Cisco Firewall :: ASA 5510 - VPN Is Up But Network Traffic / Data Transfer Is Not Happening
May 2, 2013we have ASA 5510 Configured. this is regarding site-to-site VPN.
View 1 Replieswe have ASA 5510 Configured. this is regarding site-to-site VPN.
View 1 Repliesjust upgraded my ASA5510 from IOS 8.25 to 8.42Everything is running fine apart from one VPN between ASA5510 and cisco 887V router.The VPN session is up but no data traffic is being passed through The tunnel although this VPN was working fine with old IOS. The tunnel is up but no data is passing through IKEV1 session.
protected vrf: (none) local ident (addr/mask/prot/port): (10.0.12.0/255.255.255.0/0/0) remote ident (addr/mask/prot/port): (172.16.0.0/255.255.0.0/0/0) current_peer xxxxxx port 500 PERMIT, flags={origin_is_acl,} #pkts encaps: 0, #pkts encrypt: 0, #pkts [Code]...
I am trying to connect a Control network that can not have access to the Internet, or any other network for that matter, to my Admin network so that I can retrieve trend data about the plant that goes into a database. Right now the process is print information, hand jam into excel spreadsheet, print again, and hand jam into another excel spreadsheet on the other network. Reports are printed automatically once a day, but would like a simplified way of getting data from one network to the other without having to re-enter data several times. Current policies stipulate no USB drives connected to Control systems. Even if we could loosen that, personnel needed to transfer data is not available and going to each individual machine would take more time than current system.Now that background is laid, I have two 2911 ISR routers with EIGRP configured, each with a 4 port EHWIC card. The 3 L3 ports on the router are setup as follows: interface G0/1 to the internet, interface G0/2 to a wireless back haul, and interface G0/0 for IT network. I then have 3 VLANs setup on the EHWICs for our Admin network. We will move the IT network to a VLAN on the remaining EHWIC port and connect the two 2911's through the G0/0 interface. I am going to have one computer on my Administration network dedicated to receiving the information and have a program that will take that data and import it to a database. I need to allow only that computer to receive traffic from the Control network and I need no traffic to flow back into the Control network. In other words I will transmit data from the control network to the admin computer using one protocol (TFTP more than likely) and block any other traffic coming out of and going into the Control network.
View 1 Replies View RelatedI have recently been encountering file transfer probles across our network from wireless to wired, and vice versa. The transfer will start and process about 50% and then we lose internet connection, and it requires a router reboot to get connectivity again?
View 7 Replies View Relatedhow can i connect my laptop in network so that i can transfer the data from another pc to my laptop.Also provide the information how to use ethereal software for internet traffic?
View 1 Replies View RelatedWindows 7 32 bit laptop ----> Windows 7 64 bit PC with USB network adapter.
I'm trying to move a folder from one computer to the other. There are about 300 files totalling 3mb.
At around "234 files remaining", the transfer freezes, and after a minute or so, the network connection on the destination computer is shown as Disabled. If I right click and choose "Enable", it makes the attempt, says "connection failed", and then "It is not possible to connect at this time. No network was detected. You may need to plug in your network cable to complete the connection."
What will fix it is unplugging the USB network adapter and replugging. But it only allows a little bit more transfer before it happens again.
I tried initiating the transfer from one computer, and again from the destination (bringing the files to it), but the problem occurs just the same. On additional attempts it will reconnect to the other computer and allow me to browse the files, but the connection crashes again without any more progress. My internet connection is fine otherwise, doesn't do this unless I'm transferring data across the network. I disabled Eset real-time protection but have windows firewall up (I'd rather not turn it off).
I would like to connect 3pc via switch and let them connect and be able to transfer data from one pc to another using network
View 1 Replies View RelatedWhich network provides the highest data transfer rate?
View 1 Replies View RelatedHardware Software profile;
Laptop - Windows 7
Desktop - Vista Ultimate SP2
Router - Cisco Linksys E3200
Cables - CAT6
I am a sales engineer, so I use my desktop and laptop all the time. When on road, I sync my desktop with my laptop using a program called ViceVersa. This a very good, reliable syncing program that I have been using for over 10 years ( with upgrades ).
The program allows me to sync my desktop and laptop. The program also shows the data transfer rate during the syncing process. The typical data transfer speed is between 5MB/s and 10MB/s with sometimes up to 12MB/s. A typical sync between the computers will take about 3 - 5 minutes at the ~ 10 MB/s transfer rate using ethernet CAT6 cable inteface. At about 11pm last Tuesday,there was a Windows update on both my Vist and Win7 computers. On wednesday, I went to do a typical sync. The system has dramatically slowed to 59KB/s max. This is about 150 times slower than 5-10MB/s that I was used to for so many years. My typical sync was now taking about 2 hours....unacceptable ! I have tried everything to figure out what is going on and how to fix it but nothing has worked.
Then I tried to see what would happen if I disconnected my ethernet cable ( between the router and the laptop only ) and just sync using the wireless network. With that configuration, the transfer rate is ~ 2.5 MB/s which is not great but is much, much better than 59KB/s. I actually do not know what a reasonable wireless transfer rate should be since I never really did it before due to the faster speed of the wired configuration.
This is just a LAN. Only connecting my Desktop to my Laptop via the Cisco router.
How I can get my wired configuration back up to the 5-10MB/s transfer rate that it once was?
Is it possible to import the config of a 5510 to a 5520. Trying to replace two 5510's with 5520's and wondering is there a way import the existing config files for the 5510's into the 5520's?
View 3 Replies View RelatedI have SSH and SCP enabled on the ASA 5510. I can SSH fine into the device. However, I cannot copy files to the device usng WinSCP. Used all options but nothign seems to work. I see the log authentication successful, but then WinSCP reports no response from ASA.
View 5 Replies View RelatedI have a question regarding firewall configurations. Is it possible to have two interfaces ( for two internet service providers) one for voice and one for data. Can I have two Outside Interfaces that one will apply to a pppoe client group and the other will apply to a static IP? Is this possible and if so What would be the steps on applying this connection? Also to note I have a point to point connection already established for the pppoe. I also have another point to point connection for data, but however I do not know how to apply this to the firewall.
View 3 Replies View RelatedWe have ASA 5520 configured for failover and it was working fine. When we wanted to reload the firewall and inactive( Primary) to become Active , we saw that it is in Failed state. The DMZ2 interface in the capture below is the logical sub-interface , but is in Failed State. The other sub-interface on the physical interface Gig0/2 are all fine for the Failed Firewall.
[Code] .............
I have inherited an asa 5510 whit 4GE SSM module installed. The asa runs fine, but i can not use the 4GE SSM ports. Using ASDM or console i can get and configure the gigabitethernet1/x ports but i can not get traffic on it. The ping from the console to the ip address of the Gigabitethernet1/0 is successful. On switches or hubs connected to those ports i can not see the port's mac address. The two Internal-data0/0 and Internal-data1/0 are down and i can get they up. How to configure 4GE SSM or ASA internal-data ports.
View 8 Replies View Related I am not a ASA expert but I have configured them few times. I have a vision of a task I have to complete but not sure if it is practical or how to go about doing it.
We two locations, Location A and Location B. Both locations have a 100MB internet conection. Location A has a ASA 5510. Location B has a 5505. Users at both locations access the internet via their respective ASA. Location A is the headquarters and Location B is a disaster recovery site. We want to setup a tunnel between both ASAs. This tunnel will be used to replicate data between the two locations for DR purposes. We need the users to still use the same pipe to get to the internet but want to allocate 10MB for internet use and the remaining 90MB for the DR tunnel.
We are having ASA 5550 running on 8.0(5)23 IOS. We are having 2 failover groups group1 & group2. currently all contexts are on group1 & its active & Group2 is in BulkSync mode but from last 2 days the failover for group 2 is happning, i am not able to find anything in logs. Its happing daily from 2 days.
View 4 Replies View RelatedWe have three Cisco ASA 5520 with 8.2 code in each tower. There are many configuration on the device hence we are using ip to Name to identify the naming conversion. Out of three one firewall naming conversion is not working, I mean after adding name for a IP it is not reflecting vpn tunnels or access lists or Nat config.
View 1 Replies View RelatedWe will be moving to a new data center in the very near future and with them our WAN IP addresses will be changing. Any best course of action for changing the IP addresses throughout the firewall configuration? Would it be possible/suggested to export the running-config, make the neccessary changes, then import the config? I am familiar with the ASA 5510 only so far as changes are required. It is not something I work with on a regular basis.
View 5 Replies View RelatedI would like to conect a USB device to a computer using WiFi instead of the USB cable the device has. The thing is that I'm not sure about the drivers. Is there any USB Wireless device that transmits the USB data "raw" and the receiver plugged to the computer gets the data with the driver of the remote device in the own PC?
View 1 Replies View RelatedI have a new Palm Vx and have installed Version 3 Palm Software followed by an upgrade to 4.0.1.This works fine with the new Palm but I can't transfer all the data from my old Palm (almost 12 years of stuff) to my new Palm.
View 1 Replies View RelatedI am currently using Win XP in my desktop. I am planning to buy a Laptop with Win7 o/s. S how to transfer data from XP desktop to Win7 laptop uisng the LAN cable?
View 2 Replies View RelatedI have a laptop and a pc...i want to transfer loads of data (about 100 gb) from the laptop to the desktop.I have NO means to do it wirelessly.how to accomplish this so seemingly cumbersome task via wires? (i read in some other places about connecting it via lan wire and then changing the ip addresses.where on my desktop will i see the data of my laptop?
View 5 Replies View RelatedI have 2 cat 5 cables one has the network jack end on it and the other end has a usb end? What is this used for? Can it be used to transfer data from one computer to another?Also how can i tell if I have a crossover cable?
View 3 Replies View RelatedI was assembling and testing some custom production machines here, and I had to perform a data transfer between two windows 7 machines through an HP 1400 switch. I saw 100MBps transfers for the first time. I only wish I could get the main network to operate that fast.
View 13 Replies View RelatedRV110W connected to ISP via PPPoE. MTU is default setting - 1492. IPSs tarif - 100 Mbit/sec IN, 40 Mbit/sec-OUT.When the laptop is connected to RV110w via ethernet the data transfer rate is 45 Mbit IN / 25 Mbit OUT.When a laptop is connected to ISP directly without a router a data transfer rate is 95 IN / 35 OUT.
View 0 Replies View RelatedI've recently upgraded the configuration on one of our 1130 series standalone access points. I've implemented RADIUS authentication, WPA2 encryption etc. in an effort to make our network more secure. While this part seems to be working as planned, our data transfer speeds have taken a major hit. On our test AP, with only one laptop connected, the laptop will report a connection at 54 Mbits. When using any speed test service the speed reported is approximately 15 Mbits. We have 100 Mbit internet, and desktops connected to ethernet show much higher speeds. When transferring files via our own LAN, data transfer rates average approximately 2 Mbytes/second. I've tested this on 3 separate laptops, some relatively new, and it seems they all get the same speeds.
Long story short, our wireless seems to be operating under a third of its reported speed.
I have a laptop running Windows XP that has a wireless card inside.
I have a Single Board Computer (SBC) running Linux that has an 'wireless access point' connected to one of it's Ethernet ports. I want to be able to transfer data between the laptop and the SBC wirelessly (cabling is not an option)
The 'wireless access point' I am using is the EnGenius EOC5611P - it can be configured for:
1. Access Point
2. Client Bridge
3. WDS Bridge
4. Client Router
I don't know which one of these I need,so working that out would be a good start!
I have a classical "inside + DMZ + outside" configuration.I also have a mail server in DMZ which have to be allowed to reach any destination on the outside (internet) at least on the SMTP port, of course.If I make an access rule that allows traffic from that server to "any", everything works fine, but doing so the server is allowed to reach any destination, including what is behind the inside interface (internal network).I didn't find any other option to tell the ASA machine to allow any destination, but on the outside interface only.I do believe is possibile to have the ASA to allow any kind of traffic from a host on the DMZ to the outside interface only, but I didn't figure out how.
P.S.: I'm using a 5510 machine running version 8.2
I'm using Pix 501 with firmware: Version 6.3(3)I have problem with Pix 501:
+ transfer rate data between interface outside and inside very slow, even between 2 interface inside.
+ I have test file transfer between 2 PC connect via interface inside.
+ Results transfer 1 file 1MB with total time 60s
I don't upgrade software current from 6.3(3) to 6.3(5) via TFTP. It's error Please see attach file.
Customer production environment is nexus 5000 use 1 G interface * 4 and config Port-channel ( LACP ) uplink to C3560 , The port channel link is 802.1q trunk , but Data transfer is low , the sh int display as follow :
Why transfer performance pool and how to fix
N-5548UP# sh int ethernet 1/30Ethernet1/30 is up Hardware: 1000/10000 Ethernet, address: 547f.ee14.ed25 (bia 547f.ee14.ed25) MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec, reliability 255/255, txload 1/255, rxload 1/255 Encapsulation ARPA Port mode is trunk full-duplex, 1000 Mb/s, media type is 10G Beacon is turned off Input flow-control is off, output flow-control is off Rate mode is dedicated Switchport monitor is off EtherType is 0x8100 Last link flapped 9week(s) 6day(s) Last clearing of "show interface" counters 20w2d 30 seconds input rate 152 bits/sec, 19 bytes/sec, 0 packets/sec 30 [Code]...
Just wondering if there are any methods or commands, natively, in the asa5510 for determining all traffic in to and from a certain server passing through the asa. This would be without a syslog server or something similar.
View 3 Replies View RelatedCore Internal Network -> Cisco ASA 5510 -> DMZ Switch.If i send a ping reguest from internal network to servers in DMZ Switch over the ASA 5510, i can see a delay in response, some times this delay can be more than 80ms, this is a problem for the web applications in http traffic.How i can find what's happening on my ASA? I disable the inspect traffic over the IPS, disable the policy maps below, reload the two boxes, but doesn't works, the problem still persists. [code]
View 2 Replies View RelatedI'm currently using ASA 5510 with software 8.4.1 and I have an issue with nat configuration. I used the following config line:nat (inside, dmz) source dynamic LAN Pat1 destination Server1 Server1
The traffic is not flowing and when I use Packet Tracer, packets are dropped at the NAT rule with the following error: Drop-reason: (acl-drop) Flow is denied by configured rule.The only ACE I have is permit ip any any.