Cisco WAN :: 2801 - Gather Netflow Data Over IPsec VPN?

Feb 14, 2011

I'm trying to gather netflow data over an IPSEC VPN and through my research I've learned that I need to configure Flexible Netflow.  However, I have a Cisco 2801 router with the latest ROMMON and IOS and the Flexible Netflow options aren't available. 
 
For instance:
 
flow exporter dwtmonitor
destination 10.0.16.172
source Loopback0
transport udp 2055
output-features

When I type "flow exporter <name>" it only allows me to enter "flow <name>" and there's no "destination" options or anything else.
 
ROMMON: 12.4(13r)TIOS:  12.4(25d)

View 2 Replies


ADVERTISEMENT

Cisco :: Nexus 7000 Netflow Missing Data

Jun 26, 2012

I've configured N7K to export layer 2 flows. Using 2 different flow collectors (open source and commercial), gaps/drops in the reported traffic are observed on a periodic basis.Problem doesn't seems to be with the exporters, hence I wondering if netflow configuration on N7K can be tweaked to address this symptom. Using the 'show exporter' command, no errors/drops are observed. [code]

View 2 Replies View Related

Cisco :: Fetch Data On Netflow Analyzer 9 By 2911 Router

Nov 9, 2012

I am trying to fetch data on netflow analyzer 9 by Cisco router 2911. But netflow is unable to show any data.

cr2911-01#sh runn | sec ip flow
ip flow-cache timeout active 1
ip flow-export version 5
ip flow-export destination 10.1.208.32 9996

[code]...

View 2 Replies View Related

Cisco VPN :: 2801 VPN IPSEC Is Restarted

Oct 14, 2012

I have a Cisco 2801 with flash: c2801-advipservicesk9-mz.124-16.bin where I use to doing VPN IPSEC.My problem is where I do a connection with a client, if my VPN dont have a traffic, the tunnel are closed. If a receive or send any traffic, the tunnel get up again.If  don't have traffic, this tunnel is closed and after is opened other tunnel where is changed the conn-id to 999 for example.This comportament is normal? Exist a form that my tunnel never close? I enabled the parameters below: [code] But the tunnel continues closing if a don't have traffic.

View 5 Replies View Related

Cisco VPN :: 2801 IPSec VPN Not Working

Mar 21, 2012

We are setting up a new VPN from an ASA to a cisco 2801 router (behind a third parties checkpoint firewall).  We seem to be almost there with the setup but the tunnel is not working correctly.  I have included a debug from the 2801 router and its config and a diagram of the setup. [code]

View 2 Replies View Related

Cisco Firewall :: Can Pull Netflow Style Data (Top Talkers / Sessions) From ASA 5505s

Aug 19, 2012

I need to know if I can pull Netflow style data (Top Talkers, Top Sessions, etc) from ASA 5505s?  We are looking at buying some but I need to be able to export this kind of data to my managment station which is also a collector. I have read on this forum that 8.2 and above should support Netflow but I have read conflicting information.

View 2 Replies View Related

Cisco :: 2951 - Interfaces Send Netflow Data Despite No Flow Config Under Interface

Aug 17, 2011

Cisco 2951 w/ HWIC-4ESW
IOS 15.0(1)M5 
#sh ip flow int
Vlan533
ip flow ingress
ip flow egress
#
 
The SVI sends the flow data just fine, however I also continue to receive flow data from most other interfaces.
 
I have attached a screenshot of one of our netflow collectors indicating that many of the interfaces are sending flow data even though not configured to do so. We have two different netflow collectors, from different vendors and both confirm the same interfaces sending flow data.
 
Normally I wouldn't care and ignore it, however one of them uses a license limit by interface and is a bit problematic.

View 2 Replies View Related

Cisco :: 7606 / 2811 - SNMP And Netflow Difference Displaying Different Data For Same Interfaces

Nov 29, 2012

I've got an issue with SNMP and netflow tools. They are displaying different data for the same (sub)interfaces.I've got metroethernet link which connects root A (Cisco 7606, 12.2(18)SXF8) and root B (Cisco 2811, 12.3(11)TS). MPLS is configured on the link (behind root B there is no more MPLS). I'm attaching root configurations (I've ommited parts of config).Interfaces are:

Root A - gi2/6.2144
Root B - fa0/1
 
I've configured SNMP and netflow on both devices. I'm using two SNMP tools (CA Spectrum and eHealth) and two netflow tools (CA NetQoS Reporter Analyzer and Fluke Networks NetFlow Tracker) to collect the data. SNMP tools show the same info for defined (sub)interface.Netflow tools also show the same info for defined (sub)interface. I'm attaching reports from one SNMP tool and one netflow tool for the same time period.
 
1. Looking at SNMP tool, it can be seen quite amount of that data in both in and out direction.
2. Looking at netflow tool, it can be seen quite amount of that data in out direction, while in direction shows small amount of data.
 
I'm aware that Cisco has difficulties with SNMP counters on subinterfaces. I'm also aware that MPLS netflow has its own difficulties.Root B netflow configuration is quite simple as it has just 2 interfaces to configure netflow on (Fa0/0 and Fa0/1). So I would guess SNMP and netflow data should match, but they don't. When you look at SNMP tool reports for roots A and B, it can be seen that traffic volume is practically mirrored.

View 3 Replies View Related

Cisco :: Flexible Netflow Configuration With IPSec 887

Oct 29, 2012

I am trying to configure netflow/flexible netflow on some branch site 887 routers which have a IPSec tunnel back to the main office.  It is my understanding that the router will not encrypt traffic that it generates itself so the standard netflow will not work. The workaround I have seen is to use flexible netflow rather than standard.
 
I have tried to configure flexible netflow with the following configuration;
 
flow exporter EXPORTER-1
destination 192.168.10.1
source Vlan1
transport udp 9996
[Code]...

View 2 Replies View Related

Cisco Firewall :: 5510 Exporting Netflow Over A IPSEC VPN

Sep 2, 2012

we have a local Netflow collector working fine. We also have a centralised collector that we’d like to use to send the same Netflow data, but it is not being received. We need to send the data via an IPSEC VPN.
 
When I do a 'show flow-export counters' I can see the packets sent increasing. The local collector is receive netflow data. I am using the below config, 

access-list global_mpc extended permit ip any any
!
!IP far end of VPN

[Code].....

View 3 Replies View Related

Cisco Firewall :: 5510 ASA Exporting Netflow Over IPsec Vpn

Nov 29, 2012

we have a Cisco ASA 5510 8.4, this device is reachable through a lan to lan IPsec vpn. We are able to activate the netflow export (we see flow export counters incrementing), but the flow is not passing through the vpn. Our netflow collector is on the other side of the IPsec tunnel so we define it linked to the internet interface.Is the export possible through the vpn? I read in a Solarwinds forum that it should not be possible.What ip address is choosen as source interface by ASA? Is there a way to force a source interface?

View 5 Replies View Related

Cisco VPN :: 2801 - Unable To Route Traffic Over IPsec / GRE Tunnels

Jan 12, 2013

I have an issue where I can get traffic to pass from HDQ to two branch offices over our ipsec/gre tunnels even though the tunnels appear to be UP. The HDQ is a 2811, branch is a home office using an 871W and branch runs a 2801 router. I initially had HDQ working fine with the 871W but when I configured branch2 (2801), they both broke. The tunnels appear to be up but traffic is not routing across them. The two 2801 routers run 12.4 (c2800nm-adventerprisek9-mz.124-24.T2.bin). These are gre over ipsec tunnels. Currently traffic flows over an exsting MPLS network that we are getting away from due to cost. As soon as I change the routes to point to the Tunnels, it breaks. Traffic doesn't appear to pass through the tunnel. I have attached my sanitized configs.

HDQ#sh crypto sessCrypto session current status
Interface: FastEthernet0/1Session status: UP-ACTIVEPeer: 205.205.205.21 port 500  IKE SA: local 204.204.204.66/500 remote 205.205.205.21/500 Active  IPSEC FLOW: permit 47 0.0.0.0/0.0.0.0 0.0.0.0/0.0.0.0        Active SAs: 4, origin: crypto map  IPSEC FLOW:

[Code]....

View 3 Replies View Related

Cisco VPN :: Establish IPSec Tunnel Between 2801 And Cyberoam Equipment At End Point?

Mar 31, 2011

i'm triyng to establish a vpn ipsec tunnel between my cisco2801 and a cyberoam equipment, at the end point.Debugging isakmp, i have this output, where xxx.xxx.xxx.xxx is the remote peer address, and yyy.yyy.yyy.yyy is mine.What can i try?
 
Apr  1 14:48:12.542: ISAKMP:(0): SA request profile is (NULL)Apr  1 14:48:12.542: ISAKMP: Created a peer struct for xxx.xxx.xxx.xxx, peer port 500Apr  1 14:48:12.542: ISAKMP: New peer created peer = 0x661C2D4C peer_handle = 0x80000003Apr  1 14:48:12.542: ISAKMP: Locking peer struct 0x661C2D4C, refcount 1 for isakmp_initiatorApr  1 14:48:12.542: ISAKMP: local port 500, remote port 500Apr  1 14:48:12.542: ISAKMP: set new node 0 to QM_IDLE      Apr  1 14:48:12.542: insert sa successfully sa = 66DF4F5CApr  1 14:48:12.542: ISAKMP:(0):Can not start Aggressive mode, trying Main mode.Apr  1 14:48:12.542: ISAKMP:(0):found peer pre-shared key matching xxx.xxx.xxx.xxxApr  1 14:48:12.542: ISAKMP:(0): constructed NAT-T vendor-07 IDApr 

[URL]

View 2 Replies View Related

Cisco VPN :: 5520 BUN K9 Supports Data Compression On VPN IPsec

Sep 10, 2012

I would like to know if the ASA 5520 BUN K9 supports the data compression on VPN IPsec.

View 2 Replies View Related

Cisco :: NCS 1.1.0.58 Failing To Gather Current Clients From APs

Apr 24, 2012

We're running NCS 1.1.0.58. Since updating to this release from the 1.0 release, the 'Autonomous AP Client Status' and 'Lightweight Client Status' background tasks have been failing with message 'java.lang.NullPointerException'.  I believe as a result of this that the 'Current Clients' tab on an AP monitoring screen just reports 'No data available'.

View 2 Replies View Related

Cisco Routers :: RVL200 IPSEC Channel All Or Some Data Traffic Through Tunnel

Jan 2, 2013

Is it at all possible to channel all/some data traffic through an established ipsec tunneled connection using the RVL200? I have successfully established an ipsec connection through RVL200 and RV042 routers and are able to connect to servers/computers behind it.Now I want to channel all or some traffic through the ipsec-tunnel for computers that reside on 192.168.1.0 subnet of RVL200 network.
 
Main office - RV042 router - 10.200.62.1
Remote office - RVL200 router - 192.168.1.1
 
I am trying to use the Advanced Routing option to add static routes but I am not 100% sure if I am configuring the routes correctly.To give an example of routing DNS requests for HOTMAIL.COM [65.55.72.183]: [code]For some reason this does not appear to work. I have also tried using the interface setting of WAN and tested - this also does not work.

View 10 Replies View Related

Cisco Routers :: 4400N - Gather DHCP Client Stats?

Oct 2, 2012

I've got a WRVS4400N wireless router running DHCP for a couple dozen wireless clients in a public library. We need to gather statistics on the wireless clients on a daily basis: average number of clients, max number of clients, average time used per client etc.
 
The router only gives a list of clients currently allocated an IP address, but there doesn't seem to be a way to gather statistics over time. Is there a program that will interface with the router to gather more detailed statistics?

View 1 Replies View Related

Cisco Switching/Routing :: 4948 - Difference Between Netflow / Netflow-Lite

Mar 13, 2012

Any major difrrence between Netflow v/s Netflow-Lite?
 
I am trying to understand if Cisco 4948E can do the same job as Cisco 4500E or not and difference between Netflow v/s Netflow-Lite will work for me to select correct product.

View 2 Replies View Related

Cisco Routers :: Can RV042G IPSec VPN Support Apple IOS IPSec VPN

Apr 29, 2013

I tried any type of combination and just couldn't make it works.  Only PPTP works well. Whether Apple iOS IPSec VPN is supported or not?

View 11 Replies View Related

Cisco WAN :: 2801 Cannot Always Ping 8.8.8.8

Feb 5, 2013

I have a Cisco 2801 with dual ADSL WAN connections, PATing to a network hanging on the fa0/1 interface. From the server connected to the router (hanging off of the fa0/1) interface, I can ping any address and there are no issues. But from inside the Cisco CLI, pinging certain addresses causes erratic behavior. [code]

View 5 Replies View Related

Cisco WAN :: 2801 Can't Seem To Get Protocol Up

Nov 9, 2011

I have a 2801 router.  The Fa0/0 int shows up/down.  I have plugged it into diffrent cisco and non cisco switches and even a cross over cable to my laptop.  I cant seem to get the protocol up.  I have changed the speed to 100 and duplex to full to try to get it up that way and nothing. [code]

View 7 Replies View Related

Cisco :: Netflow On 2800

Apr 17, 2013

I have configured the netflow to gathering flow from my cisco 2800 as below:
 
interface GigabitEthernet0/0
description ### To VNPT_FTTH_20M ###
no ip address
ip flow egress
ip route-cache flow
[Code]...
 
But i still not see users addresses(each individual hosts will go though) What and where i am configured wrong? I also attached here the map network.

View 5 Replies View Related

Cisco :: 5508 - WCS 7.4 Netflow

Jan 8, 2013

configured the monitor and exporter on the wcs 5508 running 7.4.100.0 and it is not working. 

View 1 Replies View Related

Cisco WAN :: 2801 Route-Map Not Seeing DHCP Next-Hop

Dec 23, 2011

I have a 2801 with dual ISP connections, and I have configured route-maps to direct voice traffic over ISP1 (working just fine), and I'm attempting send all other traffic over ISP2 (traffic is load-balancing instead).  The connection to ISP2 is DHCP, and I have configured a route-map to route this traffic using the 'ip next-hop dynamic dhcp' command, but when I look at the route-map, it states the following: ip next-hop dynamic dhcp - current value is UNKNOWN..Is there something that I need to enable in order to see the next-hop, and properly send traffic over the ISP2 connection? [code]

View 9 Replies View Related

Cisco WAN :: 2801 - Access Web Server From LAN

May 3, 2012

I have a Router 2801 What conf should i make to access the webserver from the same LAN.
 
!
no ip dhcp use vrf connected
ip dhcp excluded-address 192.168.1.1 192.168.1.63

[Code].......

View 6 Replies View Related

Cisco WAN :: Use Of USB Interface On 2801 Router?

Jul 23, 2007

I looked but could not find any information on what's the use of the USB interface on my 2801 router. I saw something about Cisco USB memory module and eToken by Aladdin. Is this interface restricted to Cisco and Aladdin only?

View 17 Replies View Related

Cisco VPN :: Getting VPN Into Home Router With 2801?

Aug 4, 2011

I have a Cisco RV110W small business router setup at my home. It has one of those HTML GUI interfaces, check the boxes, etc.., to get things working. Basically, your typical home router with VPN.   I have enabled the VPN, it's PPTP, added the password, and now it's automagically configured! I can successfully VPN to my home with a Windows7 client.  Here's my problem, I now need to VPN into my home router with a 2801.  Is this possible? Everything I found on the subject has only been to setup a Cisco IOS router as a VPN server or tunneling to another IOS router. No examples using an IOS based router as the client.

View 3 Replies View Related

Cisco WAN :: 2801 Router Having High CPU 99%?

May 29, 2012

We have one Router Cisco 2801 at the customer site and facing issue of having very High CPU coming to 99%.CPU utilization for five seconds: 99%/28%; one minute: 99%; five minutes: 98%

View 2 Replies View Related

Cisco WAN :: MLS QoS Map Command Missing On 2801

Oct 31, 2012

I am trying to run the following commands on a 2801 router, but the commands are missing:
 
mls qos
mls qos map cos-dscp 0 8 16 40 32 46 48 56
 
The only QoS command i have in global config is (no MLS qos) :
 
REMOTE-ROUTER1(config)#qos ?
restore-show-output  Restore old show output
shape-timer          Set the HQF shape timer interval
 
The router is running IOS:
 
System image file is "flash:c2801-ipbasek9-mz.151-4.M5.bin"
 
Am i just running the incorrect IOS or am i missing somehting, i need to change the QoS Map for my Nortel VoIP.  The VoIP phones connect to a 3750 PoE which used to conenct to a 2651XM to route VoIP and data traffic over the same copper pairs (WAN link to hub site) hence the need for a Service policy but being Nortel phones, require changing the cos-dscp map.  the 2801 is going to replace the 2651XM using a new HWIC.

View 4 Replies View Related

Cisco WAN :: 2801 Max Ethernet Speed

Jun 23, 2011

We have a 2801 rotuer in place that hooks up to a metro ethernet link that's obviously dropped off to us via ethernet.  Anyway, the throughput granted to us is 20MB, but for some reason I can't get it to go anything above 11MB at the most.  I've spent a day going through documentation trying to find the fastest speed the 2801 supports and I can't find my answer.  I've seen that the high speed wan cards in this router support up to 45MB, but I'm not using a WAN card, only one of the two built in 10/100 ports.
 
what the maximum throughput speed is on a 2801?

View 7 Replies View Related

Cisco VPN :: VPN Access To FWSM LAN Through A 2801

Mar 26, 2011

I have a FWSM in my 6509, this firewall is managing three VLANs, one of which holds a file server. As you all know, FWSM do not support VPN like the ASAs and PIXs do. I have been trying to add remote access to this file server LAN all week. The only VPN device i have is a 2801 router.
 
first layout: VPN router behind FWSMstatic translation from FWSM LAN (private) to VPN WAN (public)default route was facing back at FWSMip address pool was to be NAT'd on the interface facing the FWSM  the idea was that my VPN address pool would be NAT'd back to the FWSM on it's VLAN. since the FWSM was managing this VLAN and recognized the source IP of the translated address pool, i would have access to my precious file server.
 
second layout: VPN router fa 0/1 on a /30 with 6509 (public)VPN router fa 0/0 still on the same LAN as FWSM (private)address pool for VPN once again NAT'd to fa 0/0default route pointed to fa 0/1static route of FWSM LAN pointed to fa 0/0  this idea was to have more of a 'inside' and 'outside' interface on the VPN router. this too did not work, having used every trick in the book, i could still not ping anything on the FWSM LAN while VPN'd in the network (aside from the LAN interface on my router)
 
trace route was showing that the all routes were headed out fa 0/1 (default route) and all to my FWSM died. i really don't think my address pool is being NAT'd, though my route map statement applied to the NAT policy is permitting my VPN address pool.
 
I am new to VPN technology, one of those things that happened to land on my lap. how this layout could work? there are no good VPN Remote access walkthroughs for a situation like this (2801 allowing access to a FWSM controlled LAN)

View 2 Replies View Related

Cisco VPN :: 2801 Can't Ping Local LAN

Apr 23, 2011

i have configured remote access vpn on my 2801 router's gio0/0 int ip x.x.x.1. i connected my laptop through vpn client from internet. i connected successfully and my vpn router gives me the assigned ip block y.y.y.1. from my laptop i can ping the other int gio/1 ip z.z.z.1 but i cant ping the ip z.z.z.2 of my core sw which is connected on router's int gi0/1.

View 14 Replies View Related

Cisco WAN :: 2801 / Managing 6 WAN Connections

Jul 31, 2011

The application here is a wind power project, built in two phases, without any effort to coordinate or integrate the two sites during the design phase. All operations activities for both phases are performed by one staff out of a common location. This is a rural area and Internet connectivity is mission critical due to contractual obligation with Electrical Utilities.
 
The client has a need to reconfigure a network which has grown over time in a layer by layer approach, whereas at every point in time that an additional T-1 or other changes occurred to address a specific need, no thought was ever put into integrating the entire site as a whole. It is at best a dysfunctional solution which somewhat accomplishes thier needs, and at worst, a kludgy, grossly security compromised, and difficult to use infrastructure. There is every kind of equipment one can imagine, each installed by some entity providing needed services on the site, but forced to make uninformed decisions because the client really has no IT department to coordinate with. Over time, every vendor just provided their own switch, router, or maybe figured out how to reconfigure another existing device to also provide the routing or access needed, To say the least, it's a mess.
 
The client requests a solution which provides a means to accomodate 6 internet connections (4 T-1 lines, and 2 satellite) in a manner which aggregates available bandwith and provides redundancy. The T-1 lines will be the main internet access, with the satellite connections only used if available bandwidth falls below some threshold, say 3Mb. There are many internal networks which need to be routed to and between, in total, about 20 subnets. There are 2 SCADA (Control) networks which have a mandatory requirement of 1Mb each, a VoIP system which does not use any internet connetivity as there are 6 POTS lines dedicated to it, an internal office LAN and a turbine manufacturers site LAN.
 
The T-1 lines, at 1.5Mb x 4 = 6Mb.
 
The 2 SCADA networks require a guaranteed 1Mb each, the remaining 4Mb is to be allocated between the office LAN and the turbine manufacturer site LAN. The satellite connection are only to be active in the event bandwidth falls below 3Mb.
 
There are 2 Cisco 2801 routers on site which could be reutilized if appropriate. Each T-1 has it's own Adtran CSU with Ethernet out. All T-1 lines are /29 IP Blocks. 2 of the T-1 lines are adjacent IP Blocks, for what its worth.
 
Everything here is open to reconfiguration. The client wants this finally integrated correctly with the ability to address emerging Electrical Utility cybersecurity requirements in the immediate future.
 
An ideal solution would be fully redundant to eliminate the single point of failure at the edge router. As to whether there needs to be separate edge and interior routers, I just don't know that. I would guess everything could be done with just a pair of redundant routers at the edge, but perhaps it is better to do the interior routing between subnets on a different router(s).
 
Again, the goal is a well integrated, redundant, and secure solution. My part is mostly complete, with the OSP part of the network finally at 100% after 5 years of stupid and careless misconfigurations and bad fiber splicing (by others).
 
I'm absolutely covered up in business at Layer 1 & 2 on these sites, as the physical plant and associated network elements are typically very poorly designed, specified, and implemented. The complexity of this job leads me to seek outside advice and ultimately a more qualified Cisco professional than me. I'm experienced enough with Cisco to know when I'm in over my head. I know a diagram would be nice, but at this point I've only got a very detailed diagram which reveals too much site identity information to make public. I'll wait to see a few comments and in the meantime work on removing site identity info so I can post a good diagram for everyone to see.

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved