Cisco WAN :: How To Allow Ftp Connections From External Users Through 2951

Dec 14, 2011

I have a new Cisco 2951 router and I am trying to configure it for external users to connect to an internal ftp server. I created a firewall and added rules so as to allow ftp connections from the outside to the internal ftp server. I configured NAT so as to allow incoming connections through the router. I have been unsuccessful so far in trying to make this ftp connection work.I am using a zone-based firewall and for the particular ftp rule, the action is inspect so as to allow stateful inspection of packets.

View 3 Replies


ADVERTISEMENT

Cisco WAN :: Will Multiple WAN Connections Increase Total Bandwidth On 2951

Jul 27, 2011

Is it possible to increase bandwidth througput on 2951 router if you have 3 WAN connections from different ISP, lets say 12Mbps + 24Mbps + 8Mbps, so will I get 44Mbps internet connection in total?Also, on 887G router, if I use DSL 12Mbps broadband, can I use 3G internet connection constantly, not for backup only. And will I get the total bandwidth output as a sum of two connections?

View 5 Replies View Related

Cisco Firewall :: 8.2.4 External Users Will Be Intermittently Dropped

Jan 14, 2012

We just upgraded from 8.2.4 to 8.2.5.20 on each firewall. The Primary and Secondary work when they are standalone but, when we connect the fail over link from the Primary to the Secondary, invariably, one of them will go into a constant boot cycle and one will be active but, external users will be intermittently dropped. As soon as we unplug the fail over, the firewall that stays up behaves normally. This is with 8.2.5.20 code or any other code for that matter?

View 2 Replies View Related

Linksys Cable / DSL :: X3000 - External Internet Users

May 13, 2013

I have web server setting behind the Linksys ADSL modem, I set the DMZ IP to my web server IP so the external internet users can access my web pages.

This setup was working fine until I switched to “Linksys X3000” modem, external internet user can no more access my web pages.I had set the DMZ IP correctly in the new modem. The local LAN users can access the pages without any problem.

View 3 Replies View Related

Cisco Switching / Routing :: RVS4000 - Internal Users Not Accessing An External Web

Nov 13, 2012

we recently upgraded from an RVS4000 router which didn't have this issue.

the problem; Internal users from Site A cannot access the external owa address.From Site A i can successfully ping both the external/internal IP addresses/names and they resolve correctly, including pinging the address ('mail.company.com") resolves correctly to the external ip address.

[code]...

View 1 Replies View Related

Cisco Firewall :: 5505 - Users Unable To Access External Email Servers ASA?

Nov 28, 2011

I have a issue that i am at a loss as how to solve it. I have an ASA 5505 as my firewall. I have users from other companies who visit from time to time and are unable to use their outlook email to send messages. They can however receive messages without a problem. I also have a situation where users who use windows live to access gmail are unable to send messages.
 
I have narrowed it down to the fact that these uses are using  ssl/tls to send the mails. I did some research and found out about the inspect esmtp setting in the ASA.  I have disabled it and i still have to problem. I have also removed all outbound deny statements and still no luck.
 
Of note is that i can send emails without attachments. They take a long time to go out ( from minutes to hours) but eventually they do. Emails with attachments of even 10k do not go at all.
 
I was running image 8.2.3 and i downgraded to 8.0.5...still did not work...i upgraded to 8.4.3...still did not work. I am now back at 8.2.3.
 
My Firewall config is attached. I am at my wits end as to what else to try. The company has not renewed support for the device so i am on my own here!

View 2 Replies View Related

Cisco Routers :: RV220W Max DHCP Users (Max Connections) Per Vlan

Nov 19, 2011

We assign (reserve by MAC actually) static IPs to all of our devices.  Over time we have gotten rid of some devices but haven't begun (or finished really) re-using the old IPs.  On our WRVS4400N v2 routers we are able to set the max number of DHCP users per Vlan.  This prevents unauthorized devices trying to connect to our LAN.For example.  I set the range from 192.168.1.100 - 192.168.1.103.  IPs 100, 101, and 103 are in use (reserved via MAC address).  We set max number of DHCP users to 3.  This prevents someone from gaining access to 192.168.1.102.  Does this make sense?  Or at least this was the initial goal and it tested out successfully back when we implemented it.
 
How can I do the same for with the RV220W?  I can set the range, assign static IPs (reserve IPs by MAC address), but can't keep others from gaining accessing to our LAN via the unused IPs (not assigned a static IP).My initial thought was to create static IPs (for the unused IPs) using dummy MAC addresses.  I'm sure there is a much better way of accomplishing what I am trying to do.

View 3 Replies View Related

D-Link DIR-655 :: Refusing Local Connections - No External IP Address

Aug 22, 2011

I couldn't find a section for the 651.

Alright so I have an SSH server running on my network. I can successfully connect to it from a local computer using the server's internal IP address, AND I can connect to it from a remote computer using the server's external IP address (it's properly port forwarded).

However, when I try to connect to the server from a local computer using it's external IP address, I get a connection refused error. Is there something I'm missing?

View 7 Replies View Related

Cisco Firewall :: 6500 Separate Internal Server / HQ Network From 3 / 4 Different External Connections

May 21, 2012

I am using a 6500 with FWSM. I need to separate an internal server/HQ network from 3 or 4 different external connections. The external networks do not necessarily need to be isolated from each other.I have the option of using a 3 layer model: L2 Access layer to SVIs on the Distribution layer and then L3 to the 6500.L2 Access, connecting directly to the 6500s, with the SVIs on the FWSM.Is it better to have the FWSM outside the MSFC or Inside? Am i correct in thinking that "inside" vs "outside" is determined by whether the SVI's are configured on the FWSM or the MSFC? is there any performance impact from having the FWSM doing the routing instead of the MSFC.If the vlans are all configured on the FWSM, what is the 6500 doing, other than providing switch ports?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Authenticate VPN Users Via ACS 5.4 And AD Via External Identity Store

Feb 22, 2013

I have installed ACS 5.4 and we are looking to authenticate our Anyconnect users with ACS via Active Directory. I think I have the correct commands in our ASA ( we had ACS 4 and authenticated our anyconnect users ).
 
I also have configured ACS to use Active Directory  and installed the server side cert in ACS. I'm just uncertain how to program ACS to use the security group that I have setup in Active Directory.

View 6 Replies View Related

Cisco WAN :: 2951 For BGP At AS Edge?

Mar 6, 2012

our customer has a server farm in a data center.At the moment the farm has connectivity with only one ISP but sometimes it has service discontinuity.Customer wants to become AS and having two ISP connectivity for backup purposes.He needs to evaluete two  cisco routers to use at AS edge with BGP.At the moment he says that the throughputh with the server farm is max 15Mbps and in the future he thinks that it will not increase.We think about cisco2951 routers with 2GB ram.Is cisco 2951 adeguate for this task ?

View 3 Replies View Related

Cisco WAN :: 2951 Can't See SM-D-ES3-48-P Module

Jan 25, 2011

I have the situation with my new Cisco 2951 router. It has only one module on board - SM-D-ES3-48-P. I don't know what is wrong but I can't see any information about this module. When I connect my laptop to any port it's become green, but it's still green even after I disconnect PC from this port. Sh ip int brief command shows only built-in gigabit interfaces. I also connect my second PC to the router by console to monitor any changes when I connect or disconnect laptop to the module's ports. [code]

View 3 Replies View Related

Cisco VPN :: To Have IPsec On 2951

Mar 22, 2011

I'm setting up IPsec for a DMVPN between a 2811 and 2951s in a test lab.  I have enabled IPsec on the hub (2811) but I am unable to do so on either of the 2951s.  After researching, it seems that I may have the incorrect IOS for this, but I am at a loss which IOS I should be using. Currently the 2951s are on "c2951-universalk9-mz.SPA.151-2.T2.bin".

View 1 Replies View Related

Cisco WAN :: Sub-rate DS3 Configuration On 2951 Using NM-T3 / E3

Aug 15, 2012

We have an old 3725 router with a HSSI card connected to a DL3100, which in turn is connected to a subrate DS3 circuit. The plan is to replace the router with a new 2951 router and a NM-T3/E3 card.After the router was replaced, I configured the NM but the circuit remained dow/down. I'm sure it has to do with the fact that the DS3 circuit is channelized but I'm not sure how to configure this module to be channalized. Here is the configuration that I placed on the router: [code]

View 4 Replies View Related

Cisco WAN :: 2951 With IOS 15.0 No Voice Command

May 30, 2011

We recently purchased the Cisco Router 2951 router with the IOS 15.0. I have tried to put in my VIC2-4FXO card in it. When I did show invetery, it detected the card.[code] When I tried to configure the voice port by typing voice port, it shows % Invalid input detected at '^' marker. I have tried to reset the cad and replace with another one.

View 3 Replies View Related

Cisco VPN :: IPsec On 2951 Required

Jan 10, 2010

setting up IPsec for a DMVPN between a 2811 and 2951s in a test lab.  I have enabled IPsec on the hub (2811) but I am unable to do so on either of the 2951s.  After researching, it seems that I may have the incorrect IOS for this, but I am at a loss which IOS I should be using. Currently the 2951s are on "c2951-universalk9-mz.SPA.151-2.T2.bin" and the only crypto options.

View 9 Replies View Related

Cisco Firewall :: How To Integrate ASA With 2951

Nov 6, 2011

I recently installed a 2951 with a security plus license..I hate it (security featuers not router) and would like to put the asa back in place.how to integrate the asa with the 2951, I believe I need to run it in multi context mode.

View 3 Replies View Related

Cisco VPN :: 2951 / VPN Tunnel Dropping?

Jan 7, 2013

We have approx. 40 branch offices that connect to our core IOS Firewall (2951) over ipsec VPN Tunnel. One particular site has been facing issues over the past few days. This site will sporadically drop it's VPN Tunnel and reestablish after a few seconds.  If I run debug crypto ipsec and crypto isakmp on the site that is dropping, it is constantly going through the DPD process. If I run these same commands on another site, they seem to run DPD at all.
 
Here is some of the output I am seeing on the site that is failing.
 
Jan  8 11:18:38.873 AST: %FW-6-DROP_PKT: Dropping tcp session 111.222.3.106:50083 96.16.47.144:80  due to  Stray Segment with ip ident 54856 tcpflags 0x5004 seq.no 2154004347 ack 0
Jan  8 11:18:46.061 AST: ISAKMP (4028): received packet from 111.222.255.106 dport 500 sport 500 Global (I) QM_IDLE     
Jan  8 11:18:46.061 AST: ISAKMP: set new node -1497488895 to QM_IDLE     
Jan  8 11:18:46.061 AST: ISAKMP:(4028): processing HASH payload. message ID = 2797478401
Jan  8 11:18:46.061 AST: ISAKMP:(4028): processing SA payload. message ID = 2797478401

[code]....

View 2 Replies View Related

Cisco Wireless :: 2951 - LAN Controller On SRE?

Jun 27, 2011

How to get a WLC on a SRE up and running. I have a WLC installed and running on a 2951 SRE connected to a L3 switch in a lab.
 
I've tried to follow the Cisco document:
 
[URL]...
 
My wireless clients could only receive a DHCP allocated IP address for the 55.XX subnets defined on the wireless lan controller and SRE (shown on page 12 of the pdf). All traffic seemed to be routed via the native vlan of the inside router trunk interface and all DHCP requests arriving at my DHCP server were from 55.XX.  Because of this I didn't see the point of trunking

so I've changed it to a point to point routed connection, created a 55.XX DHCP scope on my DHCP server for the wireless clients and all routing works fine.I found the document rather misleading.

View 1 Replies View Related

Cisco WAN :: Configuring Interfaces On 2951 Router?

Dec 27, 2011

configuring my Cisco 2951 router. There are three routed interfaces that I need to configure: one for the internal LAN, the second for another private subnet that connects to a Data Centre and the third for the WAN connection. I have configured the Ge0/0 interface as the LAN interface with the internal network 10.17.0.0/24. I have also configured my WAN interface Ge0/1 for internet connectivity. Now, I need to configure the third interface Ge0/2 that will connect to the Data Centre. This will be a private point to point switched ethernet link. The Data Centre will host a secondary domain controlller. So, I want it to be on the same network as the internal LAN, i.e., 10.17.0.0/24. I want to be able to see all other devices that will be located at the Data Centre just like I would see all devices connected to the internal LAN.The problem I am facing is that Cisco 2951 does not allow me to configure two routed interfaces to be on the same subnet. Is there any way to work around this problem and configure both the internal LAN and the Data Centre private network to be on the same subnet.

View 6 Replies View Related

Cisco WAN :: Recommended Router Platform As 2951

Oct 17, 2012

I currently have a 50Mbps Internet Connection provided by an ethernet handoff for hosting some webservers. We are looking at adding an additional 10Mbps Internetn connection and route BGP between the two.  For the 50Mbps connection, i'm using a Cisco 2951 router.  I also have another 2951 router to terminate the 10Mbps connection.  Does these router have enough horsepower to fully route BGP?

View 1 Replies View Related

Cisco WAN :: VWIC2-2MFT-T1/E1 Work With 2951?

Jul 19, 2012

I'm just double checking here because I saw one doc that didn't mention the 2900 on the data sheet but, I ve seen the 2900 listed with on others. I don't see the 2900s listed in this with the interface.
 
[URL]

View 6 Replies View Related

Cisco WAN :: Tunnel Interfaces On 2951 Router

Apr 11, 2011

We have just installed our first 2951 router, and were suprised to see in our Netflow collector that Tunnel interfaces appeared even though we did not configure any, I have seen other posts talking about PIM tunnel when using Multicast, but we dont use multicast and the tunnel is GRE questions are, where do these interfaces come from? how do they pick up an IP address? can we shut them down? IOS is 150-1.M4 loopback interface ip address is 172.16.224.238 ( tunnel source) see output from sh int  below
 
Tunnel0 is up, line protocol is up  Hardware is Tunnel  Interface is unnumbered. Using address of Tunnel1 (172.16.0.1)  MTU 17912 bytes, BW 100 Kbit/sec, DLY 50000 usec,     reliability 255/255, txload 99/255, rxload 1/255  Encapsulation TUNNEL, loopback not

[Code]......

View 6 Replies View Related

Cisco WAN :: Connection On Multiple IP Addresses - 2951

Feb 9, 2012

configuring my Cisco 2951 router with Z0ne-based firewall. This is the scenario I would like to configure.
 
I have two ftp servers,S1 and S2, behind the router which needs to be accessed by two groups of users, G1 and G2, from the outside, i.e., from the internet.
 
I have two public IP addresses, 152.12.164.203 and 152.12.164.204. The WAN interface of the router is configured with IP address 152.12.164.203. G1 needs to access S1 on 152.12.164.203 and G2 needs to access S2 on 152.12.164.204.
 
What are the steps in configuring the router if I need the above scenario to be implemented?

View 5 Replies View Related

Cisco WAN :: Slow Speed Over Comcast 50 Mb Using 2951

Apr 11, 2012

We have 50 Mb Comcast cable conencted to 2951.  There is another conenction to AT&T 20 Mb circuit which goes thru' an ASA 5510.  Path to Internet is as below. [code]
 
As long as Comcast is up, 2951 sends Internet traffic out to Comcast and uses AT&T via ASA for backup.When traffic goes over Comcast, users complain about slow speed out to Internet.  If we force traffic to AT&T via ASA, speed issue goes away.
 
We don't see any issue on 2951 router in terms of CPU or memory util.WHat can cause slow speed despite the fact that router resources are not maxed out and Comcast circuit has 150% more capacity than AT&T?

View 8 Replies View Related

Cisco WAN :: Route Map On 2951 Router Not Working?

Jun 29, 2012

One of the route maps doesnt want to work, all the other are fine -   

route-map vlan23-out permit 40
match ip address 123
set ip next-hop 87.194.168.1
           
If it take the ip policy off interface gi0/0.123 the client can access the internet OK but over the wrong ISP?As soon as i add the policy all internet stops

View 3 Replies View Related

Cisco :: 2951 / EEM - Netflow Detector Using Application Name

Jan 2, 2013

I'm attempting to set up a detector that fires when an application is seen. I've set up the flow monitor
 
2951-HQ#sho flow monitor AppWatch cache
Cache type:                               Normal
Cache size:                                 4096

[code]....
 
I'm runnig c2951-universalk9-mz.SPA.152-3.T2.bin

View 3 Replies View Related

Cisco WAN :: 2951 Working As MPLS Router

Nov 28, 2012

Can Cisco2951 work as an MPLS router. If yes what will be needed to make it function as an MPLS router? Else which alternative router can function as an MPLS router.

View 1 Replies View Related

Cisco Firewall :: 2951 - Cannot FTP To Server From Outside Network

Feb 5, 2012

I have a Cisco 2951 Router on which I configured routes for Zone-Based Firewall. I have a FTP server inside my network and I have allowed hosts from the internet to connect to it through the router. They, are however not able to connect or they are connecting but they cannot transfer files. I checked the logs on the router and the error message is as follows:
 
%FW-6-DROP_PKT: Dropping tcp session xx.xx.xx.xx:21 xx.xx.xx.xx:21766 on zone-pair ccp-zp-out-in class FTPInbound due to  Invalid Seq# with ip ident 0

View 7 Replies View Related

Cisco WAN :: 2951 Picking Right Router For Load?

Jul 25, 2011

I have talked to two Cisco Reps via our distributor and explained our network to them both and asked for suggested equipment. Our infrastructure has 4 circuits coming into the data center from our remote sites. Two of the circuits are cat5 and two are DS3. I want to use two routers to support two circuits each (cat5 and DS3). Each circuit is around 30Mb servicing around 13 locations with T1 connections, 55 locations in total. They suggested at a minimum the cisco 2951 model because we are utilizing one NM-1T3/E3 module in each router, and suggested getting the cisco 3925 model to cover future growth. I asked for a data sheet that has suggested models of routers for the bandwidth of the incoming pipes. The technicians said they would email this information over but twice now I have not received it and cannot find this information anywhere online. We currently have a cisco 2851 utilizing one NM-1T3/E3 module and they purchased a cisco 2911 to replace this unit.

View 2 Replies View Related

Cisco WAN :: Possible To Use Gigabit Ethernet On 2951 ISR For MPLS Connection?

Dec 15, 2011

Purchased and configured 2951 router based on Telco specs that required T3/DS3 card with coax connection for MPLS.   When telco showed up to install DS3 they handed me a UTP copper connection....  Can I use one of the Gigabit ethernet connections on the 2951 as my MPLS interface into the provider's cloud?

View 2 Replies View Related

Cisco VPN :: ASA5510 To 2951 - Phase 2 Failures With 10.x Subnets

Apr 25, 2013

I have a site to site ipsec tunnel setup between an ASA5510 and a 2951 Router. The ASA 5510 is on a 10.x subnet with a few vlans behind it. There are also 7 other ASA5505 that connect to this box with ipsec.
 
The 2951 is on a 10.x subnet with multiple vlans behind it (10.x and 192.x subnets).
 
When I had ACL to allow traffic from 10.20.0.0 (ASA) to 192.168.111.0 (2951 - voice vlan) the connection comes online and is stable.
 
The minute I add any of the following, the connection drops off with Phase 2 errors: 10.20.0.0 to 10.1.200.0 10.20.1.0 to 10.1.1.0
 
I can add a second 10.20.0.0 to 192.168.10.0 with no problem at all. The issue only seems to occur when attempting to add traffic from 10 to 10 on the tunnel.

View 2 Replies View Related

Cisco WAN :: 2951 / 1841 - Backup Setup With 2 Routers And BGP?

Aug 20, 2012

I am looking to setup a solution for backing up a Metro Ethernet connection on a 2951 using an 1841 and 2 T1's in a Multilink. The Metro E will be primary, and if the BGP peer goes down, I want it to switchover to the 1841. Can it be done and is there an example of the BGP setup to work off of?

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved