ASA Question
DevilWAH
Member Posts: 2,997 ■■■■■■■■□□
Hi guys, I see a lot of jobs asking for people who have experince with ASA firewall solutions.
This is something I have never had to use a my work place so I am looking for a way in to them.
The closes I ahve come is working with IOS Zonebased firewalls. Is there much simulrity between this and ASA. I heard some one saying the ZONE based firewalls are simmler in syntax to the ASA model? but I have no idea how true this is.
Also are there any good ASA emulators out there? I know the ASA was updated so what model/version would be a good one to look at for some one comming in to learn about this?
Aaron
This is something I have never had to use a my work place so I am looking for a way in to them.
The closes I ahve come is working with IOS Zonebased firewalls. Is there much simulrity between this and ASA. I heard some one saying the ZONE based firewalls are simmler in syntax to the ASA model? but I have no idea how true this is.
Also are there any good ASA emulators out there? I know the ASA was updated so what model/version would be a good one to look at for some one comming in to learn about this?
Aaron
- If you can't explain it simply, you don't understand it well enough. Albert Einstein
- An arrow can only be shot by pulling it backward. So when life is dragging you back with difficulties. It means that its going to launch you into something great. So just focus and keep aiming.
Linkin Profile - Blog: http://Devilwah.com
Comments
-
ConstantlyLearning Member Posts: 445Hi guys, I see a lot of jobs asking for people who have experince with ASA firewall solutions.
This is something I have never had to use a my work place so I am looking for a way in to them.
The closes I ahve come is working with IOS Zonebased firewalls. Is there much simulrity between this and ASA. I heard some one saying the ZONE based firewalls are simmler in syntax to the ASA model? but I have no idea how true this is.
Also are there any good ASA emulators out there? I know the ASA was updated so what model/version would be a good one to look at for some one comming in to learn about this?
Aaron
I'm starting down this road as well.
I believe PIX OS can be emulated in GNS3 and ASA v.7 can be emulated in Qemu but not v.8.
From reading online posts there does seem to be a good bit of messing about to get the ASA emulation working though."There are 3 types of people in this world, those who can count and those who can't" -
peanutnoggin Member Posts: 1,096 ■■■□□□□□□□Also are there any good ASA emulators out there? I know the ASA was updated so what model/version would be a good one to look at for some one comming in to learn about this?
Aaron
Here's some info from Tiersten: ASA 5505
Maybe this can help you. The ASA 5505 with a 10 user license is fairly reasonable in price on ebay or different reseller's websites. I hope this helps.
-PeanutWe cannot have a superior democracy with an inferior education system!
-Mayor Cory Booker -
tiersten Member Posts: 4,505The closes I ahve come is working with IOS Zonebased firewalls. Is there much simulrity between this and ASA. I heard some one saying the ZONE based firewalls are simmler in syntax to the ASA model? but I have no idea how true this is.Also are there any good ASA emulators out there?
-
DevilWAH Member Posts: 2,997 ■■■■■■■■□□PEMU which is a modified QEMU does PIX/ASA emulation. GNS3 works as a GUI frontend to PEMU.
HAve you managed to get version 8 working on this? Also are there major differences between version 7 and 8 ?- If you can't explain it simply, you don't understand it well enough. Albert Einstein
- An arrow can only be shot by pulling it backward. So when life is dragging you back with difficulties. It means that its going to launch you into something great. So just focus and keep aiming.
Linkin Profile - Blog: http://Devilwah.com -
tiersten Member Posts: 4,505HAve you managed to get version 8 working on this?
The emulation isn't perfect though. It has some issues (or did last time I looked) with transparent mode and something else I can't remember.Also are there major differences between version 7 and 8 ? -
DevilWAH Member Posts: 2,997 ■■■■■■■■□□Sorry one last thing, If i was looking for an ASA hardware for my lab, are there any you would recomend ? Ie. Cheap but cover it all?
- If you can't explain it simply, you don't understand it well enough. Albert Einstein
- An arrow can only be shot by pulling it backward. So when life is dragging you back with difficulties. It means that its going to launch you into something great. So just focus and keep aiming.
Linkin Profile - Blog: http://Devilwah.com -
tiersten Member Posts: 4,505Sorry one last thing, If i was looking for an ASA hardware for my lab, are there any you would recomend ? Ie. Cheap but cover it all?
The 5505 doesn't do failover at all with the base license and it only does stateless Active/Standby with the Security Plus license. I'm unsure of the limitations of the IPS SSC as well. -
DevilWAH Member Posts: 2,997 ■■■■■■■■□□do most compinies expect configuration via CLI or the ASDM?
- If you can't explain it simply, you don't understand it well enough. Albert Einstein
- An arrow can only be shot by pulling it backward. So when life is dragging you back with difficulties. It means that its going to launch you into something great. So just focus and keep aiming.
Linkin Profile - Blog: http://Devilwah.com -
tiersten Member Posts: 4,505do most compinies expect configuration via CLI or the ASDM?
-
mikearama Member Posts: 749do most compinies expect configuration via CLI or the ASDM?
I've worked at two companies that employed ASA's, and both were fine with config work done via the ASDM. Businesses want the job done... I haven't seen any indication that they give a rat's ass how it's done, as long as it's done.
Having said that, the engineer where I am now is old school, and laughs when I do a rule or nat with the ASDM. Whatever.There are only 10 kinds of people... those who understand binary, and those that don't.
CCIE Studies: Written passed: Jan 21/12 Lab Prep: Hours reading: 385. Hours labbing: 110
Taking a time-out to add the CCVP. Capitalizing on a current IPT pilot project. -
accely Member Posts: 101I purchased an ASA 5505 for my home network, replaced the stupid linksys with it and it was a great move. Not only was I forced to make sure it works since it's in my live network, but I always have access to it to test stuff or to play around with it. Was only 350$ brand new. I mainly bought it for the CCSP track which I Just finished. It was a must for the SNAF and SNAA exams
Just passed my IPS test today and fully CCSP now
cya!Progress: CCIE RS Lab scheduled for Jan. 2012
Equipment: Cisco 360 program racks -
DevilWAH Member Posts: 2,997 ■■■■■■■■□□Just finaly got round to getting ASA 8 to run in GNS3
now got to work out how to get ASDM working.
I was thinking I will get hold of the CBT CCSP nuggets before I really get in to this as I can see there is a lot here to learn.
To many things I want to learn! I really must finish my CCNP before getting side tracked!- If you can't explain it simply, you don't understand it well enough. Albert Einstein
- An arrow can only be shot by pulling it backward. So when life is dragging you back with difficulties. It means that its going to launch you into something great. So just focus and keep aiming.
Linkin Profile - Blog: http://Devilwah.com -
burbankmarc Member Posts: 460Just finaly got round to getting ASA 8 to run in GNS3
now got to work out how to get ASDM working.
I was thinking I will get hold of the CBT CCSP nuggets before I really get in to this as I can see there is a lot here to learn.
To many things I want to learn! I really must finish my CCNP before getting side tracked!
The 802 IOS works fine in GNS3 .7. But in order to interface it with your PC nic card you need the dev version of GNS3. I'm pretty sure anyways. You'll need to hook it to your real network so you can upload the ASDM and stuff into it. -
DevilWAH Member Posts: 2,997 ■■■■■■■■□□burbankmarc wrote: »The 802 IOS works fine in GNS3 .7. But in order to interface it with your PC nic card you need the dev version of GNS3. I'm pretty sure anyways. You'll need to hook it to your real network so you can upload the ASDM and stuff into it.
The latest version of GNS 7.02 i think seems to work fine. I can get an ip address and see it from my vm machines.
Starting to build up a nice lab on GNS now, At the monent is mostly GNS3 running inside VM machines, but just got a few Servers, so going to have some with VMware exi running and some with GNS3 / Dynips running so I can set up a full blow lab.
- If you can't explain it simply, you don't understand it well enough. Albert Einstein
- An arrow can only be shot by pulling it backward. So when life is dragging you back with difficulties. It means that its going to launch you into something great. So just focus and keep aiming.
Linkin Profile - Blog: http://Devilwah.com -
johnwest43 Member Posts: 294old school question of the day. without googling does anyone know the name of the original operating system on a pix firewall?CCNP: ROUTE B][COLOR=#ff0000]x[/COLOR][/B , SWITCH B][COLOR=#ff0000]x[/COLOR][/B, TSHOOT [X ] Completed on 2/18/2014
-
mikej412 Member Posts: 10,086 ■■■■■■■■■■johnwest43 wrote: »old school question of the day. without googling does anyone know the name of the original operating system on a pix firewall?
Finesse (<--- highlight my post to see my answer).:mike: Cisco Certifications -- Collect the Entire Set! -
johnwest43 Member Posts: 294mikej412 wins!!! now for the lighting bonus round what does it stand for? Remember no googling.
And for the super secret question of the day what does PIX stand for?CCNP: ROUTE B][COLOR=#ff0000]x[/COLOR][/B , SWITCH B][COLOR=#ff0000]x[/COLOR][/B, TSHOOT [X ] Completed on 2/18/2014 -
mikej412 Member Posts: 10,086 ■■■■■■■■■■johnwest43 wrote: »mikej412 wins!!! now for the lighting bonus round what does it stand for? Remember no googling.
And for the super secret question of the day what does PIX stand for?
Fast something something something or other
and
something like Private Internet eXchange which I always wondered about:mike: Cisco Certifications -- Collect the Entire Set! -
peanutnoggin Member Posts: 1,096 ■■■□□□□□□□johnwest43 wrote: »mikej412 wins!!! now for the lighting bonus round what does it stand for? Remember no googling.
And for the super secret question of the day what does PIX stand for?
Okay... I had to google the answer so I'd know!!We cannot have a superior democracy with an inferior education system!
-Mayor Cory Booker -
johnwest43 Member Posts: 294Mike is on a roll!!!
fast internet server executive
Private internet exchange kind of like the ip version of pbx.CCNP: ROUTE B][COLOR=#ff0000]x[/COLOR][/B , SWITCH B][COLOR=#ff0000]x[/COLOR][/B, TSHOOT [X ] Completed on 2/18/2014 -
TesseracT Member Posts: 167I've been using an 800 router for my home connection but I'm thinking of setting it into bridge mode and getting an ASA 5505 (Expensive bridged modem I know).
Is the clustering/failover stuff really that hard with the ASAs? To get the 5510 with the proper license is way too much for a home network, and honestly GNS3 seems like a lot of stuffing around while I could be actually learning something...
Could I just learn the theory and configs for the advanced features and be done with it? -
Nobylspoon Member Posts: 620 ■■■□□□□□□□I picked up an ASA 5505 with a 10 user base license earlier this week for $250. I work next door to Cisco, bought it from one of their security guys. Definatly a heck of a deal, usually a used one with the same license is closer to $300-350 but keep shopping around and you mind find a good deal. I came across this one on Craigslist.
With work and school I haven't had a lot of time to dive deep into the ASA yet. I am currently working with a PIX 506E in school and that knowledge has made it pretty easy for me to start configuring my ASA.
I should have it fully configured and my home network migrated over to it by the end of the weekend. I am even considering throwing a honeypot on a seperate vlan since my license comes with 3 (two of which can't talk to each other)WGU PROGRESS
MS: Information Security & Assurance
Start Date: December 2013