Cisco WAN :: Can ASA5550 Act As A WAN Edge Router

Sep 15, 2011

If my ISP brings ethernet into the building via duplex LC multimode fiber can I use the ASA5550 as the first device from the WAN or do I need some type of router for this?  I realize I'll need an SFP to get to duplex LC, but I'm not sure if I need a router, or if the ASA can function as a router for this application.

View 3 Replies


ADVERTISEMENT

Cisco WAN :: Can ASA 5550 Act As Edge Router

Dec 18, 2011

If my ISP brings ethernet into the building via duplex LC multimode fiber can I use the ASA5550 as the first device from the WAN or do I need some type of router for this?  I realize I'll need an SFP to get to duplex LC, but I'm not sure if I need a router, or if the ASA can function as a router for this application.

View 9 Replies View Related

Cisco Firewall :: ASA 5510 With Edge Router That Does PBR?

Apr 9, 2011

How to configure an Asa that will have a default gateway to an edge router that will be doing PBR?  We would like Internet surfing to go out one ISP while internally hosted services in the Asa DMZ would go through the other ISP.  configuration examples for both the edge router and the Asa? 

View 3 Replies View Related

Cisco WAN :: 7204 - Edge Router Choice

Dec 22, 2011

We are replacing a DS3 Internet connection with a 100 Mbps fastE connection from a Tier 1 Provider.  I currently have a Cisco 7204VXR with 512 Mb DRAM and 128 Mb of Flash and two 10/100 ports that is connected to the DS3.  I also have a 3845 with 1 Gb of DRAM and 256 Mb of Flash with two 10/100/1000 ports available.
 
We are currently running BGP, below is the summary
 
BGP table version is 88880414, main routing table version 88880414
379041 network entries using 44347797 bytes of memory
379043 path entries using 19710236 bytes of memory(code)

View 4 Replies View Related

Cisco WAN :: Use Router On Internet Edge Rather Than SG-300 Switch?

Aug 21, 2011

Apart from the ability to participate in BGP, is there any reason you should use a router on an internet edge rather than the SG-300 switch?

View 4 Replies View Related

Cisco WAN :: 1001 - Connecting 2 Routers To One Edge Router

Mar 6, 2013

My company has purchased a second ASA for fail over reasons and I'm needing to attach it to my core router (ASR 1001). Currently I'm running the connection between my ASA and my Core as a /19   ie. ASA-10.10.10.2/19 -- ASR-10.10.10.1/19. I know the 2nd interface on the ASR will need to be on a different network segment then the first connection (10.10.10.1/19). What would be the best way to segment this out with out breaking up my /19?
 
Run /30 segments for each interface? Use a VLan ?
 
I don't want to use up my Internet rout able IP's on /30 segments. Attached diagram.

View 1 Replies View Related

Cisco Infrastructure :: ASR 1002 Internet Edge Router

Jul 26, 2012

Any router (I'm considering ASR 1002 with 10GE SPAs) that can support the following:
 
-10GE interfaces
-can handle 1.5Gbps but scales up to 5-6Gbps different seasons
-take on full internet routes from 2-3 providers
-will live on the internet edge

View 7 Replies View Related

Cisco Firewall :: Edge Router Connection For Outside Interface Of ASA 5520

May 1, 2013

We have ASA 5520 firewall.For broadband Internet access, we have T1 Router(edge router provided by ISP) which provides public IP's 198.24.210.224 / 29. We have usable public IP's 198.24.210.226 - 198.24.210.230 with default gateway 198.24.210.225. We assigned 198.24.210.230 255.255.255.0 to the outside interface.
 
If we connect the ASA 5520 outside interface directly to T1 router, can all packets with destination addresses 198.24.210.224/29 reach the outside interface without using other device like another router or switches?I just assume that only packets with destination address 198.24.210.230(outside interface ip) can reach the outside interface from the edge router.Is it wrong assumption?  If it is correct, then is there any way to route all packets with destination address 198.24.210.224/29 to the outside interface?

View 3 Replies View Related

Cisco WAN :: 3560 Switch Configuration - Setting Up As Edge Router

Nov 27, 2011

I have a cisco 3560 switch set up as my edge router.  It is working as my external demarc switch and edge router.  It is sitting between the ISP's switch and my ASA firewall.  It's a very basic configuration with port 1 set up with a fixed ip and switchport turned off which is connected to the ISP switch.  VLAN2 is configured with an IP address and 3 ports, two of which go to different firewalls.
 
I found that I cannot ping a specific address from the inside interface (VLAN2), but I can from the outside interface Gig0/1.  I have a few deny commands in an access list, but they don't apply to the network i'm trying to access, and I haven't had any other inaccessible networks otherwise. 
 
Here's my config minus passwords and full IP ranges.  There are two ranges, one with xxx and one with xx.  The xxx is set as secondary, but is the one we really use.
 
Current configuration : 4808 bytes!version 12.2no service padservice timestamps debug uptimeservice timestamps log uptimeservice password-encryption!hostname my-rtr-ext!boot-start-markerboot-end-marker!enable secret 5 !
!!no aaa new-modelsystem mtu routing 1500ip routing! 
[Code] ............

View 4 Replies View Related

TP-Link 3G/3.75G Router :: ZTE MF637U Modem Not Working With EDGE

Apr 22, 2013

Region : Others
Model : TL-MR3420
Hardware Version : V2
Firmware Version :
ISP : YU KENYA

most service providers in our country dont have 3G or 4G support,but all the same i bought an MR3420 router in the hopes that since my modem is listed,it would still connect even if on an EDGE/2G network like YU-Kenya.But this is not the case,the router does not recognize the modem i.e it says the modem is unplugged but when i look at the logs,it indicated it detected the modem but LTE was set to zero. providing a modem bin file for compatibility under EDGE/2G connection otherwise my router will be of no use to me.

View 2 Replies View Related

TP-Link 3G/3.75G Router :: TL-MR3220 Not Working On 2G (EDGE) Network?

Dec 30, 2012

Region : Poland
Model : TL-MR3220
Hardware Version : V1
Firmware Version :
ISP : Bite

Router TL-MR3220 works well on 3G network, but is not works 2G (edge) network. 3G network is not suported in my location, only 2G. My modem is Huawei E 173. In location 2G network Router show: 3G/4G USB Modem: Unplugged.

View 3 Replies View Related

Cisco Firewall :: 2821 Internet Edge Router From Internal Network

May 8, 2013

What is the best way to monitor an Internet Edge router from the Internal network behind the Firewall?We want to pull more information from the edge router like netflow.  We can use SNMPv3 and ACLs to keep the router secure.
 
But I am looking for the best config to keep both the router and firewall as secure as possible while still allowing us to monitor performance and faults.I am running an ASA and a 2821.

View 2 Replies View Related

Cisco Firewall :: 3825 - ASA 5510 And Edge Router Not Altering SIP Packets

Oct 2, 2012

My SIP provider is not convinced that my ASA  and Edge Router is not altering the SIP packets.  On the ASA I've removed the inspect SIP, and H323, what else needs to be done to make the firewall not mess with the SIP Traffic.
 
Packets are flowing in/out. 
 
access-list hbg-outside-198_access_in extended permit udp host <SIP HOST> object sfipoffice_o eq sip
access-list hbg-outside-198_access_in extended permit udp any object hbgipoffice_o gt 49152
access-list hbg-outside-198_access_in extended permit udp any object hbgipoffice_o lt 53246
  
Here are my Policy Maps.
 
policy-map type inspect dns preset_dns_map
parameters
  message-length maximum 512
policy-map type inspect dns migrated_dns_map_1
parameters
  message-length maximum client auto

[code]...

On the 3825 Its jsut a pretty simple config that jsut routes packets form one interface to another, all Public Addresses, so no NAT on it.

View 2 Replies View Related

Cisco Switching/Routing :: 3750 - Local Subnet To Edge Router Two Networks

May 13, 2012

I need to make some changes on our network. We currently have two sites 150 miles apart we join both by way of fiber and on each side we have Cisco 3750 stack switches, configure trunking for all V lans on one port in site one then through the the long haul fiber to site two with site one using 10.1.1.30 and site two using 10.1.1.40 as their default gateway, with static routing all V lan sub nets to the other sites default gateway life is good.
 
My question - seeing how we have sites using the same sub net 10.1.1.x to trunk all data to each site through switches; we need to now change the network and add each site to the MPLS network, site one switch 1 IP address 10.1.1.30 going to MPLS router one with FA0/0/0 using IP 10.1.1.31, site two having switch 1 IP address 10.1.1.40 going to MPLS router one with FA0/0/0 using 10.1.1.41. I need to know will this work.
 
We have the same sub net in each site 10.1.1.x to the MPLS routers then the external router interface connecting each site to local switches, will this cause any problems by using the same local sub net for each site?

View 1 Replies View Related

Cisco Firewall :: Can ASA5550 Run Without SSM-4GE-INC

May 30, 2012

I've inherited an ASA5550 which is missing its SSM-4GE-INC - it was taken out to upgrade a 5540, which is now in production elsewhere in the enterprise.  Trouble is, now the 5550 will not boot, it gets stuck after a panic message, and reboots:
 
Panic: Init Thread - Module SSM-4GE-INC is not present. Rebooting...
 
I'm taking this as the unit cannot function without this module installed?

View 5 Replies View Related

Cisco VPN :: New ASA5550 License Not Working?

Aug 10, 2011

I have a ASA5550 setup with two boxes in HA.I have purchased AnyConnect Essentials for 5000 users for both boxes.The box runs 8.4.2.I tried on one box to enter new activation key and rebooted the box. Still the output of show version is the same !? [code] If I re-enter the key it says same as running key.I then tried downgrade to 8.2.5, same same show version output.

View 6 Replies View Related

Cisco VPN :: VPN Tunnel Between ASA5550 And RV042

Jul 5, 2012

we are trying to establish VPN tunnel between ASA5550 and RV042. The tunnel is connected  but I cannot access any resources that are behind ASA5550. I can ping the servers but that is about it.

View 1 Replies View Related

Cisco Firewall :: Upgrading ASA5550 From 8.2(2) To 8.4(2)

Sep 20, 2011

I are currently implementing a new patching schedule (when I say new i mean a company first!!!) and I have identified that the firewalls are all running 8.2(2).  I would like to bring these up to the latest version but am a little worried about impact!!!  I have setup a test firewall with the config from our live asa's and run the upgrade but have received multiple lines.

View 9 Replies View Related

Cisco Firewall :: Name Feature On ASA5550 8.4

Feb 16, 2012

I have upgraded ASA5550 version from 7.2(4) to 8.4(2).
 
On version 7, I am used to "names" command, like this:

names
name 107.25.1.10 Picard
name 107.25.2.20 Administrativa

By addition, when configuring acls it was very usefull, for example: 

access-list inside_access_out line 15 extended permit udp host Picard host 107.25.4.61 eq snmp 

On version 8, I have verified that names replacement is no more available: 

ASA(config)# access-list outside_access_in permit ip host ?

configure mode commands/options:

A.B.C.D  Source host IP address

View 5 Replies View Related

Cisco VPN :: Benefits To Consolidating VPN Clients To ASA5550?

Feb 1, 2012

What are the benefits of consolidation the VPN client users to the ASA 5550? My client currently has the old VPN 3000 series concentrator. Other than it's EOL and EOS, are there any other reasons I can give them?

View 2 Replies View Related

Cisco Firewall :: ASA5550 - Set Up To Access Servers?

Nov 11, 2012

I am trying to set up an ASA5550 so that I can access the servers behind it. Simple.
 
As of now, I am unable to even create an access-list to allow traffic from my remote IP into the firewall. As far as my level of experience with Cisco firewalls, it's basically zero but I have taken the Cisco CCNAX class and feel that I have a good understanding of the fundamentals. That said, we only dealt with routers and switches, and it's not impossible that I'm missing something that would be totally obvious to most folks on this board. I've used CLI and ASDM with no success.
 
Here are the relevant parts of the config:

[code]...

View 6 Replies View Related

Cisco Firewall :: ASA5550 Doesn't Seem To Address Root

Feb 22, 2012

I have been getting overrun errors on 3 different ASA 5550 HA pairs with traffic rates less than 100Mbps total.  I was told by one TAC guy to split the traffic between the two slots so that traffic comes in one and exits the other to maximize throughput because the 5550 was designed to work that way.  Another TAC guy told me to enable ethernet flow control to alleviate the overrun errors because the traffic was bursty, but this doesn't seem to address the root cause of the problem to either.  TCP traffic is bursty by nature and has it own flow control mechanism.  I can't seem to find any detailed info on why traffic needs to be split for 100Mbps when the marketting throughput number is 1.2G.  Is this a design flaw or limitation?  Is there a way to alleviate overrun errors?

View 25 Replies View Related

Cisco Firewall :: ASA5550 Way To Block Incoming Connections From TOR

Nov 29, 2012

I need to block 4000 nodes (Ultrasurf, TOR exit nodes) and I've written a script that will ssh and copy in these objects (prob 100 at a time) into an object group and then put a blanket deny.  I don't see a flood of traffic (occassional hits every other day, etc) but I was wondering what the impact would be?  Can the ASA handle an object group of that size plus an ACL with it?  Any way to block incoming connections from TOR/Ultrasurf?

View 1 Replies View Related

Cisco Firewall :: CPU Utilization When Running Two Syslogs ASA5550

Mar 3, 2011

I want to run two syslogs, one to Loglogic for compliance and the other to Solarwinds for network administration. Currently the firewall is setup for just the one syslog device. If I add an additional device ie further IP in the config for the Loglogic box will there be any noticeable differences in the performance of the firewall, does affect the cpu utilisation, or memory in any way.  

View 1 Replies View Related

Cisco Firewall :: Bring ASA5550 To Factory Default?

Feb 2, 2012

getting step by step procedure to bring an ASA5550 to factory default setting, so that I can configure it from scratch via ASDM

View 3 Replies View Related

Cisco Switching/Routing :: 4.2.2 Unable To Ping 1 Internet Site From Edge Router Able To Ping

Jan 18, 2013

From My Router that connects to Cable modem i am unable to ping website 4.2.2.2I am able to ping all other websites fines.Same website i can ping from my pc and all other switches fine.Router has only 1 ACL thats for NAT.

View 25 Replies View Related

Cisco Firewall :: Policy Based Routing To ASA5550 Inside Interface?

Mar 4, 2011

Is it possible to establish PBR rules that set the ip next-hop to point directly to the inside interface of the ASA5550?Or, do I need to direct this PBR traffic first to a directly connected router interface and then default route to the ASA?At a high level, here's what we have:
 
ISP 1 - with /21 IP PrefixNo BGP Routing3845 Edge Router - Default Route to ISP 1PIX535 Firewalls (HA) - Default Route to Edge RouterLAN Core/Distribution - Default Route to PIX535 Inside InterfaceAll applications/services use this egress path for PAT/NAT/DMZ/VPN/Etc. 

Here's what we are adding:
 
ISP 2 - with /24 IP PrefixNo BGP Routing3925E Edge Router - Default Route to ISP 2ASA5550 Firewalls (HA) - Default Route to Edge RouterSame connectivity to LAN Core/Distribution 

Goals:Maintain ISP 1 for nowMigrate only end user Internet traffic to ISP 2No disruptions to applications/services using current DefGW to PIX535 

Question: how to best use PBR to selectively direct traffic to the ASA inside interface?

View 4 Replies View Related

Cisco Firewall :: How To Schedule Automatic Xlate Sessions Cleaning In ASA5550

Jan 27, 2013

How to schedule automatic Xlate sessions cleaning in ASA5550.  I want to clear few global nat sessions manually every week.Is there any way to automate that?

View 1 Replies View Related

Cisco Firewall :: ASA 5555X Is Compatible With ASA5550 On Active Standby Mode Or Not?

Apr 14, 2013

We have currently install single ASA 5550 and want to install one more ASA for active standby mode, but cisco discontinue or End of sale ASA 5550. can any one guide me ASA 5555X is compatible with ASA5550 on active standby mode or not.

View 2 Replies View Related

Cisco Firewall :: ASDM 7.1(2) / ASA5550 9.0(2) Multicontext - How To Get Remote Access To VPN Wizard

Mar 29, 2013

I have the latest ASDM 7.1(2) & ASA5550 9.0(2). When I try to start Remote Access VPN Wizard, it's just nothing to select in Wizards-VPN Wizards, except "Site-toSite VPN Wizard..."

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 3415 - Users Access Our Site Using VPN Client Connecting To ASA5550

Jun 3, 2013

I currently have a Cisco ACS 3415 appliance with 5.4. Coming from the ACS 4.2 world, I'm have a bit of a struggle creating the following and I was hoping if I could be shown clear steps I can duplicate the rest.
 
I want to creat a group ie: AIRTEMP with access time from 7:00am to 5:00pm and add 2 users to the group.
 
Users access our site using a vpn client connecting to a ASA5550. The ASA and the ACS already communicate with each other.
 
The ACS 5.4 user guide has me bouncing all over different page.

View 5 Replies View Related

Cisco WAN :: 2951 For BGP At AS Edge?

Mar 6, 2012

our customer has a server farm in a data center.At the moment the farm has connectivity with only one ISP but sometimes it has service discontinuity.Customer wants to become AS and having two ISP connectivity for backup purposes.He needs to evaluete two  cisco routers to use at AS edge with BGP.At the moment he says that the throughputh with the server farm is max 15Mbps and in the future he thinks that it will not increase.We think about cisco2951 routers with 2GB ram.Is cisco 2951 adeguate for this task ?

View 3 Replies View Related

Cisco :: Strip DSCP Tags At ISP Edge?

Oct 7, 2011

My company's spent the last few weeks struggling with an issue with their VPN backups where select packets were being lost.

View 7 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved