Any ASA gurus here?

brad310

Senior member
Nov 14, 2007
319
0
0
At work we're getting an ASA soon, was going to try to pick up some skills since i may be left to manage it. Does anyone know a good book or video training...or other recommendations on how to set it up?

I have small lab set up already for CCNA so im not opposed to adding to it if that is the only way.
 

drebo

Diamond Member
Feb 24, 2006
7,034
1
81
I'd recommend against an ASA, honestly. There are a LOT of things it doesn't do that a lot of businesses don't realize and decide they need later.

I'd recommend a normal IOS router with the Advanced Security license or maybe a Juniper SRX. A little more expensive, but a LOT more featureful.
 

RadiclDreamer

Diamond Member
Aug 8, 2004
8,622
40
91
Depends on what you are doing, things like the initial config and VPN setups have wizards that walk you through the setup, what exactly is your goal and what model are you getting?
 

RadiclDreamer

Diamond Member
Aug 8, 2004
8,622
40
91
I'd recommend against an ASA, honestly. There are a LOT of things it doesn't do that a lot of businesses don't realize and decide they need later.

I'd recommend a normal IOS router with the Advanced Security license or maybe a Juniper SRX. A little more expensive, but a LOT more featureful.

I disagree, we use the 5520 in failover pair and it does everything we need and then some.
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
I disagree, we use the 5520 in failover pair and it does everything we need and then some.

Yea, we resell and support a lot of ASAs and the only things that tend to come up as "would be nice" are content filtering, and no the shitty CSC modules don't count since they don't work most of the time, and per-user bandwidth reports. But I believe newer firmware does NetFlow now so that might be taken care of even if you have to map IPs to users after the fact.
 

ViviTheMage

Lifer
Dec 12, 2002
36,189
87
91
madgenius.com
I'd recommend against an ASA, honestly. There are a LOT of things it doesn't do that a lot of businesses don't realize and decide they need later.

I'd recommend a normal IOS router with the Advanced Security license or maybe a Juniper SRX. A little more expensive, but a LOT more featureful.

Examples as to what a company would use that an ASA doesn't provide?
 

drebo

Diamond Member
Feb 24, 2006
7,034
1
81
Examples as to what a company would use that an ASA doesn't provide?

ICMP redirect, policy-based routing, and GRE tunnels, to name 3.

There are more, but those are the biggies that ASAs don't do and that SMBs are likely to need.

Someone who only needs them to firewall (routing handled by a layer 3 switch or a multi-tiered network) can get away without those features, for the most part, or someone who only needs a VPN gateway...these two conditions would be the ones under which a 5520 would be useful. But a SMB that may move to an MPLS setup or may require more advanced features will see their investment turn up as useless.

Either way, the Juniper SRX100 is cheaper and more feature-rich than an ASA5505, and would be my recommendation if the company does not want to spend money on an IOS router with Advanced Security featureset.
 

gordita

Golden Member
Mar 24, 2001
1,020
0
0
can I offer the 'PAN's?
The visibility offered by Palo Alto's and the ability to restrict/allow based on AD is a big step-up...(for us).
we went from 5510's and 5520's to PAN 3020's and 5020's and haven't looked back..
 

drebo

Diamond Member
Feb 24, 2006
7,034
1
81
Palo Altos are great, but this thread is pretty old.

Also, Palo Altos have a few limitations as well: no GRE tunnels, and their traffic shaping leaves a bit to be desired (max of 8 classes on egress on the PA-200 at least).
 

Lithium381

Lifer
May 12, 2001
12,452
2
0
Where the PA's shine is the deep packet inspection. . they block applications at layer 7, not layer 4 like a lot of firewalls...and their reports are nice 'n' pretty to hand to management
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |