Cisco VPN :: Lan To Lan Dynamic VPN With IPSec And QOS On Physical Interface 3800

Feb 3, 2011

I have a network with Two 3800 Cisco Routers as Central and many Cisco 2811 Router as Branches. Now I set two Tunnel on each router connection Interface FastEthernet from each 2811 to SubInterface Fastethernet on 3800. I set OSPF as Routing Protocol and I configure QOS on Tunnel connections. Then I have a safe connection with backup connection between 3800 Router and each 2811 Router. Now I want to set VPN with IPSEC and Certification Authentication with CA Server for Security all connection. I set IPSEC and ISAKMP and Certificate on each Router and Set Dynamic VPN on Cisco 3800 Router and Static VPN on each Cisco 2811 Router. Now when if I configure tunnel with Crypto map, it works correct and all packets are encrypt. But if I try to set crypto on physical Interface(because I want to set qos on tunnel then protect packets on physical interface) however all packets are routed but crypto and encrypt d o not work. Set qos on tunnels and crypto on fastethernet interface.

View 4 Replies


ADVERTISEMENT

Cisco :: L2L IPSec Tunnel - ASA To 3800 Router

Mar 3, 2011

I have been struggling for a few days with getting site-to-site traffic working across a L2L IPSec tunnel. At this point, I have the tunnel up, and I see packets being decrypted on the correct IPSec SA's when I ping from a local network computer on the ASA side to a local network computer on the router side. I cannot ping from one side to the other, but those packets are getting through. We have another L2L tunnel that is from that ASA to another remote site's ASA, and that is functional. I have mirrored the configuration for ACLs, etc. from that site, so I believe that the issue is with the packets getting incorrectly translated by the NAT/NONAT statements/ACLs on the router side.

View 8 Replies View Related

Cisco VPN :: L2L IPSec Tunnel - ASA To 3800 Router?

Mar 2, 2011

I have been struggling for a  few days with getting site-to-site traffic working across a L2L IPSec  tunnel.  At this point, I have the tunnel up, and I see packets being  decrypted on the correct IPSec SA's when I ping from a local network  computer on the ASA side to a local network computer on the router side.   I cannot ping from one side to the other, but those packets are  getting through.  We have another L2L tunnel that is from that ASA to  another remote site's ASA, and that is functional.  I have mirrored the  configuration for ACLs, etc. from that site, so I believe that the issue  is with the packets getting incorrectly translated by the NAT/NONAT  statements/ACLs on the router side. 

The ASA is: Cisco Adaptive Security Appliance Software Version 8.2(2)Hardware:  

ASA5520, 512 MB RAM, CPU Pentium 4 Celeron 2000 MHz The router is:Cisco IOS Software, 3800 Software (C3845-ADVENTERPRISEK9_SNA-M), Version 12.4(20)YA3, RELEASE SOFTWARE (fc2) Router Config:!version 12.4!card type t1 0 0!no ip cef!ip multicast-routing no ipv6 cef!crypto isakmp policy 10 encr 3des authentication pre-share group 2crypto isakmp key xxxxxxx address nn.nn.12.130!crypto ipsec security-association lifetime seconds 86400!crypto ipsec transform-set 3DES-SHA esp-3des esp-sha-hmac !crypto map NOLA 11 ipsec-isakmp set peer nn.nn.12.130 set transform-set 3DES-SHA set pfs group2 match address VPN-ACL!controller T1 0/0/0 fdl both cablelength long 0db channel-group 1 timeslots 1-24!interface Loopback0 ip address 1.1.1.1 255.255.255.252 ip virtual-reassembly no ip route-cache crypto map NOLA!interface GigabitEthernet0/0 no ip address duplex auto speed auto media-type rj45!interface

[code]....

View 15 Replies View Related

Cisco WAN :: Setting Up IPSec Tunnel Between 3800 And 2600 Routers?

Jan 19, 2013

I'm setting up a IPSec Tunnel between 3800 and  2600 routers over the internet.
 
Do I need to create a tunnel interface as they suggest in this document?  [URL]
 
I just watched a couple of you tube videos saying I don't need to do that...

View 8 Replies View Related

Cisco WAN :: 877 - Virtual Interface Goes Down But Not Physical Interface

Apr 5, 2011

I have five 877 routers connected to ADSL circuits provided by Vodafone. Each has a VPN tunnel back to a PIX.
 
Occasionally one of the sites will lose it's connection to the PIX.
 
When we check the log, we find entries like these:-

Apr  5 01:31:54.085 UTC: %LINEPROTO-5-UPDOWN: Line protocol on Interface Virtual-Access2, changed state to downApr  5 01:33:19.344 UTC: %CRYPTO-

[Code].....
 
As you can see, the physical interface (ATM0) is not being reported as changing state to down, neither is the Dialer interface.
 
When the router is in this state we have to SSL to the public IP address of it and manually restart the ISAKMP SA.
 
When the router sees the ATM interface go down and subsequently come back up, the VPN connection to the PIX also recovers.
 
So - in a long winded way I think I'm asking....why does the Virtual interface go down and is there anything I can do to stop it happening?

View 3 Replies View Related

Cisco WAN :: ME 3800 Ten Gigabit Interface Not Showing

Dec 10, 2012

I am using a Cisco ME 3800 switch with 24 Gig and 2 Tengigabit interface. But after configuring the Tengig int with ip add and negotiation it is no know visible in the switch. Instead TenGig I am seeing two (Gi0/1 and G0/2). Not even showing the Tengig in the running config.

View 3 Replies View Related

Cisco WAN :: ASR 1002F - Per Tunnel QoS And Physical Interface CBWFQ

Jun 5, 2012

I am preparing configuration (currently in lab) for Per-Tunnel QoS in DMVPN on ASR 1002F for one of our customers, and I came across one issue. According to restrictions for this feature, I cannot apply per-tunnel QoS in conjunction with interface based QoS. This means, I can provide shaping with hierarchical CBWFQ for each spoke, but I cannot guarantee anything on physical interface! What if there are services in native MPLS? I am also unable give reservations for BGP which is used on PE-CE link! How about monitoring spoke PE-CE links natively? I can only apply policy-map with class-default on physical interface. When I add anything related to queuing for that class (or any other non-default class) I get the message:
 
R1(config- pmap)class routing
R1(config- pmap-c)#bandwidth 16
service-policy with queuing features on sessions is not allowed in conjunction with interface based
 
[Code] ........

View 8 Replies View Related

Cisco Firewall :: ASA 5505 Can't See Any Elements About Physical Interface

May 30, 2011

I enabled snmp config  ASA 5505 with Version 7.2(4), the NMS/reporting system can give graphs for CPU & Memory usages. But I can't see any elements about physical interfaces.

View 1 Replies View Related

Bandwidth Allocation To Vpn Interface Under Physical Eth0?

Feb 15, 2012

I have my wan connection on the eth0. The bandwidth is 2mbps. I am running qos on that interface saying 192.168.200.0/24 can use 80% of the bandwidth and 192.168.201.0/24 can use 20% of the bandwidth. I Also have vtun VPN inteface to our branch office. I also wan to run some qos on that interface. How do i go about allocating the bandwidth on this interface? it is actually going via the eth0 interface, but the system actually see's it a an independent interface on its own right, so it requires it's own qos policy.

View 3 Replies View Related

Cisco Switching/Routing :: 2800 Router Physical And Sub Interface

Oct 25, 2012

I have a pair of router Cisco 2800 running in HSRP, now I want to configure one sub interface with another sub net, Will my current IP on physical interface work or do I need to create two Sub interfaces for each network. Do i must need encapsulation on sub interface

Current Config:-

Router 1:-
interface FastEthernet0/1description Connect to LAN_SW1 Gi1/0/1ip address 192.168.1.13 255.255.255.0no ip redirectsduplex autospeed autostandby 1 ip 192.168.1.1standby 1 priority 90standby 1 preempt
Router 2:-
interface FastEthernet0/1description Connect to LAN_SW2 Gi1/0/1ip address 192.168.1.3 255.255.255.0no ip redirectsduplex autospeed autostandby 1 ip 192.168.1.1standby 1 priority 110standby 1 preempt 

For second network I do not require HSRP
Router 1:-
interface FastEthernet0/0description Connect to LAN_SW1 Gi1/0/1no ip addressduplex fullspeed 100
[ code]...
Router 2:-
interface FastEthernet0/0description Connect to LAN_SW2 Gi1/0/1no ip addressduplex fullspeed 100
[Code]...

View 3 Replies View Related

Cisco Firewall :: 5520 Recreate Logical Interfaces For Each Physical Interface

Nov 29, 2012

We have to enable FIPS 140-2 on our ASA5520's for all our IPSEC VPN connections.   We currently have failover on our 5520's. I found a lot of information out there but some seems to conflict one another.What are the things I need to look out for - caveats? Does the clients that connect to the VPN had to use different clients once the FIPS was enabled.Do we need to recreate logical interfaces for each physical interface we have?

View 1 Replies View Related

Cisco Firewall :: How To Find Which Context Group Physical Interface Gi0 / 2 Belongs

May 2, 2013

ASA  have two context groups say admin and and x. Its interface gi0/2  has 6 subinterfaces  from 1 to 6.3 subinterfaces ----0/2.1 to 3 are in admin and last 3 are in context x.when i went to system context  it does not show where interface gi0/2 belongs to it only shows up up.how can i find which context group physical interface gi0/2 belongs?

View 4 Replies View Related

Cisco Switching/Routing :: Vlan And Physical Interface Counters 3560x

Dec 9, 2012

vlan interface and physical interface (that is serving for this vlan ) have different input/output counters, there is only one physical interface in this vlan .
 
sh int vlan 64
30 second input rate 9000 bits/sec, 9 packets/sec
30 second output rate 0 bits/sec, 0 packets/sec

[Code]....

View 5 Replies View Related

Cisco WAN :: 4506s - Switch Virtual Interface (SVI) Versus Routed Physical Port

Feb 28, 2012

What are the pros and cons of configuring a Switch Virtual Interface (SVI) versus a routed physical port between layer 3 switches?For example, if I have two 4506s and have a need to run HSRP and route between them which feature is better and why?
 
switch_a
!
interface vlan 25
ip address 10.10.10.1 255.255.255.0
!
interface fa0/1
switchport mode trunk

[code].....

View 1 Replies View Related

Cisco Switching/Routing :: Configure Port-Channel Or Physical Interface On 3750

Jan 12, 2012

how to configure this. I did it in the past but kind of forgot how I did it.I have a stacked 3750 (two physical switches) connecting to a 2960.
 
I am creating trunk ports with limited access to VLAN 300, 600, and 700.
 
There is two interfaces connected from the 3750's(one on each physical stack member) to the 2960.I have the physical interfaces configured exactly the same.
 
3750 Config:
 
interface Port-channel2
!
 interface FastEthernet1/0/46
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 1, 300,600,700
switchport mode trunk
speed 100

[code]....

Should I keep the configuration on the physical ports and not configure the Port-Channel Interfaces? Do I need to configure port-channel load balancing? Is the channel-group mode sufficient? Goal is to basically create 2 links to the 2960 to double the bandwidth and provide redundancy.

View 7 Replies View Related

Cisco VPN :: 877 IPSec Tunnel With Dynamic IP Address

Aug 3, 2011

I'm having some trouble configuring 2 cisco routers (877) with ipsec vpn tunnel.The 2 of them are linked to the internet with dynamic adsl's - their ip-addresses changes all the time.when the configuration is based on ip addresses it's working ok, but when I'm trying to use host name with the DDNS feature, it's not coming up, I get a lot of errors...
 
I've searched google and various posts regarding that issue.It's seems like it's possible to do a dynamic-ip to dynamic-ip ipsec tunnel, but I found zero manuals and configuration.I've added the template that I'm using to configure the tunnel with ip addresses.

View 2 Replies View Related

Cisco VPN :: IPSEC VPN From SRP521 Dynamic IP To ASA5505 Static IP

Jun 18, 2012

I'm having problems configuring an IPSEC VPN between an SRP521 with a dynamic IP and a ASA5505 with a static IP. Static to Static is fine between these devices and I can configure that without problems.  Dynamic to Static however.

View 1 Replies View Related

Cisco Firewall :: ASA 8.4 Access List Dynamic Interface?

Mar 11, 2013

This is a working example using static. But it doesn't work with the dynamic interface or I'm doing something wrong. Need to get rdp access to my laptop.
 
ASA Version 8.4(5)6
!
hostname ciscoasa
enable password 8Ry2YjIyt7RRXU24 encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
names

[code]...

View 1 Replies View Related

Cisco Wireless :: WLC5508 - Requires To Setup A Dynamic Interface On A Network?

Aug 10, 2012

Having setup several WLC4402's in the past, I am posed with a new implementation that I have never tried before.  I will be setting up a new 5508 that will ONLY be used for remote access-points in H-REAP mode.  It is going into a data center and there will be no local LWAPP's.Is it still required to setup a dynamic interface on a network that will essentially only have the controller IP?  Or can I serve all the AP's out of the single, untagged management interface (which I believe is also the old ap-manager interface now?)

View 2 Replies View Related

Cisco Wireless :: 2504 / Assign SSID To Interface That Has Dynamic AP Management Enabled?

Jan 3, 2012

I am tasked with configuring a 2504 wireless controller.  Is it possible to assign an SSID to an interface that has dynamic ap management enabled?

Scenario:
Location1:
1) 10.0.0.0/24
2)192.168.0.0/24 DMZ
 Location 2:
1) 10.0.5.0
 
Both locations are routable using network 1 at each location.  However, I need to configure several access points and send them to location 2.  These access points will communicate with the controller at location 1 on network 1.  Two SSIDs will need to be on network 1 at location 1.  The other SSID will be on Network 2 at location 1.  This network is not routable. 

View 32 Replies View Related

Cisco VPN :: ISR1921 - Two IPSec On One Interface Not Working?

Nov 7, 2011

I'm actualy trying to bring two IPSec VPN on only one interface. I've successfully created a tunnel between Par and Barcelone and between Par and Mad. But I can't create it between Barcelone et Mad. We have a cisco ISR1921 in Mad and Barcelone, and a Netgear in Par.
 
Barcelone config:
 
crypto isakmp policy 10
encr 3des
authentication pre-share

[Code].....

View 7 Replies View Related

Cisco VPN :: IPSec VPN Connection From DMZ Interface ASA 5510?

Oct 11, 2011

I currently have an ASA 5510 setup with Dual homed ISP's and a remote access IPsec VPN setup to terminate at either interface. The first interface is named Outside and the second is simply called Outside-2. When outside the company(such as at home), the VPN client will connect on the Outside-2 interface and work normally. The problem is while testing on our DMZ, the VPN Client will not connect on the Outside-2 interface. It will try that interface fail to connect and then connect to the backup Outside interface. This isn't a huge concern because it still connects, but if we were ever to get rid of one of those connections, it would be nice to reliably test from our DMZ.

View 1 Replies View Related

Cisco WAN :: 881 - VPN IPsec Over Dialer Interface Not Working?

May 11, 2013

How to make a Cisco 881 router finally work. I have the following configuration:
 
Current configuration : 2964 bytes
!
! No configuration change since last restart
version 15.1
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec

[code].....
 
As much as I understand, the VPN tunnel is active.I can access the Internet, but I cannot access anything through the VPN tunnel.

View 3 Replies View Related

Cisco Firewall :: IPSec Tunnel On Sub-interface On ASA 5510?

Jun 11, 2012

I working on a security solution using ASA firewall. Is it possible to setup a IPSec tunnels  on each subinterface of a physical interface on ASA 5510?

View 3 Replies View Related

Cisco VPN :: 5510 IPSec VPN In Security Context / Shared Interface Or Not

Feb 17, 2013

I have at the moment an ASA5510 pair in Multiple Context configured. Everything is ok, but we use til now only ACL features.Now I would be interested in configuring 2 contexts, with IPSec VPNs. One VPN per context. But I cannot find any information if it would be possible to use a shared interface for both contexts. My wish would only be to spare public IPs.If I have to configure 100 VPNs in 100 contexts, do I need 100 public IPs ?

View 5 Replies View Related

Cisco WAN :: How To Configure 3800 With WIC-2AM-V2 To Do DDR

Sep 30, 2012

I'm trying to configure a Cisco 3800 with a WIC-2AM-V2 to do DDR.  I've gotten it to work before, but it was a while and now the config doesn't seem to work.  I'm using an Lo0 interface and ip unnumbered on the Dialer interface.  Using debug dialer and debug ppp and see nothing at all trying to dial out.
 
##############################################################
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname DDR

[code].....

View 1 Replies View Related

Cisco WAN :: 3800 As NTP Server

Sep 1, 2011

I am trying to configure cisco 3800 as NTP server for all Juniper MX router clients. Purpose is to server the clock to all Juniper routers. But i m facing weird issue.. All Juniper routers are getting synch with Cisco 3800 but there is difference of 30 min between client and server time.
 
Cisco config
 
ntp authentication-key 100 md5 11201D00163B0C1E 7
ntp trusted-key 100
ntp source Loopback1
ntp master
end

View 5 Replies View Related

Cisco VPN :: 3800 - VRF And Static Nat

Jun 12, 2011

I'm having a problem on which i cannot find an answer. I have a VPN router 3800 series (DMVPN) with 2 VRF on it, we also use dual Nat to reach our data center behind the 3800 series isr.
 
I created the Nat rules and the acl's , but the Nat is just not working, is there a special configuration needed for Nat and VRF's?

View 1 Replies View Related

Cisco WAN :: 1941 Router - Enable IPSec Virtual Tunnel Interface With Tunnel Mode IPv4

Sep 23, 2012

I'm in process of purchasing a new Cisco routers for our branches that will be used primary to enable IPSec virtual tunnel interfce with "tunnel mode ipsec ipv4". does the default IOS IP Base supports this feature? or i need to purchase DATA license or SECURITY license?

View 4 Replies View Related

Cisco WAN :: 3800 No Service Password Recovery

Sep 26, 2011

I was just configured a 3800 router with this command. I cannot get to the ROMMON mode anymore. Cisco says you should press Break key within 5 seconds after the image decompresses during the boot. But mine is ignoring it and going to load running config directly.

View 7 Replies View Related

Cisco WAN :: 3800 Router Flash Upgrade?

Jul 14, 2012

I need to upgrade compact flash memory card for a 3800 router. Basically i want to upgrade code on this router and the current flash size (64Mb)  cannot hold new image. I wanted to check if i swap the old flash (64 Mb) with a new one 256 mb, i will loose vlan.dat file since it's stored in flash. Is there a way i can copy vlan.dat to new flash which has new code before i change the boot statements and reload the router?

View 1 Replies View Related

Cisco WAN :: 3800 Series Behind A Cable Modem

Dec 22, 2010

I inherited a 3845 router. I am hopeful that I can use it for my home practice lab and connect it to a Cablevision (Optimum Online) Cable Modem. If it is possible what interface card/config I would need? It currently has a T3/E3 card with 2 coaxial connections (was used with a Cogent DS3 connection). I'm guessing I would need to replace it with an Ethernet one (?). Granted - I suspect it may cost a pretty penny, nonetheless I'd like to look into it.It also  has 2 dual-port vwic2-2mft-t1/e1 card installed. I am an absolute beginner with Cisco and networking.

View 2 Replies View Related

Cisco WAN :: 3800 - Nest QoS With Shaping - Getting Drops

May 4, 2012

I have a 3800 running 12.4 with a outbound shaped nest Qos tied to a subinterface G0/0.12 which is trunk downstream to a 3500. I am getting drops on the "sh policy-manager inter g0/0.12 so know that shaping which is 1.5mbps is dropping my packets. The 3500 looks clean
 
3800: 
policy-map A
class-map A
bandwidth 30% etc..

[Code]....

the routing is that host goes up to the 3800 and out a wan link but if wan is down, it hairpins back down from 3800 to 3500 which has a backup link on one of the ports. when we test wan down, or even when it is up, I see shape dropping packets

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved