Cisco WAN :: Securing SRDF Between Two 7204 Routers

Jan 3, 2011

We have a leased line from one office to a DR site which we use to back up our data. We are using Cisco 7204 and and OC3 circuit. The data is sent in blocks (SRDF) and we are sending changes only. However, we are getting requests from compliance to further secure this connection since it is a leased line. I guess I need to know how secure SRDF traffic is and then if required, how to secure it.

Can we create a simple VPN between the two routers without having to use a VPN concentrator or Firewall? If so, what IOS would be required? How much impact will the VPN have on current bandwidth?

View 3 Replies


ADVERTISEMENT

Cisco WAN :: What Status Is Of 7204 VXR And 7206 VXR Routers

May 22, 2011

I would like to find out what the status is of the Cisco 7204 VXR and 7206 VXR routers?I understand they are EOLife and EOSale.Are they also EOSupport? we planning to upgrade 3 of them in our environment and management requires feedback around this.We thinking of going the ASR1000 route..

View 15 Replies View Related

Cisco WAN :: 2811 / Securing Ports In Nat?

Mar 22, 2012

I have a site that is connected to the internet via T1 into 2811 runing C2800NM-ADVENTERPRISEK9-M), Version 12.4(11)X.  I have noticed that when i do a port scan on the outside nat pool i see well know ports in the closed state .ie...7,21,22,23,25,99,100,80,443.   These pools for end users to access internet.   Does this pose a security risk? What can i change to provide end user access to web but not let these well know ports open?

View 6 Replies View Related

Securing The Wireless Network With A Filter

Dec 7, 2011

In my building there are 2 wireless access points connected directly via switch into the router.So the problem is i dont want to set a password for the wireless but i want to be able to filter all computers that are connected wireless to my internet because many of them are mass-downloading torrents movies etc. and it slows the internet massively. What do i need to do to make it like a filter , which would be like a ISA server or something.

View 9 Replies View Related

Cisco Security :: 1023 / Securing And Restricting Access To A FTP?

Nov 6, 2012

I have an ASA firewall and I have never configured an FTP server for a large scale network (well large in my opinion). I want to ensure we have the highest level of security available for the FTP and to limit only the specific users designated by an ACL. Would SFTP be the best available option for security measures? Should I only use Passive FTP and what range of ports above 1023 should I open for only 1 or 2 FTP clients at a time? Also if I use Passive mode do I need to use protocol inspection for FTP?Also, Currently I'm unsure of what files need to be accessed on our network but should the SFTP Server always only be installed within the DMZ?

View 4 Replies View Related

Cisco :: AP1200 Securing Open Wireless Environment

Apr 26, 2011

Need securing a wireless environment in a hotel?  The SSID has to be broadcast of course but how can we protect guests from man in the middle attacks, etc.?  Currently the environment is all AP1200s with no hardware upgrades in the near future.  There is also a 2811 router in place but nothing else.  We would love to be able to force users to authenticate with a password in order to get out to the Internet as well.

View 2 Replies View Related

Securing Jacks On Small Biz LAN From Visiting Laptops?

Jun 29, 2012

Besides MAC address filtering, is there another good / easier way to keep visiting laptops etc from plugging in a CAT cable and accessing a LAN protected by a perimeter firewall?

View 3 Replies View Related

Cisco Switching/Routing :: 2800 - Securing Router From Outside Access

Aug 19, 2012

I have 2800 series router which is directly connected to ISP. How can secure the router from outside access; I am totally new to the security concepts.        

View 2 Replies View Related

Cisco Switching/Routing :: ASA 5510 Securing Inbound Traffic On VPN Using ACL

Nov 1, 2012

I have a VPN on my ASA 5510 between (A)192.168.255.0/24 and (B)172.20.2.0./24. The purpose of the tunnel is to send kerberos tickets from our domian controller on the A side, across to a server at B, and receive a respose. I want to lock down inbound traffic to the A network, but not sure of best method.
 
I initially tried using an ACL filtering on ports, but soon realised the incoming traffic uses a wide range of ports so this is not really possible.Seeing as the A side will always be initiating the conversation, I was wondering if I could use the 'established' option on the inbound ACL for the ASA at A side, so that it would block any flows that are not initiated by the A side.

View 3 Replies View Related

HP OfficeJet 6500 Wireless Printer Stopped Working After Securing Network?

Nov 29, 2011

I have run three computers on my wireless network for a few years now, and have an HP OfficeJet 6500 Wireless printer that has worked seamlessly on all computers. That is, until I secured my router. I had an open wireless connection that I changed to secure (WPA) a couple of weeks ago and have been unable to connect to my printer wirelessly to print. It will print if connected to USB. The first day I was able to enter in my WPA key just fine, but not since. It doesn't appear to be finding my connection. Oddly enough one of our computers (a laptop) is able to print to this printer so I am not sure. All computers are running Windows XP, I believe with SP3. I use a D-link wireless router. I have tried using the HP solutions to no avail and have checked in the documentation that came with the printer.As an aside, I now appear to also have another wireless connection which is a "computer-to-computer" connection, I believe an ad-hoc connection?

View 3 Replies View Related

Cisco WAN :: 7204 VXR With NPE-G1 CPU Maxing Out?

May 23, 2011

I have a cisco 7204 vxr that terminates a 300 meg ethernet circuit asn well as an mpls DS-3.  CPU increases along with utilization of the ethernet circuit.  When the utilization gets to around 150 Mbps on the receive, the cpu is maxed out at 100%.  I am wondering if the router can support the amount of traffic coming through it.  The majority of the traffic is voip using g729 codec, so packet size is small.  We are no where close to peak utilization and cpu is at 39%.   Here is what I see currently:
 
#sh verCisco IOS Software, 7200 Software (C7200-ADVIPSERVICESK9-M), Version 12.4(15)T4, RELEASE SOFTWARE (fc2)Technical Support: [URL] 1986-2008 by Cisco Systems, Inc.Compiled Thu 13-Mar-08 10:40 by prod_rel_team
 ROM: System Bootstrap, Version 12.3(4r)T3, RELEASE SOFTWARE (fc1)BOOTLDR: 7200 Software (C7200-KBOOT-M), Version 12.3(15), RELEASE SOFTWARE (fc3)
 uptime is 3 years, 1 week, 3 days, 6 hours, 40 minutesSystem returned to ROM by Reload CommandSystem restarted at 08:26:49 UTC Wed May 14 2008System image file is "disk2:c7200-advipservicesk9-mz.124-15.T4.bin"
 
This product contains cryptographic features and is subject to UnitedStates and local country laws governing import, export, transfer anduse. Delivery of Cisco cryptographic products does not implythird-party authority to import, export, distribute or use encryption.Importers, exporters, distributors and users are responsible forcompliance with U.S. and local country laws. By using this product youagree to comply with applicable laws and regulations. If you are unableto comply with U.S. and local laws, return this product immediately.

[code].....

View 5 Replies View Related

Cisco WAN :: Fastethernet Module For 7204 VXR?

Dec 19, 2011

We have a cisco 7204 VXR and would like to know the module which has two fastethernet  port. We tried a PA-2FEISL-TX but it did not work.

View 1 Replies View Related

Cisco WAN :: How To Configure 7204 For Internet

Mar 6, 2012

Today we got a new cisco 7204 with NPE-G2 , so we wanna to configure to root for the internet so here is my scenerio
 
1- Public Ip address =155.155.155.20
 
2 Private Ip Address =192.168.2.0 /24
 
3- Gateway = 155.155.155.1
 
4-DNS Server = 194.155.12.133
 
Interfaces:
 
1- Gigabite 0/1  - We put this for Public ip address
 
2- Gigabite 0/2 - and this for Private Ip address
 
how to route this for the internet . after routed we want our client computers to get internet from Gigabite 0/2 Interface

View 8 Replies View Related

Cisco WAN :: 7204 VXR Load Time?

May 20, 2012

is 633+ seconds (approximately 10 minutes) load time normal for a Cisco 7204 router? I find that it takes forever for the router to do :Self decompressing the image". I tried the latest IOS and tried different bootloaders but it doesnt seem improve it?

View 2 Replies View Related

Cisco WAN :: 7204 VXR - GRE Tunnel Max Bandwidth

Feb 28, 2010

We have point to point metro ether net link terminating on 7204VXR router.On this point to point link we are configuring GRE over ip sec. Problem is when the traffic exceeding 8mbps we started getting packet drops. from the Cisco documentation it seems the tunnel bandwidth is by default 8mbps and there is parameter like Inherit/receive but those actually not change the tunnel interface bandwidth.If we just give tunnel bandwidth with bandwidth mentioned it allows me to give option of 100mbps but again the tunnel interface bandwidth remains 8mbpos only and probably that 100mbps is useful only for routing decisions.
 
i am using advance security 12.4.15T12 image. Whether this is a limitation or any other way to go beyond 8mbps for the tunnel interface (7204VXR-NPEG1 processor)

View 18 Replies View Related

Cisco WAN :: Router 7204 Rebooted Unexpectedly?

May 8, 2011

One of our Routers 7204 rebooted unexpectedly. I try to access Output interpreter but is not working. The output from our router is the following:
 
 WAN-ROUTER#sh version
 Cisco IOS Software, 7200 Software (C7200-ADVIPSERVICESK9-M), Version 12.4(15)T2, RELEASE SOFTWARE (fc7)

[Code].....

View 7 Replies View Related

Cisco WAN :: 7204 - Routing Subnet To 2 Different Gateways

Nov 8, 2011

I need to route a subnet from a 7204 to 2 different gateway's which are not Cisco based. I cannot use HSRP, GLBP or VRRP as the other 2 gateways don't support theses protocols. Yet they do support OSPF, RIP, and BGP....  Take note that this setup is in a ISP scenario.  How can I acheive gateway redundancy?

View 4 Replies View Related

Cisco WAN :: Configure BGP On 7204 Router With EIGRP

Jan 18, 2012

I need to configure BGP on our 7204 and 2811 router.  The 7204 is our main router and currently running EIGRP internally.  Our remote locations just moved to an MPLS connectivity and they have a 2811 router.  I will need to configure BGP for the routing protocol. I have the AS number and the remote AS number. Attached is the the current configuration of the two routers.

View 4 Replies View Related

Cisco WAN :: 7204 - Edge Router Choice

Dec 22, 2011

We are replacing a DS3 Internet connection with a 100 Mbps fastE connection from a Tier 1 Provider.  I currently have a Cisco 7204VXR with 512 Mb DRAM and 128 Mb of Flash and two 10/100 ports that is connected to the DS3.  I also have a 3845 with 1 Gb of DRAM and 256 Mb of Flash with two 10/100/1000 ports available.
 
We are currently running BGP, below is the summary
 
BGP table version is 88880414, main routing table version 88880414
379041 network entries using 44347797 bytes of memory
379043 path entries using 19710236 bytes of memory(code)

View 4 Replies View Related

Cisco Switching/Routing :: 7204 Locks Up After Every 6 Months

Nov 28, 2007

I can't seem to find out what this means. Every 6 months or so, my 7204 locks up. I can't even get to it via the console port and I must reboot to access it. I noticed this alarm in my logs.( ASSERT CRITICAL PO1/0 Threshold Cross Alarm - B3) I've looked on-line but can't pinpoint it's meaning. Looks like a flapping interface but might be something else.

View 6 Replies View Related

Cisco WAN :: Output Drops And Input Errors On 7204 With NPE 300

May 11, 2011

My router, a Cisco 7204 with NPE 300, is experiencing output drops and input errors on a fastethernet interface. I have a 100Mbps connection with less than 15Mbps utilization at peak times.
 
FastEthernet1/0 is up, line protocol is up  Hardware is DEC21140, address is 0014.a985.1a1c (bia 0014.a985.1a1c)  Internet address is 38.102.66.134/30  MTU 1500 bytes, BW 100000 Kbit, DLY 100 usec,     reliability 255/255, txload 3/255, rxload 1/255 

[Code]....

View 17 Replies View Related

Cisco WAN :: Reasonable Replacement For 7204 VXR That Meets Requirements

Aug 25, 2012

I was planning to buy 7204 VXR for my site's router for the following requirements:
 
- support for ATM, Serial, ISDN
- support for 3 10/100/1000 ethernet interface
- support for 2 WAN interface
 
However, I realized that the 7200 series will not be available for sale after September of this year!! Any "reasonable" replacement for 7204 VXR that meets the above requirements?

View 5 Replies View Related

Cisco :: 7204 VXR - IP Flow Not Showing Egress Traffic

Dec 6, 2011

I have a 7204VXR Router, with Neflow. The collection for all interfaces is ok, but one interface (Gigabitethernet 1/0), is not showing the egress traffic in the pictures. The configuration has "ip route-cache flow", ip flow egress, and ip flow ingress set. But, is not showing the egress traffic.

View 4 Replies View Related

Cisco WAN :: 7204 VXR - Valid Image On Boot Flash

Oct 24, 2012

I have a Cisco 7204 vxr router that does not have a valid image on the boot flash or on the pcmcia card (disk 2).  I tried everything i could to try and get the router to recognize the flash but it keeps giving me a magic card error.  I'm losing my mind slowly but surely. 

The router boots into Rommon every time and the Rommon options for this router are horrible.  No tftpdnld option.  Can I get this router to boot from tftp, from Rommon?

View 1 Replies View Related

Cisco Firewall :: 7204 VXR - ZBFW Passing SCTP

Feb 16, 2012

I have a 7204VXR NPE-400 running c7200-adventerprisek9-mz.124-24.T3.bin at the moment. This device is being used as a firewall between zones in a service provider network.

My issue is we have a lab device on the corporate side that needs to talk SCTP to the core device. Since there is no option to match SCTP in ACLs or protocol matching, I can't really get this to pass properly. What is the new IOS versions support SCTP? Any options to pass this traffic through the firewall?

View 7 Replies View Related

Cisco WAN :: 7204 - Small Packet Size And Full BGP Table

Feb 7, 2012

I'm looking for a Cisco device to run a full BGP table with a 60Mb link. And one of the main restrictions is that my traffic is almost 100% real-time (voip). So the average packet size is small. Today we own a Cisco 7204 NPE400 with 512Mb RAM. I think even though I upgrade it to a G2, due to the small average packet size, the router will be near to its limit. Maybe a Cisco 7300 NSE-150? Or should I think about a switch?

View 3 Replies View Related

Cisco WAN :: 7204 / Moving T1 Branch Office To Metro Ethernet?

Jan 31, 2012

I am preparing to move two branch offices from a point to point T1 connection to Century Link Metro Ethernet.Currently my branch locations connect to my HQ 7204 router via a channelized DS3. I have a 4507R at HQ that I will connect the ME circuit to.We will also be moving our Internet connection on the ME circuit.Our service provider Clink will hand me a single Ethernet handoff for the Internet and branch office connections. For the first phase I will connect one branch office using ME. Once that is in place and tested we will move another office and so on. Then our final step is to move our web connection to the ME circuit.Each branch office has their own unique voice and data subnet. They each have a 2801 router and a 3560 switch. The routers are MGCP gateways with only one PSTN connection, a POTs 911 line on a FXO port.
 
So my questions are;

1 - Should I connect the ME directly in to the 3560 at the branch offices or use the Fa0/1 on the 2801? Fa0/0 is currently connected to the 3560.
 
2 - On my 4507R at HQ how will I configure the ME switch port? As a dot1q trunk port?
 
3 - Given that ME is basically a LAN connection will I have to re IP the branch office? HQ is 10.10.1.x/24. Branch is 10.10.166.x/24 (data) 192.168.166.x/24 (voice).
 
4 - On the 4507R will I need to configure a vlan interface for each branch subnet?
  
I attached two network diagrams. One represents our current topology (MEexisting) and the second represents the new ME circuit changes (MEprojected).

View 5 Replies View Related

Cisco AAA/Identity/Nac :: 7204 - Radius Auth For Login And VPN Conflicts

May 15, 2011

Im trying to configure a 7204 for radius login authentication, although the router is also configured with radius for VPN access. How can I configure it for both using 2 different raidus servers? the login via radius is working fine on another router, although that one is not doing VPN access so there's no conflict.
 
My config:
 
aaa group server radius RADIUS_AUTH      server x.x.3.11 auth-port 1645 acct-port 1646
aaa authentication login networkaccess group radius local

[Code]....

For some reason, this does not work. I cannot access the router and authenticate via x.x.3.11 radius server. I think there's a conflict between the VPN and the login authentication but im unsure how to resolve this.

View 3 Replies View Related

Cisco WAN :: Setup 7204 Router To Use RADIUS For Authentication Via AAA Commands

Jan 9, 2011

I was attempting to setup our 7204 Cisco router to use RADIUS for authentication via the AAA commands. I must have messed up when configuring it as it comes up via TELNET asking for a username and password but doesn't take my AD credentials. How might I login to this router to fix the config? Do I need to do a password recover process?
 
One note, I didn't save the running-config to startup-config, so if I restart the router will it load the startup-config, thus overwriting the running-config that wasn't working?

View 2 Replies View Related

Cisco Switching/Routing :: 7204 VXR Newly Installed Router Got Reloaded

May 5, 2012

One of my newly installed  router got reloaded ,showing me below error . The same IOS im using in another router and it works fine without any issue ,but this newly installed router gave me this problem. [code]
 
cisco 7204VXR (NPE-G1) processor (revision B) with 983040K/65536K bytes of memory.

View 5 Replies View Related

Cisco WAN :: 1841 Securing E1 Back-to-back Connections

Aug 28, 2012

securing a back-toback connection using E1.The connection is between two cities, using 2x CISCO 1841 router + VWIC-1MFT-E1 interface at each city.
 
The E1 connections has been provided by our local telco, and they are completely private. The customer is a bank, and they asking me if this is a secure connection or not. If possible, we need to guarantee that no body can get access to the bank network even if they brought E1 modem at one of the ends (telco PoP).

View 11 Replies View Related

Cisco Wireless :: 5508WLC Whitelist For Guest Access And Securing Guest-access?

Aug 18, 2011

Is it possible to allow certain websites to bypass the web authentication pages, so that they do not need to authenticate to get to our own website, but do have to if they wish to go anywhere else?Looking at a 5508 model at the moment

View 4 Replies View Related

Cisco Routers :: RVS4000 - Multiple Internet Connections / Routers Sharing Printers?

Sep 11, 2011

I have 2 internet connections in my office one via Verizon Fios and another  one via the local cable company. On the fios connection I have an RV042 VPN  router and on the Cable company connection I have an rvs4000 router, I would  like to know if there is a way I can connect the 2 so I can share a printer I  have on one of the 2 networks from the other network without using the VPN  feature, like via an ethernet cable connected between the 2 and some kind of  static route maybe?

View 6 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved