Popular Posts
Live Tweets
- I just downloaded iPerf3 for Mac OS and Lion @WLANBook @AccessAgility #iperf #iperf3 http://t.co/cdxb4EjE 20 hours ago
- Getting Started with Cisco Anyconnect http://t.co/EhdHuQF7 1 day ago
- Wow, where does the weekend go. I need lots and lots of caffeine. 2 days ago
- This is a pretty good cloud service that allows you to create and share visio like drawings. http://t.co/1eHdM72H 4 days ago
- Great write-up about ASA ICMP Error Inspection by @jastorino http://t.co/T6CBuSCm 4 days ago
-
Recent Posts
Recent Comments
Tag Archives: firewall
Getting Started with Cisco Anyconnect
For the last few years, Cisco has been attempting to do away with what they call the Cisco EZVPN client. This has been the solution used by many corporate users in the mobile workforce for secure access to enterprise data. … Continue reading
Migrating ASA NAT Exemption Configuration
NAT exemptions are often required when a single ASA appliance is performing NAT and terminating VPN connections. In ASA configurations prior to 8.3 and 8.4, NAT exemptions were configured with “nat 0 access-list <acl name>” and a related access-list.
ASA L2L VPN Spoke to Spoke Communication
It seems like some of the more challenging things to do on an ASA involve some sort of traffic being redirected out the same interface it was received on. This article addresses the requirement for spoke to hub to spoke … Continue reading
No SSH After Upgrading to 8.4
There are several changes when an ASA is upgraded from 8.2 to 8.4(2). The most notable of these are the ones dealing with the syntax of the NAT configuration. However, there is another gotcha that you might not be expecting. SSH will … Continue reading
Typical NAT/PAT Configuration Comparison for ASA 8.4
A little while back, I posted an article that took a very simple ASA configuration and migrated it to 8.4. This article takes it a step further and focuses on NAT and PAT, as well as the related access control … Continue reading
ASA VPN with Address Overlap
More and more, the Internet is being used as a connection to business partners. Typically this requires building an IPSec Tunnel between two VPN capable endpoints. For me the device of choice is the Cisco ASA. Since we are connecting to a business … Continue reading
Using an ASA to Establish a Guest Network
It is not uncommon to visit a small to medium sized customer for a first time and find a wireless and/or guest network that compromises security for the rest of the network. Organizations that lack policies and procedures for their … Continue reading
Egress Interface Selection on the Cisco ASA
One of the frustrating things about the Cisco ASA is that it does not support policy based routing, or pbr. With pbr, an administrator can get very granular with routing IP traffic. For example, an access-list can match traffic and … Continue reading



