Solved

Looking to upgrade my 5505 FW  to 5506 X

Posted on 2016-11-10
2
7 Views
Last Modified: 2016-11-30
Hello,

Have been thinking of upgrading my 5505 FW to a 5506X, and coincidentally, I am now having problems with the ICMP. The FW suddenly stopped blocking pings and everything seems like if they are hanging on the internet. Now all servers are pingable from both outside and inside. I have reviewed everything in the ASDM, but I am afraid to restart the FW, for fear that it may not boot up, or even more things could be wrong which will only show up after a reboot.

I am not a specialist in FW. So any expert advice will help me a great deal.
The second thing is I will like to know if i can use the same FW to create a DMZ with my two DNS servers on it with all my servers on the inside network and NAT them through to the outside as I have now. Is that the most reliable way to go about it. I am willing to spend a bit extra to have a setup with two FW's running as Active  Active. What all will i need to accomplish this setup?
Thank you in advance

Richard
0
Comment
Question by:Richard Thomas
  • 2
2 Comments
 
LVL 13

Accepted Solution

by:
SIM50 earned 500 total points (awarded by participants)
Comment Utility
Have been thinking of upgrading my 5505 FW to a 5506X, and coincidentally, I am now having problems with the ICMP. The FW suddenly stopped blocking pings and everything seems like if they are hanging on the internet. Now all servers are pingable from both outside and inside. I have reviewed everything in the ASDM, but I am afraid to restart the FW, for fear that it may not boot up, or even more things could be wrong which will only show up after a reboot.

Can you post sanitized config?

The second thing is I will like to know if i can use the same FW to create a DMZ with my two DNS servers on it with all my servers on the inside network and NAT them through to the outside as I have now.

Yes. Instead of VLAN interfaces, you will have to configure physical ports. ASA5506X has all routed ports.

I am willing to spend a bit extra to have a setup with two FW's running as Active  Active.

Contexts are not supported in ASA5506X so you can't have active/active failover cluster. You can only have active/standby.
0
 
LVL 13

Expert Comment

by:SIM50
Comment Utility
Answered.
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

Suggested Solutions

I recently had the displeasure of buying a new firewall at one of the buildings I play Sys Admin at. I had to get a better firewall than the cheap one that I had there since I was reconnecting the main office to the satellite office via point-to-poi…
Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now