cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
869
Views
6
Helpful
9
Replies

ASA Firewall Concept

_Zy._
Level 1
Level 1

Recently, I had a lab that needed configuration for the internal and external network environments with ASA firewall devices and certain ACLs. It's kind of confusing about the setting with the ASA firewall. yet master it at all; hopefully someone could assist me with these.

Configuration.png

While I'm applied these ACL, those IP from Internal starting from 192.168.X.X still unable to get access to the External Network.

 

 

 

1 Accepted Solution

Accepted Solutions

Hi @_Zy._ 

  I took a look on your project and I fix a few things.  From the PC on Private network you can access the server on the Public network. 

 Take a look and see if that resolve your problem. Let me know if you have any doubt. 

View solution in original post

9 Replies 9

you edit the post. 

For you I install packet tracer which is against my idea
I will take look and see

Ya, I'm sorry about that too. But your comment is good for me as well. coz I'm yet master it. Thanks for your comment.

 

Hi @_Zy._ 

  I took a look on your project and I fix a few things.  From the PC on Private network you can access the server on the Public network. 

 Take a look and see if that resolve your problem. Let me know if you have any doubt. 

May I know which part of the configuration is wrong? So far, I have recognized that you have just added a static route at the centre router 1 and changed the position of the routing protocol at the firewall.

 

Hi

 Of course.  The network was pretty well configured. I dont remember every detail to be honest. But one thing I always do in network like this I change the firewall interface´s security level to 0 and remove the ACL just to make sure the routing is ok. When the routing is fine I return the security config on Firewall. 

 You need to ping first even though ping will not be allowed at the end. 

 I have found some issue with routing but one problem you may faced and did not realized is that you server was not reply ping. It must be some PacketTracert problem. I replaced the server and the new one was responding normally. 

 Always have a second guess about servers. I had seeing servers not responding many times on PT.

I'll go though check again with all the details. And thanks for your time as well.

 

the packet tracer is full of bug 
use GNS3 or eve-ng it better 
anyway good that issue solve, I try today and find routing issue, ACL is good but Server is not work that new in Packet tracer. 

Time for me to change the environment to GNS3. Thanks for your assistance as well.

 

Review Cisco Networking for a $25 gift card