Need help setting up VPN

I'm tring to define you Site IPSEC to a VPN of Site connection a md seem to run into problems. Can someone look over my setup and lead me in the right direction:

#sh ROUTER1 card crypto
'TOWIFE' 1-isakmp ipsec crypto map
Peer = 10.2.2.1
Expand the access list IP HusbandToWife
HusbandToWife 192.168.1.0 ip access list allow 0.0.0.255 192.168.3.0 0.0.0.255
Current counterpart: 10.2.2.1
Life safety association: 4608000 Kbytes / 3600 seconds
PFS (Y/N): N
Transform sets = {}
3DESHMAC,
}
Interfaces using crypto card TOWIFE:
FastEthernet0/0

ROUTER1 #sh running-config
Building configuration...

Current configuration: 1027 bytes
!
version 12.4
horodateurs service debug datetime msec
Log service timestamps datetime msec
no password encryption service
!
ROUTER1 hostname
!
boot-start-marker
boot-end-marker
!
!
No aaa new-model
memory iomem size 5
IP cef
!
!
!
!
!
Authenticated MultiLink bundle-name Panel
!
!
!
!
!
Archives
The config log
hidekeys
!
!
crypto ISAKMP policy 1
preshared authentication
address of spike key crypto isakmp 10.2.2.1
!
!
Crypto ipsec transform-set esp-3des esp-sha-hmac 3DESHMAC
!
TOWIFE 1 ipsec-isakmp crypto map
defined peer 10.2.2.1
Set transform-set 3DESHMAC
match address HusbandToWife
!
!
!
!
!
!
interface FastEthernet0/0
10.1.1.1 IP address 255.255.255.0
automatic duplex
automatic speed
card crypto TOWIFE
!
interface FastEthernet0/1
IP 192.168.1.1 255.255.255.0
automatic duplex
automatic speed
!
IP forward-Protocol ND
!
!
IP http server
no ip http secure server
!
HusbandToWife extended IP access list
ip permit 192.168.1.0 0.0.0.255 192.168.3.0 0.0.0.255
!
!
!
!
!
control plan
!
!
Line con 0
line to 0
line vty 0 4
!
!
end

Router3 #sh card crypto
'TOHUSBAND' 1-isakmp ipsec crypto map
Peer = 10.1.1.1
Expand the access list IP WifeToHusband
WifeToHusband 192.168.3.0 ip access list allow 0.0.0.255 192.168.1.0 0.0.0.255
Current counterpart: 10.1.1.1
Life safety association: 4608000 Kbytes / 3600 seconds
PFS (Y/N): N
Transform sets = {}
3DESHMAC,
}
Interfaces using crypto card TOHUSBAND:
FastEthernet0/0

Router3 #sh running-config
Building configuration...

Current configuration: 1033 bytes
!
version 12.4
horodateurs service debug datetime msec
Log service timestamps datetime msec
no password encryption service
!
name of host Router3
!
boot-start-marker
boot-end-marker
!
!
No aaa new-model
memory iomem size 5
IP cef
!
!
!
!
!
Authenticated MultiLink bundle-name Panel
!
!
!
!
!
Archives
The config log
hidekeys
!
!
crypto ISAKMP policy 1
preshared authentication
spike key crypto isakmp 10.1.1.1 address
!
!
Crypto ipsec transform-set esp-3des esp-sha-hmac 3DESHMAC
!
TOHUSBAND 1 ipsec-isakmp crypto map
defined peer 10.1.1.1
Set transform-set 3DESHMAC
match address WifeToHusband
!
!
!
!
!
!
interface FastEthernet0/0
address 192.168.3.1 IP 255.255.255.0
automatic duplex
automatic speed
card crypto TOHUSBAND
!
interface FastEthernet0/1
10.2.2.1 IP address 255.255.255.0
automatic duplex
automatic speed
!
IP forward-Protocol ND
!
!
IP http server
no ip http secure server
!
WifeToHusband extended IP access list
ip licensing 192.168.3.0 0.0.0.255 192.168.1.0 0.0.0.255
!
!
!
!
!
control plan
!
!
Line con 0
line to 0
line vty 0 4
!
!
end

Please provide us with 'see the crypto isakmp peer', ' show crypto ipsec his ' and 'show ip access-list' output of these two routers site2site. Y at - it all matches in ACL? Can you ping peers of each other?

---

HTH. Please rate this post if this has been helpful. If it solves your problem, please mark this message as "right answer".

Tags: Cisco Security

Similar Questions

  • Need help setting up related content in HCM 9.1 PeopleTools 8.51

    I need help setting up related content in HCM 9.1 PeopleTools 8.51.
    I created a new service id in 'Set Related Content Service'. Its simple, it basically goes to google.com.
    Then I assigned Related Content for the Application Pages on the page «Manage the Configuration content to related» I'm my scenario, I've added it to the careers under the main menu.
    Then I went to the careers page, but the 'related information' link does not appear. How can I get this link to related information to appear at the top of the page/component?

    Thank you
    -Cory

    In order to get it work, there are a few basic server configuration requirements that you need in order to make it work.

    (1) define the field of authentication on the Web server
    (2) set the authentication of domain on the web profile
    (3) enable Single Sign-On

    The next in "My Oracle Support" document provides details on configuring content services.

    E-PORTAL: how to set up content related services. [984855.1 ID]

    In addition, here is a link to the PeopleBooks online that deals with the configuration of related content services.

    http://download.Oracle.com/docs/CD/E18083_01/pt851pbr0/Eng/psbooks/tprt/book.htm?file=tprt/htm/tprt20.htm#H3002

    In addition, there are also some know the limitations to the use of related content are different depending on the version of the tools you use.

    I hope this helps.

  • Need help setting bios to boot from the cd. I did already but the laptop does not start again for cd player.

    Hello

    I forgot that my administration windows log password after the holidays.  I have loaded down a free program called Ophcrack and had set my laptop to boot from cd 1 but I just cannot get the laptop to boot from a cd.  He just continued boot from the internal hard disk.

    The cd is an image and it is bootable on my desk.

    The model of laptop: laptop HP ENVY m6

    Product number: C2N77UA #ABL

    BIOS version: F.25

    Processor type: Intel Core i7-3632QM CPU @ 2.20 GHz

    OS: Windows 8.1

    I only did a password reset disk (I'm learning the hard way now!).

    I don't want to do a "System Recovery" because I have some data on it.

    I realize there are paid there password recovery tools windows, but I would like to use this 'free' program to try to break 1.

    I just need help / instructions to set the bios for laptop can be started from a cd.  I also tried to boot from a key USB but the laptop kept begin its internal drive.

    Help, please.  Thanks a ton!

    Ted

    Hi Ted,

    You are welcome

    Boot into the bios menu and go to the very section where you have disabled the Secure Boot.

    Find an entry called materials and this value to Activate.

    Save the changes and exit the bios.

    Follow the previous procedure below:

    Insert the bootable disc of Ophcrack and laptop stop.

    Tap away at the esc you key start Notepad to open the Start Menu.  Select boot options ( f9 ), use the arrow keys to select the CD/DVD drive and press ENTER.  You can also get a prompt to "Press any key to" continuous - it if requested.

    Kind regards

    DP - K

  • I need help setting up my home network - windows vista.

    I need help to configure my network, I ave a laptop & hubby the computer w / dsl wireless rouuter. If I can get trhis to work, maybe we can work on the printer.

    Original title: help w / home network

    Hi Luvy,

    Thanks for posting your query in the Microsoft Community Forums!

    Looks like you need information to set up home networking on the windows vista computer.

    We're here to help and guide you in the right direction.

    -What is the number of brand and model of the computer?

    I suggest you to return the items online help and check if it helps.

    Setting up a network home

    http://Windows.Microsoft.com/en-in/Windows-Vista/setting-up-a-home-network

    Setting up a wireless network

    http://Windows.Microsoft.com/en-in/Windows-Vista/setting-up-a-wireless-network

    To install the printer on the network see Help below articles.

    Install a printer on a home network

    http://Windows.Microsoft.com/en-in/Windows-Vista/install-a-printer-on-a-home-network

     

    Share a printer

    http://Windows.Microsoft.com/en-in/Windows-Vista/share-a-printer

    It will be useful.

    Let us know if you encounter problems under windows in the future. We will be happy to help you.

  • need help setting up mocrosoft send my friend uses netgear wireless rural upstate ny need help for incoming, outgoing server POP3 etc info...

    try to set up my microsoft email in my pc. I need to respond to the need help sbout incomeing craiglist.i and out going.

    I have no idea to find my server address. I use connect netgear wireless.

    Hello

    Looks like you need configure Windows Mail

    you need to configure your e-mail account windows mail with your ISP internet service provider

    They provide you with account settings you need to do

    Ask them to

    username
    password for your access broadband account / distance with them

    Server of incoming POP3 mail
    outgoing mail SMTP server

    and here's how to configure windows mail after getting the email correct account settings

    http://www.vista4beginners.com/Windows-Mail

  • BlackBerry Smartphones Newbie needs help setting up email

    Hello world

    I've been the proud owner of a "BOLD" for about 48 hours now. This is my first Blackberry, so please bear with me.

    I need to set up my Yahoo email. I remember setting up front, but I deleted it as my allowance for the use of network (3 Australia) showed 2 MB roaming allowance, of which half was used in one day.

    I think that the e-mail message has been implemented via a browser page, but I can't go back to this page. The e-mail setup wizard seems to be to the establishment through BES which I did not. Does anyone know the address of the page?

    I also remember, when I chose the browser (not of Planet 3) I was taken in a BB page that showed several options of setting up various things. There were about 5 or 6 boxes grey listed above the other? Anyone also know the address of the page for this?

    Thanks for any help,

    Paul

    You also see a personal Email Setup on the device icon? If not try going into the Options | Advanced options | The host routing table. In this screen press press the button menu and choose to register now. See if you receive a message from check delivered to your device. Subsequently, reset the unit by removing the battery for 30 seconds. See if you have this icon now after restarting the device. If you still don't you can try setting up the account again on your carrier's Web site BIS to add return e-mail accounts?

    What options do you remember on this Web site? Try to go to mobile.blackberry.com on your browser and see if it's the page.

  • Need help with Config VPN on ASA5505

    Our client has a seller who needs to establish a VPN tunnel to their own router that sits behind our firewall.

    Concentrator VPN (seller) ASA5505 customer (7.2) <------> <------->3750 Switch <------->VPN router (Vendor)

    Here is the implementation of information:

    ASA outside Interface - 208.64.1x.x4 DG - 208.64.1x.x3

    ASA inside the Interface - 172.20.58.13/30

    3750 switch Interface connected to ASA - DG - 172.20.58.13 and 172.20.58.14/30

    3750 switch Interface connected to router VPN - 172.20.58.21

    The Interface of the VPN router connected to the 3750 - 172.20.58.22/30 DG - 172.20.58.21

    I have also attached a Visio for that and the current configuration of execution of ASA and 3750. We have no access to the router VPN TNS.

    Our responsibility is to everything just to make sure that the tunnel rises.

    You kindly help me with this?

    Here is what I intend to do:

    (1) create a static NAT on the ASA Public Private IP Address of the VPN router

    Public - 208.64.1x.x5 / 28

    Private - 172.20.58.21 / 30

    Will be the ASA automatically ARP for this address or do we I have to configure another interface on the ASA with this public IP address?

    (2) what would the access on the ASA list?

    (3) the customer gave us some config to copy the stuff on the SAA so that they can create the tunnel but I couldn't put these commands in the SAA. How this would apply and which interface?

    Access to firewall: the information below is about access between the VPN router and the

    VPN concentrator. If a firewall/router is present in front of the VPN services must be

    permit:

    allow a host 208.224.x.x esp

    allow a host 208.224.x.x gre

    permit any isakmp udp host 208.224.x.x eq

    permit any eq non500-isakmp udp host 208.224.x.x

    allow a host 204.8.x.x esp

    allow a host 204.8.x.x gre

    permit any isakmp udp host 204.8.x.x eq

    permit any eq non500-isakmp udp host 204.8.x.x

    permit tcp 206.x.x.0 0.0.0.255 any eq 22

    permit tcp 206.x.x.0 0.0.0.255 any eq telnet

    allow a udp host 208.224.x.x

    allow a udp host 208.224.x.x

    Can someone help me with the commands I need to run it on the ASA? The 5505 running 7.2 code (4).

    Thanks in advance.

    HS

    Your steps are correct, you need to configure static NAT and the list of access to allow access.

    Static NAT would be as follows:

    static (inside, outside) 208.64.1x.x5 172.20.58.21 netmask 255.255.255.255

    You also need a road inside interface-oriented join 172.20.58.21:

    Route inside 172.20.58.21 255.255.255.255 172.20.58.14

    You have already access list on the external interface? If you have, then just add in the existing access list, if you don't have it, and then add the following:

    access list outside-acl permit udp any host 208.64.1x.x5 eq 500

    access list outside-acl permit udp any host 208.64.1x.x5 eq 4500

    access list outside-acl allow esp any host 208.64.1x.x5

    Access-group acl outside in external interface

    If you also have an inside interface access list, you must also allow passing traffic by as follows:

    access-list allow host 172.20.58.21 udp any eq 500

    access-list allow host 172.20.58.21 udp any eq 4500

    access-list allow host esp 172.20.58.21 all

    If you have not had any access inside the interface list, then you don't need to configure it.

    Hope that helps.

  • I have a new backup disk (a disk of 5 TB of Seagate) and need help setting up with CCC!

    Hello world

    I have a new backup disk (a disk of 5 TB of Seagate) and could use help setting up with CCC.

    I did in the past without problem, but I want to assure you of a few things:

      1. This particular drive has software available in a folder on the disk backup (w / the PC and Mac versions). But... I intend to use this disk as an exact copy of my iMac HD; It must also be bootable.
      2. Should I format the drive with disk utility? Or load the software to the CCC on the disk and just leave their only backup software?
      3. One last question: I also have a MacBook Air, an iPad and an iPhone. I want to save them as well. Should I put them on separate partitions, I created? Or can we just one big happy family? The last is best.

    One last piece of information: two computers, etc, were all backed up via Time Machine. My data the most important, photos, etc., are also saved on deposit box and/or iCloud on a regular basis.

    Thanks for any suggestions or comments!

    Sally D.

    Delete and partition the drive by making a separate partition for each computer. The iPad and the iPhone is useless their own partition because they back up using iTunes and would appear in the clone of the computer that you use for each save. Each partition must be the size of the current cloned drive that can leave you with additional partitions for other stuff. Then format the drive Mac OS Extended journaled. Do not install any software that came with the drive, none of this is necessary.

    I use a very similar setup with a 3 TB drive. I clone my boot SSD in a single partition, my drive internal 1 Tb in a second, my Macbook to a third party, and I have a fourth partition which is currently empty, because I haven't decided what to do with it yet. I also have a 3 to Apple Time Capsule.

  • Need help on ASA5505 VPN configuration

    Hello

    For the life of me I can't get this to work. I know it is something simple, yet I've not thought about it.

    My father-n-law lives in China and they block a lot of sites in the United States. I have my set VPN in place in the United States for remote access, but to get there from China it still cannot connect to the United States sites. Can someone help me if I can get this working properly?

    Thanks in advance!

    EricO

    Great, thank you.

    Here's what you need to add:

    permit same-security-traffic intra-interface

    China-VPN network object

    255.255.255.0 subnet 192.168.100.0

    dynamic NAT interface (outdoors, outdoor)

    group attributes political kikou

    Split-tunnel-policy tunnelall

    no value in split-tunnel-network-list KaileY_splitTunnelAcl

  • need help setting up a network for a game

    We tried to use a router and its not working! do I need anything else?

    Hello CrimsonZombie,

    Thank you for posting.  It seems that you are having some type of evil, but you left a little certain information.
    To help you, I would need to know a few things:

    1. what version of Vista (32-bit or 64-bit)

    2. what game you're trying to read

    3. are you a homepage of the network or need assistance to set up a home network

    Please let me know these things, so that I can be a help to you more. Zack
    Engineer Microsoft Support answers visit our Microsoft answers feedback Forum and let us know what you think.

  • Need help setting up a configuration of VLAN special using WRVS4400N

    Hi guys,.

     

    I need your help on how to implement a configuration of VLAN somehow non-standard.

    The situation is the following:

    The customer wants a WLAN set up for the company and the other for guests. Now, wouldn't that be not so difficult if we'd be using the internal internet connection. But the WRVS4400N will be used to implement wireless LANs / VLAN only.

    The company uses the DHCP protocol on both of their subnets, provided by a Watchguard Firebox XTM510.

    Now, what we would do is set up the back door #1 for the connection to the subnet of the client and the #2 for the connection to the optional subnet for the guests. The first problem is that we were not able to configure DHCP forwards to the VLAN2. It works very well on the 1st but the 2nd doesn't allow that either ENabled or disabled, grayed out DHCP.

    To work around the problem that he would be allowed to set up DHCP WRVS4400N providing in itself for the subnet invited, but try that didn't work at all.

    Is it possible? Thanks in advance!

    Best,

    Ralph.


  • Need help setting up a network home wireless to the working group. I tried everything I read and nothing has worked. I got lost.

    I just received a more recent laptop and wants to set up a network so I can transfer files back.  It seems that it would be a fairly simple network to set up, but obviously I'm missing something.

    It must be a wireless network.  I have a wireless router, two Toshiba laptops, running a Windows 7 and the other runs Windows 10, and I have a printer.  I can access internet with laptops or both if the router does not seem to be the issue.

    I read articles that said I had need of a homegroup, but that did not work.  Then I read an article saying since my computers running different operating systems, that I couldn't use a homegroup that I should use a workgroup.  I followed the instructions given in the article and which don't seem to work either.

    The names of working group on both computers are the same and so are the passwords.  The computer names are different.

    I was on the old computer and when I go into Windows Explorer, under network, I can see the two names listed, however, when I click on the other computer, I get a message saying that the computer is not on the network.  I got the internet service at the time so the router was working.  Another time I tried to copy a small file to the other computer and the message said I didn't have permissions to do so.  I got the same message when I tried to add a folder to the other computer in the network area in Windows Explorer.  I get the same types of messages when I try things peers, while on the new computer.

    Any suggestions would be greatly appreciated.  So far, since I got the new laptop, I spent nearly three weeks, trying to get things to work.  This seems to be the biggest challenge of all.

    Hi Carole,

    Thanks for posting your query in Microsoft Community.

    Let me suggest you refer to the article below which will help you to set up HomeGroup from start to finish.

    Homegroup from start to finish

    Hope this information is useful. Please feel free to answer in the case where you are facing in the future other problems with Windows.

  • Need help setting up network home (Windows 7 Professional)

    I don't know why I have so much trouble with this.  I think that I never properly put in place a network before.  Usually, I just turn on my router with a password, and then the phone and other devices connect directly to the router.  I just got a new computer with Windows 7 Professional and it is prompting me to create a home network - and have apparently created a new password for the 'network' that is different from the password for the router.  I have a feeling that this will be easy, but I do not get set up correctly.

    First question, in the instructions to configure the network at a time given, was asked if all "clients" had a "wifi protected setup" button

    What is a 'client' on the network?  My router Linksys has one of these buttons (I pushed him, but he could not get connect/setting up with Windows 7).  Is a router from a client?  If so, a client what?  (I do not understand the use of the term client.)

    Here's what I would do.  I have internet entering a cable modem.  Ethernet to the modem router Linksys WRT54G.  (I don't remember the exact model.  It has a button "wifi protection setup.  Ethernet to the router to the desktop.  The router's Ethernet compatible HP printer wifi (which is currently on its own network).  The Windows account has two users (mine, of my wife).  The goal is to have a single network, with the office and the connected printer, and who I can connect with my iPhone.  And I want to be able to print wireless from my iPhone to the printer.

    Here's what I did.  There is a lot of information, but if all goes well it will prevent additional questions.

    I have reset the router and went to the 192.168.1.1. page.  In the Administration tab, I created a new password - which I thought was the password for the network.  I was not the case.  In the wifi tab, I looked for a place to put a password, but could not find one.

    I went on the computer, the network options in Control Panel to add a new network.  I was able to get a new network with the computer (LAN) connected to the router, but I couldn't get wifi to set up.  He told me to press the setting button of protection wifi on the router, but after a long delay, he said that he could not establish a connection.  Finally, I got a message (I don't know how) if I wanted to connect older devices to the network, I need to put a code - 12 letters/numbers with dashes.  I don't know what types of devices called it.  So, I found in managing network a "network key" tab  It was the same code - and it also seemed to work as wifi password.  But I can't change it to something that is possible to remember.

    And I can't do the printer on the same network as the computer.

    I guess I'm going something wrong.  Can someone point me in the right direction?

    It seems that if the printer is in 'ad hoc wireless' mode - it is just sitting there with his wi - fi enabled: indeed, 'here I am; connect to me if you want to print. »

    You need to connect the printer to the network wireless router.  It's pretty easy, but if you want a specific rather than general instructions, please provide the exact model of your HP printer.

    Generically, see--> http://www8.hp.com/us/en/campaigns/wireless-printing-center/printer-setup-help.html , you will probably end by using the option of 3rd or 4th.  In step 4 of the "HP Wireless Assistant', 'the WEP key or a WPA password' is the 'wifi password on the router" - which really, you must configure except if the House really is miles from any other civilization.

    "Referring to the first paragraph above, what I called the mode"ad hoc"seems to be what HP calls impression of"peer-to-peer"."  More specifically, in the FAQ at this link, your printer seems to currently be configured as described in "how to print wireless without a wireless router?

    Although he adds a little more complexity, I highly recommend that - after that you get things market - you read the FAQ section of HP on "a static IP will keep my computer against the loss of communication with my printer wireless."  In an environment with multiple wi - fi devices (for example, several iPhones), if the printer is turned off for a while, when you turn it back on it you will find that your computer will display is no longer her.  Print jobs will appear to work, but nothing will print.  If this situation arises, the solution is this FAQ section.

  • Need help setting up switch SG300-10

    Hello

    I bought a SG300-10 switch and configuration.

    I have a problem to set up it causes that I'm not really used to networking.

    what I set up at the moment is the VLAN.

    VLAN 2 - step my router it for internet access

    Vlan10 - is for my server and pc in my office

    VLAN 40 - is for the wifi of comments.

    I will use the mode switch layer 3 and I want to configure a DHCP server on the vlan 40 but I'm not very well how to do.  I activated the DHCP and created a pool of ip but how I assign on the vlan 40? and how to set up everything to go on the internet? If I followed the basic logic, I will put all my members of port of vlan 2, is that correct?

    IM new in the field of networking

    Thank you

    Hi Justin,

    Here is some basic information for the switch. With VLAN, it is tag VLAN and remove the brand VLAN. A package of UNTAG means in the package header, there is no VLAN ID. The switch will provide separate from the client connection based on the transfer of bridge table. Usually UNTAG VLAN is used for the client connection. A beacon packet contains the VLAN ID in the header. In general, tag packets is used between other network device. An access port is member of 1 VLAN that is not marked. A trunk (on small business product) port is a port that has 1 UNTAG VLAN (VLAN native) and has the ability to tag the VLAN extra.

    Some examples of configuration CLI for tag and remove the brand VLAN. Keep in mind, VLAN 1 is the default VLAN, therefore, unless you make sure, VLAN 1 will default.

    To create a VLAN 2 on your switch

    Configure the terminal

    database of VLAN

    VLAN 2,3,4

    This will create the VLANs 2, 3 and 4

    To configure an IP address to a VLAN

    Configure the terminal

    interface vlan 1

    IP 192.168.1.254 255.255.255.0

    interface vlan 2

    192.168.2.254 255.255.255.0

    interface vlan 3

    192.168.3.254 IP address 255.255.255.0

    interface vlan 4

    IP 192.168.4.254 255.255.255.0

    Keep in mind, VLAN 1 must have a static IP address before you assign any other VLAN an IP address, or the switch will "lock".

    To assign an access as a member of the VLAN 1 port

    Configure the terminal

    Article IG1 interface

    switchport mode access

    To assign an access as a member of VLAN 2 port

    Configure the terminal

    interface hi2

    switchport mode access

    switchport access vlan 2

    If you check the GUI you'll notice port 1 is "1u" and port 2 is "2u".

    To create a trunk and assign some VLAN-

    Configure the terminal

    interface IG3

    switchport mode trunk

    switchport trunk allowed vlan add 2

    In the GUI, you will notice 3 port will be "1u, 2 t".

    To configure a port to have a VLAN different other that 1 as it removes the brand on a chest.

    Configure the terminal

    interface IG4

    switchport mode trunk

    switchport vlan trunk native 2

    switchport trunk allowed vlan add 3.4

    On the GUI, it will show '2u, 3 t, 4 t'

    Now that we have fundamental port assignment of the road, you can work on DHCP and IP address management.

    When the switch is in mode layer 3, if there is an IP address assigned to a VLAN, it is a switch virtual interface (SVI). The IP address of the service VLAN as default gateway which connects to this VLAN. The switch can associate the pool DHCP IP interface created on the switch-based layer 3.

    Firstly, we must establish your first jump of the switch - the default gateway of the switch statement. If you have a router connected to the SG300 you must assign the SG300 default gateway, which is the IP address of the router.

    Configure the terminal

    Default IP gateway 192.168.1.1

    Then you can concentrate on your DHCP scope. To configure a server DHCP table here is an example-

    network IP dhcp pool PRODUCTION

    address 192.168.2.1 low high 192.168.2.253 255.255.255.0

    Infinite rental

    default router 192.168.2.254

    dns-Server 8.8.8.8

    This basic table DHCP said many things.

    The name of the table is the PRODUCTION, this can be anything you want.

    low address is the first IP address that is assignable in the pool while high address is the last

    infinite lease means that had not expired DHCP lease

    Router by default, it is the most important. It is the default gateway, that the switch will be assigned to the customer. This is very important if you want router between VLAN or upstream of the internet

    DNS server, this allows to resolve the name instead of having to use IP only.

    Now, if you connect to a computer that is enable DHCP where VLAN 2 is not marked, you should receive an IP address that is assigned by the switch on this computer. Notice that the pool is a number of address IP 2 VLAN. The definition of IP pool, this is how it will bind to one VLAN, by matching the subnet.

    Now, once you have all the basic configuration complete, as Marty says, depending on the capacity of your router, it will need to need to support VLAN tagging, interface sub dot1q OR, as Marty has said, it would need static route to allow to your additional subnet route on the internet.

    Hope this will help you get on your way.

    -Tom
    Please mark replied messages useful

  • need help for the VPN connection

    Hi guys

    can you help with that?

    I installed a VPN connection, but the tunnel shows that status: upward and the protocol description: down.

    debugging is turned on and displays following-

    ITS has applications pending (xx.xx.xx.xx local port 500, xx.xx.xx.xx remote port 500)

    DEC 20 02:39:26.762: ISAKMP: (2142): sitting IDLE. From QM immediately (QM_IDLE)

    02:39:26.762 20 Dec: ISAKMP: (2142): start Quick Mode Exchange, M - ID 3357871564

    02:39:26.762 20 Dec: ISAKMP: (2142): initiator QM gets spi

    DEC 20 02:39:26.762: ISAKMP: (2142): Pack xx.xx.xx.xx my_port 500 peer_port 500 (I) sending QM_IDLE

    02:39:26.762 20 Dec: ISAKMP: (2142): sending a packet IPv4 IKE.

    02:39:26.762 20 Dec: ISAKMP: (2142): entrance, node 3357871564 = IKE_MESG_INTERNAL, IKE_INIT_QM

    02:39:26.762 20 Dec: ISAKMP: (2142): former State = new State IKE_QM_READY = IKE_QM_I_QM1

    02:39:26.794 20 Dec: ISAKMP (2142): packet received from xx.xx.xx.xx dport 500 sport Global 500 (I) QM_IDLE

    02:39:26.794 20 Dec: ISAKMP: node set-419503660 to QM_IDLE

    DEC 20 02:39:26.794: ISAKMP: (2142): HASH payload processing. Message ID = 3875463636

    DEC 20 02:39:26.794: ISAKMP: (2142): treatment protocol NOTIFIER PROPOSAL_NOT_CHOSEN 3

    SPI 2561284360, message ID = 3875463636, a = 0x87D0CFC8

    DEC 20 02:39:26.794: ISAKMP: (2142): removal of spi 2561284360 message ID = 3357871564

    02:39:26.794 20 Dec: ISAKMP: (2142): node-937095732 error suppression REAL reason "remove larval.

    02:39:26.794 20 Dec: ISAKMP: (2142): node-419503660 error suppression FALSE reason 'informational (en) State 1.

    02:39:26.794 20 Dec: ISAKMP: (2142): entry = IKE_MESG_FROM_PEER, IKE_INFO_NOTIFY

    02:39:26.794 20 Dec: ISAKMP: (2142): former State = new State IKE_P1_COMPLETE = IKE_P1_COMPLETE

    02:39:46.798 20 Dec: ISAKMP: (2142): purge the node-1177810765

    02:39:46.798 20 Dec: ISAKMP: (2142): purge the node-138734109

    02:39:56.763 20 Dec: % s-6-IPACCESSLOGRL: the rate limited or missed 2 sachets of access list record

    DEC 20 02:39:56.763: IPSEC (key_engine): request timer shot: count = 2,.

    local (identity) = xx.xx.xx.xx:0, distance = xx.xx.xx.xx:0,

    local_proxy = 0.0.0.0/0.0.0.0/0/0 (type = 4),

    remote_proxy = 0.0.0.0/0.0.0.0/0/0 (type = 4)

    the config is following.

    crypto ISAKMP policy 10

    BA 3des

    preshared authentication

    Group 2

    ISAKMP crypto key xxxxxx address xx.xx.xx.xx

    !

    !

    Crypto ipsec transform-set esp-3des esp-sha-hmac vpnset

    transport mode

    !

    Crypto ipsec tech profile

    Set transform-set vpnset

    !

    !

    my-map 20 ipsec-isakmp crypto map

    defined peer xx.xx.xx.xx

    Set transform-set vpnset

    match address 155

    Hello

    As for your question, you can have more than 1 card crypto on the interface.

    However, you can use the same card encryption for several strategies. You can change the ma-card to vpnmap.
    In this way the two are enabled on the same interface, with one having a higher priority than the other.

    So if a package came from inside, the first crypto ACL interface is checked and then the next and so on. The first match found is chosen for the IPsec negotioation.

Maybe you are looking for

  • How to add boxes to the extra letters?

    I've looked and can't find where to do. Thank you.

  • Cannot download apps on iPhone 5 s

    My apps maintains blocked and unable to download new applications on my iphone (iOS 9.3.2) 5s Also, the phone is extremely slow. I have storage space available and I have reset the settings without a bit of luck. Any advice how to solve this problem

  • Why the firefox browser displays information that are not normal

    When I use all first ff in the am, everything seems OK. However in early afternoon that the screen does not display the information in the same format, it seems odd with info as it is supposed to be. It's a bit difficult to explain exactly what happe

  • Mini chat window group

    When I take a video conversation with another person, I have a spreadsheet as my main screen (the topic of conversation) and their video image minimized in the corner of my screen. When I try to make a conversation group with 2 people or more the wid

  • Just bought it does not have Media only to convert PC recognizes but doesn't show any info

    OK, so I bought this for my husband for Christmas. I was going to download a lot of music and pictures and stuff before I sent it him. Well, I'm very disappointed. When I plugged it the first time it my computer has detected it and when I click to op