Download as pptx, pdf, or txt
Download as pptx, pdf, or txt
You are on page 1of 128

Chapter 10:

Advanced Cisco Adaptive Security


Appliance

CCNA Security v2.0


Overview of ASDM

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 2
Preparing for ASDM

Preparing the ASA


5505

Verify Connectivity to
the ASA

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Starting ASDM

ASDM Security
Certificate

ASDM Launch
Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Starting ASDM (Cont.)

ASDM Security
Warning - 1

ASDM Security
Warning - 2

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Starting ASDM (Cont.)

Authenticate to Use
ASDM

Smart Call Home


Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
ASDM Home Page Dashboards
ASDM Device Dashboard Page

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
ASDM Home Page Dashboards (Cont.)
ASDM Firewall Dashboard Page

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
ASDM Page Elements

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
ASDM Configuration and Monitoring Views
Configuration View

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
ASDM Configuration and Monitoring Views
(Cont.)
Monitoring View

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
ASDM Wizards

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
The Startup Wizard

Startup Wizard Starting


Point Window

Startup Wizard Basic


Configuration Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
The Startup Wizard (Cont.)

Startup Wizard Interface


Selection Window

Startup Wizard Switch


Port Allocation Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
The Startup Wizard (Cont.)

Startup Wizard Interface IP


Address Configuration Window

Startup Wizard DHCP


Server Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
The Startup Wizard (Cont.)

Startup Wizard Address


Translation (NAT/PAT) Window

Startup Wizard Administrative


Access Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
The Startup Wizard (Cont.)
Startup Wizard Summary Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Different Types of VPN Wizards

ASDM VPN Wizards

ASDM Remote
Access VPN
Assistant

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Other Wizards

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
Configuring Settings in ASDM

Configuration Device Setup Tab

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Configuring Settings in ASDM (Cont.)

Configuration Device Management Tab

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Configuring Basic Settings in ASDM

Configuring Hostname, Domain


Name, and Enable Password

Configuring a Master
Passphrase

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
Configuring Basic Settings in ASDM (Cont.)
Configuring Legal Notification

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Configuring Interfaces in ASDM
Configuring Interfaces

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Configuring Interfaces in ASDM (Cont.)

Adding an Outside Interface

Change Switch Port Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Configuring Interfaces in ASDM (Cont.)

Adding an Outside Interface

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
Configuring Interfaces in ASDM (Cont.)
Advanced Outside Interface Settings

Updated Interface Page

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Configuring Interfaces in ASDM (Cont.)

Verifying Interfaces

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Configuring Interfaces in ASDM (Cont.)

Enable Switch Ports

Apply
Configuration

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Configuring the System Time in ASDM

Manually Change
the System Time

Use NTP to Change the


System Time

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Configuring the System Time in ASDM (Cont.)

Add an NTP Server

Configure an NTP Server

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Configuring the System Time in ASDM (Cont.)
Apply the Configuration

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Configuring Routing in ASDM

Configuring Routing

Configuring a Default
Static Route

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Configuring Routing in ASDM (Cont.)

Add or Edit Route Window Add Static Route Details

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Configuring Routing in ASDM (Cont.)

Apply the Configuration

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Configuring Device Management Access in
ASDM
Configure ASDM/HTTPS/Telnet/SSH Access

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Configuring Device Management Access in
ASDM (Cont.)

Add Device Access Configuration Window

Configure SSH Settings

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Configuring DHCP Services in ASDM
DHCP Server Page

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Configuring DHCP Services in ASDM (Cont.)
Edit DHCP Server Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Configuring DHCP Services in ASDM (Cont.)
Configuring DHCP Server Services

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
Configuring DHCP Services in ASDM (Cont.)
Verifying DHCP Server Services

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Objects in ASDM
Network Objects/Groups Page

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
Objects in ASDM (Cont.)
Adding a Network Object/Group

Add Network Object Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
Objects in ASDM (Cont.)
Add Network Object Group Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
Objects in ASDM (Cont.)
Service Objects/Group Page

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
Objects in ASDM (Cont.)
Adding a Service Object/Group

Add Service Object Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
Objects in ASDM (Cont.)
Add Service Object Group Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Configuring ACLs Using ASDM
ACLs in ASDM

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Configuring ACLs Using ASDM (Cont.)
Add Access Rule Window Diagramming Access Rules

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Configuring Dynamic NAT in ASDM

Add Network Object Window

Creating a Network Object


for Public Addresses

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Configuring Dynamic NAT in ASDM (Cont.)

Creating a Network Object for


Dynamic NAT

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
Configuring Dynamic PAT in ASDM

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Configuring Static NAT in ASDM
Static NAT in ASDM

Advanced Static NAT Settings in ASDM

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Configuring AAA Authentication

User Accounts Page

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Configuring AAA Authentication (Cont.)
Add User Account Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
Configuring AAA Authentication (Cont.)
AAA Server Groups Page

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Configuring AAA Authentication (Cont.)
Add AAA Server Group Window Add AAA Server Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
Configuring AAA Authentication (Cont.)
Completed AAA Server Groups Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Configuring AAA Authentication (Cont.)
AAA Access Page

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Configuring AAA Authentication (Cont.)
AAA Access > Authentication Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
Configuring a Service Policy Using ASDM
Service Policy in ASDM

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Configuring a Service Policy Using ASDM
(Cont.)
Configure a Service Policy

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
Configuring a Service Policy Using ASDM
(Cont.)
Configure Traffic Classification Criteria

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
Configuring a Service Policy Using ASDM
(Cont.)
Configure Actions

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
ASA Support for Site-to-Site VPNs

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
ASA Site-to-Site VPNs Using ASDM

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Configuring the ISR Site-to-Site VPNs Using
the CLI
Basic ISR Configuration

Configure the ISAKMP Policy

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Configuring the ISR Site-to-Site VPNs Using
the CLI (Cont.)
Configure the IPsec and VPN ACL

Configure and Apply the Crypto Map

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Configuring the ASA Site-to-Site VPNs Using
ASDM

Basic ISR Configuration

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Configuring the ASA Site-to-Site VPNs Using
ASDM (Cont.)

Introduction Window

Peer Device
Identification Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Configuring the ASA Site-to-Site VPNs Using
ASDM (Cont.)

Traffic to Protect
Window

Security Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Configuring the ASA Site-to-Site VPNs Using
ASDM (Cont.)

NAT Exempt Window

Summary Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Verifying Site-to-Site VPNs Using ASDM

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Test the Site-to-Site VPNs Using ASDM
Establish the VPN Tunnel Connection to the Remote Network

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
Test the Site-to-Site VPNs Using ASDM (Cont.)
Monitoring the VPN Tunnel

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
Test the Site-to-Site VPNs Using ASDM (Cont.)
Verify VPN Tunnel Connectivity from the External Host

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
Remote-Access VPN Options

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
IPsec Versus SSL

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
IPsec Versus SSL (Cont.)
Comparing IPsec and SSL

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
ASA SSL VPNs

Remote Access VPN Wizards

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
ASA SSL VPNs (Cont.)
Cisco ASA SSL Remote Access VPN Solutions

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Clientless SSL VPN Solution
Cisco ASA Clientless SSL VPN Deployment

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
Clientless SSL VPN Solution (Cont.)

Clientless Login Web page

Web Portal Home Page

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Client-Based SSL VPN Solution

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Cisco AnyConnect Secure Mobility Client

AnyConnect
Connection Window

AnyConnect
Authenticate
Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Cisco AnyConnect Secure Mobility Client (Cont.)

AnyConnect
Authenticated Window

AnyConnect Statistics
Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
AnyConnect for Mobile Devices
Cisco AnyConnect Secure Mobility Client is available on the following
platforms:
• iOS

• Android

• BlackBerry

• Windows Mobile

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 87
Configuring Clientless SSL VPN on an ASA

ASDM Assistant

Clientless VPN
Wizard

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 88
Sample Clientless VPN Topology

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
Clientless SSL VPN

Clientless SSL VPN


Introduction Window

SSL VPN Interface


Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
Clientless SSL VPN (Cont.)

User Authentication
Window

Group Policy Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
Clientless SSL VPN (Cont.)

Bookmark List Window

Configure GUI Customization


Objects Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
Clientless SSL VPN (Cont.)

Add Bookmark List


Window

Select Bookmark Type


Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 93
Clientless SSL VPN (Cont.)

Add Bookmark Window

Revised Add Bookmark List


Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 94
Clientless SSL VPN (Cont.)

Revised Configure GUI


Customization Objects Window

Revised Bookmark List


Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 95
Clientless SSL VPN (Cont.)
Summary Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 96
Verifying Clientless SSL VPN

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 97
Testing the Clientless SSL VPN Connection

Security Certificate Window

Logon Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 98
Testing the Clientless SSL VPN Connection (Cont.)

Web Portal Home Page

Web Portal Web Access


Page

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 99
Testing the Clientless SSL VPN Connection (Cont.)

Web Portal File Access Page

Log Out of the Web Portal

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 100
Viewing the Generated CLI Config

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 101
Configuring SSL VPN AnyConnect

ASDM Assistant

Client-Based VPN Wizard

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 102
Sample SSL VPN Topology

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 103
AnyConnect SSL VPN

AnyConnect VPN Wizard


Introduction Window

Connection Profile
Identification Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
AnyConnect SSL VPN (Cont.)
VPN Protocols Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 105
AnyConnect SSL VPN (Cont.)

Client Images Window

Add AnyConnect
Client Image Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 106
AnyConnect SSL VPN (Cont.)

Browse Flash Window

Add AnyConnect
Client Image Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 107
AnyConnect SSL VPN (Cont.)
Completed Client Images Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 108
AnyConnect SSL VPN (Cont.)
Authentication Methods Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 109
AnyConnect SSL VPN (Cont.)

Client Address
Management Window

Add IPv4 Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 110
AnyConnect SSL VPN (Cont.)

Completed Client Address


Management Window

Network Name Resolution


Servers Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 111
AnyConnect SSL VPN (Cont.)
Completed Network Name Resolution Servers Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 112
AnyConnect SSL VPN (Cont.)

NAT Exempt Window

Completed NAT Exempt


Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 113
AnyConnect SSL VPN (Cont.)

AnyConnect Client
Deployment

Summary Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 114
Verifying AnyConnect Connection
AnyConnect Connection Profiles Page

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 115
Verifying AnyConnect Connection (Cont.)

Verifying the Client-Based Configuration

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 116
Install the AnyConnect Client

Security Certificate Window

Logon Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 117
Install the AnyConnect Client (Cont.)

Cisco AnyConnect VPN Client


Window

Manual Installation Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 118
Install the AnyConnect Client (Cont.)

Run Installer Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 119
Install the AnyConnect Client (Cont.)
Cisco AnyConnect VPN Client Setup Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 120
Install the AnyConnect Client (Cont.)
End-User Agreement Window

User Account Control Security Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 121
Install the AnyConnect Client (Cont.)
Ready to Install AnyConnect Client

Installing the AnyConnect Client

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 122
Install the AnyConnect Client (Cont.)
Complete Cisco AnyConnect VPN Installation

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 123
Install the AnyConnect Client (Cont.)
Start the Cisco AnyConnect VPN Cisco AnyConnect VPN Client
Cisco Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 124
Install the AnyConnect Client (Cont.)
Cisco AnyConnect VPN Connect Window

Certificate Security Warning Window

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 125
Install the AnyConnect Client (Cont.)
Cisco AnyConnect VPN Authentication
Window

Cisco AnyConnect VPN Icon in


System Tray

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 126
Install the AnyConnect Client (Cont.)
Cisco AnyConnect VPN Verifying Connectivity to Internal
Client Status Network

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 127
Viewing the Generated CLI Config

AnyConnect SSL
VPN Configuration
settings:
• NAT

• WebVPN

• Group policy

• Tunnel group

© 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 128

You might also like