01-13-2013 12:11 PM - edited 03-11-2019 05:46 PM
Hello Community,
I'm about to set up as ASA configuration with GNS3 ASA's(see link/attachment). Can someone please show how to best test the configuration once complete?
I need something like a verification plan to ensure that the configuration would perform if in production.
Alternatively, if you could point me to sample ASA configurations that include a verification or test plan that would also be great.
Cheers
Carlton
01-13-2013 12:43 PM
Hi,
I guess this mostly depends how complex each context is going to be.
The only thing I can think of at the moment would be the "packet-tracer" command on the CLI. Same can be found on the ASDM side also.
What this command does is that it shows you what rules/configurations/translations the ASA would apply to the packet if it were to enter the ASA
Basic command format is
packet-tracer input
Where
I personally use the above command to test NAT rules quite often after I've done some changes. I might also use it in cases where I have a large ACL on an interface and want to quickly test if a certain connection would pass the ACL and to which ACL line it would "hit".
I used this command quite a lot in my biggest migration project from pre 8.2 environment to post 8.3 environment. This was mostly because I didnt use any tool to convert the NAT rules but just went through them one by one and when I was done I confirmed with "packet-tracer" that everything was working OK.
In the end I ended up with only 1 NAT that wasnt working but it was simply due to Copy/Paste problems. Had a wrong destination interface in a Static NAT command.
There are naturally alot of commands to go through the firewall when you have configured it but I would say that "packet-tracer" command gives the most information out of all of them.
Please do rate if you found the information helpfull and/or ask more questions.
- Jouni
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide