Thursday, 5 January 2017

TCP reset on ASA

I often see TCP Reset-I or TCP Reset-O in the logs on the ASA. Its not clear what it means.

TCP Reset-I
Means the connection was reset from the interface with the higher security level. Usually the inside interface. Normally this means an application layer issues. Some software on the PC or the application itself reset the connection for some reason. Check windows firewall and for other AV products running on the client. Also check Java security exceptions list. Are there any other firewalls on the inside of your connection, IPS etc ?

TCP Reset-O
The connection was reset from the interface with the lower security level usually the outside interface. The reset came from the other side. Usually a server issue.

If you get these messages in the log you can do a packet capture and collect logs while trying the connect. Once you have that information you can demonstrate the traffic was passed by the firewall but then either the other side sent the reset (TCP Reset-O) or the inside host sent the reset (TCP Reset-I) and move the investigation away from the ASA.

I have seen the case where I got a TCP Reset-O in the logs but the issue was actually a NoNat was needed. In that case the user was trying to connect from anyconnect -> ASA -> S2S VPN -> Remote site -> 10.60.46.x. So check your NAT's are all correct too.

Friday, 23 December 2016

kiwi syslog server notes

You can setup several displays. Display 00 is default and is usually everything

Configure circular logging
Its a good idea to setup display 01 as (drop-deny)
Create a new rule call it drop/deny
Add a filter choose simple filter put in "drop" "deny"
Add the action of display and choose display 01
In the setup section go to display 01 and update the name to display 01 (drop-deny)
You can add other actions like send email etc
You can create lots of displays for VPN troubleshooting etc
Also enable the highlighting options, defaults are decent, you can edit as needed.
You can also tick an option to auto scale width to fit messages


I like this file name
E:\syslog\%IPAdd4-%DateISO.txt

Worth installing tail also. (cygwin is good)

Monday, 19 December 2016

packet capture on checkpoint firewall

Use the topology table on the checkpoint to see what interface you need to monitor

netstat -nr | grep x.x.x.x can be useful too

tcpdump -i eth5 -s0 host 192.168.1.50 -w /var/tmp/packet-capture.pcap


Copy your .pcap file off with win scp and open in wireshark

or read on CLI
tcpdump -r /var/tmp/packet-capture.pcap

Friday, 2 December 2016

hairpin / u-turn on ASA

Anyconnect NAT
Say you want anyconnect users to connect but then get to the internet via your public IP. You'll need the same securitycommands too

Same as your anyconnect pool
object network OBJ-10.50.150.0
 subnet 10.50.150.0 255.255.255.0

object network OBJ-10.50.150.0
 nat (OUTSIDE,OUTSIDE) dynamic interface


Hair-pin NAT
This is a NAT where I wanted to access a DMZ server on its public IP from the inside LAN
Need to set some objects up first.

nat (INSIDE,DMZ) source static OBJ-10.59.0.0-19 OBJ-10.59.0.0-19 destination static OBJ-SERVER-PUB-IP OBJ-172.59.0.10 no-proxy-arp 


Re-write DNS
Simple solution than above
object network DMZ-WEBSERVER
 nat (DMZ,OUTSIDE) static 100.190.220.74 dns

Use the created xlate to rewrite DNS record



Auto nat rule on FTD

Devices > NAT
Edit your NAT policy
Add rule
Select "Auto NAT Rule"
Type "Dynamic"
Set your inside/outside zones
Original source X LAN
Translated source destination Interface IP

Wednesday, 30 November 2016

add a gui client IP on checkpoint

SSH into the CP management server
cpconfig
3)  GUI Clients
Add the IP address

In smart dashboard go into users and administrators section
Create the user and assign as password under authentication

see also
http://www.roesen.org/files/cp_cli_ref_card.pdf

Monday, 28 November 2016

replacing an ASA steps

Before switching to get an idea of numbers you should see after switching, get a screenshot of the following:
sh conn count
sh xlate count
sh crypto map sa
Identify important VPNs
Get VPN PSKs with more system:running-config
Check for any certificates installed on ASA (they cannot be copied, must be added again)
Do full backup in ASDM make sure you have your configs.


Switch over cables
First thing make sure you have internet access
Make sure interfaces have been "no shut"
Often you have to unplug and re-plug cables on ISP devices to resolve arp cache issues
Ping out all interfaces to ensure all VLANs etc are working
Once we have that look at VPNs make sure they are up
You might need to generate some traffic to bring it up.
Check anyconnect from outside is working
Check ASDM / anyconnect image
Re-install certificates


Storage device not found. Install drive and try again. Cisco Firepower

When trying to install the cisco firepower you get the error below

When you run this command:
sw-module module sfr recover boot
The ASA returns the error:
Storage device not found.  Install drive and try again.

Some users have reported reloading the ASA resolves this (if you have SSD installed)

Most likely you are missing your SSD drive, either its not installed, broken or ASA was replaced but no SSD was sent with the replacement or it was never swapped from the old unit to the replacement unit.

You can see if you have ssd installed with "sh inv" it should look like this

Name: "Chassis", DESCR: "ASA 5525-X with SW, 8 GE Data, 1 GE Mgmt, AC"
PID: ASA5525           , VID: V04     , SN: ABCXXXXXXX

Name: "Storage Device 1", DESCR: "Model Number: Micron_M550_MTFDDAK128MAY"
PID: N/A               , VID: N/A     , SN: EFGXXXXXXX

If you don't see a storage device its not there.

If you still have your old unit you can try swap the SSD
Otherwise contact Cisco (or your support) about getting replacement


Commands to collect from CLI for cisco TAC

Show inv

Show module

Show raid