Cisco Security :: IOS VPN Endpoint Behind ASA 5510

Aug 2, 2011

trying to TS a VPN device that is behind an ASA basic set up is IOS VPN<firewall/nat<internet>ASA/nat>IOS VPN
 
I do not have a lot of insight into the other side of the connection, although the tech on the other side claims all is good. so to the point.
 
Is the asa capable of allowing this tunnel to work? The configs and debug follow.
 
1.1.1.1 = my public ip
2.2.2.2 = peer public ip
The asa -

[Code]......

View 2 Replies


ADVERTISEMENT

Cisco AAA/Identity/Nac :: Does Nac 4.7 Support Kaspersky Endpoint Security

May 17, 2012

we have installed nac for our customer and it works fine ,but the customer want the change the version of kaspersky antivirus from 6 to 8 end point security ,when we have try this the nac agent does not find the antivrus on the the workstation . i want to know if this version of kasoersky (end point security ) is supported by nac ,if no is ther a solution to make it works with the NAC .

View 3 Replies View Related

Cisco VPN :: ASA 5510 OS 8.03 Change IPSec Tunnel IP Endpoint In CLI

Mar 29, 2012

I have an ipsec tunnel  IP is changing from mythical 200.200.200.182 to 200.200.200.254.  Is it possible to change the .182 ip in  below config via the CLI to .254 and have the site-to-site vpn continue to work? [code]

View 1 Replies View Related

Cisco Security :: How Many Default Context In ASA 5510 Security Plus Edition

Aug 8, 2006

ASA 5510 security plus edition will it support active/active failover. and does it support context with securiyt plsu edition. and how many default context do we get with asa 5510 security plus edition.

View 3 Replies View Related

Cisco Security :: 2x ASA 5510 With AIP-SSM And CSC-SSM On Each One

Mar 23, 2012

I want to ask for the possibility of configuration below? 2x Cisco ASA 5510 running Multi-Context mode and Active/Active Failover1 Cisco ASA 5510 (ASA 1) has AIP-SSM1 Cisco ASA 5510 (ASA 2) has CSC-SSMThere are 2 contexts, context A and context BASA 1 is the primary firewall for context A, and secondary firewall for context BASA 2 is the primary firewall for context B, and secondary firewall for context A 

Can AIP-SSM on ASA 1 inspects traffic of context B which primarily runs on ASA 2?Can CSC-SSM on ASA 2 inspects traffic of context A which primarily runs on ASA 1? 

View 2 Replies View Related

Cisco Security :: ASA 5510 - Upgrade From 7.0(6) To 8.2(5)

Aug 18, 2011

I want to upgrade my ASA 5510 from version 7.0(6) to 8.2(5).  Reading the release notes for 8.2(5) it says the DRAM requirement is 256MB unless you have high CPU usage. Also it says I need to upgrade through the major releases, from 7.0(x) to 7.1(x) and 7.1(x) to 7.2(x) and then from 7.2(x) to 8.2(x).  The questions are:
 
- My ASA has 256MB of RAM and 68% of free memory, would you think it will run the 8.2(5) version with no problem?
- When making the upgrades to the major releases, is there any consideration regarding the configuration file? Or the versions to use for the 7.1 and 7.2 versions?
- Would you recommend making all the upgrades in one maintenance window?  How much time could it take?

View 2 Replies View Related

Cisco VPN :: ASA 5510 - Security Plus License

Aug 21, 2012

We’ve ordered ASA 5510 with security plus license as below description: 

ASA5510-K8
ASA 5510 Appliance with SW,   5FE, DES
L-ASA5510-SEC-PL=
ASA 5510 Security Plus License   w/ HA, GE, more VLANs + conns
 
The license details on the appliance shows as the below,
Fail over                        : Enabled 
Encryption-DES                  : Enabled 
Encryption-3DES-AES             : Disabled
Security Contexts                : Default 
GTP/GPRS                        : Disabled
Any Connect Premium Peers      : Default 
Other VPN Peers                 : Default 
Advanced Endpoint Assessment    : Disabled
Any Connect for Mobile            : Disabled
Any Connect for Cisco VPN Phone  : Disabled
Shared License                  : Disabled
UC Phone Proxy Sessions          : Default 
Total UC Proxy Sessions          : Default 
Any Connect Essentials            : Disabled
Bot net Traffic Filter            : Disabled
Inter company Media Engine        : Disabled 
  
I’ve noticed that the 3DES is disabled, do I need to order another license to use 3DES or not ?Also, I need 2 ~ 5 branches to connect simultaneously and have VPN access on their laptops to the main branch via vpn software, which VPN software I should use and is our license enough or I should order another license.

View 3 Replies View Related

Cisco Security :: Upgraded PIX 525 Lately To 5510 ASA

Sep 26, 2012

i have upgraded a PIX 525 lately to a 5510 ASA, but i have faced a problem after this.One of the DMZ's are connected to a switch that is not connected to my VTP domain on a DMZ port.
 
with access-list to permit from host to host with all ports opened.my problem is that the outside client is able to initiate a windows VPN to a server that i have in the DMZ, BUT it disconnects after almost 10minutes. What might be the reason of the disconnection.Note, a cisco remote access VPN is also configured on the FW, and it doesnt disconnect.

View 1 Replies View Related

Security / Firewalls :: Using NAT With Cisco ASA 5510 Firewall?

Mar 25, 2011

I was under the impression that those global addresses that we used with NAT were from the outside IP addresses range?Lets say my outside IP address is idk 192.112.40.11 /30 and I only had two usable IPs (since you can't use network and broadcast IPs) so how would I set up NAT for a couple of Inside addresses with a shorting of addresses like this? Idk if that makes sense what I'm trying to say

View 3 Replies View Related

Cisco Security :: Monitoring ASA 5510 Tunnels

Sep 22, 2008

I'm trying to monitor Tunnels activity. We want to gather statistics like bandwidth utilization per Tunnel and in the case of Remote Access also the user name associated with a tunnel. All this via SNMP
 
I've browse through the Cisco-IPSec-Flow MIB and found the TunnelTable, this seems to provide everything I need in Regards to Tunnels, I just need a tip in how to calculate or obtain the bytes Tx and Rx. I can obtain packets and Octets amounts but not actual bytes. Is there another OID I should be inquiring?
 
In regard to Remote Access I found the CRASSessionTable From here I can obtain the Group associated with the tunnel and I should be able to obtain the User name through the 1.3.6.1.4.1.9.9.392.1.3.21.1.1 OID, but I'm getting an UnSupported response when querying this particular OID.
 
What OID can provide the User name?
 
I know that Cisco Performance Monitor can in fact obtain all that info from the ASA so there must be an appropriate OID I can query to obtain this particular info.

View 3 Replies View Related

Cisco Security :: ASA 5510 Client Static IP

Sep 28, 2011

I have a ASA 5510 that uses Radius for Authentication.  What I am trying to do is assign each user that logs into VPN to have a specfic static IP based on userid.  I have about 30 to 50 users.  I don't want to complicate this by having them select a different profile when logging into the ASA.  What is a clean and simply way to assign user static ip and not use local database for login?

View 1 Replies View Related

Cisco Security :: Replacing VPN Router With ASA 5510

Feb 20, 2011

I got a task to replace our current cisco 2800 series router which is used for easy vpn remote access with cisco asa 5510.I have a got a lot of users, i wish that user shall see no difference except of ip address they are going to use for remote login.

View 1 Replies View Related

Cisco Security :: ASA 5510 - Unable To Connect SSH?

Mar 12, 2013

I configured Cisco ASA5510 firewall, but i am facing the problem with ssh login, i gave ssh for inside and outside access, but i am getting "server ... error" i enabled LOCAL  for the authentication for ssh and HTTP. and i am able to acees the device through HTTP using ASDM, but not able to access from outside.
 
ASA Version 8.2(1)
!
hostname ASA5510

[Code].....

View 3 Replies View Related

Cisco Security :: Cannot Login To Firewall ASA 5510

Sep 1, 2012

i have in my network firewall ASA 5510 but the problem i cannot login to my firewall thru telnet or ssh even ASDM or bowser this is my configuration :
 
ASA Version 8.2(5)
!
hostname Amco-ASA

[Code].....

View 9 Replies View Related

Cisco :: ASA 5510 / Upgrade All Firewalls To Security Plus?

Sep 21, 2011

I am trying to upgrade all my firewalls to Security Plus but I am not sure what firewalls are needing the upgrade.  Is there a SNMP pull I can do to see what license is on my firewall?  example: "This platform has an ASA 5510 Security Plus license." via SNMP

View 1 Replies View Related

Cisco VPN :: ASA5505 With Dhcp At Endpoint

Dec 26, 2011

I have a new customer that I installed an ASA 5505 to replace a Linksys VPN router.  They have a main office with a static IP address, 3 branch offices with static IP addresses and 2 branches that are doing DHCP from the ISP for their router address.  I have no problem getting the static VPNs up and running.  My problem is with the VPN connections that are doing DHCP.  I can go in and determine what IP they are currently using and setup a connection and it works fine.  The problem is of course when their IP address from the ISP changes, which seems to happen at least daily.  What is the proper way to setup a connection that is using DHCP?  Also, can you setup multiple connections this way?  Currently the 2 locations have different passwords setup in their routers.

View 1 Replies View Related

2960G - ID And Endpoint From Cisco Switch

Aug 13, 2012

We have a switch in our IT office, Cisco 2960G. It plugs into the wall and goes to the server room and connects somewhere. This weekend we redid almost the whole server room and now this switch can connect to the rest of the network. The uplink has a link light but can get anything.

I have rebooted the switch, used scanning on our other switches to try and find the MAC of the switch but for the life of me I cant see it. Is there a command I can run from the command line of the switch to see where its pointing?

View 11 Replies View Related

Cisco VPN :: 5520 - Changed IP For ASA VPN Endpoint

Nov 2, 2012

In my organization we have 2 sites.  These 2 sites have ASA 5520s, and the l2l between each ASA.  The interface that is forming the VPN tunnel is on the ASA, NATed on the router.  These ASAs sit behind the router, which are then connected to the ISPs.  Recently, we had to change the ISP that we were creating the tunnel on, from Comcast to Sprint on our remote site.  I re NATed the interface, and the l2l tunnel came back up after editing the tunnel-group, crypto maps, and reapplying the crypto map to the interface.  However, our remote access VPN no longer works on the ASA that we changed the IP on. The other side was never changed, and still works fine.  When I tried using debug cry isa and debug cry ip sec on the firewall, nothing shows when we attempt to connect.  We are using IPsec over TCP.  On the ASDM log, it says: Deny TCP (no connection) from xx.xx.xx.xx/49907 to xx.xx.xx.xx/10000 flags RST  on interface WAN. 
 
The VPN worked fine before, could it be an ACL thing?  All we changed was the IP so that's what I'm inclined to believe, but on the router none of the interfaces have an ACL that's applied to them.  It can't be on the ASA, because I believe we have the option to ignore the ACL enabled, but I might be incorrect about this.  I'm new at ASA/VPNs in general. 
 
I would upload the configs, but is there a pertinent output that would work, or just a general sh run? 

View 3 Replies View Related

ASA NATing For An IPSEC Endpoint?

Mar 18, 2011

Our ISP gave us a /30 for our external connection (with one IP being their side, and the other our firewall's outside int) and they then route a /28 down to us to give us 14 public IP addresses. Usually we use static NATs to give internal servers a public IP, and it works fine.

However, now I need to setup another VPN device with a public IP from our /28 pool. How the heck do I nat that? Should I give it's external int a private IP, and then NAT it at the first firewall? The 2nd firewall will be a VPN end point, and I'm afraid the NAT will break that.

View 9 Replies View Related

Cisco Security :: ASA 5510 Multiple Non-contiguous Blocks Of IPs?

Apr 30, 2012

Currently I have an asa 5510 set up with one block of outside IP addresses. Everything is working fine in regards to my initial setup. However we needed to purchase additional IPs from our provider and ended up being a whole complete different block. Where I am getting stuck is getting the new IPs to NAT to inside addresses.

View 2 Replies View Related

Cisco Security :: ASA 5510 - ASDM Software Won't Load

May 26, 2011

I've tried 3 different machines including a server.
 
Basically when I try to access my ASA 5510 with the ASDM software the software never loads.  So I have tried to access it through the management port https://192.168.1.2 and installed the software.  The software starts up, I enter the password and it connects and loads to 100% but doesn't go beyond that point.  I then try the java applet, and it as well loads up to 100% and says "Please wait, the main is coming up." 
 
I have http server enabled, and asdm image is pointed correctly
 
As I said, I've tried this on two Windows XP machines and a machine running Server 2008.
 
I can connect through CLI all day and all night, but I'd rather (read feel much safer) configuring it through ASDM. 
 
Here is some system version info
 
Cisco Adaptive Security Appliance Software Version 7.0(8)
Device Manager Version 5.0(8) 
Compiled on Sat 31-May-08 23:48 by builders
System image file is "disk0:/asa708-k8.bin"

View 4 Replies View Related

Cisco Security :: Change Ipsec Vpn To L2tp Over ASA 5510

Nov 14, 2011

i configurated ipsec vpn at cisco asa 5510. all them are working very well. now i want to change ipsec remote vpn to L2tp over ipsec.i have router, asa and 3750 switch. all nat translation are done at router , ipsec vpn configurate at asa.
 
this is my ipsec configuration. this is working config. as you see i do static nat asa outside ip for vpn at router. now i want l2tp over ipsec. before i do it i have some question
 
1. must i do static nat port  udp 1701 for l2tp over ipsec vpn?  can i write access list at asa to open port 1701?

2. can i remove this  static nat or i can not be change anything.is this nat is true for l2tp over ipsec vpn?
 
3.as you see user authentication from radius server at ipsec vpn. i also want this is same as l2tp over ipsec vpn..
 
4. i think that i must be add this addtional config. is this true? tunnel-group DefaultRAGroup ppp-attributesno authentication chapauthentication ms-chap-v2
 
is this config enougth for l2tp over ipsec vpn?? what is addtional config i need?

View 2 Replies View Related

Cisco Security :: 2911 Routers - Does ASA 5510 Support BGP

Jan 25, 2012

I have a new BGP configuration that consists of two asa 5510 and two routers 2911 at the back. My question is : Does asa 5510 support BGP?

View 1 Replies View Related

Cisco Firewall :: ASA 5510 Security For One Specific User

Jan 18, 2013

We have an ASA 5510 version 8.3 (2) that we accept VPN users via a radius server. Is there a way to lock down a specific user that connects to the ASA as a SSL client or IPSEC VPN user? If the specific user were to connect to the ASA, we would want the user to have minimal to not access to our system.

View 1 Replies View Related

Cisco Security :: Backup WebVPN Personalization On ASA 5510?

Apr 1, 2008

  I'm looking for a system to backup the configuration of the ASA like this I've noticed:
 
if the ASA is 5510 or higher and has sw 8.x and ASDM 6.x we have ASDM -> Tools -> Backup Configuration command that create a folder containing all configuration files and webvpn personalization
  
What I have to do to have the same command on ASA 5505 sw 8.x and ASDM 6.x? Or is there someting similar using the console too?
 
And what else for ASA which have sw 7.x and ASDM 5.x, is there the possibility to backup webvpn personalization?

View 2 Replies View Related

Cisco Security :: IPsec VPN Access-list At ASA 5510?

Sep 13, 2011

i configurated Ipsec vpn at asa 5510.

my inside ip 192.168.10.156
my public ip: 85.x.x.x 
my peer ip : 62.x.x.x
 
the project is that:the remote site want the interesting traffic like that:
 
source ip 172.16.1.104 can access destination ip 10.0.154.27
 
my inside ip is 192.168.10.0/0 and i can not to change it 172.16.1.0/24 and i can not to add this ip at my network.i do that way but i can not test it.
 
interface Ethernet0/0
nameif outside
security-level 0
ip address 85.x.x.x.106 255.255.255.248 standby 85.132.71.107
!

[code]....

View 1 Replies View Related

Cisco Firewall :: ASA 5510 - Difference Between CSC-10-PLUS And Security Plus License

Mar 3, 2011

I have ASA 5510. Is there any difference between CSC-10-PLUS license and Security Plus License...

View 3 Replies View Related

Cisco Security :: RDP Access For Remote VPN Client On ASA 5510?

Jan 17, 2011

We have configured site to site VPN tunnel from offshore to client location using ASA5510 and accessing RDP from client location. Also configured remote VPN access at offshore location. But using remote VPN client we are able to get RDP from officeshore location but not able to access RDP from client location. Is there any additional changes required ?

View 4 Replies View Related

Cisco :: Switch VPN Endpoint From Server To Firewall?

Apr 4, 2012

I'm pondering this new client's topology. He has: (internet) >> router >> switch >> Windows server with a VPN enabled.

Right now I access his network remotely by just RDP directly into the server with a public IP address.Now doesn't this mean that I'm already sailing through his router and switch? Doesn't that mean that all (broadcast, routing, etc) communication hitting this IP is sucking CPU cycles and bandwidth on his router, switch, and server? Wouldn't it be best if he had his VPN endpoint set on his gateway?

View 1 Replies View Related

Cisco VPN :: Can 2651XM Be Configured As PPTP VPN Endpoint?

Oct 31, 2011

Cisco 2651xm router
IOS: c2600-ipvoicek9-mz.124-15.T7.bin
 
Can a 2651XM router be configured as a PPTP VPN endpoint (client)? I ask because I want to connect this router to a professional vpn (privacy) service such as proxpn or mullvad or similar. If it can't, any vpn privacy services that cater for cisco-based vpn connection?

View 0 Replies View Related

Cisco VPN :: ASA5510 - AnyConnect With Websense Endpoint

Apr 16, 2013

We have about 160 users setup using the Anyconnect client connecting to a ASA 5510. We are using split tunneling and also using the Websense endpoint client. Every now and again after installing the endpoint client we are unable to connect the AnyConnect. It asks for credentials waits for a while and then fails with the error "AnyConnect was not able to establish a connection to the specified secure gateway.Please try again later."

If we uninstall the endpoint client it works again and normally after reinstall it fails again ( I know). Eventually it just works and then its fine.

We have logged a call with websense and sent packet traces of working and none working . Then only thing they came back with is if we filtered the non working trace with port 80 you could see a few RST,ACK coming from the ASA to the client so they blamed the Cisco components.

View 1 Replies View Related

Cisco VPN :: Where To Enter Endpoint Name In WRVS4400N For A Dynamic IP

Nov 16, 2011

I have a Snapgear 560U VPN Gateway at the main office with VPN connections to several branch offices also using Snapgear 560U. Those are no longer manufactured though, so I bought a Cisco WRVS4400N for our new office. The main office has a fixed IP but the branch office ha a dynamic one. On the Snapgear's it is very clear where I need to enter the Mandatory endpoint name on the dynamic side of the tunnel, but I can't find anything on this on the Cisco WRVS4400N. So where do I enter this information so that I can make a VPN connection between the Snapgear & Cisco boxes?

View 1 Replies View Related

Cisco Routers :: With Firmware 1.2.0.9 - Can RV110W Be Used As VPN Endpoint

Apr 2, 2012

With firmware 1.2.0.9 - can the RV110W be used as a VPN endpoint? The VPN capabilities have been expanded in this version - but from the docs this isn't quite clear to me.

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved