Cisco Switching/Routing :: 2950 Disabling Windows Firewall / Allowing Access Through The Router

Dec 18, 2012

i bought a cisco 2950 series switch to play around with and im trying to set it up to SSH. I have google'd a bit on how to do this and i've sort of hit a wall... i have downloaded the cryptographic image from cisco's website, installed a TFTP server (think this is where my issue lies) but when i do the copy tftp flash global command i keep getting the error accessing "xxxx" message.I have tried allowing the server through windows firewall, disabling windows firewall, allowing access through the router..

View 6 Replies


Cisco Switching/Routing :: 2950 Switch Not Allowing To Set Up SSh

Feb 8, 2013

After setting up the domain name I try to use the crypto key and it is no where to be located. Below is some of the information I copied from TeraTerm
Switch-1(config)#ip domain-name justin.lab.comSwitch-1(config)#crySwitch-1(config)#cry?% Unrecognized commandSwitch-1(config)#crypto key ?% Unrecognized commandSwitch-1(config)#crypto key ^% Invalid input detected at '^' marker.
Switch-1(config)#?Configure commands:  aaa 

View 6 Replies View Related

Cisco Switching/Routing :: 2951 - IP Access-group In Command Not Allowing DHCP

Feb 27, 2013

I have a Cisco 2951 Router and I am trying to set it up to use DHCP and for security purposes I need to use the "IP Access-Group in" command. The DHCP will not work when I have this command on the interface that I need to run it through, DHCP works fine when I do not have the "IP Access-Group in" command in the configuration. When I check the log after the failed DHCP attempt it shows up as denied, as if it's being blocked. The IOS I have is c2951-UNIVERSALK9-m 15.0 (1) M3. Conf Reg 0x2102.

View 6 Replies View Related

Cisco Switching/Routing :: 2950 - Can't Access Switch Via Browser Or CNA

Jan 5, 2012

I upgraded a Catalyst 2950 switch and there wasn't enough room so I deleted the flash. The upgraded went well using tftp. It booted up fine. The  I0S version includes crypto. But, I can't access switch via web browser or CNA. Port scan shows port 80 0pen. What am I missing?
Here is the flash. 
Directory of flash:/
    2  -rwx         112  Mar 01 1993 01:00:48 +00:00  info    3  -rwx     3722814  Mar 01 1993 01:02:58 +00:00  c2950-i6k2l2q4-mz.121-22.EA14.bin    4  drwx        4416  Mar 01 1993 01:03:45 +00:00  html  331  -rwx         112  Mar 01 1993 01:04:19 +00:00  info.ver  332  -rwx   [code]....

View 5 Replies View Related

Cisco Switching/Routing :: Blocking MAC From VLAN Access 2950

Dec 11, 2011

We have a group of computers on their own VLAN.  A router allows internet access while keeping them sandboxed.  We don't want them accidentally connect to our production network.  We blocked their wireless MACs in unauthorized WAPs.  I'd like to do the same thing for their ethernet MACs on our switches, (a mixture of 2950,2960 and 2960G currently testing on C2960-LANBASE-M, Version 12.2(25)SEE2).  I've been unable to locate the correct method on google, by searching these boards or in the command reference.
What is the best practice for blocking a group of MACs from accessing a particular VLAN on a network consisting of several Layer 2 Switches? 

View 4 Replies View Related

Cisco Switching/Routing :: 2950 / Vlans And Internet Access Sharing?

Apr 5, 2013

i am trying to set up a cisco 2950 with a vlan to seperate all of the pos machines on the network (4 of them) from all other machnes in the building (3 hard wired and wi-fi).  i was going to use vlan 1 as a trunk to allow internet access to go from fa0/1 to both vlans (vlan 10 and vlan 20).  i have read things about the acl having an explicit deny at the end, so i'm thinking that is my  problem.  i am testing it at my house before deploying it to the network.  i have 1 laptop setup with an ip of, and the other is .60.  my router is  i have the ethernet from the router plugged into fa0/1, the 1st laptop on fa0/2 and the other at fa0/3. before i set the vlans up, i checked the communication by just plugging them in and trying to ping, they could both ping each other, the router and  when i finished setting up the test vlans, they could not ping each other(what i wanted) and laptop 1 can ping the router, and  laptop 2 cannot ping anything. 
the only thing i did was create vlan 10 and 20, set port fa0/2 to vlan 10 and no sh, fa03 to vlan 20 and no sh, fa0/1 to vlan 1 and no sh.  then i did switchport mode trunk on fa0/1, and switchport native vlan 1.  this seems to be how i was supposed to do it, but it's been a while since i have worked with switches.  i'm sure it's simple, but after searching the internet and poring over my cisco books for 5 hours, it is turning out not to be the case. here are some details:

greenhouse#sh int fa0/1 switchport
Name: Fa0/1
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk
Administrative Trunking Encapsulation: dot1q


View 10 Replies View Related

Cisco Firewall :: Allowing FTPS Access In ASA5510

Apr 13, 2012

We had an ASA 5510 as a firewall in our environment, and there is a requirement to access an ftps server from our location. Currently from the server location they configured everything by allowing our public ip to their server and gave the following details to access ftp.Please suggest which traffic needs to be allowed in our ASA to access the ftp server address as mentioned above. From my initial analysis, it's found that 989 port is also enabled for the access, but that was not mentioned by them.

View 1 Replies View Related

Cisco Firewall :: ASA 5550 - Acl Allowing Guest Access

Jan 26, 2012

I have an ASA 5550 at our main site with an external ethernet interface to our ISP for internet access.  I would like to allow 10.100.41.x/24 http / https access but block this network's access to all other internal networks including 172.17.x.x,,  10.100.1 - 40.x, and others.  I'm having trouble identifying what IP address to use as the desitination for the permit rule for access to the internet.  The rule that comes after the permit is to deny 10.100.41.x/24 access to internal network addresses. 

View 1 Replies View Related

Cisco Firewall :: Allowing Internet Access Only For Specific Computers On PIX 501?

Jan 8, 2012

I'm a college student working on a lab involving a Cisco PIX 501 Firewall.
My project involves 1 computer and a firewall. My goal is to use the firewall to allow access to the internet for that computer which uses a static IP and ONLY for that IP address. The firewall is connected to the internet.
I have the computer hooked up to the firewall with the serial and using hyper terminal to enter commands. I think I need to use access lists in order to deny traffic on those ports for those particular hosts. I can't figure out exactly how I need to set it up.
What I need to do is permit internet access for alone. Any other IP should not be able to access the internet.
I tried:
access-list 1 permit tcp host any eq 80
access-group 1 in interface inside
I cannot access the internet using the computer with The goal is to be able to access with that IP and no other.

View 6 Replies View Related

Cisco Firewall :: ASA 5520 - Filter Is Not Allowing To Access Certain Websites

Aug 20, 2012

We have a Cisco ASA 5520 and Web sense.  I added a filter but it seems like it is still not allowing us to access a certain website from most of the machines however some machines with the same configuration work on the DMZ. Accessing website tells us:

"Firefox has detected that the server is redirecting the request for this address in a way that will never complete". 

Filter I applied on the firewall:

filter url except allow
filter https except allow

View 9 Replies View Related

Cisco Switching/Routing :: 2950 Router On Stick / Pinging Sub-interface

Oct 12, 2012

In my preparation for my coming CCNA certification I am experimenting with different network configurations. In my test network I am currently working with a "Router on a stick" setup. A Cisco 2611 router connecting a Cisco 2950 switch. VLANs configured on the switch and subinterfaces + dot1q encapsulation configured on the router. Switch only supports dot1q.Router's Eth0/1 is connected to the Switch Fa0/24 port which is also set to trunk mode. I am using a normal Cat5e twisted pair cable to connect the 2 devices.
VLANs are working since I can connect a workstation to an access port for example fa0/2 (vlan2) and get Internet access.I can also ping any of the subinterfaces of the router from the workstation.With the current setup I am not able to ping the switch from the router, or the other way around, so in other words I can't remote manage the switch from a telnet or SSH session with this setup. What I am missing?Just to be clear I am pinging the switch directly from the router (Router2611#ping, so please ignore all static routes and OSPF. [code]

