Network Security

Engage with peers and experts on network security topics such as FTD, FMC, FDM, CDO and ASA.
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

“Join

 
Labels

Forum Posts

I have configured 2 ISP on ASA 5505 which is using IP SLA to track internet connection . Following is Static NAT configurationstatic (inside,outside) tcp ISPA_Second_IP 3389 Jonas 3389 netmask 255.255.255.255static (inside,outside) tcp ISPA_Third_IP ...

Hello,I have WiFi device (host 10.6.16.21) which needs to connect to remote server (172.25.20.26 on TCP port 3613)  over L2L VPN tunnel. I see that the device is attempting connection, but it is being reset:%ASA-6-302014: Teardown TCP connection 2175...

forman102 by Level 1
  • 1688 Views
  • 1 replies
  • 0 Helpful votes

Resolved! DMZ Nat question

I have a setup like this (not real addresses--just testing here)interface Ethernet0/0 nameif outside security-level 0 ip address 12.200.200.1 255.255.255.0 !interface Ethernet0/1 nameif inside security-level 100 ip address 10.100.1.1 255.255.255.0!in...

     In a scenerio where an ASA has a Guest interface (security level 50) has only a single OUT acl applied (access-list guest.out extended deny ip any any / access-group guest.out OUT interface guest) and an outside interface (security level 0) conn...

My setup is as follows(        vlan 10                  )     (                 vlan 20                 ) ---  (vlan 30)172.21.1.30 ---- insideASA<  >outsideASA ---- gw-172.21.1.25 ---- clientThe server in vlan 10 is on the same subnet as the gateway...

Users are reporting lots of problem with the Internet at my office.  Mostly slow speeds and pages that do not fully load.  I did a "sho asp drop" on the ASA and got the info below.  Not sure what is OK or not but the large amount of out-of-order buff...

tato386 by Level 6
  • 1694 Views
  • 2 replies
  • 0 Helpful votes

Hi,As I am trying to create site to site VPN.The other side they have given me parameters.Phase 2 parameter is esp-3des esp-sha-hmac.SIM IP subnet is 10.85.170.0/23 and VPN gateway is 41.220.75.1IKE Encryption (Phase 1): 3DESIKE Hash (Phase 1): SHA1I...

Resolved! ASA 8.2.1 to 8.4.3

Hi,We are planning to upgrade our ASA 5520 from 8.2.1 to 8.4.3. Could you please help me asking the following questions?1. Which is the best migration plan to follow 8.2.1->8.3->8.4.3 or 8.2.1 to 8.4.3>?     We are using nat-control now and for this ...

Hi all,i've been using a the classmap "class-map type inspect match-any min-cls-insp-in-out"  in a policymap "policy-map type inspect min-pm-in-out" in the zone security "ccp-zp-in-out source" for my firewall. I've just noticed a "match protocol Othe...

Koblensky by Level 1
  • 3156 Views
  • 7 replies
  • 0 Helpful votes

Hi guys,I'm having issues with NAT dropping ICMP on default NAT. Do I need to create another NAT for ICMP? Please let me know. Thank you in advanced.Here's the packet-tracer result:firewall01# packet-tracer input inside icmp 172.23.1.74 0 10 8.8.8.8 ...

ja raju by Level 1
  • 3918 Views
  • 4 replies
  • 0 Helpful votes