cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
482
Views
0
Helpful
7
Replies

ASA CX console & Web Filter

Ninad Thakare
Level 1
Level 1

 

Hello Support,

I have installed ASA CX boot image and Software image on my ASA 5515-X. Now having 3 issues :

1 ) I used :

asa# session cxsc console

to login to CX. But how come I will get back to my ASA console back..?

2) I have subinterface (w.r.t VLANs on 0/1 followed with unmanaged network) and WAN link which was working fine, when I installed CX image I lost my internal network as well as Internet too. Why is it so..?

3) And is there any step by step guide to configure Web-Filter & IPS on ASA-CX.....

 

Regards,

Ninad Thakare

7 Replies 7

Marvin Rhoads
Hall of Fame
Hall of Fame

Ninda,

Please see the CX Module Quick Start Guide. That's for initial system setup.

Once you have access via PRSM, you can build and setup policies as described in the User Guide (specifically see the section of "The Basics, Managing Policy")

(properly) Installing the CX module software should not, by itself, affect in any way your base ASA operations or traffic flow. It's only when you redirect traffic (via a service policy) that you have the potential to affect traffic flow.

 

Marvin,

 

Ok. But how come I will get to ASA CLI.

I'm stuck on ASACX CLI mode. Not able to got to ASA CLI.

Whats, the way to it...?

If you are in asacx cli (having entered from the ASA cli using the "session cxsc console" command), then a simple "exit" should return you to the ASA cli.

Yes I m entered from ASA cli, and by using 'exit' command. I am just closing my putty session. And when I try to take console again, it displays asacx login/password, but not the asa login....

It sounds like you are logging into the CX management IP address and not the ASA management IP address. Perhaps you assigned it the same address as your ASA originally had? When you log into the CX cli directly, you cannot change into the ASA cli from it.

Note in the document I linked above that it directs you to assign a unique address to the CX management interface. It shares the physical M0/0 interface of the ASA.

The ASA itself does not necessarily have an address assigned to M0/0 (as it can be managed from any permitted interface address) but, if it does, it must be different than the one used by the CX module.

 

I am not using any IP to connect. I am using COM port to take console.

Where I m not even able to connect via SSH to ASA even though I have allowed it because my ASA is not accepting any username to it.

So, once in all, I lost all my ways to access ASA CLI.

I have never seen this behavior. I can only imagine some error during the CX module installation that overwrote your ASA configuration.

Since the ASA is no longer functioning correctly, I suggest your reboot while connected to the console and watch to see what image is being loaded. You may need to break in rommon and re-establish the ASA software as the primary booted image.

A TAC case is probably in order.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card