Cisco WAN :: Getting 1941 Tunnel Bandwidth Command?

May 13, 2011

I have a Cisco 1941 router with the Security license running IOS c1900-universalk9-mz.SPA.151-4.M.bin.  Is there a "tunnel bandwidth" command like with routers that have the Advanced IP Services license?  My concern is being able to adjust the bandwidth to a value greater than 8 Mbps...

View 3 Replies


ADVERTISEMENT

Cisco WAN :: 1941 Router - Enable IPSec Virtual Tunnel Interface With Tunnel Mode IPv4

Sep 23, 2012

I'm in process of purchasing a new Cisco routers for our branches that will be used primary to enable IPSec virtual tunnel interfce with "tunnel mode ipsec ipv4". does the default IOS IP Base supports this feature? or i need to purchase DATA license or SECURITY license?

View 4 Replies View Related

Cisco WAN :: Adding 3rd T1 To 1941 For More Bandwidth

Aug 15, 2012

We have a Cisco 1941 Router with two single HWIC cards supporting two T1 lines 3Mbps total bandwidth. We have a distance learning lab that takes atleast 2mb connection when in use so it realy kills our bandwidth. I was looking to possible add a thrid T1.
 
My question: Can I just buy a double wide HWIC card and replace the single port one. Would this require re-configuration or it's simply plug n play?
 
What other options can I try for more bandwidth instead of adding thrid T1.

View 4 Replies View Related

Cisco VPN :: 1941 Crypto Isakmp Policy Command Missing

Apr 19, 2011

I have been looking around and I can not find the " crypto isakmp policy " command on this Cisco Router 1941.  I just wanted to setup a regular IPSEC Lan to Lan tunnel and surprise, the command is not there.  Do I have the wrong IOS? I thought that a K9 image would do the trick. [code]

View 2 Replies View Related

Cisco VPN :: 1941 Tunnel Up But Can't Reach Devices?

May 23, 2013

We set up a 1941 Router with the Cisco Configuration Professional Tool. The VPN Tunnel works and i get an IP Adress from the pool. But i cant reach any devices in the VLAN10 Network. Do i forget anything ?
 
Here is the config from the Router:
 
version 15.1
parser view CCP_Monitor
secret 5 $1$FnN7$Qr.mbJbPOuOH7Te6MD1.I0
commands configure include end

[Code].....

View 3 Replies View Related

Cisco VPN :: 2921 And 1941 EAP TLS Fragmentation Across VPN Tunnel

May 7, 2012

I am having an issue authenticating users via 802.1x/EAP-TLS across an IPSec tunnel. I am using route-based VPN with SVTI configuration on a 2921 and 1941. I have the following settings defined:

- Under the tunnel interfaces:
- MTU 1390
- MSS 1350
- PMTUD
- Under the ingress LAN interface
- route-map to set the DNF bit to 0
- On the RADIUS Server (2008 NPS)
- Framed-MTU: 1300
 
This had been working for months until I got a call last week about users not being able to authenticate to our secured SSID. I fired up wireshark and also used my client monitor tool in my wireless NMS to watch what is going on. I see all of the access-request and access-challenge exchanges, but the final exchange never happens. In both captures you can see messages with id's 77-81, but message id 82 isn't shown in the wireshark capture, only fragments are. In the client monitor capture you can see that message id 82 is 1726 bytes in length. Now, if I capture packets on my local LAN, the 1726 byte packet is properly fragmented and users can authenticate just fine.

I have scoured the Internet trying to find a setting that I must have missed, but I can't. I've tried adjusting the Framed-MTU, all the way down to 1100.

View 1 Replies View Related

Cisco Switching/Routing :: 1941 / IPSec Tunnel Up No Traffic?

Mar 7, 2013

I have an IPSec tunnel configured on my Cisco 1941. The other device is an ZyXEL router.I can see the tunnel is up but there is no traffic.This comes out the show crypto ipsec sa

interface: Dialer1
Crypto map tag: CMAP_AVW, local addr 10.10.10.89
   protected vrf: (none)
   local  ident (addr/mask/prot/port): (192.168.200.0/255.255.255.0/0/0)
   remote ident (addr/mask/prot/port): (192.168.150.0/255.255.255.0/0/0)
   current_peer 20.20.20.161 port 500

[code]....

View 3 Replies View Related

Cisco VPN :: 1941 Encrypted GRE Tunnel Changes State To Reset / Down Upon IOS Upgrade

Jun 16, 2011

I installed a 1941 router with an encrypted GRE tunnel yesterday.  The router has ipbasek9 and securiyk9 licensed.  Initially the router was running the image c1900-universalk9-mz.SPA.150-1.M5.bin and was working fine.  The tunnel was up and passing traffic.  I then upgraded the IOS to c1900- universal k9-mz.SPA.151-2.T2.bin and when I reloaded the router the tunnel was stuck in a reset/down state.  I tried doing shut/no shut on the interface and reloading the router again, no change.  Being under some time pressure to get the device back into production I rolled back to the previous IOS image and the tunnel worked fine again.  Is there a known bug that causes this behavior?  I have searched cisco.com but have not found one.  [code]

View 1 Replies View Related

Cisco :: Command That Can Show Which Station Consume Bandwidth

Dec 7, 2012

i have 10 stations, and i think one of them generated allot of traffic.maybe a virus sending spam.is there a command that can show my which station consume bandwidth?

View 3 Replies View Related

Cisco WAN :: 7204 VXR - GRE Tunnel Max Bandwidth

Feb 28, 2010

We have point to point metro ether net link terminating on 7204VXR router.On this point to point link we are configuring GRE over ip sec. Problem is when the traffic exceeding 8mbps we started getting packet drops. from the Cisco documentation it seems the tunnel bandwidth is by default 8mbps and there is parameter like Inherit/receive but those actually not change the tunnel interface bandwidth.If we just give tunnel bandwidth with bandwidth mentioned it allows me to give option of 100mbps but again the tunnel interface bandwidth remains 8mbpos only and probably that 100mbps is useful only for routing decisions.
 
i am using advance security 12.4.15T12 image. Whether this is a limitation or any other way to go beyond 8mbps for the tunnel interface (7204VXR-NPEG1 processor)

View 18 Replies View Related

Cisco :: Interface Tunnel Command Does Not Exist?

Oct 21, 2012

I am using ASA 5520 Image in GNS3, when i come in Configuration Mode and try to create Tunnel through command "interface Tunnel 0", but this command doesn't exist. I need this command to create Tunnel for GRE Lab.

View 2 Replies View Related

Cisco WAN :: 2811 - Limiting Bandwidth In GRE Tunnel?

Jun 10, 2013

We have two Cisco 2811 Routers setup with a GRE tunnel that we would like to constrain the bandwidth on to replicate a satellite connectinon of 400 kbits. We tried the bandwidth command 400, but from what I understand that is only for routing metrics and not actual speed of the interface.

View 5 Replies View Related

Cisco WAN :: 7206VXR - GRE Tunnel Transmit Bandwidth

May 19, 2011

We have a major poblem going on with our VPN router.We have a 7206vxr router which has an mGRE tunnel forming EIGRP neighbourship with about 800 remote locations using GRE over IPsec.
 
We have a problem where the EIGRP neighbourship keeps flapping intermittently and this happens to 30-40 locations at one time and very frequently.What I noticed was that the GRE tunnel transmit bandwidth was showing as 8 Mbps. I guess there is an option to change it.Will this 8 Mbps limit cause any issues of EIGRP neighbourship flaps and will increasing the bandwidth useful.

We are also seeing output drops on the tunnel interface.

pcvpnstore#sh int tu0Tunnel0 is up, line protocol is up  Hardware is Tunnel  Internet address is 10.254.254.254/16  MTU 17912 bytes, BW 30000 Kbit/sec, DLY 50000 usec,     reliability 255/255, txload 244/255, rxload 110/255  Encapsulation TUNNEL, loopback not set  Keepalive not set  Tunnel source x.x.x.x (GigabitEthernet0/2)  Tunnel protocol/transport multi-GRE/IP    Key 0x328CDF, sequencing disabled    Checksumming of packets disabled  Tunnel TTL 255  Tunnel transport MTU 1472 bytes  Tunnel transmit bandwidth 8000 (kbps)  Tunnel receive bandwidth 8000 (kbps)  Tunnel protection via IPSec (profile "dmvpn")  Last input 00:00:00, output never, output hang never  Last clearing of "show interface" counters 00:17:06  Input queue: 0/800/0/0 (size/max/drops/flushes); Total output drops: 732

View 9 Replies View Related

Cisco :: 3560 - Missing IPv6 Tunnel Command?

Sep 17, 2011

I've finally got my 3560 switch IPv6 capable (IP Services IOS), but I've stumbled upon something strange: I can configure a tunnel interface, but I can't put the tunnel in ipv6ip mode. The command is missing. I can choose GRE, IP in IP, and a bunch of other things, but no ipv6ip. I'm a bit desperate here and probably I am going to have to live with it, but just in case? I need the IPv6 tunnel for an uplink to a tunnel broker which only supports this type of tunnel, and I'm surprised this is missing.

View 4 Replies View Related

Cisco VPN :: ASA5540 Any Command To Check Tunnel Up-time

Mar 17, 2011

I am using cisco ASA 5540, Is there any command to check the tunnel uptime?

View 2 Replies View Related

Cisco VPN :: 3925 - LAN-LAN IPsec Tunnel Command Unavailable

Apr 14, 2011

I'm looking to utilize one of my 3925's to create a LAN-LAN IPsec VPN tunnel with another site.
 
I was under the impression that I needed to get a securityk9 license installed and then I would be good to go.   I got a temporary 60 day trial license and successfully installed it, but none of the commands that I need to create the tunnel are showing up for me.
 
I'm trying to use the "crypto isakmp" command, but that is not showing up: Router(config)#crypto ?   ca   Certification authority   key  Long term key operations   pki  Public Key components
 
Here's my show license:
Index 2 Feature: securityk9
Period left: 633 weeks 4  days
Period Used: 0  minute  0  second
License Type: Evaluation
License State: Active, Not in Use, EULA accepted
License Count: Non-Counted
License Priority: Low

View 7 Replies View Related

Cisco VPN :: ASA5500 / Command To Check Tunnel Up-time?

Jun 27, 2011

I am using ASA5500 series box which has a site to site tunnel terminated on it.Is there any command by which we can check the up time of the tunnel.
 
ASA# sh isakmp sa
   Active SA: 1    Rekey SA: 0 (A tunnel will report 1 Active and 1 Rekey SA during rekey)Total IKE SA: 1
1   IKE Peer: x.x.x.x    Type    : L2L             Role    : responder     Rekey   : no              State   : MM_ACTIVE

View 2 Replies View Related

Cisco Wireless :: 2504 Bandwidth Of Capwap Tunnel

Dec 15, 2012

I'm looking at the spec sheet comparing Cisco WLCs and I see that the 2504 has a bandwidth max of 500mbps. Just to be clear, not all of the traffic from the APs goes through the WLC does it? In this setup, the APs would be plugged into a PoE switch as well as the WLC. The only traffic to WLC would be the CAPWAP tunnel, CleanAir info, etc right? All other traffic should just be handeld at the switch right?Also, does the 2504 licencing include CleanAir in the price?

View 17 Replies View Related

Cisco WAN :: 3845 Remove Tunnel Mode RBSCP Command

Sep 19, 2011

I am trying to implement RBSCP on two 3845s running 15.1(4)M1 Adv Enterprise over a satellite link.  The "show" commands all look correct, but whenever I policy route my machine through the RBSCP tunnel I dont even make it to the opposite side.  However, if I remove the "tunnel mode RBSCP" command so it acts like a regular GRE tunnel, I route through it just fine.  So I know its not a NAT, routing issue.  [code]

View 1 Replies View Related

Cisco Firewall :: Command To Check IPSEC Tunnel On ASA 5520?

Jan 7, 2013

Need to check how many tunnels IPSEC are running over ASA 5520.Tried commands which we use on Routers no luck?

View 6 Replies View Related

Cisco VPN :: 5520 - Monitoring IPSec Tunnel Bandwidth Utilization

Sep 8, 2011

We have a Cisco ASA 5520 supporting multiple VPNs - both remote-access  and Lan-to-Lan.  We would like to monitor the bandwidth utilization of the IPSec Lan-to-Lan tunnels.

View 3 Replies View Related

Cisco WAN :: 3845 Bandwidth Limitation On DMVPN Tunnel Interfaces

Apr 23, 2012

So in our DMVPN network, we have this Cisco 3845 hub router that is connected via a DS3 to the Internet, and our spoke sites usually have a broadband connection that typically have a maximum of 1Mbps upload capacity. We are getting ready to add a few more sites to our network that are connected to the Internet with 10Mbps upload speeds (and 50Mbps download). Spoke site routers are usually 800 series ISRs. We have seen spikes of 8-10Mbps on the hub router so far. So the question is that a site with 10Mbps upload speed transmit to the full capacity over a DMVPN tunnel or is it limited by other factors? What are those factors?

View 4 Replies View Related

Cisco VPN :: 1800 Site-to-Site VPN Tunnel Bandwidth For Voice Traffic

Jun 22, 2011

I have some challenges with a VPN config I recently setup for a client.I have at the HO the following:

- 1800 router
- Avaya phones and Gateway
- 1MB radio internet access
 
At the BO(branch office), i have:

- 871 Router
- Avaya phones
- 256k internet bandwidth
 
The only reason we setup the VPN in the first place was for the phones at the BO to be able to connect to the gateway at the HO and also able to make calls and receive calls as if the phones were at the HO.The phones at the BO successfully register to the HO, but are unable to recieve calls and dial out. Everytime I try to make a call, the phone displays a "connecting..." message. [code]

View 2 Replies View Related

Bandwidth Test For 1 Mbps Bandwidth Line?

Sep 9, 2011

We have 1 mpbs bandwidth line, but most of the time we are getting only 300-500 kpbs download speed, i want to send statistics report to our ISP, what will be best procedure to test the bandwidth report, i have checked in some websites like bandwidthplace and speedtest but these sites are not accurate, how to check the actual bandwidth we getting from ISP against 1 Mbps. We have solarwinds monitoring tool in this i have configured the WAN interface for 1 mbps

View 5 Replies View Related

Cisco WAN :: 7201 Option To Send All Traffic Through GRE Tunnel / L2TPV3 Tunnel

Jan 9, 2011

i have a 7201 router with NPE-G2. i have a design which i have the option to send all the traffic through a GRE tunnel or a L2TPV3 tunnel.which method is more CPU consumption ?

View 1 Replies View Related

Cisco Routers :: Set A VPN IpSec Tunnel GW To GW Tunnel Between RV110W

Oct 17, 2012

I am using a Cisco RV110W (Firmware 1.2.09) in a branch and I would like to create a VPN Tunnel to another site that has a Cisco RV042 (firmware v4.2.1.02)
 
What would be the correct Configuration? the current configuration I am using is
 
in the RV042 i am using
 
Check Enable 
Local Group Setup
Local Security Gateway Type : IP Only
IP Address : RV042 Pulbic IP address

[Code].....

View 3 Replies View Related

Networking :: To Tunnel All Routers Traffic Through SSH Tunnel With WRT300n

Jul 24, 2012

Environment :linksys wrt300n v1.1 which can have ddwrt-mega. Willing to tunnel all lan's outbound traffic through an ssh tunnel.

View 2 Replies View Related

Cisco VPN :: Tunnel With WRVS4400N Need To Push 2 IPs Through Tunnel?

Jan 23, 2012

There are a few situations were I'd like to be able to use the locally configured account on a device but still have ACS in place.I want to complete this WITHOUT adding the locally configured account into ACS.I have tried setting the advanced option under Identity for if an account is not found to "Continue" however this causes the account to be allowed as long as a password is typed (any password, as long as its not blank).

View 2 Replies View Related

Cisco VPN :: How To NAT After Connecting 1941

Feb 22, 2012

I have a Cisco 1941 which has several Cisco VPN clients connecting to it which all works fine. The details of the LAN and VPN clients are as below:
 
Cisco 1941 LAN : 172.16.1.0 255.255.255.0
VPN Clients : 192.168.5.0 255.255.255.0
 
As mentioned this works fine but I'm about to setup a point to point VPN with from the above Cisco to another site which isn't controlled by myself and the remote side of this point to point VPN will only allow connections from the "172.16.1.0" subnet to communicate with it.
 
The issue I have is that the Cisco VPN clients also need to communicate with the remote side of this point to point VPN but they are obviously coming from the "192.168.5.0" subnet. Is this possible and where to start with this that would be fantastic.

View 3 Replies View Related

Cisco WAN :: NAT IP Is Not Working In MWR 1941 DC?

Feb 18, 2011

I got 2 DC Cisco MWR 1941 and 3600, I do not know the reason why when I set up IP NAT to 1941 does not work but if I do it in the 3600 if it works.

View 13 Replies View Related

Cisco :: 1941 / IP SLA In Combination With DMVPN?

Sep 5, 2012

I have a problem with my routers (cisco 1941)I'm running a DMVPN network (Hub and spoke)All the hubs are connected to the 2 hubs. With 4 tunnels. (each hub has 2 interfaces to the spokes. the spokes only have one interface to the hubs, so I splitted them and so I now have 4 dmvpn tunnels). one of the interfaces on a hub malfuntioned and because of that the customers had problems with logging in and sending packets. I made this kind of structure because of when one of the tunnels failed the spoke could use the 3 others... BUT, what happened here was that the spoke still tried to use all 4 of the tunnels and because of that I had 25% package loss!So this didn't work. Now I read about IP SLA, but I was wondering of this could work? (I cannot test it on spare routers, and I don't want to implement it and risking a total network failure...) and how to configure it. Should I make 4 different sla processes which I should all 4 track? And when I make the ip routes, how should I make or configure it so that 1 of the tunnels/interfaces fails that the spoke would addapt the routes?

View 1 Replies View Related

Cisco WAN :: 1941 - Routing Between 3G Interfaces?

Apr 11, 2012

I'm trying to get two Cisco 1941 routers with HWIC-1T and HWIC-3G-HSPA interfaces to use the 3G interfaces if the frame is down (as it is right now).In the lab, I was not able to get these to use the 3G interfaces as a backup (i.e. backup interface cell 0/1/0) and I've not been able to workout the correct incantation for static routing either.
 
kununurra#show ip int br d1
Interface                  IP-Address      OK? Method Status                Protocol
Dialer1                    172.31.2.94     YES IPCP   up                    up

[Code]....

View 4 Replies View Related

Cisco WAN :: 1941 W Wireless Not Working

Mar 20, 2011

I have been breaking my head over a problem with my new 1941W ISR since about two weeks now.When I restart the router, the service-module wlan-ap0 is not working.After a restart of the router, when I ask a service-module wlan-ap2 status, I get:Service Module is Cisco wlan-ap0Service Module supports session via TTY line 67Service Module is waiting for registration messageService Module reset on error is disabledService Module heartbeat-reset is enabledService Module is in fail openService Module status is not available
 
After a while it changes to Service Module is failed.If I restart the module with service-module wlan-ap2 reset, it works. Is this a technical error?

View 4 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved