Cisco 2611XM syslog errors

Hello, I have these types of errors on a 2611XM router. Anyone got a clue?

tell xak #sh connect

Syslog logging: activated (0 messages dropped, rate limited, 2 messages

vacuum of 0, 0 overruns, xml disabled, filtering of persons with reduced mobility)

Recording console: level of debugging, 4812 messages, xml, disabled,.

filtering of persons with reduced mobility

Monitor logging: debug, 8 messages level, xml, disabled,.

filtering of persons with reduced mobility

Logging buffer: level of debugging, 4812 messages, xml, disabled,.

filtering of persons with reduced mobility

Logging size Exception (4096 bytes)

County and logging messages timestamp: disabled

Logging trap: notifications, lines of 1051 message logged level

192.168.10.2, lines of 1051 journaled message, xml disabled, logging

filtering of persons with reduced mobility

Log buffer (100000 bytes):

2y1w: rsa_create_handler: Invalid AVL (0x5ED3F88, 0x5ED3F90, 0x5ED3F98, 0x5ED3FA0, 0x5ED3FA8, 0x5ED3FB0, 0x5ED3FB8, 0x0)

2y1w: IPSECcard: an error return 0x007F

. June 7 03:32:11: % 3-SSH-KEYPAIR: attempt to generate keys of server failed - error code: hardware error

-Process = "SSH event handler", PW = 0, pid = 3

-Traceback = 8085F7C8 8156F154 C 8059, 338 8059F75C

. June 7 03:32:11: % SSH-5-persons with DISABILITIES: SSH 2.0 has been disabled

. 7 Jun 04:20:37: % CRYPTO-6-IKMP_MODE_FAILURE: fast processing mode has failed with the counterpart to 10.0.0.11

. June 7 05:58:29: % SYS-5-CONFIG_I: configured from console by lgcomsupport on vty1 (192.168.0.108)

. June 7 06:00:19: % SSH-5-ACTIVATED: SSH 2.0 has been activated

. June 7 06:00:21: % SYS-5-CONFIG_I: configured from console by lgcomsupport on vty1 (192.168.0.108)

. 7 June 06:03:07: % SYS-5-CONFIG_I: configured from console by lgcomsupport on vty1 (192.168.0.108)

. 7 June 09:03:52: % CLEAR-5-COUNTERS: claire counter on interface Serial0/0 by lgcomsupport on vty1 (192.168.0.184)

. June 7 09:09:31: % SYS-5-CONFIG_I: configured from console by lgcomsupport on vty0 (192.168.0.108)

. 7 June 09:10:24: % SYS-5-CONFIG_I: configured from console by lgcomsupport on vty0 (192.168.0.108)

. June 7 09:13:04: % SYS-5-CONFIG_I: configured from console by lgcomsupport on vty0 (192.168.0.108)

. 7 June 09:15:02: % SYS-5-CONFIG_I: configured from console by lgcomsupport on vty0 (192.168.0.108)

. 7 June 09:28:23: % SYS-5-CONFIG_I: configured from console by lgcomsupport on vty0 (192.168.0.108)

2y1w: rsa_create_handler: Invalid AVL (0x5ED2D08, 0x5ED2D10, 0x5ED2D18, 0x5ED2D20, 0x5ED2D28, 0x0, 0x5ED2D38, 0x5ED2D40)

2y1w: IPSECcard: an error return 0x007F

. 7 Jun 20:00:26: % 3-SSH-KEYPAIR: attempt to generate keys of server failed - error code: hardware error

-Process = "SSH event handler", PW = 0, pid = 3

-Traceback = 8085F7C8 8156F154 C 8059, 338 8059F75C

. 7 Jun 20:00:26: % SSH-5-persons with DISABILITIES: SSH 2.0 has been disabled

. 8 Jun 02:20:38: % CRYPTO-6-IKMP_MODE_FAILURE: fast processing mode has failed with the counterpart to 10.0.0.11

tell xak #sh worm

Cisco IOS software, software C2600 (C2600-ADVSECURITYK9-M), Version 12.3 (11) T, VERSION of the SOFTWARE (fc2)

Technical support: http://www.cisco.com/techsupport

Copyright (c) 1986-2004 by Cisco Systems, Inc.

Update sam 18-sept.-04 11:38 by eaarmas

ROM: System Bootstrap, Version 12.2 (7r) [next 7r], RELEASE SOFTWARE (fc1)

tell xak uptime is 2 years, 1 week, 5 days, 3 hours, 14 minutes

System to regain the power ROM

System restarted at 12:32:45 IS Wednesday, may 27, 2009

System image file is "flash: c2600-advsecurityk9 - mz.123 - 11.T.bin.

Cisco 2611XM (MPC860P) processor (revision 0 x 100) with 94450K / 3854K bytes of memory.

Card processor ID JAE071800DF (3191415314)

M860 processor: Ref. 5, mask 2

2 FastEthernet interfaces

2 serial interfaces

1 module of virtual private network (VPN)

32K bytes of NVRAM memory.

32768 K bytes of processor onboard flash system (read/write)

Configuration register is 0 x 2102

Hello

You probably have a hardware problem with your VPN module.

Kind regards.

Alain.

Tags: Cisco Network

Similar Questions

  • Center of Cisco IP solutions - error reporting, jobs SR manually removing from cli, Autostart ISC after startup

    Hello

    1. I get the following error when you run a report;

    * Unable to create the report. The following errors occurred:
    1: NBI reports the connection has failed. Invalid security identification information

    What could be the problem?

    2. How can I create custom reports? Creates the only way XML files?

    3. How can I remove pools of resources or jobs manually OS cli?

    4. is it possible to auto start ISC when the server restarts?

    Hello

    For 1. It is perhaps a license problem (NBI licenses), which version are you? I've heard reports are enabled by default on 6.0, but not sure.

    For 2. Look at http://www.cisco.com/en/US/docs/net_mgmt/ip_solution_center/6.0/infrastructure/reference/guide/monit1.html#wp1229130 . I think that xml is the only way, even if you use directly the xmlapi.

    3. I don't know if this is even possible. You can do this with the nbi and xmlapi.

    For 4. Look at the symptom of http://www.cisco.com/en/US/docs/net_mgmt/ip_solution_center/6.0/installation/guide/aptrbl.html#wp1032457 6.

    Hope I helped.

  • VPN router Cisco 2611XM VPN client

    I have 2611XM router on a Central site with two FastEthernet interfaces? XA; (FastEthernet0/0 and FastEtherne0/1). FE0/0 has private ip address?xa;192.168.1.1/24 and it connects on LAN 192.168.1.0/24. FE0/1A public? XA; address x.x.x.x/30 and his connects to Internet. There on this NAT router? XA; with overload. ? XA; This router is to give customers remote access with Cisco VPN client on? XA; Internet to the LAN and at the same time, the users local access to the Internet. ? XA; I did a config that establish the tunnel between the clients and the router but? XA; I can't ping all devices on the local network. ? XA; The router must also give remote access and LAN in the scenarios from site to site? XA;

    I can establish the tunnel between my PC and the router via a dial-up Internet connection. But when the tunnel is established that except my public IP address of the router, I can't ping any public IP address. I can ping all other customers who owns the ip address of the pool for customers.

    Addition of the sheep route map should not make you lose the connection to the router.

    Are the commands that you will need to put in

    access-list 101 deny ip 192.168.1.0 0.0.0.255 10.1.1.0 0.0.0.255

    access-list 101 permit ip 192.168.1.0 0.0.0.255 any

    sheep allowed 10 route map

    corresponds to the IP 101

    You need to delete translations of nat or remove commands 'ip nat outside' and 'ip nat inside' temporarily while you are taking the following off the coast

    no nat ip inside the source list 7 pool internet overload

    and add the command

    IP nat inside source map route sheep pool internet overload

    Make sure that you reapply the "nat inside ip' and ' ip nat outside of ' orders return of your internal users will not be able to go to the internet.

    You can search this config in the link that sent Glenn-

    http://www.Cisco.com/warp/public/707/ios_D.html

    I pasted the lines that you should look into setting up the example below

    ! - Except the private network and the VPN Client from the NAT process traffic.

    access-list 110 deny ip 192.168.100.0 0.0.0.255 192.168.200.0 0.0.0.255

    access-list 110 deny ip 192.168.100.0 0.0.0.255 192.168.1.0 0.0.0.255

    access-list 110 permit ip 192.168.100.0 0.0.0.255 any

    ! - Except the private network and the VPN Client from the NAT process traffic.

    sheep allowed 10 route map

    corresponds to the IP 110

    -Except the private network and the VPN Client from the NAT process traffic.

    IP nat inside source map route sheep interface FastEthernet0/0 overload

    Thank you

    Ranjana

  • Addition of Tesla M6 to Cisco B200 M4, error in vmware plugin

    I am trying to install my new M6 Tesla GPU card in my 6.0 ESXi host. I installed the software nvidia on the host and which seems ok. I can add the GPU card to my VMS in vcenter as well, BUT when I try to turn on the virtual machine, I get the following error:

    Not able to initialize plugin ' / usr/lib64/vmware/plugin/libnvidia-vgx.so' for vGPU 'grid_m6-8 q.

    I tried all the other GPU profiles and I get the same error for each GPU profile. I've updated my 6.0 to UP2 ESXi host and which don't seem to have any effect. I use the version of the driver host 352.83.

    I also checked the compatibility for this tesla M6 card list and my cisco M4 b200 is listed as compatible.

    For troubleshooting, I ran the following commands:

    [root@VH1:~] nvidia-smi

    Kills Apr 5 21:47:42 2016

    +------------------------------------------------------+

    | NVIDIA-SMI 352.83 driver version: 352.83 |

    |-------------------------------+----------------------+----------------------+

    | GPU name persistence-M | Bus - Id Disp.A | Volatile Uncorr. ECC |

    | Fan Temp Perf Pwr:Usage / Cap |         The memory usage | GPU-Util Compute M. |

    |===============================+======================+======================|

    |   Tesla 0 M6 on | Off 0000:81:00.0 |                    0 |

    | S/O 47 P8 16W / 100W |     30MiB / 7679MiB |      0% by default.

    +-------------------------------+----------------------+----------------------+

    +-----------------------------------------------------------------------------+

    | Process: GPU memory.

    |  The name of Type PID GPU use process |

    |=============================================================================|

    |  No common process found |

    +-----------------------------------------------------------------------------+

    Looks good to me?

    I also ran:

    [root@VH1:~] dmesg | grep-e "NVRM". NVIDIA.

    2016-04 - 04 T 17: 05:16.417Z cpu3:33421) loading module nvidia...

    2016-04 - 04 T 17: 05:16.423Z cpu3:33421) Elf: 1865: module a license NVIDIA nvidia

    NVRM: vmk_MemPoolCreate spent to 4194304 pages.

    NVRM: UNIX x86_64 Sun Feb 352.83 NVIDIA kernel Module loading 7 20:16:36 PST 2016

    2016-04 - 04 T 17: 05:16.754Z cpu3:33421) device: 191: registered driver "nvidia" of 20

    2016-04 - 04 T 17: 05:16.754Z cpu3:33421) Mod: 4943: nvidia initialization succeeded with module ID 20.

    2016-04 - 04 T 17: 05:16.754Z cpu3:33421) nvidia loaded successfully.

    2016-04 - 04 T 17: 05:17.553Z cpu29:33420) device: 326: find nvidia for device 0x36554304c6e6377b driver

    NVRM: nvidia_associate vmgfx0

    2016-04 - 04 T 17: 08:15.323Z cpu2:35277) IntrCookie: 1915: cookie 0x3d moduleID 20 < nvidia > exclusive, 0x1d flags

    Any other ideas on this?  Or anything else to try?

    Thanks in advance

    After some research, I figured this out.  Looks like the Tesla M6 and M60 Telsa get shipped in mode 'compute', which is not compatible with VMware or other hypervisors.  SO, you will need to download a gpumodeswitch utility, start the server with this utility and change the mode of the map to 'graphics '.  I hope this helps a few people running in this!  Check out the nvidia site for more information on their GPUmodeswitch utility.

  • Impossible to get the specific features of cisco in LMS syslogs

    Hello

    It's about a problem that we face with our LMS 3.2.1. We cannot get specific cisco devices syslogs, while we are able to get the rest devices syslogs. one you suggest what would be the exact reason for this and the troubleshooting steps.

    Thanks in advance,

    Raja

    Hello

    The first thing I would say is to make sure that you have these devices configured to send the syslogs to that specific server. See config below:

    3725B - CR - NMS (config) #logging host?
    Host name or A.B.C.D IP address of the syslog server

    If that is already set up, please make sure that syslog messages are on the server. Create a message simple syslog and check the syslog.log file located in NMSROOT/CSCOpx/log to make sure it's written there. You can also run a capture of packages to confirm the foregoing. If you have this installed on Linux/Solaris, check the syslog_info file (/ var/log /).

    You can generate a test syslog as shown below:

    3725 B-CR-NEM #conf t
    Enter configuration commands, one per line.  End with CNTL/Z.
    3725B - CR - NMS (config) #exit
    B-CR-NMS 3725 #.
    * 03:35:42.613 13 Oct: % SYS-5-CONFIG_I: configured from console by admin on vty1 (192.168.10.197)

    NMSROOT is the LMS installation directory

    Let me know the results.

    Allen has.

  • 2611XM support IOS IPS?

    I have a T (15) 12.4 running 2611XM, 256 ram, will support the IOS IPS service?

    Cisco IOS 12.4 (15) T, XM 2611 will support IOS IPS service. The feature value must be a set of features in advance. The IOS from Cisco IPS acts as an online intrusion prevention sensor, watching packets and sessions they flow through the router and each packet scanning to match all Cisco IOS IPS signatures. When it detects suspicious activity, it responds before network security can be compromised and records the event through Cisco IOS syslog messages or event of Security Exchange (CETS).

  • Java errors using ticket submit script.

    Hello people.

    I used the script submit_ticket.aef of your repository with success on the IPCCX 3.5.3sr2, 4.1.3sr1 CCM for several months now. The scripts have not been updated, but now we receive loads of java errors after we click on submit:

    com.cisco.app.ApplicationTaskInactiveException: is no longer running for the task

    com.cisco.wfapi.WFClassInvocationException: error call to the class.

    java.lang.reflect.InvocationTargetException

    to com.cisco.app.impl.ApplicationManagerImpl$ TaskImpl.cleanup (ApplicationManagerImpl.java:4063)

    at com.cisco.app.impl.WFWorkflowAppDebugTaskWrapper.taskAborted(WFWorkflowAppDebugTaskWrapper.java:693)

    at com.cisco.app.impl.WFWorkflowAppDebugTaskWrapper.execute(WFWorkflowAppDebugTaskWrapper.java:748)

    at com.cisco.wfframework.engine.core.TaskManager.runTaskNormally(TaskManager.java:291)

    at com.cisco.wfframework.engine.core.TaskManager.runTask(TaskManager.java:246)

    at com.cisco.wfframework.engine.core.Invoker.invoke(Invoker.java:67)

    The session ID is to be filled ok example: http://10.102.0.100:8080/ticket.jsp?%20&sessionID=1108000000007,0

    When you click submit submit & no attached java error occurs.

    When debugging the submit_ticket.aef script I get an error of class invocation. ; is:Java.lang.reflect.InvocationTargetException nested exception

    Could someone please help me with how I find what mean these errors of java and what is perhaps the task no longer running.

    Tips/advice etc would be greatly appreciated.

    See you soon,.

    NJ.

    1. in the office administrator, according to the company, make sure you have

    This two fields created: sessionID (type 2) sequence (type 3)

    2. change the available to field (type 252) by selecting default in the page layout list.change the name, rather than default, the ticket name.

    3 Add the sessionID and the succession to the field of page layout.

    4. now, go in the Workflow in Desktop Admin: in the office administrator select Workflow.In events, select the (s) loose.

    Add a rule called ticket and enter an action called ticketEntry.Select launch application external nd:

    : May Explorer\IEXPLORE. EXE

    Hover over the sessionID of the arguments column. Select Enable rule, any Condition is true, and a condition set sessionID is not empty.

    Click OK.

    5. go in the app and create submit_app. In the field script select submit_ticket.aef, and then add a HTTP trigger (/ ticket)

    6 Creat a subsystem HTTP: URL: / ticket (please do not confuse this name with the ticket.jsp that is executed when the agent filed the appeal)

    Language: EnglishApplication name: name of your choice (example Submit_app)

    Please do not forget that you have followed all of these steps.

  • ACI Cisco Simulator in a virtual machine?

    I understand (http://www.cisco.com/c/en/us/products/collateral/cloud-systems-managemen... ) that this need for Simulator machine physical but all the world got it running on a virtual machine?

    I use aci-Simulator - s dk9.1.1.1 .iso

    I'm running it on 6.0 ESX and VM configuration is as below.

    100 GB SSD

    10 NW cards,

    16 GB memory

    8 cores

    Even if get you this to install, it won't rise properly.  The software is written in order to check the ID of physical product of the machine on which it is installed.  If that does not match an expected value, the APIC fails to start properly - DME services begin voluntarily.  You must purchase an APIC-SIM-S and install it on that.  In manufacturing the APIC-SIM-S hardware is programmed with the right PID.

    Mike

  • CISCO ASA 5520 telnet

    I have a CISCO5520 and telnet has suddenly stopped working on my inside interface.

    I checked my syslog error and get the following

    5 October 15, 2013 11:56:02 Resource 'telnet' limit 5 reaching for the context "single_vf".

    No idea what this could be?

    Thank you

    James.

    You can get the output of

    Conn. HS all the port 23

    Show proc | in telnet and

    See the version

    ~ BR
    Jatin kone

    * Does the rate of useful messages *.

  • 51 in VM system error?

    Hi all

    Not sure if this is corect forum but I'm sure someone will put me right.

    I have a Windows Server 2003 SP2 running on a San connected to my very small ESX3.5 server supporting six virtual servers. Two of the servers have been moved on the SAN while the other remain on the local storage of the ESX host.

    One of these servers is configured as follows: Server 2003 SP2 32-bit, 2048 RAM with 2 GB SCSI disks 50 mg hard confgiured Basic versus dynamic inside Windows.le server disks host several small SourceSafe databases, but also a new software used by our QA department. This software contains a large number of small files stored in its own local database format. I'm not sure if this software is the culprit in my scenario.

    What I see is a small number of system error 51 s generated in the event log system on this server at random times during the day. Googling this error against VMs comes with questions and answers from 2005 to 2008 to virtualize SQL servers with a large amount of disk i/o. I wonder if I see the same thing, if it's really a question or if I can do some other configuration changes to help solve the problem?

    Kind regards

    Gordon

    Hello

    In regard to the remark of MS and not performing VM enough, it is interesting to note that MS has this kind of comments so that their own product (Hyper-V et al.) are powerful enough to properly support the MS SQL in a virtual environment. I would chalk up to MS FUD.

    in any case, I guess it of mud slinging and not very relevant to the discussion.

    For a more relevant counterargument, take a look at this article from VMware performance group:

    http://blogs.VMware.com/performance/2008/05/100000-IO-Opera.html

    Or for a report of no vmware, take a look at this study of Brocade:

    http://www.Brocade.com/downloads/documents/white_papers/WP_VMWareSQLServerBenchmark-00.PDF

    Using virtualization and bays of external storage, you can stagger out better as simply assigning the entire machine to SQL Server, and assuming that you get the same scaling performance upward. So by applying good configuration you can actually get more performance from your hardware in the VMS as using physical hardware.

    With regard to SQL2000, SQL2005 vs. I do not know your application and SQL 2005 is if I remember correctly - that's all right now-backward compatibility with SQL 2000 almost everything. I'm a database developer, but use about any server SQL, not only the products of Ms.

    The reason why I mentioned, it's that I don't think that even Microsoft still supports SQL 2000, so if you can improve it, would be nice. With respect to the resolution of the 51 system error report, I also don't think that this will solve, but don't really know. I can't test/check here because I have no more SQL 2000 configurations.

    Now, back to your syslog error event. Personally, I doubt it is a serious mistake and that a report of an absence of cache, but for now, I'm having trouble to back up this statement. If it's a mistake that occurs every day, then you might be able to set up some performance counters to check if the host is trading at the time of such a report.

    If I look at the log of my current VM system, I also see an error 51 error, but it's for my floppy drive.

    An error was detected on device \Device\Floppy1 during a paging operation.

    Consider that your report is for the physical hard drive? He also has the part "paging operation"?

    You have only a single mounting of hard disk with this virtual machine?

    --

    Wil

  • ASA 5505 host under license limit has been exceeded

    I'm receive syslog message 450001 - host license limit has been exceeded.

    To see the version on my ASA 5505 (8.0.2), inside hosts are limited to 10. The limit of 10 corresponds to the limit (10) syslog error message.

    How is this calculated number of hosts? Show arp represents 6 addresses glued to the inside interface.

    Hello

    Don't use "show arp", use "local host" instead.

    Excerpt from http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/specs.pdf

    In routed mode, hosts inside (business and home VLAN) account in the limit only when communicating with the outside (Internet, VLAN).

    Internet hosts are not counted toward the limit. Also, guests who initiates the traffic between businesses and home are not counted toward the limit. The interface

    partner with the value default route is considered to be the Internet interface. If there is no default route, hosts on all interfaces are taken into account in the limit.

    In transparent mode, the interface with the smallest number of hosts is counted within the limits of the host. See the show local-host command to view the host

    limits.

    Kind regards

    Dandy

  • nat ASA 5520 problem

    Hi I have a Cisco Asa 5520 and I want to vpn site-to-site by using another interface with a carrier of lan to lan, the problem is when I try to pass traffic have the syslog error to follow:

    No translation not found for udp src lan2lan:10.5.50.63/44437 dst colo: biggiesmalls groups / 897
     
    LAN to LAN service interface is called: lan2lan
    one of the internal interfaces is called: colo

    I think that is problem with Nat on the SAA but I need help with this.
     
    Config:
     
    !
    interface GigabitEthernet0/0
    nameif outside
    security-level 0
    eve of fw - ext 255.255.255.0 address IP XXaaaNNaa
    OSPF cost 10
    OSPF network point-to-point non-broadcast
    !
    interface GigabitEthernet0/1
    No nameif
    no level of security
    no ip address
    !
    interface GigabitEthernet0/1.50
    VLAN 50
    nameif lb
    security-level 20
    IP 10.1.50.11 255.255.255.0
    OSPF cost 10
    !
    interface GigabitEthernet0/1,501
    VLAN 501
    nameif colo
    security-level 90
    eve of fw - int 255.255.255.0 172.16.2.253 IP address
    OSPF cost 10
    !
    !
    interface GigabitEthernet1/1
    Door-Lan2Lan description
    nameif lan2lan
    security-level 0
    IP 10.100.50.1 255.255.255.248
    !
    access extensive list ip 10.1.0.0 lan2lan_cryptomap_51 allow 255.255.0.0 object-group elo
    permit access list extended ip sfnet 255.255.255.0 lan2lan_cryptomap_51 object-group elo
    pager lines 24
    Enable logging
    host colo biggiesmalls record
    No message logging 313001
    External MTU 1500
    MTU 1500 lb
    MTU 1500 Colo
    lan2lan MTU 1500
    ICMP unreachable rate-limit 1 burst-size 1
    ARP timeout 14400
    NAT-control
    Global 1 interface (external)
    interface of global (lb) 1
    Global (colo) 1 interface
    NAT (lb) 1 10.1.50.0 255.255.255.0
    NAT (colo) - access list 0 colo_nat0_outbound
    NAT (colo) 1 10.1.13.0 255.255.255.0
    NAT (colo) 1 10.1.16.0 255.255.255.0
    NAT (colo) 1 0.0.0.0 0.0.0.0
    external_access_in access to the external interface group
    Access-group lb_access_in in lb interface
    Access-group colo_access_in in interface colo
    Access-group management_access_in in management of the interface
    Access-group interface lan2lan lan2lan
    !
    Service resetoutside
    card crypto match 51 lan2lan_map address lan2lan_cryptomap_51
    lan2lan_map 51 crypto map set peer 10.100.50.2
    card crypto lan2lan_map 51 game of transformation-ESP-3DES-SHA
    crypto lan2lan_map 51 set reverse-road map
    lan2lan_map interface lan2lan crypto card
    quit smoking
    ISAKMP crypto identity hostname
    ISAKMP crypto enable lan2lan
    crypto ISAKMP policy 10
    preshared authentication
    3des encryption
    sha hash
    Group 2
    life 86400
    Crypto isakmp nat-traversal 20
    enable client-implementation to date
    IPSec-attributes tunnel-group DefaultL2LGroup
    pre-shared-key xxXnnAA
    tunnel-group 10.100.50.2 type ipsec-l2l
    tunnel-group 10.100.50.2 General-attributes
    Group Policy - by default-site2site
    No vpn-addr-assign aaa
    No dhcp vpn-addr-assign
    Telnet timeout 5
    !
     

    The VPN is OK? ("' isakmp crypto to show his" should show a MM_Active tunnel to the peer address ")

    Normally exempt us VPN site-to-site of NAT traffic. This could be your problem. If you can share your configuration, we can have a look.

    p.s. you should affect the question of the security / VPN forum.

  • Question solve the WSUS on VPN server

    Hi all

    I have 18 sites connected by cisco SA520 is our main office through broadband connections. I can ping my main server at the remote locations. I of the GPO that is written in my XP SP3 of remote computers by telling them the name of my server of wsus http://my-server but they don't connect to the wsus for updates windows server. When I open an IE window on a remote computer and type in http://my-server get the administration page of Cisco A DNS error occurred while opening the page.

    The Cisco device is a DHCP server, has my office main DNS and IP addresses in the network settings on the WINS servers. Clients get the DNS and WINS entries on remote sites to my main site.

    Any help would be greatly appreciated.

    Thank you

    Willis

    With the FULL domain name, you still receive the error DNS and the Cisco management page?  When you do a nslookup check what address IP it solves in and this is the correct IP address of your wsus Server?

    This server is NAT'ed on the outside?  Is this a separate machine or WSUS reside on the domain controller itself?  Do you have other services such as sharepoint installed on the same server?  Have you installed WSUS on a port different for example 8530?  Did you modify the entry of WSUS IIS host header?

    http://support.Microsoft.com/default.aspx?scid=kb;en-us;294382

    http://www.wsuswiki.com/WSUSServerFAQ

    Check the WSUS port: http://technet.microsoft.com/en-us/library/bb632477.aspx

    Make sure that WSUS is assigned an IP address in IIS.  Make sure the port 80 443, or 8530 are open in the firewall.

    Of what you mentioned earlier, it seems to resolve the address to the address of the ASA which is why you get the Cisco administration page.

    A remote client, perform an nslookup check and make sure it is resolve correctly.  If it is to do a tracert and check she was going through the tunnel.  After a running-config rubbed.  Also, in the GPO, you can only use the IP address of the server ex: http://10.10.10.15 or http://10.10.10.15:8530.

    Is this the only DNS problem that you are experiencing?  Group Policy is being processed correctly?  Have you checked for any additional errors eventvwr.exe?

  • Enable SNMP to send blocked due to the loop network interface

    Dear community,

    We had a customer who has created a loop on his layer access and STP blocked some interfaces in order to protect the network.

    Normal behaviour until now, but we would like to receive the device, when these events occur, usually when an interface is set to err - disable or close (I guess it's more err - disable).

    We noticed that somehow the concerned interface was sometimes stay down without checking back and maybe change her status.

    I tried a few commands such as:

    Server enable SNMP traps stpx root-incompatibility incompatibility loop-inconsistent

    Enable SNMP-Server intercepts the port security (this is probably more for quantity of excess on the interface MAC)

    I also found a nice MIB called Cisco-Err-disable

    But I have the feeling that I missed something on the side of the device,

    Any help in setting this up would be greatly appreciated,

    Thank you

    STP will not put the port in err-disable mode.   The mib, CISCO-ERR-DISABLE report when the port is placed in a State of err - disable one of these events published in the MIB:

    CErrDisableFeatureID: = TEXTUAL-CONVENTION
    Current STATUS
    DESCRIPTION
    '- Integer value assigned to several functions/events.
    This error can disable a system entity

    Uni-directional: unidirectional link detection

    bpduGuard: Spanning feature Tree BPDU Guard that prevents
    treatment of BPDU packets on an interface to access

    channelMisconfig: bad configuration of aggregation of General links

    pagpFlap: Link Aggregation of Cisco PAGP protocol errors

    dtpFlap: Dynamic Trunking Protocol errors

    linkFlap: heartbeat of status of links

    l2ptGuard: Tunnel Protocol L2 errors

    dot1xSecurityViolation: 802. 1 x of violations of authentication

    Addition: breaches of Port

    gbicInvalid: invalid errors GBIC (examples):
    GBIC not taken in charge being inserted)

    dhcpRateLimit: DHCP snooping rate limit violation

    unicastFlood: unicast flooding threshold violations

    veterinarians: VLAN Membership Policy Server are related errors

    stormControl: Storm control (unicast, multicast, broadcast)
    threshold violations

    inlinePower: inline power errors

    arpInspection: errors detected by dynamic Arp Inspection
    Feature (DAI)

    portLoopback: Interface Loopback error

    packetBuffer: error on Buffer packets

    macLimit: errors by a function limited Mac address

    linkMonitorFailure: followed link failure

    oamRemoteFailure: Remote failure detected by Ethernet OAM
    (Operations, Administration and Maintenance) function

    dot1adIncompEtype: 802.1ad ether-type incompatible errors

    dot1adIncompTunnel: 802.1ad Pdu Tunnel Incompatible errors

    sfpConfigMismatch: incompatibility of the SFP configuration

    communityLimit: violations of Community limit Vlan

    invalidPolicy: violation of QoS policy

    lsGroup: errors by the State group link tracking feature

    ekey: errors by a key error mechanism

    portModeFailure: failed to change Port mode

    pppoeIaRateLimit: errors by an Agent through PPPoE
    Speed limit feature

    oamRemoteCriticalEvent: Ethernet OAM critical event remote
    Failure

    oamRemoteDyingGasp: Ethernet OAM remote Dying Gasp failure

    oamRemoteLinkFault: remote fault of the Ethernet OAM of link failure

    MRP: Errors detected by multiple VLAN Registration Protocol

    The switch will generate traps with:

    # Server enable snmp traps errdisable

    -Dan

  • IP redirection problem

    Hi all

    I write about this support from the community to ask your help for fact special configuration.

    I have a network of 3 cisco 2611XM routers on the same network with their f0/0 interfaces.

    I have the f0/1 of 3 routers some element of networks that have the same IP addresses.

    Here is a diagram:

    10.1.1.1/24---F0/0 RTR1 network with 1.0.1.0/8 IP f0/1---1.0.1.5/8---element.

    Lo0 10.255.255.1

    10.1.1.2/24---F0/0 RTR2 network with 1.0.1.0/8 IP f0/1---1.0.1.5/8---element.

    Lo0 10.255.255.2

    10.1.1.3/24---F0/0 RTR3 network with 1.0.1.0/8 IP f0/1---1.0.1.5/8---element.

    Lo0 10.255.255.3

    What I want is the following thing:

    When I do a telnet to the f0/0 of router I want to telnet access to the network with IP 1.0.1.0 element

    When I do a telnet to the router Lo0 I want access telnet to the router itself.

    Any other type of traffic is allowed.

    Thanks for your help.

    Jean-Yves

    Hello, Mr. Yves.

    Thank you for your question.

    However, the small business support community is limited to Cisco Small Business Products and the 2611XM router is an enterprise-level product.

    You might consider this question to the business forum to get a better answer.

    https://supportforums.Cisco.com/index.jspa

    Best regards

    Diego Rodriguez

    Cisco Small Business Community engineer

Maybe you are looking for