<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: replace 1811 router with ASA 5505 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581305#M568461</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;here's the sanitized config of the 1811. I appreciate your input. Please let me know what other issues you notice with this conversion. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 30 Jan 2011 03:31:58 GMT</pubDate>
    <dc:creator>lcaruso</dc:creator>
    <dc:date>2011-01-30T03:31:58Z</dc:date>
    <item>
      <title>replace 1811 router with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581304#M568460</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hi, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please see the attachments. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm trying to come up with the config that would allow me to replace an 1811 router with a ASA 5505.The ASA has a Security Plus license.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;While there are many unfortunate features of the current network design that could be vastly improved, I'm currently constrained to simply replacing the 1811 with the 5505. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The first issue is the 1811 has an ip local pool that hands out dhcp addresses to clients behind the 851 router over a site-to-site vpn. This is an issue because when try to define the dhcpd server and use interface outside, it complains that cannot be done with this error message&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;dhcpd address 172.x.x.1-172.x.x.32 outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Address range subnet 172.x.x.1 or 172.x.x.32 is not the same as outside interface subnet 68.x.x.18&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How do I work around this and create the same functionality?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:41:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581304#M568460</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2019-03-11T19:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: replace 1811 router with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581305#M568461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;here's the sanitized config of the 1811. I appreciate your input. Please let me know what other issues you notice with this conversion. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jan 2011 03:31:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581305#M568461</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2011-01-30T03:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: replace 1811 router with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581306#M568462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another issue I have is there is a helper-address on the 1811 vlan1 interface.&lt;/P&gt;&lt;P&gt;I understand the ASA 5505 series cannot provide helper addresses. How do I deal with this? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jan 2011 03:39:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581306#M568462</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2011-01-30T03:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: replace 1811 router with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581307#M568463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately the DHCP capacity of the ASA firewall is very limited. It is intended for SOHO. As you can see on the document below, the ASA cannot handle Addresses to host that are not directly connected to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;"DHCP clients must be directly connected to the interface on which the server is enabled." &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA firewall does support DHCP relay (Helper address) However, it does have some limitations. I suggest you to please read the following document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/dhcp.html#wp1059065"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/dhcp.html#wp1059065&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jan 2011 04:05:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581307#M568463</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2011-01-30T04:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: replace 1811 router with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581308#M568464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to this document: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/dhcp.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/dhcp.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DHCP clients must be directly connected to the interface on which the server is enabled. &lt;BR /&gt;I believe this is why the ASA complains about the pool not being on the same range as the outside IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA has a DHCP relay functionality that I believe could be used for ''ip-helper'' (explained on the above link as well).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jan 2011 04:08:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581308#M568464</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-01-30T04:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: replace 1811 router with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581309#M568465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so the solution is to use another ASA 5505 where the 851 router sits. Would you agree?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jan 2011 04:16:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581309#M568465</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2011-01-30T04:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: replace 1811 router with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581310#M568466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for all of your great posts which are very timely as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jan 2011 04:17:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581310#M568466</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2011-01-30T04:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: replace 1811 router with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581311#M568467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You're very welcome &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I guess it depends what was the motivation behind the idea of replacing the 1811 witht the ASA 5505.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As it was mentioned, the ASA lacks the ability to deliver DHCP to non-directly connected users, so you might want to stick with the 1811.&lt;/P&gt;&lt;P&gt;But, staying with the 1811 is an option for you? Do you need any features particulary to the 5505?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jan 2011 04:23:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581311#M568467</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-01-30T04:23:18Z</dc:date>
    </item>
    <item>
      <title>Re: replace 1811 router with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581312#M568468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the link and your discussion. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Unfortunately the DHCP capacity of the ASA firewall is very limited. It is intended for SOHO.&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assume you mean the ASA 5505 offers these limitations instead of the ASA platform in general. Would a 5510 have the capability to hand out addresses to a subnet not directly connected?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This site does not have more than 100 users which fits the SOHO criteria. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jan 2011 14:06:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581312#M568468</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2011-01-30T14:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: replace 1811 router with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581313#M568469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Do you need any features particulary to the 5505?&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The site has been unmanaged for a couple of years and has security issues. It has become a target for hackers and internally it is unknown what security issues may exist. Need to intervene with a manageable firewall to easily see what is getting in/out, save and review logs, create and manage policies, provide alerts, defeat denial of service attacks, shun attackers, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 1811 only has two static routes and runs no routing protocols. I know the IOS Firewall is effective, but not as manageable in my estimation. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jan 2011 14:23:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581313#M568469</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2011-01-30T14:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: replace 1811 router with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581314#M568470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Remote access vpn with anyconnect was another requirement&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jan 2011 16:55:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581314#M568470</guid>
      <dc:creator>lcaruso</dc:creator>
      <dc:date>2011-01-30T16:55:22Z</dc:date>
    </item>
    <item>
      <title>Re: replace 1811 router with ASA 5505</title>
      <link>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581315#M568471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would not argue with you about moving to a 5505 but for you to know the ZWF (Zone-based Firewall) that can be configured on the router along with security measures can make the router really secure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, the remote AnyConnect can be configured on the router as well.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Jan 2011 17:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/replace-1811-router-with-asa-5505/m-p/1581315#M568471</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2011-01-30T17:24:26Z</dc:date>
    </item>
  </channel>
</rss>

