Cisco ASA 5505 Routing Between Two (Internal) VLANS
Nov17

Cisco ASA 5505 Routing Between Two (Internal) VLANS

KB ID 0000869  Problem I had to set this up for a client this week, I’ve setup a DMZ on a 5505 before and I’ve setup other VLANs to do other jobs, e.g. visitor Internet access. But this client needed a secondary VLAN setting up for IP Phones. In addition I needed to route traffic between both the internal VLANs. I did an internet search and tried to find some configs I could reverse engineer, the few I found were old (Pre version 8.3)...

Read More
Cisco ASA 5500 – Sub Interfaces and VLANS
Nov17

Cisco ASA 5500 – Sub Interfaces and VLANS

KB ID 0001085  Problem You can take the physical interface of a Cisco ASA firewall, (or an ether channel) and split it down into further sub-interfaces. This way you can set multiple VLANs to use this interface as a gateway at the same time whilst still separating the traffic. In this scenario I’m going to have two VLANs, one for my wired clients, and one for a ‘Guest WiFi’ that I’m setting up. I want the guest...

Read More
Cisco ASA5500 Change the AnyConnect Port
Nov17

Cisco ASA5500 Change the AnyConnect Port

KB ID 0000422  Problem AnyConnect runs over TCP port 443 (That’s HTTPS/SSL), but if you only have one public IP and need to forward that port to a web server or internal host then you are a bit snookered. You can of course change the port that AnyConnect runs over, so that it’s no longer on TCP port 443. Why you would NOT want to do this. Bear in mind that https is a well known port, and its open in most places for secure...

Read More
AnyConnect  – “Error Contacting Host”
Nov17

AnyConnect – “Error Contacting Host”

KB ID 0000555  Problem I was creating some “Bookmarks” on a client’s AnyConnect web portal last week. They were simply CIFS links to shared folders on his servers so he could access them remotely from his Android tablet PC’s. However every time I clicked a link I got this error; Solution A bit of searching later and I found that in the release notes for version 8.0(4) this was a known problem that had been...

Read More
Cisco AnyConnect – Essentials / Premium Licenses. Explained
Nov17

Cisco AnyConnect – Essentials / Premium Licenses. Explained

KB ID 0000628  Problem Note: With Anyconnect 4 Cisco now use Plus and Apex AnyConnect licensing. When Cisco released the 8.2 version of the ASA code, they changed their licensing model for AnyConnect Licenses. There are two licensing models, Premium and Essentials. Solution Cisco ASA AnyConnect Premium Licenses. You get two of these free with your firewall*, with a ‘Premium License’ you can use the AnyConnect client...

Read More