Cisco Firewall :: SA520W LAN Port Don't Work Correctly
Nov 20, 2012
I have a problems with one SA520W.The LAN port don't work correctly. If i connect PC directly via ethernet cable (i try 2 different cable and 2 different PC) the DHCP don't assign an IP. If i reset to factory default and manual insert IP (192.168.75.1) don't work.
First off, my router is a D-Link DIR-655, firmware v2.07. I'm trying to port forward port 25565.
My port forward settings are this:
However, when I use this open port checker, it claims that I don't have that port open. It looks like this, without the blurred out parts:
Added note: The way I want to use it is by my IP (xxx.xxx.xxx.154:25565). I have the software installed to do so (I'm using a minecraft server, connecting through minecraft), but I can't enter my IP in the IP address field, it says that it's out of the range of the LAN.
I have done this before on this exact model about a month ago, so it's still fresh in my mind on port forwarding. (note, I'm using firmware version: 1.0.00) I am running a windows 7 computer wirelessly using this router.What I do for port forwarding is type in router IP (192.168.2.1) in internet explorer, type in "default" as username and "admin" as password. I click the "applications and gaming" link which brings me to port range forwarding.
I fill in my port info, in this case a mine craft server running on 25565. I set up two of the same ports, different names both at the same port, one running TCP and the other UDP, when it worked previously the "both" option did not work correctly. (I used to have a private network that a buddy of mine set up a while back, and I doubt he remembers what to do and I don't know where the manual is to make a new one, searching the internet sends me spam of people asking questions.)
I read somewhere it may have something to do with DHCP server settings conflicting with my IP. My IPv4 address reads 192.168.2.100, and the DHCP settings says the same.
I am trying to get the ACS 5.3 to work with NCS but cannot make it work correctly. url...But this does not show how the ACS referencing AD groups would work when determining which custom attributes to use.
On the ACS 5.3 i have set up the following .The ad is working and in Users and identity stores/External identity stores/Active Directory then my AD test works fine.I have set up the Users and Identity stores/Identity Groups with appropriate ip s.I have configured the Network Device Groups/Network Devices and AAA Clients with the ip address and Authenication optionsA.In Policy Elements/Authorisation and Permissions/device administration/shell profiles.I have creeated a shell profile called network shell pro which das a common tasks of def priv = 0 and max priv = 15
Now i can get into the NCS but i do not see any of the administration buttons on NCS - so this means the custom attributes are not working.i shouldnt need a user for this on the ACS as its using AD.
Ok so our company has a VPN set up on our workstation laptops for employees to be able to connect to the office network from home.We use CISCO VPN CLIENT, and a pre-setting .pcf file to upload our vpn into the client. The settings are correct completely to allow the VPN to work from home. All of our older workstations (Latitude D510-D630's) work with Windows XP SP3 32b. Recently i purchased new laptops (Latitude E6410's) and have started issuing them out with Windows 7 Enterprise 64b.A couple employees from home cannot get their VPN to work correctly at home with the New Laptops. Their old laptops work fine with the VPN, but the new ones dont. They are running a Frontier DSL modem with wireless.The VPN connects just fine on the new laptops, but the problem is... Nothing works. Outlook does not connect, They cannot access any of our network shares or drives. And cannot use any of our company's software that requires our network access.
I tried uninstalling the the CISCO Client, and reinstalling it, No Go.I tried changing the MTU Settings on the client and network adapters and wireless adapters, No Go.And it seems to be just an ISSUE with employees trying to VPN through a dsl connection using the new laptops, where others with the new laptops can VPN in fine through a time warner connection. But remind you, their old laptops work fine.. which seems kind of odd to me.
I am user of Dell Inspiron 1545 and I have problem with Internet. Till yesterday everything just worked great, when I was turning on a wi fi, it always found a network I wanted to. Yesterday, the current has been cut of. (?) and I lost connection to internet. After current camer back, everyone got internet back, but not me. My wi fi is still finding almost all networks except one, the most important one.
I have hardware version B1, firmware version 2.00NA and several computers (wired & wireless) with Vista & Win 7 x64 and a Brother HL1440 printer.When I print something it comes out scrambled, images missing or cut off, empty pages, etc. This same setup worked fine when it was directly into one computer, then shared on the network though windows sharing. The problem was that computer had to be running to print off the network. I got the dir655 since it had printer sharing but so far its not been of any luck.
Does Cisco 602 office connect AP working correctly with a 5508 controller? As cannot get it to work as having random problems. Ie I see the SSID broadcast on the AP, but no authentication messages for clients on the controller.I have the same configuration setup on a 1142 office extend access point and works fine.The other 602AP i have is seen by the controller, but will not even broadcast the SSID.
I just upload firmware1.0.1.10 on 2 WAP121. After the update and reboot, I was able to confirm the firmware version in the System Summary menu. The update is uneventful.However, the functions WDS Bridge and WorkGroup Bridge no longer works on two WAP121:
- For WDS Bridge, when I configure a Remote MAC Address with WPA Encryption and then I click on the Save button, nothing happens there. But it works well when I choose without Encryption.
- For WorkGroup Bridge, when I click on the Save button (even without changing the configuration), I have a message "Certificate file uploaded successfully" and another error message in the background: "error occured for query you send path . device.sync ... "
1.0.0.3 firmware is not available on your site, it is imposible for me to go back.
E4200v2 DMZ does not appear to work correctly?I have two e4200v2 both with latest firmware and it appears to me that the DMZ setting does not work. I continue to have to apply many port forwarding and triggering rules to make needed ports accessible.
Im having a issue with that any of my computers without a wireless connection have been incapable of getting out on the internet with the new router that i got myself, i know the cables works etc, since they work perfectly fine with the old modem alone, but wont work at all with this unless on a computer with wireless connection
I purchased a SA520W for my company, and i have some probles for configuring firewall. I want to deny access to facebook, youtube and twitter but not for 4 hosts which needs this websites for work. I tried to configure content filtering > blocking URLs but with this solution, I deny acces for all users, So, I tried to make IP v4 rules :
The 4 hosts who may access to these websites are 192.168.50.124 to 127
Example : FROM Zone : LAN TO : WAN Service : Any Action: block always Source hosts : 192.168.50.32 to 192.168.50.123 destination hosts : 66.220.158.11 (one of the facebook's ip)
but it does not work. So, I am looking for an other solution, or maybe my rule is not correctly configured ?
I have a server on the inside of my network (with a internet Routable IP). It has been requested to me that people from the internet access port 80, and that is translated at the firewall to port 7080. I have set up a temp Access rule to allow access to 7080 from the outside and it is accessable. I am not sure what I am doing wrong, but I am tion from 80 not able to get the translato 7080 to work.
and i see output "show interface Po4A" up up on switch-1, "show interface Po4B" up up on switch-2
5.- In the show running-config not appear configured Po4A and Po4B. it only show on outputs
6.- Po4A and Po4 was not configured on neither switches, my question is why appear Po4A and Po4B on switch-1 and switch-2 respectively? and why Po4 appear in down down.
7.- I solved this issue by shutdown and not shutdown to the interfaces on both routers, currently all is OK.
I have bought an RV180 Firewall/VPN and try to use the Backup Software Crashplan. As per the supplier it needs Port 443 and 4242 open. Port 443 is fine and allows me to use the service to backup to the Cloud. However when I want to allow other users to backup to my computer this traffic is blocked. I tried to open port 4242 on the firewall and forward the traffic to the computer that hosts the service but it does not work. I have tried to Telnet this port from the WAN but I don't get a response. When I check the Open Ports this port is not listed as a LISTEN port either.
I recently implemented an ASA 5520 HA pair with CSC-SSM-20s in each non stateful per cisco. The CSC management sits in a management subnet 192.168.4.0/24 with the management interface of the ASA as its default gateway in the same subnet. Ever since the implementation frequently webpages will not load correctly, the formating will not look right and pictures will be red x. If you hit f5 to refresh the pages loads fine. If I add a deny any any eq 80 rule before the permit any any eq 80 the issue appears to go away. TAC can't seem to find anything worng. All we want to do is use a simple web content filter with the check boxes in the global filtering policy. ASA is running 8.2(5) and CSC is running 6.3.1172.0. Everything else works fine SVC and rules and such. [code]
I have a problem with my ASDM Logging(ASA5520, System image file is "disk0:/asa804-k8.bin").If i generate any traffic, the ASDM do not show the packets correctly. For example, if i generate a icmp traffic from interface inside to outsite, the ASDM does not show the packets, when it shows it apperars just in one direction.
I need to setup an ASA 5520 to correctly NAT over two wan links. The idea sounds pretty straingforward but it does not, I have only 2 IPs that are involved with the NAT
I have 2 interfaces that sould be applied to it let's say outside1, outside2. The server is reacheable through each outside interface, the outside interfaces is selected uppon dynamic routing and that is working OK.
So if link outside1 is up the Nat follows this schema 192.168.1.10(inside) -- 172.16.1.10(outside1)
that works fine, but I want that automagically changes over when the link outside1 is down to 192.168.1.10(inside) -- 172.16.1.10(outside2).I know I can't have a NAT with 2 IPs and 2 different interfaces (ASDM doesn't allow me to), is there a way to implement this??
I have an SSL VPN set up on my ASA 5520 with a self signed cert. When I run the AnyConnect install on my desktop machine I have click through a few windows to accept the certificate. When I connect through the mobile client on Android, the connection goes right through without a prompt to import/choose/download a certificate. I'm able to connect but I'm wondering if the phone has actually recieved a certificate. I'm in the 'Advanced Connection Editor' screen and the certificate setting says "Automatic".
I want to create a site-to-site VPN from one SA520w to another.The main office has a static IP, the branch office has dynamic.I have read the manual several times, but I am not sure what to do on the SA in the main office and on the SA on the branch office.
We are using a SA520W as our primary router and have a fiber connection attached to the default WAN interface. We would like to improve our uptime using a secondary internet connection on the optional WAN interface.
We have bought a dovado tiny 4g router for this other connection. It acts as a dhcp server but the Cisco router does not get an IP from the dovado router. The router works as expected when connected to a normal computer. But somehow the cisco router doesnt get an IP.
I have also tried to set a static IP for the Cisco router but that didn't work either. The dovado router is setup do deliver ip in the range 192.168.0.2-254
Need to boost signal coverage on an SA520W (even though it is very good, building floor is too clutterd and too darn big.Even using a 2nd unit to extend things may not get it all done; However, searching the site tells me there is an external aerial (one of...) in the SMB range, and it uses "N" style connectors. Looking at the specs on the SA520W, it makes no mention of what sort of connectors those are (Happy to admit I am not a cable guy... well not co-ax anynore at least!).
I have a problem to configure a IPSEC VPN on the SA520W ( 1.0.39) with Cisco VPN Client (5.0.05.290). In the logs are following error:
ERROR: Could not find configuration for x.x.x.xERROR: Could not find configuration for x.x.x.xERROR: Could not find configuration for x.x.x.xERROR: Could not find configuration for x.x.x.x
We've got an SA520W that's performing nicely, but we need to extend our wireless coverage to a new area of the building (we can get a network cable there). What would be our best option? Just a second SA520W, or are there are APs we should look at?
I have an SA520W firewall, and am implementing a new AP541N. On the SA I am using port 4 to connect the AP. Trunking is on with Vlan 1 and 25. Connecting the AP I am able to use VLAN1, however when I assign a new VAP using Vlan 25, I only receive IP addresses for VLAN1.
A is behind a Watchguard XTM25 11.5.3 B is behind a CISCO SA520W
Both have static public facing IP's.
B only has a IP based PBX system attached to it over a SIP ALG. (originally it was hooked up to the watchguard but they didn't play nice, but works great with the Cisco. Problem is the Cisco don't have all the features of the Watchguard)
A has all my users workstations attached. The issue is that computers on A need to talk to server on B for a desktop application to work. Since they are on separate subnets, it isn't working. The app itself still doesn't work by port forward/sNats, etc.
A & B are right next to each other, so cabling between them is not an issue.
Currently, I have a cable between the watchguard and the Cisco. The watchguard end is configured with a static private ip on the subnet A (the cisco side), and plugged into the lan on the cisco side. I have a policies to let all traffic flow freeley, and from the logs on the Watchguard, all A subnet traffic is correctly going to the Cisco via said cable.
But, nothing is coming back from the Cisco. So my question is, how can I get the Cisco to play nice with the other subnet and send traffic back to the B subnet?
Any AP that would be able to wrielessly repeat traffic to my SA520W (so that the AP has no ehternet wiring at all). First off, there is no WDS option anywhere in the SA520W, so there is no method for which to simply create a WDS link between the two devices. Yet the Factory Default Settings table in the SA520W Admin guide indicates there should be (search on WDS in the PDF to find this). both at the lack of integration of these Small Business Pro devices, and moreso at the fact that I was told that these two would be compatible for wireless-only repeating. I've been messing around for hours trying to get something to happen. Maybe I'm just missing something obvious as this is my first time trying to get an AP to talk wireless-only to a wireless capable internet gateway device (the SA520W).
I have setup an SA520W and configured SSL-VPN for our small business. Everything seemed to go smoothly and I tested SSL VPN by logging in and playing around a bit which seemed to be fine. However, shortly after deployment I started getting complaints about it being much slower than our old VPN through the consumer grade router I just replaced. I investigated and tested with IE8 and Chrome on Windows XP 32-bit with several different machines, and in all instances it did seem very slow indeed. While looking around I noticed that the Task Manager under the Networking tab shows the SSL VPN connection as VirutalPassage at 64 Kbps. Going into Network Connections shows VirtualPassage under the Dial-up heading with device name Virtual Passage SSLDrv Adapter. Additional properties describe it as an ISDN channel. I have attached an image of the Task Manager pane.The router is running the latest firmware of 2.1.51. It is connected via a static IP that does not require a login, to our dedicated 5 Mbit / 5 Mbit ethernet over copper link to our ISP. We get great speeds and low latency through everything but SSL VPN connections. I haven't done anything fancy so the router certificate is the factory default. Currently we are using the existing 2 SSL VPN licenses that come with the router until we need more access, at which point I want to upgrade to the 25 user bundle. However, I don't feel comfortable upgrading until I get this resolved, because 64kbps simply cannot work for us for a VPN solution.how to configure the SSL VPN to not limit at 64kbps? My engineers are making fun of me for bringing us back to dialup, and I have to agree with them!
I have a Cisco SA520W router and needs to set up VPN. Du to major problems with the SSL VPN Client and windows 7, I had to let it go and try a different approach.
That was the QuickVPN client, but as it turs out, it simply impossible from reading the user manual to understand just how I have to set thing up. For instance, the VPN Wizard tells you to enter a preshared key. But in the QuickVPN Client, where do I enter the key?
And shall the "Enable Cisco VPN Client" be ticket off, I assumed yes, but seriously it is impossible to know.
Then in the VPN Wizard again, in the Remote & Local WAN Adress, what shall use FQDN or IP Address. The if FQDN, what shall a enter, the domain name for the router, whats the point in that? The domain name of the VPN Client, seriously, what's the point in that? I would assume that 99% of the VPN Client does NOT have a domain name. Then, if IP address, am I supposed to know the IP address of the client? Same with the "Secure Connection Remote Accessibility", what am I supposed to enter. The IP address which the Quick VPN Client network adapter shall have?
I have a sa520w router I configured w a vlan for the wireless and port 2. Now I would like the switch to handle both traffic from the default lan and the vlan. I tried creating a vlan on ports 28 and 10 but I cant get it to work. I have my other lan on port 27. Ive read something about switch layers? not sure. so I want port 10 to route to the vlan and other ports go to the default lan.
if my SA520w will support link aggregation for network devices within my LAN. If so, is there a Cisco wiki or how-to on how to setup this up in the SA520w? I only find a brief mention of this in Section D of the manaul.