Cisco :: LMS 4.2.2 Cannot Backup An ASA 5525-X

Nov 21, 2012

Any one see the pronl;em where LMS 4.2.2 cannot backup an ASA 5525-X (UKHSL-N01-AFW02)..The Inventory collection is fine, to a point.I have applied all updates LSM etc. [code]

View 7 Replies


ADVERTISEMENT

Cisco Firewall :: PIX 525 6.3 To ASA 5525-x?

May 9, 2013

I have read that it is possible to migrate from a 525 to an ASA via a upgrade to pix asa version 7.0 then using the migration tool once copied to the new ASA 5500 series, but i have alos read in a forum somewhere that a migration from PIX to ASA 5500-x series is not possible,, is this true ?

View 1 Replies View Related

Cisco Firewall :: NAT On ASA 5525 8.6(1)

Apr 8, 2013

We have recently installed new 5525 8.6(1) ASA's. Our setup is like; where we are using Public IP for web server, which needs to be mapped/natted to internet VIP address and that VIP is configured on F5 LB. Setup is below; This Public IP is the web server IP. The firewall get hits, but web server page is not being displayed. In the logs FW built tcp but then tear down the session, syslog id (302014) 77 TCP Reset-I
 
                          |INTERNET|
                                 |
                                 |
                         195.201.55.X
                            [ ASA ]
                          Natting to
                         10.100.100.151
                              [ F5 ]
                                |
                              / 
                            /      
Real Servers---> .150   .151
 
 
NAT Config is; nat (DMZ1,OUTSIDE) source static 10.100.100.151  195.201.55.X.

View 8 Replies View Related

Cisco Firewall :: How To Enable Ssh On ASA 5525

Aug 15, 2012

May I know how to configure for remote accessing ASA 5525 via ssh?I have issued the following commands
 
ssh 10.60.0.0 255.255.0.0 outside
ssh 10.60.0.0 255.255.0.0 dmz
ssh 10.60.0.0 255.255.0.0 inside
ssh timeout 5
 
but I am not able to access ASA via ssh. Do I need to add any other command

View 20 Replies View Related

Cisco Firewall :: Migration PIX 515 8.0(3) To ASA 5525-X

May 28, 2012

I have a PIX 515 with version 8.0(3). We buy a ASA 5525-X for replace the PIX.
 
The question is, what is the better method to migrade the configurations? Manually?

What is the better version for 5525-X? 8.6.1?

View 4 Replies View Related

Cisco VPN :: ASA 5525-X Dynamic PAT Policy S2S VPN

Jul 17, 2012

I am prepping new ASA 5525-X's for a client that has multiple S2S VPN's.  On some of the VPN connections, I need to do a policy nat to translate some of their subnets to a single IP address before it goes over the S2S VPN.  However, when I try to use a subnet, I keep getting the following error:
 
Subnet cannot be used as mapped source in dynamic nat policy.
 
This works fine on their old ASA's which are running 8.2 code.  I figured out I can use a network range, but cannot go over 65535 (or whatever it is) addresses in that range.  This is very annoying when they have multiple networks they want to allow over the S2S VPN.  Is there anyway around this or am I stuck creating a network range for each subnet?

View 6 Replies View Related

Cisco VPN :: VPN Filter Vs Interface ACLs On ASA 5525

Mar 19, 2013

I need some clarification on the differences between a VPN-Filter v an Interface filter.I am using an ipsec crypto tunnel between our site using ASA 5525 and a remote client who are using a Palo Alto Firewall.  I have applied a vpn-filter on the tunnel for these sites but I am being told that an interface filter would have been more simplier.

View 9 Replies View Related

Cisco Security :: ASA 5525 - New Versions Of 8.x Code

Dec 4, 2012

We are updating our older Pix boxes to ASA 5525s.  A book covering the new versions of 8.x code.

View 3 Replies View Related

Cisco Firewall :: ASA 5525-x Flash Memory

Nov 14, 2012

We have a customer that has a ASA 5525-x reporting only 4g flash memory rather than 8g has any 4g version of the 5525 or is the IOS reporting incorrectly the size,  as it seems to be embedded on these units as a USB disk internal.

View 4 Replies View Related

Cisco Firewall :: 5525 - Upgrades From 8.2 To 8.6 For Some Customers

Nov 13, 2012

We have a 5525 that has not been deployed to production yet so we're using it in the lab.  I want to lab some upgrades from 8.2 to 8.6 for some customers but the 5525 comes loaded with 8.6.  Would there be any problem with reimaging the 5525 with 8.2?  I'm just not sure if there would be an issue with this new hardware running that old software.

View 3 Replies View Related

Cisco Firewall :: Upgrade From ASA 5520 To 5525

Feb 27, 2013

I'm about to  upgrade from an ASA5520 to ASA5525.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: 5525 Ignoring Users Using AD Agent

May 13, 2013

its been a while since I configured a Cisco firewall (PIX 6.0, SDM) - I've now been thrown in the deep end with a pair of 5525-X's (Latest Software) and I need to achieve the belowWebsense integration (Got this working)AAA Authentication for various outbound traffic routes.I'm using ASDM as I'm more comfortable with the GUI than CLI (I'm the other way round with switches!!!), I have AD Agent configured but the ASA isn't doing anything based on User Name but I have a few other things to try. What I'm trying to achieve now is ignoring certain user names from being matched to IP Addresses as I believe that this may have something to do with it.We use Sophos AV and each PC requires a Service Account to run Sophos under. Each update that Sophos attempts is seen as a login and that is the user attached to the IP Address of the machine. Within Websense, it can be told to ignore certain users for purposes of filtering and reporting etc.. but I dont seem to be able to do this with the AD Agent.

View 3 Replies View Related

Cisco Firewall :: 5525 Authenticated User Access

Oct 31, 2012

We've just replaced our Fortinet Firewalls with 5525's but are struggling to get a feature working that worked great on the Fortinet firewall.All our users use a proxy for internet access that's configured in IE but from time to time some users need to remove this proxy and go directly out to the internet, with the Fortinet devices we created a rule right at the bottom of the inside access out rule that had it authenticate users via TACACS which worked a treat and could be used from PC or laptop. We want to do a similar thing on the 5525 and I thought the Authenticated user would give me this access but I don't seem to be able to get it to work. I've got the AD side of it working fine the ASA can pull user and groups from AD but I'm struggling to get this working for a user.

View 3 Replies View Related

Cisco Firewall :: Monitoring ASA 5525-X With System Center 2012

May 21, 2013

We are using MS System Center Operations Manager to monitor network devices.   We are trying to monitor our Cisco ASA 5525-X firewall interfaces.
 
We have a generic management pack installed that seems to work for parts of the 5525.  We can see performance info for IF-4 but none of the other interfaces.
  
Our Management Pack is a generic Cisco Adaptive Security Appliance Version 9.1(1) management pack.
 
Is there a management pack that is specifically for this Cisco firewall?  

View 0 Replies View Related

Cisco Firewall :: 5520s To 5525-Xs - Transfer User Accounts

May 21, 2013

I am in the process of upgrading a client's firewalls from 5520s to 5525-Xs.  I have 2 independent firewalls that are merging into a single firewall.  Both of the source ones have a TON of user accounts defined for remote user VPN, is there any way to move these user accounts with passwords in tact??  The goal is not to have to tell the 250+ users that they need to reset their passwords at once.

View 2 Replies View Related

Cisco Firewall :: Way To Create A Guest Access Lobby On ASA 5525

Sep 23, 2012

Is there a module or way to create a Guest Access Lobby on the ASA 5525? We currenly leverage the WLC to do this for us, but are moving to a routed access enviornment which is causing some issues. We would like to offload the guest access responsibility to the ASA if possible.                   

View 1 Replies View Related

Cisco Firewall :: 5525-X Cannot Create New Sub-interfaces / Etherchannels Through ASDM 7.1(1)

Apr 9, 2013

We are suffering an issue with ASDM 7.1(1) on a 5525-X with 9.1(1) software. In the Configuration --> Interfaces window, I can modify parameters on physical interfaces, I can modify parameter on subinterfaces, but I cannot create new subinterfaces or Etherchannels through ASDM.
 
When I create a subinterface, entering all parameters, interface name, vlan id, security level, etc., then I click on "Apply" button and nothing happens. It doesn't send anything to ASA. If I click on another window, ASDM ask for applying changes, I click on it, but nothing is applied and window doesn't change. It happens only when creating new interfaces. If I create them through CLI, then I can modify parameters without any problem.
 
I have tried re-installing java and I have tested with 6.31, 7.9, 7.11, 7.17 Java versions, from Windows XP, Windows 2003 Server and Windows 7 computers with same issue. Also with Linux Mint distro with IcedTea Java.

View 3 Replies View Related

Cisco Firewall :: ASA 5525 - Asdm Won't Work After Installing IPS Module License

Mar 14, 2013

I recieved my  IPS  module license for my  ASA 5525  . I enetered the key  via the ADSM and it prompted me to restart the firewall  .. After that i cannot get into the firewall via the ASDM . 

View 3 Replies View Related

Cisco Firewall :: To Setup ASA 5525 In Active Standby Failover Mode

Feb 12, 2013

I need to setup an ASA 5525 in Active/Standby failover mode. I am setting up the ASA for a company that purchased only one public IP address. The public IP address is assigned to the outside interface. My question is will failover work correctly if I don't use a secondary IP address on the failover configuration on the outside interface?

View 4 Replies View Related

Cisco Firewall :: ASA 5525 - Bandwidth Management (Rate Limit) Using QoS Policies

May 22, 2013

We have an ASA 5525 running version 8.6(1)2 and a 10 MG pipe. I have execs that want to limit bandwidth on users for stuff like youtube, stream media, and downloads. I found the article on ‘Bandwidth Management(Rate Limit) Using QoS Policies’ so it appears our firewall can do what we want. I’m not a cisco person. My knowledge is limited when it comes to configuration – that’s why we have SmartNet.

Can bandwidth be limited on end users and/or can they limit the ‘bandwidth rate limit’ to just youtube, steaming media, and downloads? If so, what should the limit be? and I’m assume this would be for ‘incoming’ traffic only? we’re running into some bandwidth hogs – usually youtube and/or streaming media. We have a Barracuda web filter which we’ve used to block and monitor activity but I simply do not have time to babysit this all day. I should also mention we do have critical data running up and down the pipe; such as credit card processing, DB replication between in house DB and hosted website, TPCx and EDI, FTP, and such that we don’t want restricted.

View 7 Replies View Related

Cisco Switching/Routing :: ASA-5525 - Connecting Multiple Switches To Single Firewall?

May 28, 2012

Could I configure and connect 3 Dell switches to an ASA-5525 Firewall which has got 8 interfaces.

View 7 Replies View Related

Cisco Switching/Routing :: ASA 5525 - Configure Site-To-Site IPsec VPN To 3 Peers

Nov 21, 2012

I have an ASA 5525 and need to configure site to site ipsec vpn to 3 peers. I currently have an existing /28 public address from my ISP that is used by other services.Is there a way to use this existing ip range to configure IPSEC tunnels to 3 peers ?

View 10 Replies View Related

Cisco :: Backup LMS 4.01 Don't Run

Oct 18, 2011

After the upgrade of LMS 3.2 to LMS 4.01 everthing works. After i fixed my last problem (syslog time issue). I´d saw that the automated system backup doesn´t work. I´d tried to backup the system by script. Than i find out that the perl.exe is damaged (0KB). So than i copied the perl.exe from my old Cisco Works Server to the new Server. Than i tried to make a Backup and get the mentiond error ... 
 
D:CiscoWorksCSCOpxin>perl.exe D:CiscoWorksCSCOpxinackup.pl d:Temp
ew
install
************************************************************
Backup to 'd:/Temp/newinstall' started at: [Wed Oct 19 09:39:50 2011]
 [Wed Oct 19 09:39:50 2011]  ERROR(375): No database files are available for the
installed applications; nothing to back up.
[Wed Oct 19 09:39:50 2011]  Backup failed: 2011/10/19 09:40:00

[code]....

View 1 Replies View Related

Cisco VPN :: ASA With Backup Peer On L2L VPN?

Jan 10, 2013

Why does Cisco recommend a configuration of originate-only on the ASA with multiple peers configured and the answer-only to the other end? Shouldn't it work as Bi-Directional ?

[URL]
 
The only scenario I see which could break is if both peers try to establish a VPN at the same time to the ASA. Is there any other reason ?

View 0 Replies View Related

Cisco :: Backup Configuration On LMS 4.2

Nov 21, 2012

1)how can i backup the configuration on cisco lms 4.2 and to re-imported later when i re-install the lms 4.2
  
2)how can i change the admin password on cisco lms 4.2

View 3 Replies View Related

Cisco WAN :: 876 To Use It As Backup Line

May 5, 2011

One of my branch offices is connected to an ADSL line as well as a VDSL line.Since I really don't need the ADSL line I came up with the idea to use it as a backup line.So I searched google and found this nice little article URL. I wonder if the router will switch back to the primary ISP if the primary line comes up again?

View 3 Replies View Related

Cisco WAN :: ATM Soft Pvc Across T3 And T1 Backup?

May 3, 2006

I am trying to create a VBR soft pvc across a T3 and T1 backup link, but I am confused about what values to use for PCR, SCR and MCR.  If I use high values for the T3, what will happen when this link is down and the soft PVC reroutes across the T1?  I would like to use percents (%) for the values, i.e. voice can use 25% of the link, then it would make more sense when using the backup T1 link.

View 2 Replies View Related

Cisco :: WCS 7.0.230.0 Server Backup

Nov 21, 2012

if i  enable Controller Configuration Backup is that included  in the server backup? and can the controller configs be specifically  extracted from the server backup?

View 8 Replies View Related

Cisco :: Backup And Restore LMS 3.1?

Apr 11, 2012

We have cisco works LMS 3.1  and the server have very problems, we need format the server and reinstall the Cisco Works, when I doin backup and restore of data LMS We lost the licenses? or when we restore the data in the server we have the same licenses? or get the new licenses to cisco?

View 5 Replies View Related

Cisco WAN :: 887 / ATM Router As Backup

May 31, 2012

at the moment I have a 888 router that works fine, I want to configure backup (I already have configure ISDN backup but the performance it's to poor), and I want to use an other router 887 (that I already have) with adsl.
 
My idea is to configure the second router as stand alone gateway, and confiure in the first router a "ip route 0.0.0.0 0.0.0.0 VLAN1 192.168.0.253 100".But I know that this second route is used only in case the interface status of primary route goes down but not in case fault only protocol.
 
configure a better routing or faulting procedure?
 
-----------------------------------
888
VLAN1 192.168.0.254
ATM0.1 1.1.1.1
ip route 0.0.0.0 0.0.0.0 ATM0.1
ip route 0.0.0.0 0.0.0.0 VLAN1 192.168.0.253 100
-----------------------------------
887
VLAN1 192.168.0.253
ATM0.1 2.2.2.2
ip route 0.0.0.0 0.0.0.0 ATM0.1
 -----------------------------------

View 3 Replies View Related

Cisco :: Backup WAN Connections With OSPF?

Feb 11, 2013

implement backup WAN links to complement the metro Ethernet links we currently use so we have some redundancy. These will most likely be a VPN over an Internet service but might be another Ethernet type service, the medium shouldn't really matter I wouldn't think. What I am looking for input on is what is the best way to implement this? Would I just set costs so that the backup is only used when the primary goes down, or should I create new OSPF area for the backup links?

Currently the core switches that are also our routers are 3750G stacks running ip services. We are getting ready to install new firewalls at each location that will become the gateways for the vlans currently on the core switches to give us much more control over segmentation, and because of this I am thinking that it may make sense to then move the OSPF instance from the core to the firewalls. In the drawing I did not show the access layer switches off of the core, and the MOE circuits actually terminate into a 3550-12T switch before the core. I think I will actually eliminate those 3550-12T switches and go straight into the core. This is a current state drawing, so does not include the backup links I am planning.

View 4 Replies View Related

Cisco :: Wireless As Backup Link?

Feb 18, 2011

want to connect three networks with each other via two media one ethernet/fiber optic and other through wireless as backup link.how can i connect these three networks so that if my ethernet/ fiber optic connection fails than computer on networks can still communcate via wireless link (i mean if ethernet/fiber optic fails then wireless link should automatically be established/

View 1 Replies View Related

Cisco :: LMS 3.2.1 - Cannot Backup Running Configurations In RME 4.3.2

Jan 18, 2013

Platform: LMS 3.2.1 with RME 4.3.2 on Windows 2003.I'm having a problem with several devices that were backing up fine until this week - suddenly they aren't backing up their running configurations, but RME is fetching their startup configurations fine and VTP backups are fine. At first I thought it might be timeouts, so I used inline edit to incease the telnet timeout for a device to 180s. However, the job fails well within this time period (debug shows on i/o error?). My order of protocols is SSH, Telnet, TFTP. I took a stab in the dark that this suggested a database problem so I picked one at random and deleted it from DCR, and readded it and it worked. However, for the other 48 devices affected it did not.
 
I'm wondering if I need to do anything to the RME database to get things back to where they were? Do I need to reinitialize the RME database, and if I do that what do I lose? [code]

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved