Cisco Security :: 3000 Vpn Concentrator Load Balancing

May 19, 2012

We have two 3000 vpn concentrators. Under both of  their load balancing fields, Configuration - Load balancing , the checkbox for loadbalancing is enabled.However both have different priorities, one with 10 and other with 1. Does this mean both are actually loadbalancing. What does the priorities indicate here?If we replace the concentrators with ASA , how will this load balancing need to be configured on ASA & how will it work.

View 5 Replies


ADVERTISEMENT

Cisco Security :: Load Balancing With ASA5510

Aug 29, 2011

We have an ASA5510 with two ADSL lines connected and the auto fail-over set up - this is all tested and if the main line fails, the backup line is used in it's place - no problem there.
 
However, I'd like to increase our connection speed, and one way I've done this in the past is to add a couple of extra ADSL lines to a router that is capable of load balancing.
 
I'm aware that the ASA5510 does not load balance (seems a waste as we've got the backup line just sitting there doing nothing!), but would it be feasible to add another router in front of the ASA device to perform this load balancing function?

View 2 Replies View Related

Cisco :: How To Setup LAN-to-LAN VPN Via 3000 Concentrator

May 28, 2011

I have been trying to setup a LAN-to-LAN VPN between two sites that are using a 3000 series CISCO Concentrator. After following the basic setups from the CISCO site, I am still unable to create a tunnel. At the moment I'm starting to believe it is how I have physically setup the network. Site 1 is using a Billion BiPAC 7404VNPX ADSL2+ Modem, Site 2 is using a Netgear DGN2000 ADSL2+ Modem, The VPN Concentrators are setup behind these devices with each firewall setup to allow the needed ports forwarded.

View 5 Replies View Related

Cisco VPN :: VPN Concentrator 3000 Login

Apr 14, 2011

Our VPN 3000 concentrator's admin password was changed by somebody so i reset the password by using straight through serial cable, now the problem is it allows me to login with admin through console but not through admin web interface or telnet. I have enabled telnet and http access but still no success. Concentrator is using internal database so no AAA server is configured.

View 1 Replies View Related

Cisco VPN :: VPN 3000 Concentrator And AnyConnect?

Aug 14, 2011

I have a client who saw there was a android version of the AnyConnect client and want me to go through and get their VPN 3000 Concentrator confingured to be able to connect in with it.
 
The Conncentrator is currently setup several groups of users and the base group is set up to all other products to connec tin via a pre shared key. It took alot research to get it configured to this point and all the searches i pull up are for a ASA.

View 1 Replies View Related

Cisco :: VPN Concentrator 3000 DES-56 LAN To LAN Stopped Tx

Apr 4, 2012

I have a VPN Concentrator 3000 with LAN-to-LAN DES-56 connections connected to it (Cisco PIX 506). Everything was working fine and then over the night something messed up on it. No settings were changed or anything.
 
First issue was anything using DHCP (getting IPs from the sites local PIX) couldn't be pinged or reach out through the Concentrator. It was only Thin Clients that didn't work. I could still ping the PIX, printers and desktop computers that were static set IPs. But this was happening at every site going through this Concentrator. The sites going through out MPLS network are fine.
 
I tried setting the Thin Clients to a static IP but still couldn't ping them.
 
I then decided to reboot the Concentrator, when it came back up all sites reconnected back to the Concentrator but now couldn't ping anything at the sites, not even the LAN IP of the PIX (or printers and desktops now). I power cycled a few of the sites PIXs but they still were not pingable even though the Concentrator showed they were connected.
 
I then decided to physical power cycle the Concentrator, it's back up and all sites are connected but none of the devices on the LAN side are reachable.
 
The Concentrator can ping the sites WAN IP but nothing on the LAN side going through and out the Concentrator. It can ping the LAN through the private interface (going back towards my LAN) just not going through the public interface (over the WAN).
 
The sessions show that Bytes are Rxing but no Bytes are Txing.

View 0 Replies View Related

Cisco VPN :: 3000 Concentrator Manager Access

Aug 8, 2011

I have 3000 concentrator in 192.168.1.x/24 network (concentrator has static IP of 192.168.1.4/24 assigned to its private int). I can manage it thru HTTP from any PC in the same subnet, but connection failes while trying to connect from PC on different subnet (i.e. 10.1.1.x/24). Is there ACL in concentrator config which needs to be modified to allow management from different subnet?

View 2 Replies View Related

Cisco VPN :: VPN Concentrator 3000 To View Log History

Nov 21, 2010

Our enterprise uses a VPN Concentrator 3000 for our VPN access. Is there a way to view a log history of what user connected to VPN and what IP address they were assigned?  It would be for 2 days ago which was over the weekend.

View 3 Replies View Related

Cisco VPN :: VPN Concentrator 3000 Setup With Client

Mar 27, 2011

I've the following scenario VPN Concentrator is connected to a router which is connected to a router and at the edge Cisco 515E PIX is connected to the internet. The problem is that the normal VPN Dial-up connection (a utility of windows) are getting connected but Cisco VPN Client throws error 412. Here's what I've tried (Initially groups and user were created):

(1) Allowed port 10000 on PIX ( access-list from-outside-coming-in permit tcp any host <public ip> eq 10000) and checked IPSec over UDP on VPN Conc. under Mode Config tab. Also checked IPSec over TCP tab under tunneling panel at port 10000. Tried connecting through VPN Client but it threw error 412
(2) In the reference guide, I read that IPSec over NAT is allowed on ports ranging from 4000 something to 40000 something.

I tried 33333, both on PIX and VPN Conc. under Mode Config tab but still no use. Same error 412.

View 3 Replies View Related

Cisco VPN :: VPN Connection Between Concentrator 3000 And RV220W

Jun 27, 2011

is it generally possible to configure a site to site VPN connection between Cisco VPN Concentrator 3000 and Cisco RV220W / RV120W?

View 2 Replies View Related

Cisco VPN :: Old VPN 3000 Concentrator Password Reset?

Jul 8, 2012

I have an old VPN 3000 Concentrator that I do not have any idea what is running on it. The previous network admin didn't leave a password for it, so I tried to reset the password. I was successful in doing so, but when I try to access it with the default of admin/admin via web browser, I still cannot access it. I am loathe to remove or power off this device without knowing what is on it.

View 6 Replies View Related

Cisco VPN :: 3000 Concentrator Intermittent Login Failures

May 11, 2011

I manage a VPN 300 concentrator which has been happily working for several years without any problems. All users are part of the same group and authenticate to an RSA server. We recently moved from RSA authentication manager 6.1 to RSA authentication manager 7.1. Everthing continued working fine for several weeks, then at the beginning of this week we started getting users intermittently failing to connect to the VPN. I'm not sure if this problem relates to our new RSA server, but we have other network devices which authenticate to it with no problem so I guess the problem is with the VPN concentrator itself.
 
When users fail they just get a generic "Reason 427 connection terminated by peer" error message. The live event log shows "group = vpn, status = Not-in-service" when their connection fails. Other times they connect normally and no error messages are displayed. There seems to be no real pattern, sometimes your connection fails but if you keep trying you will eventually get in [however it can take many attempts over an hour or two before you succeed, or you may get in straight away with no problem].
 
I dont believe its a network problem, as I have run continuous pings to the concentrator and the RSA server whilst users are experiencing these problems and there are no drops.
 
The RSA servers authentication monitor always shows that the user has successfully authenticated, whether the users connection actually succeeds or not. I am tempted to just reboot the concentrator, but we have site-to-site VPN tunnels connected off it and I'm a little concerned that if it is faulty it may not come back up at all.

View 2 Replies View Related

Cisco VPN :: Private-to-Public IP NAT Through IPSEC VPN On 3000 Concentrator

Jul 27, 2011

We have to setup an IPSEC tunnel for a client that does not what to exchange private IP address information for security and overlapping address space reasons.  We will both be natting our source private ip address space as public IP address space and send those packets through the established tunnel.  Im using a Cisco 3000 concentrator. 

View 1 Replies View Related

Cisco VPN :: ASA5520 / Concentrator 3000 Open TCP Ports?

Sep 21, 2011

We recently had a Port Scan done on our external IP Addresses.  One of those IP Addresses scanned was our Concentrator 3000.  The report came back with the following TCP ports being open on the Concentrator 3000 - 80, 443, 1723, 10000, 10001, 10002, 10003, 10004, and 10009.  I am unsure if it is necessary to have any or all of these open.  The Concentrator 3000 is in front of our ASA5520.

View 1 Replies View Related

Cisco VPN :: Configure VPN 3000 Concentrator To Work With AnyConnect?

Oct 10, 2011

is it possible to use cisco AnyConnect client to connect users with Cisco VPN 3000 appliance?If so how to configure VPN 3000 concentrator to work with AnyConnect?

View 1 Replies View Related

Cisco VPN :: Site-to-Site VPN Between ASA 5510 And Concentrator 3000?

Jan 23, 2013

Is it possible to configure a site-to-site VPN between an ASA 5510 running 8.2(1) and an old Cisco VPN Concentrator 3000?  I've only been able to find an old 3000 to PIX guide on Cisco's site, and I cannot figure out how the two device's VPN options match up.
 
These are the options from the 3000:
 
IKE Proposal
Authentication:
Encryption options:
 
On the 5510's Site-to-Site Connection Profile, all the options are clumped into two boxes under Encrption Algorithms:

IKE Proposal: Encryption, Hash, DH Group, Authentication
IPsec Proposal: ESP Encryption, ESP Authentication
 
We have a pre-shared key configured, but I cannot find a set of options on the 5510 to match the 3000; I always get this error:
 
3Jan 24 201310:10:09713902Group = 63.192.x.x, IP = 63.x.x.191, Removing peer from correlator table failed, no match!1Jan 24 201310:10:11713900Group = 63.x.x.191, IP = 63.x.x.191, construct_ipsec_delete(): No SPI to identify Phase 2 SA!

View 2 Replies View Related

Cisco WAN :: ASR1001 / L2 Over L3 With Load-balancing?

Nov 30, 2011

i'm trying to accomplish the following:I want to trasport a bunch of vlan layer 2 etherchannel on a pair of layer3 connections, using L3 to load balance.i was considering a pair of options:
 
1) bridging + gre (non applicable since i cant bridge 2 interface beloging to a etherchannel to a tunnel)
 
2) L2TP is it possible to accomplish this with the above tecnology? any reference, configuration example?
 
3) AoMLPS is it possible to accomplish this with the above tecnology ? any reference, configuration example?
 
I cant modify topology, the routers used are ASR1001 It is mandatory that both sites have a layer2 connection between them.

View 1 Replies View Related

Cisco WAN :: 2811 DSL Load Balancing

Dec 9, 2010

I have a Cisco 2811 router with two HWIC-ADSL cards configured for dsl connection. I have two lines from the same ISP and i am load balancing between them. I have created a couple of SLA's to check the state of the connections and add to the routing table the two default routes if both are up or any one of them is up.My problem is that when i  try to download big files (especially antivirus updates) the download at some point stops (especially the antivirus exits with an error of unreachability). If i shut down one line everything works fine.Could i use something (configuration-wise) to prevent this problem from happening?????Is there any way i can combine the two lines? They are simple ADSL connctions with static ip's.

View 8 Replies View Related

Cisco WAN :: Load Balancing On ASR1002?

Jun 25, 2012

One of our customer just purchased ASR1002 router, they have three internet links from different ISPs and they dont have any remote site, they have three different public IP pool as their respective ISPs. So, is it possible to load balance the internet traffic using all three link on Cisco ASR router ( IOS - Advance Enterprise Services)

View 3 Replies View Related

Cisco WAN :: 4506-E DSL Load Balancing

Jun 10, 2012

I need to configure DSL Load Balancing on Core Cisco Switch 4506-E. I have a Router Cisco 2811 with 2GE Ports and a Firewall Cisco ASA5505. I have 8 Physical DSL Connections with 1Mb each. I need to combine that 8 Mb on Core Switch and allow each end user to access the Internet via the available DSL connection which means that every user has 8 Mb available.

View 7 Replies View Related

Cisco VPN :: Load Balancing ASA 5520

Sep 13, 2011

We have an ASA5520 pair that we will be installing to load balance SSLVPN connections.  Below is a portion of our configs pertaining to the VPN load-balancing feature (configured on both ASAs):My specific question is related to routing of return traffic to load-balanced VPN sessions.  Is there some kind of persistence function that tells the return traffic which ASA to route back to?  For instance, if ASA1 has a VPN connection having IP address 10.211.112.1 associated to it, and ASA2 has a VPN connection having IP address 10.211.112.100, how does the return traffic for each connection know which ASA to route back to?

View 1 Replies View Related

Cisco VPN :: Load Balancing ASA 5510

Sep 13, 2011

Currently we have deployed site to site vpn between 2 asa 5510 model. one is corporate site and one is remote site. now we plan to use radware load balancer in which 2 isp will terminate. now if at a remote site wecreate only 1 ipsec tunnel and mention sigle isp peering. if one isp fails at corporate how remote site will be access by site to site vpn through 2 isp vpn. what thing we need to do over asa as well as load balancer at both end.

View 6 Replies View Related

Cisco Application :: URL Load Balancing In ACE 20?

May 23, 2011

I have 2 rservers 10.30.1.73, 10.30.1.76,I have 3 URLs in both

[URL]
 
I want to have only one link for two same link in both servers with this ip address 10.30.1.172 so I will have 3 link and will load balance to 6 links

[URL]

View 4 Replies View Related

Cisco WAN :: WAN Load Balancing On 2811

Apr 18, 2012

i have a one 2811 router with 2 nos of HWIC-1FE card, and also i have two mpls connection [code] how can i configure it with mpls load balancing ?

View 10 Replies View Related

Cisco :: Check Load Balancing On The Routers Using BGP?

Apr 8, 2011

How is the best and easiest way to check kind of load balancing on the routers using BGP (Border Gateway Protocol)?

View 6 Replies View Related

Cisco WAN :: 11501 CSS Load / Advance Balancing

Mar 1, 2011

We have Cisco CSS 11501 and connected in  One-Arm way.Currently there are 4 source sending traffic and 3 server to  receive the request. We are using Advance-balancing with Source IP. So  the ratio become 2:1:1 or 1:2:1 or 1:1:2.But our target is to do the load balancing in equal ratio.

View 1 Replies View Related

Cisco Routers :: RV016 Is Not Load Balancing UDP?

Feb 22, 2012

this router (RV016v3, Firmware: v4.1.1.01-sp (Dec 6 2011 20:03:18)) in regards to it not properly directing UDP packets out of the right WAN, as per the settings stored in Protocol Binding section of [System Management, Multi-WAN].I use the section to direct all traffic from desktop computers (192.168.5.100 ~ 192.168.5.199) through WAN4, and all VoIP related traffic (192.168.5.200 ~ 192.168.5.239) through WAN2(PPPoE).Everything seems to be working well except for some of the UDP traffic from 192.168.5.200 which is seen in the log going out of WAN4 instead of WAN2.I have even created a new entry for [UDP/5060~5060]->192.168.5.200~192.168.5.200(0.0.0.0~255.255.255.255)WAN2, and placed it at the very top of the list.Here are a few lines that I've observed in the log: (Refreshed the registration of two SIP Trunks configured in our PBX)
 
Feb 23 18:11:47 2012     Connection Accepted     UDP 192.168.5.200:5060->184.72.227.214:5060 on eth4
Feb 23 18:11:46 2012     Connection Accepted     UDP 192.168.5.200:5060->50.56.59.168:5060 on ppp2
Feb 23 18:11:46 2012     Connection Accepted     UDP 192.168.5.200:5060->184.72.227.214:5060 on eth4
Feb 23 18:11:46 2012     Connection Accepted     UDP 192.168.5.200:5060->50.56.59.168:5060 on ppp2
 
There are no static routes configured, so i'm baffled by what could cause some of the UDP packets to go through the wrong WAN.All TCP Traffic from 192.168.5.200 is seen going though WAN2 as it should.

View 2 Replies View Related

Cisco WAN :: ASR1001 - Internet Load Balancing

Feb 3, 2013

I want to load balance my Internet traffic between two ASR 1001 routers that are connected to our core switches.  Both routers are connected to the same ISP (Comcast) going to the same BGP AS on different /30 subnets.  Is there a way for me to load balance my Internet traffic using both connections with BGP rather than having one of these connections sitting idle?  If not, the only solution I see is to configure my layer 3 devices to split internet traffic between both routers (i.e. default routes with same AD).

View 6 Replies View Related

Cisco WAN :: 2821 / 881 - Load Balancing Between Two Routers?

Feb 24, 2011

We have a network topology like 2821 router with MPLS link and 881 Router with DSL Connection(DMVPN).

MPLS Link runs in BGP
DSL Connection runs in EIGRP.

So the existing scenario is like When ever MPLS link goes down Traffic will be moved to DSL connection. and once it come again it will be moved back to DSL using HSRP we are doing this. in this case most of the times my DSL connection will be in standby mode.Now my management decided to use both the links in active state and want to do some load balance between the links for some specific traffic like Internet, WSUS Updates, Antivirus updates need to go through the DSL connection even the MPLS is up and running.

View 2 Replies View Related

Cisco Routers :: RV042 Load Balancing And OWA

Apr 6, 2012

I have a rv042 router with two internet connections. I have setp the WAN1 and WAN2 and set the load balance mode. Surfing on internet is then not a problem and I checked that I was using the two internet connection.However if I try to connect to my corporate (OWA) outlook web access i am looping on the first page where I should provide my credentials.I know that most of the load balancer could be set up with a sticky bit to keep the session on the same WAN connection.

View 4 Replies View Related

Cisco Application :: 389 Load Balancing LDAP In ACE?

Dec 5, 2011

Does loadbalancing ldap services in ACE? Both port 389 and 636.

View 4 Replies View Related

Cisco Firewall :: ASA 5545X And Two ISP Load Balancing

Mar 2, 2013

I have two Internet connections which are connected to two ISR 2951s. Also I have two ASAs 5545-Xs, which I want to use in Active/Active failover mode with multicontext. The question is: how can I configure ASAs to perform ISP load-balancing as well?

View 4 Replies View Related

Cisco WAN :: CEF - Per Packet Load Balancing (3560)?

Jul 5, 2011

confirm is Per packet load balancing is supported in the 3560's ?
 
I am going around in circles, and can't find a definate Y or N answer.
 
I have a suspicion this CEF feature is only available on routers.

View 8 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved