What makes the CISCO ASA to remove nonat when we enable access in tcp or udp level
What makes the CISCO ASA to remove nonat when we enable access in tcp or udp level
We got our first of many 5500-X ASA's in, and found there are 3 code, 8.6.1, 9.0.1, and 9.1.1. Out of these, which one should we go with? We use them single context with Voice SIP and H323 transisting the ASA, so SIP needs to be stable, we also do...
Hi,We having FWSM running ver 4.1.11. We have configured deny ACEs with log command at the end of ACL but when give show logging, there is no any deny ACL logs and it shows simply only the system logs. We verified with changing logging buffered level...
Hello all,I think the title says everything, but I will go into more detail. I want to define an auto NAT as kind of a catch all for the 10.0.0.0 /8 subnet. This would be a PAT to the outside interface and look similiar to this. object network NAT-I...
Dear allI have FWSM and I configure it to send the logs to the manage engine firewall Analyzer to analyze the logs and give the monthly report. The FA is giving me the top hosts and destinations by bytes.Current config on the FWSMlogging enableloggin...
Hi,I have IPS 4270, is there signature for port scanning, so that it fires when any user run the scan (angry port scan, etc.....), if not can i creat a signature for this, how ???thankssss
Hi,I'm trying to source and destination NAT a connection over my ASA. I am using Twice NAT for this. The config looks like that:object network OBJ_HOST1 host 172.18.45.245object network OBJ_HOST1_MAPPED host 172.29.1.12object network OBJ_192.168.10.0...
Hi,Have a 5545X with 5545-IPS module. It is up, updateing signatures but there are no packets checked on it. On the sensor side I'm confused that hardware/software version is shown as N/A. ASA config:access-list test extended permit ip interface outs...
Hello everyone,is it possible to run a firewall cluster over an ADSL internet connection with a single IP address? My thoughts say, that it is not possible and that it would be neccesary to place a router before the two firewalls and work with a tran...
I am aware that we can allow external admins to telnet over a custom port to the internal router. Even i was allowed to connect to a remote router via the remote firewall. The way i was accessing the router is by telnet to the remote ASA address on p...
Hey guys,We have a 5585X running in multi context mode, and we are getting log entries for scanning threat detection, such as:%ASA-4-733100: [ Scanning] drop rate-1 exceeded. Current burst rate is 2 per second, max configured rate is 10; Current aver...
Hello when we are configuring ASA 5510 8.2(5) for Authenticating with ACS 5.X Server is not authentication fail error.
I have an issue with ACLs I have FTP forwarded via PAT to an internal server on my edge router. I have a rather extensive ACL that denies spider servers and certain ranges i know to be spammers. The issue lies in FTP. When the ACL is applied to my ou...
Helo,I am a total Cisco novice who has just had a ASA5505 installed to replace a linux freeware firewall (smoothwall).I'm told that the 5505 can't port forward traffic (e.g. ssh) from two external IP addresses to two internal destination machines via...
if you create 100 acl with in that 100 acl we need to create new acl middle of that 100 acl how can you write acl middle of acl with out over write before create acl
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide
| Subject | Author | Posted |
|---|---|---|
| 05-05-2026 09:59 AM | ||
| 05-02-2026 06:09 AM | ||
| 04-30-2026 12:46 AM | ||
| 04-24-2026 07:04 AM | ||
| 04-22-2026 11:56 AM |