background image

Americas Headquarters

Cisco Systems, Inc.
San Jose, CA

Asia Pacific Headquarters

Cisco Systems (USA) Pte. Ltd.
Singapore

Europe Headquarters

Cisco Systems International BV
Amsterdam, The Netherlands

Cisco has more than 200 offices worldwide. Addresses, phone numbers, and fax numbers are listed on the 

Cisco Website at 

www.cisco.com/go/offices

.

Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL:

 www.cisco.com/go/trademarks

Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R)

© 2011-2016 Cisco Systems, Inc. All rights reserved.

Printed in the USA on recycled paper containing 10% postconsumer waste.

78-19752-02

7. (Optional) Allowing Access to Public Servers Behind the ASA

The Public Server pane automatically configures the security policy to make an inside server accessible from the Internet. As a business 
owner, you might have internal network services, such as a web and FTP server, that need to be available to an outside user. You can 
place these services on a separate network behind the ASA, called a demilitarized zone (DMZ). By placing the public servers on the 
DMZ, any attacks launched against the public servers do not affect your inside networks.

Step 1

In the main ASDM window, choose 

Configuration

 > 

Firewall

 >

 Public Servers

. The Public Server pane appears.

Step 2

Click 

Add

, then enter the public server settings in the Add Public Server dialog box. (For information about any field, click 

Help

.)

Step 3

Click 

OK

. The server appears in the list.

Step 4

Click 

Apply

 to submit the configuration to the ASA.

8. (Optional) Running VPN Wizards

You can configure VPN using the following wizards:

Site-to-Site VPN Wizard—Creates an IPsec site-to-site tunnel between two ASAs.

AnyConnect VPN Wizard—Configures SSL VPN remote access for the Cisco AnyConnect VPN client. AnyConnect provides secure 
SSL connections to the ASA for remote users with full VPN tunneling to corporate resources. The ASA policy can be configured to 
download the AnyConnect Client to remote users when they initially connect via a browser. With AnyConnect 3.0 and later, the 
client can run either the SSL or IPSec IKEv2 VPN protocol. 

Clientless SSL VPN Wizard—Configures clientless SSL VPN remote access for a browser. Clientless, browser-based SSL VPN lets 
users establish a secure, remote-access VPN tunnel to the ASA using a web browser. After authentication, users access a portal page 
and can access specific, supported internal resources. The network administrator provides access to resources by users on a group 
basis. ACLs can be applied to restrict or allow access to specific corporate resources.

IPsec (IKEv1) Remote Access VPN Wizard—Configures IPsec VPN remote access for the Cisco IPsec client.

Step 1

In the main ASDM window, choose 

Wizards

 > 

VPN Wizards

, then choose one of the following:

Site-to-Site VPN Wizard

AnyConnect VPN Wizard

Clientless VPN Wizard

IPsec (IKEv1) Remote Access VPN Wizard

Step 2

Follow the wizard instructions. (For information about any wizard field, click 

Help

.)

 Q

UICK

 S

TART

 G

UIDE

Cisco ASA 5505 Adaptive 
Security Appliance

Содержание ASA 5505

Страница 1: ...QUICK START GUIDE Cisco ASA 5505 Adaptive Security Appliance ...

Страница 2: ...is guide See http www cisco com go asadocs for links to the RCSI and other documents 1 Verifying the Package Contents Cisco ASA 5505 Power cable US shown Power supply adapter Blue console cable Security Services Card Slot 1 2 CONSOLE RESET POWER 48VDC 7 POWER over ETHERNET 6 5 4 3 2 1 0 Documentation C i s c o A S A 5 5 0 5 Q u i c k S t a r t G u i d e ...

Страница 3: ...rvers with Ethernet cables to Ethernet 1 through 7 Note Connect a PC to the ASA so that you can run the Adaptive Security Device Manager ASDM See 4 Initial Configuration Considerations Step 3 Connect Power over Ethernet PoE devices such as Cisco IP Phones or network cameras with Ethernet cables to switch ports 6 or 7 the only ports providing power to PoE devices If you connect a server such as a w...

Страница 4: ...ved an IP address on the 192 168 1 0 24 network using DHCP Step 6 Check the LINK ACT indicators to verify interface connectivity Interface Connectivity Each Ethernet interface has an LED to indicate a physical link is established When the LED is solid green a link is established When the LED is flashing green there is network activity If a LINK ACT LED is not lit the link could be down due to a du...

Страница 5: ...commended or required For example you should change the following settings from their defaults The privileged EXEC mode enable password that is required to administer the ASA through ASDM and the CLI When using the ASA as a VPN endpoint using the SSL VPN features The hostname domain name and DNS server names Outside interface IP address to a static address Identity certificate WINS names when acce...

Страница 6: ... enter the following URL https 192 168 1 1 admin The Cisco ASDM web page appears Step 3 Click Run Startup Wizard Step 4 Accept any certificates according to the dialog boxes that appear The Cisco ASDM IDM Launcher appears Step 5 Leave the username and password fields empty and click OK The main ASDM window appears and the Startup Wizard opens See 6 Running the Startup Wizard ...

Страница 7: ... not already running in the main ASDM window choose Wizards Startup Wizard Step 2 Follow the instructions in the Startup Wizard to configure your ASA Step 3 While running the wizard you can accept the default settings or change them as required For information about any wizard field click Help Hostname Domain name Administrative passwords Interfaces IP addresses Static routes DHCP server Network a...

Страница 8: ...ices on a separate network behind the ASA called a demilitarized zone DMZ By placing the public servers on the DMZ any attacks launched against the public servers do not affect your inside networks Step 1 In the main ASDM window choose Configuration Firewall Public Servers The Public Server pane appears Step 2 Click Add then enter the public server settings in the Add Public Server dialog box For ...

Страница 9: ...nnect via a browser With AnyConnect 3 0 and later the client can run either the SSL or IPSec IKEv2 VPN protocol Clientless SSL VPN Wizard Configures clientless SSL VPN remote access for a browser Clientless browser based SSL VPN lets users establish a secure remote access VPN tunnel to the ASA using a web browser After authentication users access a portal page and can access specific supported int...

Страница 10: ...ards VPN Wizards then choose one of the following Site to Site VPN Wizard AnyConnect VPN Wizard Clientless VPN Wizard IPsec IKEv1 Remote Access VPN Wizard Step 2 Follow the wizard instructions For information about any wizard field click Help ...

Страница 11: ...fices Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and or its affiliates in the U S and other countries To view a list of Cisco trademarks go to this URL www cisco com go trademarks Third party trademarks mentioned are the property of their respective owners The use of the word partner does not imply a partnership relationship between Cisco and any other company 1110R ...

Отзывы: