Cisco WAN :: Setup NAT On 2811?

Mar 19, 2012

i have a branch router that connects to mpls WAN.  Also has a second interface that is used for dmvpn failover in case WAN goes down.We want to use this second interface also as the primary internet circuit for the branch.  I changed the default route to the next hop address on the other side of the second interface and expected this to work.But i was told i need to set up NAT for this to work, and set up an ACL for NAT to use. how to set up NAT?

View 1 Replies


Cisco :: Setup NTP Server Using 2811?

Sep 30, 2012

I've setup a NTP service by using Cisco 2811 routers. This works fine at the moment, but in the end there are some questions left.
1. I'm using two 2811 Routers, one for primary, which is resceiving the time from PUBLIC NTP 1, and one for backup, which is resceiving the time from PUBLIC NTP 2. Is it possible to compare these to times an check if the match? And if not, generate an alarm via e.g. SNMP
2. Is it possible to check via SNMP, if the routers are reaching PUBLIC NTP 1 and PUBLIC NTP 2 for sync?

View 3 Replies View Related

Cisco Security :: Setup SSL VPN On 2811?

Mar 7, 2011

I'm trying to setup a SSL VPN on a 2811. I believe I have the SSL VPN portion understood, but I can't tell because I keep getting stuck on the Certificate Server, ca trustpoint and identity trustpoint configuration.
guide that walks you through the CA cert, Cert Server, ca trustpoint and identitiy trustpoint to ios SSL VPN?

View 6 Replies View Related

Cisco Firewall :: DMZ Setup Using 2811 Router

Aug 11, 2011

I am pretty new to the configuration of a DMZ and I have the task of setting one up.I have a Cisco 2811 Router running Cisco IOS Software, 2800 Software (C2800NM-ADVENTERPRISEK9-M), Version 12.4(24)T1, RELEASE SOFTWARE (fc3), 2 FE interfaces.One FE is connected to the WAN, with a loop back interface configured with the public IP for Internet access in the office.The other FE has 2 sub interfaces configured, one for data and the other for voice traffic.Users within the office are configured to use the data VLAN to access the internet through the WAN.
Now we are setting up some new services and we require to have DMZs setup.I want to setup 3 zones now that the different servers would reside in. How can i achieve this using the existing infrastructure I have?I have an idea to create more subinterfaces and assign them to the zones, but I am still not sure how this would play out. I have been on this for the whole day and unable to make significant progress.

View 5 Replies View Related

Cisco WAN :: 2811 / 5510 - What Is Recommended Setup

Sep 10, 2012

I am lacking experience in BGP and now I am trying to figure out what should be the ideal and recommended design.

- Having two Internet Service Provider with two ASN
- Having one idenpendant IPv4 public address
- Having two Internet Cisco Router e.g. 2811
- Having two Cisco ASA Firewall e.g. 5510

View 3 Replies View Related

Cisco WAN :: 2811 / Setup Bandwidth On Border Router Or ASA Pix?

Jan 6, 2011

I got connected ASA ----- ROUTER 2811) to metroethernet switch from my ISP , with a 4MB of bandwidth but the internet connections to all my LAN has been frozen and we lost connection to the internet, to restart the internet service I need to boot the ROUTER 2811 - and ISP switch to rollback the internet operation,My ISP support tell me if is possible to set up the traffic bandwidth in one or  both borders devices,  ( ASA 5510 or ROUTER 2811)

View 3 Replies View Related

Cisco VPN :: Setup L2L IPSec VPN Between VPN3020 Concentrator And 2811?

Feb 22, 2011

I am trying to setup a L2L IPSec VPN between cisco VPN3020 concentrator and Cisco 2811 something is not working and I don't understand why.I describe my situation in detail my router has 2 interfaces

External interface Fa 0/1 ip 193.P.Q.R
Internal interface Fa 0/0 141.G.H.254 
Lan on internal interface is 141.G.H.0/24

 remote VPN concentrator has 2 interfaces
Public interface 131.A.B.C
Private interface 131.A.I.E
I have to set up L2L so that host 141.G.H.10 can talk to host 131.A.H.D whici is behind the VPN concentrator my router config:
crypto isakmp policy 3 encr 3des hash md5 authentication pre-share group 2crypto isakmp key * address 131.A.B.C!crypto ipsec transform-set presid-set esp-3des esp-md5-hmac !crypto map presid-map 5 ipsec-isakmp set peer 131.A.B.C set transform-set presid-set match address presid!interface FastEthernet0/1 ip address 193.P.Q.R duplex full speed 100 crypto map presid-map!interface FastEthernet0/0 ip address 141.G.H.254 duplex auto speed auto!       
 ip access-list extended presid permit ip host 141.G.H.10 host 131.A.H.D
 ip route 193.P.Q.S 
Then I configured VPN3020 accordingly creating a lan to lan profile with the proper IKE proposals ecc ecc when interesting traffic is matched by VPN acl (presid) I see this messages in the VPN concentrator logs:

57101 02/23/2011 15:49:05.310 SEV=4 IKE/119 RPT=4033 193.P.Q.R Group [193.P.Q.R]PHASE 1 COMPLETED 57102 02/23/2011 15:49:05.310 SEV=4 AUTH/22 RPT=3935 193.P.Q.R User [193.P.Q.R] Group [193.P.Q.R] connected, Session Type: IPSec/LAN-to-LAN 57104 02/23/2011 15:49:05.310 SEV=4 AUTH/84 RPT=11 LAN-to-LAN tunnel to headend device 193.P.Q.R connected 57110 02/23/2011 15:49:54.820 SEV=4 IKE/123 RPT=1093 193.P.Q.R Group [193.P.Q.R]IKE lost contact with remote peer, deleting connection (keepalive type: DPD) 57112 02/23/2011 15:49:54.820 SEV=5 IKE/194 RPT=3778 193.P.Q.R Group [193.P.Q.R]Sending IKE Delete With Reason message: Connectivity to Client Lost. 57114 02/23/2011 15:49:54.820 SEV=4 AUTH/23 RPT=14 193.P.Q.R User [193.P.Q.R] Group [193.P.Q.R] disconnected: duration: 0:00:49 57115 02/23/2011 15:49:54.820 SEV=4 AUTH/85 RPT=11 LAN-to-LAN tunnel to headend device 193.P.Q.R disconnected: duration: 0:00:49
and from router side I See this with show crypto isakmp sa
131.A.B.C   193.P.Q.R  CONF_XAUTH           5    0 ACTIVE
but the status got stuck in CONF_XAUTH state and then disconnects?

View 1 Replies View Related

Cisco Infrastructure :: 2811 / 1841 / WIC-1AM-V2 - Setup POTS Dial Connection Between 2 Routers?

Jun 17, 2012

I would like to set up a POTS Dial connection between 2 Cisco routers, using the modem card WIC-1AM-V2. I'd like to use this as an out-of-band connection to a remote site, if the primary internet connection fails. So, this setup will only be used in one direction, 1 router placing calls, the other one receiving calls.Here's my config of the receiving router:
chat-script dial "" ATZ AT OK "ATX3D T" ATS0=8 TIMEOUT 120 CONNECT C
interface Async0/2/0 description out of band for network no ip address encapsulation slip async mode interactive
line 0/2/0 session-timeout 5 absolute-timeout 10 script connection dial login local modem InOut transport input all escape-character BREAK autoselect ppp stopbits 1 speed 115200 flowcontrol hardware

This config is working fine, when dialing in via a Windows Hyperterminal Dial connection. After a while of dialing I get the login prompt of the router.Now I want to have a router placing calls instead of a Windows Server. I can't figure out how to tell a router to place calls to a POTS phone number.
Receiving router: 2811, WIC-1AM-V2, IOS c2800nm-ipbasek9-mz.124-25a
Calling router: 1841, WIC-1AM-V2, IOS c1841-advsecurityk9-mz.124-25a

View 5 Replies View Related

Cisco Routers :: QuickVPN Setup On RV120W Without Changing Internal Setup

Nov 8, 2011

Is there a way to set up Quick VPN on the RV120W without changing the internal subnet? I have just taken over responsibility for a network and I don't know all of the nooks and crannies yet, so I'd rather not change the internal sub net. I've tried setting up a user then changing the LAN settings afterward, but it automatically removed the VPN user when I did so.

View 1 Replies View Related

Cisco Routers :: SRP527W - Setup - Cannot Find Web Console To Setup

Jan 1, 2012

I've just purchased a couple of SRP527W routers. I've been unable to even browse to the default to start my configuration. My local network is 192.168.1.x. At risk of showing my stupidity, what am I doing wrong.

View 5 Replies View Related

Cisco VPN :: Use 2811 Instead Of PIX For VPN?

Sep 19, 2012

My setup is ISP-2811-PIX 515E-LAN. Right now, I am doing a PAT for IPSEC tunnels to terminate on the PIX. Do you recommend I use the 2811 instead of PIX for VPN or keep things the way it is? Trying to determine the best box to use.

View 4 Replies View Related

Cisco :: Which IOS For 2811

May 27, 2013

I need to know which IOS should I download for my 2811 router to get all ip sla features 
Router(config)# ip sla ?
<1-2147483>   Entry Number
Note this is from my 2951 router.
I need full features like this in my 2811 which IOS should I download.

View 3 Replies View Related

Cisco :: 2811 To Upgrade LMS 3.2 To 4.1

Feb 29, 2012

I want to upgrade LMS 3.2 to 4.1. But when I look to "Special Notes and Exceptions for Devices Supported" document ,It seems that 2811 have 2 SysID.

Why there are two IDs for the same hardware and under which ID will my 2811 routers be classified into inventory database. This information is important since customer want to have support of 2811 in CiscoView of LMS 4.1 (around 200 devices).

View 3 Replies View Related

Cisco WAN :: CoPP On 2811 ISR?

Aug 23, 2012

Looking to implement CoPP in our 2811 ISR. We currently have the base 256mb of DRAM in there. Will this bring our router to its knees? I've priced a RAM upgrade.

View 0 Replies View Related

Cisco WAN :: Configuring BGP With 2811

Nov 2, 2011

I have BGP router 2811. Want to configure BGP on it with two ISPs. How can i configure it?

View 1 Replies View Related

Cisco WAN :: 2811 - Configuration Of Router And BGP

Nov 8, 2011

I want to configure BGP but i am finding it very difficult to know BGP as I am new to this concept.
What is theoretical and practical approach to configure bgp??
I have to configure my office router 2811 for two ISPs which will be acting as fail-over.
I have to start it from scratch.

View 5 Replies View Related

Cisco VPN :: 2811 / VPN Connects But Can't See Network

Feb 14, 2013

I have a 2811 that I can remotely VPN to using Cisco VPN client however I cannot see the internal admin network ( 
Current configuration : 4845 bytes
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption


View 2 Replies View Related

Cisco WAN :: 2811 With G.SHDSL WIC CPU Running At 99%

Sep 23, 2012

I have a particular site that is causing me trouble, this site is connected in a back to back configuration using 2811 at CO and 2621XM at CPE.  The CO end is also the CO for 3 other sites so has a total of 4 wics installed (WIC-1SHDSL-v2), these other sites also have 2621XMs for the CPE.
The problem i am getting is when one site in particular transfers large files to/from client machines, the CPU on the 2811 jumps to 99%:
CPU utilization for five seconds: 99%/98%; one minute: 26%;
PID Runtime(ms)   Invoked      uSecs   5Sec   1Min   5Min TTY Process
 11    12881868  37249378        345  0.49%  0.50%  0.51%   0 ARP Input
 54     8548592  30375358        281  0.40%  0.45%  0.41%   0 XDSL BACKGROUND


View 2 Replies View Related

Cisco WAN :: 2811 - External IP Not Pingable From Outside

Apr 20, 2013

We have a cisco 2811 router with 2 ADSL interfaces. One dialer interface is used for internet and another dialer interface is used for VPN.
The dialer interface that is used for internet purpose is "Dialer 1" and the VPN is "Dialer 2".
The route looks like this: ip route dialer 1
Basically, I am able to the ping the external IP address associated with the Dialer 1 interface, however, I cannot ping the external IP address associated with Dialer 2.

View 5 Replies View Related

Cisco WAN :: 2811 NAT Anything Heading Out Of WAN Port

Mar 22, 2012

I have a Cisco 2811 with an additional HWIC-4ESW card. [code] I need to NAT anything heading out of the WAN port. [code] I can ping anything connected to my other private networks from my network but nothing on the Internet. [code]

View 3 Replies View Related

Cisco WAN :: 2811 To Enable Ssh On A Router

Jan 3, 2012

I just bought an additional router for my network and I'm in the process of setting it up.I have however hit a snag with enabling ssh on the device. It is a cisco router 2811 running IOS 15.0 (refer below to my attempts)

View 3 Replies View Related

Cisco WAN :: IOS Image Download 2811?

Sep 4, 2011

I want the below mentioned IOS image for backup purpose. But I am not finding it in or anywhere in the in internet. where can I get this version of image other than my router.

View 1 Replies View Related

Cisco WAN :: Configuring ASA5510 With 2811 ISR

May 26, 2012

I have a 2811 ISR configured to provide the following services to my network: Internet access to LAN usersCisco Call Manager ExpressSite-to-stie VPN to 3rd party networksVPN server to provide VPN access to remote usersSecurity Zone configurationsStatic NAT configurations.Now I recently just got the ASA5510 device and I am not sure how to go about with the setup, whether to put the ASA in between the internet and the ISR (Internet - ASA - ISR - LAN), or put the ISR in between the internet and the ASA (Internet - ISR - ASA - LAN)? While i know I can move most of the config unto the ASA, i know that the CME cannot be moved, hence I would like to do the setup such that users on the network still have access to CME.

View 2 Replies View Related

Cisco WAN :: 2811 / Securing Ports In Nat?

Mar 22, 2012

I have a site that is connected to the internet via T1 into 2811 runing C2800NM-ADVENTERPRISEK9-M), Version 12.4(11)X.  I have noticed that when i do a port scan on the outside nat pool i see well know ports in the closed state .ie...7,21,22,23,25,99,100,80,443.   These pools for end users to access internet.   Does this pose a security risk? What can i change to provide end user access to web but not let these well know ports open?

View 6 Replies View Related

Cisco WAN :: 2811 DSL Load Balancing

Dec 9, 2010

I have a Cisco 2811 router with two HWIC-ADSL cards configured for dsl connection. I have two lines from the same ISP and i am load balancing between them. I have created a couple of SLA's to check the state of the connections and add to the routing table the two default routes if both are up or any one of them is up.My problem is that when i  try to download big files (especially antivirus updates) the download at some point stops (especially the antivirus exits with an error of unreachability). If i shut down one line everything works fine.Could i use something (configuration-wise) to prevent this problem from happening?????Is there any way i can combine the two lines? They are simple ADSL connctions with static ip's.

View 8 Replies View Related

Cisco VPN :: Create A VPN Between 2 Host With 2811 And NAT?

Jan 12, 2012

I want to create a VPN between two PC's, (the server "Data" and "Remote Desktop" check the topology below), the Router Clabeck (cisco 2811 ) is connected to the internet through int f0/0 using a PPPoE connection and connects all the LAN PC's by PAT to the internet (you can see all the configurations in the Show Run below), the "Remote Desktop" is any PC with internet connection. 
F0/1                         F0/0
DATA--------------------SW-------------------ROUTER(Cisco 2811)---------------------INTERNET---------------REMOTE DESKTOP                                                                       
Current configuration : 2116 bytes
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec


View 1 Replies View Related

Cisco Firewall :: 2811 ZBF URL Filtering

Apr 18, 2012

I try to implement the url filtering feature on a cisco 2811 router and whenever i enable the parameter map patterns the router retuns (after some time)

%Unable to compile obj regex.[code] The result is that the router blocks ALL webpages without giving a block page message.

View 2 Replies View Related

Cisco WAN :: 2811 IOS For BGP Routing Protocol

Jul 6, 2011

I am currently configuring a  number of cisco 2811 routers that require the BGP exterior routing  protocol, however the IOS version (12.4) currently installed does not  support the bgp protocol.After entering the commands into the cisco CLI 'protocol not in this image' is returned.

View 2 Replies View Related

Cisco WAN :: 2811 Router LAN Ports?

Jun 14, 2012

how many extra interface port can be plugged in to the 2811 router ,there are 2 fixed FE port on this router and i have 3 connection i.e one mpls link , one internet link  and one sip trunk .. some body confirm me  that i can insert module in 2811 ?

View 5 Replies View Related

Cisco WAN :: 2811 High Cpu Utilization

Apr 29, 2013

I have a 2811 that is really hitting the CPU hard.  Nothing shows on CPU processes.  It has an IPsec VPN tunnel back to HQ which also has a 2811 that terminates the VPN.  The HQ has 2-3 IPsec tunnels to other remote sites.  The CPU at the HQ avg 50% utilization during business hrs, peaks at about 80%.  The remote one is very high 95% peaks, avg 80%-95% during business hours with bandwidth utilization of only 10-20Mbps.  I read somewhere that its possible that fragmentation could be causing this.  My question is, if I set the MTU to 1450 on the remote, I am guessing I will need to do all the other routers as well, the HQ and other remote sites?  Siince they use the same outside interface to my HQ, is that correct?

View 3 Replies View Related

Cisco WAN :: Latest Supported IOS For 2811?

Aug 22, 2012

latest supported version of IOS for the Cisco 2811? 

View 3 Replies View Related

Cisco WAN :: CPU Utilization High In 2811

Jun 23, 2011

We have Cisco 2811 router and facing high CPU utilisation as 70%/67%;,IOS Runing :c2800nm-advsecurityk9-mz.124-3f.bin.

View 4 Replies View Related

Cisco WAN :: 2811 - Allocate CPU To Certain Processes?

Apr 23, 2013

Is there a way to allocate CPU or memory resources to specific processes - similar to a QoS-style configuration where you can prioritize the processes being handled by the CPU? We have a 2811 router whose CPU periodically spikes to 100% utilization. At these times, all of our EIGRP neighbor adjacencies bounce - either a peer goodbye is received or the hold time expires.
Our thinking is that we could possibly tell the router to prioritize the EIGRP process with the CPU so that routing is maintained, even though we realize other processes (like qos or ISAKMP for our tunnels) may suffer.

View 2 Replies View Related

Copyrights 2005-15, All rights reserved