ASA Firewall basic configuration Command
ASA 5505 ASA 5510 SME
5520 5540 5550 5580 large enterprises
ASA is a Cisco product, formerly known as PIX.
ASA basic configuration command
Command name
Pattern
Specific command
Modify the firewall name
Config#
Hostname xxxx
Configure privileged password
Config#
Enable password xxxx
Remote login password
Config#
Password xxxx
Configure the interface name
Config-if #
Nameif xxxx
Configure the interface security level
Config-if #
Ecurity-level xxxx (0-100)
Basic configuration of ASA ACL
Standard ACL
Asa (config) # access-group acl_name {in | out} interface interface_ name
Extended ACL
Asa (config) # access-list acl_name [extended] {permit | deny} protocol src_ip_addr src_mask dst_ip_addr dst_mask [operator port]
Apply ACL to an interface
Asa (config) # access-group acl_name {in | out} interface interface_ name
Example: allow ICMP to pass through the firewall
Asa (config) # access-list 111permit icmp any any
Asa (config) # access-group 111in int outside
Static rout
Asa (config) # route interface-name network mask next-hop-address
Other commands
Command name
Pattern
Specific command
Save running config configuration
Config#
Asa# write memory or
Asa# copy running-config startup-config
Clear all configurations for running config
Config#
Clear configure all
Clears the configuration of specified commands in running config
Config#
Asa (config) # clear config configcommand [level2configcommand]
For example, clear all ACL
Clear configure access-list
Clears the specified ACL in_to_out
Clear configure access-list in_to_out
Delete startup-config profile
#
Asa# write erase