EtherChannel error on 2811 router

Hello

I met 2 problems related to Etherchannel.

1. I have two servers connected to Etherswitch on 2811 router via Etherchannels 3-port. All computers on the network can see both servers, but servers are unable to see each other, that is, ping, network access, etc does not work. Related config:

GC21RR01 #sh inv
NAME: "2811 chassis', DESCR:"2811 chassis.
PID: CISCO2811, VID: V07, SN: FCZ14027226

NAME: "ADSL over POTS on the Slot, SubSlot 0 0 ', DESCR:"ADSL over POTS.
PID: HWIC-1ADSL, VID: V01, SN: FOC14473PJ6

NAME: "16 Port 10BaseT/100BaseTX EtherSwitch on Slot 1 ', DESCR:" 16 Port 10BaseT/100BaseTX EtherSwitch.
VID, PID: NM-16ESW: V01, SN: FOC14445QB8

GC21RR01 #sh worm
Cisco IOS software, 2800 Software (C2800NM-ADVSECURITYK9-M), Version 15.1 (1) T, RELEASE SOFTWARE (fc1)
Technical support: http://www.cisco.com/techsupport
Copyright (c) 1986-2010 by Cisco Systems, Inc.
Updated Tuesday, March 22, 10 01:25 by prod_rel_team

ROM: System Bootstrap, Version 12.4 T11 (13r), RELEASE SOFTWARE (fc1)

GC21RR01 operating time is 23 hours, 15 minutes
System returned to ROM by reload at 13:48:11 BEST Sunday, March 20, 2011
System restarted at 13:49:35 GREEN Sunday, March 20, 2011
System image file is "flash: c2800nm-advsecurityk9 - mz.151 - 1.T.bin.
Last reload type: normal charging

This product contains cryptographic features and is under the United States
States and local laws governing the import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third party approval to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. laws and local countries. By using this product you
agree to comply with the regulations and laws in force. If you are unable
to satisfy the United States and local laws, return the product.

A summary of U.S. laws governing Cisco cryptographic products to:
http://www.Cisco.com/WWL/export/crypto/tool/stqrg.html you need assistance, please contact us by mail at
[email protected] / * / 2811 (revision 53.51) with 245760K / 16384K bytes of memory.
Card processor ID FCZ14027226
18 FastEthernet interfaces
1 ATM interface
1 module of virtual private network (VPN)
Configuration of DRAM is wide with parity 64-bit capable.
239K bytes of non-volatile configuration memory.
62720K bytes of ATA CompactFlash (read/write)

If

Cisco

License info:

License IDU:

-------------------------------------------------
Device SN # PID
-------------------------------------------------
* CISCO2811 0 FCZ14027226

Configuration register is 0 x 2102

GC21RR01 #sh etherchannel detail
List of channel-group:
-----------------------

Group: 1
----------
Group status = L2
Ports: 3 Maxports = 8
Port-channel: 1 Port Max-channels = 1
Ports in the Group:
-------------------
Port: Fa1/0
------------

Port status Up Mstr in Bndl
Group of channels = 1 Mode = we / FEC Gcchange = 0
Port channel = Po1 GC = 0 x 00010001 port-channel Pseudo = Po1
Port index = 0
Age of the port in the current state: 00d: 11: 00: 15:00
Port: Fa1/1
------------

Port status Up Mstr in Bndl
Group of channels = 1 Mode = we / FEC Gcchange = 0
Port channel = Po1 GC = 0 x 00010001 port-channel Pseudo = Po1
Port index = 1
Age of the port in the current state: 00d: 11: 00: 15:00
Port: Fa1/2
------------

Port status Up Mstr in Bndl
Group of channels = 1 Mode = we / FEC Gcchange = 0
Port channel = Po1 GC = 0 x 00010001 port-channel Pseudo = Po1
Port index = 2
Age of the port in the current state: 00d: 11: 00: 15:00
Port-channels of the Group:
----------------------

Port-channel: Po1
------------

The Port-Channel = 00d age: 23: 00: 15:00
Logical slot/port = 8/0 number of ports = 3
GC = 0 x 00010001 HotStandBy port = null
State of Port = Port-Channel Ag-Inuse

Ports in the Port-Channel:

The community of Port index State
------+------+------------
Fa1/0 0
1 Fa1/1 on
SA1 2/2 on

Time since the last group port: 00d: 11: 00: 15:00 Fa1/2

Group size: 2
----------
Group status = L2
Ports: 3 Maxports = 8
Port-channel: 1 Port Max-channels = 1
Ports in the Group:
-------------------
Port: Fa1/4
------------

Port status Up Mstr in Bndl
Group of channels = 2 Mode = we / FEC Gcchange = 0
Port channel = Po2 GC = 0 x 00020001 port-channel Pseudo = Po2
Port index = 0
Age of the port in the current state: 00d: 11: 00: 15:00
Port: Fa1/5
------------

Port status Up Mstr in Bndl
Group of channels = 2 Mode = we / FEC Gcchange = 0
Port channel = Po2 GC = 0 x 00020001 port-channel Pseudo = Po2
Port index = 1
Age of the port in the current state: 00d: 11: 00: 15:00
Port: Fa1/6
------------

Port status Up Mstr in Bndl
Group of channels = 2 Mode = we / FEC Gcchange = 0
Port channel = Po2 GC = 0 x 00020001 port-channel Pseudo = Po2
Port index = 2
Age of the port in the current state: 00d: 11: 00: 15:00
Port-channels of the Group:
----------------------

Port-channel: Po2
------------

The Port-Channel = 00d age: 23: 00: 15:00
Logical slot/port = 8/1 number of ports = 3
GC = 0 x 00020001 HotStandBy port = null
State of Port = Port-Channel Ag-Inuse

Ports in the Port-Channel:

The community of Port index State
------+------+------------
0 Fa1/4 on
1 Fa1/5 on
2 Fa1/6 on

Time since the last group port: 00d: 11: 00: 15:00 Fa1/6

GC21RR01 #sh etherchannel summary
Flags: D - low P - port-channel
I have - autonomous s - suspended
R - Layer 3 S - Layer2
U - in use
Ports of Port-Channel Group
-----+------------+-----------------------------------------------------------
1 Po1 (SU) Fa1/0 (P) Fa1/1 (P) Fa1/2 (P)
2 Po2 (SU) Fa1/4 (P) Fa1/5 (P) Fa1/6 (P)

2. I can't information see the Port-Channel. I could do that, before the router restarts:

GC21RR01 #sh po int 1
^
Invalid entry % detected at ' ^' marker.

GC21RR01 #sh po int 2
^
Invalid entry % detected at ' ^' marker.

GC21RR01 #sh int in. ip 1
^
Invalid entry % detected at ' ^' marker.

GC21RR01 #sh ip po int 2
^
Invalid entry % detected at ' ^' marker.

Any help is appreciated.

Hello

So you have a L2 etherchannel sh ip int can only work if it is a portchannel L3 interface.

Kind regards.

Alain.

Tags: Cisco Network

Similar Questions

  • ISAKMP error - 2811 router

    Hi guys,.

    I would like to create a VPN site-to site between my ASA and a remote router in China.

    On the router, when I typed ""crypto isakmp enable ' command I know that isakmp is not present. "

    What can I do, where is the problem? License, ios image,...? !

    error type:

    Router (config) #crypto enable isakmp

    ^

    Invalid entry % detected at ' ^' marker.

    Router (config) #crypto?

    CA Certification Authority

    main activities key long-term

    public key PKI components

    commissioning Secure Device Provisioning

    Wui Crypto HTTP configuration interfaces

    News of the router:

    Cisco CISCO2811C/K9

    Version 12.4 (13r) T13, RELEASE SOFTWARE (fc1)

    c2800nmc-spservicesk9 - mz.150 - 1.M7.bin

    Thank you very much.

    Luca

    To configure the site to site VPN, or any other VPN, you need advanced business picture, advanced security or Advanced IP Services.

  • VPN site to Site btw Pix535 and 2811 router, can't get to work

    Hi, everyone, I spent a few days doing a VPN site-to site between PIX535 and 2811 router but returned empty-handed, I followed the instructions here:

    http://www.Cisco.com/en/us/products/ps9422/products_configuration_example09186a0080b4ae61.shtml

    #1: config PIX:

    : Saved

    : Written by enable_15 to the 18:05:33.678 EDT Saturday, October 20, 2012

    !

    8.0 (4) version PIX

    !

    hostname pix535

    !

    interface GigabitEthernet0

    Description to cable-modem

    nameif outside

    security-level 0

    address IP X.X.138.132 255.255.255.0

    OSPF cost 10

    !

    interface GigabitEthernet1

    Description inside 10/16

    nameif inside

    security-level 100

    IP 10.1.1.254 255.255.0.0

    OSPF cost 10

    !

    outside_access_in of access allowed any ip an extended list

    access extensive list ip 10.1.0.0 inside_nat0_outbound allow 255.255.0.0 10.20.0.0 255.255.0.0

    inside_nat0_outbound list of allowed ip extended access all 10.1.1.192 255.255.255.248

    outside_cryptomap_dyn_60 list of allowed ip extended access all 10.1.1.192 255.255.255.248

    access extensive list ip 10.1.0.0 outside_1_cryptomap allow 255.255.0.0 10.20.0.0 255.255.0.0

    pager lines 24

    cnf-8-ip 10.1.1.192 mask - 10.1.1.199 IP local pool 255.255.0.0

    Global interface 10 (external)

    15 1.2.4.5 (outside) global

    NAT (inside) 0-list of access inside_nat0_outbound

    NAT (inside) 15 10.1.0.0 255.255.0.0

    Access-group outside_access_in in interface outside

    Route outside 0.0.0.0 0.0.0.0 X.X.138.1 1

    Crypto ipsec transform-set ESP-DES-MD5 esp - esp-md5-hmac

    Crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac

    Crypto ipsec transform-set ESP-AES-256-SHA 256 - aes - esp esp-sha-hmac

    Crypto ipsec transform-set ESP-3DES-MD5-esp-3des esp-md5-hmac

    Crypto ipsec transform-set esp-SHA-ESP-3DES-3des esp-sha-hmac

    Crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac

    Crypto ipsec transform-set ESP-AES-128-SHA aes - esp esp-sha-hmac

    Crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac

    Crypto ipsec transform-set ESP-AES-128-MD5-esp - aes esp-md5-hmac

    Crypto ipsec transform-set ESP-DES-SHA esp - esp-sha-hmac

    life crypto ipsec security association seconds 28800

    Crypto ipsec kilobytes of life - safety 4608000 association

    Crypto-map dynamic outside_dyn_map 20 the value transform-set ESP-3DES-SHA MD5-ESP-3DES ESP-DES-MD5

    life together - the association of security crypto dynamic-map outside_dyn_map 20 28800 seconds

    Crypto-map dynamic outside_dyn_map 20 kilobytes of life together - the association of safety 4608000

    Crypto-map dynamic outside_dyn_map 40 value transform-set ESP-3DES-SHA MD5-ESP-3DES ESP-DES-SHA

    life together - the association of security crypto dynamic-map outside_dyn_map 40 28800 seconds

    Crypto-map dynamic outside_dyn_map 40 kilobytes of life together - the association of safety 4608000

    Dynamic crypto map outside_dyn_map 60 match address outside_cryptomap_dyn_60

    Crypto-map dynamic outside_dyn_map 60 value transform-set ESP-3DES-MD5 ESP-3DES-SHA ESP-DES-MD5 ESP-DES-SHA

    life together - the association of security crypto dynamic-map outside_dyn_map 60 28800 seconds

    Crypto-map dynamic outside_dyn_map 60 kilobytes of life together - the association of safety 4608000

    Dynamic crypto map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs

    Crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 value transform-set ESP-SHA-3DES ESP-MD5-3DES ESP-DES-SHA ESP-DES-MD5

    Dynamic crypto map SYSTEM_DEFAULT_CRYPTO_MAP 65535 define security association lifetime 28800 seconds

    cryptographic kilobytes 4608000 life of the set - the association of security of the 65535 SYSTEM_DEFAULT_CRYPTO_MAP of the dynamic-map

    card crypto outside_map 1 match address outside_1_cryptomap

    outside_map game 1 card crypto peer X.X.21.29

    card crypto outside_map 1 set of transformation-ESP-DES-SHA

    outside_map map 1 lifetime of security association set seconds 28800 crypto

    card crypto outside_map 1 set security-association life kilobytes 4608000

    outside_map card crypto 65534 isakmp ipsec dynamic SYSTEM_DEFAULT_CRYPTO_MAP

    map outside_map 65535-isakmp ipsec crypto dynamic outside_dyn_map

    outside_map interface card crypto outside

    ISAKMP crypto identity hostname

    crypto ISAKMP allow outside

    crypto ISAKMP policy 10

    preshared authentication

    the Encryption

    sha hash

    Group 1

    life 86400

    crypto ISAKMP policy 20

    preshared authentication

    3des encryption

    sha hash

    Group 2

    life 86400

    crypto ISAKMP policy 65535

    preshared authentication

    3des encryption

    sha hash

    Group 2

    life 86400

    Crypto isakmp nat-traversal 3600

    internal GroupPolicy1 group strategy

    cnf-vpn-cls group policy internal

    attributes of cnf-vpn-cls-group policy

    value of 10.1.1.7 WINS server

    value of 10.1.1.7 DNS server 10.1.1.205

    Protocol-tunnel-VPN IPSec l2tp ipsec

    field default value x.com

    sean U/h5bFVjXlIDx8BtqPFrQw password user name is nt encrypted

    IPSec-attributes tunnel-group DefaultRAGroup

    pre-shared-key secret1

    RADIUS-sdi-xauth

    tunnel-group DefaultRAGroup ppp-attributes

    ms-chap-v2 authentication

    tunnel-group cnf-vpn-cls type remote access

    tunnel-group global cnf-vpn-cls-attributes

    cnf-8-ip address pool

    Group Policy - by default-cnf-vpn-cls

    tunnel-group cnf-CC-vpn-ipsec-attributes

    pre-shared-key secret2

    ISAKMP ikev1-user authentication no

    tunnel-group cnf-vpn-cls ppp-attributes

    ms-chap-v2 authentication

    tunnel-group X.X.21.29 type ipsec-l2l

    IPSec-attributes tunnel-Group X.X.21.29

    Pre-shared key SECRET

    !

    class-map inspection_default

    match default-inspection-traffic

    !

    !

    !

    global service-policy global_policy

    context of prompt hostname

    Cryptochecksum:9780edb09bc7debe147db1e7d52ec39c

    : end

    #2: 2811 router config:

    !

    ! Last configuration change to 09:15:32 PST Friday, October 19, 2012 by cnfla

    ! NVRAM config update at 13:45:03 PST Tuesday, October 16, 2012

    !

    version 12.4

    horodateurs service debug datetime msec

    Log service timestamps datetime msec

    no password encryption service

    !

    hostname THE-2800

    !

    !

    Crypto pki trustpoint TP-self-signed-1411740556

    enrollment selfsigned

    name of the object cn = IOS - Self - signed - certificate - 1411740556

    revocation checking no

    rsakeypair TP-self-signed-1411740556

    !

    !

    TP-self-signed-1411740556 crypto pki certificate chain

    certificate self-signed 01

    308201A 8 A0030201 02020101 3082023F 300 D 0609 2A 864886 F70D0101 04050030

    2 060355 04031326 494F532D 53656 C 66 2 AND 536967 6E65642D 43657274 31312F30

    69666963 31343131 37343035 6174652D 3536301E 170 3132 31303136 32303435

    30335A 17 0D 323030 31303130 30303030 305A 3031 06035504 03132649 312F302D

    4F532D53 5369676E 656C662D 43 65727469 66696361 74652 31 34313137 65642D

    34303535 3630819F 300 D 0609 2A 864886 01050003, 818, 0030, 81890281 F70D0101

    8100F75F F1BDAD9B DE9381FD 7EAF9685 CF15A317 165B 5188 1 B 424825 9C66AA28

    C990B2D3 D69A2F0F D745DB0E 2BB4995D 73415AC4 F01B2019 C4BCF9E0 84373199

    E599B86C 17DBDCE6 47EBE0E3 8DBC90B2 9B4E217A 87F04BF7 A182501E 24381019

    A61D2C05 5404DE88 DA2A1ADC A81B7F65 C318B697 7ED69DF1 2769E4C8 F3449B33

    010001A 3 67306530 1 130101 FF040530 030101FF 30120603 0F060355 35AF0203

    1104 B 0 300982 074C412D 32383030 551D 551 2304 18301680 14B56EEB 301F0603

    88054CCA BB8CF8E8 F44BFE2C B77954E1 52301 D 06 04160414 B56EEB88 03551D0E

    054CCABB 8CF8E8F4 4BFE2CB7 7954E152 300 D 0609 2A 864886 F70D0101 04050003

    81810056 58755 56 331294F8 BEC4FEBC 54879FF5 0FCC73D4 B964BA7A 07D 20452

    E7F40F42 8B 355015 77156C9F AAA45F9F 59CDD27F 89FE7560 F08D953B FC19FD2D

    310DA96E A5F3E83B 52D515F8 7B4C99CF 4CECC3F7 1A0D4909 BD08C373 50BB53CC

    659 4246 2CB7B79F 43D94D96 586F9103 9B4659B6 5C8DDE4F 7CC5FC68 C4AD197A 4EC322 C

    quit smoking

    !

    !

    !

    crypto ISAKMP policy 1

    preshared authentication

    ISAKMP crypto key address SECRET X.X.138.132 No.-xauth

    !

    !

    Crypto ipsec transform-set the-2800-trans-set esp - esp-sha-hmac

    !

    map 1 la-2800-ipsec policy ipsec-isakmp crypto

    ipsec vpn Description policy

    defined by peer X.X.138.132

    the transform-set the-2800-trans-set value

    match address 101

    !

    !

    !

    !

    !

    !

    interface FastEthernet0/0

    Description WAN side

    address IP X.X.216.29 255.255.255.248

    NAT outside IP

    IP virtual-reassembly

    automatic duplex

    automatic speed

    No cdp enable

    No mop enabled

    card crypto 2800-ipsec-policy

    !

    interface FastEthernet0/1

    Description side LAN

    IP 10.20.1.1 255.255.255.0

    IP nat inside

    IP virtual-reassembly

    full duplex

    automatic speed

    No mop enabled

    !

    IP nat inside source map route sheep interface FastEthernet0/0 overload

    access-list 10 permit X.X.138.132

    access-list 99 allow 64.236.96.53

    access-list 99 allow 98.82.1.202

    access list 101 remark vpn tunnerl acl

    Note access-list 101 category SDM_ACL = 4

    policy of access list 101 remark tunnel

    access-list 101 permit ip 10.20.0.0 0.0.0.255 10.1.0.0 0.0.255.255

    access-list 110 deny ip 10.20.0.0 0.0.0.255 10.1.0.0 0.0.255.255

    access-list 110 permit ip 10.20.0.0 0.0.0.255 any

    public RO SNMP-server community

    !

    !

    !

    sheep allowed 10 route map

    corresponds to the IP 110

    !

    !

    !

    !

    WebVPN gateway gateway_1

    IP address X.X.216.29 port 443

    SSL trustpoint TP-self-signed-1411740556

    development

    !

    WebVPN install svc flash:/webvpn/svc.pkg

    !

    WebVPN gateway-1 context

    title 'b '.

    secondary-color white

    color of the title #CCCC66

    text-color black

    SSL authentication check all

    !

    !

    policy_1 political group

    functions compatible svc

    SVC-pool of addresses "WebVPN-Pool."

    SVC Dungeon-client-installed

    SVC split include 10.20.0.0 255.255.0.0

    Group Policy - by default-policy_1

    Gateway gateway_1

    development

    !

    !

    end

    #3: test Pix to the router:


    ITS enabled: 1

    Generate a new key SA: 0 (a tunnel report Active 1 and 1 to generate a new key during the generate a new key)

    Total SA IKE: 1

    1 peer IKE: X.X.21.29

    Type: user role: initiator

    Generate a new key: no State: MM_WAIT_MSG2

    > DEBUG:

    12:07:14 pix535:Oct 22 Oct 22 12:20:28 EDT: % PIX-vpn-3-713902: IP = X.X.21.29, Removing peer to peer table has not, no match
    !
    22 Oct 12:07:14 pix535: 22 Oct 12:20:28 EDT: % PIX-vpn-4-713903: IP = X.X.21.29, error: cannot delete PeerTblEntry
    #4: test the router to pix:
    LA - 2800 #sh crypto isakmp his
    IPv4 Crypto ISAKMP Security Association
    status of DST CBC State conn-id slot
    X.X.138.132 X.X.216.29 MM_KEY_EXCH 1017 ASSETS 0
    > debug
    LA - 2800 #ping 10.1.1.7 source 10.20.1.1
    Type to abort escape sequence.
    Send 5, echoes ICMP 100 bytes to 10.1.1.7, time-out is 2 seconds:
    Packet sent with a source address of 10.20.1.1
    Oct 22 16:24:33.945: ISAKMP: (0): profile of THE request is (NULL)
    22 Oct 16:24:33.945: ISAKMP: created a struct peer X.X.138.132, peer port 500
    22 Oct 16:24:33.945: ISAKMP: new created position = 0x488B25C8 peer_handle = 0 x 80000013
    22 Oct 16:24:33.945: ISAKMP: lock struct 0x488B25C8, refcount 1 to peer isakmp_initiator
    22 Oct 16:24:33.945: ISAKMP: 500 local port, remote port 500
    22 Oct 16:24:33.945: ISAKMP: set new node 0 to QM_IDLE
    22 Oct 16:24:33.945: ISAKMP: find a dup her to the tree during the isadb_insert his 487720 A 0 = call BVA
    22 Oct 16:24:33.945: ISAKMP: (0): cannot start aggressive mode, try the main mode.
    22 Oct 16:24:33.945: ISAKMP: (0): pair found pre-shared key matching 70.169.138.132
    Oct 22 16:24:33.945: ISAKMP: (0): built of NAT - T of the seller-rfc3947 ID
    Oct 22 16:24:33.945: ISAKMP: (0): built the seller-07 ID NAT - t
    Oct 22 16:24:33.945: ISAKMP: (0): built of NAT - T of the seller-03 ID
    Oct 22 16:24:33.945: ISAKMP: (0): built the seller-02 ID NAT - t
    22 Oct 16:24:33.945: ISAKMP: (0): entry = IKE_MESG_FROM_IPSEC, IKE_SA_REQ_MM
    22 Oct 16:24:33.945: ISAKMP: (0): former State = new State IKE_READY = IKE_I_MM1
    Oct 22 16:24:33.945: ISAKMP: (0): Beginner Main Mode Exchange
    Oct 22 16:24:33.945: ISAKMP: (0): package X.X.138.132 my_port 500 peer_port 500 (I) sending MM_NO_STATE
    22 Oct 16:24:33.945: ISAKMP: (0): sending a packet IPv4 IKE.
    22 Oct 16:24:34.049: ISAKMP (0:0): packet received dport 500 sport Global 500 (I) MM_NO_STATE X.X.138.132
    22 Oct 16:24:34.049: ISAKMP: (0): entry = IKE_MESG_FROM_PEER, IKE_MM_EXCH
    22 Oct 16:24:34.049: ISAKMP: (0): former State = new State IKE_I_MM1 = IKE_I_MM2
    Oct 22 16:24:34.049: ISAKMP: (0): treatment ITS payload. Message ID = 0
    Oct 22 16:24:34.049: ISAKMP: (0): load useful vendor id of treatment
    Oct 22 16:24:34.049: ISAKMP: (0): provider ID seems the unit/DPD but major incompatibility of 123
    Oct 22 16:24:34.049: ISAKMP: (0): provider ID is NAT - T v2
    Oct 22 16:24:34.049: ISAKMP: (0): load useful vendor id of treatment
    Oct 22 16:24:34.049: ISAKMP: (0): provider ID seems the unit/DPD but major incompatibility of 194
    22 Oct 16:24:34.053: ISAKMP: (0): pair found pre-shared key matching 70.169.138.132
    Oct 22 16:24:34.053: ISAKMP: (0): pre-shared key local found
    22 Oct 16:24:34.053: ISAKMP: analysis of the profiles for xauth...
    22 Oct 16:24:34.053: ISAKMP: (0): audit ISAKMP transform 1 against the policy of priority 1
    22 Oct 16:24:34.053: ISAKMP: DES-CBC encryption
    22 Oct 16:24:34.053: ISAKMP: SHA hash
    22 Oct 16:24:34.053: ISAKMP: default group 1
    22 Oct 16:24:34.053: ISAKMP: pre-shared key auth
    22 Oct 16:24:34.053: ISAKMP: type of life in seconds
    22 Oct 16:24:34.053: ISAKMP: life (IPV) 0 x 0 0 x 1 0 x 51 0x80
    22 Oct 16:24:34.053: ISAKMP: (0): atts are acceptable
    . Next payload is 0
    22 Oct 16:24:34.053: ISAKMP: (0): Acceptable atts: real life: 0
    22 Oct 16:24:34.053: ISAKMP: (0): Acceptable atts:life: 0
    22 Oct 16:24:34.053: ISAKMP: (0): fill atts in his vpi_length:4
    22 Oct 16:24:34.053: ISAKMP: (0): fill atts in his life_in_seconds:86400
    22 Oct 16:24:34.053: ISAKMP: (0): return real life: 86400
    22 Oct 16:24:34.053: ISAKMP: (0): timer life Started: 86400.
    Oct 22 16:24:34.053: ISAKMP: (0): load useful vendor id of treatment
    Oct 22 16:24:34.053: ISAKMP: (0): provider ID seems the unit/DPD but major incompatibility of 123
    Oct 22 16:24:34.053: ISAKMP: (0): provider ID is NAT - T v2
    Oct 22 16:24:34.053: ISAKMP: (0): load useful vendor id of treatment
    Oct 22 16:24:34.053: ISAKMP: (0): provider ID seems the unit/DPD but major incompatibility of 194
    22 Oct 16:24:34.053: ISAKMP: (0): entry = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE
    22 Oct 16:24:34.053: ISAKMP: (0): former State = new State IKE_I_MM2 = IKE_I_MM2
    Oct 22 16:24:34.057: ISAKMP: (0): package X.X.138.132 my_port 500 peer_port 500 (I) sending MM_SA_SETUP
    22 Oct 16:24:34.057: ISAKMP: (0): sending a packet IPv4 IKE.
    22 Oct 16:24:34.057: ISAKMP: (0): entry = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE
    22 Oct 16:24:34.057: ISAKMP: (0): former State = new State IKE_I_MM2 = IKE_I_MM3
    22 Oct 16:24:34.181: ISAKMP (0:0): packet received dport 500 sport Global 500 (I) MM_SA_SETUP X.X.138.132
    22 Oct 16:24:34.181: ISAKMP: (0): entry = IKE_MESG_FROM_PEER, IKE_MM_EXCH
    22 Oct 16:24:34.181: ISAKMP: (0): former State = new State IKE_I_MM3 = IKE_I_MM4
    Oct 22 16:24:34.181: ISAKMP: (0): processing KE payload. Message ID = 0
    Oct 22 16:24:34.217: ISAKMP: (0): processing NONCE payload. Message ID = 0
    22 Oct 16:24:34.217: ISAKMP: (0): pre-shared key found peer corresponding to X.X.138.132
    Oct 22 16:24:34.217: ISAKMP: (1018): load useful vendor id of treatment
    Oct 22 16:24:34.217: ISAKMP: (1018): provider ID is the unit
    Oct 22 16:24:34.217: ISAKMP: (1018): load useful vendor id of treatment
    Oct 22 16:24:34.217: ISAKMP: (1018): provider ID seems the unit/DPD but major incompatibility of 55
    Oct 22 16:24:34.217: ISAKMP: (1018): provider ID is XAUTH
    Oct 22 16:24:34.217: ISAKMP: (1018): load useful vendor id of treatment
    Oct 22 16:24:34.217: ISAKMP: (1018): addressing another box of IOS
    !
    Oct 22 16:24:34.221: ISAKMP: (1018): load useful vendor id of treatment
    22 Oct 16:24:34.221: ISAKMP: (1018): vendor ID seems the unit/DPD but hash mismatch
    22 Oct 16:24:34.221: ISAKMP: receives the payload type 20
    22 Oct 16:24:34.221: ISAKMP: receives the payload type 20
    22 Oct 16:24:34.221: ISAKMP: (1018): entry = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE
    22 Oct 16:24:34.221: ISAKMP: (1018): former State = new State IKE_I_MM4 = IKE_I_MM4
    22 Oct 16:24:34.221: ISAKMP: (1018): send initial contact
    22 Oct 16:24:34.221: ISAKMP: (1018): ITS been pre-shared key, using id ID_IPV4_ADDR type authentication
    22 Oct 16:24:34.221: ISAKMP (0:1018): payload ID
    next payload: 8
    type: 1
    address: X.X.216.29
    Protocol: 17
    Port: 500
    Length: 12
    22 Oct 16:24:34.221: ISAKMP: (1018): the total payload length: 12
    Oct 22 16:24:34.221: ISAKMP: (1018): package X.X.138.132 my_port 500 peer_port 500 (I) sending MM_KEY_EXCH
    22 Oct 16:24:34.221: ISAKMP: (1018): sending a packet IPv4 IKE.
    22 Oct 16:24:34.225: ISAKMP: (1018): entry = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE
    22 Oct 16:24:34.225: ISAKMP: (1018): former State = new State IKE_I_MM4 = IKE_I_MM5
    ...
    22 Oct 16:24:38.849: ISAKMP: (1017): purge the node 198554740
    22 Oct 16:24:38.849: ISAKMP: (1017): purge the node 812380002
    22 Oct 16:24:38.849: ISAKMP: (1017): purge node 773209335...
    Success rate is 0% (0/5)
    # THE-2800
    Oct 22 16:24:44.221: ISAKMP: (1018): transmit phase 1 MM_KEY_EXCH...
    22 Oct 16:24:44.221: ISAKMP (0:1018): increment the count of errors on his, try 1 5: retransmit the phase 1
    Oct 22 16:24:44.221: ISAKMP: (1018): transmit phase 1 MM_KEY_EXCH
    Oct 22 16:24:44.221: ISAKMP: (1018): package X.X.138.132 my_port 500 peer_port 500 (I) sending MM_KEY_EXCH
    22 Oct 16:24:44.221: ISAKMP: (1018): sending a packet IPv4 IKE.
    22 Oct 16:24:44.317: ISAKMP (0:1018): packet received dport 500 sport Global 500 (I) MM_KEY_EXCH X.X.138.132
    Oct 22 16:24:44.317: ISAKMP: (1018): package of phase 1 is a duplicate of a previous package.
    Oct 22 16:24:44.321: ISAKMP: (1018): retransmission jumped to the stage 1 (time elapsed since the last transmission 96)
    22 Oct 16:24:48.849: ISAKMP: (1017): serving SA., his is 469BAD60, delme is 469BAD60
    22 Oct 16:24:52.313: ISAKMP (0:1018): packet received dport 500 sport Global 500 (I) MM_KEY_EXCH X.X.138.132
    Oct 22 16:24:52.313: ISAKMP: (1018): package of phase 1 is a duplicate of a previous package.
    Oct 22 16:24:52.313: ISAKMP: (1018): retransmission due to phase 1 of retransmission
    Oct 22 16:24:52.813: ISAKMP: (1018): transmit phase 1 MM_KEY_EXCH...
    22 Oct 16:24:52.813: ISAKMP (0:1018): increment the count of errors on his, try 2 of 5: retransmit the phase 1
    Oct 22 16:24:52.813: ISAKMP: (1018): transmit phase 1 MM_KEY_EXCH
    Oct 22 16:24:52.813: ISAKMP: (1018): package X.X138.132 my_port 500 peer_port 500 (I) sending MM_KEY_EXCH
    22 Oct 16:24:52.813: ISAKMP: (1018): sending a packet IPv4 IKE.
    Oct 22 16:24:52.913: ISAKMP: (1018): package of phase 1 is a duplicate of a previous package.
    Oct 22 16:24:52.913: ISAKMP: (1018): retransmission jumped to the stage 1 (time elapsed since the last transmission of 100)
    22 Oct 16:25:00.905: ISAKMP (0:1018): packet received dport 500 sport Global 500 (I) MM_KEY_EXCH X.X.138.132
    22 Oct 16:25:00.905: ISAKMP: node set 422447177 to QM_IDLE
    ....
    22 Oct 16:25:03.941: ISAKMP: (1018): SA is still budding. New application of ipsec in the annex
    . (local 1 X. X.216.29, remote X.X.138.132)
    22 Oct 16:25:03.941: ISAKMP: error during the processing of HIS application: failed to initialize SA
    22 Oct 16:25:03.941: ISAKMP: error while processing message KMI 0, error 2.
    Oct 22 16:25:12.814: ISAKMP: (1018): transmit phase 1 MM_KEY_EXCH...
    22 Oct 16:25:12.814: ISAKMP (0:1018): increment the count of errors on his, try 4 out 5: retransmit the phase 1
    Oct 22 16:25:12.814: ISAKMP: (1018): transmit phase 1 MM_KEY_EXCH
    Oct 22 16:25:12.814: ISAKMP: (1018): package X.X.138.132 my_port 500 peer_port 500 (I) sending MM_KEY_EXCH
    22 Oct 16:25:12.814: ISAKMP: (1018): sending a packet IPv4 IKE.
    Oct 22 16:25:22.814: ISAKMP: (1018): transmit phase 1 MM_KEY_EXCH...
    22 Oct 16:25:22.814: ISAKMP (0:1018): increment the count of errors on his, try 5 of 5: retransmit the phase 1
    Oct 22 16:25:22.814: ISAKMP: (1018): transmit phase 1 MM_KEY_EXCH
    Oct 22 16:25:22.814: ISAKMP: (1018): package X.X.138.132 my_port 500 peer_port 500 (I) sending MM_KEY_EXCH
    22 Oct 16:25:22.814: ISAKMP: (1018): sending a packet IPv4 IKE.
    Oct 22 16:25:32.814: ISAKMP: (1018): transmit phase 1 MM_KEY_EXCH...
    22 Oct 16:25:32.814: ISAKMP: (1018): peer does not paranoid KeepAlive.
    ......

    22 Oct 16:25:32.814: ISAKMP: (1018): removal of reason ITS status of 'Death by retransmission P1' (I) MM_KEY_EXCH (post 70.169.138.132)

    22 Oct 16:25:32.814: ISAKMP: (1018): removal of reason ITS status of 'Death by retransmission P1' (I) MM_KEY_EXCH (post 70.169.138.132)

    22 Oct 16:25:32.814: ISAKMP: Unlocking counterpart struct 0x488B25C8 for isadb_mark_sa_deleted(), count 0

    22 Oct 16:25:32.814: ISAKMP: delete peer node by peer_reap for X.X.138.132: 488B25C8

    22 Oct 16:25:32.814: ISAKMP: (1018): error suppression node 1112432180 FALSE reason 'IKE deleted.

    22 Oct 16:25:32.814: ISAKMP: (1018): error suppression node 422447177 FALSE reason 'IKE deleted.

    22 Oct 16:25:32.814: ISAKMP: (1018): node-278980615 error suppression FALSE reason 'IKE deleted.

    22 Oct 16:25:32.814: ISAKMP: (1018): entry = IKE_MESG_INTERNAL, IKE_PHASE1_DEL

    22 Oct 16:25:32.814: ISAKMP: (1018): former State = new State IKE_I_MM5 = IKE_DEST_SA

    22 Oct 16:26:22.816: ISAKMP: (1018): purge the node 1112432180

    22 Oct 16:26:22.816: ISAKMP: (1018): purge the node 422447177

    22 Oct 16:26:22.816: ISAKMP: (1018): purge the node-278980615

    22 Oct 16:26:32.816: ISAKMP: (1018): serving SA., its A 487720, 0 =, delme = A 487720, 0

    The PIX is also used VPN client, such as the VPN Cicso 5.0 client access, works very well. Router is used as a server SSL VPN, too much work

    I know there are a lot of data here, I hope that these data may be useful for diagnostic purposes.

    All suggestions and tips are greatly appreciated.

    Sean

    Recommended action:

    On the PIX:

    no card crypto outside_map 1

    !

    crypto ISAKMP policy 5

    preshared authentication

    3des encryption

    sha hash

    Group 2

    life 86400

    !

    card crypto outside_map 10 correspondence address outside_1_cryptomap

    crypto outside_map 10 peer X.X.216.29 card game

    outside_map crypto 10 card value transform-set ESP-3DES-SHA

    life safety association set card crypto outside_map 10 28800 seconds

    card crypto outside_map 10 set security-association life kilobytes 4608000

    !

    tunnel-group X.X.216.29 type ipsec-l2l

    IPSec-attributes tunnel-Group X.X.216.29

    Pre-shared key SECRET

    !

    On the router:

    crypto ISAKMP policy 10

    preshared authentication

    Group 2

    3des encryption

    !

    Crypto ipsec transform-set esp-SHA-ESP-3DES-3des esp-sha-hmac

    output

    !

    card 10 la-2800-ipsec policy ipsec-isakmp crypto

    ipsec vpn Description policy

    defined by peer X.X.138.132

    game of transformation-ESP-3DES-SHA

    match address 101

    !

    No crypto card-2800-ipsec-policy 1

    Let me know how it goes.

    Portu.

    Please note all useful posts

    Post edited by: Javier Portuguez

  • EZVPN 2811 router VPN module

    Hi all

    I have a spare 2811 router that would like to use for the temporary easy VPN server.

    the router IOS is already updated security advance 15.0 K9.

    My question is the AIM - VPN a real map/module on the motherboard of the router or just pop up once the router has been upgraded to IOS security?

    SH ve | I have IOS
    Cisco IOS software, 2800 Software (C2800NM-ADVSECURITYK9-M), Version 15.0 (1) M8, RELEASE SOFTWARE (fc1)

    #sh inv
    NAME: "2811 chassis', DESCR:"2811 chassis.
    PID: CISCO2811, VID: V02, SN: FTX0911Cxxx

    NAME: ' PVDMII DSP SIMM with a DSP on the Slot 0 SubSlot 4 ', DESCR: 'PVDMII DSP SIMM with a DSP.
    PID: PVDM2-16, VID: V01, SN: FOC13071xx

    NAME: "virtual private network (VPN) on the Slot Module 0 ', DESCR: 'encryption PURPOSE Element '.
    PID: AIM-VPN/EPII-PLUS, VID: v01, SN: FOC09072xx

    You have now two VPN modules in your router:

    1. The module for basic needs
    2. The module see you in "inventory to see the" which is placed in the OBJECTIVE of on-board connector. This module has a flow more and a greater number of tunnel and will be used by default.

    There are many examples of EzVPN configuration guide:

    http://www.Cisco.com/c/en/us/TD/docs/iOS-XML/iOS/sec_conn_esyvpn/configuration/15-Mt/sec-easy-VPN-15-Mt-book/sec-easy-VPN-Srvr.html

    If it is more then a temporary solution, I would also consider using an ASA to remote access VPN. EzVPN is more or less obsolete, and the ASA has many more features with the AnyConnect client. On the router, you can also configure remote access for AnyConnect, but it is much more complicated.

  • DNS error with wired router

    When I first bought a PS3, I needed a router to access the internet for my PC and my PS3. It worked fine for several months and then one day, that my router is no longer me connected to the internet. Currently I am connected to the internet directly from my modem which means that it is not my ISP that has the problem. When I connect the router it says that there is some sort of DNS error. Help?

    What is the model of the router?

    Are you on the computer or on the... PS3 DNS error ?

    On the computer, click on start > all programs > Accessories > guest... A black box will appear (command prompt)... In the command prompt window type ipconfig and press "Enter"... Look for Ethernet adapter Local Area Connection address IP, subnet mask, and default gateway... IP address must be 192.168.1.x, subnet mask: 255.255.255.0 default gateway: 192.168.1.1 (assuming that your router is 192.168.1.1)...

    If you get mentioned above IP address, a subnet and address the gateway then you ping the gateway, type ping 192.168.1.1 and press ENTER... If she gives you ask has expired, and then disable any firewall, the security software on the computer...

    If you get 4 replies then type ping 4.2.2.2 and press ENTER, if you get the request exceeded, then you must update the firmware on your router... If you get 4 replies then type ping yahoo.com and press ENTER... If you get answers from Yahoo, then you should get the Internet after adjusting the browser settings...

    Setting of the browser settings: open an IE, click on tools > Internet Options, and then delete all files, cookies, history, forms... GoTo 'Connections', make sure that never Dial a connection is selected, click on network settings and make sure that all the options are unchecked... Once you are finished, click OK... Close IE and reopen...

    If yahoo expires, provide static DNS on your connection to the local network...

    Click the Start button > settings > Panel > Network Connections - right click on Local area connection icon and go to properties On the "Général" tab, select "TCP/IP Internet Protocol" and click on the properties button - select "Use the following DNS parameters" DNS preferred 192.168.1.1 DNS auxiliary - 4.2.2.2 > Click on the button Ok to save and click on 'Close' in the main window of properties... You should be able to go online...

  • Radio card of Cisco 2811 router wireless

    Hello

    Is it possible to configure the card wireless in a router as a customer to use another radio as gateway?

    The situation is that I need to set up Internet access temporary to query users on a local network cable but have no Internet connectivity. I have a Novatel MiFi, which allows Internet connectivity which I want the radio on the router to connect to. In this case, the radio will be more than one client or a bridge.

    Thanks for any input.

    Vincent

    The answer is no. Cisco access points using the Protocol IAPP talk to each other... Cisco with Non-cisco, we cannot communicate...

    Let me know if that answers your question...

    Concerning
    Surendra
    ====
    Please do not forget to note positions that answered your question and mark as answer or was useful

  • Error in virtual router Manager

    I installed the VRM module successfully. But every time I try to connect to a device through VRM one massage appears "the service cannot accept messages of control at the moment. (Exception from HRESULT: 0 x 80070425) »

    Thus the connection could not be established.

    Need suggestion to solve the problem.

    Hi Jackson,.

    Thanks for posting your query in Microsoft Community.

    According to the description of the issue, I recommend you post your query in the TechNet Forums. TechNet is watched by other computing professionals who would be more likely to help you.

    TechNet Forum

    Hope this information is useful.

  • How to solve - LIBTUX_CAT:4053: ERROR: failure of the routing function - error?

    Hello

    We use TUX 8.1 and I get the error:

    LIBTUX_CAT:4053: ERROR: function of routing failed

    citing a tpforward call.

    My UBB for the new service is below.

    'NewXXInqu '.
    LOAD = 50 PRIO = 50
    BUFTYPE = "ALL".
    ROUTING = 'PARTITION
    TRANTIME = 90
    TRANSCENDING = N

    BY DEFAULT: LOAD = 50 PRIO = 50 BUFTYPE = 'ALL' TRANSCENDING = N
    * ROUTING
    'PARTITION
    FIELD = "ID_PARTITION."
    BUFTYPE = "FML32.
    WILL = «1:P1, 2:P2»

    Sound also to give the error: GP_CAT:1064: ERROR: field 'NewXXInqu' null routing
    LIBTUX_CAT:1401: WARN: failure of tpacall tpforward TPESYSTEM - internal system error

    I have the file object created NewXXInqu, which is related to NewXXSvr. This NewXXSvr server is up and running and I can see that using ps - ef.

    can you please tell me what is missing this im here. What does routing field null 'xx' mean?

    Even if I call my new service directly, it gives the same error: GP_CAT:1064: ERROR: routing field for 'xxx' null.
    LIBTUX_CAT:4053: ERROR: function of routing failed.

    Appreciate your response,
    Thank you
    Gopi.

    Hey Gopi,

    The routing criterion you set requires that the being sent to the FML32 buffer must contain field id_partition. If it does not contain this field, Tuxedo does not know how to route the request. You could add a routing by default for the routing criterion, but I suspect that will hide just everything that is the real problem. As I mentioned in response to your other post, try to print on with Fprint32() FML32 buffer before calling the service and checking that the field is present.

    Another thought, since it occurs in a TPFORWARD application, make sure that the server that makes the TPFORWARD has access to the field table that defines the id_partition. If the transfer server does not well-positioned FML32 field table environment variables, Tuxedo cannot find PARTION_ID to determine if the field is present in the buffer or not.

    Kind regards
    Todd little
    Chief Architect of Oracle Tuxedo

  • 2811 VPDN Configuration

    Hello

    I try to configure the VPDN on 2811 router, but I am not able to connect to the VPN. Frist when I start the Dialer VPDN from my PC, I get this message.

    * 27 sep 12:00:33.314: % CRYPTO-6-IKMP_MODE_FAILURE: treatment of quick failed XX.XXX with the peer. XX.218

    as a result, the configuration... Please let me know where I get the error

    Building configuration...

    Current configuration: 2043 bytes

    !

    version 12.4

    horodateurs service debug datetime msec

    Log service timestamps datetime msec

    no password encryption service

    !

    hostname VPN_R1

    !

    boot-start-marker

    boot-end-marker

    !

    no set record in buffered memory

    activate the password

    !

    No aaa new-model

    !

    resources policy

    !

    IP subnet zero

    !

    !

    IP cef

    No dhcp use connected vrf ip

    !

    !

    IP flow-cache timeout active 1

    name of the server IP XX.XX.XX.180

    name of the IP-server 1.2.1.211

    without denying the action of ips ips-interface ip

    VPDN enable

    !

    VPDN-Group 1

    ! Default L2TP VPDN group

    accept-dialin

    L2tp Protocol

    virtual-model 1

    no authentication of l2tp tunnel

    !

    !

    !

    !

    username password 0 test1234 test1234

    username password 0 ciscovpn ciscovpn

    !

    !

    !

    crypto ISAKMP policy 10

    BA 3des

    preshared authentication

    Group 2

    ISAKMP crypto key CisC01234 address 0.0.0.0 0.0.0.0

    !

    Crypto ipsec transform-set esp-3des esp-sha-hmac PSAB

    transport mode

    !

    Crypto-map Dynamics cc 10

    Set nat demux

    Set transform-set PSAB

    !

    !

    map cisco 10-isakmp ipsec crypto dynamic cc

    !

    !

    !

    !

    interface Loopback0

    10.1.1.1 IP address 255.255.255.0

    !

    interface FastEthernet0/0

    Description $FW_OUTSIDE$

    IP address xxx.xxx.xxx.94 xx.xx.xx.252

    full duplex

    Speed 100

    Cisco card crypto

    !

    interface FastEthernet0/1

    Description $FW_INSIDE$

    IP address 1xx.1x1.xx3.1x3 255.255.255.192

    route IP cache flow

    automatic duplex

    automatic speed

    !

    interface virtual-Template1

    IP unnumbered Loopback0

    peer default ip address pool-l2tp pool

    Chap PPP authentication protocol

    !

    IP local pool pptp 1.100.0.1 1.100.0.10

    IP classless

    IP route 0.0.0.0 0.0.0.0 1xx.1xx.xx.93

    !

    The FastEthernet0/1 flow-export source IP

    IP flow-export version 5

    IP destination of the import-export 9996 stream 1xx.1xx.xxx.250

    !

    IP http server

    no ip http secure server

    !

    Server SNMP ifindex persist

    !

    !

    !

    !

    control plan

    !

    !

    Line con 0

    line to 0

    line vty 0 4

    password

    opening of session

    !

    Scheduler allocate 20000 1000

    !

    end

    Please let me know why I am not able to connect to the VPN

    Diego,

    It is not necessary.

    Example of configuration:

    http://www.Cisco.com/en/us/docs/iOS/sec_secure_connectivity/configuration/guide/sec_l2tp_nat_pat_ps6441_TSD_Products_Configuration_Guide_Chapter.html#wp1047641

    It is quite common to use the loopback.

    Marcin

  • DMVPN Tunnel and EIGRP routing problem

    I have redundant paths to a remote 2811 router on my network of sites.  The first links is a T1 frame relay connection that has been in place for years, and the new link is on a 54 Mbps fixed wireless that was recently created.

    I'm under EIGRP to my process of routing protocol 100 for the two links.

    I installed a DMVPN Tunnel between the remote 2811 and no. 2851 router on my host site.  The tunnel interface shows to the top and to the top of both sides and I can ping the IP remote tunnel of my networks side host.

    However my eigrp routes are not spread over this new tunnel link and if I run a command show ip eigrp neighbor on each router I show only the neighbor for the frame relay link and not the new wireless link.

    What I'm missing here?

    A tunnel0 to see the shows the following:

    Tunnel0 is up, line protocol is up
    Material is Tunnel
    The Internet address is 10.x.x.x/24
    MTU 1514 bytes, BW 54000 Kbps, DLY 10000 usec,
    reliability 255/255, txload 1/255, rxload 1/255
    Encapsulation TUNNEL, loopback not set
    KeepAlive not set
    Tunnel source (FastEthernet0/1), destination 172.x.x.x 10.x.x.x
    Tunnel/GRE/IP transport protocol
    Key 0x186A0, sequencing of the people with reduced mobility
    Disabled packages parity check
    TTL 255 tunnel
    Quick tunneling enabled
    Tunnel of transmission bandwidth 8000 (Kbps)
    Tunnel to receive 8000 (Kbps) bandwidth
    Tunnel of protection through IPSec (profile "CiscoCP_Profile1")
    Last entry of 00:00:01, exit ever, blocking of output never
    Final cleaning of "show interface" counters never
    Input queue: 0/75/0/0 (size/max/drops/dumps); Total output drops: 947
    Strategy of queues: fifo
    Output queue: 0/0 (size/max)
    5 minute input rate 0 bps, 0 packets/s
    5 minute output rate 0 bps, 0 packets/s
    packages of 880, 63000 bytes, 0 no buffer entry
    Received 0 broadcasts, 0 Runts, 0 Giants 0 shifters
    errors entry 0, 0 CRC, overgrown plot of 0, 0, 0 ignored, 0 abort
    output of 910 packages, 81315 bytes, 0 underruns
    0 output errors, 0 collisions, 0 resets interface
    unknown protocol 0 drops
    output buffer, the output buffers 0 permuted 0 failures

    Please go ahead and add a static route on the hub, so it goes through the wireless link and let me know if everything works correctly.

    Federico.

  • The Autorouter of preprocessing error.

    Hello

    Earlier, I make a big enough drawing in Ultiboard.

    My drawing is composed of 4 layers. Upper, lower and internal 2. I use the inner layers to Vcc and GND.

    Now, I want the rest of the nets to be connected using copper top and bottom copper.

    After placing all components on my Board, I tried to use the auto-router.

    Do all the nets by hand is ridiculous, as my schema contains 7 pages in Multisim.

    Now, my point is this. When I use the automatic router, I get an error message saying:

    "Error during automatic router of preprocessing.
    Source: Autorouter
    "Not valid by definition - must be multiple layers and circular.

    I use components through-hole and SMT components.

    I couldn't find a topic on this issue, but he said in Portuguese, and I can't read this language.

    Unfortunately, I can't give or download the scheme because it is a product.

    I hope someone can answer my question, because it makes me nuts.

    Thanks in advance,

    Erik

    Problem solved. I had to do my of via a little larger.

    Thanks anyway.

    Erik

  • "Error of SJphone: ' NAT/firewall: blocked".

    "SJphone has stopped working a few months ago on 3 computers of x. error display: ' NAT/firewall: blocked".

    Using Wireshark ISP said: "This shows that traffic is having issues is internal to your network." Please try to disable the firewall. "They have all been disabled.

    Tried X-Lite and receive: registration error: 503 - no route to the host.

    Could MS security updates caused the problem?

    Any suggestion is appreciated.

    Ultimately VoIPtalk could not solve the problem except by suggesting the X-Lite. That works fine!

  • error 322 when reinstalling the wireless modem

    Hi all

    I have WAG54G2 wireless modem. It was working perfectly until I formatted my computer desktop and reinstalled Windows XP. Now I want to reinstall my modem but is giving this error:

    'Error 322 new router or gateway not detected '.

    The old configuration wireless works always with my laptop, but I'm afraid of losing my wireless connection, so I did not reset the modem. I need to reset it?

    If you have no connectivity problem, there is no need to re-install/use the CD Setup again and you don't need to reset the wireless modem.

  • WRT54G2 intermitened DNS error

    I have WRT54G2 router model linksys wierless but on even my Wired once per day or if I get an error when the router cannot connect to a DNS server and I lose the connection.  Bike sometimes the router works othertimes that it doesn't and I must circomvent the router to use internet that day.  any ideas?

    I had this problem but I put in some static dns servers and now its fine.

    serve your servers dns 8.8.8.8 and 8.8.4.4 (c/o of google: http://code.google.com/speed/public-dns/ )

  • 2811 - specific need IOS!

    Hello to all-->

    I have a 2811 router, 12.3 (8) T6 (SPSERVICES) running. I would like to configure this router as a VPN endpoint, firewall, but I also need to run voice through this device, in the future. When I load 12.4.1a (ADVANCED SECURITY features), the IOS does not have 2 FXO interfaces, I have installed.

    I need an IOS for this machine, which will take place at the end of firewall, VPN, voice and IPS. Is it possible, or can I only have one or the other?

    I will cross-post to other boards... Thanks in advance!

    Of course, you would get everything in "Advanced Enterprise Services", but I think you could settle with "Advanced IP Services.

    See this PDF file. First page, the lower right corner.

    http://www.Cisco.com/warp/public/765/tools/quickreference/ISR.PDF

Maybe you are looking for

  • Satellite A660 - 11 m display is safe for the eyes?

    If any body know of course if the screen of the trunk Satellite A660 - 11 m for the eye because I have heard this eye turn red for a long time remain on the monitorIf any body know about the safety of the monitor answer me & thank you

  • How to separate data in 'several Information.vi tone "?

    NOTE: I have another post on this subject. Here is the link.----------------------------------------------------------------------------------- My ultimate goal is to get/display of the frequency at which the peaks that passes. I've used different me

  • Can not start after Windows update

    Hello My laptop has done a windows update, but crashed to halfway through, now when it starts and after that I entered my password windows 7 it crashes just, finally it loads my desktop but it took 3 hours to fully charge it and my icons but whenever

  • WAP4400N Mode, SSID, IP addresses

    Hello: I set up a wireless cable/DHCP for a motel.  They currently use a WRVS4400N Wireless - N Router connected to their cable modem and maintains two access points wireless (WAP4400N) of wire to the router, Internet wireless for all their guest roo

  • Problem of errors multiple blue screen

    Hello I seem to have a problem with my desktop Compaq Presario SR5275AP, OS: Windows Vista Home Basic Edition, 1 GB RAM, 80 GB HARD drive. Already when I turned on the pc, it has successfully started. But after a while, blue error screen open & then