Cisco VPN :: 5510 / 5505 - Filter VPN Traffic Using Barracuda

Sep 20, 2012

I have a site to site VPN setup between a 5510 and 5505.  All traffic is sent ovet the VPN from the remote site to the home office.  Everything is working fine but the remote site "www" traffic is not going to the Barracuda. ISP -> CISCO ASA -> Barracuda -> Internal Switch.The Barracuda is setup "inline" with the internal network.

View 7 Replies


ADVERTISEMENT

Cisco Switching/Routing :: WCCP Settings In Catalyst 3750X And Barracuda Web Filter

May 12, 2013

configuration of a Catalyst 3750X and Barracuda Web Filter using WCCP protocol.
 
We used various WCCP protocol settings, unable set to redirect traffic to the Web Filter.
 
This is the current configuration of 3750X:
 
ip routing
ip wccp 94 redirect-list 194 group-list 50
ip wccp 95 redirect-list 195 group-list 50

[Code]......

View 5 Replies View Related

Cisco Firewall :: ASA 5510 Barracuda Exchange Emails Deferred

Nov 29, 2011

Our ASA 5510 has been in place for nearly two years, we never have any issue what so ever with it. All along the ASA has been using the default policy. Lately, we beeen getting email deferred in our Barracuda Spam firewall. Google quickly reveals that ESMTP does not play nice with Barracuda witch i disabled eventhough we haven't had any issue with it before. However, the issue remains, we still getting email deferred in the barracuda.
 
While doing more troubleshooting on the ASA, I constated when issue the command show local-host + IP of the Barracuda, there is an IP address in outside of the interface that can get up to 96 UDP port 53 connections with the Barracuda, this connection never get lower than 20! However, when checking the default setup for the Barracuda, i have the values below:
 
Incoming SMTP Timeout: 20
Message per SMTP Session : 8
Maximum SMTP Error SMTP Session: 2
Maximum Connection per Client 30m:40
 
My question is if that ASA show up to 96 DNS session with an outside host to my barracuda, won't that push the barracuda to play email deferred timeout ? Should I change the barracuda default setting? Or should i change the connections limits for the Barracuda in the ASA?

View 3 Replies View Related

Cisco 5510 Barracuda Link Balancer With Virtual PFSense Appliance

May 8, 2013

trying to get my ducks in a row for replacing a Cisco 5510 and a Barracuda Link Balancer with a virtual pfSense appliance. This is partially due to eliminating support contract costs (nearly $3k annually between both appliance) and partially to utilize the redundancy and fault tolerance that our virtual environment can provide. I'm also implementing a colo site for replication/DR this year so doing a tunnel from site to site would make it a lot easier with like for like virtual appliance firewalls.

The VPN aspect. We are currently doing Cisco VPN with Radius auth on the back end, this is seamless to setup from an end user perspective as they just hit a URL, download/install the ANyConnect client, and log in with their credentials. Is there a comparable alternative in pfSense? I'm leaning toward IPsec but it still doesn't seem as seamless as what we currently have in the ASA.

View 8 Replies View Related

Cisco VPN :: No Traffic Over Tunnel Between ASA 5505 And 5510

Dec 5, 2010

I've a asa 5510 on the main site and different ASA 5505 on secundary sites for VPN tunneling between the sites. The problem is that the tunnels are acomplished but no traffic is going over them. What am i doing wrong? For the moment there is a ASA 5505 on the main site managing the tunnels but I want the 5510 to take over the job.

View 5 Replies View Related

Cisco Firewall :: Traffic Shaping ASA 5510 Vs 5505?

Oct 19, 2011

Is there any difference with traffic shaping capability on the 5510 as opposed to the 5505? is there anything the 5510 can do that the 5505 cant? with regards to TShaping?

View 4 Replies View Related

Cisco VPN :: 3030 - How To Filter Web Traffic

May 29, 2013

Most of our VPN connections are done with our Cisco 3030 and the internet goes out the ASA. We are able to filter all web traffic by doing a a span port for web traffic.
 
When we move VPN connections to the ASA we will loose the ability to span web traffic becuase its coming in and going out the same interface on the ASA. We will loose the ability to filter web traffic when this happens.
 
How we can filter web traffic on VPN connections on the ASA. We are using websense. I know there is some integration that can be done with the ASA and websense but it doesn't have all the capabilities as doing a span port for websense to monitor.

View 1 Replies View Related

Cisco Firewall :: How To Filter L2L Traffic To A PIX 7.2(4) (or ASA)

Feb 6, 2013

I've got a PIX running 7.2(4) with its outside interface on the Internet.  The only thing this PIX is doing is acting as the endpoint for an IPSEC LAN-to-LAN tunnel with an Internet-connected ASA on another network.
 
I'd like to filter inbound Internet traffic to this PIX so that only the designated ASA can attempt to establish an IPSEC connection -- in other words, I want to prevent any other device on the Internet from even being able to attempt to establish an IPSEC connection to the PIX.  As far as I know (and have seen), this can't be done with an access-list on the outside interface, since that access-list doesn't apply to traffic to the PIX itself.

View 3 Replies View Related

Cisco VPN :: Filter Remote Access Traffic On PIX 501?

Mar 20, 2012

Is it possible to filter remote access VPN traffic on a PIX 501 (like you can on an ASA?)

View 1 Replies View Related

Cisco Security :: C3800 / Filter Traffic By Mac Address?

Jan 23, 2011

Is it possible to configure cisco router like C3800 or catalyst switches like C4500 or C2960  to filter traffic based on allowable mac addresses only? I would like only to allow those devices that belongs to the domain, meaning if a user connects a computer or any devices that concerns network which I have not allowed the mac addresses, it will be denied access to the network. However, any of the allowable devices could able to use any port of the switch, meaning I dont want to associate an allowable Mac Address to a physical port on the switch.

View 2 Replies View Related

Cisco Firewall :: ASA 5520 8.2(1) - Botnet Traffic Filter?

Jun 28, 2011

When I try to configure the Botnet Traffic filter with the commad "dynamic-filter use database" through the ASDM I get the following error message.
 
[ERROR] dynamic-filter use-database  Dynamic Filter: New data file not terminated with newline

View 14 Replies View Related

Cisco Switching/Routing :: 6500 / How To Filter IPX Traffic

Feb 23, 2013

We have a lot of IPX traffic flowing through a switched network and we are being asked to filter it from a network standpoint. At one point they were using IPX in their network, but no longer need to, so they still have a lot of machines spewing out IPX traffic. We have removed the IPX routing commands from our distribution switches, (Cisco 6500), but after running a short 10 minute Wireshark capture I'm still getting a good bit of IPX traffic from a lot of different devices.

View 2 Replies View Related

Cisco Switching/Routing :: ASA 5585 - Filter Traffic Between Vlans?

Apr 9, 2013

I have a ASA 5585 and a Nexus 5596, and i need a sugestion to configure this cenário:
 
My users in the Vlan 10 need access on the network in the Vlan 20, but this traffic must be filtered for firewall. In the firewall a received a trunk port for Nexus 5596, and i created subinterfaces to receive the Vlans for this trunk.
 
The gateway for my users is the address for the ASA subinterfaces.
 
What i do to filter the traffic between the Vlans?

View 3 Replies View Related

Cisco Switching/Routing :: SRP547w - Allow Traffic On Port 25 From External IP Filter?

Nov 16, 2011

Can the SRP547W be configured to allow traffic on port 25 from an external ip range to an internal address?

View 0 Replies View Related

Cisco Switching/Routing :: Filter IP Traffic By MAC Address On Catalyst 4500?

Dec 19, 2012

We want to filter IP traffic by MAC address on Catalyst 4500. Since we are using bonding (active-backup mode) we need those mac addresses appear on different ports. Below are solutions that we have tried: ACL but it does not   work since mac acls only match non ip traffic (We CAN NOT use ip acl). Use a static mac address-table entry to ALLOW specific mac addresses. It does not work  either since the same MAC address needs to be seen on a different port. Catalyst 4500 does not support auto-learn option (as e.g. Nexus 5000). 

View 3 Replies View Related

Cisco Firewall :: How To Filter By MAC Address With ASA 5510

Mar 3, 2013

I am using an ASA 5510 firewall in routed mode.How can I filter incoming traffic by mac address on the AS 5510 ? I have already setup a static access rule for rdp users on the outside to access a terminal server on the inside.Now, i would like to further limit access from specific computers only.

View 7 Replies View Related

How Does Firewall Block Or Filter Traffic On Specific Port Or IP Address

Nov 15, 2011

How does a firewall block or filter traffic on a specific port or IP address?

View 1 Replies View Related

Cisco Switching/Routing :: Sonic Wall 3060 - Filter Traffic From VLAN Through ASA?

Dec 18, 2011

I'm decommissioning my SonicWall PRO 3060 and upgrading to an ASA5550 (we're increasing our WAN link speed to 1Gig and need the 5550).  In any case, I want to copy over the configuration from the PRO to the ASA.  I have everything documented and I've started doing the changeover, but in looking at some other network diagrams on the net I'm seeing router symbols between the LAN switches and the ASA and I'm beginning to worry that I might need routers to do this which, of course, would increase cost quite a bit.
 
So my question is this: If I have a core switch carved into multiple VLANs and I connect each VLAN to a port on the ASA, will I be able to route and filter traffic from VLAN to VLAN through the ASA?  If so how, in general, is this accomplished (I'm betting ACLs).  I think that the ASA will be able to do this easily, but I just want to be sure before I get too far into the configuration of this unit,.
 
                                                                                          ASA
  -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
               GigE0/0          GigE0/1          GigE0/2          GigE0/3          GigE1/0          GigE1/1          GigE1/2          GigE1/3
                    |                    |                      |                      |                     |                     |                     |                     |
                    |                    |                       |                      |                     |                      |                     |                     |
                WAN          BackupWAN                                                  VLAN400        VLAN500        VLAN600         VLAN700

View 4 Replies View Related

Cisco Firewall :: 2851 - Unable To Filter Https Traffic With Router And Websense

May 25, 2011

I am having a setup with a 2851 router & websense url filtering server where I need to forward the traffic to websense server for all the internet requests. The http traffic is getting filtered properly, but the https traffic is not getting filtered. The two commands I ahev given for http & http are as follows: ip inspect name test http urlfilter ip inspect name test https.

View 9 Replies View Related

Cisco Routers :: RV042G - ProtectLink Enabled To Filter Out Various Categories From Network Traffic

Jun 29, 2012

I have upgraded to the new RV042G to take advantage of the gigabit Ethernet speeds and to prepare for when our ISP upgrades our bandwidth. I currently use the RV042 with Protect Link enabled to filter out various categories from our network traffic. I noticed that this feature is not included with the RV042G.

Is this something Cisco will decide to add back in later? In the meantime, how to block content on the network? The basic URL and keyword filter will not meet our needs, since it is much easier to let a service such as Trend Micro manage what is blocked in the categories they offer.

View 2 Replies View Related

Cisco VPN :: 5510 VPN Filter And Service From Remote Clients

Mar 21, 2012

We have remote VPN setup with Cisco ASA 5510. By using VPN filter, I can follow the guide and make client to use all necessary server services. (dns, ssh etc). However, is there any way that allow inside server access remote VPN client's services, ex. let inside server ssh to remote VPN client? Consider remote access VPN filter ACL's syntax, I have to always let source be the "remote VPN client PC", the dest is "inside firewall server", how can I let the other way traffice going?

View 1 Replies View Related

Cisco Switching/Routing :: C2960G / C3750 - Any Way To Filter (on Ingress Port) Type Of Traffic

Jun 22, 2012

I have couple C2960G and C3750. Is there any way to filter (on ingress port) type of traffic? I would like to allow IP only, and discard (i.e.) IPX, or other garbage, that any device can produce.I have tried to find something about this, but only thing I have found is feature : protocol filter, which doesn't seems to be working on my hardware.

View 6 Replies View Related

Cisco Firewall :: ASA 5510 Does The Feature Content Filter Comes As Built In

Nov 11, 2011

In Cisco ASA Firewall 5510 does the feature content filter come built in?

View 1 Replies View Related

Cisco Firewall :: ASA 5510 - Does Feature Content Filter Come Built In

Jun 26, 2012

In Cisco ASA Firewall 5510 does the feature content filter come built in?

View 3 Replies View Related

Cisco Firewall :: 5510 - Filter Internet IP Address Allow To Initiate VPN Connection

Apr 10, 2011

Using Cisco ASA5510 Security Plus (Post May 2010) with 8.2(1)
 
I was trying to limit the number of internet IP Address that can initiate Remote Access VPN connection to the firewall. I have plan to only allow internet IP Address from few ISPs for control.
 
However, blocking AHP, ESP, ISAKMP, NON500-ISAKMP, and IPSec Over TCP Port Assigned in the firewall outside interface doesn't work. But it works by putting the ACL in the router before the firewall. It seems that the  firewall have a "hidden" process VPN first before user entered ACL (or explicit rule), similar to Checkpoint FW's implied rule. How to get around it?

View 4 Replies View Related

Cisco Firewall :: 5505 - Bootnet Filter No Longer Functions After Disk Format

Jul 2, 2011

I was having major issues with a 5505 (too long a discussion to go into here) so I formatted the disk and uploaded fresh binaries and recreated my configuration. I noticed the licenses were preserved. I also noticed there were several fsck records after the format that were reclaiming lost chains. I suspect the flash on this ASA is going bad, since everytime it boots it says "reading from flash ..!!" like it cannot even read flash successfully. When I purchased this one new, it also had several fsck records being brand new. I'm going to open a case on these flash issues/questions.
 
Anyway, after all of the above, the only thing that is not working is the botnet filter. [code]

View 4 Replies View Related

How To Reinstall Barracuda 410 OS

Sep 30, 2012

We have a client whose Barracuda 410 has been out of warranty for at least 6 months, and had its hard drive die. They have a sister location with a 410 as well. Any way to clone the hard drive of the working 410 onto a new hard drive, then do a factory reset to set it up from scratch, or maybe import a config file if one was saved?Or, did they just get downgraded to a shitty $4000 1U server? I'm sure I could install something like untangle and get it to do some filtering without issue, or since it's actually an Athlon II X2 635e, which supports VT, I may just bump it to 8GB of RAM, throw in a pair of low profile drives (at least one, as I can fit that under the LAN/WAN ports), and turn it into an ESXi server to replace a few machines that are sitting around doing practically nothing (AV server, WSUS server, and whatever their door security system server is).

View 7 Replies View Related

Cisco VPN :: 449 Site-to-Site VPN Traffic Filter (ACL)

Jul 31, 2012

I had to edit an ACL on an active S2S VPN today because traffic was being denied from a host onsite to a host on the remote site (port 449).  After I made the change, we tried to make the connection again, but it was still denied.  Do we need to tear down the S2S vpn for the change to the ACL to take effect? Also, what if we just wait for the connection to rekey itself?  Will it work after that?

View 2 Replies View Related

Cisco Firewall :: ASA 5505 Firewall To Filter HTTPS Websites?

May 28, 2012

I have a cisco asa 5505 firewall. Is it possible to block secure websites in it like [URL]? I have already tried regular expression filtering but it filters only http traffic.

View 4 Replies View Related

Cisco Firewall :: Exchange Direct Push / ASA 5540 / Barracuda?

Jun 15, 2011

I have the following scenario.
 
                            INET
                      (205.50.50.1)
                              |
                              |
                      (205.50.50.2)
                 [CISCO ASA 5540]
                       (10.10.10.1)
                              |
                              |
                             + ---------------------------------------------+
                      (10.10.10.2)                              (10.10.10.3)
                    [BARRACUDA]                         [Exchange SRV]
 
 Mail Domain:            mail.domain.com (205.50.50.50)
 
Ok so the mail flows to the Barracuda using a static 1:1 NAT configuration and then gets delivered from the Barracuda to the Exchange server.  I want to implement active sync (Direct Push) for Windows mobile devices.  They need to communicate with mail.domain.com over port 443.  The problem is I want mail to continue to flow to the Barracuda, but direct Direct Push traffic to the Exchange server.I cnow I can't implement two 1:1 NAT mappings from the same external hostname to 2 different servers.

View 3 Replies View Related

Linksys Wired Router :: Setting Up A Rv042 A Barracuda?

Aug 22, 2012

I have been running a email/web/ftp server on one server for 9 years. I have currently acquired a Barracuda spam 300. I cant get the emails to go thru the barracuda first. Here is how it is setup: my email and web come in thru one outside address..call it 166.5.5.5 I have a 1 to 1 nat for 166.5.5.5 to 10.0.0.2 (email/web/ftp server) ports 25 and 53 are forwarded to the 10.0.0.4 (barracuda) then out on 25 to my 10.0.0.2 no emails go thru as long as it is set this way I can nat the 166.5.5.5 to the barracuda first and emails go thru, but I lose my web and ftp will this router work for me? I was told that i needed to change mx records for email to 166.5.5.6 and then forward nat on that address to the barracuda. I dont really want to change mx records for 10-12 email domains.

View 1 Replies View Related

Cisco WAN :: LAN Traffic Not Getting Out On ASA 5505

Apr 18, 2012

For some reason my ASA is preventing my traffic from going out. I've added some crumby access-list and applied it to NAT for it to work. I don't like this. I know it is not right, but I am not sure what part is wrong. I will highlight the stuff I have added to make it work. I don't see what I am missing. If I were to remove these lines my ASA could ping in both directions (in and out), but my LAN cannot do anything but ping the ASA. No other traffic is going out unless I have added these unsafe lines of code.
  
!
interface Vlan1
nameif inside
security-level 100

[Code].....

View 2 Replies View Related

Cisco WAN :: ASA 5510 - Traffic From Location 1 To Another Via HQ?

Jun 15, 2011

Remote office 1 has an asa 5510 connected to a HQ office which has also an ASA 5510.The HQ office has also a IOS router 2921 with a DMVPN connection an other Remote offices.

Remote office 1 = Cisco asa 5510
Remote office 2 = Cisco IOS router 888

[code]...

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved