Avatar of tabush
tabush

asked on 

Help enabling http access for Cisco ASA - (ET)

I'm having trouble enabling http on my Cisco ASA. I am trying to do this so i can download and use the Cisco ASDM.

You'll see in the screenshot i already ran
http server enable
http 192.168.1.0 255.255.255.0 inside


however when i try try to browse to my device the page still wont open.
I tried browsing to it using the following
http://192.168.1.1
https://192.168.1.1
http://192.168.1.1/admin
https://192.168.1.1/admin

None of these are working.


User generated image
CiscoHardware Firewalls

Avatar of undefined
Last Comment
tabush
Avatar of SIM50
SIM50
Flag of United States of America image

Do you have asdm image specified?
Avatar of tabush
tabush

ASKER

Not that i'm aware of. What's that for and how to i set that?
Avatar of SIM50
SIM50
Flag of United States of America image

Do "sh run | i asdm". If nothing comes up, check flash for asdm image "sh flash" and then configure it with "asdm image disk0:/asdm-xxx.bin".
Avatar of SIM50
SIM50
Flag of United States of America image

I also see aaa only for ssh. You will need one https too.
aaa authentication http console LOCAL
Avatar of Pete Long
Pete Long
Flag of United Kingdom of Great Britain and Northern Ireland image

I see your SNMP info points to a host on 192.168.1.0/24. Can we assume that the internal/private subnet that you're trying to access the ASDM on is actually on the 192.168.1.0/24 as well?

MO
Avatar of Feroz Ahmed
Feroz Ahmed
Flag of India image

Hi,

You are missing a very useful wivered syntax in ASA always you have apply this Syntax in Policy unless and untill you define in policy  you will not be able to access http Server whereas in Router it works with the given syntax .So,plz follow these steps in order to Access http Server.

ASA(Config-t) #Policy-Map Global_policy
ASA(Config-t)#class inspection_default
ASA(Config-t)#Inspect http

It should work if you apply this Syntax on ASA Configuration Mode.
Avatar of Pete Long
Pete Long
Flag of United Kingdom of Great Britain and Northern Ireland image

http inspection does not have to be on, to access the ASDM?

heres. mine

PetesASA# show run policy-map
!
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum client auto
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map 
  inspect ftp 
  inspect h323 h225 
  inspect h323 ras 
  inspect rsh 
  inspect rtsp 
  inspect sqlnet 
  inspect skinny  
  inspect sunrpc 
  inspect xdmcp 
  inspect sip  
  inspect netbios 
  inspect tftp 
  inspect icmp 
  inspect ipsec-pass-thru 
  inspect ip-options 
  inspect pptp 
 class class-default
  set connection decrement-ttl
!

Open in new window


And the ASDM works fine?

P
Avatar of SIM50
SIM50
Flag of United States of America image

Service policies and ACLs (with one exception) on ASA are for the pass through traffic. The traffic directed at ASA itself isn't filtered by them.  One exception to ACLs is the keyword "control-plane" which allows to filter control-plane traffic destined to ASA.
Avatar of tabush
tabush

ASKER

Thanks everyone for your answers. I am still having trouble though.
@sim50. Yes it does look like it was enabled. See screenshot. Not sure if "no asdm history enabled" is an issue.
User generated image
I also ran this command however dont think helped: aaa authentication http console LOCAL
Or is there a different command i should run for enabling https?

@michael. Yes i am trying to connect from a computer in that subnet.

@Feroz. I ran the first 2 commands however i'm hesitant to run the third because i dont know what affect it will have on my network.
Avatar of SIM50
SIM50
Flag of United States of America image

What page do you get when you go to https://192.168.1.1?
What's your current version on ASA? sh ver
ASDM 5.22 is very old.

aaa authentication http console LOCAL - this configures authentication so you could login with the local user name/pw.
Avatar of tabush
tabush

ASKER

Software version 8.2 (5) 59

I get "this webpage cannot be found" from IE.
Chrome says "404 Not Found. The requested URL /admin/public/index.html was not found on this server."
SOLUTION
Avatar of SIM50
SIM50
Flag of United States of America image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
@tabush,

You should update the System and ASDM software. That version is quite old. Can you serial into the device and update the software via TFTP?

MO
Avatar of tabush
tabush

ASKER

thank you.
That might be the only option however we're going to leave it on the current version. We're planning on replacing it very soon and dont want to make any big changes before we do so.
Avatar of SIM50
SIM50
Flag of United States of America image

You don't need to upgrade ASA image, just ASDM image. ASA image upgrade is optional.
Avatar of tabush
tabush

ASKER

Are you able to attach that image file to this thread? This device doesnt have an active license with cisco so cannot login and download it.
ASKER CERTIFIED SOLUTION
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
Dear Tabush,

Try to reset the rsa keys, and test again.

Also it will be great if you provide me with show run all output.

Regards,
Muhannad
Avatar of tabush
tabush

ASKER

thank you for your help
Cisco
Cisco

Cisco PIX is a dedicated hardware firewall appliance; the Cisco Adaptive Security Appliance (ASA) is a firewall and anti-malware security appliance that provides unified threat management and protection the PIX does not. Other Cisco devices and systems include routers, switches, storage networking, wireless and the software and hardware for PIX Firewall Manager (PFM), PIX Device Manager (PDM) and Adaptive Security Device Manager (ASDM).

27K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo