Cisco Security :: ASA-5505 - Getting Home Users Internet Access?

Feb 28, 2013

I have configured and tested an ASA-5505 that will be deployed at a customer's home.  The ISP cable modem will connect to the E0 (outside) interface of the ASA.  All other interfaces on the ASA are configured for the inside network 192.168.5.0/24. I have created a VPN site-to-site tunnel between this ASA and the UC540 to allow 192.168.5.0/24 subnet access to the internal networks on the UC540. 

 The user has requested that all the network devices used by the rest of the family will only need to connect to the Internet.  They will not need access to the VPN tunnel and they will not need access to the computers on the 192.168.5.0/24 inside network.  I was planning on performing the following tasks to get this to work.

View 2 Replies


ADVERTISEMENT

Home Network :: Netgear Router WNR 2000 V3 - Cannot Access Internet When Security Password Chosen?

Apr 13, 2013

I just bought a Netgear Router WNR 2000 v3 and installed it. I got inside the router and could set up a Network Name and security key. However, I can not access the internet when I chose a security password using WPA 2, WPA-PSK + WPA 2 PSK, or WPA/WPA 2. It only accesses the internet when I chose None.( no secured ).At this time, my network is unsecured because there isn't way I can access the internet when I create a security key using the 3 options the router offers.

Note : I have tried the 3 security options creating a key number and my computer connect to the wireless network but don't access the internet. It only access the internet when I select None ( no secured )

View 2 Replies View Related

Security / Firewalls :: VPN Client Users Cannot Access LAN?

Jul 23, 2012

I configured a dynamic vpn(easy vpn) in a cisco isr. But the vpn clients cannot access any of the lan devices. VPN pool is 10.0.0.1- 10.0.0.20 & internal netwrk add is 172.17.x.x. I tried to disable zone based firewall but no resultout[CODE]

View 1 Replies View Related

Cisco VPN :: 5505 Allow VPN Users To Access A Different VLAN

Jan 17, 2012

I have an ASA 5505.  I have configured Remote Access VPN so that users can connect to VPN and access my main VLAN (Inside).  I would like to secure it so that when a user VPN's in, they are only allowed access to the HVAC vlan (Vlan 2) as seen in my configuration.  Please note there is also a LAN- 2- LAN VPN which has been configured as well.

View 17 Replies View Related

Cisco Firewall :: 5505 - Users Unable To Access External Email Servers ASA?

Nov 28, 2011

I have a issue that i am at a loss as how to solve it. I have an ASA 5505 as my firewall. I have users from other companies who visit from time to time and are unable to use their outlook email to send messages. They can however receive messages without a problem. I also have a situation where users who use windows live to access gmail are unable to send messages.
 
I have narrowed it down to the fact that these uses are using  ssl/tls to send the mails. I did some research and found out about the inspect esmtp setting in the ASA.  I have disabled it and i still have to problem. I have also removed all outbound deny statements and still no luck.
 
Of note is that i can send emails without attachments. They take a long time to go out ( from minutes to hours) but eventually they do. Emails with attachments of even 10k do not go at all.
 
I was running image 8.2.3 and i downgraded to 8.0.5...still did not work...i upgraded to 8.4.3...still did not work. I am now back at 8.2.3.
 
My Firewall config is attached. I am at my wits end as to what else to try. The company has not renewed support for the device so i am on my own here!

View 2 Replies View Related

Cisco Security :: ASA 5505 For Remote Access VPN

Dec 21, 2012

I try to configure my CISCO ASA 5505 for remote access vpn, and I encounter the following issue : Secure VPN Connection terminated locally by the Client. Reason 412: The remote peer is no longer responding. [code]

View 2 Replies View Related

Cisco Security :: 5505 - No Access To ADSM

Feb 19, 2013

I still can't access ASDM. I deleted the old ASDM versions and upgraded to ASDM 7.1(1)52 which shows compatible with ASA 8.2(1). I'm on an inside NAT address connected to Eth 0/5, 192.168.1.5/24. I can ping and SSH to the FW but no ASDM. Following is passing traffic and everything else works just fine.

JEREMY-ASA# show ver
Cisco Adaptive Security Appliance Software Version 8.2(1) Device Manager Version 7.1(1)52
JEREMY-ASA# show run asdm
asdm image disk0:/asdm-711-52.bin
no asdm history enable
[Code]...

View 4 Replies View Related

Restrict Internet Access To Particular Users?

May 28, 2011

got myself the Netgear internal PCI wifi adapter today & it works just fine on my Windows XP SP3 desktop.

The only problem I have is the question of restricting access to kids @ home. If it was an external USB adapter, I could have just taken it away but the concern is the device being an internal & always available one. The user configuration on the PC is such that there is 1 main administrator (The actual windows "administrator" account) that no one uses. Apart from that,

- 1 user with admin privileges (me)

- 1 limited account for the kid

- 1 admin privilege account for the kid again (for purposes like installation of games which require an admin account as mandatory)

I would like for the wifi PCI card to work only when I login to my account. There must be someway by which I could disable the device or make the internet inaccesible in the other accounts,, (but pls bear that 1 of the account that the kid uses also has admin privilege)

I tried disabling the device from control panel but in vain.. (tried something like the sys admins do in corporates ..) disabling the usb ports on the PC's in my office..!

View 14 Replies View Related

Restricting Internet Access To Particular Users On XP?

May 28, 2011

got myself the Netgear internal PCI wifi adapter today & it works just fine on my Windows XP SP3 desktop.

The only problem I have is the question of restricting complete internet access to kids @ home. If it was an external USB adapter, I could have just taken it away but the concern is the device being an internal & always available one.

The user configuration on the PC is such that there is 1 main administrator (The actual windows "administrator" account) that no one uses. Apart from that,

- 1 user with admin privileges (me)

- 1 limited account for the kid

- 1 admin privilege account for the kid again (for purposes like installation of games which require an admin account as mandatory)

I would like for the wifi PCI card to work only when I login to my user account. There must be someway by which I could disable the device or make the internet inaccessible in the other accounts,, (but pls bear that 1 of the account that the kid uses also has admin privilege)

I tried disabling the device from control panel but in vain.. (tried something like the sys admins do in corporates ..) disabling the usb ports on the PC's in my office..!

View 4 Replies View Related

Cisco WAN :: 2801 Router Can Access Internet But Not LAN Users

Feb 9, 2012

The goal is to add a 2801 router between a DSL modem and a switch and obviously still access the internet. I connected and configured as explained below and the results are:
 
- I am able to ping internet addresses from the 2801 router
- I am not able to ping internet addresses from userlaptop but I am able to ping LAN gateway (192.168.254.254)
  
I cannot understand why the internet requests from the user laptopuser are not routed to the internet but the router itself can access the internet.
 
INTERNET====DSLmodem=====CISCO2801=====unmanagedSwitch=====userlaptop 
 
DSLmodem:
non-bridged mode and does the PPPOe authentication.
WAN interface: Dynamic IP address assigned by ISP

[Code].....

View 14 Replies View Related

Home Network Fails After Uninstalling Norton Internet Security

Nov 12, 2012

My Vista computer and my XP computer had been happily "talking" to each other, sharing files and printers. I got tired of paying $70 a year for Norton Internet Security, so I uninstalled it (using the Norton removal tool) and selected the Windows Firewall. I also installed Avast! and SuperAntiSpyware. Now neither computer talks to the other. When I run "\FamilyRoomHPOfficeJet" I get "Windows cannot access \FamilyRoomHPOfficeJet" . Check spelling, etc. Get error code 0x800704b3 "The network path was either typed incorrectly, does not exist or the network provider is not currently available..." What have I messed up by going from the Norton firewall to the Windows one.

[code]....

View 14 Replies View Related

Setting Up Restricted Internet Access For 20 Users

Jan 10, 2012

restricting access to internet for roughly 20 users. Right now we are connected using broadbandand using dhcp as assigned by common switch. All pc's are in a common workgroup. recommend me the hardware / software required to restrict this access.

1. Will I require a router as well as a switch ? or should I simply get a new switch ( for more then 20 users ) This would mean static ip for all users.

2. My idea is to create a AD server and use websense on it so that users who require internet access can still open internet sites but will be restricted through websense proxy.

View 1 Replies View Related

Cisco Switching/Routing :: Internet Access To Users Using 871 Router

Jan 21, 2013

I'm currently undergoing CCNa academy so I got a "job" from  my boss to configure Cisco 871 router.  Unfortunately we just finished  first semester at academy so there are some things that I'm still having  hard time to understand. I managed to configure router so it connect to internet or to be  exact it has internet access through  another adsl modem that is in  bridge mode. url...The problem is that users are not able to use internet when connected  to this router.  I'm able to access router through telnet  ( ip  192.168.13.10)  but that's it.192.168.13.0 255.255.255.128 is network that we use at work.   192.168.13.5 is IP address that is assigned to zyxel adsl modem ( If I'm  correct, we could have used any address here since we are connecting  this directly to router ? ) Zyxel adsl modem  is connected to FA4 port on Cisco router.   LAN  cable is connected to FA0 port and from there it goes to switch ( it's  some  asus switch with 50 ports). [code]

If I ping google dns from router e.g. ping 8.8.8.8 it works.  If I ping url... it doesn't work. Also I'm able to access router via 192.168.13.10 but if I use router as  default gateway then I'm not able to access the internet.

View 8 Replies View Related

Cisco Switching/Routing :: 3750 / LAN Users Have No Internet Access

Mar 19, 2013

We have a Cisco 3750 stack connecting to the MPLS router, able to ping 8.8.8.8 - [URL], the internal users on their own Vlan can ping the default gateway the 3750 switch but no further, trace route from the PC/Servers stops at the 3750 stack.We have the switch configured to ip route 0.0.0.0 0.0.0.0 to the public interface in the MPLS router, from the switch I'm able to ping the internet.

View 17 Replies View Related

Cisco :: ASA5505 - AnyConnect VPN Users Lose Internet Access

May 16, 2012

I am able to successfully connect to my ASA5505 via AnyConnect via a mobile device. Upon doing so, I lose internet connectivity.  My access list appear to be correct to I'm sort of at a loss.

[code]....

View 6 Replies View Related

Wireless Home Network With Verizon Internet Security - Changing IP Address?

Dec 24, 2011

I have verizon fios internet and a wireless home network with verizon internet security and I want to ghange my IP adress on my laptop

View 6 Replies View Related

Cisco WAN :: 1800 Router Does IP NAT Translation / Slow Internet Access For Users

Oct 4, 2012

We have an ethernet port on Cisco router 1800 connected to the ADSL modem. The router does ip nat translation, but users complained it is slow when they access to internet. [code]

View 1 Replies View Related

Cisco Security :: ASA 5505 / HTTPS From Vpn Client To Internet Host Through Tunnel Ipsec-spoof?

Jan 17, 2013

we have a cisco ASA 5505 and are trying to get the following working:
 
vpn client (ip 192.168.75.5) - connected to Cisco ASA 5505
 
the client gets a specific route for an internet address (79.143.218.35  255.255.255.255     192.168.75.1     192.168.75.5    100) when i try to access the url from the client i get a syn sent with netstat when i try the packet tracer from the ASA i see the following:
 
<Phase>
 <id>1</id>
 <type>FLOW-LOOKUP</type>
 <subtype></subtype>
 <result>ALLOW</result>

[code].....

View 5 Replies View Related

Cisco Routers :: Configure RV120W So That Internet Users Can Access Internal Company Websites?

Apr 4, 2012

How does one configure the router so that Internet users can access internal company websites? The only thing that appears is the Cisco router login. Also I need to configure Terminal Services and its not on the list under Service.

View 2 Replies View Related

Two Home Routers To Access Internet From Work / Internet Cafes

Feb 22, 2012

I have a laptop that I take to work, and would like to set things up to use my home internet connection from elsewhere. I don't have another computer to function as a server for me at home, so would like to do it so that my router alone provides this access (log into it from the internet anywhere and use my internet as if I am using it from home). How would I go about doing this? Would it require installing new firmware?

View 1 Replies View Related

Cisco Security :: ASA 5505 Security Plus Licensing?

May 24, 2011

I have a ASA 5505 that I test with which originally came with the Security Plus license. I recently erased flash and loaded the latest asa841-k8.bin version of IOS along with asdm-642.bin. Everything booted fine and came up as it does when freshly wiped however I noticed that i was now only running a base license. If I issue the sh activiation-key command, I noticed the following messages (full output is at the bottom):
 
The Running Activation Key is not valid, using default setting
......
This platform has a Base license.
......
Failed to retrieve flash permanent activation key

 Did I somehow kill my Security Plus licensing when I did the erase flash? If so how do I recover it? 
 
ciscoasa# sh activation-key
Serial Number:  JMXXXXXXHU
Running Permanent Activation Key: 0x00000000 0x00000000 0x00000000 0x00000000 0x00000000

The Running Activation Key is not valid, using default settings:
 
Licensed features for this platform:
Maximum Physical Interfaces       : 8              perpetual
VLANs                             : 3              DMZ Restricted
Dual ISPs                         : Disabled       perpetual
VLAN Trunk Ports                  : 0              perpetual

[code]...

 This platform has a Base license.Failed to retrieve flash permanent activation key.The flash permanent activation key is the SAME as the running permanent key.

View 2 Replies View Related

How To Setup Home Server And Restricting Users

Feb 20, 2013

I am a networking student so have access to a free copy of Windows Server 2012. I want to setup and get experience with AD, DHCP, and DNS, among other services. Right now I have a Netgear router attached to a Cisco switch. (studying for CCENT cert) I have my desktop and server plugged into switch. I want my desktop to connect to the domain for testing and messing aroudn with. My wife has a netboook, smartphone, and wireless ipod. I'd like her 3 devices to get an IP from the DHCP server without having her authenticate to the server. Will the Netgear router allow this since wirless access is on? Or will she need to authenticate with the server to get a DHCP IP? I am gonig to disable the router's DHCP service.

View 3 Replies View Related

Cisco Firewall :: ASA 5505 - Block Certain URL On Certain Users

May 20, 2013

I am using ASA5505 and I would like to block certain websites such as facebook.com on some users only

View 3 Replies View Related

Cisco Firewall :: ASA 5505 Users Restriction?

Jul 2, 2012

There are 10, 50 and unlimited users profiles for the ASA 5505, reason for that restriction? Does that mean for example that only 10 users can go through a 10-user 5505?

View 6 Replies View Related

Cisco Firewall :: ASA 5510 - Users Unable To Access Internet Through Firewall

Feb 26, 2013

I have some problem with the ASA 5510 ver 7.0(6). My manager wants to keep this as backup. tried lots of things but still users not able to access internet nor can i ping anywhere.For example when i ping 4.2.2.2 i dont get any reply.The runing config is below for ur ref :
 
HQ-ASA-01# show  running-config
: Saved
:

[Code]......

View 9 Replies View Related

Cisco Firewall :: Users Behind ASA5505 Firewall Are Unable To Access Internet

Feb 24, 2011

I have a normal setup of ASA5505 (without security license) connected behind an internet router. From the ASA5505 console I can ping the Internet. However, users behind the Firewall on the internal LAN, cannot ping the Internet even though NATing is configured. The users can ping the Inside interface of the Firewall so there is no internal reachability problem. In addition, I noticed that the NAT inside access list is not having any hit counts at all when users are trying to reach the internet.

When i replace the ASA5505 with a router with NAT overload configuration on it, the setup works normally and users are able to browse the internet.

The ASA5505 configuration is shown below.

hostname Firewall

interface Ethernet0/0
description Connected To Internet Router
switchport access vlan 10

[Code].....

View 2 Replies View Related

Home Network :: Connection Timeout For Some Users In Windows 7?

Jul 6, 2011

I have a network set up with file sharing. I use a Windows 7 PC to host files that are shared with few other PCs - some on Windows 7, some on Windows XP. The file sharing works but sometimes some users are unable to get access to the files. It seems to be only on the machines that are on XP that this problem occurs. The error message is something like \PCNAME is not accessible...

The user can connect if the machine storing the files is restarted but it will happen 4-5 times during the day.

View 4 Replies View Related

Home Network :: How To Stop Internet Access Through Network Complete Internet Access

Jan 26, 2012

i would like to know that how to stop internet access through network complete internet access

View 2 Replies View Related

Cisco VPN :: 5505 Local Users Authenticate To AnyConnect

Jul 16, 2012

I am trying to configure a Cisco ASA 5505 so that users can authenticate via Radius or via a Local account using the Cisco AnyConnect client.  In the AnyConnect Connection profile, the basic tab, it has Authentication Method.  We have this going to an AAA server group with Use Local if Server Group fails option is checked.Each time, I see where the user has failed while attemtping to log in to the domain via the radius servers and thus bypasses the local user database all together.       

View 3 Replies View Related

Cisco Firewall :: Restricted Inside Users Of ASA 5505

Jul 6, 2011

i have an asa 5505 firewall with asa version 8.2(1). my asa connected on wan port over isp router on internet.inside users connected over dlink switch and the allied telesis 24 ports switch on this asa. the inside users are blocked and they can't communicate. all inside ports of asa 5505 are in one vlan and all ports are switch ports. the configuration of my firewall is 
 
: Saved : Written by xxxxxx at 11:26:22.109 CEDT Thu Jul 7 2011 ! ASA Version 8.2(1) ! hostname asa5505 domain-name dri.local enable password 8Ry2YjIyt7RRXU24 encrypted passwd 2KFQnbNIdI.2KYOU encrypted names ! interface Vlan1 no

[Code].....

View 5 Replies View Related

Cisco Firewall :: Numbers Of Users For ASA Content Security Module 1703

Feb 1, 2012

I run a website for a local football team using Serif Webplus X6. On uploading the weekly updates of the site the process seems ok for a few minutes with progress bars showing uploading of files but then it all stops and I have to reset my wireless network adaptor 1703 and it continues but I can't just leave it to work on its own. Device manager says that the drivers are up to date but I'm fed up with having to nurse the adaptor. This didn't happen with previous computers.

View 2 Replies View Related

Cisco Security :: Disabling XAuth For Remote VPN Users On ASA 5510 Version 7.2(1)?

Jul 1, 2006

how to disable XAuth for Remote VPN users on the ASA 5510 running 7.2(1)? 
 
HPMFIRE(config)# tunnel-group vpn3000 general-attributes
HPMFIRE(config-tunnel-general)# authen
HPMFIRE(config-tunnel-general)# authentication-server-group none
ERROR: The authentication-server-group none command has been deprecated.
The isakmp command in the ipsec-attributes should be used instead.

--[code]....
 
I couldn't find anything under isakmp to disable it. 

View 2 Replies View Related

Home Network :: No Internet Access?

Sep 8, 2011

Since yesterday im unable to connect to the wireless connection in my dormsI'm able to connect but i get yellow triangle with exclamation mark in it, and it says "no internet access".In the living room im able to gain internet access, my friend also tried in my room and he was able to get internet access, he has tp-link adapter on his laptop.I have dell vostro 3500 with "DW1051 wireless-N WLAN half-mini card" as my adapter.I opened IE9 and pressed "Diagnose connection problems" and got the messege "Wireless Network connection" does not have valid IP configuration.OS: windows 7 ultimate x64

View 6 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved