ALS IP Cisco 2901 and POLITICS with dual gateways LAN-based ROUTING

Hello

I am configuring a failover solution combined with the ACB using two bridges already configured. See the attached diagram.

I currently have two ASA 5505 and a 2901.

According to the example: http://www.firewall.cx/cisco-technical-knowledgebase/cisco-routers/861-c... I've set up the following in the 2901:

Interface Port - channel1.1
encapsulation dot1Q 1 native
IP 192.168.200.100 255.255.255.0
intellectual property policy map RM-Comcast-traffic route

IP route 0.0.0.0 0.0.0.0 192.168.200.200 track 1
IP route 0.0.0.0 0.0.0.0 192.168.200.150 track 2
Route IP 10.10.10.1 255.255.255.252 192.168.200.150

IP extended ACL-Comcast-traffic access list
object-group permit COMCAST_Routed 192.168.200.0 0.0.0.255 any

RM-Comcast-traffic route map permit 1
corresponds to the IP ACL-Comcast-traffic
set ip next-hop check availability 10.10.10.2 1 excerpt 2

object-group service COMCAST_Routed
Eq ftp TCP
TCP eq www
TCP eq ftp - data

ALS IP 1
ICMP echo - 192.168.200.200
threshold 2
timeout of 1000
frequency 30
IP SLA annex 1 point of life to always start-time now

ALS IP 2
10.10.10.2 ICMP echo
threshold 2
timeout of 1000
frequency 30
IP SLA annex 2 to always start-time life now

track 1 accessibility of als 1 ip
Track 2 accessibility of ALS 2 ip

I did some tests and the part of failover seems to work but the configuration of the ACB does not work as expected. Only thing missing track 1 each time delivering properly and trak 2 is declining.

Any help clarifying the feasibility and practicality of this configuration is greatly appreciated.

Dan

Adding a value of AD won't fix ACB (sorry if I gave that impression).

On the client that you are testing with can you look it's the example routing table ' netstat - nr ' example and see what it shows in terms of gateways.

It can be that you want to debug your routing policy to see what is happening on the router.

Jon

Tags: Cisco Network

Similar Questions

  • Cisco 2112 and Apple TV Airplay wireless LAN Controller

    Hi all

    I'm having a problem with the help of iTunes, iPhones, and iPads on our wireless network. We have the WLC 2112 and 10 1142N WAP. If I do a network scan, I can see the Apple TV and port 5353 is open, which is Apple's morning service.  However, if I try to play the music/video on iTunes, or on an iPhone/iPad, I don't see the Airplay icon.  If I connect to the local network, the Airplay icon appears immediately. I created an allow all the rules in the ACL, but still no dice.  Any help would be greatly appreciated.

    THX

    Benm

    This Solution has been added in the following document

    https://supportforums.Cisco.com/docs/doc-21728

    If you have enabled IGMP snooping. To the title of controller, you have too many active multicast and multicast address?

  • License of dry and Cisco 2901

    Hi guys,.

    CISCO2901-V/K9 can support IPSec VPN Tunnel or should I order SL-29-SEC-K9 in order to create IPSec?

    Guys do you know where I can find the support of the Cisco router boot feature?

    Thank you for helping me!

    Hello Harry,.

    You can check this:

    Software licenses available on the ISR G2

    C2900 router is a powerful platform, but it requires the license of security for VPN support.

    The SSEC-K9 license removes the reduction applied by the US Government on the encrypted tunnel and encrypted flow export restrictions. SSEC-K9 is available only on the Cisco 2921, 2951 Cisco, Cisco 3925, 3945 Cisco, Cisco 3925th and 3945TH Cisco. With the SSEC-K9 license, the ISR G2 router can go above the limit of the reduction of the maximum of 225 tunnels for IP (IPsec) security and the flow rate of 85 Mbps of one-way traffic in or out the ISR G2 router encrypted, with a total of 170 Mbps bidirectional / s.

    Cisco 1941 and 2901 2911 already have maximum encryption within the limits of export capabilities. The HSEC license requires pre-installed image of the universalk9 and license DRY.

    FL-29-HSEC-K9

    US Export Restriction Compliance license for 2921/2951

    2921 SRI and SRI 2951

    SEC - K9 license

    Ordered with system license

    FL-29-HSEC-K9 =.

    US Export Restriction Compliance license for 2921/2951

    2921 SRI and SRI 2951

    SEC - K9 license

    Paper PAK spare

    L FL-29-HSEC-K9 =

    US Export Restriction Compliance license for 2921/2951

    2921 SRI and SRI 2951

    SEC - K9 license

    PAK electronic alternative

    HTH.

    Update: the previous post included the wrong table.

  • How do I set up a dual boot Vista and XP with 2 hard drives?

    Dual boot Vista and XP with 2 hard drives

    I tried to get my computer has a separate hard drive put in place that lets me run Windows XP or Windows Vista. I tried the path of the CMD, but I could do things wrong with that because the news NTLDR appeared much too different info from Vista. Currently, I have deleted this change to the startup configuration. I want to know what I have to do to get these two to be able to boot. I noticed problems similar to mine, but the answer always seems to be a software that would cost me money.

    Thank you

    Tevans95

    Hello Tevans95,

    You cannot install two different operating systems on two different disks. For a dual-boot environment, you must install both XP and Vista on the same drive with different partitions.

    In addition, you must install Windows XP first and then Windows Vista.

    You can check the items below which will give you information on Dual boot.

    Install multiple operating systems (multiboot)

    Set up a dual-boot system

    Change the default operating system for startup (multiboot)

    There is no software that can help you to install XP and Vista on different drives.

    Thank you
    Irfan H, Engineer Support Microsoft Answers. Visit ourMicrosoft answers feedback Forum and let us know what you think.

  • Help remove vista and options to dual boot with Windows 7

    I think that I have selected the bits from the right here, but please let me know if not.  I recently installed windows 7 and I love it so much I want to remove vista.

    I can't find any instructions on how to make sure (after formatting the drive with Vista on it - it's on a drive of 500 GB physically separated for Win 7) that I can remove the dual boot option, I currently have.  I also read if I do badly I can leave windows 7 unusable.

    Win 7 is a full do not install an upgrade, just like vista.

    Any help on the Microsoft site means how to repair xp, vista or windows 7, so to delete this post.

    Any help or direction is appreciated, I have a few days to make what I just place my order for a 2 TB HDD, so won't try until it happens.

    Hello

    "Just to check and then (which seems easier to me), if I transfer my data from the vista disc (assuming that it is the system disk) then delete and restart with the win7 dvd, a repair will then sign the Windows 7 disk as the system disk and remove any dual boot option?

    Yes, it should work. As the Win7 disk does not currently startup files, made only with this disc a repair will create the most necessary.

    "Out of curiosity if I format the Vista disc, and then restart your computer with the win7 dvd, this will give the same effect as having Remode the floppy disk in the first place?

    No, except if you use Disk Manager to designate the Win7 drive than active first. If you simply format the Vista disk and then run a repair, startup files will be rewritten on the disk of Vista. Good luck, Rick Rogers, aka "Crazy" - Microsoft MVP http://mvp.support.microsoft.com Windows help - www.rickrogers.org

  • connection of switches cisco and hp with gbic

    I have a new Cisco 2960 x and an existing HP 2910al. I am OK with the set up, I have the hp interface and Cisco all the time with copper but this is the first that I had with fiber. I know that Cisco switch will a Cisco gbic (can move only with service not taken into charge-transmitter/receiver) and HP will want a Gbic hp (new Hp operating system only works with HP Gbic).

    So here's the question, Cisco Gbic and Hp Gbic of interconnection? I guess Yes, but want to ask before you buy and know that they don't.

    As long as they are of the same wavelength (like SR to LR to LR or SR) Yes they do.

  • Cisco Firepower 4110 Clustering with ASA and DFT

    Hi all

    We have a pair of Cisco 4110 firepower devices and have them clustered for the ASA Security Module.

    There seems to be no option to add an additional logical device for the threat of fire power defence Module, so can only assume this is not supported in an active/active state.

    More on the SAA Module there is no tab of remote access VPN Configuration.

    So my question is how to incorporate the functionality of defense threat in the ASA, I suppose that this would be by the engine unloading in the advanced settings, but requires the SAA be in Active mode / standby and the power of fire threat defense logical device will be available?

    Second question is it would have been better buy the Cisco ASA 5585 X with the Module of firepower in support of all the regular features of the SAA as well as traffic inspection unloading to the module of firepower?

    I found some documentation on the Cisco site, but tend to lose sight of where the reference to FTD and not be supported of the Clustering or RAS VPN not supported by ASA or FXOS docs, so I was hoping for some insight on here.

    Appreciate any clarity around the support of devices 4110 of the firepower and configuration of the FTD and ASA combines the features supported.

    We run ASA v9.6 (2) and FXOS 2.0.1 (86).

    Thanks in advance.

    Mark

    On a firepower 4100 Series chassis, you can run a single logical unit. Several logical devices are supported only on the 9300 firepower that supports up to 3 modules of security.

    So choosing between types of module ASA and DFT (or technically you can also deploy the RADware vDefense Pro but it is mainly for service providers).

    One or the other and never the two.

    The module of the SAA supports remote access VPN over 4110 of firepower. I put one in place personally nothing this month. Have you recorded the chassis with the smart licence and applied ASA licenses (basic an and 3DES / AES)?

    The ASA modules take supported the HA and inter-chassis clustering on the 4100 series hardware.

    If you run picture FTD, there is currently no support for remote access VPN. It is a high priority position of roadmap for a future version (post - 6.2). FTD does not currently support the chassis inter cluster but that should be in version 6.2.

  • IPsec VPN with Cisco AnyConnect and 1921 ISR G2 router

    Hello

    Is it possible to establish a remote access VPN IPSec using Cisco Anyconnect client with router Cisco ISR G2 1921.

    If someone does share it please the sample configuration. as I've been on this topic since last week a.

    My Cisco rep recommended I have not try AnyConnect a router ISR or ASR.  So I used an Open Source client.  Don't say that AnyConnect won't work, just the route I took on my project.  I work good known configuration for a 1921 with strongSwan as a Client.  It is with IPSEC and IKEV2 using certificates for authentication.

  • EliteBook 840 G1 and 2013 UltraSlim Dock with dual only monitors Windows 8.1 no second monitor

    My company recently purchased HP EliteBook 840 G1 laptops with discrete graphics.  Alongside this, we use the Dock UltraSlim 2013 with dual monitors HP LV2311 connected using HP DisplayPort / DVI adapters.

    8.1 Windows displays only a single monitor, that the second monitor is not available.  I can try to cover both monitors for a resolution fo 3840 x 1080, but when I try to do just the display reverts to the poster in mirror.

    I can use the DisplayPort on the side of my laptop and just a single DisplayPort on the platform and the OS will see both monitors.

    Please advise, it is unnecessary to have a dock with double DisplayPorts which cannot display two monitors with them.

    Yes the problem really existed with the original HP driver and that Microsoft installs by default.  HP released a newer driver for 8.1.

  • PowerCLI defining politics NTP to "Start and stop with the host" in ESXi 5

    Would appreciate any help in the definition of the strategy NTP on ESXi 5 hosts 'start and stop with the host. My script is currently using the following:

    Get-VMHost MyEsx | Get-VMHostService | where {$_.} Key - eq 'ntpd'} | Game-VMHostService-policy "automatic."

    This sets up the NTP service in "start automatically if all ports are open and stop when all ports are closed.

    "When I cange to 'MyEsx Get-VMHost | Get-VMHostService | where {$_.} Key - eq 'ntpd'} | Game-VMHostService-political ' market / stop with host"" the following is returned:

    «The possible enumeration values are "auto, On, Off«»»»

    Anyone know of a way (in PowerCLI) of the set up for the 'start and stop with host?

    OK, then you should choose politics "on".

    These are the policy values and what they match.

    Like this

    Get-VMHost MyEsx | Get-VMHostService | where {$_.Key -eq "ntpd"} | Set-VMHostService -Policy On
    
  • Copy the configuration of Cisco 881 to Cisco 2901

    We replace our router Cisco 881 with a Cisco 2901 router.  If I backup the configuration of the 881 and restore it on the 2901, will there be problems? We just want our 2901 to work the same. Thank you.

    routers/switches etc. can with a base image which may allow only certain features the devices come with these out of the box so that they work.

    You can buy advanced ip services images or images of advanced security that will allow all the features work. For example, you cannot use BGP or ACB unless you have an advanced picture, but you can be allowed to use RIP and EIGRP stub.

    You can check what is running on your 881 with a license to show what it will tell you what is on

  • Portege M300 with Dual Core

    Hello

    Does anyone know if it is planning to produce a Portege M300 with new processors dual-core?

    I need to replace an old Portege 4010 and wait if dual core is on the right track. 4010/M300 is a brilliant compromise of size because it fits into a safe hotel standrad room when they travel.

    Thank you, Richard

    Hello

    I got this Toshiba brochure on dual-core technology.
    But unfortunately I found nothing on the protégé and the dual-core.
    http://EU.computers.Toshiba-Europe.com/contents/Toshiba_teg/EU/workshop/files/Tech-Insight-2006-02-dual-core-explained-en.PDF

    But if you want, you can check this from Toshiba Web site.
    http://EU.computers.Toshiba-Europe.com/cgi-bin/ToshibaCSG/csg_national_entry_page.jsp?service=EU&from=http%3 A / / www.toshiba-europe.com/
    under Preview & information you will find a lot of news.

  • Where to put M.2 SSD drives in P900 Workstation with Dual processor

    So I have a P900 with dual Xeon E5 - 2643 v3 CPU. I have two m.2 SSD pluged in a flex connector. I was wondering if there is any advantage or increase performance by dividing the two SSD between processors, i.e. to put each training into its own flex connector and pluggin then those in the respective location of each processor.

    Thank you

    Bench1

    No, you should not see a significant change in the UC records Division. The FLEX connector is a custom x 8 PCIe 3.0 slot and therefore supports about 7880 MB/s to the entire map of FLEX. It's about 3940 MB/s bandwidth of each SSD m2 on the adapter.

    Until your SSD meet or exceed the 4 Gbps by SSD, it is not a value of split.

  • Cisco VCS and integration Lync2013

    Hello!

    Could you tell me please, when CISCO officially support Lync2013 - free new software for VCS - C and documentation on integration?

    The main interest is the possibility of transferring video between CISCO/MCU and Lync endpoints on the H.264 Protocol, who hails from Lync2013.

    Right now, I've got VCS - C and RTM Lync2013 X7.2. During the video call without AMGW appeal established as audio only.

    When using with Lync2010, it worked on Protocol H.263 and CIF resolution.

    Evgeniy salvation,

    We are currently investigating the possibilities to achieve interoperability between Lync 2013, VCS and video devices on the side of the VCS standards-based, it is a work in progress and at this stage, it is to early to provide any factual information on when interop will be available.

    In contrast to Lync 2010, Lync 2013 does not support H.263 for video and it so that will remove the OCS/Lync integration. I do however think that you should be able to make a two-way video between Lync 2013 and VCS-joined endpoints if you use an AMGW tried that yet?

    Thank you

    Andreas

  • Backdoor in Cisco routers and firewalls.

    The more I read on the NSA scandal (and Yes, I apparently a scandal) less I trust corporations hardware and software.  There is no reason for anyone to doubt that all Cisco equipment comes with a backdoor.  Because these probable backdoors exist it's a matter of time before hackers discover and exploit them.  It's happened to Microsoft a number of times and there is no reason that it could not happen to Cisco.  It is no longer our trust Cisco equipment and have already started researching alternatives network.

    It is more a crazy conspiracy theory, that is the reality.

    In all liklihood, we use a series of firewall to further isolate our network against intrusions.  To reduce costs, we can keep our existing in this topology Cisco equipment, but we will replace hardware Cisco when it breaks down or needs to be upgraded.  I do the same thing with my home network.

    In the last months, we already moved all of our e-mail to secure servers overseas and changed all our McAfee, AVG and Avast antivirus software.  We are also researching Linux distributions to replace Microsoft.

    If Cisco wants to protect their brand, they need to take a stand or see their market share continue to erode.  There must be a CEO to a U.S. company that will take this position and be a hero rather that continue to be a lap dog.

    Hello

    use open-source based linux firewalls and routers.

    and check the source cod

Maybe you are looking for

  • Is it possible to reset the subject: newtab to remove personalization / repopulate?

    In newtab page which debuted in Fx13:If we delete a thumbnail, it will not appear here once again. Clicking on through every inch just leave an empty spot at the end.That is why I want to repopulate the 'speed dial '. Is there a trigger for that in t

  • Qosmio F50 - 10 M - infrared driver for Windows 7 64 bit missing

    I want to change my OS from VISTA (32 bit) to Windows 7 (64-bit), I'm on downloading all the drivers needed for the proper functioning of my laptop in the future. When the choice of my laptop (Qosmio F50 - 10 M) and operating system (Windows7 - 64 bi

  • HP F4580: power adapter

    I lost the power for the printer HP F4580 adapter.  What I need to find? Thank you very much simonederouin

  • migrate from Raid 1 to Raid 5 with IX4 - 300 d

    I am considering buying an IX4 - 300 d. But what I want to know: I might consider commissioning with 2 drives in RAID-1 and later on the road buy a 3rd drive to upgrade my RAID-5. Is this possible on the fly, which means that I can just put in the dr

  • Can I do a waveform graph view more samples currently read?

    I have DAQ 17 channels at a rate of 500 samples per second read and then write in a PDM file and a few gauges, a waveform graph.  I'd like to graph waveform to display more than the samples that are currently read, I want to only show the last 10 sec