Cisco Firewall :: 5580 Not Pinging Virtual Interface

May 1, 2012

I have got new cisco ASA 5580 running 7.2(4) on it  when i am trying to configured Virtual interface on vlan 400 in  Gi0/0.400 to LBASE.now the problem is from my MZ zone 10.242.107.17 to Lbase virtual interface 10.242.103.1 iam not able to ping.

View 2 Replies


ADVERTISEMENT

Cisco Firewall :: 5580-40 - Input Errors / Overruns And Reset Drops On 10Gig Interface?

May 10, 2012

I have an issue with input errors, overruns, and input reset drops on the inside interface of an 5580-40 (v8.2.5: Transparent mode)  The box is not stressed at all according to the 'show' commands in the Cisco troubleshooting performance document for PIX/ASA v8.2.5.  Nothing stands out because is pretty much normal, nothing (processes, RAM, blocks, IO...) really being highly utilized.  I have replaced the 10Gig card and that seemed to work because the rate of errors has gone down tremedously.  The next step is to RMA the whole box.My question is what would be the cause of the inside interface to stop processing traffic (I say that because the syslog server stops receiving messages) for some periods of 30 seconds periodically throughout the day and clients lose their connections (ie Outlook, IBM Sametime, Oracle, MSSQL..etc).  Can the issue be somewhere related to the overruns and input errors?

View 2 Replies View Related

Cisco Firewall :: Load Balancing Using Virtual IP On DMZ Interface Of 5520 ASA

Feb 21, 2012

We want to achieve a load balancing scenario using Virtual IP on DMZ interface on a Cisco ASA 5520.
 
The IPs we are going to use on DMZ are 10.15.1.2 and 10.15.1.3
 
These IPs are going to be NATted to all inside IPs.
 
Lets say our outside IP is X.X.X.X
 
This IP points to 10.15.1.2 and 10.15.1.3 with .2 being the primary and .3 being the secondary. When I hit the outside IP, it should point me to .2 and that .2 should take me to the inside IPs.

View 1 Replies View Related

Cisco Firewall :: 4710 - Unable To Ping From MZ To Virtual Interface Of ASA

May 3, 2012

one of my SNMP server 10.242.103.42 sits in MZ zone,and ACE 4710 is connected to core switch,coreswitch is connected to firewall asa.
 
Now iam trying to ping from MZ zone SNMP server to loadbalancer ip 10.242.105.1,iam unable to ping my LB interface to discover SLB on my SNMP server.

View 1 Replies View Related

Cisco Switching/Routing :: 4507R+E Switch / SVI Interface Not Pinging?

Aug 4, 2012

last day i went to one client for the installation of C(WS-C4507R+E)
 
current ios :cat4500e-ipbase-mz.122-53.SG2.bin
 
there is only one sup engine installed and  redundant slot is empty.
 
I installed one ethernet module in the slot 6 and it get detected working fine. I also want to install one fiber module but that module is only supported by 12.2 54 sg or later ios version.so i need an ios upgrade.
 
For the ios upgrade I decide to do it through svi interface For that i igive an ip address to vlan 1 (192.168.1.2) and plug cable in gigabit 6/1 and added that port into valn 1.
 
my laptop's ip is 192.168.1.1 @ this point i faced a rare problem the PING IS NOT WORKING.(switch is directly connected to my laptop).
 
Then i create another VLAN (2) and add that port into vlan 2 still ping is not getting.last thing i tried is that making that gigabit port into a routed port and result is same.

View 4 Replies View Related

Cisco Switching/Routing :: 2950 Router On Stick / Pinging Sub-interface

Oct 12, 2012

In my preparation for my coming CCNA certification I am experimenting with different network configurations. In my test network I am currently working with a "Router on a stick" setup. A Cisco 2611 router connecting a Cisco 2950 switch. VLANs configured on the switch and subinterfaces + dot1q encapsulation configured on the router. Switch only supports dot1q.Router's Eth0/1 is connected to the Switch Fa0/24 port which is also set to trunk mode. I am using a normal Cat5e twisted pair cable to connect the 2 devices.
 
VLANs are working since I can connect a workstation to an access port for example fa0/2 (vlan2) and get Internet access.I can also ping any of the subinterfaces of the router from the workstation.With the current setup I am not able to ping the switch from the router, or the other way around, so in other words I can't remote manage the switch from a telnet or SSH session with this setup. What I am missing?Just to be clear I am pinging the switch directly from the router (Router2611#ping 172.16.100.2), so please ignore all static routes and OSPF. [code]

View 3 Replies View Related

Cisco WAN :: 877 - Virtual Interface Goes Down But Not Physical Interface

Apr 5, 2011

I have five 877 routers connected to ADSL circuits provided by Vodafone. Each has a VPN tunnel back to a PIX.
 
Occasionally one of the sites will lose it's connection to the PIX.
 
When we check the log, we find entries like these:-

Apr  5 01:31:54.085 UTC: %LINEPROTO-5-UPDOWN: Line protocol on Interface Virtual-Access2, changed state to downApr  5 01:33:19.344 UTC: %CRYPTO-

[Code].....
 
As you can see, the physical interface (ATM0) is not being reported as changing state to down, neither is the Dialer interface.
 
When the router is in this state we have to SSL to the public IP address of it and manually restart the ISAKMP SA.
 
When the router sees the ATM interface go down and subsequently come back up, the VPN connection to the PIX also recovers.
 
So - in a long winded way I think I'm asking....why does the Virtual interface go down and is there anything I can do to stop it happening?

View 3 Replies View Related

Cisco Firewall :: Pinging Across 2 ASA 5510s

Dec 16, 2012

Here's my basic setup:
 
Computer A:
IP- 192.168.0.3
Mask- 255.255.252.0
Gateway- 192.168.0.2

[Code]....

Computer A can ping Firewall 1 and Firewall 2, but not Computer B. Computer B can ping Firewall 1 and Firewall 2, but not Computer A. Firewall 1 can ping Firewall 2, Computer A, and Computer B. Firewall 2 can ping Firewall 1, Computer A, and Computer B.
 
Why can't the computers ping each other, but their default gateways can? I've specifically allowed ICMP any any on all the affected interfaces.

View 6 Replies View Related

Cisco WAN :: 1841 With Virtual-Access Interface

Dec 22, 2010

I have a problem in my Cisco 1841 in Virtual-Access Interface  all interfaces is UP Except Virtual Access is Down . [code]
 
when i want recover the virtual access to up ,should i do shut & no shut to the ATM interface.What is the cause of the problem, and how I can solve this issue?

View 2 Replies View Related

Cisco Firewall :: ASA-5580 / Unable To Ping Firewall

Apr 18, 2012

We are going to impliment Spectrum (CA) in my network,i have ASA-5580-20 firewall now my spectrum server want to communicate with firewall,then only it will discover the firewall logs.Now the problem is my spectrum server is in MZ zone(10.10.10.45) security leval is 70 and my inside interface(10.20.20.101) security leval is 100.
 
I am unable to ping from spectrum server to firewall because of high security leval.How can i solve this problem,can  i change my inside security leval to 69 then i think it will ping.

View 1 Replies View Related

Cisco Firewall :: Firewall / Can ASR 1006 Replace ASA 5580

Oct 30, 2011

i check ASR 1006 config with ESP-40, the firewall permonce can reach 40G, ASA 5580 is 20G, can ASR 1006 replace ASA 5580, is there any function feature problem?

View 1 Replies View Related

Cisco WAN :: 3745 Virtual-Access Interface For VPDN

Feb 11, 2012

We have a 3745 LNS router, currently there are less number of users connected.when a user dials request authenticated and one virtual-access interface is formed in LNS router.Now the user is disconnected the vpn and connected to VPN again in this case, whether the user is connected to the same virtual-access interface which was assigned before disconnecting or different virtual-access interface is created.

View 0 Replies View Related

Cisco Switches :: SG500 Possibility To Bind ACL To A Virtual Interface

Mar 24, 2013

I have a switch from SG 500 Series the works as Layer 3 Routing Switch with the Firmeware 1.2.7.76. I have create some diferent VLAN´s and have defined one ACL for each VLAN. Now i try to do a binding from the ACl to a VLAN but i have only the option to bind the ACL to a phys. Interface or  a LAG.is the a possibility to bind the ACL to a virtual interface like in other Cisco serieses and how it works ? the Backround is i have connectetd 2 Hyper-V Server where the Guests are in different VLAN´s and the server is connectetd with a 10Gb Trunk to the Switch now the switch routed the different VLAN´s and i must have some restrictions between the VLAN´s.

View 2 Replies View Related

Cisco Firewall :: Cannot SSH / Telnet To ASA 5580

Oct 15, 2011

accessing my cisco ASA, last night we were doing VA on our ASA, after that iam not able to access it through ssh nor telnet. its not giving me any error.. i tried from different system also. SSH & telnet allowed from inside to 0.0.0.0 i have re-generated rsa keys when it was working. ASA version is 8.2 now when i connect telent is giving me blank prompt. i can login using ASDM.

View 5 Replies View Related

Cisco Switching/Routing :: 4500 Internal Virtual Interface On SUP7

Jul 22, 2012

We recently had a contractor deploy a 4500 catalyst switch with a WS-x45-SUP7-E. After installation and configurations, HP openview is detecting a "downed" interface on the 4500 chassis that is not in the configuration. I have attached an image with the interface circled. We assumed that it may be a configuration issue with openview, however after running diagnostics with a network analyzer, the same ip address for the down interface is still detected. Is this some sort of internal virtual interface on the SUP7?

View 4 Replies View Related

Cisco Firewall :: Cannot Activate Failover On Asa 5580

Sep 27, 2011

I got a problem with a cisco asa 5580 like two days ago and the device stop working (there was a mainteinance window and after that the device didn't work). Now we receive the RMA and we are trying to configure the failover so the new device get the configuration form the one that is working.
 
But this is the message that I gettin:
 
Failover message decryption failure. Please make sure both units have the same failover shared key and crypto license or system is not out of memory
 
We already changed the shared key and crypto license but the failover is still down, what are the features that the cisco need to activate to enable the failover?

View 5 Replies View Related

Cisco Firewall :: ASA 5580 Arp Collision Errors?

Feb 11, 2012

I am receiving allot of Errors "%ASA-4-405001: received ARP collision from IP/MAC on interface dmz1 with existing ARP Entry IP/MAC
 
When i checked this MAC address in the same firewall it shows too many IP Addresses. What could be the reason ?

View 0 Replies View Related

Cisco Firewall :: 5580 - Can't Ping ASA Different Interfaces

May 23, 2012

We are using Cisco ASA 5580 (8.2) firewall. When i try to ping from inside lan to firewall DMZ interface IP it is not pingable and but from inside users i am able to ping firewall inside interface IP address.
 
I think we can't ping to other interfaces of ASA by default. But can we allow the single IP address who can ping all the interfaces of firewall?
 
We are not doing any natting in firewall, for that we used the Load Balancer.

View 7 Replies View Related

Cisco Firewall :: ASA 5580-20 System LED Flashing Red

May 16, 2011

A customer's ASA is presenting the System LED flashing red.I have already analysed the show tech-support and show environment output: Found nothing, everythink seems OK.Cisco ASA 5580-20 - 8.2.1.Single appliance, no failover, multiple context and transparent mode.

View 5 Replies View Related

Cisco Firewall :: Upgrading ASA 5580 Cluster From 7.2 To 8.2

Aug 19, 2012

we are going to upgrade our 5580 ASA Cluster from 7.2 to 8.2 and want to do it like this way ( which worked for all 7.x upgrades ) :download asa8.2 Image to primary + secondary Firewallreboot primary ( message come up " mate version ...)reboot secondary.Does it works any experience? Does it work if both firewall can see each other during the boot process ?
 
Do I have to bring the secondary into the monitor mode so the fw is not visible for the primary ?

View 2 Replies View Related

Cisco Firewall :: Does ASA 5580 Support NAT-PT For IPv6

Mar 29, 2011

I want to ask that does ASA 5580 support the nat-pt for IPv6?

View 2 Replies View Related

Cisco Firewall :: ASA 5580 Command Itself Is No Longer Used

Mar 5, 2011

i'm new with the asa's...i'm familiar with the FWSM's on 6500's and pix..I'm running Version 8.3(2) and i wanted to setup nat-control and use of identify nats for advertising inside subnets to my outside networks.
 
the old command was static(inside,outside) 10.x.x.x 10.x.x.x netmask 255.255.255.x i'm having a little difficulty decyphering the pdf about the static nat...the command itself is no longer used, nat-control is no longer used, but i'm not quite sure what the equivalent nat command is that equates to the old static inside,outside command.

View 8 Replies View Related

Cisco Firewall :: ASA 5580-20 System LED Is Flashing Red?

Apr 8, 2012

In my ASA 5580-20 system LED is flashing RED how can i trobleshoot this.
 
I checked rarepanel everything is ok also i saw environment also showing ok

View 1 Replies View Related

Cisco Infrastructure :: Removing Unused Virtual-access Interface On 3725 Router

Sep 8, 2004

I had the 2 circuits go down at the same time from our ISP and I had to power cycle the router and when it came back up I went from VA # 2 to now VA 3#....I know what is what but it is confusing for my counterpart and I can not remove the old entry for VA#1 and VA#2. [code]

View 3 Replies View Related

Cisco WAN :: 4506s - Switch Virtual Interface (SVI) Versus Routed Physical Port

Feb 28, 2012

What are the pros and cons of configuring a Switch Virtual Interface (SVI) versus a routed physical port between layer 3 switches?For example, if I have two 4506s and have a need to run HSRP and route between them which feature is better and why?
 
switch_a
!
interface vlan 25
ip address 10.10.10.1 255.255.255.0
!
interface fa0/1
switchport mode trunk

[code].....

View 1 Replies View Related

Cisco Firewall :: Failover ASA 5580 Unsync With Active

Feb 19, 2012

I have encountered a problem in one of customer that the Active ASA 5580 is unable to sync with Standby Failover ASA. When Active is connected with FO and push the configs to it will not find the ethernet/Gig interfaces due to which the all the configuration were not applied and when the primary ASA the secondary is unable to respond.
 
When i attached console with the Standby ASA i have seen this error.
 
Number of interfaces on Active and Standby are not consistent.If the problem persists, you should disable and re-enable failover on the Standby.
 
For detail undestanding i am attaching the configs of primary and standby ASA. The KHI-DR-ASA-BB-01 is the standyby firewall.

View 2 Replies View Related

Cisco Firewall :: ASA 5580 With 4*10 GB Module Act / Act Failover Not Working

Jul 11, 2012

If we switch from primary to secondary firewall the interfaces on the secondary  go to state waitung than to failed. after awhile the secondary gives the control to the primary.
 
it seem that traffic passes the secondary firewall during this short failover time . we have several context created  on the firewall, Switch Ports checked , cabeling check everythink checked
  
blackhole Interface inside (10.255.102.134): Normal (Waiting)
blackhole Interface shared (10.255.102.134): Normal (Waiting)         
blackhole Interface inside (10.255.102.133): Failed (Waiting)
blackhole Interface shared (10.255.102.133): Normal
blackhole Interface inside (10.255.102.133): Normal (Waiting)
blackhole Interface shared (10.255.102.133): Normal

View 5 Replies View Related

Cisco Firewall :: ASA 5580 - Possibility To Generate Activation Key

Nov 23, 2011

We got a replacement ASA 5580 from Cisco. We were not aware of PAK, Is there any other possible to generate Activation key? Can we generate PAK or Activation Key using SO (service order) number?

View 1 Replies View Related

Cisco Firewall :: 5580 Failover Active And Standby

Dec 21, 2011

I have a problem with failover. On My site I have 2 Firewalls 5580. And I did this configuration on my firewall.interface GigabitEthernet3/0description LAN/STATE Failover Interfacespeed nonegotiate.

View 5 Replies View Related

Cisco Firewall :: Synchronizing Two Firewalls In Two Different Location 5580

Jun 14, 2012

I have two firewalls in 2 different locations. They act as primary and secondary for my WAN connectivity. I would want a way to synchronize access-lists in both without manually replicating.(access list, NAT and Route)FW model cisco 5580

View 1 Replies View Related

Cisco Firewall :: ASA 5580 - Ping Allowed But Not Configured?

Apr 4, 2012

We have a Cisco ASA 5580 and the outside interface has a public IP address and we noticed we can ping this address from the Internet. I did a packet capture on the outside interface and confirmed the pings and the IP address sending the pings. The 5580 does not have an access list allowing icmp so I'm not sure what is allowing the pings to this interface.

View 5 Replies View Related

Cisco Firewall :: 5580 Do Static Command Needed

Oct 3, 2011

The firewall is running version #8.2 on ASA 5580. Address translation is not needed on Inside network and Outside network.But the customer has hundreds of static command as below.. [code] Can they all be removed and replace with one single command as below? 

View 1 Replies View Related

Cisco Firewall :: 5580 Need To NAT Addresses To Inside Servers

Jul 7, 2012

We are going to setup a L2L VPN with a vendor and they asked us to NAT a couple IP addresses for remote access to a couple of servers on our inside network. Our device is an ASA 5580 with version 8.1 and we have a handfull of public IP addresses for use if needed. The vendor's remote network is a public IP address but for this posting I will use 192.168.10.0. Our inside servers are 10.100.10.20 and 10.100.10.30. Because 10.100.10 is in use with another customer they asked us to NAT 10.77.97.20 and 10.77.97.30 to the two inside servers.

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved