Solved

asa5505 asdm gui configuration steps

Posted on 2014-09-20
8
226 Views
Last Modified: 2014-10-04
hi I have never used my asa5505 before, but I have managed to configure it separating the 'inside & outside' network and can now also open the 'asdm' gui as per below link:

http://www.youtube.com/watch?v=hdgFBfs6xu4

qns1.  currently I have no vpns or anything like that and all I wish to do at this point is protect my win 7 internal network users, so what else should I configure within the gui ?

note:  I could look on youtube but I wish to gain that understanding first of what I need to do first and then continue bit by bit.

note: at the moment I have a virgin/media hub that is using the built-in dhcp, so the following is setup at the moment:

inside: 192.168.1.x - set on vlan 1
outside: 192.168.0.3 - set on vlan 2
0
Comment
Question by:mikey250
  • 6
  • 2
8 Comments
 
LVL 57

Accepted Solution

by:
Pete Long earned 500 total points
ID: 40334618
OK, I would put your Virgin media hub in 'modem' mode, then your ASA will get the public IP address on its outside interface - so when you get round to doing VPN's things will work.

If you want some ASA Walkthroughs theres a ton on my site that cover just about everything Ive ever had to deploy, and Ive been deploying ASA/PIX for nearly 10 years http://www.petenetlive.com/Top_Level/techmain.html#CISCO

PL
0
 

Author Comment

by:mikey250
ID: 40335033
hi petelong,  yes I normally do use 'modem/enable' but just for the purposes of getting my asa5505 up and running I left it as it was and yes If I wanted to setup a vpn I am aware this would need to be done.

yes I will look at your link:

 http://www.petenetlive.com/Top_Level/techmain.html#CISCO

qns1.  what I want to know is as I have configured my firewall enough for protection  ?
0
 

Author Comment

by:mikey250
ID: 40335157
hi petelong,

qns1.  why can I not receive my public ip address  ?

- I have now set my virgin to modem/enable
- if I plug in my standalone laptop it does provide a public ip address.
- I then unplug my laptop and reboot my virgin hub
- I thn plugged my x-over cable from my asa5505 eth/0 port to my specific port on my virgin hub but no public ip address has been allocated  ?

the outside interface config has not changed ie:

int vlan 2
nameif outside
security-level  0
ip address dhcp setroute
no shut
I then switched off the asa5505 and did not do a reload but assumed this should still provide a public ip address, but I may have not waited long enough!! not sure.
0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 57

Expert Comment

by:Pete Long
ID: 40335196
>>qns1.  what I want to know is as I have configured my firewall enough for protection  ?

Essentially yes out of the box you have protection :)

>>qns1.  why can I not receive my public ip address  ?

You shold not need a crossover cable the 5505 ?

The problem you are seeing is probably, because the modem does not like that mac address being changes power everything off, wait a couple of minutes, power up the HUB, then plug the firewall into it. You cant just SWAP over internal devices.
0
 

Author Comment

by:mikey250
ID: 40335247
hi petelong,

qns1.   after changing the ip addressing scheme within my asa5505 via the command line, I can also see that the 'dhcpd data' has also been removed.  - I assume this is ok because I have a running: dhcp via my master dc, mentioned below  ?

I have now got the 'public ip address' showing via my asa5505 & I have also plugged in a 'straight-thru' cable from my asa5505 eth0 port to my cisco 2950 and my master dc/ad/dhcp/dns server can also receive the internet access.

qns2.  I have now logged on to my domain with my win 7 desktop successfully and my master dc/ad/dhcp/dns - has allocated an ip address as expected, but I cannot receive internet access - why ...is there something I should be adding on my asa5505  as currently I have all machines within active directory located in the default computer container and not currently using any gpo's yet  ?
0
 

Author Comment

by:mikey250
ID: 40335249
hi petelong,  I forgot to mention I have 3 cisco 2950 switches for fault tolerance testing:

- vtp server (primary) - master dc & fileprint server plugged in here
- vtp server (secondary)
- vtp client - win 7 desktop user plugged in here

win 7 - I can ping from vtp client switch to the following:  successfully

- master dc
- fileprintserver
- default gateway
0
 

Author Comment

by:mikey250
ID: 40361349
the default gateway was missing from my internal master dc via my dhcp and once added my win 7 desktop can now receive internet access.
0
 

Author Closing Comment

by:mikey250
ID: 40361351
sound advice.  appreciated.
0

Featured Post

Courses: Start Training Online With Pros, Today

Brush up on the basics or master the advanced techniques required to earn essential industry certifications, with Courses. Enroll in a course and start learning today. Training topics range from Android App Dev to the Xen Virtualization Platform.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

785 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question