Cisco Firewall :: Drop Rate-1 ASA 5505 Web Server Not Accessible
May 8, 2012My web server was down for the day now it's back on but the ASA not accessible with error drop rate-1 exceed
View 3 RepliesMy web server was down for the day now it's back on but the ASA not accessible with error drop rate-1 exceed
View 3 RepliesI have two ASA5510-BUN-K9 Fws and I am planning to buy 2 x L-ASA5510-SEC-PL= to put them in HA.I was wondering if the support contract that I curently have for the two ASAs is still valid or do I have to buy any support upgrade?
View 1 Replies View RelatedI have made a Nat Rule to access local IP in outer world with external IP on asa 5505 . Before creating nat rule external IP was directly given to server but after that I put server behind ASA. But now external IP is not accessible externally.
View 4 Replies View RelatedWe have Cisco ASA 5505 with ASDM 5.2 We have one Proxy server in our Local Lab and pointed to Hosted service(Simple Signal)issue is, When our proxy server send register to hosted server, ASA change private IP and post with outside IP and src port as 1063 every time.
Here is debug log on real time monitoring.
Aug 24 2011 05:21:19 302015 203.xxx.xxx.226 192.168.1.51 Built outbound UDP connection 3774 for outside:203.xxx.xxx.226/5060 (203.xxx.xxx.226/5060) to inside:192.168.1.51/27014 (99.119.161.107/1142)
Aug 24 2011 05:21:19 607001 203.xxx.xxx.226 Pre- allocate SIP Via UDP secondary channel for inside:192.168.1.51/27014 to outside:203.xxx.xxx.226 from REGISTER message
Aug 24 2011 05:21:19 710005 203.xxx.xxx.226 99.xxx.xxx.107 UDP request discarded from 203.xxx.xxx.226/5060 to outside:99.xxx.xxx.107/1063
Here 99.xxx.xxx.107 is Our ASA Outside IP address 203.xxx.xxx.226 is Hosted server IP address. My ASA config is attached.
Cisco ASA5505..Made a VPN connection (SSL or ANYconnect) with a domain notebook. After that via RDP (connect with domain user) to one of the PC's in the domain. Until now everything is ok.The mapped drives are there but I do not have access to them. Normaly when I logged in into the network no problem but only with VPN connection.I have to login to get access but when I do that get message unknown user.
View 1 Replies View RelatedI'm working on a small network (1 server, 6 workstations, stand-alone, not connected to the main Company Network) "reinstalling" a Workstation. Re-imaging from semi-generic Norton Ghost image (4 of the 6 Workstations run the same programs with different addresses). I then had to reset the IP, the Computer Name, and then the Domain (I did it in that order).
I'm using Windows Server 2003 as the domain controller, and the Workstation is Xp Pro Sp 2.
The Workstation is using the same IP, Name, User as before, and they were working with the server previously (a program had corrupted prompting the reinstall).
The problem is that if I open windows explorer and type in the Workstations IP (\000.00.0.1) I get access to the computer. But if I go there and type in the Workstations Name (\Computer01) I get a "you may not have permission to use this network resource" error.
If I go to the work station, and try the same thing except with the Server's IP (\000.00.0.100) and Name (\Server01) I get access.
This Workstation controls an I/O device that is used by a program running on the server (most of the time, not while I'm doing the install of course) and the program uses the Workstation's Computer Name to access it.
As far as I can tell all the settings on this Workstation match the 3 that are running the same programs, but I could have missed something.
I'm a bit stumped by this, I don't normally deal with the Server side of the computers. I usually just set up the workstations to whatever Name/IP the Net-admins give me. But my bosses put me in charge of this little network, mainly because the Net-admins din't want to deal with it.
I have nated my 172.81.15.0 255.255.255.0 into my internal server 10.1.10.164 , i can ping the out side server but the internal server is not accessible from out side static (Database-Servers,interface-sms) 172.81.15.2 10.1.10.164 netmask 255.255.255.255icmp permit 172.81.15.0 255.255.255.0 interface-smsroute zemen-sms 172.81.15.0 255.255.255.0 10.131.199.201 1access-list Database-Servers-in extended permit tcp host 10.1.10.164 host 10.185.62.144 eq 9090access-list Database-Servers-in extended permit tcp host 10.1.10.164 host 10.185.62.144 eq wwwicmp permit host 10.185.62.144 interface-smsi can ping the out side server 10.185.62.144 with out a problem . from the server 10.185.62.144 i can ping untill 172.81.15.2 and it will not ping the natted server 10.1.10.164. as u seen the accesslist ping is permitted.
View 1 Replies View RelatedIn my client office, We have replaced small business router cisco RV042 with Cisco ISR router 2911, in that router we have configured NAT to allow internal user to access internet and port forwarding for outside user to access web servers and other application that are hosted internally.
we are not able to access [URL] (name changed) from internally and one of the application that are runnning on port no. 8280., and same is working properly from outside the network.other application that running on 8287 is accessible form internally.
We are accessing with ip address http://192.168.1.51:8280. and [URL] not working from inside.
But all works fine with old cisco RV042.
I have a question that�s been bugging me and that internet searches didn�t quite explain and that is how do I make a resource available publicly e.g. web serverAll I hear so far is register a domain name but that doesn�t quite answer the full question. Id like to know exactly what happens when a user types in the url of my web site and how their traffic gets to me. Is it.. get a static ip from my isp then provide this to the domain name registrar and that it now every one can access my site?? Seems to simple.
View 1 Replies View RelatedI`ve had a problem with my WAG320N for some time now.I`ve add a 1,5Tb hard drive to the usb and I can access it at LAN.Now I want to take it a bit further and be able access it from the outside.
View 9 Replies View RelatedI have a Cisco ASA configured for Any Connect clients. I also want to pass 443 traffic back to an internal web server, but not sure if I can do this since the Any Connect clients are already connecting over 443 to the ASA, right?
View 8 Replies View RelatedWe have a Cisco ASA 5505. As of yesterday we could no longer access our web server (the web server is hosted off-site). Pinging the DNS address and direct IP (from the firewall and a PC) both return no response. Pinging the IP from the T1 router responds properly, meaning the router can access the web server, but the firewall cannot. Accessing the web server has never been a problem, and no configuration changes have been made to the network/firewall. Other locations can access the web server just fine.
View 1 Replies View RelatedI have a Cisco ASA5505 and windows DHCP server, how do I add this external server to ASA so my PC clients can get DHCP from this server?
View 3 Replies View RelatedI'm configuring a Cisco ASA 5505 ASA Version 8.3.1 I want to publish my web server is in the DMZ (10.30.30.1) and server address is 10.30.30.30 but it still fails.I have only one public IP, and hope that when they call the Public IP, my web server appears, another problem I have is that when I assign the public IP to my interface OUTSIDE my LAN loses internet connection.I have to do to publish my web server and the LAN computers have internet access?
View 16 Replies View RelatedI want to configure my Cisco asa 5505 as a dns server, so that when i configure any of my network systems ip address and use my firewall as a default gateway and dns ip, the system should be able to browse internet.
View 5 Replies View RelatedI have a domain with a domain controller Server 2003. I have a backup dc running an application with server 2008. The shared folder I am trying to access is on an nt server 2000. We have had a mapped drive "I:" and have used it for years. Our copier also scans to a shared folder on the server 2000 machine. All of the desktop systems are xp sp3 with one W7 machine. A couple of weeks ago when user attempted to access the shared/mapped drive, an error would occur that "the drive was in use and they could not be logged on". Sometimes the error would say "you don't have permission to access the drive." Mind you no settings have been changed on the network. When either of these errors would occur it would occur for everyone but if I rebooted the server everyone could connect again. The same errors would occur the next day or 6 - 8 hour later. Now the error has occured "Drive is already in use and you cannot be logged in" (I have tried drive Z as well the drive is not in use) and restarting the serever no longer works. No one can access the shared drive. I have unmapped the drive on my system and have attempted to reconnect, I enter the path and check reconnect at logon and it asks for a password. I enter the administrator password (which is what I always used) and it just pops right back up asking for a password as if I entered nothing. I can ping the server with the shared folder and even logon remotely so I know it is not a physical disconnect. I am not sure what changed and have followed many suggestions found to no avail. We cannot access the shares or scan.
View 1 Replies View RelatedInstead of using a IP address I would like to use a host address that points to a NTP pool.An example would be:ntp server 0.north-america.pool.ntp.org Can this be done on the ASA series?
View 1 Replies View RelatedI have a client in a workgroup environment. They are a small company with perhaps twenty systems. Their infrastructure consists of a Dell Switch, a Cisco ASA-5505 which hands out the DHCP and a router. And that's that.They have been using an external IP as their DNS Server to get out to the Web. However, they now want to add an internal Linux-based DNS server.In looking through the ASA-5505 today I noticed a field for DNS enteries. Is this where the IP for this new internal DNS Server (in the secondary DNS field) would go?If so, would it be necessary to reboot the ASA-5505 for this change to take effect?
View 12 Replies View RelatedI get the following message when appling "DHCPD ENABLE INSIDE"
DHCP: Interface 'INSIDE' is currently configured as CLIENT and cannot be changed to a SERVER by a SERVER feature
This is an ASA 5505 Running 8.2.
I would like to allow users from network 10.132.23.0/24, 10.132.33.0/24, 10.132.24.0/24 access to our SQL server(192.168.1.7) located on the inside interface(192.168.1.0/24 network) Those networks (10.132.0.0/16) come from the DMZ interface.
View 12 Replies View Related: Saved
: Written by enable_15 at 03:51:29.049 UTC Mon Feb 4 2013
ASA Version 8.4(4)1
host name cisco asa
enable password xxxxx encrypted
password xxxxx encrypted
names
interface Ethernet0/0
switch port access v lan 100
interface Ethernet0/1
interface Ethernet0/2
[code]...
I tried the solution posted at [URL] however it did not work on my ASA5505 8.4(2). I thought that it may be because I only have a single public address so the web server is responding to port forwarding through the one public IP already. looking in ASDM it appears to indicate that a configured access list is blocking the server from responding to the internal hosts.
object network Private_IP
host 192.168.1.15
object network Public_IP
host 1.1.1.1
object-group network internal_net
[code]....
Can I fix an access list (or something) to make this work or am I wishing for too much with only one public IP? This worked by default on my Netgear firewall.
I need configuring RDP access to my local server from a remote location on my Cisco ASA 5505 Firewall.I have attempted to configure rdp access but it does not seem to be working for me. How to modify my current configuration to allow this? I need to allow the following IP addresses to have RDP access to my server: [code] The other server shows up as 99.89.69.334 but is working fine.
I already added one server for Static route and RDP but when I try to put in same commands it doesnt allow me to for this new one. My configuration file and what are the commands i need in order to put this through. Also, if there are any bad/conflicting entries. Also I have modified IP information so that its not the ACTUAL ip info for my server/network etc... lol for security reasons of course.Also the bolded lines are the modifications I made but that arent working. [code]
I would like to allow remote access to a windows server through a ASA (5505) firewall. Users will use the vpn connection in order to connect to a private network. Is there any link that describes the steps for ASDM?
View 3 Replies View Relatedi can't get it working to expose on internal server to an outside interface.I used the public server function in ASDM.Internet access works if i nat my private adress to one of the available ipadresses provided by our isp.
Internal Server : owncloud 172.10.0.4
External Server : ext181 46.245.171.181
I can't see the error in the configuration,
: Saved
:
ASA Version 9.1(1)
!
hostname rhedetest
domain-name xxxxx.de
enable password 59t92OvRofWL9yf3 encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
[code]....
I have ASA 5505 firewall with base license.I am using 10.91.40.0/24 IP series.Below are the requirements that i need to configure
1. First 30 IP's need to have direct internet access.
2. All remaining IP traffic i need to send proxy server( Squid server).
Note that my ASA 5505 is in base license and also tell whether my ASA is support for this feature.
I am facing Tear down problem on cisco asa 5505.Users are always disconnecting 25-30 min from outside server. [code]
View 2 Replies View RelatedI like the ASA 5505 for SMB and Home Offices very much, but I'm missing sadly a DNS Server or at least the ability of the DHCP Server to use static addresses for certain MAC's. In SOHO's the ASA is the only thing always powerded on and often even a Server where a DNS Server could be installed is missing.So is there a chance to see such a feature (DNS Server and/or static DHCP) in the next SW Release? how name resolution in a small LAN can be done without a local DNS Server?
View 3 Replies View RelatedI just purchased a domain name, that I have forwarding to my WAN address. I want to be able to access my home websie via this route. I have an ASA 5505, how do I get the ASA to point to the home server when the WAN IP address is entered?
View 16 Replies View RelatedI'm trying via the ASDM to port forward http connections to a DVR for the purpose of viewing IP cams.I've tried via ASDM to create a public server but I'm not allowed to use my public IP address for the public Interface.I have only one public IP address available.Is there any way round this ? I would also like to know how I can enable NAT with PAT.I've tried setting the outside Interface for use with PAT but It keeps reverting to the setting for a range of external addresses.I'm not really used to the ASA cli yet , I'm getting there.If there's a workaround via the CLI , I'll take that route.
View 4 Replies View RelatedI have a server that I need to open up some ports on to allow access to the new internal Sharepoint server we're setting up. I've been having some issues getting the ports open like once I put the commands in and save them that server suddenly stops allowing outbound traffic. After looking at a few things I noticed while I was looking at the config file that the ASDM location is showing 2 IP's, both are the same as the server I'm trying to open ports for one being the private IP and the other is the public IP I'm trying to use. Is this the reason I'm having problems when I try to open those ports to my server? Do I need to use both a different private and public IP for this server so I can get my ports to work? The programmers selected these IP's so if I need to change them I'll let them know in case they need to make changes for the Sharepoint setup. This is on an ASA 5505.
View 12 Replies View RelatedI'm having trouble setting up the correct rules on an ASA 5505 I'm using in my home office. I have a couple of IP Cams I need to access remotely.
I've tried setting up simple NAT(PAT) and/or Access Rules, but it hasn't worked. I have a single dynamic IP for the Outside interface. Call it 77.76.88.10 and I am using PAT. The CAM is setup to connect on port 80, but could be configured if necessary. I've tried setting up NAT Rules using ASDM as follows:
Match Criteria: Original Packet
Source Intf = outside
Dest Intf = inside
[Code]....
I'm afraid to use CLI only because I am not confident I'll know how to remove changes if I make a mistake.
Currently I have an ASA setup as a Firewall with 1 outside interface and 2 inside interfaces. Initially, the Guest interface was setup to receive DHCP from the ASA and everything was working. I'm adding router and a server for the guest interface and what I'm trying to accomplish now is the following: ASA 5505 > Airport Extreme with a public static IP (69.xx.xx.6), handling DHCP and NAT > Mac Server as DNS Server.Right now, when I connect to my Airport Extreme with any computer, I don't have internet. I don't understand what's wrong. My DNS Server has a reserved IP address: 192.168.226.2 and it's pointing to itself and forwarding the ISP DNS servers, the Airport Extreme is handling the DNS Server IP and the ISP DNS Server IP but I can't connect to the internet from the server. [code]
View 31 Replies View Related