some of the inital issues I was having. But I continue to be plagued with issues of computers saying there are duplicate names on the network and the internet only working on some devices most of the time and the internet going out completely after a day or two. Now when the internet only goes out for some devices its usually limited to everything thats not hooked directly into router 1.but everything hooked directly into router 1 still has internetand the basic hard restart of everything does nothing to solve the problem. The only real way Ive been able to solve things on a large scale for a short time frame is to unhook everything and setup reouter 1 and the computers that hook into it on day one. come back on day two and setup switch one and comback the next day and so on and so forth. and usually by day 5 everything has worked for about a day or two then Im back with nothing working.

View 4 Replies View Related

Cisco Firewall :: Users Behind ASA5505 Firewall Are Unable To Access Internet

Feb 24, 2011

I have a normal setup of ASA5505 (without security license) connected behind an internet router. From the ASA5505 console I can ping the Internet. However, users behind the Firewall on the internal LAN, cannot ping the Internet even though NATing is configured. The users can ping the Inside interface of the Firewall so there is no internal reachability problem. In addition, I noticed that the NAT inside access list is not having any hit counts at all when users are trying to reach the internet.

When i replace the ASA5505 with a router with NAT overload configuration on it, the setup works normally and users are able to browse the internet.

The ASA5505 configuration is shown below.

hostname Firewall

interface Ethernet0/0
description Connected To Internet Router
switchport access vlan 10


View 2 Replies View Related

Sharing :: Setting Up A Home File Server?

Jun 15, 2012

I have a PC ready to use that I want to be used for sharing files, pictures and videos on between our multiple PCs in the house hold. I am going to have it constantly running (I have alot of cooling for it) but I need setting it up.I dont know if I should use Ubuntu Server or FreeNAS?

View 1 Replies View Related

Protocols / Routing :: Setting Up Home Network With VPN?

Feb 19, 2013

I have a problem figuring out how to setup a home network connection running a VPN. I have been looking through the internet for answers and am still not sure how it all works.

View 9 Replies View Related

Setting Up Proxy On Home For Business Purpose

Mar 28, 2012

I am attempting to set up a proxy on a home network that is used for business purposes. I am not at all a networking person, I know enough to be dangerous. If I follow the steps listed here: URL Will this encrypt the data that is sent to the internet from any computer that connects to my network or just the one I follow the steps on?

View 7 Replies View Related

Setting Up A Multi Ethernet Connection At Home

Nov 26, 2012

I have a single Ethernet connection into my house that is wired back to the main router right the other side of the house which is approx 40m away. The whole main house is cabled but I want an Ethernet cable to my TV,DVD and ps3, plus I need wireless for upstairs in my room. My question is, can I use the same wire or unit to connect the 3 different scores?and is there a wireless extender that will reach the further 40m to my part of the house?

View 1 Replies View Related

Cisco Firewall :: ASA5505 Lose Configuration If Upgrade Firewall

May 17, 2011

i have asa 5505 with the asdm v5.2 (4), and the asa v7.2(4). This platform has a base license. if i upgrade adsm and asa on v6.2(1) and v8.2(2) if I lose my license and that you need to activate them? i configured site to site vpn (this firewall and the another) that i lose my configuration if i upgrade my firewall.

View 2 Replies View Related

Cisco Firewall :: ASA5505 Can't Ping New Firewall On Inside Interface

Jul 14, 2011

I've recently upgraded my old firewall from a PIX to an ASA5505 and have been trying to match up the configuration settings to no avail. I have is that I can't ping the new firewall on it's inside interface, despite having "icmp permit any inside" in the running config. Secondly, the server I have on there ("Sar") can't connect out to the internet.I've included the ASA's running config incase anybody can see if something stands out. I have a feeling it's either not letting anything onto the inside interface, or there is no nat going on. Lastly (and possibly relevant), the firewall is actually going at the end of a vlan, which is different to the firewall's inside vlan number. I don't know if this is actually the problem because the server can't connect out even if connected directly into the firewall.

View 32 Replies View Related

Cisco Firewall :: Unable To Ping Internet IPs From ASA5505 Firewall

Jan 9, 2013

Internet ISP -> Juniper SRX 210 Ge-0/0/0
Juniper fe0/0/2  -> Cisco ASA 5505
Cisco ASA 5505 - >Inernal LAN switch.
1.  Internet  is connected to Juniper Ge0/0/0  via /30 IP.
2. Juniper fe0/0/2 port is configured as inet port and configured the Internal public LAN pool provided by the ISP. And this port is directly connected to  Cisco ASA 5505 E0/0. Its a /28 pool IP address. This interface is configured as outside and security level set to 0.

From Juniper SRX, am able to ping public Internet IPs (

1. From ASA am unable to ping public ip configured on Juniper G0/0/0 port.(/30)
2. From ASA no other Public internet IP is pinging.
Troubleshooting Done so far.
1, Configured icmp inspection on ASA.
2. Used the packet tracer in ASA, it shows the packet is flowing outside without a drop.
3.  Allowed all services in untrust zone in bound traffic in Juniper SRX.
4. Viewed the logs when I was trying the ping in ASA. It says "Tear down ICMP connection for faddrr **** gaddr **

View 2 Replies View Related

Home Network :: Setting Up A Small Home Network Of 10 PC's?

Jul 27, 2012

want to setup a small home network of about 10 PC's.I want them to share the internet connection of 25mbps.I also want Printer Sharing.

View 2 Replies View Related

Home Network :: Setting Up Two Wireless Connections In The Same House?

Aug 3, 2011

I currently have one wireless router in my house. Of course its hooked up the the modem, but i also have it hooked up directly to my desktop considering the router is on the desk where my computer is.I recently moved to a new house.One of the rooms has a huge brick wall in it, unfortunately the computer is in that room.AND, its on the far left side of the house, so the other side of the wall barely gets any signal (Enough to work, but it bounces and only gets about 2 Megabytes Per Second, which is awful, because the router sends out 20 megabytes per second due to our internet plan.) Now, my room is all the way on the far right side of the house, in my room, i get barely any connection at all, 20% is normal in my room. I have my Playstation 3 in my room, so I had to wire an ethernet cable from the wireless router, up through the attic, to my PS3. I can now get 20 MBPS while playing video games. While that is great, i still don't have a wireless connection back there.

What i want to know is, can i plug in another wireless router to the ethernet cable in my room, sending out another signal. So basically, im plugging up a wireless router to another wireless router, and want them to both send out internet.I plan on getting a gaming laptop in December and will be playing it most of the time in my room. I need to know if this is possible, and if it is, how do i do it?First off, let me state that moving the computer or router in front of the brick wall is completely out of question.Also, know a lot of stuff about computers, but know almost nothing about networking.

View 7 Replies View Related

Setting Up Home File Server - Ubuntu Or FreeNAS?

Jun 15, 2012

I have a PC ready to use that I want to be used for sharing files, pictures and videos on between our multiple PCs in the house hold. I am going to have it constantly running (I have alot of cooling for it) but I need setting it up. I dont know if I should use Ubuntu Server or FreeNAS?

View 1 Replies View Related

D-Link DIR-655 :: Setting Up AppleTV Or ITunes Home Share

Mar 2, 2011

If you can't home share on iTunes between Computers or AppleTV, try turning multicast on

1) login to router
2) Go to Advanced tab
3) Select Advanced Networking on Left hand column
4) Select checkbox to enable multicast streams
5) Save the changes

In order to get all my machines working, I also had to enable multicast streams on my network extender as well.  The IP address for the network extender is or type in DLINKAP in the URL bar and follow the relevant instructions for your model number.

Please note if you use a software firewall on your PC or Mac, you may need to also free up TCP port 3689 and UDP port 5353.  However there are plenty of support articles at Apple / Norton / Microsoft / etc... on how to do this for your relevant firewall..

View 4 Replies View Related

Copyrights 2005-15, All rights reserved