Cisco ASA – Port Forwarding To A Different Port
Nov17

Cisco ASA – Port Forwarding To A Different Port

Port Translation KB ID 0001087  Problem Note: This is for Cisco ASA 5500, 5500-x, and Cisco Firepower devices running ASA Code. A very long time ago I wrote an article about how to port forward from a public IP address to multiple servers for RDP. Basically you would connect to the firewall using various different ports, and the firewall would change the port to the correct one for RDP (TCP port 3389, unless you changed it on the...

Read More
Redirect AnyConnect Browser Connections From HTTP to HTTPS
Nov17

Redirect AnyConnect Browser Connections From HTTP to HTTPS

KB ID 0000707  Problem AnyConnect, is great for users, but most of them are not used to typing full URL’s into their browsers. Modern browsers will prefix your URL with ‘http://’ for you. That’s brilliant most of the time, but AnyConnect and SSL VPN need to go to ‘https://’. Wouldn’t it be good if your users typed vpn.petenetlive.com into their browsers, and instead of the browser...

Read More
Cannot Manage ASA via AnyConnect VPN
Nov17

Cannot Manage ASA via AnyConnect VPN

KB ID 0000925  Problem I haven’t needed to use my AnyConnect for a long time. But this week I needed to spin up some test servers. I connected fine, but I could not access the ASA via telnet, SSH or ASDM. Solution 1. Traditionally all you needed to do to manage an ASA from a remote VPN session, was to set the management-access to inside. User Access Verification Password: Type help or ‘?’ for a list of available...

Read More
Replace an ASA 5505 with an ASA 5506-X
Nov17

Replace an ASA 5505 with an ASA 5506-X

KB ID 0001091  Problem Given the amount of ASA work I do it’s surprising that the first time I saw an ASA 5506-X was last week (I’ve been working on larger firewalls for a while). I’m probably going to have to do a few of these over the next couple of years so I’ll update this article as things surface. Solution Q: Can I just copy the config from an ASA 5505 to an ASA 5506-X? A: No, that would be nice, truth be...

Read More