Packet Tracer lab 18 : ASA 5505 DMZ configuration

2.734693877551 1 1 1 1 1 Rating 2.73 (49 Votes)

Network diagram

 Packet Tracer 6.1 - ASA 5505 DMZ lab

 

Lab instructions

Coming soon

 

ASA 5505 license limitations

The ASA 5505 firewall provided in Packet Tracer 6.1.1 is shipped with the basic licence bundle. The content of this licence package is displayed below :

Licensed features for this platform:
Maximum Physical Interfaces : 8 perpetual
VLANs : 3 DMZ Restricted
Dual ISPs : Disabled perpetual
VLAN Trunk Ports : 0 perpetual
Inside Hosts : 10 perpetual
Failover : Disabled perpetual
VPN-DES : Enabled perpetual
VPN-3DES-AES : Enabled perpetual
AnyConnect Premium Peers : 2 perpetual
AnyConnect Essentials : Disabled perpetual
Other VPN Peers : 10 perpetual
Total VPN Peers : 25 perpetual
Shared License : Disabled perpetual
AnyConnect for Mobile : Disabled perpetual
AnyConnect for Cisco VPN Phone : Disabled perpetual
Advanced Endpoint Assessment : Disabled perpetual
UC Phone Proxy Sessions : 2 perpetual
Total UC Proxy Sessions : 2 perpetual
Botnet Traffic Filter : Disabled perpetual
Intercompany Media Engine : Disabled perpetual
This platform has a Base license.

 

Problem with DMZ creation :

The ASA 5505 is configured by default with 2 vlans :

  • VLAN 1 : Inside VLAN (interfaces E0/1 -> E0/7)
  • VLAN 2 : Outside VLAN (interface E0/0)

If you try to configure a third vlan to host your DMZ,the ASA device will return the following error because of the limited licence :


ERROR: This license does not allow configuring more than 2 interfaces with nameif and without a "no forward" command on this interface or on 1 interface(s) with nameif already configured.

 

 

Explanation :

You have to limit communications between two vlan interfaces to make the creation of the third vlan interface possible. This can be done for example using the command no forward interface vlan 1 on the "interface vlan 3" to deny communications betwen the inside network and the DMZ

The "security plus" licence bundle which remove this limitation is not available in Packet Tracer 6.1.1 simulator.

 

Lab Solution

Coming soon