Re: [fw-wiz] Odd Cisco ASA question. . .



Problem is, it appears a LOT of my filtering is over a single interface.
Don't understand. What does this mean? Are you seeing inbound traffic going
back out through the same interface?
KS1500s could handle that with ease (although not recommended), don't know
about the ASA.

-----Original Message-----
From: firewall-wizards-bounces@xxxxxxxxxxxxxxxxxxxxx
[mailto:firewall-wizards-bounces@xxxxxxxxxxxxxxxxxxxxx] On Behalf Of Keith
A. Glass
Sent: Friday, June 08, 2007 6:10 PM
To: firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
Subject: [fw-wiz] Odd Cisco ASA question. . .

Here's my situation: I'm having to replace several old Cyberguard KS-1500s
with new Cisco ASA 5500's. Problem is, it appears a LOT of my filtering is
over a single interface.

It doesn't help that we're on an entirely private network, and subnets have
been added willy-nilly.

And re-organizing the network is NOT a player.

Suggestions ? Other than "Down, not across", that is. . . .



_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: VPN IP Addressing Problem
    ... to the inside interface of the Router. ... can use the ASA interface for both the PAT and the VPN address, ... Can I just VPN to the public IP that is NATed to the ...
    (comp.dcom.sys.cisco)
  • Re: VPN IP Addressing Problem
    ... to the inside interface of the Router. ... that same subnet is already being used for my mail server (static NAT). ... can use the ASA interface for both the PAT and the VPN address, ... Can I just VPN to the public IP that is NATed to the LAN ...
    (comp.dcom.sys.cisco)
  • Re: VPN IP Addressing Problem
    ... If I took the public IP I am using for PAT and applied it to the ... to the inside interface of the Router. ... can use the ASA interface for both the PAT and the VPN address, ... Can I just VPN to the public IP that is NATed to the LAN ...
    (comp.dcom.sys.cisco)
  • ASA 5505 Outside problem
    ... I have configured a new 5505 ASA with Security Plus licence. ... With show interface I haven't any error. ... 1702 packets output, 224296 bytes, 0 underruns ... minute output rate 0 pkts/sec, ...
    (comp.dcom.sys.cisco)
  • Re: Adding an extra IP net to an external interface
    ... Why do you need an extra set of IP addresses on the interface? ... Is it necessary that the ASA be pingable at the new IP range? ... add appropriate entries to the outside interface ACL ...
    (comp.dcom.sys.cisco)