Mar 01

ASA 8.3/8.4 NAT Migration Lab Guide

Lets reinvents the wheel. Just to add a bit more fun to NAT, Cisco now a new (third) way to configure NAT on the Cisco devices. Yes, third as its already a bit different for configuring NAT on Rotuers, different on ASA pre 8.2 and here we are with NAT on ASA 8.3/8.4. I am …

Feb 21

Cisco ASA 8.4 on GNS3

I struggled quite a lot of get ASA 8.4 working on GNS3. I had 8.0(2) working and was helping to test the configurations and VPNs but now wanted to get 8.4 running such that I can prepare myself for new NAT statements and migration from 8.0(2) to 8.4(2).

Here are the steps to get it …

Feb 10

Cisco ASA Concurrent Auth Proxy Connection Limit

If you are using authentication proxy to authenticate users before accessing any services through the firewall, you can be looking at limiting the number of concurrent connections which are allowed through. To change this limit you can either use ASDM or command line.

Command Line: The command to use

aaa proxy-limit 15 or whatever number …

Mar 24

Cisco ASA Running Config doesnt show password strings

The show running config command on Cisco ASA devices doesnt show the password in output and also hides the SNMP Community Strings. To include passwords in the output file use the following command

ASA5520#more system:running-config

Feb 03

Traceroute through Cisco ASA Firewall

To allow traceroute through firewall needs configuration depending on the source of traceroute command. Microsoft uses tracert command and  ICMP message types for traceroute (unreachable, time-exceeded, echo-reply). You will use following ACL entries to allow trace traffic to pass through the firewall. In the following example the inside interface is allow to reach hosts but outside …

