Cisco Firewall :: Allow Printing Through ASA 5505
Apr 4, 2013I have a Cisco ASA 5505 and i need to allow printing from an outside network.
View 2 RepliesI have a Cisco ASA 5505 and i need to allow printing from an outside network.
View 2 RepliesI am trying to protect the computing assets on a perimeter firewalled / protected LAN from visiting laptops while still permitting the laptops wifi internet access and printing priviledges on the LAN's networked HP printer To do that I was thinking of setting up a computer as a dedicated firewall with 3 NICs (external internet, internal LAN and a DMZ for a Guest wifi router for use by the visiting laptops). (Will probably use free Untangle Firewall software software or such on the dedicated firewall computer).What I can't figure out is the firewall's topology, IP ranges and rules / forwarding that would permit such laptop operation.I would think it would be a common need for small offices but can't find much material on the subject.I do understand that such would slightly weaken the firewall but feel that I would gain more security overall.
View 2 Replies View RelatedHow I can actively monitor the interfaces and overall status of 2 x ASA 5500s in an Active/Standby configuration?
I can setup monitoring of the interfaces on the Active member but I'm not sure how to manage the Standby member?
We were having a discussion of ios firewall vs. asa for smaller clients(less than 50). On using ios firewall(zbf or cbac)and an asa 5505/5510. One of the arguments brought up on using ios firewall on the router is that a router will do an ip sla failover. I have configured a number of isr's for this and i know it works good.
View 1 Replies View RelatedI have a Cisco ASA 5505 in our office. We are currently using Interface 0 for outside and 1 for inside. We only have 1 Vlan in our environment. We have two three switches behind the firewall. Today the uplink to Interface 1, to the firewall, on the switch went bad. I want to setup a second inside interface on the firewall and configure it as failover incase this happens again. I want to attach it to the other switch. Can I do this? If so, what do I need to do? would it only be a passive/standby interface?
View 1 Replies View Relatedsetting up an ASA 5505 to be used as a firewall between a BT internet router(BTNet service) and a Cisco 3560 Lan switch. BT have presented me with a cisco 3800 series router with the following details:
Network Address Network Mask BTnet NTE Router LAN Address
There are 2 Gigethernet ports on the back of the router port Ge0/0 is connected to the BT NTE and the status light is flashing green. Int ge0/1 is connected into port int e0/1 of the ASA but i am unable to get any connection.
I'd like to see some REAL LIFE comparisons of ASA firewall throughput (a bit like this one for ISR G2 Routers - [URL].
The reason I ask is that I recently upgraded a firewall from an ASA5505 to an ASA5520 on a small network where the only outside connectivity was a single 10meg Internet circuit with an IPSEC VPN (not landed on the firewall but on a router) to another site.
When I swapped out the firewall the users noticed a big improvement. The firewall is not doing anything out of the ordinary - no IPS or VPN, just standard state full inspection.
Trying to set up a asa 5505 in transparent firewall mode. I cannot set the management ip address:
ciscoasa> enable
Password:
ciscoasa# config term
[Code].....
I have been working with ASA 5510,20,40,80 but not with 5505 this vlan and its interfaces are quite confusing.Just want to know how it works and its connectivity to Cisco Switch.Do i have to put the interface of the switch in the same vlan as i am creating the interface vlan in firewall ?Now the switch port connecting to this Eth1 interface should also be in the same vlan ? i.e vlan3 ?? or it will be in trunk ? The default configuration shows the eth0 with no access vlan and interface eth1 with access vlan 2... does it mean the eth0 is in vlan1 ? (Nativ Vlan ) ???
View 4 Replies View RelatedI have a cisco asa 5505 firewall. Is it possible to block secure websites in it like [URL]? I have already tried regular expression filtering but it filters only http traffic.
View 4 Replies View RelatedI am trying to configure our ASA 5505 so that our users can access our ftp site using [URL] while inside the firewall. Our ftp site is setup so that you can reach it by either browsing to the above url or by browsing to ftp://99.23.119.78 but we are unable to access our ftp site from either route while inside the firewall. We can access our ftp site using the internal ip address of 192.168.1.3.
Here is our current confguration:
Result of the command: "show running-config"
: Saved:ASA Version 8.2(1) !hostname ciscoasaenable password qVQaNBP31RadYDLM encryptedpasswd 2KFQnbNIdI.2KYOU encryptednames!interface Vlan1nameif insidesecurity-level 100ip address 192.168.1.1 255.255.255.0 !interface Vlan2nameif ATTsecurity-level 0pppoe client vpdn group ATTip address pppoe setroute !interface Ethernet0/0switchport access vlan 2!interface Ethernet0/1!interface Ethernet0/2!interface Ethernet0/3!interface Ethernet0/4!interface Ethernet0/5!interface Ethernet0/6!interface Ethernet0/7!ftp mode passiveobject-group service DM_INLINE_TCP_1 tcpport-object eq ftpport-object eq ftp-dataport-object eq wwwaccess-list ATT_access_in extended permit tcp any host 99.23.119.78 object-group DM_INLINE_TCP_1 access-list ATT_access_in extended permit tcp any interface ATT eq ftp access-list ATT_access_in extended permit tcp any interface ATT eq ftp-data access-list ATT_access_in extended permit tcp any interface ATT eq www access-list 100 extended permit tcp any interface ATT eq ftp
[code]....
New to the ASA 5505 8.4 software version, but here is what I'm trying to do:
-Single static public IP: 16.2.3.4
-Need to PAT several ports to three separate servers behind firewall
-One server houses email, pptp server, ftp server and web services: 10.1.20.91
-One server houses drac management (port 445): 10.1.20.92
-One server is the IP phone server using a range of ports: 10.1.20.156
Basically, need to PAT the ports associated with each server to the respective servers behind the ASA 5505. Is anything missing from this config? Do I need to include a global policy for PPTP and SMTP? [code]
I'm integrating a Cisco ASA5505 with a Websense proxy. I have a configuration setup where we have four routers which are used for Internet access. There are two VLAN's - Guest and Private. What I would like to achieve is making the use of available bandwidth by load distribution via GLBP, and filtering users web traffic. Two routers will be used for a GLBP group in one VLAN, and the other two routers will be used for GLBP in another VLAN.The users are connected to a Cisco 2960 switch and are in their respective VLAN's. I'm planning a 802.1q trunk to a Cisco ASA from the 2960 switch, carrying both VLAN's.What I would like to know is if there is a CSC module (or similar) which has Websense installed on it, and if it is possible to setup the ASA5505 in transparent mode to filter the traffic in this way? Hopefully this would allow multiple users to take advantage of the additional bandwidth, and not be restricted by using a traditional proxy setup which where all web traffic would be originating from a single MAC address.
View 1 Replies View RelatedI have an issue with my firewall,each time i configured a trunk port in the firewall and connect a sw 2960S with a trunk port also, all the interfaces in the Firewall go down ( virutal intertaces, inside, outside , dmz) , also another switch 3750 that is connected to another port in the firewall( access port only) it start to a new negotiation of spanning tree.What could be causing this problem? the firewall didnt sedn bdpdu i think the IOS of the firewall its a 8.2
View 3 Replies View Relatedwe are planning on connecting a new aquired company to ours soon?We will connect the remote site to the HQ via a D3. I've been told we will need to have a firewall between them and us for a time. I was thinking of terminating the D3 connection at the remote site of 80 users. Can I use the asr as a firewall as well, to protect the HQ from the Remote site - or should I use a seperate appliance?I was thinking of a asa5505 but, am concerned with bandwidth limitations of the box?
View 1 Replies View RelatedI want to configure an ASA 5505 in transparent mode (7.x). Somehow, I got it to work.. but i need some kind of step by step description. I just want to connect it with outside on a route .. inside in my LAN. Its working now with one ASA. But in the Web Interface the Interfaces inside and outside are down.. but its working.
View 5 Replies View RelatedThe scenario I am facing is, trying to have the ability to print from my laptop computer remotely to my home printer which supports IPP.What I did so far was to make sure that I enabled IPP in the printer. So the URL is 192.168.1.101:631. (I am able to connect and print to the printer on local network usinghttp://192.168.1.101:631.) I then went into my router and enabled port forwarding for that address and made sure to specify port 631. It doesn't work. I took the following steps: (It works neither with XP or 7)Windows 7 Steps:1. Start-Devices and Printer2. Add a printer3. Add a network, wireless or Bluetooth printer4. Clicked "The printer that I want isn't listed5. Choose "Select a shared printer by name" Below is the scheme I followedWhat is the proper way of setting this to function properly so that I can print to my computer remotely. I want to be able to print to the printer directly and not through a server or another computer. Is this even possible?
View 2 Replies View RelatedI need to be VPN'd in to work all day but during the day I need to print to my home network printer. The work around has always been to press print then disconnect from VPN, wait for the document to finish then reconnect VPN. This is starting to get on my nerves and I was hoping that there was a way to be on VPN through my physical LAN and maybe print over my wireless network. Is there a way to separate traffic in Windows 7?
View 2 Replies View RelatedWhen I upgrade the ios on switches, I just create int vlan1 assign it an ip and subnet, then tftp to my pc that is plugged into the switchport using the download-sw command.
I am not sure how to do this on the asa. Do I just plug my pc into port 0 which the documentation says is mapped to vlan 1 with and ip of 192.168.1.1? I tried this by making my pc's ip 192.168.1.2 but am unable to ping the asa. Do I have to change the security level or anything?
I’ve been using a Cisco ASA 5505 Security Plus bundle for two years now without any problems. My previous Internet Service Provider was routing the external IP I was leasing directly through to my internal network without NAT which my ASA 5505 was working well with. Thus, I had configured my 5505 to provide NAT to my inside network which includes two subnets one for my workstations and internal "private" resources and a DMZ to provide access to my webserver, email server and two domain name servers; but restrict access to my internal; resources. i recently changed my ISP to Verizon FiOS (which is providing me with 25 Mb bandwidth at a fraction of the cost of my old T1) which is set up to provide 5 Static externally facing IP numbers for my email, webserver and name servers;. The problem is the Verizon router doesn’t support my use of the ASA Appliance (at least not the way it is currently configured. Verizon recommend I purchase a business class router and use it in place of the one they provided with my installation. With this in mind, I bought a Cisco RVS4000. I have configured it to use the primary external IP number and have internet access; however, the new router is providing NAT addressing which the ASA is in conflict with (they are both using the same NAT IP range). I'm assuming the ASA 5505 is expecting to have access to the external IP addressed (since that is what it was getting before) and NOT NAT address. How to configure the new router to either provide access to the five static external “real world” IP to my Cisco ASA Firewall. However, I just need to get my ASA 5505 back in the loop and would prefer to do this rather than go back to the Verizon router combined with a low end firewall. So, my questions are: Does the ASA 5505 expect real world External IP numbers? Or can it work with NAT addresses being fed to it from the router? And, if so, how do I configure the access rules and other items which are currently mapping to external numbers?
View 27 Replies View RelatedI am configuring a Cisco ASA 5505 firewall.In the office there is 1 x SBS 2008 server and 5 x PCs, all sat behind a Netgear DGN1000 ADSL router.We want to implement a ASA 5505 for added security.I have configured the internal interface of the Cisco ASA 5505 to be 192.168.0.1 - this is connected to local switch. The client PCs use 192.168.0.1 as their default gateway.I have configured the external ASA 5505 interface to be x.x.x.217. [code]Change the current router status from Router/Firewall/Modem to Modem only (Bridge mode). The ASA 5505 has its outside interface connected into one of the LAN ports of the netgear. The lan port has an IP of 192.168.0.254.
View 3 Replies View Relatedwhen i am booting ASA firewall i am getting the following error.
<0>Kernel panic - not syncing: Attempted to kill init! and it stops and will not work. check below the whole log file
how can i solve this issue?
Log file:
Evaluating BIOS Options ...Launch BIOS Extension to setup ROMMON
Cisco Systems ROMMON Version (1.0(12)11) #4: Thu May 1 14:50:05 PDT 2008
Platform ASA5505
Use BREAK or ESC to interrupt boot.Use SPACE to begin boot immediately.
Launching BootLoader...Boot configuration file contains 1 entry.
[Code]...
Over the course of the past three days, our ASA 5505 firewall has shut down twice. I looked through the Field Notices and it looks like this was a problem identified several years ago that was resolved for units built after June 1, 2007. The serial number on our unit is not in the "effected" range.
View 1 Replies View RelatedMy printer is hard wired to my wireless router, allowing me to print wirelessly from my laptop. After successfully printing this way, it is no longer working. I have tried re-installing the software, however, it is unable to "find" the printer. I have tried this from 2 laptops with no success. My wireless router appears to be working as far as internet.
View 1 Replies View Relatedi want give the dos printing from remote desktop to local computer on anotherlocation
View 2 Replies View RelatedI'm having trouble printing from anything other than "windows desktop 1" (exclude "xbox 360 & Apple TV) So I need to know how to setup printing on the "macbook pro", "Windows laptop" & "windows desktop 2" These computer (except the macbook) all were connected once and I did have home group successfully connected to share the printer between them all as long as "windows desktop 1" was on. But now there in the setup in the pic and the home group and printers don't communicate with each other anymore.
View 3 Replies View RelatedFrom my Dell Vostro laptop I can connect to the internet but cannot print wirelessly on any of my three printers. The Mac computer in the house works on one printer.Not really sure where to start working on this problem.
View 1 Replies View RelatedA weird issue that came up a couple weeks ago, about 15 users that print to network printer via IP. The printer is attached to a print controller with all print jobs are spooled to.
So when a user prints, lets say three pages, it spools to the windows queue and each page takes about 1.5min to get to the print controller queue, when it would only take a few seconds to spool.
Different switches, print drivers..etc have been tried and narrow it down to one thing. When working with the NAS server plugged into the switch, that's when it takes long but when unplug from the NAS, prints come out fast like normal.
how to find out if the NAS is broadcasting some crazy traffic? but it seems that it's only affecting this printer, other printers that don't have a controller print out fine and fast.
A friend has asked me to work with him set up a new office. He already has a PC and a phone line but not broadband, so he is going to organise that and getting a wireless router.He wants a wireless colour laser printer so that his visitors/guests can print easily from his office, or the next office. Does he really need a wireless printer to do this? Or if I plug a network printer directly into his router with an Ethernet cable, same with his PC, will that enable laptop users to print wirelessly (assuming they know the router passphrase of course)? I guess they would need to install the relevant printer driver to do this too.
View 2 Replies View RelatedThis is to see if I am the only one disappointed with the Mapping portion of Cisco Prime Infrastructure: my disappointments are as follows: The Map can only be zoomed up to a certain size, under WCS and NCS we could almost zoom indefinitely into the map.2. The edit map sizing tool bit and its working has changed and quite difficult to use, the tool tip has changed into a small square, and uses double click which are not as intuitive as before, why change a working thing?3. Printing the Map is almost like priting the screen, when you say print you are telling it to print the map and not how it appears on your screen, for there are other tools like snagit or greenshot.
View 1 Replies View RelatedI have walked into a company that has several small (1-4 PC's each) remote locations, and they all connect to Terminal Server to use our POS app. This app will not keep redirected printers saved between each session, so in order to save the printers, they have software VPN's set up on each client, then the local printers are installed on the server through a Local Port using the VPN ipaddressprinter share name. This allows the printers to be saved in the program and not re-assigned each session. Now, let's say that I have implemented a new desktop replacement procedure, and we are now in phase one of said procedure. I have purchased Windows 7 64-bit desktops. After setting up my deployment standards and testing in-house, I placed one of these PC's in the field. This is where I learned the issues of printing from a 32-bit server to a 64-bit client. I have not been able to successfully print to the printer installed on the server using the Local Port of the client, print job errors out. I have done some research, and found the issues with printing from 32-bit to 64-bit, and have installed all the additional drivers I can find, with no success.
View 1 Replies View RelatedShared printer not printing. Have two PCs, one with Vista OS with the printer connected and the other XP, both connected via network sharing. I cannot print from the XP PC. It says I do not have permission even though I have shared the printer.
View 4 Replies View RelatedI've tried scanning for viruses, using winsock fix (they had a static ip I also set to automatic since they should not need it). I just turned off the firewall as well, tried "selective startup" and unchecked "load startup items" and nothing has worked so far. We're working on giving them another computer but I'd like to know why this happens.
View 7 Replies View Related