Raleigh Office Cisco ASA Configuration
The following sections cover the steps necessary to complete the goals listed earlier.
Configuring IP Addressing and Routing
This section demonstrates how to configure the interfaces and default gateway on the Cisco ASA using the Adaptive Security Device Manager (ASDM). The following are the configuration steps:
Step 1 Working with a new Cisco ASA installation, the administrator logs in via the command-line interface (CLI) and sets the management interface IP address (10.10.30.1) and other interface configuration with the following commands.
Co-A-ASA1# configure terminal Co-A-ASA1(config)# interface Management0/0
Co-A-ASA1(config-if)# nameif management Co-A-ASA1(config-if)# security-level 80 Co-A-ASA1(config-if)# ip address 10.10.30.1 255.255.255.0 Co-A-ASA1(config-if)# no shutdown Co-A-ASA1(config-if)# exit Co-A-ASA1(config)# Step 2 The administrator enables ASDM access only from machines on the management network with the following commands:
Co-A-ASA1(config)# http server enable
Co-A-ASA1(config)# http 10.10.30.0 255.255.255.0 management Co-A-ASA1(config)# asdm location 10.10.30.0 255.255.255.0 management
Step 3 The next step is to configure the outside, inside, and DMZ interfaces. The administrator connects to the Cisco ASA via ASDM and clicks Configuration > Device Setup > Interfaces, as illustrated on Figure 12-2.
Step 4 The administrator selects the GigabitEthernet0/0 interface and clicks the Edit button. The screen illustrated in Figure 12-3 is shown. The administrator enters the interface name (outside), the IP address configuration (209.165.200.225), subnet mask (255.255.255.0), and a description for the outside interface.
Figure 12-2 Configuring the Cisco ASA Interfaces on ASDM
Figure 12-2 Configuring the Cisco ASA Interfaces on ASDM

- Figure 12-3 Outside Interface Configuration
Step 5 Similarly, the GigabitEthernet0/1 interface is configured as the inside interface, as shown in Figure 12-4. The security level for the inside interface is set to 100.
Figure 12-4 Inside Interface Configuration
Figure 12-4 Inside Interface Configuration
Step 6 The GigabitEthernet0/2 interface is configured as the dmz interface, as shown in Figure 12-5. The security level of the dmz interface is set to 50.
Step 7 The next step is to configure the default route of the Cisco ASA to point to the ISP router (209.165.200.226). To configure the default route, navigate to Configuration > Device Setup > Routing > Static Routes and click Add. The screen shown in Figure 12-6 is displayed. Choose the outside interface from the drop-down menu, and enter 0.0.0.0 for the IP address and 0.0.0.0 for the Mask. The Gateway IP is 209.165.200.226, and the metric is 1. Leave all the other options with their default value.
Figure 12-5 DMZInterface Configuration
Figure 12-5 DMZInterface Configuration

- Figure 12-6 Inside Interface Configuration
Configuring PAT on the Cisco ASA
The next step is to configure PAT for internal users to be able to communicate to the Internet. Complete the following steps to configure PAT on the Cisco ASA.
Step 1 To configure PAT, go to Configuration > Firewall > NAT Rules, click Add, and choose Add Dynamic NAT Rule from the drop-down menu, as illustrated in Figure 12-7.
Figure 12-7 Configuring PAT for Internal Users
Figure 12-7 Configuring PAT for Internal Users
Step 2 The screen shown in Figure 12-8 is displayed. Under the Original section, choose the inside interface from the drop-down menu.
Step 3 Expand the Source option to select the inside source address space. This is illustrated in Figure 12-9. Select the inside network (10.10.10.0/24) and click OK.
Figure 12-8 Adding a Dynamic NAT Rule
Figure 12-8 Adding a Dynamic NAT Rule
Figure 12-9 Selecting the Source
Step 4 Under the Translated section, click the Manage button to add a global address pool.
Step 5 The screen shown in Figure 12-10 is displayed. Under the IP Addresses to Add section, click Port Address Translation (PAT) using IP Address of the interface and click the Add button to include it under the Address pools, as shown in Figure 12-10.
Figure 12-10 Configuring PAT to Use the Outside Interface Address
Figure 12-10 Configuring PAT to Use the Outside Interface Address
Step 6 Click OK and apply your changes to the Cisco ASA.
Configuring Static NAT for the DMZ Servers
The DMZ servers must be statically translated with a public IP address. Table 12-1 lists the IP address mapping of the DMZ servers.
|
Server |
Inside IP Address |
Translated Address |
|
10.10.20.10 |
209.165.200.227 |
|
|
E-mail server |
10.10.20.20 |
209.165.200.228 |
Complete the following steps to configure static NAT for the DMZ web and e-mail servers.
Step 1 Navigate to Configuration > Firewall > NAT Rules, click Add, and choose Add Static NAT Rule from the drop-down menu, as illustrated in Figure 12-11.
Figure 12-11 Adding a Static NAT Rule
Figure 12-11 Adding a Static NAT Rule
Step 2 The screen shown in Figure 12-12 is displayed. First configure static NAT for the web server. Under the Original section, choose the dmz interface from the drop-down menu, and enter the web server physical IP address (10.10.20.10) as the source.
Figure 12-12 Adding a Static NAT Rule
Step 3 Under the Translated section, choose the outside interface from the drop-down menu.
Step 4 Click the Use IP address option, and enter the public address to which the web server will be translated (209.165.200.227).
Step 5 Click OK.
Step 6 Repeat the same procedure for the e-mail server.
Continue reading here: Cisco ASA Antispoofing Configuration
Was this article helpful?