Connect a Cisco L3 switch behind a 871 using easyvpn

Hello

It is our habit to use easyvpn on 871 routers to connect our remote to our ASA 5500 VPN concentrators.

It works well, we define them VLAN on the 871 and connect Cisco L2 switches behind the VPN routers.

Problem is that now we have to connect the Cisco L3 switch behind the VPN routers and if we face problems of routing...

No way to make works for all the VLAN defined on the switch of L3!

I guess we have to use a specific configuration (IRB?).

Or do we have to use IPSEC-L2L instead of the easyvpn?

Thanks for your help.

Kind regards

Patrick Lee

Patrick,

It will certainly benefit you started.

You can google some more for that.

Someone posted this on the forums, but I think you might want to ask them

https://supportforums.Cisco.com/docs/doc-3066;JSESSIONID=444194CDE250004E116705FF0ADAD955. Node0

I hope this helps.

Marcin

Edit: many thing depend on whether you use NEM and if you plan to use. If you in any qustions stumple - post here.

Tags: Cisco Security

Similar Questions

  • Connecting two cisco ESW 500 series switches.

    Hi Experts,

    I have a basic knowledge of the network and need help.

    I have two switches cisco ESW 500 series and I want to connect with each other.

    Q1 # what type of cable should I use to connect these two CrossOver switches or fiber... What is the advantage of the use of fiber on CrossOver. ?

    Q2 # what are the ports marked in the image used to...?

    Hi tech spec.

    You can use copper or fiber. You can use directly through crossover is not necessary. Fiber is generally more reliable, can offer a higher flow and distances much longer if needed. You will need to buy SFP modules to connect the fiber switches, which is an added expense.

    The ports on the right are shared. If you plug a FPS in the far-right for the fiber port, then the port to the left of it becomes idle. Only port copper or SFP port can be used at the same time. In addition, these ports are usually used for the uplink to another switch or router.

    Please mark this thread as answer or reply if you have any additional questions.

    -Marty

  • VNX 5300 file shared storage - connect to Cisco UCS 6200 interconnection fabric

    Hello

    I'm designing a calculation and Shared Storage solution to help

    • EMC VNX 5300 shared storage

      • Block
      • File - sharing two Data Mover with i/o 10GE ports
    • Cisco UCS Blade Server Platform
      • Interconnection of Cisco UCS 6248 fabric
      • Chassis Cisco UCS 5108

    I have a question about where the connection Data movers with i/o 10GE ports. I connected to the 6248 UCS Cisco fabric interconnections or connect them to the switch IP network?

    kind is ok.

  • Cisco Catalyst 4503-> Cisco 3560 L3-> Cisco 2960 L2-> Cisco SMB switch

    Hi Experts,

    I am trying to add a Cisco SMB SF300 - 24 Switch to an infrastructure that has only the Cisco Catalyst switches

    The base layer is Cisco Cataylst 4503. Distribution is Cisco Catalyst 3560 and Cisco 2960 switches access layer.

    There are about 30 VLAN present in the infrastructure that is announced to all switches using VTP. Inter VLAN routing takes place at basic switches

    by creating the Interface VLAN for each VLAN of L2.

    1. the new 150 VLAN must be created on the new Cisco SMB switch. If I create a corresponding interface 150 VLAN on core switches, it will forward the other VLANs traffic just as he is currently working for Cisco 2960 Catayst switches?

    2. While they inspected, I could see that the DERIVATIVE is not supported on the Cisco SMB switches and I would need to go GVRP if I need to make advertising information to other switches VLAN. But since GVRP is only supported on CatOS and there is no inter operability between GVRP and DERIVED, I would need to manually create the VLAN on the new switch. Is this correct?

    Help, please!

    Thank you very much

    ANUP

    Good afternoon Anup Sasikumar

    Please use our forum

    My name is Johnnatan I am part of the community of support to small businesses, I saw your post and I understand that you want to configure VTP and GVRP.

    I'm afraid you will have to configure it manually each Vlan in each device CatOS GVRP, in order to keep their databases vlan in sync. As you say, VTP is support it not in CatOS

    You can try to connect the two protocols, but I encourage you do not follow this procedure.

    On your question about intervlan routing, if you create a corresponding interface 150 VLANS on switches to base it is routed, if your configuration is correct (port access, ports of junction, intervlan etc..)

    I hope that you will find this answer useful, if it was satisfactory to you, please indicate the question as answer.

    Please evaluate the useful messages.

    Greetings,

    Johnnatan Rodriguez Miranda.

    Support of Cisco network engineer

  • MS NLB Multicast configuration on Cisco Bladecenter switches mode

    We seek to MS NLB Multicast configuration on Cisco Bladecenter switches mode. We are adding static ARP and CAM entries for each port on the switches kernel that

    the Bladecenters are connected to, or just the port of the virtual machine arrives at

    push traffic at this time here? If we add it to a single port,

    How vmotion will work... because it seems that we have to manually

    transfer the arp from one port to the other entry.

    We add the static ARP entry to the entire Cisco switch. If you can VMotion VMs NLB to another host that is physically connected to another switch, then this switch have thus added ARP entry. We have not tested the configuration only on the specified ports. But if you do, make sure that you include all the ports connected to the physical switch (if for DS you have four natachasery configured in a vSwitch...).

    Here's a guide to how we have configured it several times in our society.

    http://www.VI-tips.com/2009/04/NLB-in-VMware.html

  • NIC will not connect at 100 Mbps switch

    I installed VMware 3.5 U3 on 3 HP BL460c blades. I am trying to connect to a switch of 100 Mbps for a VM networks. No network adapters connect to a switch of 100 Mbps, as well the NICs embedded or the NPI NC364M. The status of the env said simply disconnected, and it's not even a light on the switch. Connect a laptop to the NIC with a crossover shows connectivity when the laptop NIC is 1000 but drop down to 100 and the connect light turns off. Connection to a 1000Mbps switch works fine.

    I tried to use the esxcfg-NICS command to set the speed and binary rhythm to 1000, 100 Full Full/Half and 10/half. No luck

    I tried to use ethtool to adjust the speed of the NETWORK card to 100, but the results ' cannot set new parameters: function not implemented.

    The result of ethtool says:

    "Supported binding modes: 1000baseT/Full.

    This means that the NETWORK card supports only 1000? I find it hard to believe that both the NC364M and the embedded NICs are experiencing this problem. Can anyone help?

    It is a problem of capacity of the equipment. The network to blade interface is designed to 1000Mbps and this is how you will link with her.  Please consult the card of HP:

    http://h18000.www1.HP.com/products/servers/networking/NC364m/specifications.html

    http://h18000.www1.HP.com/products/servers/networking/nc373m/index.html

    It is true, that they take over only 1 Gbps connections. If your 2960 uplinks are available, try them and see. Note that the interface of Cisco 1000 t is only 1000Mbps too - it is not just a thing of the blade. Optimized for connections of 1 Gbit/s do not always have options to speed restoration of the interfaces (i.e. 10/100/1000). It is particularly common in the blade architectures.

    -Collin C. MacMillan

    SOLORI - Oriented Solution, LLC

    http://blog.Solori.NET

  • Droid Turbo could not connect the Cisco access point

    Greetings.

    Since the upgrade to a droid turbo, I was unable to connect to the network without wire of my work. I work in the it Department, but my experience with Cisco technologies and wireless is limited, so I tried to understand why. My previous bike x worked fine. We have a network of all the access points managed by a controller Cisco 4402 running version 7.0.98 of the BONES. I was able to connect to another wireless network that I could meet outside of work, and I am able to connect to the network of my work if I connect it is unsecured guest SSID. Only connections to our 4 secure networks fail. The controller reports that my phone cannot all simply to authenticate. The controller is configured for WPA2 / AES using a key 284 on the particular network, that I am trying to connect. I entered this key manually both via copy and paste. As far as my phone goes, I only tried to withdraw and time networks like tent to start it in safe mode without success. I read on various forums android that maybe it's a problem related to Kit Kat and this kind of problem has appeared on other handsets from other manufacturers, but nothing definite.

    Any suggestions would be much appreciated.

    -Josh

    Let me direct you to two other discussions here on the Droid Turbo forum and the other from Cisco which may help.

    Unable to connect to company wifi

    https://forums.Motorola.com/posts/af633eb3e4

    DROID WiFi Turbo questions

    https://forums.Motorola.com/posts/06a2f3c5ca

    Connectivity issues with Cisco and Moto X (Gen 2) allowed RMC controllers (probably related)

    https://supportforums.Cisco.com/discussion/12331486/connectivity-issues-Cisco-controllers-and-PMF-enabled-Moto-x-Gen-2

    I hope this helps!

  • How to distinguish the physical interface and logic (subinterface) interface to the Cisco router/Switch?

    Hi Expert,

    How to distinguish the physical interface and logic (subinterface) interface to the Cisco router/Switch? Can you please clarify a formal way for this so have?

    A physical interface is numbered with the same name of the interface when printing on the physical port. For example "GigabitEthernet 0/1" corresponds to port 1 of the 0 module (or the base unit).

    A logical interface can be a subinterface on a routed port and will have a point ("". "") preceding the number sous-interface (ex. GigabitEthernet 0/1.1). It can also be a loop or a virtual interface (on a router this could also include interfaces like the tunnel and virtual tunnel or VTI types). A switch may also have a VLAN logical interfaces (e.g. interface vlan 1) which are used as layer 3 virtual interfaces of type.

  • Cisco Nexus switches

    I'm looking to deploy a series 5100 Cisco NEXUS switch at 10 Gbps.

    I know that the Nexus is supposed to work with the converged network adapter (for 10 Gbps FCoE, etc.), but can it operate without an ANC?

    I want to put some passthrough 10 Gbps modules in my Dell m1000 chassis and the cables directly to the Nexus switch.

    I know that the Nexus is perhaps overstated for this solution, but it is a step in the UCS solution for us.

    Thoughts?

    James

    Hi, you don't need special drivers for "low latency" 10 Gbit ethernet on a 5 k.

    for example, to switch non-nexus 5 k

    PING 10.10.10.1 (10.10.10.1) 56 (84) bytes of data.

    64 bytes of 10.10.10.1: icmp_seq = 1 ttl = 255 time = 0,530 ms

    64 bytes of 10.10.10.1: icmp_seq = 2 ttl = 255 time = 0.618 ms

    and a nexus 5000 with a qlogic 8152

    PING 172.16.78.3 (172.16.78.3) 56 (84) bytes of data.

    64 bytes from 172.16.78.3: icmp_seq = 1 ttl = 128 time = 0.150 ms

    64 bytes from 172.16.78.3: icmp_seq = 2 ttl = 128 time = 0,134 ms

    Oracle rac cluster will fly!

  • Can't buy - please connect to iTunes in your currency settings to use buy features

    I bought an app a few years ago and they did an update and I want to subscribe to their premium subscription, but when I try I get this message "can not buy - please connect to iTunes in your currency settings to use the purchase functions.

    I logged onto my itunes account on my phone and can make other purchases.  I deleted the app and reinstalled it, but in vain.

    I contacted the developer of the app and they said I need to contact Apple that this message is not of them.

    Any help would be appreciated.

    Have you used another Apple ID for the app previously?

  • I used 128 usd with my couse accident I didn't know my dads credit card has been connected, I tried glitch a game bud I used my dads credit card money was connected couse I bought something on a game and I need the money please help me

    I used 129 usd with couse anaccident I didn't know that my dads credit card has been connected

    It has been connected couse I used on another game, then its

    already connected so I need money I have not used anything else for I have buyed and I want my dads back money / my money

    Please help me

    Nobody here can help you. We are just other users as you are. You can contact the support iTunes Store here, but they are not obliged to refund you, as all sales are final in Apple digital stores. Explain what you were doing and ask for their help.

    https://getsupport.Apple.com/

  • Unable to connect to a Sony DV from my laptop using the firewire port after the installation of updates

    Original title: connection for Vista FireWire camcorder problem

    I used to be able to connect my Sony DV camcorder to my laptop using the FireWire on the camcorder and laptop.   Once it is connected the Movie Maker detect my camcorder and automatically transfer the video.  However, since I've updated my computer laptop July 13, 2012, my laptop does not recognize not the camcorder.  I checked my computer and your camcorder is not yet listed.  I checked the latest updates for the driver of the firewire port 1394 and is the day the device is functioning properly.  Can anyone throw any light on this.  The only thing I can think is that since the update, he may have done something for the connection.

    Hi Scarlett,

    Thanks for the post. I'm sorry to hear that the Sony DV camcorder is not detected.

    I imagine the inconvenience that you are experiencing. I will definitely help you with this.
    To help you suggest several steps to solve the problem, I would appreciate it if you could answer the following questions:

    1. What is the model number of the Sony DV camcorder?
    2. you receive an error code or message?

    3 update do you have installed?

    See the Windows updates are installed:

    http://Windows.Microsoft.com/en-us/Windows-Vista/see-which-Windows-updates-are-installed

    Please follow the methods and mark the question below:

    Method 1:

    First of all, let us check the status of the FireWire port in Manager devices to do this, follow the steps below:

    Check the status of the port in FireWire devices Manager

    a. Click Start, in the search box type Device Manager and press to enter.
    b. If you don't see the FireWire controller (probably listed under "IEEE 1394 Bus host controllers") in the list, then it is not correctly installed.
    c. If you see a yellow exclamation point, then you must install the drivers, who are usually on a CD that comes with the FireWire card with the camcorder.

    Method 2:

    Step 1:

    Hardware devices do not work or are not detected in Windows

    http://support.Microsoft.com/mats/hardware_device_problems/en-us

    Step 2:

    A device driver is not installed or a hardware device does not work correctly after you install a Service Pack in Windows Vista:

    http://support.Microsoft.com/kb/948187

    Method 3:

    Connecting i.Link® (IEEE 1394) of the camcorder is not recognized by the computer.

    http://www.KB.Sony.com/selfservice/viewContent.do?externalId=C86798&sliceId=1&MDL

    For more information, see the link below:

    Import analog video to your computer by using a DV camera:
    http://Windows.Microsoft.com/en-us/Windows-Vista/import-analog-video-to-your-computer-by-using-a-DV-camera

    Import video from a videotape:
    http://Windows.Microsoft.com/en-us/Windows-Vista/import-video-from-a-videotape

    Your response is very important for us to ensure a proper resolution. Please get back to us with the information above to help you accordingly.

  • I have problems wireless on my Acer laptop which has Windows Vista. I am able to connect to my school of university network and used to connect to my home network.

    original title: Wireless on the Fritz

    I have problems wireless on my Acer laptop which has Windows Vista.  I am able to connect to my school of university network and used to connect to my home network (both are networks limited requiring a password or log in).  However, last week my computer stopped connecting to my home network (no one else has this problem with the home network).  I tried to fix the problem, but my computer says that "Wireless association failed because Windows did not receive response from the access point or wireless router."  That said also thatthe connection "(my wireless network)" has been cancelled.  This is perhaps due to a timeout or user action. »

    The only different thing I did last week was click option at my University 'connect long-term' instead of 'connect short term' to their wireless network.  Maybe who has messed up my settings?  That's what my University said of his record long term: "students, faculty and staff also have an option to easily record their computer (or other wireless devices), so that it is not necessary to authenticate each day they connect from the network wireless campus, to resources outside the University.»  However, these settings are saved on their network (I can access it online from another computer), so I think it is unlikely that he messed up my settings.

    I don't really know what the problem is.  Any ideas as to what I can do?  I don't want to reset my computer everything.

    Thank you!

    Hello

    You can view these methods:

    Method 1:

    I suggest you to disable any program of security on your computer and check if it solves the problem.

    After reviewing the question you must reactivate the security on your computer program.
    Note: Run the computer without antivirus software or firewall is a potential threat to the computer; Be sure to activate security software after completing the troubleshooting steps and after identifying the problem.
    Method 2:
    I suggest also allows you to check in SafeMode with network.
    Method 3:
    I also suggest you to check the settings of the router firewall.
  • SIP trunk behind a router using NAT

    Hello

    Is it possible to use a SIP trunk to a provider SIP ITSP having the CUBE / router gateway behind a firewall using a NAT?

    Does anyone do this?

    I ask because I'm having problems to make my SIP trunk to work and my router for cube is behind my generic service provider router, which makes the NAT. I just want to rule this out as a problem.

    Has anyone else done this? Or is it really impossible?

    Thank you very much

    Tom

    Hello

    As NAT works fine SIP would work properly as the Protocol.

    Here is the RFC for "NAT Traversal practices for Client - Server SIP"

    https://Tools.ietf.org/html/rfc6314

    HTH

    JB

  • I keep getting the 'Network security Key Mismatch' message when you try to connect using my wireless internet connection. I don't know that I use the password.

    I keep getting the 'Network security Key Mismatch' message when you try to connect using my wireless internet connection.  I don't know that I use the password.

    Hi oms1957

    I recommend you try these methods

    Method 1:

    Reset the wireless network and make sure that you set the level of security to WPA2-Personal, as it is recommended.

    Here are some links that will help you set up the wireless network

    What are the different wireless network security methods?

    Method 2:

    If this does not clear if installed third-party antivirus and then try to connect. If the problem is resolved, you have to uninstall the antivirus and reinstall back or check with the settings.

    Method 3:

    Cycle power to the router and check if this is useful.

    Thank you, and in what concerns:

    Samhrutha G S - Microsoft technical support.

    Visit our Microsoft answers feedback Forum and let us know what you think.

Maybe you are looking for

  • replace the subset of table

    I have a problem that I can't solve.  I have a table of 6 valves that are a def type.  I want to tell those who are on the use of a loop for.  The for loop count is a wiring number of valves that are put to the test.  I expected indicators 1 to 5 to

  • OTA Download but installation did not start

    Hello yesterday, I received the notice about the 5.0.2 update on my xt1068. OTA did download (full I can tell), but the installation started. I tried to restart and manually check for updates, but I never had the update since. Can I do to trigger the

  • Dv6000 - hard drive error #10009

    Hello world I already read something on this issue, but I write a new topic because I am in the worst trouble - the problem is related to the laptop, which I did not myself, it's computer of my father who is 1500km She was leaving that he told me tha

  • ntkranlmp.exe error code 7 at startup in WinXP

    Download the message title to start once the system crashed.  Windows XP SP3. KB has suggested swapping of RAM but no joy.  Installed a new 320 GB HD, still no joy but get the same error. What should do? Dave

  • 745 rebuild raedon install

    Reference Dell 745 Intergrated graphics x 1300 pro.  2G ram, windows xp professional. After installing a new hard drive, I find that I can not install my video drivers.  I first tried the installer of R215191 from Dell, then I tried subsequently inhe