asa5505 asdm gui configuration steps

Posted on 2014-09-20
Last Modified: 2014-10-04
hi I have never used my asa5505 before, but I have managed to configure it separating the 'inside & outside' network and can now also open the 'asdm' gui as per below link:

qns1.  currently I have no vpns or anything like that and all I wish to do at this point is protect my win 7 internal network users, so what else should I configure within the gui ?

note:  I could look on youtube but I wish to gain that understanding first of what I need to do first and then continue bit by bit.

note: at the moment I have a virgin/media hub that is using the built-in dhcp, so the following is setup at the moment:

inside: 192.168.1.x - set on vlan 1
outside: - set on vlan 2
Question by:mikey250
  • 6
  • 2
LVL 57

Accepted Solution

Pete Long earned 500 total points
ID: 40334618
OK, I would put your Virgin media hub in 'modem' mode, then your ASA will get the public IP address on its outside interface - so when you get round to doing VPN's things will work.

If you want some ASA Walkthroughs theres a ton on my site that cover just about everything Ive ever had to deploy, and Ive been deploying ASA/PIX for nearly 10 years


Author Comment

ID: 40335033
hi petelong,  yes I normally do use 'modem/enable' but just for the purposes of getting my asa5505 up and running I left it as it was and yes If I wanted to setup a vpn I am aware this would need to be done.

yes I will look at your link:

qns1.  what I want to know is as I have configured my firewall enough for protection  ?

Author Comment

ID: 40335157
hi petelong,

qns1.  why can I not receive my public ip address  ?

- I have now set my virgin to modem/enable
- if I plug in my standalone laptop it does provide a public ip address.
- I then unplug my laptop and reboot my virgin hub
- I thn plugged my x-over cable from my asa5505 eth/0 port to my specific port on my virgin hub but no public ip address has been allocated  ?

the outside interface config has not changed ie:

int vlan 2
nameif outside
security-level  0
ip address dhcp setroute
no shut
I then switched off the asa5505 and did not do a reload but assumed this should still provide a public ip address, but I may have not waited long enough!! not sure.
LVL 57

Expert Comment

by:Pete Long
ID: 40335196
>>qns1.  what I want to know is as I have configured my firewall enough for protection  ?

Essentially yes out of the box you have protection :)

>>qns1.  why can I not receive my public ip address  ?

You shold not need a crossover cable the 5505 ?

The problem you are seeing is probably, because the modem does not like that mac address being changes power everything off, wait a couple of minutes, power up the HUB, then plug the firewall into it. You cant just SWAP over internal devices.
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails


Author Comment

ID: 40335247
hi petelong,

qns1.   after changing the ip addressing scheme within my asa5505 via the command line, I can also see that the 'dhcpd data' has also been removed.  - I assume this is ok because I have a running: dhcp via my master dc, mentioned below  ?

I have now got the 'public ip address' showing via my asa5505 & I have also plugged in a 'straight-thru' cable from my asa5505 eth0 port to my cisco 2950 and my master dc/ad/dhcp/dns server can also receive the internet access.

qns2.  I have now logged on to my domain with my win 7 desktop successfully and my master dc/ad/dhcp/dns - has allocated an ip address as expected, but I cannot receive internet access - why there something I should be adding on my asa5505  as currently I have all machines within active directory located in the default computer container and not currently using any gpo's yet  ?

Author Comment

ID: 40335249
hi petelong,  I forgot to mention I have 3 cisco 2950 switches for fault tolerance testing:

- vtp server (primary) - master dc & fileprint server plugged in here
- vtp server (secondary)
- vtp client - win 7 desktop user plugged in here

win 7 - I can ping from vtp client switch to the following:  successfully

- master dc
- fileprintserver
- default gateway

Author Comment

ID: 40361349
the default gateway was missing from my internal master dc via my dhcp and once added my win 7 desktop can now receive internet access.

Author Closing Comment

ID: 40361351
sound advice.  appreciated.

Featured Post

Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

Join & Write a Comment

From Cisco ASA version 8.3, the Network Address Translation (NAT) configuration has been completely redesigned and it may be helpful to have the syntax configuration for both at a glance. You may as well want to read official Cisco published AS…
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now