Cisco WAN :: Topology To Access To Internet Using 2921

Jun 7, 2013

I'm designing a new topology to access to the Internet using Cisco2921 NAT and MS ISA Firewall. I'm going to use ISA as a proxy to public some internal services and to provide internet access for my users. ISA won’t use NAT. It will route traffic. Cisco 2921 will handle NAT, ISP Failover and IPSec VPN to datacenters.

Cisco 3750 will route outbound internal traffic.My routing for internal users on Cisco 3750 will look like this: [code] My question is about route from Cisco 2921 to my local network 192.168.0.0/22.If I use this route, I'll restrict my traffic from datacenter to go through ISA server BUT all responses from the Internet will go directly to 3750 too.I doubt about security and functionality of such solution. Of course I will public my internal resources to internet that way. It is on Cisco 2921
 
ip nat inside source static tcp 172.16.0.2 80 (my external IP) 80.I could use PBR to divide my traffic from datacenter and other traffic, but I don't know how to use PBR with IPSec VPN traffic.

View 1 Replies


ADVERTISEMENT

Cisco WAN :: 2921 - Block Mac Based System To Access Internet?

Aug 22, 2012

I have a netwokr in which users are getting ip address from DHCP server that is window server.i want to block some users to access interent by using their device mac address.i have these devices in my network...
 
2921 cisco cme router
cisco 2960 switches
cisco 892 cisco internet router
internet ADSL that cnnected with cisco 892...
wireless AP 1142...
 
i have no firewall or any asa...how can i block some users for accessing internet but they can access internal network...for file sharing and prinitng,...

View 15 Replies View Related

Cisco Switching/Routing :: 2921 - How To Access Router From Internet Using Public IP

Nov 21, 2012

the cisco 2921 Router has a default  ip hhtp  access class command  found  in it. Just  i  changed the default  IP to the new ip  i will use.The Router is accessable  from the LAN only  but  not from the internet  configured the Public ip . I think this is due to the standard access list 23 . how will i access the Router from the Internet using the Public IP.

View 6 Replies View Related

Cisco :: Why Can't Remotely Access Topology Services In LMS3.2

Mar 24, 2012

I noticed that I cannot remotely check the Topology Services in Ciscoworks LMS 3.2. I have attached a screenshot of the error for reference. When I access Topology Services on the server itself, everything works well.

View 5 Replies View Related

Cisco WAN :: 2921 How To Access Firewall From Command Line

Jun 11, 2012

we just bought a 2921 with the following modules: 4 port clear channel T1/E1 HWICSM-ES3G-24-P: EtherSwitch.I read some CISCO documents, and not be able to find what I need. I would prefer all instructions from you are for CLI interface.This is my first time to deal directly with T1, WIC and 2921 etc. The following is what I get from ATT, IP masked IP Address Block IP Address: 20.20.20.136/29 WAN Link Details: WAN Link IP Address:13.13.13.92 AR Serial INT IP Address:13.13.13.93 CR Serial INT IP Address:13.13.13.94 WAN Link Subnet Mask:255.255.255.252
 
A: how do I configure T1, what does "AR, CR" stands for, and do I need to use both IP addresses? What is the WAN Link IP for?
 
B: We have two T1 lines, so I should plug them both to the WIC, say port 0 and port 1, how to configure them?
 
C: how do I access the firewall from the command line?
 
D: I followed T1/E1 HWIC installation guide, and as soon as I add channel-group to the controller t1, the serial interface went down?

View 2 Replies View Related

Cisco WAN :: 2921 - CBAC Firewall Access List

Jul 1, 2011

I need to configure the access list on the outbound internet port to accept the following:
 
ip access list 10
access-list 10 permit PPTP vpn any xxx.xxx.xxx.xxx
access-list 10 permit RDP any xxx.xxx.xxx.xxx
access-list 10 permit FTP any xxx.xxx.xxx.xxx
access-list 10 permit Postgresql any xxx.xxx.xxx.xxx
access-list 10 permit MacARD any xxx.xxx.xxx.xxx
 
This method does not work on the Cisco 2921 router with FW

View 1 Replies View Related

Cisco Switching/Routing :: 2921 / Limit Access By HW Address?

Sep 15, 2012

I have a 2921, and I have 4 network segments. In segment 172.16.0.0./27 I wand to "pair" somehow connections. I mean IP 172.16.0.x has to have MAC aaaa.bbbb.cccc and so on, and not accept connections otherwise.How can I do that?

View 7 Replies View Related

Cisco WAN :: 2921 ISR For Routing 100Mbps ISP Internet

Feb 16, 2012

It seems that Cisco mentioned, in their data sheet of 2921 ISR, that it can support up to 50Mbps. However, from Google search, it says 2921 can handle 100Mbps with no problem.I am planning on getting 2921 ISR in small office where only ~10 people are connected to it. And we do have two different line of 100Mbps ISP internet line  and wish to share them in the office.I am confused why ~$2k router can not support 100Mbps where ~$100 consumer routhers like Linksys has no problem with handling that speed.  The reason why I am planning on 2921 is the rich feature like Voip solution (CME) it offeres.  I have several remote offices that needs to be connected with Voip phones. and I could go with UC500 series but it seems to me UC500 does not support IP Phone 9900 series.

View 5 Replies View Related

Cisco WAN :: 2921 Router For Both MPLS And Internet Connection

Apr 4, 2011

i m planning to use the 2921 router for both mpls and internet connection , to 2 different isp also am planning to use bgp with a public providor independant
 
i m planning to buy sla for the mpls link

View 9 Replies View Related

Cisco WAN :: Dual Internet Link In Terms Of Load Balancing ISR 2921

Jan 20, 2012

We have deploy a Cisco ISR 2921 to connect two ISP for internet access, Link 1 is fix public IP, link 2 is xDSL.And we configure dual link load-balance, the configure just like the famous DOC "[URL]" name:"dual internet links NATing with PBR and IP SLA". Inside network to internet is ok, and traffic was load-balance, Dual link can be redundancy. But there has some issue we don't realize.Most people interesting how the inside traffic load-balance outside, but ignore the traffic from outside issue.

View 2 Replies View Related

Cisco Switching/Routing :: 2921 - Network Segmentation And Internet Bandwidth Splitting

Feb 24, 2012

Now I have a 172.16.0.0/16 network with a def. gw. for internet where is a MS Forefront TMG 2010 with BSplitter for traffic shaping. I purchased an 2921, 2,5 GB RAM, security+data license and an EHWIC-D-8ESG.

I made 4 subnets in a test environment with some access-lists, nothing fancy yet. How can I use FF TMG for bandwidth management, where should I put it? For those 4 subnets the def. gw. is, normally, the 2921 router. TMG is splitting traffic by client IP.

View 1 Replies View Related

Cisco :: LMS 4.2 Topology Data Collection

Mar 20, 2012

i have an issue with the lms 4.2 Topology Data Collection. After installation the Topology Data Collection was running normaly, but since first server reload the Topo Data Collect under Inventory > Dashboards > Device Status > Collection Summary is "frozen".Is there any option to stop this process elsewhere? I cannot find anything under jobs in running state or so. Clicking on Schedule only give me the option to start data collection, but lms always returns that the process is running.

View 9 Replies View Related

Cisco :: LMS 4.2 - Devices Not Connected To Topology

Nov 26, 2012

1)i have problem in LMS 4.2 , he  shows most devices not connected to topology sitting lonly even though the have cdp enable , how to force these to join the topology
 
2)why some devices are shown unreachable , even though i can ping them from lms server and gets reply, also they have community and cdp configured

View 1 Replies View Related

Cisco :: LMS 4.0.1 - Telnet From Topology Services Map

Dec 19, 2011

On a LMS 4.0.1 :I want to know what is the right way to change the telnet program on the campus mgr map (topology services map), when right-clicking a device icon and selecting telnet.I would like to use a tool of mine, and not to launch a telnet command from the IE browser.I changed the default telnet of Windows in the registry, but the program is still launched as a telnet URL in the browser and this is not what I would like to do.

View 2 Replies View Related

Cisco :: LMS 4.1 - WAN Links In Topology View?

Mar 12, 2012

The regular problem with the LMS topology and WAN Links when you see the branches are disconnected from the HQ BUT in my case the branches are already connected via Layer2 links but unfortunately some intermediate layer2 modem/switch exist in some branches which prevent CDP discovery but you will find both HQ and branch router in the same subnet .

View 1 Replies View Related

Cisco :: 2960 LMS 4.1 Did Run Topology Service

Jun 20, 2012

i have only 1 switch 2960 POE at customer enviroment.i did run topology service and checked on the right side POE CAPABLE Devices
 
it shows me that i have 4 switch POE while actually there is only 1 switch POE in real enviroment.

View 7 Replies View Related

Cisco :: Cannot Open Topology Service LMS 4.1

Feb 4, 2012

have ether-channel across 2 switches?i am new in cisco LMS . now i am in client site  installing cisco LMS 4.1 in UCS server-rack version. we did it well for  the installation, and the LMS working properly until i cannot open  topology service.
 
i attached the error message

View 14 Replies View Related

Cisco :: Does Disabling CDP Affect LMS 4.0 Topology

Feb 14, 2012

I have a customer who wants to disable cdp on all switches for securtity reasons. The same customer has also LMS 4.0 installed.
 
When disabling cdp, does it affect the topology services on LMS? Can you still see the topology tab on device manager or the topology map of the entire network?

View 4 Replies View Related

Cisco :: EIGRP / Static Route In Same Topology?

Oct 13, 2012

I config the routers with EIGRP and also write Static route between two PC before remove the link between router0 and router1 , destination is reachable , but when remove this connection , packet from pc1 to pc0 will drop in a loop and never reach to destination , is it possible to have a Link state routing protocol and static route at the same network like this scenario , how to prevent loop in this topology static route is configure as bellow :

router0 <==> router 1 <==> router2 <==> router3 <==> router <==>pc1

View 6 Replies View Related

Cisco :: LMS 4.2.1 - Tunnels Missing In Topology View

Jun 12, 2012

I have problem with topology view in LMS 4.2.1, it doesn't show the tunnels connecting branches, though both devices are shown in sh cdp neighbour command output. If I choose Show Devices in Admin > Collection Settings > Data Collection, it is showing cdp neighbours correctly.

View 4 Replies View Related

Cisco :: Bandwidth Utilization On Topology Diagram Of LMS 4.2?

Feb 12, 2013

I am running LMS 4.2 , using that i am monitering some switches . I am using topology services also. In that i am getting veiw of all connected devices with links. But bandwidth utilization is for those links are not showning in topology veiw .
 
Is there any settings to be done in LMS 4.2.2 or any configuration changes to done on my switches ?  to find the traffic flow  bandwidth utilization.

View 1 Replies View Related

Cisco :: LMS 4.0.1 Topology Services Not Running On Windows 7?

Sep 19, 2011

I installed LMS 4.0.1 and every module works from the local server. Http login from a remote system, topology services does not start, complains about java version. I followed the link to install the java version, it then complains about some Ansiserver stuff.
 
the client os is win7 64 bits, eplorer version is 7.

View 1 Replies View Related

Cisco :: LMS 3.2 Devices Appear In Topology And Reports By IP Not Hostname

Jun 14, 2012

i have a problem that i see the devices by ip not hostname in devices report and topology and i checked in device discovery to appear by hostname

View 2 Replies View Related

Cisco :: Unable To Launch Topology Services LMS 4.0

Nov 7, 2011

When i try to launch topology services in LMS 4.0 i get prompted to install a java plugin. When i install this it tells me to restart the browser but nothing is changed, it asks me if i want to install the java plugin again.

View 7 Replies View Related

Cisco Routers :: Possible To Use RV042G For Attached Topology

Mar 24, 2013

I'm trying to make an attached topology. This router should be attached to 2 different ISPs on both WAN interfaces (ISP1 with IP address - A.B.C.D, and ISP2 with IP W.X.Y.Z) and I want to use DMZ, too. My idea is to make a L2/L3 segmentation with 2 VLANs - Vlan RED for DMZ (private network 192.168.1.0/24)  and vlan BLUE for Internal network (network 192.168.2.0/24). I checked in the manual that vlans are supported, but I can't see anything about 802.1q, can I use one trunk port or I should use 2 physical cables?
 
There should be inter-vlan routing and basic stateful firewall, so PCs in Vlan Blue should be able to initiate connections to DMZ servers, but the opposite should be denied. Router should make a port forwarding on its both WAN interfaces and forward incomming traffic (from Internet) to DMZ servers (with NAT). Both DMZ servers and internal PCs should have an internet access with NAT over both WAN uplinks.
 
Can I use RV042G for this setup and if not at all - are there any cisco SMB device which can do this?

View 5 Replies View Related

Cisco :: LMS 4.1 Topology View N7K Missing Links

Oct 17, 2011

I work with the topology view in LMS 4.1. I can see all the links between the differrent switches (N7K, 3750, 3040).I miss only the links between the different N7K's. This links have one special thinks: they are configured as "  rate-mode dedicated force" In the N7K cli this interfaces are displayed with the SN too.

sw-bb13# show cdp ne.The links to sw-bb11 and sw-bb21 are not painted in the topoloyview.

View 3 Replies View Related

Cisco WAN :: 65000 BGP Confederation / Configuration And Topology

Jan 15, 2012

Attached is BGP confederation configuration and Topology. They are taken from "Routing TCP/IP Volume 2" book.AS 65000 is designed as a backbone AS connected to non-backbone AS 65535, 65534 and 65533. All are member AS's in AS 1200.I have couple of questions as i think some parts of Sunshine's and Talisman's configurations are incorrect.
 
1. The next-hop-self keyword is mentioned only for Panorama router, why the keyword wasn't mentioned for Nakiska and Talisman routers? .. As we know, the next hop is preserved throughout the confederation, therefore, next hop self should be configured in all member AS's inside the confederation. The same thing with Talisman, why the next hop keyword wasn't mentioned for Lakeridge and Sunshine?
 
2. Why the remote-as keyword wasn't mentioned for Panorama in Sunshine's configuration while the keyword was mentioned correctly for every neighbor routers in Talisman's configuration?
 
3. I don't understand the below statements that are stated in the book, as it conflicts with the rule "MEDs are preserved throughout the confederation"
 
"AS 65000 can safely send MEDs to AS 65535. A route that includes 65000 in its AS_PATH is not accepted by Sunshine or Talisman, so MEDs sent from those routers to AS 65535 are not seen by other member AS's".

View 3 Replies View Related

Cisco :: LMS 4.0.1 - Topology Shows Not In Network Links

Jun 21, 2012

Using Topology I can show device view from all my managed VTP domains. I don't understand why all links are "not in network"!?

View 3 Replies View Related

Cisco Switches :: Frequent MSTP Topology Changes On SF-300-08 And SG-300-10?

May 22, 2011

I am trying to configure MSTP on Layer-2 network at work. We have multiple switches connected on Wireless point-to-point links with redundent links.MSTP is configured with multiple regions. All the servers are located in RegionA and other regions are connected to RegionA via multiple links.
 
There are 3 SG-300-10 switches in RegionA  --- SwitchA_1, SwitchA_2 and SwitchA_3.One of the simple regions (RegionB) has a single SF-300-08 switch (SwitchB) connected to SwitchA_2 via port e7 and SwitchA_3 via port e8. Hello Time, Forward Delay and Max Age are at their default values of 2, 15 and 20 respectively. The link between SwitchB (port e7) ---- SwitchA_2 is the primary link with cost 200,000 and the link between SwitchB (port e8) ---- SwitchA_3 is the backup link with cost 500,000.
 
The log on SwitchB is shows in the table below. As it is seen from the table there are frequent topology changes for very short duration (1-4 seconds) before the topology settles back to the configured one. (Primary link forwarding and secondary link blocking). During this time there have been no link failures reported.Same thing is also observed within RegionA (SwitchA_1, SwitchA_2 and SwitchA_3 are connected to each other).
 
How to stop these frequent topology changes? The topology changes within RegionA causes a lot of PPPoE sessions to reset and re-establish.Is there any way to find out what triggers these topology changes?
 
21474646232011-May-24 13:54:15Warning%STP-W-PORTSTATUS: e7 of instance 1: STP status Forwarding21474646242011-May-24 13:54:15Warning%STP-W-PORTSTATUS: e7 of instance 0: STP status Forwarding21474646252011-May-24 13:54:15Warning%STP-W-PORTSTATUS: e8 of instance 1: STP status Blocking21474646262011-May-24 13:54:15Warning%STP-W-PORTSTATUS: e8 of instance 0: STP status Blocking21474646272011-May-24 13:54:13Warning%STP-W-PORTSTATUS: e8 of instance 1: STP status Forwarding21474646282011-May-24 13:54:13Warning%STP-W-PORTSTATUS: e8 of instance 0: STP status Forwarding21474646292011-May-24 13:54:13Warning%STP-W-PORTSTATUS: e7 of instance 1: STP status Blocking21474646302011-May-24 13:54:13Warning%STP-W-PORTSTATUS: e7 of instance 0: STP status Blocking21474646312011-May-24 12:53:22Warning%STP-W-PORTSTATUS: e7 of instance 1: STP status Forwarding21474646322011-May-24 12:53:22Warning%STP-W-PORTSTATUS: e7 of instance 0: STP status Forwarding21474646332011-May-24 12:53:22Warning%STP-W-PORTSTATUS: e8 of instance 1: STP status Blocking21474646342011-May-24 12:53:22Warning%STP-W-PORTSTATUS: e8 of instance 0: STP status

[code]....

View 1 Replies View Related

Cisco :: LMS 4.0 Stops To Refresh Network Topology

Oct 14, 2012

After some time LMS stops to refresh network topology (not changing colors for devices which lost/found). However, if I restart topology services devices are refreshed.

Checked the processes. Everything is fine but there is a process named "1018". But I did not found any job with this number.

View 2 Replies View Related

Cisco :: Client LMS 4.0 Error Connect Topology

Sep 10, 2012

I have problem with LMS 4.0 when i connect the topology from client PC. On client PC (Install windows 7), I had some check:

- Telnet LMS 42342 ------ OK

- Add host in Program files/system32/drivers/etc: 10.10.10.14 LMS

View 9 Replies View Related

Cisco Wireless :: 2911 - WLC Configuration Topology

Sep 3, 2012

I have CISCO 2911 with SRE module for Wireless Lan controller software. also between my local network and CISCO router is a firewall, CISCO router is an edge router so router and my Lan are in different subnets.  i want Wlan and Lan to be in a same subnet is it possible? In other words, can WLC and Access points be in different subnets? the case is that wireless devices should be behind the firewall.

View 5 Replies View Related

Cisco :: 2811 / 2801 - LMS 4.1 Topology Fail

Sep 2, 2012

I have HQ and Branch router
 
HQ       = 2811
Branch = 2801
Connection type Freme-relay between HQ and Branch
CDP enable on interface

The Branch router show in UNCONNECTED DEVICE VIEW of Topology

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved