Cisco VPN :: ASR901 Support IPsec - Cannot Encrypt ICMP Packet Back

Apr 25, 2013

I'm trying to setup a GDOI based IPsec connection between a cisco AS901 (advanced Metro lic - asr901-universalk9-mz.152-2.SNI ) and a 7606-S.What I see is that the ASR901 is capable of decrypting the IPsec packet but I cannot encrypt the ICMP packet back, so the question is if the AS901 can support IPsec in software. What I could not find in the docs on CCO. [code]

View 1 Replies


ADVERTISEMENT

Cisco WAN :: Unframed E1 / T1 Support In ASR901?

Feb 3, 2013

For a customer we want to deploy the Cisco ASR 901 and connect them to a E1 unframed connection. However I don't see in the documentation that unframed is described and I was wondering if the Cisco ASR 901 is supporting E1/T1 in unframed mode? [URL]

View 1 Replies View Related

Cisco Switching/Routing :: 7450 / ASR901 Only Support MSTP In The EVC Configuration?

Jun 20, 2012

I have RSTP rings consisting of Alcatel 7450's and Foundry FES switches.  I want to insert Cisco ASR901's into these rings and have been testing in the lab.  It appears that the ASR901's only support MSTP in the EVC configuration.  So I would prefer to keep RSTP on the Alcatel and Foundry's and enable MSTP on only the ASR901's. 
 
Topology is:7450-2 <=> Foundry-2 <=> ASR901-2 <=> Foundry-1 <=> ASR901-1<=> 7450-1 with a VPLS between the 7450's.
 
If I enable MSTP in the Foundry's, Alcatel and ASR901 everything works fine.  If I keep RSTP on the Foundries and 7450's, then STP also works, with the exception of a Foundry-2 switch running RSTP, that is located between 2 ASR901's running MSTP.  This switch does not seem to interact with the other switches (i.e. thinks it is the root bridge).Since there are mulitple MSTP boundary's, do the ASR901's need to be in different IST's/instances?

View 2 Replies View Related

Cisco VPN :: 2691 - Packets Not Getting Encrypt And Decrypt IPSEC

Dec 14, 2012

I have 2691 Router conencted to Internet and it is doing Nat.
 
This connects to 3550A  Switch which has connection to 1811W  Router.
 
I setup VPN between 1811W and 3550A.
3550A has connection to 2691 via ospf. 
OSPF is running between 1811w and 3550A.  
1811
1811w# sh crypto isakmp sa
IPv4 Crypto ISAKMP SA

[Code]....

View 7 Replies View Related

Cisco Switching/Routing :: 2611 / 2801 - Configuration For Back To Back Support

Oct 19, 2012

I have 1 2611xm router and 1 2801 router. For my own lab purpose, i want to configure them back to back to support voice services. I don't know what configuration will be required at each end. in 2611xm, i have NM-2V and its also detecting the card, so i hope it will work ? also what commands i need to run on both ends .

View 1 Replies View Related

Cisco Switching/Routing :: 1811W - Packets Not Getting Encrypt And Decrypt IPSEC

Dec 14, 2012

I have 2691 Router conencted to Internet and it is doing Nat. This connects to 3550A  Switch which has connection to 1811W  Router.
 
I setup VPN between 1811W and 3550A. 3550A has connection to 2691 via ospf.
 
OSPF is running between 1811w and 3550A.
  
1811 
1811w# sh crypto isakmp sa
IPv4 Crypto ISAKMP SA

[Code].....

View 5 Replies View Related

Cisco Firewall :: ASA 5540 - IPSec Tunnel / ASA Refuses To Encrypt Traffic But Decrypts It

May 31, 2012

This has to be the most weirdest issue I have seen since the past year on my ASA. I have an ASA 5540 running the 8.4(2) code without any issues until I stumbled upon this problem last week and I have spent sleepless nights with no resolution! So, take a deep breath and here is a brief description of my setup and the problem:
 
A Simple IPSEC tunnel between my ASA 5540 8.4(2) and a Juniper SSG 140 screen OS 6.3.0r9.0(route based VPN)
 
The tunnel comes up without any issues but the ASA refuses to encrypt the traffic but decrypts it with GLORY! below are some debug outputs, show outputs and a packet tracer output which also has an explanation of my WEIRD NAT issue:  

My setup - ( I wont get into the tunnel encryption details as my tunnel negotiations are **** perfect and comes up right off the bat when the ASA is configured as answer only)
 
CISCO ASA - IPSec networking details
LOCAL NETWORK - 10.2.4.0/28
REMOTE NETWORK - 192.168.171.8/32
JUNIPER SSG 140 - IPSec networking details
PROXY ID: LOCAL NETWORK - 192.168.171.8/32
REMOTE NETWORK - 10.2.4.0/28 
HOST NAME# sh cry ipsec sa peer <JUNIPER SSG PEER>
peer address: <JUNIPER SSG PEER>
[code]... 

As you can see, there is no echo reply packet at all as the packet is not being encapsulated while it is being sent back. I have been going mad with this. Also, this is a live production multi tenant firewall with no issues at all apart from this ****** ip sec tunnel to a juniper!!

Also, the 192.168.10.0/24 is another IP Sec tunnel remote network to this 10.2.4.0/28 network and this IP SEC tunnel has a similar Juniper SSG 140 screen os 6.3.0r9.0 at the remote end and this woks like a charm without any issues, but the 171 is not being encrypted by the ASA at all.

View 2 Replies View Related

Cisco WAN :: ICMP Packet Drop On Nexus 7018

Mar 9, 2011

I am running ping between two Nexus 7018 over WAN link ,and I can see some set pattern of packet drop(7.40 % drop) with MTU size 1500.When I ping between my 6500 VSS pair and same Nexus 7018 over different SP WAN link on diffrent location , I am still getting same kind of packet drop (8% drop) with MTU 1500. Has any one else come across this issue with Nexus?

View 1 Replies View Related

Cisco WAN :: ICMP Packet Can't Transit Between 7609 Router

Jul 11, 2012

We have two 7609 routers at different city . Our both 7609 routers make MTU 1800 bytes and when I ping the other router with  packet (1500 bytes) ,it can get thought .But when I ping with 15000 even 1506 bytes ,it didn.t work .As I didn't  disable the DF field .
 
Internet address is 202.112.38.54/30
MTU 1800 bytes, BW 1000000 Kbit, DLY 10 usec,
reliability 255/255, txload 96/255, rxload 81/255

[Code].....

View 4 Replies View Related

Cisco Firewall :: VPN Tunnel Built Via ASA5505 But Unable To RDP / ICMP Back To Internal Network

Oct 10, 2012

I'm able to build my tunnel but unable to RDP nor ICMP back to the internal network. 
 
VPN Client IP: 192.168.200.200
INTERNAL IP:  172.17.130.200
 
my configuration is below:

HOME-ASAFW02(config)# wr t: Saved:ASA Version 8.4(4)!hostname HOME-ASAFW02domain-name hsd1.nj.comcast.netenable password ViPq56cvd3SGvB08 encryptedpasswd 8bcozHCAwCqA5BmN encryptednames!interface Ethernet0/0description OUTSIDE-Connectionswitchport access vlan 2switchport protected!interface Ethernet0/1description INSIDE-Connectionswitchport protectedspeed 100duplex full!interface Ethernet0/2description WiFi-LinkSYSswitchport access vlan 3switchport protected!interface Ethernet0/3shutdown!interface Ethernet0/4shutdown!interface Ethernet0/5shutdown!interface Ethernet0/6shutdown!interface Ethernet0/7shutdown!interface Vlan1description INTERNAL-Networknameif insidesecurity-level 100ip address 172.17.130.129 255.255.255.128!interface Vlan2description OUTSIDE-Link-to-ISPnameif

[code]....

View 12 Replies View Related

Cisco Switching/Routing :: 7200 - QoS Input Policy Doesn't Classify ICMP Packet Based On DSCP

Dec 20, 2011

I have made some test and i noticed that qos input policy does not classify the icmp packet based on their dscp.The "match dscp ef" or "match precedence 5" is not working only the "match protocol icmp" shows hits.
 
We need to classify the different icmp packets based on dscp ( TOS ) for measurement purpose.CISCO 7200, 12.4.25d and 12.4.20T have a same behavior.

View 6 Replies View Related

Cisco VPN :: ASA 5520 8.4.1 IPSec VPN No Matching Connection For ICMP

Jun 23, 2011

I am trying to set up remote access vpn on an asa 5520 running 8.4.1.  I have the ipsec group, policies, and ip pool set up.  When I try and connect with the cisco vpn client I see the following in the logs.  Deny icmp src outside:214.67.39.42 dst outside:24.252.51.73 (type 3, code 3) by access-group "acl_inbound".  Do I need to put in some firewall rules to allow this traffice so that the VPN can connect?

View 9 Replies View Related

Cisco Routers :: Can RV042G IPSec VPN Support Apple IOS IPSec VPN

Apr 29, 2013

I tried any type of combination and just couldn't make it works.  Only PPTP works well. Whether Apple iOS IPSec VPN is supported or not?

View 11 Replies View Related

Cisco Switching/Routing :: IP SLA ICMP Echo Support Catalyst 3560X / 3750X?

Feb 13, 2012

Need to clarify if ip sla icmp echo operation is supported in catalyst 3kx switches (ip services)? on the configuration guide, commands are available, but on the feature navigator, i can't find the feature, only ip sla video operation. i don't have a device to test on here.

View 2 Replies View Related

Cisco VPN :: ASA5540 L2L IPSec And Packet Filtering

Mar 24, 2013

I need to set up several L2L ipsec tunnels using ASA 5540 (8.2) as a central node and ASA 5505s (8.4) for branch offices. So far I've configured ipsec for the sake of testing between a 5540 and one of 5505, but it blocks ICMP between hosts behind ASAs. Although there's an echo response from 5540's inside interface (172.30.0.1) to echo requests from a host behind ASA 5505 and I see ipsec counters growing. I still can't figure it out despite hurting my eyes with cisco manuals for the relevant ASA software versions.

One thing I couldn't understand in the 8.4 documentation - it says I need ACLs to allow ipsec traffic on outside if I don't NAT/PAT it. Isn't it achieved with "sysopt connection permit-vpn" or do I have to do it manually? I've actually tried adding access-groups for the "in" traffic on outside and those ACLs get hits on both ASAs.
 
The packet-tracer shows some weird DROP at phase 6 on 5505, but I see no rule denying this traffic and the description doesn't mention implicit rules. [code]

View 1 Replies View Related

Cisco WAN :: 1921 Provide IPSEC Tunnel Back To Central Office

May 5, 2011

Equipment Cisco1921, HWIC-1ADSL, 2 x GB Ethernet interfaces (Only one used for local LAN) Software IOS Version 15.1(1)T2..I have been asked to configure this router to provide an IPSEC tunnel back to our central office.We have been provided with an ADSL business class 7MB service from Telecom Italia, they have presented the circuit to our office with no terminating equipment (wires only). Telecom Italia have provided us with some IP addressing information as follows (I will not disclose the entire IP address) [code]

I can see that the packet count is increasing both inbound and outbound on the ATM interface. I have read many documents and tried many different way to try and get this resolved, I even logged a call with Cisco but no dice.

View 5 Replies View Related

Cisco WAN :: 1841 / Packet Drop In Ipsec Tunnel?

Oct 23, 2012

I have a 1841 router connected to an ISP (currently SDSL EFM 10Mbps through an ISP modem, the router and the model are connected with a FastEthernet interface). On another location I have a linux server.There is an ipsec tunnel (3des-sha esp) between the router and the linux server (actually done with a crypto mac).The router has a hierarchical QOS policy on the egress interface.When sending traffic from the network inside the router to the linux host without the ipsec tunnel, everything is working fine and throughput is correct.When sending traffic from the inside network to the linux host internal ip through the ipsec tunnel, some packets are lost and the traffic throughput decrease.When sending traffic through the tunnel in the reverse direction (from the linux host to the internal network), everything is fine.I looked at the QOS statistics and the dropped packets counters don't increase. I looked at the egress/ingress interface statistics and no packets dropped there.I lowered the MTU on the egress interface, but it didn't solve the problem. I played by sending various ping icmp packets size, but even small packets are sometimes lost.I tried to check the router CPU, but it seems relatively fine (<= 10%)I captured the traffic on both side, and I see the packets emitted, and then I can see that some of the esp packets of the corresponding side are not received, so it looks like the cisco router is the culprit. This 1841 router is running: 1841 Software (C1841-ADVIPSERVICESK9-M), Version 12.4(24)T4,How can I troubleshoot where and why those packets are lost?

View 0 Replies View Related

Cisco VPN :: Cannot Ping Packet Size Larger Than 9200 Over IPSec On ASR

Feb 22, 2011

I have an existing site-2-site VPN between a Cisco 2621 router (IOS 12.3) and Cisco 1841 (IOS 12.3) and I can ping packet size of 17000 over the IPSec tunnel without any issue:c2621#ping 192.168.230.254 source f0/1 repeat 20 size 17000,Type escape sequence to abort.Sending 20, 17000-byte ICMP Echos to 192.168.230.254, timeout is 2 seconds:Packet sent with a source address of 192.168.208.254!!!!!!!!!!!!!!!!!!!!Success rate is 100 percent (20/20), round-trip min/avg/max = 144/146/148 msc2621#I replaced the Cisco 2621 with a more powerful ASR 1002 running IOS version asr1000rp1-adventerprisek9.03.01.00.S.150-1.S.bin.  However, I can not ping packet size larger than 9200 over the IPSec tunnel:Feb 24 02:42:52.362: %IOSXE-3-PLATFORM: F0: cpp_cp: QFP:00 Thread:015 TS:00000015834854465792 %IPSEC-3-PKT_TOO_BIG: IPSec Packet size 10072 larger than maximum supported size 9216 hence dropping it.Success rate is 0 percent (0/10)asr1002# Why is not working?  Basically the more expensive ASR router can not perform the same task as the old Cisco 2621 router.

View 6 Replies View Related

Cisco VPN :: 7200 Getting IPSEC Decrypted Packet Failed SA Identity

Jan 23, 2013

I´ve try to configure a VPN IPSEC between a Cisco 7200 and Juniper ISG2000.The tunnel looks like good but when a ping is sending, I´ve packets lost and getting the next error:IPSEC(epa_des_crypt): decrypted packet failed SA identity check.My configuration en both sites is the follow: [code] What is the possible problem here. mea be in the Cisco 7200 configuration or in ISG Configuraton??

View 4 Replies View Related

Cisco VPN :: 3925e / IPsec Packet Batching - Increase Latency

Jun 14, 2011

I just installed a new ISR G2 3925e (spe200 integrated) in a VPN environment it works well but I lost latency (it adds around 8-10 ms in the VPN) because of " IPsec packet batching" :Queues multiple packets at the interrupt service routine level after being processed by crypto engine Reduces interrupt context switching by allowing one crypto interrupt for multiple crypto packetsIt's not very good specaly if you tunnel ToIP and/or video streamsI'm trying to find a solution how to disable it without impact other things or is there something planned soon to improve itfyi I use IOS c3900e-universalk9-mz.SPA.151-4.M.bin

View 3 Replies View Related

Cisco VPN :: 2921 - IPSec Tunnel Random Packet Drops

Mar 15, 2013

I'm trying to troubleshoot a random packet drop issue for an IPSec tunnel between two VTIs. For over a month, we didn't see any issue, and starting today, we have up to 30% packet loss across an IPSec tunnel.
 
After some analysis, I concluded that the packet loss happens somewhere on the path from the uc520 to the 2921. Packet counts show up correctly on the uc520 physical egress interface, but the packet count is low on the ingress interface on the 2921.

Pings outside the tunnel along the same path are fine.
 
I also cleared the tunnels on both ends and after they reestablished, the issue was still present.
 
Any pointers on finding where the packets get lost?
  
rr-hq-2921#ping 10.1.13.1 source g0/1 rep 100         
Type escape sequence to abort.
Sending 100, 100-byte ICMP Echos to 10.1.13.1, timeout is 2 seconds:

[Code].....

View 3 Replies View Related

Linksys Wireless Router :: Apple Bonjour Packet Support For WRT110

Jul 10, 2011

Can the WRT110 forward Bonjour packets?  I have one WRT110 running my home wifi network with firmware version 1.0.07.  I've spent hours trying to get my iPad to print to a wireless printer (HP D110a).  I can print and scan from several wireless PC's on the same network but cannot see the HP printer.  I started with the WEP 128-bit and then switched to WPA for a while but no luck so I switched back to WEP.  I've read that other's have had similar problems with this and other Linksys routers.
 
From the iPad point of view I have iOS version 4.3.3.  When I try to Airprint, for example through the Safari web browser, I see no printers available.  I've tried many apps all with the same problem.

View 3 Replies View Related

Cisco VPN :: IPv6 Support On ASA 8.4 IPSEC

May 7, 2011

I need to implement IPv6 for ASA VPN. According to the ASA_8.4_cli_cfg.pdf , IPv6 is not supported on ASA IPSEC vpn and remote client vpn. I do not have a ASA 8.4, any way to verify on ASA8.4 whether the crypto command support ipv6 address ? If  the crypto command do support ipv6 address then probably there is chance it will work.what i mean is eg. crypto map xxx set peer <ipv6 address| ipv4 addres> able to set ipv6 address.

View 4 Replies View Related

Cisco VPN :: 1921 Router Q - How Many IPsec Tunnels Will It Support

Nov 8, 2011

I need to know how many IPsec VPN tunnels one Cisco1921 can support reliably. Haven't had any luck sifting through documentation on the web.

View 2 Replies View Related

Cisco VPN :: Does AnyConnect 3.0 Support IPSec Remote-access VPN

Jul 12, 2011

I've read on Cisco AnyConnect 3.0 Q&A that it supports IPSec remote-access VPN: url...I've downloaded and installed AnyConnect 3.0.0629 Secure Mobility Client, but I'm not able to get IPSec VPN working. There's also no option to use PCF files from the previous Cisco IPSec VPN client. How to get IPSec VPN working on AnyConnect 3.0?

View 2 Replies View Related

Cisco WAN :: Does Router 887va K9 Support EIGRP And IPsec

May 12, 2013

does a router Cisco 887 va k9 support EIGRP and IPsec ?

View 2 Replies View Related

Cisco Wireless :: WLC 5508 Support IPSec To Radius Server?

Jan 23, 2013

I am trying to follow the Fips guide for the WLC5508 and it wants to encrypt the connection to the Radius, either with PSK key wrap or IPsec. I have the options for Ipsec only as the Windoes NPS does not support Key wrap from what a previous user confirmed for me here on the board.. But then found another post that states that the 5508 does not support IPsec?

View 5 Replies View Related

Cisco Switching/Routing :: ATM 8510 Back To Back With 7206vxr 155Meg Only Get 44Meg?

Nov 25, 2012

I have a Cisco 8510msr that is connected back to back with a 7206vxr across a 155Meg connection.I receive lots of Output drops on the 7206vxr interface facing the atm switch. When I do the following command:-

kwdair9#sh atm int atm 1/0Interface ATM1/0:AAL enabled:  AAL5 , Maximum VCs: 4096, Current VCCs: 27 Maximum Transmit Channels: 0Max. Datagram Size: 4528PLIM Type: SONET - 155000Kbps, TX clocking: LINECell-payload scrambling: ONsts-stream scrambling: ON797522 input, 881483 output, 203946630 IN fast, 223768062 OUT fast, 0 out dropVBR-NRT : 110288 Avail bw = 44712   <====  

I only have 44megConfig. is ACTIVEkwdair9# I only get 44Meg of the available 155Meg.There is no QOS on the router and the only commands I can find that vaguely see that refer to QOS are on the ATM switch:-

atm address 47.0091.8100.0000.0007.0d87.b201.0007.0d87.b201.00atm router pnnino aesa embedded-number left-justifiednode 1 level 56 lowest  redistribute atm-static?why this is acting like a DS3 link and not a 155Meg link?

View 4 Replies View Related

Cisco Switching/Routing :: Connecting Two 2951 Back To Back Through A HWIC-4T1 Card

Dec 4, 2011

What cable I need to connect two 2951 back to back through a HWIC-4T1/E1 card ?

View 1 Replies View Related

Cisco Switching/Routing :: HWIC-4SHDSL-E Router Back To Back Connection?

Apr 11, 2013

I have two site that has a copper wire ( 2 wire) connection between each router ( No Telco in between ). Now I want to use 1921 router with HWIC-4SHDSL-E card to connect these two site together. Can I use attach configuration to make the connection reference from the diagram ?

View 1 Replies View Related

Cisco Switching/Routing :: Connecting 2650XM - 2620 Router Back To Back WIC - T1?

Nov 25, 2011

I have 2650XM  router and 2620 Router Both routers have built in WIC  T1 CSU/DSU cards
 
2620Router --
 
2620Router#sh int se0/0
Serial0/0 is down, line protocol is down
  Hardware is PQUICC with Fractional T1 CSU/DSU
  Description: DTE  side
  MTU 1500 bytes, BW 1544 Kbit, DLY 20000 usec,
     reliability 255/255, txload 1/255, rxload 1/255
  Encapsulation HDLC, loopback not set

[code]....
 
My question is that cisco website says there are two type of cable connections for this type of config --which are  --T1 CSU/DSU ConfigurationSet one CSU/DSU to clock source internal, and the other CSU/DSU to clock source line. The linecode, framing, data-coding, and timeslots must be set the same on both CSU/DSUs.Four-Wire 56k CSU/DSU Configuration For my network connection which type of config i should use??Secondly i try to connect these ports by normal crossover cable  it did not work.So for this type of connection i know i need T1 cross over cable--  which has RJ 48 connections at both sides.I check cable from ebay which is RJ45 RJ48 cross over  --  will this cable work in my router to router connection.

View 5 Replies View Related

Cisco WAN :: 1921 / Connect Two Router Back To Back Via 2 Pin Copper Wire?

Jan 8, 2013

I would like configure two router (e.g. 1921) back to back via a 2 pin copper wire.  Can I use HWIC-4SHDSL-E card to do it? What is the configuration I can use?

View 7 Replies View Related

Cisco WAN :: HWIC-4SHDSL-E Router Back To Back Connection

Apr 14, 2013

I have two site that has a copper wire (2 wire) connection between each router ( No Telco in between )Now I want to use 1921 router with HWIC-4SH DSL-E card to connect these two ste together.Can I use attach configuration to make the connection reference from the diagram?

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved