Packet Tracer lab 18 : ASA 5505 DMZ configuration

2.6206896551724 1 1 1 1 1 Rating 2.62 (58 Votes)

Network diagram

 Packet Tracer 6.1 - ASA 5505 DMZ lab

 

Lab instructions

Coming soon

ASA 5505 license limitations

Basic license bundle problems with DMZ creation

The ASA 5505 firewall provided in Packet Tracer 7.1.1 is shipped and installed by default with the basic license bundle. The content of this license package is displayed below :

Licensed features for this platform:
Maximum Physical Interfaces : 8 perpetual
VLANs : 3 DMZ Restricted
Dual ISPs : Disabled perpetual
VLAN Trunk Ports : 0 perpetual
Inside Hosts : 10 perpetual
Failover : Disabled perpetual
VPN-DES : Enabled perpetual
VPN-3DES-AES : Enabled perpetual
AnyConnect Premium Peers : 2 perpetual
AnyConnect Essentials : Disabled perpetual
Other VPN Peers : 10 perpetual
Total VPN Peers : 25 perpetual
Shared License : Disabled perpetual
AnyConnect for Mobile : Disabled perpetual
AnyConnect for Cisco VPN Phone : Disabled perpetual
Advanced Endpoint Assessment : Disabled perpetual
UC Phone Proxy Sessions : 2 perpetual
Total UC Proxy Sessions : 2 perpetual
Botnet Traffic Filter : Disabled perpetual
Intercompany Media Engine : Disabled perpetual
This platform has a Base license.

The ASA 5505 is configured by default with 2 vlans :

  • VLAN 1 : Inside VLAN (interfaces E0/1 -> E0/7)
  • VLAN 2 : Outside VLAN (interface E0/0)

If you try to configure a third vlan to host your DMZ,the ASA device will return the following error because of the limited licence :
ERROR: This license does not allow configuring more than 2 interfaces with nameif and without a "no forward" command on this interface or on 1 interface(s) with nameif already configured.

You have to limit communications between two vlan interfaces to make the creation of the third vlan interface possible. This can be done for example using the command no forward interface vlan 1 on the "interface vlan 3" to deny communications betwen the inside network and the DMZ

Security Plus license bundle activation

The "security plus" license bundle which remove this limitation in the ASA 5505 is now available in Packet Tracer 7.1.1 and can be unlocked with the activation-key 0x1321CF73 0xFCB68F7E 0x801111DC 0xB554E4A4 0x0F3E008D command. Up to 20 vlans can now be configured in the ASA 5505.

 Packet Tracer 7.1 ASA 5505 security plus license features

Lab Solution

Coming soon