Cisco Security :: Dual ASA 5520 WCCP Configuration?

Dec 6, 2012

I recently configured WCCP with a Sophos Web Filter on my network it works good but the problem I am having is I have two 5520s so I am directing the device to look at 2 different IP addresses and since the devices are in an Active/Passive failover.  The problem is because the second device is in a passive failover it is not responding which is throwing connection errors to my Sophos device.  I know you can have a single management connection for the ASA's but is there a way to have a single IP for the ASAs for the WCCP?

View 1 Replies


ADVERTISEMENT

Cisco :: Roll Out A Bluecoat As A WCCP For A ASA 5520

May 25, 2012

I need to roll out a Bluecoat as a WCCP for a ASA 5520.

View 3 Replies View Related

Cisco Firewall :: WCCP Redirection On ASA 5520

Jul 17, 2011

I currently have WCCP redirection setup on my ASA 5520 to redirect to an ironport on ip address 10.11.1.10. The ASA inside ip is 10.11.1.1 and the ironport is setup for transparent redirection to that IP. This all works well and the Service Identifier i'm using for WCCP is 95.I am now creating another WCCP group because on my ironport I have 4 interfaces so I wanted to use them for our admin network. So I created an ACL on the ASA for our admin traffic and I want to redirect that using Service Identifier 94 to the ip on the ironport of 10.11.1.22. But I can't get traffic to redirect.

View 1 Replies View Related

Cisco Firewall :: ASA 5520 VPN Users With WCCP Redirection To IronPort

Apr 11, 2012

I have a 5520 ASA using wccp redirection to our IronPorts on the inside and everything works great for inside users. What I'm trying to do is get VPN users off split tunneling and to filter their traffic through the IronPorts as well but I can't figure out how. When they connect they seem to bypass the Ironport completely.

View 5 Replies View Related

Cisco Infrastructure :: WCCP Configuration On 4507

Jun 16, 2012

I am trying to setup WCCP on our 4507. For some reason I cannot get this to work! The config I have tried is below. I can't figure out
 
ip wccp web-cache group-list IRONPORT-GROUPLIST
ip wccp source-interface GigabitEthernet2/24
!
Interface Vlan160

[Code].....

View 2 Replies View Related

Cisco Firewall :: ASA 5512 WCCP Configuration With Web Filter

Oct 31, 2012

I am currently trying to enable WCCP between a Cisco ASA 5512 firewall and Barraccuda Webfilter 410 Vx applicance. The ASA firewall is running IOS version 8.6(1)2 and the Barracuda is funning firemware 6.0.0.013. Both the ASA and Barracuda are in the same network and can ping eachother. The ASA has several interfaces, outside, inside, data and dmz. The PCs and barracuda appliance are behind the data interface.  ASA data IP 172.16.18.1 Barracuda IP 172.16.18.40   All PCs in the 172.16.18.0/24 subnet use the ASA as the default gateway and should have web requests redirected to the Barracuda. 
 
Below are the respecive bits of my ASA config
 
interface GigabitEthernet0/0
description Management
speed 1000

[Code].....
 
I suspect my issue is that the ASA is generating a Router Identifier of 172.21.20.1 which is my inside network and the barracuda cannot communicate with it.  how I can get this working ?

View 3 Replies View Related

Cisco Switching/Routing :: WCCP Configuration On Catalyst 3750G?

Jul 5, 2010

I have a WCCP Configuration on a Catalyst 3750G and a IronPort Webappliance. I have configured this situation many times before with cisco asa and ironport wsa, but with a switch, this is my first time.
 
VLAN 147 is a transportation vlan between the cisco switch and a hp coreswitch with the clients and servers behind the hp coreswitch.
 
VLAN 147 IP Address of the Catalyst is 172.30.47.1
 
IP of the IronPort Appliance is 172.30.47.10
 
IP of the HP Coreswitch is 172.30.47.2
 
Plan  is to redirect the webtraffic coming from clients and servers from the 10.0.0.0/8 net behind the hp switch to the ironport wsa. In have configured these settings.
 
ip wccp web-cache group-list 15 password 7 091D1C5Aip wccp 80 redirect-list 16 group-list 15 password 7 14464058
interface GigabitEthernet1/0/22 description IRONPORT P1 BUWOG switchport access vlan 147 switchport mode access
interface Vlan115 ip address 172.30.15.2 255.255.255.0 standby 10 ip 172.30.15.1 standby 10 priority 90 standby 10 preempt standby 10 track Vlan115!interface Vlan147 ip address 172.30.47.1 255.255.255.0 ip wccp web-cache redirect in ip wccp 80 redirect in

[code]....

View 6 Replies View Related

Cisco Routers :: VPN Configuration For Dual WAN On Dual RV042

Feb 21, 2013

I run 2 RV042 V1 for home and office with Gateway to Gateway VPN connection with single WAN connection in use. Everything works like a charm!
 
I was even able to create VPN connection with 2 WAN connection on one Router and 1 WAN connection on another with Smart link failover and VPN Tunel Backup.
 
I got problem though when i tried more complex connection diagram. [URL]
 
So basically I now have 2 ISP connections on each point with Static IPs and I'd like VPN Connection to be alive for ALL 4 options automatically with failovers (smart links) And tunel backups but i'm not sure if that's ever possible with my equipment.

View 2 Replies View Related

Cisco VPN :: Dual ISP And SSL VPN On ASA 5520?

Dec 30, 2012

I configured dual ISP on ASA 5520 following cisco doc below. Now I would like to configure SSL VPN to work with this for failover? I tried to find an article regarding this but I could not. [URL]

View 3 Replies View Related

Cisco Firewall :: ASA 5520 - Dual ISP

Mar 12, 2011

I have Cisco ASA 5520 . I want to deploy this in the following scenario. Two ISP( for internet) links are connected in the ASA. Three  zone ( Outside , DMZ , Inside) specified on the ASA.In DMZ , there are two proxy server ( proxy 1 , proxy 2) . Branch user will use proxy server 1 and Head office will use proxy 2. 
 
In the above scenario management requirements are, Proxy 1 will use ISP 1 and proxy 2 will use ISP 2.If ISP 1 goes down then proxy 1 will use ISP 2 for internet. Please suggest me how I will configure the ASA in the above requirements or if possible send me the configuration.

View 3 Replies View Related

Cisco WAN :: Dual ISPs In ASA 5520

Jul 10, 2011

We got 2 ISPs -------> two ASA 5520 Primary / secondary --------> LAN . ASA is configured with ACL and Static NAT for our mail , web & ftp servers .
 
My question is how to configure the 2nd ISP on the ASA to auto switch to the 2nd ISP when the 1st is down with a backup static NAT and backup ACL for the new ISP , in other words how to configure a active static NAT and Backup Static NAT and ACL only for Exchange/Mail Server.Here is the example of our configuration where PIE is Primary ISP & EMC is Backup ISP.
  
ASA Version 8.2(1)
hostname Corp-ASA
enable password 2KFQnbNIdI.2KYOU encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
names
[code]....

View 1 Replies View Related

Cisco Firewall :: ASA 5520 Dual ISP Feature

May 31, 2013

I would like to knwo if i have dual ISP feature with my ASA 5520 licence? With ASA 5505 i can see Dual ISP feature but with ASA 5520 it's not!

View 3 Replies View Related

Cisco WAN :: BGP Multihomed ISP Dual Routers And ASA 5520

Aug 3, 2010

I have a client that is requesting redundant internet connections using 2 7204 routers to 2 asa 5520 in an active standby configuration.  There is no load balancing requirement this is strictly for failover.  The issue that I am having is that I have to have 1 of there public IP addresses on the Lan side of the 7204 for the ASA connectivity.  Because of this both routers advertise out their public subnet to the respective providers, but the issue is that when the wan link on the primary router fails and traffic traverses the secondary wan the return traffic comes back in the secondary wan and stops because it sees the link to the asa as being up even though the asa is in standby.  No matter what route manipulations I do a directly connected route is alway going to be better. How I can get this to work.  Below is a rough sketch:
  
Verizon------Router A (Primary)-----ASA A (Active)--------------Nexus1
                         |                              |                              |
                         |  IBGP                    | Keepalive               | VPC Link
                         |                              |                              |
AT&T---------Router B (Backup)-----ASA B (Standby)------------Nexus2

View 6 Replies View Related

Cisco Firewall :: ASA 5520 For Dual Active ISPs

Dec 14, 2011

I inherited a network redesign project mid implementation and ran across an issue that I was not 100% sure able to be resolved.  Implementation is occurring in which the organization is changing over to a different ISP and we have some customers that will not be able to change their settings over to our new addresses from some time.  I have seen a lot of posts about fail over and dual ISP configurations, but I could not relate them to this particular scenario.

View 3 Replies View Related

Cisco VPN :: ASA 5520 - Configure VPN To Dual Remote Endpoints

Dec 13, 2011

Not sure if my subject is a good decription of the problem or not.
 
I have an ASA 5520 at my home office and a SonicWALL NSA2400 at my remote office.  The remote office has dual internet connections and I wanted to create two seperate VPNs between the devices using each internet connection on the SonicWALL.
 
I know how to configure this on the SonicWALL, the problem is on the ASA 5520
 
OK Basic network config
 
Main Office

ASA Public IP 1.1.1.1

ASA Internal network 192.168.1.0 (VPN source)
 
Remote office

Public IP 1     2.2.2.2

Public IP 2     3.3.3.3

Iternal network 192.168.2.0 (VPN destination on ASA)
 
If I have a VPN from the main ASA to either one of the SonicWALL's public IPs everything works fine

If I create 2 VPN tounels from the main ASA, 1 to each public IP on the SonicWALL, the VPN shows as up but no traffic flows.

View 1 Replies View Related

Cisco Firewall :: Does ASA 5520 Support Dual Network Drops

Oct 9, 2011

We are looking to deploy an ASA 5520, but I need to know if it is possible for it to work in this environment.
 
We have colo space, with two IP ranges. They provide two network drops, one from each switch connected to different routers. One in which has 4 usable IP's for management purposes. This address range will be used only for remote access to the ASA and VPN into the management VLAN. The management VLAN will have all internal devices such as the switches, etc. The second range is for the servers, of which will be assigned directly to the hosts and the ASA will need to act as just a firewall. I can do this on IOS, but not sure about the ASA.
 
I need to answer the following questions:
 
Does the ASA support dual network drops, and would this be a failover port configuration in order for it to work?A management VLAN with outbound internet access only, and VPN/RA capability. NAT will need to be used I'm guessing. Can we have a DMZ VLAN which has defined ports, say 80, 443 and 25 inbound and outbound. I need the hosts to have the public IP assigned to them with no NAT configuration.
 
I know there are some advantaged to using NAT, but I really can't use it because the applications behind prefer public IP's being assigned to them.

View 23 Replies View Related

Cisco WAN :: 891-K9 Dual Wan Configuration Using PFR

Mar 30, 2012

The basic setup Newly installed redundant ISP, thus setting up the 891 with dual WAN Using PFR to load balance between the two. Did initial config through CCP (not express), but I am familiar with the basics of IOS CLI (not used to the new zone based firewall yet, managed aour old Pix for too long, but that is a different subject)
 
I cannot seem to get anything but Gi0 to be accepted as a WAN interface. I go through the entire setup in CCP, test each connection, etc, and it all looks good until I exit out of CCP and go back in. At that point, I get squat out of Fa8. CCP won't let me test the connection, won't let me edit the connection, wont let me delete the connection. The wizard for a new WAN connection becomes available again (Wanting to set up a "second" WAN on Fa7...)
 
Again, I have verified connections to each ISP line independently, either one works just fine on Gi0, neither ever works on Fa8. This is my first real foray into PfR.
 
Building configuration...
 
Current configuration : 21486 bytes

Last configuration change at 18:59:43 UTC Mon Mar 26 2012 by admin
[URL]....

View 4 Replies View Related

Cisco Firewall :: ASA 5505 / 5520 Dual Gateway From 3750 And 2010

May 17, 2011

I need to move the client machines off of the 3750 (and their DHCP dependency on it) to the SGE2010 and absolutely route their internet traffic out through the outside interface on the 5505. They must also be able to communicate back into the internal environment in order to communicate with the production servers.
 
The clients currently use .254 addressing through a dumb dell switch to the 3750 but I am trying to migrate them over slowly to the .253. I know that the 2010 will not do DHCP, so I am putting a DHCP server on that switch right now. The 5505 won't let me add an additional nameif statement onto one of the other eth0/x interfaces and I'm not sure if that has anything to do with it's capabilities to act as a DHCP server (it's not an option in the ASDM) or it's ability to serve as the internet gateway for the 2010 clients. (Side notes: The 5505 has a base license and is currently also connecting 1 site to site VPN. As is the 5520, so all of it's interfaces are used as well).
  
I statically assigned a moved client with a .253 address and plugged it into the 2010. I have tried giving the 2010 both a .4 address and a .253 address but neither will allow me to ping any of the addresses on the 5505. The 2010 shows automatic routes to the two subnets and I set it's default route to 253.1. The link between the 2010 and the 3750 works - clients receive a .254 address from the 3750 and can get out to the internet via the 5505 and reach the production servers as well.
 
Why won't the 2010 see the 5505 as a gateway and allow clients to get to the internet and also traverse the 3750 when they need access to the production network?

The reason why I dont' just connect the two swtiches and call it a day is because I also need the production servers to ALWAYS go out/receive web requests via  the 5520 outbound/outside interface. I'm having such a hard time wrapping my head around why i can't get my clients moved over to the new switch, I haven't even grasped how I'm going to do that yet.

View 1 Replies View Related

Cisco Switching/Routing :: 5520 Dual Core Switch For Redundancy

Sep 16, 2012

I have the following: 1 5520 ASA connected to the internet, 2 core switches, and several access switches.Aside from implementing RSTP, VRRP, hard code access and trunk ports, is there any other recommendation you would like to add.

View 7 Replies View Related

Cisco Security :: ASA5505 Dual ISP Capability?

Jun 18, 2008

I have two ISP's and I want to channel specific traffic out of an interface based on traffic type.  Will the ASA 5505 security bundle allow me to route specific traffic out through a specific interface?

View 2 Replies View Related

Cisco Firewall :: ASA 5505 Security Plus Dual ISP

Apr 5, 2010

I have an ASA5505 with Security Plus license so I can have many interfaces (not 2 + 1 limited DMZ like in base license)
 
I have 2 VLANs.Is it possible to use one ISP for VLAN 1 and other for VLAN 2 ? Is it limited to 2 ISP's or can have more ?

View 14 Replies View Related

Cisco WAN :: Dual ISP Failover Configuration 891W?

Apr 18, 2012

What I currently have is a Cisco 891W Router as well as two ISP's (both with dynamic IP's) in.  I'm currently just running one of my modems into the 891 through the FE8 port and then if for some reason I have an internet failure switching the ISP modems.  What I'm wondering is if there is a fairly simple way to configure (and attach) both modems to this router and then set it up to handle this failover automatically?

View 1 Replies View Related

Cisco Firewall :: ASA 5510 Dual ISP Configuration Required

Jul 13, 2011

I have existing Sonic FW in my company we are moving from sonic FW to ASA 5510 Security plus lice. I have two ISP currently connected to sonic Firewall I am planning to implement Dual ISP configuration on ASA5510.

View 12 Replies View Related

Cisco WAN :: RV082 Dual Wan Terminal Server Configuration

Jan 31, 2012

I've a RV082 with 2 internet connections.The idea is to permit external connections to my server and if one Internet line falls, automatically switch to the other.
 
We have configured the router in Smart Link backup.We try to connect with WAN1 and WAN2 enabled and all works fine.
 
We try to connect with WAN1 disabled and automatically WAN2 is activated.The problem start here...if WAN1 is activated while there are connections using WAN2, these connections falls!
 
How I must configure the router to permit that active connections are not disconnected from WAN2 even when WAN1 connection come back?

View 1 Replies View Related

Cisco Routers :: RV082 Dual WAN Configuration Required

Jun 12, 2012

RV082 configured for Dual WAN [Code]....

(2) identical DSL connections, configured as Static IP (not PPPoE) with modems in bridged mode. Static IP's are /25 subnet and same gateway  ** this may be a problem? Dual WAN set for Load Balance, network service detection is OFF
 
We have a 2003 terminal server running and successfully receiving connections through both WAN connections.  Depending on location, half the users are connecting to WAN1 IP and the other half to WAN2 IP.  We are getting sporadic disconnects of the remote users when they are idle for a couple minutes and automatic reconnection of the session takes over a minute.  If they close the (locked up) session and reconnect manually it will let them in right away. 
 
Could the handling of the Dual-WAN be the culprit?   Could the same gateway for both WAN's create this issue upstream (out of my control)?I am going to move everyone to connecting through WAN1 and then change to Smart Link Backup and see if the issues persist.
 
Another thought is to use a secondary IP on the terminal server and use Protocol Binding to match "All traffic" for IP1 to WAN1 and IP2 to WAN2, which theoretically would stabilize the situation?

View 36 Replies View Related

Cisco Switching/Routing :: RV016 Dual Wan Configuration

Oct 15, 2012

I have recently  implimented an RV016 device into our network. We have a bonded T1  service with Paetec/Windstream (5 static IPs) and also a cable  connection with Comcast (no static IP). The T1 has been our primary  connection, and our MX and A records all use this IP address. I have the  rules set and using a one-to-one NAT setup with our 5 IPs. Everything  is working great with the T1 in place and email is flowing with no  problems, however when I connect the cable into the WAN2 port and try to  send email, its using that outbound connection, rather then the T1 and  our spam filter is blocking it. So the email is rejected and we get this  message below.

---------------------------------------------------------------------------
Delivery has failed to these recipients or groups:
 
xxxx@gmail.com (xxxx@gmail.com)Your  message wasn't delivered due to a permission or security issue. It may  have been rejected by a moderator, the address may only accept e-mail  from certain senders, or another restriction may be preventing delivery.
 
The following organization rejected your message: (our smtp spam relay)
-------------------------------------------------------------------------
 
The reason for being rejected is just because it doesn't recongnize the IP address/gateway it is coming from.
 
My  question is, how do I define that all email is sent out through our T1  connections IP address in the router?I see options for Advanced Routing  or Bandwidth Management, but not sure what one I need to configure as I  am not too familiar with these settings. I have Intelligent  Balancer(Auto Mode) enabled as well by default.
 
The reason  for adding the second internet connection is strictly for load  balencing and getting some more bandwidth in our location.

View 3 Replies View Related

1811 Dual Wan Port Forward Configuration?

Nov 13, 2011

I'm trying to configure cisco 1811 with dual isp internet connections. Everything is working fine till i get to setting up port forwards.The port forwards for 2nd ISP do not work while connection to 1st isp is active. If if shutdown the connection to isp1 the port forwards work fine.

here's relevant section of the config

Code:
track 123 ip sla 1 reachability
delay down 15 up 10
!
track 456 ip sla 2 reachability
delay down 15 up 10

[code]....

I can access the 192.168.2.131 web server using the ISP1 ip but not ISP2 ip If i shutdown ISP1 interface the server becomes accessible through ISP2.Also while ISP1 is active I can't remote desktop to 192.168.1.210There are no acls, firewall zones or anything else.

View 3 Replies View Related

Cisco Switching/Routing :: How To Do Dual ISP Configuration - 2811 Router

Dec 9, 2011

Will 2811 Router with 4 switch port module, How to do dual ISP configuration on this router.

View 10 Replies View Related

Cisco WAN :: 4507R - Dual Homed To Single ISP Configuration And HSRP?

Mar 6, 2007

In the LAN network 4507R as core switch configured with several vlans.One vlan connects to the dual homed routers which in turn connecting to the single isp. I need to configure the HSRP for the internal vlans and the same time to use the load balancing or failover using the dual homed routers to the isp.

View 7 Replies View Related

Cisco Switching/Routing :: 15.0 VSS Dual Active Detection Configuration

Jun 24, 2012

In IOS verson 12.X there was a Bidirectional Forwarding Detection configuration however in IOS 15.0 this isn't available at least not with the same syntax. Is this feature not available in 15.0?
 
In 12.X this was the syntax of the command:switch virtual domain <number>.

View 1 Replies View Related

Linksys Wired Router :: RV016 Dual Wan Configuration

Oct 16, 2012

I have recently implimented an RV016 device into our network. We have a bonded T1 service with Paetec/Windstream (5 static IPs) and also a cable connection with Comcast (no static IP). The T1 has been our primary connection, and our MX and A records all use this IP address. I have the rules set and using a one-to-one NAT setup with our 5 IPs. Everything is working great with the T1 in place and email is flowing with no problems, however when I connect the cable into the WAN2 port and try to send email, its using that outbound connection, rather then the T1 and our spam filter is blocking it. So the email is rejected and we get this message below.

View 1 Replies View Related

TP-Link Dual-Band Wireless :: WDR3600 Cannot Reset After Trying WDS Configuration

Feb 8, 2013

Region : UnitedStates
Model : TL-WDR3600
Hardware Version : V1
Firmware Version :
ISP :

I recently bought wdr3600 and just trying to configure bridge through WDS configuration. I just enabled WDS and picked my initial wireless router after clicking the Survey button, then save it. After the reboot, I cant seem to ping/access 192.168.0.1 and the wireless SSID cant be seen any longer. I tried doing the reset button for 30secs but looks like nothing is working and not resetting. And I am still getting 169.254.x.x

View 5 Replies View Related

Cisco Security :: ASA 5520 - Upgrade 8.2.x To 9.1.x?

Jan 17, 2013

I have a project to upgrade an ASA 5520 to 9.1.x, then add another ASA for failover.  What will be the correct way ?
 
I had the 2 Gb memory.
 
I have rewritten all nat statements (during my other 8.2 to 8.3 or 8.4 upgrade project, the nat conversion was catastrophic, so I rewrite all now).
 
Can I upgrade directly to v9 ? Or 8.2 -> 8.4 -> 9.1 ?
 
I think to :
 
- inject actual config in the new ASA in 8.2
- remove nat statement
- upgrade to 8.4
- configure new nat
- upgrade to 9
- connect the new ASA to the network and deconnect the other ASA
- test
- upgrade old ASA to 8.4 or 9 directly ?
- configure failover

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved