Cisco Firewall :: 5520 - ASA 8.6.1 Shape Command Invalid

Jul 9, 2012

Tried setting up a Shape Policy and it states its invalid.  Worked fine on my 5520, just curious to know why its coming as invalid now                  
      
ciscoasa(config-pmap-c)# shape
^
ERROR: % Invalid input detected at '^' marker.
ciscoasa(config-pmap-c)# shape ?
ERROR: % Unrecognized command

View 11 Replies


ADVERTISEMENT

Cisco Firewall :: ASA 5520 Cancel / Abort Command

Jan 23, 2012

So, I made the fatal mistake while consoled in to do a "Show Run". Now, it is just stuck in that cycle. I tried the usual "Ctrl+Shift+6" command, and even the "Ctrl+6" with no success.

View 5 Replies View Related

Cisco Firewall :: Command To Check ASA 5520 Is Passing Traffic

May 14, 2012

how can i check that ASA is passing traffic? Also what command we can use to make sure VPN is working fine.

View 2 Replies View Related

Cisco Firewall :: Command To Check IPSEC Tunnel On ASA 5520?

Jan 7, 2013

Need to check how many tunnels IPSEC are running over ASA 5520.Tried commands which we use on Routers no luck?

View 6 Replies View Related

Cisco Switching/Routing :: 4500 L3 / 500 Invalid Port Command

Nov 14, 2012

i just want to ask whether i should do some configurations or not on my cisco switch 4500 L3 regarding the error of 500 invalid port command when host try to access FTP active on to FTP server, i just did static route on gig interface with no switchport mode to that host network, all traffic type was allowed except the FTP with active mode?

View 7 Replies View Related

Cisco Firewall :: Can Traffic Shape To 200Mbps On ASA5510

May 30, 2012

I have ASA5510. It's include security plus license.I want to traffic shape to 200Mbps. But , I checked a CCO.CCO said that  a shaping limit is 154400000. "Enables traffic shaping, where the average rate argument sets  the average rate of traffic in bits per second over a given fixed  time period, between 64000 and 154400000. "It's mean shaping limit 154400000 ?Can I shape to 200Mbps ?

View 2 Replies View Related

Cisco Firewall :: ASA5520 8.0(2) Does Not Have Traffic Shape Feature

Dec 21, 2011

Recently I want to apply traffic shape on my ASA5520, but after entering the configure mode of policy-map, I couldnot find the shape command.. If I type the command, the device would notify me that there is no such command..  My version is 8.0(2),PS. Police command is working fine...

View 5 Replies View Related

Cisco Firewall :: ASA5510 Credentials Are Invalid

Jan 4, 2012

I am setting up a new ASA.  Actually it's an old 5510, but this is a new temporary install until the one we ordered comes in.  Everything is working except for SSH.  I have SSH open on the inside and outside interfaces and I get a prompt when I try to SSH to it from either the inside or outside.  But after I put in my username and password it tells me that my credentials are invalid.  I am using a local username/password, not AAA and it accepts that username and password for the console.  Console and telnet (password only) both work so I can get in to make changes.  When I debug SSH, the error states that my username and password are incorrect.  But this happens even when I create a new, simple username/password to test.  I've even gone so far as to copy/paste the username and password into the login window just to be safe (making sure I don't copy spaces, etc).  Below is a copy of the SSH Debug output followed by a sanitized copy of the config.  I have AAA configured for remote VPN users, but not for access to the ASA.  Also, this problem existed before I created the AAA settings for the VPN users.  Also, I have zeroized and regenerated the RSA keys a couple of times to no avail.  [code]

View 2 Replies View Related

Cisco Firewall :: PIX 515 - Installation / Invalid Input Detected

Mar 16, 2011

I've just got my hands on a Cisco PIX 515. I mainly brought it too learn and play with, i done some Cisco stuff in the past but not much.

I just need too get this up and running with a IP Address on ethernet1 (192.168.1.254) but when I run the command "name if ethernet1 inside security100" in enable mode all I keep getting is ERROR % Invalid input detected at '' maker

View 61 Replies View Related

Cisco Firewall :: ASA5520 Username Password Invalid?

Nov 3, 2012

Two 5520 firewall configuration of the failover and SSH, the first remote landing SSH, can use user and password successful landing, again landing, to prompt the user name password is invalid, what is the reason?

View 4 Replies View Related

Cisco Firewall :: Getting ASA 5505 Invalid Input Error

Apr 15, 2012

Whenever I use the following command I get an invalid input error
 
ciscoasa#conf t
ciscoasa (config) # crypto isakmp enable outside
ciscoasa (config) #object network net-local
ciscoasa (config-network) # subnet 192.168.101.0 255.255.255.0
                                             ^ 
I have reset the firewall (cisco 5505) to factory default. The marker ^ is under the subnet

View 10 Replies View Related

Cisco Firewall :: DNS Through ASA5510 Returns Inspect-DNS-Invalid-PAK

Dec 27, 2011

ASA5510, ASA 8.0(4), ASDM 6.1(5), this is a productino ASA with plenty of lookups working through its 3 interfaces - outside, inside, dmz.  The problem is a new use.  I've segmented a switch on the inside network with a VLAN, and have a workstation routing through the switch to the default VLAN where all other hosts on the inside network reside so far.  The ASA inside interface is the default gateway for the inside network.  My test worksttion can PING inside hosts, so the static route is OK.
 
     ASA 10.1.1.2/16     DNS Server 10.1.5.1/16
                |                                  |
------------------------------------------------------------------
                    |
               Switch 10.1.8.20/16

[code]....
                        
  But lookups fail, Wireshark says the test workstation sends, the dns server receives and responds, but the test workstation never receives.  I used the Packet Tracer tool, it gets to the last step syayin OK then finally "inspect-dns-invalid-pak".  I can't find any more there to tell just what is invlid about it.  So I'm trying to figure out global inspection.  Here's an extract from the config:
 
class-map inspection_default
match default-inspection-traffic
!
!
policy-map global_policy
class inspection_default

[code]....

View 26 Replies View Related

Cisco VPN :: 5520 Configure Intra Interface Command To Enable Connectivity Between Remote Clients

Feb 3, 2013

I'm working with AnyConnect for the first time (my prior experience is with IPSec client) and I have multiple remote users who connect to a 5520 via AnyConnect client; they need to print to each others' shared printers but currently have no connectivity between each other.
 
Can I configure the 'intra-interface' command to enable connectivity between remote clients, or is there more that needs to be done to enable this, presuming that it can be done at all?

View 3 Replies View Related

Cisco Firewall :: PIX-4-500004 / Invalid Transport Field For Protocol TCP

Apr 28, 2011

Geting this message, having low performance and overrun errors Apr 29 13:45:59 pix-servidores %PIX-4-500004: Invalid transport field  for protocol=TCP, from 188.120.243.238/80 to 174.56.110.0/0

View 3 Replies View Related

Cisco Firewall :: ASA5520 Cannot Connect VPN / It Will Prompt Invalid Username And Password

Jan 29, 2013

I have a ASA 5520 which is intended to use as a VPN for clients using PDA, I think the PDA is a very old product that the VPN only support CHAP/ MS- CHAP, but seems it cannot connect the VPN, it will prompt "invalid username and password" (but in fact the username and password is valid when using PAP), below is the log i captured from the ASDM when the PDA is connecting the VPN. when i tried to connect it in windows PC, I also have the same issue if the VPN setting is using MS-CHAP, if I choose PAP, it can connect with no problem. But the PDA has no option of PAP. [code]

View 0 Replies View Related

Cisco Firewall :: Invalid Hostname With Dynamically Assigned DNS Error On ASA 5505

Jul 7, 2011

I have connected an ASA 5505 to an ADSL router that is able to assign the IP address and the also the DNS servers for the ISP for the outside interface. The ASA is loaded up with IOS "asa842-k8.bin"
 
I am using vpnclient with a hostname as oppose to an IP address to connect to a headend remote server. If I hardcode the DNS servers IPs in the "dns server-group DefaultDNS" I am able to resolve the hostname. If I then remove the IPs from the group and rely on the dhcp to assign them, when I try to resolve the name I have an error at the console "ERROR: % Invalid Hostname"

View 2 Replies View Related

Cisco :: WLC 2125 Modify Heatmap Shape

Mar 20, 2011

I am quite new to WCS and preparing a demo for a client. I am also using WLC2125 with LAP1252s for this setup. Is it possible to modify the shape of the heatmaps of the APs? I know how to regulate TX power of the radios and all works great but how can I controll RF leakage outside the perimiter of the building? Is it possible to controll the RF so that it will not be going outside and same time giving a good coverage inside?

View 1 Replies View Related

Cisco WAN :: Shape Output Traffic 2821

Mar 8, 2012

I have a Cisco 2821 with ios Version 12.4(21). On that router I have a WAN link that is 550mbit dual. The interface is 1000FD so i need to shape my output traffic to max 550mbit - otherwise my ISP policing is dropping the traffic.
 
I've looked at this document url... and i'm trying to use this interface command:traffic-shape rate
 
But the router wont accept rate value 550000000 that should be 550mbit in bits/s
 
Is it not possible to shape the traffic to 550mbit on the 2821 router?

View 10 Replies View Related

Traffic Shape Group 101 500000

Apr 21, 2012

what are the values of Bc and Be?interface fast 0/0 traffic-shape group 101 500000

View 11 Replies View Related

Cisco WAN :: 3825 - What Does Shape Average Percent Mean In QoS Policy

Jan 3, 2010

I am working at a client site that is an MPLS customer.  The customer has an MPLS circuit that runs between their Main HQ and their Disaster Recovery site.  I have been asked to analyze and report as well on the way the Qos Policy is written, and to provide any recommendations on how they can improve performance.There is a statement within the Qos Policy as it exists at each end on the 3825 routers.  The statement is called "shape average percent".  Here is the policy from one side:
 
policy-map QoS
class COS2_traffic
set dscp af31
shape average percent 12
bandwidth percent 13

[code]....

What does this statement mean and how is it different than the the "bandwidth percent" statement?

View 2 Replies View Related

Cisco WAN :: Traffic Shape Per Policy (ASA5510 With 8.x Software)

Jun 25, 2012

I have a asa 5510 with 8.x software and I want to reserve (i mean RESERVE not PRIORITIZE) traffic based on protocol, like if I have  a 10Mbit I want to :
 
- give 3 Mb for smtp

- give 5 Mb to http/s whatever

- 2 Mb for other stuff.
 
Of course QOS won't do that, can you do that with ASA?

View 1 Replies View Related

Cisco Switching/Routing :: Inexpensive 881 Switch That Can Shape?

May 15, 2013

We currently "need" to shape certain services very specifically....we curently do this via routers for CE's (881's etc) i.e. 10Mb service, we need:
 
-class class-default
-shape average 9800000 40000 0
 
Some of our clients want to run firewalls as CE's that are unable to shape to this degree, so we are wanting to put an inexpensive switch in front of their CE to do the shaping for them(L2 - either per-port or per-vlan)...the ME3400 looks ok, but is quite expensive.

View 6 Replies View Related

Cisco WAN :: Configured Policies To Shape Traffic On Interface Of 7206 Router?

May 1, 2012

I have configured policies to shape the traffic on the interface of cisco 7206 router. Now my managemet wants to configure these policies on time based ie policy should be applicable during specified time period onle. Is it possible? if yes how to configure it?

View 11 Replies View Related

Cisco Firewall :: Different Between ASA-5520-K9 And ASA-5520-K8

Nov 2, 2012

We were using ASA-5520-K9 with  ASA-SSM-AIP-20-K9 but recently found some hardware problem in our running ASA. Now cisco want to replace with ASA-5520-K8.

View 1 Replies View Related

Cisco Switching/Routing :: Shape 3560 For 10Meg Metro-E Internet Connection

Nov 12, 2012

I have been reading for awhile now on all the Cisco forums on the 3560 and shaping egress traffic but I wanted to verify my thoughts on this.  I have 3560 that connects to the ISP that is policing at 10Megs, I want to shape my egress traffic going to the ISP, I do not want to provided QOS to any specific traffic type but only shape all traffic outbound.  Will my config below shape "all" egress traffic going to the ISP on the 3560, on a port that is physically connect at 100Meg Full duplex?
  
int gi0/1
srr-queue bandwidth shape 40 40 40 40
 
I gathered these numbers using the formula of 100* 1/weight, which would equal 2.5 and if each queue has 2.5 meg that would = 10Meg.  However another concern is that I don't think I have the full 100Meg on the interface to use (correct?)

View 3 Replies View Related

Cisco Firewall :: NAT Command Conversion PIX 6.3 To ASA 8.4(2)

Dec 28, 2011

I am in the process of migrating a production firewall from PIX 6.3 to ASA 8.4(2). This is going to be a complete firewall rebuild and I will not be upgrading the configs because they have become out of date and very bloated. I am in the process of converting the NAT commands.[code] I am hoping these commands would be enough to replicate the previous functionality. I removed all the static identity NATs because NAT control is no longer in place so those rules are not required. Additionally I didn't re-create the rules that had NAT ID 0 or 1 because it didn't look like they were doing anything. correct way to do the static NAT commands at the bottom.

View 3 Replies View Related

Cisco Firewall :: ASA 8.4 NAT Command Selection

Jul 4, 2011

I am designing a new NAT configuration for an ASA 8.4
 
On my PIX 8.0 configuration I needed to allow bidirectional traffic between interfaces with different security levels.  For example, Inside at 100 and dmz at 50.To accomplish this in 8.0 I used a static NAT command along with any necessary ACLs.

 I now need to apply this same 8.0 config for 8.4.  With the static command not availablein 8.4 I am unsure of which NAT commands to use to achieve the bidirectional traffic.

View 1 Replies View Related

Cisco Firewall :: What New Command Is For NAT In Version 8.3

May 29, 2013

what the new command is for NAT in version 8.3?The config i have is from Version 7.2 and doesnt work on 8.3. [code]

View 12 Replies View Related

Cisco Firewall :: 5505 - Command Changes From 7.2 To 8.6

Mar 10, 2013

I'm coming from a 5505/5510 ASA to a 5512x. I see the following 7.2 commands are now set with the NAT command in 8.6:
 
-------------begin 7.2 commands---------------------
global (outside) 1 interfaceglobal (inside) 10 interfaceglobal (wireless) 1 interfacenat (inside) 0 access-list nonatnat (inside) 1 192.168.3.0 255.255.255.0static (inside,outside) tcp interface www 192.168.3.114 www netmask 255.255.255.255static (inside,outside) udp interface 5008 192.168.3.117 5008 netmask 255.255.255.255static (inside,outside) tcp interface 3390 192.168.3.101 3389 netmask 255.255.255.255static (inside,outside) tcp interface h323 192.168.3.118 h323 netmask 255.255.255.255
--------------end 7.2 commands----------------------

View 10 Replies View Related

Cisco :: Command To List Firewall Rules?

May 17, 2012

Boss wants a listing of the firewall rules only. What's a command I can run that will give me a listing of this?If I can get an output of firewall rules only, via GUI, that'll work too. It just needs to end up with a printout on a piece of paper telling me what the firewall is doing.

View 17 Replies View Related

Cisco Firewall :: ASA 8.4 - New Configuration To Replace Old NAT 0 Command

Jan 15, 2012

What is the new configuration in ASA 8.4 to replace the old "nat 0" command.

View 1 Replies View Related

Cisco Firewall :: Command For Configuring NAT On ASA5505?

Dec 5, 2012

want to know the command for configuring NAT on My ASA5505.

Local IP - 192.168.1.0/241

Public IP - 182.73.109.118 255.255.255.252

View 4 Replies View Related

Cisco Firewall :: Need Pix 506E Version 4.3 Command

Nov 19, 2012

I have a PIX506E that was resently reset and it has version PIX Version 7.1(2) .  It either uses some different commands or I am not using them correctly. [code]

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved