Announcement of network user VPN via eigrp route

I can't have the VPN client user network advertising via eigrp, here is what I have so far. 10.55.1.0 is not announced.

Router eigrp xx

No Auto-resume

no default - information in

no default-information

by default 10000 100 255 1 1500 metric

Network 10.55.0.0 255.255.255.0

Network 10.55.1.0 255.255.255.0

passive-interface default

no interface passive inside

redistribute static

I already have about 30 static routes and they have redistributed successfully, the only way I can think to announce that the VPN, it is inside the neighbor is using a card of route-attached to the static method redistribute. The ACL roadmap would then 30 networks of the static routes in and the VPN. I really don't want to do that. Because every time someone adds a new static route, they would also have to be added to the ACL for the road map. Any ideas appriciated.

Hi Matthew,

Please, add the following command under your dynamic crypto map:

test of dynamic-map of crypto-map 10

the value reverse-road

HTH.

Portu.

Tags: Cisco Security

Similar Questions

  • IP address of the IPSec VPN client did not get distributed via EIGRP

    We use an ASA for VPN remote access. He is running EIGRP redistribute static routes. When a client Anyconnect SSL connects, the SAA creates a static route for this client, and it gets redistributed via EIGRP. When an IPSec VPN client connects, the SAA creates a static route for this customer, but he isn't redisributed via EIGRP and so the client can not achieve anything. Why he would distribute a static created by an IPSec client?

    Thank you

    Have you set up IPP on dynamic Cryptography?

  • Static route of VPN in EIGRP redistribution (FD is Inaccessible)

    Hi all

    I redistribute the site to site VPN static route in EIGRP, but what I noticed on the 6509 when I sh ip eigrp 200 topol, the static route to the ASA "FD is inaccessible."

    6509 output:

    Topology EIGRP-IPv4 for AS(200)/ID(10.33.95.34 table)

    Code: P - passive, A - Active, U - update, Q - Query, R - reply,.

    r response status, s - AIS status

    P 199.x.x.240/28, successors 1, FD 53760, tag is 36539

    through reallocation (53760/0)

    P 10.64.129.0/24, successors 1, FD is 28416

    Via 10.210.98.200 (28416/28160), Vlan98

    P 10.1.2.0/24, 0 successors, FD is Inaccessible

    Via 10.210.98.200 (28416/28160), Vlan98

    P 10.210.98.0/24, successors 1, FD is 2816

    Via connected, Vlan98

    ASA5510 output:

    Topology EIGRP-IPv4 for AS(200)/ID(10.64.129.253 table)

    Code: P - passive, A - Active, U - update, Q - Query, R - reply,.

    r response status, s - AIS status

    P 10.1.2.0 255.255.255.0 successors 1, FD is 28160

    Via Rstatic (28160/0)

    P 10.64.129.0 255.255.255.0 successors 1, FD is 28160

    Via connected, Ethernet0/0

    P 199.x.x.240 255.255.255.240, successors 1, FD 79360, tag is 36539

    Via 10.210.98.254 (79360/53760), Ethernet0/1

    P 10.210.98.0 255.255.255.0 successors 1, FD is 28160

    Via connected, Ethernet0/1

    The ASA config:

    200SW_EIGRP list standard access allowed 10.1.2.0 255.255.255.0

    permissible static in eigrp route map 10

    200SW_EIGR match ip address

    Router eigrp 200

    redistribute static static in eigrp route map

    external route 10.1.2.0 255.255.255.0 x.x.x.

    Thank you

    Thomas,

    When the flight director is not accessible in the EIGRP topology table, the router does not use this EIGRP route in its routing table.

    Probably, the road is overridden by any other routing protocol that has the lowest administrative distance.

    Could you please share the routing table?

    Thank you.

  • VPN via a natted router

    Hello

    I think that vpn via nat is 'enabled' in the 6.3.1 software for the pix? I have problems to run. Can someone give me directions, including everything I need to know about the router?

    I guess that everything that I have to do is create a static nat from 1 to 1 of the legal IP outside the pix outside IP router? Then configure the vpn as usual to accept vpn as usual (I use the 4.0.1 cisco client).

    I'd appreciate any help.

    Thanks for your time

    Andy

    I think that you need to configure the NAT-Traversal, the command to do this is isakmp nat-traversal]

    NAT - T can be enabled or disabled:

    By default? OFF for site to site tunnels

    By default? We'RE for hardware and software VPN clients

  • NAC Appliance with ASA (for remote user VPN)

    I have a pair of firewall 5520 cisco which is used as a VPN gateway (for remote user VPN) and perimeter firewall Internet (to provide outbound internet connectivity).

    We allow the NAC to remote VPN users. I have it will be deployed with active 3 layer inband.

    The problem with this design is that how to ensure that outgoing internet traffic does not pass through the CASE?

    I heard about couple of optioins:

    -ACB (for send only IP subnet to VPN users remote to go through CASE)

    -Version 8.x characteristic of ASA (Restrcit access to VLAN under Group Policy).

    I intend to do with ASA firewall where I can set a new subinterface on the SAA (with a new tag VLAN) and under the group policy for remote user VPN, I select the option to "restrict access to the new VLAN.

    My question is: is - it still works (even if the firewall have a route to the internal network by using the 'inside' interface and NOT the new interface of the NAC). If this does not work, please let me know what are the other options for this type of deployment.

    Thanks in advance.

    Hello

    It should work. Please see the attached PDF for more clarity on this topic: https://supportforums.cisco.com/docs/DOC-9102

    HTH,

    Faisal

  • Network Concentrator VPN access.

    We have a 3000 Concentrator and is configured with a remote vpn on it. All inside network is allowed once a connceted to the vpn user. It is quite behind firewalls. I can access an external IP.

    But I can't log in to the vpn from the inside network. I can ping the public interface; but when I try to log in from the client, the server report displays no records to my IP.

    Why can't I connect from the inside?

    Thank you

    = Internal network = Concentrator VPN = FW = off-grid

    Why try you to VPN from the inside? The purpose of the VPN is to encrypt the traffic between your PC over the internet to the VPN concentrator, once traffic arrives to your VPN concentrator, it is decrypted, and he'll be in the clear to your internal network.

    So, what's the purpose of attempting to connect from the network Cabinet?

    The reason why it does not work is because of the delivery. You are on the internal network, while traffic will exit to the firewall and return by the same firewall to connect to the public interface of the VPN concentrator, which is why it does not work and if the goal is access to the internal network, you are already inside the network which complicates things as your ip pool must then be routed to the inside.

    Hope that makes sense.

  • IP SLA for EIGRP routes

    Hello

    I searched high and low for an answer to this but have not found anything specific to my situation. We have 7 remote sites and one social site. All sites are connected by a primary MPLS cloud and all remote sites have a local circuit of cable Comcast connected to an ASA for the failover of the internet. IP SLA for internet connection works as expected. Now I understand how to configure IP SLA to track the availability of the static routes by default, but we use EIGRP on our remote sites for business traffic. The idea is that we want to follow our neighbour MPLS switch basis at each remote site, where the SPLM neighbor is more accessible, we want to install a static route for all LAN traffic through a VPN, I put in place on the SAA at the headquarters office. This static route would replace all redistributed to the MPLS provider, EIGRP routes until the neighbor MPLS is once again accessible. According to me, I'm missing something very simple, but I can't just it identify.

    Any help is greatly appreciated,

    -Mike

    Mike

    -What precedes a remote site?

    If so you have nothing to do because you already have a default route for the internet anyway. If the MPLS network drops the EIGRP routes are lost, so the default route would be used not only for internet but also other sites connected to the MPLS network.

    While each remote site has it's own internet connection?

    Sorry about all the questions, just want to be sure that I fully understand the current configuration.

    Jon

  • Access to a remote network through VPN remote access

    Hello

    I'm having a problem with users who access VPN from home.  We currently have 3 offices facility, as shown below.  When I VPN in the Philadelphia office, I am unable to access the resources of Connecticut offices or North Carolina.

    The VPN subnet is 192.168.10.0.  Inside the office of the PA, I have no problem with NC or CT.  I have to add a static route from the Pennsylvania Treasury and NC?  If so, could you give me a hand with the correct syntax?

    Office <-----------IPSecVPN---------->Office <------------IPSecVPN------------->Office of Connecticut from Pennsylvania, North Carolina

    192.168.5.0                                                            192.168.1.0                                                        192.168.2.0

    Hello

    Yes, basically the ASA accommodation the customer VPN service in this case well enough is the same configuration related to two sites with the exception of course which is obvious

    • Networks/subnets
    • Different ACL for each VPN L2L

    Although naturally the problem for me is the WRVS4400N configuration.

    Basically, you do the same things on this unit than the other remote site.

    You add the VPN pool as another remote network for VPN L2L configurations. You also confirm that there is operation NAT0 for this network also. I don't know I can help you there as I do not know the device.

    Can you please mark it as answered and evaluate other useful answers

    Naturally ask for more and I'll try to help you if I can

    -Jouni

  • Unique IP address redirection by user VPN

    Hi all

    I'm having a problem with the VPN user. For users connected via the AnyConnect VPN client, all their Internet traffic out of their local Internet connection, since I was on the split tunneling. However, I need a specific IP address public through the VPN tunnel and on the diameter of the main office, rather than the internet connection at the user's local. I managed to have this IP address through the tunnel of the ASA headquarters, but it seems that it gets stuck somewhere here, or maybe the return traffic gets blocked. I use an ASA 5520 at Headquarters, with the software version 8.3. Can someone help me?

    Thank you!

    Hi Nathalie,.

    This is what you need:

    network vpn-pool objects

    subnet 192.168.1.0 255.255.255.0

    !

    external-server object from network

    host 7.7.7.7

    !

    NAT (outside, outside) 1 source vpn-pool dynamic interface external-server static external-server destination

    permit same-security-traffic intra-interface

    That should allow the u-turn on the external interface, so the customers out to the Internet with the external IP of the FW when trying to reach the 7.7.7.7 server.

    Let me know.

    Thank you.

    Portu.

    Please note any workstation that you be useful.

  • I am running winXP home on laptop wireless via a router, and I continue to have an effect on the net.

    login procedure

    I am running winXP home on laptop wireless via a router and I continue to have an effect on the net, and a window saying I need to go through a certain procedure of connectivity in order to return on the net than what seems to come regularly and after that I went through the procedure, I'm back on the net could you please inform me how to eliminate this problem.

    Hi conorcloris,

    ·         What is the exact error message?

    ·         Did you do changes on the computer before the show?

    Follow the steps in the article.

    How to troubleshoot a network home in Windows XP

    http://support.Microsoft.com/kb/308007

    In Windows network connection issues

    http://support.Microsoft.com/kb/313242/en-us

    Troubleshooting Internet connection sharing in Windows XP

    http://support.Microsoft.com/kb/308006/en-us

  • How to configure the network home wiFi with dlink router

    I need to create a home network using the dlink WiFi router
    a computer with Vista and the second with XP
    can someone tell me what havo to do to configure the router etc etc o give me same informamation on where I can learn to do
    I want just the old pc with xp for the server and the vista one customer but more importantly I need the file on XP to migrate under vista.
    Thank you very muche for your end of the patient cooperation
    in return, I give free cooking classes
    see you soon

    I'm not sure if you are asking how to set up a secure wireless network, if you ask how to share files between your two computers (and there is no "customer" or "server" in a working group, in a field - which is not), or both.

    So I will give you information on doing both.

    Router - configure manually

    Setting up a router is simple enough. Normally, you run the CD that came with the router and follow the instructions. If you're running Vista, maybe the CD that came with the router does not work; I do not know this. But you can set up the router without the CD. Note that if you have Internet cable for the connection you have just set up the router to DHCP (or there may even be a choice of cable to choose). If you have DSL Internet, you select TRP usually and enter the username and password you selected when you initially set the DSL connection. So:

    1. turn off the power to your cable modem.
    2. attach a class (usually supplied with the router) ethernet cable cat5e port Internet/WAN from the router to the ethernet port on the cable modem.
    3. connect the ethernet cable cat5e from the network card in your computer to one of the ports on the router. If you do not have an ethernet cable (because you were using USB), you will need to go to the store and buy a.
    4. turn on the cable modem. After that all the lights are on, turn on the router.

    To configure the router:

    Have a computer connected to the router with an ethernet cable. Examples given are for a Linksys router. See the manual of your router or the router mftr's Web site. for the parameters by default if you don't have a Linksys. Open a browser such as Internet Explorer or Firefox and in the address bar type:

    http://192.168.1.1 [Enter] (it is default IP address of the router, which varies from router to router then check your manual)

    This will bring you to the login screen of the router. The default username is blank and the Linksys default password is "admin" without the quotes. Enter this information. You are now in the configuration of the router utility. Your configuration utility may be slightly different from mine. The first thing to do is to change the default password because * all * known default passwords for different routers.

    Click the Administration link at the top of the page. Enter your new password. MAKE A NOTE SOMEWHERE THAT YOU WILL NOT LOSE. Re-enter the password to confirm it, and then click Save settings at the bottom of the page. The router will reboot and show you the box of connection again. Do not fill in the user name and put it in your new password to enter the configuration utility.

    Now, click on the link wireless at the top of the page. Change the network name (SSID) wireless by default to something, you'll recognize. I suggest that my clients not use their surname as the SSID. For example, you might want to name your network wireless network "CastleAnthrax" or similar. ;-)

    Click on save settings and when you get the prompt that your changes were successful, click the wireless security link which is just beside the Basic Wireless Settings link (where you changed your SSID). Most computers purchased during the last 4 years have the wireless hardware that will support WPA2-Personal (also known as WPA2-PSK). This is the desired encryption level. If your wireless hardware is older, use WPA. Don't use WEP, because who is easily broken within minutes. So go ahead and set the Security Mode WPA2-Personal. Do this and enter a password. For example, you could use the password ' here be dragons, beware you scurvy dogs! The password is what you enter on all computers that are allowed to connect to the wireless network. MAKE A NOTE SOMEWHERE THAT YOU WILL NOT LOSE.

    At this point, your router is set up and if the computer that you use to configure the router will normally connect wireless, disconnect the ethernet cable and wireless of the computer should see your new network. Enter the password that you have created (exactly as you wrote it with all capital letters and punctuation) to join the network and start surfing.

    Networking

    Here are the steps of general network troubleshooting. Just cannot apply to your situation, so just take the bits that are. It may seem daunting, but if you follow the steps in the links and suggestions below calmly and consistently, you will have no difficulty to implement your sharing.

    Excellent, comprehensive, but easy to understand article on sharing files/printer under Vista. Contains information about sharing printers and files, and the folders:

    http://TechNet.Microsoft.com/en-us/library/bb727037.aspx

    For XP, start by running the Network Setup Wizard the on all machines (see warning in section A below).

    Problems sharing files between computers on a network are usually caused by 1) a misconfigured firewall or a firewall neglected (including a dynamic firewall in a virtual private network); or (2) inadvertently run two firewalls such as the firewall of Windows and a third-party firewall. and/or (3) do not have accounts to the same users and passwords on all computers in the workgroup. (4) tries to create actions where the operating system does not.

    A. configure the firewall on all machines to allow traffic to local area network (LAN) as being approved. With the Windows Firewall, it means which allows file sharing / print on the Exceptions tab normally run the XP Network Setup Wizard will take care of this for these machines. The only "witch hunt", it will turn on the XPSP2 Windows Firewall. If you are not running a third-party firewall or you have an antivirus/security with its own firewall component program, then you're fine.  With a third-party firewall, I usually set up the allocation of LAN with an IP address range. E.g. would be 192.168.1.0 - 192.168.1.254. Obviously you would substitute your correct subnet. Refer to the safety of any third party program or the user forums for how to correctly configure its firewall. Do not run more than one firewall. DON'T STOP FIREWALLS; CONFIGURE THEM CORRECTLY.

    (B) to facilitate the Organization, put all computers in the same workgroup. This is done from the System applet in Control Panel, the computer name tab.

    C. create the counterpart of the user accounts and passwords on all machines. You do not need to be logged into the same account on all machines and assigned to each user account passwords can be different; accounts/passwords just need to exist and to match on all machines. DO NOT NEGLECT TO CREATE PASSWORDS, EVEN IF ONLY OF SIMPLE. If you want a machine to boot directly to the desktop (a particular user account) for convenience, you can do this:

    XP - configure Windows to login automatically (MVP Ramesh) - http://windowsxp.mvps.org/Autologon.htm

    Vista - Start ORB > Search > type: netplwiz [Enter]
    Click continue (or provide an administrator password) when you are prompted by UAC

    Uncheck "users must enter a user name and password to use this computer". Select a user account to connect automatically by clicking on the account you want to highlight and press OK. Enter the password for this user account (when it exists) when you are prompted. Leave blank if there is no password (null).

    D. Si one or more of the computers is XP Pro or Media Center, turn off Simple file sharing (Folder Options > view tab).

    E. create share as you wish. XP Home does not share the users directory or the Program Files, but you can share folders inside those directories. A better choice is to simply use the Shared Documents folder. See the first link above for more information on Vista sharing.

    F. you have the job of file sharing (and tested by exchanging a file between machines), if you want to share a printer connected locally to one of your computers, share of this machine. Then go to the printer mftr Web site. and download the latest drivers for the correct system. Install them on the target machines. The printer must be collected during the installation procedure. If this isn't the case, install the drivers and then use the Add Printer Wizard. In some cases, printers must be installed as local printers, but it is outside this response.
    MS - MVP - Elephant Boy computers - don't panic!

  • My wireless via a router disconnects completely and it is difficult to connect again

    My printer is connected to my computer via a router (D-link, DIR-655) en. When I try to use all the functions of my connection printer wireless disconnects tottaly and its very difficult to connect again. My computer can not find the network connection at all. After several time setting the router power on and off, the computer can find the network connection wireless and after that the printer works fine until the next time the printer again, same procedure repeated again.

    Oh, I don't think you want to connect your printer to the router with a USB cable.  There may be a link to troubelsome, you will only be able to print to it, analyzing him.

    Connect the printer to your router with an Ethernet cable.  After that go on each PC and delete all instances of the printer in Control Panel > printers (or devices & printers on Win 7).

    Then, add the printer in this way:

    1. make sure the printer is on and connected to your network. Verify that you can access the printer's internal web page by accessing its IP address before continuing. Get his IP address for a network Test printed on the front of the printer.
    2. click on > start > Control Panel > devices & Printers.
    3. click on add a printer
    4. Select local printer
    5. Select create a new port and select Standard TCP/IP Port, and click Next.
    6. under device type, select TCP/IP Device. Under the name of host or IP address, enter the IP address of the printer. Click Next.
    7. Select Hewlett-Packard in the list of manufacturers and select and select your printer model. Click Next.
    If your printer model is not in the list, then select disk provided, browse the CD that came with your HP printer and select the first file begins with hp and ending with INF. click Open, then OK. Select your printer model. Click Next.
    8. If prompted, use the driver that is currently installed.
    9. He will ask the name of the printer - enter a new name or use the one existing. This will be the name of the printer that you select from other applications.
    10. we may ask you to share the printer. Choose No.
    11. the printing area of Test Page is displayed. Go ahead and print it out.
    12. click on finish.

  • BlackBerry smartphones can not connect to ISP via wireless router.

    I have my cell service through T-Mobile and recently upgraded to a Bold 9700 with internet service. I can browse the internet via 3G network and an address of hot spot using Wi - Fi. What I can't do, is access to the internet via my router wireless at home. The router Netgear (WPN824 v3) works very well via the modem cable for laptops and smartphone Motorola click on my daughter. When I turn off the 3G network, I get a "cannot find server message".

    I went through the technical support to the company of cable, Blackberry and Netgear without solution. The problem seems to be with the router, but I can't find a way to fix it. I'm about to buy another phone or router. If anyone has any ideas please help. Thank you

    It works!  I've accessed the configuration of the router. It would work without security. It would not work with WPA - PSK [TPIK], I activated the two WPA2-PSK [AES] AND WPA-PSK [TPIK] AND IT is CONNECTED. I don't KNOW WHY, BUT I SURE AM HAPPY. I guess the BB don't like TPIK

  • DMVPN Tunnel and EIGRP routing problem

    I have redundant paths to a remote 2811 router on my network of sites.  The first links is a T1 frame relay connection that has been in place for years, and the new link is on a 54 Mbps fixed wireless that was recently created.

    I'm under EIGRP to my process of routing protocol 100 for the two links.

    I installed a DMVPN Tunnel between the remote 2811 and no. 2851 router on my host site.  The tunnel interface shows to the top and to the top of both sides and I can ping the IP remote tunnel of my networks side host.

    However my eigrp routes are not spread over this new tunnel link and if I run a command show ip eigrp neighbor on each router I show only the neighbor for the frame relay link and not the new wireless link.

    What I'm missing here?

    A tunnel0 to see the shows the following:

    Tunnel0 is up, line protocol is up
    Material is Tunnel
    The Internet address is 10.x.x.x/24
    MTU 1514 bytes, BW 54000 Kbps, DLY 10000 usec,
    reliability 255/255, txload 1/255, rxload 1/255
    Encapsulation TUNNEL, loopback not set
    KeepAlive not set
    Tunnel source (FastEthernet0/1), destination 172.x.x.x 10.x.x.x
    Tunnel/GRE/IP transport protocol
    Key 0x186A0, sequencing of the people with reduced mobility
    Disabled packages parity check
    TTL 255 tunnel
    Quick tunneling enabled
    Tunnel of transmission bandwidth 8000 (Kbps)
    Tunnel to receive 8000 (Kbps) bandwidth
    Tunnel of protection through IPSec (profile "CiscoCP_Profile1")
    Last entry of 00:00:01, exit ever, blocking of output never
    Final cleaning of "show interface" counters never
    Input queue: 0/75/0/0 (size/max/drops/dumps); Total output drops: 947
    Strategy of queues: fifo
    Output queue: 0/0 (size/max)
    5 minute input rate 0 bps, 0 packets/s
    5 minute output rate 0 bps, 0 packets/s
    packages of 880, 63000 bytes, 0 no buffer entry
    Received 0 broadcasts, 0 Runts, 0 Giants 0 shifters
    errors entry 0, 0 CRC, overgrown plot of 0, 0, 0 ignored, 0 abort
    output of 910 packages, 81315 bytes, 0 underruns
    0 output errors, 0 collisions, 0 resets interface
    unknown protocol 0 drops
    output buffer, the output buffers 0 permuted 0 failures

    Please go ahead and add a static route on the hub, so it goes through the wireless link and let me know if everything works correctly.

    Federico.

  • I want to use a Terminal Airport Express to extend network provided by my Fios router/modem without going through another airport base.  Is there a way to do this?  I understand that Apple does not support this, but surely there must be a way to do this.

    Can someone tell me how to set up an Airport Express Terminal to expand Network provided by my Fios router/modem without going through an airport as a base?  I understand that apple does not support this use, but my applecare Advisor said it's possible.  Thank you!

    Unfortunately, your AppleCare Advisor is wrong if he or she has told you that an AirPort Express to extend wireless signal of a Fios router/modem.

    Function of "Extend a wireless network" Apple is an exclusive feature that was designed by Apple engineers to extend the signal from another wireless only router from Apple. Thus, the AirPort Express... or any other router Apple besides... would not be able to extend wireless a Fios network.

    SO... you have the possibility to locate the Airport Express where it is needed... And... Connect it to the Fios router/modem with a permanent, wired Ethernet cable connection, then the AirPort Express can 'extend' in this way.

    Or... If you are ready to add a second AirPort Express, connect the first near Fios modem/router with an Ethernet cable, then the second Airport Express could extend the signal first Express wireless.

    Another way to say the same thing, is that if you want an Apple AirPort router to extend wireless network... then you need two Apple routers to achieve this goal.

Maybe you are looking for

  • Fade tool will not work

    Hello I'm trying to use the gradient tool to make a fade out on a track. I chose it and drag it on the end of the runway, but it creates just a highlighted area, and then disappears - even if you click and drag on the desktop of a mac and it creates

  • Can not find the attachments uploaded to email. Cannot find downloads for upgrades. Cannot find downloaded games.

    I followed the procedure, as it is indicated on the screen, when downloading attachments to e-mail and after it shows the process ended the download seems to disappear. I can't find anywhere. The same thing happens when I try to download games, updat

  • Launch Startup Repair does not work

    Hi, the 'Launch Startup Repair' option does nothing for my installation of Windows 7 64-bit edition.  If I select the screen simply refreshes and presents me with the same two options - Launch Startup Repair and start Windows normally.  It's as if so

  • Windows 7 computer goes into Sleep Mode while the activity of the system

    Hello, I have windows 7 premium.  I think there may be a bug that needs to scan, my system goes to sleep while there is the activity of the system.  For example, when downloading a file, do a virus or by post where analyze or defragment.  I believe t

  • How to add the application menu

    Hi guys, I want to add a menu to the application. I can not get the menu. I just tried to add the menu for the lettering of calendar and I can't get any code, what could be the problem public class Main extends Application { Main() { MyMenuItem myMen