ASA 5510 and Higher Default Configuration

The default factory configuration for the ASA 5510 and higher adaptive security appliance configures the following:

• The management interface, Management 0/0. If you did not set the IP address in the configure factory-default command, then the IP address and mask are 192.168.1.1 and 255.255.255.0.

• The DHCP server is enabled on the security appliance, so a PC connecting to the interface receives an address between 192.168.1.2 and 192.168.1.254.

• The HTTP server is enabled for ASDM and is accessible to users on the 192.168.1.0 network.

H Accessing the Command-Line Interface

The configuration consists of the following commands:

interface management 0/0

ip address 192.168.1.1 255.255.255.0

nameif management

security-level 100

no shutdown

asdm logging informational 100

asdm history enable

http server enable

http 192.168.1.0 255.255.255.0 management

dhcpd address 192.168.1.2-192.168.1.254 management

dhcpd lease 3 600

dhcpd ping_timeout 750

dhcpd enable management

PIX 515/515E Default Configuration

The default factory configuration for the PIX 515/515E security appliance configures the following:

• The inside Ethernetl interface. If you did not set the IP address in the configure factory-default

command, then the IP address and mask are 192.168.1.1 and 255.255.255.0.

• The DHCP server is enabled on the security appliance, so a PC connecting to the interface receives

an address between 192.168.1.2 and 192.168.1.254.

• The HTTP server is enabled for ASDM and is accessible to users on the 192.168.1.0 network.

The configuration consists of the following commands:

interface ethernet 1

ip address 192.168.1.1 255.255.255.0

nameif management

security-level 100

no shutdown

asdm logging informational 100

asdm history enable

http server enable

http 192.168.1.0 255.255.255.0 management

dhcpd address 192.168.1.2-192.168.1.254 management

dhcpd lease 3 600

dhcpd ping_timeout 750

dhcpd enable management

Accessing

the Command-Line Interface

For initial configuration, access the command-line interface directly from the console port. Later, you

can configure remote access using Telnet or SSH according to Chapter 40, "Managing System Access."

If your system is already in multiple context mode, then accessing the console port places you in the

system execution space. See Chapter 3, "Enabling Multiple Context Mode," for more information about

multiple context mode.

%

Note

If you want to use ASDM to configure the security appliance instead of the command-line interface, you

can connect to the default management address of 192.168.1.1 (if your security appliance includes a

factory default configuration. See the "Factory Default Configurations" section on page 2-1.). On the

Setting Transparent or Routed Firewall Mode H

ASA 5510 and higher adaptive security appliances, the interface to which you connect with ASDM is Management 0/0. For the ASA 5505 adaptive security appliance, the switch port to which you connect with ASDM is any port, except for Ethernet 0/0. For the PIX 515/515E security appliance, the interface to which you connect with ASDM is Ethernet 1. If you do not have a factory default configuration, follow the steps in this section to access the command-line interface. You can then configure the minimum parameters to access ASDM by entering the setup command.

To access the command-line interface, perform the following steps:

Step 1 Connect a PC to the console port using the provided console cable, and connect to the console using a terminal emulator set for 9600 baud, 8 data bits, no parity, 1 stop bit, no flow control.

See the hardware guide that came with your security appliance for more information about the console cable.

Step 2 Press the Enter key to see the following prompt: hostname>

This prompt indicates that you are in user EXEC mode. Step 3 To access privileged EXEC mode, enter the following command:

hostname> enable

The following prompt appears:

Password:

Step 4 Enter the enable password at the prompt.

By default, the password is blank, and you can press the Enter key to continue. See the "Changing the Enable Password" section on page 8-1 to change the enable password.

The prompt changes to:

hostname#

To exit privileged mode, enter the disable, exit, or quit command. Step 5 To access global configuration mode, enter the following command:

hostname# configure terminal

The prompt changes to the following:

hostname(config)#

To exit global configuration mode, enter the exit, quit, or end command.

Continue reading here: Configuring VLAN Interfaces

Was this article helpful?

0 0

Readers' Questions

  • Paul
    How to enable asdm on asa 5505?
    8 months ago
  • To enable ASDM on an ASA 5505:
    1. Login to the ASA CLI using your admin credentials.
    2. Enter the “enable” command.
    3. Enter the “configure terminal” command.
    4. Enter the “http server enable” command.
    5. Choose whether to use http or https:a. For http, enter the “http 0.0.0.0 0.0.0.0 inside” command. b. For https, enter the “ssl enable” and “ssl trust-point <SSL Cert Name>” commands.
    6. Enter the “username <admin username> privilege 15 password <admin password>” command.
    7. Enter the “exit” command or “wr mem” command to save the changes.
    8. Open a web browser and type the IP address of the ASA into the address bar (http://[IP Address of ASA]).
    9. Log in with the admin username and password.
    10. Click the “ASDM” link, or “Launch ASDM” button to launch ASDM.