<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Config of new ASA 5510 transparent mode in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323282#M310509</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I went and removed the management int ip and gave that to the bvi int, but it won't allow me to put an ip to the management int, I don't have a way to access asdm or ssh now or is that done through the bvi int now but I can't ping the bvi ip. Somehow the system is not allowing me to put my internal ip's on both the bvi and man int, any ideas, thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;carlo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Oct 2013 17:00:43 GMT</pubDate>
    <dc:creator>Carlomd</dc:creator>
    <dc:date>2013-10-23T17:00:43Z</dc:date>
    <item>
      <title>Config of new ASA 5510 transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323278#M310505</link>
      <description>&lt;P&gt;Hi all, &lt;/P&gt;&lt;P&gt;&amp;nbsp; I'm new to ASA's and also since it's been a while since I configured any Cisco device, I'm re-learning most of this stuff, we got a new asa 5510 (actually a refurb) and need to get it setup into our existing network, I read it would be easier to put it in transparent mode than router if you have an existing network and dont wanna redo the whole thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp; Our current setup right now is, internet &amp;gt; cisco leased router(with a set of external ip's from ATT) &amp;gt; juniper ns25(our internal set of ip's mipped with the external) &amp;gt; internal network. So far I've put the asa in transparent mode and got the basics configured reading from some of the docs here and even some youtube vids, I've read the docs on transparent mode for the ASA's, one question is on the BVI 1, it won't allow me to put the same ip range as my internal, it needed a different one like right now I have 192.168.1.1 on it, I know there might be a few more things needed to get it right, here's my running conf right now, if you have any pointers or ideas to get me in the right direction, thanks in advanced.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;carlo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crxasa# sh run&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 9.1(2)8&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;firewall transparent&lt;/P&gt;&lt;P&gt;hostname crxasa&lt;/P&gt;&lt;P&gt;domain-name domain.com&lt;/P&gt;&lt;P&gt;enable password jtiwndTuzIDdTcxA encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;nameif outside&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;no security-level&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;no security-level&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt;management-only&lt;/P&gt;&lt;P&gt;nameif management&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.1.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface BVI1&lt;/P&gt;&lt;P&gt;ip address 208.36.7.11&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot system disk0:/asa912-8-k8.bin&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;clock timezone PST -8&lt;/P&gt;&lt;P&gt;clock summer-time PDT recurring&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt;domain-name domain.com&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;mtu management 1500&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-714.bin&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;no arp permit-nonconnected&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 management&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart&lt;/P&gt;&lt;P&gt;crypto ipsec security-association pmtu-aging infinite&lt;/P&gt;&lt;P&gt;crypto ca trustpool policy&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 management&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;ssh key-exchange group dh-group1-sha1&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;username admin password 571.UcWz1aqKyGh3 encrypted&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;Cryptochecksum:37fe70a1f301b2adb5136c6fce4ca9de&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;crxasa#&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:54:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323278#M310505</guid>
      <dc:creator>Carlomd</dc:creator>
      <dc:date>2019-03-12T02:54:59Z</dc:date>
    </item>
    <item>
      <title>Config of new ASA 5510 transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323279#M310506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK the BVI interface IP needs to be within the range of the network that is inter-connecting, so if you need to ARP for traffic on the 208.36.7.0/24 that would be the IP that you need to put on the BVI. If that is the case remove it from the configuration of the management interface if not the configuration is correct and you are just missing the next:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you need to add the interfaces that inter-connect on to the bridge-group:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif OUTSIDE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bridge-group 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bridge-group 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specifies the management IP address for the bridge group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do not assign a host address (/32 or 255.255.255.255) to the bridge&amp;nbsp; group. Also, do not use other subnets that contain fewer than 3 host&amp;nbsp; addresses (one each for the upstream router, downstream router, and&amp;nbsp; transparent firewall) such as a /30 subnet (255.255.255.252). The ASA&amp;nbsp; drops all ARP packets to or from the first and last addresses in a&amp;nbsp; subnet. Therefore, if you use a /30 subnet and assign a reserved address&amp;nbsp; from that subnet to the upstream router, then the ASA drops the ARP&amp;nbsp; request from the downstream router to the upstream router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA does not support traffic on secondary networks; only traffic on&amp;nbsp; the same network as the management IP address is supported.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; If by any chance you getting ARP from none direclty connected networks on the bridge please define: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;arp permit&lt;/EM&gt;-&lt;EM&gt;nonconnected&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 00:21:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323279#M310506</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-10-23T00:21:38Z</dc:date>
    </item>
    <item>
      <title>Config of new ASA 5510 transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323280#M310507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jumora, thanks for the help, so basically my internal ip needs to be in the BVI config and give that its own management ip, and remove the actual management port ip, I'm thinking of re-doing it over, maybe configuring the e0/0 and 0/1 first with the bvi group and add it's management ip, then followed by the actual int management port config. I'll let you know how it goes, I think I'll go through a few trial and error here, it's on a lab setup so I can break it down and start over. Thanks again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;carlo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 16:39:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323280#M310507</guid>
      <dc:creator>Carlomd</dc:creator>
      <dc:date>2013-10-23T16:39:08Z</dc:date>
    </item>
    <item>
      <title>Config of new ASA 5510 transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323281#M310508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great to here that I put you on the right track, have a nice one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI: If you believe that your questions have been answered please change the status to answered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 17:00:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323281#M310508</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-10-23T17:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: Config of new ASA 5510 transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323282#M310509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I went and removed the management int ip and gave that to the bvi int, but it won't allow me to put an ip to the management int, I don't have a way to access asdm or ssh now or is that done through the bvi int now but I can't ping the bvi ip. Somehow the system is not allowing me to put my internal ip's on both the bvi and man int, any ideas, thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;carlo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 17:00:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323282#M310509</guid>
      <dc:creator>Carlomd</dc:creator>
      <dc:date>2013-10-23T17:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Config of new ASA 5510 transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323283#M310510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you got to do this over console, what you can do to&amp;nbsp; avoid getting disconnected is the next, and this is me thinking that you&amp;nbsp; have a laptop connected to the ASA and not through your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reload the ASA, it will come back up with the previous&amp;nbsp; configuration if you saved it; log into the unit and instead of&amp;nbsp; removing the IP address from the interface Management0/0 overwrite it&amp;nbsp; and also remove the IP address from the BVI, folllow this example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable&lt;/P&gt;&lt;P&gt;config t&lt;/P&gt;&lt;P&gt;interface BVI1&lt;/P&gt;&lt;P&gt;no ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable&lt;/P&gt;&lt;P&gt;config t&lt;/P&gt;&lt;P&gt;interface Management0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address&amp;nbsp; 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will lose connection for a moment but as soon as&amp;nbsp; you reconfigure your LAN adapter to the 192.168.1.0/24 network you&amp;nbsp; should be able to connect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The reconfigure the BVI to the network that you need:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable&lt;/P&gt;&lt;P&gt;config t&lt;/P&gt;&lt;P&gt;interface BVI1&lt;/P&gt;&lt;P&gt;ip address &lt;IP_ADDRESS&gt; &lt;NETMASK&gt;&lt;/NETMASK&gt;&lt;/IP_ADDRESS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI: If you are near to the unit I would just console before I get everything set up.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 17:26:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323283#M310510</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-10-23T17:26:17Z</dc:date>
    </item>
    <item>
      <title>Config of new ASA 5510 transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323284#M310512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I'm consoled into it, I'll give this a shot, I'll keep you posted, thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;carlo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Oct 2013 17:41:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323284#M310512</guid>
      <dc:creator>Carlomd</dc:creator>
      <dc:date>2013-10-23T17:41:23Z</dc:date>
    </item>
    <item>
      <title>Config of new ASA 5510 transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323285#M310513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi all,&lt;/P&gt;&lt;P&gt; Finally got back to this project again, so I've had this in an internal lab setup, but I wanted to test this with our isp connection over the weekend, I been reading around some more to get familiar with the ASA, couple of questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. If I need to get our external public IP's from ATT to map with any of our internal sources like www and smtp, I just add those through acl's right, on our old juniper we used mip to set the external ip's with internal then allowed or denied in policies.&lt;/P&gt;&lt;P&gt;2. Do I have to use nat, I'm in trasparent mode and I wonder if that would be required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Coming from Juniper using the web interface the ASA can get daunting but I just need to get the hang of it, but there's a lot of good guides here and a pretty great support forum, looking fwd to finishing this project. Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;carlo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 23:13:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323285#M310513</guid>
      <dc:creator>Carlomd</dc:creator>
      <dc:date>2013-10-25T23:13:15Z</dc:date>
    </item>
    <item>
      <title>Config of new ASA 5510 transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323286#M310515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. If I need to get our external public IP's from ATT to map with any&amp;nbsp; of our internal sources like www and smtp, I just add those through&amp;nbsp; acl's right, on our old juniper we used mip to set the external ip's&amp;nbsp; with internal then allowed or denied in policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, only ACLs, make sure that you apply access-group on the lower security interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Do I have to use nat, I'm in trasparent mode and I wonder if that would be required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only if you requiere the ASA to do so because the device behind it is on a private network that is not routable over the Internet and your upstream device (ATT device) does not do NAT.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2013 23:37:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323286#M310515</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-10-25T23:37:39Z</dc:date>
    </item>
    <item>
      <title>Config of new ASA 5510 transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323287#M310517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi jumora, I got into a road block here with my config on the acl's, I have an asa book, and I read the config part of a transparent fw but somehow I can't get my lab setup to work going into the private lan, going out is fine since a rule of 100 allows most access outgoing, and seems like the samples on the book are outdated since I'm on asa9.1, can you take a look at my config and see what I'm missing, my setup in the lab is:&lt;/P&gt;&lt;P&gt;internal network &amp;gt;&amp;gt;outside int&amp;gt;&amp;gt;inside int&amp;gt;&amp;gt;switch&amp;gt;&amp;gt;pc, there's no router facing the inside int as what some samples show and I was wondering if that's the main issue, like now I'm testing rdp into the private lan and it won't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here's my basic config mainly showing acl's :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crxasa(config)# sh run&lt;BR /&gt;: Saved&lt;BR /&gt;:&lt;BR /&gt;ASA Version 9.1(2)8&lt;BR /&gt;!&lt;BR /&gt;firewall transparent&lt;BR /&gt;hostname crxasa&lt;BR /&gt;domain-name domain.com&lt;BR /&gt;enable password jtiwndTuzIDdTcxA encrypted&lt;BR /&gt;names&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/0&lt;BR /&gt; nameif outside&lt;BR /&gt; bridge-group 1&lt;BR /&gt; security-level 0&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/1&lt;BR /&gt; nameif inside&lt;BR /&gt; bridge-group 1&lt;BR /&gt; security-level 100&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/2&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt;!&lt;BR /&gt;interface Ethernet0/3&lt;BR /&gt; shutdown&lt;BR /&gt; no nameif&lt;BR /&gt; no security-level&lt;BR /&gt;!&lt;BR /&gt;interface Management0/0&lt;BR /&gt; management-only&lt;BR /&gt; nameif management&lt;BR /&gt; security-level 100&lt;BR /&gt; ip address 192.168.1.1 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;interface BVI1&lt;BR /&gt; ip address 208.x.x.x 255.255.255.0&lt;BR /&gt;!&lt;BR /&gt;boot system disk0:/asa912-8-k8.bin&lt;BR /&gt;ftp mode passive&lt;BR /&gt;clock timezone PST -8&lt;BR /&gt;clock summer-time PDT recurring&lt;BR /&gt;dns server-group DefaultDNS&lt;BR /&gt; domain-name domain.com&lt;BR /&gt;access-list outside-in extended permit icmp any any echo-reply&lt;BR /&gt;access-list outside-in extended permit icmp any any unreachable&lt;BR /&gt;access-list outside-in extended permit icmp any any traceroute&lt;BR /&gt;access-list outside-in extended permit icmp any any time-exceeded&lt;BR /&gt;access-list outside-in extended permit udp any any eq domain&lt;BR /&gt;access-list outside-in extended permit tcp any host 208.x.x.x eq 3389&lt;BR /&gt;http server enable&lt;/P&gt;&lt;P&gt;: end&lt;BR /&gt;crxasa#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 00:26:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323287#M310517</guid>
      <dc:creator>Carlomd</dc:creator>
      <dc:date>2013-10-30T00:26:40Z</dc:date>
    </item>
    <item>
      <title>Config of new ASA 5510 transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323288#M310519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you get me the show ARP, what is the IP of the layer 3 device that is in front of the ASA?&amp;nbsp; I need to know if the BVI IP address is under the same range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ASA enable logging &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging buffered debugging&lt;/P&gt;&lt;P&gt;logging buffer-size 1048576&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when you generate traffic look at the logs with "show log" and send me the output.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 01:28:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323288#M310519</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-10-30T01:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: Config of new ASA 5510 transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323289#M310521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok here's my arp and log attached, and my lab in the network is like below, the layer 3 device in front of the asa would be the leased router from ATT that connects to our internal network, I don't manage that, that will have ATT's public ip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;internal network (208.36.7.0)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;layer 2 linksys sw&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;outside int of asa&amp;gt;&amp;gt;bvi 1 (208.36.7.11)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;inside int of asa&amp;gt;&amp;gt;bvi 1 (208.36.7.11)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;2900 catalyst sw (208.36.7.96)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;PC (208.36.7.4), 2nd nic is for management int (192.168.1.1)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Oct 2013 16:55:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323289#M310521</guid>
      <dc:creator>Carlomd</dc:creator>
      <dc:date>2013-10-30T16:55:16Z</dc:date>
    </item>
    <item>
      <title>Config of new ASA 5510 transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323290#M310523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all, &lt;/P&gt;&lt;P&gt;I decided to change my config on the acl to object-groups and when I try to put them together to create an access-list I get this error, I'm still learning to get the hang of the ASA cli, the syntax is pretty tricky, I was reading the section on object groups in the asa book, seems like the sample doesn't work with asa 9.1, is there any config samples for 9.1 on object grouping and acl's, thanks in advanced -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crxasa# conf t&lt;BR /&gt;crxasa(config)# sh obj&lt;BR /&gt;object-group protocol TCP_UDP&lt;BR /&gt; description: Grouping of TCP and UDP protocols&lt;BR /&gt; protocol-object tcp&lt;BR /&gt; protocol-object udp&lt;BR /&gt;object-group service All-service&lt;BR /&gt;description: grouping of all services&lt;/P&gt;&lt;P&gt; service-object gre&lt;BR /&gt; service-object icmp echo&lt;BR /&gt; service-object tcp destination eq www&lt;BR /&gt; service-object udp destination eq domain&lt;BR /&gt;object-group network internal-servers&lt;BR /&gt; network-object host 208.36.7.4&lt;BR /&gt;object-group network internet-hosts&lt;BR /&gt; network-object host 208.36.7.98&lt;BR /&gt;crxasa(config)# access-list outside_access_in extended permit object-group TCP_UDP object-group All-service object-group internal-servers&lt;BR /&gt;ERROR: specified object group &lt;ALL-SERVICE&gt; has wrong type; expecting network type&lt;BR /&gt;Usage:&lt;BR /&gt;Extended access list:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Use this to configure policy for IP traffic through the firewall&lt;/ALL-SERVICE&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 00:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323290#M310523</guid>
      <dc:creator>Carlomd</dc:creator>
      <dc:date>2013-10-31T00:00:51Z</dc:date>
    </item>
    <item>
      <title>Config of new ASA 5510 transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323291#M310527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, look the issue is related to the format:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group TCP_UDP &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; This is related to TCP and UDP as protocols&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group All-service &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; This is related to GRE that is a protocol then ICMP that is a protocol and then you mention TCP port 80 and UDP 53&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group internal-servers &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; that mentions a server IP 208.36.7.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You cannot combine different objects related to protocols.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tell me what you want to allow a towards where and I can help you with the format.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 17:44:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323291#M310527</guid>
      <dc:creator>jumora</dc:creator>
      <dc:date>2013-10-31T17:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: Config of new ASA 5510 transparent mode</title>
      <link>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323292#M310530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jumora,&lt;/P&gt;&lt;P&gt;I got that from the 2nd ed asa book samples for acl grouping, I attached some screens from the book, I was following the samples but just changing the ip's to my internal network, basically I'm just trying to get 208.36.7.98(this is on my interet hosts obj group) on the outside to be able to get to 3389, http, smtp to the inside 208.36.7.4 (I put this on my internal servers obj group)&lt;/P&gt;&lt;P&gt;I will need to use acl grouping to save from having a ton of entries. I just need to get the hang of the syntax, on my juniper I used the web interface so it was easy to create the entries, but I wanted to start right with the ASA using cli and get the hang of it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;update&lt;/SPAN&gt;: got the access-list to accept the syntax, I needed to add object-group all-services and tcp_udp seperately. I thought you can combine them in one command. It's getting clearer to me now, got the 1st access rule set and working. Thanks for all your help and pointers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Nov 2013 16:44:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/config-of-new-asa-5510-transparent-mode/m-p/2323292#M310530</guid>
      <dc:creator>Carlomd</dc:creator>
      <dc:date>2013-11-01T16:44:05Z</dc:date>
    </item>
  </channel>
</rss>

