Cisco WAN :: 1941 - Dual WAN Failover And Partial Failure

May 10, 2011

We had an interesting situation after an electrical storm moved through where a few of our dual WAN clients didn't have any Internet connectivity.  Generally speaking, they are on a wireless broadband and something like DSL/cable/T1.  One customer in particular has a cisco 1941 router setup for dual WAN which tested fine during install (pull either connection, external IP changes dynamically and no difference is noticed by user).  Well, this storm knocked the wireless broadband out enough that it wasn't usable, but would respond to pings randomly.  Because the wireless is the fastest of the two connections it has a higher priority but because it was down but still responded to some pings, the traffic didn't go through the DSL that didn't go down.  how to make the dual WAN more reliable in these partial-down situations?  I thought about playing with the network service detection (we have a customer on an RV042 who experienced the same problem) but am not real sure what I could change that would make the connection more reliable, especially on the 1941 router.

View 1 Replies


ADVERTISEMENT

Cisco Switching/Routing :: 1941 Auto Failover With Load Balancing?

Jan 27, 2013

One of our customer has  3 ISP Line, out of which Two are Broadband and One is Leased Line.   All 3 ISP interfaces are Etherent.
 
Now, they want Auto Failover with Load balancing among these 3 ISP lines.
 
Can we do same implementation in Cisco 1941 Router??  What licenses required in router for same?

View 1 Replies View Related

Cisco WAN :: 881g Dual NAT Failover Not Working

Mar 24, 2011

Below is the config has done on my 881g but the dual NAT failover is not working.I have a easy vpn over NAT (easy vpn firewall: 10.10.10.2 behind the router).
 
1. After completed the config, I shut down the FastEthernet4, cleared the nat translations, found that nat translations are happening on to Cellular0 with error ( Incomplete ESP translations: 0 esp_conn=0x85A91FF0, hanging off nat entry 0x85A7D1D0)But still the easy vpn is not up as I am not able to ping the remote devices.

2. If I reboot the router then the nat translations are happening with no above error and easy vpn is up and I am able to ping the remote servers. Below is the config, what needs to be done to achieve the NAT failover and easy VPN up.
 
interface FastEthernet4 bandwidth 2048 ip address 206.206.206.2 255.255.255.240 ip flow ingress ip nat outside ip virtual-reassembly duplex auto speed auto interface Cellular0 ip address negotiated ip nat outside ip virtual-reassembly encapsulation ppp dialer in-band dialer string gsm dialer-group 1 async mode interactive ppp chap hostname. [code]

View 5 Replies View Related

Cisco WAN :: Dual ISP Failover Configuration 891W?

Apr 18, 2012

What I currently have is a Cisco 891W Router as well as two ISP's (both with dynamic IP's) in.  I'm currently just running one of my modems into the 891 through the FE8 port and then if for some reason I have an internet failure switching the ISP modems.  What I'm wondering is if there is a fairly simple way to configure (and attach) both modems to this router and then set it up to handle this failover automatically?

View 1 Replies View Related

Cisco WAN :: 3845 Dual ISP Hardware Failover

Feb 27, 2011

In my network we have 2 ISPs connections 2mbps from different service providers are terminated in two different routers (Cisco 3845).Now i want to achive if one router fails(ISP down) next router has to up and if both the links is up i need to achive load balance for both the routers(ISPS).i need 100% uptime.
 
How can I configure the routers, any examples to achieve the HW failover.

View 2 Replies View Related

Cisco WAN :: 2811 Non-stacked Dual Switch Failover

Jun 6, 2012

I'm trying to see if I can use both ethernet ports on a 2811 to run hsrp for non-stacked dual switch fail over.  Then link the the NM-32A ports to L0, so the remote access server trying to use them can use the l0 ip and failover much faster (it's programming is limited).  This is on IOS 12.4(25)f, though we are moving to 15 soon.

View 2 Replies View Related

Cisco VPN :: 6513 / 7206 - Dual ISP Failover With Two ASAs That Are Not HA

Dec 4, 2012

I am having a hard time getting tunnel fail over working.  My setup is illustrated below:
 
I derive my default route on the border routers.  The 6513 peers with the 7206's using BGP to get the default route from each ISP into the core.   On the core I use BGP weighting to get my primary default to point to ISP1.  So far so good.  When I look at my core I see to defaults with ISP1 preferred.
 
Each ASA has an IP Sec tunnel to the head end site configured (Not shown).  The head end site has a crypto map entry with ISP1 and ISP2 defined (in that order) using the "set peer" command.
 
Fail over works great if an ISP drops the connection or my 7206 or ASA fails, but... While testing fail over I had an issue where both tunnels would be active and there were issues with traffic between sites. I could not determine the root cause.  I can only guess that some traffic was going out one tunnel and when trying to come back across the other tunnel was dropped from the firewall because there was no connection built for it.  After reading I found that in order to use multiple peers in the "set peer" statement, I needed to configure my head end as "originate-only".  I have not done this yet as I have concerns.  If the head end site is "originate-only" and the tunnel, for whatever reason drops, I cannot wait for interesting traffic at the head end site bound for this site to bring up the tunnel as most of the traffic originates at this site.
 
I have been reading about IKE keep alives and DPD but that doesn't sound like it will re-initiate the tunnel.  Is this correct? If so I'm looking for a way to make this work. 

View 10 Replies View Related

Cisco WAN :: 1921 Dual Links Failover And Fail Back

Sep 19, 2012

I have a 1921 router with two wan interface configured, one is primary and the other is standby or backup in case the primary goes down, I was able to configure links to failover from primary to backup once there primary is down, but how do I configure to make sure when primary is up it failbak to to it. [code]

View 3 Replies View Related

Cisco Firewall :: ASA 5500 WAN Failover MPLS / Internet Using Dual ASA

Jun 1, 2011

I am putting together a solution for a client. The client has an MPLS circuit and internet as a backup circuit. I understand that we can do WAN failover using ASA5510 appliance.Now, if i am adding dual ASA5510 active/standby mode, How do i automatically failover WAN circuits to standby firewall if both MPLS and Internet circuits are connecting to primary ASA5510. Should i connect MPLS circuit to ASA1 and Internet circuit to ASA2? Ideally, i want both circuits to connect to primary ASA5510 for automatic WAN failover. My concern is , if the primary ASA5510 fails which has WAN and Internet circuits connected , do i need to manually switch connection from primary to standy? The goal is to fully automate wan failover and asa failover .

View 5 Replies View Related

Cisco WAN :: 1921 Dual ADSL Load Balancing / Failover?

Mar 28, 2011

We have purchased a Cisco 1921 with twin ADSL after advice from a Cisco sales rep. However I am having trouble working out the load balancing/fail over config for the device.
 
I would like traffic to balance over both ADSL lines and if one goes down not to interrupt connectivity.
 
I had a look at ppp multilink but I am unsure our ISP (BT) support this?
 
!! Last configuration change at 13:18:34 UTC Tue Mar 29 2011!version 15.0service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname xxxxxx

[Code]......

View 10 Replies View Related

Cisco Firewall :: 5520 - ASA Active / Active Failover And IPS Failure

Mar 30, 2011

I have 2 asa 5520 firewalls including and 1 AIP-SSM-10 module in each of them. the configuration is set using active/active failover and context mode.
 
Both of them run individualy the IPS module. The IPS is configured using inline mode and fail-open option. However when one of the module fails and the state is changing from up to init or anything else making the IPS to fail then failover is detected and ASA consider it as failover and bounce context to the other unit.
 
IPS soft is 6.0(4) and ASA soft is 8.0(3)
 
I have checked cisco doc and it is confusing to me. it says:  "The AIP-SSM does not participate in stateful failover if stateful failover is configured on the ASA failover pair." but it really does participate. Running is not really an option because of production network impact matter..

View 2 Replies View Related

Cisco Switching/Routing :: 6509 SUP720-3B / Dual Link With Failover And Redundant Configuration?

Feb 24, 2013

I have a two fiber connection from our Central Office(6513) to Remote office (6509). I have a requirement that on the remote office if one of the fiber goes down, the second fiber should work as a failover. I am planning to use SUP720-3B SFP to connect to the CO.

Can I connet one fiber to Sup720-3b G5/1 & another fiber connection to G5/2?  or Can I connet one fiber to Sup720-3b G5/1 & another fiber connection to G6/2? I am running EIGRP between sites. Any sample config.
 
sup-bootflash:s72033-pk9sv-mz.122-18.SXD7b.bin"

View 4 Replies View Related

Cisco Firewall :: ASA5520 - Active / Active Failover In Multiple Security Contexts With Dual ISP?

Jun 1, 2011

I have an ASA5520 in location A with an ISP connection and a matching ASA5520 in location B with a separate ISP connection. We have fiber connecting the two locations and vlans passing back and forth so I will be able to configure the failover via a vlan as well as extend the ISP's to each location via vlans. The Active/Active configuration with the multiple security contexts does not seem to be an issue but how is a redundant ISP configured in this mode?We want to have context A using the ASA in location A with ISP1 as the primary and failing over to ISP 2 in locaiton B We also want to have context B using the ASA in location B with ISP 2 as the primary and failing over to ISP1 in location A Would route tracking provide the desired result? Is there a better option?

View 1 Replies View Related

Cisco WAN :: 2xT-1 Deciding Between A Partial DS3 And Metro Ethernet

Jan 22, 2012

We are in the process of upgrading the bandwidth at a few offices. Each currently have a 2xT-1 connection but have high utilization on the circuit which is why they are being upgraded. We are trying to decide b/t either a partial DS3 or metro ethernet connection. Are there pros/cons b/t the two in order to decide which to go with? Cost is not an issue. Some say going with a partial DS3 circuit offers benefits over metro ethernet such as network-based failover, end-to-end availability is better with DS-3 and QoS.

View 3 Replies View Related

Cisco WAN :: 2911 With Partial EBGP Routes

Jun 29, 2011

a customer of us asked if C2911 (to be bought) is ok for partial BGP routes.This is the situation: 2 cisco 2911, each peering with 3 other AS (AS1, AS2, AS3), and maybe, in the future, at a small IXP (AS4, AS5, AS6, AS7).They will accept defaults plus partial routes from upstream AS1, AS2, AS3.When deployed at the IXP they also will accept partial routes from AS4-7.So, is 2911 ok for that configuration?the default route is included in the first row of as-path, isn't it?I have no experience with partial routes, only with full (for our datacenter) and default only (for other customers).

View 5 Replies View Related

Cisco :: LMS 4.2 Partial Success In Archive Jobs?

Sep 25, 2012

I am getting some weir behaviour in my LMS 4.2 setup. I am doing and Archiveupdate job and am receiving a partial success for roughly 1400 devices.  Here is some output.
 
Execution Result:
STARTUP
CM0057 PRIMARY STARTUP Config fetch SUCCESS, archival failed for
xxxxxx Cause: CM0210 Unable to generate
processed config Action: Verify that archive exists for device.
RUNNING

[code]...
 
I went on and checked the dcmaservice log file.I found the following entry at the same time of this particulair job
 
ERROR,[Thread-72920],com.cisco.nm.xms.xdi.pkgs.SharedDcmaIOS.analyzer.IOSConfigletRules,loadRules,42,Could not locate configlet rule file : com/cisco/nm/xms/xdi/pkgs/SharedDcmaIOS/analyzer/IOSConfigletRules.ser
[ date taken out ],ERROR,[Thread-72920],com.cisco.nm.rmeng.dcma.configmanager.DeviceArchiveManager,archiveNewVersionIfNeeded,1115,CM0210 Unable to generate processed config  

I then searched if I had the IOSConfigletRules.set file on the box. And no it is not there. My question is this the reasson that I have som manny partial sucess archive results?

View 2 Replies View Related

Dell Pe2950 - Losing Partial Network Connection?

Jun 28, 2012

We are running Sharepoint 2007(sp3 and wss sp3) on a dell pe2950 running Server 2003 std x64 sp2, 4 146gb 15k sas raid 10, 16gb ram, dual xeon 516 3ghz. the network card is a quad port intel 1gb pci-x server nic. Was running broadcom net xtreme dual port onboard, and had the same issue.

We are losing partial network connection, after about 14-15 hours of the machine working correctly. What happens is that it cannot ping, or access, any machines not on the same network segment(this machine is on 192.168.3.* and cannot access machines, or be accessed from 192.168.2.*, 192.168.4.*, etc, etc). what i have found is that when i try to ping 192.168.2.210(our dns, dhcp server). its times out about 20 times and replies 2-3 times, and then repeats the cycle all over again. i have done a winsock reset on the machine, and sometimes it starts back up and works again, sometimes it doesn't.

View 3 Replies View Related

Cisco WAN :: 2921 Handle 100mbps Connection Plus Operate BGP With Partial Updates

Mar 1, 2013

Can a Cisco 2921 handle a 100mbps connection plus operate BGP with partial updates? I am worried about the CPU.                  

View 5 Replies View Related

D-Link DIR-655 :: Shareport On Various Platforms Locks Up After Partial Page Printed

Apr 4, 2012

I have an HP OfficeJet J4500 that works fine with shareport on my Win7 x64 computer. the XP and Win2000 ones both have the same "partial page then lockup" problem. when this happens, the only way to disconnect shareport is to reboot the router.  It shows connected to the same computer even if I reboot that computer.  I started with V1?? from the install disk then tried 3 and finally 4 with no improvement.  I have read several posts about this or similar problems.  This is the primary reason I switched routers and bought the D-Link DIR-655, for the print server feature...

View 3 Replies View Related

Cisco Switching/Routing :: Nexus 5596UP Dual-sided VPC Design With Dual Connected

Feb 19, 2012

I would like to make a design with 4 Nexus 5596UP. 2 of them equipped with Layer 3 Expansion Module  so they can serve as core layer and the other 2 Nexus used as Layer 2 for aggregation server layer.The 2 Nexus in the core layer will run HSRP and will peer with ISP via BGP for Internet connection The 2 Nexus in the aggregation layer will be configured as layer 2 device and have FEX and switches connected to them.What I am ensure of is how the vpc and port-channel configuration should look like between the 4 nexus. What I was thinking is to run vpc between the 2 Nexus in the aggregation layer and between the 2 Nexus in the core layer. Than I was thinking of connecting each Nexus in the aggragtion layer to both Nexus in the core layer using port-channel and vice-versa.

View 3 Replies View Related

Cisco :: Dual SSID (with Dual VLAN) On AiroNet 1130?

Dec 17, 2012

how to change our wireless setup. Currently, we have 2 Cisco AiroNet 1130 WAP's in the office that go directly into the 2 POE ports on our Cisco ASA 5500. These WAP's have 1 SSID and are using WEP for security. After demonstrating the flaws of WEP to my boss, he has agreed that we should use something more secure and I've suggested WPA. We want visitors to our office to be able to hop on our wireless but on a separate guest SSID with WEP.
 
I'd like the internal SSID to route to the ASA and take the default route to the internet (it will be our new fiber connection once it's installed in a couple weeks). The default route is whichever connection is working since our ASA 5500 will fail over when it detects an outage.
 
I'd like the guest SSID to route to the ASA and then go over our existing cable connection. This connection will be our backup once the fiber connection is installed. Since we won't be using it very often, but will be paying for it, I advised that we send all guest wireless traffic over this connection since 50/5 is plenty for guests.
 
The current SSID (which will be the internal SSID) has no VLAN. We do currently have a few VLANS on our network, one for voice (.42) and one for data (.100) and the default (.0). What device to I create the VLAN on (Cisco 5500?) and how to I setup the WAP? I need very basic instructions to start and I'm also trying to do this without causing downtime if possible.
 
I've attached a diagram of what it should look like. Red indicates our internal network and Blue indicates the guest network. I can send screenshots as well.

View 2 Replies View Related

Cisco WAN :: Dual MPLS Routers Connected To Dual N5K Core

Mar 29, 2012

I wanted to ask a question about the diagram I have included.  We are bringing up 2 MPLS WAN connections and would like some specifics on the best design.  We are using BGP to the providers.  From there we have big questions.  We can run BGP internal and are licensed to do so on the N5K's.  The N5Ks are currently using HSRP for inside LAN clients as default gateway.  We want to load balance and provide redundant routes using a dynamic approach.  Should we use BGP internal utilizing the connections between the routers?  Should we use HSRP on the routers?  How best to get the routes to the N5K and should we be considering this?

View 5 Replies View Related

Cisco Routers :: VPN Configuration For Dual WAN On Dual RV042

Feb 21, 2013

I run 2 RV042 V1 for home and office with Gateway to Gateway VPN connection with single WAN connection in use. Everything works like a charm!
 
I was even able to create VPN connection with 2 WAN connection on one Router and 1 WAN connection on another with Smart link failover and VPN Tunel Backup.
 
I got problem though when i tried more complex connection diagram. [URL]
 
So basically I now have 2 ISP connections on each point with Static IPs and I'd like VPN Connection to be alive for ALL 4 options automatically with failovers (smart links) And tunel backups but i'm not sure if that's ever possible with my equipment.

View 2 Replies View Related

Cisco VPN :: How To NAT After Connecting 1941

Feb 22, 2012

I have a Cisco 1941 which has several Cisco VPN clients connecting to it which all works fine. The details of the LAN and VPN clients are as below:
 
Cisco 1941 LAN : 172.16.1.0 255.255.255.0
VPN Clients : 192.168.5.0 255.255.255.0
 
As mentioned this works fine but I'm about to setup a point to point VPN with from the above Cisco to another site which isn't controlled by myself and the remote side of this point to point VPN will only allow connections from the "172.16.1.0" subnet to communicate with it.
 
The issue I have is that the Cisco VPN clients also need to communicate with the remote side of this point to point VPN but they are obviously coming from the "192.168.5.0" subnet. Is this possible and where to start with this that would be fantastic.

View 3 Replies View Related

Cisco WAN :: NAT IP Is Not Working In MWR 1941 DC?

Feb 18, 2011

I got 2 DC Cisco MWR 1941 and 3600, I do not know the reason why when I set up IP NAT to 1941 does not work but if I do it in the 3600 if it works.

View 13 Replies View Related

Cisco :: CSM 4.1 / ACS 5.1 Non-ACS AAA Failure

Jan 10, 2012

I know that CW Common Services 3.3 does not work with pre-defined roles on ACS AAA. So I followed these forums and enabled non-ACS AAA and selected TACACS+. I have a single rule that is matching in my ACS (after looking at the audit trail):
 
Authentication Details
Status:
Passed

[Code]....
 
As you may have noticed even though it is matching an access service that allows Priv15. That doesn't seem to be passing through as you can see on top I am only receiving Priv 1. What can I do to properly pass through the access service profile?

View 2 Replies View Related

Cisco :: 1941 / IP SLA In Combination With DMVPN?

Sep 5, 2012

I have a problem with my routers (cisco 1941)I'm running a DMVPN network (Hub and spoke)All the hubs are connected to the 2 hubs. With 4 tunnels. (each hub has 2 interfaces to the spokes. the spokes only have one interface to the hubs, so I splitted them and so I now have 4 dmvpn tunnels). one of the interfaces on a hub malfuntioned and because of that the customers had problems with logging in and sending packets. I made this kind of structure because of when one of the tunnels failed the spoke could use the 3 others... BUT, what happened here was that the spoke still tried to use all 4 of the tunnels and because of that I had 25% package loss!So this didn't work. Now I read about IP SLA, but I was wondering of this could work? (I cannot test it on spare routers, and I don't want to implement it and risking a total network failure...) and how to configure it. Should I make 4 different sla processes which I should all 4 track? And when I make the ip routes, how should I make or configure it so that 1 of the tunnels/interfaces fails that the spoke would addapt the routes?

View 1 Replies View Related

Cisco WAN :: 1941 - Routing Between 3G Interfaces?

Apr 11, 2012

I'm trying to get two Cisco 1941 routers with HWIC-1T and HWIC-3G-HSPA interfaces to use the 3G interfaces if the frame is down (as it is right now).In the lab, I was not able to get these to use the 3G interfaces as a backup (i.e. backup interface cell 0/1/0) and I've not been able to workout the correct incantation for static routing either.
 
kununurra#show ip int br d1
Interface                  IP-Address      OK? Method Status                Protocol
Dialer1                    172.31.2.94     YES IPCP   up                    up

[Code]....

View 4 Replies View Related

Cisco WAN :: 1941 W Wireless Not Working

Mar 20, 2011

I have been breaking my head over a problem with my new 1941W ISR since about two weeks now.When I restart the router, the service-module wlan-ap0 is not working.After a restart of the router, when I ask a service-module wlan-ap2 status, I get:Service Module is Cisco wlan-ap0Service Module supports session via TTY line 67Service Module is waiting for registration messageService Module reset on error is disabledService Module heartbeat-reset is enabledService Module is in fail openService Module status is not available
 
After a while it changes to Service Module is failed.If I restart the module with service-module wlan-ap2 reset, it works. Is this a technical error?

View 4 Replies View Related

Cisco VPN :: PAK To Activate VPN On 1941 K9 Router

Jul 1, 2012

We bought a CISCO1941 K9 router. To enabled IPSec feature, I need the PAK to active IPSec on 1941. Where I can buy a valid PAK? Could it be done via on-line support?

View 5 Replies View Related

Cisco VPN :: Activating SSL On 1941 Router?

Mar 23, 2011

I have got a Cisco 1941 router and would like to activate my SSL VPN license on it. How do i go about it?

View 6 Replies View Related

Cisco WAN :: What Is The Processor Available In 1941 Router

Jan 31, 2012

What is the processor available in cisco 1941 router? is it RISC?

View 4 Replies View Related

Cisco VPN :: How To Configure SSL VPN On 1941 Router

Mar 22, 2011

How do i configure SSL VPN on a Cisco 1941 router? I would very much want a howto guide that does step by step. I have not found one my self so far.

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved