Checkpoint · Firewalls · Wireless

Cisco WLC Mobility Groups

pre { font-family:arial; font-size:12px; border:1px dashed #CCCCCC; width:99%; height:auto; overflow:auto; background:#f0f0f0; padding:0px;color:#000000; text-align:left; line-height:20px; } code { color:#000000; word-wrap:normal; } Cisco WLC Mobility Groups – Data Path down/ Control Path down Cisco Mobility Group – Anchor : Data Path Down The path of the mobility group EtherIP tunnel between WLCs passes through a single CheckPoint… Continue reading Cisco WLC Mobility Groups

ASA

Cisco ASA 5505 RAM – compatible modules

pre { font-family:arial; font-size:12px; border:1px dashed #CCCCCC; width:99%; height:auto; overflow:auto; background:#f0f0f0; padding:0px;color:#000000; text-align:left; line-height:20px; } code { color:#000000; word-wrap:normal; } th.rotate { /* Something you can count on */ height: 100px; white-space: nowrap; } th.rotate > div { transform: /* Magic Numbers */ /*translate(25px, 51px)*/ /* 45 is really 360 – 45 */ rotate(270deg); width:… Continue reading Cisco ASA 5505 RAM – compatible modules

IPv6 · VPN

Cisco ASA IPv6 Site-to-Site IPSec IKEv2 VPN

pre { font-family:arial; font-size:12px; border:1px dashed #CCCCCC; width:99%; height:auto; overflow:auto; background:#f0f0f0; padding:0px;color:#000000; text-align:left; line-height:20px; } code { color:#000000; word-wrap:normal; } Cisco ASA IPv6 Site-to-Site IPSec IKEv2 VPN I took delivery of a 5545-X from Bedfont Lakes to evaluate in my IPv6 lab; this post covers the steps to connect two ASA’s via IPv6 IPSec VPN.… Continue reading Cisco ASA IPv6 Site-to-Site IPSec IKEv2 VPN

AAA · ISE

Cisco ISE AAA configuration for VTY logins

pre { font-family:arial; font-size:12px; border:1px dashed #CCCCCC; width:99%; height:auto; overflow:auto; background:#f0f0f0; padding:0px;color:#000000; text-align:left; line-height:20px; } code { color:#000000; word-wrap:normal; } Cisco ISE AAA configuration for VTY logins Switch configuration ( 3750X – IOS 15.0(1)SE3 ) ! username admin secret pa55w0rd ! aaa new-model ! aaa group server radius radius-ise-group server name radius-ise ! aaa authentication… Continue reading Cisco ISE AAA configuration for VTY logins

AnyConnect · ASA

Cisco ASA AnyConnect configuration

The first step is to configure the ASA to Web-deploy the AnyConnect Client. Prior to version 8.0(2) it was necessary to configure WebVPN to listen on a different port to the ASDM client. This is no longer the case. ciscoasa(config)# webvpn ciscoasa(config-webvpn)# port 443 ciscoasa(config-webvpn)# enable outside ciscoasa(config-webvpn)# anyconnect image disk0:/anyconnect-win-3.1.04066-k9.pkg ciscoasa(config-webvpn)# anyconnect enable ciscoasa(config-webvpn)#… Continue reading Cisco ASA AnyConnect configuration

IPv6 · Monitoring · munin

Munin IPv6 neighbor state graphs

A recent issue with a Linux IPv6 firewall which saw on-link hosts appear to be flapping according to monitoring tools, highlighting a IPv6 ND table overflow problem. The short version of the solution required: net.ipv6.neigh.default.gc_thresh1 = 256 net.ipv6.neigh.default.gc_thresh2 = 1024 net.ipv6.neigh.default.gc_thresh3 = 2048 To keep an eye on the neighbor table I created a series… Continue reading Munin IPv6 neighbor state graphs