User Tools

Site Tools


network_stuff:cisco:asa

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
network_stuff:cisco:asa [2020/09/03 10:33] jotasandokunetwork_stuff:cisco:asa [2023/11/02 14:38] (current) – external edit 127.0.0.1
Line 174: Line 174:
 **Unified NAT** is used instead of NAT order meaning to down and more specific first order.  **Unified NAT** is used instead of NAT order meaning to down and more specific first order. 
 \\ \\
 +
  
 ---- ----
 +
 +__INSERT ACCESS LIST IN POSITIONS__:\\
 +
 +  access-list outside-in line 1 extended permit tcp object-group mycompany1-networks object tanium-internal eq 17472 # Ao line x is what you’re looking for on where to put the new rule
 +  show access list # blah it’ll show you the rule number order
 +  
 +
 +----
 +
 +
  
 **Troubleshooting**  **Troubleshooting** 
Line 187: Line 198:
   show conn count   show conn count
   show processes cpu-usage sorted non-zero   show processes cpu-usage sorted non-zero
-  fw01/dc.grapeshot.co.uk/pri/act# show perfmon +  fw01/dc.mycompany1.co.uk/pri/act# show perfmon 
      
   PERFMON STATS:                     Current      Average   PERFMON STATS:                     Current      Average
Line 832: Line 843:
 Network Operations profile: Network Operations profile:
  
-ukvpn.marketaxess.com/NETOPSSLVPN+ukvpn.mycompany4.com/NETOPSSLVPN
    
  
Line 957: Line 968:
  
  
-vpn.marketaxess.com +vpn.mycompany4.com 
-usvpn.marketaxess.com (legacy?) +usvpn.mycompany4.com (legacy?) 
-ukvpn.marketaxess.com+ukvpn.mycompany4.com
  
 Anyconnect. To check who is currently connected: Anyconnect. To check who is currently connected:
Line 1124: Line 1135:
  
 Unified NAT is used instead of NAT order meaning to down and more specific first order.  Unified NAT is used instead of NAT order meaning to down and more specific first order. 
 +
    
 Review "Sample Error Messages" from http:www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/5409-ipsec-debug-00.html Review "Sample Error Messages" from http:www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/5409-ipsec-debug-00.html
Line 1308: Line 1320:
  
  
 +----
 +
 +  conf t
 +  pager 0 # to stop scroll pauses
 +  
  
 ---- ----
 +
  
 **FIREPOWER** ( new evolved asa ) \\ **FIREPOWER** ( new evolved asa ) \\
network_stuff/cisco/asa.1599129197.txt.gz · Last modified: (external edit)