How to configure a Cisco No. 2851 to access customer VPN Cisco router?

It is my current configuration below, can someone help me see problems with it:

AAA new-model
!
!
AAA authentication local connection user
AAA authorization network group local
AAA accounting update newinfo

crypto ISAKMP policy 10
BA 3des
preshared authentication
!
crypto ISAKMP policy 11
BA 3des
preshared authentication
Group 2
!
12 crypto isakmp policy
BA 3des
md5 hash
preshared authentication
Group 2
!
crypto ISAKMP policy 15
BA 3des
md5 hash
preshared authentication
Group 2
!
crypto ISAKMP policy 20
md5 hash
preshared authentication

!
ISAKMP crypto client configuration group vpngroup
key cisco123
pool VPN_POOL

Crypto ipsec transform-set esp-3des esp-sha-hmac vpnc1
!
Crypto-map dynamic dynmap 15
Set transform-set vpnc1
!
!

local IP 10.1.1.1 VPN_POOL pool 10.1.1.20

list user card crypto Test client authentication
card crypto isakmp authorization list Group Test
Crypto map Test address client configuration address
Discover 15 Test card crypto ipsec-isakmp dynamic dynmap
!
!
!
!
interface GigabitEthernet0/0
Description *.
IP address
NAT outside IP
IP virtual-reassembly
automatic duplex
automatic speed
No cdp enable
card crypto Test

Hi Ralema,

Please see this link:

http://www.Cisco.com/en/us/Tech/tk583/TK372/technologies_configuration_example09186a00800949ba.shtml

It will be useful.

Federico.

Tags: Cisco Security

Similar Questions

  • My IP security camera is different my network ip address, how to configure the camera to match the ip address with the router cable time Wörner

    Please someone help me configure my camera IPsecurity model m12 mobotix ag. It allows to work in the corporate network, but they close down and I didn't bring the camera House but there different IP address of my network and I don't know how to configure the camera to have the same IP address with my home router to TWC, thanks

    Router connections by opening network, in the Panel control, search for the router / properties, enter its configuration

    data in the boxes provided, you will get on the router, a sticker shows data. If lost or deleted, go to its Web

    for the data. Also, perhaps the home page of IP camera offers software/drivers.

  • How to configure ASDM Cisco ASA 5505

    I have a Cisco ASA 5505 firewall, and currently it is a command-line firewall. I want to configure ASDM so that I can use it as a Web based GUI interface.

    I don't really know what to do. Can someone help me please how I can configure ASDM on my firewall.

    Kind regards

    Naushad Khan

    Hi Naushad,

    First of all, must load the image ASSDM on SAA and then use the command:

    ASDM image dosk0: / asdm645.bin (if the image name is asdm645.bin)

    then:

    Enable http server

    http 10.0.0.0 255.0.0.0 inside (if your machine is 10.0.0.0 subnet behind inside the inetrafce)

    Go to the machine, open a browser and type:

    https://

    It will open the GUI.

    Thank you

    Varun

    Please evaluate the useful messages.

  • How to set up a Windows VM internet access?

    I have 1 server with VMware ESXi 5 installed.

    It has 1 physical NETWORK adapter with 1 static IPv4 address.
    I can connect to the host with vSphere Client and SSH.
    It has 2 windows (Windows XP, 1 Windows Server 2008 1) VM installed and running. They have all both VMWare Tools installed.
    I have no access to the physical switches or routers.
    How to configure networking for virtual machines can access the internet?

    I'm afraid that you won't be happy with ESXi with only a single IP address. What wshould is a hosted as VMware Workstation solution. With this you can configure NAT network for the virtual machine as well as the redirect in order to access the virtual machines outside port.

    André

  • How to configure Cisco Telepresence SX 20

    Looking for this topology please help me how I can configure SX 20.

    If you do a search in these forums for autonomous SX20, you'll see a lot of messages that describe how to configure a SX20 and required firewall ports.

    A good example is this: autonomous SX20

    Wayne
    --
    Remember the frequency responses and mark your question as answered as appropriate.

  • How to configure the VPN LAN to access the internet from the remote network

    I have set up for our project site to another Office VPN. Please join.
    Now I have already configured Site to site vpn between ASA 5510 and 1841 router.

    HQ LAN

    Branch of the LAN
                     10.2.1.0/24 > ASA 5510 1841 > > INTERNET < 1841=""> <> 10.30.3.0/24
    ^
    ^
    ^
    ^
    Call Manager
    No. 2851
    Now access from branch LAN LAN of HQ each other.

    I face problems that are
    (1) in the direction of LAN, they can access HQ LAN & resource, but cannot access the internet. I did not configure NAT on the router PH
    (2) can I access internet BRANCH LAN via HQ LAN INTERNET. Where can I access the Internet of general management of the LAN of the PH router directly while access to the VPN to the local network of HQ?
    (3) in the Site of the Directorate, phone hard cannot work but phone on PC can call to Headquarters. Hard IP phone are same in remote network (172.16.1.0/24 ). What's the problem? How can I configure separately?

    Please give advise me how should I do.

    Hello

    (1) in the direction of LAN, they can access HQ LAN & resource, but cannot access the internet. I did not configure NAT on the router PH

    Answer:

    You must configure the NAT and crossed to the ASA HQ so that the VPN branch router provides LAN and u-Turn, access to Internet of the SAA.  You must first seup NAT for the branch on the SAA router subnet, then you must type the command:

    permit same-security-traffic intra-interface

    Here's a great example for VPN client hairpining.

    http://www.Cisco.com/en/us/products/ps6120/products_configuration_example09186a00805734ae.shtml

    (2) can I access internet BRANCH LAN via HQ LAN INTERNET. Where can I access the Internet of general management of the LAN of the PH router directly while access to the VPN to the local network of HQ?

    Yes, you can

    (3) in the Site of the Directorate, phone hard cannot work but phone on PC can call to Headquarters. Hard IP phone are same in remote network (172.16.1.0/24 ). What's the problem? How can I configure separately?

    You must change your subnet VLANS to be different from the subnet HQ voice phone IP VOice VLAn, it should be fine.

    Kind regards

    Mohamed

  • Stand-alone configuration of Cisco Aironet 700i

    Hello

    I'm well aware new products Cisco. So please forgive my basic questions.

    I have Cisco Aironet 700 series AP(AIR-SAP702I-Q-K9). I don't have a controller. I need to set this up as standalone access point.

    I tried all the basic steps and tried to activate the two radios, but no luck. Anyone can guide me please on how to configure the AP.

    I use web access to configure the AP.

    Help, please

    Thank you

    Sagar

    Hi Sam,

    Please check these messages to set up autonomous AP.

    https://rscciew.WordPress.com/2014/05/24/single-SSID-configuration-on-au...

    https://rscciew.WordPress.com/2014/05/24/multiple-SSID-configurations-on...

    Concerning

    Remember messages useful rates

  • How to configure a FTP server and the web and integrate with 5.2 DMM

    Hi all...

    I need to set up an external server only for publishing content to reduce the overhead of the DMM server.

    can someone guide me on how to configure the external server and it intergrate with the DMM 5.2

    Thank you

    semuthu,


    Notes from the Release Notes:


    Limitations of compatibility with Microsoft Internet Information Server (IIS)

    DMP who use firmware version 5.2 is compatible with a single version of Microsoft Internet Information Server.

    This supported version is IIS 6.0 for Windows 2003 Enterprise Edition. If you do not have the support for IIS version but

    want your DMP to recover the assets of a Web server, we recommend that you use Apache instead of IIS.



    I suggest to use Apache instead of IIS for the Web Server service. IIS can be used as FTP if necessary.

    There are a lot of Documents on the Internet concerning the implementation of Apache and FTP servers.


    Using Apache with Microsoft Windows

    http://httpd.Apache.org/docs/2.0/platform/Windows.html


    Quick HOWTO: Ch20: Apache Web Server

    _ http://www.linuxhomenetworking.com/wiki/index.php/Quick_HOWTO: _Ch20_:_The_Apache_Web_Server


    Once the Web server is configured and operational. You simply record your multimedia content on the Web server

    and then have your DMS assets in the library using an external URL address for its location.


    If you want to use the external server for other features in the DMM, you can see how to set up

    here:


    http://www.Cisco.com/en/us/partner/docs/video/digital_media_systems/5_x/5_1/DMM/user/guide/DSM+ETV.html#wp1073210

    Goto the section just below the CNSC & WAAS...


    If this answers your question, take the time to mark this

    discussion answered & rate the answer.


    Thank you!


    T.


  • How to configure ACS 5.2 to manage the Junos 10.4R6.5 fwl via GANYMEDE.

    Hi all

    I have a camera ACS 5.2 newly installed, integrated with our announcement and his work with cisco product, routers switches and etc.  Now I would like to include Juniper firewalls so to be authenticated via ACS 5.2 either via ssh and web access.  Can someone share me how to initiate this, creating policies.

    FYI: I have 14:00 groups regionaladm and regionalops, read/write and read-access, respectively.

    Kind regards

    Marlon

    Marlon,

    I stuck in a config below file I made for our ScreenOS Firewall work with Cisco ACS v5.2.  This configuration may not work because yours is Junos, but it could bring closer you reach to understand.  Also, if you have not been on the Juniper J-Net ask autour, give it a shot. (forums.juniper.net)

    Good luck!

    -Chris

    Title: Example configuration - GSU of Juniper and Cisco ACS v5.x

    Product: SSG320M juniper (Cisco ACS v5.x)

    Version: 6.3.0r10.0 ScreenOS (Cisco ACS v5.2.0.26.8)

    Network topology:

    [Juniper SSG320M]-[Cisco 3560 Switch]-[Cisco ACS VM]

    Description:

    Goal - authenticate GSU administrators using GANYMEDE + instead of local connections

    Description - This configuration for Cisco ACS v5.x, JTACS had only configuration v3.3.

    ACS v5.x is a VM based on Linux with a completely new user interface and structure.

    Configuration:

    Configure the Juniper (CLI)

    1. Add configuration Cisco ACS and GANYMEDE +.

    Set id CiscoACSv5 of auth-server 1
    set the auth-CiscoACSv5 server ServerName 192.168.1.100
    set server CiscoACSv5-type of admin account
    set the server CiscoACSv5 auth type Ganymede
    Define auth-server CiscoACSv5 Ganymede secret CiscoACSv5
    define CiscoACSv5 Ganymede 49 auth-server port
    Set the server auth admin CiscoACSv5
    Set admin auth distance primary
    Remote admin auth root set
    define outer-get administrator privileges

    Configure the Cisco ACS (GUI) v5.x
    1. navigate to elements of strategy > authorization and permissions > peripheral Administration > Shell profiles
    Create the profile of Shell of Juniper.
    Click the button [create] at the bottom of the page
    Select the general tab
    Name: Juniper
    Description: Custom for Juniper SSG320M attributes
    Select the custom attributes

    Add the vsys attribute:
    Attribute: vsys
    Requirement: required
    Value: root
    Click on the [Add ^] button above the field for the attribute

    Add the attribute of privilege :

    Attribute: privilege
    Requirement: required
    Value: root

    Note : you can also use "read-write", but then the local admin does not work correctly
    Click on the [Add ^] button above the field for the attribute
    Click the button [send] at the bottom of the page

    2. navigate to access policies > Access Services > default device Admin > authorization
    Create the authorization policy of Juniper and filter by IP address.
    Click [customize] at the bottom right of the page
    In terms of customize, select IP address in the left window
    Click the [>] button to add
    Click the [OK] button to close the window

    Click the button [create] at the bottom of the page to create a new rule
    In general, the name of the new rule Juniper and make sure that this option is enabled
    In Conditions, check the box next to IP address
    Enter the ip address of the Juniper (192.168.1.100)
    Under results, click the [Select] button next to the Shell profile field
    Select "Juniper" and click the [OK] button
    Under results, click the [Select] button under the command field sets (if used)
    Select "allow all the" and make sure all other boxes are not CHECKED
    Click the [OK] button to close the window
    Click the [OK] button at the bottom of the page to close the window
    Check the box next to the policy of Juniper , and then move the policy to the top of the list
    Click on the [Save] button at the bottom of the page

    Audit:

    Connect to the CLI of Juniper and GUI using an ACS internal user account and try to change something to check the level of privilege.

  • Please give index on configuring vpn site to site on 881 to ASA 5505 cisco router

    Earlier my boss asked me to prepare to implement the VPN site-to site on router Cisco 881 Integrated Services to ASA 5505 router, which is now running on the side of HQ. Someone please give me a hint. I am now learning the pdf file from Cisco that mention how to configure VPN site to site between 1812 Cisco IOS router and router of the ASA 5505 using ASDM V6.1 and SDM V2.5. Cannot find the book for the Cisco 881 device.

    Someone please please suggest me something as soon as POSSIBLE.

    Thank you

    CLI version:

    http://www.Cisco.com/en/us/products/HW/vpndevc/ps2030/products_configuration_example09186a00807ea936.shtml

    ASDM and SDM Version:

    http://www.Cisco.com/en/us/partner/products/ps5855/products_configuration_example09186a0080a9a7a3.shtml

  • MS NLB Multicast configuration on Cisco Bladecenter switches mode

    We seek to MS NLB Multicast configuration on Cisco Bladecenter switches mode. We are adding static ARP and CAM entries for each port on the switches kernel that

    the Bladecenters are connected to, or just the port of the virtual machine arrives at

    push traffic at this time here? If we add it to a single port,

    How vmotion will work... because it seems that we have to manually

    transfer the arp from one port to the other entry.

    We add the static ARP entry to the entire Cisco switch. If you can VMotion VMs NLB to another host that is physically connected to another switch, then this switch have thus added ARP entry. We have not tested the configuration only on the specified ports. But if you do, make sure that you include all the ports connected to the physical switch (if for DS you have four natachasery configured in a vSwitch...).

    Here's a guide to how we have configured it several times in our society.

    http://www.VI-tips.com/2009/04/NLB-in-VMware.html

  • How to configure rdm to use iscsi lun in a virtual machine using ms iscsi initiator?

    I have equallogic SAN attached to a cisco 3750

    switch. It comes to our storage network.

    Within the virtual machine for all readers of data other than my c:\ that has the operating system I would use iscsi data switch that has 4 network ports on four different nic cards already assigned.

    According to what I read a virtual machine can use only 4 nic so I have a Production network the other three that I would

    Use it for iSCSI data.

    Three ports of each virtual computer network for using ms iscsi with MPIO

    initiator.

    I have already attached the RDM using esxi 3.5 as a physical mapping of RDM.

    My question is how to configure the ports of the network adapter in the virtual machine?

    The VM network is on 172.19.2. * where iscsi is on 172.19.21. *.

    What would be the entrance on the network adapters in the virtual machine that is running ms win 2 k 3 r2 x 64.

    Thank you.

    ESX / Configuration / networking

    Propertties (near vSwtich3).

    On vSwitch object / change

    NIC Teaming tab.

    Menu of load balancing.

    André

    * If you found this device or any other answer useful please consider awarding points for correct or helpful answers

  • How to configure microsoft exchange account

    How to configure Microsoft Exchange account on iPhone.

    I'm getting a problem while creating a Microsoft Exchange account on the iPhone. Can any body tell me How to set up a mail in iPhone because I want to set up an account for Microsoft exchange on iPhone

    Thank you in advance

    Alondra Cooper

    You can read this article to learn how you can put your email on iPhone

  • How to configure firefox to open outlook e-mail links in a new tab instead of having this "crush" a tab currently open?

    How to configure firefox to open outlook e-mail links in a new tab instead of having this "crush" a tab currently open? For example, that I have a tab open and consult the information about this. An email comes in via outlook and I want to read a confined link. When I click on the link, it will open in the tab I have currently open. I would like to open it in a new tab.

    You mean Outlook, the standalone version and not the new iteration of Live (live.com) mail to Outlook.

    I think that the default is to open in a new tab in the last active window, but you can check it out here and replace the default value:

    (1) in a new tab, type or paste Subject: config in the address bar and press ENTER. Click on the button promising to be careful.

    (2) in the search above the list box, type or paste link.o and make a pause so that the list is filtered

    (3) double-click the preference browser.link.open_newwindow.override.external and change it to 3 and OK change

    The options are:

    -1 = apply the setting in Options > general > tabs of external links (default)
    3 = open external links in a new tab in the last active window
    2 = open external links in a new window
    1 = open external links in the last active tab replaces the current page

  • How to configure iPhone to get an exit "braille display" correct in Chinese, traditional way?

    We realize that somebody helps us to clarify the question of using iPhone (iOS9.3)

    When you use "braille display" under the English mode, the output is correct. However, using "braille display" in Chinese, traditional mode, the result is false. How to configure iPhone to get an exit "braille display" correct in Chinese, traditional way?

    did you ask the developer of the accessory to display braille at the end of the day, they are the only ones who can provide a 100% response

Maybe you are looking for

  • can I add an antivirus protection for my iPad?

    It is necessary (or possible) to add anti-virus software for my iPad? I saw this question; However, it seemed there was an ongoing argument... didn't see the real answer. Thanks to anyone who can answer me just. Not a techie.

  • What wireless card for P2800?

    Hello I would like to add a wireless card to my P2800, Win 2000 family Edition. I decided to go through Netgear PC Card wireless 32-bit CardBus Dual Band WAG511 - 108 MB/sec. What do you think? Do I have a problem with it on my pc? Thanks a lot for y

  • Upgrading processor on Satellite L500-1QE

    I have a Satellite L500-1QE and I want to know if I can change my processor to something again, because now I use Dual-Core 2.2 Ghz T4400. (I don't know much about the updates that is why I ask) Thanks in advance.

  • Printer HP B209a does not get the IP address of my router

    Computer is a HP G71 running under Windows 7 64-bit Router is a NETGEAR's WNR3500L with the latest firmware and a unique SSID Using the latest version of the software install HP B209a Towards the end of the installation for the wireless feature, the

  • Second product key?

    HelloI have a copy of the retail of Vista Ultimate, with disks and a touch # valid. I want to install Vista Ultimate on a new computer as a second operating system with windows 7 which is above. Can I buy just an another # key valid microsoft or some