Solved

Pysically turn off ports on ASA 5505

Posted on 2014-01-22
3
300 Views
Last Modified: 2014-03-05
I have an ASA 5505 at a construction site, which means I don't have control on who can have physical access to my asa. That being said, I want to turn off all of the ports that are not being used, just in case someone wants to try to plug into them. I did the shutdown command on all of the interfaces, but when some yahoo on site plugged in their SoHo router it started taking the DHCP requests instead of my ASA. How would I go about turning those ports completely off?
0
Comment
Question by:j_crow1
3 Comments
 
LVL 1

Expert Comment

by:raduk
ID: 39801568
You should configure port security on your router's interfaces.  Good info here:

http://www.cisco.com/en/US/docs/routers/7600/ios/15S/configuration/guide/port_sec.html#wp1044659
0
 

Author Comment

by:j_crow1
ID: 39801672
Does that work on the Asa?
0
 
LVL 31

Accepted Solution

by:
Gareth Gudger earned 500 total points
ID: 39801721
If you do the shutdown command on the ports then the ports are off. They can't be used.

Sounds like he unplugged something from a working jack and plugged in the SOHO instead.

If that is the case then a shutdown won't work and you need a Network Access Control mechanism. NetClarity appliances are great at this but they are pricey. They will basically automatically shut down anything on the network that isn't supposed to be there, until you allow them. Very simple management, deploys on the network in minutes. So rogue DHCP servers are blocked.

http://www.netclarity.net/
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

When I upgraded my ASA 8.2 to 8.3, I realized that my nonat statement was failing!   The log showed the following error:     %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows It was caused by the config upgrade, because t…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now