Network Security

Engage with peers and experts on network security topics such as FTD, FMC, FDM, CDO and ASA.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

“Join

 
Labels

Forum Posts

Hi, i have problem configuring DMZ to access outside.I'm not able to ping from DMZ network to DMZ interface (gateway) neither am i able to contact the internet with DMZ hostsI'm able to ping from LAN to LAN gateway (inspect ICMP service policy) inter...

hi,i created a S2S VPN and the ASA2's internet connection isn't that good and some packet losses would be 'normal'.i'm not sure if that relates to the unequal encap/decaps on my 'sh crypto ipsec sa' output.is the below reading normal? ASA1:      #pkt...

I am doing some testing of access and identity policies and need to make sure that when I run a test of changes to the policies that I am seeing accurate results vs. getting inaccurate results due to the ASA still using active flow or cached settings...

tato386 by Level 6
  • 790 Views
  • 4 replies
  • 0 Helpful votes

hi all,apologies for my NAT getting rusty, just a quick confirmation if my identity NAT below is correct: object network IDENTITY-NAT-OBJ  host 111.203.23.1object network INSIDE-NET-OBJ  host 111.203.23.1  nat (inside,outside) static IDENTITY-NAT-OBJ...

So i understand the basic syntax for NATing a single internal network to an outside interface for allowing internet access.  Something like below... object network NAT_INSIDE_NETS  subnet 10.0.0.0 255.255.255.0object network NAT_INSIDE_NETS  nat (ins...

We have 2 IP camera in the computer room and we would like to use an acl to control http access to the individual IP addresses and only leave the access through the server.  The server is on port 21. The Cameras are on an unmanaged switch hooked to t...

laren_lrb by Level 1
  • 1537 Views
  • 2 replies
  • 0 Helpful votes

Hello,we have 2 ASA 5520s (active/standby) which have a throughput of 450mbps and we have been hitting this recently and the CPU goes through the roof and I see overruns too.I've been using this method to gather the stats, but it is too manual and I ...

Hi, community! Bug CSCur94645 is related to incorrect packet generated by ASA, when you try to log in ASDM via RADIUS authentication.As it seen in bug description - it's fixed, but fixed releases include some strange one: 100.12(0.109)100.13(0.14)100...

ditrizna1 by Level 1
  • 334 Views
  • 2 replies
  • 0 Helpful votes

We are getting ready to upgrade from a FWSM running 4.0x to an ASASM 9.1.5. I have run the migration tool and uploaded the config to startup and let it boot. I have seen several references to having the change access-lists to use the real IP not the ...