0.0.0.0 Lab - Instructor Lab Using ASA 5506-X
0.0.0.0 Lab - Instructor Lab Using ASA 5506-X
© 2015 - 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 1 of 10 www.netacad.com
Lab – Instructor Lab Using ASA 5506-X
IP Addressing Table
Objectives
In this lab, you will initialize the router, switch, and ASA. You will download and install USB console software
that allows the use of a mini-USB cable to access the console port on a Cisco device. You will also download
the AnyConnect Secure Mobility Client Software and upload it to the ASA.
Part 1: Initialize and Reload Network Devices
Initialize the router and reload.
Enable the security technology package license.
Initialize the switch and reload.
Initialize the ASA.
Part 2: Access a Cisco Router Using a Mini-USB Console Cable
Setup the physical connection with a mini-USB cable.
Verify that the USB console is ready.
Enable the COM port.
Part 3: Download and Install the AnyConnect Secure Mobility Client Software Package
Download the AnyConnect Secure Mobility Client software from cisco.com.
Upload AnyConnect Secure Mobility Client to ASA 5506-X.
Background/Scenario
Part 1 of this instructor lab provides the steps for initializing devices back to their default settings. Part 2 of
this lab provides the steps necessary to set Java settings on the PC hosts. Part 3 of this lab provides optional
information on how to download, install, and use the Cisco USB driver on a Windows PC.
© 2015 - 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 2 of 10 www.netacad.com
Lab – Instructor Lab Using ASA 5506-X
Required Resources
3 Routers (Cisco 1941 with Cisco IOS Release 15.4(3)M2 image with a Security Technology Package
license)
3 Switches (Cisco 2960 with cryptography IOS image for SSH support – Release 15.0(2)SE7 or
comparable)
1 ASA 5506-X (OS version 9.10(1) and ASDM version 7.10(1) and Base license or comparable)
3 PCs (Windows, SSH Client and Java version compatible with installed ASDM version)
Serial and Ethernet cables, as shown in the topology
Console cables to configure Cisco networking devices
-----------------------------------------------------------------
Technology Technology-package Technology-package
Current Type Next reboot
------------------------------------------------------------------
ipbase ipbasek9 Permanent ipbasek9
security disable None disable
data None None None
© 2015 - 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 3 of 10 www.netacad.com
Lab – Instructor Lab Using ASA 5506-X
b. Enter the license boot module c1900 technology-package securityk9 to enable the securityk9
technology package.
R1(config)# license boot module c1900 technology-package securityk9
R1(config)# exit
R1# copy running-config startup-config
Destination filename [startup-config]?
Building configuration...
[OK]
Directory of flash:/
© 2015 - 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 4 of 10 www.netacad.com
Lab – Instructor Lab Using ASA 5506-X
© 2015 - 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 5 of 10 www.netacad.com
Lab – Instructor Lab Using ASA 5506-X
© 2015 - 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 6 of 10 www.netacad.com
Lab – Instructor Lab Using ASA 5506-X
Note: You must use either the USB port or the RJ-45 port. Do not use them simultaneously. When the USB
port is used, it takes priority over the RJ-45 console port.
© 2015 - 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 7 of 10 www.netacad.com
Lab – Instructor Lab Using ASA 5506-X
When the LED indicator for the USB console port has turned green, the USB console port is ready for access.
a. Open the Device Manager to determine the associated COM port.
b. Click the Ports (COM & LPT) tree link to expand it. Right-click the USB Serial Port icon to determine the
COM port associated with USB Serial Port. Take note of the assigned port number. In this sample, COM
5 is used for communication with the router.
c. Open Tera Term. Click the Serial radio button and choose COM5: Cisco Serial (COM 5). If it is
successful, skip the next step. Otherwise, perform the next step to enable to COM port.
Step 1: Download the AnyConnect Secure Mobility Client software packages from cisco.com.
a. Using a browser, connect to the www.cisco.com and log in.
b. Click Support & Downloads > Search for AnyConnect Secure Mobility Client v4.x. or use this directly
link for the available versions:
https://software.cisco.com/download/home/286281283/type/282364313/release/
c. Download the AnyConnect Headend Deployment Package (.pkg) version compatible with your operating
system.
© 2015 - 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 8 of 10 www.netacad.com
Lab – Instructor Lab Using ASA 5506-X
d. From the Download Software – Select a Product screen, click AnyConnect Secure Mobility Client.
Step 2: Upload the AnyConnect Secure Mobility Client to the ASA 5506-X.
a. After the AnyConnect client has been downloaded, connect the PC to the ASA 5506-X G1/2 interface and
assign a static IP address of 192.168.1.3 with a subnet mask of 255.255.255.0.
Note: This PC will also need TFTP server software installed. Free or trial versions of TFTP server can be
downloaded from the Internet. Use a web browser to search for “free windows tftp server” and refer to the
software documentation for more information.
The IP addresses used in this example are for reference only. The file anyconnect-win-4.5.05030-
webdeploy-k9.pkg will be used in this example.
b. Configure the ASA’s interface G1/2 with an IP address of 192.168.1.1, a subnet mask of 255.255.255.0,
and the nameif to inside.
ciscoasa(config)# interface G1/2
ciscoasa(config-if)# ip address 192.168.1.1 255.255.255.0
ciscoasa(config-if)# nameif inside
INFO: Security level for "inside" set to 100 by default.
ciscoasa(config-if)# security-level 100
ciscoasa(config-if)# no shut
c. Start the TFTP server software and verify that the AnyConnect Secuity Mobility Client is located in the
default directory.
d. From the CLI on the ASA, issue the copy tftp://192.168.1.1/ anyconnect-win-4.5.05030-webdeploy-
k9.pkg flash: command.
ciscoasa# copy tftp://192.168.1.3/anyconnect-win-4.5.05030-webdeploy-k9.pkg
flash:
Accessing tftp://192.168.1.3/anyconnect-win-4.5.05030-webdeploy-
k9.pkg...!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Writing file disk0:/anyconnect-win-4.5.05030-webdeploy-k9.pkg...
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
INFO: No digital signature found
35431181 bytes copied in 37.410 secs (957599 bytes/sec)
e. Issue the show flash command on the ASA to verify that the file has been uploaded to flash.
ciscoasa# show flash
--#-- --length-- -----date/time------ path
121 35431181 Mar 04 2018 10:57:43 anyconnect-win-4.5.05030-webdeploy-k9.pkg
21 4096 Aug 29 2017 13:16:38 coredumpinfo
22 59 Aug 29 2017 13:16:38 coredumpinfo/coredump.cfg
20 4096 Sep 17 2017 12:07:32 crypto_archive
119 115316320 Feb 21 2018 18:01:22 asa9101-lfbff-k8.SPA
© 2015 - 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 9 of 10 www.netacad.com
Lab – Instructor Lab Using ASA 5506-X
Router Model Ethernet Interface #1 Ethernet Interface #2 Serial Interface #1 Serial Interface #2
1800 Fast Ethernet 0/0 Fast Ethernet 0/1 Serial 0/0/0 (S0/0/0) Serial 0/0/1 (S0/0/1)
(F0/0) (F0/1)
1900 Gigabit Ethernet 0/0 Gigabit Ethernet 0/1 Serial 0/0/0 (S0/0/0) Serial 0/0/1 (S0/0/1)
(G0/0) (G0/1)
2801 Fast Ethernet 0/0 Fast Ethernet 0/1 Serial 0/1/0 (S0/1/0) Serial 0/1/1 (S0/1/1)
(F0/0) (F0/1)
2811 Fast Ethernet 0/0 Fast Ethernet 0/1 Serial 0/0/0 (S0/0/0) Serial 0/0/1 (S0/0/1)
(F0/0) (F0/1)
2900 Gigabit Ethernet 0/0 Gigabit Ethernet 0/1 Serial 0/0/0 (S0/0/0) Serial 0/0/1 (S0/0/1)
(G0/0) (G0/1)
Note: To find out how the router is configured, look at the interfaces, identify the type of router used, and how
many interfaces the router has. There is no way to effectively list all the combinations of configurations for each
router class. This table includes identifiers for the possible combinations of Ethernet and Serial interfaces in the
device. The table does not include any other type of interface, even though a specific router may contain one. An
example of this might be an ISDN BRI interface. The string in parenthesis is the legal abbreviation that can be
used in Cisco IOS commands to represent the interface.
© 2015 - 2019 Cisco and/or its affiliates. All rights reserved. Cisco Public Page 10 of 10 www.netacad.com