Cisco VPN :: VPN Filter Vs Interface ACLs On ASA 5525

Mar 19, 2013

I need some clarification on the differences between a VPN-Filter v an Interface filter.I am using an ipsec crypto tunnel between our site using ASA 5525 and a remote client who are using a Palo Alto Firewall.  I have applied a vpn-filter on the tunnel for these sites but I am being told that an interface filter would have been more simplier.

View 9 Replies


ADVERTISEMENT

Cisco :: Full Access To Everything Since The Tunnel Is Set To Bypass Interface ACLS?

Nov 23, 2011

I have ip phones at the remote location that connect into the phone switch(it's a nortel cs1000 system) over the tunnel. Internal calls work just fine, however when somebody calls from the outside, or calls are made to the outside the connection is never finalized. Like if I call from my cell it rings the phones, but when I answer there is nothing but dead air.In the group policy for the tunnel, I gave the remote site FULL access to the phones vlan and vice versa...which obviously works since internal calls work fine. If I remove my group policy and give it the Default group policy which essentially gives that tunnel full access to everything since the tunnel is set to bypass interface ACLS, external calls work fine. So it's definitely related to the group policy.

The group policy is basicallyAllow remote site to X network/host on these ports no denies since it blocks whatever isn't specifically allowed. However since it can get the phone switch and it can get to the internet I'm not seeing why the calls aren't working.The only thing I can think of to try doing as well is remove the allow inbound traffic to bypass interface rules and treat it just like another vlan interface on the ASA. Create the rules on each interface for the remote site network etc and see if it works that way.

View 5 Replies View Related

Cisco Switching/Routing :: 3750E / Applying ACLs When Routing Between SVI And Routed Interface?

Mar 12, 2013

Quick question here. Using 3750E series switches with multiple VLANS configured. These switches serve as our 'core'. I have SVIs configured for the different VLANs and add inbound ACLs in each of the SVIs to control traffic between VLANS. This switch also terminates a P2P Ethernet link which connects to our Colo facility. The port used for this is configured as an L3 port. I noticed today that I was able to send traffic across this L3 link that I thought should have been blocked by an ACL I had in place but it wasn't. So the traffic flowed from a port in say VLAN 20 across this L3 link (assigned with an IP address). Would this traffic flow not cause traffic to be checked against an ACL applied in the inbound direction on the SVI of VLAN 20 (int vlan 20)? Traffic does get checked when routing between SVIs. Why would it not get checked when routing between SVI and L3 interface?

View 2 Replies View Related

Cisco Wireless :: 1552E - Setting Up Mac Filter / Drop Down Selection For Interface Name

Mar 12, 2013

We have a number of 1552e's deployed as RAP / MAPs, using a 5508 WLC. All those are working fine.I have a few requirements for an outdoor access point... not a RAP or MAP, but just a simple outdoor AP. I assume that if I use a 1552e for that requirement, I would place the mode in local, rather than in bridge mode, correct ? Also, a question on mac filtering.  When setting up the mac filter, there is a drop down selection for "interface name".  The radios seem to work fine with "none" selected, so I'm confused about what exactly that selection is doing.  Is it simply a reference lable, or does it actually have a purpose?

View 2 Replies View Related

Cisco :: LMS 4.2.2 Cannot Backup An ASA 5525-X

Nov 21, 2012

Any one see the pronl;em where LMS 4.2.2 cannot backup an ASA 5525-X (UKHSL-N01-AFW02)..The Inventory collection is fine, to a point.I have applied all updates LSM etc. [code]

View 7 Replies View Related

Cisco Firewall :: PIX 525 6.3 To ASA 5525-x?

May 9, 2013

I have read that it is possible to migrate from a 525 to an ASA via a upgrade to pix asa version 7.0 then using the migration tool once copied to the new ASA 5500 series, but i have alos read in a forum somewhere that a migration from PIX to ASA 5500-x series is not possible,, is this true ?

View 1 Replies View Related

Cisco Firewall :: NAT On ASA 5525 8.6(1)

Apr 8, 2013

We have recently installed new 5525 8.6(1) ASA's. Our setup is like; where we are using Public IP for web server, which needs to be mapped/natted to internet VIP address and that VIP is configured on F5 LB. Setup is below; This Public IP is the web server IP. The firewall get hits, but web server page is not being displayed. In the logs FW built tcp but then tear down the session, syslog id (302014) 77 TCP Reset-I
 
                          |INTERNET|
                                 |
                                 |
                         195.201.55.X
                            [ ASA ]
                          Natting to
                         10.100.100.151
                              [ F5 ]
                                |
                              / 
                            /      
Real Servers---> .150   .151
 
 
NAT Config is; nat (DMZ1,OUTSIDE) source static 10.100.100.151  195.201.55.X.

View 8 Replies View Related

Cisco Firewall :: How To Enable Ssh On ASA 5525

Aug 15, 2012

May I know how to configure for remote accessing ASA 5525 via ssh?I have issued the following commands
 
ssh 10.60.0.0 255.255.0.0 outside
ssh 10.60.0.0 255.255.0.0 dmz
ssh 10.60.0.0 255.255.0.0 inside
ssh timeout 5
 
but I am not able to access ASA via ssh. Do I need to add any other command

View 20 Replies View Related

Cisco Firewall :: Migration PIX 515 8.0(3) To ASA 5525-X

May 28, 2012

I have a PIX 515 with version 8.0(3). We buy a ASA 5525-X for replace the PIX.
 
The question is, what is the better method to migrade the configurations? Manually?

What is the better version for 5525-X? 8.6.1?

View 4 Replies View Related

Cisco VPN :: ASA 5525-X Dynamic PAT Policy S2S VPN

Jul 17, 2012

I am prepping new ASA 5525-X's for a client that has multiple S2S VPN's.  On some of the VPN connections, I need to do a policy nat to translate some of their subnets to a single IP address before it goes over the S2S VPN.  However, when I try to use a subnet, I keep getting the following error:
 
Subnet cannot be used as mapped source in dynamic nat policy.
 
This works fine on their old ASA's which are running 8.2 code.  I figured out I can use a network range, but cannot go over 65535 (or whatever it is) addresses in that range.  This is very annoying when they have multiple networks they want to allow over the S2S VPN.  Is there anyway around this or am I stuck creating a network range for each subnet?

View 6 Replies View Related

Cisco Security :: ASA 5525 - New Versions Of 8.x Code

Dec 4, 2012

We are updating our older Pix boxes to ASA 5525s.  A book covering the new versions of 8.x code.

View 3 Replies View Related

Cisco Firewall :: ASA 5525-x Flash Memory

Nov 14, 2012

We have a customer that has a ASA 5525-x reporting only 4g flash memory rather than 8g has any 4g version of the 5525 or is the IOS reporting incorrectly the size,  as it seems to be embedded on these units as a USB disk internal.

View 4 Replies View Related

Cisco Firewall :: 5525 - Upgrades From 8.2 To 8.6 For Some Customers

Nov 13, 2012

We have a 5525 that has not been deployed to production yet so we're using it in the lab.  I want to lab some upgrades from 8.2 to 8.6 for some customers but the 5525 comes loaded with 8.6.  Would there be any problem with reimaging the 5525 with 8.2?  I'm just not sure if there would be an issue with this new hardware running that old software.

View 3 Replies View Related

Cisco Firewall :: Upgrade From ASA 5520 To 5525

Feb 27, 2013

I'm about to  upgrade from an ASA5520 to ASA5525.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: 5525 Ignoring Users Using AD Agent

May 13, 2013

its been a while since I configured a Cisco firewall (PIX 6.0, SDM) - I've now been thrown in the deep end with a pair of 5525-X's (Latest Software) and I need to achieve the belowWebsense integration (Got this working)AAA Authentication for various outbound traffic routes.I'm using ASDM as I'm more comfortable with the GUI than CLI (I'm the other way round with switches!!!), I have AD Agent configured but the ASA isn't doing anything based on User Name but I have a few other things to try. What I'm trying to achieve now is ignoring certain user names from being matched to IP Addresses as I believe that this may have something to do with it.We use Sophos AV and each PC requires a Service Account to run Sophos under. Each update that Sophos attempts is seen as a login and that is the user attached to the IP Address of the machine. Within Websense, it can be told to ignore certain users for purposes of filtering and reporting etc.. but I dont seem to be able to do this with the AD Agent.

View 3 Replies View Related

Cisco Firewall :: 5525 Authenticated User Access

Oct 31, 2012

We've just replaced our Fortinet Firewalls with 5525's but are struggling to get a feature working that worked great on the Fortinet firewall.All our users use a proxy for internet access that's configured in IE but from time to time some users need to remove this proxy and go directly out to the internet, with the Fortinet devices we created a rule right at the bottom of the inside access out rule that had it authenticate users via TACACS which worked a treat and could be used from PC or laptop. We want to do a similar thing on the 5525 and I thought the Authenticated user would give me this access but I don't seem to be able to get it to work. I've got the AD side of it working fine the ASA can pull user and groups from AD but I'm struggling to get this working for a user.

View 3 Replies View Related

Cisco Firewall :: Monitoring ASA 5525-X With System Center 2012

May 21, 2013

We are using MS System Center Operations Manager to monitor network devices.   We are trying to monitor our Cisco ASA 5525-X firewall interfaces.
 
We have a generic management pack installed that seems to work for parts of the 5525.  We can see performance info for IF-4 but none of the other interfaces.
  
Our Management Pack is a generic Cisco Adaptive Security Appliance Version 9.1(1) management pack.
 
Is there a management pack that is specifically for this Cisco firewall?  

View 0 Replies View Related

Cisco Firewall :: 5520s To 5525-Xs - Transfer User Accounts

May 21, 2013

I am in the process of upgrading a client's firewalls from 5520s to 5525-Xs.  I have 2 independent firewalls that are merging into a single firewall.  Both of the source ones have a TON of user accounts defined for remote user VPN, is there any way to move these user accounts with passwords in tact??  The goal is not to have to tell the 250+ users that they need to reset their passwords at once.

View 2 Replies View Related

Cisco Firewall :: Way To Create A Guest Access Lobby On ASA 5525

Sep 23, 2012

Is there a module or way to create a Guest Access Lobby on the ASA 5525? We currenly leverage the WLC to do this for us, but are moving to a routed access enviornment which is causing some issues. We would like to offload the guest access responsibility to the ASA if possible.                   

View 1 Replies View Related

Cisco Firewall :: 5525-X Cannot Create New Sub-interfaces / Etherchannels Through ASDM 7.1(1)

Apr 9, 2013

We are suffering an issue with ASDM 7.1(1) on a 5525-X with 9.1(1) software. In the Configuration --> Interfaces window, I can modify parameters on physical interfaces, I can modify parameter on subinterfaces, but I cannot create new subinterfaces or Etherchannels through ASDM.
 
When I create a subinterface, entering all parameters, interface name, vlan id, security level, etc., then I click on "Apply" button and nothing happens. It doesn't send anything to ASA. If I click on another window, ASDM ask for applying changes, I click on it, but nothing is applied and window doesn't change. It happens only when creating new interfaces. If I create them through CLI, then I can modify parameters without any problem.
 
I have tried re-installing java and I have tested with 6.31, 7.9, 7.11, 7.17 Java versions, from Windows XP, Windows 2003 Server and Windows 7 computers with same issue. Also with Linux Mint distro with IcedTea Java.

View 3 Replies View Related

Cisco Firewall :: ASA 5525 - Asdm Won't Work After Installing IPS Module License

Mar 14, 2013

I recieved my  IPS  module license for my  ASA 5525  . I enetered the key  via the ADSM and it prompted me to restart the firewall  .. After that i cannot get into the firewall via the ASDM . 

View 3 Replies View Related

Cisco Firewall :: To Setup ASA 5525 In Active Standby Failover Mode

Feb 12, 2013

I need to setup an ASA 5525 in Active/Standby failover mode. I am setting up the ASA for a company that purchased only one public IP address. The public IP address is assigned to the outside interface. My question is will failover work correctly if I don't use a secondary IP address on the failover configuration on the outside interface?

View 4 Replies View Related

Cisco Firewall :: ASA 5525 - Bandwidth Management (Rate Limit) Using QoS Policies

May 22, 2013

We have an ASA 5525 running version 8.6(1)2 and a 10 MG pipe. I have execs that want to limit bandwidth on users for stuff like youtube, stream media, and downloads. I found the article on ‘Bandwidth Management(Rate Limit) Using QoS Policies’ so it appears our firewall can do what we want. I’m not a cisco person. My knowledge is limited when it comes to configuration – that’s why we have SmartNet.

Can bandwidth be limited on end users and/or can they limit the ‘bandwidth rate limit’ to just youtube, steaming media, and downloads? If so, what should the limit be? and I’m assume this would be for ‘incoming’ traffic only? we’re running into some bandwidth hogs – usually youtube and/or streaming media. We have a Barracuda web filter which we’ve used to block and monitor activity but I simply do not have time to babysit this all day. I should also mention we do have critical data running up and down the pipe; such as credit card processing, DB replication between in house DB and hosted website, TPCx and EDI, FTP, and such that we don’t want restricted.

View 7 Replies View Related

Cisco :: ACS 5.2 Downloadable ACLs For WLC

Jun 19, 2011

I'd like to set up a downloadable ACL from my ACS 5.2 server to be applied for users authenticating for just one of my SSIDs / WLANs.
 
I intend to use this primarily for mobile devices to allow them to go to any of my physical locations, connect to the same WLAN regardless of location and then get the same downloaded ACLs (filtered based off  of destination port and address) applied in each case.

View 3 Replies View Related

Cisco Switching/Routing :: ASA-5525 - Connecting Multiple Switches To Single Firewall?

May 28, 2012

Could I configure and connect 3 Dell switches to an ASA-5525 Firewall which has got 8 interfaces.

View 7 Replies View Related

Cisco :: Configuring ACLs For HSRP

Feb 13, 2013

I'm screwing around with HSRP running between two L3 interfaces of routers. I placed an inbound and outbound ACL on the same interface on both of these routers specifying to "permit ip any host 224.0.0.2" Why am I only seeing counters ticking for the inbound ACL of both of these routers? Is it an order of operations thing?

View 3 Replies View Related

Cisco Firewall :: ASA 8.2 Getting ACLs Loss

Jan 23, 2013

I'm almost afraid to post since my stuff is so OLD! I have a 350 Series PCI Wireless LAN Adapter in my old WinXP, not wireless-ready Compaq.I live off the grid, no landlines and have been using a Franklin CDU680 USB air card to connect to the Internet. The air card doesn't like my Compaq - occasionally crashes it. I thought to put the air card in a router to solve the problem and communicate with the router using the Cisco 350. Bought a Cradle Point router from my ISP and plugged in the Franklin.  Then spent the next 5 days trying to get the Cisco 350 to associate with the router.I now have a profile with the router's SSID in it that according to the ACU's status report is associated with that SSID. Problem is that there is no Internet connection.

View 4 Replies View Related

Cisco :: IPS Configures Router's ACLs Thing?

Mar 18, 2011

This "IPS configures your router's ACLs" thing seems like a bad idea to me, other than letting it be it out of line and reducing your IPS's load abit doesn't really seem to really give you any real benefits..

View 1 Replies View Related

Cisco :: Implement ACLs In Layer3 Switch?

Oct 15, 2012

Is it possible to implement ACLs in layer3 switch??

View 4 Replies View Related

Cisco Firewall :: ASA 5505 - Static NAT And ACLs

May 25, 2011

Currently a customer has all theLAN devices using a router as the Default Gateway. The router also do the Dynamic NAT to the internet access and has NAT/PAT rules to publish some services like HTTP and FTP. As I know the router will permit all the incoming traffic in all its interfaces without restrictions at less there is an ACLs that restrict the incoming traffic on an specific interface.Now the customer has bought a brand new ASA and wants to use it as the default gateway for the entiery LAN. This means, the ASA will have the internet connection and will be the responsible for the NAT/PAT process.

I have configured the NAT/PAT rules already following the current router configuration, but I need to know if I have to configure ACLs allowing the incoming traffic on th Outside interface for the services I NATed.

View 1 Replies View Related

Cisco Firewall :: ASA5510 Post And Pre 8.3 NAT And ACLs

Aug 30, 2012

In the near future I plan on updating all of my firewalls to 8.4, currently we're on a mix of 8.0 and 8.2. I've heard that if your equipment is on 8.2 there's an auto-conversion feature when upgrading to 8.3. However, I do not want to rely on that and am trying my hand at re-writing the NAT and ACLs myself. Attached is my pre 8.3 ASA 5510 config (santized) and a document that shows the particular sections pre 8.3 and what I think they should be after the upgrade.

View 1 Replies View Related

Cisco :: To Configure MAC Based ACLs With AIR-SAP1602I

May 19, 2013

I  want to buy an AIR-SAP1602I-E-K9 and I don't know if I can configure a MAC-BASED ACL with this AP, because I must permit the access of the wireless netwok only to determined wireless devices.

View 4 Replies View Related

Cisco Firewall :: ASA 5510 - Multiple V LAN's And ACLs

Feb 27, 2013

I'm having a bit of trouble determining the best way to do this... I have 12 V LAN's set up (sub interfaces on a redundant group of two NICs) on my ASA 5510.  On several of these, I want them to be able to access the internet but not access other V LAN's. 

By default, they have a rule like "any to any less secure", and since the outside interface has a lower security level, this works great.  But if I create an ACL on the interface, this rule disappears.  I can restore internet access by adding an "any to any" or "(this interface's sub net) to any" rule, but this seems to imply that it allows access to any v LAN.  Do I have to create a set of "deny" rules for each V LAN, on each V LAN, followed by an any-any rule to allow internet access, or is there a cleaner approach?

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved