Author Archives: Paul Stewart, CCIE 26009 (Security)

About Paul Stewart, CCIE 26009 (Security)

Network and Security Consultant, Trainer and Blogger who enjoys understanding how things really work. Troubleshooting and problem resolution is fun, especially if it involves packet. What's on your wire[s]?

Getting Started with Cisco Anyconnect

For the last few years, Cisco has been attempting to do away with what they call the Cisco EZVPN client. This has been the solution used by many corporate users in the mobile workforce for secure access to enterprise data. … Continue reading

Posted in security | Tagged | Leave a comment

CCIE Routing and Switching Written Exam Resources

Last week I took and passed the CCIE Routing and Switching Written exam (350-001). The first and foremost reason for taking this exam was to re-certify my current CCIE Security certification. Cisco requires any CCIE level written exam to be … Continue reading

Posted in career | Leave a comment

The Future of the OSI Model

The OSI model is that thing that everyone seems to love to hate. The OSI is actually just a model that has its roots in the International Organization for Standardization. We’ve all had disagreements how certain protocols map to certain … Continue reading

Posted in Uncategorized | Leave a comment

Migrating ASA NAT Exemption Configuration

NAT exemptions are often required when a single ASA appliance is performing NAT and terminating VPN connections.  In ASA configurations prior to 8.3 and 8.4, NAT exemptions were configured with “nat 0 access-list <acl name>” and a related access-list.

Posted in security | Tagged | Leave a comment

ASA L2L VPN Spoke to Spoke Communication

It seems like some of the more challenging things to do on an ASA involve some sort of traffic being redirected out the same interface it was received on. This article addresses the requirement for spoke to hub to spoke … Continue reading

Posted in security | Tagged | Leave a comment

No SSH After Upgrading to 8.4

There are several changes when an ASA is upgraded from 8.2 to 8.4(2). The most notable of these are the ones dealing with the syntax of the NAT configuration. However, there is another gotcha that you might not be expecting. SSH will … Continue reading

Posted in security | Tagged | 3 Comments

Typical NAT/PAT Configuration Comparison for ASA 8.4

A little while back, I posted an article that took a very simple ASA configuration and migrated it to 8.4. This article takes it a step further and focuses on NAT and PAT, as well as the related access control … Continue reading

Posted in security | Tagged | Leave a comment

ASA VPN with Address Overlap

More and more, the Internet is being used as a connection to business partners. Typically this requires building an IPSec Tunnel between two VPN capable endpoints. For me the device of choice is the Cisco ASA. Since we are connecting to a business … Continue reading

Posted in security | Tagged | 8 Comments