Cisco VPN :: Setting Up VPN Through 2 ASA 5510 Firewalls

Jan 10, 2012

'm trying to set up a vpn connection through two ASA 5510 firewalls.My network is as follows:
 
PC | FW A | Internet |FW B| - lan |
 
I am trying to achieve the following:
 
PC | FW A | Internet |FW B| - | DMZ | - | FW C| - | lan |
 
However, I am not sure where the VPNs will need to terminate and how I will achieve this taking into account the WAN IPs.

View 1 Replies


ADVERTISEMENT

Cisco Firewall :: ASA 5510 - Setting Up Active And Standby Firewalls

Oct 14, 2011

I have a 5510 ASA and have been given another an told to make them active and standby.  Basically the active one is working great but the second one has no config on it apart from the default one, but is the same firmware level.  I guess I need a crossover cable, and what happens with the inside and outside interfaces, would they need to go into a vlan on a switch, one inside vlan where the 2 firewalls inside interface go into and another vlan for the outside?  Otherwise if it failsover to the standby ASA the inside and outside interfaces wouldn't work. 

View 4 Replies View Related

Cisco Firewall :: 5510 / Adding AIP Firewalls To Existing CSC Firewalls Setup?

Mar 3, 2011

I have a customer with active/standby on a pair of 5510's with the CSC modules. They were inquiring about the AIP/ASA, and since this would NOT work in their current setup, would getting a pair of 5510/AIP configured for transparent failover work placed in front fo the existing units? Would I need to have a switch placed between the AIP and CSC ASA's?  Or would I setup the ASA's for context based Active/Active failover to interconnect the ASA's to the existing units, but I still see a need for a switch.

View 1 Replies View Related

Security / Firewalls :: List Require For Setting Up Data Center For Either University Or Government?

Feb 26, 2012

What are the list require for setting up Data Center for either University or Government?

View 4 Replies View Related

Security / Firewalls :: Using NAT With Cisco ASA 5510 Firewall?

Mar 25, 2011

I was under the impression that those global addresses that we used with NAT were from the outside IP addresses range?Lets say my outside IP address is idk 192.112.40.11 /30 and I only had two usable IPs (since you can't use network and broadcast IPs) so how would I set up NAT for a couple of Inside addresses with a shorting of addresses like this? Idk if that makes sense what I'm trying to say

View 3 Replies View Related

Cisco :: ASA 5510 / Upgrade All Firewalls To Security Plus?

Sep 21, 2011

I am trying to upgrade all my firewalls to Security Plus but I am not sure what firewalls are needing the upgrade.  Is there a SNMP pull I can do to see what license is on my firewall?  example: "This platform has an ASA 5510 Security Plus license." via SNMP

View 1 Replies View Related

Cisco Firewall :: ASA 5510 - Speed Through 2 Firewalls

Jun 5, 2012

We have a configuration where we go through a firewall (ASA 5510) to a router, which decides if it is internet traffic or another network used for colleges etc in Canada called SR Net. If it is internet traffic it then goes through another ASA 5510 to the internet.
 
When we tested we were not seeing the speed of our internet (about 1/10th). We tested by putting the laptop before the internet firewall and we get the throughput. We also threw the test laptop before the router and we got the throughput expected. But when the test laptop is before the internal (first) firewall we get about 1/10th the speed. We are Nating on both firewalls, so from the inside we are going from a private IP to a Public IP (so it can go to SR Net is need be), then Nating again to the internet IP on the second firewall.

View 2 Replies View Related

Cisco WAN :: 5510 Simple Network Architecture For Redundant Switches And Firewalls?

Oct 17, 2012

We'll be building a small remote site that will use two Windows 2008 servers.  We would like redundancy in firewalls, IPS's and switches.   Is it better to buy stand-alone ASA 5510s (with embedded IPS's) and 2960s, or is it a better option to buy a  Cat 6000 with FW modules.  We'll have several internet IP addresses available. 

View 2 Replies View Related

Cisco WAN :: Setting Up ASA 5505 Behind 5510?

Aug 14, 2011

My company has leased some office space to an outside company that handed me a 5505 and said "We want to VPN to our HQ through your Internet". I have two issues: I need this to work and I need to be able to access the 5505 from the management network. I don't care about the VPN aspect as much as making sure that I have basic communication down. I have everything configured per the diagram, but I can't ping the 5505 outside (Vlan 2) interface. I want to be able to configure and test the VPN setup on the 5505 from Putty on my PC.
 
The default route on the 5520 sends traffic to 10.10.1.1 and the default route on the 5510 sends traffic to the WAN interface. I added this route on the 5510:
 
outside 10.94.4.0 255.255.255.0 10.10.8.1
 
I still can't ping the default gateway on the 5505. There is a switch between my PC and the 5520 but the default route passes the traffic to the 5520. However on my tracert I don't even get to the 5520. What's going on here? Do I have to add a route to the switch just to manage the ASA 5505?

View 30 Replies View Related

Cisco VPN :: 5510 - Setting Up Second VPN Connection

May 3, 2011

I have multiple offices that I want to vpn into one office....  So is there anything special I have to do to establish this....Or can i do the same set up for one office then copy those setting to the next office?

Office 1 - main office .........asa 5510......ip 111.111.111.111
Office 2 - remote office......asa 5505......ip  222.222.222.222
Office 3 - remote office......asa 5505......ip 333.3333.333.333

I want office 2 and 3 to be able to vpn into office 1.
 
Currently I have already set up the vpn connection for office 2 to office 1.  Everything works well with that so I know it is good! So could I basicly copy those setting to office 3?  Or is there some weird settings or anything I should do or avoid by now setting out office 3 to vpn into office 1??

View 2 Replies View Related

Cisco :: Setting Up DHCP For VPN Clients On ASA 5510?

Jun 30, 2011

I'm trying to understand my options for assigning addresses to VPN clients on an ASA 5510. Under the ASDM, I have a field for DHCP servers, radio buttons: none, dhcp link, dhcp subnet, and field: client address pools. Cisco's VPN examples demonstrate setting up a client address pool, which I did, but the VPN client isn't assigned a gateway in the process so it can't connect to anything; I really don't understand the point of this. I'd like to create a DHCP pool on the ASA for VPN clients as this seems to be the standard configuration. However, I don't know where in the ASDM to configure this and how it's applied. The only DHCP options I found involved creating a DHCP server on an interface, which I don't want to do since VPN users aren't on a physical interface, right?

View 6 Replies View Related

Cisco VPN :: Setting Up Two Separate 5510 At Two Different Locations

Nov 1, 2011

I'm setting up two separate 5510's at two seperate locations. The client wants two seperate SSL-VPN's; one for the HQ and one for the COLO location. They have a single domain for which I have added a-records to point to the corrosponding ASA's thusly: [code]
 
My questions is this: do i need to buy seperate certificates for each ASA/fqdn/IP combo? I'm using godaddy to buy the certs. If I do need to buy seperate certs, that makes the installation easier, but may waste $$. If I only need to buy one cert, how do I set it up so that both combo's are verified?

View 2 Replies View Related

Cisco Firewall :: VPN Setting Keep Dropping On ASA 5510?

Jan 23, 2012

I have a Cisco ASA 5510 firewall, my problem is that when the first VPN connections is established everything is good.  But when that connections is cancel or terminated due to non connectivity.  No one can connect to that firewall through that VPN unless that firewall is restarted.

View 1 Replies View Related

Cisco Firewall :: Setting Up ASA 5510 Cannot Get SMTP To Come In

Mar 21, 2013

I have a ASA 5510 (ver 8.4) and I have been all over the support sites looking for what I am doing wrong. I have a sanitized cut n paste of the OBJECT, NAT, ACCESS-LIST and Packet Tracer output and it keeps failing on the NAT with a rpf-check. Once i get the SMTP flowing I have to open up HTTP and HTTPS to one of the servers also.
 
Here it is:
  
RVGW# sh run object
object network WiFi
subnet 172.17.100.0 255.255.255.0

[Code]......

View 1 Replies View Related

Cisco VPN :: Setting Up L2TP / IPsec VPN To ASA 5510

Jun 23, 2011

Co-worker just got a Blackberry Playbook tablet and, try as I might, we cannot get the darn thing to successfully set up a working IPSEC/L2TP vpn tunnel to our ASA 5510, which acts as a multi-purpose VPN concentrator.  Any luck setting up L2TP/IPSEC VPN to ASA from Blackberry Playbook?

View 0 Replies View Related

Cisco Firewall :: ASA 5510 - Setting Up ACL To Permit Access Only To The Nat Subnet?

Apr 9, 2012

setting up an ACL on my ASA 5510 to permit access only to the Nat subnet from inside to the outside interface. This firewall is setup for the DR solution in the production network. I am applying following acl in the inbound direction on the inside interface.
 
permit ip any "Nat_subnet"
 
After appliying this acl to inside interface I observed that I can ping to the destinations in NAT'ed subnet but unable to ssh to the servers. Following is the summary of my configuration.

!
interface Ethernet0/0
nameif outside
security-level 0
ip address 192.168.135.241 255.255.255.248 standby 192.168.135.242

[code].....

View 3 Replies View Related

Cisco Firewall :: ASA 5510 - Setting Up SMTP Port Block?

Mar 5, 2012

how to go about setting up the ASA to block any SMTP traffic outbound except for our Exchange Server. This is in relationship to a SpamBot issue that blacklisted us. I have an ASA 5510 running version 6.2(5) / 8.2(2) with three ports. DMZ, Inside and the Outside interface. Up till today, I only needed to block outside traffic to our internal network which I used the ASDM to configure a rule on the outside interface for an incoming rule. I am assuming I need to create an outgoing rule on the outside interface; however, just to make sure I understand the terminology/traffic flow, I created the rule with my computer as the source (192.168.0.131) with ALL destination and the service as HTTP. My logic, which seems to fail here, is that any traffic from my computer going outbound would be blocked; however I am still able to browse... That said, if I were to change the source as the Exchange server and the Service Type to SMTP, it would not actually block traffic and therefore not solve our problem.  I even gone as far as permitting traffic from my computer, expanding the hit counter and I see no hits.  So I am no doubt doing this wrong. What I do know, is when I first created the rule, a second rule was automatically created (Implicit rule) that deny all sources and blocked all HTTP traffic until I changed it to Permit?

View 2 Replies View Related

Cisco Firewall :: Unable To Authenticate With Common Setting With ASA 5510 Running 8.0

Nov 11, 2008

I have allways configured and run LDAP Server Groups authenticating to Active Directory Domain Controllers using LDAP, never an issue, until I hit a Domain Controller running on a Windows Server 2008. I have been unable to authenticate with the common setting with an ASA5510 running 8.0.1.

View 4 Replies View Related

Cisco :: Discovery ASA Firewalls In LMS 4.0

Feb 16, 2012

I have a problem discovering some ASA firewalls on a network. I have several ASA firewalls on this /24 network, but some of them I can't discover e.g 149.x.x.107 is discovered ok, but 149.x.x.20 I can't discover. It seems that it's not even trying to discover the devices I have problems with. Nothing is shown in the discovery log.

View 11 Replies View Related

Firewalls Over TCP / IP Stack

Jun 25, 2011

For protection of any network architecture,use of firewalls (either hardware or software) only at Network ,Transport and Application Layers of TCP/IP stack. Why not at remaining layers?

View 1 Replies View Related

Cisco :: Upgrading Software On ASA Firewalls?

Feb 13, 2012

Am I able to legally download and upgrade software versions still on ASA firewalls?I have not had an issue in the past as this has not effected the license.I cant find anything online saying that you cant due to Cisco's new Software license policy changes.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: 5505 - ACS 5.2 With ASA Firewalls

Dec 16, 2010

I am trying to setup a Cisco ACS 5.2 for both login and enable authentication to asa 5505s, 5510s, and catalyst switches. I am testing with an ASA 5505. The initial authentication to the firewall works, but when I try to enter privileged exec mode using the enable command, it doesn't work. I have the user setup on the ACS with a password and an enable password and privilege level 15, I have the device setup on the ACS, I have the tacacs+ server setup on the firewall and pointed to the correct server address, and the AAA commands for telnet, ssh, and enable.

View 9 Replies View Related

Security / Firewalls :: What Can The Other Computers See

Feb 13, 2012

I opened my iTunes program today and noticed a roommate's MP3 files were picked up on my network. I think the name of the program is Rocket Tube MP3. Anyway, I came on here because our computers use a Wi-Fi internet connection and I was wondering how much of my web activity (history, cookies, temporary files, etc) he could see from my laptop if his computer was a desktop downstairs. He's very tech-savvy (a former IT guy) and I don't want him snooping through my personal records.

View 2 Replies View Related

Cisco :: 2 WLC 2504 With Two Firewalls - Backup Port

Apr 24, 2012

I have a question about 2504 deployment.Two WLC's , one will be acting as primary controller, second as secondary controller.
 
There will be two firewalls with High Availability between them. Ok, if primary controller will go down, we would need to wait about 2minutes, and AP's would join secondary controller.
 
But  if there is a problem with firewall? Etc. FW 1 goes down. Is it  possible with WLC 2504 to use it's second port as backup port ? And use  the same IP address between them?
 
Because if we configure the second port with different IP address, we would need to wait  about 2minutes, because AP's is in "rejoining" mode )(To  use second port as backup, but have the same IP address on it ( like  put these two interfaces into the same "vlan") , because this would be  really great, if one Firewall goes down, we would still will be using  the same wireless controller.)

View 3 Replies View Related

Security / Firewalls :: How To Protect Network

Nov 29, 2011

We are a non-profit organization that is heavily reliant on interns that use their own laptops a lot here. My concern is they come in and connect to our wireless network with no supervision or anything else. I am worried they will introduce a virus, trojan, or something to our network. What the best way to keep them from introducing unwanted malware from a thumb drive, virus in email, or something to that effect shy of standing over them while they install and run an antivirus software?

View 7 Replies View Related

Security / Firewalls :: Lan To Lan Vpn Tunnel Is Not Working

Feb 12, 2012

I have problem with the Lan-to-Lan VPN tunnel.the VPN working fines since 9 months ago without any problems.Suddenly got the problem!,In last two days we faced problem the VPN down.in first time the problem in phase-2.. but after that in phase-1... in latest no data packet received to their side.

View 1 Replies View Related

Security / Firewalls :: Static IP Will Be Changing With The New ISP?

Apr 27, 2011

I am looking for some resources on what steps would be involved in configuring a Cisco ASA 5500 when obtaining a new ISP. Since our static IP will be changing with the new ISP, just need to know what configurations changes will need to take place. We currently have a working config with DSL, but are switching to cable. We are using a DMZ configuration, and are going to try using ASDM first since that should be easier

View 3 Replies View Related

Security / Firewalls :: Port Scanning On LAN

Jul 24, 2012

There are three Win 7 laptops on the LAN trying to connect to the ASA5500 Firewall. They generate a Severity Level 3 alert and try the same port three times then move to the next numerical port and try that three times. Is this a malicious Hack.

View 5 Replies View Related

Security / Firewalls :: Possible To Change Nat Type

May 22, 2012

can i change my nat type from type 3 to type 1

View 19 Replies View Related

Security / Firewalls :: Why Can't Get Into Specific Website

Dec 6, 2011

I have been trying to get into one website (url)The world's best online marketplace, List free Classifieds,buy and sell - auction,post a job and get hire from over 1 million top professionals. | Wanaifieds.com and I can't get into the site from my home I can get into the site everywhere else but here I called the service provider and their telling me it's not them they don't block website and the IP is not stationary so their nothing wrong with their end I called the hosting company of the website and they told me they don't block any IP's I don't know what to do I do remember when it was working about 4 days ago I tried something o the site and I messed up and I clicked back instead of putting my password a little box poped up and said something about a certificate or something but I just clicked off and when I tried to get back on the site.

View 6 Replies View Related

Security / Firewalls :: Some Of IP Address Is Shunned?

Aug 26, 2012

I'm working with Cisco ASDM 6.1 for pix. I want some of ip addresses are not shunned thus provide a list of addresses which should not be shunned in threat detection, but some of ip addresses are shunned yet.

View 1 Replies View Related

Security / Firewalls :: How To Block Website

May 20, 2012

I want to block 10.0.0.1 and 192.168.1.1 but my router says invalid domain so if will the guess network be able to go to page 10.0.0.1 and 192.168.1.1 even though I don't block it? I have a bypass account but don't want anyone else to access 10.0.0.1 and 192.168.1.1. Also can you tell me some proxy sites I can block?

View 11 Replies View Related

Security / Firewalls :: Associated Service Not Running

Nov 30, 2011

Windows firewall settings cannot be displayed because the associated service is not running

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved