Cisco Firewall :: Planning To Integrate ASA 5505 Device

Mar 21, 2011

I planning to integrate cisco asa5505 device in runing enviornment for filter ip traffic.Internet ----router----ciscoasa----lan.Ip series is public(25.263.25.0/24) througout of network (no privateIP)now how do I set asa in such case and filter traffic from comming into lan and going out to internet.

View 5 Replies


ADVERTISEMENT

Cisco Firewall :: How To Integrate ASA With 2951

Nov 6, 2011

I recently installed a 2951 with a security plus license..I hate it (security featuers not router) and would like to put the asa back in place.how to integrate the asa with the 2951, I believe I need to run it in multi context mode.

View 3 Replies View Related

Cisco Firewall :: ASA 5505 Making A Device Inaccessible Via Vpn

Apr 21, 2013

Within a workgroup environment we  have four large drives, statically assigned and all accessbile via VPN.  Our FW is a Cisco ASA-5505. Where within the ASA-5505 GUI can one of these drives be made inaccessible via VPN ?

View 0 Replies View Related

Cisco Firewall :: ASA 5505 Portforwarding To Device With Different Default Gateway

Feb 27, 2012

A customer got a new VoIP PBX, and now I have to forward port 443 on the ASA to the PBX for remote administration purposes. The LAN-interface of the PBX is in the same subnet as the ASA but has an external VoIP-router as default gateway and not our ASA. Is it even possible to forward the port to the PBX when there is no route of any sort to our ASA on it?

View 2 Replies View Related

Cisco Firewall :: ASA 5505 - Losing Configuration When Device Powered Off

Feb 28, 2011

i did a reset on my asa by stopping the boot process because i could not remember what my enable password was, i had no problems with the reset the asa came backup as it should and i started configuring the device again. My problem is when the device is powered off and back on i lose all configuration that were made, i save the changes with "write me" before the restart and they are still being over wrote.

View 4 Replies View Related

Cisco Firewall :: ASA 5505 / Lost Enable Password For Spare Device?

Jul 13, 2011

Is there a way to restore the device to factory settings.  I tried the reset button with a paper clip.

View 2 Replies View Related

Cisco Firewall :: ASA 5505 Connection Limit And TIME_WAIT Freezing Device

Sep 30, 2011

My little ASA 5505 is working great The device appears to be artificially crippled and limited to 10,000 connections.  This isn't a "CPU limit" it's just some fake limit in the device as far as I can tell.
 
The problem we have is that we are only using around 500-600 connections and CPU usage is only like 25%, and yet the connection count is pegged at 10,000 and locks us out of our network.
 
I am pretty sure this is because there are a lot of "dead" TIME_WAIT connections hanging around not being used.  In our application we only have the couple hundred connections but they do move around a bit every now and then.
 
Is there anyway to get the device to ignore the "dead" connections and not count them towards the artificial limit on the device given that it's pretty clear the CPU / etc., is not utilized sufficiently.  These aren't real connections, we only have a couple 100 established, they do just move around a bit however.
 
We are really only using 500-700 connections according to our servers, the others are just sitting in TIME_WAIT doing nothing.

View 1 Replies View Related

Cisco Firewall :: Asterisk / FreePBX Phone System Located Behind ASA 5505 Device

Feb 27, 2011

We have an Asterisk/FreePBX phone system located behind an ASA 5505 device where we are having problems with sip inspection.
 
We connect to three different phone providers, and things works as expected for 2 of the 3 providers,but for the last one (Draytel) we are having problems with sip inspection.
 
The key difference about the VoIP provider where we are having problems is that they are using differetn servers for the voice (RTP) traffic than the server we are registered with to establish SIP sessions.
 
sip inspection is configured with the default out of the box options.The problems we see are this:
 
1. For ingoing calls sip inspection does not open the required pinhole to allow the traffic to flow through. As a result we can not hear the voice of the calling party, but voice from our side is passed through ok.As a workaround we have added and ACE allowing traffic in the used UDP (RTP) range from this VoIP providers ip addresses to pass through the ASA, and with that in place incoming calls work.
 
2. Outgoing calls doesn't work because sip inspection doesn't kick in, and as a result of this we forward internal ip addresses in the SIP / SDP body to the VoIP provider. I'm not sure whether this is a consequence of sip inspection not kicking in for this provider, or a result of having added the ACE for an ip ragnge that covers the ip address we register with.
 
As stated above sip inspection does work as expected for two other providers where all traffic goes through a single server.We actually have had this working with ASA firmware 7.2(4), but as that version intermittently had a problem where sip inspection would stop working (fixable by power off/on or a clear command), then we decided to upgrade.

View 1 Replies View Related

Cisco WAN :: 7606-S Planning To Install New IOS

Sep 18, 2012

I have a fresh piece of 7606-S router, i am planning to install a new IOS ( 15.2.4S or 12.2.33-SRD8 ) SIP-200 / RSP720 moduls ... would ypu plese provides me a configuration guide for installing IOS for 7600 serise router.I have the image on TFTP server.

View 3 Replies View Related

Cisco Wireless :: Planning To Upgrade WCS To 7.0.240.0

Apr 26, 2013

We have WCS running 7.0.164.3...We had upgraded WLSE to WCS a few years back.
 
I am planning to upgrade WCS to 7.0.240.0... What is the procedure of upgrading WCS in this case? I am not quite sure about the procedure as our WCS was a WLSE before.

View 3 Replies View Related

Implementing / Planning / Building A LAN

Mar 25, 2012

I have to propose/design a network system. It has 350 computer terminals/workstations out of which 300 of them are divided into two separate networks while the other 50 are to be on another network. So I assume I'd need 3 networks (or LANs) I guess (all connected ofcourse)So far I've inferred it needs a mail server, a file server, a print server, a DHCP server to assign IP addresses (C class and private ones ofcourse) and a web proxy server. Also I thought a fast Ethernet LAN network might be ideal here but I'm not quite sure on that (nor have I ascertained what sort of topology or hardware to use).

View 5 Replies View Related

Cisco WAN :: 5540 Planning A New Redundancy Network

Jun 26, 2011

I designing a new network for the company.

-Core layer is Cat6509 with VSS
-FW Lauer: Cisco ASA 5540
-Switches: L2 Cisco 2960
 
 What is the best plan to make this redundant to the Firewalls?

View 1 Replies View Related

Cisco WAN :: Planning To Install And Configure VSS 6509 Switches

Mar 4, 2011

I am planning to install and configure VSS (6509) switches. But the customer requires that the First Switch should be the main and the second Switch should act as a backup one. (Disaster Recovery).
 
Once the Main (Primary switch) DOWN the Secondary one should coming UP.But what I am understand in VSS concept the two switches will act as one Switch. And both of them will be UP in the same time.
 
Is there any solution to configure the both VSS switch as primary and standby switch to provide HA?

View 4 Replies View Related

Cisco Switching :: 3750 - IP / VLAN Planning For Routed Access Design?

Sep 10, 2012

We are currently designing a complete Layer 3 to the edge solution for our customers. The network design is a combination of a collapsed core (Core to access) as well as a three layer model (Core/Distro/Access) for connectivity to the Data Centre, Internet and Wireless Blocks.
 
The core of the network contains two 6509E switches interconnected on a Layer 3 Port channel (no VSS). Access Layer switches (3750 Stacks) connect to the core switches over p2p routed links (Collapsed core part of the design). Distribution layer switches provide connectivity to the Data centre, Internet and Wireless Blocks.(three layer model.
 
All IP addressing is being planned for assignment from the private RFC 1918 address block(10.0.0.0/8) for both Infrastructure and Access layer VLANs for users.
 
Clarifications required for the following:

[code]...

View 17 Replies View Related

Cisco 5505 - Cannot Ping The Laptop From The Device

Jul 21, 2011

I have a new 5505 that im trying to upgrade the IOS on. The 5505 and the laptop are connected via a 5 port switch.From the laptop i can ping the inside interface of the 5505, but i cannot ping the laptop from the 5505. As a result, my TFTP is failing.

View 5 Replies View Related

Cisco :: How To Integrate WLC 2100 With ACS 5.0

Jan 17, 2011

i have a cisco ACS version 5.0, I need to authenticate a wireless users connected to WLC 2100 controller when i connect the controller to a Dot1x port in the switch , the port go down.

View 6 Replies View Related

Cisco VPN :: ASA 5505 Can't Ping Any Device Internal Network

Feb 6, 2011

I'm new to this cisco 5505 and I want to carry out a task as simple as a remote access VPN, in my case I did the wizard, with time on my test, I could connect to the VPN, but I can not ping any device internal network. [code]

View 6 Replies View Related

Cisco :: LMS 4.0 / How To Integrate NetFlow To Some Ciscoworks Module

Jun 20, 2012

how to integrate NetFlow to some Ciscoworks module.

View 3 Replies View Related

Cisco WAN :: 5520 Best Way To Integrate 20meg WAN Link Into LAN

Jan 16, 2012

We have a core 6500 switch that has a PRI module in it that binds (4) T1 lines together and we also have a 2600 Rtr that binds 4 other T1 lines together and pipes them into a ASA5520. We are changing WAN vendors but still have to maintain the (8) T1 connections until our contract runs out, which will be in a few years. The 8 T1's are not enough bandwith for our operation and we will be adding a 20meg WAN link in the next month. What I am trying to figure out is how to best integrate 3 different WAN links into one LAN. What I am thinking of doing is to leave the 6500 core switch as is and then to purchase a router that can hold (4) T1 wics and the 20meg link. Is it possible to bind those 5 links together even though they are different vendors?

View 4 Replies View Related

Cisco :: Integrate Remote Syslog Collector With LMS 4.1

Jul 7, 2012

We have LMS 4.1 in our network. We had recently installed Remote Syslog Collector on a new Server to collect logs from all the devices. How can we integrate the Remote Syslog Collector with the LMS Server?

View 3 Replies View Related

Cisco :: Integrate 1250 To Active Directory

Jan 5, 2011

I have installed 4 unit Cisco Aironet 1250 acting as Autonomous AP each. I want to integrate these AP to Windows Active Directory for authentication level.
 
When I read configuration guide on Cisco Aironet, they must be authenticated via RADIUS server.
 
Is it possible that these AP directly authenticated to Active Directory via LDAP protocol?

View 4 Replies View Related

Cisco Wireless :: 5508 - Any Way To Integrate 5760

May 15, 2013

We are looking at possibly adding a second 5508 controller to our network and running in HA mode.  I see now that there are 5760's available that run on IOS.  Is there any way we can integrate a 5760 into our existing network instead of going with a second 5508?   I would prefer to invest in newer hardware whenever possible.

View 15 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 Appliance Integrate Multi Domain

Sep 1, 2011

I have a question. What is the requirement of integrate ACS 4.2 Appliance and AD about CA server? it has to be windows 2003 server enterprice o windows 2008 enterprice? or it can be windows 2003 and 2008 stand alone? another question is about multi domain, i have domain father and children. the installation of CA Server is in domain father to enable 802.1x with AD with all domain children integrate? or I can be install the CA server in the server of domain children and is it work (CA server installed in server in domain child and it working all domains child and father)?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - AD Integrate With Single Domain Name With Multiple ADs

Sep 3, 2011

We having ACS version 5.2 0.26 with Active/Standby. We need to integrate active directory with ACS. Domain name given by Server team was as xyzcompy.local. When I tried to resolve the same domain name I got five servers ip address against the same domain name. however we given the ip reachability to only for two servers. We we try to save we get error saying that "Can not resolve the network address".
 
So my questions are;

- does ACS should have ip reachaibility to all five servers

- does the username/password we entered in the ACS should have domain admin rights?.

- the given AD is configured with windows NTP [URL] but when we configured ACS as windows NTP it was taking  local server as active NTP..?
 
When we check the ACS logs, we saw the following error;

in acsLocalStore:
AdminName=acsadmin, DomainName=qatarconvention.local, ADOperationResult=unable to create secured connection against AD server, switching to non-secured connection. javax.naming.CommunicationException: simple bind failed: qnccad02.xxxxconvention.local:636 [Root exception is java.net.SocketException: Connection reset],
in ACSADAgent;
32484]: INFO  dns.findsrv FindSrvFromDns failed: res_query failed _ldap._tcp.xxxxconvention.local
Sep  4 12:43:20 acs01-cc4 adjoin[32484]: INFO  cli.adjoin Join to domain 'xxxxconvention.local', zone 'null' failed.
 
I attached some screen print which saw the error and output of nslookup for the domain name.

View 3 Replies View Related

Cisco Wireless :: UCS C220 M3 - Integrate Prime Infrastructure 1.2.0.103 And Virtual MSE 7.3.101

Jan 12, 2013

I cannot integrate Virtual MSE 7.3.101 with my Prime Infrastructure 1.2 After I setup MSE via its wizard, I make a change on WCS username and password. When I try to integrate MSE with Prime Infrastructure, Prime notify me about the mismatch username/password.
 
Both systems are fresh install on my UCS C220 M3.

View 4 Replies View Related

Cisco WAN :: 2951 - Integrate To CUCM / Plug Siemens ISDX?

Mar 5, 2012

I have a 2951 which i want to integrate to the CUCM and wish to plug a Siemens ISDX into it which is the best card to use
NM-HDV2-1T1/E1 or  WIC2-2MFT-T1/E1? its QSIG

View 1 Replies View Related

Cisco :: WLC 2500 - Integrate Creating Guest Users In Intranet Application

Feb 27, 2012

I would like to integrate our intranet web page with Cisco WLC 2500. Is it possible to integrate custom web page with WLC. I know, that I can create custom authentication page, but what about creation of the user?

View 5 Replies View Related

Cisco Wireless :: Integrate ISE And WLC5508 With FlexConnect (local Switching) Using EAP-TLS Security?

Nov 29, 2012

I need to integrate Cisco ISE and WLC5508 with FlexConnect (local switching) using EAP-TLS security for wireless clients across multiple floors (dynamic VLAN assignments based on floor level). The AP model used is 3602.

- What RADIUS Attribute can be used for dynamic VLAN assignments based on floor level? Is there an option where I can group all LWAPs in same floor for getting certain VLAN from ISE?

- I intend to use WLC software version 7.2 since 7.3 is latest version. Has someone use WLC software version 7.3 without any major bugs/issues pertaining to FlexConnect and EAP-TLS?

- I read some documents saying L3 roaminig is where the associated WLC has changed. However if user move to different subnet but still associated to the same WLC, would this be consider as L3 roaming too?

View 3 Replies View Related

Cisco VPN :: Integrate Server PPTP On 2821 Router Series With Active Directory?

Apr 14, 2011

I have a 2821 ciso router and i want to setup a vpn for my windows domain users , they must to reach the domain from outside. There is  posibile to intregrate Active directory auth with pptp running on 2821 router? kind of dialin via radius server(IAS running on windows server 2003).

View 3 Replies View Related

Cisco Security :: Can Integrate Acs Version 5.x With Active Directory Microsoft Windows Server 2012

Apr 5, 2013

Can we integrate cisco acs verison 5.x with active directory Microsoft windows server 2012 ?

View 1 Replies View Related

Cisco WAN :: 5505 Correct Site-to-site / SSLVPN Security Device

Dec 12, 2012

I have tried Cisco presales but got bounced - go Cisco !So, i have a small customer who requires a single device which will provide .....
 
1/ Leased Line connection @ 10mb
2/ ADSL failover onbox (so configurable from CLI, unlike the 860’s which I see only have one ‘active’ wan port)
3/ IOS based
4/ integrated 4 ports (min) switch
5/ site to site VPN
6/ up to 10 x SSLVPN remote users
 
I did pitch in with ASA5505 with external ADSL router but he is “space-constrained”.It worries me when Cisco doc's say only one WAN port is 'active' - since it doesn't say the second port automatically comes up if the first goes down so I can't take a gamble on that being the case.

View 3 Replies View Related

Cisco VPN :: ASA 5505 - Creating Site To Site VPN To Another Location / Device?

Feb 27, 2012

I recently purchased a new ASA5505 and have been having trouble creating a site to site VPN to another location/device.  I've used the VPN Site to Site wizard to configure the VPN but after the wizard completes how does one verify VPN connectivity via ASDM?  Also, I've run debug crypto IPSec and isakmp and see absolutely nothing?  So how does one verify that the VPN is up and if it is not, how does one troubleshoot why it is not?  The other side is configured and I had no trouble getting this same VPN working on an old Watchguard device. 

View 4 Replies View Related

Cisco Firewall :: Monitoring ASA 5505 Firewall Active / Standby Pair Using SNMP?

Sep 7, 2011

How I can actively monitor the interfaces and overall status of 2 x ASA 5500s in an Active/Standby configuration?
 
I can setup monitoring of the interfaces on the Active member but I'm not sure how to manage the Standby member?

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved