Hi all, I just want to know how to force ASA use udp/4500 as a phase-II of IPSec VPN all the time. How to disable Automatic NAT Detection features? Toshi
Hi all, I just want to know how to force ASA use udp/4500 as a phase-II of IPSec VPN all the time. How to disable Automatic NAT Detection features? Toshi
Two questions really.Q1. What is a safe peak for a cluster (Active/Standby) pair of ASA 5520's?During different times of the day, I can see major peaks that push the ASA cluster into the high 80's and low 90% utilization.Q2. To combat these peaks, I'...
I have a pair of ASA5550 with OSPF enabled on the outside interfaces with our internet routers. Firewalls get the candidate default route from the internet routers.Anyway, when I do a "sh ospf interface" all interfaces are listed under area0..it shou...
HiI have a PIX 515E that i have to upgradecurrently it's running 6.3(5)and i'm going to 8.0(4)28,what i wanted to know is do i have to upgrade to 7 before i can upgrade to 8.Or can i go directly to version 8
Hi all I have an IPS running 6.1(1) image with E1 engine.I want to upgrade this to E3.Is to possible to upgrade directly to E3?.What are the things to consider for upgrading the Engine(i want to upgrade manually)? Is there any advange on E3 over E2 o...
I have a natted network , all the users in side are accessing one global server Exchnage server xx.xx.xx.21, now i want to implement a rule in my local firewall to block traffic , so that usera cant not access this global server \\xx.xx.xx.21 using f...
When configuring a CatOS switch to work with the ASA sub-interfaces, are these the right commands? Thanks much.clear trunk 2/28 1-91,94-1005,1025-4094set trunk 2/28 on dot1q 92-93
Is using identity nat as compared to nat exemption merely a preference, or are there benefits to one over the other? I've changed all of my identity nats over to policy nat, but I'm not sure (other than ease of reading and it doesn't add to the xlate...
Hi,Is it possible to create a NAT statement on an ASA that NATs a source address to an IP address that is not part of a subnet on the ASA?I want to NAT a source address from the inside interface to a public IP address. I will configure a static route...
Hi Problem1: I am trying to upgrade pix 515e from 6.3(1) to 8.0(4) version in monitor mode and I am not able to do that. monitor>interface 1 address 192.168.16.250 server 192.168.16.20 (my laptop with tftp program on) file pix804.bin tftp I get the b...
We have an IRC Network based on IRCD, we keep getting ddosed by people, servers are falling apart, so we currently did not find a way on how to block the ddos packages,i was wondering if you could be kindly and suggest me somethin about it , anything...
Is there any doc which tells about the best practice on ASA.Like the one we have on C6500.Awaiting reply,ThanksRaj
hi there,I'd like org users to connect to the internet thru vpn once conenction established. I have an easyvpn server installed on cisco 1711 router.Users can connect to the vpn but uable to browse the internet.Need help please - I have attached my c...
So, I was doing some testing this weekend, and I had noticed something that I wanted someone to verify my findings. In an ASA, if I create an acl and policy nat, it seems that it's two directions.access-list NONAT permit ip 192.168.1.0 255.255.255.0 ...
All,Is there documentation somewhere that states how many users can run behind pat? I've got between 300 - 1000 at any one time that can be on, and currently I'm using the interface address on the asa to do this with. I was wondering if I needed to s...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide
| Subject | Author | Posted |
|---|---|---|
| 09-30-2026 08:23 AM | ||
| 09-22-2026 04:13 PM | ||
| 08-25-2026 06:22 PM | ||
| 08-24-2026 12:26 AM | ||
| 08-20-2026 05:54 AM |
| User | Count |
|---|---|
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |