Hoi Zäme,
stehe hier etwas auf dem Schlauch.. Irgendwie will das Ding einfach nicht so, wie ich will.
Habe eine Cisco ASA 5505 mit der Software in der Version asa823-k8. Per TFTP ist auch das ASDM (asdm-634-53) unter disk0: installiert worden
In der Config habe ich asdm image disk0:/asdm-634-53.bin konfiguriert, http aktiviert, entsprechendes Subnet auch den http Zugriff erlaubt.
Per SSH klappt die Verbindung einwandfrei.. Versuche ich jedoch per Webinterface das ASDM zu starten, kommt jedoch "Internet Explorer cannot display the webpage", als ob der Webserver gar nicht laufen würde.
Jemand eine Idee?
Die Config im Detail:
Code
- ASA Version 8.2(3)
- !
- hostname ASATEST
- enable password 8Ry2YjIyt7RRXU24 encrypted
- passwd 2KFQnbNIdI.2KYOU encrypted
- names
- !
- interface Ethernet0/0
- switchport access vlan 2
- !
- interface Ethernet0/1
- !
- interface Ethernet0/2
- shutdown
- !
- interface Ethernet0/3
- shutdown
- !
- interface Ethernet0/4
- shutdown
- !
- interface Ethernet0/5
- shutdown
- !
- interface Ethernet0/6
- shutdown
- !
- interface Ethernet0/7
- shutdown
- !
- interface Vlan1
- nameif inside
- security-level 100
- ip address 192.168.1.1 255.255.255.0
- !
- interface Vlan2
- nameif outside
- security-level 0
- ip address 9.9.9.9 255.255.255.0
- !
- ftp mode passive
- pager lines 24
- mtu inside 1500
- mtu outside 1500
- icmp unreachable rate-limit 1 burst-size 1
- no asdm history enable
- arp timeout 14400
- route outside 0.0.0.0 0.0.0.0 9.9.9.8 1
- timeout xlate 3:00:00
- timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
- timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
- timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
- timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
- timeout tcp-proxy-reassembly 0:01:00
- dynamic-access-policy-record DfltAccessPolicy
- aaa authentication http console LOCAL
- aaa authentication ssh console LOCAL
- http server enable
- http 192.168.1.0 255.255.255.0 inside
- no snmp-server location
- no snmp-server contact
- snmp-server enable traps snmp authentication linkup linkdown coldstart
- crypto ipsec security-association lifetime seconds 28800
- crypto ipsec security-association lifetime kilobytes 4608000
- telnet timeout 5
- ssh 192.168.1.0 255.255.255.0 inside
- ssh timeout 5
- console timeout 0
- threat-detection basic-threat
- threat-detection statistics access-list
- no threat-detection statistics tcp-intercept
- webvpn
- username example password 9hx9DtELyXf6OAqH encrypted privilege 15
- !
- class-map inspection_default
- match default-inspection-traffic
- !
- !
- policy-map type inspect dns preset_dns_map
- parameters
- message-length maximum client auto
- message-length maximum 512
- policy-map global_policy
- class inspection_default
- inspect dns preset_dns_map
- inspect ftp
- inspect h323 h225
- inspect h323 ras
- inspect ip-options
- inspect netbios
- inspect rsh
- inspect rtsp
- inspect skinny
- inspect esmtp
- inspect sqlnet
- inspect sunrpc
- inspect tftp
- inspect sip
- inspect xdmcp
- !
- service-policy global_policy global
- prompt hostname context
- call-home
- profile CiscoTAC-1
- no active
- destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
- destination address email callhome@cisco.com
- destination transport-method http
- subscribe-to-alert-group diagnostic
- subscribe-to-alert-group environment
- subscribe-to-alert-group inventory periodic monthly
- subscribe-to-alert-group configuration periodic monthly
- subscribe-to-alert-group telemetry periodic daily
- Cryptochecksum:b3667e094803935fd2855f4a90fab279
- : end