Solved

Pysically turn off ports on ASA 5505

Posted on 2014-01-22
3
307 Views
Last Modified: 2014-03-05
I have an ASA 5505 at a construction site, which means I don't have control on who can have physical access to my asa. That being said, I want to turn off all of the ports that are not being used, just in case someone wants to try to plug into them. I did the shutdown command on all of the interfaces, but when some yahoo on site plugged in their SoHo router it started taking the DHCP requests instead of my ASA. How would I go about turning those ports completely off?
0
Comment
Question by:j_crow1
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 1

Expert Comment

by:raduk
ID: 39801568
You should configure port security on your router's interfaces.  Good info here:

http://www.cisco.com/en/US/docs/routers/7600/ios/15S/configuration/guide/port_sec.html#wp1044659
0
 

Author Comment

by:j_crow1
ID: 39801672
Does that work on the Asa?
0
 
LVL 31

Accepted Solution

by:
Gareth Gudger earned 500 total points
ID: 39801721
If you do the shutdown command on the ports then the ports are off. They can't be used.

Sounds like he unplugged something from a working jack and plugged in the SOHO instead.

If that is the case then a shutdown won't work and you need a Network Access Control mechanism. NetClarity appliances are great at this but they are pricey. They will basically automatically shut down anything on the network that isn't supposed to be there, until you allow them. Very simple management, deploys on the network in minutes. So rogue DHCP servers are blocked.

http://www.netclarity.net/
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question