Cisco Firewall (ASA/PIX) – Granting Access to an FTP Server
Nov17

Cisco Firewall (ASA/PIX) – Granting Access to an FTP Server

KB ID 0000772 Problem If you have an FTP server, simply allowing the FTP traffic to it wont work. FTP (in both active and passive mode) uses some random high ports that would normally be blocked on the firewall. So by actively inspecting FTP the firewall will know what ports to open and close. Solution How you ‘allow’ access to the FTP server will depend on weather you have a public IP address spare or not, if you only...

Read More
Boot Cisco ASA From TFTP (Upgrade from ROMMON)
Nov17

Boot Cisco ASA From TFTP (Upgrade from ROMMON)

KB ID 0000792 Problem If your firewall wont boot, either because the OS is corrupt, or you have a faulty flash memory. You can get up and running by booting the device from a TFTP server instead. Solution Before you start make sure you have your TFTP server running and the operating system in its root folder. Install and Use a TFTP Server 1. Power on the firewall, during the boot phase press ESC to boot to ROMMOM mode. 2. The...

Read More
Cisco ASA 5500 – Configuring PPPoE
Nov17

Cisco ASA 5500 – Configuring PPPoE

KB ID 0000831  Problem Until very recently I’d never had to configure PPPoE. Most of my clients in that sort of connection speed range have ADSL with a router provided by their ISP. A Router that connects via PPPoA usually. Here in the UK the main ISP’s (BT and Virgin) are busy rolling out FTTC connections that terminate with a ‘modem’ that presents an RJ45 socket. So without the need for a router, you can get...

Read More
Cisco ASA – Find Out VPN Tunnel Uptime
Nov17

Cisco ASA – Find Out VPN Tunnel Uptime

KB ID 0000863  Problem I needed to get the Uptime/Duration of a particular VPN tunnel this week. It was for a client with multiple VPN tunnels that was having problems with just one. Solution Option 1 via Command Line 1. Connect to to the firewall > Go to enable mode and use the following command, replace 123.123.123.123 with the IP of your VPN endpoint. PetesASA> PetesASA> enable Password: ******** PetesASA# show...

Read More
Cisco ASA 5505 Routing Between Two (Internal) VLANS
Nov17

Cisco ASA 5505 Routing Between Two (Internal) VLANS

KB ID 0000869  Problem I had to set this up for a client this week, I’ve setup a DMZ on a 5505 before and I’ve setup other VLANs to do other jobs, e.g. visitor Internet access. But this client needed a secondary VLAN setting up for IP Phones. In addition I needed to route traffic between both the internal VLANs. I did an internet search and tried to find some configs I could reverse engineer, the few I found were old (Pre version 8.3)...

Read More