GANYMEDE for ASA 5550

Hello

How to configure Ganymede for ASA 5550 with acs4.2. I have two asa, one is active and others in mode. pls tell me how to set up. I couldn't find any good docs either.

Thank you.

Hi Gavin,

Here is the sample config for ASA's telnet authentication from Tacacs: username admin password xxxxx privilege 15 aaa-server TEST protocol tacacs+ aaa-server TEST (inside) host x.x.x.x  yyy   [x.x.x.x is the ip address of the tacacs server and is reachable from the inside interface and yyy is the shared secret key.] aaa authentication telnet console TEST LOCAL   [This will send the telnet authentication request to the tacacs server first and if it is not reachable then use the local database of the ASA] aaa authentication ssh console TEST LOCAL    [same as above but for ssh session] aaa authorization exec authentication-server    [this enables exec authorization for the telnet and ssh sessions.] 
aaa authentication http console TEST LOCAL [for HTTP]
order of accounting AAA TEST [this helps accountants of the order for all orders entered in the telnet or ssh session.]  On the Ganymede server we need to add this ASA as a RADIUS client with shared secret key yyy.

You can find more details: -.

http://www.Cisco.com/en/us/docs/security/ASA/asa80/configuration/guide/mgaccess.html#wp1042026

The GBA, you need to add ASA as device under config network with Protocol Ganymede.

Thank you

Vinay

If this helps you or answers to your question if it you please mark it as 'responded' or write it down, if other users can easily find it.

Tags: Cisco Security

Similar Questions

  • What VPN Client for ASA 5550 AnyConnect Premium connection?

    We have version9 a couple of ASA550 I want to put in place a VPN client for use with remote access to administration.  We have included AnyConnect VPN, Premium license peers 2 so I guess we can just use of Cisco AnyConnect VPN client.  I went to Cisco's Web site and it says that I don't have right to the last Anyconnect VPN Client 4.x but I don't have access to the version 3.x.

    The 3.x client is compatible with the ASA and also Windows 10?

    If Yes, what is the correct file to use, there are many files listed for download in AnyConnect 3.x?

    In addition, what is the difference between the AnyConnect 3.x and 4.x customer and why Cisco restricting 4.x?

    Jim

    AnyConnect 4.x has changed the licensing model. AnyConnect 4.x licenses are term based licensing vs perpetual 3.x. There are a number of other differences, mainly due to there being only two license types - more and Apex - no Mobile plus, Advanced Endpoint Assessment, shared VPN etc. Cisco offers a nominal or no license cost of migration until the end of 2015. (depending on what you have: positive Essentials or Apex at premium)

    AnyConnect 3.1 will work with Windows 10 and the latest version of the Software ASA (since Version 3.1.10010). Reference:

    http://www.Cisco.com/c/en/us/TD/docs/security/vpn_client/AnyConnect/ANYC...

    There are two ways it is distributed - as a stand-alone installation or package for the distribution of the ASA station. Both come in Windows, Mac OS X and Linux distributions. For a Windows client, you must use either:

    AnyConnect-Win-3.1.12020-pre-deploy-K9.ISO

    AnyConnect-victory - 3.1.12020 - k9.pkg

    .. .to the current version of these respective form factors.

  • ASA 5550 inspect necessary for h323 and SIP?

    Is it necessary to have "inspect h323 h225", "inspect h323 ras", and "sip inspect" active on an ASA 5550? We have a VCSC, deployment of telepresence vcse... just wondering if with these permits, if there is no possibility of causing packet loss to public or external codecs the inspection process. We have a 250 MB, Internet connection... General average use runs approximately 180 MB. Twice a week or two, we get loss of packages are essential to some of the external codecs... I was wondering if by disabling the inspection process, so who would speed things a bit or other problems.

    Thank you for your response.

    Charlie

    Hello

    If your VCSE is not behind a NAT on its way to the internet, you can go one disable any SIP/h.323 inspection mechanism, once this may cause some problems and it is not at all in your case.

    Communication between the control VCS and motorway, it is strongly recommended not having NAT of VCS Control to VCS Expressway, once that VCS control is not in a position to address NAT inside SIP/H3232 messages, and you may not use any mechanism of inspection/ALG SIP / h.323 in this way once he can cause problems because the communication uses a non-standard protocol The sanction of cisco.

    Problem of packet loss, however, is not much related to inspection firewall features. You tell him you have enough bandwidth in your link to the appeal, but you should also ask, the remote side has bandwidth enough to host the call? Packet loss can occur in any part of the whole path of the call, then you should analyze the path of the entire network, end to end. Also, the links internet it is not possible to apply QoS (normally), so you really do not guarantee that your traffic is be prioritized by your service provider and the remote site.

    Concerning

    Paulo Souza

    My answer was helpful? Please note the useful answers and do not forget to mark questions resolved as "responded."

  • Work around the EXEC Mode when connect in SSH for ASA 8.4 (2)

    Hi all

    I would check with you all, is there anyone able to access the 8.4 (2) Cisco ASA CLI without needs to enter the enable password?

    Currently, it is configured with GANYMEDE for CLI and ASDM access.

    ASDM, we have not had any problems and be able to access and to change directly in own entry GANYMEDE credential.

    However for the CLI, we need to type 'enable' and also the enable password before login.

    Is there anyway that we could ignore the EXEC mode and access to the PRIVILEDGE mode directly?

    Thanks a lot for your help!

    Current config:

    AAA-server xxxx Protocol Ganymede +.

    AAA-server xxxx (management) host xxxx

    Kind regards

    Danny

    Unfortunately, ASA does not support the feature AAA Exec permission yet, so he can't be configured with GANYMEDE or RADIUS to directly access the privileged exec mode. We go through with authentication enable

    Like this:

    ===================

    ASA:username: *.

    ASA:password: *.

    ASA: > activate

    Password: *.

    ===================

    This is because the ASA does not include the cisco-avpair = "" shell: priv-lvl = 15 "attribute."

    The ASA does not support the Exec AAA authorization still features, so it cannot be configured with RADIUS or GANYMEDE.

    The workaround for this problem is to manually the user to activate the mode mode switch.

    It is compatible with IOS (routers/switches).

    Kind regards

    Jatin kone

    -Does the rate of useful messages-

  • Cisco Anyconnect/WebVPN license for ASA 5510

    Hello

    Someone could please check the licenses for ASA 5510 attachment and let me know. We currently have ASA 5510 with basic license. According to the table attached under VPN sessions, he mentions that "250 combined SESSIONS IPSec and WebVPN" and to "Max box of WebVPN Session" it is mentioned that 2nd meeting, exceeding that we must buy license optional webvpn. While we the 250 combined license for IPSec and webVPN. We must purchase additional anyconnect license to set up remote access for users who want to use the internal resources from outside the network. OrElse, we don't have to purchase license and can configure webvpn/anyconnect of existing combined license existing users basic ASA license? Waiting for your response. Thank you.

    You are welcome.

    1 Yes

    2 AnyConnect requires no Java, but it can he use when connecting to one AnyConnect SSL VPN client and launch the Web browser option start Java-based. There was a bug with the AnyConnect old versions had later who should have addresses. You also have the option to launch via IE and using ActiveX or simply throw AnyConnect directly - neither of these two methods require Java.

    Here is a document TAC on the Java questions if you want more details.

    Please take a moment to note the useful messages and mark your answers questions.

  • ASA 5550 VPN question

    Dear Experts,


    / * Style definitions * / table. MsoNormalTable {mso-style-name : « Table Normal » ; mso-tstyle-rowband-taille : 0 ; mso-tstyle-colband-taille : 0 ; mso-style-noshow:yes ; mso-style-priorité : 99 ; mso-style-qformat:yes ; mso-style-parent : » « ;" mso-rembourrage-alt : 0 à 5.4pt 0 à 5.4pt ; mso-para-marge-top : 0 ; mso-para-marge-droit : 0 ; mso-para-marge-bas : 10.0pt ; mso-para-marge-left : 0 ; ligne-hauteur : 115 % ; mso-pagination : widow-orphelin ; police-taille : 11.0pt ; famille de police : « Calibri », « sans-serif » ; mso-ascii-font-family : Calibri ; mso-ascii-theme-font : minor-latin ; mso-fareast-font-family : « Times New Roman » ; mso-fareast-theme-font : minor-fareast ; mso-hansi-font-family : Calibri ; mso-hansi-theme-font : minor-latin ; mso-bidi-font-family : Arial ; mso-bidi-theme-font : minor-bidi ;}

    I configured Cisco ASA 5550 as a VPN server at the head office.

    I configured the material Cisco ASA5505 branch customer.

    Tunnel is up & I can access my local computer in the branch of LAN H.O. But I am unable to ping / LAN access machine from branch headquarters.

    It's just a communication face right now.


    Need help.


    Thank you


    I.A

    Is your customer/PAT ezvpn or NMS (network expansion Mode) mode?

    If the NEM, then you will need to add the following in your inside_nat0_outbound ACL:

    inside_nat0_outbound 10.10.10.0 ip access list allow 255.255.255.0

    Also, please add the following command on ASA5550:

    management-access inside

    And from the remote host, see if you can ping 10.10.10.1.

  • GANYMEDE + for the unified management of ASA and VPN auth

    Hello, I have ASA 5540 and 4.2 ACS (AD backend), I want authentic unified management and vpn access.

    For example, I have two groups in ACS (mapping AD): Admins, VPN access.

    I wish that Admins have full access (shell, VPN) and "Access VPN" only vpn, without shell of any kind.

    I understand how to do with RADIUS - use 'Service-type' and network access profile, but how to do it with GANYMEDE +?

    There is something

    I explained to him almost the same scenario in the post of 2008

    https://Cisco-support.hosted.Jivesoftware.com/message/853751#853751

    To achieve this, you should have even ASA added to GANYMEDE and RADIUS AAA cleint.

    Since you want to group admin must have FULL access so don't change anything on this group.

    Now vpnaccess Group on ACS must have only access to the VPN, then here you need to implement IP-based NAR

    Go into the setup of the Group > ip based NAR

    I hope this helps.

    Rgds, jousset

    Note the useful posts ~

  • 10.8.2 OSX driver for deskjet 5550?

    HP never, ever release a driver HP Deskjet 5550 for OSX 10.8.2? If not, why? It is a printer perfectly fine now, I can't use. Thank you...

    Signed,

    A frustrated owner of HP printer

    Hello

    The printer is no longer supported for Mac OS X 10.6 and will not become supported in the future on new versions of the OS.

    http://support.HP.com/us-en/document/c01856359

    However, you can still find 3rd-party solutions that you can use the printer.

    Try the HPIJS 3rd part drivers printer below, don't forget to install one of the 3 required downloads and and follow the Set Up instructions... These drivers compatible with all the latest versions of OS and your printer list as supported:

    http://www.linuxfoundation.org/collaborate/workgroups/OpenPrinting/macosxhpijs#Downloads_Required

    Shlomi

  • Download SNMP MIB for Laserjet 5550 and 1505n. Paper, stuffing, etc.

    Please help me. I need the MIB files for SNMP messages as paper, jam, etc. Printers are LaserJet 5550 and 1505n. Rules of HP.

    Thank you very much for the help. I discovered a different way, but it's here:

    On the right side you can see the address and in the Middle, the data type and name. They are all in position 0.

    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_PaperJam, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.9
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_PaperOut, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.8
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_PeripheralError, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.6
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_ConnectionTerminationAck, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.5
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_NewMode, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.4
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_InterventionState, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.3
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_AtBusy, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.24
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_TcpBusy, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.23
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_LlcBusy, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.22
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_NovBusy, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.21
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_Reserved, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.20
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_PaperState, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.2
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_PaperOutput, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.19
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_Printing, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.18
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_DoorOpen, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.17
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_Initialize, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.16
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_Wait, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.15
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_Busy, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.14
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_IoActive, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.13
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_MemoryOut, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.12
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_PagePunt, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.11
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_TonerLow, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.10
    syDeviceValueDefinitionWithVariableAddress, 0, SnmpIntegerSPS, HP_LineState, SnmpIntegerSPS2ScadaInteger, Y, N, N, DIN, 0, 0, 0, 1.3.6.1.4.1.11.2.3.9.1.1.2.1

    I hope it is useful for someone too.

    Best regards to all users of the forum!

    Cristian

  • Protect and control the license for ASA with the power of fire

    I had 1 ASA 5515 initially delivered with the software cx, then made room for the software of firepower and got the virtual firesight for 2 devices and license of TAMAS tha L-5515, but this license was told only the URLs and malware license, I thought that this license was for all that since he has no other licenses in the data sheet and it's Reference with more features.

    How can I get the license protect and control now so I can add the asa with the firepower to firesight and apply to all licenses

    Thank you

    Hello

    L ASA5515-TAMAS = SKU license plans to "MALWARE" and "URLFilter" and legally gives the user to updates of the signature "PROTECT + CONTROL". It does not license "PROTECT + CONTROL". You need to buy "ASA5515-CTRL-LIC =" to license "PROTECT + CONTROL".

    Please discuss a case with CISCO GLO, they can help provide a CTRL license

    -DD

  • For ASA IPS modules

    Hello

    I would ask you to help learn p/n for the IPS/IDS modules in:

    -ASA 5510

    -ASA 5515 X

    I would like to buy our dealer, but he asks that no part numbers, that he can't find them...

    I know that for ASA5510 was AIP-SSM-10, but it currently is EOS. ASA 5515 X has software module, but I can't find this p/n.

    Concerning

    Hi Michal,

    IPS-ASA5515-SSP

    SSP ASA IPS 5515-X license

    SF-ASAIPS64 - 7.1 - K9

    ASA software IPS 5500-X 7.1 for IPS SSP

    You can always check through "https://apps.cisco.com/Commerce/home".

    It may be useful

    G1

  • Issue of NAT for ASA running 8.4 (5)

    We have a client who is about to hang an ASA off the coast of the demilitarized zone of our firewall that is running 8.4 (5). This firewall is currently on another part of our network, and NAT will be considerably changed. Now, everything on the client firewall must be coordinated outside for the same thing as the IP model internal, for example like the old "static (inside, outside) 172.16.16.0 172.16.16.0 netm 255.255.255.0" command.

    When I look at the document from Cisco for (conversion) NAT

    ( http://www.cisco.com/en/US/docs/security/asa/asa83/upgrading/migrating.html#wp96828), I see not all conversions between the two. This is not a "nat 0" because users need access to certain hosts inside the firewall of our customers.

    Can someone tell me please in the right direction? Thank you

    Hello

    Lets assume that the following is true

    • The new ASA has 'inside' and 'outside' network/interface only
    • The ASA News should do EVERYTHING NAT 'inside' to 'outside' to any kind of situation traffic (your firewall handles this?)

    Then you can simply have the ASA with absolutely no. NAT configurations. The ASA with new software releases 8.3 and above all automatically passes all traffic through the ASA UNNATED. We use it on a single client and it works very well.

    Please let me know if the above is the case, or can't think of anything else

    -Jouni

  • SSH failure for ASA 8.2 (3)

    I have a pair of 5520 s 8.2 (3) running in active failover mode / standby, routed. I have a problem with SSH as it stops worked shortly after, less than 8 hours during the current network, telnet works fine as is https/AMPS.

    I've recreated the encryption key and ssh access. When I try to connect, I just get a blinking cursor, telnet to the ip address and port 22 also works.

    Thank you

    Hi Patrick,

    There were a handful of SSH bugs fixed since 8.2 (3). A couple of note are:

    CSCti72411 - ASA 8.2.3 may not accept connections from management after failover

    CSCtf01287 - SSH to the ASA may fail - ASA can send Reset

    You should switch to 8.2 (5) to obtain the fix for these bugs, and your problem should be solved.

    -Mike

  • Minimum memory on ASA5585 for ASA OS 9.1

    Hello

    I´d would like to know how many DRAM and flash memory, an ASA5585 must run the ASA OS 9.1.

    Thank you for all.

    Hello

    We ordered 5 ASA5585 - SSP-20 x, a couple of years back. They have 12 GB of memory.

    The document I linked also list they have 12 GB of memory. So, I wonder if you run software 8.2 on the SAA? It could be that it limits the amount of memory that recognizes the ASA.

    -Jouni

  • AIP - SSM upgrade for ASA active / active

    Hello world!

    I need help on improving the aip - ssm modules to E4 on two s asa who are active/active state. I'll be able to do this without downtime? What are the considerations?

    AIPs are independent of the resumption of the SAA, however, the SAA can consider the status of the AIP in passage of failover, which means it can failover

    If it detects a module AIP descending on the active device.

    The best method for upgrading in this situation will be the status of active failover Setup for all groups on the SAA primary, then upgrade the AIP of the ASA high school.

    Once the agreement in principle of the school is completely updated and functional, then set all groups to be active with the ASA failover secondary.

    Then the primary AIP.

    Once the primary AIP is completely level and working, you can then restore the status of the ASAs failover, by setting the active failover for the Group on the ASAs specific you want them to be active on...

    Kind regards

Maybe you are looking for

  • I can't load Yahoo or cbonline

    I can't load Yahoo or cbonline my favorites, or a google search and I have yahoo as my home page, but when I run Firefox I get "Oops Firefox cannot load my.yahoo.com

  • Error message: "cannot find this file" and songs seem to disappear from Windows Media Player 11.

    Original title: my songs seem to disappear from windows media player 11 I make a playlist and some of the songs come with a "cannot find this file" dialog box I click on 'place to open the file' and the song is there but will not play. Help, I'm losi

  • My laptop is not booting

    My laptop is acer aspire 5349 series: when I start my laptop it says BOOTMGR is missingPress Ctrl + alt + delete to restart,any solution me please?

  • Problem with WIFI adapter

    HelloA friend has HP 2000-2d51eu laptop and he gave me car wifi just left. I have try all the drivers from the HP website for this model and I can't activate it. Installed the new windows 7 and still nothing. Trying to find the drivers to work but I

  • Unistall Olympus Master 2

    It cannot install Olympus Master 2 and help? Milt