Cisco VPN :: ASA5520 - Migrate Configuration / Certificates And Private Keys?

Apr 1, 2013

I am going to migrate an ASA5520 with another one having VPN configuration+certificates etc. I am a bit concern about the certificates. Shall I need a new certificate because of new IP addresses on the new ASA ? Should I configure the same IP in order to avoid this. There are many VPN clients with public keys that also need to change. Is there any way for minimal changes for migration ?

View 4 Replies


ADVERTISEMENT

Cisco VPN :: How To Arrange Installed Certificates Into Chain On ASA5520

Oct 12, 2011

I have the following problem:

I ordered a certificate from Geotrust. Geotrust signed my certificate with an intermediate certificate. The problem that ASA needs the Geotrust global ceritificate to be installed to accept my device certificate (intermediate certificate needs to be authenticated as well). When I install my device certificate on the firewall I got this error:
 
"ERROR: Failed to parse or verify imported ceritificate"
 
I do not know the way how to add two authentication certificate on ASA. I need similar solution like this: [URL]
 
So the question how to arrange the installed certificates into chain on Cisco ASA.
 
My firewall frimware/type is: Cisco Adaptive Security Appliance Software Version 8.3(2)
Hardware:   ASA5520, 2048 MB RAM, CPU Pentium 4 Celeron 2000 MHz

View 11 Replies View Related

Cisco Application :: Update SSL Certificates To 2048 Bit Key Certificates?

Sep 17, 2012

I'm working on task to update the SSL certificate for an application. steps to upgrade the SSL, stuffs need to be checked before and after the installation and how to verify the new certificates.

View 1 Replies View Related

Cisco :: RME 4.2 Can't Get Configuration File From ASA5520

Aug 10, 2010

I have a problem with RME 4.2 from CWLMS 3.1. I have configured SSH in my asa 5520 device but RME can't get the configuration file. I ran a job to sync archive but i get this message error:
 
*** Device Details for ASA_5520_VOZ_01 ***  Protocol ==> Unknown / Not Applicable  Selected Protocols with order ==> Telnet,TFTP,SSH  Execution Result: CM0062 Polling ASA_5520_VOZ_01 for changes to configuration.  CM00 Polling not supported on

[Code].....

View 2 Replies View Related

Cisco Firewall :: ASA5520 Basic Configuration

May 21, 2012

This is my 1st time trying to configure an ASA.

I'm trying to establish a very basic connection (ping) between 2 laptops, one sat on the outside interface, and one on the inside as per the diagram below:
  
I can ping back and forth from the ASA to 192.168.1.4, and to 10.1.1.1. However, what I'm trying to achieve is to be able to ping from 10.1.1.1 to 192.168.1.4 and vice versa.

I have attached the configuration file with this post as well.

View 4 Replies View Related

Cisco Security :: Copying Configuration From PIX To ASA5520?

Aug 21, 2012

i hav asa5520 i copying configuration from PIX to ASA5520 (7.2) everything working fine bt problem is that after sometime my DMZ interface losing connectivity ...

View 1 Replies View Related

Cisco Firewall :: Getting ASA5520 Total Configuration Dump?

Oct 9, 2011

We have a pair of ASA5520 firewalls setup in a very inefficient fashion, and I wish to convert them to an active/passive cluster. Trouble is, there are a number of configuration option I will need to re-implement (VPN tunnels, remote users etc), and trying to capture the configuation with a simple "show running-config" or "show running-config all" or even "show startup-config" doesn't get me things like the pre-shared-key from the VPN configurations - and I don't know them all, so I can't simply re-enter them.Is there any way to get a dump of the running (or startup) config which shows the hidden settings like pre-shared keys and OSPF message digest keys?

View 5 Replies View Related

Cisco Security :: ASA5520 How To Remove Configuration File

Jul 15, 2007

I want to put the asa5520 to the factory default please let me know how to do that. how to remove the configuration file from it.

View 5 Replies View Related

Cisco Switching/Routing :: Private Vlan Configuration On 3560E 24 Port Switch

Dec 12, 2012

We have a 24 port and 48 port 3560 E switches with identical IOS the 48 port switch supports private vlan while 24 port switch doesnt
 
configure private vlans on 24 ports 3560e and is it best practise to configure private vlan on this platform(3560)?
  
IOS version : C3560E Software (C3560E-UNIVERSALK9-M), Version 12.2(55)SE3, RELEASE SOFTWARE (fc1)
flash:/c3560e-universalk9-mz.122-55.SE3/c3560e-universalk9-mz.122-55.SE3.bin

View 3 Replies View Related

Cisco Firewall :: ASA5520 Unit Not Accessible On Network For Initial Configuration

Dec 15, 2011

We received an ASA5520-K8 through Cisco's Loan program so we could demo it as a replacement for our aging Cisco 3005 VPN appliances.  Given that we are a non Cisco shop (except for specific appliances like concentrators and wireless access points), I don't have a great deal of experience with Cisco gear.I started to set to setup the appliance this morning but immediately ran into issues.  The 5520 doesnt seem to be acting as a DHCP server, and worse yet, I can't access the unit even if I hard code the IP on the PC being used for configuration.  I have to say that I feel kinda stupid having to post this, since I actually followed the documentation avaiable for this menial task and I fully expect the problem to be a simple one.  Namely, I am using two specific sources of info for connections.

View 20 Replies View Related

Cisco Firewall :: ASA5520 Configured NAT / ACL With Real IP In Existing Configuration After Upgrade

Mar 7, 2011

I am forced to upgrade my ASA 5520 software from 7.1 - 8.2 or higher, as I am not familiar with ASA I need expert opinions.I have following concerns regarding the upgrade.
 
1-Do I need to worry about the software licensing when I download 8.2

2-I read about the few difference in commands (ACL and NAT) in 8.2 what exactly I have to do here should I change the configured NAT and ACL with real IP in the existing configuration after the upgrade ?

View 5 Replies View Related

Cisco Firewall :: Migrating PIX515E To ASA5520 - Update BIN Files In Configuration For ASA?

Jul 18, 2011

I am in the process of migrating my config from my PIX running 8.0(4) to my ASA5520 running 8.2(1).  I have converted the config so that it is ready for the ASA.  I noticed the "boot system flash:" and "asdm image flash:" command references the old PIX files.  Do I need to update these or will they be updated when the ASA reboots with the new config?

View 2 Replies View Related

Cisco Firewall :: ASA5520 To ASA5520 Via L2L Tunnel

May 31, 2011

Our firewall expert has gone off on long term illness leave and I am trying to pick up the pieces :-(
 
We have an ASA 5520 (local office) talking to another ASA (remote office) via a VPN Tunnel.
 
My 1st problem is that I cannot ping from my inside network (local) to the outside interface of my remote ASA.
 
My 2nd is that I have debug enabled on my rules but am not logging anything.

View 1 Replies View Related

Cisco :: Why 2 Encryption Keys For IPSEC VPN

Oct 7, 2011

how IPSEC VPN works but i hit a stumbling block understanding symmetric encryption keys.Here is my understanding about the process

1.Peers will negotiate plocies

2.Authenticate using pre-shared or certificates

3.Exchange DH Public Keys

4.Using Public keys encrypt symmetric key and exchange the same key which will be useful for communication

5.maintain sessions

But when we are configuring we will define encryption keys in isakmp phase and ipsec transform set ,i thought we will use the same encryption key for both management and data communication in fact i thought management phase is to give us a securely exchanged encryption key for the data tunnel.But we can use 2 different encryption keys in 2 phase i am bit confused.

View 3 Replies View Related

Cisco :: Need To Retrieve Wireless Keys From WC2504

Feb 13, 2012

I need retriving the wireless key from WC 2504.  I have a lot of clients connected to the WLAN and need to add another one but my notes/files got deleted.  Is there a way to see the keys on the controller? 

View 0 Replies View Related

Cisco VPN :: 5540 How To Go About Getting Session Keys From Either Device

Apr 25, 2013

I have a Cisco 5540 that terminates one end of a L2L tunnel, the remote end is a Sonicwall TZ100.  The tunnel is in place to carry voice traffic and I have a need to decrypt the traffic that's been captured in .cap file using Wireshark 1.8.5. How to go about getting the session keys from either device?

View 3 Replies View Related

Cisco Firewall :: ASA5510 - Can't Generate RSA Keys Or SSH

Feb 10, 2013

ASA5510, Can't generate RSA keys, so can't SSH. [code]

View 2 Replies View Related

Cisco Firewall :: ASA 8.0 - Back Up VPN Pre-share Keys?

Apr 22, 2013

I have an old Pix(on ASA 8.0) having a lot VPNs with pre-share keys setup.  And it has been too old to find out what those pre-share keys are on any documents.  Now I need to replace this PIX with a new ASA. My question is how can I find out those pre-share keys, so I can setup same VPNs on the new firewall and make it plug-and-play.  Any way I can export then import those VPN pre-share keys from the old PIX to the new ASA?  Or export and import whole configuration, but hardware are different.
 
How can I setup same VPN pre-share keys as the that of the old Pix on the new ASA?

View 4 Replies View Related

How To Enable FN (hot Keys) On Toshiba Satellite

Jul 8, 2012

I can't access the internet. When searching I get message"turn on radio button".I have the Toshiba Satellite P775 and I use Win7 64bit. My router is doing fine, because I go online with my other laptop. Device Manager shows that everything is o.k. I have traced it down to the FN keys because they are not working. Therefore I can't press FN+F8 to turn on WiFi.There is no switch anywhere on this laptop. Have been working trying to resolve without success.How to enable (turn on) the FN Keys?

View 6 Replies View Related

Samsung Wireless Function Keys?

Aug 6, 2011

my samsung laptop is not connectiong to the internet wireless network . my other dell computer is working but samsung laptop says there ius no wireless connectivity.

View 2 Replies View Related

Turn On Wireless With The Function Keys?

Feb 25, 2011

how do you turn on wireless with the function keys

View 1 Replies View Related

Cisco Application :: ACE 4710 SSL Performance (TPS) For 2048bit Keys?

Apr 18, 2013

Any info about the SSL performance for 2kb keys on ACE4710? There is only SSL performance for 1024b keys on ACE4710 (7500 SSL TPS) in the data sheet.

View 5 Replies View Related

Cisco Switching/Routing :: 3750 - IOS Keys And Certain Features

Feb 24, 2013

We just purchased a bunch of 3750s, and we need to do EIGRP stub routing and VRF routing
 
For the newer IOS versions (15+), will I need activation keys?

View 5 Replies View Related

Connecting To A Wireless Internet Security Keys?

Feb 4, 2012

How can i connect to a wireless internet security keys

View 1 Replies View Related

Cannot Find Security Keys For Wireless Network?

Nov 19, 2012

I cannot find my security key-network is xerbelec127tac- how I can find this?

View 3 Replies View Related

Charter Wireless Security Keys Password?

Dec 2, 2012

i am trying to connect a new computer to my home wireless network. I can't remember the passcode I used to set it up originally. I can't find any answers on my own. I have tried all of the passcodes that I normally use and nothing works.

View 1 Replies View Related

Cisco Firewall :: Recover VPN Keys And User Passwords On ASA5505?

Feb 9, 2012

I'm just wondering, is it possible to find out or recover  the passwords for users and pre-shared key for tunnel-group? The VPN connection was confiigured on ASA5505 before me, but no login details were left.

View 3 Replies View Related

Find Security Keys For Admin PC Wireless Network?

Sep 3, 2011

How do I find the security key for admin-pc network, when i type the one i have it comes up as mismatched.

View 1 Replies View Related

Compaq Presario CQ62 Laptop - Enable Wireless Capability Without Function Keys?

Aug 11, 2012

I have a Compaq presario CQ62 Laptop. The other day, my friend accidentally spilled water on my laptop keys. The computer works perfectly fine except for the keyboard. I tried replacing the keyboard but it did not work. Anyways, For some strange reason my wireless capability was turned off and now I have no way of turning it back on. I have searched many forums but have not found an answer.

Q: Is there any way to turn on the wireless capability i.e. using the function keys to turn on the wireless radio, WITHOUT actually using the function keys? i.e. using a command or something within the computer?

View 3 Replies View Related

Cisco VPN :: Where Are Certificates Used On This ASA (8.4)

Aug 27, 2012

I have access to an ASA running 8.4 and I need to copy the config to another one, to have it has as a spare.All configuration has coppied fine except for this part in the config;
 
crypto ca trustpoint ASDM_TrustPoint0
enrollment self
subject-name CN=GS2-NT-FIR-01
proxy-ldc-issuer
crl configure

[code]....
 
So firstly, I assume this certificate is for the SSL vpn that is configured on the ASA? Secondly, this wouldn't copy across (the HEX part). But I believe this ASA is using a self signed cert so instead I probably ned to generate a new one on this spare ASA, so how do I do that?

View 3 Replies View Related

Cisco :: Migrate From WCS 7.0.172.0 To Prime NCS

Mar 12, 2012

Is there anyway to migrate off of WCS to Prime NCS? We have a fully built WCS system with maps and all configs and was wondering if there was a way to restore to NCS.

View 1 Replies View Related

Cisco :: Certificates For SSL Work On The ASA?

Aug 8, 2011

I am delving into the world of Certificates and the ASA. I am having the HARDEST time grasping this though. I've poured over Cisco whitepapers, been reading through books and things just aren't solidifying in my head. So my question is, how do Certificates for SSL work on the ASA? Where does the data transmit and how does an ASA talk to a CA and User for things?

Lets do this basic topology for the discussion:

End User------SSL VPN---> ASA--->Internal CA

So in theory we are supposed to create a certificate and install it on the ASA and then set the outside interface to trust that cert?

How do identity certs and root certs also work out on the ASA? I have instructions that pretty much say

Create RSA key
Create new trustpoint
cry ca auth newtrustpoint
cry ca enroll newtrustpoint
cry ca import ?

So what are all of these steps specifically doing? Also in ASDM it shows a normal Certificate and an Identity Certificate. I can't really figure out the difference between the two. Does one cert talk to the CA and the other identify the ASA to the CA?

View 7 Replies View Related

Cisco VPN :: ASA 8.4(3) VPN Tunnels With Certificates?

Aug 16, 2012

My ASA's have the follwing Versions: ASA Version 8.4(3) ASDM Version 6.4(7)Have I a chance  to configure a site-to-site tunnel with a hostname as peer address when I will use Identity and CA Certificates?

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved