GNS3 step by step

Posted on 2010-09-14
Last Modified: 2012-05-10
I am new  with GNS3, I used to work with packet tracer but now i want to test ASA which is not included in packet tracer software!
Actually i would like to know how can I get started with GNS! i guess it needs an IOS! where can i download ASA IOS for free just to make a test!

anyone can help me step by step how can I start with GNS and where can I download the IOS!

Question by:yahyooz
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 5
LVL 57

Accepted Solution

Pete Long earned 500 total points
ID: 33676260
LVL 10

Expert Comment

ID: 33686321
You cannot download ASA for free. however there must be some links out there on the internet..

on the other hand, I found this easier than GNS3:

You can download an ASA as a VM, or as an installer; it works great and doesn't give you the problem GNS3 does.

As far as I know, ASAs on GNS3 have a problem where you cannot enable any of the interfaces, there are problems saving configurations, etc.
LVL 10

Expert Comment

ID: 33686601

Hey, I tried the method you have on your site and I would like to make a correction, or suggest something:

Let people know that they have to copy their device ID and paste it into the script or it will complain about:

Error Initialising interface \Device\NPF_{73E6A630-EF98-4CBB-8C30-A60FA09DF59F}
Don't miss ATEN at NAB Show April 24-27!

Visit ATEN at NAB Show to learn how our "Seamlessly Entertaining" solutions deliver fast, precise video streaming without delays for the broadcasting and media environment. ATEN will showcase its 16x16 Modular Matrix Switch (VM1600) and KVM Over IP Solution (KE6900 series).


Author Comment

ID: 33690783
Thanks ddiazp,

I have download the ASA vm but whenever i start it it just freeze on (booting the kernel)!!!
is there any ideas!!!


Author Comment

ID: 33690787
and FYI,I am using  VMware Workstation 6.5.3
LVL 10

Expert Comment

ID: 33692662
Yes, that's what it's supposed to
Do. Once you see that go to the folder where you downloaded the file, run start_gw.bat and then run Connect.bat

You will then have access to the console port

Author Comment

ID: 33694389
Thanks Pete,

is there possibility to connect ASA vmware with other devices, I mean is it possible to create a virtual switch and hosts and connect them all together to test!!!

LVL 10

Expert Comment

ID: 33694413
You can create loopback interfaces on your machine and map these interfaces to the ASA,

DOing this I am able to have 2 ASAs and ping between them through my PC which acts as a router.

Author Comment

ID: 33700449
thanks ddizp,

now i just followed pete instructions and everything works fine, but when i try to ping from ASA to my PC it wont work!! but when i ping from the PC to ASA it works!
ASA e0/0
Virtual PC LAN

and what IP address should i give to lookback interface!
LVL 10

Expert Comment

ID: 33706340
the loopback interface must be ont he same subnet as your ASA.

Also, make sure you map the loopback to the ASA

In this case, you can give your loopback, and this is the IP you want to ping from the ASA first. Once that works, add a default route on the ASA pointing to your loopback:

route inside

For ASA practice, you should use 2 loopback interfaces so you can have an outside and an inside network on your ASA

Author Comment

ID: 33707010
OK, here is the configuration that i made:
int e0/0: inside
int e0/1: outside
route inside 0 0

virtual LAN: ASA-E-0
virtual LAN: ASA-E-1
loopback interface1 : named (route-inside)
loopback interface2: named (route-outside)
from the PC i can ping all IPs, but when i try to ping from ASA, still no success!!! I have tried to open ICMP echo,
access-list acl_in permit icmp any any echo-reply
access-list acl_out permit icmp any any echo-reply

but still no success!!  any other idea!
LVL 10

Expert Comment

ID: 33707534
Woop, made a mistake, I meant

Route outside 0 0

Also, you'll want to name both your access lists the same

Nat (inside) 1
Global (outside) 1 interface
Access-group  in interface outside

Make sure your interfaces have the nameif statement with the proper name (inside and outside) and the inside has security level of 100, outside security level lower than inside level, usually 0.


Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Network over eigrp 100 topology ? 3 63
Single Number Reach 3 60
Cisco Licensing for Wi Fi 4 53
Blocking outside IP Addresses 16 61
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
Many of the companies I’ve worked with have embraced cloud solutions due to their desire to “get out of the datacenter business.” The ability to achieve better security and availability, and the speed with which they are able to deploy, is far grea…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question