50% pings are sucesfful

My problem is the following:

I have VPN site-to-site and easy VPN server on router 831. VPNS are in place and work very well. But the problem is when I try to access hosts on the LAN side another VPN tunnel. When I ping local interface of the router I got 100% successful replay but when I ping host on LAN I received 50% replays. Because of this I can't use Win DRC hosts to access.

Router when I do ping local host, I had 100% replay.

I don't know when I'm wrong Mr. Please help as soon as possible.

Try to remove the config line:

IP route 0.0.0.0 0.0.0.0 Ethernet1

and replace it with this line:

IP route 0.0.0.0 0.0.0.0 xxx.yyy.zzz.ggg, where the address of .ggg is the gateway to the upstream provider.

I think that some of the cause is due to the fly table arp or arp process running too much to process icmp frames.

If you can, I would hardcode the speed and duplex settings on the two ethernet interfaces on the router and a hub/switch to which they can connect to. I've seen cases where autonegotiation prevents traffic to flow through the router with very low charges.

I would like to know if the replacement of the route is viable, and what you can do with the change of setting speed/duplex as well.

Tags: Cisco Security

Similar Questions

  • Satellite Pro M70-132: excellent WiFi connection but the pings are slow

    Hi all...
    My Satellite Pro M70-132 have problems with Wi - Fi connections (WiFi built in)... Generally, when the connection is excellent (indicator of windows), the pings are slow - very long time: 1212ms, 325ms, 645ms, 2112ms, 91ms, s 168ms... etc 'demand time limit has expired' (or sth like this).
    I have updated with the latest version of the Intel WiFi driver - it does not work...
    I installed new system - it does not work...

    Is it possible, that LAN WiFi is dead on my M70-132? How can I check before sending my 'Toshi' to the service?

    (BTW - built-in Bluetooth has been switched off...)

    I was tempted to access with several AP and also ad hoc. Every time, same results... connection strong-great but pings are slow... and often ping timeout...

    The IP address has been set manually and automatically - it does not work... too multidimensional :-(

    It's not metter WEP encryption is enabled, 'on' or 'off' and no authentication method does not change the situation with WLAN...

    Post edited by: maxgoldie

    Hello

    If the work of WLan connection and you are connected to the router so I guess everything's ok.
    Time to ping depends on not always the strength of the signal.

    If you ping other ip on the net if the time depends on the provider and type of connection.
    But if you ping your WLan router and it s very slow so it s a bit strange.

    If you think there could be something wrong with the Wlan card then you can try asking for help ASP.

  • How a tracking of the source of a 'ping '?

    What are the best ways to find on who/where a 'Ping' are created and how to follow?

    If you have the IP address, there is some site online that you could use to show the location of intellectual property. These sites are not always reliable, but if you are looking a bit on find ip location, you'll find something.

  • When I try to ping from a specific site

    Hey guys I have a problem, I don't know if its on the side of router or computer but when I ping a site, for example hackforums.net I get this

    Ping hackforums.net [208.115.245.75] with 32 bytes of data:
    Request timed out.
    Response from 64.31.4.94: the unreachable Destination network.
    Response from 64.31.4.94: the unreachable Destination network.
    Request timed out.

    Ping statistics for 208.115.245.75:
    Packets: Sent = 4, received = 2, Lost = 2 (50% loss),
    and sometimes, I have 3 net unreachable destination messages,

    I tried to update my firmware, reboot and every thing possible, but the same error would come just to the top again and again,

    Please help me

    N ° as I wrote before: a router on the path to the server filter packets. That's all.

    For example: try this site: http://ping.eu/ping/

    Type 208.115.245.75 and you will see that the pings are filtered. Windows reports "network unreachable Destination" for this.

  • Not possible to Ping from a computer on the Local IP network

    Through the IP address, I am unable, by using cmd.exe, ping multiple computers on the local network.  I'm able to do a ping of some local computers, but not all.  How can I solve this?

    Hello

    If the pings are not blocked by the firewall on the computers in question.

    Change their IPs and so you ping anything or something else is the problem with the network making it unreachable computers.

    Try to download and run this free application, may be it will show better the State of the network.

    http://www.SoftPerfect.com/products/networkscanner/

  • Cannot ping PIX 515e Interfaces

    I know it's a very silly question for this forum, but I have already tried many things and cannot get the answer from the PIX firewall interfaces.

    It's my (very easy) installation:

    Using a FastEthernet port on router, I have a cable connected directly to the outside I / F of the PIX-515e. (Crossover cable works, I have already tested). Router <-->PIX directly connected.

    I configured the PIX firewall to allow pings (I used different commands):

    ICMP allow any response of echo outdoors

    ICMP allow all outside

    ICMP permitted - echo outside response

    I tried to configure each of them and also combined.

    Also tried to send the PIX to its default values. Supposed to be after that the PIX should allow all pings if no "icmp" command is configured.

    I have configured the ports on both sides to 100 Full

    On both sides of the link (PIX and router) I have the links to the top. The lights are on.

    The 'show interest' on the PIX firewall shows to the top/top

    The same thing on the router...

    The two interfaces are configured in

    10.1.1.0/24 (10.1.1.1 & 10.1.1.2)

    What I am doing wrong?

    This should be very easy...

    Hello

    Majority of the time interfaces refuses explicitly to ICMP packets unless you indicate otherwise. Here is a link to a pretty good setup guide... Have a look at the link to the ping Security Appliance Interfaces section in this guide. I'm really frustrated myself during the installation/testing phase because the pings are not working and it helped. Hope this helps a little and makes your life easier =) (rate if it please and thank you)

    http://www.Cisco.com/en/us/products/ps6120/products_configuration_guide_chapter09186a00805521b6.html#wp1059645

    Thank you

    Chris

  • Problem with Site-to-Site VPN. VPN tunnel is broken but can ping

    OK, so I am trying to understand why I can't not only appears when I sh crypto isakmp his or sh crypto ipsec his. I did the basic to site vpn settings to another and I can't ping on both networks fine no problem. So, when I ping from one pc to the address 172.16.0.0 192.168.0.0 network network there is no problem at all because the pings are very well received. But when I go to sh crypto isakmp sa, there's simply nothing and I can't for the life of understand me why. I watched my sh run for both routers and all seems well, but I guess I could be overlooking something. I would really appreciate if someone could help me to diagnose this problem.

    I've attached my plotter file of package and two routers use the binary password. I also have the sh run two routers also attached.

    I'm not on any of the router 172.16.0.0/24 only 172.16.0.0/16 and I think that is the question.

    In Crypto ACL you have on the router of branch:

    !

    S2S-VPN-TRAFFIC extended IP access list

    Licensing ip 192.168.0.0 0.0.0.255 172.16.0.0 0.0.0.255

    If it should not be:

    !

    S2S-VPN-TRAFFIC extended IP access list

    Licensing ip 192.168.0.0 0.0.0.255 172.16.0.0 0.0.255.255

    and coursed mirrored on the main router.

    If this isn't the case, you are saying that some ping between 192.168.0.x and 172.16.0.x is going ok. Can you please indicate exactly that one? I could see that you have attached a package tracer, but I couldn't open it.

  • Problem face Time and sky Hub... Help!

    Hi, we have a Hub of Sky - SR102-Z for our connection broadband. Speeds are great, without connection problems with the exception of FaceTime on iPhone, iPad and iMac too.

    Our connection speeds are-

    Upstream (Kbps) 5676

    Downstream (kbit/s) 30816

    We are broken video connections gel, pause, audio drop inside and out, total nightmare! This only happens on our network of Sky at home, we have no problem anywhere else, be on wifi or 3G or 4G. The problems occur with a cable and a Wi - Fi connection.

    I talked to the sky and they say that some ports that require FaceTime will be blocked on the firewall of the router. If someone had this problem and have you been able to fix. Apologies if this has already been covered, while hoping for help.

    Just downloaded Skype and it works very well, no problem, but prefer to use Face Time if possible.

    I have the same problem with ipad/iphone on the hub of sky-, as well as with my friend who has internet sky

    My pings are low and my connection up and down stream is great - just facetime

    My wok phone and ipad on our ADSL (demon provider) photo works is clear as day, if not the devices.

    It would be interesting to know why the Skys connection is bad with Facetime, if the port has been blocked while it wouldn't work?

  • Possible bad SPA2102.

    I'm in a game of tennis to tech support. The news is: I initially installed two days ago and things were great. Now I have one of three levels of failure. No dial tone. I can call, I get a ring, he goes to the busy signal or can I make a call with a soft rattling seconds toutes.75 the other end can hear. Incoming calls also get a msg "out of Service".

    Now, with no other devices online I 1.2/.7 GB ADSL. When I * try * to make a call and run the test (http://minneapolis.speedtest.qwest.net/) it fails me with latency issues. Qwest reports my ping to 70 to 120 and said players would kill for her. Now my VOIP (VOIPGO) says it's a problem of about 100ms latency and a 120 means no dial tone than a ping over 75 can cause problems, a ping of 100 will cause problems. They also say that the spa2102s never fail.

    Now, I see two questions they can't answer, or at least agree on. With huge bandwidth, pings are acceptable and can the SPA2102 flooding my connection?

    (Mod Note: under the guidance of the compliance of the directive.)

    Check back. the problem was that the SPA should be between the modem and the router DSL. Not through the router. Even with the priorities set for the SPA, the WRT160n is too slow.

  • My group IP Equallogic rattling of unknown Internet hosts

    Hello

    I have an Equallogic group composed of former members of PS6000 and also running firmware 5.02 (I know it's old).  Our network security team saw that the IP of the Equallogic group sends constant pings to certain IP addresses.  Some of these IP addresses are no. DHCP Server related (169.254.1.151 169.254.1.19, etc.), but also we are seeing pings being sent to internet two IPS, 20.20.20.2 and 20.20.20.3.  These pings are apparently constant, and we can not find in the logs in the management console, why they produce.

    Any thoughts or ideas?

    Kind regards

    Kevin

    Hello

    I suspect that you have a Server Windows, with HIT / me installed.  But the MPIO configuration wizard has not been run to exclude all non-iSCSI subnets.  If the hosts are trying to log on by using all available subnets.  To ensure than a back road, the table first ping this IP address.  In case of failure it will not attempt a connection.

    Then once you run the Remote Setup Wizard, you will see the option of MPIO.  Make sure only the iSCSI subnet is included and this should solve your problem.

    Re: Firrmware.  Very old firmware.  If you run VMware ESXi, you are also at risk of corruption of VMFS metadata.  The minimum EQL firmware to address this problem is 6.0.7.  There are also a lot of improvements to the management of disk errors, etc...   5.0.2 is released Oct. 2010.

    Kind regards

    Don

  • 6224 PC kills my network. Help? :)

    Howdy,

    I have a PowerConnect 6224 that I use at home on my home network.  I recently started having a really * internet connection with Pings in the range of several hundred.  My configuration is very simple:

    Cable modem-> Wireless Router-> PC-> stuff 6224 (printers, VOIP, file server computer box, etc.)

    If I go to www.pingtest.net with everything connected (I'm on wifi to router), I've been around average a 300ms ping response.  Then, I found that if I simply unplug the router to the switch and run the test again, I get a sub 20ms ping without making any other changes.  If I can plug it in the switch back in, my pings are up in the scale of several hundred.

    Then I unplugged the switch for a bit and let it restart.  I have rant pingtest again, he jumped up to autour 95ms ping.  It's much better than it was before the restart, but still not as good as I would like.

    If it seems to tell me that the traffic from switch is to flood the router with something that is causing all the average traffic to slow down.  When I brought the home switch, I installed the latest firmware and reset all settings to their default value and has not changed anything.

    I wonder if there is some setting I should change the switch that could help with this problem.  Should I just used to reboot it every so often?  What can I do?

    Thanks for any help!

    The switch should not be restarted regularly. Most of the common time for a reboot is when you do the firmware updates. The latest firmware is 3.3.15.1.

    http://Dell.to/2c7auvh

    While the problem is occurring, I'd take a look at some of the controls, see the following. The output may help to better identify the possible causes.

    Show # command logging, will give you the output of any saved messages. If there are errors messages, they can help to better identify the possible causes.

    You can use the command # show interfaces counters to check all interfaces with errors, or the high amounts of packets compared to the total of broadcast packets.

    Use these commands to check the resources on the switch. # Show processes cpu and # see the cpu memory. If they are on the high side, it can affect performance.

    While the problem occurs, you can try unplugging the devices that are attacked to the switch, instead of disconnect switch of the router. Disconnect one at the time and a test to see if there is an impact on the network.

    Keep us posted on your results.

  • Update firmware on AN Equallogic SAN on a cluster

    I'm new to Equallogic and need to update the firmware on a PS 6000 SAN that is in a cluster with TWO of SEM, that the firmware needs go to v6.0.7 to v7.0.5

    My questions: I was told that I need to evacuate the SAN (migrate everything out of him) to the second SAN in the cluster, so there is no risk on everything that's wrong in the virtual machine, while the firmware update coming.

    Where am I supposed to go? I checked the workgroup SAN Equallogic and VMWare vsphere GUI Manager interface, and I don't see a place where I can do.

    Any advice will be greatly appreciated.

    We assume that your EQLs have two controllers on the right?  EQL use a controller Active and standby and in the event of a failure of the controller failover took about 10 sec. To survive this event or need a propper configuration of your phys. Switch, hosts and virtual machines. Just follow the installation and best practices.

    Then... a firmware perform the same type of failover. From an update FW flashing the standby controller first, then asks for a 'restart' which performs failover. That the 'new' standby also will Flash.

    All our EQL + VMware configurations remain 10 seconds (4 pings are missing) breakage.

    If you wish to cancel a member of a pool for maintenance it takes something like that

    -Both of your members are in the same pool

    -You create a new and "move a member" of the existing pool in the new. If there is enough space left all volumes is automatically migrated to the existing Member and the last in the pool

    -If the Member is now in your pool maintenance you can perform the FW update

    Its fully transparent and non interruptible for hosts/VMs. But takes a looooonnnnng time finshed.

    If your members are in different pools already and assuming that enough space

    -Use 'move the volume' to transfer a volume of a pool to another. You need to check if there is enough space left

    -Another method would be to activate SyncRep for all Volumes and perform a switch over. If a member holds all the SyncAlternates you can put paused the SyncRep and perform the update of FW.

    In the first 7 months of this year we perform 3 (4?) FW upgrade of our 11 EQLs that currently spans 7.0.6. The process time vacuate trust has never been an option for us.

    The FW comes with a PDF file on how to perform the upgrade and contains some notes so please take a look inside.

    Kind regards

    Joerg

  • Storage array error event (PS4100X)

    Dear Sir, I have VMwaer Vsphere 5.5 x 2 and only switch and DELL PS4100X storage I don't know why, I'm wearing the messeage PS4100X like this form = the table eql-1 storage subsystem ERROR event: event SP [secondary]: 15.4.1 time: Fri Jul 25 11:52:10 2014 NVRAM contains valid data. It is a RECOVERY of PANIC because of the panic on a processor of NetBSD. -Event of the table eql-1 storage subsystem ERROR: event SP [secondary]: 15.4.5 time: Fri Jul 25 11:52:10 records of 2014 saves CPU, CPU 1 to 0000000000000000 0000000004010000 v0 v1 ffffffffbef08010 a0 0000000000000104 a1 a2 a3 0000000000000000 0000000000000104 ffffffffd2243b70 t0 0000000000000001 t1, ffffffffd2243b70 t2 ffffffff804e2f88 t3 t4 0000000000000001 ffffffff8041f1d0 t5 0000000000001000 t6 0000000033de3e40 t7 0000000033de4290 s0 ffffffff8098b718 s1 ffffffffd2243b70 s2 ffffffff8098b718 s3 s4 0000000000000000-0000000000000000 s5 s6 0000000000000000 ffffffff82c84e60 s7 ffffffffc0131000 t8 t9 0000000000000000-0000000000000000 k0 k1 000000000010849f gp ffffffff80033000 000000000010845f SP ffffffffd22439e8 S8 ffffffff80976cf8 ra ffffffff804d2cac - the table eql-1 storage subsystem ERROR event: event SP [secondary]: 15.4.6 time: Fri Jul 25 11:52:10 2014 saved CP0 registers, CPU 1 sr 00488005 badva c01320a0 EPC 806a2ba0 errorepc 804d2c80 cause 00000108 errctl 00000000 cacheeri 00000000 cacheerd 00000000 buserr 0000000000000000 cacheerrdpa 0000000000000000 - ERROR event of the table eql-1 storage subsystem: SP [secondary] event: 15.4.7 time : Fri Jul 25 11:52:10 function call 2014 saved battery, CPU 1 804d2c80 804d2cac 804d2e90 806d99e0 804e2e88 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 00000000 80697a 38-= can you tell me why? Please HELP Storage control F/W is V6.0.8

    We installed VMware Tools in all virtual machines and have also a good configuration of switch for our ESXi hosts tolerate the 10 sec 'dead time' of the connection of storage. Controller failover takes less than 10 seconds here and only 4 pings are missed.

    We do FW updates in a low period of IO. I have to manage 25 EQLs and we carry out the FW update without blocking down the cluster. I have disable HA 'Host followed' as well as the notification by e-mail from vCenter for the time.

    Yes version 7.0.5 is the latest public version available. 2 days ago, the FW Drive Kit 5.0 comes out so you can take one taken if your drives are on the list. If so, update the first readers.

    Yes, as readers can be improved without closing anything. Drive for affected car kit checks and do one after the other.

    Yes, you can upgrade directly from 6.0.8 7.0 x

    You will see the service tag to the title of Member-> maintenance in the EQL Groupmanager. Go to dell.com and support and see if you have a support contract is valid. Check www.dell.com/.../Contact-Information how to contact Dell technical support. If nothing is done, use the support link after you connected to https://eqlsupport.dell.com

    Kind regards

    Joerg

  • Best practices to play multiple sounds - a MediaPlayer or many?

    Hello!

    I use the MediaPlayer in QML object.

    Problem: If I have 10 items, and when you touch an object sound... then plays with a MediaPlayer, the sound that plays must finish before its different can begin. (Or you can write the code for "stop the existing sound and plays another"). Whatever it is, you can have a musical whirl when you click each object.

    Current solution: Add a MediaPlayer component to each object, so when you type this object, he plays his own MediaPlayer. Sounds amazing because sounds overlap. In a game, if you hit the fastest objects that their noise can play, it sounds good as the boops/dings/pings are nicely stacked as they sound.

    However, I think that this could be taken memory useless? For example if I had 100 items, I don't think I would 100 elements of MediaPlayer set?

    Is there a better way to make its competitor in QML?

    Select this check box.   They used several simultaneous sounds with a single soundmanger.

    https://github.com/BlackBerry/presentations/tree/master/2012-BlackBerryJam-Americas/JAM09/BaDumTss

  • RV180 router: impossible to get Inter-VLAN routing to work.

    I've been hit in this now for two days and just can't get Inter-VLAN routing to work on this router.

    Here is the place is:.

    Updated to the latest firmware of Cisco (1.0.1.9).
    From default settings, I added 2 VLAN as follows:

    VLAN (id = 1) default: dhcpmode = port IP=192.168.1.1/24 from server 1
    VLAN vlan2 (id = 2): dhcpmode = port IP=192.168.2.1/24 from Server 2
    VLAN vlan3 (id = 3): dhcpmode = port IP=192.168.3.1/24 Server 3

    (without link)
    WAN port
    |
    Routing/NAT
    |
    --------------------------------------
    VLAN ip 192.168.1.1 192.168.2.1 192.168.3.1
    name of VLAN by default vlan2, vlan3
    VLAN id ID = 1 ID = 2 ID = 3
    Inter-VLAN only routing Yes Yes
    Excluded excluded unidentified 1 port
    2 excluded excluded Untagged port
    Port 3 unmarked excluded except
    Port 4 (not interest) without excluded tag excluded
    ---------      --------     --------
    1 2 3 Port port
    |              |            |
    AdminPC PC3 PC2
    192.168.2.191 192.168.3.181

    PC2 is assigned an IP address of 192.168.2.191 (DGW = 192.168.2.1) - OK
    PC3 is assigned an IP address of 192.168.3.181 (DGW = 192.168.3.1) - OK

    (IP 192.168.2.191) PC2 can ping 192.168.2.1 and 192.168.3.1 - OK
    (IP 192.168.3.181) PC3 can ping 192.168.3.1 and 192.168.2.1 - OK

    BUT...
    PC2 cannot ping PC3 - don't DO NOT WORK
    PC3 can not ping PC2 - don't DO NOT WORK

    (does not work in gateway and router Mode)

    CAN SOMEONE HELP ME UNDERSTAND WHY?

    Your help is very appreciated.

    I bought this unit specifically because she supported routing inter - VLAN!

    Vlaminck

    ---------------------------------------------------------------------------

    Support information:

    Screenshots:
    Belonging to a VLAN:
    VLAN ID Description Inter VLAN device Port 1 Port 2 Port 3 Port 4
    Routing Mgment
    1 default disabled enabled unmarked excluded excluded unlabeled
    2 active active VLAN2 excluded unmarked excluded excluded
    Unmarked 3 VLAN3 active active excluded excluded excluded

    Several subnets VLAN:
    VLAN ID IP address Subnet Mask DHCP DNS Proxy Mode status
    1 192.168.1.1 255.255.255.0 DHCP Server enabled
    2 192.168.2.1 255.255.255.0 DHCP Server enabled
    3 192.168.3.1 255.255.255.0 DHCP Server enabled

    Routing table (Bridge Mode)

    Destination Gateway Genmask Metric Ref use Interface Type flags
    127.0.0.1 127.0.0.1 255.255.255.255 1 0 0 static lo upward, gateway, host
    192.168.3.0 0.0.0.0 255.255.255.0 0 0 0 dynamic bdg3 to the TOP
    192.168.2.0 0.0.0.0 255.255.255.0 0 0 0 dynamic bdg2 upward
    192.168.1.0 0.0.0.0 255.255.255.0 0 0 0 static bdg1 to the TOP
    192.168.1.0 192.168.1.1 255.255.255.0 1 0 0 static bdg1 upward, gateway
    127.0.0.0 0.0.0.0 255.0.0.0 0 0 0 lo dynamic

    Routing table (router Mode)

    (Ditto)

    Hello

    It's not because the pings are allowed on the same subnet that they come from a different subnet.

    You probably have a firewall problem windows software because that by default, it removes a different subnet icmp echoes.

    Concerning

    Alain

    Remember messages useful rate.

Maybe you are looking for