Cisco :: Configuration Management In LMS 4.1 Is Not Working?
Jan 9, 2013I need to archive the configuration for the devices but it states that SSH fails to authenticate although I have checked the credentials many times.
View 1 RepliesI need to archive the configuration for the devices but it states that SSH fails to authenticate although I have checked the credentials many times.
View 1 RepliesI'm using LMS 4.0.1 (current patches and device packages)
There is a problem with the configuration fetch.There are some 2503 routers with IOS 11.3(6) and the message on LMS is: Couldnot enter ENABLE Mode from USER Mode on Device
The devices arn't configured with username, only telnet pw and enable pw; no access-lists or other limitations configured
The credential check is ok ... multiple checks done ... devices deleted, new discovery ... devices deleted and manually added .... with the link //serverip:1741/rme/rmedevices.do I've changed the timeouts multiple times (up to 60 seconds for TFTP, SNMP) .... all these have had no effect of the config fetch
I would like to configure a Management ip address on 6500 by giving ip to the SVI. Following is the configuration done
1) int vlan X
ip address 10.1.1.1 255.255.255.0
no shut
However i am not able to reach this Switch IP from other subnet's. for ex:- 192.168.1.0/24.What next configuration should be done, in order to make this work. I dnt want to use any routing protocol.
in lab trying to run a test upgrade of an Ace30,can seem to get it right ace30 is in slot 1 of the 6500, management vlan 10
View 4 Replies View Relatedi am currently trying to use LMS 3.2 Compliance management to verify and alter our access port configurations for 802.1x. Below is our current configuration
View 1 Replies View RelatedI am just going to deploy some new 4900Ms for a customer. Want to know if configuring management for 4900 (everything like NTP, AAA, SNMP , DNS ) is doable through management interface in management VRF and there are no caveats to be aware of.
View 1 Replies View RelatedI am working to configure AP541n AP, is able to connect to the AP wired, assign AP static IP with proper subnet mask & default gateway, when it's done, everything looks perfectly, but since I changed the management VLAN ID from 1 to 2, I can't even connect to the AP wired from the PC, why does the change matter?
View 2 Replies View RelatedI am looking at management (backup of the configuration) of the ACE 4710 running A4.1, the management software is Cisco Cirrus. The question I have is around the management of the context's, I have a backup of the Admin but would like the user context's also, how this is completed.
View 3 Replies View RelatedI am just going to deploy some new 4900Ms for a customer. Want to know if configuring management for 4900 (everything like NTP, AAA, SNMP , DNS ) is doable through management interface in management VRF and there are no caveats to be aware of.
View 1 Replies View RelatedI've got a new 5508 wireless lan controller and can ping the ip address of the management interface, but can't access the GUI at the management interface's ip address. I can access the GUI on the service-port interface. No static routes in the controller; trunk appears to be set up correctly.
View 5 Replies View RelatedI am setting up a 3 host ESXi cluster. I am using a pair of stacked SG500-28 switches for switching redundancy. Each host has 8 NICs. 4 to each switch. I have successfully setup a 3 NIC LAG with 1 path to one switch and 2 paths to the other. These LAGs work. When I setup a 2NIC LAG via the console for management, and the associated ports on the switches, I lose managment communication with the host. Before setting up the LAG in the ESXi console, I set that vswitch properties to us IPHASH as instructed here bit.ly/VLaTEt I have attempted to follow those instructions as closely as possible. The one thing that I am wondering is whether the SG series supports etherchannel. I can't find any reference. Either way, it works on the other vswitch that is for vMotion. I can vmkping between the hosts over that LAG. But setting up a LAG on the management vSwitch doesn't?
View 5 Replies View RelatedI have a RVS4000 hardware v2 with firmware 2.0.2.7. I have a DSL modem in bridge mode and have the router set to PPPoE. Everything works fine except I want to use QOS which doesn't work fine. I have some vonage boxes set up on a switch set to port 1 trust mode is set to port and level 4 for highest priority. Port 2 I have on another switch set to priority 3. I tried turning bandwidth mangement on which doesn't seem to work at all so I don't even know if they QOS is even working. I set the max down stream and upstream provided after running a number of speed tests and setting it a little lower than my worst speed results. Once I did that I set up a rule for all traffic for rate control and set them just below the min and max I put in for isp bandwidth. I set the ip range from 192.168.1.100-190 this will cover anything that dhcp hands out and I also have a few statics set up on 192.168.1.180 and 181. However after enabling it I ran some speed tests and I still get full speed and the rules seem to be getting ignored.
View 2 Replies View RelatedWe have a Service Policy rule setup on our 5510 for SMTP traffic.
Problem is, this week someone sent a larger email 20+mb to dozens of recipeints and the outside interface was hitting 10mb, which is not what I would have expected with this rule in place, so I'm questioning the configuration. We know it was email because I disabled the server that receices our outbound mail to apply a signature and the traffic dropped immediately.
I can access the admin pages from inside the network.I can access the admin pages remotely from my iphone (safari).If I try and access them from my PC at work (IE6 or Google Chrome), I can access the router, give the password and get the status screen. But if I try and go to any other page on the router, it asks for the password again and takes me back to the status screen.I have Hardware B1 and firmware 2.0 (not upgraded it yet).
View 1 Replies View RelatedI recently picked up a Catalyst 2960G and am trying to get SNMP management working over IPv6. I have the IP Address set to the local link, and can successfully ping and telnet to the switch (so the network can get traffic to and from the switch). However, SNMP packets just seem to disappear. I am running WireShark on my machine, and I see the packets go out to the proper IP, but nothing comes back. When I check "sho ipv6 traffic", I can see where there are UDP packets that are received, but, again, none going out. Also, when I run "sho snmp", all of the packet counts are 0.
Here are some relavant snipets from my "sho run":
interface Vlan1
no ip address
no ip route-cache
ipv6 enable
[code]....
I have a new 5508 that I am setting up. My first one from scratch.
Interfaces:
managment -> 10.10.10.10 ->dhcp 10.10.10.1
voice -> 10.10.7.1 ->dhcp 10.10.10.1
guest -> 192.168.1.2 ->dhcp 192.168.1.2
Local DHCP (via the 5508) is for the guest network while the management and voice use the Windows DHCP server.
My problem, Voice and guest work fine. I have two SSID's (one 802.1X and the other PSK) that use the management interface that will not get an IP. I have enabled dhcp proxy from the cli on the controller. I tried with the management VLAN tagged and untagged.
We have several pairs of ASA5510s in failover A/P mode, some running 8.3(2) and others running 8.4(1).
e0/0 = outside
e0/1 = inside
m0/0 = management
The problem we're having is we can't get anything to route out of the management interface unless we put in a static route at least to the subnet level. For example, we want syslog traffic to exit out m0/0 to our syslog server 10.71.211.79. Our 'gateway of last resort' points to the next hop out e0/0, and a second static route with a higher metric and a more distinct network space is for m0/0 as in:
route outside 0.0.0.0 0.0.0.0 192.168.49.129 1route management 10.72.0.0 255.255.0.0 10.72.232.94 10
This doesn't work, and ASDM loggin gives this error: ".....Routing failed to locate next hop for udp from NP Identity Ifc:10.72.232.89/514 to management:10.72.211.79/514"
If I put in a more granular subnet route, or a host route of the syslog server it works, such as:
route management 10.72.211.0 255.255.255.0 10.72.232.94 10 <------------- this works
route management 10.72.211.79 255.255.255.255 10.72.232.94 10 <------------- this works too
Why won't a static route for 10.71.0.0 255.255.0.0 work in this case?
We are going to have numerous hosts access and be sent messages though the management interface of these ASAs, and it would be very burdonsome to have to add a host, or even a subnet, route for every one. I've removed all static routes and tried to rely on EIGRP, but that doesn't work. I also had to put 'passive-interface management' under the EIGRP for this to work.
Here is the pertinant ASA config concerning syslog, routing, and interfaces:
interface Ethernet0/0 nameif outside security-level 0 ip address 192.168.49.140 255.255.255.128 standby 192.168.49.141 !interface Ethernet0/1 nameif inside security-level 100 ip address xxx.xxx.xxx.xxx 255.255.255.128 standby
[Code].....
I have a 6 month old RV042 with the newest firmware (v4.2.1.02). Over the weekend I configured the DMZ which after a lot of trial and error, was able to get working. Prior to configuring DMZ, I was able to log in with remote management. However now remote management no longer works. I've tried:
- Rebooting the router
- Turning the firewall off/on
- Turning remote management off/on
- Changing the remote management port
The only step I haven't taken is resetting the router back to factory defaults and trying to reconfigure it all again. This router is so finicky I have no faith I'd be able to get my current functionality back again.
After I have upgraded our ASA 5510 to 8.4.2 I have problem with the management interface.Our former firmware 8.2.3 had no problem using the management interface as a DMZ zone, but after we upgraded to 8.4.2 we can't make it work.The interface and the protocol is up, when I type: show interface.But when I ping the interface from a computer connectet to the interface, nothing happens.
Even the logging shows nothing.
Region : Malaysia
Model : TD-W8968
Hardware Version : V1
Firmware Version : 0.6.0 1.1 v0005.0 Build 120926 Rel.27100n
ISP : TM
The Remote Management Port is not working correctly. For whatever port I set, it will uses port 80 to access.
This is the RVS 4000
Firmware version 1.3.3.5
STAR 9202 Chipset
64 MB DRAM
8MB Flash
DOS, Block WAN Rq, Remote mgmt all OFF
IPSec Tunnel none used
[code].....
Every day or so the Router becomes unresponsive to the HTTP mgmt interface, as well as it no longer offers DHCP services.then this happens the only remedy is to power reboot.
Everything comes back online just fine, however, the LOGS are initilaized so no data to figure out what`s going on.My next step is to setuo a syslog server and have the logs copied out.( No, I have no Torrents running at all, but I do have several devices like AppleTV, PS3s etc that run streaming Video plus I have the SPA3102 )
why the following configuration is not working? I have two clustered ASAs inline from one another, in front of a 4506-E switch in front of a host I want to access via RDP, like so: My issue at this stage lies with getting the UNTRUST firewall configured. I've tried the following configuration 1) Creating the host.
View 13 Replies View RelatedI would like to configure a cisco ASA5505 IPSEC VPN. I used the wizard and tried to connect to the outside .. does not work .. The network is configured in this manner: - ADSL router with public address and internal address 192.168.2.1 -> firewall interface inside and outside 192.168.2.2 192.168.3.1 (my network is 192.168.3.0). I used a VPN to the pools ranging from 192.168.4.1 to 192.168.4.100.
INTERNET ----- ROUTER ------ ASA5505 -------LAN
What should I change? there could be problems between the router and firewall?
I have bought a 861w to replace my 877w. We switched from telco(ADSL) to Cable due to faster speeds for up and down. My current physical setup is as such. Cable modem is a straight trough with 4 lan port in the back. Al lan ports are configured by the cable company for my assigned public ip’s. (24.x.x.2 through .6 – 255.255.255.x) I also have my assigned gateway as 24.x.x.1
My goal is to setup the new router same as the old one so all interfaces (e0 to e3) use a Vlan1 and Bridge Bvi1 to get the traffic go through e4 which is my WAN port on 861. I am not even concerned abt the wireless because I can’t get this to work. I am attaching the running config on the old 877 and 861 so you all can see what it was and what I am trying to do. As of now I am so confused that my head is spinning……I am able to ping out and ping e4 from outside but I am not able to connect any pc’s or node and connect to net from inside on any of e0 to e3.
my problem in configuring a cisco 1841 as VPN server using SDM, everytime i press Lunch Easy VPN Wizard botton, there were no response at all. my IOS is:
Cisco IOS Software, 1841 Software (C1841-ADVIPSERVICESK9-M), Version 12.4(15)T15, RELEASE SOFTWARE (fc3)
ROM: System Bootstrap, Version 12.4(13r)T, RELEASE SOFTWARE (fc1)
System image file is "flash:c1841-advipservicesk9-mz.124-15.T15.bin
by the way I took this IOS to other router with the same model(CISCO1841).
I am having a wierd case, where in i have a 5520 and i am not able to ssh into that firewall. When did a capture on that firewall it shows my connection is getting reset as soon as i try to ssh into the box. Given below is the config for ssh into the firewall.
!
ssh 10.252.253.0 255.255.255.0 inside
ssh 10.114.255.240 255.255.255.255 inside
ssh 169.2.162.75 255.255.255.255 inside
[Code].....
I grew tired of entering my username and password in my 2500 series lab router. So I removed authentication by typing "no username xxxxxx password xxxxxx".Different than what I expected (removal of authentication), the router still prompted me for my username, it just won't accept anything I type.
I decided to do a password reset, I changed the register to 0x2102 and then typed "i" for Initialize. It comes back with error "Configuration from version 12.0 message may not be understood correctly." and then boots to running config with a prompt for username again....right back where I started.
why removing authentication by just typing "no username xxxxx password" would lock me out?If I am actually locked out or maybe there is another way to access?
A new industrial control system uses 891K9's, an existing system uses 1811K9's. We are using (1) 891 per identical machine group w/NAT to translate to translate identical IP's/ports in each group (LAN side/inside) to unique IP's in another subnet (WAN side/outside) (Port forwarding). At the office I tested an 1811 config. in a new 891 and was able to connect to a piece of the equipment on loan for this test. Communications were good, no issues.
Onsite, the 891 is able to establish communications & all is well for about 15 minutes, then comm's fail and I lose comm's. I've done this on many systems with the 1811 but cannot get the 891 comm's to remain on.
Attached is the Router config. used. My PLC (outside device) is looking at the Router FE8 WAN address and inside device static IP/logical port in the LAN, through theLAN ports to the machines switch/hub where the devices connect.
Is there a config. detail that needs to be in the 891 that the 1811 didn't need or have? I use the blue cable w/Hyperterminal/CLI to copy/paste the config files into the Routers. I use "Write erase", "Reload", "enable" then paste to host in Hyperterminal and the config self loads. No issues with that procedure, logging in to the new Router config, etc.
We have a configuration that work fine but one of the combinations it don´t work. When we connect a guest laptop, the first time work fine. The configuration is when the laptop don´t authenticates with radius, the dhcp server assigned vlan guest and ip guest. The first time was ok. After, We connect a laptop with users authenticates work ok, the radius asigned vlan of users and dhcp server assigned ip users. The problem was when we connect for two time a guest laptop, radius didn´t validate and laptop didn´t negociate ip with dhcp server. In this time, the administrator of dhcp server, tell us that they didn´t see nothing traffic of my mac. and anymore run fine. If Whe change the port of switch , the laptup start working again.
Radius=NPS
Server dhcp: is typical.
Our scenario is with a ip cisco phone. the ip phone don´t have the authentication. The administrator of radius tell us that the configuratation is fine and the configuration of dhcp is fine. When we connect only laptop, everything run ok.
Configuration Port.
interface GigabitEthernet1/0/3
switchport access vlan 202
switchport mode access
[Code]...
I live in a college dorm room, and my internet stopped working about 2 days ago. My roommates don't have this problem. I don't know what kind of details to give you because I know nothing about this stuff.
Here's my ipconfig /all.
Windows IP Configuration
Host Name . . . . . . . . . . . . : silvery-snow
Primary Dns Suffix . . . . . . . :
[Code]......
I don't know how to copy / paste the ip config so I ss'd it:(url) internet provider is RCN, I have AVG and Malwarebytes installed, I've tried disabling them both and didn't fix it! Anyways my internet was working fine, until one day it just suddenly stopped working. We have multiple computers hooked up to the network (5) and all work except mine. This same problem happened to my sister's computer, she has almost the same model as mine. We fixed it by switching it to wireless, but I was wondering if there was any way around that. It's a HP Pavilion. The box thingie lights up green and everything. I can access the other computers through the network, it's just the internet that won't work.
View 3 Replies View RelatedI was changing the port forwarding configuration when suddenly the router stopped working, and now the "D-Link" light is constantly on, and the power light and the 4 LAN lights are flashing. Nothing worked, resetting, or unplug and plug again in a short time.
I disconnected it for 12 hours, and when I plugged in again, it kinda worked, and the settings where factory defaults, so when I tried to connect it to DSL via PPoE, when ( I believe ) it reboots to accept the changes, it starting flashing again and completely stopped working.
So I waited 12 hours more unplugged, plugged it and it worked, and the setting from 12 hours earlier were still there. But when trying to connect to the DSL it stopped working AGAIN.
Now I don't know what to do. I guess I am going to keep trying connecting with little differences, until something.
I believe it still has warranty but since the is no official service in Uruguay, it isn't economically viable to send it overseas.
I am currently connected directly to the DSL, sharing connection to other computers through a switch and hosting an ad-hoc wireless network, but the performance is terrible and the wireless range is minimal.
Any working configuration to connect the iPad VPN-client (IPSEC) to the RV042?
View 16 Replies View Related