cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
103
Views
0
Helpful
2
Replies

Problem while replacing an ASA firewall

Ab26
Level 4
Level 4

I have an old ASA firewall that I want to replace. The FW is used for guest access, where clients are redirected to a portal when they first connect to the network.

After replacing the FW, clients were no longer redirected to the portal. I copied the exact CLI config from the old FW and pasted it onto the new firewall.

What could be the problem? 
I think the portal is configured on a WLC, and maybe the redirect handled by an ISE. Is it possible that the APR table in the WLC/ISE must be flushed when the new FW is connected?

2 Replies 2

@Ab26 is the basics working such as routing working? From the firewall can you ping the source networks and the portal?

Run packet-tracer from the CLI to simulate the traffic flow, provide the output for review. Provide the configuration will also help understand your scenario better?

DFWTechGuy
Visitor

If the ASA config is identical, you should also look outside the firewall. If the captive portal is handled by the WLC and ISE, they may still have the old ASA's MAC address or ARP entry cached. Try clearing the ARP cache on the WLC (and ISE if applicable), then reconnect a test client. Also make sure the new ASA is using the same IP, interface settings, and NAT behavior as the old one. Even a small difference there can prevent the redirect from working.

Levi - DFWTechGuy
Review Cisco Networking for a $25 gift card