Servers :: Configure Ipchain Firewall In Ubuntu

Feb 5, 2011

I want to set up ipchain firewall of my ubuntu so that it prevents to traffic to an specific IP address?

View 1 Replies


ADVERTISEMENT

Servers :: How To Configure Firewall Assign NAT IP

Apr 22, 2012

How to assign NAT IP to server from Firewall

View 2 Replies View Related

Servers :: ISA Server 2000 Networking - Connecting Ubuntu Desktop?

Jan 27, 2012

windows server 2003,ISA server 2000 Networking :: Connecting ubuntu desktop?

View 1 Replies View Related

Cisco Firewall :: Ubuntu 10.04 / Firewall Starts Randomly Responding To ARP Requests For Other IPs

Aug 22, 2011

I have my firewall on IP 192.168.0.1 (for example, real IP is a class C address).  I have a web server (Ubuntu 10.04, though this happened before with an 8.04 box as well) on ip 192.168.0.101.  Everything will be functioning fine, and I won't have any issues for a while.  Then, randomly I'll have problems getting to my web server, getting disconnected from SSH sessions.  I go to one of my linux boxes and do an "arping -b 192.168.0.101" and I will get  two responses, one from my firewall and one from the box, as illustrated below.  The only way to correct the issue that I've run into is to reload the firewall, which will then behave properly again until it randomly decides to start answering ARP requests on the other IP again.
 
nwiadmin@vm-test-lx:~$ arping -b if-webdevint4-lxWARNING: interface is ignored: Operation not permittedARPING 192.168.0.101 from 192.168.0.168 eth0Unicast reply from 192.168.0.101 [xx:xx:xx:xx:xx:xx]  2.309msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  2.434msUnicast reply from 192.168.0.101 [xx:xx:xx:xx:xx:xx]  2.280msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  2.377msUnicast reply from 192.168.0.101 [xx:xx:xx:xx:xx:xx]  2.129msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  2.221msUnicast reply from 192.168.0.101 [xx:xx:xx:xx:xx:xx]  1.839msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  1.934msSent 4 probes (4 broadcast(s))Received 8 response(s)
 
Reloaded firewall
 
nwiadmin@vm-test-lx:~$ arping -b if-webdevint4-lxWARNING: interface is ignored: Operation not permittedARPING 192.168.0.101 from 192.168.0.168 eth0Unicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  2.839msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  1.935msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  1.758msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  2.733msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  9.568msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  1.931msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  2.283msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  1.756msUnicast reply from 192.168.0.101 [yy:yy:yy:yy:yy:yy]  2.070msSent 9 probes (9 broadcast(s))Received 9 response(s)

View 5 Replies View Related

Cisco Firewall :: Mask DMZ Servers From Private Servers And LAN ASA 5520

Jun 11, 2013

We are planning to split the Private servers from the DMZ Servers and configure an additional Interface and segment for this purpose.
 
Private Servers Segment: 192.168.4.0/24 (there is no DHCP all servers' IPs are statically configured)
DMZ Segment: 192.168.3.0/24 (This is a future deployment)
LAN Segment: 172.17.0.0/16
 
Both, Private Servers and DMZ Servers are in a collocation as well as the ASA5520. There are multiple Branch offices that uses subnets within the 172.17.0.0/16 Network and they are connected to the ASA5520 via Metro-E.
 
I do not know if this is possible but what I want to do is this:
 
In order to avoid the change of internal DNS records I want to mask the DMZ servers with a Private Server IP when a Private server or LAN host wants to access it like this:
 
The FTP server in the DMZ has the IP address: 192.168.3.100. But when a PC from the LAN wants to reach the FTP server it should points to its old IP: 192.168.4.100. This way the PC sends a packet to the ftp.corporate.net (192.168.4.100) the ASA recieves the packet and translate it to the (192.168.3.100) and send it out through the DMZ Interface.
 
Also if the Private Servers wants to reach the same FTP the ASA will act like a proxy-ARP and send the paquet to the DMZ by means of the translation of the IP.

View 6 Replies View Related

Servers :: Configure Toshiba Canvio HDD As A Server?

Nov 27, 2011

is there a owners manual for Toshiba Canvio Portable Hard Drives?

View 1 Replies View Related

Servers :: Configure Linux Server With LDAP?

May 31, 2011

the linux server should be configured with LDAP, so that any user should not login into that machine by local user credentials but by his intranet credentials.

View 1 Replies View Related

Servers :: Step To Configure LAN In Windows Server 2003

Apr 25, 2011

In my collage i have a LAN to the wind server 2003 again i m also configure a small LAN may be take a 5 computer but the communication is not done.

View 1 Replies View Related

Cisco WAN :: 4500 When NIC Configure With Teaming / Servers Gets Not Reachable

Jan 11, 2011

I have windows servers connected on cisco switch 4500 series. Issue is when server NIC configure with Teaming, some times servers gets not reachable, and after restarting the servers it gets reachable. Is 4500 series switch support the teaming software?

View 3 Replies View Related

Cisco VPN :: 888 Configure VRF With COOP Having Primary And Secondary Key Servers

Jun 19, 2012

We are trying to configure vrf aware GET VPN with COOP having primary and secondary key servers and also 3 GM routers. All GM routers we use are Cisco 888 and Key servers we use cisco 2911 routers. All GMs crypto maps have been applied into Vlan interface as there's no L3 interface on 888 routers.
 
Always members can form a tunnel with primary KS, we have configured redundancy with secondary key server and listed on each GM primary and secondary KS on GDOI group.
 
The issue we facing is that whenever we shutdown the primary or secondary servers the tunnel is not forming with available KS unless otherwise we mannually clear the crypto session. In another way when primary KS down it doest not fall back to secondary KS and no GM get registered. We have already played with all the timers such as DPD, SA lifetimes, GDOI rekey lifetime etc and also exchanging the keys (import/export) with KS and COOPs but there's no luck. We could see the following message was seen on both KS.
 
[code] 192.168.1.3 is the primary KS and 192.168.1.6 is the secondary KS.I captured attached debug output from 1 GM and secondary KS while I shutdonw the primary KS and also attached is our senario we were trying get work.
 
Also attached is the show output from both KSs when it form a tunnel with GM.

View 2 Replies View Related

TP-Link 300Mbps Wireless :: TL-WR1042ND How To Configure Virtual Servers

Nov 9, 2012

Region : Argentina
Model : TL-WR1043ND
Hardware Version : v1

I have read how to configure the Virtual Servers - Forwarding url...and added two entries, one for port 44612 and one for 32680 , my pc ip is 192.168.0. 100.Before I installed the router (my pc was connected directly to the lan connection) all was working just fine.And I double checked that the ports are not being blocked by firewall.

View 4 Replies View Related

Cisco Application :: Configure ACE 4710 For Load Balancing Speech Servers?

Sep 18, 2012

I'm configuring ACE 4710's for the first time and I want to load balance my Nuance speech servers on port 554. Here's my configuration on ACE01:
 
[code].....

View 23 Replies View Related

Cisco Switching/Routing :: C3750 - How To Configure 2 DHCP Servers For Two User Vlans

May 1, 2012

I can't seem to find any info on how to configure 2 DHCP server pools on a C3750, to use with 2 user vlans. The purpose is that users in vlan 1 should get an IP address from DHCP server1, and users in vlan 2 should get an IP address from DHCP server2. Both DHCP servers are configured in a stack of C3750 switches, which acts a a L2 switch.

View 2 Replies View Related

Cisco Application Networking :: How To Configure ACE 4710 Bypass Traffic From Servers To Internet

Jan 1, 2013

I'm looking for a way to configure Cisco ACE4710 loadbalancer to bypass traffic that is initiated from server side to Internet?Are there any way to configure this, so that the loadbalancer will not maintain session for this bypass traffic to maximize throughput?

View 1 Replies View Related

Cisco Firewall :: 5505 PAT With Single Public IP And Several Servers Behind Firewall

Nov 21, 2012

New to the ASA 5505 8.4 software version, but here is what I'm trying to do:
 
-Single static public IP:  16.2.3.4
-Need to PAT several ports to three separate servers behind firewall
-One server houses email, pptp server, ftp server and web services: 10.1.20.91
-One server houses drac management (port 445): 10.1.20.92
-One server is the IP phone server using a range of ports: 10.1.20.156
 
Basically, need to PAT the ports associated with each server to the respective servers behind the ASA 5505.  Is anything missing from this config? Do I need to include a global policy for PPTP and SMTP? [code]

View 11 Replies View Related

Cisco Firewall :: 6500 Cannot Ping The Servers Behind The Firewall

Feb 18, 2013

I have 2 modules of FWSM in 6500 switch (failover).I need 5 context.When I use in routed mode (like in the picture) , I cannot ping the servers behind the firewall. (I have ping to FW context),In transparent mode, it is not happening.what is the problem with routed mode?

View 1 Replies View Related

Cisco Firewall :: Putting Servers Behind ASA5505?

Jan 25, 2012

I am in the process of adding a lot of servers to sit behind our new ASA 5505 (8.4) firewall. At the moment I have added 2 servers and they are both NAT'ed to 2 different public IPs.
 
Server 1     192.168.10.1 -> 80.*.*.1
Server 2     192.168.10.111 -> 80.*.*.6
 
The first server can only be RDP'ed in to using its public IP which is what I want it to do. The second one has most of the service ports open like 443, 80, 110, 25 and etc. However when I try and browse externally to [URL]. I get an " Error 107(net::ERR_SSL_PROTOCOL_ERROR): SSL protocol error." in Google Chrome or any other browser. and the ASA reports:11:27:30192.168.10.111262680.*.*.6443Inbound TCP connection denied from 192.168.10.111/2626 to 80.*.*.6/443 flags SYN  on interface inside and I also get a Land to Land attack detected from 80.*.*.6 to 80.*.*.6
 
Is it worth setting up a DMZ or can I get away with the setup I have?

View 2 Replies View Related

Cisco Firewall :: ASA 5550 - Two Different Syslogs Servers?

Aug 9, 2010

In my Cisco ASA 5550, I need to set two different syslogs servers, and I need to send the system logs to the first one (only admins login/logout), and the traffic logs and all the rest (informational level) to the second one. Do you know if is it possible or not and, if yes, how to configure it?

View 6 Replies View Related

Cisco Firewall :: Mapping Servers Behind An ASA5505?

Nov 12, 2012

I have the following configuration: An ASA5505 with Security bundle license sits at the perimeter with a single public IP address assigned to VLAN2 (outside) out of a /29 block. I have two servers with static IP addresses of 10.70.21.6 and 10.70.21.7 connected to the inside ports with default gateway of 10.70.21.1 (which is the IP address for the VLAN1 inside). I have already configured a default static route and NATing (PAT) so we have internet connection for the PCs. Now I need to configure the ASA to allow remote desktop connection to the servers (with static IP addresses above). Can I use a spare public IP address for each server and if so, whats the syntax? or is there another method? I have used this before but I had a Cisco 2811 router on the perimeter so the syntax was at then: ip nat inside source static 10.30.1.248 81.85.199.44

View 6 Replies View Related

Cisco Firewall :: No Traffic To Public Servers PIX 515

Jun 8, 2011

Upgrading from a PIX 515 ,V6.2, I can get internet traffic out through the ASA , but no traffic in to the servers. The NATS are the same on the old firewall. The routers outside the firewalls are doing further natting from the .253 netwrok to a publilc address. No changes have taken place on the routers. [code]

View 3 Replies View Related

Cisco Firewall :: ASA 5520 - Allow Traffic Between DMZ Servers?

Dec 20, 2011

We can´t reach DMZ servers from other DMZ servers?If I make a ping from DMZ server to another, sometimes only recieve one ping, sometimes 4, sometimes 0.How can I allow the traffic between DMZ servers??
 
(ASA 5520 Version 8.4)

View 2 Replies View Related

Cisco Firewall :: ASA IOS 8.3 - Access To Servers At Company Out On Web?

Jul 26, 2011

I have a AD server that needs to access to servers at a company out on the web. it an asa the protocol is ldap
 
AD server 10.12.1.56 / 24

External servers 206.123.45.122, 174.87.96.143
 
ASA configuration
 
access-list outside permit tcp host 206.123.45.122 host 10.12.1.56 eq 389

access-list outside permit tcp host 174.87.96.143 host 10.12.1.56 eq 380

View 12 Replies View Related

Cisco Firewall :: ASA5550 - Set Up To Access Servers?

Nov 11, 2012

I am trying to set up an ASA5550 so that I can access the servers behind it. Simple.
 
As of now, I am unable to even create an access-list to allow traffic from my remote IP into the firewall. As far as my level of experience with Cisco firewalls, it's basically zero but I have taken the Cisco CCNAX class and feel that I have a good understanding of the fundamentals. That said, we only dealt with routers and switches, and it's not impossible that I'm missing something that would be totally obvious to most folks on this board. I've used CLI and ASDM with no success.
 
Here are the relevant parts of the config:

[code]...

View 6 Replies View Related

Servers :: Renewal Charges Of Hardware Firewall Is High

Aug 11, 2011

Is renewal charges of hardware firewall is high?I want to buy the hardware firewall for my office were about 20 comp are there and i heard that its renewal is very high is it true. i can spend rs 40-.50 k for firewall but it tough for me to pay renewal of 20 k every year, is this much high renewal i have to pay/

View 1 Replies View Related

Cisco Firewall :: Shared Public IP To Two Servers - ASA 5510 8.3 - NAT / PAT

Feb 5, 2012

I have a situation where we have a single DMZ server currently statically forwarded to a single public IP.  TCP ports 80, 443, 8080, 8500, 53, and 21 are open to this server via an access list.
 
However, we have added an additional server to the DMZ, and because our web developers did not communicate with me beforehand, we are forced to use the same DNS name (thus, the same piblic IP) for this server.  This server only needs traffic on TCP/8800 forwarded to it.
 
I am using ASDM 6.4 for configuration of this, as I am required to take multiple screen shots of the procedure for our change control policy.
 
My question lies in the reconfiguration of NAT/ PAT.  Since our current server has a single static NAT to a single public IP, it is simply natted for "any" port.  I understand that I can add the new server as an object, and only PAT it on TCP 8800, but will I then have to go back and reconfigure the first server multiple times for PAT, or will the ASA notice the specific PAT, and forward 8800 to the new server without affecting the existing "old" server?
 
It appears ASDM will not allow me to put multiple ports into a single network object.  I am assuming I will need to add 6 separate object translations for the "old" server based on TCP port, and 1 object translation for the "new" server, correct?

View 6 Replies View Related

Cisco Firewall :: Can't Access Internal Servers From Behind ASA 5505

Apr 3, 2013

I am having some trouble accessing some backup Email (Outlook Web Access) and Citrix servers located behind an ASA 5505 firewall at a remote datacentre. Simply put, when I go to the specific URL (e.g. [URL]) I do not arrive at the splash page, I just get a message saying that the server took too long to respond in the web browser. I'm wondering whether I have missed something on the configuration or the firewall itself is not letting my requests through. The remote servers are located at a remote Disaster Recovery site and use the subnet 192.168.4.0/24. I am at head office which is connected to the DR site via a VPN using 192.168.1.0/24.

[Code] .....

View 2 Replies View Related

Cisco Firewall :: How To Set Up NAT For Two Servers Using Same Port With ASDM ASA 5505

Apr 10, 2012

We have a new installation of a ASA 5505 and are trying to get some NAT issues straightened out. On our internal network, we have two servers running Filemaker Server, a relational database server that clients connect with using port 5003. Our goal is to be able to allow users from the outside to access either of these servers as needed. I know how to set up a simple static NAT rule and matching Access rule in ASDM which would be fine for a case in which only one server using a given port is running on a network, but for simple static rules I seem to be blocked from entering a different translated port number from the orginal port number, which becomes a problem when two servers we need to access from the outside are running software using the same port number.
 
What is the simplest way to address this need? I am guessing that I need to set up a scenario like this, where port 5004 (or any arbitrarily choosen unused port, can be used to access the second server: [code]

View 1 Replies View Related

Cisco Firewall :: Initial Connections To SQL Servers Timeout Through ASA 8.2(1)

Aug 23, 2012

I am on version 8.2(1) of ASA Code.When accessing a SQL server on a secure internal interface,(Traffic is sourcing from DMZ) i'm getting some timeouts on the initial connection on port 1433.   All subsequent connections work fine.   Packet tracer shows the connection builds properly, and shouldn't have a connectivity issue.   The problem server is a webserver that connects back through the firewall to access the SQL server on port 1433.    We also have many other webservers in the DMZ which access the same SQL server, but do not have the same timeout issues.   Here are my timeouts, from the config
 
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
arp timeout 14400
 
 I've seen a couple articles about increasing the tcp timeout to 3 hours for the DMZ interface?

View 1 Replies View Related

Cisco Firewall :: ASA 5505 Not Able To Access Internet And Outside To DMZ Servers

Jul 20, 2011

I have configured the ASA 5505 for internet access and outside users to use two servers in the DMZ. Every thing is working fine. When I was configure VPN, I did some mistake I guess, now inside users are not able to access internet. They get an error 405. Thats an error. The request method XXX is inappropriate for the URL /. Thats all we know. Even I am not able to access the server in the DMZ from outside and I get an error : Bad Request - Invalid HeaderThese things just happend after I did some thing on the ASA. I copy and pasted the my old configuration but still insider users are not able to connect to internet and from outside I am not ableto connect to server. The weired thing is that I can user VPN with out any issues. I can connect to vpn but I cant access any internal resources. Even inside users are able to ping internet addresses with out any issue.

View 2 Replies View Related

Cisco Firewall :: 5580 Need To NAT Addresses To Inside Servers

Jul 7, 2012

We are going to setup a L2L VPN with a vendor and they asked us to NAT a couple IP addresses for remote access to a couple of servers on our inside network. Our device is an ASA 5580 with version 8.1 and we have a handfull of public IP addresses for use if needed. The vendor's remote network is a public IP address but for this posting I will use 192.168.10.0. Our inside servers are 10.100.10.20 and 10.100.10.30. Because 10.100.10 is in use with another customer they asked us to NAT 10.77.97.20 and 10.77.97.30 to the two inside servers.

View 2 Replies View Related

Cisco Firewall :: ASA5510 Cannot Publish Internal Web Servers To Outside

Mar 26, 2013

Cisco ASA 5510  directly facing the internet on E0/0 (1 Public IP only) with internal  LAN on E0/1. Exchange 2010 OWA working fine with ACL and NAT rules  configured.Problem:

•1. Cannot publish internal web servers to outside, have tried PAT.
•2. Have multiple web servers to publish with all on one protocol (HTTP) to  a single public IP which I don’t know if it’s possible on a ASA.
•3.When SSL VPN is configured with Local user database, connecting from  Anyconnect client gives a certificate error. Upon viewing the  certificate it points to the internal mail server.

View 7 Replies View Related

Cisco Firewall :: ASA 5510 - Get Traffic Through Box To 4 Dedicated Servers

Apr 17, 2013

Recently moved into the hardware firewall space and have a ASA 5510. Having some issues trying to get traffic through the box to my 4 dedicated servers. all the servers have static IP's and are connected to a private switch into one of the ethernet ports on the firewall(0/2). Public internet connection into another(0/0). 1 of my servers has a connection to the management port, and the public switch, and this is the one im trying to do the configuration on.
 
Im unsure what to set the IP address of my "outside" interface as. need to have RDP,FTP, HTTP traffic going to each of the 4 servers independently, pretty sure i can get the rules in place to allow this, but cant seem to get any traffic to go through the firewall to any of the other 3 servers.

View 6 Replies View Related

Cisco Firewall :: ASA 5510 - How PAT With One Public IP To Two Internal Servers

Sep 18, 2012

I've tried a bunch things but it didn't work, I'm about to gave up! :-/
 
I have the following scenario:
 
ASA5510 - v8.3(2)
 
Interfaces
ETH0/0 = outside  = 189.xxx.xxx.129
ETH0/1 = inside = 10.xx.1.15

[Code]....

What should I do to get the SIP and 8080 port working on my Public IP, likewise just as access from my browse the http://189.xxx.xxx.129:8080 and get through directly to my internal server 10.xx.xx.61 ?

View 5 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved