Cisco WAN :: 2801 How To Protect It For Sessions Of SSH And Telnet
Dec 19, 2012
Someone told me the commands, but I can't remember them. Have a router (2801) at the end of a highly utilized T1 link/router. How do I protect it so my SSH and/or Telnet sessions will get serviced if the router is real busy.
We have a new 2911 that needs to be configured, unfortunately it's at a remote site. I had installed the following config: [code]
Now, I do get a dhcp ip on the G0/0 interface and I can ping it from my remote network and the local router as well as the local lan. The hands and eye guy is able to telnet from the local lan but I am unable to telnet from either my remote lan or the local router.The only error I receive is "connection refused by remote host". All lines are clear so I have no conflicts with multiple telnet sessions.
I have recently installed four Cisco RV042 v3 VPN routers for a customer of ours to replace existing Nortel Contivity 1010 devices which were providing VPN tunnels from the customer's 3 branches to their headoffice. The original Nortel devices were working perfectly but the customer wanted some firewall rule changes and the Nortels were proving to be somewhat inflexible and incomprehensible in their configuration hence why they were replaced.
When installing the Cisco routers I configured the VPN settings to match the Nortel device settings so that I could swap out a branch at a time without taking the whole setup down for a day.The customer has a Unix based dumb-terminal application running on a server at headoffice that they access from their branches using terminal emulators on Windows PCs and thin client hardware devices that support vt100 terminal emulation.
Prior to installing the Cisco RV042's everything was working fine. Now they are using the RV042's they keep getting the sessions from their branches dropped. Both PC users and thin client users are losing sessions and it happens with active and idle sessions. I have checked the logs on the routers when users are disconnected and there is nothing logged at that time (other than my login)... I had thought maybe it was to do with tunnel renegotioations so I have set to phase 1 / phase 2 SA timeouts to 86400 & 28800 seconds respectively but this has had no effect. I had also seen somebody advised disabling 'SPI' in the firewall... I have tried this and it makes no difference.
I am using a Cisco 2801 Router and currently have Telnet enabled on all interfaces. How do I change that so it is enabled from all inside networks, but not on the outside interface?
I've got an HP Printer which supports ePrint, which is very useful for me because I always need to print stuff, especially when i'm at college.The only problem is: we've got almost 200 people on the same network here. And I don't want radom trolls to just be able to print with my printer. (The printer has a direct wired connection to the network)
I feel a bit in over my head here as I've never dealt with QoS stuff before, but what I'm trying to do can't be all that difficult. We are using a Cisco ASA 5505 appliance for routing/firewall.We are on a cable Internet connection with 3 MB upload.
On Sunday mornings, we send audio from a device on our network out over the Internet to a radio station which then broadcasts it, but we've had some jitter problems lately and would like to reserve some space for this audio feed to get out without other traffic getting in the way.
The device on our network sending the audio has IP address 192.168.0.22. The device's documentation states it uses TCP 9002 to send session data and UDP 9000 to send the audio data.
So, it seems to me I need to simply tell the firewall to give priority to the device at IP address 192.168.0.22, perhaps also specifying the ports and protocols. I'd rather not try to do this using command line stuff but will do what I need to.
Using the Cisco ASDM launcher to configure the ASA 5505, I created the following security policy but I'm thinking it may be incomplete, or perhaps the wrong thing altogether:
I created a "Source" called WLFJ_Tieline which is a network object with IP address 192.168.0.22.For "Destination" I just chose "any" to cover it all.For "Service" I don't know what I'm doing in that field. I see I can choose from things like TCP, UDP, IP, and also add port numbers, but I'm just not sure what I'm doing in there and chose IP.Then there is the "Source Service" field that I don't know if should be blank.
We are a non-profit organization that is heavily reliant on interns that use their own laptops a lot here. My concern is they come in and connect to our wireless network with no supervision or anything else. I am worried they will introduce a virus, trojan, or something to our network. What the best way to keep them from introducing unwanted malware from a thumb drive, virus in email, or something to that effect shy of standing over them while they install and run an antivirus software?
We bought two packs of IPCAM online from a vendor named HooToo, who seems have different online sites for selling various surveillance cameras. What we purchased is a unit with model no. of HT-IP206, according to its advertisement it has a storage temperature as low as minus 10 degree, and adversely high up to 60degree. While on the other hand, it states that the operating temperature shall be strictly between zero and 55degree. What Im concerned is that what if temperature drops down to minus when a camera is fully operating? Shall extra heating system be needed while the real temperature fails to meet the above-said requirement?
At the school I live in various sites are blocked so I need to use a proxy to access them. Is there any way that someone could steal my password or something while I use one? Also, let's say that I use a proxy in one web browser (let's say Opera) to view a blocked site, but then use a different browser (Firefox) with my normal IP, would I be able to use Firefox with no worries if I need to check something like my bank account? Basically, can you restrict them to one program so you can use personal information on one and normal browsing on the other?
Right now mine isn't PW protected, but I think I'm going to do that. Anyway, my question is, if I change my router settings and make it PW protected will I have to type that in every time I turn on my computer to get access to the internet?
I just installed a new Synology DS212j NAS behind an old Belkin F5D7230-4 wireless router (probably from 2006) on my home network. The wifi network uses WPA-TKIP with a strong password but otherwise has no security. The NAS is connected to the router with cat5. The NAS is setup with a couple password-protected shares (accounts setup on the NAS) that the Windows 7 PCs on the wifi network can access.
Since the NAS and router will be on 24/7, what else do I need to do to ensure that the NAS is secure?
I went through the install procedure outlined in the ProtectLink Gateway install manual and i activated the ProtectLink Web product through Trend Micro (which shows up through their web site as a registered product to me). It still doesn't show up as installed on the SA540 (under Administration/License Management screen). When I try to activate the product again, it shows as "Already registered". Trend has no idea why it won't work. They said Cisco sold the license, so try their support.
I will try to explain my problem as clear as possible but my knowledge about networks and routers is very limited.
I have a DIR-615 version:C1 firmware:3.13NA My ISP is ATT DSL Modem is Siemens SpeedStream 4100, it does not have a router built in Internet line is connected from wall to modem, to router, to PC.
after I upgraded the firmware I had no internet coming out of the router, I bypassed the router and connected straight to the PC and I got internet. I unplugged the power on both modem and router waited a whole night (I was too tired) and in the morning internet was back to PC and I had WIFI again BUT. When I put a password on the WIFI network all my stuff finds the signal but cannot connect, if I open the signal meaning if I have no password and the WIFI is open I can connect all of my electronics without any problems.
I already tried using WEP and WPA but still unable to connect anything, I been leaving my signal open when I'm at home for the last week and I don't like it.
Before the update everything worked fine.
I don't know if this matters but I have a PS3, Wii, Roku box, Laptop and a couple cell phones connected to it. And there are like 6 or 7 network signals close to my house.
I have a Cisco RV082 that doesn't appear to filter any selected categories. To run through what i've done so far, within the 'Web Protection' screen i've: enabled URL filteringconfigured a number of categories to filter by putting a tick in the repective business hours boxset the business days to 7 days a weekspecified business time as 24hrshit the save button.
My licence appears as activated and my platform shows as "gateway service".I've gone on to a number of machines and all are able to access websites that fall under my blocked category (facebook for example even though i've blocked the social networking category).
I use to be running on firmware 1.0.2.4 with ProtectLink-Web working great, but then it expired. Some time later I updated the router to 1.0.4.17 and purchased a three year subscription to ProtectLink-Web, followed the registration link on the router, obtained an activation code, followed the activation link on the router and activated the service, however it didn't activate on the router.
I try to activate again and Trend Micro's site just says that it's already been activated. I contacted Trend Micro support and they see the activation attempts on there end and they said everything should be working. They recommended a factory reset which I performed and then attempted activation again, and again their site says that the service has already been activated. And yet when I go to Cisco ProtectLink Web > License > Summary it just says: "Please activate ProtectLink License to display the license information" and wont allow me to access the features. What is going on? Could the firewall be blocking the service? I didn't have this trouble the first time I used ProtectLink with f/w 1.0.2.4
How to protect shared folders to denie access from server???i am really in need of a software where i can share files on network but i don't want the system administrator to access those files.
I have an asus wireless router the router lost connection for a few days and when Internet came back there was no password to protect Internet and was just basically open access. The computer which all the Internet setting are on went away for repair. When the man brought it back after backing up the computer I asked him to put the password back on the Internet. This he has done. We entered the new passwords on our iPhones and they connected and worked no problem. Then we tried to do it with our laptops but they won't connect. Phoned the bloke back he said we had to get the laptops to forget all the old settings for the router and it would on take five minutes but he never told us how to do it.
I am trying to password protect my router but when I go into wireless> security mode and click on WPA or any of the other choices it goes back to disabled.
I rexently bought a EA6500 to controll when and how much my children should access internett. Even before I have installed it my son have downloaded a program called Netcut, who hacks innto the router and take controll over the access and the prioritation of computers on the network. Is there any way I can block such software to access my router. I had a livechat with Linksys, and they claimed that the router have no capability to block programs. I also tried to download "Netcut Defender" but my AVG warned me about a worm/virus in the download, so i aborted the operation
My router has been in use for some time. WRT54G. I did the set up from the disc and instructions and it's been no problems. I would now like to add a password to log on to it from a wireless computer such as my laptop or the other household computer.
I got an Linksys WRT54GL-DE and my problem is,that someone manipulates the router.Is there any chance to protect the router in that way,that is not possible to reset the router by using the Reset-ButtonNOR by the Linksys software-tool?Especially the software-tool is the problem - I am afraid,that somebody reset / manipulate the router by using the software.
What is the maximum allowed number of BGP sessions on Cisco platforms sup720 BXL and 7200 G2? Particulaty what are these numbers if BGP sessions are under MPLS vrf (i.e. maximum number of BGP session per vrf?).
We are finding the price for ASA 5505 to high and our clients are having problem securing budgets for these devices. We don't want to move to different vendors and we have a team of people we already know Cisco well.I have seen Cisco router 877 which have the ipadvance ios, is this the same as the ASA5505.We would like to offer our clients an alternative to ASA5505, but something which can do the same as a edge device but also protect the client from malicious attacks and has CLI.
My rv082 router protect link gateway is already activated. How do i change the key or activate it with a new activation key?The router dont have any link to change the key. I'm using v1-2 rv082
I have a Netgear router which feeds an Eugenius ecb3500 Wireless Access point. I did not install the access point. I need to password protect our wireless environment, and that needs to be done on the Engenius. However, though I have tried many ways to access that device, I cannot. I cannot get an IP address for it,either. When I plug it directly in to my laptop (Win7), and type in the command line ipconfig, I get the IPv4 addresses of my laptop's local and wireless LAN card. How to get into the Engenius access point and password protect it?
I am making my wireless network with Wireless router DIR-600 and DWA-525 desktop adapters for my office. I created a most secured type of network WPA2. And I have to create profile for DWA-525 desktop adapter to connect to my network and it requires the network secret key to connect. But This secret key is viewable from the "Network connection manager" when one can click on modify network and click on "Show text in the password field" by everyone using this computer (I mean by all other office staff). I don't want to let any one know my wireless network secret key. Is there any way to protect the key while having the computers automatically connected to wireless network. More information is below
Model: DWA-525 Hardware Version: A1 Firmware Version: 1.10 Operating System: Windows 7 Service Pack: 1
I have a linksys WRT54G router. I am able to get to the admin menu via IP 192.168.1.1 but can not figure out where to to navigate to or how to put a (password on the wireless access) so my neighbors wont be able to use my router to get on the internet.
the customer has a problem with LMS 3.2. This software doesn't terminate ssh sessions created by LMS on ACE. All ssh sessions still exist on ACE, so no new ssh session can be created until the administrator manually clear these session on ACE.