ASA 5506-X Basic Configurations

แชร์
ฝัง
  • เผยแพร่เมื่อ 9 มิ.ย. 2019
  • Download Packet tracer's source files:
    drive.google.com/file/d/19rSo...
    Download the lab walk through docs:
    drive.google.com/file/d/1Pqkw...

ความคิดเห็น • 86

  • @IchBinAmLeben
    @IchBinAmLeben 3 ปีที่แล้ว +3

    Explained in a concise manner, and the accent, pronunciation and enunciation should be the goal of everyone wishing to do a tech video. Excellent!

  • @Gunslinger088
    @Gunslinger088 3 ปีที่แล้ว

    Thanks, Saleh. My first security lab practice. It worked very well.

  • @GA-tl4iy
    @GA-tl4iy 4 ปีที่แล้ว

    Thank you so much Saleh, this video is amazing , helpful and great for me as a beginner. Thanks again and God bless.

  • @dystopian_1
    @dystopian_1 ปีที่แล้ว

    Worked like a charm. Thank you!

  • @glenntembo2693
    @glenntembo2693 5 ปีที่แล้ว

    Thanks always Saleh, welcome back Sir

  • @ogboabeyone
    @ogboabeyone 8 หลายเดือนก่อน

    thanks for this video, it short with great meaning and impacts

  • @jhayadevbaral2218
    @jhayadevbaral2218 3 ปีที่แล้ว

    I had configured inside and outside address opposite. Thank you it worked

  • @zadkieladdae8145
    @zadkieladdae8145 5 ปีที่แล้ว

    Good work as usual.

  • @samstone4196
    @samstone4196 2 ปีที่แล้ว

    I have no words to thanks you but thank you sir

  • @diamondfacilities7259
    @diamondfacilities7259 3 ปีที่แล้ว

    Thank you , saved my day

  • @markvillanueva5358
    @markvillanueva5358 3 ปีที่แล้ว

    Thank you for sharing your knowledge Sir.

  • @maharjan_sakin
    @maharjan_sakin 2 ปีที่แล้ว

    Thank you sir for your explanation. It really helped me

  • @phenaphosa4785
    @phenaphosa4785 5 ปีที่แล้ว

    sweet work. I like when you do the configurations and you add the step by step documents and packet tracer file, than the step by step documents and packet tracer file without you doing it. am new to this tho. Great work.

  • @An-xv1jo
    @An-xv1jo 3 ปีที่แล้ว

    Thank you bro Ramesh, it worked, great, thanks alot

  • @junrenchen4492
    @junrenchen4492 2 ปีที่แล้ว

    Prof Saleh, you don't need to reply my previous msg. I just found out that Packet Tracer can be very unstable. Thank you for your videos. After many tries, when I go back to my previous file, it just work without any changes. I also managed to get outside network to access to DMZ FTP & Web Servers.
    Thank You!

  • @helaoueslati5937
    @helaoueslati5937 2 ปีที่แล้ว

    Thank you, valuable lab

  • @mohammedalrawe3535
    @mohammedalrawe3535 4 ปีที่แล้ว +2

    The best 👍🏻👏🏻 you make things easier tbh, thanks you so much Sir, i hope if you can make a video for the 3 zones INSIDE , OUTSIDE and DMZ with more than one ASA.

    • @ShaunDan
      @ShaunDan ปีที่แล้ว

      Yes This is a Good one If you can do

  • @sudipdas-jd4my
    @sudipdas-jd4my ปีที่แล้ว

    great job

  • @mdarman2682
    @mdarman2682 4 ปีที่แล้ว

    thanks , easy to understand

  • @syedabitheen600
    @syedabitheen600 3 ปีที่แล้ว

    Sir, your videos are Awesome. however Little bit more explanation will be expected for some commands. your Lab manuals and Files are great helpful

  • @omarbenazza
    @omarbenazza 4 ปีที่แล้ว

    Merci beaucoup monsieur salah

  • @tufuefiso2820
    @tufuefiso2820 8 หลายเดือนก่อน

    Thank you sir, very helpful

  • @bhimgrg05
    @bhimgrg05 4 ปีที่แล้ว

    Thank you sir !!!

  • @GA-tl4iy
    @GA-tl4iy 4 ปีที่แล้ว +2

    Thank you so much Saleh for a great video. Can you please make a video for three zones INSIDE, OUTSIDE AND DMZ PLEASE. Thanks brother

  • @Remo_Creations
    @Remo_Creations ปีที่แล้ว

    I am CCNA completed. I want to learn Firewall.
    Your vedeo is Great, and easy to uderstand.

  • @meetparekh7407
    @meetparekh7407 3 ปีที่แล้ว

    Thank you so much

  • @thuanminh2810
    @thuanminh2810 2 ปีที่แล้ว

    thanks a lot

  • @babyalonoeabdullah7672
    @babyalonoeabdullah7672 5 ปีที่แล้ว

    Thank you Sir

  • @junrenchen4492
    @junrenchen4492 2 ปีที่แล้ว

    Prof Saleh, why is it that I added inspection icmp command to the global policy but my ping packets kept on stuck at ASA even though, the destination address at simulation event is directing to the PC?
    I checked every commands related to glabal policy, class mapping ...

  • @gregoryadolphine339
    @gregoryadolphine339 4 ปีที่แล้ว

    Also, if we are matching default-inspection-traffic which seems to include well know port numbers, why do we still have to go an inspect (allow) each one?

  • @EviLno0osa77
    @EviLno0osa77 4 ปีที่แล้ว

    thhhhhhaaannnnk you so much

  • @luisverenzuela3932
    @luisverenzuela3932 4 ปีที่แล้ว

    Thanks Saleh

  • @cavourtadjouteu8084
    @cavourtadjouteu8084 4 ปีที่แล้ว

    super

  • @saltech2024
    @saltech2024 3 ปีที่แล้ว

    What about in the case where the outside access list of of the firewall has three routers, VLANs together with classless sub networks?
    ie ciscoasa---->> R1 ---->> R2 ---->> R3 ---->>SW1 ---->> VLANs (classless sub-networks)?

  • @issamnaouali1574
    @issamnaouali1574 ปีที่แล้ว

    Hi
    I have à question what i have to do yo ping my router and asa outside from gns3 ?

  • @jmhm17
    @jmhm17 3 ปีที่แล้ว

    Great stuff wish there was more context around the syntax tho, I don't follow the "inspect" logic. Why is it not just "permit"?

  • @jserr9682
    @jserr9682 2 ปีที่แล้ว

    Great tutorial. question how about the ip address for the switch

  • @uksheffeild7979
    @uksheffeild7979 5 ปีที่แล้ว

    thanks sir for that have you done but why do you not make a video on each suggestion like ( Configure Clientless, Cisco Anyconnect, and Site to Site VPN With ASA Firewall) ,ASA MPLS VPN, ASA redundancy , or ASA virtualization .

  • @ogboabeyone
    @ogboabeyone 8 หลายเดือนก่อน

    i can't ping anything outside the firewall despite that i followed your steps from A to Z including using the same ip addresses that you used here but yet i can't ping my router and server, i got all these (dns, http and icmp) in my server but yet i can i not ping server from inside pc . What should i do next

  • @hamayoonnawabzada2838
    @hamayoonnawabzada2838 2 ปีที่แล้ว

    Hi Sir
    I have a problem when. I configure ASA 5506X interfaces and saving the configuration after closing packet tracer topology.
    When start again the topology firewall show its interfaces in down state.

  • @scott2495
    @scott2495 3 ปีที่แล้ว

    What command would you do to inspect all service protocols by default rather then creating individual entries to inspect dns, http, icmp?

    • @mukharjirachapudirachapudi8796
      @mukharjirachapudirachapudi8796 ปีที่แล้ว

      each one is policy based

    • @yvesmugisha5634
      @yvesmugisha5634 2 หลายเดือนก่อน

      use these commands
      policy-map global_policy
      class inspection_default
      inspect
      then the ASA will inspect common protocols by default.

  • @khmernetworkinglearning5621
    @khmernetworkinglearning5621 ปีที่แล้ว

    👍

  • @aivanlozada3004
    @aivanlozada3004 7 หลายเดือนก่อน

    I can't ping the dns icmp and http just like other problems that i read in the comment. does anyone tell me whats the problem? or maybe the version of his packet tracer is outdated? coz im using updated maybe thats the reason?

  • @sharwandalal9739
    @sharwandalal9739 2 ปีที่แล้ว

    Hi Sir if possible please make a detailed configuration video on Asa 5506 x complete video

  • @wadep
    @wadep 3 ปีที่แล้ว

    My ASA seems to still be blocking the ICMP. After creating the class map I still connot ping 8.8.8.8 from either PC. Thoughts? the ports are enabled

    • @wadep
      @wadep 3 ปีที่แล้ว +2

      also getting the warning WARNING: Policy map global_policy is already configured as a service policy

    • @nau_hazmi7425
      @nau_hazmi7425 ปีที่แล้ว

      ​@@wadep you fix that buddy ?

    • @AntonBuketov
      @AntonBuketov 2 หลายเดือนก่อน

      @@nau_hazmi7425 did you find solution?

  • @MacCaraX
    @MacCaraX 2 ปีที่แล้ว

    I can't do ping with dns.
    PCB request timed out.
    And doesn't appear the http ping

  • @gregoryadolphine339
    @gregoryadolphine339 4 ปีที่แล้ว

    What gives? I did the same configuration in packet tracer and the pings would not go through. When i do a simulated ping, packet tracer says "The ASA does not allow any traffic from a lower security interface to a higher security interface unless it is explicitly permitted by an extended access list." Any ideas?
    object network LAN
    subnet 192.168.1.0 255.255.255.0
    !
    !
    object network LAN
    nat (inside,outside) dynamic interface
    !
    !
    !
    !
    class-map inspection_default
    match default-inspection-traffic
    !
    policy-map global_policy
    class inspection_default
    inspect icmp
    !
    service-policy global_policy interface outside

    • @MrSaleh970
      @MrSaleh970  4 ปีที่แล้ว

      Hello Gregory, sorry for the late respond, but i will do a thorough lab with walk through documents with explanations, once again, sorry for being late.

  • @amosantoine9606
    @amosantoine9606 3 ปีที่แล้ว

    Wow

  • @alisalman-lo7km
    @alisalman-lo7km ปีที่แล้ว

    hi,does anyone know how to solve this issue:WARNING: Policy map global_policy is already configured as a service policy

  • @abyanfaishal
    @abyanfaishal 2 ปีที่แล้ว

    hello sir, can make another video with inside outside and dmz, im struggling with asa pls help me

  • @lohti6399
    @lohti6399 หลายเดือนก่อน

    The network is /24 and /30 .. How can the network see each other ?

  • @EviLno0osa77
    @EviLno0osa77 4 ปีที่แล้ว

    I have been configured the same topology and I save the configuration but when I close the packet tracer and enter the file i find the DHCP works fine but the DNS in the PCs not configured and I can't access the web. any help? why the DNS becomes 0.0.0.0

    • @MrSaleh970
      @MrSaleh970  4 ปีที่แล้ว

      Salam Anas, start over you work from scratch, and follow the walk through document, and to have further help, see one of my latest videos about ASA 5506.

    • @EviLno0osa77
      @EviLno0osa77 4 ปีที่แล้ว

      @@MrSaleh970 it's from the scratch and i follow the steps , before i close the packet tracer file , everything works fine .
      the problem when i close it and reenter it the DNS change to zeros but the DHCP work fine

    • @MrSaleh970
      @MrSaleh970  4 ปีที่แล้ว

      @@EviLno0osa77 did you save your work before you close packet tracer?

    • @EviLno0osa77
      @EviLno0osa77 4 ปีที่แล้ว

      @@MrSaleh970 yes i did

    • @brbiitstaff3032
      @brbiitstaff3032 4 ปีที่แล้ว

      @@EviLno0osa77 you must copy run start each device

  • @An-xv1jo
    @An-xv1jo 4 ปีที่แล้ว

    i tried two of your labs (the above one and the one where all configurations are there) but am not able to ping server in any case, after giving the exact comments in packet tracer, all your labs used to work for me but not for this asa configs.

    • @MrSaleh970
      @MrSaleh970  4 ปีที่แล้ว

      Hello, did you follow the walk through documents? download both files, the P.T. and the word documents,and follow through, and when you are done with your configurations, try to run some show commands to make sure you did the right configurations.

    • @An-xv1jo
      @An-xv1jo 3 ปีที่แล้ว

      thank you @karthik ramesh, it worked brother. i am going to ask you a small favor, i checked for packet tracer 6.2 from netacad but they have taken out it seems, i prefer to download directly from netacad website, anything you can suggest to get 6.2 version ?

  • @thepuldarshana9056
    @thepuldarshana9056 11 หลายเดือนก่อน

    can you do a vpn connection configuration with ASA and other remote location ?

  • @varshithreddy8236
    @varshithreddy8236 3 ปีที่แล้ว

    what is mean by security level (0,100,70) what was the use of that..? can anyone explain please

    • @mukharjirachapudirachapudi8796
      @mukharjirachapudirachapudi8796 ปีที่แล้ว

      security level ranges from 0-100 ,100 is trusted; the lower level the security is
      the less trusted zone it is.

  • @teknotouc2155
    @teknotouc2155 ปีที่แล้ว

    You Mail addres ?

  • @An-xv1jo
    @An-xv1jo 4 ปีที่แล้ว +1

    Sir i tried again on this again, but cannot ping 8.8.8.8 , what could be the reason ?

    • @MrSaleh970
      @MrSaleh970  4 ปีที่แล้ว

      Salam dear, make sure the ports are enabled, and that you configure the default route for outside on the ASA, if you still can't ping, please send me a message on Messenger, and will help you out, wishing you a blessed day. S.

    • @An-xv1jo
      @An-xv1jo 4 ปีที่แล้ว

      @@MrSaleh970 Salam Sir. Thank you so much for your prompt reply. Yes the ports are all enabled, I been trying in and out but cannot get an idea why so this happens with all ASA labs. 8.8.8.1 gets pinged in all cases but not .8. Really need your help to get thru this. How to contact you on messenger ? Greetings and have a great day, Anand

    • @zeeshanbasharat5361
      @zeeshanbasharat5361 3 ปีที่แล้ว

      assign IP to DNS server statically 8.8.8.8 255.0.0.0 default gateway 8.8.8.1

  • @jhayadevbaral2218
    @jhayadevbaral2218 3 ปีที่แล้ว

    i have issue that i can't ping 8.8.8.8 server though everything look fine

  • @brodakebangoura6438
    @brodakebangoura6438 ปีที่แล้ว

    Hello sir please I needed your help because of project of end my engineering cycle
    I work on ASA5505

  • @DineshKumar-vu6dx
    @DineshKumar-vu6dx 4 ปีที่แล้ว

    How to ping from outside to inside it's not working please help me

    • @MrSaleh970
      @MrSaleh970  4 ปีที่แล้ว +1

      Hello, Please follow the walk through documents, and check your work as you go.

  • @ivanrished5228
    @ivanrished5228 2 ปีที่แล้ว

    I would like to watch configuration of DMZ

  • @christmvouenze1071
    @christmvouenze1071 ปีที่แล้ว

    why dhcp option 3 IP command?

    • @yvesmugisha5634
      @yvesmugisha5634 2 หลายเดือนก่อน

      used for default-gateway whereas for dns is option 6.

  • @xpromatrix4499
    @xpromatrix4499 4 ปีที่แล้ว

    it is not big deal just give the network with multiple vlans in multilayer switch them show the demo. unsatisfied

  • @AntonBuketov
    @AntonBuketov 2 หลายเดือนก่อน +1

    I want to write to other people who will watch this tutorial, don’t watch it - it doesn’t work. This guy glued it together somewhere in the middle and everything works for him. All the other dudes who wrote here were either bought or bots. The real comments that are here also encountered a problem, in the end he sends them to the stolen manual. Conclusion - don't watch.

  • @leothalion3983
    @leothalion3983 3 ปีที่แล้ว

    Thank you so much