Cisco

23K

Solutions

14K

Contributors

Cisco PIX is a dedicated hardware firewall appliance; the Cisco Adaptive Security Appliance (ASA) is a firewall and anti-malware security appliance that provides unified threat management and protection the PIX does not. Other Cisco devices and systems include routers, switches, storage networking, wireless and the software and hardware for PIX Firewall Manager (PFM), PIX Device Manager (PDM) and Adaptive Security Device Manager (ASDM).

Share tech news, updates, or what's on your mind.

Sign up to Post

Calling on all Cisco CUBE Experts;
CUBE setup for SIP trunking that that talks to the provider's SBC missing SIP port (5060) in the SIP URI, can anyone shine light on why it is happening? Is there a tweak or hack
someone can suggest ? The IP address is coming fine, BTW.

Thanks;
0
Become an IT Security Management Expert
Become an IT Security Management Expert

In today’s fast-paced, digitally transformed world of business, the need to protect network data and ensure cloud privacy has never been greater. With a B.S. in Network Operations and Security, you can get the credentials it takes to become an IT security management expert.

Hello

I connect to a remote computer with an IP Address of 10.x.x.x via Cisco Anyconnect Secure Mobility Client on a Windows 10 pro host with IP Address of 192.168.1.xx. I need a virtual machine with Windows 10 Pro (VM Workstation) currently IP Address of 192.168.1.x on the Windows 10 Pro Host to access that computer. I can ping the remote computer on the Host, but not on the vm workstation. I tried installing the Cisco Anyconnect Secure Mobility Client on the VM, and it connects, but I still can't ping the remote computer. I tried setting tweaking the VM Workstation's network adapter to Bridged, Bridged with replicate physical network state, NAT, Host Only, but no ping. I turned off Firewalls on Host and VM....

Thank you!
0
Hi,

We have a main Cisco 3750 Switch. From that switch fiber connections run from the trunk ports to different stacks, essentially all other stacks connect back to this switch. We want to add a backup to this switch in case of hardware failure. Question how do we add it.
1. Do we add it as a second switch in Slave role or is there another way adding it.
2. Also if the first switch does go down, how do we prepare the second switch so that the trunk port are ready to accept the fiber cables
0
Hey Guys,

 I am a complete newbie to Cisco so excuse my ignorance,

I have just setup the device and want the Outside interface  to receive traffic from my  home Netgear broadband router and then pass it through to inside interface.

How do i go about doing this? I have tried different ways but none seem to work.

All I want is the ASA to act as the firewall.

current setup is as follows



Netgear Router / Modem 10.0.1.1 (gets dynamic ip from ISP using PPPOA and does the NAT) Please note my router does NOT have bridge mode option
ASA 5506 Outside Interface ip 10.0.1.7 (Static)
ASA 5506 Inside Interface ip 192.168.1.1

The bit i can't work out it adding static routes and do I need to NAT on the ASA as the router already does that

Thanks
J
0
1. What are the GRC (SIEM) tools available?
2. Diff. between SIEM tools and CISCO Meraki?
0
Dear Experts, is there any simulation apps (such as EVE-NG, GNS3, packet tracer) which can represent the stacking process of Cisco switch? or HP aruba switch?
Many thanks!
0
Cisco 800

need help whit nat translation


i set u the nat to Dialer0 but the wan wont let me get a ping to 8.8.8.8

--------------------------------------------show run
hostname G1_router
!
ip source-route

!
ip dhcp pool ccp-pool
 dns-server 10.10.10.1
!

interface Vlan1
 ip address 10.10.10.200 255.255.255.0
!
interface Dialer0
 description *** WAN ***
 mtu 1492
 ip address negotiated
 encapsulation ppp
 dialer pool 1
 ppp authentication chap callin
 ppp chap hostname *****@EDPNETFIX
 ppp chap password 0 ******
 ppp ipcp dns request
!
ip route 0.0.0.0 255.0.0.0 Dialer0
!
0
TFTP connections, I just opened my tftp software, as I needed to save a switch config and I'm seeing tons of these entries in my tftp server.
Does anyone know what these are?  I haven't configured any switch to automatically backup configs or anything.
tftp
0
Hi - Currently we have several Cisco 2960-24PC-S switches at a location, and we are upgrading them to Cisco WS-C2960X-24PD-L gigabit switches. I haven't worked on Ciscos in about 15 years. Does anyone have an easy, preferable way to backup/restore the running config? Any info would be helpful. Thanks in advance!
0
What is the best way to configure the following on an asa 9.x code

There is a l2lvpn between vendor and corp the vendor ip source is 192.168.100.103  (up and working able to ping 10.52.176.x network)

This is part I am unclear on and need help

vendor needs to connect to (3 rd party )using 10.52.176.34 as the source ip
10.52 176 34 ports 2930 tcp/udp needs to be fowarded to 172.16.31.135 (3 rd party)
10.52.176.34 ports 3150 tcp/udp needs to be forwarded to 172.16.30.216 (3 rd party)

MORE INFORMATION ABOUT SETUP

(3 rd party) 172.16.31.135 and 172.16.30.216 are routable networks from a router 10.52.176.11 (local) which is pingable from all other subnets local

(3 rd party) only accepts traffic from 10.52.176.x  networkvisual
0
Cloud Class® Course: Microsoft Office 2010
LVL 12
Cloud Class® Course: Microsoft Office 2010

This course will introduce you to the interfaces and features of Microsoft Office 2010 Word, Excel, PowerPoint, Outlook, and Access. You will learn about the features that are shared between all products in the Office suite, as well as the new features that are product specific.

Hi all,

We have Cisco 5505 with new layer 3 switch to be installed as main switch and 2x other layer 2 switches to piggy back from it.

The plan is to have multi-vlan to separate the teams in the offices.

vlan ideas

10 - shared resources (printers, scanners)
11 - Team 1
12 - Team 2
13 - Team 3
14 - DMZ network (Accessible by vlan 13 only)
20 - Internal Wifi (accessible to vlan 10 and 13)
21 - Guest Wifi (accessible to public internet only)

DHCP to be configured on the main layer 3 switch.

Question here is by configuring each vlans in the main switch would I need physical port on the firewall as the gateway for each vlan?
or can it route to go through the same port on the firewall?
0
I have a cisco 3750G switch that for some strange reason, all of a sudden my trunk port, that is the link to the other switch just stopped working.
I have restarted the switch, works fine for a few hours and then shut off again.  I don't get any errors in the logs, just dies, any idea how to troubleshoot?
0
Hello,

We're in the process of configuring a Cisco CSR router within Azure. Users connect to the Cisco CSR router via the AnyConnect VPN client and authenticate via Azure MFA. Users are able to connect to the VPN and authenticate successfully with Azure MFA. However, we are unable to connect to any devices/services within Azure once we are connected to VPN. The Cisco CSR router can ping all devices/services within Azure without any issues, but users are unable to communicate with any devices/services while connected via VPN.

Any ideas?

Thanks!
0
Hello Experts-
We have subscribed to MPLS IPVPN via Service Provide to connect our branch offices with HQ.
We have been given /30 subnet at HQ and each offices and running BGP between CE Router and ISP. We suppose to send the routes to ISP and then take will foreward via MPLS Cloud.

We want to install firewall at the HQ between MPLS Router and L3 Switch.

I am just concerned what routing protocol I should between MPLS Router and L3 Switch at HQ so that all HQ hosts can reach to branch offices.. Shall I used IGP or Static Routes ?
How to inject the routes from MPLS routes to firewall ? Is it advisable to run a routing protocol between them
How I can achieve redudancy if a router or firewall fails in HQ Office.

I am attaching a basic design.
Any suggestions and comments are welcome.
0
Hi ,

we have subsidiary company with around 150 Users . it is linked to us (HO ) over IPVPN (1 MB)  and services getted from Us are :

1- CISCO IP telephone ( currently around 75 Users)
2- ERP ( about 50 USers)

thier existign Setup :

1- Domain COntroller ( seprate totally from us ) + Antivirus server ( 1 physical box)
2-finance system
3-Backup Server
4-Sonicwall NSA2600
5-Switches
7-Router for IPVPN

the managment is thinking to host the setup for the subsidary company so my questions are:

1- how I can do the proper sizing for the link ? so i ensure the users are not feeling slowness
2-what equipment should i move from there and what i should not ? best desing fro myour experince
3- how the internet should be provided to thier users ? from us or locally ?
4- what are the adv and disadvanage for such plan? should we recommend this plan or let them continue as they are
5- risks?
6- what are the pre requisits needed in the HO Data Center for hosting those equipment
0
All of a suddent, I'm getting these error messages and I'm not sure why.  It's not giving me the IP address of the other switch, I'm not sure what the T46.... number referenced is?
Any thoughts?

cisco
1
I need help converting a NAT policy from ASA ASDM to Cisco FTD. Before anyone recommends using the convert tool, the ASA version is too old to convert.

Here is my original ASDM rule:
Original ASDM rule that needs converted
I need to configure that rule on the FTD which has quite a few more options. Any help would be greatly appreciated.
How the NAT rules look on FTD
0
Ruckus Wireless ZoneFlex R500 Wireless Access Point  does not power up.  It does not come POE injector.  I plugged it into the Cisco POE switch but still no LED lights.   I also used the same ethernet cable to test connectivity issues with my laptop.  No problems there.   Thoughts?  Also, Amazon purchases void all warranty support...  Fun stuff!
0
Hi,

I have a Cisco 890 with IOS 15. Please help me solve the following two problems related to NAT.

1. I would like to access a NVR from both inside and outside the network using the same public IP.
2. I would like to access internal VLANs without any NAT between them.

If I configure ip nat enable, the first problem gets solved but the second does not.
If I configure ip nat inside/outside, the second problem gets solved but the first one does not.

Following is the configuration.

interface Null0
 no ip unreachables
!
interface ATM0
 no ip address
 shutdown
 no atm ilmi-keepalive
!
interface BRI0
 no ip address
 encapsulation hdlc
 shutdown
 isdn termination multidrop
!
interface Ethernet0
 no ip address
 shutdown
!
interface GigabitEthernet0
 switchport mode trunk
 no ip address
!
interface GigabitEthernet1
 switchport access vlan 10
 no ip address
!
interface GigabitEthernet2
 switchport access vlan 10
 no ip address
!
interface GigabitEthernet3
 switchport access vlan 10
 no ip address
 spanning-tree portfast
!
interface GigabitEthernet4
 switchport access vlan 10
 no ip address
 spanning-tree portfast
!
interface GigabitEthernet5
 switchport access vlan 10
 no ip address
 spanning-tree portfast
!
interface GigabitEthernet6
 switchport access vlan 10
 no ip address
 spanning-tree portfast
!
interface GigabitEthernet7
 switchport access vlan 10
 no ip address
 spanning-tree portfast
!
interface …
0
Cloud Class® Course: CompTIA Healthcare IT Tech
LVL 12
Cloud Class® Course: CompTIA Healthcare IT Tech

This course will help prep you to earn the CompTIA Healthcare IT Technician certification showing that you have the knowledge and skills needed to succeed in installing, managing, and troubleshooting IT systems in medical and clinical settings.

Hello Experts,

We have 4 Ethernet Point 2 Point link between my 2 branch office location 1 & location 2 distance between both office is 1430 KM
and getting end to end latency 25-32 ms. From both sides all links connected with Cisco 2811 Router (HWIC Port) & configure as a eigrp 100

once i send traffic (download or upload) from location 1 to location 2 why its using only one interface, it should be distributed & forwarded from using
all 4 interfaces as a single (marge) speed.

please suggest configuration to forward traffic using all interface as a equal- equal bandwidth

 
Location 1 Router

interface FastEthernet0/0
 ip address 192.168.10.1 255.255.255.0
 ip flow ingress
 duplex auto
 speed auto
!
interface FastEthernet0/1
 description 4MBPS Link
 ip address 1.1.1.1 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/0/0
 description 2 MBPS Link
 ip address 2.2.2.1 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/0/1
 description 2 MBPS Link
 ip address 3.3.3.1 255.255.255.0
 duplex auto
 speed auto
!
interface FastEthernet0/1/0
 description 2 MBPS Link
 ip address 4.4.4.1 255.255.255.0
 duplex auto
 speed auto
!
!
router eigrp 100
 network 1.1.1.0 0.0.0.3
 network 2.2.2.0 0.0.0.3
 network 3.3.3.0 0.0.0.3
 network 4.4.4.0 0.0.0.3
 network 192.168.10.0


 
Location 2 Router
 
 interface FastEthernet0/0
 ip address 192.168.207.1 255.255.255.0
 duplex auto
 …
0
My customer has 1 pair of Cisco N5K configured with VPC.

I going to deploy 1 DellEMC Unity 300 storage to their infra. The Unity 300 will serve as their NFS server.
The proposed interface configuration is LACP on Unity 300.
which mean from SPA, I will have 1 connection to their first N5K switch and another connection to their second N5K.

I just want to know is this doable? from what I understand, VPC is 2 separated switch unlike stacked.

thanks
0
Hi experts,

I connect to VPN to a clients environment via Cisco AnyConnect Secure Mobility Client.  Once connected I then remote desktop into the machine at the client and I can work etc.

Whenever I do this I lose all internet access from the laptop I connect through at my home.  So I can't have an email client running locally as it will not connect to email server.  I can't minimize the remote desktop and browse internet with a local browser.  It's like it completely takes over my internet for some reason.

So I created a new VM via VMWare and thought I would just use the VM to vpn into the client as the VM should share the internet connection.   To my surprise, even when I do that, the internet will not work on my local machine.  The VM completely takes over my entire internet once I connect to Cisco AnyConnect.

I figure this is probably security related but is there anywhere or any setting I can do so it shares the connection?

Or in VMWare something where it won't allow it to take over entire connection?

Thanks for any inisight.
0
blocking webmail on Cisco Umbrella but allowing gmail, office365 links

the problem is i am allowing gmail.com and mail.google.com but when i block the webmail category it also blocks gmail. can idea what other url i need to allow?
0
Hi,

We have a switch stack of 7 3750 switches. One switch just seemed to stop working, still has power. After restart, using the sh switch command, the switch seems to be stuck at initializing, after restart the of the stack, the switch shows ready. Its a POE switch and plugging a phone directly into the switch, no power. However plugging in a laptop works, data is working just not power no data. I used some basic commands, show config, ver, vlan, int and compared the configs to the other switches and everything looks good.  The switch in question has no error using sh int. Any suggestions greatly appreciated. Below is a output from sh int, for the switch in question,  all ports are shown the same.

FastEthernet5/0/20 is down, line protocol is down (notconnect)
  Hardware is Fast Ethernet, address is 0017.94b5.d016 (bia 0017.94b5.d016)
  MTU 1500 bytes, BW 10000 Kbit, DLY 1000 usec,
     reliability 255/255, txload 1/255, rxload 1/255
  Encapsulation ARPA, loopback not set
  Keepalive set (10 sec)
  Auto-duplex, Auto-speed, media type is 10/100BaseTX
  input flow-control is off, output flow-control is unsupported
  ARP type: ARPA, ARP Timeout 04:00:00
  Last input never, output never, output hang never
  Last clearing of "show interface" counters never
  Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 0 bits/sec, 0 packets/sec
  5 minute output rate 0 …
0
Can someone tell me where I can find autonomous code for a 3800 series Cisco access point?
0

Cisco

23K

Solutions

14K

Contributors

Cisco PIX is a dedicated hardware firewall appliance; the Cisco Adaptive Security Appliance (ASA) is a firewall and anti-malware security appliance that provides unified threat management and protection the PIX does not. Other Cisco devices and systems include routers, switches, storage networking, wireless and the software and hardware for PIX Firewall Manager (PFM), PIX Device Manager (PDM) and Adaptive Security Device Manager (ASDM).