ASA 5505 Determine Your License Version
Nov17

ASA 5505 Determine Your License Version

KB ID 0000701 Problem If you are having problems with internal clients NOT getting through the firewall, the license on your ASA 5505 may be ‘to small’. ASA 5505 License Differences Essentially the licenses come in 10 user, 50 user, and unlimited*. You can also have a Security Plus License, this increases IPSEC VPN’s from 10 to 25, and adds Active/Standby failover, Dual ISP Support, and DMZ Support. *Note: These...

Read More
Cisco ASA – Using ‘logging’ to see what ports are being blocked
Nov17

Cisco ASA – Using ‘logging’ to see what ports are being blocked

KB ID 0000702  Problem If you look after a firewall, sooner or later something will fail, and the blame (rightly or wrongly), will be leveled at the firewall. I came back from holiday this week to find a client had got a problem with secure POP email. The problem had been fixed (temporarily) by dropping the affected users into a group, and opening all ports. As this had fixed the problem then it’s fair to say that the ASA was...

Read More

Cisco ASA to Juniper SRX Site to Site VPN

KB ID 0000710 Problem You want to establish a site to site VPN from a site with a Cisco ASA firewall, to another site running a Juniper SRX firewall. I had to do this this week, and struggled to find any good information to help. In the example below I’m configuring the whole thing from a laptop (172.16.254.206) that’s on the Juniper’s site. Use the diagram below, and substitute your own IP addresses and subnet...

Read More
Cisco ASA 5500 Active/Standby – Zero Downtime Upgrade
Nov17

Cisco ASA 5500 Active/Standby – Zero Downtime Upgrade

KB ID 0000733 Problem You have two ASA firewalls deployed in Active/Standby failover configuration, and need to upgrade either the operating system or the ASDM. As you already have a high availability solution you do not want any downtime. Before we start, we need to make sure we know the difference between primary, secondary, active and standby. From the rear (Active=Green, Standby=Amber) The Primary and Secondary firewalls are...

Read More
Cisco ASA 5500 – Deny a Single IP Address External Access
Nov17

Cisco ASA 5500 – Deny a Single IP Address External Access

KB ID 0000743  Problem This got asked on Experts Exchange today, the poster specifically asked for an ASDM solution, so here goes. However I will also do the commands as well. Solution Block an IP via ASDM 1. Connect to the ASDM > Configuration > Firewall > Add ‘Network Object’. Note: You could create a Network Object Group, then add a Network Object to that group. This is handy if there are liable to be more IP...

Read More
Cisco ASA 5500 Allowing Tracert
Nov17

Cisco ASA 5500 Allowing Tracert

KB ID 0000753 Problem I’d always assumed that as Tracert uses ICMP, and that simply adding ICMP inspection on the ASA would let Tracert commands work. A client of mine is having some comms problems and wanted to test comms from his remote DR site, he had enabled time-exceeded and unreachable on the ASA (for inbound traffic) and that had worked. I checked the default inspection map and found inspect ICMP was there? As it turns...

Read More
Cisco ASA 5500 – VPN Works in One Direction
Nov17

Cisco ASA 5500 – VPN Works in One Direction

KB ID 0000759 Problem The title of this article can cover a multitude of possible causes, however I recently had a strange problem where a client with a remote site protected by an ASA5505 had a VPN tunnel connected to their main site which had an ASA5510. The tunnel established at phase 1, and phase 2, the main site could talk to the remote site, but the remote site refused to talk back to the main site. Update 23/04/19: Seen again...

Read More
ASA TFTP Error – (Cannot allocate memory)
Nov17

ASA TFTP Error – (Cannot allocate memory)

KB ID 0000787  Problem I updated my ASA to version 9.1(1) tonight, that went well, but when I tried to update the ASDM image to version 7.1(1)-52 this happened; Accessing tftp://10.254.254.109/asdm-711-52.bin…!!!!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!...

Read More
Cisco Firewall (ASA/PIX) – Granting Access to an FTP Server
Nov17

Cisco Firewall (ASA/PIX) – Granting Access to an FTP Server

KB ID 0000772 Problem If you have an FTP server, simply allowing the FTP traffic to it wont work. FTP (in both active and passive mode) uses some random high ports that would normally be blocked on the firewall. So by actively inspecting FTP the firewall will know what ports to open and close. Solution How you ‘allow’ access to the FTP server will depend on weather you have a public IP address spare or not, if you only...

Read More
Boot Cisco ASA From TFTP (Upgrade from ROMMON)
Nov17

Boot Cisco ASA From TFTP (Upgrade from ROMMON)

KB ID 0000792 Problem If your firewall wont boot, either because the OS is corrupt, or you have a faulty flash memory. You can get up and running by booting the device from a TFTP server instead. Solution Before you start make sure you have your TFTP server running and the operating system in its root folder. Install and Use a TFTP Server 1. Power on the firewall, during the boot phase press ESC to boot to ROMMOM mode. 2. The...

Read More