Cisco WAN :: Assign MAC ACL To Layer 2 Interface On 887VA Router?
Mar 24, 2013I wish to assign a MAC ACL to a layer 2 interface on an 887VA router but cannot seem to see how to do this.
View 2 RepliesI wish to assign a MAC ACL to a layer 2 interface on an 887VA router but cannot seem to see how to do this.
View 2 RepliesI have a cisco 878 router and I can’t assign ip address to it’s fast Ethernet interface. When I assign ip address give me this message: “you can not assign ip address to layer 2 interface”.
But I can not understand why give me this alert when I use a layer3 device?!
i have set up a layer 2 tunnel on my 887va router and the traffic transmits accross this to my second 887va. unfortunately, I do not seem able to get the layer 2 traffic from my host PC and down the tunnel.
I believe the problem to be the router settings for the fastethernet aqnd forwarding this data out of the dialer port.
Here is my config:
Building configuration...
Current configuration : 3973 bytes
!
! Last configuration change at 13:03:15 UTC Thu May 2 2013
[Code].....
I have cisco router 887VA.Question is when i connect that WAN port ( eth0) with any switch or laptop/pc i do not see the port in up state. What can be the reason.I have done "no shutdown " on interface level and there is no configuration on interface except the IP address , but it show " up down "state even the port is connected to some device. ( Is the port is faulty or some other reason).As per my concept it should show up state when we connect to some device ( Like router / switch / laptop).
View 6 Replies View RelatedJust got hold of my first 887va for my home, never configured a vdsl interface before and was just wondering if my setup looked good to someone whos done it a few times.
View 6 Replies View RelatedI have a question regarding mlppp and bonding mpls T1 circuits. For the longest time we have been able to get by on one T1 circuit coming into our 3845 router. Well this T1 has now become congested and they are wanting to add bandwidth to this T1. We connect to the phone company via an MPLS T1 currently. So now it appears as though we are going to purchase another MPLS T1 circuit and bond the two T1's together. The way our network is currently set up, we utilize the same AS number on all of our remote routers regardless of location. Keep in mind I don't have any sort of mlppp set up at this moment, so unfortunately I can't post any configs. I'm just questioning the design portion and how to go about doing this.
Here is where my dilemma begins........
For every MPLS circuit we order on the remote end, we specifiy an IP for the remote router itself and one for the provider to assign to their equipment (the bgp neighbor statements). Now granted i'm no BGP extraordinaire, not even a novice really, but I don't understand how I am going to bring two T1 circuits into the same router (basically with 2 pairs of IP's). In order to bond the two T1's together, i'll need to create a multilink interface and assign an IP to that, but yet I still have 2 SETS of ip addresses. And if that isn't enough of a dilemma, I also need to spedify a neighbor statement in order for my AS to bind to the adjacent provider AS, but yet I have two IP addresses for that as well.
I have ASA 5505 with base license. I created 3rd vlan on it.it was created. but i am unable to assign IP to it. i assign ip address it takes it. But when i do sh int ip brief it does not show any ip.
Code...
How do i tell my firewall to start listen also on another outside ipadress assigned by my ISP? I have it used on other firewall right now. So my steps would be shutting down ip address assignment off old firewall interface. Assign that ip address to ASA5510 outside interface and configure NAT.
View 13 Replies View RelatedI need to configure a Cisco 2911. I need to give an interface in this module (VWIC3 - 4MFT-T1/E1) an IP address. My question is, how to assign an IP to an interface in this module.
My purpose is to get connectivity via T1 line to another router.
With most of my Layer2/Layer3 switches, I'm accustom to giving them a SVI on my management VLAN, and calling it a day. I can't find in the Cisco Nexus guides how to do something similar; everything points to the mgmt0 physical interface, which seems like I need to uplink it to an access port on another switch. Can somebody point me in the right direction for how to do give the Nexus an IP that I can ssh/snmp into it across a trunk for management? I must just be missing the keyword.. NX-OS is still quite a different beast.I see in the manual it says: "SSH has the following prerequisites: You have configured IP on a Layer 3 interface, out-of-band on the mgmt 0 interface or inband on an Ethernet interface." Cisco Nexus 5000 Series Switch CLI Software Configuration Guide page 284, How do I configure an IP on a Layer 3 interface on a Nexus?
View 16 Replies View RelatedWhy layer 2 switches need its mac address, even it does not have any interface ? (does not have stp and etc)
View 8 Replies View RelatedI am trying to harden my Nexus box and I am not able to ACL assigment command. Following are the commands I am trying to add.
interface cmp-mgmt module 5
Ip access-group NETWORK_MANAGEMENT_ACCESS in
I am trying to assign static ip address on vlan 1 interface , the model no of switch is SG300 & the firmware version is 1.1.2.0 .But whenever I type the IP address & press enter , a question is popped up asking for confirmation (switch0d851f(config-if)#ip address 1.1.1.1 255.0.0.0.
Please ensure that the port through which the device is managed has the proper settings and is a member of the new management interface.Would you like to apply this new configuration? (Y/N)[N] N )
Is it possible to configure more than one layer 3 interface for netflow on a 3845? I can't seem to do it. Is there something I am missing?
View 2 Replies View RelatedCisco 3750 with IP Service Image 12.2.55, Trying to enable Web Authentication on Layer 3 interface:
!
ip auth-proxy name bp_auth_proxy http inactivity-time 60
!
interface GigabitEthernet1/0/5
no switchport
ip address 192.168.1.27 255.255.255.0
ip access-group 101 in
I am tasked with configuring a 2504 wireless controller. Is it possible to assign an SSID to an interface that has dynamic ap management enabled?
Scenario:
Location1:
1) 10.0.0.0/24
2)192.168.0.0/24 DMZ
Location 2:
1) 10.0.5.0
Both locations are routable using network 1 at each location. However, I need to configure several access points and send them to location 2. These access points will communicate with the controller at location 1 on network 1. Two SSIDs will need to be on network 1 at location 1. The other SSID will be on Network 2 at location 1. This network is not routable.
Is it possible to establish a interface dialer on a layar 3 switch?Or is it only interface for routers?I have a c3750 switch (WS-C3750G-24T), and when i try to establish a dialer interface i get an error message:
[code]...
How do i get the 12.4 code to assign a dhcp address to my ethernet interface from my server? I deleted the default config on the 1141 and searching has not turned up anything useful.
View 1 Replies View Relateddifference of CISCO887VA-K9 and CISCO887VA-SEC-K9.I thought it because of the Advanced Security and Advanced IP Licenses, but it isn't, I've got the -SEC- Version now just with the Advanced Security license. So I asking myself why I bought the more expensive CISCO887VA-SEC-K9 if I have to buy the additional Advanced IP Services licenses extra..
View 14 Replies View Relatedhow to configure vlan tag on routed layer 3 interface in cisco 3945 device?
View 2 Replies View RelatedHow to set the management interface on a SG300 Switch in Layer 3 mode? I've some vlans configured on the switch with interfaces in each of them:
Vlan 100 (10.0.1.254 /24)
Vlan 200 (10.0.2.254 /24)
Vlan 300 (10.0.3.254 /24)
...
Vlan 900 (10.0.9.254 /24)
Now, the management interface is listening on all interfaces (IPs). But I would like to configure the switch to only listen on 10.0.9.254. What I need to configure or whether it is possible?
I am setting up a link between buildings that uses wireless links. I'm using Layer 3 routed ports on 2 3560 switches to handle the routing between sites. Normally I would just put these in a /30 and then the switches handle the rest. However, the wireless access points have a web interface for managing them that I want to be able to access, but it's only available on the single NIC that also carries traffic. What would be the best way of making this work? Should I make the link a /29 and give the access points an IP in the same range? If this is the case what do I use for the default gateway for the access points?
I have included a diagram to try to explain the issue clearer. The IP addresses in black are what I would do if this were a standard cable (and indeed this will work, but I wont be able to access the admin interface of the wireless AP) and the red ip addresses are the alternative if I use a /29 (but as I said, I'm not sure what to use for the default gateways).
I understand the vlans on the catalyst side of the house on 2900 to 6500 Catalyst switches.
This 7010 running nx-os 5.1(3) I did not setup, but have to manage it. Hasn't really been a proble till now.
My nexus 7010 has a Layer 2 only vlan 11. It is "Active" but the interface is "shutdown". Yet, it is passing traffic across the directly connected ports on the nexus 7010 and to other switches in my network. Vlan 11 is being set out via VTP to all my switches and things are running fine.
I need to create another L2 only Vlan. I can't seem to find any docs that indicate that a Layer2 vlan Interface on nx-os should be in "shutdown" mode as part of the setup. I do see in the docs where it has to be set "Active" as part of the process.
Is this the correct way to seutp a L2 only vlan on nex-os? Leave the interface in "shutdown" but make it "Active"?
Mystery Vlan 4 and 6
The mystery deepens. I have other L2 vlans ,Vlan4&6 that are NOT defined as "Interface Vlan4" in the nexus config, yet it is applied to GigE ports on the nexus and these Vlans 4/6is also being sent out VTP to all switches. Even weirder is that these vlans have names associated with the numbers. These are valid Vlans that were configured on the old 6509 before the Nexus was installed.
I have checked all switches, NONE are running in Server mode for VTP, all are in CLIENT. The nexus 7010 is the only device running in VTP Server mode.
I want to setup VLAN with the switches SG300 and SLM2024. What is the suggestion to connect these 2 switches. We have the Juniper net screen.
View 1 Replies View RelatedI have a question if I Stack a Catalyst 3750 L3 with a Catalyst just L2, will we able to use all L3 capabilities?
Switches are
WS-C3750G-24TS-E1U
WS-C3750V2-24PS-S
Is there a GUI that can be used to setup the 887 router. I need to setup a VPN.
View 1 Replies View Relateddoes a router Cisco 887 va k9 support EIGRP and IPsec ?
View 2 Replies View RelatedI have been trying to connect a new Cisco 887VA Router to the Internet using ADSL via PPPoE and have been unsuccessful. The DSL line is active and functioning correctly since the current "old" router is connected and working without any problems (the "old" DLink router is connected to an Alcatel DSL Modem). AT&T provides the ADSL service to the office. When the Cisco Router is connected it tries to negotiate a connection via PPPoE on the WAN interface but utlimately fails. The IP for the WAN interface is dynamic.
Below is the current configuration of the router.
!
! Last configuration change at 00:43:54 UTC Sun Jun 26 2011
!
version 15.1
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
[code]....
I'm having some problems getting an ipsec tunnel established between a cisco 887VA router and a cisco srp527w router.I am working from a few text books and some example materials. I have worked through many combinations of what I have got and am still struggling a little bit.I look at debug results and it appears as though the policies do not match between the devices:
Jul 23 05:44:37.759: ISAKMP (0): received packet from XXX.XXX.XXX.XXX dport 500 sport 500 Global (R) MM_NO_STATE
broute1#
Jul 23 05:44:57.079: ISAKMP:(0):purging SA., sa=85247558, delme=85247558
broute1#
Jul 23 05:45:17.031: ISAKMP (0): received packet from XXX.XXX.XXX.XXX dport 500 sport 500 Global (N) NEW SA
[code]....
Some specific questions:
1) on the SRP in the example's I have used (and I have a few SRP->SRP VPN's that work) I see you need to enter the preshared key, I'm not seeing in the examples I have used anything about the IKE preshared key on the IOS box. Any examples where you use the preshared key for IKE? I wonder if this is my primary issue as it states clearly in the log that there is no Preshared key :|
2) I have used a mish mash of names between the various sections as on the SRP the naming convention isnt the same; ie: which parts of the IPSEC negotiation come from the IKE policy section and which from the IPSEC policy section. Do the names really matter across different ends of the VPN?
3) I notice when I perform this command in the(config-crypto-map)#:
set peer FQDN
It is converted to:
set peer XXX.XXX.XXX.XXX
Is this expected? I want the device to look at the FQDN as this particular host is using DDNS and not use a static IP address.
I've got problem trying to connect the CISCO-887VDSL/ADSL OVER POTS ROUTER to internet. Only got the LAN part working.I'm trying to setup PPPoE with dynamic IP Followed CISCO's documentations but the commands used were not recognized by the router.
here's my config.
!
! Last configuration change at 08:31:51 UTC Sat Feb 11 2012
version 15.1
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
[code]....
We have a remote site connected to ADSL line with a Cisco 887VA router attached. This has been working fine for the last couple of months. However, recently, the site have started to complain of performance issues (network slow, applications disconnecting, etc)Looking on the router, we can see evidence of packet loss/timeouts from a simple ping to the internet e.g. [code]
However, we have logged the fault with our service provider and they return all line tests as clear but what is particularly strange is that they also report “and the SNR Margins are well within threshold levels (Upstream 11.5 and Downstream 15.0)” which, unless I’m misunderstanding something, seems to be completely different from what the router itself is reporting.Is there a reason why the service provider’s stats for Noise Margin would appear to be so different from what the router is reporting?
Is it possible to assign a single ssid to multiple interface groups by assigning the ssid to multiple AP groups?
I have buildings geographically dispersed that are configured with multiple vlans in interface groups so that I can maintain an addressing scheme of dhcp assigned addresses per building. Each building is also further grouped as AP groups. I'd like to know if by assigning the same wlan ssid to each of the AP groups, will I maintain addressing integrity for each building? I'm thinking it will work.
Do the buildings have to be outside AP range of each other to avoid problems?
5508 controller
7.2.110.0 code
6 buildings
6 interface groups
1 ssid
I am taking an introduction class to CCNA and we are focusing on the Application Layer,and I'm having some difficulty in understanding what is an Application Layer Service. Is the Application Layer Service the same as Application Layer Software?
View 3 Replies View Related