05-11-2011 08:17 AM - edited 03-11-2019 01:32 PM
I am troubleshooting a s2s vpn between an ISR871 and my ASA5520 and I suspect a problem with my crypto-maps.
Is there a way I can display an access-list on the ASA and have the object names substituted with their IP addresses?
Thanks very much.
John
Solved! Go to Solution.
05-11-2011 10:34 AM
John,
I am really glad it worked for you. Yes, "no names" command is revertible, all you need to do is give the command "names" back on to the ASA, and it would show the names again.
Just for your future reference, this is the command reference link for ASA 8.2:
http://www.cisco.com/en/US/partner/docs/security/asa/asa82/command/reference/no.html#wp1769321
If you can provide me the correct software version, i can provide you the command ref for that as well.
Hope this helps.
Thanks,
Varun
05-11-2011 10:43 AM
John,
Here are a few documents which would definitely help you in the future for ASA 8.0
CLI config guide:
http://www.cisco.com/en/US/partner/docs/security/asa/asa80/configuration/guide/conf_gd.html
Command Ref:
http://www.cisco.com/en/US/partner/docs/security/asa/asa80/command/reference/cmd_ref.html
ASDM config guide:
http://www.cisco.com/en/US/partner/docs/security/asa/asa80/asdm60/user/guide/usrguide.html
Syslog messages:
http://www.cisco.com/en/US/partner/docs/security/asa/asa80/system/message/syslog.html
Hope this helps.
Thanks,
Varun
05-11-2011 10:20 AM
Hi John,
Well if you are using names, then if you do "no names" on the firewall, it would substitute the names with the IP addresses. But if you are talking about object-group names being used in ACL, then I am afraid there is no such way, although if you do "show access-list
Hope this helps.
Thanks,
Varun
05-11-2011 10:27 AM
Hi Varun,
Thank you for your reply.... was very helpful. Yes, I was referring to names (i.e. for hosts, and networks, etc) and not actually object-groups... sorry for the confusion.
So if I issue the "no names" command, that will blow away all the names commands in the config, correct? I guess it's not reversible either, is it?
It would be nice to have that option when using the "show access-list" command to specify only IP addresses be displayed.
Thanks again.
John
05-11-2011 10:34 AM
John,
I am really glad it worked for you. Yes, "no names" command is revertible, all you need to do is give the command "names" back on to the ASA, and it would show the names again.
Just for your future reference, this is the command reference link for ASA 8.2:
http://www.cisco.com/en/US/partner/docs/security/asa/asa82/command/reference/no.html#wp1769321
If you can provide me the correct software version, i can provide you the command ref for that as well.
Hope this helps.
Thanks,
Varun
05-11-2011 10:37 AM
OK, cool... that'll do the trick fo rme for sure! Thanks a lot.
BTW, my version info is:
Cisco Adaptive Security Appliance Software Version 8.0(4)
Device Manager Version 6.1(5)51
05-11-2011 10:43 AM
John,
Here are a few documents which would definitely help you in the future for ASA 8.0
CLI config guide:
http://www.cisco.com/en/US/partner/docs/security/asa/asa80/configuration/guide/conf_gd.html
Command Ref:
http://www.cisco.com/en/US/partner/docs/security/asa/asa80/command/reference/cmd_ref.html
ASDM config guide:
http://www.cisco.com/en/US/partner/docs/security/asa/asa80/asdm60/user/guide/usrguide.html
Syslog messages:
http://www.cisco.com/en/US/partner/docs/security/asa/asa80/system/message/syslog.html
Hope this helps.
Thanks,
Varun
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide