I spoke with the carrier. There are numerous issues here (all on behalf of the carrier). There is some history here but I will give everyone the nutshell point of view ...
Area 1 should not be used but when Area 0 wasn't working I was told to use it. Area 1 is not supposed to be able to talk...
It was determined that my carrier had me pointing to the wrong OSPF area. Creating a new process on the router and applying that to the T3 interface (S1/0) I was able to get this going. However, this has created a new question ...
How do I force all traffic over the T3 and not load balance on...
I'll see about posting the config.
Minue: I was under the impression that by default the IOS automatically assigns an OSPF cost value to the interface on turn-up. I've verified that my T3 does have a lower overall cost than the multilink.
Thoughts?
Hi Everyone,
My design is as follows:
MPLS Cloud
|
T3 Multilink
| |
ROUTER
|
LAN
My router is a CISCO 3845. I recently installed a T3 which is now operational. However, still in place are the orginal bonded T1s which were the default gateway handling all...
garnetbobcat
I stand corrected. After looking at your response I believe this is possible. I completely forgot about the EZVPN client!
Since the early days of PIX, I've been primarily following CISCO's example here (though this has been updated to the ASA it now appears)...
Correction to my last post, I need to confirm, but I do not believe the SSH, Telnet, VNC, and CITRIX plugins are all ActiveX. I know for sure the RDP plug-in requires your browser to both support ActiveX, allow popups, and be trusted. At least in IE.
asanchev4
I am not using any client at all. My clients login directly thru the site and click on Applications, then a button which launches a window (using java).
Inside this window, there is a local and remote collumn. The user should already have positioned on their desktop a shortcut...
There's a CISCO whitepaper on this. Go to CISCO.com. It's right on the ASA config docs page.
And DYNDNS isn't going to allow you to setup an IPsec tunnelf rom an ASA to ASA. You need to configure your ASA to accept a default pre-shared key from any IP address.
DYDNS is something else...
There is an ActiveX RDP plugin (not the java) which allows for full screen access. However, it does require the user first allow the ActiveX module to be installed which requires a bit of help from a support perspective to the end user.
I have this setup on 3 different ASA's ... I'm using...
You need to look at your show run to see inactive tunnels. If you're at least attempting to bring an inactive tunnel online, you can use 'show crypto isakmp sa' to see the status.
Utilize debug to see why a tunnel doesn't come online 'debug crypto isakmp 127'. Keep in mind, mm_active means...
Solved this issue ... subnet mismatch on the IPsec parameters.
Matched subnets, Phase II completed as usual and everything is online.
Curious to note that information on this error was extremely limited on the web. Searching for Security Parameter Index had me looking in the direction of...
ASA 5510 7.2(3) and trying to setup L2L but receive the following error in PHASE II when trying to establish tunnel:
construct_ipsec_delete(): No SPI to identify Phase 2 SA!
This one is new to me. Phase I goes smoothly, Phase II is where the hang up is. I'm waiting to speak to the remote...
Am I mistaken or in the subject line you are also asking about VOIP?
Are you looking to provide both VOICE and data over a single port? If so, the above won't suffice. You will need to do auxiliary VLAN's too. Not to mention, is POE in play here, 802.3af, 802.1p yadda yadda yadda ...
We...
Realizing what a reverse DNS zone is, I don't see how this will help me. In any event, I thought it important to ask just in case I'm missing something here.
I've just added a 2nd T1 to my office location which is wireless based @ 10Mb. My setup is pretty standard:
(Internet) -- Router -- Firewall -- Router -- LAN
I can ping any host that is pingable on the internet with more than reasonable response times. However, when I attempt to hit many...
I have a CISCO 3005 Concentrator (4.1.7.K Feb 08 2006) which currently routes specific traffic to a client (for example 100.100.0.0) over a vpn tunnel. I am PAT'ing internal users which travel across this tunnel. This tunnel works just fine.
I now have a remote office which also has a tunnel...
Go into Outlook Express and click on Tools + Options. Click on the Maintenance tab. Copy the store location and paste it into the RUN command by going to START + RUN. There is all of your OE dats. Copy that to an external disk
you can also launch it this way via a command line ... and have it prompt you to enter a password:
runas /user:domain\username "mmc.exe compmgmt.msc"
You need to quotes and you can use any console you like.
Usernames aren't tied to Machines name unless you specified the only allow to logon to permission.
The only real way to gleen what you're asking here noting the exception above is to turn on auditing to the level which records both the username and machine name.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.