cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
453
Views
0
Helpful
1
Replies

ASA5505

helow guys ,

i have many problem with ASA5505 version 9

1- I save factory default configuration  (write memory )after command " config factory default " but when i make reload i found no configuration saved . my question from where i know the device booting the configuration file ? .

 

2- i want to ask after i make factory default , my inside network can access internet without more configuration or i have to allow outsidenetwork to access my internal network ?

 

ciscoasa(config)# sh running-config 
: Saved
:
ASA Version 9.0(3) 
!
hostname ciscoasa
enable password 8Ry2YjIyt7RRXU24 encrypted
names
!
interface Ethernet0/0
 switchport access vlan 2
!
interface Ethernet0/1
!
!
interface Vlan1
 nameif inside
 security-level 100
 ip address 192.168.1.1 255.255.255.0 
!
interface Vlan2
 nameif outside
 security-level 0
 ip address dhcp setroute 
!
ftp mode passive
object network obj_any
 subnet 0.0.0.0 0.0.0.0
pager lines 24
logging asdm informational
mtu outside 1500
mtu inside 1500
icmp unreachable rate-limit 1 burst-size 1
no asdm history enable
arp timeout 14400
no arp permit-nonconnected
!
object network obj_any
 nat (inside,outside) dynamic interface
timeout xlate 3:00:00
timeout pat-xlate 0:00:30
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
timeout floating-conn 0:00:00
dynamic-access-policy-record DfltAccessPolicy
user-identity default-domain LOCAL
http server enable
http 192.168.1.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart
crypto ipsec security-association pmtu-aging infinite
crypto ca trustpool policy
telnet timeout 5
ssh timeout 5
console timeout 0

dhcpd auto_config outside
!
dhcpd address 192.168.1.5-192.168.1.132 inside
dhcpd enable inside
!
threat-detection basic-threat
threat-detection statistics access-list
no threat-detection statistics tcp-intercept
!
!
prompt hostname context 
Cryptochecksum:8f6339a57a322a0de5de1e9703e95198
: end
ciscoasa(config)# 

 

 

 

 

3- i want to make port forwarding any one write my real ip : 3389  forward to local server with the same port .

outside ip . 41.41.41.41/30   port (3389)

 inside ip   192.168.1.5     port 3389

1 Reply 1

Marvin Rhoads
Hall of Fame
Hall of Fame

1. The startup-config is stored in a hidden area on the system partition of the internal compact flash card (disk0:)

2. With a default configuration as you show above, internal hosts on the 192.168.1.0/24 subnet will be NATted to use the outside interface address and reach the Internet (assuming the outside interface obtained a DHCP address from an upstream device and that device routes to the Internet).

3. Follow the menu for setup of public server in the ASDM configuration tool to do this most easily.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: