<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Do the FTP servers need to be in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036242#M147480</link>
    <description>&lt;P&gt;Do the FTP servers need to be accessed from the internet or do they just need access to the internet? &amp;nbsp;Also, what license is your ASA running (Base license or security plus license). &amp;nbsp;Issue the show version command to get this info.&lt;/P&gt;
&lt;P&gt;is it a layer 3 switch or layer 2. and how many subnets do you have in your network. &amp;nbsp;Do they just need to be seperated from the FTP servers or also from eachother?&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
    <pubDate>Sun, 22 Jan 2017 21:54:38 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2017-01-22T21:54:38Z</dc:date>
    <item>
      <title>Needs basic help with asa5505</title>
      <link>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036241#M147479</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;&lt;BR /&gt;I just started my new job at a company ( finally made it to change my line of work it IT )!&lt;BR /&gt;&lt;BR /&gt;Here's the problem, They have already setup a working network before me and my boss wants to keep that network working but i need to set up a basic switch to asa5505 to connect a ( atm only one but will be more hence the switch ) ftp server to it and grant it access to internet but im new to this kind of gear *still learning*.&lt;BR /&gt;&lt;BR /&gt;SO i was hoping someone has a bit of free time over and can guide me to open that switch to the internet but still closed off to the rest of the network without f'ing up the old config.&lt;BR /&gt;Yeah and btw, would be easiest / best if i could do it from COM port because thats how it's connected atm&lt;BR /&gt;&lt;SPAN&gt;Sincerely New guy!&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:48:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036241#M147479</guid>
      <dc:creator>k.lundgren91</dc:creator>
      <dc:date>2019-03-12T08:48:51Z</dc:date>
    </item>
    <item>
      <title>Do the FTP servers need to be</title>
      <link>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036242#M147480</link>
      <description>&lt;P&gt;Do the FTP servers need to be accessed from the internet or do they just need access to the internet? &amp;nbsp;Also, what license is your ASA running (Base license or security plus license). &amp;nbsp;Issue the show version command to get this info.&lt;/P&gt;
&lt;P&gt;is it a layer 3 switch or layer 2. and how many subnets do you have in your network. &amp;nbsp;Do they just need to be seperated from the FTP servers or also from eachother?&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jan 2017 21:54:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036242#M147480</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2017-01-22T21:54:38Z</dc:date>
    </item>
    <item>
      <title>the ftp servers is going to</title>
      <link>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036243#M147481</link>
      <description>&lt;P&gt;the ftp servers is going to be used as online storage for all&amp;nbsp;employees so i guess only accessed from the internet.&lt;BR /&gt;&lt;BR /&gt;Base License&lt;BR /&gt;&lt;BR /&gt;Is there a command i issue to get you all the info you need?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Sincerely &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2017 12:12:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036243#M147481</guid>
      <dc:creator>k.lundgren91</dc:creator>
      <dc:date>2017-01-23T12:12:27Z</dc:date>
    </item>
    <item>
      <title>Are you going to place the</title>
      <link>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036244#M147482</link>
      <description>&lt;P&gt;Are you going to place the server in a DMZ so you can filter traffic for internal users also or will it be placed on the inside network?&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2017 12:52:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036244#M147482</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2017-01-23T12:52:09Z</dc:date>
    </item>
    <item>
      <title>i want it to be placed</title>
      <link>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036245#M147483</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;i want it to be placed outside all networks for security reasons and there is no reason to have it internal since the company server computer will have another network cable going to the internal network on differnet subnet, But ill try to not make a fool of myself by making this:&lt;BR /&gt;Server 1 will be for employees only&lt;BR /&gt;Server 2,3 will be for renting out etc.&lt;BR /&gt;&lt;BR /&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/idea.jpg" class="migrated-markup-image" /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2017 14:37:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036245#M147483</guid>
      <dc:creator>k.lundgren91</dc:creator>
      <dc:date>2017-01-23T14:37:32Z</dc:date>
    </item>
    <item>
      <title>Where is the ASA coming into</title>
      <link>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036246#M147484</link>
      <description>&lt;P&gt;Where is the ASA coming into play in your network diagram here? &amp;nbsp;I am assuming the red boxes?&lt;/P&gt;
&lt;P&gt;If the ASA is just going to sit between the internet and the servers and not route or touch any traffic from the office computers then you could do a simple configuration like the following just remember to change the interfaces, IPs passwords, host names, etc. as needed. &amp;nbsp;Also, &lt;STRONG&gt;&lt;SPAN style="text-decoration: underline;"&gt;be sure to use passive FTP, not active&lt;/SPAN&gt;&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;hostname ciscoasa&lt;BR /&gt;domain-name home.local&lt;BR /&gt;enable password&amp;nbsp;PASSWORD&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/1&lt;/P&gt;
&lt;P&gt;description Internet&lt;BR /&gt; nameif outside&lt;BR /&gt; security-level 0&lt;BR /&gt; ip address dhcp setroute &lt;BR /&gt;!&lt;BR /&gt;interface Ethernet1/2&lt;/P&gt;
&lt;P&gt;description Office Computers&lt;BR /&gt; nameif&amp;nbsp;Inside&lt;BR /&gt; security-level&amp;nbsp;100&lt;BR /&gt; ip address 10.1.2.1 255.255.255.0&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network OFFICE_SERVER1_Private&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;host 10.1.2.10&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network OFFICE_SERVER2_Private&lt;BR /&gt;&lt;SPAN&gt;host 10.1.2.11&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;object network OFFICE_SERVER1_Public&lt;BR /&gt;&lt;SPAN&gt;host 11.11.11.10&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;object network OFFICE_SERVER2_Public&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;host 11.11.11.11&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;object network OFFICE_COMPUTERS&lt;BR /&gt; subnet 10.1.2.0 255.255.255.0&lt;/P&gt;
&lt;P&gt;object network &lt;SPAN&gt;OFFICE_COMPUTERS&lt;/SPAN&gt;&lt;BR /&gt; nat (inside,outside) dynamic interface&lt;/P&gt;
&lt;P&gt;nat (inside,outside) source static &lt;SPAN&gt;OFFICE_&lt;/SPAN&gt;&lt;SPAN&gt;SERVER1&amp;nbsp;OFFICE_SERVER1_Public&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;nat (inside,outside) source static &lt;SPAN&gt;OFFICE_&lt;/SPAN&gt;&lt;SPAN&gt;SERVER2 OFFICE_SERVER2_Public&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;access-list outside_access_in permit tcp any host 10.1.2.10 eq 21&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;access-list outside_access_in permit tcp any host 10.1.2.11 eq 21&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;access-group outside_access_in in interface outside&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;route outside 0.0.0.0 0.0.0.0 11.11.11.1&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;username NAME password PASSWORD&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;aaa authentication http console LOCAL &lt;BR /&gt;aaa authentication ssh console LOCAL &lt;BR /&gt;aaa authentication enable console LOCAL &lt;BR /&gt;aaa authentication serial console LOCAL&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;ssh 10.1.2.0 255.255.255.0 inside&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;http server enables&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;http10.1.2.0 255.255.255.0 inside&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;--&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;Please remember to select a correct answer and rate helpful posts&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 20:20:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036246#M147484</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2017-01-25T20:20:45Z</dc:date>
    </item>
    <item>
      <title>i think you missunderstood, i</title>
      <link>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036247#M147485</link>
      <description>&lt;P&gt;i think you missunderstood, i just want to configure a port on the asa 5505 router&amp;nbsp;that i can plug into a switch and have all the ftp servers on. and its atm configured alrdy so i just want to "add" to the config to a physical port on the router, can i write something in the terminal and copy here that shows how's it configured?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 13:23:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036247#M147485</guid>
      <dc:creator>k.lundgren91</dc:creator>
      <dc:date>2017-01-27T13:23:47Z</dc:date>
    </item>
    <item>
      <title>Ok, Then the interface</title>
      <link>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036248#M147486</link>
      <description>&lt;P&gt;Ok, Then the interface configuration you want would be something like this just replace the vlan in the no forward command to your inside network, and change the interface vlan do the desired VLAN number. &amp;nbsp;NAT and ACL configuration will differ depending on if you are running ASA version 8.2 or earlier or 8.3 and higher. &amp;nbsp;Here is an example of what you could do to grant access to FTP servers from the internet.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;interface&amp;nbsp;vlan3&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;no forward interface vlan 1&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;description&amp;nbsp;SERVERS&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;nameif DMZ&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;security-level&amp;nbsp;50&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;ip address 10.1.2.1 255.255.255.0&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;no shut&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;object network SERVERS_privarte&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; host 10.1.2.10&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; nat (inside,outside) static interface service tcp ftp ftp&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;access-list outside_access_in permit tcp any host 10.1.2.10 eq ftp&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;access-group outside_access_in in interface outside&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 14:30:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036248#M147486</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2017-01-27T14:30:58Z</dc:date>
    </item>
    <item>
      <title>Cant help :/ ? Sincerely </title>
      <link>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036249#M147487</link>
      <description>&lt;P&gt;Cant help &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt; ?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Sincerely&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2017 13:05:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036249#M147487</guid>
      <dc:creator>k.lundgren91</dc:creator>
      <dc:date>2017-01-29T13:05:56Z</dc:date>
    </item>
    <item>
      <title>Did you delete your reply ? :</title>
      <link>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036250#M147488</link>
      <description>&lt;P&gt;Did you delete your reply ? &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;EDIT: nvm.. the forum bugged out&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2017 13:07:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036250#M147488</guid>
      <dc:creator>k.lundgren91</dc:creator>
      <dc:date>2017-01-29T13:07:18Z</dc:date>
    </item>
    <item>
      <title>Cisco Adaptive Security</title>
      <link>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036251#M147489</link>
      <description>&lt;P&gt;Cisco Adaptive Security Appliance Software Version 8.4(2)&lt;BR /&gt;&lt;BR /&gt;VLAN Name Status Ports&lt;BR /&gt;---- -------------------------------- --------- -----------------------------&lt;BR /&gt;1 inside up Et0/1, Et0/2, Et0/3, Et0/4&lt;BR /&gt; Et0/5, Et0/6, Et0/7&lt;/P&gt;
&lt;P&gt;2 outside up Et0/0&lt;BR /&gt;&lt;BR /&gt;any other command i should type and post ? since im worried im gonna break something in the existing config for the equipment already connected to it *im not allowed to change so that dosnt work*&lt;BR /&gt;&lt;BR /&gt;a thousand thanks so far mate, you are gold!&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2017 13:26:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036251#M147489</guid>
      <dc:creator>k.lundgren91</dc:creator>
      <dc:date>2017-01-29T13:26:15Z</dc:date>
    </item>
    <item>
      <title>I am getting emails that</title>
      <link>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036252#M147490</link>
      <description>&lt;P&gt;I am getting emails that there have been updates to the discussion but when I come to the discussion page I do not see any updates. &amp;nbsp;I have sent a mail to support and asked them to check this.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Jan 2017 13:33:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/needs-basic-help-with-asa5505/m-p/3036252#M147490</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2017-01-29T13:33:44Z</dc:date>
    </item>
  </channel>
</rss>

