More small Cisco 800 series + DMVPN?

Hello

Recently I looked into the possibilities to extend a DMVPN (already implemented) with very remote of small (1-2 user) on a single link to the ISP.

I would use what is essentially the smallest Cisco router supporting DMVPN and EIGRP (heel) - here is an example configuration:

Tunnel interface *.

bandwidth *.

IP address

IP - eigrp hold time *.

authentication of property intellectual PNDH *.

map of the PNDH IP * *.

multicast IP PNDH card *.

network IP PNDH ID *.

Holdtime PNDH IP *.

property intellectual PNDH nhs *.

property intellectual PNDH registration timeout *.

tunnel source *.

multipoint gre tunnel mode

tunnel key *.

tunnel path-mtu-discovery

Ipsec-tunnel protection profile *.

All this accompanied by the overall policy and isakmp transform appropriate.

I know that the 881 can accomplish the above without problem (if it has IP Adv licenses Services).

I would like to know if I can use the small routers (physically smaller, that is) for a similar configuration. Can anyone provide an overview here? Pouvez router Cisco 819 (http://www.cisco.com/en/US/prod/collateral/routers/ps10906/ps380/ps11615/data_sheet_c78-678459.html)

provides the same functionality? What the 866VAE router (http://www.cisco.com/en/US/prod/collateral/routers/ps380/data_sheet_c78-693249.html)?

819 does support both DMVPN and EIGRP.

866VAE does not support the DMVPN.

Tags: Cisco Security

Similar Questions

  • block websites Web of Cisco 800 series Router

    Hello

    I have a Cisco router running. I want to block certain websites (facebook, twitter, etc.) and download files with extensions such as

    *.AVI, *.mp3, *.mp4, *.exe, *.wma, *.wmv and *.torrent etc...

    I want to block for some users (based on the MAC address) and allow other users to have access to it on the same network.

    Help me to do this?

    Here's what you do:

    IP block ip extended access list

    allow an ip

    permit tcp host 192.168.0.100 any eq www

    permit tcp host 192.168.0.107 any eq www

    I suggested to do the following:

    IP block ip extended access list

    permit tcp host 192.168.0.100 any eq www

    permit tcp host 192.168.0.107 any eq www

    Can't you see the difference?

    Concerning

    Alain

    Remember messages useful rate.

  • Easy vpn server issues of Cisco 800 series.

    Hello.

    I want to deploy the easy vpn server on cisco 876 and 877 10 routers and access from a remote location (company headquarters). When I leave the firewall of the router off the vpn server works. When I turn it on it doesn't.

    Although I allow all traffic to my ip for example 80.76.61.158 I can't access the vpn server.

    I tried a place to let the firewall off and it worked fine.

    I use SDM to configure the vpn server. Any ideas what I can do with the cause of firewall I really can't leave it "open."

    Thanks in advance.

    It would be a good idea to paste the configuration of the VPN server to the firewall.

    Kind regards

    Kamal

  • Configuration of SNMP on Cisco Small Business 300 Series managed switch

    Please can someone help me configure SNMP on Cisco Small Business 300 series switch?

    Thank you

    Hi Anton,.

    Don't forget to activate the service SNMP is first of all: Security > Services TCP/UDP.

    http://sbkb.Cisco.com/CiscoSB/UKP.aspx?VW=1&docid=3b13278d9ef9402a8fef57...

    also, you will find useful documents for configuration etc on our server community kb:

    http://sbkb.Cisco.com/CiscoSB/UKP.aspx?VW=1&docid=183cae2148d445b2a07473...

    Let us know if you have any problems.

    Aleksandra

  • The vs ASA55xx 800 series routers

    Can someone give me a kind of overview of the differences between the devices of the ASA and 800 series routers (specifically 871)?

    Mainly interested in VPN and security, but everything that can give me an idea of which one fits my scenario is greatly appreciated.

    I have several agencies that I'll set up, a few small (1 WinXP), support (WinXP 5-15, 1-10 VPN), some big (for me) (10-100 WinXP, 10-50 VPN).

    I am also interested in the same question.

    You may want to look at

    http://www.Cisco.com/application/PDF/en/us/guest/products/ps2030/C1650/ccmigration_09186a00801daa53.PDF

    ASA firewalls are certainly faster than the 800 series routers, but for small offices (10 users), it may be not important. I like the ASA 5505 because there a switch 8 ports built-in, while the 871 has a 4 port switch.

    One thing to remember is that, although the ASA has a FEW abilities of routing... it is first a firewall. So, you lose some flexibility by going with an ASA you may have a router. (for example: I don't think that the SAA can be a "router on a stick" with packets routed in & out on the same interface)

    However, on the router 871 with all the features of firewall, to ensure that firewall features are enabled and configured... by default the SAA is a firewall... not to not do anything except plug it in and the firewall features are run automatically.

    That's my opinion anyway

    Thomas

  • Question of the router Cisco RV series

    Hello

    I have a question. We sell a lot of cisco 800 routers. Now for some clients, we have that they are expensive.

    Then we thought about the RV series, but I can't find any good routing performance for these routers specifications.

    If I go to:

    http://www.Cisco.com/Web/partners/downloads/765/tools/quickreference/routerperformance.PDF

    I see a lot of details of the cisco product, but the RV series isn't here.

    Can someone tell me what are the specifications of performance of these routers? (packets per second, Mbit/s data rate)

    Thanks in advance,

    Tom

    You can also access the data at smallnetbuilder. There are many different performance tests

    http://www.SmallNetBuilder.com/lanwan/router-charts/view

  • 800 series and VPN

    Hi all

    I have searched high and low for answering this question and came from far away confused.

    Should I DMVPN in order to use a VPN endpoint behind a perfomring NAT router?

    ISP---> Internet router---> 800

    In addition, if the answer is no, then can al of the 800 series and soho routers support this?

    I appreciate really all help with that.

    I'm glad to hear that.

    If you have any other questions, let us know

    Please evaluate the useful messages.

    Federico.

  • 800 series Router and ASA will not create a tunnel

    Hey everybody, what had confused me for a week now, and I feel that it is something small that im overlooking. My 800 router and my ASA will not pass traffic through a VPN. Here are my configs (less sensitive data of course). I also removed irrelevant data to narrow down the config.

    800 series router:

    DHCP excluded-address 192.168.2.1 IP 192.168.2.100

    !

    IP dhcp pool internaldhcp

    network 192.168.2.0 255.255.255.0

    x.x.x.x where x.x.x.x DNS server

    default router 192.168.2.1

    !

    !

    IP cef

    no ip domain search

    domain IP (domain here)

    Server name x.x.x.x IP

    Server name x.x.x.x IP

    No ipv6 cef

    !

    !

    crypto ISAKMP policy 1

    BA 3des

    md5 hash

    preshared authentication

    Group 2

    address key (password) crypto isakmp (ip WAN of ASA)

    !

    !

    Crypto ipsec transform-set esp-3des esp-sha-hmac 3des-sha

    Crypto ipsec transform-set esp-3des esp-md5-hmac 3des-md5

    Crypto ipsec transform-set esp-3des esp-md5-hmac distance

    !

    !

    map KentonMap 1 ipsec-isakmp crypto

    defined peer (ASAs WAN IP)

    the value of the transform-set 3des-sha

    match address 110

    !

    !

    !

    !

    !

    interface FastEthernet0

    no ip address

    !

    interface FastEthernet1

    no ip address

    !

    interface FastEthernet2

    no ip address

    !

    interface FastEthernet3

    no ip address

    !

    interface FastEthernet4

    Description outside the int

    (Local WAN) 255.255.255.252 IP address

    NAT outside IP

    IP virtual-reassembly in

    automatic duplex

    automatic speed

    card crypto KentonMap

    service-policy output VoiceLLQ

    !

    interface Vlan1

    IP 192.168.2.1 255.255.255.0

    IP nat inside

    IP virtual-reassembly in

    Fair/fair-queue

    !

    !

    IP nat pool insidepool (WAN IP) (WAN IP) netmask 255.255.255.252

    IP nat inside source list 100 insidepool pool overload

    IP route 0.0.0.0 0.0.0.0 (Next Hop)

    !

    access-list 100 permit ip 192.168.2.0 0.0.0.255 any

    Note access-list 110 VPN ACL

    access-list 110 permit ip 192.168.2.0 0.0.0.255 192.168.24.0 0.0.0.255

    !

    The ASA config:

    interface Ethernet0/0

    switchport access vlan 2

    !

    interface Ethernet0/1

    !

    interface Ethernet0/2

    !

    interface Ethernet0/3

    !

    interface Ethernet0/4

    !

    interface Ethernet0/5

    !

    interface Ethernet0/6

    !

    interface Ethernet0/7

    !

    interface Vlan1

    nameif inside

    security-level 100

    IP 192.168.24.1 255.255.255.0

    !

    interface Vlan2

    nameif outside

    security-level 0

    (LOCAL WAN) 255.255.255.252 IP address

    !

    permit same-security-traffic intra-interface

    IP 192.168.24.0 allow Access - list extended sheep 255.255.255.0 192.168.2.0 255.255.255.0

    Access extensive list ip 192.168.24.0 LimatoKenton allow 255.255.255.0 192.168.2.0 255.255.255.0

    OutsideIn list extended access permit tcp any interface outside eq 3389

    Global 1 interface (outside)

    NAT (inside) 0 access-list sheep

    NAT (inside) 1 192.168.24.0 255.255.255.0

    Route outside 0.0.0.0 0.0.0.0 (Next Hop) 1

    Server enable SNMP traps snmp authentication linkup, linkdown cold start

    Crypto ipsec transform-set esp-3des esp-sha-hmac 3des-sha

    life crypto ipsec security association seconds 28800

    Crypto ipsec kilobytes of life - safety 4608000 association

    card crypto LimaMap 1 corresponds to the address LimatoKenton

    card crypto LimaMap 1 defined peer (800 WAN router)

    card crypto LimaMap 1 the value transform-set 3des-sha

    LimaMap interface card crypto outside

    crypto isakmp identity address

    crypto ISAKMP allow outside

    crypto ISAKMP policy 1

    preshared authentication

    3des encryption

    md5 hash

    Group 2

    life 86400

    tunnel-group (800 WAN router) type ipsec-l2l

    tunnel-group (800 WAN router)

    IPSec-attributes

    pre-shared key *.

    ISAKMP crypto release:

    ASA

    Type: L2L role: initiator

    Generate a new key: no State: MM_ACTIVE

    Router

    DST CBC conn-State id

    (Local WAN)    (ASA WAN)   ACTIVE QM_IDLE 2003

    Hello, Benjamin.

    I guess that your router does NAT same for site traffic to site.

    So, you have to deny traffic between ACL 100 sites.

    PS: If this does not resolve your problem, could you please share isakmp/ipsec its on both sides?

  • Australian release for HP IQ 800 series date - someone has an idea?

    The touchsmart IQ800 series computers were available in the markets of USA, Europe and Asia for almost a year. Despite several requests remained unanswered, in August 2009, the uncompromising HP still refuses to give Australian clients a final release date. The 800 series is clearly an important step of the 500 series, throughout all the technical characteristics of the product.  If, like me, you're interested in investing in one, the only option available to Australian customers at the moment, is to import from Asia or USA at risk and cost.  Having expressed my dissatisfaction, someone at - he a clue regarding when this model will be available in this country?

    HP headquarters informed me today that the IQ818a is available through Harvey Norman on special order only.

    As a solution to this issue, they also advised a new IQ series (record still forthcoming) version will be available on the market in October 2009.

  • Satellite A660 - 11 M - Possible to get more small/more lightweight charger?

    Very satisfied with my new A660 - 11 M, but find the charger (V85) to be almost too big/heavy to be portable. Its a minus 3 times the size of my old notebook charger (which admittedly gave only half of the current).

    The A660 relatively short battery life means I almost always win the my cell phone charger. No clue on the question of whether a more small/more light charger is available?

    > but find the charger (V85) to be almost too big/heavy to be portable

    My charger a500 is also great in comparison with other models like Asus, Hp, dell. You should contact the Asp (SAV) and ask them if you can get less size AC adapter

  • More HP psc 1200 series (all-in-one)

    MI more HP psc 1200 series all in a no prints porque el sistema reported that no tiene papel. He puesto cantidades of papel, pero continua respond that no papel tiene distintas. MI PC desktop are HP y tiene Windows 7 Ultimate. Gracias.

    Please select your language from the drop-down menu above to post your question in the language of your choice. The forum in which you've posted is for English only. If you can't find your language above, support for additional international sites options are by following the link below:

    http://support.Microsoft.com/common/international.aspx

    Please, select su idioma in her lista desplegable anterior to send you in el idioma of choice su pregunta. El foro Québec ha published're para frances only. If usted no encuentra el idioma no desee por encima of las options para support otros destinos international themselves can find following el siguiente enlace:

    http://support.Microsoft.com/common/international.aspx

    Gracias.

  • Why is the size of the Web page to get more small or bigger while I'm online? Am I touch a button or by pressing something by accident?

    Why is the size of the Web page to get more small or bigger while I'm online? Am I touch a button or by pressing something by accident? This happens to my daughter. We have all two computers laptops sony vaio. Does anyone else have this problem? Is there a way to avoid this?

    It is possible that one of the CTRL on your keyboard is blocked by sticky dirt coke or a faulty design on this model since it happens on 2 different Laptops:
    If you use the mouse wheel to scroll up and down your pages in Internet Explorer, CTRL + roulette is a shortcut for zoom, what would cause this symptom.

    The Vaio seems to use a complex configuration of the main keyboard drivers, search the Web for "sony vaio ctrl key pressed" to see some of these horror stories and how others solved the problem. Add your specific Vaio model name to the search string for more accurate results.
    Also check if the function FN keys work correctly, go to the Sony web site to check the driver for your model and Windows 7 updates.

    If you need to clean the keyboard, I suggest that you seek professional help.

  • -Adding memory for Cisco 7200 Series hardware

    Can anyone help point me to any document from Cisco on the addition of memory SDRAM and Flash in the Cisco 7200 series routers?

    Thanks in advance.

    DTA

    Does that help?

    http://www.Cisco.com/en/us/products/HW/routers/PS341/products_installation_guide_book09186a00800f0371.html

  • Cisco 1220 series b AP

    a cisco AP1220B series will support wpa2?

    Hi William,.

    My understanding is that the AP1220b was released prior to the adoption of the WPA2 and does not support.

    Sorry man!

    Rob

  • Have two black stripes on the right and left of the screen making it my screen more small and does not know how to remove them permanently.

    Problem with the screen!  Have two black stripes on the right and left of the screen making it my screen more small and does not know how to remove them permanently.  Can someone help, please step by step details.  Thank you.  Have Windows7!

    Original title: screen

    Looks like a monitor / setting screen. Horizontal and vertical positions may need to be adjusted in the monitor buttons. Another possibility is that the display resolution is not optimal.

Maybe you are looking for

  • Tecra M5 requires more EasyGuard HDD password

    Hi all I was a complete key and changed some BIOS settings, specific WOL on my laptop. Now, when I try to start I get is more asked for the password (the blue screen with * etc.) but rather a message saying "error loading operating system". I've trie

  • HP deskjet inkadvantage 2545: complaint

    When I connected my laptop 2545 printer via usb work is nice, but I can't connect wirelss with my camera in my laptop when I want to connect the printer application password I don't know what is my password and I don't know how to change it please te

  • I can eprint with printer HP 3050 J610A

    I can help eprint. hp3050 J610a printer

  • How to use the control ring before the G15

    Steps to set up the control ring before the G15 are difficult to follow in the guide.  Any help would be appreciated.

  • Prints perfectly but scan

    My Officejet J6480 prints perfectly, but everything is digitized out black withvariable width and color lines.  I cleaned the glass and it made no difference.  Help