+ All Categories
Home > Documents > Cisco ASAv Configuration Lab

Cisco ASAv Configuration Lab

Date post: 15-Apr-2017
Category:
Upload: mykhaylo-skrypka
View: 58 times
Download: 0 times
Share this document with a friend
16
Cisco ASAv Configuration Lab (in progress) VMware and Linux based CLI configuration only
Transcript
Page 1: Cisco ASAv Configuration Lab

Cisco ASAv Configuration Lab (in progress)VMware and Linux basedCLI configuration only

Page 2: Cisco ASAv Configuration Lab

Network topology created on GNS3

VMware topology diagram

Page 3: Cisco ASAv Configuration Lab

Lab requirements

● Must be CLI configuration only● Create network topology in VMware● Configure services (DHCP, NAT and Identity NAT)● Configure object (network, services and groups) and ACLs● Layer 5-7 advanced inspection ● Configure site-to-site IPSec VPN● Enable SNMP and NetFlow● Use free Linux NMS based on Nagios OMD - Open Monitoring Distribution

Page 5: Cisco ASAv Configuration Lab

Dynamic NAT/PAT configuration

Page 6: Cisco ASAv Configuration Lab

Dynamic NAT/PAT configuration

Page 7: Cisco ASAv Configuration Lab

Dynamic NAT/PAT configuration

Page 8: Cisco ASAv Configuration Lab

Dynamic NAT/PAT configuration

Page 9: Cisco ASAv Configuration Lab

Object Groups and ACLs configuration/verification

Page 10: Cisco ASAv Configuration Lab

Object Groups and ACLs configuration/verification

Page 11: Cisco ASAv Configuration Lab

Object Groups and ACLs configuration/verification

Page 12: Cisco ASAv Configuration Lab

Object Groups and ACLs configuration/verification

Page 13: Cisco ASAv Configuration Lab

Object Groups and ACLs configuration/verification

Page 14: Cisco ASAv Configuration Lab

Layer 7 advanced inspection configuration/verification

Page 15: Cisco ASAv Configuration Lab

Layer 7 advanced inspection configuration/verification

Page 16: Cisco ASAv Configuration Lab

London-FW1(config)# flow-export destination MANAGEMENT 192.168.1.156 2055

London-FW1(config)# flow-export template timeout-rate 1

London-FW1(config)# flow-export delay flow-create 60

London-FW1(config)# logging flow-export-syslogs disable

London-FW1(config)# access-list IPANY extended permit ip any any

London-FW1(config)# class-map NETCLASS

London-FW1(config-cmap)# match access-list IPANY

London-FW1(config)# policy-map NETPOLICY

London-FW1(config-pmap)# class NETCLASS

London-FW1(config-pmap-c)# flow-export event-type all destination 192.168.1.156

London-FW1(config)# service-policy NETPOLICY global


Recommended