Solved

Cisco ASA 5505

Posted on 2008-09-30
7
855 Views
Last Modified: 2012-06-27
Hi Experts,

I'm using IE (https) to try to change the default ip address from 192.168.1.  to my preferred LAN ip address, whne it try to send the command to ASA, it doesn't get through.

I even tried with the wizard but again it doesn't complete the changes.

I have not tried the console yet to change the default ip.

Any suggestion?

thanks
mcse2007
0
Comment
Question by:mcse2007
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
7 Comments
 
LVL 1

Expert Comment

by:Foo_Guru
ID: 22611736
When you say it "doesn't get through" what exactly happens? IS there an error?

Obviously if you change the IP when connected to the old IP  you will lose connectivity. So you can go into configuration (assuming you are logged into it with level 15 security) change the interface IP and then click apply.

After you click apply you need to close the browser, which is easier to just close the smaller window which loads the applet as it will close them both. Then browse to the new IP via HTTPS and make sure you save it.

Console is the best way to do this, but via browser works too you just have to go through more steps.

Hope that helps!
0
 
LVL 12

Expert Comment

by:Pugglewuggle
ID: 22611749
The browser setup on the ASA works sometimes... If you can avoid it, please do so. Instead use the ASDM startup wizard if you don't know a lot about the ASAs or PIXes. If you are familiar with the ASA, I recommend using the CLI for management instead.
If you need help with configuring it for internet access let me know - I'll send you the commands to put into the console.
Cheers! :-)
0
 
LVL 7

Author Comment

by:mcse2007
ID: 22611854
There is an issue with the ASDM when I try to reach the router, see enclosed so I resorted to IE but cannot change the bloody ip address since it doesn't complete the changes, ie error in command etc.etc

By default, the router can be reached through HTTPS/ASDM, so how do I change the vlan1 ip address through CONSOLE, then change it back to HTTPS/ASDM. At the moment, I cannot even access it through HTTPS, it says 'done' on the bottom left hand corner. I'm thinking about pressing the 'reset' button.



error.JPG
0
Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

 
LVL 12

Accepted Solution

by:
Pugglewuggle earned 250 total points
ID: 22611925
On console to enable ASDM access run the following commands (replace xxxxxxx with your password - passwd and enable password must be different - WRITE THESE DOWN- THESE ARE YOUR MASTER PASSWORDS):
passwd xxxxxxx
enable password xxxxxxx
!
password
interface vlan 1
nameif inside
ip address 192.168.1.1 255.255.255.0
security-level 100
no shut
!
interface ethernet 0/1
switchport access vlan 1
no ip address
no shutdown
!
crypto rsa key generate mod 1024
!

http server enable
http 192.168.1.0 255.255.255.0 inside

Connect the PC to the ASA on ethernet port 0/1 (second one) and assign the PC a static IP of 192.168.1.2 with a subnet mask of 255.255.255.0 and a default gateway of 192.168.1.1
Now try accessing the ASDM with a blank username and your passwd (not enable)
You can now run the startup wizard.
Cheers! Let me know if that does it!
0
 
LVL 7

Author Comment

by:mcse2007
ID: 22611966
By default, asa appliance can only accessible by https/asdm?

So the issue is  I'm connected to ASA by console, then power restart it, open a terminal session but all I can see some wierd characters.
0
 
LVL 12

Expert Comment

by:Pugglewuggle
ID: 22612003
You can always access the console (unless you lock yourself out of it when configuring AAA).
Make sure your console settings are:
speed: 9600
data bits: 8
stop bits: 1
parity: none
flow control: xon/xoff.
I use a terminal program called putty. It's very good. Probably the most popular one out there.
http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html
One other thing: you should NEVER have to power cycle an ASA unless you're upgrading the software or the activation key. Just letting you know. :-) These devices are designed to run for years without stopping provided you don't reboot them - even when the config is completely changed you shouldn't ever have to reboot it. Restarting it won't fix anything unless you didn't save the latest config - it will just reload the last saved one on reboot - but you lose everything you've done on it since last save.
0
 
LVL 7

Author Closing Comment

by:mcse2007
ID: 31501849
I've download the latest JAVA program, installed then was able to using ASDM and abled to change the vlan1 ip address to preferred ip address.
0

Featured Post

Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question