Cisco :: 3500 - WLC QoS Profiles Not Applying Egress

Sep 8, 2011

In regards to QoS profiles on the WLC. I have applied a profile to a newly created WLAN and set the Per User Bandwidth to 512k and it seems to be kicking in on the ingress only, this is supposed to work ingress AND egress or is it just designed to work one way?  I have a 4402-25 with Cisco 3500 AP's and am running the 7.0.98 code. If it is designed to work one way only is there a different way to apply it ingress and egress simultaneously off the WLC?

View 3 Replies


ADVERTISEMENT

Cisco WAN :: Why IP Flow Egress Is Not Functioning On 7600

Jun 2, 2012

why ip flow egress is not functioning on 7600?When I do "sho ip cach flow",  I can see only inbound flows.

View 5 Replies View Related

Cisco WAN :: Egress Queuing On Catalyst 6500

Mar 16, 2012

i have a question regarding egress queuing on cat6500 modules. e.g. WS-X 6704 has 1p7q4t is egress-modell. my goal is to limit the priority queue to 15% of the available bandwidth. i can put weights on the wrr-queues and limit their ressources: "wrr-queue bandwidth 50 20 15 0 0 0 0." but this isn´t possible for the priority-queue. only available command is "priority-queue queue-limit 15" but this only restricts the buffer to 15%.
 
at the end of the day i want to prevent that the wrr-queues don´t have remaining bandwidth when the priority-queue is saturated.
 
is there an easy way to restrict the bandwidth of the priority queue or do i have to implement additionally some kind of policing?

View 5 Replies View Related

Cisco WAN :: 7200 - BGP Multi Ingress / Egress QoS

Nov 4, 2012

I have a question that so far I haven't been able to find a suitable answer for. This is focused from an ISP perspective. So suppose I have the following scenario:
 
I have a BGP transit area. On each edge of the my network I have a e BGP connection to the same client for redundancy. This client has his own ASN, iBGP and prefixes. I'm receiving the same NLRI from the client through both sides. Let's assume he's advertzing the prefix 10.10.0.0/16 through both ends. I'm receiving it with no problems and I'm passing it along to the next providers with whom I also have multiple ingress and egress points.
 
Something like this:
                                                       PROVIDER A                                   PROVIDER A
                                                                 |                                                  |
                                                            eBGP                                             eBGP
                                                                 |                                                  |
CLIENT A (ASN65100) --- eBGP --- MYROUTERA(ASN65200) ----- iBGP --- MYROUTERB(ASN65200) --- eBGP --- CLIENT A(ASN65100)
                                                                 |                                                  |
                                                            eBGP                                             eBGP
                                                                 |                                                  |
                                                       PROVIDER B                                   PROVIDER B
 
Let's say my client pays for a 10Mb. Both links are configured to 10Mb so that each can handle the load in case the other one fails and both are always active. So my question is:
 
How can I shaped or police the client's traffic across multiple points of entry on different routers so that it won't go beyond the 10Mb. The same scenario applies on how can I limit traffic coming from the providers A, and B destined to the client's prefix: 10.10.0.0/16.
 
I don't mean using MED, local-pref, weight. Sure I can funnel all the traffic through one single point, but consider that I'm also trying to move away from basic routing and more into PfR, which mean that I have more granular control of the flows. Perhaps there is a PfR service-policy or something that can work.
 
For this scenario I'm using 7200 as my routers. If there is a solution that assumes any other model don't hesitate to post it. TLDR; How can I police or shape across multi interfaces on different routers?

View 2 Replies View Related

Cisco :: 7204 VXR - IP Flow Not Showing Egress Traffic

Dec 6, 2011

I have a 7204VXR Router, with Neflow. The collection for all interfaces is ok, but one interface (Gigabitethernet 1/0), is not showing the egress traffic in the pictures. The configuration has "ip route-cache flow", ip flow egress, and ip flow ingress set. But, is not showing the egress traffic.

View 4 Replies View Related

Cisco WAN :: C2811 Separate Ingress / Egress Interfaces

Apr 14, 2011

I have a 2811 Router with two fast ethernet wic cards installed. I need traffic to go out one interface, but it's received back through another. Both interfaces have public IP's and the same subnet, and are connected directly to satellite modems. One can receive data / the other only send.

View 3 Replies View Related

Cisco Switching/Routing :: 6500 QoS COS Egress Not Marked

Feb 15, 2012

Problem: My traffic coming inbound appears to be marked but is not marked when egressing.

Setup:
Ingress from encoder G3/9->> Egress G8/1Default DSCP/COS map table (DSCP 24 is COS3) 
Cos-dscp map:
cos:   0  1  2  3  4  5  6  7
------------------------------------
dscp:   0  8 16 24 32 40 48 56
 
1. Any reason COS 3 is not marked outbound on this traffic? I'm determining this by doing a wireshark off of interface g8/1. The traffic appears to be marked on the ingress correctly but does not maintain its mark on the egress. I can confirm this with equipment on other Ethernet links in produciton as well as my test port listed in the config below with wireshark.
 
FYI: Unfortunately with my cards in the 6509 I cannot port mirror and see outbound multicast (determined through a TAC case). Because the STB does not understand tagged traffic I setup the native vlan for it to function. To see the multicast with tags I temporarily remove the native command and do the wireshark to see the multicast. It still shows a COS setting of 0. I will try to attach a capture of a multicast packet.
 
interface GigabitEthernet3/9 description Mulicast Encoder
switchport
switchport access vlan 962
switchport mode access
logging event link-status
load-interval 30

View 2 Replies View Related

Cisco Firewall :: ASA 5510 - Failed To Locate Egress Interface?

Jul 22, 2012

having a bit of trouble setting up our 5510.  None of us have ever played with a firewall before.  We've got most of the basics covered.  I was able to get to the outside world to do a software update to the box, but my laptop that sits in the inside can't see the outside.  We only have the default access rules in place at the moment.  Our old ISA firewall rules don't really translate all that well to this new box.

View 2 Replies View Related

Cisco Switching/Routing :: 3560 Egress Policing And Classification

Jan 17, 2012

I have a customer who requires to identify and police traffic on egress on a 3560 trunk link.  I cannot use ingress classifications because we do not know what route the traffic will take yet.  The egress interface connects to multipoint wireless equipment with 4 different bandwidth point to point links. So the ingress traffic may be routed via any one of 4 point to point wireless links connected to the single egress interface.  Am I correct in assuming we cannot mark on the egress direction then put the traffic in a SRR shaped egress queue based on the marking ? So we would only have the option to egress queue based on markings applied or trusted on the inbound direction ? I had thought of some kind of policy map/aggregate policer configuration based on the exit VLAN but it seems we can only apply this type of config inbound. From reading the 3560 configuration guides it seems the 3560 cannot deploy the kind of requirements this customer needs.  Perhaps they should have deployed some kind of Metro switch ?

View 1 Replies View Related

Cisco Firewall :: ASA 5510 - Failed To Locate Egress Interface

Mar 9, 2011

I have ASA 5510 with 8.3 version and using multi context. I created a new context ABC and tryed to add routes in the context for the ABC networks it would not work.  There was an error in the log stating, “failed to locate egress interface”.  I changed the metric on the static routes from 1 to 2 and it started working.  Is it normal in a multi context?

View 4 Replies View Related

Cisco Firewall :: ASA 5505 / Failed To Locate Egress Interface For TCP From DMZ

Apr 9, 2013

I have ASA 5505, in routed mode, basic license.I run a web server in DMZ. I can reach Internet from DMZ. Also, the trafic from outside can reach the web server. However, if the web site is requested from within the DMZ, the request will fail, and the firewall log contains the following message:
 
Failed to locate egress interface for TCP from DMZ50: 30.30.30.10/49213 to 170.70.30.114/80 

I don't have DNS, so the request must go to Internet, even the web site is hosted on the server in DMZ.

Here is sample of my config file:

interface Vlan1
nameif inside
security-level 100
ip address 162.160.1.3 255.255.255.0
!
interface Vlan2

[code]....

What can be the reason for requests, originated in DMZ, to fail, and how could it be fixed?

View 1 Replies View Related

Cisco Switching/Routing :: 3750 Auto-QoS Egress Discards

Dec 18, 2011

I have an issue where I'm seeing output discards on pretty much all my ports configured for QoS. The switches are cisco WS-C3750V2-48PS running 12.2(50)SE1. There are four switches stacked using stack cables. The QoS implemeted was auto-qos with no modifications to the standard config. All ports are in queue-set 1. The phones connected are Cisco 7942's. Already did the standard check for speed duplex mismatch, crc's, runts, giants, etc...No discards before the QoS was applied. No bug ID's I could find regarding these switches and this IOS version. The one thing noticed is that 99% of all the drops are from queue's 2 and 4 or 1 and 3 doing the below command.
 
**I've limited the cut and paste as to not clutter the discussion until someone requests something else**
 
show platform port-asic stats drop
Port 18 TxQueue Drop Statistics
  Queue 0
    Weight 0 Frames 0
    Weight 1 Frames 0
[Code]....

View 5 Replies View Related

Cisco :: Number Of RF Profiles On 5508?

Feb 17, 2013

I've searched the release notes for 7.2+, but I haven't found a documented number of how many active RF Profiles a 5508 can support. Any limitation of how many RF Profiles they can have?

View 3 Replies View Related

Cisco VPN :: Disable VPN Profiles In ASA 5550

Feb 11, 2010

I need to disable approxematly 40 different VPN profiles in our ASA5550`s without deleting them (need the ability to quickly activate them again if needed). I thought maybe i could disable IPSec for those profiles, but since the IPSec is an attribute for Group Policy, i cant do it - as many other profiles are sharing the same policy.

View 2 Replies View Related

Cisco VPN :: ASA And ACS 5.3 Multiple VPN Profiles For One User

May 21, 2012

I have a question about ACS 5.3 and ASA VPN profile authorization. I am not sure if it is possible to allow one single user for a set of VPN profiles on ASA, let's make an example:ACS 5.3 group hierarchy:VPN users global should have access to VPN profiles A, B and Z (here we create an authorization profile with no class an no lock attributes, so the group is allowed for all VPN profiles),VPN users A should have access to VPN profile A (here we create a authorization profile with class and lock attributes for profile A),VPN users B should have access to VPN profiles B and Z (is this possible and how does the authorization profile have to look like?)

View 3 Replies View Related

Cisco :: Lobby Ambassador Profiles In ACS 5.3

Jul 14, 2012

We've set our WCS up to do AAA through our ACS 5.3 which works great. So in order to log into the WCS for Administration or as a Lobby Ambassador (to create guest users etc) the AAA is all done by the ACS, GREAT!
 
I have assigned a set of users the Lobby Ambassador role as passed that back through TACACS to the WCS, so those users have their role setup as Lobby Ambassador and are limited from doing anything else, as expected.
 
What I want to know is: With normal local AAA on the WCS, when you created a Lobby Ambassador account, you could give the account a set of defaults for any guests accounts created by that Lobby Ambassador account, which was good, so Lobby Ambassadors couldn't set up unlimited time accounts and stuff like that.
 
What I want to know now is that since I'm now doing all the AAA on the ACS, is there an attribute I can pass to the WCS in the Shell Profile, along with the roles etc telling the WCS what the guest user creation defaults for the Lobby Ambassador account is, so that we can continue to limit the defaults of any guest account that the Lobby Ambassador accounts create, as it used to be? We'd really like different lobby ambassadors to be able to do different things as well. i.e., Lobby Ambassador X can only create accounts for one region. Lobby Ambassador Y can create Unlimited time accounts where the others can not. We used to do this by assigning different guest user creation defaults to different lobby ambassador accounts on the WCS.

View 1 Replies View Related

Cisco VPN :: One User Associated With Two VPN Profiles ASA 5510

Apr 3, 2011

Is there a way that i can associate one user with two VPN profiles. Now here is the scenario.Our company has bought a win 7 64 bit pc for some of the employees , so i had to create anyconnect. But the same users are also connecting via normal cisco vpn client. they will give away these old pc but for the time being my need is that both users shall connect to anyconnect profile and ipsec profile.

I tried ti to assign same profile with both ipsec and svc so that they could use single profile but anyconnect didn't work. I am having cisco ASA 5510 as VPN gateway.And How many licenses does cisco asa have by default for anyconnect users. Here is the configuration for anyconnect
 
group-policy Broad_Anyconnet internalgroup-policy Broad_Anyconnet attributes dns-server value 4.2.2.2 vpn-tunnel-protocol svc webvpn split-tunnel-policy tunnelspecified split-tunnel-network-list value Nit_Broadcast_Network_Tunn_ACL address-pools value Broadcast_AnyPool webvpn  svc ask none default svc
 [Code]...

View 5 Replies View Related

Cisco WAN :: 7200 - Egress Netflow V9 And Output Packet Marking Order

Aug 17, 2011

when using egress netflow (v9) and output marking.
 
The topologie : Server <-----> R1 1>-----<1 R2 2>----<2 R3
 
R2 is a 7200 with c7200p-adventerprisek9-mz.124-15.T11.bin What I'm doing :- R2 forwards ping packets from Server to R3. When they arrive on R2, icmp packets are marked with CS3

- I change the DSCP to CS4 on R2 before forwarding packet to R3. I'm using for that an output service-policy on the R2-2 interface like this : interface ATM2/0.36 point-to-point

ip address 192.168.1.1 255.255.255.252
ip flow ingress
ip flow egress

[Code]....

View 3 Replies View Related

Cisco Wireless :: WLC 2504 / Group APs To Get Different Profiles?

Aug 21, 2012

Is there way to group APs to get different profiles. I need to have some that have the 2.4GHz turned down and some wiht the 2.4 and 5.0 GHz on.

View 7 Replies View Related

Cisco VPN :: Adding User Profiles In AnyConnect VPN 2.5

Feb 15, 2012

I recently upgraded to Windows 7 in my company and the OS came bundled with Anyconnect VPN client version 2.5.
 
In the earlier version I used to add user profile using a .pcf file by importing it into the client to access customer LAN.
 
But in the Anyconnect VPN client I dint find any option to import the file. The IT support has told to edit the xml file to add it. The problem is I even after i edit the anyconnect-cert.xml with changes in host name and host address tags  I am not able to start a connection. I dont knw know exactly what address must be given in Host address tag. I copied the host address from .pcf file which i used earlier.
 
Whether I will be able to add a user profile in this way or any correction is to be done in the whole process of adding the user profile,

View 1 Replies View Related

Cisco :: WLC 4402 / Can Use ISE Server And Make Profiles

Jun 13, 2012

Customer has a WLC 4402 and 21 AP's LAP1131AG, there is a PDA wlan created to give PDA's and wireless Phones access to the webmail. This is done by access lists and firewalls. Now the customer wants more access to the internet in this PDA wlan, maybe in a later phase to the other vlans, can we use an ISE server and make profiles, is this the only additional server that we need or is an upgrade of the WLC and ÄP's also needed.

View 1 Replies View Related

D-Link DCS-942L :: How To Switch Profiles

Dec 18, 2012

I just bought new 942L (HW Rev3, 1.12 FW) and the only profile which is used to stream to iPhone or Web browser in mydlink is profile 3 which is limited to JPEG. Is there some way how to change the profile to be used for streams or is there a way how to make to profile 3 something else then JPEG?

View 1 Replies View Related

Cisco Switching/Routing :: Configure Egress Netflow In 6500 (VSS) With VS-S720-10G Supervisor?

Jun 9, 2013

I'm trying to configure a egress netflow in a 6500 (VSS) with VS-S720-10G supervisor. I foud some old posts and understood that netflow wasn't supported on 6500 but i found a new document and it seems that netflow is supported in Supervisor Engine 2T:[URL] Does the netflow still not supported in VS-S720-10G? It's weird because the command is supported:
 
#sh run int vlan 4
Building configuration... 
Current configuration : 353 bytes
!
interface Vlan4
ip address X.X.X.X 255.255.0.0

[cod]....

View 1 Replies View Related

Cisco Switching/Routing :: Net-flow Not Reporting Egress Traffic On 6509 Vlan

Nov 27, 2011

We have a pair of 6509 working in a VSS configuration (IOS 12.2(33)SX5). The 6509s connect to a pair of ASAs (7.2 code) running in an Active/Standby setup. These ASAs in turn connect to routers going to remote sites. I have configured Netflow on the following VLANS,
 
VLAN 10 - Servers Vlan
VLAN 9 - Transit/ASA VLAN (connects ASAs to 6509s). All traffic originating from any VLAN on the 6509 crosses this VLAN in order to reach remote sites and vice versa
 
I configured the netflow source VLAN 11 although I am not collecing any netflow from it.Although I have been getting lots of Netflow info, I noticed that netflow for traffic originating from any user VLAN on the 6509s going to any remote site via TRANSIT/ASA VLAN(9) does not get reported, I even tested with 4 GB traffic but no result. Only reverse traffic (i.e. from remote site to user VLAN) is reported as it traverses the Transit VLAN (9).
 
I read somewhere that egress netflow is not supported in 6500, but isnt traffic originating from a user vlan to a remote site via the transit VLAN (9) considered ingress with respect to the transit VLAN (9)? I would like to know whether bidirectional Netflow is supported on 6500 VLANS. I have mimimum control on routers beyond the ASAs, and since these ASAs run 7.2 code netflow is not supported, and Monitoring this Transit Vlan gives me extremely useful info.
 
I do get netflow biderectional traffic from the Server Vlan 10, but I think it is correlated by the netflow collector from vlans 9 and 10. [code]

View 9 Replies View Related

Cisco AAA/Identity/Nac :: Network Access / Authorization Profiles ACS 5.4

Apr 17, 2013

For ACS 5.4: In Network Access -> Authorization Profiles there is a Permit Access profile. If you try to edit it a message pop's up that says: "The profile you have selected is reserved and cannot be deleted or modified". What this profile contains in its rule base? If I wanted to create a similar profile what Common Tasks, or Radius Attributes would I need to use? The same would go for a Deny Access profile. I have looked at the Common Tasks and Radius Attributes for a new profile and it doesn't seem very intuitive.

View 2 Replies View Related

Cisco VPN :: ASA 5510 - AnyConnect VPN Multiple Connection Profiles?

Nov 9, 2011

I use a Cisco ASA 5510 with the AnyConnect VPN for remote workers. Now we want to give access to a select group of consultants who only need access to one sever and block everything else.
 
I was thinking this could be done by creating a separate AnyConnect Connection Profile on the ASA. From that new connection will come a new GroupPolicy with a ACL to only allow access to the one system. That GroupPolicy will point to the Radius Server looking for an account in a specific MemberOf group.
 
My question is - Could you explain how the ASA knows what Connection Profile to use when a user tries to authenticate? Does it automatically hunt down each Connection Profile until there is a username match via RADIUS in the Connect Profile?

View 1 Replies View Related

AAA/Identity/Nac :: ACS 5.41 Same Username With Two Different Group / Shell Profiles

Mar 23, 2013

In my ACS 5.4 I want to have same useranme to use two shell profiles. Here is the requirement.One shell profile with privelege 15 for IOS device admin and other one with different privelege for WCS admin.As there can't have two shell profiles on the same authroization profile, I created two different profiles, and match with the ACS local group name. However whenever user tries to access it always hits the 1st profiles.

View 3 Replies View Related

Cisco :: WLC 4402 / Order Of WLAN Profiles In AP Group From MIB Files

May 19, 2009

WLC Model
---------
WLC 4402
 Software Version
----------------
5.2.178 
Problem Statement
-----------------

Do we have any Cisco WLC MIB to get WLAN profile (Order in which WLAN profiles are added inside an AP Group) information present in an AP group?

View 3 Replies View Related

Cisco VPN :: 5510 - Separate RADIUS Profiles For SSLVPN Group

Sep 11, 2012

We are starting to deploy SSL VPN in our company and we recently purchased two ASA 5510 firewalls. I have already completed the initial configuration but I do have some inquiry on how to have it configured properly.
 
1. Employees and clients will access the URL
2. They will select the appropriate group on where they should login.
3. Enter credentials, etc.
4. Username/Password authentication is via RADIUS. The usernames were all created in Cisco ACS 5.3.
 
My challenge is, we have several clients and all their usernames were created in ACS5.3. Meaning if the configuration is just being differentiated by group settings, clientA can select the profile of clientB and still get authenticated. If that happens, they will be able to access the resources of each other. Also in the future, we will be deploying 2-Factor authentication for some of our clients.

View 4 Replies View Related

Cisco VPN :: ASA 8.2.x / Assigning AnyConnect Client Profiles Based On The Machine?

Mar 3, 2010

I have an ASA running 8.2.x code with AnyConnect 2.4.x.I have both Radius and LDAP (AD) AAA available.If a user connects from a company owned laptop, I want to push down AnyConnect client ProfileA (with scripts to map drives etc...) and network ACL's set A.
 
If a user connects from any other computer, I want to push down AnyConnect client ProfileB (no scripts etc...) and network ACL's set B.
 
What I would like to do is CSD to do a machine certificate check (for presence of a cert from my private CA) and to assign a EndPoint Policy attribute (Managed on successful check or Unmanaged on failure). I can then use DAP to tailor the ACL's that get set.
 
It seems like the only way to handle AnyConnect client profiles is with Group-Policy. Using LDAP I can assign a user to a Group-Policy, but I have no way of determining is they are coming in from a company laptop or not when assigning the Group-Policy. DAP can not assign an AnyConnect client profile.
 
If at all possible, I do not users to have to pick a conenction profile or use different URL's.

View 1 Replies View Related

Pending - Windows 7 And XP Profiles On Server 2003 Environment?

May 16, 2011

i have recently added to a domain. The initial setup is a server running windows 2003 and several xp machines which logon to the domain using mandatory profiles. However, after adding windows 7 machines and logging them on to the system it doesnt load the profiles. (which is fine as I understand you cannot use the same profiles with windows 7+xp)The problem is it automatically creates a roaming profile when logging off and saves it back to the same path as the other profiles under user.V2 which is growing considerably and causing huge logoff and logon times.How can I get the windows 7 machines to not attempt roaming profiles back to the server and instead to just save the profiles locally when logging off.

View 14 Replies View Related

Cisco Firewall :: 5510 - AnyConnect Client Profiles Not Replicating To Standby ASA

Jan 18, 2012

We have 2 ASA 5510's running in a Active/Standby configuration.  It appears that most of the changes we make on the active unit are replicated to the standby unit.  However, there are 3 AnyConnect Client Profiles on the active unit and none of them show up on the standby, the standby has no AnyConnect Profiles.  We also have 1 OnConnect script on the active unit and it does not appear on the standby unit either.
 
I was under the assumption that all config items on the active unit would replicate to the standby.  Is this not correct?  Do I need to do something extra to get everything replicated?  Are there other items that do not replicate? 

View 3 Replies View Related

Cisco AAA/Identity/Nac :: Acs 5.2 Unable To Launch Common Task On Authorization Profiles?

Feb 15, 2013

I have recently installed acs5.2 evaluation on a vmware and i can't launch common task on authorization profiles when i click on it i have the bellow message javascript:cuesToggleTab('NetworkAccess',1,false,false

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved