Advertisement

04.08.2008 at 03:06PM PDT, ID: 23306461
[x]
Attachment Details

How do I allow web, ping, rdp etc. into ASA 5505

Asked by cyberdragon666 in IPSec Security Protocol, Virtual Private Networking (VPN), Cisco PIX Firewall

Tags: Cisco, ASA, 5505

I have a Cisco ASA 5505 running version 8.0
For some reason this seems to be pretty different from the previous version code.
I have it set up for a site to site VPN and remote access vpn with the Cisco VPN client (I'm using version 4.8).
Currently I am testing the remote access vpn with the Cisco VPN client part.
I can connect with the VPN client with no problem BUT I can not ping into or out of the ASA and I can not browse the web from inside and I can not RDP into or out of the ASA.
Any help would be awesome!

Following is the config:
: Saved
:
ASA Version 8.0(3)
!
hostname ciscoasa
domain-name ciscoasa.com
enable password eQ239kfSqAf0KCj9 encrypted
names
name 172.16.8.0 Supa_172
name 192.168.5.0 Supa_192
!
interface Vlan1
 nameif inside
 security-level 100
 ip address 10.5.4.1 255.255.255.0
!
interface Vlan2
 nameif outside
 security-level 0
 ip address 10.1.15.66 255.255.240.0
!
interface Ethernet0/0
 switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
passwd kK.q4TiQYsIGwwH/ encrypted
ftp mode passive
dns server-group DefaultDNS
 domain-name ciscoasa.com
object-group network DM_INLINE_NETWORK_1
 network-object Supa_172 255.255.248.0
 network-object Supa_192 255.255.255.0
object-group network DM_INLINE_NETWORK_2
 network-object Supa_172 255.255.248.0
 network-object Supa_192 255.255.255.0
access-list outside_cryptomap extended permit ip any 10.5.4.0 255.255.255.0
access-list outside_cryptomap extended permit ip 10.5.4.0 255.255.255.0 object-group DM_INLINE_NETWORK_1
access-list inside_outbound_nat0 extended permit ip any 10.5.4.0 255.255.255.0
access-list inside_outbound_nat0 extended permit ip 10.5.4.0 255.255.255.0 object-group DM_INLINE_NETWORK_2
pager lines 24
logging asdm informational
mtu inside 1500
mtu outside 1500
ip local pool tunnel_dhcp_pool 192.168.1.2-192.168.1.33 mask 255.255.255.0
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-603.bin
no asdm history enable
arp timeout 14400
nat (inside) 0 access-list inside_outbound_nat0
nat (inside) 1 0.0.0.0 0.0.0.0
route outside 0.0.0.0 0.0.0.0 10.100.15.201 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout uauth 0:05:00 absolute
dynamic-access-policy-record DfltAccessPolicy
http server enable
http 0.0.0.0 0.0.0.0 inside
http 0.0.0.0 0.0.0.0 outside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac
crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac
crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac
crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac
crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac
crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set ESP-3DES-MD5
crypto map outside_map0 1 match address outside_cryptomap
crypto map outside_map0 1 set peer 6.4.2.158
crypto map outside_map0 1 set transform-set ESP-3DES-MD5
crypto map outside_map0 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
crypto map outside_map0 interface outside
crypto map inside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
crypto map inside_map interface inside
crypto isakmp enable outside
telnet 0.0.0.0 0.0.0.0 inside
telnet 0.0.0.0 0.0.0.0 outside
telnet timeout 5
ssh 0.0.0.0 0.0.0.0 inside
ssh 0.0.0.0 0.0.0.0 outside
ssh timeout 5
console timeout 0
dhcpd auto_config outside
!
dhcpd address 10.5.4.2-10.5.4.33 inside
dhcpd auto_config outside interface inside
dhcpd enable inside
!

threat-detection basic-threat
threat-detection statistics access-list
ntp server 64.90.182.55 source outside
username administrator password mA.PO.MreHVa1cuu encrypted
tunnel-group 6.4.2.158 type ipsec-l2l
tunnel-group 6.4.2.158 ipsec-attributes
 pre-shared-key *
tunnel-group TunnelGroup1 type remote-access
tunnel-group TunnelGroup1 general-attributes
 address-pool tunnel_dhcp_pool
tunnel-group TunnelGroup1 ipsec-attributes
 pre-shared-key *
!
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect esmtp
  inspect sqlnet
  inspect skinny
  inspect sunrpc
  inspect xdmcp
  inspect sip
  inspect netbios
  inspect tftp
!
service-policy global_policy global
prompt hostname context
Cryptochecksum:42d32c44dcbb6895d2d541d783e963c2
: endStart Free Trial
[+][-]04.08.2008 at 03:33PM PDT, ID: 21310239

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.09.2008 at 11:57AM PDT, ID: 21317938

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.09.2008 at 12:54PM PDT, ID: 21318433

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.09.2008 at 02:55PM PDT, ID: 21319465

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.09.2008 at 03:18PM PDT, ID: 21319625

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.09.2008 at 05:38PM PDT, ID: 21320540

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.09.2008 at 06:53PM PDT, ID: 21321035

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.09.2008 at 07:22PM PDT, ID: 21321173

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.09.2008 at 08:13PM PDT, ID: 21321399

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.10.2008 at 06:32AM PDT, ID: 21324525

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.10.2008 at 08:18AM PDT, ID: 21325749

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.10.2008 at 09:10AM PDT, ID: 21326362

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]04.10.2008 at 09:26AM PDT, ID: 21326565

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]04.10.2008 at 09:30AM PDT, ID: 21326606

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: IPSec Security Protocol, Virtual Private Networking (VPN), Cisco PIX Firewall
Tags: Cisco, ASA, 5505
Sign Up Now!
Solution Provided By: cyberdragon666
Participating Experts: 1
Solution Grade: A
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628