Solved

Looking to upgrade my 5505 FW  to 5506 X

Posted on 2016-11-10
2
10 Views
Last Modified: 2016-11-30
Hello,

Have been thinking of upgrading my 5505 FW to a 5506X, and coincidentally, I am now having problems with the ICMP. The FW suddenly stopped blocking pings and everything seems like if they are hanging on the internet. Now all servers are pingable from both outside and inside. I have reviewed everything in the ASDM, but I am afraid to restart the FW, for fear that it may not boot up, or even more things could be wrong which will only show up after a reboot.

I am not a specialist in FW. So any expert advice will help me a great deal.
The second thing is I will like to know if i can use the same FW to create a DMZ with my two DNS servers on it with all my servers on the inside network and NAT them through to the outside as I have now. Is that the most reliable way to go about it. I am willing to spend a bit extra to have a setup with two FW's running as Active  Active. What all will i need to accomplish this setup?
Thank you in advance

Richard
0
Comment
Question by:Richard Thomas
  • 2
2 Comments
 
LVL 14

Accepted Solution

by:
SIM50 earned 500 total points (awarded by participants)
ID: 41882673
Have been thinking of upgrading my 5505 FW to a 5506X, and coincidentally, I am now having problems with the ICMP. The FW suddenly stopped blocking pings and everything seems like if they are hanging on the internet. Now all servers are pingable from both outside and inside. I have reviewed everything in the ASDM, but I am afraid to restart the FW, for fear that it may not boot up, or even more things could be wrong which will only show up after a reboot.

Can you post sanitized config?

The second thing is I will like to know if i can use the same FW to create a DMZ with my two DNS servers on it with all my servers on the inside network and NAT them through to the outside as I have now.

Yes. Instead of VLAN interfaces, you will have to configure physical ports. ASA5506X has all routed ports.

I am willing to spend a bit extra to have a setup with two FW's running as Active  Active.

Contexts are not supported in ASA5506X so you can't have active/active failover cluster. You can only have active/standby.
0
 
LVL 14

Expert Comment

by:SIM50
ID: 41907003
Answered.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question