Cisco :: Using Advanced Baseline Template To Push Change LMS 3.2.1
Oct 13, 2011
LMS 3.2.1, what is the correct baseline template syntax to accomplish the requirement 2:
Requirement 1
• Check if the router is running H323: You can do it looking for the command “h323-gateway voip interface”. If that command is found on a router then it is an H323 voice gateway
• Configure the global command: voice class h323 1
[Code]...
We are using a CISCO1921-SEC (ISR) with IOS 15.1 and we configured a "crypto isakmp client configuration group". We can connect with the "Cisco System VPN Client Version 5.0.07.0410" via IPSec/UDP.
1. Is it possible to push routing informations to the System running the VPN Client ? A the moment all traffic is routed to the tunnel but we like only one route to the network permitted with "pool ..." in the "crypto isakmp client configuration group NAME" section.
2. We searched for changing from upd connection to tcp connection via special port. Is it possible with IOS 15.1 on the CISCO1921-SEC ? Is there something possible like "iskamp ipsec-over-tcp port 10000" ?
According to cisco manual in order to change SDM template i need to reboot switch, but when i have C3750-X stack do i need to reboot stack or maybe will be enough reboot in sequence the stack members?
I have created a baseline template to run compliancy checks, I understand that lines beginning with a + are mandatory and lines begining with a - should not be on the router. What I need to know is, is there a catch all for any other commands on the router config (startup or running) but not mentioned in the baseline? For example, lets say this is my baseline:
+ service timestamps debug datetime msec + service timestamps log datetime msec + service password-encryption + hostname [hostname]
The router comes back as compliant as it has all the above lines. However there is obviously more config on the router, but this doesn't show? So I know I can get commands that are in the baseline but not on the router; but what about the other way round - on the router but not on the baseline? Surely this exists - at the least from a security point of view, an attacker could well have configured the Dot11Radio int, however without entering the command with the minus prefix I can't tell? LMS 2.6
I've to connect 2 building with fiber, for this I use 2 HP baseline switches.How do I have to configure the 2 switches so that i can have PC connected to switch 2 able to "talk" with the server connected to switch 1 ?
We need to implement VLANs on my company's network. I have 3750 L3 swtich, ive setup 3 vlans for testing. ive setup SVI everything.now how do I connect it to 3com that will also use VLANs. should I set trunk port of cisco and 3com? or no need?
Using LMS 3.1 in win 2003 SP2. Recently experiencing a problem, not able to fetch/push config for the n/w devices. I deleted and re added the device to lms and found able to perform the task. There was no connectvity issue during the problem.
I have a VPN tunnel with an WRVS4400N (teleworker) on one side and sonicwall firewall on the other. I need the telework's router to know to push two ip's through the tunnerl, 9.19.178.( ) and 172.20.0.( ). It looks like when you setup the tunnel you can only do one. The tunnel does work with 9.19.178.( ) but how do I tell the router to also push 172.20.0.( ) traffic through the tunnel as well?
I am having an issue here. I have 2x 5508 that each have 100 AP license and a little under 200 access points. Basically all of the access points are using DNS to connect to the primary controller that has the DNS entry. Basically half of my access points need to be on the second controller and in order to do this I have been using the high availability mode of each access point to push them to the second controller IP address.It was working perfectly until now. I have pushed 28 access points to the second controller and the last two I need to push at this location just keep resetting on the primary controller. Neither controller is configured as master controller.
My organization has about 15 workstations, all running XP Pro. Our server is running MS Server 2003.Is there a way to push Security Essentials definition updates to all these machines behind the scenes, rather than having each one download the updates individually?I would like to automate the process, if possible, so that once a week the update file is downloaded from MS update, then applied to all workstations, but I don't know where to begin.
Ok so the mail flows to the Barracuda using a static 1:1 NAT configuration and then gets delivered from the Barracuda to the Exchange server. I want to implement active sync (Direct Push) for Windows mobile devices. They need to communicate with mail.domain.com over port 443. The problem is I want mail to continue to flow to the Barracuda, but direct Direct Push traffic to the Exchange server.I cnow I can't implement two 1:1 NAT mappings from the same external hostname to 2 different servers.
We have 30+ wireless access points controlled by a Cisco 4400 Series WLC (mostly AP1231's and some AP1242's). The WLC's system time is set by a network NTP server and is correct. However the APs clock is an hour behind that of the controller.
is there a way on a WLC5508 to push the same configuration on multiple APs in 1 shot?I need to change the High Availability settings on most of the APs (not all). And the only solution i find is to do 1 by 1...
I want to add the command "no logging event link-status" to all switchport mode access ports EXCEPT for the ones with the following switchport access vlans: 4022,4032,4042,4052,4072 & 4082. How do I create a compliance template to do this? LMS 3.2, RME 4.3.1
Have upgraded WCS to 7.0 due to a Mesh network feature we needed, but now see I can no longer edit the AP migration templates. The interface allows me to create or delete them but the command dropdown box does not show an Edit option. So now for every AP I want to migrate I need to create a new template before I can select the AP's and migrate them. I still need to migrate about 220 APs....
Looking though the function it tells me to click on the Migration Template name. However neither in MS IE nor Firefox this works, there is no link activated.
I am facing problems of the WPS Push Button on the Linksys WRT610N version 2.0 router which has stopped working. I don't see the Blue LED blinking. The WPS button no more works on the router. It was working before. I did a firmware upgrade. Could this be the cause?
I am trying to create a very basic template in compliance manager that checks for interfaces that aren't members of specific VLANs. VLAN 10 being one of them. I want to match interfaces assigned to VLAN 20. According to the documentation I have read, the following range statement should work because 10 falls between 3 and 19:
With the preceeding statement, however, interfaces assigned to both VLAN 10 and VLAN 20 are matching the rule. With this specific rule (not a range), only interfaces w/VLAN 20 are processed by the template, which is expected. We actually have numerous VLANs that we want to exclude/include. I only mentioned VLANs 10 and 20 for brevity.
Any recommendation for creating a configuration template for the SRP521W? I can use the Admin-->Backup Config to get a xxx.cfg file, but I cannot edit it with notepad++. Also, i know the config can be view via view-source: [URL], but how would I load a modified copy of this back to the router?
Me and some friends of mine talking about making a small website for us to share our photos together and be able to add comments under each photo, for example or even better with a simple forum. I have a bit experience making website, but we prefer to use web templates / packages for that also we would be able to add comments( built-in Code, no external links for those codes be needed). We prefer to have our website sure we know there are thousands of free photo-sharing websites out there.
just to relieve a little those who complain for the loss of functionalities/control caused by the new firmware, I want to let you know that yesterday evening when I came back home the router was bricked. After more than 2 hours of tests with the online support, they ended up the device has to be replaced.To add insult to injury, I ALSO HAVE TO PAY to ship my router to Cisco warehouse. I couldn't believe my eyes... It's not for the 10 bucks it costs the shipment (even if 10 bucks are much better in my wallet than in Cisco's), but I already spent around 300 bucks less than 2 months ago to buy the two devices and now I have to pay to fix something I have not broken.
Region : UnitedKingdom Model : TD-W8951ND Hardware Version : V5 Firmware Version : TD-W8951ND_v5_120522 ISP : N/A
The wireless adapter settings page has an entry for 'PIN' and 'PBC' for WPS.Selecting either always results in the client station requesting the routers pin, indicating that the pushbutton selection is not working properly.The router was doing this with the version of hardware that it was shipped with. i have downgraded to 120522 and the router is behaving exactly the same.Has anyone successfully configured the router for pushbutton connection? do not suggest that we use the pin setting as we have a requirement for dumb devices to connect to wireless and they only support pushbutton connection.
Asking about Packet Tracer. I currently use packet tracer 5.3.2.Can you give me any link where to download router template on packet tracer? I want to explore cisco 2821 but packet tracer 5.3.2 has an existing of cisco 2811 only then, I tried to add the 4 ports of RJ11 but I cannot see the 4 port telphone.
I get that to avoid fragmenting the packets we need to reduce the MTU to 1492, fine, but should the MTU restriction be applied at the virtual-template (server)/dialer (client) or on the physical ethernet interfaces?If I apply it to one or the other, which takes precedence? Should I just apply it to both the virtual/dialer interfaces and the ethernet interfaces?
I am trying to apply WLAN template from NCS to two WLCs 5508 and I receive this message."Another WLAN with same SSID and either WPA1/ WPA2/ WPA1+WPA2 is enabled. Please change the Layer 2 security policy."The template has layer 2 security with WPA+WPA2 enable and 802.1x.I have other WLAN template with other name and other SSID with the same security policies with no problem to apply.
The business i work for uses a "Do it myself" template for their website. (this is through their webhosting company). I can not add FTP to this website, we have to completely redo it with code and whatnot in order to have access to FTP. We would like users to download a template from our website (no problem) and then send us their artwork files back to us. These can be upwards of 150mb. Is there another option that i am not aware of to do this? Can't use email, has a limit of 25mb.