Cisco WAN :: 3925 - Telnet Is Not Working
Apr 19, 2013I have one router 3925 equipment DIRECTLY connected to the Router that needs to be accessed by telnet port 23.
Please find the attached config details.
I have one router 3925 equipment DIRECTLY connected to the Router that needs to be accessed by telnet port 23.
Please find the attached config details.
i have 68 sites with Routers. On each site I have one equipment DIRECTLY connected to the Router that needs to be accessed by telnet port 23.
I have 15 off this sites that the access via telnet to the equipment’s connected after the routers are not working. These sites are using Router Cisco 3925. The other sites that are working are using Routers Cisco MWR 2921.
Both router models are running the same configuration with no filter on it.
The equipment’s after the routers are all accessed directly via telnet without the router. If the router is directly plugged to the equipment the 15 sites with Router Cisco 3925 are not accessed via telnet.
There is any bug related with the IOS version that Router Cisco 3925 is using?:
Cisco IOS Software, C3900 Software (C3900-UNIVERSALK9-M), Version 15.1(2)T2, RELEASE SOFTWARE (fc1).ROM: System Bootstrap, Version 15.0(1r)M8, RELEASE SOFTWARE (fc1).System image file is "flash0:c3900-universalk9-mz.SPA.151-2.T2.bin"
1.SCP Not Working on my Linux Box (Fedora release 7 (Moonshine))to Fedora fc11.i686 running box[CODE]
View 5 Replies View RelatedI am not able to telnet or ssh to ASA running 8.2.5(33). [code] I am able to ping inside interface of the ASA. Telnet gets stuck at Trying
View 2 Replies View Relatedimplementation of the cisco CSS 11501 boxes available as spare on our site into production for an application evry thing worked as expected. i was able to telnet the active/master box and was able to console both master and backup box from the console port.however a week post the activity im faced with this weird problem where im not able to take console or the telnet access of my primary/active box.The boxes are working in BOX-to-BOX redundancy and now im not able to telnet or console my active/master box. The telnet and console window prompts me for username and password and after entering the credentials nothing happens. no prompt or no error message is displayed.
The telnet primary authentication is via tacacs and secondary is via local. however for console im not using any method for primay authentication and local for secondary authentication. however i can successfully console my backup box. below are my obsrvations 1. the left and right status LED on the active CSS box is OFF.- it means my CSS 11501 failed and has no power. 2. upon firing the rcmd command with show line command on backup box i see that the telnet sessions and console session is established with the master box3. the redundancy state of the active box says it is master and has not changed state since my last activity, no application issue reported, all the services are active on the active box and also i can ping the active box ip address from my backup box over which box to box redundancy is established. This confirms the active box is functioning well 4. i initially thought the telnet sessions are not getting cleared, however the show line cmd with the rcmd cmd on the backup box confirms this is not happening. now im stuck as the active box cannot be accessed at all via console or telnet. i was thinking of below steps to be carried out.1. to failover the boxes and make the backup as master2. then try to take the faulty box off the network and troubleshoot (are there any other commands that i should use to troubleshoot)3. if nothing works try rebooting the box and check
NOTE: the software running is version 7.20.30.3 with standard feature set. we are not using cvdm or the CSS GUI. we could access the css initially on CSS gui and that is also not working now.
I have a customer with a 861 ISR.I want to block all the privilege 0 users from access the enable command
If i telnet into the device, as a priv=0, enable does not work
If i telnet into the device, as a priv=15, enable does work
If i telnet into the device, as a priv=0, enable does not work
If i telnet into the device, as a priv=15, enable does not work
I have issued the command:privilege exec level 15 enable Should block everyone except 15's from accessing the enable command SSH and TELNET are on the same vty:
line con 0
login authentication local_authen
no modem enable
line aux 0
line vty 0 3
[code]....
Basically TELNET is following the rules ( priv=0 not allowed to access enable ) but SSH is not following the rules ( both priv=15 and priv=0 cannot access the command ) is there a way from blocking somes users from login in completely?
I only want SSH to be allowed when accessing this switch, but telnet is still allowed, why? Whe authenticate via radius.version 12.2no service padservice timestamps debug datetime msecservice timestamps log datetime msecservice password-encryption!hostname 3750!boot-start-markerboot-end-marker!logging buffered 64000logging console informationallogging monitor informationalenable secret 5 $1$1K$!username admin privilege 15 secret 5 $1$Bs$cLHusername users view priv3 secret 5 $1$Jfnviwp!!aaa new-model!!aaa authentication login default group radius localaaa authentication enable default lineaaa authorization consoleaaa authorization exec default group radius local !!!aaa session-id commonclock timezone GMT 0clock summer-time BST recurring last Sun Mar 2:00 last Sun Oct 3:00switch 1 provision ws-c3750g-12sswitch 2 provision ws-c3750g-12ssystem mtu routing 1500udld aggressiveno ip domain-lookupip domain-name CB!!login on-failure loglogin on-success log!!crypto pki trustpoint TP-self-signed-3817403392enrollment selfsignedsubject-name cn=IOS-Self-Signed-Certificate-3817403392revocation-check nonersakeypair TP-self-signed-3817403392!!crypto pki certificate chain TP-self-signed-3817403392certificate self-signed 01 3082024C 308201B5 A0030201 02020101 300D0609 2A864886 F70D0101 04050030 31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274 69666963 6174652D 33383137 34303333 3932301E 170D3132 30343133 31303539 33395A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649 4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 38313734 30333339 3230819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281 8100C31D AE6DD8B5 56245317 AD96F4F4 727385D4 97A5B138 488A215E 4294FC40 1C5B2F26 2B75E1CF E562F240 118F2F50 0CFF2449 16EC66EA 2D489F5F F36BFD05 ACCC79CA DDDA984D 4CB7AB DD95A5E0 9274A225 3F5A3634 DEBF1A2A 416E2189 B35B4473 C7D5EE2C E3D41675 A86F31CD.
View 3 Replies View RelatedI have configured the ip telnet source-interface Loopback 0 command on a Nexus7010, but when I telnet to another device and do a show users, the ip address is of the closest interface to the device I telnet to, not the ip address of the Loopback. All interfaces are in vrf default. I am running 5.1(6) NXOS.
View 6 Replies View RelatedI need 3925 router that support BGP as well as IPSEC VPN. is this correct part number i ordered? CISCO3925-SEC/K9. Its always hard to understand Cisco licensing, specially new one. will above package will have router wth ipbasek9+seck9?
View 4 Replies View RelatedI have a new 3925 ISR G2 router with the universal IOS, 256kb flash in CF0, 1gb flash in CF1. When the router boots it prompts to enter initial config. Whether I say yes or no, enter the appropriate info, "write memory", and reload it comes up with a blank config. I've checked the config-register (2142), copied the start up-config to nvram:, flash0:, and flash1: but nothing works.
View 2 Replies View RelatedI have spend half day to look up this question in cisco official web site, but get nothing . Any infomation about vpn performance of 3925 router?Produce : cisco 3925 ( Cisco 3925 Security Bundle w/SEC license PAK )Question is , how much ipsec vpn tunnels can be carried as a vpn server of this bundle ? if more licenses may be bought, how much most tunnels can be held?
View 5 Replies View RelatedI have a Cisco 3925 router running IOS 15.2 I am trying to configure IP SLA on it. The configuration is supposed to be what is pasted below. but the CLI is rejecting the commands.Its taking oly the "ip sla responder" command after that if I enter "ip sla 1083180034" command it says invalid input. [code]
View 5 Replies View Relatedhow to setup natting on a 3925 router.
View 1 Replies View RelatedI have a question regarding the 3925 router. In the past on my old 3660's, in order to add a new line to an ACL, I would have to remove the entire ACL and readd it when adding new ACL lines to the list. Is this required on the 3925's, or is it like the ASA 5520's where you can just add an ACL any 'ol time without having to remove/add the entire ACL list?
View 2 Replies View Relatedwe are configuring a ras on 3925 router with e1 controller. when we connect the e1 controller to pbx we got on pbx a no frame alarm (detailed error is that we have nfas but we do not have cas). what could be the error? do the router need dsp to have a framed e1?
View 1 Replies View Relatedi said in the title i have forgot my password for my cisco3925 rourtor and how to reset my password
View 3 Replies View Relatedchecked all the recovery doc, however, there is no one specific for 3900 series router
View 2 Replies View RelatedI have cisco router 3925 and i add install HWIC-4ESW, as i sew on cisco documents you can hot swap the hwic without reload the router but i it's not working at all. How to do it ?
View 1 Replies View RelatedI am trying to set up a redundant OSPF setup and I am seeing behavior I don't quite understand. At the main office I have two routers, a 3825 connected via full DS3 to the MPLS cloud, and a 3925 connected to the Internet for VPN backup.There are nine branches, but I am only going to talk about three. The three branches all connect together as well as having their own MPLS connections to the cloud. They are all 2821 routers with a 4.5 Mbps multilink interface into the cloud (three T1's). One of the branches has a backup IPSec/GRE Internet connection that I want any of them to be able to use in case of an MPLS problem (which there have been many lately, sometimes involving all of them going down at the same time). The connection into MPLS uses Inter-area OSPF with the provider. The Tunnel connection is also using IA OSPF (the main office is area 0 and this cluster of branches are all on area 100).
OSPF seems to be behaving oddly. At the main office, on the 3825 with the "backup" shut off, if I do "show ip route 10.51.0.0" it shows this output: [code]If the metric before was 24, why would it put in a route with a metric of 53 now? What's worse is that the branches all think they should connect over the MPLS and the main office sends everything over the VPN. It works, but I don't really want asymetric routing! I have included some configs as well... those which I consider relevant. I am including a diagram that has more on it than is relevant, but what I referenced is here (and yes, spanning-tree has been properly configured on the red fiber connections with the connection between FEC2960 and Hl2960 blocking, but try to ignore the LAN stuff because this is in a transitional phase right now anyway).
I want to connect my clients from the Windows WS to a VPN Tunnel using 3925 router w/o Cisco VPN client. Is there the way to use native IPSec client on Windows XP or Windows 7?
View 1 Replies View RelatedI need to install an ATM module in a 3925 router. I would like to know if this card is that I have to buy with the transceiver(SFP)?
Will use a fiber cable LC LC singlemode fiber optic.
Module: NM-1A-OC3-POM
Transceiver :SFP-OC3-IR1
Monitoring H.323? I've got a 3925 running15.1(3)T with 9 PRI's. Because of our volume, syslogging is not the desired solution. We want something that we can potentially graph over an 8 hour period, so while the RTMT is accurate, either it won't store the data for 8 hours, or we aren't using it correctly (plus, mgmt may want access to the stats/graphs, and we're not keen on granting them access). So far, we've used: [code] None of these seem to accurately portray utilization. cdsp Active Channels seems to get the closest, so perhaps I have to tweak it a little bit, but so far, nothing accurate.
View 3 Replies View RelatedI have a network architecture like the one HERE but with alot more spokes (32). Would my cisco 3925 be able to support so many crypto maps?
View 2 Replies View RelatedRecently fitted 2 3925 routers on a WAN Mulitlink (2 * 2Mb) which has been working reasonably well but have noticed CRC's and intremitteny up/downs on E1 links. This could be due to issues with Microwave links but on checking nothing stands out on these - no errors or traps form radios.
Anyway taing a closer look at E1 lines and had some questions:-
Microwave radios E1 circuits are set to UNFRAMED, router interfaces set to NO-CRC4, didnt think this was the same?
E1 card are VWIC3-2MFT-T1/E1 and also noticed the following:-
no network-clock-participate wic 0(same for 1 and 2), my card are in slot 0 and 1.
I see no slips etc on E1 controllers .
I was wondering if the NM-1HSSI is supported on the cisco 3925. documentation seems to include only till 3800 series but can't find if it's supported or is there an alternative option for 3925.
View 6 Replies View RelatedI have a new Cisco 3925 router. I have 2 network segments 10.0.1.X with net mask 255.255.255.0 and 10.0.2.x woith netmask 255.255.255.0. I have an internet gateway router at 10.0.1.21. I have set GBethernet 0/0 to 10.0.1.1 / 255.255.255.0 and GBethernet 0/1 to 10.0.2.1 / 255.255.255.0. I have set a static route 0.0.0.0 / 0.0.0.0 to 10.0.1.21 for gateway of last resort.
When I setup a workstation on the 10.0.2.X segment at 10.0.2.100 wirh a gateway of 10.0.2.1, I can ping 10.0.2.1 and 10.0.1.1 but can not ping anything else on the 10.0.1.X network or on the internet. When I am connected to the console port on the router I can ping 10.0.1.1 and 10.0.2.1 and 10.0.1.21 and any address in the internet but I can not ping 10.0.2.100.
When I am on a network connected to the 10.0.1.x network af 10.0.1.100 I can ping 10.0.1.1 and 10.0.2.1 and 10.0.1.21 and anywhere on the internet but can not ping 10.0.2.100 or any other address on the 10.0.2.x network other than 10.0.2.1. What Do I need to do on the 3925 to get to all address on each segment and to get to the 10.0.1.21 gateway from the 10.0.2.x addresses?
I am using a Cisco 3925 router and attempting to install an EHWIC card with no luck. The card I am trying to install is EHWIC-D-8ESG.
I have powered down the router, inserted the card into the proper slot and my router doesn't seem to recognize the new card. Is there a command I need to enter to enable the card?
What the maximum concurrent users you can have on a Cisco 3925 for :-
1) Site to Site VPN using IPSEC tunnels
2) GRE tunnel sIf I have 90 users on a single GRE tunnel with 50mb Internet pipe using fat clients will this work ?
To have GRE tunnel support in a Cisco3925 do I need any specific license (DATA, SEC, etc) or it is include in the UNIVERSAL IOS?
View 1 Replies View RelatedI have a new 3925 router and it came with 1 VWIC3-4MFT-T1/E1 card installed. I added a 2nd one and although it shows up in inventory, the interfaces do not show up in configuration in any form, interface or controllers. I used to just install a card and it would be recognized, is that no longer supported and is it platform specific or IOS specific?
View 3 Replies View RelatedI'm looking to utilize one of my 3925's to create a LAN-LAN IPsec VPN tunnel with another site.
I was under the impression that I needed to get a securityk9 license installed and then I would be good to go. I got a temporary 60 day trial license and successfully installed it, but none of the commands that I need to create the tunnel are showing up for me.
I'm trying to use the "crypto isakmp" command, but that is not showing up: Router(config)#crypto ? ca Certification authority key Long term key operations pki Public Key components
Here's my show license:
Index 2 Feature: securityk9
Period left: 633 weeks 4 days
Period Used: 0 minute 0 second
License Type: Evaluation
License State: Active, Not in Use, EULA accepted
License Count: Non-Counted
License Priority: Low
How many numbers of GRE Tunnels are supported on Cisco 3925 router?
View 2 Replies View RelatedI just receive a new Cisco 3925 with a etherswitch module 24 port :
SM-ES3G-24-P,I successfully boot the switch module and gain access to it.
I found some documentation on CCO but I don't sorted out this small information :,
Switch#sh cdp neig Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone, D - Remote, C - CVTA, M - Two-port Mac Relay
Device ID Local Intrfce Holdtme Capability Platform Port IDRouter Gig 0/26 143 R S I CISCO3925 Gig 2/0Switch#
The Router is connected to the switch module via a HIMI :
The Cisco enhanced EtherSwitch service modules also provide a physical Gigabit Ethernet serializer/deserializer integrated circuit transceiver (HIMI) interface. In the Cisco 2900 series and Cisco 3900 series routers, the HIMI link on the Cisco enhanced EtherSwitch service modules is connected to the router internal Gigabit Ethernet backplane. This link is used for interconnection between other interface cards or network modules attached to the router Gigabit Ethernet backplane bypassing the router host CPU; thus, increasing CPU performance by decreasing CPU processing.
If I do a sh ip int brief on the switch, I have 26 interface but only 24 are physicaly present on the front.The type of the 0/25 and 0/26 are the same : media type is 1000BaseXThe interface gi 0/26 is up up but the 0/25 is down down.