Configure Cisco ASA firewall version 8.4 on GNS3

by Ras 6. February 2012 21:23

 

As I have had a couple of requests about running Cisco ASA 8.4 on the GNS3, I decided to post a new article which shows you how to do it.

To get ASA 8.4 running on GNS3 plz follow the below steps:

1-Download and Install GNS3 from the below url:

http://www.gns3.net/download

2- Download the required files from the below address:

http://www.mediafire.com/download.php?ssadit26tl3llms

or

https://rapidshare.com/files/2538881267/asa.zip

3- Configure GNS3 preferrences -> QEMU -> ASA with below settings

RAM: 1024 MiB
Number of NICs: 6

Qemu options: -m 1024 -icount auto -hdachs 980,16,32

Initrd:          C:\ASA\asa842-initrd.gz
Kernel:          C:\ASA\asa842-vmlinuz
Kernel cmd line: -append ide_generic.probe_mask=0x01 ide_core.chs=0.0:980,16,32 auto nousb console=ttyS0,9600 bigphysarea=65536

4- Activate the licenses using below codes:


activation-key 0x4a3ec071 0x0d86fbf6 0x7cb1bc48 0x8b48b8b0 0xf317c0b5

activation-key 0xb23bcf4a 0x1c713b4f 0x7d53bcbc 0xc4f8d09c 0x0e24c6b6

 

Tags:

Cisco | Security

Comments (55) -

rasoolg
rasoolg United States
2/15/2012 3:43:05 PM #

I found this article on GNS3 web site very useful,
Please check the "CPU usage with PIX" section if the CPU load is %100!

http://www.gns3.net/gns3-pix-firewall-emulation

Reply

Sachin
Sachin India
2/27/2012 3:06:23 AM #

Awesome, Thansk and appreciate your time on this blog. Knowledge has to be free.

Reply

Blastodon
Blastodon United States
2/29/2012 12:56:10 PM #

Is it possible that you could check the link? I wasn't able to download asa.zip. Thank you

Reply

rasoolg
rasoolg United States
2/29/2012 6:14:27 PM #

The link is fine, I have put a rapidshare link too.

Reply

Tourman
Tourman United States
3/2/2012 12:11:07 PM #

rapidshare link is already down. Mediafire works

Reply

Jason
Jason United States
3/4/2012 3:24:53 AM #

Thank you very much .....God bless you ...

Can you please share what features you were able to activate and scenario tested in GNS3? I am new to Cisco ASA (Juniper Engineer) and would like to go for Cisco Security based certifications.

Reply

rasoolg
rasoolg United States
3/7/2012 3:46:59 PM #

This is a fully featured ASA, so you can use it in any network design on GNS,
However there is a problem with CPU usage that cannot be fixed with GNS itself and needs a third party software.
I think single ASA for command test is fine.

Reply

Niranjan
Niranjan Bahrain
3/7/2012 2:25:41 AM #

I downloaded and configured qemu as given above, and my ASA starts (I see the green indication) but when I double click or try to open the console, it opens and closes without any text, warning or message.

Dont know what is happening please guide

Reply

rasoolg
rasoolg United States
3/7/2012 3:45:15 PM #

Hi,

This could be multiple different things.
GNS version? Memory on your machine? OS version? Firewall? a typo on the configuration texts?
I have tested this with the latest GNS3 portal version on Windows 7 64 bit and 8GB memory.

Reply

otunbadree
otunbadree Nigeria
6/26/2012 5:54:42 AM #

The problem has to do with the qemu settings. It shows that the qemu process/server  was not started. The problem might be solved if you test your qemu in Preferences.

Reply

Niranjan
Niranjan Bahrain
3/8/2012 12:34:09 AM #

Some how I can now get the console and see lot of scrolling then I get a screen with message

REBOOT: open message queue fail: no such file or directory/2
REBOOT: enforce reboot

and the cycle goes on !

Reply

acer787
acer787 United States
3/10/2012 3:52:35 PM #

I followed the instruction mentioned above, but quemu doesn't start. I don't see any action. I'm using GNS3 8.2 beta 2. Please help and thanks for the post

Reply

rasoolg
rasoolg Australia
3/11/2012 5:07:01 PM #

Are you using all in one version?
I am using the same version but all in one and also 64 bit.

Reply

phaze01
phaze01 Canada
4/4/2012 7:59:48 PM #

I came across this too. Realized I forgot to put in the Qemu options.

Reply

rewanta
rewanta Nepal
3/9/2012 5:37:45 PM #

I was able run few commands-tunnel-group, interface level....that works great, would test other nats!!! and update later

thanks very much

Reply

rewanta
rewanta Nepal
3/26/2012 3:56:19 PM #

it works greats!!! thanks for sharing the images

Reply

andrew
andrew United States
3/31/2012 12:02:07 AM #

how did you get it? I spend the entire day trying to run this and  I could not. The ASA starts but the window for configuration continuously stucks. I only try one single ASA based on the configuration above indicated by RAS.

Reply

niranjan
niranjan Bahrain
3/11/2012 8:13:59 PM #

I am using the latest all in one GNS3. I dont know if that is 64 or 32. I will download the 64bit standalone and test it. winpcap and wireshark I can put later on.

I need ASA, IPS and SDM working .

any new guide please do let me know

Reply

iman
iman United States
3/23/2012 10:16:32 PM #

Hi
thanks for your tutorial but could you provide me which version of GNS3 and Qemu do you used?
i can’t used this because i get ‘connection lost’ error each time try to start ASA.
please inform me as soon as you can
thanks in advance

Reply

Maggie MC
Maggie MC Mexico
8/20/2012 12:20:27 PM #

I was getting this same error, but I was not setting the Qemu option right, so I just put it right, and restarted GNS3 once.

Worked for me! Smile

Reply

YinYun Cai
YinYun Cai People's Republic of China
3/26/2012 12:49:07 AM #

www.mediafire.com/download.php?ssadit26tl3llms

or

https://rapidshare.com/files/2538881267/asa.zip


oh!         the two links can not download ?

Reply

Speedester
Speedester El Salvador
4/14/2012 11:57:50 PM #

Iman, for the issue when put your ASA 8.4 in GNS3 just go to GNS3 Preference -> Dynamips and enable sparse memory support.

I can running ASA but when it's loading crashed, if someone can run this version please share the process and configuration.

Visit: http://tecnosystemsv.wordpress.com/

Reply

andrian
andrian Romania
11/28/2012 4:34:16 AM #

thank for "enable sparse memory support"  !!!!!!

Reply

Ganesh
Ganesh India
4/26/2012 1:15:15 AM #

It works......superb
Thanks for sharing..

Reply

nagarjun007
nagarjun007 India
4/28/2012 12:36:43 AM #

Thanx...finally working after following ur steps....But taking too much cpu resouces.
any solution for this??

Reply

lcndkc
lcndkc United States
5/7/2012 11:26:15 PM #

Good evening, I have followed the steps up to #4.  When I launch the ASA via the console option it just stays on the black screen with the last displayed text of:

ata0 master: QEMU HARDDISK ATA-7 Hard-Disk (256 MBytes)
ata1 master: QEMU DVD-ROM ATAPI-4 CD-Rom/DVD-Rom

I know I'm pretty close to having it up and operational.  Please help.  I appreciate it!

Reply

lcndkc
lcndkc United States
5/7/2012 11:42:16 PM #

Nevermind.  I forgot that I closed the box that starts the ASA.  FYI: You need to keep that window open and then console into the ASA.  All is well that ends well.

Hope this helps someone else.

Reply

KK
KK Australia
5/12/2012 11:33:17 PM #


Dear author, you have done a great job sharing the valuable information.
The best site for the security lab tools.

Reply

SIN
SIN Germany
5/23/2012 7:24:27 AM #

Hi guys

Kindly i need to know how i install this ASA on VM...??

Many thanx ...

Reply

Black
Black United States
5/30/2012 7:17:39 PM #

Cant believe my eyes..... it is working like charm.....love you man

Reply

sightlay
sightlay United States
6/1/2012 2:28:59 PM #

I don't think the license works. I can't enable VPN Anyconnect client and can't enable 3des?

Reply

Vikas
Vikas India
6/4/2012 10:36:32 PM #

For those having console problems...

TRY TO CHANGE memory from 1024 to 512... (RAM: 512 MiB and -m 512)

It worked for me.

Reply

AlexanderSupertramp
AlexanderSupertramp United States
6/18/2012 4:46:26 AM #

This works very good! Thanks!

Reply

Mukesh
Mukesh Qatar
6/18/2012 7:29:19 AM #

Can someone please let me know how to enable licence.

4- Activate the licenses using below codes:


activation-key 0x4a3ec071 0x0d86fbf6 0x7cb1bc48 0x8b48b8b0 0xf317c0b5

activation-key 0xb23bcf4a 0x1c713b4f 0x7d53bcbc 0xc4f8d09c 0x0e24c6b6

Reply

pierrot
pierrot France
7/5/2012 3:31:36 AM #

ok, it works !
how do you extract the initrd and kernel image from the asa84x.bin ? the howto for asa802.bin does not work with 8.4 version.
thanks

Reply

sathish damodaran suresh
sathish damodaran suresh India
7/11/2012 1:05:32 PM #

Thanks a lot .. finally i got 8.4


ciscoasa# sh ver

Cisco Adaptive Security Appliance Software Version 8.4(2)

Compiled on Wed 15-Jun-11 18:17 by builders

Reply

Sidd
Sidd United States
7/13/2012 7:46:57 AM #

working great..thanks for sharing.Very helpful

Reply

network security software
network security software United States
8/8/2012 9:35:44 PM #

This is the perfect blog for anyone who wants to know about this topic. The article is nice and it’s pleasant to read. I have known very important things over here. I admire the valuable advice you make available in your expertly written content. I want to thank you for this Informative read; I really appreciate sharing this great.

Reply

Trok
Trok France
8/12/2012 1:37:18 PM #

When I start the ASA via the play button, the qemu windows opens and stays on the black screen with the last displayed text of:

ata0 master: QEMU HARDDISK ATA-7 Hard-Disk (256 MBytes)
ata1 master: QEMU DVD-ROM ATAPI-4 CD-Rom/DVD-Rom

There is no "uncompressing linux image ..." thing

And I when click console, putty opens itself but get stuck on a black screen.

Reply

abc
abc Honduras
8/13/2012 2:00:51 AM #

yes got it working now

Reply

airwolf
airwolf United States
9/4/2012 8:48:28 PM #

I installed GSN3 on windows 7 and it works fined but there is one problem. I can't and unable to save the configuration.
when I issue command "copy run /disk0:/.private/startup-config"
it then return the error "%Error opening /disk0:/.private/startup-config (No such file or directory)"
how can I save the configuration as startup-config?

any help on this really appreciated.

Reply

Maryland_ITGuy
Maryland_ITGuy United States
9/11/2012 3:06:20 PM #

Similar problem as Airwolf. I have the latest version of GSN3 on my 64-bit Windows 7 Operating System, with the above ASA configurations/files. When I enter the copy startup-config disk0:/.private/running-config command, it's prompting %% Non-volatile configuration memory invalid or not present.

I would greatly appreciate help resolving this problem.

Reply

User500
User500 United States
9/13/2012 6:37:43 AM #

I followed the instructions as described above but I get two error message when trying to add tha ASA to the diagram.

1. asa842-initrd.gz seems to not exist, please check
2. asa842-vmlinuz seems to not exist, please check

I have a folder c:\ASA that contains both files.
Can anyone please shed some light  on this issue.

Reply

vicky
vicky Bahrain
10/27/2012 6:54:32 PM #

i have recently bought Apple MAC OS 10.7.5 . and unable to run ASA please guide me how to do it.

Reply

firefly
firefly Vietnam
11/9/2012 7:02:51 PM #

thank a lot

Reply

XiXiIE
XiXiIE United States
11/11/2012 11:02:38 PM #

Cool,
I fond all Internet, only this is correct.
Tank you very much.

Reply

GP
GP India
11/14/2012 3:44:42 AM #

help me please.

when I configure the ASA in GNS3 it works fine for the first time. When I reboot it. ASA is rebooting continuously. Any guess why. I use win7 32 bit. GNS3 ver 0.8.3.1 and latest patch of Qemu.

Reply

gwKid
gwKid United States
11/25/2012 4:41:17 PM #


everything is working fine. I am simulating ASA site to site VPN by using two ASA.

both ASA are working fine. however, if second one is up, it made first ASA down. in other words, somehow only one of ASA is working at the same time.

I used BES just in case in order to lower CPU, but cpu was not an issue.

Reply

Phil
Phil Zimbabwe
1/28/2013 11:02:51 PM #

I have tried to configure the ASA as per the instructions but am getting a message that says connection lost when  i drag the ASA icon onto the work space. What could be wrong with my install ?

Reply

Mustafa
Mustafa Iraq
1/31/2013 12:58:34 AM #

Hi,
Thank you very much for your post.

I've had strange issue:

ASA works fine, but when I am trying to get to the exec mode it is asking me for a password!!!???

Do you have any idea about this?!

Reply

Mustafa
Mustafa Iraq
1/31/2013 1:02:33 AM #

Ok, I found it, no need to enter any password
Smile

Reply

Phil
Phil Zimbabwe
1/31/2013 3:58:00 AM #

Followed the steps up to 4 but when I drag the asa onto the work area, it disappears and a message saying connection lost is displayed.Please help.

Reply

Aj
Aj United States
2/12/2013 4:00:00 PM #

For the activation key, go the config mode# and type "activation-key 0xb23bcf4a 0x1c713b4f 0x7d53bcbc 0xc4f8d09c 0x0e24c6b6 " cheers!

Reply

Aj
Aj United States
2/12/2013 4:02:02 PM #

go to config mode# and type "activation-key 0xb23bcf4a 0x1c713b4f 0x7d53bcbc 0xc4f8d09c 0x0e24c6b6"

Reply

Hani
Hani Greece
4/18/2013 9:17:02 PM #

Thanks for the config. it really nice to work with ASA Firewall on GNS3

Reply

Pingbacks and trackbacks (1)+

Add comment

  Country flag

biuquote
  • Comment
  • Preview
Loading

About the author

Ras is a network/Security professional working on multiple areas with multiple certificates like CCNP, CCIP, CCSP, CCSA, CCSE, LPI, PM, IPv6, ..

Month List