Как освободить ram на asa5505
Как освободить ram на asa5505
1. Подключение через COM-порт
2. Настройка интерфейса управления и доступа по ssh
3. Настройка доступа через ASDM
4. Обновление системы и ASDM
- внешняя сеть с белым ip (outside);
- выделенная сеть с серверами (dmz): 192.168.20.0/29;
- локальная сеть с пользователями (lan): 192.168.10.0/24;
6. Настройка NAT во внешнюю сеть и ping
7. Настройка NAT снаружи во внутреннюю сеть до сервера
- организации вашей сети (сейчас и в перспективе) и месте Cisco ASA в ней;
- детальном изучении документации, статей, обзоров: какие из поддерживаемых технологий можно задействовать;
- специфика вашей организации: какие уровни безопасности и доступности сервисов необходимы;
- и т.п.
29 thoughts on “ Cisco ASA: первичная настройка ”
Версия Асы
Cisco Adaptive Security Appliance Software Version 8.4(4)1
Device Manager Version 6.4(9)
Как освободить ram на asa5505
a1msk# show memory detail
Free memory: 23038344 bytes ( 4%)
Used memory:
Allocated memory in use: 308311672 bytes (57%)
Reserved memory: 205520896 bytes (38%)
—————————— ——————
Total memory: 536870912 bytes (100%)
Least free memory: 6002896 bytes ( 1%)
Most used memory: 530868016 bytes (99%)
MEMPOOL_DMA POOL STATS:
Non-mmapped bytes allocated = 41041920
Number of free chunks = 66
Number of mmapped regions = 0
Mmapped bytes allocated = 0
Max memory footprint = 41041920
Keepcost = 3525080
Max contiguous free mem = 3525080
Allocated memory in use = 37505504
Free memory = 3536416
| Страница 1 из 1 | [ 1 сообщение ] |
Cisco ASA 5505 Hardware Installation Guide
The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
Book Title
Cisco ASA 5505 Hardware Installation Guide
Maintenance and Upgrade Procedures
View with Adobe Reader on a variety of devices
View in various apps on iPhone, iPad, Android, Sony Reader, or Windows Phone
View on Kindle device or Kindle app on multiple devices
Results
Chapter: Maintenance and Upgrade Procedures
Maintenance and Upgrade Procedures
This chapter describes how to install the chassis on the wall or rack, remove and replace the chassis cover, the power supply, and the CompactFlash. This chapter includes the following sections:
- Removing and Replacing the Chassis Cover
- Replacing the Lithium Battery
- Setting the Clock and Time Zone After Replacing the Battery
- Installing and Replacing the SSC
- Upgrading Memory
Removing and Replacing the Chassis Cover
This section describes how to remove and replace the chassis cover. This section includes the following topics:
- Working in an ESD Environment
- Removing the Chassis Cover
- Replacing the Chassis Cover
Working in an ESD Environment
Electrostatic discharge (ESD) can damage equipment and impair electrical circuitry. ESD damage occurs when electronic components are improperly handled and can result in complete or intermittent failures. Always follow ESD-prevention procedures when you remove and replace components. Ensure that the chassis is electrically connected to earth ground. Wear an ESD-preventive wrist strap, ensuring that it makes good skin contact. Connect the grounding clip to an unpainted surface of the chassis frame to safely ground unwanted ESD voltages. To guard against ESD damage and shocks, the wrist strap and cord must operate properly. If no wrist strap is available, ground yourself by touching the metal part of the chassis.s
Removing the Chassis Cover
To r emove the chassis cover, perform the following steps:
Note Removing the chassis cover does not affect Cisco warranty. Upgrading the adaptive security appliance does not require any special tools and does not create any radio frequency leaks.
Step 1 Read the Regulatory Compliance and Safety Information for the Cisco ASA 5500 Series document.
Step 2 Power off the adaptive security appliance.
Warning Before working on a system that has an On/Off switch, turn OFF the power and unplug the power cord. Statement 1
Step 3 Turn the chassis upside down so that the top of the chassis is resting on a flat surface, and the front of the chassis is facing toward you.
Step 4 Remove the three screws located on the bottom of the chassis as shown in Figure 4-1.
Figure 4-1 Removing the Screws
Step 5 Return the chassis to the upright position. Note that the chassis is comprised of two sections: top and bottom.
Step 6 Hold both sides of the top section, at the base of the appliance in the rear and pull outward while gently lifting upward.
Replacing the Chassis Cover
To replace the chassis cover on the adaptive security appliance, perform the following steps:
Step 1 Place the chassis on a secure surface with the front panel facing you.
Step 2 Hold the chassis cover so that the rear of the chassis cover are aligned with the chassis bottom.
Step 3 Lower the front of the cover onto the chassis, making sure that the side tabs of the cover fit under the side panels of the chassis.
Step 4 Slide the chassis cover toward the front, making sure that the cover tabs fit under the back panel, and the back panel tabs fit under the chassis cover.
Step 5 Secure the chassis cover with the screw you set aside earlier.
Step 6 Reconnect the network interface cables.
Step 7 Reconnect the power cord to the power outlet to power on the adaptive security appliance.
Replacing the Lithium Battery
This section describes how to remove and replace the lithium battery in the adaptive security appliance. The lithium battery is a field-replaceable unit (FRU).
Warning Danger of explosion exists if the lithium battery is incorrectly replaced. Replace only with the same or equivalent type recommended by the manufacturer. Dispose of used batteries according to the manufacturer’s instructions. Statement 33
To remove and replace the battery in the adaptive security appliance, perform the following steps:
Step 1 Remove the chassis cover as described in the “Removing the Chassis Cover” section.
Step 2 Slide the metal clip back and pull the battery out.
Figure 4-2 Cisco ASA 5505 Lithium Battery Location

Step 3 Place the used battery aside.
Step 4 Replace the battery with a compatible Lithium CR-2032 battery (which is available at your local electronics or drug store), by sliding the metal clip back and sliding the battery into place.
Step 5 Replace the chassis cover as described in the “Replacing the Chassis Cover” section.
Setting the Clock and Time Zone After Replacing the Battery
After replacing the battery on the ASA 5505, you might have to set the clock twice so that it remains set to the correct time. You only need to configure the time zone setting once for the ASA 5505 to save the correct time zone.
To successfully set the clock and time zone, perform the following steps:
Step 1 Power up the ASA 5505 and allow it to complete the boot process.
Step 2 Enter privileged EXEC mode:
Step 3 Verify that the clock is set to the default:
Step 4 Enter global configuration mode:
Step 5 Set the time zone for your location:
Step 6 Set the date and time:
Step 7 Save the new time and time zone to memory:
Step 8 Reboot the adaptive security appliance:
Step 9 After the adaptive security appliance boots up, return to privileged EXEC mode:
Step 10 Verify that the time is correct:
Step 11 If the adaptive security appliance does not display the correct time, enter the correct time again:
Настройка Cisco ASA 5505
- межсетевого экрана;
- интернет-провайдера (WAN).
-
Нужно создать три подсети VLAN: административная ADMLAN (192.150.1.1/24), пользовательская LAN (192.168.1.1/24), гостевая GUEST (192.130.1.1/24).
-
Выполнить привязку подсети VLAN с физическими интерфейсами Ethernet (выполнить настройку PPPoE): Ethernet0/0 – WAN, Ethernet0/1 – ADMLAN, Ethernet0/3 – GUEST, Ethernet0/7 – Trunk (LAN,ADMLAN, GUEST), на остальных Ethernet0/2,0/4,0/5,0/6 – LAN.
-
Провести настройку DHCP, чтобы раздавать адреса подсетей (LAN, ADMLAN, GUEST).
-
Настроить доступ к сети Интернет из подсетей (LAN, ADMLAN, GUEST).
Подключение к Cisco ASA 5505
ciscoasa# configure terminal
ciscoasa(config)# clear configure all
ciscoasa(config)# config factory-default
ciscoasa(config)# interface vlan 1
ciscoasa(config-if)# nameif LAN
ciscoasa(config-if)# description LAN
ciscoasa(config-if)# ip address 192.168.1.1 255.255.255.0
ciscoasa(config-if)# security-level 70
ciscoasa(config-if)# no shutdown
ciscoasa(config)# interface vlan 10
ciscoasa(config-if)# nameif WAN
ciscoasa(config-if)# description Internet
ciscoasa(config-if)# security-level 0
ciscoasa(config-if)# no shutdown
ciscoasa(config)# interface vlan 20
ciscoasa(config-if)# nameif ADMLAN
ciscoasa(config-if)# description Admins LAN
ciscoasa(config-if)# ip address 192.150.1.1 255.255.255.0
ciscoasa(config-if)# security-level 100
ciscoasa(config-if)# no shutdown
ciscoasa(config)# interface vlan 30
ciscoasa(config-if)# nameif GUEST
ciscoasa(config-if)# description Guest LAN
ciscoasa(config-if)# ip address 192.130.1.1 255.255.255.0
ciscoasa(config-if)# security-level 50
ciscoasa(config-if)# no shutdown
ciscoasa(config)# show switch vlan
VLAN Name Status Ports
1 LAN down Et0/0, Et0/1, Et0/2, Et0/3
Et0/4, Et0/5, Et0/6, Et0/7
ciscoasa(config)# show interface vlan 1
Interface Vlan1 «LAN», is down, line protocol is down
Hardware is EtherSVI, BW 100 Mbps, DLY 100 usec
MAC address 74a0.2f2a.e28d, MTU 1500
IP address 192.168.1.1, subnet mask 255.255.255.0
Traffic Statistics for «LAN»:
0 packets input, 0 bytes
0 packets output, 0 bytes
0 packets dropped
1 minute input rate 0 pkts/sec, 0 bytes/sec
1 minute output rate 0 pkts/sec, 0 bytes/sec
1 minute drop rate, 0 pkts/sec
5 minute input rate 0 pkts/sec, 0 bytes/sec
5 minute output rate 0 pkts/sec, 0 bytes/sec
5 minute drop rate, 0 pkts/sec
ciscoasa(config)# interface Ethernet0/0
ciscoasa(config-if)# description WAN
ciscoasa(config-if)# switchport access vlan 10
ciscoasa(config-if)# no shutdown
ciscoasa(config)# interface Ethernet0/1
ciscoasa(config-if)# description Admins LAN
ciscoasa(config-if)# switchport access vlan 20
ciscoasa(config-if)# no shutdown
ciscoasa(config)# interface Ethernet0/3
ciscoasa(config-if)# description Guest LAN
ciscoasa(config-if)# switchport access vlan 30
ciscoasa(config-if)# no shutdown
ciscoasa(config)# interface Ethernet0/7
ciscoasa(config-if)# description Trunk port
ciscoasa(config-if)# switchport mode trunk
ciscoasa(config-if)# switchport trunk allow vlan 1,20,30
ciscoasa(config-if)# no shutdown
ciscoasa(config)# show interface ip brief
Interface IP-Address OK? Method Status Protocol
Internal-Data0/0 unassigned YES unset up up
Internal-Data0/1 unassigned YES unset up up
Virtual0 127.0.0.1 YES unset up up
Vlan1 192.168.1.1 YES manual down down
Vlan10 10.241.109.251 YES manual up up
Vlan20 192.150.1.1 YES manual down down
Vlan30 192.130.1.1 YES manual down down
Ethernet0/0 unassigned YES unset up up
Ethernet0/1 unassigned YES unset down down
Ethernet0/2 unassigned YES unset down down
Ethernet0/3 unassigned YES unset administratively down down
Ethernet0/4 unassigned YES unset administratively down down
Ethernet0/5 unassigned YES unset administratively down down
Ethernet0/6 unassigned YES unset administratively down down
Ethernet0/7 unassigned YES unset down down
ciscoasa(config)# ping 87.250.250.242
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 87.250.250.242, timeout is 2 seconds:
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/14/30 ms
ciscoasa(config)# show route
Codes: C — connected, S — static, I — IGRP, R — RIP, M — mobile, B — BGP
D — EIGRP, EX — EIGRP external, O — OSPF, IA — OSPF inter area
N1 — OSPF NSSA external type 1, N2 — OSPF NSSA external type 2
E1 — OSPF external type 1, E2 — OSPF external type 2, E — EGP
i — IS-IS, L1 — IS-IS level-1, L2 — IS-IS level-2, ia — IS-IS inter area
* — candidate default, U — per-user static route, o — ODR
Как освободить ram на asa5505

Ваш Mac работает мучительно медленно? Приложение только что зависло? Вы видели сообщение «Ваша система исчерпала память приложения» или страшный вращающийся пляжный мяч? Все это может быть признаком того, что ваша память или ОЗУ используется максимально. Читайте дальше, чтобы узнать, как очистить RAM на вашем Mac и различные полезные советы, которые помогут вам очистить или оптимизировать память Mac, в том числе, что делать, если ваша Mac Mac всегда заполнена.
My Network Security Journal
Sharing my lab notes and personal experience in Network Security.
Saturday, August 29, 2015
Cisco ASA 5505 Boot (RAM) Problem
My ASA 5505 lab firewall suddenly died on me when I was preparing it for my CCNA Security lab. I saw the Status LED light became amber, which means Power-On Self Test (POST) had failed. I tried to reseat the RAM a couple of times and the ASA booted up again.

The Active LED light became solid green after POST and ASA image boots up.

Below is the internal circuitry of an ASA 5505 chassis and the RAM slot is located near the front faceplate and highlighted in yellow.

This is not the first time I reseated a RAM module. I did this for my Cisco 2511 router’s RAM and it booted up afterwards. This seems to be common especially on old or refurb device and when you often move them in different places and the internal parts get shaken. Below is the complete bootup on my ASA 5505 firewall.
CISCO SYSTEMS
Embedded BIOS Version 1.0(12)13 08/28/08 15:50:37.45
Low Memory: 632 KB
High Memory: 507 MB
PCI Device Table.
Bus Dev Func VendID DevID Class Irq
00 01 00 1022 2080 Host Bridge
00 01 02 1022 2082 Chipset En/Decrypt 11
00 0C 00 1148 4320 Ethernet 11
00 0D 00 177D 0003 Network En/Decrypt 10
00 0F 00 1022 2090 ISA Bridge
00 0F 02 1022 2092 IDE Controller
00 0F 03 1022 2093 Audio 10
00 0F 04 1022 2094 Serial Bus 9
00 0F 05 1022 2095 Serial Bus 9
Evaluating BIOS Options .
Launch BIOS Extension to setup ROMMON
Cisco Systems ROMMON Version (1.0(12)13) #0: Thu Aug 28 15:55:27 PDT 2008
Use BREAK or ESC to interrupt boot.
Use SPACE to begin boot immediately.
Launching BootLoader.
Default configuration file contains 1 entry.
Searching / for images to boot.
Loading /asa901-k8.bin. Booting.
Platform ASA5505
Loading.
IO memory blocks requested from bigphys 32bit: 9928
dosfsck 2.11, 12 Mar 2005, FAT32, LFN
Starting check/repair pass.
Starting verification pass.
/dev/hda1: 460 files, 28778/31033 clusters
dosfsck(/dev/hda1) returned 0
Processor memory 343932928, Reserved memory: 62914560
Total SSMs found: 0
Total NICs found: 10
88E6095 rev 2 Gigabit Ethernet @ index 09 MAC: 0000.0003.0002
88E6095 rev 2 Ethernet @ index 08 MAC: c84c.7596.e7c5
88E6095 rev 2 Ethernet @ index 07 MAC: c84c.7596.e7c4
88E6095 rev 2 Ethernet @ index 06 MAC: c84c.7596.e7c3
88E6095 rev 2 Ethernet @ index 05 MAC: c84c.7596.e7c2
88E6095 rev 2 Ethernet @ index 04 MAC: c84c.7596.e7c1
88E6095 rev 2 Ethernet @ index 03 MAC: c84c.7596.e7c0
88E6095 rev 2 Ethernet @ index 02 MAC: c84c.7596.e7bf
88E6095 rev 2 Ethernet @ index 01 MAC: c84c.7596.e7be
y88acs06 rev16 Gigabit Ethernet @ index 00 MAC: c84c.7596.e7c6
Verify the activation-key, it might take a while.
Running Permanent Activation Key: 0x3021cd54 0x20efac90 0xc852410c 0xb95cd094 0xc108009a
Running Timebased Activation Key: 0x11580c70 0xbc7e2ac4 0x093d128a 0x4834133b 0x8abfcf80
Licensed features for this platform:
Maximum Physical Interfaces : 8 perpetual
VLANs : 3 DMZ Restricted
Dual ISPs : Disabled perpetual
VLAN Trunk Ports : 0 perpetual
Inside Hosts : 10 perpetual
Failover : Disabled perpetual
Encryption-DES : Enabled perpetual
Encryption-3DES-AES : Enabled perpetual
AnyConnect Premium Peers : 2 perpetual
AnyConnect Essentials : Disabled perpetual
Other VPN Peers : 10 perpetual
Total VPN Peers : 12 perpetual
Shared License : Disabled perpetual
AnyConnect for Mobile : Enabled 91 days
AnyConnect for Cisco VPN Phone : Disabled perpetual
Advanced Endpoint Assessment : Disabled perpetual
UC Phone Proxy Sessions : 2 perpetual
Total UC Proxy Sessions : 2 perpetual
Botnet Traffic Filter : Disabled perpetual
Intercompany Media Engine : Disabled perpetual
Cluster : Disabled perpetual
This platform has a Base license.
Encryption hardware device : Cisco ASA-5505 on-board accelerator (revision 0x0)
Boot microcode : CN1000-MC-BOOT-2.00
SSL/IKE microcode : CNLite-MC-SSLm-PLUS-2.03
IPSec microcode : CNlite-MC-IPSECm-MAIN-2.08
Cisco Adaptive Security Appliance Software Version 9.0(1)
****************************** Warning *******************************
This product contains cryptographic features and is
subject to United States and local country laws
governing, import, export, transfer, and use.
Delivery of Cisco cryptographic products does not
imply third-party authority to import, export,
distribute, or use encryption. Importers, exporters,
distributors and users are responsible for compliance
with U.S. and local country laws. By using this
product you agree to comply with applicable laws and
regulations. If you are unable to comply with U.S.
and local laws, return the enclosed items immediately.
A summary of U.S. laws governing Cisco cryptographic
products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
If you require further assistance please contact us by
sending email to export@cisco.com.
******************************* Warning *******************************
This product includes software developed by the OpenSSL Project
for use in the OpenSSL Toolkit (http://www.openssl.org/)
Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com)
All rights reserved.
Copyright (c) 1998-2011 The OpenSSL Project.
All rights reserved.
This product includes software developed at the University of
California, Irvine for use in the DAV Explorer project
(http://www.ics.uci.edu/
webdav/)
Copyright (c) 1999-2005 Regents of the University of California.
All rights reserved.
Busybox, version 1.16.1, Copyright (C) 1989, 1991 Free Software Foundation, Inc.
51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
Busybox comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it under the General
Public License v.2 (http://www.gnu.org/licenses/gpl-2.0.html)
See User Manual (»Licensing») for details.
DOSFSTOOLS, version 2.11, Copyright (C) 1989, 1991 Free Software Foundation, Inc.
59 Temple Place, Suite 330, Boston, MA 02111-1307
675 Mass Ave, Cambridge, MA 02139
DOSFSTOOLS comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it under the General
Public License v.2 (http://www.gnu.org/licenses/gpl-2.0.html)
See User Manual (»Licensing») for details.
grub, version 0.94, Copyright (C) 1989, 1991 Free Software Foundation, Inc.
59 Temple Place, Suite 330, Boston, MA 02111-1307
grub comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it under the General
Public License v.2 (http://www.gnu.org/licenses/gpl-2.0.html)
See User Manual (»Licensing») for details.
libgcc, version 4.3, Copyright (C) 2007 Free Software Foundation, Inc.
libgcc comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it under the General
Public License v.2 (http://www.gnu.org/licenses/gpl-2.0.html)
See User Manual (»Licensing») for details.
libstdc++, version 4.3, Copyright (C) 2007 Free Software Foundation, Inc.
libstdc++ comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it under the General
Public License v.2 (http://www.gnu.org/licenses/gpl-2.0.html)
See User Manual (»Licensing») for details.
Linux kernel, version 2.6.29.6, Copyright (C) 1989, 1991 Free Software
Foundation, Inc.
51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
Linux kernel comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it under the General
Public License v.2 (http://www.gnu.org/licenses/gpl-2.0.html)
See User Manual (»Licensing») for details.
module-init-tools, version 3.10, Copyright (C) 1989, 1991 Free Software
Foundation, Inc.
59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
module-init-tools comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it under the General
Public License v.2 (http://www.gnu.org/licenses/gpl-2.0.html)
See User Manual (»Licensing») for details.
numactl, version 2.0.3, Copyright (C) 2008 SGI.
Author: Andi Kleen, SUSE Labs
Version 2.0.0 by Cliff Wickman, Chritopher Lameter and Lee Schermerhorn
numactl comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it under the General
Public License v.2 (http://www.gnu.org/licenses/gpl-2.0.html)
See User Manual (»Licensing») for details.
pciutils, version 3.1.4, Copyright (C) 1989, 1991 Free Software Foundation, Inc.
51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
pciutils comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it under the General
Public License v.2 (http://www.gnu.org/licenses/gpl-2.0.html)
See User Manual (»Licensing») for details.
readline, version 5.2, Copyright (C) 1989, 1991 Free Software Foundation, Inc.
59 Temple Place, Suite 330, Boston, MA 02111 USA
readline comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it under the General
Public License v.2 (http://www.gnu.org/licenses/gpl-2.0.html)
See User Manual (»Licensing») for details.
udev, version 146, Copyright (C) 1989, 1991 Free Software Foundation, Inc.
51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
udev comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it under the General
Public License v.2 (http://www.gnu.org/licenses/gpl-2.0.html)
See User Manual (»Licensing») for details.
Cisco Adapative Security Appliance Software, version 9.0,
Copyright (c) 1996-2012 by Cisco Systems, Inc.
Certain components of Cisco ASA Software, Version 9.0 are licensed under the GNU
Lesser Public License (LGPL) Version 2.1. The software code licensed under LGPL
Version 2.1 is free software that comes with ABSOLUTELY NO WARRANTY. You can
redistribute and/or modify such LGPL code under the terms of LGP(http://www.gnu.org/licenses/lgpl-2.1.html). See User Manual for licensing
details.
Restricted Rights Legend
Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software — Restricted
Rights clause at FAR sec. 52.227-19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227-7013.
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, California 95134-1706
Reading from flash.
. Warning: unexpected configuration tag ‘timeout-alert’ (line=131,column=5,position=5927)
*** Output from config line 254, » enable outside»
..
Cryptochecksum (unchanged): 68173df4 8d6682e2 aecca03a 09d84505
+—————————————————————+
| This equipment is privately owned and monitored. |
| Disconnect immediately if you are not an authorized user. |
+—————————————————————+
Type help or ‘?’ for a list of available commands.
ASA5505> // STARTUP-CONFIG STILL INTACT
Cisco ASA 5505 – Compatibile CF/RAM Upgrade Modules
Some very generous people at work decided to offer me (for free!) Cisco ASA 5505 security appliance. Great isn’t it? Great indeed given ASAs are top class firewall devices.
Appliance itself has unlimited number of users (other options made by Cisco are 10 and 50 users based on internal to external VLAN connections) and its running security plus licensing model. Needless to say that’s about £500 worth of money!
So moving to the ASA itself – model I have shipped with 512MB of RAM and 128MB CF card. Both of them modules can be upgraded to incorporate e-pen (RAM) and more space for historical data i.e. logs (CF card).
I just happen to have spare Integral IN1T1GNSKCX 1GB DD1 PC3200 (400 MHz) stick which, to my surprise, worked straight away! ASA didn’t have any issues detecting the new memory and booted up absolutely fine. There are lots of modules that won’t work full stop and quick search using your favourite search engine reveals that some people had tried 2-3 different sticks with no luck whatsoever. In my case completely random module worked first time. Awesome.
2GB compact flash card has been ordered from eBay and should turn up any day now so I will let you guys know how that goes. 2GB is the maximum that ASA can take, anything above will be most likely seen as 0MB so no point trying (it’s a limitation of FAT16 and cluster size not the ASA itself though). Card I have ordered is made by SanDisk and the exact model reads as ‘Ultra II 2GB 15MB/s’. USB CF card reader is also required so you can copy ASA firmware, ASDM and license file from old card to the new one.