EIGRP on the Cisco ASA: Configuration and Neighbor Gotchas
Full EIGRP build on the Cisco ASA captured live from an ASAv 9.24, from working adjacency to the number-one neighbor failure that produces no error, no log, just an empty neighbor table.
Cisco Adaptive Security Appliance, the stateful firewall platform that has anchored enterprise perimeters for two decades and is now being succeeded by Secure Firewall (FTD). Articles tagged ASA cover security levels, NAT 8.3+ and twice NAT, ACLs, AnyConnect SSL and IKEv2 VPN, site-to-site IPsec, failover, packet-tracer, hardening, and ASAv 9.x lab walkthroughs.
Full EIGRP build on the Cisco ASA captured live from an ASAv 9.24, from working adjacency to the number-one neighbor failure that produces no error, no log, just an empty neighbor table.
The full OSPF build on a Cisco ASA: configuration, a verified adjacency with MD5 authentication, the DR/BDR election the firewall loses, the link-state database, and redistribution, all captured from a live ASAv 9.24.
The ASA supports OSPF, EIGRP, RIP, and BGP, but with different defaults and its own opinions about which routes it installs. Get oriented with live captures from an ASAv 9.24 in CML before you configure any of them.
Nine printable pages covering Cisco ASA NAT section order, post-8.3 ACL addressing, the packet pipeline, inspection engines, and the troubleshooting commands that matter, condensed so you can stop scrolling docs at 2am.
When to migrate from ASA to Secure Firewall Threat Defense, what tooling does the migration well, what it does not move automatically, and what to verify on the FTD side before declaring the migration done.
Multiple context mode turns one Cisco ASA into several virtual firewalls, each with its own config, interfaces, ACLs, NAT, and admins. Covers the system, admin, and user-context split, what the feature costs, and the configuration to enable it.
The ASA Modular Policy Framework binds inspection engines to traffic with class-maps, policy-maps, and service-policies. Walk the default global policy every ASA ships with, then add custom HTTP, FTP, or ESMTP inspection without breaking it.
The production-ready ASA upgrade procedure: back up off-box, stage the image to flash, set the boot variable, reload, verify, and roll back if needed. Works for a single ASA or a failover pair.
Six lines of config give the ASA sane production syslog. This article walks the destinations, the eight severity levels, message lists for filtering, and reading the %ASA-X-XXXXXX format using real lab logs from IKEv2 failures and ACL denies.
A production-ready hardening pass for the Cisco ASA management plane: SSH and HTTPS the right way, AAA with local fallback, per-interface management ACLs, password policy, and disabling what you do not need.
Static routes, default routes, administrative distance, and SLA-tracked failover for multi-WAN on the Cisco ASA, plus how to read show route. Most production firewalls run all-static routing, and this is the syntax that runs them.
The classic three-zone ASA build end to end on an ASAv 9.23: inside, outside, and DMZ security levels, outbound NAT, inbound web publishing, ACLs in both directions, and the show output that proves traffic flows.