ASA Basics: Architecture & Initial Setup
Cisco ASA Firewall EVE-NG — ASAv (CLI + ASDM)
مقصدObjectiveObjective
ASA سافٹ ویئر آرکیٹیکچر سمجھیں اور مکمل initial setup کریں: hostname، passwords، management interface، SSH، اور ASDM رسائی۔ASA software architecture samjho aur complete initial setup karo: hostname, passwords, management interface, SSH, aur ASDM access.Understand the ASA software architecture and perform a complete initial setup: hostname, passwords, management interface, SSH, and ASDM access.
آسان مثالSimple AnalogySimple Analogy
ASA کو عمارت کے مین گیٹ پر کھڑے سیکیورٹی گارڈ کی طرح سمجھیں۔ شناختی کارڈ چیک کرنے (ACLs) یا پاس اسٹیمپ کرنے (NAT) سے پہلے اسے اپنا دفتر سیٹ کرنا ہوتا ہے: نام، میز (management interface)، اور دروازے کی چابیاں (passwords، SSH)۔ASA ko building ke main gate par khara security guard samjho. IDs check karne (ACLs) ya pass stamp karne (NAT) se pehle use apna office set karna hota hai: naam, desk (management interface), aur darwaze ki chabiyan (passwords, SSH).Think of the ASA as the security guard at a building's main gate. Before it checks anyone's ID (ACLs) or stamps passes (NAT), it needs its own office set up: a name, a desk (management interface), and keys to the door (passwords, SSH).
سیٹ اپLab SetupLab Setup
EVE-NG لیب میں ایک ASAv node (8.4+ image)۔ EVE-NG سے console access۔ Management 0/0 کو IP 192.168.10.10/24 ملے گا؛ آپ کا PC/VM SSH/ASDM کے لیے 192.168.10.0/24 پر ہے۔EVE-NG lab mein ek ASAv node (8.4+ image). EVE-NG se console access. Management 0/0 ko IP 192.168.10.10/24 milega; aapka PC/VM SSH/ASDM ke liye 192.168.10.0/24 par hai.EVE-NG lab with one ASAv node (8.4+ image). Console access via EVE-NG. Management 0/0 will get IP 192.168.10.10/24; your PC/VM is on 192.168.10.0/24 for SSH/ASDM.
اقداماتStepsSteps
Step 1
Privileged mode اور global config میں جائیں۔ فائر وال کا hostname اور domain name سیٹ کریں (SSH keys generate کرنے سے پہلے domain ضروری ہے)۔Privileged mode aur global config mein jao. Firewall ka hostname aur domain name set karo (SSH keys generate karne se pehle domain zaroori hai).Enter privileged mode and global config. Set the firewall hostname and domain name (domain is required before generating SSH keys).
enable configure terminal hostname ASA-LAB domain-name lab.local
Step 2
Enable password اور Telnet/login password سیٹ کریں۔ یہ box پر access control کی پہلی layer ہیں۔Enable password aur Telnet/login password set karo. Ye box par access control ki pehli layer hain.Set the enable password and the Telnet/login password. These are the first layer of access control on the box.
enable password cisco123 passwd cisco123
Step 3
Management interface کنفیگر کریں: اسے نام دیں (nameif)، سب سے high security level (100)، IP address، اور اسے up کریں۔Management interface configure karo: ise naam do (nameif), sab se high security level (100), IP address, aur ise up karo.Configure the management interface: give it a name (nameif), the highest security level (100), an IP address, and bring it up.
interface management 0/0 nameif management security-level 100 ip address 192.168.10.10 255.255.255.0 no shutdown exit
Step 4
RSA key pair generate کریں، SSH version 2 force کریں، اور صرف management subnet سے SSH allow کریں، local users سے authenticate ہو۔RSA key pair generate karo, SSH version 2 force karo, aur sirf management subnet se SSH allow karo, local users se authenticate ho.Generate an RSA key pair, force SSH version 2, and allow SSH only from the management subnet, authenticated against local users.
crypto key generate rsa modulus 2048 ssh version 2 ssh 192.168.10.0 255.255.255.0 management aaa authentication ssh console LOCAL
Step 5
ASDM کے لیے HTTPS server enable کریں، اپنی management subnet permit کریں، اور ASA کو disk0 پر ASDM image کی طرف point کریں۔ نوٹ: classic ASDM launch کرنے کے لیے Java چاہیے۔ASDM ke liye HTTPS server enable karo, apni management subnet permit karo, aur ASA ko disk0 par ASDM image ki taraf point karo. Note: classic ASDM launch karne ke liye Java chahiye.Enable the HTTPS server for ASDM, permit your management subnet, and point the ASA at the ASDM image on disk0. Note: Java is required to launch classic ASDM.
http server enable http 192.168.10.0 255.255.255.0 management asdm image disk0:/asdm-841.bin
🖱️ ASDM launcher: Configuration > Device Setup — HTTP/ASDM settings graphically verify کریں۔ASDM launcher: Configuration > Device Setup — HTTP/ASDM settings graphically verify karo.ASDM launcher: Configuration > Device Setup — verify HTTP/ASDM settings graphically.
Step 6
Privilege 15 کے ساتھ local admin user بنائیں اور configuration کو startup-config میں save کریں تاکہ reload کے بعد بھی رہے۔Privilege 15 ke sath local admin user banao aur configuration ko startup-config mein save karo taake reload ke baad bhi rahe.Create a local admin user with privilege 15 and save the configuration to startup-config so it survives a reload.
username admin password Admin123 privilege 15 write memory
تصدیقVerifyVerify
Hostname ASA-LAB show ہو، management 0/0 192.168.10.10 کے ساتھ up ہو، آپ کے PC سے SSH کام کرے، اور browser میں HTTPS پر ASDM کھل جائے۔Hostname ASA-LAB show ho, management 0/0 192.168.10.10 ke sath up ho, aapke PC se SSH kaam kare, aur browser mein HTTPS par ASDM khul jaye.Hostname shows ASA-LAB, management 0/0 is up with 192.168.10.10, SSH works from your PC, and ASDM opens in the browser over HTTPS.
show version | include Version show interface ip brief show run http show crypto key mypubkey rsa
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ https://192.168.10.10 پر ASDM نہیں کھل رہا — browser timeout۔https://192.168.10.10 par ASDM nahi khul raha — browser timeout.Cannot reach ASDM at https://192.168.10.10 — browser times out.
✅ `show run http` چیک کریں — management subnet management interface پر permit ہونی چاہیے، اور `http server enable` on ہونا چاہیے۔ ASAv interface up ہے یا نہیں، `show interface ip brief` سے confirm کریں۔`show run http` check karo — management subnet management interface par permit honi chahiye, aur `http server enable` on hona chahiye. ASAv interface up hai ya nahi, `show interface ip brief` se confirm karo.Check `show run http` — the management subnet must be permitted on the management interface, and `http server enable` must be on. Also confirm the ASAv interface is up (`show interface ip brief`).
⚠️ Interface reachable ہونے کے باوجود SSH connection refused۔Interface reachable hone ke bawajood SSH connection refused.SSH connection refused even though the interface is reachable.
✅ RSA key موجود ہونی چاہیے (`show crypto key mypubkey rsa`)۔ اگر missing ہے تو `crypto key generate rsa` سے regenerate کریں۔ یہ بھی verify کریں کہ `ssh <subnet> <mask> <if-name>` آپ کی source IP cover کرتا ہے۔RSA key mojood honi chahiye (`show crypto key mypubkey rsa`). Agar missing hai to `crypto key generate rsa` se regenerate karo. Ye bhi verify karo ke `ssh <subnet> <mask> <if-name>` aapki source IP cover karta hai.An RSA key must exist (`show crypto key mypubkey rsa`). If missing, regenerate with `crypto key generate rsa`. Also verify `ssh <subnet> <mask> <if-name>` covers your source IP.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ Cisco ASA کیا ہے اور لیبز میں ASAv کیوں استعمال کرتے ہیں؟Cisco ASA kya hai aur labs mein ASAv kyun use karte hain?What is the Cisco ASA and why do we use the ASAv in labs?
ASA سسکو کا stateful فائر وال پلیٹ فارم ہے (Adaptive Security Appliance)۔ ASAv ورچوئل ورژن ہے جو EVE-NG یا VMware میں چلتا ہے، ہارڈ ویئر ASAs والا وہی CLI اور فیچرز دیتا ہے — لیب پریکٹس کے لیے بہترین۔ASA Cisco ka stateful firewall platform hai (Adaptive Security Appliance). ASAv virtual version hai jo EVE-NG ya VMware mein chalta hai, hardware ASAs wala same CLI aur features deta hai — lab practice ke liye perfect.ASA is Cisco's stateful firewall platform (Adaptive Security Appliance). The ASAv is the virtual version that runs in EVE-NG or VMware, with the same CLI and features as hardware ASAs, ideal for lab practice.
❓ ASDM کیا ہے اور ASA CLI سے اس کا کیا تعلق ہے؟ASDM kya hai aur ASA CLI se iska kya rishta hai?What is ASDM and how does it relate to the ASA CLI?
ASDM گرافیکل مینیجر ہے (ASA سے HTTPS پر serve ہونے والا Java applet)۔ Bulk config کے لیے CLI تیز ہے؛ monitoring، packet-tracer اور visual ACL editing کے لیے ASDM کارآمد ہے۔ دونوں ایک ہی running-config ایڈٹ کرتے ہیں۔ASDM graphical manager hai (ASA se HTTPS par serve hone wala Java applet). Bulk config ke liye CLI tez hai; monitoring, packet-tracer aur visual ACL editing ke liye ASDM handy hai. Dono same running-config edit karte hain.ASDM is the graphical manager (a Java applet served by the ASA over HTTPS). CLI is faster for bulk config and exams; ASDM is handy for monitoring, packet-tracer, and visual ACL editing. Both edit the same running-config.