Cisco VPN :: ASA 5505 Which Is Replacing An Old Firewall

Mar 21, 2013

I have a ASA 5505 which is replacing an old firewall. Everything is working apart from the dail in pptp sessions. These are forwarded to the windows 2003 server. [code]

View 3 Replies


ADVERTISEMENT

Cisco Firewall :: Replacing PIX 506e With ASA 5505?

Apr 29, 2012

I need to replace an ageing PIX 506e with an ASA 5505.The current setup looks like this:  The PIX is used for site-to-site VPN connection via the WAN 2 link.  The WAN 1 link is used for general Internet connectivity.I don't have access to the Draytek Router as it is supported by a 3rd party, but I believe it uses static routing to direct the relevant traffic to/from the PIX.
 
When I replace the PIX with the ASA, the inside i/f connection experiences dropouts - but no errors show in the logs.The only significant difference I can see in the config is that the ASA utilises VLans for the inside & outside interface configs - I used the PIX-to-ASA Migration tool to make the initial configuration on the ASA.In tests, if I only connect the inside i/f of the ASA, pings from the LAN are stable.  Once I connect the outside i/f, pings timeout approx 80% of the time.

View 2 Replies View Related

Cisco Firewall :: 6509 - Replacing Faulty FWSM Module In Cluster

Apr 15, 2013

We have a faulty FWSM module in Cisco 6509 switch in Active/Standby cluster mode
 
We have purchased a refurbished FWSM module to replace it. It has the same FWSM OS 4.0 (4) and is in factory default configuration
 
What procedures should I follow to make this unit live and sync the config between the current active unit to this one.

View 1 Replies View Related

Cisco Firewall :: Monitoring ASA 5505 Firewall Active / Standby Pair Using SNMP?

Sep 7, 2011

How I can actively monitor the interfaces and overall status of 2 x ASA 5500s in an Active/Standby configuration?
 
I can setup monitoring of the interfaces on the Active member but I'm not sure how to manage the Standby member?

View 1 Replies View Related

Cisco Firewall :: IOS Firewall Versus ASA (5505 / 5510) For Smaller Clients (less Than 50)?

Apr 24, 2012

We were having a discussion of ios firewall vs. asa for smaller clients(less than 50). On using ios firewall(zbf or cbac)and an asa 5505/5510.  One of the arguments brought up on using ios firewall on the router is that a router will do an ip sla failover.  I have configured a number of isr's for this and i know it works good. 

View 1 Replies View Related

Cisco Firewall :: Failover ASA 5505 - Setup Second Inside Interface On Firewall?

Feb 19, 2012

I have a Cisco ASA 5505 in our office. We are currently using Interface 0 for outside and 1 for inside. We only have 1 Vlan in our environment. We have two three switches behind the firewall. Today the uplink to Interface 1, to the firewall, on the switch went bad. I want to setup a second inside interface on the firewall and configure it as failover incase this happens again. I want to attach it to the other switch. Can I do this? If so, what do I need to do? would it only be a passive/standby interface?

View 1 Replies View Related

Cisco Firewall :: Setting Up ASA 5505 To Be Used As Firewall Between BT Internet And 3560 LAN Switch?

Aug 23, 2011

setting up an ASA 5505 to be used as a firewall between a BT internet router(BTNet service) and a Cisco 3560 Lan switch. BT have presented me with a cisco 3800 series router with the following details:

Network Address   Network Mask  BTnet NTE Router LAN Address
      
There are 2 Gigethernet ports on the back of the router port Ge0/0 is connected to the BT NTE and the status light is flashing green. Int ge0/1 is connected into port int e0/1 of the ASA but i am unable to get any connection.

View 21 Replies View Related

Cisco Firewall :: Upgrade From 5505 To 5520 On Network - ASA Firewall Throughput

Feb 27, 2013

I'd like to see some REAL LIFE comparisons of ASA firewall throughput (a bit like this one for ISR G2 Routers - [URL].
 
The reason I ask is that I recently upgraded a firewall from an ASA5505 to an ASA5520 on a small network where the only outside connectivity was a single 10meg Internet circuit with an IPSEC VPN (not landed on the firewall but on a router) to another site.
 
When I swapped out the firewall the users noticed a big improvement. The firewall is not doing anything out of the ordinary - no IPS or VPN, just standard state full inspection.

View 5 Replies View Related

Cisco Firewall :: 5505 - Setting Transparent Firewall Ip Address?

Dec 22, 2011

Trying to set up a asa 5505 in transparent firewall mode. I cannot set the management ip address:
 
ciscoasa> enable
Password:
ciscoasa# config term

[Code].....

View 7 Replies View Related

Cisco Firewall :: ASA 5505 Creating Interface Vlan In Firewall

May 3, 2011

I have been working with ASA 5510,20,40,80 but not with 5505 this vlan and its interfaces are quite confusing.Just want to know how it works and its connectivity to Cisco Switch.Do i have to put the interface of the switch in the same vlan as i am creating the interface vlan in firewall ?Now the switch port connecting to this Eth1 interface should also be in the same vlan ? i.e vlan3 ?? or it will be in trunk ? The default configuration shows the eth0 with no access vlan and interface eth1 with access vlan 2... does it mean the eth0 is in vlan1 ? (Nativ Vlan ) ???

View 4 Replies View Related

Cisco Firewall :: ASA 5505 Firewall To Filter HTTPS Websites?

May 28, 2012

I have a cisco asa 5505 firewall. Is it possible to block secure websites in it like [URL]? I have already tried regular expression filtering but it filters only http traffic.

View 4 Replies View Related

Cisco Firewall :: ASA 5505 - Can't Reach FTP Site While Inside Firewall?

Feb 26, 2011

I am trying to configure our ASA 5505 so that our users can access our ftp site using [URL] while inside the firewall. Our ftp site is setup so that you can reach it by either browsing to the above url or by browsing to ftp://99.23.119.78 but we are unable to access our ftp site from either route while inside the firewall. We can access our ftp site using the internal ip address of 192.168.1.3.
 
Here is our current confguration:
 
Result of the command: "show running-config"
: Saved:ASA Version 8.2(1) !hostname ciscoasaenable password qVQaNBP31RadYDLM encryptedpasswd 2KFQnbNIdI.2KYOU encryptednames!interface Vlan1nameif insidesecurity-level 100ip address 192.168.1.1 255.255.255.0 !interface Vlan2nameif ATTsecurity-level 0pppoe client vpdn group ATTip address pppoe setroute !interface Ethernet0/0switchport access vlan 2!interface Ethernet0/1!interface Ethernet0/2!interface Ethernet0/3!interface Ethernet0/4!interface Ethernet0/5!interface Ethernet0/6!interface Ethernet0/7!ftp mode passiveobject-group service DM_INLINE_TCP_1 tcpport-object eq ftpport-object eq ftp-dataport-object eq wwwaccess-list ATT_access_in extended permit tcp any host 99.23.119.78 object-group DM_INLINE_TCP_1 access-list ATT_access_in extended permit tcp any interface ATT eq ftp access-list ATT_access_in extended permit tcp any interface ATT eq ftp-data access-list ATT_access_in extended permit tcp any interface ATT eq www access-list 100 extended permit tcp any interface ATT eq ftp

[code]....

View 6 Replies View Related

Cisco Firewall :: 5505 PAT With Single Public IP And Several Servers Behind Firewall

Nov 21, 2012

New to the ASA 5505 8.4 software version, but here is what I'm trying to do:
 
-Single static public IP:  16.2.3.4
-Need to PAT several ports to three separate servers behind firewall
-One server houses email, pptp server, ftp server and web services: 10.1.20.91
-One server houses drac management (port 445): 10.1.20.92
-One server is the IP phone server using a range of ports: 10.1.20.156
 
Basically, need to PAT the ports associated with each server to the respective servers behind the ASA 5505.  Is anything missing from this config? Do I need to include a global policy for PPTP and SMTP? [code]

View 11 Replies View Related

Cisco Firewall :: ASA 5505 Transparent Firewall With Web Sense Integration

Apr 27, 2011

I'm integrating a Cisco ASA5505 with a Websense proxy. I have a configuration setup where we have four routers which are used for Internet access. There are two VLAN's - Guest and Private. What I would like to achieve is making the use of available bandwidth by load distribution via GLBP, and filtering users web traffic. Two routers will be used for a GLBP group in one VLAN, and the other two routers will be used for GLBP in another VLAN.The users are connected to a Cisco 2960 switch and are in their respective VLAN's. I'm planning a 802.1q trunk to a Cisco ASA from the 2960 switch, carrying both VLAN's.What I would like to know is if there is a CSC module (or similar) which has Websense installed on it, and if it is possible to setup the ASA5505 in transparent mode to filter the traffic in this way? Hopefully this would allow multiple users to take advantage of the additional bandwidth, and not be restricted by using a traditional proxy setup which where all web traffic would be originating from a single MAC address.

View 1 Replies View Related

Cisco Firewall :: 5505 ASA Trunk Port In Firewall

Apr 30, 2012

I have an issue with my firewall,each time i configured a trunk port in the firewall and connect a sw 2960S with a trunk port also, all the interfaces in the Firewall go down ( virutal intertaces, inside, outside , dmz) , also another switch 3750 that is connected to another port in the firewall( access port only) it start to a new negotiation of spanning tree.What could be causing this problem? the firewall didnt sedn bdpdu i think the IOS of the firewall its a 8.2

View 3 Replies View Related

Cisco Firewall :: 5505 Firewall Between HQ And Remote Site

Jun 12, 2012

we are planning on connecting a new aquired company to ours soon?We will connect the remote site to the HQ via a D3. I've been told we will need to have a firewall between them and us for a time. I was thinking of terminating the D3 connection at the remote site of 80 users. Can I use the asr as a firewall as well, to protect the HQ from the Remote site - or should I use a seperate appliance?I was thinking of a asa5505 but, am concerned with bandwidth limitations of the box?

View 1 Replies View Related

Cisco Firewall :: ASA 5505 Transparent Firewall Configuration?

Sep 11, 2007

I want to configure an ASA 5505 in transparent mode (7.x). Somehow, I got it to work.. but i need some kind of step by step description. I just want to connect it with outside on a route .. inside in my LAN. Its working now with one ASA. But in the Web Interface the Interfaces inside and outside are down.. but its working.

View 5 Replies View Related

Cisco :: Considering And Replacing AIR-LAP1131AG-A-K9 APs

May 20, 2013

We have about 70 AIR-1131AG-A-K9 APs that were installed about 5 years ago.  The controller we use is a 4404 WLC, with software 4.1.171.0.  This provides us our wireless network.  We use Cisco switches as access, distribution, and core switches.
 
We have two guest networks, one for visiting physicians and another for patients and their guests.  Each of these guest networks use a 4402 WLC as an anchor controller, with software 4.1.171.0.  They use the same APs as our business network. 
 
According to my understanding of the guest networks is that a tunnel (I don't know if it is encrypted or or encapsulated) is created between the APs/Guest WLAN to the anchor controllers, so this guest traffic is isolated from our business traffic.  Futhermore, these guest controllers connect directly to our firewall, which only allows them access to the Internet, and not our Internal LAN.
 
Our Problem
=========================
Well, we've been having problems with our wireless system, specifcally with patient guest access.  It has gotten bad enough that they are looking to replace the Cisco APs on the south side of the hospital.  We've been told that "you can get better guest access at McDonalds" : ( .  I think part of our problem is that our controller code is so very old and we are have a our patient guest network open and "restrict" the number of clients attached to it by limiting our DHCP scope.  The biggest complaint we get regarding the patient/guest wireless is people saying "I can't connect to the wireless", which we almost always identify as an issue caused by us running our of DHCP leases (we have about 200).  These DHCP lease are used quickly, by an devices that comes into range that is set to automatically connect to any network that is in range.  A lot of our staff is connected to our patient guest network and don't even realize it.
 
We are interested in Meraki APs because they are magaged using a cloud controller (we won't have the added expense of another controller) and they seem really easy to manage.  Our biggest concern regarding Mearki is security.  They make use of NAT, a Layer 3 firewall, and LAN isolation (a firewall rule that only allows clients Internet access) in each AP as a means of isolating the guest traffic from the business traffic.  Does this seem like a secure way to accomplish this or are the Layer 2 tunnels that Cisco and from what I've been told recently Aruba and Juniper make use of a more secure approach?
 
We've been working with a Meraki vendor, who also happens to sell Aruba and Juniper wireless networks.  It seems like don't suggest Meraki if we are concerned with security.  They said they are good for situations where you have many geographically seperated sites.  They suggested we use Juniper and Aruba, specifically because they use Layer 2 tunnels and that they used technologies like clear air (APs self adjust channels and power, which Meraki claims to do too).  I thought that, hey does Cisco that too, why wouldn't we just go with Cisco if those are your selling points for Juniper and Aruba?

View 2 Replies View Related

Cisco VPN :: Replacing Sonicwalls With ASA 5520?

Jan 1, 2012

I am currently replacing my Sonicwalls with Cisco ASA5520's. One of my VPN tunnels currently functioning on the Sonicwall Requires a IKE Peer ID be programmed, I tried programing the ASA without one but the tunnel will not stay established.

View 2 Replies View Related

Cisco WAN :: Replacing SUP32 With RSP720

Jan 8, 2012

I have a 7606-S router ( non redundant ) with SUP32 and i wand to replace it with RSP720-3C-GE , i am asking abouth the procedure?shall i switch off the router ? or just removeSUP32 and insert RSP720 ?are there any steps should i do before the upgrade ?i am planning to take the router out of service during the operation, how much down time it will be ?

View 9 Replies View Related

Cisco Firewall :: Update ASA 5505 Firewall IOS?

Nov 11, 2011

When I upgrade the ios on switches, I just create int vlan1 assign it an ip and subnet, then tftp to my pc that is plugged into the switchport using the download-sw command.
 
I am not sure how to do this on the asa.  Do I just plug my pc into port 0 which the documentation says is mapped to vlan 1 with and ip of 192.168.1.1? I tried this by making my pc's ip 192.168.1.2 but am unable to ping the asa.  Do I have to change the security level or anything?

View 1 Replies View Related

Cisco Firewall :: RVS4000 NAT To ASA 5505 Firewall?

Mar 18, 2011

I’ve been using a Cisco ASA 5505 Security Plus bundle for two years now without any problems. My previous Internet Service Provider was routing the external IP I was leasing directly through to my internal network without NAT which my ASA 5505 was working well with. Thus, I had configured my 5505 to provide NAT to my inside network which includes two subnets one for my workstations and internal "private" resources and a DMZ to provide access to my webserver, email server and two domain name servers; but restrict access to my internal; resources. i recently changed my ISP to Verizon FiOS (which is providing me with 25 Mb bandwidth at a fraction of the cost of my old T1) which is set up to provide 5 Static externally facing IP numbers for my email, webserver and name servers;. The problem is the Verizon router doesn’t support my use of the ASA Appliance (at least not the way it is currently configured. Verizon recommend I purchase a business class router and use it in place of the one they provided with my installation. With this in mind, I bought a Cisco RVS4000. I have configured it to use the primary external IP number and have internet access; however, the new router is providing NAT addressing which the ASA is in conflict with (they are both using the same NAT IP range). I'm assuming the ASA 5505 is expecting to have access to the external IP addressed (since that is what it was getting before) and NOT NAT address. How to configure the new router to either provide access to the five static external “real world” IP to my Cisco ASA Firewall. However, I just need to get my ASA 5505 back in the loop and would prefer to do this rather than go back to the Verizon router combined with a low end firewall. So, my questions are: Does the ASA 5505 expect real world External IP numbers? Or can it work with NAT addresses being fed to it from the router?  And, if so, how do I configure the access rules and other items which are currently mapping to external numbers?

View 27 Replies View Related

Cisco Firewall :: Configuring ASA 5505 Firewall

Sep 21, 2012

I am configuring a Cisco ASA 5505 firewall.In the office there is 1 x SBS 2008 server and 5 x PCs, all sat behind a Netgear DGN1000 ADSL router.We want to implement a ASA 5505 for added security.I have configured the internal interface of the Cisco ASA 5505 to be 192.168.0.1 - this is connected to local switch. The client PCs use 192.168.0.1 as their default gateway.I have configured the external ASA 5505 interface to be x.x.x.217. [code]Change the current router status from Router/Firewall/Modem to Modem only (Bridge mode). The ASA 5505 has its outside interface connected into one of the LAN ports of the netgear. The lan port has an IP of 192.168.0.254.

View 3 Replies View Related

Cisco Firewall :: ASA 5505 Firewall Booting

Jan 6, 2013

when i am booting ASA firewall i am getting the following error.

<0>Kernel panic - not syncing: Attempted to kill init! and it stops and will not work. check below the whole log file
 
how can i solve this issue?
 
Log file:
Evaluating BIOS Options ...Launch BIOS Extension to setup ROMMON
Cisco Systems ROMMON Version (1.0(12)11) #4: Thu May  1 14:50:05 PDT 2008
Platform ASA5505
Use BREAK or ESC to interrupt boot.Use SPACE to begin boot immediately.
Launching BootLoader...Boot configuration file contains 1 entry.
[Code]...

View 1 Replies View Related

Cisco Firewall :: ASA 5505 Firewall Shut Down

Dec 19, 2012

Over the course of the past three days, our ASA 5505 firewall has shut down twice.  I looked through the Field Notices and it looks like this was a problem identified several years ago that was resolved for units built after June 1, 2007.  The serial number on our unit is not in the "effected" range. 

View 1 Replies View Related

Limited Or No Connectivity After Replacing New NIC?

Apr 19, 2011

I just installed a new NIC after troubleshooting old NIC and I am still receiving limited or no connectivity error. I checked router, cable modem & cable; all work fine.

View 13 Replies View Related

Replacing SBS 2003 X64 With Windows 7?

Mar 14, 2013

I'm currently in the process of replacing SBS 2003 x 64 on my Poweredge 2900 server. I would prefer to upgrade to Windows 7 x 64, but would do XP in a pinch.

View 4 Replies View Related

Replacing D-link 604 With Ebr-2310?

Apr 3, 2011

Can I replace my Replacing D-link 604 w/ D-link ebr-2310 ?

View 4 Replies View Related

Cisco :: 5500 - Replacing Existing Wi-Fi Network

Jan 28, 2013

Any documentation or information pertaining to replacing an existing wireless network.  I will be looking to replace a 4400 w/12APs with a 5500 w/12APs.  The users typically utilize the WiFi network on a regular, so I am trying to figure out how to replace the existing hardware without interrupting the service.
 
What would be the best way of handling a situation as such?   I am currently looking on the Cisco Doc. website, hoping to find something related to this.   

View 5 Replies View Related

Cisco WAN :: Replacing A 877W Router With A C887VA-W-A-K9?

Apr 10, 2012

I'm replacing an 877W router with an C887VA-W-A-K9.The new router uses the service module for managing the AP independently - So I know I can't simply paste the config accross from the old one.
 
The current router is connected to an ISP with a VPN back to the head office router. DHCP is supplied from the router and clients connect to that via wireless.
 
I know I can type most of the commands in - but what is best practice going from an all-in-one to having a separate AP? What order should thing be entered?

View 1 Replies View Related

Cisco Security :: Replacing VPN Router With ASA 5510

Feb 20, 2011

I got a task to replace our current cisco 2800 series router which is used for easy vpn remote access with cisco asa 5510.I have a got a lot of users, i wish that user shall see no difference except of ip address they are going to use for remote login.

View 1 Replies View Related

Cisco WAN :: Replacing 6509s As Edge Routers?

Nov 19, 2012

We have two 6509 will active/passive sup 720-3BXL cards in each and 1GB DRAM. Each handles full bgp  routing table with 4-5 ISP(eBGP) connections. The problem we are facing is.. 6509 were meant for core/aggregation and seam to be wasted are edge devices. With each ISP added the DRAM creeps up to a point were is it 80% utilized.
 
I am looking to replace both 6509's with routers which were meant to work on the edge. As mentioned earlier, it will have 4-6 external bgp peers per router. Handle full bgp tables. Should be capable of policy based routing.

View 4 Replies View Related

Cisco Wireless :: Replacing WLC 4404 With 5508

Jun 10, 2013

I am new to Cisco wireless and would like replacing WLC 4404 with 5508. I mean any link or doc (best practices).

View 13 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved