Cisco WAN :: 2801 / Managing 6 WAN Connections

Jul 31, 2011

The application here is a wind power project, built in two phases, without any effort to coordinate or integrate the two sites during the design phase. All operations activities for both phases are performed by one staff out of a common location. This is a rural area and Internet connectivity is mission critical due to contractual obligation with Electrical Utilities.
 
The client has a need to reconfigure a network which has grown over time in a layer by layer approach, whereas at every point in time that an additional T-1 or other changes occurred to address a specific need, no thought was ever put into integrating the entire site as a whole. It is at best a dysfunctional solution which somewhat accomplishes thier needs, and at worst, a kludgy, grossly security compromised, and difficult to use infrastructure. There is every kind of equipment one can imagine, each installed by some entity providing needed services on the site, but forced to make uninformed decisions because the client really has no IT department to coordinate with. Over time, every vendor just provided their own switch, router, or maybe figured out how to reconfigure another existing device to also provide the routing or access needed, To say the least, it's a mess.
 
The client requests a solution which provides a means to accomodate 6 internet connections (4 T-1 lines, and 2 satellite) in a manner which aggregates available bandwith and provides redundancy. The T-1 lines will be the main internet access, with the satellite connections only used if available bandwidth falls below some threshold, say 3Mb. There are many internal networks which need to be routed to and between, in total, about 20 subnets. There are 2 SCADA (Control) networks which have a mandatory requirement of 1Mb each, a VoIP system which does not use any internet connetivity as there are 6 POTS lines dedicated to it, an internal office LAN and a turbine manufacturers site LAN.
 
The T-1 lines, at 1.5Mb x 4 = 6Mb.
 
The 2 SCADA networks require a guaranteed 1Mb each, the remaining 4Mb is to be allocated between the office LAN and the turbine manufacturer site LAN. The satellite connection are only to be active in the event bandwidth falls below 3Mb.
 
There are 2 Cisco 2801 routers on site which could be reutilized if appropriate. Each T-1 has it's own Adtran CSU with Ethernet out. All T-1 lines are /29 IP Blocks. 2 of the T-1 lines are adjacent IP Blocks, for what its worth.
 
Everything here is open to reconfiguration. The client wants this finally integrated correctly with the ability to address emerging Electrical Utility cybersecurity requirements in the immediate future.
 
An ideal solution would be fully redundant to eliminate the single point of failure at the edge router. As to whether there needs to be separate edge and interior routers, I just don't know that. I would guess everything could be done with just a pair of redundant routers at the edge, but perhaps it is better to do the interior routing between subnets on a different router(s).
 
Again, the goal is a well integrated, redundant, and secure solution. My part is mostly complete, with the OSP part of the network finally at 100% after 5 years of stupid and careless misconfigurations and bad fiber splicing (by others).
 
I'm absolutely covered up in business at Layer 1 & 2 on these sites, as the physical plant and associated network elements are typically very poorly designed, specified, and implemented. The complexity of this job leads me to seek outside advice and ultimately a more qualified Cisco professional than me. I'm experienced enough with Cisco to know when I'm in over my head. I know a diagram would be nice, but at this point I've only got a very detailed diagram which reveals too much site identity information to make public. I'll wait to see a few comments and in the meantime work on removing site identity info so I can post a good diagram for everyone to see.

View 1 Replies


ADVERTISEMENT

Cisco :: Port 6050 Accepting Connections On 2801?

Dec 14, 2012

I have a 2801 with a very simple config that's accepting telnet connections on port 6050 from everywhere:

View 1 Replies View Related

Cisco LAN :: Asa 5510 Managing The Ports

Sep 26, 2012

We just got a new ASA5510 (straight out of the box). I’m new to the Cisco but feel we followed the directions. We connect to the management port and have our workstation set to get an ip via dhcp. A cat5 is connected to the management port, that goes into a hub (tested to work) and a cat5 is connected from the hub to the workstation (tested to work). Nothing else is connected. The workstation does not get an ip address. (assigns APIPA) Both the 5510 and workstation have been rebooted.The workstation works otherwise. We have also connected both a crossover and straight through cable from the 5510 to the workstation. We have statically assigned an ip of 192.168.1.2 to the workstation and cannot ping the cisco (192.168.1.1).

View 2 Replies View Related

Cisco 5505 Asa Vpn Tunnel Managing Apps

Aug 12, 2011

I have an interesting SVPN challenge that I'm asking the subject experts here to assist me in solving.A customer in Domain A wants to transmit data to Domain B. The customers have agreed to establishing a secure vpn connection from Domain A to Domain B to transmit real time data. The challenge comes from sending unencrypted data from nodeA to nodeB & nodeC withing an encrypted VPN tunned to node d.The challenge is sending non-encrypted data from NodeA to NodeB where an encrypted VPN session is active. Every time I attempt to configure the interface (AppC) the VPN session is terminated, and the interface can no longer "see" nodeD via IP mapping. An engineer recommended adding a second NIC card to NodeB thereby permitting control of the AppC even when the VPN is up and running.Can I send live non-encrypted data to NodeB data buffer, while AppC sends data to NodeD in a VPN tunnel ?

View 1 Replies View Related

Cisco :: Managing Test Lab In Enterprise Environment

Jan 5, 2012

I want to create a network with a bunch of routers and switches to be used as a test network for company employees to remotely login and learn networking.I don't want this network to interfere with the rest of the network in any way.I am basically trying to create a stub network or a passive network!!

View 4 Replies View Related

Cisco :: Managing Dell 6224 From 2950g?

May 28, 2012

I am trying to manage my Dell switch that is trunked from my Cisco 2950, I have trunked vlan 251 (management vlan) and 252,configs below

Cisco 2950 :-

Current configuration : 4794 bytes
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption

[code]....

View 7 Replies View Related

Cisco :: Managing WLC 4404 Running Version 6.0.202

Feb 27, 2013

I've downloaded Prime Infrastructure 1.2 eval and wanted to see what it looked from WCS that I am currently using to manage the wireless network and I added the WLC (4404) device but it list the device as  "Managed with Warning" and I can't find what the warning is. 

View 3 Replies View Related

Cisco AAA/Identity/Nac :: NAC 4.1.6 Managing Trunk Port?

Sep 1, 2011

Running Cisco NAC 4.1.6 OOB on the LAN.  For some reason in the middle of the night, the snmp trap mac-notification added command appeared on the trunk uplink port of one of our switches. 

I don't know exactly when the command was added but at 2am when the backup of the config was taken, it was there.  At around 4:30am, the uplink went off-line.  Is there anything within NAC that would push a change like that automatically to a switch.  We do have NAC Profiler running on the network also.The problem was in a branch office so I only got the information second hand what was on the switch itself.  We moved the uplink to a different port which allowed the switch to show up on the CAM again, however when I viewed it, the uplink port was set to controlled! 
Does this make any sense?

how long devices will stay in the certified device list if no timer is configured to clear it out?

View 2 Replies View Related

Managing Browser Permissions On Network

Sep 23, 2011

I have been trying to convince my bosses, the IT department, and others where I work, in a small call center, to switch to a different browser other than IE. The reason is IE times out on the techs a lot and freezes up constantly. I am able to use Firefox and Chrome at the lead station and do not have any issues, but the only browser currently allowed on the techs computers is IE. The reason I am getting as to why this is not possible is that with IE, IT is able to block certain options in IE from being changed such as proxy settings, add-ons, and advanced settings, but that these settings cannot be blocked or managed in firefox and chrome.

View 4 Replies View Related

Cisco :: Managing Lightweight Access Points In Ciscoworks LMS 4.0?

Jul 25, 2011

Is it possible to manage Lightweight Access Points in Ciscoworks LMS 4.0?

View 3 Replies View Related

Configuring Network Server For Managing Internet And LAN?

Jun 1, 2011

I have a small lan of around 10 computers in my office which are connected through a switch connected to a airtel broadband connection. I want to configure a network server so that I could manage an control the internet traffic used by all the workstations in the lan through that server. All the workstations have either WinXP or Windows 7 on it. I haven't purchased a server. I want to use a desktop(having some good configuration) as my network server.

View 6 Replies View Related

Cisco Switching/Routing :: Nexus 1000v / VSM - Managing Multiple VDS?

Apr 17, 2012

Anyone got a single VSM (albiet in HA) managing two vDS split over two ESX clusters connected to a single instance of vCenter?

View 0 Replies View Related

Cisco Wireless :: Aironet 1040 Access Point Managing

May 22, 2012

We are currently using several AP's in our organization. And in this one AP i want to give a user the power to change the password of the wireless network to prevent miss use. I was wondering if it was possible to create an account who only has the privilege to change the WPA key?? I want to prevent that he will accidently change other settings.

View 5 Replies View Related

Cisco Application :: Managing CSS11500 Loadbalancers In Cluster Mode

Jul 1, 2012

This is a newbie question regarding CSS11500 series loadbalancers as I trying to get up to speed with managing them as part of my job.  I noticed that there are a couple of CSS "clustered together" since I see they are managed using a single ip address.
 
My question is around how to establish a session to each individual device in this cluster, if at all possible?  If is not possible, how do manage the secondary device in this cluster to perform tasks such as copying new software to it, backing it up, etc.?        

View 1 Replies View Related

Cisco Firewall :: Managing ASA5510 Using ASDM Via Internal Interface

May 17, 2012

I am currently managing an ASA5510 using ASDM through the management port but I would like to manage the ASA through the internal port.
 
My concern is that I thought I remembered reading someplace that if you setup an internal port for management that it can't be used for anything else.  Is this correct?
 
I only configured one internal port and it is the path to my LAN.  I would hate to configure the port for management only to find that I disconnected my firewall from my internal network in the process.  Can I use my one and only configured internal port for both ASA management and route from my LAN thru the ASA firewall?
 
I currently have the management port set to 192.168.1.1 and my internal interface is 10.1.1.1.  If I open ASDM and connect thru the management port and select Configuration/Device Management/Management  Access/ASDM/HTTPS/Telnet/SSH
 
select "ADD"
select access type "ASDM/HTTPS"
select interface "internal"
IP Address   "10.1.1.0"
Mask       "255.255.255.0"
 
Will that give me access to ASA management thru my internal network but cripple my network access to the ASA? 

View 6 Replies View Related

Cisco Switching/Routing :: Managing Proper VLAN Configuration To 3750 Switch

Mar 6, 2013

I have a 2911 router connected to a 3750 switch. I have configured vlan interfaces on the 2911 router:I am using the vlan 89 (89.2) as the management ip address for me to remotely get to the switch. Is this a proper configuration or could this cause issues in the future.

View 4 Replies View Related

Linksys Wireless Router :: Managing Bandwidth / Users On Home Network With E2000

Aug 13, 2012

I've got the E2000 at home for our private network.
 
We are three guys sharing a flat. We have personal laptops, work laptops, mobile phones, games consoles, tablets etc that connect to the internet.
 
Problem is that when someone downloads stuff, the speed is slow for the rest of us. So i was hoping i could set up something like three "channels" so each of us could have the same download speed, ie 1 mbs each regardless if others are using the network at the same time. And then maybe a guest network for all the mobiles and tablets etc. MAC filtering for access for our personal laptops should work.
 
We have a 20mbit cable network line.
 
Can i do all of this on the E2000 and how?

View 5 Replies View Related

Cisco Switches :: SG300-28P And SG300-52 Web Managing - Fans

May 26, 2011

1) I have a Cisco SG300-28P. I plan to add a SG300-52. Would it be possible to manage the new switch through the SG300-28P web browser ?

2) There are 2 fans in the POE model SG300-28P. How many fans are they in the non POE switch SG300-52 ?

View 2 Replies View Related

Cisco WAN :: 2801 Cannot Always Ping 8.8.8.8

Feb 5, 2013

I have a Cisco 2801 with dual ADSL WAN connections, PATing to a network hanging on the fa0/1 interface. From the server connected to the router (hanging off of the fa0/1) interface, I can ping any address and there are no issues. But from inside the Cisco CLI, pinging certain addresses causes erratic behavior. [code]

View 5 Replies View Related

Cisco WAN :: 2801 Can't Seem To Get Protocol Up

Nov 9, 2011

I have a 2801 router.  The Fa0/0 int shows up/down.  I have plugged it into diffrent cisco and non cisco switches and even a cross over cable to my laptop.  I cant seem to get the protocol up.  I have changed the speed to 100 and duplex to full to try to get it up that way and nothing. [code]

View 7 Replies View Related

Cisco WAN :: 2801 Route-Map Not Seeing DHCP Next-Hop

Dec 23, 2011

I have a 2801 with dual ISP connections, and I have configured route-maps to direct voice traffic over ISP1 (working just fine), and I'm attempting send all other traffic over ISP2 (traffic is load-balancing instead).  The connection to ISP2 is DHCP, and I have configured a route-map to route this traffic using the 'ip next-hop dynamic dhcp' command, but when I look at the route-map, it states the following: ip next-hop dynamic dhcp - current value is UNKNOWN..Is there something that I need to enable in order to see the next-hop, and properly send traffic over the ISP2 connection? [code]

View 9 Replies View Related

Cisco WAN :: 2801 - Access Web Server From LAN

May 3, 2012

I have a Router 2801 What conf should i make to access the webserver from the same LAN.
 
!
no ip dhcp use vrf connected
ip dhcp excluded-address 192.168.1.1 192.168.1.63

[Code].......

View 6 Replies View Related

Cisco WAN :: Use Of USB Interface On 2801 Router?

Jul 23, 2007

I looked but could not find any information on what's the use of the USB interface on my 2801 router. I saw something about Cisco USB memory module and eToken by Aladdin. Is this interface restricted to Cisco and Aladdin only?

View 17 Replies View Related

Cisco VPN :: 2801 VPN IPSEC Is Restarted

Oct 14, 2012

I have a Cisco 2801 with flash: c2801-advipservicesk9-mz.124-16.bin where I use to doing VPN IPSEC.My problem is where I do a connection with a client, if my VPN dont have a traffic, the tunnel are closed. If a receive or send any traffic, the tunnel get up again.If  don't have traffic, this tunnel is closed and after is opened other tunnel where is changed the conn-id to 999 for example.This comportament is normal? Exist a form that my tunnel never close? I enabled the parameters below: [code] But the tunnel continues closing if a don't have traffic.

View 5 Replies View Related

Cisco VPN :: 2801 IPSec VPN Not Working

Mar 21, 2012

We are setting up a new VPN from an ASA to a cisco 2801 router (behind a third parties checkpoint firewall).  We seem to be almost there with the setup but the tunnel is not working correctly.  I have included a debug from the 2801 router and its config and a diagram of the setup. [code]

View 2 Replies View Related

Cisco VPN :: Getting VPN Into Home Router With 2801?

Aug 4, 2011

I have a Cisco RV110W small business router setup at my home. It has one of those HTML GUI interfaces, check the boxes, etc.., to get things working. Basically, your typical home router with VPN.   I have enabled the VPN, it's PPTP, added the password, and now it's automagically configured! I can successfully VPN to my home with a Windows7 client.  Here's my problem, I now need to VPN into my home router with a 2801.  Is this possible? Everything I found on the subject has only been to setup a Cisco IOS router as a VPN server or tunneling to another IOS router. No examples using an IOS based router as the client.

View 3 Replies View Related

Cisco WAN :: 2801 Router Having High CPU 99%?

May 29, 2012

We have one Router Cisco 2801 at the customer site and facing issue of having very High CPU coming to 99%.CPU utilization for five seconds: 99%/28%; one minute: 99%; five minutes: 98%

View 2 Replies View Related

Cisco WAN :: MLS QoS Map Command Missing On 2801

Oct 31, 2012

I am trying to run the following commands on a 2801 router, but the commands are missing:
 
mls qos
mls qos map cos-dscp 0 8 16 40 32 46 48 56
 
The only QoS command i have in global config is (no MLS qos) :
 
REMOTE-ROUTER1(config)#qos ?
restore-show-output  Restore old show output
shape-timer          Set the HQF shape timer interval
 
The router is running IOS:
 
System image file is "flash:c2801-ipbasek9-mz.151-4.M5.bin"
 
Am i just running the incorrect IOS or am i missing somehting, i need to change the QoS Map for my Nortel VoIP.  The VoIP phones connect to a 3750 PoE which used to conenct to a 2651XM to route VoIP and data traffic over the same copper pairs (WAN link to hub site) hence the need for a Service policy but being Nortel phones, require changing the cos-dscp map.  the 2801 is going to replace the 2651XM using a new HWIC.

View 4 Replies View Related

Cisco WAN :: 2801 Max Ethernet Speed

Jun 23, 2011

We have a 2801 rotuer in place that hooks up to a metro ethernet link that's obviously dropped off to us via ethernet.  Anyway, the throughput granted to us is 20MB, but for some reason I can't get it to go anything above 11MB at the most.  I've spent a day going through documentation trying to find the fastest speed the 2801 supports and I can't find my answer.  I've seen that the high speed wan cards in this router support up to 45MB, but I'm not using a WAN card, only one of the two built in 10/100 ports.
 
what the maximum throughput speed is on a 2801?

View 7 Replies View Related

Cisco VPN :: VPN Access To FWSM LAN Through A 2801

Mar 26, 2011

I have a FWSM in my 6509, this firewall is managing three VLANs, one of which holds a file server. As you all know, FWSM do not support VPN like the ASAs and PIXs do. I have been trying to add remote access to this file server LAN all week. The only VPN device i have is a 2801 router.
 
first layout: VPN router behind FWSMstatic translation from FWSM LAN (private) to VPN WAN (public)default route was facing back at FWSMip address pool was to be NAT'd on the interface facing the FWSM  the idea was that my VPN address pool would be NAT'd back to the FWSM on it's VLAN. since the FWSM was managing this VLAN and recognized the source IP of the translated address pool, i would have access to my precious file server.
 
second layout: VPN router fa 0/1 on a /30 with 6509 (public)VPN router fa 0/0 still on the same LAN as FWSM (private)address pool for VPN once again NAT'd to fa 0/0default route pointed to fa 0/1static route of FWSM LAN pointed to fa 0/0  this idea was to have more of a 'inside' and 'outside' interface on the VPN router. this too did not work, having used every trick in the book, i could still not ping anything on the FWSM LAN while VPN'd in the network (aside from the LAN interface on my router)
 
trace route was showing that the all routes were headed out fa 0/1 (default route) and all to my FWSM died. i really don't think my address pool is being NAT'd, though my route map statement applied to the NAT policy is permitting my VPN address pool.
 
I am new to VPN technology, one of those things that happened to land on my lap. how this layout could work? there are no good VPN Remote access walkthroughs for a situation like this (2801 allowing access to a FWSM controlled LAN)

View 2 Replies View Related

Cisco VPN :: 2801 Can't Ping Local LAN

Apr 23, 2011

i have configured remote access vpn on my 2801 router's gio0/0 int ip x.x.x.1. i connected my laptop through vpn client from internet. i connected successfully and my vpn router gives me the assigned ip block y.y.y.1. from my laptop i can ping the other int gio/1 ip z.z.z.1 but i cant ping the ip z.z.z.2 of my core sw which is connected on router's int gi0/1.

View 14 Replies View Related

Cisco WAN :: 2801 How To Protect It For Sessions Of SSH And Telnet

Dec 19, 2012

Someone told me the commands, but I can't remember them.  Have a router (2801) at the end of a highly utilized T1 link/router.  How do I protect it so my SSH and/or Telnet sessions will get serviced if the router is real busy. 

View 9 Replies View Related

Cisco WAN :: 2801 And Switch Trunk Port

Apr 20, 2012

1- Cisco Router
Eth0/0 : Ip address 192.168.1.1 /24   == connected my laptop of 192.168.1.2
 /1: Ip address : 192.168.2.1 /24   = connected cisco swith

2 - Cisco Switch
VLAN 2 Name : Sales : ip address 192.168.3. 1 = connected computer 192.168.3.2
VLAN 3  Name : Marketing : ip addres 192.168.4.1 = connected computer 192.168.4.2

So I want my laptop that connected the router Eth0/0 Interface should access both VLAN 2 and VLAN 3 computers

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved