Question

ASA 5505 initial configuration

Asked by: bkana

I recently purchased a ASA 5505 and need some assistance in the initial setup. I only need 2 VLANS, business and outside. I used the ASDM Sart up wizard to configure the device in hopes that I would, at least, be able to connect to the internet. I am using the 192.168.0.1-255 address scheme for all inside hosts and have Public address range of 216.64.x.x consisting of 15 addresses. Using my old firewall settings I used 192.168.1.1 (default on the 5505) for the inside interface and 216.64.x.2 for the outside. Would someone be able to work with me in setting up the firewall? I have a very basic network infrastructure with only a few needs for NAT, ie: SMTP, HTTP, HTTPS.

Regards,
Bill

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2007-03-26 at 11:00:09ID22473057
Tags

asa

,

5505

,

configuration

Topics

Networking Hardware Firewalls

,

Network Software Firewalls

,

Cisco PIX Firewall

Participating Experts
2
Points
500
Comments
37

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. ASA initial configuration
    Experts, I am trying to configure an ASA 5505 for the first time in a home network. I am very new to Cisco, so please be verbose and patient :) . I will provide a quick description of the setup, followed by some numbered questions, and then the running config at the end of...
  2. ASDM
    hello, Im trying to download ASDM for asa 5510 from the cisco website but its saying I need to have a service aggreement to download it. I do not have a service aggreement anymore and i lost the cds of my equipment. Where else can I download the utility?
  3. Access ASA via ASDM via VPN
    I currently use a remote access VPN connection to reach a client's VLAN that is a sub-interface on an ASA 5510 Security Plus. I can ping and access all network devices instead of 192.168.100.1 which is the gateway for said sub-interface. Because I cannot ping or access the ga...
  4. Unable to access ASDM on Cisco ASA 5505 FIrewall
    Any one know how I can access the asdm on a ASA-5505? I'm pretty retarded when it comes to Cisco appliances. when i go to http://x.x.x.x/admin nothing loads. Here is my running config : Saved : ASA Version 7.2(2) ! hostname organic-asa domain-name changed.com ena...
  5. ASA 5505 VLAN Help
    Hello, I have an ASA 5505 Security Plus firewall fresh from the box that I am trying to configure, but continuously run into a problem where vlans on the firewall will not communicated with each other. We have 2 ISPs and 4 internal subnets. I have configured the firewal...
  6. ASA 5505 ASDM configuration
    We have a new ASA 5510 and are trying to use the ASDM when you load the program and connect to the device it seems to load and then says unable to read configuration from device and to check the configuration. However if you put the ASA's IP address in a browser and select ru...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: MrHusyPosted on 2007-03-26 at 11:19:59ID: 18794845

    Can you please post your running config. In CLI, type sh run and paste the output please.

 

by: bkanaPosted on 2007-03-26 at 11:28:51ID: 18794913

Sure, here it is. Your probably going to have a lot of questions, as I haven't done much to set it up yet.

Result of the command: "sh run"

: Saved
:
ASA Version 7.2(2)
!
hostname ciscoasa
domain-name audiology.org
enable password ulzaQiFnKVzDwUmW encrypted
names
!
interface Vlan1
 nameif inside
 security-level 100
 ip address 192.168.1.1 255.255.255.0
!
interface Vlan2
 nameif outside
 security-level 0
 ip address 216.64.78.2 255.255.255.240
!
interface Vlan3
 shutdown
 no forward interface Vlan1
 nameif dmz
 security-level 50
 no ip address
!
interface Ethernet0/0
 switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
passwd 2KFQnbNIdI.2KYOU encrypted
ftp mode passive
dns server-group DefaultDNS
 domain-name audiology.org
same-security-traffic permit intra-interface
pager lines 24
logging enable
logging asdm informational
mtu inside 1500
mtu outside 1500
mtu dmz 1500
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-522.bin
no asdm history enable
arp timeout 14400
global (outside) 1 216.64.78.3-216.64.78.12 netmask 255.255.255.255
nat (inside) 1 0.0.0.0 0.0.0.0
route outside 0.0.0.0 0.0.0.0 216.64.78.1 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout uauth 0:05:00 absolute
http server enable
http 192.168.1.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
telnet timeout 5
ssh timeout 5
console timeout 0
dhcpd auto_config outside
!
dhcpd address 192.168.1.2-192.168.1.129 inside
!

!
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect esmtp
  inspect sqlnet
  inspect skinny
  inspect sunrpc
  inspect xdmcp
  inspect sip
  inspect netbios
  inspect tftp
!
service-policy global_policy global
prompt hostname context
Cryptochecksum:f815428ef39f2bd2773d754d076546f9
: end

 

by: MrHusyPosted on 2007-03-26 at 12:14:22ID: 18795269

       What type is your connection type to internet? DSL?
        What device are you using to connect to internet?        

 

by: bkanaPosted on 2007-03-26 at 12:16:33ID: 18795285

It is a T-1 solution running through a Cisco IAD2400

 

by: bkanaPosted on 2007-03-27 at 05:32:39ID: 18799298

MrHusy,

Do you have any further information regarding this? I need to get this firewall operational and your help would be greatly appreciated.

 

by: MrHusyPosted on 2007-03-27 at 05:40:33ID: 18799361

    Too little points to spend so much time on m8 sorry :(. I though it was 500, somehow your question passed my filter.

 

by: bkanaPosted on 2007-03-27 at 05:47:30ID: 18799403

I understand - Could you at least pass it on to someone who might be able to help me or post a couple of quick responses to what has been given so far? Maybe a couple of things I could change just to get started?


 

by: bkanaPosted on 2007-03-27 at 05:57:16ID: 18799454

I have increased the point value on this question.

 

by: MrHusyPosted on 2007-03-27 at 06:42:04ID: 18799733

      Dont worry, now you increased the points and this question will pass the filter of Irmoore :)
       Never used to work together with Cisco IAD2400 but in my opinion, Cisco IAD2400 already supposed to acquire the reserverd ips (216.x.x.x) as public (global) and there supposed to be another local newtwork (like 192.168.1.0 or 172.16.1.0) between one interface of Cisco IAD2400 and outside interface of PIX. Therefore you mustn't assign your global ip addresses to PIX as interface ip or global range.

 

by: bkanaPosted on 2007-03-27 at 06:51:27ID: 18799828

Yes, except my local network is 192.168.0.1-255 (does it matter that it's not 192.168.1.0?) Could you explain more about the global range? What do I assign to my outside interface then? I thought you assign one of your public ips to the outside interface. So, do I need to first remove the 216.64.x.x - 216.64.x.x range from my gloabl (outside) interface?

 

by: MrHusyPosted on 2007-03-27 at 07:54:10ID: 18800353

     If the statement below is correct,

             outside↓                   ↓inside      outside↓         ↓inside
                     int0                  int1                       int0     int1
Internet-----T1------Cisco IAD2400------------------PIX-------------Inside network
↑------216.64.x.x------↑       ↑-----------?------------↑  ↑--192.168.0.0/24---↑                                  

   *I assume that statement above is correct, so you will need another network to the ? place for NAT.
   *It doesn't matter if its 1.0 or not. An ip address ending with 0 means the subnet. In your condition 192.168.0.0/24 is your subnet (24 means 255.255.255.0 subnetmask and 192.168.0.0 means 192.168.0.1-192.168.0.254)
   I Want to ask some questions  
   *Plug the network cable, which is coming from Cisco IAD2400 to a random PC, and check what IP , dns server, subnetmask and gateway addresses does the PC acquire from Cisco IAD2400. Then I can build you a configuration.
    *Again if the statement above is correct, you shuld do the global assignments in Cisco IAD2400.

 

by: bkanaPosted on 2007-03-27 at 08:33:57ID: 18800698

Thanks for the info.

I put a laptop on the IAD and configured the laptop for DHCP - but I don't think the IAD threw the right information or any at all. When I ran ipconfig /all I got an IP of 169.254.99.161 and a mask of 255.255.0.0

The above statement is correct, but I do not have access to the IAD2400 - it was installed by my ISP when we upgraded to our current Dynamic T-3 solution. My current (old) firewall has 216.64.x.2 as it's outside address (at least that's what it appears to be in the configuration). Can't we just mirror that on the ASA 5505 or put that address as the outside address?

 

by: MrHusyPosted on 2007-03-27 at 08:45:47ID: 18800818

       So we should go on according to your old firewall's config. Can you please post the both your old firewall's and ASA 5505's current running configs?

 

by: bkanaPosted on 2007-03-27 at 10:48:08ID: 18801855

I don't have a CLI file for the old firewall persay, but I can give you all the parameters and how it is setup:
The following are the only settings configured on the old firewall:
Interface Configuration:
Interface Name - untrust
IP = 216.64.x.2
mask = 255.255.255.240
Gateway = 216.64.78.1

Interface Name - trust
IP=192.168.0.1
mask = 255.255.255.0
no gateway defined

There is a "Mapped IP" option on the untrust section that has some entry's that map my public addresses to my inside private addresses such as 216.64.x.10  mapped to 192.168.0.62 for my mail server with a mask of 255.255.255.255. I have about 8 mapped that way for things like a web server and RDP

There is also a Static Route section that has:
192.168.0.0, mask of 255.255.255.0, gateway of 0.0.0.0 with the interface being trust and metric of 0
216.64.x.0, mask of 255.255.255.240, gateway of 0.0.0.0 with the interface being untrust and metric 0
0.0.0.0, mask of 0.0.0.0, gateway of 216.64.78.1, with the untrust interface, metric 1

There is an address section with two tabs, trust and untrust
on the trust tab there is an entry called mycompany Internal:
IP/Domain name: 192.168.0.0
mask = 255.255.255.0
trust location

There's also one called Inside Any with 0.0.0.0 for both ip and mask

There's a Policy section with two tabs as well: incoming and outgoing
on the outgoing tab there a few entries
Source                               Destination                 Service                  NAT           Action

Inside Any                           Outside Any               NetBios                  N/A            deny
companynameInternal         Outside Any               Any                       yes             allow
comaonynameInternal         Outside Any               https                      N/A             allow

Hers is the current ASA 5505 config:

Result of the command: "sh run"

: Saved
:
ASA Version 7.2(2)
!
hostname ciscoasa
domain-name audiology.org
enable password xxxxxxxxxxxxxxrypted
names
!
interface Vlan1
 nameif inside
 security-level 100
 ip address 192.168.1.1 255.255.255.0
!
interface Vlan2
 nameif outside
 security-level 0
 ip address 216.64.78.2 255.255.255.240
!
interface Vlan3
 shutdown
 no forward interface Vlan1
 nameif dmz
 security-level 50
 no ip address
!
interface Ethernet0/0
 switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
passwd 2KFQnbNIdI.2KYOU encrypted
ftp mode passive
dns server-group DefaultDNS
 domain-name audiology.org
same-security-traffic permit intra-interface
pager lines 24
logging enable
logging asdm informational
mtu inside 1500
mtu outside 1500
mtu dmz 1500
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-522.bin
no asdm history enable
arp timeout 14400
global (outside) 1 216.64.78.3-216.64.78.12 netmask 255.255.255.240
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0
route inside 216.64.78.0 255.255.255.0 216.64.78.1 1
route outside 0.0.0.0 0.0.0.0 216.64.78.1 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout uauth 0:05:00 absolute
http server enable
http 192.168.1.0 255.255.255.0 inside
http 192.168.0.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
telnet timeout 5
ssh timeout 5
console timeout 0
dhcpd auto_config outside
!
dhcpd address 192.168.1.2-192.168.1.129 inside
!

!
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect esmtp
  inspect sqlnet
  inspect skinny
  inspect sunrpc
  inspect xdmcp
  inspect sip
  inspect netbios
  inspect tftp
!
service-policy global_policy global
prompt hostname context
Cryptochecksum:7e0a014cbb4ffc245596f4e47f79b763
: end

 

by: MrHusyPosted on 2007-03-27 at 14:27:36ID: 18803741

then your configuration is OK except the following route
route inside 216.64.78.0 255.255.255.0 216.64.78.1 1

remove it by typing
no route inside 216.64.78.0 255.255.255.0 216.64.78.1 1

then
wr mem
cl xl

A question= Are your web servers and etc in inside interface hast static IPs like 192.168.0.62 mail server? If yes, we should define the default PIX inside interface and DHCP pool as 192.168.0.1 so you wont spend time on configuring clients.
    Get into CLI and do following.

enable
"type your pass"
conf t
conf fac 192.168.0.1 255.255.255.0
"press enter till you see your firewall hostname"
wr mem
rel
"press enter to reload"

         Now your inside interface is 192.168.0.1. Lets go on configuration

enable
"type your pass"
conf t

int eth0
nameif outside
no shu
dup au
ip add 216.64.78.2 255.255.255.240
sec 0
quit

int eth1
nameif inside
no shu
dup au
sec 100
quit

route outside 0 0 216.64.78.1
nat (inside) 1 0 0
global (outside) 1 216.64.78.3-216.64.78.12 netmask 255.255.255.240

"now time for static NAT mappings"

static (inside,outside) 216.64.78.10 192.168.0.62 netmask 255.255.255.255
access-list mailserver permit tcp any host 216.64.78.10 eq smtp
access-list mailserver permit icmp any any  "this is for ping,just check connectivty,remove if you want"
access-group mailserver in interface outside

"lets say that your terminal server is 192.168.0.60 in inside and global ip is 216.64.78.11. Then do following

static (inside,outside) 216.64.78.11 192.168.0.60 netmask 255.255.255.255
access-list termserver permit tcp any host 192.168.0.60 eq 3389
access-group termserver in interface outside

        ACLs above permit anyone from outside to connect to related global ip. If you like to permit only one ip to connect from internet to related ip, type   host x.x.x.x   instead  any    If you like to give only a few IPs to access, then you should create an object group. If you need object-grouping tell me and ill explain it too.

 

by: bkanaPosted on 2007-03-27 at 14:42:22ID: 18803828

Let me clarify a few things, what do you mean by:
then
wr mem
cl xl

and

enable
"type your pass" (is this my password that I setup for accessing the firewall?)
conf t

Are those just commands in the CLI?

And, yes all of my servers (mail, web, ect) are inside and all have a static address using the 192.168.0.3-255 addresses scheme. I have IP mappings setup on the old firewall to public addresses for things like smpt, and https. I only have 30 clients without DHCP on the network - I have them all set to static IP's. Do I still need DHCP?

I do not have a terminal server, but I get the idea. I'll do what you posted and get back with you.




Also,

 

by: MrHusyPosted on 2007-03-27 at 14:54:44ID: 18803912

         *Yes they are just CLI commands except "then", "and" and the phrases in "... ".
          *Yes it is the password for accessing firewall.
          *You dont need DHCP, so you can disable it with the following command when you are in config t mode.

no dhcpd enable inside
         
          *Please post the latest running config of your PIX. We would start implementing vlans after ve provide basic connection.

 

by: bkanaPosted on 2007-03-28 at 04:48:15ID: 18807173

Here is the latest config. I had a little trouble running the commands for eth0 and eth1, but I'm assuming we were trying to configure the outside interface with 216.64.x.2 with security set to 0, correct? If so, I went ahead and did it in the gui. Can you tell from the config that I did it properly. I also setup one mapping for my mail sevrer. I have others I would like to do though.

Couple of questions before we move on:
1. What do these commands do: "wr mem"   "conf t"   "nu shu" "dup au"
and what does the "access-group mailserver in interface outside" command do?


Result of the command: "sh run"

: Saved
:
ASA Version 7.2(2)
!
hostname ciscoasa
domain-name default.domain.invalid
enable password ulzaQiFnKVzDwUmW encrypted
names
!
interface Vlan1
 nameif inside
 security-level 100
 ip address 192.168.0.1 255.255.255.0
!
interface Vlan2
 nameif outside
 security-level 0
 ip address 216.64.78.2 255.255.255.240
!
interface Ethernet0/0
 switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
passwd 2KFQnbNIdI.2KYOU encrypted
ftp mode passive
dns server-group DefaultDNS
 domain-name default.domain.invalid
access-list mailserver extended permit tcp any host 216.64.78.10 eq smtp
pager lines 24
logging enable
logging asdm informational
mtu outside 1500
mtu inside 1500
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-522.bin
no asdm history enable
arp timeout 14400
global (outside) 1 216.64.78.3-216.64.78.12 netmask 255.255.255.240
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0
static (inside,outside) 216.64.78.10 192.168.0.62 netmask 255.255.255.255
access-group mailserver in interface outside
route outside 0.0.0.0 0.0.0.0 216.64.78.1 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout uauth 0:05:00 absolute
http server enable
http 192.168.0.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
telnet timeout 5
ssh timeout 5
console timeout 0
dhcpd auto_config outside
!
dhcpd address 192.168.0.2-192.168.0.129 inside
!

!
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect esmtp
  inspect sqlnet
  inspect skinny
  inspect sunrpc
  inspect xdmcp
  inspect sip
  inspect netbios
  inspect tftp
!
service-policy global_policy global
prompt hostname context
Cryptochecksum:7b79511728a54eaaf624771524c0916f
: end

 

by: MrHusyPosted on 2007-03-28 at 05:36:49ID: 18807436

1. What do these commands do: "wr mem"   "conf t"   "nu shu" "dup au"
and what does the "access-group mailserver in interface outside" command do?
      Wr mem=write memory: writes your current config to memory permenantly
      conf t=configure terminal: allows you to enter config mode. You can make essential configurations under that node. a (config) appears nect to your PIX device's hostname in CLI
     no shu=no shutdown: enables the interface
     dup au=duplex auto: sets the interface duplex to auto.

"and what does the "access-group mailserver in interface outside" command do?
we created an access list (ACL) named mailserver by typing
access-list mailserver extended permit tcp any host 216.64.78.10 eq smtp
and we tagged this acl to outside interface by
access-group mailserver in interface outside
   
     Interface Vlan1, and Interface Vlan2  ? Did you set these from GUI?

 

by: bkanaPosted on 2007-03-28 at 05:57:20ID: 18807562

Thanks for the info!

So basically we can create as many ACL's as we like, give them a name, and then use that name on one of the interfaces to activate it per say, or put it in use. The ACL's are sort of like the IP Mappings I had on my old firewall that would allow certain services such as SMTP, HTTPS, etc to traverse the firewall, correct?

Yes, I setup the Vlans through the GUI. Looking at the Interfaces tab, the outside interface is marked as Vlan2 and the inside is marked as Vlan1. Vlan2 is using the switched port of Ethernet0/0 and the rest are being used by Vlan1 for the inside. I think the running config shows the interfaces as being Vlan1 and Vlan2 - is that not correct?

 

by: MrHusyPosted on 2007-03-28 at 06:16:31ID: 18807701

          I think in your old firewall, that IP mapping function was providing both access configuration and mapping. But in PIX, IP mapping is provided by static command, and allow/deny access configurations are provided by ACLs. ACLs allow SMTP, HTTPS etc.

static (inside,outside) 216.64.78.10 192.168.0.62 netmask 255.255.255.255 "provides ip mapping"
access-list mailserver permit tcp any host 216.64.78.10 eq smtp "configure access permission (smtp in example)"
access-group mailserver in interface outside "tagging the ACL to related interface"
             If your network with that configuration, then that means your Vlan config is correct.
            Could you please post me the output of sh int command in CLI?

 

by: bkanaPosted on 2007-03-28 at 06:32:02ID: 18807837

Thanks for clarifying the commands and thier respective meanings. Here is the output of the sh int command:

Keep in mind that I do not have the firewall connected to my network/IAD yet.

Result of the command: "sh int"

Interface Vlan1 "inside", is up, line protocol is up
  Hardware is EtherSVI
      MAC address 0019.0726.0bfe, MTU 1500
      IP address 192.168.0.1, subnet mask 255.255.255.0
  Traffic Statistics for "inside":
      35034 packets input, 2605959 bytes
      26742 packets output, 11912832 bytes
      2132 packets dropped
      1 minute input rate 10 pkts/sec,  770 bytes/sec
      1 minute output rate 7 pkts/sec,  2871 bytes/sec
      1 minute drop rate, 0 pkts/sec
      5 minute input rate 10 pkts/sec,  786 bytes/sec
      5 minute output rate 7 pkts/sec,  2911 bytes/sec
      5 minute drop rate, 0 pkts/sec
Interface Vlan2 "outside", is down, line protocol is down
  Hardware is EtherSVI
      MAC address 0019.0726.0bfe, MTU 1500
      IP address 216.64.78.2, subnet mask 255.255.255.240
  Traffic Statistics for "outside":
      0 packets input, 0 bytes
      0 packets output, 0 bytes
      0 packets dropped
      1 minute input rate 0 pkts/sec,  0 bytes/sec
      1 minute output rate 0 pkts/sec,  0 bytes/sec
      1 minute drop rate, 0 pkts/sec
      5 minute input rate 0 pkts/sec,  0 bytes/sec
      5 minute output rate 0 pkts/sec,  0 bytes/sec
      5 minute drop rate, 0 pkts/sec
Interface Ethernet0/0 "", is down, line protocol is down
  Hardware is 88E6095, BW 100 Mbps
      Auto-Duplex, Auto-Speed
      Available but not configured via nameif
      MAC address 0019.0726.0bf6, MTU not set
      IP address unassigned
      0 packets input, 0 bytes, 0 no buffer
      Received 0 broadcasts, 0 runts, 0 giants
      0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
      0 L2 decode drops
      0 switch ingress policy drops
      0 packets output, 0 bytes, 0 underruns
      0 output errors, 0 collisions, 0 interface resets
      0 babbles, 0 late collisions, 0 deferred
      0 lost carrier, 0 no carrier
      0 rate limit drops
      0 switch egress policy drops
Interface Ethernet0/1 "", is up, line protocol is up
  Hardware is 88E6095, BW 100 Mbps
      Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)
      Available but not configured via nameif
      MAC address 0019.0726.0bf7, MTU not set
      IP address unassigned
      35735 packets input, 3448660 bytes, 0 no buffer
      Received 500 broadcasts, 0 runts, 0 giants
      0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
      0 L2 decode drops
      4 switch ingress policy drops
      27198 packets output, 12701821 bytes, 0 underruns
      0 output errors, 0 collisions, 0 interface resets
      0 babbles, 0 late collisions, 0 deferred
      0 lost carrier, 0 no carrier
      0 rate limit drops
      0 switch egress policy drops
Interface Ethernet0/2 "", is down, line protocol is down
  Hardware is 88E6095, BW 100 Mbps
      Auto-Duplex, Auto-Speed
      Available but not configured via nameif
      MAC address 0019.0726.0bf8, MTU not set
      IP address unassigned
      0 packets input, 0 bytes, 0 no buffer
      Received 0 broadcasts, 0 runts, 0 giants
      0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
      0 L2 decode drops
      0 switch ingress policy drops
      0 packets output, 0 bytes, 0 underruns
      0 output errors, 0 collisions, 0 interface resets
      0 babbles, 0 late collisions, 0 deferred
      0 lost carrier, 0 no carrier
      0 rate limit drops
      0 switch egress policy drops
Interface Ethernet0/3 "", is down, line protocol is down
  Hardware is 88E6095, BW 100 Mbps
      Auto-Duplex, Auto-Speed
      Available but not configured via nameif
      MAC address 0019.0726.0bf9, MTU not set
      IP address unassigned
      0 packets input, 0 bytes, 0 no buffer
      Received 0 broadcasts, 0 runts, 0 giants
      0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
      0 L2 decode drops
      0 switch ingress policy drops
      0 packets output, 0 bytes, 0 underruns
      0 output errors, 0 collisions, 0 interface resets
      0 babbles, 0 late collisions, 0 deferred
      0 lost carrier, 0 no carrier
      0 rate limit drops
      0 switch egress policy drops
Interface Ethernet0/4 "", is down, line protocol is down
  Hardware is 88E6095, BW 100 Mbps
      Auto-Duplex, Auto-Speed
      Available but not configured via nameif
      MAC address 0019.0726.0bfa, MTU not set
      IP address unassigned
      0 packets input, 0 bytes, 0 no buffer
      Received 0 broadcasts, 0 runts, 0 giants
      0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
      0 L2 decode drops
      0 switch ingress policy drops
      0 packets output, 0 bytes, 0 underruns
      0 output errors, 0 collisions, 0 interface resets
      0 babbles, 0 late collisions, 0 deferred
      0 lost carrier, 0 no carrier
      0 rate limit drops
      0 switch egress policy drops
Interface Ethernet0/5 "", is down, line protocol is down
  Hardware is 88E6095, BW 100 Mbps
      Auto-Duplex, Auto-Speed
      Available but not configured via nameif
      MAC address 0019.0726.0bfb, MTU not set
      IP address unassigned
      0 packets input, 0 bytes, 0 no buffer
      Received 0 broadcasts, 0 runts, 0 giants
      0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
      0 L2 decode drops
      0 switch ingress policy drops
      0 packets output, 0 bytes, 0 underruns
      0 output errors, 0 collisions, 0 interface resets
      0 babbles, 0 late collisions, 0 deferred
      0 lost carrier, 0 no carrier
      0 rate limit drops
      0 switch egress policy drops
Interface Ethernet0/6 "", is down, line protocol is down
  Hardware is 88E6095, BW 100 Mbps
      Auto-Duplex, Auto-Speed
      Available but not configured via nameif
      MAC address 0019.0726.0bfc, MTU not set
      IP address unassigned
      0 packets input, 0 bytes, 0 no buffer
      Received 0 broadcasts, 0 runts, 0 giants
      0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
      0 L2 decode drops
      0 switch ingress policy drops
      0 packets output, 0 bytes, 0 underruns
      0 output errors, 0 collisions, 0 interface resets
      0 babbles, 0 late collisions, 0 deferred
      0 lost carrier, 0 no carrier
      0 rate limit drops
      0 switch egress policy drops
Interface Ethernet0/7 "", is down, line protocol is down
  Hardware is 88E6095, BW 100 Mbps
      Auto-Duplex, Auto-Speed
      Available but not configured via nameif
      MAC address 0019.0726.0bfd, MTU not set
      IP address unassigned
      0 packets input, 0 bytes, 0 no buffer
      Received 0 broadcasts, 0 runts, 0 giants
      0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
      0 L2 decode drops
      0 switch ingress policy drops
      0 packets output, 0 bytes, 0 underruns
      0 output errors, 0 collisions, 0 interface resets
      0 babbles, 0 late collisions, 0 deferred
      0 lost carrier, 0 no carrier
      0 rate limit drops
      0 switch egress policy drops

 

by: MrHusyPosted on 2007-03-28 at 06:46:47ID: 18807949

      You are welcome.
           You should start processing the implementation of PIX into your environment at a time when your company is not working for at least 3 hours.
           And also please apply the commands below for syslog get enabled and feedback you.
           
          logging on
          logging trap 7
          logging que 150
          wr mem

Logs will appear in ASDM window.

 

by: bkanaPosted on 2007-03-28 at 06:59:06ID: 18808055

Are you recommending 3 hours due to the IAD and or ASA having to "learn" about each other and the new device. I understand arp cache also has something to do with it, correct. I might have time this afternoon to connect it to my network and begin troubleshooting (if need be).

Also, can I assume that by default the ASA will not permit anything to come in to the network, unless otherwise explicitly told to do so? I will contact you when I am ready to connect it.

 

by: MrHusyPosted on 2007-03-28 at 07:17:39ID: 18808224

          Adaptive Security Algorithm, is set to permit traffic flow from higher security interface to lower security interface and block traffic from lower sec to higher one. And you will permit the traffic with acls.
          Always calculate the worst possiblity and recover back time to running config if implementation fails. I recommend you to workaround with some examples in a test environment with PIX.

 

by: bkanaPosted on 2007-03-28 at 08:24:08ID: 18808829

What I can do is connect one of my Windows 2003 member servers and a copule of test PC's to my extra hub and us that for testing.

 

by: MrHusyPosted on 2007-03-28 at 08:39:19ID: 18808995

            That is enough too. Use PIX in this small test environment, ask me the problems you ancounter and get used to PIX.

 

by: bkanaPosted on 2007-03-30 at 03:55:08ID: 18822454

Good news, I connected the firewall to my network, reset the IAD and I was able to connect to the internet. Sent a few test e-mails and e-mail seems to be working as well.

Now: I had several other mappings on the old firewall to allow certain services like RDP, HTTPS, SSL. I think I can configure the HTTP ones with the examples you gave me. But what about RDP - do I have to find out the port used by RDP to set it up? In one of your earlier examples, I typed in eq smtp for mail. What would be the one for "RDP"? Is the following command correct for setting up the mapping:

static (inside,outside) 216.64.x.12 192.168.0.212 netmask 255.255.255.255  (this is for accessing my pc via RDP)
How do I right the access-list command for this one?

 

by: MrHusyPosted on 2007-03-30 at 06:33:31ID: 18823140

access-list outside_access_in permit any host 216.64.78.12 eq 3389
access-group outside_access_in in interface outside

 

by: bkanaPosted on 2007-03-30 at 06:41:37ID: 18823197

Thanks MrHusy.

Can you verify my current config below. This is without the above entires but I added two for HTTP and HTTPS to the same server and it looks like it added them to the "mailserver" tag. They do work though.
I'm a little confused about the access-group command and the access-list outside_in statements in the current config.

Result of the command: "sh run"

: Saved
:
ASA Version 7.2(2)
!
hostname ciscoasa
domain-name default.domain.invalid
enable password ulzaQiFnKVzDwUmW encrypted
names
!
interface Vlan1
 nameif inside
 security-level 100
 ip address 192.168.0.1 255.255.255.0
!
interface Vlan2
 nameif outside
 security-level 0
 ip address 216.64.78.2 255.255.255.240
!
interface Ethernet0/0
 switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
passwd 2KFQnbNIdI.2KYOU encrypted
ftp mode passive
clock timezone EST -5
clock summer-time EDT recurring
dns server-group DefaultDNS
 domain-name default.domain.invalid
access-list mailserver extended permit tcp any host 216.64.78.10 eq smtp
access-list mailserver extended permit tcp any host 216.64.78.4 eq https log
access-list mailserver extended permit tcp any host 216.64.78.4 eq www
access-list outside_in extended permit tcp any host 216.64.78.4 eq https
access-list outside_in extended permit tcp any host 216.64.78.4 eq www
pager lines 24
logging enable
logging trap debugging
logging asdm informational
logging queue 150
mtu outside 1500
mtu inside 1500
ip verify reverse-path interface outside
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-522.bin
no asdm history enable
arp timeout 14400
global (outside) 1 216.64.78.3-216.64.78.12 netmask 255.255.255.240
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0
static (inside,outside) 216.64.78.10 192.168.0.62 netmask 255.255.255.255
static (inside,outside) 216.64.78.4 192.168.0.4 netmask 255.255.255.255
access-group mailserver in interface outside
route outside 0.0.0.0 0.0.0.0 216.64.78.1 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout uauth 0:05:00 absolute
http server enable
http 192.168.0.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
telnet timeout 5
ssh timeout 5
console timeout 0
dhcpd auto_config outside
!
dhcpd address 192.168.0.2-192.168.0.129 inside
!

!
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect esmtp
  inspect sqlnet
  inspect skinny
  inspect sunrpc
  inspect xdmcp
  inspect sip
  inspect netbios
  inspect tftp
  inspect icmp
!
service-policy global_policy global
prompt hostname context
Cryptochecksum:e9422190102b4c2d9c49bab8522241ed
: end



 

by: MrHusyPosted on 2007-03-30 at 06:57:16ID: 18823305

          Ahh sorry Bill, working on so many PIX issues that i forgot your config once. It doesn't differ, my command  above works too but we alreeady have a acl name, so we better go on with it and not create multiple names. So it has to be as folowing

access-list outside_in permit any host 216.64.78.12 eq 3389
access-group outside_in in interface outside

or if you like, you may name your acl according to your protocol

access-list RDP_Allowpermit any host 216.64.78.12 eq 3389
access-group RDP_Allow in in interface outside

acl names do not matter since you tag it to interface with access-group command. I named it as mailserver coz rules war all related about your mailserver. You may change as you wish.

 

by: bkanaPosted on 2007-03-30 at 08:39:25ID: 18824204

No worries, I understand how busy you must be.

When I used the "access-group outside_in in interface outside" it cleared all of my previous entires and I had to use the GUI under Security Policy to re-add the permits for SMTP and HTTPS. It's all working now though. I think I got the hang of it now. I know you prefer to use the CLI - but how do I view the various acl's in the gui? It's not that big of a deal. And, one more question: Is "tagging it to an interface" the same as "Adding an Access Rule" on one of the interfaces under the Security Plicy in the GUI?

I really appreciate all of your help on this - only wish I could return the favor! I may ask a copule of more questions in the upcoming week, but for now I think I got it!  Thanks again!

 

by: MrHusyPosted on 2007-03-30 at 09:12:45ID: 18824463

         You are welcome Bill.
               *GUI is just some graphics for people to understand better and not to memorize so many commands. There must be an option in Options/Tools or preferences in GUI that shows you first what you have done (as CLI codes) and then sends to PIX. So you would be able to see which commands does GUI send to PIX when you make config.
               *"access-group outside_in in interface outside"  shouldn't clear previous entries. Somethin must ve gone wrong.
                *When you add an ACL via GUI, GUI writes the ACL then tags it to the interface. You wont need extra operation. You would see that it uses access-group command after access-list automatically ,if you enable the option in GUI that i mentioned above.

See you in upcoming questions :)

 

by: MrHusyPosted on 2007-04-02 at 05:16:29ID: 18835628

          Hello Bill
              If my assistance was helpful for you, please accept one of my posts as an answer with a deserved grade.
              Thank You.

 

by: bkanaPosted on 2007-04-02 at 05:19:19ID: 18835647

Got it!

The only thing I have left to do is setup VPN. I ran through the VPN wizard to setup Remote Access, went home and loaded the Cisco VPN Client (4.6), but couldn't connect. I'm assuming the host you connect to is the outside interface of the ASA correct? Do most people use the Cisco client to connect or do they use the built-in Microsoft client? I know I have to setup a few things on the ASA first, but am unclear as how to do so.

 

by: MrHusyPosted on 2007-04-02 at 05:27:46ID: 18835690

           Hi Bill,
                Most people use Cisco client for more security and the interface differs according to your needs. Configuring VPN is a different issue, so should be asked in a new question.
                Regards.

 

by: ralphcarter2008Posted on 2008-03-07 at 13:29:37ID: 21074279

yes it is the outside interface IP that you connect to with the client.

under group authentication of the vpn client, make sure the Name: is spelled exactly as it is in your config, case sensitive.

Under password: make sure you have the exact Pre-shared Key:

Then when you connect you should be assigned an IP that you defined in your DHCP Pool for VPN. Make sure your inside routers  (if any) know how to get to this VPN pool subnet.

And dont try to VPN in from the inside of your network!

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...