Network Security

Engage with peers and experts on network security topics such as FTD, FMC, FDM, CDO and ASA.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

“Join

 
Labels

Forum Posts

I currently have a NAT statement on my firewall for a public facing server which looks like this:nat (any,any) source static any any destination static server_ext_ip server_int_ipTypically I believe this would be better off as an object NAT but for n...

Matthew by Level 1
  • 440 Views
  • 3 replies
  • 0 Helpful votes

I have an ASA-5505 running 8.4  I have entered the following ... object service WLG-Rng-1 service udp source range 10000 11000Then this ..nat (inside,outside) source static VOIP-Sys-4 interface service WLG-Rng-1 WLG-Rng-1The nat command fails with "E...

Hello,Does anyone knows how long are the IP-to-user mappings kept on the Cisco Context Directory Agent?Is there a setting that dictates for how long to keep these mappings if a user doesn't logoff? The scenario i have seen is that user lock their PCs...

lm20ele by Level 1
  • 1639 Views
  • 5 replies
  • 0 Helpful votes

Hi All, Please correct me If I am wrong. I am upgrading from 8.0 to 8.4. One of my customer has nat rules in 8.0 as belowFor all the access lists for below they used permit ip any anynat (inside) 0 access-list xxxxxnat (outside) 0 access-list xxxx ou...

i'd like to change the outside address that my 5540 listens on for our ipsec vpn clients, where exactly do i change this?  perhaps in nat rules (tcp 1000?) we have a /29 and i'd like to replace our pix that is serving as our vpn and would love to reu...

Hi All,Recently observed constant high cpu in asa firewall with version 8.2.5 - 80% utilization. The process consuming more cpu is - tmatch compile thread around 60%. Do you recommend downgrade to 8.2.3 or is it an opened bug in the current version 8...

secureIT by Level 4
  • 2043 Views
  • 5 replies
  • 0 Helpful votes

I have an ASA 5512 running asa915-smp-k8.bin I enter the following commands and get this error.FW-5512-ASA(config)# object network TCP_OWA_443FW-5512-ASA(config-network-object)# nat (inside,outside) static interface service tcp https httpsERROR: NAT ...

burleyman by Level 8
  • 2381 Views
  • 2 replies
  • 0 Helpful votes

I want to PAT traffic from the remote sites after it arrives at the ASA from the site 2 site VPN and as it goes out the "inside" interface. See attached diagram.I want traffic from 192.168.90.0/24 to be PAT to 192.168.36.90 as it goes out the "inside...

burleyman by Level 8
  • 5977 Views
  • 14 replies
  • 0 Helpful votes