Cisco ASA – Policy NAT
Nov17

Cisco ASA – Policy NAT

KB ID 0001042 Problem I’ve been working on a large firewall deployment for a client, each of their DMZ’s have both a production and a management network. nothing particularly strange about that, but each of their DMZ’s has its own firewalled management network and it’s routable from the LAN. So If I’m an admin and I want to talk to a Linux appliance in their DMZ via its management interface, my traffic...

Read More
Cisco ASA ASDM – Packet Tracer Wont Work
Nov17

Cisco ASA ASDM – Packet Tracer Wont Work

KB ID 0001051  Problem I don’t usually use the graphical packet tracer tool, but I did this week, and this happened; Following error(s) occurred- packet-tracer input inside {protocol} inline-tag -l {source} {source port} {target} {target port} xml %Invalid input detected at ‘^’ marker Solution Well from CLI it worked fine, so I’m guessing it’s a fault in the ASDM. An Internet/forum search threw up a load...

Read More
Cisco AnyConnect – PAT External VPN Pool To An Inside Address
Nov17

Cisco AnyConnect – PAT External VPN Pool To An Inside Address

KB ID 0001104  Problem I got sent to Holland this week to look at a firewall deployment, and while I was sat in the Airport, I was going over the job I had to do, when I realised the solution I had suggested had a problem see below; My brief was to provide remote AnyConnect VPN into the network so the client could get their network setup, and manage things remotely. However as I drew the network out in my head I realised that the...

Read More