Cisco WAN :: How To Test Aaa Authentication On ASR1000
Dec 15, 2012How to test the aaa on cisco asr 1000 ? I wana test some user account to a cisco acs.
View 5 RepliesHow to test the aaa on cisco asr 1000 ? I wana test some user account to a cisco acs.
View 5 Repliesi am trying to test EAP_TLS authentication on acs 4.2.1.15 running on Appliance 1120 , I have installed my server certficate along with CA certficate on my appliance box , I have enabled features of EAP_TLS under golbal authentication setup .
I have downloaded client supplicant certficate file for my windows XP machine .When i tried to authenticated i am finding following error message under failed attempts(EAP-TLS or PEAP authentication failed due to unknown CA certificate during SSL handshake) on my acs appliance box .Under certficate revocation list , I have forced my CA as CRL in use . Attached snap shot of all .
Question re: DIR-655; Hardware ver A4; Firmware version 1.32NA
During bandwidth tests to several sites (principally speedtest.net) I get ping times of 10-11 ms, download speeds of 12+ to 17+ mbps but failure on upload tests using my DIR-655.
When I bypass the 655 and test directly with my cable modem, all (including upload) tests work reliably and consistently.
I have swapped the two ethernet cables involved as well as replacing both with new cables but the results are the same (uploads fail with 655 and work without it)
I have seen several postings over the the last year with this same problem but have never seen any comment from D-Link, or a solution from any reader.
Not that it should have any bearing, but I have TA785GE-128M motherboard and am running Windows 7 (patch current) on COMCAST
is this problem acknowledged by D-Link and is there a solution?
Am trying to find out what is the suitable SPA for ASR1000 routers to connect ATM DS3 through the local telco. Currently this is connected to a NM-ATM-DS3 module on a C3845 router. The reason for asking is we need to upgrade the WAN router to ASR1000.
View 2 Replies View RelatedI am looking for a way to use a 3G connexion on ASR1000.Is it possible to install HWIC module of ISR2 in SPA slot or use an USB modem on the RP?
View 2 Replies View RelatedThe ASR1000 router supports hot-swap modules and network interfaces?
View 1 Replies View RelatedWe use ISG on asr1000 (l3 routed subscriber). Now we are trying to implement ipv6 isg sessions. so.. for ipv4 sessions we have
radius-server attribute 8 include-in-access-req
radius-server attribute 32 include-in-access-req but for ipv6 there is no such attribute#radius-server attribute ?
11 Filter-Id attribute configuration
188 Num-In-Multilink attribute configuration
218 Address-Pool attribute
25 Class attribute
30 DNIS attribute
31 Calling Station ID
32 NAS-Identifier attribute
4 NAS IP address attribute
44 Acct-Session-Id attribute
55 Event-Timestamp attribute
6 Service-Type attribute
60 CHAP-Challenge attribute
61 NAS-Port-Type attribute configuration
66 Tunnel-Client-Endpoint attribute
67 Tunnel-Server-Endpoint attribute
69 Tunnel-Password attribute
77 Connect-Info attribute
8 Framed IP address attribute
95 NAS IPv6 address attribute
list List of Attribute Types
nas-port NAS-Port attribute configuration
nas-port-id Nas-Port-Id attribute configuration
what is best practice for authorize ipv6 l3 subscribers ?
We have asr1006 with 2 esp-40 and 2 rp2 and 2 sip-40. we need to bridge vlan from portchannel (2*10) to single 10ge port.
So fn said that EVC on Port-Channel supported on our software and document [URL] have such example
- configure terminal
- interface port-channel channel-group
- service instance id ethernet
But on our router we have not service command on port-channel. only on non portchannel interface.
But other document have Restrictions for Configuring EVCs on the Cisco ASR 1000 Series Router The following features are not supported: EVC on Etherchannels
Connect ww port-channel 1 2 tenGigabitEthernet 0/1/0 2 this is possible command on our router (but i can't create service instance on portchannel interface)
We need to bridge l2 without l3 termination ? is this possible with port-channel ?
we're trying to integrate our SBC instances (CUBE SP on ASR1000) into our network management system (EMC SMARTS)Syslog messages from SBC instances are some kind of cumbersome with lot of line breaks resulting in multiple syslog messages the NMS must parse.How do I configure it to just put it all into one line just as "normal" log messages?
View 2 Replies View RelatedI have a question regarding netflow and NAT. I have read some documentation (on ASR1000) regarding monitoring NAT process on Cisco ASR1000 that can be done using netflow version 9 (the term was called netflow event logging a.k.a NEL). The problem is, I have not found the netflow collector that can do that. I have queried several software such as manage engine "Netflow Analyzer" and Lancope, but they said their software can not do that.
View 11 Replies View RelatedI'm trying to use EPC on ASR1001 running IOS-XE 3.4, and it won't work. Configuration commands are accepted by the router, but there are no packets in the capture buffer.In release notes for IOS-XE, in the 2.5 section, there is a statement that EPC is not supported on ASR1k. Is it true also for newer versions of IOS-XR?
View 1 Replies View RelatedOne of our customer would like to connect 3 datacentres and decided to use VPLS to extend layer 2 VLANs . For this purpose they have bought six Cisco ASR1000 edge routers( two at each side).They also wanted to buy MPLS SP backbone but have decided to buy 2x10G dark fibre links instead.My question is,
1-Will it still possible to run VPLS over dark fibre? Because all the documents I read regarding VPLS are deployed over MPLS backbone.
2-Any sample configuration for implementation VPLS in ASR1000 ?
how the ASR1000s are being setup.I am looking at ASR1000s as part of network refresh and was looking at RJ-45 based Gigabit Ethernet ports compatible with the ASR1000s SPA-5X1GE-V2 seems to be an option but they are all SFPs. Are there any options for RJ-45 ones on ASR1000s?
There is an option for the 2 port where one can mix and match SFPs and RJ45 but I was looking for something which is RJ45 only.Are there any options for them available.I know I could get something with FastEthernet type but was looking for the GigabitEthernet type.
I'm trying to find out what platforms support Multilink PPP with Link Fragmentation and Interleaving over a single link, when that single link is PPPoE. In searching the documentation, the best information I can find is that it seems to be supported in one direction on the ASR1000 url...Many platforms appear to support PPPoE and also MLPPP w/LFI, but it's not clear that both features are supported on the same link.
The application is a radio that has an Ethernet interface on its terrestrial link, and acts as an Ethernet bridge. Would like to use Multilink PPPoE with LFI in order to provide LFI in order to run VoIP over lower speed links (e.g 256kb). For what it's worth, the radio also supports RFC 5578 PPPoE Extensions for Credit Flow and Link Metrics. It was fairly easy to find what platforms support RFC 5578. But RFC 5578 would be used to support variation in the capacity of the link. If the link speed is fixed, RFC 5578 is not needed. I was trying to find if the set of platforms supported increase if the need for RFC 5578 is taken off the table.
In particular, I'd be interested in the whether the ASR 9000 series supports MLPPP bundles with LFI when the links are PPPoE.
We're installing ASR1000 series (ASR1001 and ASR1006) routers on a new WAN and have a requirement to enrypt the traffic between the EIGRP neighbors. Each ASR will be connected to the MOE with a gig interface and we will be using L3 on the interfaces with EIGRP as the routing protocol. We have advipservices-k9 IOS-XE
The ASR1006 is our datacenter WAN router and all remote sites have the ASR1001s. The ASR1006 WAN interface will be configured with L3 subinterfaces, one to each remote location, using a /30 mask.
What is the best method to encrypt the traffic between the ASR1006 WAN interface and the remote ASR1001 WAN interface?
Any equivalent show command to get the "FIB TCAM Usage" on An ASR 1006 ?the "show platform hardware capacity forwarding" does not work on ASR1006 Example on 6500: Router# show platform hardware capacity forwarding.
View 1 Replies View RelatedI want to know what the default behavior about the command 'mls qos trust dscp' under router platform interface. the router is ASR1000 series.we don't need to put above command line to trust dscp in case of router? otherwise, we have to add it as welll as like switch platform.
View 4 Replies View RelatedThe ASR1000 router supports hot-swap modules and network interfaces?
View 2 Replies View Relatedhow to perform UBRL User Based Rate Limiting on ASR1000 like we can do it on Catalyst6500?
View 3 Replies View RelatedI am working on a network which has two ISP connections (Active/Active) terminating on router (ASR1000). From the LAN side (6500 switch) all the traffic need to be route on ISP1 but some of the specific subnets like 10.250.0.0/16 need to be route on ISP2 connection.
I am planning to use PBR and NAT with route maps. any documents or refrences are provided.
(access switches)---------(core switch)----------(routers)----------------(ISP1)
----------------------(ISP2)
I am trying to test and setup some ACL's on a switch, the current setup is:
Core Switch - HP ProCurve 2610-24-PWR
Edge Switch - HP ProCurve 2510-24
VLANS 5, 10, 15, 20, 25, 30
I want to deny access to VLAN 5 from VLAN 20 which is are client VLAN.
IXIA----DUT-----IXIA
| | |
|_______ |________|
DUT has redudant connections to IXIA. Im pumping traffic from IXIA and traffic takes PATH A .. When I shut PATH A, i expect traffic to shift to PATH B within 100ms (example). How do I test this ?
I have an old Pentium 3 PC that I want to test out as a home server. I am thinking of using Linux server is but I don't have any ideas how to do it.
View 4 Replies View RelatedI have upgraded my network service from 2M to 6M per month last week. But the network speed is not so satisfactory. I could hardly feeling its upgrading.Is there any trustful and accurate method or tool to test the network speed?
View 4 Replies View Relatedit seems that if i want to get IBM Cognos 10 BI OLAP Developer certification i have to pass COG-635 exam. it is said exampdf has released the latest COG-635 study guides.
View 1 Replies View RelatedI want to create a network with a bunch of routers and switches to be used as a test network for company employees to remotely login and learn networking.I don't want this network to interfere with the rest of the network in any way.I am basically trying to create a stub network or a passive network!!
View 4 Replies View RelatedAny way to test throughput on a routed SG-300. I tried using iperf with netbook on VLAN1 to netbook on routed interface running @ 100mb. I was getting results as low as 40mb upto 200mb (sometimes even 2gb, I assumed these to be flukes). Since implementing it, the throughtput seems worse, I'm getting between 10 - 40mb of throughput. I have about 30 clients behind it routing across a 100mb leased link. I don't see why the SG300 shouldn't be able to do wire speed routing (upto 100 hosts). How to verify the expected throughput consistently?
View 3 Replies View RelatedI need configuring a newly reinstated PIX515E with IOS 6.3 to test the configuration of a load balancer.I would like to setup with two Inside interfaces (or simply two interfaces) for testing. I just need it to pass traffic (basically HTTP and HTTPS) between these two interfaces without using NAT.The older IOS is causing me some problems. I don't have an outside interface configured for Internet access,but trying to connect via IP address does't work either. I may be able to configure a second DNS server for the 192.168.12.X network for testing purposes if needed. I even tried to set the default route to the Interface of the production ASA's inside interface (3.1), but that did not work either.
View 6 Replies View RelatedI have configured an Cisco 881 router in our lab with netflow commands and pointed to our network monitoring tool and I want to check if the tool can collect valid traffic statistics from this router (eg. utilization). The problem this router has nothing plugged into a production LAN that would potentially generate traffic to measure using this tool.
Is there a way to configure a Cisco router (ex. Cisco 881 router) to artificially generate network traffic to test that I have setup the monitoring tool correct to capture future utilization statistics?
I have recently set up a MDS9000 san fabric in two locations connected by DWDM. My DWDM links come up fine but I am looking to test this link before we go live. How to test this?
View 1 Replies View RelatedI have 2 CSS, 1 as primary and 2nd as standby. I configured the standby CSS as my old standby CSS box and now wanted to test the faliover. I am not aware of how to test it in. ny how i have cr for that.
View 1 Replies View RelatedI've been having problems downloading full ISO's before they're interrupted. There doesn't seem to be any real rhyme or reason to it. Sometimes a 4.1GB ISO will stop at 2GB, other times at 4.0GB. I realize I could run a ping from the time I walk in until the time I leave, but that seems a bit too archaic of a solution.nfortunately, our CTO believes SNMP is too much of a security risk
View 11 Replies View RelatedI know ping and traceroute are commands that test network connectivity. what about netstat and telnet? can they also test network connectivity?
View 4 Replies View Related