Cisco 5510 - ASA SSL / IPsec VPN Edition Quick Start Manual

Asa 5500 series adaptive security appliance
Hide thumbs Also See for 5510 - ASA SSL / IPsec VPN Edition:

Advertisement

Cisco ASA 5500 Series
Quick Start Guide
Americas Headquarters
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-1706
USA
http://www.cisco.com
Tel:
408 526-4000
800 553-NETS (6387)
Fax:
408 527-0883
Customer Order Number: DOC-78-19753-01
Text Part Number: 78-19753-01

Advertisement

Table of Contents
loading

Summary of Contents for Cisco 5510 - ASA SSL / IPsec VPN Edition

  • Page 1 Cisco ASA 5500 Series Quick Start Guide Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 Customer Order Number: DOC-78-19753-01 Text Part Number: 78-19753-01...
  • Page 2 Cisco and the Cisco Logo are trademarks of Cisco Systems, Inc. and/or its affiliates in the U.S. and other countries. A listing of Cisco's trademarks can be found at www.cisco.com/go/trademarks. Third party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company.
  • Page 3: Table Of Contents

    C H A P T E R Regulatory Compliance and Safety Information Verifying the Package Contents Powering On the ASA Connecting Interface Cables and Verifying Connectivity Maximizing Throughput What to Do Next Cisco ASA 5500 Series Quick Start Guide 78-19753-01...
  • Page 4 (Optional) Making Internal Services Accessible from the Internet (ASDM 6.2 and Later) (Optional) Running the VPN Wizards for Remote Access Connectivity (ASDM 6.0 or Later) (Optional) Running the VPN Wizards to Configure VPN Tunnels (Optional) Other Wizards in ASDM Related Documentation Cisco ASA 5500 Series Quick Start Guide 78-19753-01...
  • Page 5: Chapter 1 Before You Begin

    C H A P T E R Before You Begin Use the following table to find the installation and configuration steps that are required for your implementation of the Cisco ASA 5500 series adaptive security appliance: ASA 5510, ASA 5520, and ASA 5540, page 1-1 •...
  • Page 6: Asa 5550

    Perform initial setup of the ASA Chapter 6, “Configuring the ASA” Configure optional and advanced ASDM Help or ASDM user guide for features your release ASA CLI configuration guide for your release Cisco ASA 5500 Series Quick Start Guide 78-19753-01...
  • Page 7: Asa 5580

    ASA CLI configuration guide for your release Operate the system on a daily basis ASDM Help or ASDM user guide for your release ASA CLI configuration guide for your release System Log Messages guide for your release Cisco ASA 5500 Series Quick Start Guide 78-19753-01...
  • Page 8: Asa 5585-X

    ASA CLI configuration guide for your release System Log Messages guide for your release Install the SSP and IPS SSP Cisco ASA 5585-X Adaptive Security Appliance Hardware Installation Guide Configure IPS User Guide for Cisco IPS Manager Cisco ASA 5500 Series Quick Start Guide 78-19753-01...
  • Page 9 Subscribe to the What’s New in Cisco Product Documentation as a Really Simple Syndication (RSS) feed and set content to be delivered directly to your desktop using a reader application. The RSS feeds are a free service and Cisco currently supports RSS Version 2.0.
  • Page 10 Chapter 1 Before You Begin ASA 5585-X Cisco ASA 5500 Series Quick Start Guide 78-19753-01...
  • Page 11: Chapter 2 Installing The Asa 5510, Asa 5520, Or Asa 5540

    ASA 5540 Regulatory Compliance and Safety Information Read the safety warnings in the Regulatory Compliance and Safety Information for the Cisco ASA 5500 Series and follow proper safety procedures when performing these steps. Verifying the Package Contents Verify the contents of the packing box to ensure that you have received all items necessary to install your ASA.
  • Page 12 ASA 5510, 20, or 40 Chassis Rack-mounting Brackets 2 Yellow Ethernet Cables 2 Long Cap Screws Blue Console Cable PC Terminal Adapter 4 Flathead Screws Cable Holder 4 Cap Screws 4 Rubber Feet 10 Documentation Cisco ASA 5580 Series Quick Start Guide 78-19753-01...
  • Page 13: Powering On The Asa

    If you want to use the CLI, connect your PC to the console port and see Note the CLI configuration guide more information. Connect your networks to the appropriate ports. Step 2 Cisco ASA 5580 Series Quick Start Guide 78-19753-01...
  • Page 14: What To Do Next

    LINK SPD LINK SPD LINK SPD LINK SPD Unsecured Network Secured Network Check the LINK/ACT indicators to verify interface connectivity. Step 3 What to Do Next Continue with Chapter 6, “Configuring the ASA.” Cisco ASA 5580 Series Quick Start Guide 78-19753-01...
  • Page 15: Chapter 3 Installing The Asa 5550

    Installing the ASA 5550 Regulatory Compliance and Safety Information Read the safety warnings in the Regulatory Compliance and Safety Information for the Cisco ASA 5500 Series and follow proper safety procedures when performing these steps. Verifying the Package Contents Verify the contents of the packing box to ensure that you have received all items necessary to install the ASA.
  • Page 16 SP D LIN K SP D LIN K SP D ASA 5550 Chassis Rack-mounting brackets 2 Yellow Ethernet Cables 2 Long Cap Screws Blue Console Cable PC Terminal Adapter 4 Flathead Screws Cisco ASA 5500 Series Quick Start Guide 78-19753-01...
  • Page 17: Powering On The Asa

    CLI configuration guide more information. Connect your networks to the appropriate ports. If you are using the fiber ports, Step 2 you need an SFP module. See the Cisco ASA 5500 Series Hardware Installation Guide for information. Cisco ASA 5500 Series Quick Start Guide...
  • Page 18: Maximizing Throughput

    LINK SPD Secured Unsecured Network Network Check the LINK/ACT indicators to verify interface connectivity. Step 3 Maximizing Throughput The ASA has two internal buses providing copper Gigabit Ethernet and fiber Gigabit Ethernet connectivity. Cisco ASA 5500 Series Quick Start Guide 78-19753-01...
  • Page 19 Bus 1. Traffic from hosts on the secure network flows through interface 0/0 on Bus 0 to hosts on the unsecure network. Traffic from hosts on the unsecure network flows through interface 1/0 on Bus 1 to hosts on the secure network. Cisco ASA 5500 Series Quick Start Guide 78-19753-01...
  • Page 20: What To Do Next

    FLASH LINK SPD LINK SPD LINK SPD LINK SPD Incoming and Incoming and outgoing traffic outgoing traffic Unsecured Network Secured Network What to Do Next Continue with Chapter 6, “Configuring the ASA.” Cisco ASA 5500 Series Quick Start Guide 78-19753-01...
  • Page 21: Chapter 4 Installing The Asa 5580

    Installing the ASA 5580 Regulatory Compliance and Safety Information Read the safety warnings in the Regulatory Compliance and Safety Information for the Cisco ASA 5580 Adaptive Security Appliance and follow proper safety procedures when performing these steps. Verifying the Package Contents Verify the contents of the packing box to ensure that you have received all items necessary to install your ASA.
  • Page 22 Two slide assemblies • Two chassis rails • Four Velcro straps • Six zip ties • One cable management arm • A package of miscellaneous parts (screws, and so forth) • Cisco ASA 5580 Series Quick Start Guide 78-19753-01...
  • Page 23: Powering On The Asa

    Connect the power cables to the electrical outlets. Step 2 Power on the ASA. Step 3 Check the Power LED on the front of the ASA; if it is solid green, the device is Step 4 powered on. Cisco ASA 5580 Series Quick Start Guide 78-19753-01...
  • Page 24: Connecting Interface Cables And Verifying Interface Connectivity

    The ASA 5580 has nine expansion slots. Slots 3 through 8 support PCI Note Express network interface adapters. Slots 1, 2, and 9 are reserved. Your exact configuration depends on the configuration you purchased. Cisco ASA 5580 Series Quick Start Guide 78-19753-01...
  • Page 25: Maximizing Throughput

    Slots 3 through 8—For supported PCI Express network interface adapters • Slots 1, 2, and 9—Reserved • The ASA 5580 includes two types of PCI buses: Normal Capacity (PCI Express x4 non-hot-plug)—Slots 3, 4, and 6 • Cisco ASA 5580 Series Quick Start Guide 78-19753-01...
  • Page 26: What To Do Next

    • I/O bridge 2: Slot 7 and slot 8 • See the Cisco ASA 5580 Adaptive Security Appliance Hardware Installation Guide for more information about the network interfaces on the ASA 5580. Optimizing Performance You should use the high-capacity slots for 10-Gigabit Ethernet adapters; other •...
  • Page 27: Chapter 5 Installing The Asa 5585-X

    Installing the ASA 5585-X Regulatory Compliance and Safety Information Read the safety warnings in the Regulatory Compliance and Safety Information for the Cisco ASA 5585-X Series and follow proper safety procedures when performing these steps. Verifying the Package Contents Verify the contents of the packing box to ensure that you have received all items necessary to install the ASA.
  • Page 28: Powering On The Asa

    Rack-Mount Brackets Cable Management Brackets 1. The Cisco ASA 5585-X ASAships with one power supply module installed and one power cable. The ASA 5585-X SSP-60, ships with two power supply modules installed and two power cables. Powering On the ASA Attach the power cable to the back of the ASA.
  • Page 29: Connecting Interface Cables And Verifying Interface Connectivity

    Ethernet cable, or connect the PC and the ASA to the same management network. The ASA 5585-X has 2 management interfaces (Management 0/0 and Note Management 0/1); however, only Management 0/0 is configured for use. Cisco ASA 5580 Series Quick Start Guide 78-19753-01...
  • Page 30 Gigabit Ethernet ports (as shown in the following figure). The ASA 5585-X with SSP-40 and SSP-60 include 4 10-Gigabit Ethernet and 6 Gigabit Ethernet ports. See the Cisco ASA 5585-X Adaptive Security Appliance Hardware Installation Guide for more information. RESET...
  • Page 31: What To Do Next

    IPS SSP, you can use the IPS SSP non-management ports as additional network ports. Check the LINK/ACT indicators to verify interface connectivity. Step 3 What to Do Next Continue with Chapter 6, “Configuring the ASA.” Cisco ASA 5580 Series Quick Start Guide 78-19753-01...
  • Page 32 Chapter 5 Installing the ASA 5585-X What to Do Next Cisco ASA 5580 Series Quick Start Guide 78-19753-01...
  • Page 33: Chapter 6 Configuring The Asa

    The Cisco ASDM web page appears. Click Run Startup Wizard. Step 3 Click Yes in each dialog box to accept the certificates. The Cisco ASDM-IDM Step 4 Launcher appears. Leave the username and password fields empty and click OK.
  • Page 34: Running The Startup Wizard In Asdm

    Follow the instructions in the Startup Wizard to configure your ASA. Step 3 While running the wizard, you can accept the default settings or change them as required. (For information about any wizard field, click Help in the window.) Cisco ASA 5580 Series Quick Start Guide 78-19753-01...
  • Page 35: (Optional) Making Internal Services Accessible From The Internet (Asdm 6.2 And Later)

    Click Add, then enter the public server settings in the Public Server dialog box. Step 2 (For information about any field, click Help.) Click OK. The server appears in the list. Step 3 Cisco ASA 5580 Series Quick Start Guide 78-19753-01...
  • Page 36: (Optional) Running The Vpn Wizards For Remote Access Connectivity

    Users have no direct access to resources on the inside network. The Cisco AnyConnect VPN client provides secure SSL connections to the ASA for remote users with full VPN tunneling to corporate resources. The ASA downloads the AnyConnect Client to remote users.
  • Page 37 (In ASDM 6.3 or earlier, choose Wizards > SSL VPN Wizard > SSL VPN connection type—Clientless, Cisco SSL, or both.) Follow the wizard instructions. (For information about any wizard field, click Step 2 Help in the window.) Cisco ASA 5580 Series Quick Start Guide 78-19753-01...
  • Page 38: (Optional) Running The Vpn Wizards To Configure Vpn Tunnels

    In the main ASDM window, choose Wizards > VPN Wizards > Site-to-Site Step 1 VPN Wizard or IPSec (IKEv1) Remote Access VPN Wizard. (In ASDM 6.3 or earlier, choose Wizards > IPSec VPN Wizard > Tunnel type—Site-to-Site or Remote Access.) Cisco ASA 5580 Series Quick Start Guide 78-19753-01...
  • Page 39: (Optional) Other Wizards In Asdm

    After capturing packets, you can save the captures to your PC for examination and replay in the packet analyzer. Related Documentation To access all documents related to this product, go to: http://www.cisco.com/en/US/docs/security/asa/roadmap/asaroadmap.html Cisco ASA 5580 Series Quick Start Guide 78-19753-01...
  • Page 40 Chapter 6 Configuring the ASA Related Documentation Cisco ASA 5580 Series Quick Start Guide 78-19753-01...

This manual is also suitable for:

Asa 5510Asa 5520Asa 5540Asa 5550Asa 5580Asa 5585-x

Table of Contents