<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Cisco forum - dslreports.com community</title>
<link>http://www.dslreports.com/forum/equip,cis</link>
<description>Cisco forum current topics</description>
<language>en</language>
<copyright>Copyright 2007, dslreports.com</copyright>
<pubDate>Sat, 21 Nov 2009 22:28:50 EDT</pubDate>
<lastBuildDate>Sat, 21 Nov 2009 22:28:50 EDT</lastBuildDate>

<image>
<title>dslreports.com</title>
<url>http://i.dslr.net/bbrdisc1.gif</url>
<link>http://www.dslreports.com</link>
<width>19</width>
<height>18</height>
<description>bbr disc</description>
</image>

<item>
<title>Vlan Assignments issues on ASA5505-SEC-BUN-K9</title>
<link>http://www.dslreports.com/forum/remark,23375506</link>
<description><![CDATA[I'm trying to setup a new ASA5505-SEC-BUN-K9 but seem to be having issues assigning VLANs to ethernet ports 1-7

Using the command line you can assign port-0 (outside) to VLAN2. Ports 1-7 are on the inside are to take up VLAN1.Even though the virtual VLAN1 interface is created and ports 1-7 are assigned to it via switchport-access-vlan1 command, the show-run indicates that the ports are still not assigned.

I've also used the SDM and even though the web-interface shows VLAN are assigned the sh-run output from SDM indicates this is not so. Is this an IOS bug ?

ASA Version 8.2(1) 
!
hostname ciscoasa
enable password 8Ry2YjIyt7RRXU24 encrypted
passwd 2KFQnbNIdI.2KYOU encrypted
names
!
interface Vlan1
 nameif inside
 security-level 100
 ip address 192.168.1.1 255.255.255.0 
!
interface Vlan2
 nameif outside
 security-level 0
 ip address 41.x.x.x 255.255.255.248 
!
interface Ethernet0/0
 switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
ftp mode passive
pager lines 24
logging asdm informational
mtu inside 1500
mtu outside 1500
no failover
icmp unreachable rate-limit 1 burst-size 1
no asdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 1 0.0.0.0 0.0.0.0
route inside 0.0.0.0 0.0.0.0 41.x.x.x 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
dynamic-access-policy-record DfltAccessPolicy
http server enable
http 192.168.1.0 255.255.255.0 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
telnet timeout 5
ssh timeout 5
console timeout 0
dhcpd auto_config outside
!
dhcpd address 192.168.1.5-192.168.1.254 inside]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23375506</guid>
<pubDate>2009-11-21 15:11:57</pubDate>
</item>

<item>
<title>[HELP] Cisco 1721 question regarding WIC</title>
<link>http://www.dslreports.com/forum/remark,23374479</link>
<description><![CDATA[Hi everyone,

I bought mini lab setup on Ebay, it consists of the following hardware: 1721 router, 2924 XL EN switch.

I also have a ZyXEL DSL modem/router/switch from my ISP.

The Router has the following WIC on WIC0: WIC-1B-S/T.

The setup I want is:

DSL(modem/router/switch) -> 1721 router -> 2924 switch -> laptop/computers

After some research on the Internet, I found out that I will need a WIC-1ADSL or a WIC-1ENET. If the modem that I have can be set to solely perform modem function, I would be able to use the WIC-1ADSL as the dialer. Is this true? Or do I need a WIC-1ENET to act as a WAN port? The WIC-1B-S/T, I think I have no use for it, or I don't know what to use it for. If someone can tell me how to use this WIC would also be nice.

Can someone shed some light on this for me?

Hope for your support. :) Thanks!

Gideon]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23374479</guid>
<pubDate>2009-11-21 09:13:04</pubDate>
</item>

<item>
<title>corp -&#x3E; internet -&#x3E; 1751 -&#x3E; 7965 phone</title>
<link>http://www.dslreports.com/forum/remark,23372998</link>
<description><![CDATA[Hey guys,

I've got a 1751-v with two WIC-1ENET modules. 
IOS = c1700-k9o3sy7-mz.124-11.t.bin

I recently relocated from my corporate office to a home-based office and ended up bringing my cisco 7965 phone with me, with power-supply -- I'd really like to make use of the phone as I'm getting tired of using my soft-phone.  

My goal is to use the second ethernet interface for sort of a "hard VPN" line into my corporate office, eliminating the need to fire up my cisco vpn client on my computer.  Is there a way for me to have the router negotiate with our corporate network as the client software normally would on my pc?  
  
I have okay (at best) experience with Cisco routers.. limited VPN exposure, but was wondering if this was even possible.

Thanks!

Dan]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23372998</guid>
<pubDate>2009-11-20 20:57:47</pubDate>
</item>

<item>
<title>[Config] Using tunnel to join vlans (Xconnet / pseudowire</title>
<link>http://www.dslreports.com/forum/remark,23365445</link>
<description><![CDATA[Hi Everyone,
A brief description of what I am trying to do - We have a network (Lets call it public network, vlan 100) which is not on our inside network (it's behind a router + ISA firewall). For disaster recovery purposes, we want to install servers on this network, at another site (Lets call this inside network, vlan 20). We don't want to do this via bringing the Vlan across, due to security implications, and also that the Public network is behind an ISA.

I have been trying to setup a tunnel to bridge the 2. My idea, is, setup vlan 100 on the inside network, with an ip on that network. I will have a Cisco 2800 series router hanging off the switch, on vlan 100 on one port, vlan 20 the other, with a routable loopback interface.

I Will then have another Cisco 2800 series router hanging off the Public network, with 1 interface on vlan 100, and the other interface on a seperate network (inside network, different vlan), again with loopback interface. This was done as the ISA wasn't playing ball, blocking traffic, and we have got desperate, so are bypassing the ISA. We will only route tunnel traffic through this back door, everything else is routed the normal way through the ISA.

Tunnel seems to be up, but I can't work out how to route tunnel traffic through the tunnel! Any chance anyone has any ideas?

Cheers!

Definitions:
192.168.1.1 (Loopback int of router 1)
192.168.2.1 (Loopback int of router 2)
Vlan 100 (This is the Vlan that I want to tunnel to different network)
Vlan 20 (This is local vlan of site where i want server
192.168.100.132  (This is IP of the server I want to install)

ROUTER 1:

l2tp-class vlantunnel1
 authentication
 password passwordexample
 cookie size 8

pseudowire-class vlantunnel1
 encapsulation l2tpv3
 protocol l2tpv3 vlantunnel1
 ip local interface Loopback0

bridge irb
!
!
!
interface Loopback0
 ip address 192.168.1.1 255.255.255.255
!
interface FastEthernet0/0
 ip address bb.bb.bb.bb (used to talk to Public Net Router)
 duplex full
 speed 10
!
interface FastEthernet0/0.100
 encapsulation dot1Q 100
 no cdp enable
 xconnect 192.168.2.1 1 pw-class vlantunnel1

interface FastEthernet0/1
 ip address aa.aa.aa.aa (inside network ip address used to talk bypass isa)
 duplex auto
 speed auto
!
ip default-gateway 192.168.100.254  (gateway of vlan 100)
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 aa.aa.aa.aa  (This is the gateway of fa0/0 address' network)
ip route 192.168.100.0 255.255.255.0 bb.bb.bb.bb
ip route 192.168.100.132 255.255.255.255 192.168.2.1  (This is the server I want off site - this route is what I don't think is right)

bridge 1 protocol ieee

ROUTER 2:

l2tp-class vlantunnel1
 authentication
 password passwordexample
 cookie size 8

pseudowire-class vlantunnel1
 encapsulation l2tpv3
 protocol l2tpv3 vlantunnel1
 ip local interface Loopback0

interface Loopback0
 ip address 192.168.2.1 255.255.255.255
!
interface FastEthernet0/0
 no ip address
 duplex auto
 speed auto
!
interface FastEthernet0/0.100
 encapsulation dot1Q 100
 no cdp enable
 xconnect 192.168.1.1 1 pw-class vlantunnel1
!
interface FastEthernet0/1
 no ip address
 duplex auto
 speed auto
!
interface FastEthernet0/1.20
 encapsulation dot1Q 20
 ip address cc.cc.cc.cc (IP of local LAN, routable, and talking to network)
!
ip default-gateway dd.dd.dd.dd (IP of vlan 20's default gateway)
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 dd.dd.dd.dd

bridge 1 protocol ieee]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23365445</guid>
<pubDate>2009-11-19 13:58:34</pubDate>
</item>

<item>
<title>please If you are cisco engineer I need help it is urgent</title>
<link>http://www.dslreports.com/forum/remark,23353303</link>
<description><![CDATA[This is the plan. and if you can help in this you are the best.

Main Office
My plan is to use a Cisco 2811 router with 3 Ethernet interfaces. 1st Ethernet port connects to Layer 3 Cisco 3560 switch that it has 2 VLANs . VLAN2(172.20.0.0),VLAN3 (172.10.0.0) and 2nd Ethernet connects to WAN via CPE router(10.4.1.0) and then have the 3rd interface connect to my cable modem ISP (77.42.246.0). Simple right, that what I thought first.
I wanted clients on VLAN 2 to be able to go on the internet and be able to talk to clients on the other VLANs. And VLAN 3 should only have access to the internet.
Branch office
Router is 2621, with 3 FE interfaces LAN, WAN , DSL. VLAN 2 can access main office and internet , VLAN 3 can only access the internet
In each site currently I have the following:

Branch Office

172.21.1.0 &172.11.1.0
LAN &#150;L2 Cisco switch 2960========== VLAN 2, VLAN 3
^
|
|Trunk
|
|
E0/1 (172.21.1.X)
Router Cisco2811 (Branch office) E0/3 (77.42.244.17)- -- - - -244.18 DSL---Internet
E0/0(WAN-10.4.2.2)
|
|
|
|
|CPE 10.4.2.1
| WAN CLOUD all static IP (10.4.0.0)
|CPE 10.4.1.1
|
|
|
|
| MAIN Office
|
E0/0 (10.4.1.2)
Router Cisco2811 (MAIN office)-E0/3-(77.42.246.17) - - - - - 246.18 DSL-------Internet
E0/1 (192.168.100.1)
|
|
|
| outside E0 192.168.100.2)
Firewall ASA5505
| inside interface1(172.20.1.254)
|
|
|
LAN L3 Cisco switch 3650 = VLAN 2 172.20.1.0, VLAN 3 172.10.1.0

Note:
&#149; Each location will have its own DSL to connect to the internet
&#149; VLAN 2 can talk to WAN, MAIN office servers and internet
&#149; VLAN 3 can only talk to internet cannot talk to WAN or VLAN 2

Please what is the best way to configure this anyone have configuration idea or help me in configuration of the router switch and Firewall. do i need routing statement on the DSL router to be able to access the internet since we using static everywhere.

How the ASA 5505 should be setup to have traffic from all VLAN access the internet (NAT, Access list.. )

Your help in this matter is highly appreciated.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23353303</guid>
<pubDate>2009-11-17 10:40:46</pubDate>
</item>

<item>
<title>[Config] is it possible: 2 goups of LAN go to 2 internet connect</title>
<link>http://www.dslreports.com/forum/remark,23346295</link>
<description><![CDATA[is it possible for 2 groups of LAN accessing to 2 internet connections with ASA5510 ? 
I have 2 groups: for group 1 I want them to use internet connection1 . and the group 2 I want them to use internet connection2. 
is it possible and how to config? 
please suggest
Thank you]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23346295</guid>
<pubDate>2009-11-15 22:01:48</pubDate>
</item>

<item>
<title>errors related with MTU between two switches</title>
<link>http://www.dslreports.com/forum/remark,23368876</link>
<description><![CDATA[I have a fallowing L2 link between two switches:

Code:
WS-C2960G-24TC-L[gi0/20; MTU 1500 bytes; Full-duplex, 1000Mb/s]          WS-C4506[gi3/3; MTU 1552 bytes; Full-duplex, 1000Mb/s]

As you can see, MTU size is different. If I do "sh interface gi3/3 counters errors" in WS-C4506, there are no errors. However, in WS-C2960G-24TC-L there is a different story:

Code:
WS-C2960G-24TC-L#sh interfaces gi0/22 counters errors

Port        Align-Err     FCS-Err    Xmit-Err     Rcv-Err  UnderSize  OutDiscards
Gi0/20              0           0           0           0          0        55915

Port      Single-Col  Multi-Col   Late-Col  Excess-Col  Carri-Sen      Runts     Giants
Gi0/20             0          0          0           0          0          0      10780

Could somebody explain, why there are 'Giants' errors on port gi0/20? What WS-C2960G-24TC-L does with those 'Giant' frames? Drops? Are 'Giants' and 'OutDiscards'
related? Any additional explanations are most welcome as well!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23368876</guid>
<pubDate>2009-11-20 04:08:40</pubDate>
</item>

<item>
<title>Cisco Aironet 1231 AP - POS!!!</title>
<link>http://www.dslreports.com/forum/remark,23355826</link>
<description><![CDATA[I recently purchased one of these AP's and going thew the web config I found myself to be very disappointed with the available options on security and setup.  The only way I found to setup WPA is with a radius server.. No WPA-PSK options. Only WEP.  

And forget trying to bridge it with another AP. Other than setting it as a root bridge, I see no other way to select another AP for it to assoc with.

So if anyone thinks they can help me with this, please feel free to do so.  Thanks

/end rant
--
Have a Networking problem or question? Stop by the Networking Forum and let us help you.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23355826</guid>
<pubDate>2009-11-17 18:24:10</pubDate>
</item>

<item>
<title>Cannot access internet with Cisco 837 router</title>
<link>http://www.dslreports.com/forum/remark,23363633</link>
<description><![CDATA[Hi all. I have a slight problem with my cisco 837 router. I have entered all the relevant commands (i think) to get it up and running but still cannot access the internet. My service provider is UK BT and i know they use PPPoA and I have entered these settings correctly. I think it is just something really simple that I need to do and the answer is probably staring me right in the face. All help will be greatly appreciated guys. ill post my running config below. Thanks in advance for your help.

R1#show run
Building configuration...

Current configuration : 3724 bytes
!
! Last configuration change at 12:40:15 PCTime Thu Nov 19 2009
!
version 12.3
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname R1
!
logging buffered 51200 warnings
enable secret 5 $1$QanM$N9aEBqHDEL6ns/wevaZZW1
!
username dave privilege 15 password 0 cisco
clock timezone PCTime 0
clock summer-time PCTime date Mar 30 2003 1:00 Oct 26 2003 2:00
no aaa new-model
ip subnet-zero
ip domain name dispatchteam
ip name-server 194.72.9.34
ip name-server 194.72.9.38
ip dhcp excluded-address 192.168.1.1
ip dhcp excluded-address 192.168.1.62
!
ip dhcp pool sdm-pool1
   import all
   network 192.168.1.0 255.255.255.192
   default-router 192.168.1.1
   dns-server 194.72.9.34 194.72.9.38
   domain-name thedispatchteam
!
!
ip inspect name SDM_LOW cuseeme
ip inspect name SDM_LOW ftp
ip inspect name SDM_LOW h323
ip inspect name SDM_LOW icmp
ip inspect name SDM_LOW netshow
ip inspect name SDM_LOW rcmd
ip inspect name SDM_LOW realaudio
ip inspect name SDM_LOW rtsp
ip inspect name SDM_LOW sqlnet
ip inspect name SDM_LOW streamworks
ip inspect name SDM_LOW tftp
ip inspect name SDM_LOW tcp
ip inspect name SDM_LOW udp
ip inspect name SDM_LOW vdolive
ip audit notify log
ip audit po max-events 100
no ftp-server write-enable
!
!
!
!
!
!
!
interface Ethernet0
 description $FW_INSIDE$
 ip address 192.168.1.1 255.255.255.192
 ip access-group 100 in
 ip nat inside
 hold-queue 100 out
!
interface ATM0
 no ip address
 no atm ilmi-keepalive
 dsl operating-mode auto
!
interface ATM0.1 point-to-point
 pvc 0/38
  encapsulation aal5mux ppp dialer
  dialer pool-member 1
 !
!
interface FastEthernet1
 no ip address
 duplex auto
 speed auto
!
interface FastEthernet2
 no ip address
 duplex auto
 speed auto
!
interface FastEthernet3
 no ip address
 duplex auto
 speed auto
!
interface FastEthernet4
 no ip address
 duplex auto
 speed auto
!
interface Dialer0
 description $FW_OUTSIDE$
 ip address negotiated
 ip access-group 101 in
 ip nat outside
 ip inspect SDM_LOW out
 encapsulation ppp
 dialer pool 1
 dialer-group 1
 ppp authentication chap callin
 ppp chap hostname ##############
 ppp chap password 0 ############
!
router rip
 version 2
 passive-interface Dialer0
 passive-interface Ethernet0
 network 192.168.1.0
 no auto-summary
!
ip nat inside source list 1 interface Dialer0 overload
ip classless
ip route 0.0.0.0 0.0.0.0 Dialer0
!
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 600 life 86400 requests 10000
!
access-list 1 remark SDM_ACL Category=2
access-list 1 permit 192.168.1.0 0.0.0.63
access-list 100 remark auto generated by SDM firewall configuration
access-list 100 remark SDM_ACL Category=1
access-list 100 deny   ip host 255.255.255.255 any
access-list 100 deny   ip 127.0.0.0 0.255.255.255 any
access-list 100 permit ip any any
access-list 101 remark auto generated by SDM firewall configuration
access-list 101 remark SDM_ACL Category=1
access-list 101 deny   ip 192.168.1.0 0.0.0.63 any
access-list 101 permit icmp any any echo-reply
access-list 101 permit icmp any any time-exceeded
access-list 101 permit icmp any any unreachable
access-list 101 deny   ip 10.0.0.0 0.255.255.255 any
access-list 101 deny   ip 172.16.0.0 0.15.255.255 any
access-list 101 deny   ip 192.168.0.0 0.0.255.255 any
access-list 101 deny   ip 127.0.0.0 0.255.255.255 any
access-list 101 deny   ip host 255.255.255.255 any
access-list 101 deny   ip host 0.0.0.0 any
access-list 101 deny   ip any any log
dialer-list 1 protocol ip permit
!
line con 0
 no modem enable
line aux 0
line vty 0 4
 privilege level 15
 login local
 transport input telnet ssh
!
scheduler max-task-time 5000
!
end
 ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23363633</guid>
<pubDate>2009-11-19 08:16:07</pubDate>
</item>

<item>
<title>[Config] manual dhcp bindings</title>
<link>http://www.dslreports.com/forum/remark,23350640</link>
<description><![CDATA[This is driving me nuts.

I have a polycom phone that I want to assign a manual dhcp binding to.  I have it's MAC address and have tried both "client-identifier" and "hardware-address" in my single IP pool for the phone, but the router keeps giving it an address from the larger pool.  My dhcp debug is showing me that I have the correct MAC.  

Lots of confusion about this has been revealed with Google, but no solid answers.

Here's a snippet to illustrate:

! general dhcp stuff&#012;ip dhcp database tftp://10.10.10.41/office/dhcp&#012;ip dhcp excluded-address 10.10.10.34 10.10.10.63&#012;ip dhcp ping packets 5&#012;ip dhcp ping timeout 100&#012;! main dhcp pool&#012;ip dhcp pool 568-office&#012;   network 10.10.10.0 255.255.255.192&#012;   domain-name foo.net&#012;   default-router 10.10.10.57 &#012;! static binding for a cisco phone (works, phone mac is 0015.2b17.68e3)&#012;ip dhcp pool voip2&#012;   host 10.10.10.2 255.255.255.192&#012;   client-identifier 0100.152b.1768.e3&#012;!&#012;! same for a polycom with MAC 0004.f21d.8dc0 (doesn't work)&#012;ip dhcp pool voip7&#012;   host 10.10.10.7 255.255.255.192&#012;   client-identifier 0004.f21d.8dc0&#012;!&#012;
In that last non-working phone's config, I've tried "client-identifier" followed by the MAC, also the MAC with "01" appended to it as noted in the cisco docs, and with the mac and the "01" + MAC set using "hardware-address".

No matter what, the phone grabs an IP from the main pool.

Debug output:
Nov 16 18:46:48.569 EST: DHCPD: DHCPDISCOVER received from client 0004.f21d.8dc0 on interface FastEthernet0/0.1.&#012;Nov 16 18:46:48.569 EST: DHCPD: Sending DHCPOFFER to client 0004.f21d.8dc0 (10.10.10.27).&#012;Nov 16 18:46:48.573 EST: DHCPD: creating ARP entry (10.10.10.27, 0004.f21d.8dc0).&#012;Nov 16 18:46:48.573 EST: DHCPD: unicasting BOOTREPLY to client 0004.f21d.8dc0 (10.10.10.27).&#012;Nov 16 18:46:51.573 EST: DHCPD: DHCPREQUEST received from client 0004.f21d.8dc0.&#012;Nov 16 18:46:51.577 EST: DHCPD: Sending DHCPACK to client 0004.f21d.8dc0 (10.10.10.27).&#012;Nov 16 18:46:51.577 EST: DHCPD: creating ARP entry (10.10.10.27, 0004.f21d.8dc0).&#012;Nov 16 18:46:51.577 EST: DHCPD: unicasting BOOTREPLY to client 0004.f21d.8dc0 (10.10.10.27).&#012;
--
with every mistake we must surely be learning]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23350640</guid>
<pubDate>2009-11-16 18:57:23</pubDate>
</item>

</channel>
</rss>
