Karsten Iwen

Member Since: Dec 21, 2006

English
Karsten Iwen's Activity on Cisco Support Community
Currently displaying 50 results

Karsten Iwen has commented on Cisco ASA 5505 - DMZ Web Server help!

2 weeks 6 days ago
First: It's always best to open a new thread for a new problem. Especially...

Karsten Iwen has commented on bandwidth restriction on asa 5512

1 month 1 day ago
The ASA is quite limited regarding to QoS. You can't shape the traffic, but...

Karsten Iwen has commented on Anyconnect VPN-Authentication multiple profiles via Single RADIUS/Windows NPS

1 month 3 days ago
There are multiple ways to achieve that. IMO, the easiest is the following (if...

Karsten Iwen has commented on ssl version 2 and 3 protocol detection

1 month 3 days ago
Which device are you talking about? If it's the ASA up to v9.2, use "...

Karsten Iwen has commented on Support for ASA5506X VPN Tunnel to VPN3020

1 month 3 days ago
The VPN3k uses IKEv1 IPsec which is supported by the ASA 5506.The ASA 5505 is...

Karsten Iwen has commented on Can't ping through Firewall

1 month 3 days ago
Have you enabled ICMP-inspection? fixup protocol icmp With that you don...

Karsten Iwen has commented on ASA SaAB Flags - Incomplete TCP 3-way handshake

1 month 3 days ago
You can see the flags description with  show conn detail "SaA...

Karsten Iwen has commented on Changing VPN fqdn

1 month 4 days ago
You can change the fqdn in the client profiles which get pushed to the clients...

Karsten Iwen has commented on Migrating IKEv1 to IKEv2 (ASA 5520)

1 month 4 days ago
IKEv2 is supported starting with ASA version 8.4. You need to upgrade first to...

Karsten Iwen has commented on VPN IPSec residing on Inside Firewall - traverse outside firewall?

1 month 4 days ago
Yes, you can terminate the VPNs on the inside firewall, but the VPN-config on...

Karsten Iwen has commented on ACL allowing internet but blocking rfc addresses

1 month 4 days ago
I also use these private networks quite often in ACLs. For that, one of my...

Karsten Iwen has commented on block port 25 on single public IP ASA5505

1 month 4 days ago
Nearly correct. There is nothing to "no shutdown" and a reload is not...

Karsten Iwen has commented on Communication between different networks across ASA

1 month 5 days ago
By default, the ASA doesn't allow pinging through, as icmp is not inspected...

Karsten Iwen has commented on TACACs not working on Firewall device

1 month 5 days ago
> Important to get the key to match with the one on the radius server...

Karsten Iwen has commented on CA Certificates for ASA on Active/Standby Configuration

1 month 5 days ago
Upgrade to the newest 8.2 release (8.2(5)57 is the newest in your release-train...

Karsten Iwen has commented on Does it possible ASA 5512-X with Switch 2960 (Inter-Vlan)

1 month 5 days ago
Yes, the ASA can be used for inter-vlan-routing. That's a quite common...

Karsten Iwen has commented on Does it possible ASA 5512-X with Switch 2960 (Inter-Vlan)

1 month 5 days ago
> I want to ping from IP 21.20.20.1 to 22.20.20.1 . These are the...

Karsten Iwen has commented on Dual ISP setup with ASA 5512X With baselicense

1 month 5 days ago
The easiest would be to upgrade both ASAs to Security-Plus, run A/S failover...

Karsten Iwen has commented on Does it possible ASA 5512-X with Switch 2960 (Inter-Vlan)

1 month 5 days ago
Is it only ping that fails or also other traffic? Have you enabled icmp-...

Karsten Iwen has commented on Help with new code NAT statement that has no destination but translate hits

1 month 6 days ago
Have you tested it without the NAT-exemptions? That's the most important...

Karsten Iwen has commented on ASA 5525X With FirePOWER Setup

1 month 6 days ago
No, the FirePOWER module only works on the m0/0 interface. If that is connected...

Karsten Iwen has commented on CA Certificates for ASA on Active/Standby Configuration

1 month 6 days ago
You certificates should sync to the standby unit. Is your failover working...

Karsten Iwen has commented on Does it possible ASA 5512-X with Switch 2960 (Inter-Vlan)

1 month 6 days ago
> What is the problem ?The main problem is, that you don't ask a...

Karsten Iwen has commented on ASA 5525X With FirePOWER Setup

1 month 6 days ago
You don't need a route for your directly connected management-network, but...

Karsten Iwen has commented on Can't ping across the firewall

1 month 6 days ago
After thinking about it twice, it's clear. I wrote to change it...

Karsten Iwen has commented on Can't ping across the firewall

1 month 6 days ago
On R1: For Ethernet, always use the next-hop IP in static routes, and not...

Karsten Iwen has commented on Can't ping across the firewall

1 month 1 week ago
You config shows that you have enabled the statefull inspection of icmp,...

Karsten Iwen has commented on Exempting NAT traffic for VPN when sysopt is disabled...

1 month 1 week ago
The vpn-filter is shown in the config-guide:http://www.cisco.com/c/en/us/td/...

Karsten Iwen has commented on Help with new code NAT statement that has no destination but translate hits

1 month 1 week ago
Yes, the five statements seem to be not needed in your scenario.Is the API...

Karsten Iwen has commented on same security level state table

1 month 1 week ago
The ASA will still work as a firewall for traffic between interfaces with the...

Karsten Iwen has commented on AutoNAT and ManualNAT question

1 month 1 week ago
Yes, the syntax a bit confusing ... You configure the nat-rule in object-mode...

Karsten Iwen has commented on Help with new code NAT statement that has no destination but translate hits

1 month 1 week ago
These NAT-exemption-rules are only needed if there is done NAT on the ASA,...

Karsten Iwen has commented on Packet drops between ASA and ISP Modem

1 month 1 week ago
1) You should revert all ARP/MAC manipulations that you did. It's not...

Karsten Iwen has commented on AnyConnect VPN configuration on a 2921 router ?

1 month 1 week ago
The command is "interface Virtual-Template1". Here is an example-...

Karsten Iwen has commented on Can I port forward accross a VPN

1 month 1 week ago
If you have crypto-maps running and you prefer split-tunneling, then I would...

Karsten Iwen has commented on Show NAT tranlations on ASA

1 month 1 week ago
What are you looking for exactly if "show xlate" is not what you need...

Karsten Iwen has commented on Can I port forward accross a VPN

1 month 1 week ago
You are probably running into more then one problem here (I assume that you are...

Karsten Iwen has commented on Remtoe VPN users lost their local internet connection after they made the VPN connection.

1 month 1 week ago
For sure, go to configuration -> Remote-Access-VPNs, edit the Group-policy...

Karsten Iwen has commented on Exempting NAT traffic for VPN when sysopt is disabled...

1 month 1 week ago
You only need one new NAT-rule at the beginning of the NAT-list: object-...

Karsten Iwen has commented on Remtoe VPN users lost their local internet connection after they made the VPN connection.

1 month 1 week ago
It more a routing issue that gets controlled by an ACL. Bay default the client...

Karsten Iwen has commented on Remtoe VPN users lost their local internet connection after they made the VPN connection.

1 month 1 week ago
You need Split-Tunneling. With that you tell the client to only send traffic...

Karsten Iwen has commented on Help with new code NAT statement that has no destination but translate hits

1 month 1 week ago
If there is no destination in the NAT-statement, then the destination is "...

Karsten Iwen has commented on Subscription addtional Feature of UT M

1 month 1 week ago
Yes, you can add additional services to the ASA. For that you have to add the...

Karsten Iwen has commented on IPEP Inlien posture without ASA

1 month 1 week ago
If you don't want to posture your clients to assign differentiated access-...

Karsten Iwen has commented on Multiple public IP Addresses on ASA 5505

1 month 1 week ago
On the ASA, there are no multiple addresses on an interface. But your scenario...

Karsten Iwen has commented on ASA5545-k9 - Backup FW Status failed in Failover

1 month 1 week ago
You should be physically at then secondary appliance anyway to analyze the...

Karsten Iwen has commented on ASA5545-k9 - Backup FW Status failed in Failover

1 month 1 week ago
failover needs to to be configured on the secondary unit. Here is how I would...

Karsten Iwen has commented on TACACs not working on Firewall device

1 month 1 week ago
not sure what you tried, but the ASA-config for TACACS looks like the following...

Karsten Iwen has commented on Unencrypted vs encrytped password

1 month 1 week ago
First and most important: The type-7 passwords that you get with "service...

Karsten Iwen has commented on Giving internet access to additional subnet on 877W

1 month 1 week ago
You just need to allow your new VLAN to use NAT-services. Your ACL 1 which...

Bio

I started my work in the IT at about 1995/1996 as a freelance Trainer and consultant with a focus on networking, Novell NetWare and Microsoft Backoffice. In 2001 I started teaching Cisco classes at Global Knowledge in Germany. Since 2003 I'm again Freelancer with a strong focus on security technologies and infrastructure.
And yes, you can hire me for your security-projects and security-workshops. ;-)








  • Cisco Designated VIP

    2015 Security





  • Cisco Designated VIP

    2014 Security





  • Cisco Designated VIP

    2013 Security





  • Community Spotlight Award

    Mobile App Contributor August 2012









Karsten Iwen's Stats

Points4562
Discussion started 16
Answers marked as Correct 643
Endorsed 14
Content Rated 78