...
...
Hi everyone,I tried to create an ACL for IPv6. But the acl always drops my packetes. Only in case I allow an Permit Icmp6 any any statement. It works.With detailed IPv6 entries. I have got drops.ipv6 access-list ipv6-inside; 6 elements; name hash: 0x...
Hello Looking for a recommended code on the ASA 5585x firewall. We ran into a bug (CSCtr24705) on version 8.4.2 where it rebooted the primary firewall. The bug has to do with modifying an existing ACL that's part of a custom policy-map inside a serv...
We support many clients and we have found that many of them are sharing VPN credentials when logging in via AnyConnect/WebVPN. We were thinking about restricting simultaneous log in to 1. I also know that users may have situations where they lock up ...
Hello everyone,I have an issue with an 4255 IPS using an inline VLAN pair. Here's the rough sketch of the topology:SW1port 1 access vlan 10 - PC (10.20.30.2/24)port 48 trunk to SW2 - all vlans allowed and forwardingSW2port 48 trunk to SW1 - all vlans...
Customer with an internal network with several VLAN, Switch Layer-3 and Firewall.VPN L2L with site B.Now I need to add a leased line that directly connect site A with site B.To protect my Network, I would like to connect this leased line to a new DMZ...
First off, I'm by no means an ASA expert and I was just starting to understand things before 8.3 came out. I have a 5512 that I'm trying to put in. I think I've got everything configured correctly for the most part, but I need help with the last pie...
I am trying to configure an IPSEC vpn on an ASA5505I setup an SSL vpn and it works fine, I can browse to the https: address log in and connnect to serversHowever when I try to setup the ipsec client access vpn it will not connect and I am getting the...
Hi everyone,I just got 2 Cat6504 Chassis and 2 ASASM pluged in them. show version from submodule ASA as follow:SVC-APP-HW-3#show verCisco IOS Software, trifecta Software (trifecta-SP-M), Version 15.1(1)SY, RELEASE SOFTWARE (fc2)Technical Support: htt...
Hi out thereJust got my attention on this other discussion on hign cpu on ips module - we have a set of 5585x where the ips module (quad core) is showing very high cpu utilization - 75% - according to the IME 3 of the 4 cores are running 100% and the...
Hey,I would like to know if ACL could filter specific packet type or unique packet id. How does it work? Let's say i have some captured packets, how do i filter some of them?For example: i want to stop Meterpreter to open a session. I've analyzed the...
I'm currently working on setting up 2 ASA 5510's with redundancy/failover. I'm not an expert when it comes to the ASA's so I'm not 100% sure if I can do what I need to.I have 2 inside networks that need to remain separate, a DMZ network,and an outsid...
Hello,This question is in the context of servers sitting in a colocation environment behind an ASA5510 with security plus license.Our colo provider is going to be statically routing a /28 public subnet to our ASA5510 (say 1.1.1.0/28). We will also b...
At my last count there were 182 different "match protocol" statementsone could put in an inspection class-map.Some of these inspections are there only to allow you to filter on L7fields. Some, FTP for example, must be in your class map or active-mod...
Hi allcustomer has ASA cluster pair which is running 8.2 (5) This firewall is participating in the OSPF process, and the affected interface are in the "Area 0". "Remote stations" are also a Cisco components (eg, WS-C3750-24TS-S with 12.2 (44) SE5, Wh...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide
Subject | Author | Posted |
---|---|---|
07-16-2025 04:21 AM | ||
07-06-2025 01:40 PM | ||
07-04-2025 01:59 AM | ||
06-19-2025 07:32 AM | ||
06-17-2025 01:07 PM |
User | Count |
---|---|
8 | |
7 | |
7 | |
2 | |
1 |