It is currently Sat Sep 21, 2019 7:45 pm


All times are UTC




Post new topic Reply to topic  [ 97 posts ]  Go to page 1, 2, 3, 4, 5 ... 10  Next
Author Message
 Post subject: ASA 8.02 - Good old FW, but full tuned
PostPosted: Sat Nov 13, 2010 7:48 pm 
Offline

Joined: Thu Jun 24, 2010 3:58 pm
Posts: 411
Location: [email protected]
Hi, I know that this is a little bit old version, but in this "release" I've combined all kind of hacks/tricks I find on the Internet, so have fun :)

[Combines]
Jeremy Grossmann and Pedro Flor original how to tutorials/scripts which allows you to emulate ASA with WebVPN and multiple contexts firewall;
Nekkro-kvlt tutorials which make it work with any ASDM version you have, without a proxy server, hard-coding it as hardware ASA5520;
Plus my new script with start menu which allows you to choice between single mode, multi-mode and more.

Download Area: [bayfiles] - [4shared]

Youtube: [HOWTO use my custom ASA startup-script in GNS3]
Youtube: [HOWTO use ASA with ASDM without proxy]
Please use HD quality for view! (720p)

This image is compatible with the following files [Best, at build date]:
HW - ASA5520 - (ASA 5520 Series Adaptive Security Appliance)
ASA - 8.0(2) - (Adaptive Security Appliance Software)
ASDM - 6.3(1) - (Cisco Adaptive Security Device Manager)
CSD - 3.2.0.136 - (Cisco Secure Desktop)
ACVC - 2.0.0343 - (AnyConnect VPN Client)
Attachment:
File comment: Custom Startup script for ASA
first_start_v2_dec_2010.zip [2.3 KiB]
Downloaded 8212 times

If you got problems starting ASDM update your Java software:
Download and install latest JAVA version (Get Offline file - Full setup version)
Download and install ASDM client from ASA, don't just run it...
Change the "javaw.exe" path in ASDM-IDM.lnk (desktop shortcut) to point to your latest java. "C:\Program Files\Java\<latest_ver>javaw.exe"
And be sure that you have this "-Xms256m -Xmx256m" in that shortcut as well

Attachment:
File comment: Configure GNS3 Settings for Qemu to fix the console on hosts with IPv6 installed
Install1.jpg
Install1.jpg [ 58.93 KiB | Viewed 76247 times ]
Attachment:
File comment: Configure GNS3 Settings for ASA and hide main window
Install2.jpg
Install2.jpg [ 65.71 KiB | Viewed 77947 times ]


Technologov edit: grossmj recommends: replace "e1000" by "i82559er", if e1000 doesn't work.




Last edited by tranzitwww on Thu Dec 23, 2010 10:50 am, edited 8 times in total.

Top
 Profile  
 
 Post subject: Re: ASA 8.02 - Old good FW, but full tuned
PostPosted: Sat Nov 13, 2010 8:34 pm 
Offline

Joined: Thu Jun 24, 2010 3:58 pm
Posts: 411
Location: [email protected]
For those of you which can't start ASA in GNS3 please reconfigure GNS3 as described in above screenshots.
Without those settings is very possible to have this problem: Qemu starts fine no errors, but when you open the console, it just open a empty putty/telnet window and remains like that forever, enter key has no effect...
This issue is present only for users where a ping to localhost responds from '::1' and not '127.0.0.1' (IPv6 installed), Qemu has a problem when binding is on IPv6, for [debug details check this post]

Qemu IPv6 binding for serial/console connection gets unexpected results...
Attachment:
ASA_bad_qemuwarper.png
ASA_bad_qemuwarper.png [ 136.4 KiB | Viewed 75217 times ]


To hide Qemu's main VGA window (which has no use for ASA) configure Qemu options with those options:
"-vga none -vnc none" (windows) or "-nographic" (linux)

After booting you have this menu to choice between single mode and multiple mode.
Because it is not possible to switch mode from ASA commands. You will get errors like: "ERROR: The requested mode was not saved because the flash update failed."
Attachment:
ASA_Menu.jpg
ASA_Menu.jpg [ 65.83 KiB | Viewed 74633 times ]


In the previous version of startup script where lina's binary (ASA main application) were copied on /mnt/disk0 (flash drive) it gets stuck in the first start-up for every new ASA dragged into topology. The solution was to press 'Ctrl+C' until this message "Exiting lina main!" is received, than restart the ASA. Or to wait few minutes before choice a option in script menu.
From version two of the script this is not a problem any more, it will boot and work from the first time...
Attachment:
Lina_Stuck.jpg
Lina_Stuck.jpg [ 56.58 KiB | Viewed 74345 times ]


Last edited by tranzitwww on Sat Dec 04, 2010 6:00 pm, edited 3 times in total.

Top
 Profile  
 
 Post subject: Re: ASA 8.02 - Old good FW, but full tuned
PostPosted: Sat Nov 13, 2010 8:52 pm 
Offline

Joined: Thu Jun 24, 2010 3:58 pm
Posts: 411
Location: [email protected]
When you switch back from [single]->[multi] or [multi]->[single] it automatically saves your old configuration as a backup into the flash ('disk0:/.private/') named
'startup-config-multiple.old' or 'startup-config-single.old' and copy in 'startup-config' the previous one (backup) if exists or just put the default config...
Attachment:
config_backup.jpg
config_backup.jpg [ 73.55 KiB | Viewed 74355 times ]


Single context mode
Attachment:
ASA_single.jpg
ASA_single.jpg [ 49.22 KiB | Viewed 74305 times ]


Multiple context mode
Attachment:
ASA_multiple.jpg
ASA_multiple.jpg [ 50.94 KiB | Viewed 74322 times ]


Top
 Profile  
 
 Post subject: Re: ASA 8.02 - Good old FW, but full tuned
PostPosted: Mon Nov 22, 2010 8:53 pm 
I have tried this image with the new wrapper and I still get a blank screen. Are there any specific GNS config settings?

Thanks !


Top
  
 
 Post subject: Re: ASA 8.02 - Good old FW, but full tuned
PostPosted: Tue Nov 23, 2010 10:00 pm 
Offline

Joined: Thu Jun 24, 2010 3:58 pm
Posts: 411
Location: [email protected]
Hi,
Reconfigure Qemu and ASA settings like the posted screenshots.

What version of GNS3/Qemu/Qemuwrapper you use?
What OS you have: Windows/Linux?

Please post the 'command line' that was used to start Qemu for ASA.
Code:
wmic PROCESS get Caption,Commandline | find /I "qemu.exe"
ps -aux | grep -i qemu


Top
 Profile  
 
 Post subject: Re: ASA 8.02 - Good old FW, but full tuned
PostPosted: Wed Dec 08, 2010 1:26 pm 
I am using GNS3 0.7.3 beta
I'm not sure what version of qemuwrapper I'm using but it is one of the latest...

I have tried and tried but when I start the ASA it hangs on this screen...HELP
http://i51.tinypic.com/2n1unm.png

Any assistance will be greatly appreciated


Top
  
 
 Post subject: Re: ASA 8.02 - Good old FW, but full tuned
PostPosted: Wed Dec 08, 2010 1:40 pm 
Offline

Joined: Thu Jun 24, 2010 3:58 pm
Posts: 411
Location: [email protected]
Well that's the QEMU VGA window, ignore that window (but don't close it!!) and open the console to your ASA....
Right click on ASA and select "Console"
Have Fun :))


Top
 Profile  
 
 Post subject: Re: ASA 8.02 - Good old FW, but full tuned
PostPosted: Wed Dec 08, 2010 4:19 pm 
tranzitwww wrote:
Well that's the QEMU VGA window, ignore that window (but don't close it!!) and open the console to your ASA....
Right click on ASA and select "Console"
Have Fun :))



thanks for the quick reply...I did that but when I click on the console, nothing happens...

Here is my setup on the qemu page...
http://i52.tinypic.com/2mdmjyb.png
http://i54.tinypic.com/2ch0x76.png
http://i54.tinypic.com/fthwmr.png


Top
  
 
 Post subject: Re: ASA 8.02 - Good old FW, but full tuned
PostPosted: Wed Dec 08, 2010 8:01 pm 
Offline

Joined: Thu Jun 24, 2010 3:58 pm
Posts: 411
Location: [email protected]
What do you mean "nothing happens..." ?
I don't know how you tested it, but just to show you how this thing works I've recorded a video...

Youtube: [HOWTO use my custom version of ASA in GNS3]
Please use HD quality for view! (720p)


Top
 Profile  
 
 Post subject: Re: ASA 8.02 - Good old FW, but full tuned
PostPosted: Wed Dec 08, 2010 8:37 pm 
tranzitwww wrote:
What do you mean "nothing happens..." ?
I don't know how you tested it, but just to show you how this thing works I've recorded a video...

Youtube: [HOWTO use my custom version of ASA in GNS3]
Please use HD quality for view! (720p)



Thank you so much....Following this procedure worked...I was using the wrong image for the initrd...I'm going to watch your video now..

Great video....it shows me what I needed and a couple of things that I was missing...

Would it be possible to show the asdm config or show the tutorial on that? Your post mentions that asdm is configured in your system without requiring a proxy like fiddler. How would I do that?

Thanks again




Last edited by blkr00t on Wed Dec 08, 2010 8:47 pm, edited 1 time in total.

Top
  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 97 posts ]  Go to page 1, 2, 3, 4, 5 ... 10  Next

All times are UTC


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group

phpBB SEO