Solved

Cisco ASA 5510 Firewall setup

Posted on 2009-04-06
7
904 Views
Last Modified: 2012-05-06
Hello Cisco experts

We  just recently bought  a Cisco ASA 5510 appliance and I am supposed to set it up and install in our network (currently use Watchguard)

My conection to the internet is a 5MB Optical Circuit (Metro Ethernet)  and the Ethernet cable is plugged straight into Watchguard outbound port.  (no router)

Behind the firewall I have 3 internal  networks (2 + 1 DMZ) .  I am trying to figure out the best way to set the ASA up so I have started to read an article Cisco Document ID 63880  "Connecting Multiple Internal Networks with Internet: Configuration Example"
This document refers to PIX/ASA 7.x or higher and one of the prerequisites is to use a Cisco router behind the PIX (?!)  I don't know if this apply to ASA device, it it does then I am in trouble  (need a router)

My ASA 5510 software is 7.12 . I have tried to upgrade to 8.X (available on the CD which came with the unit) but it fails every time I try to upgrade the software

I have also noticed that Packet Tracker is not available on my ASDM interface.  Should I upgrade to v 6.11 ( also available on CD) or is something else I should to to get this very usefull tool

Thank you all in advance for your help

Cheers
0
Comment
Question by:Bibecu
7 Comments
 
LVL 8

Expert Comment

by:Sniper98G
ID: 24083192
For all intensive purposes the ASA is a pix. It uses the same code/interface as a pix.

You can configure each of the interfaces on the device (4 on your model I believe) to a different subnet. So; you do not require a router. The only problem you may run into is if you want the to subnets to communicate directly without restriction you will need to set them to the same security level and configure the "same-security-traffic permit inter-interface" command to get that to work.
0
 
LVL 57

Accepted Solution

by:
Pete Long earned 250 total points
ID: 24085352
To Update see my website here http://www.petenetlive.com/Tech/Firewalls/Cisco/updateasacli.htmor here if you prefer the CLI http://www.petenetlive.com/Tech/Firewalls/Cisco/updateasacli.htm
To connect see http://www.petenetlive.com/Tech/Firewalls/Cisco/connect2.htm then for simple setup http://www.petenetlive.com/Tech/Firewalls/Cisco/5505Setup.htm (note that page shows, and demonstrates an ASA 5505 not a 5510 but the process is the same with the exeption of assigning VLANS - the 5510 does not have VLANs allready setup, the 5505 does, so to be honest the basic setup is slightly easer on your firewall.
If you need to setup VPN's etc there are other walkthrough on the site :)
0
 
LVL 5

Expert Comment

by:shirkan
ID: 24138506
first, you have 3 100mbit interfaces (incl the management) and 2 1Gb interfaces (0 and 1 i think)

of course use the GB interfaces for LAN and whichever DMZ has the most traffic,  spread the others

u dont need a router to make the different Networks connected to the ASA to communicate with each other

you use static and access-list commands to restrict communication the way you want.

you will have to give me more detail on your network to make any other suggestions and since you have an ASA now, tell your boss you need Cisco Training for that thing, otherwise you will never really know what you are doing and less understand it

this - "same-security-traffic permit inter-interface" is the lazy version if you dont need access rules between the interface (physical and virtual)

anyways, without a plan its hard to say whats best for you
0
VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

 
LVL 5

Expert Comment

by:shirkan
ID: 24138550
if you want to stay with version 7 you need to upgrade to 7.2.4 and ASDM 5.2.4 - i dont really recommend version 8 as it has alot more bugs then 7
it has advantages if you use alot of ssl-vpn, other then that stay with 724
and you need a tftp or ftp server to upload the image or you use the http interface for it, dont forget to match ASDM with the Version you want to run and edit the config to tell it to boot the right image
0
 

Author Closing Comment

by:Bibecu
ID: 31570091
Thank you guys for the time taken to answer.  Yes, I am new to cisco stuff.  So far I have managed to upgrade to v 8 and ASDM 6, configure the appliance, and I am in process to setup the access rules. Compared with Watchguard is a different world !    I am not going to use "Enable traffic between interfaces with the same security level"  because yes, that's a lazy way to do it. Again, thank you all for your time responding to my question.
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 32644435
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 32644711
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
syslog id vs. msg 2 30
How to setup 3 isps on a redundant mode? 3 30
How to safely test out TFTP server software 12 68
Ping configured interface on Sonicwall 16 48
Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question