«

»

Feb 21

Cisco ASA 8.4 on GNS3

I struggled quite a lot of get ASA 8.4 working on GNS3. I had 8.0(2) working and was helping to test the configurations and VPNs but now wanted to get 8.4 running such that I can prepare myself for new NAT statements and migration from 8.0(2) to 8.4(2).

Here are the steps to get it working. All links to any images or keys are removed for legal reasons. Once its gone its gone.

1. Download the ASA 8.4 files for GNS3 from the following address

I am afraid you will have to search google for reputable sources to get firewall ASA842 image. Please dont ask here for the image.

2. Configure GNS3 as following. ( I am using Ver 0.8.2 Beta 2, Also Tested 8.3 with Windows 7 64 bit which worked without any issues).  Type the code below into relevant fields

 

Qemu Options: -vnc none -vga none -m 1024 -icount auto -hdachs 980,16,32
Kernel cmd line: -append ide_generic.probe_mask=0x01 ide_core.chs=0.0:980,16,32 auto nousb console=ttyS0,9600 bigphysarea=65536
 
Configure the paths for Initrd and Kernel to where you have extracted the files.
 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

3. Once the firewall is up and running use following activation keys

Again the activation keys are in public domain so get it using your search capabilities.

 

It will take a while (10-15 min) to accept the second activation key and will take the same time at first reboot.

That's all done and we have a working firewall to play with.

 

 

Now if you want to run two ASAs, you will have to change the Qemu options on the second firewall as below

Qemu Options: -vnc :2 none -vga none -m 1024 -icount auto -hdachs 980,16,32

 

Troubleshooting:

Please check the comments at the end of post where you will find different ways to resolve issues if you face any. Specially very helpfull comments from GD and are detailed below

 

Download and install the latest version of GNS3 0.8.2 after that download the •Qemu 0.13.0 patched 32 bits binary for Windows from
 
 
Copy and replace all downloaded qemu files and folders with existing qemu files and folders under GNS3 folder.

 

After you have ASA running in GNS and want to play with ASDM, here is the guide to follow

http://www.xerunetworks.com/2012/03/asa-84-asdm-on-gns3-step-by-step-guide/

 

and if you want to connect two GNS3 networks running on two different PCs, use following

http://www.xerunetworks.com/2012/03/connect-gns3-network-to-real-networks-other-gns3-network/

I have posted a LAB Guide for migrating NAT from 8.2 to 8.3/8.4 Version, which is still work in progress but has a lot of stuff already added into it

http://www.xerunetworks.com/2012/03/asa-8384-nat-migration-lab-guide/

334 comments

11 pings

Skip to comment form

  1. ato

    ciscoasa(config)# asdm image flash:asdm-647.bin
    Device Manager image set, but not a valid image file flash:asdm-647.bin
    ciscoasa(config)#

  2. usaKKK

    DynamIP CONNECTIOn CLOSED error resolved onWin 8.1 64 bit.

    upadating to GNS 8.6 appears to be causing this error.

    downgrade to GNS 8.3.1 and it worked for me. here is the old version
    http://www.uploadable.ch/file/PazVfvNBRtfq/GNS3-0.8.3.1-all-in-one.exe

  3. Khalid

    Please help me as I can not ping host 192.168.30.3 from ASA 192.168.30.1. Spent much time but still shows ???? instead of !!!!! , i have also added per icmp any inside.

  4. Artem

    My consolr tells /dev/hda1: No such file or directory and ASA just continues rebooting
    REBOOT: open message queue fail: No such file or directory/2

  5. ac

    I do everything here and assign 192.168.1.99 to the MS loopback for the cloud and then 192.168.1.90 to the eth1 on asa but still cannot ping 192.168.1.99 from asa..Why?

  6. Namasivayam

    HOW TO SOLVE UNABLE TO LAUNCH DEVICE MANAGER FROM 192.168.1.1

    Software Details:
    asa842-initrd.gz
    asa842-vmlinuz
    Cisco asdm-647.bin
    jdk-7u51-windows-i586
    Windows 7 32 bit O/s
    Internet Explorer version 9
    tftp32.exe
    GNS3 0.8.6

    Qemu Options: -vnc none -vga none -m 1024 -icount auto -hdachs 980,16,32
    Kernel cmd line: -append ide_generic.probe_mask=0×01 ide_core.chs=0.0:980,16,32 auto nousb console=ttyS0,9600 bigphysarea=65536

    ——————————————————————————————————
    MY CONFIGURATIONS:
    ciscoasa(config)#interface gigabitEthernet 0
    ciscoasa(config-if)#ip address 192.168.1.1 255.255.255.0
    ciscoasa(config-if)#nameif inside
    ciscoasa(config-if)#no shutdown
    ciscoasa(config-if)#exit
    ciscoasa(config)#ping 192.168.1.2
    Type escape sequence to abort.
    Sending 5, 100-byte ICMP Echos to 192.168.1.2, timeout is 2 seconds:
    !!!!!!!!
    Success rate is 100 parcent (5/5), round-trip min/avg/max = 1/1/1 ms
    ciscoasa(config)#http server enable
    ciscoasa(config)#http 192.168.1.2 255.255.255.255 inside
    ciscoasa(config)#username cisco password admin privilege 15
    ciscoasa(config)#copy tftp: flash:
    Address or name of remote host[]? 192.168.1.2
    Source filename []? asdm-647.bin
    Destination filename [asdm-647.bin]?
    !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
    !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
    ciscoasa(config)#asdm image flash:asdm-647.bin
    ciscoasa(config)#wr mem
    ————————————————————————————–
    MY ERROR:
    Step 1: Go to IE Browser
    Step 2: Type https://192.168.1.1
    Step 3: I Enter username and password
    Step 4: I install Run the Asdm
    Step 5: i Enter firewall ip, username and password in asdm launcher
    Step 6: i have one Error unable to launch device manager from 192.168.1.1
    Step 7: how to solve this error.
    ————————————————————————————————————————
    Plz help me any one this problem.
    namasivayam.cse@gmail.com

  7. Sam

    Dears I cannot run ASA on Gns3 8.6, 8.4 tried all versions it is prompting some kind of lima_physarea error 2 on Win 7 machine, I am tring to solve this for one week tried all options please let me know the best solution as I can find the device is running but I cannot open a console to it

  8. ABC

    Thanks…..everything seems to work fine only that i can do trunking. I want to use it as a lab for CCNA Security as taught by Keith Barker but i can’t configure the ethernet ports.

  9. Mahammad Imran

    Hello

    I am able to run 842ASA but its not pinging to loopback interface from GNS3 kindly provide the sollutuin

    1. ac

      Got the same issue…Were you able to solve it?
      Thanks!

1 16 17 18

  1. Assistance in GNS3

    […] PM #2 Everything you need is in here Cisco ASA 8.4 on GNS3 – XeruNetworks Working on CCNP Security FIREWALL, VPN and IPS passed! Quote […]

  2. GNS3 – ASA on Mac OSX | IPv6 Freely

    […] http://www.xerunetworks.com/2012/02/cisco-asa-84-on-gns3/ NOTE:  You don’t know…links fall of the Internet all the time, you might have to Google “GNS3 ASA 8.42″ to find a suitable download location. […]

  3. Como configurar un Firewall ASA 8.4 en GNS3 | Redes Cisco.NET

    [...] Fuente: http://www.xerunetworks.com/2012/02/cisco-asa-84-on-gns3/ [...]

  4. Cisco ASA 8.4 on GNS 3 | » Ali's Technology Blog

    [...] was able to use the following site to get the right files for this setup, XeruNetworks. Once you install GNS3 successfully here are some of the first [...]

  5. ASA 8.3/8.4 NAT Migration Lab Guide - My Tech World » My Tech World

    [...] « Cisco ASA 8.4 on GNS3 [...]

Leave a Reply

%d bloggers like this: