Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Search results for query: *

  1. Frenchie2069

    Tacacs+ and Groups

    In the group configuration can you see a list of allowed NAS? I think that on the windows version (2.6) that I used to use you were able to restrict the groups to a list of valid NAS (Network Access Servers). Each router needs to be configured as a NAS for CiscoSecure to authenticate logins, so...
  2. Frenchie2069

    Point-to-Point Configuration

    Rather than use the 1721 as the DHCP server, you should consider using a helper address on the 1721 and use the Windows 2000 server for all sites - makes management of DHCP MUCH easier! Configue a helper address on the remote offices like this: int fa0/0 ip helper-address x.x.x.x...
  3. Frenchie2069

    Need help on WIC-T1-DSU for Cisco 1602 - Error Messages

    The problem is that the IOS version that you have installed does not recognise the card that you have installed (unless those messages are coming from the boot loader). To verify that the card is supported you can check the hardware-software compatibility matrix. I think you need a CCO login...
  4. Frenchie2069

    Stop ISDN T1 PRI from dialing remotes.

    The dialer-list command defines the "interesting" traffic for the dialer interface. To prevent it dialing you should do: no dialer-list 1 This will not prevent it from receiving calls. HTH, Michael.
  5. Frenchie2069

    NAT - Internet to Internal

    Try this: ip nat inside source static tcp 192.9.207.1 6989 1.1.1.1 6989 This document is fairly straightforward (as far as Cisco docs go): http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080093f31.shtml HTH, Michael.
  6. Frenchie2069

    How do I configure a router to a secondary ISP

    How about a star then ;)
  7. Frenchie2069

    Router Access from Outside via Telnet

    Just wanted to make sure you knew about the potential of being hacked when putting the real IP Address on a board like this ;) You never know who might be watching... Some versions of the IOS support 15 concurrent VTY (telnet) connections. If your config currently has line vty 0 4 then it is...
  8. Frenchie2069

    Router Access from Outside via Telnet

    You are better off using access-class on the vty line: access-list 10 permit host x.x.x.x access-list 10 permit host y.y.y.y access-list 10 permit 192.168.10.0 0.0.0.255 line vty 0 15 access-class 10 in This will allow only hosts x.x.x.x and y.y.y.y plus the local network (192.168.10.0/24) to...
  9. Frenchie2069

    Access-list problm (for a site to site vpn w/ nat)

    The problem is that the access-list is processed before the NAT rules so you need to use the external addresses in your acl. You also need to allow your 2 routers to communicate using GRE. I would recommend changing the nat pool slightly to make the rules easier: ip nat pool rem-natpool-0...
  10. Frenchie2069

    How do I configure a router to a secondary ISP

    BGP is not a trivial thing to set up, but there are a couple of things to consider when planning: * always use route-maps to filter route updates in and out of your AS - don't allow 192.168.x.x, 10.x.x.x, etc in or out and only allow specific networks out (or you might find yourself a transit...
  11. Frenchie2069

    config for 1721

    It probably doesn't matter which interface is used for the WAN connection, but I would probably use the 10 Mb. If you think about it though, the router will only be processing packets that are traversing from the inside to the outside (or vice versa) so the bottleneck will be the 10 Mb no...
  12. Frenchie2069

    Help securing a 1721

    You could do that, but it shouldn't be necessary with the CBAC (Context Based Access Control) features of the firewall feature set. Basically, CBAC adds entries to the top of your access-list to permit replies to conversations that were initiated from inside the router (or any interface that has...
  13. Frenchie2069

    Help securing a 1721

    I usually put the deny 80 in because of the number of viruses that scan the internet looking for vulnerable IIS servers. If you leave that out it will still be blocked by the last line (deny any any log) but it will be sent to the log as well. What is in the log (show log) when the access-list...
  14. Frenchie2069

    Help securing a 1721

    You need to configure your firewall feature set first. A simple configuration would be: ip inspect name InternetIN http ip inspect name InternetIN smtp ip inspect name InternetIN tcp ip inspect name InternetIN udp ip inspect name InternetOUT http ip inspect name InternetOUT...
  15. Frenchie2069

    cisco router 1721 configuration

    If it is just a leased line then all you need to do is configure an IP Address on each interface and configure routing (using static routes or with a dynamic protocol such as EIGRP). Cheers, Michael.
  16. Frenchie2069

    2501 and 1912 (trunk)

    You are correct, you need a 100 Mb interface to do trunking. The command you need to use on the subinterface is encapsulation dot1q x - where x is the vLAN number. Also, I am not sure that the 1900 series switches do trunking - you should check this. Cheers, Michael.
  17. Frenchie2069

    Cisco 2501 and nokia ip650

    You don't actually need to use NAT on the Cisco in this configuration. You can use the addresses as they are and just add a static route on the Cisco: ip route x.x.x.x 255.255.255.y 10.0.0.2 The source address of your packets will be fixed by the Nokia. The 10 subnet just becomes a transit...
  18. Frenchie2069

    Subnetting a Class C on same Router

    I assume that the /24 is configured on your external interface (E0) and you want to use it on your internal interface (E1)? The best thing to do in this case is a 1 to 1 NAT, this way you will be able to use all of the addresses. HTH, Michael.
  19. Frenchie2069

    Tacacs+ and Groups

    You should be able to put the users into groups and restrict the list of allowed NAS for each group. This works on the Windows version, I have never used the linux version HTH, Michael.
  20. Frenchie2069

    NATing to 2 different Interfaces with 2 different address pools

    Are the 2 Serial interfaces your external interfaces? Do you only have 1 internal interface?

Part and Inventory Search

Back
Top