Cisco WAN :: 867VAE Web-based Configuration?
Nov 8, 2012
i am planning to buy 867vae router and i would like to ask you a few things the configuration is through cli only(because i am not familiar with cli) or it can be web based ? the basic configuration for dsl and routing are preconfigured or i have to do everything from scratchf? if someome has configured let say a draytek router, is it the same with this router or its a different world?
View 9 Replies
ADVERTISEMENT
Mar 14, 2013
we installed two weeks ago a 867VAE-K9 as a border router for a medical practice.It's got two vlan interfaces for inter-vlan routing, only one Gi interface up in trunk mode to the core switch and the ATM for ADSL2+ connection to the local ISP. A cisco wap is on the secon vlan for the patients. There is a voip pbx on a linux machine that registers 5 trunks to an external provider (only one trunk is used right now, and it works fine).(Almost) everything works fine :-) Sometimes (it can be hours or days) the routing to the internet stops. The meds can still use the LAN accessing everything in it with no lag, and the patients can access the isolated SSID on a Cisco wap on the second vlan. They simply cannot surf the internet.
- DNS and local routing is fine
- the router is reachable through the Gi interface
- they can send and receive traffic to and from the 867 vlans' IPs
- the ATM, dialer 0 and virtual access are up, line protocol up
- the dialer has got the IP address negotiated from the ISP
- default route is negotiated through ipcp
- the controller vdsl 0 is in showtime! state
- from the outside we can ping the PPP peer, but not the IP of dialer 0
The only thing is the queue counter of ATM which shows drops and total output drops. Attenuation is fine, noise margin not so well. The point is that outside traffic to the internet is at low levels and the routing almost always stopped when no one was using the internet (i.e. out of office hours). It already happened 7 times in 16 days. The problem obviously is that voice traffic is impaired by the stuck router, and no med there is able to ssh into the router and re-activate the atm 0 with a shut/no shut.
It is not necessary to reload. A fast shut/no shut of the atm0 (no wait between the commands) will make it running again.We're activating the smarnet for this router to update dsl fw and ios image, but I thought I could post here before that.[code] As a brutal workaround till the update/fix, I was thinking about monitoring the reachability of some external systems and use snmp from the lan to shutdown/no shutdown the atm (though I don't even know if that would be possible from snmp on this router).
View 1 Replies
View Related
Jul 18, 2011
I need to configure Policy Based Routing. There are two WAN Links from two Different ISP : Campus NW has one CORE switch - Cisco Catalyst 6506. [code]
View 3 Replies
View Related
Dec 12, 2012
I have a 867VAE-K9. On feature navigator it is listed as supporting OSPF. However when I go into config mode and type "router ?" BGP is there, but OSPF is not. Also, under my tunnel interfaces there is no support for any OSPF commands such as "ip ospf cost" etc. I'm in the process of raising a TAC. I have tried five or six different versions of IOS code that is available for this device, in each, we never see OSPF listed but sometimes see "router odr" or "router lisp"...
View 5 Replies
View Related
Jun 26, 2012
I have to install a wireless mesh network shortly using Cisco 1552 APs. This will be controller based using 5508 controllers. The controllers currently have some 1262 APs configured in a mesh and bridging configuration so happy that it all basically works. My question is - what is the "config mesh range' command doing on the controller ( or setting the Range(RootAP to MeshAP) setting on the controller mesh GUI. The default setting is 12000feet and I have left it at default at present. Just interested in what this is used for - I assume it alters the mesh protocol parameters somehow ( or the RF parameters perhaps ) as it suggests in the guide that mesh APs will reboot following this command being changed.
View 4 Replies
View Related
Apr 16, 2013
i have problem connecting Cisco 867VAE this is my config and my diagnostic file ( IOS version ==> c860vae-ipbasek9-mz.151-4.M4.bin )
diag file :
sBelfort#sh atm int atm0
Interface ATM0:
AAL enabled: AAL5,, Maximum VCs: 2, Current VCCs: 0
VCIs per VPI: 1024,
Max. Datagram Size: 2096
PLIM Type: ADSL - 4608Kbps Upstream, DMT, TX clocking: LINE
[code].....
View 6 Replies
View Related
Feb 3, 2013
I currently have an 867vae router and a 1131ag ap setup with 2 vlans and 2 ssid's. I am in the process of baby proofing the house and would like to use the cisco plsk400 homeplug system to relocate my wap. I use 2 networks to seperate and filter the kids internet traffic from my own. It also allows me to shut the kids vlan when they shouldnt be on the internet.
As far as i can tell the plsk400 homeplug doesnt support 802.1q.... so is there any way i can keep the seperate networks/SSID's and the abilty to filter and turn off one of them at will without a trunked link to the router?
View 2 Replies
View Related
Oct 17, 2010
I recently bought and installed a WAP4410N access point (using PoE) and it's running stable. I was able to access the web-based configuration by using the IP address of the AP (something like 192.168.0.184, coming from the DHCP of my router). However, I'm unable to access the web-based configuration using the host name of the device (mentioned next to the device name in the basic setup section of the web-based configuration). I changed the host name several times, but I can't connect to the device using the host name. Accessing the device by its IP address works, but I have to check the logging of my router to find out which IP address I have to use. Is there a way to access the device using the host name?
(I think my WAP4410N has firmware version 2.0.2.1 installed)
View 3 Replies
View Related
Nov 30, 2011
is it possible to create some Configuration Template that pushes configurations only to switches or interfaces with a certain actual existing configuration element- e.g. a certain interface description?
Example:Template Parameter Mask asks User for an Interface Description- the User enters e.g. "A101" Second Parameter asks User for an access vlan to deploy to this interfaces- e.g. " 10"
So during deployment LMS make a "switchport access vlan 10" only on interfaces that contain the description "A101".
I know this is possible via Compliance Check/Deploy, but we want to make this more User friendly and flexible so that e.g. a Helpdesk Member can use this Template to easily change the VLAN based on a interface description (which refers in this case to a CAT5 outlet label).
View 1 Replies
View Related
Feb 12, 2012
I was unable to configure vlan-based qos on Cisco IOS Software, s72033_rp Software (s72033_rp-IPSERVICESK9-M), Version 12.2(33)SXH6, RELEASE SOFTWARE (fc1) Seems to me my configuration is not working. Here is the output of the interface:
sh int G1/6 | i rate
Queueing strategy: fifo
30 second input rate 25231000 bits/sec, 4282 packets/sec
30 second output rate 46940000 bits/sec, 9257 packets/sec
And here is my configuration:
interface Vlan3
ip address 192.168.1.1 255.255.252.0
service-policy input TEST_IN_PMAP
service-policy output TEST_OUT_PMAP
[code]....
Why I can't see matches in ACLs? I've double checked the direction and seems to me it is correct. I can't see matches even I configure something like this:
10 permit ip host 192.168.1.168 any
20 permit ip any host 192.168.1.168
Why my output rate is higher than 30M? Is it bacause there is no matching traffic here in ACLs? I'm absolutely shure that this host with such ip connected to this interface:
#sh arp | i 192.168.1.168
Internet 192.168.1.168 0 feed.beef.f00d ARPA Vlan3
#sh mac address-table | i feed.beef.f00d
* 3 feed.beef.f00d dynamic Yes 0 Gi1/6
View 9 Replies
View Related
Apr 9, 2012
I have Verizon FIOS internet/wireless router and then a WRT310N wireless router connected to it thru Ethernet cable. I want to disable DHCP in the Linksys, but when I try to access the set up page at address 192.168.1.1 the Verizon router set up page shows up. I've tried to connect the router directly to the computer, but it needs the internet connection from the Verizon router. How do I get to the set up of the Linksys at the same time the Verizon is using the same address?
View 5 Replies
View Related
Mar 4, 2012
I've one Cisco 3750G-12S with ip routing enable, the swtich is with IP Service firmware, with PRR support.Currently set my default static route 0.0.0.0 0.0.0.0 10.1.18.71 to my Firewall A Currently all of the VLAN for will be routed to 10.1.18.71
I've created a new VLAN 2 for my 10.1.2.0/24 network with the VLAN interface 2 ip address 10.1.2.10, my intention is to route 10.1.2.0/24 traffic to my 10.1.2.1 by creating the access list and route-map.
I've configure my test pc with a static ip and my gateway pointing to 10.1.2.10 (VLAN 2 gateway) , i'm not able to route to 10.1.2.1.
View 7 Replies
View Related
May 16, 2011
I have two 1811's connected in a lab using a ipsec vpn tunnel (using a switch to simulate an internet connection between them).I am trying to configure one of the routers as a ZBPF just to allow a remote windows login (DC on the firewalled side, workstations on the other side).I'm trying to verify that the zbpf is working, but it doesn't seem to stop anything. I had match icmp added to the class-map, but took it out to test if icmp would fail. It didn't. Basically, I don't think the firewall is working at all. Any thoughts on how I can configure this so that the policies will work between zone-pairs?
Here's an quick drawing:
Here are the configurations:
Local router:
hostname sdc-1811-LocalLab
!
boot-start-marker
boot-end-marker
!
no aaa new-model
!
resource policy
[code]....
View 11 Replies
View Related
Jan 18, 2012
How do I...add a dos based computer to a network running windows 2003
View 1 Replies
View Related
Jul 17, 2012
I am position to migrate from CatOS 6509 switch to native IOS 6509 switch. long time ago, there was some site to convert automatically based on copy and paste onto the tool, but i can not find.
Does anybody know how to convert CatOS configuration to Native IOS configuration ? It is not IOS change, but it is configuration convert.
View 1 Replies
View Related
Feb 28, 2011
Is it possible to log when a user connects/disconnects their VPN session? They are connecting to an asa 5510.
View 5 Replies
View Related
Sep 19, 2010
I have been configuring anyconnect VPN. The requirement from customer is to configure MAC address based authentication for anyconnect clients. I have gone through various cisco documents. I couldnot find this option explained. Is MAC address based authentication possible in anyconnect vpn without having AAA server in place?There is an option to select end point attribute as MAC address, while creating Dynamic access policies. But at the host scan configuration of Cisco secure desktop, there are no options for performing MAC retrieval.
My ASA is running on version 8.2(1) and ASDM version 6.3(1) and a memory of 512 MB RAM. Any way for MAC based authentication in cisco anyconnect VPN.
View 3 Replies
View Related
Sep 20, 2011
I am having a problem trying to get to my root view. I am trying to set up some views to allow restricted access to one of our routers.I am running C2800NM-ADVIPSERVICESK9-M Version 12.4(20)T as the IOS and have the following AAA entries in my config
View 1 Replies
View Related
Feb 27, 2011
How can I configure police-based nat to allow ICMP-only traffic on asaos 8.4.1 or 8.3?On 8.3 it was very simple:global (outside) 1 interface ,access-list outside_nat_outbound extended permit icmp any any,nat (outside) 1 access-list outside_nat_outbound.
View 10 Replies
View Related
Jun 23, 2011
We are testing the use of a web based tn3270 emulator through our ASA5510 SSL VPN appliance. We have it configured to use clientless SSL VPN. Access to the 3270 session works internally, however when we connect to the SSL session, the session does not load. Each application that we are testing uses activex components that are downloaded to each connecting client. Are there settings that need to be addressed to allow for the downloading of ActiveX components. Also, one of the 3270 applications uses java instead of ActiveX and this app is having the same problem. working with web base tn3270 emulators functioning over ASA SSL VPNs?
View 1 Replies
View Related
Dec 21, 2009
It has been know to all of us that ASA is the great device for creating SSL VPN web portals and the ability to publish several plugins. My interest is about IOS based SSL VPN. Is there anyway to publish RDP plugin into the portal built with 1841 router?
View 1 Replies
View Related
Apr 14, 2011
what web-based programs do i need to install a 887VA? I tried Cisco CP express version 2.1, not a supported device.
View 2 Replies
View Related
Mar 28, 2012
I want to apply QoS policy on a particular VM for specified port range only. I have created following script file but that doesnt work. I mean it doesnt apply any policy on vm residing on Veth1.
config t
ip access-list acl_in
101 deny tcp any any eq 443
exit
[Code].....
View 1 Replies
View Related
Aug 8, 2009
I'm having an issue with a Linksys RVS4000 which doesn't appear to be behaving as I think it should.I need to forward a port (Single Port Forwarding) through to an internal NAT host. However, I only want that host/port to be accessible from one host on the internet, for security reasons.
I have created the port forwarding entry and this works fine. I then created two rules in IP Based ACL - one to block all access to that port from the WAN interface and one to allow access from a single host.
However, it appears that when a port forwarding entry is added, it will completely bypass the ACL and allow all traffic for that port/host by default.Is this the correct behaviour?
Firmware version is v1.2.11
View 12 Replies
View Related
Dec 14, 2012
I have webcams that need port 8081 opened and I did that, everything worked fine until my DIR655 jammed up and power cycling it and the modem 3-4 times DID not make it work: no internet access and it was definitely a DIR655 problem. So, out with the paperclip to do the big reset, causing me to lose my configuration. When "most" of it came back up with my new config (I had screen prints), all was okay EXCEPT the webcams. Addresses and ports were all configured properly, address was fixed too on the client computer rather than use DHCP. I had a DNS relocation service running (DYNDNS) for the WAN side, but that address (My IP) didn't change either. I tried EVERYTHING. Finally, I realized in all my screwing around that I had enabled UPnP in my application, something I hadn't done before, but did this time as a desperation move. UPnP had always been checked off in the router. So.....I REMOVED my port forwarding and virtual server settings (either one worked before), and voila, everything working, Is this a normal occurrence, that if you have UPnP running, that this auto configuration overrides any manual configuration?
View 2 Replies
View Related
Sep 24, 2011
is it possible to use the asa dhcp server function to assign based on mac address (yet)? I have read numerous places that it was not possible (as of 8.2) at least, but I am workin in 8.4. I should have mentioned that I've already tried commands (asa 5510 btw)
View 4 Replies
View Related
Sep 18, 2012
I'm having a few problems at the moment with a zone based firewall setup. The more I looked into the problems the more I question whether I need the ZBF or not.My network is pretty simple. 1 Internet connection and 1 LAN interface and a few site to site vpns to the router.So what do people think to having this kind of set up and not using a ZBF?
View 11 Replies
View Related
Apr 30, 2012
I am configuring a new ACS 5.3 system. Part of the rules is that I want to match the users specific AD group membership, and match appropriatly to an identity group.What i'm trying to do is say that if the user is a member of the AD Group (G-CRP-SEC-ENG) then associate them with the Identity Group SEC-ENG. The under the access service, authorization portion, i assign shell profiles and command sets based on Identity Group.It seems that the ACS server will not match the AD Group for the user, and it will match the Default of teh Group Mapping portion of the policy every time.
I tried several configuration choices from : AD1:ExternalGroups contains any <string showing in AD>, AD1:memberOf <group>.Is there something special i need to do in the Group Mapping Policy to get it to match and active directory group and result in assigning the host to an Identity Group?
View 7 Replies
View Related
Mar 29, 2012
I have a Cisco 2851 (with a 4 port switch module) that I am trying to set up with two different internet connections, and have it route traffic out to them based on the source IP. One connection is a 50mb Comcast connection, another is our T1 that our servers are hosted on. The goal is to guide server/phone system traffic to the T1 and have the rest default to the Comcast. I currently have the 2851 connected to our Layer 3 switch (Dell Powerconnect 6224) with a subnet created between them. Static routes have been created on the 2851 back to all of our existing subnets. Traffic flows internally without a problem between the subnets and 2851 (and vice versa). I set up the 2851 with route-map's in the NAT to control the flow of traffic, with the default route set to the Comcast connection. Default route works great, speedtest shows full speeds and everything looks great. The problem happens when I apply my route-map policy to the internal LAN interface with the ACL list of IP's that I want to guide to the T1 (with a next-hop of the T1's IP address). I tested some tracert's and pings from one of the IP's in this list and they would stop at the T1 modem and not go any further. I did a "show ip nat translations" and noticed that the "outside" portion (right half) was blank for every IP that was in the ACL or related to the T1. So my guess is it looks like this is not doing NAT for the T1? I double-checked that I had my "ip nat inside" on the LAN interface and "ip nat ouside" on the T1 VLAN interface and Comcast interface and they were there.
View 6 Replies
View Related
Mar 18, 2013
I have setup a basic PBR config to route Http and Https out of a different interface (fa0/0/0) but for some reason http traffic is still going out of the Gi0/1 interface.
Config attached minus the crypto stuff and the publics have been changed.
View 17 Replies
View Related
Jan 15, 2013
Is Cisco 3945 router support URL based filtering . For example to block website [URL] but not the main site [URL].
View 1 Replies
View Related
Aug 21, 2012
Last night I had a crack at setting up PBR on my companies Cisco 1811.Joy, I thought, it's actually working. Alas I was wrong, the addresses were getting translated to our ADSLs external ip address but routed over our EFM.What I want to acheive is to send all HTTP(s) traffic from our workstations over the ADSL (FastEthernet1) whilst all other traffic and VPN goes out over our Bonded ADSL (FastEthernet0). There is also a minor failover in place for traffic routed to the ADSL in the route-map PBR_VLAN1. The servers are on IPs 200, 202, 204 and 240.
Anyway, I have re-written the configuration and xxx'd and x.a/b/c'd all the IP addresses I want to keep secret. Need to make sure that the PBR is correct, and will do what I want it to? I have a very small time-frame to get this correct and I dont want to fudge the bucket so to speak.
View 8 Replies
View Related
Feb 10, 2011
I currently have a asa 5500. is there a way to authenticate based on mac address throught the vpn client. We are haveing problems with useres using there home computers to connect. Yes they are smart enought to install the client and copy the profile.
View 1 Replies
View Related