Courseiva
Cisco ASA · Firewall & VPN Reference

Cisco ASA Command Reference

67 ASA commands covering NAT, VPN, ACL, firewall policy, and high availability. Essential for CCNP Security and Cisco firewall administration.

VPN (IPSec / SSL)

15 commands

anyconnect enable

Enables AnyConnect VPN access on the ASA for a specific group policy or tunnel group.

WebVPN Config

anyconnect image disk0:/[filename]

Specifies the AnyConnect client image file to be used for SSL VPN connections on the Cisco ASA.

WebVPN Config

authentication pre-share

Configures pre-shared key authentication for IKEv1 policies on Cisco ASA Firewall.

IKEv1 Policy Config

crypto ikev1 enable [intf]

Enables IKEv1 (ISAKMP) on a specified interface for IPsec VPN negotiations.

Global Config

crypto ikev1 policy [priority]

Configures an IKEv1 policy with a specified priority for IPsec VPN negotiations on Cisco ASA Firewall.

Global Config

crypto map [name] [seq] match address [acl]

Associates an access list with a crypto map entry to define which traffic should be encrypted for an IPsec VPN tunnel.

Global Config

crypto map [name] interface [intf]

Applies a crypto map to an interface to enable IPsec VPN policy on that interface.

Global Config

encryption aes-256

Specifies the AES-256 encryption algorithm for IKEv1 policy to secure VPN tunnels.

IKEv1 Policy Config

ip local pool [name] [start]-[end]

Creates a local pool of IP addresses for VPN remote access clients to be assigned dynamically.

Global Config

pre-shared-key [key]

Sets the pre-shared key for IKE authentication in an IPsec tunnel group on a Cisco ASA firewall.

Tunnel Group IPsec Config

show crypto ipsec sa

Displays the current IPsec security association (SA) database, showing active tunnels and their parameters.

Privileged EXEC

show crypto isakmp sa

Displays the current Internet Key Exchange (IKE) Phase 1 security associations (SAs) on the Cisco ASA Firewall, showing the status of ISAKMP negotiations.

Privileged EXEC

show vpn-sessiondb

Displays detailed information about active VPN sessions on the Cisco ASA Firewall.

Privileged EXEC

tunnel-group [peer-ip] type ipsec-l2l

Creates or modifies a tunnel group for IPsec LAN-to-LAN VPN connections on Cisco ASA.

Global Config

webvpn enable [intf]

Enters WebVPN configuration mode and optionally enables WebVPN on a specific interface.

Global Config

NAT

9 commands

ACL

5 commands

Firewall Policy

2 commands

Interfaces

6 commands

Routing

6 commands

High Availability

6 commands

Security

6 commands

Diagnostics

8 commands

System Management

4 commands

Prepare for CCNP Security

ASA commands down. Test your firewall knowledge with CCNP Security-style practice questions.