Cisco Firewall :: Maxed Out With ASA 5505

Jun 17, 2012

Looking at upgrading an ASA 5505 I've inherited.  Wondering what type of license(s) I need to get (or if I should look at a different solution) to "max it out"

So.. there are 8 switch ports.  I know I can create vlans, and assign vlans to individual switchports.  But can I fully use ALL 8 ports? and have 8 security segments? If I wanted to 'max out' the available subnets, would the following arrangement be feasible?

Port Level VLAN Name (Function)E0/0 o 1 outside (ISP)E0/1 100 100 inside (corp)E0/2 20 20 sec_logs (security management/logging)E0/3 30 30 dmz_prod (PRODUCTION DMZ)E0/4 40 40 guestaccess (Internet access for guests)E0/5 50 50 labnet_1 (test lab subnet)  E0/6 60 60 labnet_2 (test lab subnet)E0/7 70 70 labnet_3 (test lab subnet)

Finally, I'd really like (not NEED) to have this config with GigE ports vs FastE ports.  Money is not unlimited, but I do need to stay as low as possible (and still stay Cisco).. I'd love to see some maxed (or nearly so) sample configs (sanitized, of course).

View 9 Replies


ADVERTISEMENT

Cisco :: Bandwidth Allocation - Connection Is Maxed Out?

Feb 5, 2013

We have a DSL line at work which a few people share for Internet access.Sometimes if someone is doing a Windows Update or big download etc, the connection is maxed out and slow for everyone else.Is there a way to give everyone a set amount of bandwidth via a Cisco router (2811) or will I need to use something like a packeteer?

View 4 Replies View Related

Cisco :: Redundancy For Maxed Out 4404 Controller

Apr 27, 2011

We currently have a 4404 controller that is approaching 100 AP’s (their max).  The boss would like to add redundancy into the project.  Which leaves me with a lot of questions and I am fairly new to cisco WLAN controllers.While a second 4404 would cover for redundancy would that be true if the AP’s pass the 100 mark?If I get a bigger controller that can support more than 100 (5508?)can the existing 4404 still work in the plan as a backup?Or do I just need to purchase two bigger units and auction off the 4404?

View 3 Replies View Related

DLink DIR-655 Router Maxed Out On Allowed MAC Address?

Nov 30, 2011

I use a DLink DIR-655 router but it only allows around 24 MAC addresses to be specified in the filter list of ALLOWED MAC ADDRs. With a few laptops in the family, a game box, NAS, printer, e-readers, smart phones, I'm maxed out. Alternatively, could I daisy chain them to have one handle wireless devices only and another handle wired devices? If so, I could probably dealt with 24 max wireless MAC addresses specified for a while. If there's a better router out there that's not so limited, I'll upgrade.

View 2 Replies View Related

Cisco Switching/Routing :: Nexus 5548 - Fans Maxed Out All The Time

Apr 22, 2013

I've just plugged in 4 Nexus5548 switches and ran through the initial setup without any issues. However, the fans seem to be stuck on full speed. At the moment they're the loudest thing in the server room.
 
I know this isn't the most recent OS however I was hoping to avoid updating if necessary as I don’t have the service agreement linked to my account and can’t download the update without it. Is there anything else I can try first or anything I have missed?

Software  BIOS:      version 3.5.0  loader:    version N/A  kickstart: version 5.1(3)N1(1a)  system:    version 5.1(3)N1(1a)  power-seq: Module 1: version v1.0  Module 3: version v2.0  uC:        version v1.2.0.1  SFP uC:    Module 1: v1.0.0.0  BIOS compile time:    

[Code]......

View 1 Replies View Related

Cisco Firewall :: Monitoring ASA 5505 Firewall Active / Standby Pair Using SNMP?

Sep 7, 2011

How I can actively monitor the interfaces and overall status of 2 x ASA 5500s in an Active/Standby configuration?
 
I can setup monitoring of the interfaces on the Active member but I'm not sure how to manage the Standby member?

View 1 Replies View Related

Cisco Firewall :: IOS Firewall Versus ASA (5505 / 5510) For Smaller Clients (less Than 50)?

Apr 24, 2012

We were having a discussion of ios firewall vs. asa for smaller clients(less than 50). On using ios firewall(zbf or cbac)and an asa 5505/5510.  One of the arguments brought up on using ios firewall on the router is that a router will do an ip sla failover.  I have configured a number of isr's for this and i know it works good. 

View 1 Replies View Related

Cisco Firewall :: Failover ASA 5505 - Setup Second Inside Interface On Firewall?

Feb 19, 2012

I have a Cisco ASA 5505 in our office. We are currently using Interface 0 for outside and 1 for inside. We only have 1 Vlan in our environment. We have two three switches behind the firewall. Today the uplink to Interface 1, to the firewall, on the switch went bad. I want to setup a second inside interface on the firewall and configure it as failover incase this happens again. I want to attach it to the other switch. Can I do this? If so, what do I need to do? would it only be a passive/standby interface?

View 1 Replies View Related

Cisco Firewall :: Setting Up ASA 5505 To Be Used As Firewall Between BT Internet And 3560 LAN Switch?

Aug 23, 2011

setting up an ASA 5505 to be used as a firewall between a BT internet router(BTNet service) and a Cisco 3560 Lan switch. BT have presented me with a cisco 3800 series router with the following details:

Network Address   Network Mask  BTnet NTE Router LAN Address
      
There are 2 Gigethernet ports on the back of the router port Ge0/0 is connected to the BT NTE and the status light is flashing green. Int ge0/1 is connected into port int e0/1 of the ASA but i am unable to get any connection.

View 21 Replies View Related

Cisco Firewall :: Upgrade From 5505 To 5520 On Network - ASA Firewall Throughput

Feb 27, 2013

I'd like to see some REAL LIFE comparisons of ASA firewall throughput (a bit like this one for ISR G2 Routers - [URL].
 
The reason I ask is that I recently upgraded a firewall from an ASA5505 to an ASA5520 on a small network where the only outside connectivity was a single 10meg Internet circuit with an IPSEC VPN (not landed on the firewall but on a router) to another site.
 
When I swapped out the firewall the users noticed a big improvement. The firewall is not doing anything out of the ordinary - no IPS or VPN, just standard state full inspection.

View 5 Replies View Related

Cisco Firewall :: 5505 - Setting Transparent Firewall Ip Address?

Dec 22, 2011

Trying to set up a asa 5505 in transparent firewall mode. I cannot set the management ip address:
 
ciscoasa> enable
Password:
ciscoasa# config term

[Code].....

View 7 Replies View Related

Cisco Firewall :: ASA 5505 Creating Interface Vlan In Firewall

May 3, 2011

I have been working with ASA 5510,20,40,80 but not with 5505 this vlan and its interfaces are quite confusing.Just want to know how it works and its connectivity to Cisco Switch.Do i have to put the interface of the switch in the same vlan as i am creating the interface vlan in firewall ?Now the switch port connecting to this Eth1 interface should also be in the same vlan ? i.e vlan3 ?? or it will be in trunk ? The default configuration shows the eth0 with no access vlan and interface eth1 with access vlan 2... does it mean the eth0 is in vlan1 ? (Nativ Vlan ) ???

View 4 Replies View Related

Cisco Firewall :: ASA 5505 Firewall To Filter HTTPS Websites?

May 28, 2012

I have a cisco asa 5505 firewall. Is it possible to block secure websites in it like [URL]? I have already tried regular expression filtering but it filters only http traffic.

View 4 Replies View Related

Cisco Firewall :: ASA 5505 - Can't Reach FTP Site While Inside Firewall?

Feb 26, 2011

I am trying to configure our ASA 5505 so that our users can access our ftp site using [URL] while inside the firewall. Our ftp site is setup so that you can reach it by either browsing to the above url or by browsing to ftp://99.23.119.78 but we are unable to access our ftp site from either route while inside the firewall. We can access our ftp site using the internal ip address of 192.168.1.3.
 
Here is our current confguration:
 
Result of the command: "show running-config"
: Saved:ASA Version 8.2(1) !hostname ciscoasaenable password qVQaNBP31RadYDLM encryptedpasswd 2KFQnbNIdI.2KYOU encryptednames!interface Vlan1nameif insidesecurity-level 100ip address 192.168.1.1 255.255.255.0 !interface Vlan2nameif ATTsecurity-level 0pppoe client vpdn group ATTip address pppoe setroute !interface Ethernet0/0switchport access vlan 2!interface Ethernet0/1!interface Ethernet0/2!interface Ethernet0/3!interface Ethernet0/4!interface Ethernet0/5!interface Ethernet0/6!interface Ethernet0/7!ftp mode passiveobject-group service DM_INLINE_TCP_1 tcpport-object eq ftpport-object eq ftp-dataport-object eq wwwaccess-list ATT_access_in extended permit tcp any host 99.23.119.78 object-group DM_INLINE_TCP_1 access-list ATT_access_in extended permit tcp any interface ATT eq ftp access-list ATT_access_in extended permit tcp any interface ATT eq ftp-data access-list ATT_access_in extended permit tcp any interface ATT eq www access-list 100 extended permit tcp any interface ATT eq ftp

[code]....

View 6 Replies View Related

Cisco Firewall :: 5505 PAT With Single Public IP And Several Servers Behind Firewall

Nov 21, 2012

New to the ASA 5505 8.4 software version, but here is what I'm trying to do:
 
-Single static public IP:  16.2.3.4
-Need to PAT several ports to three separate servers behind firewall
-One server houses email, pptp server, ftp server and web services: 10.1.20.91
-One server houses drac management (port 445): 10.1.20.92
-One server is the IP phone server using a range of ports: 10.1.20.156
 
Basically, need to PAT the ports associated with each server to the respective servers behind the ASA 5505.  Is anything missing from this config? Do I need to include a global policy for PPTP and SMTP? [code]

View 11 Replies View Related

Cisco Firewall :: ASA 5505 Transparent Firewall With Web Sense Integration

Apr 27, 2011

I'm integrating a Cisco ASA5505 with a Websense proxy. I have a configuration setup where we have four routers which are used for Internet access. There are two VLAN's - Guest and Private. What I would like to achieve is making the use of available bandwidth by load distribution via GLBP, and filtering users web traffic. Two routers will be used for a GLBP group in one VLAN, and the other two routers will be used for GLBP in another VLAN.The users are connected to a Cisco 2960 switch and are in their respective VLAN's. I'm planning a 802.1q trunk to a Cisco ASA from the 2960 switch, carrying both VLAN's.What I would like to know is if there is a CSC module (or similar) which has Websense installed on it, and if it is possible to setup the ASA5505 in transparent mode to filter the traffic in this way? Hopefully this would allow multiple users to take advantage of the additional bandwidth, and not be restricted by using a traditional proxy setup which where all web traffic would be originating from a single MAC address.

View 1 Replies View Related

Cisco Firewall :: 5505 ASA Trunk Port In Firewall

Apr 30, 2012

I have an issue with my firewall,each time i configured a trunk port in the firewall and connect a sw 2960S with a trunk port also, all the interfaces in the Firewall go down ( virutal intertaces, inside, outside , dmz) , also another switch 3750 that is connected to another port in the firewall( access port only) it start to a new negotiation of spanning tree.What could be causing this problem? the firewall didnt sedn bdpdu i think the IOS of the firewall its a 8.2

View 3 Replies View Related

Cisco Firewall :: 5505 Firewall Between HQ And Remote Site

Jun 12, 2012

we are planning on connecting a new aquired company to ours soon?We will connect the remote site to the HQ via a D3. I've been told we will need to have a firewall between them and us for a time. I was thinking of terminating the D3 connection at the remote site of 80 users. Can I use the asr as a firewall as well, to protect the HQ from the Remote site - or should I use a seperate appliance?I was thinking of a asa5505 but, am concerned with bandwidth limitations of the box?

View 1 Replies View Related

Cisco Firewall :: ASA 5505 Transparent Firewall Configuration?

Sep 11, 2007

I want to configure an ASA 5505 in transparent mode (7.x). Somehow, I got it to work.. but i need some kind of step by step description. I just want to connect it with outside on a route .. inside in my LAN. Its working now with one ASA. But in the Web Interface the Interfaces inside and outside are down.. but its working.

View 5 Replies View Related

Cisco Firewall :: Update ASA 5505 Firewall IOS?

Nov 11, 2011

When I upgrade the ios on switches, I just create int vlan1 assign it an ip and subnet, then tftp to my pc that is plugged into the switchport using the download-sw command.
 
I am not sure how to do this on the asa.  Do I just plug my pc into port 0 which the documentation says is mapped to vlan 1 with and ip of 192.168.1.1? I tried this by making my pc's ip 192.168.1.2 but am unable to ping the asa.  Do I have to change the security level or anything?

View 1 Replies View Related

Cisco Firewall :: RVS4000 NAT To ASA 5505 Firewall?

Mar 18, 2011

I’ve been using a Cisco ASA 5505 Security Plus bundle for two years now without any problems. My previous Internet Service Provider was routing the external IP I was leasing directly through to my internal network without NAT which my ASA 5505 was working well with. Thus, I had configured my 5505 to provide NAT to my inside network which includes two subnets one for my workstations and internal "private" resources and a DMZ to provide access to my webserver, email server and two domain name servers; but restrict access to my internal; resources. i recently changed my ISP to Verizon FiOS (which is providing me with 25 Mb bandwidth at a fraction of the cost of my old T1) which is set up to provide 5 Static externally facing IP numbers for my email, webserver and name servers;. The problem is the Verizon router doesn’t support my use of the ASA Appliance (at least not the way it is currently configured. Verizon recommend I purchase a business class router and use it in place of the one they provided with my installation. With this in mind, I bought a Cisco RVS4000. I have configured it to use the primary external IP number and have internet access; however, the new router is providing NAT addressing which the ASA is in conflict with (they are both using the same NAT IP range). I'm assuming the ASA 5505 is expecting to have access to the external IP addressed (since that is what it was getting before) and NOT NAT address. How to configure the new router to either provide access to the five static external “real world” IP to my Cisco ASA Firewall. However, I just need to get my ASA 5505 back in the loop and would prefer to do this rather than go back to the Verizon router combined with a low end firewall. So, my questions are: Does the ASA 5505 expect real world External IP numbers? Or can it work with NAT addresses being fed to it from the router?  And, if so, how do I configure the access rules and other items which are currently mapping to external numbers?

View 27 Replies View Related

Cisco Firewall :: Configuring ASA 5505 Firewall

Sep 21, 2012

I am configuring a Cisco ASA 5505 firewall.In the office there is 1 x SBS 2008 server and 5 x PCs, all sat behind a Netgear DGN1000 ADSL router.We want to implement a ASA 5505 for added security.I have configured the internal interface of the Cisco ASA 5505 to be 192.168.0.1 - this is connected to local switch. The client PCs use 192.168.0.1 as their default gateway.I have configured the external ASA 5505 interface to be x.x.x.217. [code]Change the current router status from Router/Firewall/Modem to Modem only (Bridge mode). The ASA 5505 has its outside interface connected into one of the LAN ports of the netgear. The lan port has an IP of 192.168.0.254.

View 3 Replies View Related

Cisco Firewall :: ASA 5505 Firewall Booting

Jan 6, 2013

when i am booting ASA firewall i am getting the following error.

<0>Kernel panic - not syncing: Attempted to kill init! and it stops and will not work. check below the whole log file
 
how can i solve this issue?
 
Log file:
Evaluating BIOS Options ...Launch BIOS Extension to setup ROMMON
Cisco Systems ROMMON Version (1.0(12)11) #4: Thu May  1 14:50:05 PDT 2008
Platform ASA5505
Use BREAK or ESC to interrupt boot.Use SPACE to begin boot immediately.
Launching BootLoader...Boot configuration file contains 1 entry.
[Code]...

View 1 Replies View Related

Cisco Firewall :: ASA 5505 Firewall Shut Down

Dec 19, 2012

Over the course of the past three days, our ASA 5505 firewall has shut down twice.  I looked through the Field Notices and it looks like this was a problem identified several years ago that was resolved for units built after June 1, 2007.  The serial number on our unit is not in the "effected" range. 

View 1 Replies View Related

Cisco Firewall :: How To Add 861 Behind ASA 5505

Feb 18, 2013

I will be setting up a VPN with a client soon.  They are shipping 2 Cisco 861's that are planning to go behind our ASA 5505.  They are set up to be NATed.I am trying to understand what the best way to do this would be as I seem to keep running into limitations of the ASA 5505. Our ASA has a public IP of 2.1. 2.14/30 assigned to it's outside interface.The public IPs to be NATed to the 861's are 2.1.2.218 and 2.1.2.219/29.
 
1. How can I assign this seperate public IP block to the ASA? Is it even possible?

2. If not possible, what would other options be?

3. Would an upgraded license that allows for additional interfaces make this easier? (I would not do the NATing then, just assign the new public IP block to another interface)

View 4 Replies View Related

Cisco Firewall :: ASA 5505 How To Use CLI

Apr 24, 2011

My company purchased a Cisco ASA 5505 firewall from our phone company, who installed and configured it but will no longer support it.
 
The first thing you should probably know is that I make no claims to know anything about Cisco equipment.  My primary job is a Web developer, so I can work with Linux boxes, and usually fix them, but this thing is a Mystery to me.
 
The Quick Start guide url... says I can use ASDM if I go to url... When I try this with either Firefox or MSIE 8, the connection times out and I can't get to ASDM (which I was able to find instructions for)I am able to telnet in to the firewall, but have no clue how to use the Cisco CLI.
 
I was able to locate a 3800 page manual online, but since my primary function is actually production, and I need to produce products for our customers, I don't have much time to read and work through the manual to find what I need to know.All I have is the firewall itself.  No printed manual, or software CD as mentioned on most of the online stores I can buy the device from.
 
Howto get ASDM working, or instructions on how to open up Port 23 so I can NAT it to 192.0.0.112 ?Just in case it is important, when the phone company installed our firewall config, we had them NAT port 80 to one server and 443 to another, so if these will affect what needs to be done, I can provide more information.

View 1 Replies View Related

Cisco Firewall :: Can't Access ASA 5505 Via SSH

Apr 23, 2010

I can't access our ASA 5505 via SSH from the outside. I've configured this through the ASDM to allow SSH (Device Management > Management Access > ASDM/HTTPS/Telnet/SSH). I added a rule that allows SSH on the outside interface from 0.0.0.0 0.0.0.0. When I try to ssh in with putty, it says "server unexpectedly closed network connection" When I watch the logs on the ASA, it shows a Built inbound TCP connection on port 22, but then immediately a Teardown TCP connection. It doesn't show it's being blocked by any rule. Is there something I'm missing on enabling SSH?

View 13 Replies View Related

Cisco Firewall :: ASA 5505 IP Routing

Apr 8, 2013

I am new to the ASA so I am not completely familiar with it's ins and outs but here is the situation.I have a VPN connection that my company uses regularly. I have the VPN Pool on 192.168.18.0/25 and my Internal network at 192.168.16.0/24. My problem is that I have my phone system on 192.168.16. 254 and the only way to see it is if I change the pool to be within the same IP range as my internal network. The catch is that if I do this then that is the ONLY IP that is available to that VPN connection. Is there a way to make the 192.168.16.254 available to 192.168.18.0/25?

View 7 Replies View Related

Cisco Firewall :: CSC Modules On ASA 5505?

Mar 25, 2012

Is it possible to install Content Security and Control (CSC) Modules on ASA 5505 ? Or only AIP SSC-5 Modules are the only modules that can be installed on ASA 5505s ?

View 3 Replies View Related

Cisco Firewall :: Two Host With Same Nat On ASA 5505

Mar 22, 2011

I have 2 web servers that replicate between them (two different internal ip). My idea is that if one of them will not work, the other to do the relay.I have a Cisco ASA 5505 I can do a nat for each machine. How should I set ?

View 3 Replies View Related

Cisco Firewall :: Could URL Filtering Be Done On ASA 5505 BUN-K9

May 16, 2013

Could URL FIltering be implemented on Cisco ASA 5505-BUN-k9?i mean to block certain websites, like facebook, youtube, to block certain download files like .exe, .com .bat etc....Is there any extra license needed for this, or it could be done with the simple IOS ASA5505-bun-k9?

View 4 Replies View Related

Cisco Firewall :: Sub Interface On ASA 5505?

Dec 10, 2012

I want to creat sub int on ASA 5505 but when I am trying below command it show error.

------------------------------------
config t
int f0/0.3400
------------------------------------

My ASA software version is 8.2(5).

View 5 Replies View Related

Cisco Firewall :: Asa 5505 Cannot See Videos Through This

Aug 4, 2012

We have an ASA-5505 running 8.2(1) with a Bosch DVR 600. When a machine is on the local subnet, it can see the video; however, when it's moved to the DMZ, the unit can be accessed, but all video screens are black and an java script error pops up as follows:  URl This message does not pop up when on the local subnet. Additionally, in the login screen, there is a language selection, and sometimes all languages are blanked out. There is a space for them, but they don't display. I've tried this on a half a dozen machines, either XP or Win7 with IE8 and IE9, and they all do the same thing. I disabled http inspection, but that doesn't work. I also did a packet capture, and the only packets that traverse the ASA.

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved