IPsec Through an ASA: NAT-T, ESP Pass-Through, and Why the Tunnel Won't Come Up
Endpoint versus pass-through on the Cisco ASA: inspect ipsec-pass-thru, NAT-T on UDP 4500, and the classic Phase 1 up, Phase 2 down failure.
Endpoint versus pass-through on the Cisco ASA: inspect ipsec-pass-thru, NAT-T on UDP 4500, and the classic Phase 1 up, Phase 2 down failure.
Map IKEv1 to IKEv2 on the Cisco ASA command by command, then cut a live site-to-site tunnel over without an outage.
A real LAN-to-LAN IKEv2 tunnel from a Cisco ASA to an IOS XE peer, verified with show vpn-sessiondb from a live CML capture.
EtherType ACLs let a transparent-mode Cisco ASA filter non-IP frames a routed firewall never sees. Learn what bridges through a Layer 2 firewall by default and how to control it.
Typing firewall transparent wipes the ASA's entire running configuration instantly. This walkthrough covers switching modes safely from the console with a saved config, then building a working transparent-mode firewall on the ASAv.
Connections that die crossing the ASA with no ACL deny are usually TCP normalization. You see the real tcp-map and accelerated-security-path drop counters from an ASAv 9.24 that turn this silent killer into something visible.
Build a custom Layer 7 HTTP inspection policy on the ASA that blocks a specific URL by regex, then prove it with a real before-and-after test: one URL loads instantly, the other hangs until timeout. Captured on an ASAv 9.24 in CML.
L3 and L4 filtering is half a firewall. This post shows the ASA's application inspection engines in action on a real ASAv 9.24 in CML, including the default inspection policy and live per-interface counters.
MPF is the engine under nearly every advanced ASA feature. Build class-maps, policy-maps, and service-policies from scratch on a real ASAv 9.24 in CML, with live counters climbing as a Linux client hits a published web server.
Failover, clustering, contexts, redundant interfaces: the ASA HA menu is long. We tested every option live on asav 9.24, so each supported or rejected cell in this comparison is a tested fact, not a datasheet claim.
Cisco ASA clustering pools up to sixteen units into one logical firewall that shares load and state. This article explains spanned vs individual interface mode, plus a real capture of ASAv 9.24 rejecting the cluster commands and what that tells you.
Multiple ASA contexts draw from the same connection, translation, and inspection pools. Resource classes cap and guarantee slices of firewall capacity so one busy context cannot starve the rest.