Solved

Cisco ASA 5500 Firewall

Posted on 2011-09-12
3
314 Views
Last Modified: 2012-05-12
Hi there,

We work on a site where with two networks, one is a 192.168.1.x and one 192.168.2.x - the .2 being "GUEST" mode on a Cisco ASA 5500 Firewall.

The Firewall has 10 User Licenses.

We don't manage the firewall nor have access to it.

We have found that on the 192.168.1.x sometimes some of the machines don't browse. They can ping the gateway. The same happens on the 192.168.2.x network. It's very sporadic but machines can ping the gateway but not browse.

How is a "User" license decided? Are they fixed, i.e. first 10 devices? Is it connection based? Should it just block all connectivity!?

Any advise which could be offered would be greatfully received.

M
0
Comment
Question by:mattstannard
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 3

Expert Comment

by:Thomas_Roes
ID: 36525168
Cisco want's your cache. This 10 user license mean's 10 devices can access the internet. I'm not exactly sure how long an IP (of MAC) address is cached as using the internet, but you do want to add extra user licenses if you have them.

Good router, but Cisco asks a lot (of cache) for it.

Thomas Roes
0
 

Author Comment

by:mattstannard
ID: 36525227
Hi Thomas,

Does it just block everything?

Can you force the cache to be cleared?

M
0
 
LVL 3

Accepted Solution

by:
Thomas_Roes earned 500 total points
ID: 36525640
As far as I remember, it block's everything for the 11th device. Clearing cache, don't know, rebooting the firewall helps, but you don't want that.

I see two options:
- 10->25 user upgrade (or unlimited)
- replace router (depending on your needs, this can be cheaper that the user license upgrade).

BUT: if you don't have access to it, and you don't manage it, put the problem at the guy's who do.

Thomas
0

Featured Post

Revamp Your Training Process

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
Monitoring a network: how to monitor network services and why? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the philosophy behind service monitoring and why a handshake validation is critical in network monitoring. Software utilized …

691 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question