Cisco VPN :: 3745 DMVPN Design Using ISP Dial-up Redundancy At Spoke Side

Apr 14, 2013

I'm working on a new DMVPN configuration with one 3745 at the hub site and a 1941 the spoke. I have internet through gsm for the primary line at the spoke and a dsl line for  backup on spoke.I have one tunnel interfaces on both the hub and the spoke.Currently my VPN tunnel is coming up fine , however we are planing to do an ISP failover at spoke side . since in the tunnel interface i can only define one "tunnel source interface" which is gsm cellular interface , i don;t know how to use my another ISP for the same tunnel interface as it will always initiate traffic from gsm.
 
do i have to create another tunnel interface with same hub site , or do i need another hub as backup? is their any other way to create loopback interface and initiate the traffic from that loopback?

View 1 Replies


ADVERTISEMENT

Cisco :: Config DMVPN Between 2 Hub Location And One Spoke?

Nov 19, 2011

suppose i have 2 hub location and one spoke and i want to config DMVPN between them and want to keep 1 HUB as active and 2nd HUb as passive then how its possible.

View 2 Replies View Related

Cisco WAN :: 2900 - LAN Side Redundancy?

Nov 14, 2011

We will be getting a circuit from the same ISP at two of our sites and will be doing eBGP.  Couple of notes. 1. We are fully aware of the risks associated with depending on a single ISP and have mitigated them as much as possible with the ISP. 2. We will be getting assistance on the eBGP setup from the ISP, so I’m not as concerned with that config at this point.
 
Site Summary
 
Site A:Cisco 2900 Series (RtrA) connected to single Ethernet based ISP circuit (ISP-1-A)eBGP will run between RtrA and ISP-1-A, default routes from provider onlyLayer 2 Switch (SwA) connected to LAN of RtrA and uplinks to SwB
 
Site B:Cisco 2900 Series (RtrB) connected to single Ethernet based ISP circuit (ISP-1-B)eBGP will run between RtrB and ISP-1-B, default routes from provider onlyLayer 2 Switch (SwB) connected to LAN of RtrB and uplinks to SwA
 
I need advise on the LAN side redundancy. Our goal is redundancy; load balancing is not a concern (If load balancing ever becomes a concern I will look at GLBP). We have several devices on the LAN side of the routers that can only use a single gateway. Given that I’ve surmised I need to use HSRP in some way for LAN gateway redundancy.

1. HSRP with Object Tracking, No IGP.HSRP handles LAN gateway failover if a router dies. Object tracking ensures LAN gateway failover if an interface fails or if an interface is up, but there is an upstream traffic issue. ie. track the physical WAN interface and use an IP SLA icmp to track a specific upstream IP incase of an upstream traffic issue.
 
2. HSRP with OSPFHSRP handles LAN gateway failover if a router dies. OSPF redistributes eBGP default routes to RtrA and RtrB so that each router should have a route to the ISP even if they loose their local ISP circuit.  i.e if ISP-1-A on Router A goes down, Router A knows to send traffic out ISP-1-B via RtrB. In other words, traffic enters RtrA LAN, but exits on RtrB WAN.
 
3. HSRP with iBGP HSRP handles LAN gateway failover if a router dies. I have no experience with BGP, but assuming this would work similar to the OSPF solution above except for the required iBGP config and possible route reflectors?

View 2 Replies View Related

Cisco VPN :: ASA 5520 - Communicate To EzVPN Client Side Internal IP From Server Side

Mar 13, 2013

i configured cisco asa 5520 as cisco ezvpn server and cisco 891 as ezvpn client .the configurtion is working fine.i am using client mode on the ezvpn client side.but my quesion is , is it possible to communicate to ezvpn client side internal ip from the ezvpn server side?and one more thing what is the benefit of network extension mode on the client side and how it will work what are possible changes need to do in the server and the client side.

View 4 Replies View Related

Cisco Firewall :: ASA And UC540 Side-by-side Traffic?

Mar 17, 2013

I'm trying to setup an ASA and a UC540 side by side, to utilize the ASA for data networking and the UC540 for voice. This 'should' work fine, I just seem to be having an issue where the ASA seems to be blocking traffic from the voice network as it passes through.So here is the LAN setup:ASA: 1.1.1.1UC540: 1.1.1.2The UC has a voice vlan 10.1.1.1/24 and a service module at 10.1.10.1/30My PC uses the ASA as its default gateway, 1.1.1.1The ASA then has static routes to the UC networksRoute 10.1.1.1/24 1.1.1.2Route 10.1.10.1/30 1.1.1.2Ping from PC to the UC networks works fine. However, ping from the UC networks to PC fails. ASA logs show traffic being denied due to not having an established connection or something.My guess is that the traffic is being blocked because the egress and ingress paths are different? Traffic from the PC goes to the ASA, then gets routed to the UC and it works. However in the other direction, traffic from the UC is going directly to the PC and bypassing the ASA, because its a directly connected network and doesn't have to route through the ASA to get to the PC. The reply traffic from the PC DOES go through the ASA following its route table, thus the issue of the ASA not seeing the established connection?Same-security inter and intra interface is enabled.So I think I see the issue, I just don't know how to fix it. Is there something I can configure on the ASA to allow for this? My only other option would be to configure a /30 on a new vlan to handle the routing between the UC and ASA or something, but that seems like its going to make this simple setup way too complicated with extra networks, vlans, trunks, etc.I am running ASA version 8.4.5?

View 1 Replies View Related

Linksys Wireless Router :: E1500 LAN-side Works / WAN-side Just Goes Away

Jan 30, 2013

My E1500 enters a state where the LAN-side (broadcast, etc.) works, but the WAN-side (internet connection) just goes away. If I go unplug and replug the E1500 the internet connectivity comes back.When this happens, the wireless indicator on my desktop (Dell with Intel wifi) says I have an internet connection, but I clearly don't.

View 2 Replies View Related

Getting A 64K Dial Up Modem Or A 64K Dial Up External Adapter?

Feb 15, 2013

I need to purchase an 64K dial up modem or a 64K dial up external adapter

View 1 Replies View Related

Cisco VPN :: L2L Hub And Spoke Using ASA 5510

Feb 18, 2012

I'm setting up a L2L VPN Hub and Spoke. I have 3 sites (1 HUB and 2 SPOKES).
 
HUB-----------SPOKE1
|
|
|
SPOKE 2
 
HUB and SPOKE 1 is okay. My problem was the communication between HUB and SPOKE 2. PING failed on both directions. BTW, I am simulating this only in GNS3. :-). The configuration for HUB and SPOKE 1 are the same also for HUB and SPOKE 2.
 
Here is my show isakmp sa and ipsec sa on HUB
 
ciscoasa# sh isakmp sa
Active SA: 1
Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)
Total IKE SA: 1

[Code].....

View 4 Replies View Related

Cisco VPN :: ASA5505 And Spoke VPN Between Multiple Sites

Aug 12, 2012

I currently have a "hub" ASA 5505 that links to 4 sites running 877 routers. From the hub network i can connect to all sites fine but what i would like to do is to almost compartmentalise the various VPN links into little clusters.The hub ASA 5505 basically provides IP telephony through the VPN's from a PBX allowing the users at the other end of the VPN to make outgoing calls and recieve incoming calls. However, a couple of the sites would like to be able to call between eachother internally via the hub. This obviously requires traffic to be allowed between their various networks. Currently when you attempt an internal call it rings but there is no audio either way. I assume this is due to access list restrictions. I am not even sure whether what I am trying to achieve is possible. I've attached the hub and 2 spokes below. The ideal end result would be interconnectivity between the two spokes via the hub, from reading up it would seem that its possible but i can't quite get my head around it! Would it involve using different subnet masks at the hub?

View 1 Replies View Related

Cisco VPN :: 2800 / Tunnel Is Not Forming Between Hub And Spoke?

Jan 12, 2012

i am trying to set up a tunnel connection between twO 2800 routers A<->B

1) destination  ip is-204.x.x.x-ROUTER A2) source  ip is 166.x.x.22-ROUTER B The router B has the modem connected to GE0/1 whose interface ip is 166.x.x.22 The ip-forward-protocol nd is configured as  below

ip route 204.x.x.x 255.255.255.255 166.x.x.21

Also tunnel 1 configuration,isakmp policy are configured properly when i run show crypto isakmp sa it shows MM_NO_STATE,i checked the preshared key on both ends and they are same.whenever i remove the ip address of the interface Ge0/0 and ip route i can ping the 166.x.x.21  which is the modem gateway.when i revert back the configuration to the above ,the ip 166.x.x.21 cannot be pinged,the dsl connection is live though.ways to fix this so that i can make this tunnel state to QM_IDLE?

View 1 Replies View Related

Cisco Routers :: Hub And Spoke Between SA540 And RV120

Jul 11, 2011

I want to build a "hub and spoke" topology for one of my clients. For the "HUB" , I'm planning to use an SA540, with a static public IP provided by a 4Mb SDSL. For the "spokes" (21 at the moment), I'm planning to use RV120. They will be behind a NAT, provided by a "SAGEM LIVEBOX", and a static public IP. The boss will connect to the HUB using Cisco VPN client, or quickVPN, and get access to all the spokes. Some spokes will have to connect to each other, via the HUB. I searched a long time on this forum and reading documentation, but I didn't find at the moment the answer to my question : is this topology suitable with the choosen hardwares ?

View 7 Replies View Related

Cisco WAN :: 2851 How To Make Spoke Going To Hub To Get To Internet

Mar 23, 2011

Imagine MPLS network. Total of 4 sites.
 
HQ-HUB is the only site with access to the Internet.
 
So if Site1 or Site2 or Site3 need to access the Internet, traffic will have to go through HQ-HUB and from there reach the Internet.I have routes 2851's on the spoke sites. Which command or mechanism you would explore in this case to make the spoke sites point to the HQ-HUB to reach the Internet?
 
Would you do this based on DNS settings or getting an access-list & static route defining when the spoke routers traffic need to go the internet, point to the HUB-HQ as the default?

View 3 Replies View Related

Frame Relay Hub And Spoke Resiliency?

Apr 7, 2011

I am having real problems trying to build resiliency into a hub and spoke frame relay scenario. I know the hub is a single point of failure. Is there any way to put some resilience into the network? There is 4 attached branch offices.

View 8 Replies View Related

Cisco VPN :: Allow Access For VPN Client To Spoke Network Through ASA 5520?

Mar 26, 2012

I'm trying to set-up 3 remote access groups on an ASA5520 running version 8.4(3) software so that remote clients connected via Cisco VPN Client can also access spoke networks which are also connected to the ASA.   I've previously set this up on ASAs running v7.2 software without issue but don't seem to be able to do the same here and can't for the life of me figure out what's wrong!
 
I have set-up the 3 remote access groups:
 
Group 1 - subnet 192.168.1.48/28Group 2 - subnet 192.168.2.0/25Group 3 - subnet 192.168.3.0/25
 
My remote access user groups can all connect to the head office subnet (10.0.0.0/8) without issue.  But only one of the groups (192.168.1.48/28) appears to be able to access the spoke sites (172.30.10.0/24 and 172.30.20.0/24) that I have set-up.  However, I can't see what the difference is between the 3 groups I have configured so can't understand why it works ok for one group and not the others?
 
When I use the packet tracer, it tells me that the flow is being dropped at the VPN encryption phase but why is that?  How can I find out more? Here's the relevant config on my ASA:
 
!same-security-traffic permit intra-interface!crypto dynamic-map remoteuser 5 set transform-set ESP-3DES-MD5crypto dynamic-map remoteuser 5 set security-association lifetime seconds 28800crypto dynamic-map remoteuser 5 set security-association lifetime kilobytes 4608000!crypto map outside_map 65000 ipsec-isakmp dynamic remoteuser!ip local pool pool1clients 192.168.1.49-192.168.50.54ip local pool pool2clients 192.168.2.1-192.168.2.126ip local pool pool3clients 192.168.3.1-192.168.3.126!access-list split-tunnel-pool1 standard permit 10.0.0.0 255.0.0.0 access-list split-tunnel-pool1 standard permit 172.30.10.0 255.255.255.0 access-list split-tunnel-pool1 standard permit 172.30.20.0 255.255.255.0  !access-list split-tunnel-pool2 standard permit 10.0.0.0 255.0.0.0 access-list split-tunnel-pool2 standard permit 172.30.10.0 255.255.255.0access-list split-tunnel-pool2 standard permit 172.30.20.0 255.255.255.0  !access-list

[code].....

View 12 Replies View Related

Cisco WAN :: 2900 ISR - Upper Limit For EIGRP Hub And Spoke Setup?

Aug 9, 2011

Is there any suggested upper limit to a single EIGRP hub-and-spoke design (i.e. with a single central router)?
 
Router is a 2900 ISR
 
I'm vaguely aware of a similar design limitation with OSPF areas where no single area should contain more than 40 - 80 routers. Could be heresay...

View 13 Replies View Related

Cisco WAN :: 2900 Isr Suggested Upper Limit For EIGRP Hub And Spoke Setup

Mar 25, 2013

Is there any suggested upper limit to a single EIGRP hub-and-spoke design (i.e. with a single central router)?Router is a 2900 ISR,I'm vaguely aware of a similar design limitation with OSPF areas where no single area should contain more than 40 - 80 routers.

View 8 Replies View Related

Cisco WAN :: How To Run GetVPN On 3745

Jun 6, 2011

I need to connect site to MPLS provider and run Cisco GETVPN.Problem:I have been browsing Cisco Feature Navigator Tool and to my surprise when I enter "platform:3745" I can't find an image compatible with GET VPN. there is no workaround (image) I can run GET VPN on 3745? I need IP routing (BGP, OSPF) as well.

View 1 Replies View Related

Cisco WAN :: 3745 IOS 15.2 Changed Commands

Jan 22, 2012

we've got a pair of old 3745's that are getting upgraded to new  2911's, and I'm trying to run IOS 15.2 on the new routers to get them most current before going into test and production use.The routers are doing BGP, IPv4, and HSRP, and I'm trying to put one in  at a time as to not have to big bang everything at once.  I'm putting  the one that matters least in first, and basically using the same config  as the old one, which was running IOS 11.
 
I was using "no ip mroute-cache" on ethernet interfaces, and it says  that command is deprecated and I should use the MFIB commands instead.  Darn if I know what that means, I believe it was set up so the ethernet  interfaces had IP multicast fast switching disabled, which was set up by  our vendor 10 years ago so I'm not sure if it matters. It would seem  logical to me this would have an impact on HSRP and speed of failover.   Does this matter, and if so how in the world do I do this with IOS 15.2?The second one is the use of "no fair-queue" on our serial connection  for a T1.  This command isn't there either, and I'm not sure if I even  need to bother on this. It was set up on the old router on a T1 Frame  Relay circuit.

View 2 Replies View Related

Cisco WAN :: What Is Best Router To Be Replaced 3745 EOL

Jan 15, 2012

There is no special requirements, just need new hardware with some reserve availability. As for now it's 3745 EOL and I assume to use 3945.

View 4 Replies View Related

Cisco WAN :: Routing With 3640 And 3745 Via WIC-2T

Feb 8, 2012

I have two routers I am trying to connect via the WIC-2T port. I can ping from router to router, but not from my PC (192.168.2.122) to the 3745 (10.0.1.3)..

3640:
Current configuration : 1846 bytes
!
version 12.2

[Code].....

View 15 Replies View Related

Cisco WAN :: GRE Over IPSEC On 3745 With VPN Module CPU

Jun 19, 2012

i just configured GRE over IPSEC on my Cisco 3745 router with VPN module installed. As soon i hit 25Mbps traffic, my CPU is touching 80%.
 
What maximum Traffic 3745 with GRE over IPSEC it can support?
 
Also show process CPU sorted dont show any evidence of which process eating it up.
  
sh processes cpu sorted
CPU utilization for five seconds: 75%/75%; one minute: 77%; five minutes: 78%
PID Runtime(ms)   Invoked      uSecs   5Sec   1Min   5Min TTY Process

[Code].....

View 3 Replies View Related

Cisco :: Upgrading 3745 To A 3945 Device?

Mar 29, 2012

I have to replace the 3745 which is our edge router (running (C3745-ADVIPSERVICESK9-M), Version 12.4(23), RELEASE SOFTWARE (fc1)) with (I think) a 3900 (drawing from memory, I haven't actually seen the device yet).In an ideal world, I SHOULD be able to just set term length to "0", do a show run, copy that off to a text file, and then paste it into the new one...

View 19 Replies View Related

Cisco WAN :: How Many NM-32A Or NM-16A Module Can Be Installed On 3745 And 3640

Jul 19, 2011

how many NM-32A or NM-16A module can be installed on 3745 and 3640 routers?

View 1 Replies View Related

Cisco WAN :: 3745 / Migrating Configuration To New Router With Different IOS?

Sep 28, 2011

One of my clients has an older 3745 running IOS 12.3 and we are looking at replacing it with a new 3945 that runs IOS 15.0. This router is also configured with CME. Is it possible to migrate the current 12.3 config to load on the new 15.0 IOS? This will be my first encounter with 15.0 so I don't know what I am up against at this time. I am just hoping I don't have to retype all the ephone config, dial-peers, etc

View 2 Replies View Related

Cisco WAN :: 3745 - Upload IOS Using X Modem Or Tftpdnld

Aug 14, 2010

Our 3745 router goes into Rommon  mode . I am trying to upload the ios using x modem & tftpdnld , but it giving error " monitor: command 'copy not found" for x modem & " monitor: command"tftpdnld" not found" for tftpdnld.

View 3 Replies View Related

Cisco WAN :: 3745 - Difference Between PA-POS-2OC3 And NM-1A-OC3SMI

Apr 18, 2012

i have Cisco 7200 VXR in which OC3 circuit is terminated. Module installed in VXR is PA-POS-2OC3 Now i have to move this connection to 3745 Router.

What i need to know which card is required to connect OC3 in cisco 3745, as per online search this module NM-1A-OC3SMI will work, but i am confused with term ATM OC3 module, so is this the right card to connect same OC3 circit on 3745?

View 20 Replies View Related

Cisco :: Voice And Data Network Using 3745 And 2811?

Sep 7, 2012

I intend to deploy a voice+data network using some old 3745 and 2811. The network in effect has six 3745 in a hybrid topology at different locations and each having three WIC-2T, one WIC-4T, three NMHDV-2E1. That's pretty much juicing out the maximum from these routers These will serve as my core routers and for access I will be using my 2811s with more VWICs and lesser WIC-2T to give voice and data to subscribers. The 2811s will have links to multiple 3745s. The NMHDV-2E1 will serve for the voice needs at the 3745 locations. All the WAN links will be E1. All my telephones will be on analog voice using traditional EPABX with CEPT/ PRI E1 cards for connecting to the routers. And for data, ethernet ports.Two of the routers will have E1 links to the PSTN and Internet which has to be extended to all my folks. Now, for the tricky part, all my network modules are refurbished stuff from ebay and all the ports will have links on them. I intend to use OSPF with only the backbone area.

View 7 Replies View Related

Cisco WAN :: How Many Subrate T3/E3 Port Card Can Be Installed In 3745

Dec 21, 2011

I have a Cisco 3745 Router with 1 Subrate T3/E3 port card installed on it. We want to add another T3/E3 card,
 
Q1- Can i add another card in this model? Q2- Can we multilink bundle up two T3/E3 cards?  (current we have a single DS3 P2P connection between two office, so want to increase the bandwidth)

View 4 Replies View Related

Cisco WAN :: 3745 Virtual-Access Interface For VPDN

Feb 11, 2012

We have a 3745 LNS router, currently there are less number of users connected.when a user dials request authenticated and one virtual-access interface is formed in LNS router.Now the user is disconnected the vpn and connected to VPN again in this case, whether the user is connected to the same virtual-access interface which was assigned before disconnecting or different virtual-access interface is created.

View 0 Replies View Related

Cisco WAN :: 2600 Router / IBM 3745 Modem - SNA To Ethernet Via 56k

Jun 5, 2011

trying to establish a connection on  an ibm 3745 controller via two IBM 5822 modems to a cisco 2600 router using sdlc encapsulation secondary bridging data from the serial port to the E/Net port to run the 3270 client ???

View 19 Replies View Related

Cisco Security :: 3745 - VPN - Reserving Pool Addresses?

Dec 11, 2012

I have created a PPTP VPN on a cisco  3745 router, and a pool of addresses for the VPN clients. Now i want to find a way to reserve the addresses in the pool for specific machines,  for example,  if machine A connects to the VPN it should always be given the IP address a.a.a.a and that address should never be assigned to any other machine even if machine A is not connected to the VPN.

View 1 Replies View Related

Cisco WAN :: Have ADSL Router (887) At Site Which Has GRE Tunnel To 3745

Sep 14, 2011

Have an ADSL router (887) at a site which has a GRE tunnel to to a 3745.The GRE tunnel is setup with default ip mtu of 1476.If I ping from the 3745 to the ADSL router (or in the reverse direction)with a packet size of 1500 bytes this works fine.However if I ping from a router (R1) that is directly connected to 3745 to the ADSL router with a pkt size of1500 bytes then the first ping succeeds while the subsequent pings fail.Pkt sizes less than or equal to 1476 work okay.Pinging between R1 and the 3745 with a packet size of 1500 bytes works fine.If I set the tunnel ip mtu size to 1500 bytes then it works.This is obviously something to do with fragmentation, but I don't undertsand why itdoesn't work with the default mtu set to 1476.

View 11 Replies View Related

Cisco WAN :: Does 3745 1FE2W Module Support MPLS

Jan 16, 2011

I have a couple of these routers in the lab with a very basic MPLS configuration on them.  Everything works fine on the fixed interfaces but I cannot get the ldp neighborship to form between the 1FE2W interfaces on each router.  Does this module support MPLS?

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved