Amazines Free Article Archive
www.amazines.com - Wednesday, April 17, 2024
Read about the most recent changes and happenings at Amazines.com
Log into your account or register as a new author. Start submitting your articles right now!
Search our database for articles.
Subscribe to receive articles emailed straight to your email account. You may choose multiple categories.
View our newest articles submitted by our authors.
View our most top rated articles rated by our visitors.
* Please note that this is NOT the ARTICLE manager
Add a new EZINE, or manage your EZINE submission.
Add fresh, free web content to your site such as newest articles, web tools, and quotes with a single piece of code!
Home What's New? Submit/Manage Articles Latest Posts Top Rated Article Search
Google
Subscriptions Manage Ezines
CATEGORIES
 Article Archive
 Advertising (133573)
 Advice (161671)
 Affiliate Programs (34799)
 Art and Culture (73855)
 Automotive (145712)
 Blogs (75614)
 Boating (9851)
 Books (17223)
 Buddhism (4130)
 Business (1330636)
 Business News (426446)
 Business Opportunities (366518)
 Camping (10973)
 Career (72795)
 Christianity (15848)
 Collecting (11638)
 Communication (115089)
 Computers (241951)
 Construction (38962)
 Consumer (49953)
 Cooking (17080)
 Copywriting (6733)
 Crafts (18203)
 Cuisine (7549)
 Current Affairs (20319)
 Dating (45908)
 EBooks (19703)
 E-Commerce (48258)
 Education (185520)
 Electronics (83524)
 Email (6438)
 Entertainment (159854)
 Environment (28970)
 Ezine (3040)
 Ezine Publishing (5453)
 Ezine Sites (1551)
 Family & Parenting (111007)
 Fashion & Cosmetics (196605)
 Female Entrepreneurs (11853)
 Feng Shui (134)
 Finance & Investment (310615)
 Fitness (106469)
 Food & Beverages (63045)
 Free Web Resources (7941)
 Gambling (30227)
 Gardening (25202)
 Government (10519)
 Health (630137)
 Hinduism (2206)
 Hobbies (44083)
 Home Business (91657)
 Home Improvement (251210)
 Home Repair (46243)
 Humor (4723)
 Import - Export (5459)
 Insurance (45104)
 Interior Design (29616)
 International Property (3488)
 Internet (191029)
 Internet Marketing (146687)
 Investment (22861)
 Islam (1161)
 Judaism (1352)
 Law (80506)
 Link Popularity (4596)
 Manufacturing (20914)
 Marketing (99316)
 MLM (14140)
 Motivation (18233)
 Music (27000)
 New to the Internet (9496)
 Non-Profit Organizations (4048)
 Online Shopping (129734)
 Organizing (7813)
 Party Ideas (11855)
 Pets (38165)
 Poetry (2229)
 Press Release (12689)
 Public Speaking (5643)
 Publishing (7566)
 Quotes (2407)
 Real Estate (126700)
 Recreation & Leisure (95495)
 Relationships (87674)
 Research (16182)
 Sales (80350)
 Science & Technology (110290)
 Search Engines (23514)
 Self Improvement (153300)
 Seniors (6220)
 Sexuality (36010)
 Small Business (49311)
 Software (83033)
 Spiritual (23516)
 Sports (116155)
 Tax (7663)
 Telecommuting (34070)
 Travel & Tourism (308304)
 UK Property Investment (3123)
 Video Games (13382)
 Web Traffic (11790)
 Website Design (56919)
 Website Promotion (36663)
 World News (1000+)
 Writing (35844)
Author Spotlight
TAL BARNEA

Tal is an electrical engineer with over 25 years of expertise with hardware, software, mechanical an...more
MANMOHAN SINGH

Digital marketing professional with 8 years of experience. A good listner, Stratgist and fun loving ...more
LEMUEL ASIBAL

Lemuel Asibal is a web content writer who also ventures on writing articles and blog posts about any...more
TUSHAR BHATIA

Tushar Bhatia is the Founder President of EmpXtrack Inc with over 19 years of experience in the soft...more
BRENDA PANIN

Passionate blogger and a great animal lover. ...more


Troubleshooting ASA, PIX, and FWSM by iris dan





Article Author Biography
Troubleshooting ASA, PIX, and FWSM by
Article Posted: 09/04/2013
Article Views: 106
Articles Written: 93
Word Count: 2110
Article Votes: 0
AddThis Social Bookmark Button

Troubleshooting ASA, PIX, and FWSM


 
Computers,Internet,Telecommuting
Q&A: How to Troubleshoot ASA, PIX, and FWSM? ASA/PIX-Basic Configuration Q. Is ASA 5500 limited to one outside interface? A. No, customers who are running DMZ both public-facing and internet-facing, and even have the inside port internet-facing. Basically, you could have 2 interfaces internet facing but, only one is default route. Click here for the live answer. Q. Is it possible to have two (2) inside interfaces on the same subnet on ASA 5505/5510? A. Meaning, inside1 and inside2? Certainly. On the same subnet? No. It has to be on a different subnet. Click here for the live answer Q. Can reserved addresses be configured in the DHCP scope on the DHCP server on the ASA? A. Yes, you can configure those scopes from 10 to 20, and start off at 30 to 40, ignoring the small segement left out. Click here for the live answer. Q. We setup our ASAs via CLI and plan to implement CSM to manage the Firewall and VPNs. Are there any issues or reasons why we should not to use CSM? A. No, I don't see any reason why not to use CSM. People use CSM to because many people are involved in making minor, access-less changes that work on a shift basis and don't have priviledge15 access on the firewall. It allows people to make requests for changes, etc. It also allows for archiving of changes, which allows you to roll back a config it it doesn't work. But bear in mind, once you start managing a device with CSM, only make changes from CSM. DO NOT make changes with CLI, only from CSM. If you make changes with CLI, then implement changes with CSM, your CLI changes will be ignored. Click here for the live answer.

Q. What are the different modes you can run on the ASA firewall and what is the most practical mode to run the ASA? A. There are two modes you can run a firewall in: - Routed - Transparent

In routed mode ASA is a hop in a network and in transparent mode, ASA is not a hop and works at Layer 2. A transparent firewall can only use 2 interfaces for traffic filtering and can be installed in an existing network with minimal changes. It completely depends on security policy/environment as to which mode would suite the network.

ASA/PIX-Software Versions Q. Why should we upgrade to ASA Version 8.3 considering the learning curve with changes to the NAT rules? A. ASA version 8.3 has new features like Smart Call Home, global ACLs, VPN and inspection enhancements that could be very useful to people. I would suggest looking at the ASA 8.3 Release Notes for all the new features. As a side note, the learning curve is something that will take time. One more advantage is that NAT will be simpler in ASA 8.3. I hope this makes sense. Q. When I upgraded to 8.3, our NAT quit working. Looking through the Release notes and Migration guide, we didn’t see any notes on this or even procedures to take before the upgrade. Do you have any suggestions? A. the Release notes say that you need to upgrade memory. But the rest of the migration should go smoothly. Also the notes will say how to downgrade using the downgrade command. Now if you faced issue you could be hitting one defect we have seen with ACL migration or one with overlapping nats. I am not sure which exactly. I would suggest downgrading if there are issues and keep a copy of the 8.3 config to talk to TAC to see if you hit the defects I mentioned. Q. I have an ASA 5510 running 7.0(6). If I upgrade to 8.2, will I have to update the config file for incompatibility? A. There have been few commands which got changed/deprecated from 7.0 -> 8.2. Hence, it would be better to possibly do a step-by-step upgrade so that command changes are done accordingly. 7.0 -> 7.1 -> 7.2 -> 8.0 -> 8.2. Q. What special considerations do I need to consider when I have to put private addresses on the outside of the ASA? In this case, we have a subordinate campus that wants their own ASA but we are in 10.1.1.x here for their uplink (We are the ISP). A. Private IP address is to save address space. They will work as other IP addresses as long as there is the routing in place. I am not sure exactly how you will assign private IP addresses to a campus reachable from the internet, but you need to consider routing and also that sometimes following RFC1918, network administrators might block private ip addresses on their routers,firewalls etc. Otherwise the private ranges can be used exactly as public. I hope it helps. Q. I'm using an ASA 5505. When copying a config from tftp to startup config, is startup config merged with the tftp config like when using pix w/ 6.3, or is the startup config overwritten completely? A. The config is completely overwritten, only when do you copy over to the running config, it merges. Once you copy over the startup config, it will completely overwrite the startup config. Click here for the live answer.

Q. Can I copy the config from ASA5550 to ASA5540? A. Yes we can. However, keep in mind that ASA5550 comes with a bundled 4-GE-SSM module. If these interfaces are in use on ASA5550, but do not exist on ASA5540, configuration related to those interfaces will be ignored. Failover Q. We have our failover going through a switch. This is preferred over a cable? We had a module fail that had the primary interfaces and the failover on it, so the ASA did not fail over. We assume to fix this; we need to move the failover to another switch blade as the primary interfaces. Is this correct? A. That would be correct. The firewall performs an ARP test before failing over when the failover link goes. It wills ARP out all interfaces for its peer to see if it can elicit a response. If any response is received a failover will not take place as to avoid an active/active scenario. With the failover link down, the two firewalls cannot communicate their status to each other. In your case, they probably saw each other on another interface preventing the failover. Q. Is VPN's supported in an active/active configuration? A.When the security appliance is configured for security contexts (also called firewall multimode) or Active/Active stateful failover, IPSec or SSL VPN cannot be enabled. Therefore, these features are unavailable. Q. Can you configure a two 5500 ASAs in failover mode via the management interface to connect the two? A. Yes. However, keep in mind that Management interfaces are FastEthernet interfaces. If you plan to share stateful link also with failover link, you should use fastest interface available on the unit. Q. Is it possible to have a failover ASA that does not have the AIP - SSM installed when the primary has the AIP-SSM installed? A. Yes. However, if the configuration is utilizing AIP-SSM, then this would not work. Q. Shouldn't stateful failover include routing information / OSPF negotiations if customers aren't supposed to notice an outage during a failover event? A. Correct. Currently, dynamic routing tables are not replicated from active to standby unit. There is an enhancement request filed to add this feature--Refer the bug ID CSCsu90386 (registered customers only). Q. Is there a roadmap to adding routing tables to stateful failover? We have ASA's in statefull failover, but that is worthless as we need to wait 20-40 seconds for OSPF to update the routing tables on the newly active ASA when a failover occurs. A. Yes. This is on the roadmap. There is an enhancement bug filed for this --Refer the Bug ID CSCsl08631 (registered customers only). You can track the progress of this request or you can work with Accounts team to get this feature added in future releases. Q. Can we upgrade the firmware for a pair of firewalls in HA mode without downtime? Especially since only one of the firewalls needs to be upgraded. A. You can use 'Zero-downtime upgrade' procedure. Please find the same on following link: http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mswlicfg.html#wp1053398 Q. What is difference between STATE failover & LAN failover? Type of failover: like LAN, STATE, and Serial? What is exact difference? A. There are two types of failover mechanisms: -Cable based failover (Only on PIX) -Lan based failover

In cable based failover a serial cable is connected between two firewalls over which failover communications happen. In Lan based failover [fast/gig]ethernet ports of two units are connected on which failover communications occur. Stateful failover is an additional feature which can be utilized in cable/lan failover. This feature allows replication of state table from Active to Standby unit. Thus, in event of failover, user does not have to re-establish the connection. Q. Between these two commands -- failover interface ip FAILOVER and failover interface ip STATE -- what is difference between both commands? A. One is for interface, the other is for stateful. Stateful is the state that tcp will be updated between the two machines over the STATE link. Sometimes the failover and STATE links are over the same line. When a failover happens, and the stateful is not defined, all the tcp and udp sessions have to be re-established Click here for the live answer.

Q. for ASA5510, will it be better to use 1GE interface as failover interface or 100T interface? Which is sufficient to become failover interface? A. For these connections, will you be routing the traffic out to an intermediary device on the outside interface then back to the ASA? Without knowing the exact requirements it is hard to say exactly how this will be accomplished. Here is a link for intra interface communications on the ASA. http://www.cisco.com/en/US/partner/products/ps6120/products_tech_note09186a0080734db7.shtml Q. Do route tables sync in 3.1 failover? A. No. For example, OSPF will need to re-converge after a failover event. I hope it makes sense. ASA/PIX-Support Q. Does the ASA5505 and 5510 support DMVPN with SR520? A. ASA does not support DMVPN. Click here for the live answer.

Q. Is it still a recommended feature to keep the number of firewall rules not in a big number? A. You can say that it is a good recommendation. It makes the ACE search faster so your firewall can process packets faster. most people will not notice any difference but we have seen CPU issues in the past with huge ACLs (~400K on an ASA). I hope it helps.

Q. To confirm, ASA doesn't do routing protocol/BGP for multiple internet connections? Must use router or L3 switch? A. Correct. The ASA will not do BGP. It can do RIP, OSPF, EIGRP. The FWSM will support BGP. I hope it clarifies it. Cisco ASA-QoS Q. Can the ASA set QoS tags? A. Nope. The ASA will match and police/shape/prioritize based on tags. But it cannot set them. Q. I have a cisco 5510 and several Cisco 5505's. At each location we have a Cisco 5505, with 2 types of traffic: staff and public. How can I setup QoS or prioritization for our staff so they get priority through the VPN? A. There is a very good example here https://supportforums.cisco.com/docs/DOC-1230#Traffic_Policing_with_Prioritization

You match on the staff traffic and you police the rest of your VPN. Note that you need to police in order for prioritization to kick in. So decide how much your VPN will take and prioritized traffic that matches the staff. I hope it helps. Q. We are using phone proxy on our ASA5520 in our organization. Is there anything that can be done to improve call quality? A. the ASA does provide functionality for QOS and priority queuing of the voice traffic. This typically only comes into play if the interfaces are being saturated with traffic. Besides QOS we would need to take a look at the interfaces to see if there are any errors or indications or problems. It may be something further upstream which is causing the quality issues. It is also important to monitor when the problem occurs. Does it only happen during peak times? This would be an indication of link saturation.

More about: Full info of How to Troubleshoot ASA, PIX, and FWSM?

More Related TOPICS: Create IPv6 LAN-to-LAN VPN Tunnel on Cisco ASAs

What Things to be Considered While Upgrading ASA 5500 Series?

What is Cisco ASA CX Security Module?

ght Commands on a Cisco ASA Security Appliance You Should Know

How to Configure Cisco PIX Firewall?

Related Articles - troubleshoot ASA, PIX, FWSM, ASA/PIX-Basic Configuration, PIX firewall, network security, DHCP,

Email this Article to a Friend!

Receive Articles like this one direct to your email box!
Subscribe for free today!

 Rate This Article  
Completely useless, should be removed from directory.
Minimal useful information.
Decent and informative.
Great article, very informative and helpful.
A 'Must Read'.

 

Do you Agree or Disagree? Have a Comment? POST IT!

 Reader Opinions 
Submit your comments and they will be posted here.
Make this comment or to the Author only:
Name:
Email:
*Your email will NOT be posted. This is for administrative purposes only.
Comments: *Your Comments WILL be posted to the AUTHOR ONLY if you select PRIVATE and to this PUBLIC PAGE if you select PUBLIC, so write accordingly.
 
Please enter the code in the image:



 Author Login 
LOGIN
Register for Author Account

 

Advertiser Login

 

ADVERTISE HERE NOW!
   Limited Time $60 Offer!
   90  Days-1.5 Million Views  

 

Great Paranormal Romance


LAURA JEEVES

At LeadGenerators, we specialise in content-led Online Marketing Strategies for our clients in the t...more
TIM FAY

After 60-plus years of living, I am just trying to pass down some of the information that I have lea...more
ALEX BELSEY

I am the editor of QUAY Magazine, a B2B publication based in the South West of the UK. I am also the...more
GENE MYERS

Author of four books and two screenplays; frequent magazine contributor. I have four other books "in...more
SUSAN FRIESEN

Located in the lower mainland of B.C., Susan Friesen is a visionary brand strategist, entrepreneur, ...more
STEVERT MCKENZIE

Stevert Mckenzie, Travel Enthusiast. ...more
STEPHEN BYE

Steve Bye is currently a fiction writer, who published his first novel, ‘Looking Forward Through the...more
SHALINI MITTAL

A postgraduate in Fashion Technology. Shalini is a writer at heart! Writing for her is an expression...more
ADRIAN JOELE

I have been involved in nutrition and weight management for over 12 years and I like to share my kn...more
JAMES KENNY

James is a Research Enthusiast that focuses on the understanding of how things work and can be impro...more

HomeLinksAbout UsContact UsTerms of UsePrivacy PolicyFAQResources
Copyright © 2024, All rights reserved.
Some pages may contain portions of text relating to certain topics obtained from wikipedia.org under the GNU FDL license