View 3 Replies View Related

Cisco Firewall :: 5505 Rule For Allowing Computer Access Microsoft

Apr 24, 2012

I have a computer behind the ASA 5505 firewall. The computer needs to access Microsoft Activation Server. Reading some website information, I need to allow a huge list of servers that basically points to www and https traffic. Therefore, looking at this heavy requirements, I prefer to allow this computer to navigate to any https or http (www) server outside of the firewall.I have included my current asa 5505 configuration. [code]

View 3 Replies View Related

Cisco Switching/Routing :: 2950 And Cable Router - Expand Home Network

Apr 27, 2012

I just picked up a 24 port Catalyst 2950 to expand my home network and learn a bit more about networking. Having just upgraded the IOS software 'm now trying to get this to work as required on my network but I'm having a few issues.
My intentions are to plug my cable router/modem wan connection which is set up as the dhcp server to fa 0/1, then use fa 0/2 - 24 for the rest of my wired network. So essentially all on the same subnet interfacing with the router
So far I have set up all of the security on the switch, and have all switch ports assigned to vlan1 with no IPs. My laptop connected to fa0/2 however is not assigned an ip address. Looking at a few posts I ahve rightly or wrongly played about with dhcp snooping.
Current configuration : 2205 bytes                                             
version 12.1                                                                   
no service pad                                                                 
service timestamps debug uptime                                                
service timestamps log uptime                                                  
service (code)

View 3 Replies View Related

Cisco Firewall :: ASA 5520 - Allowing Guest Wireless Network Access To Internal Subnets

Jan 23, 2012

We have a Cisco wireless infrastructure in place that includes a guest network with its own subnet that is a sub interface of the inside interface on our ASA 5520.  There are no routes for it to be allowed access to the internal subnets.  So it can only access the internet.  This is primarily used by the public, but we have several non employee personnel that we only want to give internet access and force them to access the internal network through our clientless SSL vpn portal or through other internet facing internal resources such as webmail.I have done packet traces from within the ASA and the break appears to be there is no ACL allowing the traffic back into the network once the web resource replies to the request and the traffic is attempting to come back into the network from the web resource.  Is that as clear as mud?
I know that this has to be a common problem and a way around this is to allow the guest wireless network access to the internal network but only for the select resources that they require.  And that this can be done seemlessly by network specific routes and or alternate DNS entries, but I would like to keep this simple and just allow them to access the web resource, webmail and VPN, from the guest wireless using internet DNS servers without route trickery.

View 8 Replies View Related

Cisco Firewall :: 2950 Switch Access-list On Dmz

Mar 4, 2012

On firewall we have zone created for dmz and ip is 192.x.x.x and it is connected to 2950 switch(DMZ switch)  with vlan 25..We have L3 switch on this we have created vlan 25 and connected cable from L3 with 2950 switch with vlan 25
As we have the servers on L3 and wanted to bring on dmz zone  we have connected a cable.Now the problem is when i connect a pc on 2950 switch (directly on dmz switch) with access-list below we are not geeting any hist on it.

View 6 Replies View Related

Cisco Switching/Routing :: Allowing RDP On 891w

Sep 24, 2012

I am trying to allow RDP through my 891w.I have tried a few different yjing to no avail. [code]

View 23 Replies View Related

Local Access Only - Router Not Allowing Access To Internet?

May 18, 2011

Abruptly internet access disappeared. It's a router issue, none of the computers here can connect. Further, I can't access the router through a browser - results in a "Firefox cannot connect" message. I've tried resetting the DNS to no avail. I'm typing via cell phone and it's annoying, but I'm willing to try about anything.

View 4 Replies View Related

Cisco Switching/Routing :: 3560x - Running IP Services And Error When Disabling EIGRP Stub

Jan 15, 2013

I have A 3560x running 12.2(58)SE2 and jus tupgraded to IP services to allow Enhanced EIGRP as found on feature navigator. I need to run full EIGRP and disable Stub.
however, when I try to disable it, I get this error:
dist2-3560x(config-router)#do sho licenseIndex 1 Feature: ipservices            Period left: Life time        License Type: Permanent        License State: Active, In Use        License Priority: Medium        License Count: Non-Counted
Index 2 Feature: ipbase                 Period left: 0  minute  0  second  Index 3 Feature: lanbase                Period left: Life time        License Type: Permanent        License State: Active, Not in Use        License Priority: Medium        License Count: Non-Counted
dist2-3560x(config-router)#no eigrp stub connected summaryEIGRP is restricted to stub configurations only on this platform.
I have installed the license and rebooted. by all indications th elicense is installed and should allow for Full EIGRP routing.

View 2 Replies View Related

Cisco Switching/Routing :: RV180W Not Allowing Internet Connection?

Mar 4, 2013

I recently saw it for a good price online, and required a new router (had a netgear that died, and my backup was a really buggy Belkin which I'm currently using).I'm having an issue with the internet, in that when I connect my ADSL modem to the WAN port it seems to work fine, however the PC can't connect to the internet. When I go into the settings it says that the WAN connection is OK and even shows my external IP. I have it set via the stardard DHCP setup.Should I have done anything specific to my ADSL modem before plugging it into the RV180W? The Modem (D-Link 320B) also has a DHCP server on it, however I assume that this causes no issues when connected to the RV180W.

View 1 Replies View Related

Linksys Wireless Router :: E4200 - VPN Is Disabling Internet Access

Sep 26, 2011

I have a Linksys E4200 router with firmware version 1.0.02. I am using a Macbook Pro. I can connect to a VPN server with the default VPN client software, but it kills my internet connection and disables connecting to SMB

View 5 Replies View Related

Cisco Firewall :: 7100 Allowing NAT / PAT From Router Through ASA

Mar 17, 2013

I have a 7100 router that has some servers behind it. I need to translate each server to a public IP. The only thing is that between the outside world and the router is an ASA. We have a small data center where the ASA is connected to a core switch on the inside and the ISP on the outside. How would I do the NAT/PAT translations on the 7100 and then have them pass through the ASA? for example:

View 6 Replies View Related

Cisco Firewall :: 881 Router - IOS ZBF Not Allowing IPv6

Oct 4, 2011

I am trying to configure Zone Based Firewall (IOS 15.2T) on Cisco 881 router for IPv6. Current setup is simple:

LAN --> WAN zone security LAN
zone security WAN
class-map type inspect match-any Internet-cmap
match protocol dns
match protocol http
match protocol https
[ code ] ........
Current configuration behaves as expected for IPv4, but blocks all IPv6 traffic. If zone-security is removed from WAN interface IPv6 works normally (connected to Internet). As soon as zone-security is enabled on WAN interface all IPV6 traffic is discarded when connecting to Internet from local LAN.
Error messages on console: Half-open Sessions source destination tcp SIS_OPENING/TCP_SYNSENT
Are there any special settings for ZBF which should be turned on for IPv6 protocol?

View 1 Replies View Related

Cisco Switching/Routing :: 881 - Zone Based Firewall (Can't Access Router With CCP)

Mar 3, 2013

I'm having an issue accessing a clients router on the WAN interface with Cisco config pro. I can get CLI access with SSH without any issue.  I have port 22 and 443 allowed as management access from my public IP - SSH working fine but config pro being refused connection, Possibly a certificate issue?

View 1 Replies View Related

Cisco Switching/Routing :: Allowing DHCP / ARP Broadcast Through Nexus 3048TP?

May 8, 2013

I have a 3945 with a basic DHCP configuration applied to it. This 3945 is connected into one of the access ports of my nexus switch. I'd like to simply have the 3945 hand ip addresses out to other clients connected to the nexus switch. I have zero experience with nexus & haven't been able to turn much up through searching the net.

View 1 Replies View Related

Cisco Switching/Routing :: 3560 / Allowing Etherchannel Or Port Channel?

Mar 3, 2012

I am using 3560.IP rouitng is being turned off on this.Curious to know if I will create etherchannel or port channel.I think etherchannel.Correct me if I am wrong.On connecting switches I have vlan10,20,30 to be allowed.I am sure I need to allow these all vlan in 10,20,30 which are on the trunk port on each side switch.Post that will add channel-port lacp and make it in active mode.Is that correct.This way traffic will be load-balanced/aggregated on minimum 2 ports who are the part of this.

View 2 Replies View Related

D-Link DIR-655 :: Router Not Allowing Internet Access?

Jan 14, 2012

I just bought the 655, mainly for school/Xbox. My parents use it also, but I bought it for myself mainly (shh). I set it up correctly and got connected, but suddenly I wasn't allowed Internet access. The router connects to my laptop, but won't get Internet access. I called customer service and he didn't know what to do. We tried everything he knew and nothing worked. I don't want to return the router cause I read it was very good, but I need internet for school. I have Rev. A and F/W 2.00.

View 8 Replies View Related

Cisco Switching/Routing :: 3550 / 2950 DHCP Relay Option To Router Handing Out DHCP

Apr 3, 2012

Have a client wanting to hand out public ip addresses to all clients from a PFSense Firewall terminating the internet connection.
How do I allow the Cisco Switches currently in place, configured with private ip addresses in the 10.10.x.x ranges and Vlans, where the main 3550 layer 3 has defined dhcp scopes for each vlan, to relay dhcp requests from all vlans to the PFSense firewall?
I assume I would take off the currently defined dhcp scopes for the vlans and configure each vlan/switch with the ip helper address and specify the PFSense firewall and that Nat would have to be disabled onthe firewall?

View 1 Replies View Related

Unresponsive Router - Stopped Allowing Wireless Internet Access

Nov 3, 2012

My Netgear wireless router had been working just fine and then inexplicably stopped allowing wireless internet access. My modem is fine. I contacted my internet service provider, and no luck. I unplugged the router's power source and plugged it back it in. Still not working. I switched the power on and off. Nothing. I do not know what to try next.

View 1 Replies View Related

Linksys Wireless Router :: E2000 Not Allowing Access To Other Devices

Nov 5, 2011

I just set up my e2000 on a PC using Windows 7.  I am additionally trying to set up additional devices on the network.  The two that I am currently working with are:Dell Latitude d240 running Windows XP.HTC Evo smartphone running Android
I can't get these on the network through the e2000.  They can access the internet through the e2000 but only as a guest and therefore don't have the same level of security.  What do I need to do to successfully put the above devices on the network?

View 2 Replies View Related

Cisco Switching/Routing :: Way To Get More Messages Out Of 2950 Set To Syslog

Feb 11, 2012

Is there a way to get more messages out of a 2950 set to syslog? I've turned every logging option I can find to DEBUG, but all I get in my syslog are LinkUp/Down messages and "Configured from console by console". I'd love to see more information such as configuration changes, or even someone attempting to set up DTP on a switchport set to access mode.

View 2 Replies View Related

Cisco Switching/Routing :: 2950 CRC Errors On Switch

Jun 22, 2012

One of my wi-fi site having 2nos cisco 2950 switchs. in that network some D-link unmanageble swithes also there and access points also connected to cisco switchs and D-link switchs.after one or two days i am not able to connect the wi-fi, then i need to restart the access point then only wi-fi is working fine.I upgraded the latest ios also.I connected some access points to the cisco switch ports, those ports are showing crc error messages like below. [code]

View 18 Replies View Related

Cisco Switching/Routing :: 2950 / NIC Teaming On Two Switches?

Apr 25, 2013

I have a server windows 2008 that I would like to have a nic teaming configuration, the server has two nics, each nic is connected to a different switch. One is connected to cisco 2960 and the other is connected to cisco 2950. I have read here in forums about nic teaming but using the same switch. I have not found using different switch. Is this possible?

View 1 Replies View Related

Cisco Switching/Routing :: Set 2950 IOS To Be Loaded From TFTP

Jan 11, 2012

2950 switch has a IOS on flash , but i would like to set the swith like...

1. switch IOS to be loaded from TFTP server .if it fails

2. Loaded from local flash IOS1 , if it fails

3. IOS loaded from local flash IOS2.
does 2950 switch support this feature.

View 2 Replies View Related

Copyrights 2005-15, All rights reserved