Cisco :: RV042 - Establishing A VPN / Communication Is Not Working?
Jul 20, 2011when entering Remote group 0.0.0.0/0.0.0.0 to establish a VPN, and all communication is not working.You do not know how to set up-work?
View 1 Replieswhen entering Remote group 0.0.0.0/0.0.0.0 to establish a VPN, and all communication is not working.You do not know how to set up-work?
View 1 RepliesMy company bought another company and moved them into our building. the company moved in but are on an entirely different network all together. wired separately, different domains.what i would like to do is be able to have them communicate with each other. have users on company A be able to use printers on company B's side of the network.
View 15 Replies View Related I'm trying to dial a Cisco 1841 BRI from my Cisco 2811 PRI. I'm getting a few errors but not sure what else to do to correct the issue. Config & Logs below from 1841:
interface BRI0/0/0no ip addressencapsulation pppdialer pool-member 2isdn switch-type basic-niisdn point-to-point-setupno cdp enableppp authentication chap callin
00:26:44: ISDN BR0/0/0 Q931: RX <- SETUP pd = 8 callref = 0x46 Bearer Capability i = 0x8890 Standard = CCITT Transfer Capability = Unrestricted Digital Transfer Mode = Circuit Transfer Rate = 64 kbit/s Channel ID i = 0x89 Signal i = 0x40 - Alerting on - pattern 0 Called Party Number i = 0xC1, '452####' Plan:ISDN, Type:Subscriber(local) Locking Shift to Codeset 5 Codeset 5 IE 0x2A i = 0x808001039E05, 'From ', 0x8B0C, '214 ###-####', 0x8001, '<'00:26:44:
[Code]....
I have created a new DMZ and a LAN on my ASA5510.My Ethernet DMZ port is connected directly to a server (192.168.220.10) This server is able to get to the internet properly.Gateway ASA router: 192.168.220.222..My Ethernet LAN port is connected to a L3 switch, This L3 switch is connected to a server (192.168.210.11). This server is able to get to the internet properly.My issues is that I cannot communicate from my 192.168.210.11 server to my DMZ server 192.168.220.10. From my 192.168.210.11 server I can ping my gateway 192.168.210.1 and 192.168.210.222. But I cannot ping 192.168.220.222. [code]
View 7 Replies View RelatedI've had 1 to 1 NAT setup for years now with no issues and the other day it simply stopped working. Rebooted everything, had ISP clear arp on their cable modem yet nothing going. As soon as I remove the 1 to 1 NAT on the router the PC has internet access. Add the 1 to 1 back and no out going internet. The configuration is pretty basic and has not changed.Thinking it could be a hardware issue I swapped it out with another RV042 I have with the exact config, same thing 1 to 1 NATs have no internet access. Upgraded one of the RV042 firmware to Firmware Version: 1.3.13.02-tm, had cable modem replaced, spent numerous calls with ISP. nada
I have found one interesting thing however, any internal machine which is set to dhp works fine, and static ip that does not have a 1 to 1 nat works fine and the last ip in the 1 to 1 nat range works fine. If I extend the range it is always only the last ip that works. Even if I add 1 to 1 nats one line at a time, it is always the last entry that works..
I tried to configure two RV042 working together. [code] WAN2 of both Router1 and Router2 are unused (unplugged). However, the Host2 can never ping to Host1. So as to Host1. Should I need to configure the protocol binding for all the traffic to the WAN1?
View 3 Replies View RelatedSo have a RV042 VPN router that is directly connected to the ethernet port of our comcast cable modem.
If I connect to it using QuickVPN (1.4.2.1) from a PC that is connected using AT&T 3G Network it works fine!
If I connect to it using QuickVPN (1.4.2.1) from a different PC that is connected using home WiFi (linksys wrtxxx) then it fails. In the VPN log all I see is failure messages for ping.
2011/10/22 15:47:28 [WARNING]Failed to ping remote VPN Router!
If I open a regular command prompt and attempt to ping the VPN router it works so not understanding why the QuickVPN is unable to ping.
how I can troubleshoot this further. Makes me think the RV042 config is fine otherwise it would not work on a 3G connection. Something on the home PC or the home network. Not sure what to check.
Updated to newest firmware 4.2.1.02 and wanted to perform a backup of the startup configuration. I get a "The webpage cannot be found" HTTP 400 error when trying to do this backup. I have changed some settings since my last backup, but that backup was done using the last firmware revision.
View 3 Replies View RelatedI have an I pad 1, a Linksys RV042 At My Office. And a Cisco RV042 at my Home
However I'm Creating PPTP Connection on my I pad For Both VPN , Office is Connection, but Home is not Connecting. I tried to connect to Home Thru any PC, And It is Working. Any Issues With I pad and Cisco Firmwares and Software?
On my RV042 (I used it for a couple of years now without issues), the DIAG led light amber (steady). It's not documented in the user manual.User manual says only:,Diag (Red) The Diag LED lights up when the Router is not ready for use. It turns off when the Router is ready for use.",Router does not work anymore and I can't access its web page as I used to do before this problem.I did a reset to factory default (reset button hold for more than 30 sec.) but it didn't change anything.
View 1 Replies View RelatedI have set up an RV042 v1 and v3 both in Load Balancing mode. Set in Router mode.I want one of the WAN ports to be preferred so I added a static route to 0.0.0.0 metric 5 to that WAN.Sometimes the route shows in the routing table and sometimes it goes away!!
View 2 Replies View RelatedWhen my RV042 is accessed for long transmissions (svn check out, usually after 20 minutes ) the client receives a message "Gateway not responding, do you want to wait".
When this happens I see the following in the RV042 system log (the first 3 lines of the log below are normal):
Apr 2 17:36:53 2012Connection AcceptedTCP 192.168.2.2:8888->192.168.1.5:50046 on ppp1Apr 2 17:36:54 2012Connection AcceptedTCP 192.168.2.2:8888->192.168.1.5:50046 on ppp1Apr 2 17:36:54 2012Connection
[Code]....
We bought an RV042 at the end of June. It is used as a gateway and VPN router. DHCP server is disabled and all IPs are configured manually.Every once in a while (Tuesday night, then Friday night - yesterday, it has hapened once or twice before that) the router appears to restart (see log below) then comes back up with system time of Jan 01 2010. At this point the router will no longer load its configuration page (https://10.29.238.197:16443/) and VPN connection to our customer in Africa drops. However, devices behind the router can be reached and can access the internet. The only way to fix this is to power cycle the router at which point everything starts working flawlessly again.The PID VID is RV042 V03 running firmware v4.0.3.03-tm (May 12 2011 21:27:37). Our RV042 is a newer one with Cisco SMB Router branding not the older Linksys branding.
From the log when the router reboots:
Aug 12 22:38:42 2011VPN Log(g2gips0) #141: retransmitting in response to duplicate packet; already STATE_QUICK_I2Jan 1 01:00:05 2010System Logheart : System is upJan 1 01:00:13 2010System LogWAN connection is up : 10.29.238.197/255.255.255.192 gw 10.29.238.225 on eth1Jan 1 01:00:15 2010VPN Log(g2gips0) #1: [Tunnel Negotiation Info] >>> Initiator Send Main Mode 1st packet
I looked at the log more and all the usual messages assosciated with VPN being established are there - the last thing in the log before the router coming back up again is:
Jan 1 01:03:49 2010VPN Log(g2gips0) #4: [Tunnel Negotiation Info] Quick Mode Phase 2 SA Established, IPSec Tunnel ConnectedJan 1 01:03:49 2010VPN Log(g2gips0) #4: [Tunnel Negotiation Info] Quick Mode Phase 2 SA Established, IPSec Tunnel ConnectedJan 1 01:03:49 2010VPN Log(g2gips0) #4: sent QI2, IPsec SA established {ESP=>0x575a01c0 <0x6534ae4e
So it even claims the tunnel should be up but I can never reach anything on the far side.
My organization has deployed 3 Cisco RV042 (v3) at our 3 sites. They have been working pretty well up until about a week ago. One of them continues to route traffic and perform port-forwarding, but the VPN has completely stopped working and I can no longer access the web administration interface. I get the standard login page, but any attempt to login (with correct or incorrect password) takes maybe 5 minutes with a spinning status icon, followed by a blank page leaving the browser at: url...
I have the router logs e-mailed to me, and I can see that the system boots up with Jan 1 2010 as the system date, but it eventually gets the correct date from NTP, so I'm doubting this is causing the problem.
These were working for months prior to this happening, and even a reboot of the affected RV042 does not allow me to log into it or setup the VPN tunnels. I have found similar threads on this forum: url...
We have an RV042 on firmware version 1.3.13.02 and 2 ISPs:
WAN1 = Telepacific T1
1.5Mbps down and 1.5Mbps up
WAN2 = AT&T U-Verse
12Mbps down and 5Mbps up
I have it set to Load Balance, Primary WAN = WAN2
Network Service Detection enabled, only pinging the Remote Host of 4.2.2.2 and set to Generate Log
Bandwidth is set to:
WAN1 = 1000Kbps upstream & downstream
WAN2 = 5040Kbps upstream & 12000Kbps downstream
It seems to pick WAN1 a lot of the time. Do I have something setup wrong?
I have my RV042 set up in Dual WAN mode and both WANs are working properly. I would like to configure WAN1 to handle all traffic, unless it fails and then have everything to go to WAN2. Pretty much what Smart Link Backup does, however with that enabled only 1 of the WANs is live at any given time. I'd like both WANs to always be live as I'm going to see the second one as a back-door into the network. Is this possible to do with routing? I tried setting a routing rule to have everything to go WAN1, but when WAN1 goes down, nothing is rounted via WAN2.
View 0 Replies View RelatedI have a remote location that has a Linksys/Cisco RV042 router [URL] that allows PPTP connections based on username and password combinations. There are no intermediary routers between this device and the internet - only a DSL modem. A secondary WAN connection is not present.
I am able to dial into this VPN using the Windows XP and Windows 7 dialers from any of my local free-wifi locations(e.g. Starbucks). I WAS able to connect to this VPN connection from my house when my home router was a Buffalo brand router.
I have replaced the Buffalo router with a 2620(non-XM) that is connected in ROaS fashion to a 2950 switch. I need some guidance on what in my config is not allowing me to connect to this remote site.
Home network info: Local subnets : 192.168.x.x
Remote network info: Local subnet : 10.214.x.x
The Windows XP dialer client indicates that the username and password challenge is where the connection fails. It ultimately gives me the error code 619. I have performed a Wireshark packet capture of an attempt to connect from ip 192.168.10.11. This packet capture shows multiple "Configuration Request" packets being exchanged between the two endpoints, but does not ever show an exchange of authentication.
My nat translation table shows an entry for both a GRE tunnel as well as port 1723 between 192.168.10.11 and the WAN port of the RV042 when attempting to establish this VPN.
I have attached my 2620 configuration for your review.
Any working configuration to connect the iPad VPN-client (IPSEC) to the RV042?
View 16 Replies View RelatedI have a 6 month old RV042 with the newest firmware (v4.2.1.02). Over the weekend I configured the DMZ which after a lot of trial and error, was able to get working. Prior to configuring DMZ, I was able to log in with remote management. However now remote management no longer works. I've tried:
- Rebooting the router
- Turning the firewall off/on
- Turning remote management off/on
- Changing the remote management port
The only step I haven't taken is resetting the router back to factory defaults and trying to reconfigure it all again. This router is so finicky I have no faith I'd be able to get my current functionality back again.
We have a fixed IP address 3G data SIM which we intend to use as backup for our ADSL connectivity using a CISCO887VAG+7-K9 router. (We have previously implemented similar using the older CISCO887G-K9 router without any issues)
The problem is, we don't seem to be able to establish 3G connectivity with this new router. Our service provider assures us that the SIM card is active (although they have seen no connection attempts from us on their RADIUS server)
The router is running IOS version 15.1(4)M4 and the following is the relevant config we have used:
!
cellular 0 gsm profile create 1 $apn chap $user $pass ipv4
!
chat-script INTERNET "" "AT!SCACT=1,1" TIMEOUT 60 "OK"
!
[Code].....
I have a RV042 router on a single WAN and an internal LAN. I have configured port forwarding as follows: HTTP[TCP/80~80]->10.0.0.6HTTPS[TCP/443~443]->10.0.0.6IMAP[TCP/143~143]->10.0.0.5IMAP SSL[TCP/993~993]->10.0.0.5SMTP SSL[TCP/587~587]->10.0.0.5
Everything works just fine when I have the firewall DISABLED. However, when I enable it the behaviour is erratic. 1 out of 10 attempts to connect to ANY port forwarded works. Almost all attempts time out. Notice that this happens even if using only the default firewall rules (which should be bypassed by the port forwarding as I read in other posts).
My second try was to create firewall rules manually, overriding the default ones. I tried adding rules from source WAN1 (where my connection is) to ANY and to SINGLE IP's on every port. Nothing seems to work.
I don't know what I'm doing wrong, this is really bugging me. I had to turn the firewall off so we can access our servers from outside the office. This shouldn't have to be done.
Just found out that my firewall is getting LOTS and LOTS of Blocked - SYN Flood entries. I think this is why we are having trouble with the firewall. Could this be the problem? I have no idea where all these SYN packets are coming from since they appear with spoofed IPs or come from different bots all over.
I live in a very rural location with very few high speed Internet options.Unlike a lot of others, i have a relative 1.5 miles away who does have a high speed internet connection and is willing to up their package and split the cost with me. We've each gone up on our roofs with binoculars and confirmed we have a good line of sight, so setting up a long range point-to-point connection is what I am looking to do.
I already have a Tranzeo CPQ (TR6) to place on my roof (destination), so I just need something on my relative's house (source) to connect with.My initial thought was just to pick up another Tranzeo unit like mine from eBay for $100, but after doing some research, it appears the Tranzeo unit I have can only act as a client at the destination, so placing one at the source won't work ... or am I wrong here?
I have used my Tranzeo in the past over a much shorter distance (<800ft) to link up with a consumer Belkin N router, and it worked fine. For this new setup,I'm looking to connect the source's long range unit into my relative's router, then connect the Tranzeo on my roof to my router's WAN port.This way, my router will receive a DHCP address from my relatives router.
I have a site to site IPSec tunnel setup and operational but periodically the remote site goes down, because of a somewhat reliable internet connection. The only way to get the tunnel to re-establish is to go to the remote site and simply issue a ping from a workstation on the remote network. We were having this same issue with a Cisco PIX 506E but decided to upgrade the hardware and see if that resolve the issue. It ran for well over a year and our assumtions was that the issue was resolved. I was looking in the direction of the security-association lifetime but if we power cycle the unit, I would expect that it would kill the SA but even after power cycling, the VPN does not come up automatically.
View 1 Replies View RelatedAttached are the configuration files for the devices in question. I have a 5510 that belongs to my company and a 5505 that belongs to another company. The 5505 sits behind the 5510 and is able to connect to the Internet. My thought was that VPN access should be a trivial pursuit. I was planning on just giving the admin at the remote office the public IP address that's natted to the 5505 and all would be good.
View 7 Replies View RelatedA multipoint GRE (mGRE) and IPSec tunnel is built between two routers. The topology of the device is briefied below:Configuration in End Router: This is a cisco 2811 router. Amoung 2 ethernet interface ,one is using for LAN and one is for WAN. In WAN part , we have configured mGRE (Tunnel1 and Tunnel 2)by creating sub-interface of the router. From the interface ,we terminating the link to MPLS cloud from there its pointing towards our core router.From End router we are advertising the path through EIGRP and from the cloud BGP advertisied to the core router.[code]
View 1 Replies View RelatedI am having an issue with establishing L2L VPN with remote site. My side is cisco asa 5520 and other side is check point UTM-- tunnel is not up.just wnated to confirm on my sidde if the configuration is OK.al the parameters using are correct for both side. any issue with below conf ? default route is pointing to my next GW address is there additiona default is required for VPN ? to reach the remote LAN somthing like pointing to remote peer address.to give a brief idea front end device is router as GW wher in internet is terminated and other wan connections ASA is behind ther GW rtr and outside int of asa and lan interface of GW rtr is having public ip. LAN switch is connected to ASA
access-list insideinterface_nat0_outbound extended permit ip 192.168.36.0 255.255.255.0 10.34.12.0 255.255.254.0
access-list outsideinterface_cryptomap_40 extended permit ip 192.168.36.0 255.255.255.0 10.34.12.0 255.255.254.0
nat (insideinterface) 0 access-list insideinterface_nat0_outbound
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
[code]....
establishing a Static NAT on an 1841 router.
I'm at a FOX affiliate TV station, and in order to connect our EAS Device to the internet & Fox Splicer, I need to setup a Statio NAT, so we picked up an 1841 on eBay.
I've done a little configuration in HyperTerminal.
I've done these ip addresses:
FE0/0 10.1.10.13 this is the subnet our EAS device is on
FE0/1 10.110.81.174 this is the subnet of the Fox Splicer.
I need to have NAT translate 10.1.10.11 to 10.110.81.170 and I also need to set a route for 10.110.81.0/24 pointing to 10.110.81.161
I have 100 mbps fiber connection. I bought 320N today I bought 320N and here is the problem:
We have a switch in the building. I am getting connection via CAT5. So I choosed "Use as WAN Port" from Ethernet settings. There is not much you can do here. I just used PPPoE and connected internet without any problem. The problem is I am only getting 32mbps. When I connect CAT5 cable directly to my computer I am getting 92mbps.
Maybe WAG320N is not establishing a full duplex connection.
My ISP (OTEnet, Greece) offers IPv6 connectivity in the form of dual-stack IPv4/IPv6 with the requirement that the router supports DHCPv6 Prefix Delegation for establishing an IPv6 connection.Using other routers (Cisco 887W, DrayTek Vigor2130n), I have established an IPv4/IPv6 connection but I am unable to do so with the EA4500. As a matter of fact, when I have the "IPv6 - Automatic" option enabled the router not only cannot obtain an IPv6 prefix from the ISP but it gets stuck in the connection attempt and never obtains an IPv4 or an IPv6 address. I have to disable the IPv6 option in order to simply establish an IPv4-only connection without problems.So, my questions are:
1. Does the latest (2.1.38.38880) firmware support dual-stack IPv6 and DHCPv6 Prefix Delegation?
2. If the router cannot negotiate an IPv6 connection why is it not establishing an IPv4 connection only but gets stuck in the process?
I reset the wap610N,after establishing connection, my iphone see my network domain but does not connect. I heard of dual band setting,how do i go about that. What must i do to establish connection with the iphone.
View 4 Replies View RelatedI have recently bought two CISCO routers RV220W for our main and brach office mainly for VPN tunneling. I didnt know they are routers only not modems. so I have set it up using BT 2wire Router as modem only.
I have successfuly setup the routers and manage to establish the VPN tunneling between two routers. AS bt doesnt give static WAN IP address so I have used Dyndns which works fine. although I have 5 static ip address which cannot be used for WAN unless i cahnge to one IP address even then BT tech said it will not work.
when I created the tunnel i could ping both servers with their IP only not with the names. I can ping them fine locally. I could also see the network from branch office to main office but not from main office to branch office. today when I restarted the server I cannot ping both server i mean vice versa but VPN tunnel is established. now I cannot see the network from branch office to main office as well.
Both sites running windows server 2008 standard. main office server has 6 NIC cards two wwith public and three with private ip addresses, its also runing Terminal server, exchange, file etc. the branch office has two NIC card one with private and one with public ip. Intially I could establish the VPN tunnel as the network range was same on both sites so I changed one in th e10.0.0.0 range other in 192.168.1.0 range and VPN tunnel was established straightaway.
As soon as the VPN tunnel was created I manage to creat an external trust without any problems and both servers are added in each other forward zones as name servers.
in the main office the fues went off and I had to re-start the router and now the VPN tunnel is not establishing, mainly the error is ISAKMP-SA Expired I will paste the log of both routers below
1. How to Clear Old or Existing Security Associations (Tunnels) on RV220W
2. how to fix the problem where I can ping the server with their IP as well as domain names ?
3. how to set it up so that both sides can see the network resources as well as access it ?
4. how to set it up so if the staff in branch office wants to log on the domain in main office he can simply do it as he does it in his office.
I am trying to establish a Site-to-Site VPN to our customer. I am using ASA5510 and the customer was using Fortigate 1000A. The problem that we're having was regarding the IKE Phase 2, I think!. Cisco debug information indicates "All IPSec SA proposals found unacceptable!"
View 11 Replies View RelatedI have a problem configuring a site to site VPN between two sites, one is an ASA5540 with version 8.2, the other is an ASA5545X with version 9.0 I'll try to include the relevant portions of the configs here... the tunnel will not establish and nothing shows on debug logs that I can find. I know the outside addresses for both work, as clients can connect into both.
ASA5540:
: Saved
:
ASA Version 8.2(5)
object-group network VEYANCE_NET
network-object <ASA5540NetworkObject>
[code].....