Stie to Site VPN for a Cisco 5505 ASA , should connect but doesn't

Ok I have gone through the asdm wizard I have created the VPN and the damn thing should work but is not. I am posting my config here for you guys to tell me if I am missing something. I need PFS on the first phase but not the second one, and have no idea how to tell on an ASA 5505. If you need anything else let me know.

UPDATE: Just after I posted this I noticed that my IKE for outside interface was turned off, so I turned it on that let me get a IKE tunnel up but then fails at the IPSEC tunnel.

Thanks
Bill

hostname ciscoasa
domain-name default.domain.invalid
enable password NuLKv.x9HEKO encrypted
names
!
interface Vlan1
 nameif inside
 security-level 100
 ip address 192.168.21.180 255.255.255.0
!
interface Vlan2
 nameif outside
 security-level 0
 ip address 201.120.12.233 255.255.255.248
!
interface Ethernet0/0
 switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
passwd 2KFQnb2K encrypted
ftp mode passive
dns server-group DefaultDNS
 domain-name default.domain.invalid
object-group network MOBILE
 network-object 192.168.170.0 255.255.255.224
access-list outside_access_in extended permit tcp any interface outside eq 3399

access-list outside_access_in extended permit udp any host 201.120.12.233 eq 22

access-list outside_access_in extended permit tcp any host 201.120.12.233 eq ssh

access-list outside_access_in extended permit tcp any range pop3 pop3 interface
outside range pop3 pop3
access-list outside_access_in extended permit tcp any range smtp smtp interface
outside range smtp smtp
access-list outside_access_in extended permit tcp any interface outside eq smtp

access-list outside_access_in extended permit tcp any interface outside eq pop3

access-list inside_nat0_outbound_1 extended permit ip 192.168.21.0. 255.255.255.0
host 172.21.65.128
access-list outside_1_cryptomap extended permit ip 192.168.21.0. 255.255.255.0 172
.21.65.128 255.255.255.224
access-list inbound extended permit tcp any any eq smtp
access-list inbound extended permit icmp any any
access-list inside_nat0_outbound extended permit ip 192.168.21.0. 255.255.255.0 ho
st 172.21.65.128
access-list inside_access_in extended permit ip any any
pager lines 24
logging enable
logging asdm informational
mtu inside 1500
mtu outside 1500
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-523.bin
no asdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 0 access-list inside_nat0_outbound_1
nat (inside) 1 0.0.0.0 0.0.0.0
static (inside,outside) udp interface 22 192.168.21.210 22 netmask 255.255.255.25
5
static (inside,outside) tcp interface ssh 192.168.21.210 ssh netmask 255.255.255.
255
static (inside,outside) tcp interface 4810 192.168.21.210 4810 netmask 255.255.25
5.255
static (inside,outside) tcp interface 3399 192.168.21.45 3399 netmask 255.255.255
.255
static (inside,outside) tcp interface pop3 192.168.21.45 pop3 netmask 255.255.255
.255
static (inside,outside) udp 201.120.12.233 110 192.168.21.45 110 netmask 255.255.
255.255
static (inside,outside) tcp interface smtp 192.168.21.45 smtp netmask 255.255.255
.255
access-group outside_access_in in interface outside
route outside 0.0.0.0 0.0.0.0 206.127.13.241 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout uauth 0:05:00 absolute
http server enable
http 192.168.21.0. 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto map outside_map 1 match address outside_1_cryptomap
crypto map outside_map 1 set pfs
crypto map outside_map 1 set peer 204.8.56.125
crypto map outside_map 1 set transform-set ESP-3DES-MD5
crypto map outside_map 1 set nat-t-disable
crypto map outside_map interface outside
crypto isakmp policy 10
 authentication pre-share
 encryption 3des
 hash md5
 group 2
 lifetime 3600
telnet timeout 5
ssh timeout 5
console timeout 0
dhcpd auto_config outside
!
dhcpd address 192.168.1.2-192.168.1.129 inside
!

!
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect sqlnet
  inspect skinny
  inspect sunrpc
  inspect xdmcp
  inspect sip
  inspect netbios
  inspect tftp
!
service-policy global_policy global
group-policy DfltGrpPolicy attributes
 banner none
 wins-server none
 dns-server none
 dhcp-network-scope none
 vpn-access-hours none
 vpn-simultaneous-logins 3
 vpn-idle-timeout 30
 vpn-session-timeout none
 vpn-filter none
 vpn-tunnel-protocol IPSec l2tp-ipsec
 password-storage disable
 ip-comp disable
 re-xauth disable
 group-lock none
 pfs disable
 ipsec-udp disable
 ipsec-udp-port 10000
 split-tunnel-policy tunnelall
 split-tunnel-network-list none
 default-domain none
 split-dns none
 intercept-dhcp 255.255.255.255 disable
 secure-unit-authentication disable
 user-authentication disable
 user-authentication-idle-timeout 30
 ip-phone-bypass disable
 leap-bypass disable
 nem disable
 backup-servers keep-client-config
 msie-proxy server none
 msie-proxy method no-modify
 msie-proxy except-list none
 msie-proxy local-bypass disable
 nac disable
 nac-sq-period 300
 nac-reval-period 36000
 nac-default-acl none
 address-pools none
 smartcard-removal-disconnect enable
 client-firewall none
 client-access-rule none
 webvpn
  functions url-entry
  html-content-filter none
  homepage none
  keep-alive-ignore 4
  http-comp gzip
  filter none
  url-list none
  customization value DfltCustomization
  port-forward none
  port-forward-name value Application Access
  sso-server none
  deny-message value Login was successful, but because certain criteria have not
 been met or due to some specific group policy, you do not have permission to us
e any of the VPN features. Contact your IT administrator for more information
  svc none
  svc keep-installer installed
  svc keepalive none
  svc rekey time none
  svc rekey method none
  svc dpd-interval client none
  svc dpd-interval gateway none
  svc compression deflate
tunnel-group 204.8.56.125 type ipsec-l2l
tunnel-group 204.8.56.125 ipsec-attributes
 pre-shared-key *
 isakmp keepalive disable
prompt hostname context
no compression svc http-comp
Cryptochecksum:5ec712a9e71f712171eb60ff0cc01dde
ciscoasa(config)#
maxeybAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

maxeybAuthor Commented:
Update: I have both tunnels up now, I turned off PFS on the IPSEC tunnel but I am not able to ping or send data.

Thanks
Bill
0
RustyZ32Commented:
your nat exemption ACL doesnt looke right try this:

no access-list inside_nat0_outbound_1 extended permit ip 192.168.21.0. 255.255.255.0
host 172.21.65.128

replace with:

access-list inside_nat0_outbound_1 extended permit ip 192.168.21.0. 255.255.255.0 172.21.65.128 255.255.255.224


also remove:

no crypto map outside_map 1 set nat-t-disable







0
maxeybAuthor Commented:
The tunnels have both dropped now and I can't get them back up. Not sure why here is an updated config.

Thanks
Bill

names
!
interface Vlan1
 nameif inside
 security-level 100
 ip address 192.168.1.200 255.255.255.0
!
interface Vlan2
 nameif outside
 security-level 0
 ip address 201.120.12.233 255.255.255.248
!
interface Ethernet0/0
 switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
passwd 2KFQnbN.2KYOU encrypted
ftp mode passive
dns server-group DefaultDNS
 domain-name default.domain.invalid
access-list outside_access_in extended permit tcp any interface outside eq 3399

access-list outside_access_in extended permit udp any host 201.120.12.233 eq 22

access-list outside_access_in extended permit tcp any host 201.120.12.233 eq ssh

access-list outside_access_in extended permit tcp any range pop3 pop3 interface
outside range pop3 pop3
access-list outside_access_in extended permit tcp any range smtp smtp interface
outside range smtp smtp
access-list outside_access_in extended permit tcp any interface outside eq smtp

access-list outside_access_in extended permit tcp any interface outside eq pop3

access-list inside_nat0_outbound_1 extended permit ip 192.168.21.0 255.255.255.0
172.21.65.128 255.255.255.224
access-list outside_1_cryptomap extended permit ip host 192.168.21.0 172.21.65.12
8 255.255.255.224
access-list inbound extended permit tcp any any eq smtp
access-list inbound extended permit icmp any any
access-list inside_nat0_outbound extended permit ip 192.168.21.0 255.255.255.0 ho
st 172.21.65.128
access-list inside_access_in extended permit ip any any
pager lines 24
logging enable
logging asdm informational
mtu inside 1500
mtu outside 1500
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-523.bin
no asdm history enable
arp timeout 14400
nat-control
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0
static (inside,outside) udp interface 22 192.168.21.210 22 netmask 255.255.255.25
5
static (inside,outside) tcp interface ssh 192.168.21.210 ssh netmask 255.255.255.
255
static (inside,outside) tcp interface 4810 192.168.21.210 4810 netmask 255.255.25
5.255
static (inside,outside) tcp interface 3399 192.168.21.45 3399 netmask 255.255.255
.255
static (inside,outside) tcp interface pop3 192.168.21.45 pop3 netmask 255.255.255
.255
static (inside,outside) udp 201.120.12.233 110 192.168.21.45 110 netmask 255.255.
255.255
static (inside,outside) tcp interface smtp 192.168.21.45 smtp netmask 255.255.255
.255
access-group outside_access_in in interface outside
route outside 0.0.0.0 0.0.0.0 206.127.13.241 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout uauth 0:05:00 absolute
http server enable
http 192.168.21.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto map outside_map 1 match address outside_1_cryptomap
crypto map outside_map 1 set peer 204.8.56.125
crypto map outside_map 1 set transform-set ESP-3DES-MD5
crypto map outside_map interface outside
crypto isakmp enable inside
crypto isakmp enable outside
crypto isakmp policy 10
 authentication pre-share
 encryption 3des
 hash md5
 group 2
 lifetime 28800
telnet timeout 5
ssh timeout 5
console timeout 0
dhcpd auto_config outside
!

!
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect sqlnet
  inspect skinny
  inspect sunrpc
  inspect xdmcp
  inspect sip
  inspect netbios
  inspect tftp
!
service-policy global_policy global
group-policy DfltGrpPolicy attributes
 banner none
 wins-server none
 dns-server none
 dhcp-network-scope none
 vpn-access-hours none
 vpn-simultaneous-logins 3
 vpn-idle-timeout 30
 vpn-session-timeout none
 vpn-filter none
 vpn-tunnel-protocol IPSec l2tp-ipsec
 password-storage disable
 ip-comp disable
 re-xauth disable
 group-lock none
 pfs disable
 ipsec-udp disable
 ipsec-udp-port 10000
 split-tunnel-policy tunnelall
 split-tunnel-network-list none
 default-domain none
 split-dns none
 intercept-dhcp 255.255.255.255 disable
 secure-unit-authentication disable
 user-authentication disable
 user-authentication-idle-timeout 30
 ip-phone-bypass disable
 leap-bypass disable
 nem disable
 backup-servers keep-client-config
 msie-proxy server none
 msie-proxy method no-modify
 msie-proxy except-list none
 msie-proxy local-bypass disable
 nac disable
 nac-sq-period 300
 nac-reval-period 36000
 nac-default-acl none
 address-pools none
 smartcard-removal-disconnect enable
 client-firewall none
 client-access-rule none
 webvpn
  functions url-entry
  html-content-filter none
  homepage none
  keep-alive-ignore 4
  http-comp gzip
  filter none
  url-list none
  customization value DfltCustomization
  port-forward none
  port-forward-name value Application Access
  sso-server none
  deny-message value Login was successful, but because certain criteria have not
 been met or due to some specific group policy, you do not have permission to us
e any of the VPN features. Contact your IT administrator for more information
  svc none
  svc keep-installer installed
  svc keepalive none
  svc rekey time none
  svc rekey method none
  svc dpd-interval client none
  svc dpd-interval gateway none
  svc compression deflate
tunnel-group 204.8.56.125 type ipsec-l2l
tunnel-group 204.8.56.125 ipsec-attributes
 pre-shared-key *
 isakmp keepalive disable
prompt hostname context
no compression svc http-comp
Cryptochecksum:358dfde193017b6e61998189
0
Introducing the "443 Security Simplified" Podcast

This new podcast puts you inside the minds of leading white-hat hackers and security researchers. Hosts Marc Laliberte and Corey Nachreiner turn complex security concepts into easily understood and actionable insights on the latest cyber security headlines and trends.

RustyZ32Commented:
nat (inside) 0 access-list inside_nat0_outbound_1  

put that back in.
0
maxeybAuthor Commented:
The IKE and IPSEC tunnel are still both down.

Thanks
Bill
0
RustyZ32Commented:
no access-list outside_1_cryptomap extended permit ip host 192.168.21.0 172.21.65.12
8 255.255.255.224

access-list outside_1_cryptomap extended permit ip 192.168.21.0 255.255.255.0 172.21.65.12
8 255.255.255.224


no crypto isakmp enable inside



make sure the transform-sets  and the crypto isakmp policy's match exactly on both ends

also the outside_1_cryptomap needs to be the exact opposite on the other end:

access-list outside_1_cryptomap extended permit ip 172.21.65.12 255.255.255.224 192.168.21.0 255.255.255.255


do the same for the nat0_outbound list on the other end.





0
maxeybAuthor Commented:
Hey Rusty,

sorry I am a bit slow today something to do with 2 hours of sleep in the last 2 days. but can you go into a little more detail about.

make sure the transform-sets  and the crypto isakmp policy's match exactly on both ends

also the outside_1_cryptomap needs to be the exact opposite on the other end:

access-list outside_1_cryptomap extended permit ip 172.21.65.12 255.255.255.224 192.168.21.0 255.255.255.255

do the same for the nat0_outbound list on the other end.

BTW here is an updated config.

names
!
interface Vlan1
 nameif inside
 security-level 100
 ip address 192.168.1.200 255.255.255.0
!
interface Vlan2
 nameif outside
 security-level 0
 ip address 210.127.13.240 255.255.255.248
!
interface Ethernet0/0
 switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
passwd 2KFQnbNIdI.2KYOU encrypted
ftp mode passive
dns server-group DefaultDNS
 domain-name default.domain.invalid
access-list outside_access_in extended permit tcp any interface outside eq 3399

access-list outside_access_in extended permit udp any host 210.127.13.240 eq 22

access-list outside_access_in extended permit tcp any host 210.127.13.240 eq ssh

access-list outside_access_in extended permit tcp any range pop3 pop3 interface
outside range pop3 pop3
access-list outside_access_in extended permit tcp any range smtp smtp interface
outside range smtp smtp
access-list outside_access_in extended permit tcp any interface outside eq smtp

access-list outside_access_in extended permit tcp any interface outside eq pop3

access-list inbound extended permit tcp any any eq smtp
access-list inbound extended permit icmp any any
access-list inside_access_in extended permit ip any any
access-list outside_1_cryptomap extended permit ip 192.168.21.0 255.255.255.0 172
.21.65.128 255.255.255.224
access-list inside_nat0_outbound extended permit ip host 192.168.21.0 172.21.65.1
28 255.255.255.224
pager lines 24
logging enable
logging asdm informational
mtu inside 1500
mtu outside 1500
icmp unreachable rate-limit 1 burst-size 1
asdm image disk0:/asdm-523.bin
no asdm history enable
arp timeout 14400
nat-control
global (outside) 1 interface
nat (inside) 0 access-list inside_nat0_outbound
nat (inside) 1 0.0.0.0 0.0.0.0
static (inside,outside) udp interface 22 192.168.21.210 22 netmask 255.255.255.25
5
static (inside,outside) tcp interface ssh 192.168.21.210 ssh netmask 255.255.255.
255
static (inside,outside) tcp interface 4810 192.168.21.210 4810 netmask 255.255.25
5.255
static (inside,outside) tcp interface 3399 192.168.21.45 3399 netmask 255.255.255
.255
static (inside,outside) tcp interface pop3 192.168.21.45 pop3 netmask 255.255.255
.255
static (inside,outside) udp 210.127.13.240 110 192.168.21.45 110 netmask 255.255.
255.255
static (inside,outside) tcp interface smtp 192.168.21.45 smtp netmask 255.255.255
.255
access-group outside_access_in in interface outside
route outside 0.0.0.0 0.0.0.0 206.127.13.241 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout uauth 0:05:00 absolute
http server enable
http 192.168.21.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
crypto map outside_map 1 set peer 204.8.56.125
crypto map outside_map 1 set transform-set ESP-3DES-MD5
crypto map outside_map 1 set nat-t-disable
crypto map outside_map interface outside
crypto isakmp enable outside
crypto isakmp policy 10
 authentication pre-share
 encryption 3des
 hash md5
 group 2
 lifetime 28800
telnet timeout 5
ssh timeout 5
console timeout 0

!
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
 parameters
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect sqlnet
  inspect skinny
  inspect sunrpc
  inspect xdmcp
  inspect sip
  inspect netbios
  inspect tftp
!
service-policy global_policy global
group-policy DfltGrpPolicy attributes
 banner none
 wins-server none
 dns-server none
 dhcp-network-scope none
 vpn-access-hours none
 vpn-simultaneous-logins 3
 vpn-idle-timeout 30
 vpn-session-timeout none
 vpn-filter none
 vpn-tunnel-protocol IPSec
 password-storage disable
 ip-comp disable
 re-xauth disable
 group-lock none
 pfs disable
 ipsec-udp disable
 ipsec-udp-port 10000
 split-tunnel-policy tunnelall
 split-tunnel-network-list none
 default-domain none
 split-dns none
 intercept-dhcp 255.255.255.255 disable
 secure-unit-authentication disable
 user-authentication disable
 user-authentication-idle-timeout 30
 ip-phone-bypass disable
 leap-bypass disable
 nem disable
 backup-servers keep-client-config
 msie-proxy server none
 msie-proxy method no-modify
 msie-proxy except-list none
 msie-proxy local-bypass disable
 nac disable
 nac-sq-period 300
 nac-reval-period 36000
 nac-default-acl none
 address-pools none
 smartcard-removal-disconnect enable
 client-firewall none
 client-access-rule none
 webvpn
  functions url-entry
  html-content-filter none
  homepage none
  keep-alive-ignore 4
  http-comp gzip
  filter none
  url-list none
  customization value DfltCustomization
  port-forward none
  port-forward-name value Application Access
  sso-server none
  deny-message value Login was successful, but because certain criteria have not
 been met or due to some specific group policy, you do not have permission to us
e any of the VPN features. Contact your IT administrator for more information
  svc none
  svc keep-installer installed
  svc keepalive none
  svc rekey time none
  svc rekey method none
  svc dpd-interval client none
  svc dpd-interval gateway none
  svc compression deflate
tunnel-group 204.8.56.125 type ipsec-l2l
tunnel-group 204.8.56.125 ipsec-attributes
 pre-shared-key *
 isakmp keepalive disable
prompt hostname context
no compression svc http-comp
Cryptochecksum:736da5e0e7a2d0b37c75669642f5fd55
ciscoasa(config)#
0
vreinaldoCommented:
Hi there,

If this is a site to site tunnel, is better that you post both config, to see wheres is the mismatch, but, a you said in your first post, the tunnels where up, but no traffic is passing, anyways i checked your config, and to this device, you HAVE to make this:

no access-list inside_nat0_outbound extended permit ip host 192.168.21.0 172.21.65.128 255.255.255.224
access-list inside_nat0_outbound extended permit ip 192.168.21.0 255.255.255.0 172.21.65.128 255.255.255.224
nat (inside) 0 access-list inside_nat0_outbound !(This is in the config, but every time you delete an access list from the config it disappear in the rest of it, so you have to write it back just FYI)

and:

crypto map outside_map 1 match address outside_1_cryptomap !(i could not see it anywhere in your last config post, so you need this in order to make the tunnels UP...)

If your tunnels are back UP, but no traffic is passing keep reading.

Make sure that both sites have the NONAT statement like this:

(SITE A) --> The one that is posted in here.

access-list inside_nat0_outbound extended permit ip 192.168.21.0 255.255.255.0 172.21.65.128 255.255.255.224
nat (inside) 0 access-list inside_nat0_outbound


(SITE B) --> The remote one that we haven't see yet

access-list inside_nat0_outbound extended permit ip 172.21.65.128 255.255.255.224 192.168.21.0 255.255.255.0
nat (inside) 0 access-list inside_nat0_outbound

Good luck!!



0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
maxeybAuthor Commented:
I am splitting the points, the last poster had the finally solutions but rusty had some stuff I needed as well. Thanks for all the help.

Thanks

Bill
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Routers

From novice to tech pro — start learning today.