Cisco Firewall :: Web Authentication On Layer 3 Interface With Cat 3750

Sep 12, 2012

Cisco 3750 with IP Service Image 12.2.55, Trying to enable Web Authentication on Layer 3 interface:
 
!
ip auth-proxy name bp_auth_proxy http inactivity-time 60
!
interface GigabitEthernet1/0/5
no switchport
ip address 192.168.1.27 255.255.255.0
ip access-group 101 in

View 1 Replies


ADVERTISEMENT

Cisco WAN :: 3750 - Establish Interface Dialer On Layer 3 Switch?

May 7, 2012

Is it possible to establish a interface dialer on a layar 3 switch?Or is it only interface for routers?I have a c3750 switch (WS-C3750G-24T), and when i try to establish a dialer interface i get an error message:

[code]...

View 2 Replies View Related

Cisco Infrastructure :: Stacking Catalyst 3750 Layer 2 And Layer 3

Nov 15, 2011

I have a question if I Stack a Catalyst 3750 L3 with a Catalyst just L2, will we able to use all L3 capabilities?

Switches are  

WS-C3750G-24TS-E1U
WS-C3750V2-24PS-S

View 4 Replies View Related

Cisco Firewall :: 3750 / ASA 5510 - Allow Access To Server On Inside Interface From DMZ?

Feb 28, 2013

My internal network consists of Catalyst 3750 switches segmented into different VLANs.  There is a default route on the layer 3 Catalyst switch sending all unknown traffice to the inside Internet of the ASA 5510.  However, I'd like to have a separate VLAN for wifi guest access and send all of that traffic through one of the DMZ interfaces on the ASA 5510.  I don't think you can have separate default routes based on VLANs on the 3750 switches so my only option is to make the ip address of the DMZ port the default gateway for all hosts on the wifi guest VLAN. 
 
The problem I have is that I have a couple servers behind the inside interface that have services available to the public Internet via a NAT address on the outside interface.  I want the guests on the wifi VLAN to have the ability to access the servers on the inside interface using the public address as well, but have not been able to come up with a solution yet. 
 
Here is my config that pertains to this setup:
 
interface Ethernet0/0description Outside Interfacenameif Outsidesecurity-level 0ip address 76.47.10.x 255.255.255.224 rip send version 1rip receive version 1!interface Ethernet0/1description Inside Interfacenameif Insidesecurity-level 100ip address 192.168.17.1 255.255.255.0 rip send version 1rip receive version 1!interface Ethernet0/3description Wifi Guest Accessnameif DMZ2security-level 50ip address 192.168.60.1 255.255.255.0
 
global (Outside) 1 interface
nat (Inside) 0 access-list nonat
nat (Inside) 1 0.0.0.0 0.0.0.0
nat (DMZ2) 1 0.0.0.0 0.0.0.0
static (Inside,Outside) 76.47.10.x 192.168.17.88 netmask 255.255.255.255
 
I've tried the following commands below but no dice. 

same-security-traffic permit intra-interface
static (inside, inside) 76.47.10.x 192.168.17.88 netmask 255.255.255.255

View 3 Replies View Related

Cisco WAN :: WLC 3750 With 41 APs Web With Layer 2 - Clients Get Deauthenticated

Jan 30, 2012

I have a WLC 3750 with 41 APs. We use Web Authentication with the combination of a layer 2 security feature (WPA/WPA2 with PSK). With this combination some clients have the problem that they get deauthenticated and have to authenticate again while being in an active session. For testing I disabled the layer 2 security feature i.e. I set it to "none" but I left the Web Authentication enabled. With these settings none of the clients has any more problems with getting deauthenticated. They stay online for the entire session.

View 5 Replies View Related

Cisco :: How To Configure IP On Layer 3 Interface On Nexus

Apr 11, 2011

With most of my Layer2/Layer3 switches, I'm accustom to giving them a SVI on my management VLAN, and calling it a day. I can't find in the Cisco Nexus guides how to do something similar; everything points to the mgmt0 physical interface, which seems like I need to uplink it to an access port on another switch. Can somebody point me in the right direction for how to do give the Nexus an IP that I can ssh/snmp into it across a trunk for management? I must just be missing the keyword.. NX-OS is still quite a different beast.I see in the manual it says: "SSH has the following prerequisites: You have configured IP on a Layer 3 interface, out-of-band on the mgmt 0 interface or inband on an Ethernet interface." Cisco Nexus 5000 Series Switch CLI Software Configuration Guide page 284, How do I configure an IP on a Layer 3 interface on a Nexus?

View 16 Replies View Related

Why Layer 2 Switches Need Mac Address Even It Does Not Have Any Interface

Dec 27, 2011

Why layer 2 switches need its mac address, even it does not have any interface ? (does not have stp and etc)

View 8 Replies View Related

Cisco Switching/Routing :: Can Use Switch 3750 As Router Layer 3 Without NAT

Jan 13, 2013

I've created a scenario using a 3750 cisco as core switch ad other 6 switch model 2900 in access level.my problem is this, the router is not a cisco router, and this router is not able to make NAT on more than one subnet.Into the core switch I've created 4 VLAN and I must to give internet access to 3 of them, 192.168.0.0/24 (vlan1), 172.16.0.0/24 (vlan2), 172.17.0.0/24 (vlan3).I've connected the switch to router via  gigabit ethernet 0/1 and I've assigned to this interface ip address 192.168.10.2, the router ip address is 192.168.10.1, Switch ip default-gateway is router ip address 192.168.10.1, ip default route is 0.0.0.0 0.0.0.0 192.168.10.1 I've enabled ip routing feature and I've set no switchport feature to interface gigabit ethernet 0/1.From core switch I can ping router ip address but I can't make it from all other user, and the users not able to have internet access.

Below the switch configuration (only necessary strings)
 
version 12.1
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption

[code].....

View 6 Replies View Related

Cisco Security :: 3750 Layer 2 Encryption Over Gigabit Ethernet

Feb 28, 2008

We are looking for a solution to avoid VPNs to encrypt data between HQ and Bldgs (point-to-multipoint) Gigabit fiber(untrusted media).Is there any cisco's product providing layer2 encryption over Giga fiber?The HQ has a 6509s and remote bldgs have mixed of 3750s,4500s  in trunks.

View 2 Replies View Related

Cisco WAN :: Configure More Than One Layer 3 Interface For Netflow On 3845?

Mar 20, 2013

Is it possible to configure more than one layer 3 interface for netflow on a 3845? I can't seem to do it. Is there something I am missing?

View 2 Replies View Related

Cisco WAN :: Assign MAC ACL To Layer 2 Interface On 887VA Router?

Mar 24, 2013

I wish to assign a MAC ACL to a layer 2 interface on an 887VA router but cannot seem to see how to do this.

View 2 Replies View Related

Protocols / Routing :: Setting Up A Cisco 3750 Layer 3 Switch With Several Vlans?

Feb 4, 2011

I'm setting up a Cisco 3750 layer 3 switch with several vlans. I thought enabling routing would route between the vlans, but no such luck.What I want is to share the internet access of vlan 100 with the other vlans/ip-nets.How can I do that?

View 2 Replies View Related

Cisco Switching/Routing :: 3750 - Create A Layer Loop Intentionally?

Mar 1, 2012

I Like To Intentionally Create A Layer 2 Loop in My LabI have 2960 and 3750 switches and servers with multiple NIC's and also Some PC's and Hubs. Connections and Commands And Features Which Sould Be Disabled or Enabled)

View 4 Replies View Related

Cisco Switching/Routing :: 3750 EtherChannel / Stacking In Core Layer

Nov 23, 2011

As we know there are three layer in cisco Network Model:
 
-Core
-Distribution
-Access
 
So my question is  in Core / Distribution layer should i use Etherchannel between switches or use Stacking if switches are stackble.For ex: suppose I have two cisco 3750 switches . so should i use etherchannel between them or use stacking in core layer?What are the advantages and disadv of both.

View 5 Replies View Related

Cisco Switching/Routing :: Cannot Assign Ip Address To Layer 2 Interface In 878

Apr 19, 2012

I have a cisco 878 router and I can’t assign ip address to it’s fast Ethernet interface. When I assign ip address give me this message: “you can not assign ip address to layer 2 interface”.
 
But I can not understand why give me this alert when I use a layer3 device?!

View 3 Replies View Related

Cisco Switching/Routing :: 3750-X OOB Management With IP Base And Routed Access Layer

Aug 14, 2012

I've got a bunch of 3750-X switches all running IP Base and acting as a routed access layer. They run OSPF in a totally stubby area with the distribution layer (Nexus 7K) as the ABR. We also have a physically separate management network into which the fa0 management interface of the 3750-X is connected. The management network itself runs OSPF and has multiple subnets and external access.
 
On the 3750-X, I'd ideally like to be able to run some sort of separate OSPF process for the management network or at the very least have a static default route for management traffic pointing out the fa0 interface, but clearly not have it interfere with the main default route for data traffic coming from the N7K ABR. Normally I'd just create a management VRF, sling the fa0 interface into it and run a separate OSPF process in that VRF. The problem is you can't create VRFs in IP Base! Surely there must be a way to do this? Cisco don't really expect customers to upgrade to IP Services just to have a working OOB Management network, do they?!

View 4 Replies View Related

Cisco Switching/Routing :: 3750 - Rapid Spanning Tree In Access Layer?

Apr 9, 2012

My colleague and I have been having a discussion about using rapid spanning tree in the access layer.  Most of our infrastructure has been migrated to a routed access layer with 3750s.
 
The idea was brought up to configure the switches with rapid PVST.  On the surface, it seems like a better idea, faster convergence, in the event that spanning tree ends up being used for some reason.  My colleague prefers sticking with standard PVST.  His argument is that, in the event of a layer 2 loop, some consumer-level switches filter out BPDUs and if the control plane is overwhelmed, the shorter timers of rapid PVST just puts that much more of a burden on the CPU trying to regain control, whereas with standard PVST it will have around 20 seconds before it starts to engage.  (It may still be overwhelmed, but the longer timer delays the additional burden.)  He says he's seen this problem with rapid PVST and that his opinion is backed up by our Cisco rep.  (I haven't spoken to him yet.)
 
In our model, it should be very rare -- pretty much never -- that we would layer 2 span another switch off of our access stack.
 
One suggestion I saw is to use BPDU Guard, which is a good suggestion as well.
 
But we have had experiences with overloading the control plane on a 3750.  I believe that concern is valid.  If the CPU can't service spanning tree. But I'm interested in hearing about other experiences people have had in terms of rapid spanning tree in the access layer, end users plugging in unauthorized devices and creating loops, and the effects when using rapid spanning tree vs standard spanning tree.

View 6 Replies View Related

Cisco WAN :: How To Configure Vlan Tag On Routed Layer 3 Interface In 3945 Device

Jun 10, 2012

how to configure vlan tag on routed layer 3 interface in cisco 3945 device?

View 2 Replies View Related

Cisco Switches :: SG300 - Setting Management Interface In Layer 3 Mode

Jun 13, 2012

How to set the management interface on a SG300 Switch in Layer 3 mode? I've some vlans configured on the switch with interfaces in each of them:
 
Vlan 100 (10.0.1.254 /24)
Vlan 200 (10.0.2.254 /24)
Vlan 300 (10.0.3.254 /24)
...
Vlan 900 (10.0.9.254 /24)
 
Now, the management interface is listening on all interfaces (IPs). But I would like to configure the switch to only listen on 10.0.9.254. What I need to configure or whether it is possible?

View 3 Replies View Related

Cisco Switching / Routing :: 3560 - Accessing Management Interface Using Layer 3 Link

Apr 9, 2012

I am setting up a link between buildings that uses wireless links. I'm using Layer 3 routed ports on 2 3560 switches to handle the routing between sites. Normally I would just put these in a /30 and then the switches handle the rest. However, the wireless access points have a web interface for managing them that I want to be able to access, but it's only available on the single NIC that also carries traffic. What would be the best way of making this work? Should I make the link a /29 and give the access points an IP in the same range? If this is the case what do I use for the default gateway for the access points?
 
I have included a diagram to try to explain the issue clearer. The IP addresses in black are what I would do if this were a standard cable (and indeed this will work, but I wont be able to access the admin interface of the wireless AP) and the red ip addresses are the alternative if I use a /29 (but as I said, I'm not sure what to use for the default gateways).

View 1 Replies View Related

Cisco Switching/Routing :: Configure 3750 Stack As Core / 2960 As Access Layer Switches

Sep 29, 2012

I configure 3750 stack switch as core and 2960 stack switches as access layer switches.I connected my laptop to one of my core stack in VLAN 10 and I am pinging to one of my server in VLAN 1. What will be the minimum latency at the time of inter VALN routing

View 2 Replies View Related

Cisco Switching/Routing :: 2900 - Nexus 7010 Layer 2 VLan 11 Active But Interface Shutdown

Sep 13, 2012

I understand the vlans on the catalyst side of the house on 2900 to 6500 Catalyst switches.
 
This 7010  running nx-os 5.1(3) I did not setup, but have to manage it.  Hasn't really been a proble till now.
 
My nexus 7010 has a Layer 2 only vlan 11. It is "Active" but the interface is "shutdown".  Yet, it is passing traffic across the directly connected  ports on the nexus 7010 and to other switches in my network.  Vlan 11 is being set out via VTP to all my switches and things are running fine.
 
I need to create another L2 only Vlan.  I can't seem to find any docs  that indicate that a Layer2 vlan Interface on nx-os should be in  "shutdown" mode as part of the setup. I do see in the docs where it has  to be set "Active" as part of the process.
 
Is this the correct way to seutp a L2 only vlan on nex-os? Leave the interface in "shutdown" but make it "Active"?
 
Mystery Vlan 4 and 6
The mystery deepens.  I have other L2 vlans ,Vlan4&6 that are NOT defined as "Interface Vlan4" in the nexus config, yet it is applied to GigE ports on the nexus and these Vlans 4/6is also being sent out VTP to all switches.  Even weirder is that these vlans have names associated with the numbers.  These are valid Vlans that were configured on the old 6509 before the Nexus was installed.
 
I have checked all switches, NONE are running in Server mode for VTP, all are in CLIENT. The nexus 7010 is the only device running in VTP Server mode. 

View 2 Replies View Related

Cisco :: NTP Authentication On 3750

Oct 31, 2011

Trying to apply NTP authentication to 3750 switches (layer-2 WS-C3750-24P switches) but they don't wont to work. Applying the same config to any router or 4500/6500 chassis, and NTP authenticates straight away. NTP without authentication works fine on 3750s as well...
 
ntp authentication-key 1 md5 <key>
ntp authenticate
ntp trusted-key 1
ntp server 10.200.11.200 key 1
 
Is there additional config required for 3750s? This is across different IOS versions, so doesn't look like a bug..

View 1 Replies View Related

Cisco WAN :: Dot1x Authentication On 3750 Switch?

Jan 18, 2010

I have 3750 switch (WS-C3750G-24TS-S1U) with IP Services version
 
Switch Ports Model              SW Version            SW Image------ ----- -----              ----------            ----------*    1 28    WS-C3750G-24TS-1U  12.2(46)SE            C3750-IPSERVICESK9-M
 
on the switch, I have configured aaa new-modelaaa authentication dot1x default group radius dot1x system-auth-control but i am not able to implement the command under interface
 
Switch(config)#int gigabitEthernet 1/0/20Switch(config-if)#do?down-when-looped
dot1x commands are not available under the interface config. Is the IOS version is compatible with dot1x?

View 5 Replies View Related

Cisco Switching/Routing :: Sg300 And SLM2024 VLAN As Layer 2 And Layer 3 Switches Connection

Mar 18, 2012

I want to setup VLAN with the switches SG300 and SLM2024. What is the suggestion to connect these 2 switches. We have the Juniper net screen.

View 1 Replies View Related

Cisco Switching/Routing :: Dot1x Authentication On 3750?

Oct 6, 2009

I configured dot1x port-authentication on a 3750. The switch sends out a request to the radius server. The radius server sends a answer-packet to the switch udp port 21645 but it seems the switch discards the packet or something like that. The radius server gets the answer "Destination unreachable, Port Unreachable"

View 8 Replies View Related

Cisco AAA/Identity/Nac :: 3750 - IP HTTP Server (with No Authentication)

Dec 29, 2011

I have a customer who used to own a 3750 with a older version of IOS. The switch he had used a three year old version of IOS which allowed him to browse to the switch IP and manage it via HTTP without entering a password at all. Now that he has a replacement switch with a new ver of IOS (since the previous switch died). We slapped the config on from the old switch but no matter what we do (understanding that new http aaa authentication commands were added) we cant get this thing to let him in without prompting him for a password. I understand this was an insecure config to begin with so I shouldn't be advocating using it in the first place, but this is what the customer wants.Basically what I'm trying to figure out is are we banging our heads into the wall for nothing as the "ip http server" will not allow an authentication method of "none" anyway? None of the offical documentation I have read for the http aaa authentication cmds shows this as an example nor have I found any blog posts on how to do it ether. Perhaps Cisco removed this by design.

Here is the config: 
 
aaa new model
aaa authentication login default local
aaa authentication enable default none
aaa authentication login none none
 ip http server
ip http authentication aaa login-authentication none

[code]....

View 1 Replies View Related

Cisco Firewall :: Does ASA 5520 Have Layer 7 Firewall

Oct 24, 2012

Need to know if ASA  5520 does Layer 7 firewall or  not?

View 2 Replies View Related

AAA/Identity/Nac :: Authentication Login On Switch 3750 E

Mar 29, 2011

I would like to make a centralized management of loggin account on my cisco switch (with a radius server). But, on Cisco 3750 E, i use 12.2(44) SE1 IOS and no command aaa authentication login exist.
 
Cisco 3750 can support other IOS than 12.2 who have this ability ?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: 3750 AAA Authentication Banners And Banner Logins

Aug 10, 2009

I'm experiencing some problems with AAA authentication banners and banner logins.I'm trying to use spaces and empty lines, but when login, all the lines are after each other, no empty lines, no spaces.The problem appears on a 3750 with IOS version  12.2(5)SE2.

View 5 Replies View Related

Cisco AAA/Identity/Nac :: 3750 / Get RADIUS Setup For Authentication To Switches And Routers?

Sep 19, 2012

We are setting up a new office and I am trying to get RADIUS setup for authentication to my switches and routers.  Currently I am working on a 3750 running IOS 15 and getting hung on what I think on something small.  I have attached my Microsoft NPS Network Policy.  Below is my IOS config:
 
aaa group server radius corp-radius
server 10.15.10.20 auth-port 1812 acct-port 1813
!
aaa authentication login default group corp-radius local
aaa authentication login radius-localfallback group corp-radius enable
aaa authorization exec default group radius

[code]....

View 4 Replies View Related

Cisco Security :: Catalyst 3750 / Uploading Image Into Web-authentication Page?

Dec 21, 2009

i tried to create a customized web-authentication page that will re-direct any user to the web-page once they are connected to the network.
 
The problem is, i just cant attach/upload the image of the logo into the customized web-page (welcome/login page).Been researching about it, found and tried some clue bout it on cisco documentation, but still can't solve the problem.
 
Cisco document :Catalyst 3750 Switch Software Configuration GuideCisco IOS Release 12.2(52)SESeptember 2009
 
switch version :WS-C3750-48TS
 show flash :2 -rwx 12305677 Mar 1 1993 01:27:03 +00:00 c3750-ipservicesk9-mz.122-52.SE.bin3 -rwx 131 Mar 1 1993 00:17:25 +00:00 log.text5 -rwx 3254 Mar 1 1993 00:01:01 +00:00 config.old8 -rwx 113 Mar 1 1993 03:24:33 +00:00 pass.htm9 -rwx 1088 Mar 1 1993 03:39:18 +00:00 login.htm10 -rwx 113 Mar 1 1993 03:21:30 +00:00 fail.htm11 -rwx 104 Mar 1 1993 03:25:32 +00:00 expire.htm12 -rwx 856 Mar 1 1993 00:05:19 +00:00 vlan.dat14 -rwx 2479 Mar 1 1993 01:25:05 +00:00 web_auth_logo.jpg16 -rwx 1048 Mar 1 1993 00:01:01 +00:00 multiple-fs27 -rwx 1053 Mar 1 1993 02:18:34 +00:00 webauthpage.html38 -rwx 6551 Mar 1 1993 01:19:33 +00:00 logotest.html
 
following is my running configuration :Building configuration...
 
Current configuration : 4205 bytes!version 12.2no service padservice timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname Switch!boot-start-markerboot-end-marker!!!!aaa new-model!!aaa authentication login default group radiusaaa authentication login line-console noneaaa authentication dot1x default group radiusaaa authorization auth-proxy default group radius!!!aaa session-id commonswitch 1 provision ws-c3750-48tssystem mtu routing 1500authentication mac-move permitip subnet-zeroip

[code]....

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Catalyst 3750 - TACACS Authentication Stopped Working

Jul 25, 2011

We have a Catalyst 3750 switch that failed over to local login after the Tacacs authentication stopped working. I went through the configuration settings and everything appears to be identical to another switch in this same building.

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved