Problem setting default route

I have a SG300-20 configured with 4 VLANS, 1, 10, 20, 30. It is configured to the L3.  I use this for my lab to the home network.  VLAN 1 is connected to my cable modem and gets it's IP address and the gateway via DHCP.  I have a host on VLAN 20 and VLAN 10.  I can ping from one host to another host very well.  I can ping the switch for the hosts and the switch to cable modem and internet.  I can't ping a host on the cable modem or the internet.

Here is the relevant switch (hidden IPs) config:

#sh int ip

IP address I / F Type achieved priority status

Broadcast

------------------- --------- ----------- ---------- ---------- -----------

76.xxx.xxx.XX/20 vlan 1 disable invalid DHCP

192.168.10.1/24 vlan 10 static disable invalid

192.168.20.1/24 vlan 20 static disable invalid

192.168.30.1/24 vlan 30 static disable invalid

#sh ip route

Maximum parallel paths: 1 (1 after reset)

IP routing: enabled

Codes: > - best, C - connected, S - static

S 0.0.0.0/0 [1/2] via 76.xxx.xx.x, 21:43:15, vlan 1

C 76.xxx.XX.0/20 is directly connected, vlan 1

C 192.168.10.0/24 is directly connected, vlan 10

192.168.20.0/24 C is directly connected, vlan 20

C 192.168.30.0/24 is directly connected, vlan 30

It would appear that the switch routes between all the VLAN except VLAN 1.   Any ideas what I'm missing here?

Hi Brandon, I think the problem is that you expect from NAT to work. It feels like for me the VLAN 1 has the internet connection and you try to put the other 3 virtual local networks on the internet.

In theory, you are right on but it does not work without NAT. The switch is not as compatible NAT.

-Tom
Please mark replied messages useful

Tags: Cisco Support

Similar Questions

  • Problem setting 7606 router for authentication GANYMEDE +.

    Hello community support.

    I have two routers Cisco 7606 I tried in vain to have users authenticated using servers GANYMEDE +. As noted below, I have two servers (1.1.1.1 and 2.2.2.2) accessible via vrf OAM which is accessible from desktop to ssh login. The real IPS and FFS have been changed because it's a router of the company.

    I use two servers to authenticate on a lot other devices Cisco network that they work properly.

    I can reach the vrf servers and the source in use interface. I can also port telnet 49 if the source interface servers and the vrf.

    The server key is hidden, but at the time of configuration, I can see that it is correct.

    The problem is that after confuring for authentication RADIUS, the router always uses the password to enable instead of GANYMEDE. While debug output shows "incorrect password", why not the router authenticates using GANYMEDE? Why is he using the enable password?

    Please review the outputs below and help point out what I may need to change.

    PS: I have tried many other combinations, including obsolete without success, including the method proposed in this page.

    http://www.Cisco.com/en/us/docs/iOS/sec_user_services/configuration/guide/sec_vrf_tacas_svrs.html

    Please help I'm stuck.

    ROUTER #sh running-config | s aaa

    AAA new-model

    AAA server Ganymede group + admin

    Server name admin

    Server name admin1

    IP vrf forwarding OAM

    Ganymede IP interface-source GigabitEthernet1

    AAA authentication login admin group Ganymede + local activate

    AAA - the id of the joint session

    ROUTER #sh running-config | dry Ganymede

    AAA server Ganymede group + admin

    Server name admin

    Server name admin1

    IP vrf forwarding OAM

    Ganymede IP interface-source GigabitEthernet1

    AAA authentication login admin group Ganymede + local activate

    GANYMEDE Server Admin

    1.1.1.1 ipv4 address

    button 7 XXXXXXXXXXXXXXXXXXXX

    GANYMEDE Server admin1

    2.2.2.2 ipv4 address

    button 7 XXXXXXXXXXXXXXXXxxxx

    line vty 0 4

    authentication admin login

    ROUTER #sh Ganymede

    GANYMEDE + - public server:

    Server name: admin

    Server address: 1.1.1.1

    Server port: 49

    Opening of socket: 15

    Firm grip: 15

    Write-offs of socket: 0

    Socket errors: 0

    Socket timeouts: 0

    Failed connection attempts: 0

    Total packets sent: 0

    Recv packets total: 0

    GANYMEDE + - public server:

    Server name: admin1

    Server address: 2.2.2.2

    Server port: 49

    Opening of socket: 15

    Firm grip: 15

    Write-offs of socket: 0

    Socket errors: 0

    Socket timeouts: 0

    Failed connection attempts: 0

    Total packets sent: 0

    Recv packets total: 0

    Oct 22 12:38:57.587: AAA/BIND(0000001A): link i / f

    22 Oct 12:38:57.587: AAA/AUTHENTIC/LOGIN (0000001 a): Select method list "admin".

    Oct 22 12:38:57.587: AAA/AUTHENTIC/ENABLE(0000001A): action of treatment application LOGIN

    Oct 22 12:38:57.587: AAA/AUTHENTIC/ENABLE(0000001A): reported GET_PASSWORD

    Oct 22 12:39:02.327: AAA/AUTHENTIC/ENABLE(0000001A): action of treatment application LOGIN

    Oct 22 12:39:02.327: AAA/AUTHENTIC/ENABLE(0000001A): reported FAIL - wrong password

    22 Oct 12:39:04.335: AAA/AUTHENTIC/LOGIN (0000001 a): Select method list "admin".

    Oct 22 12:39:04.335: AAA/AUTHENTIC/ENABLE(0000001A): action of treatment application LOGIN

    Oct 22 12:39:04.335: AAA/AUTHENTIC/ENABLE(0000001A): reported GET_PASSWORD

    Oct 22 12:39:08.675: AAA/AUTHENTIC/ENABLE(0000001A): action of treatment application LOGIN

    Oct 22 12:39:08.675: AAA/AUTHENTIC/ENABLE(0000001A): reported FAIL - wrong password

    22 Oct 12:39:10.679: AAA/AUTHENTIC/LOGIN (0000001 a): Select method list "admin".

    Oct 22 12:39:10.683: AAA/AUTHENTIC/ENABLE(0000001A): action of treatment application LOGIN

    Oct 22 12:39:10.683: AAA/AUTHENTIC/ENABLE(0000001A): reported GET_PASSWORD

    Oct 22 12:39:14.907: AAA/AUTHENTIC/ENABLE(0000001A): action of treatment application LOGIN

    Oct 22 12:39:14.907: AAA/AUTHENTIC/ENABLE(0000001A): reported FAIL - wrong password

    ROUTER #sh worm

    Cisco IOS software, software of c7600rsp72043_rp (c7600rsp72043_rp-ADVIPSERVICESK9-M), Version 15.1 (3) S3, RELEASE SOFTWARE (fc1)

    Technical support: http://www.cisco.com/techsupport

    Copyright (c) 1986-2012 by Cisco Systems, Inc.

    Updated Saturday, March 30, 12 08:34 by prod_rel_team

    ROM: System Bootstrap, Version 12.2 SRE (33r), RELEASE SOFTWARE (fc1)

    BOOTLDR: Cisco IOS software, software c7600rsp72043_rp (c7600rsp72043_rp-ADVIPSERVICESK9-M), Version 15.1 (3) S3, RELEASE SOFTWARE (fc1)

    The availability of ROUTER is 7 weeks, 5 days, 16 hours, 48 minutes

    Availability for this control processor is 7 weeks, 5 days, 16 hours, 49 minutes

    System returned to ROM by reload (SP by charging)

    System restarted at 20:00:59 UTC Wednesday, August 28, 2013

    System image file is "sup - bootdisk:c7600rsp72043 - advipservicesk9 - mz.151 - 3.S3.bin.

    Last reload type: normal charging

    Reload last reason: power

    This product contains cryptographic features and is under the United States

    States and local laws governing the import, export, transfer and

    use. Delivery of Cisco cryptographic products does not imply

    third party approval to import, export, distribute or use encryption.

    Importers, exporters, distributors and users are responsible for

    compliance with U.S. laws and local countries. By using this product you

    agree to comply with the regulations and laws in force. If you are unable

    to satisfy the United States and local laws, return the product.

    A summary of U.S. laws governing Cisco cryptographic products to:

    http://www.Cisco.com/WWL/export/crypto/tool/stqrg.html

    If you need assistance please contact us by mail at

    [email protected] / * /.

    Processor CISCO7606 - S (M8500) Cisco (revision 1.1) with 3670016 K/K 262144 bytes of memory.

    Card processor ID FOX1623G61B

    PLINTH: RSP720

    CPU: MPC8548_E, Version: 2.1 (0 x 80390021)

    KERNEL: E500, Version: 2.2, (0 x 80210022)

    CPU:1200 MHz, CCB:400 MHz, DDR:200 MHz,

    L1: D-cache 32 KB active

    I'm hiding active 32 KB

    Last reset of tension

    3 virtual Ethernet interfaces

    76 of the gigabit Ethernet interfaces

    8 ten interfaces Ethernet Gigabit

    3964K bytes of non-volatile configuration memory.

    500472K bytes of the map of PCMCIA ATA internal (512 bytes sector size).

    Configuration register is 0 x 2102

    To resolve this problem. Please replace the below listed order

    AAA authentication login admin group Ganymede + local activate

    with;

    Enable AAA authentication login default local admin group

    You have set the group name server as a list of methods and instead use admin as a group of servers, you used Ganymede +.

    Note: Please ensure that you have local users and enable the password configured in the case of Ganymede inaccessible server.

    ~ BR
    Jatin kone

    * Does the rate of useful messages *.

  • Problems setting up router WRT1900ac and fiber

    I feel that my question is so obscure that I won't be able to get a lot of help here, but I'll post anyway.

    First of all, I live in the Philippines. My ISP is PLDT. I have FTTH - fiber to the home. My internet connection is DHCP - no login or password. I thought that perhaps they checked the serial number on the modem to see if I was an authorized user but apparently not; They told me if I wanted to buy another optical modem, I could and that I wouldn't need to do anything to save it on the network, but that they could not provide me with a list of modems that would work.

    They delivered to me with a router/modem made by a company called FiberHome. "Like the big business of high-tech directly affiliated to belonging to the active state of oversight and Board of Directors of the Council of State, FiberHome Technologies is the company of the kernel located in Wuhan Optics Valley of China."

    The model number is AN5506-04-FG. There are very few configurable on this. Can I change my wifi network name (they insist that the name of the network begins with PLDTHOMEFIBR, no idea why) and a few passwords here and there. For the most part, I just post status on the LAN and WAN.

    Therefore, because it is so little that I can do with it that I decided that I needed a router/gateway and not simply an Extender. I bought the WRT1900ac.

    Brought it home, that he repaired, it connected via ethernet cable between a LAN port on the FiberHome on the Internet on the Linksys port.  I then used the WiFi on my iPad to try on the Linksys Setup, try with Safari and Chrome.

    Went to put in place and smart control of Linksys could not understand my internet connection, despite several reboots, power off and cable disconnected, etc.

    So I went to the manual configuration. I put the connection to a static IP address. Following the minimal instructions in the booklet of FiberHome, I put the IP address of the router to 192.168.1.28; the subnet mask of 255.255.255.0; This gateway 192.168.1.1 (internal IP of the fiber to the home, address) DNS of Google DNS.

    This would actually work - but only for a few minutes at a time. Then the network diagram would show that I was always connected to the FiberHome but no connection to Internet in addition. (Although my PC, connected to the FiberHome via a LAN cable, still had access to the internet.)

    I used the live chat Linksys to ask an agent to this topic. She said that my gateway setting is correct. She had me reset the router and try again, but he could not yet know the connection to the internet on its own. She had me download the iOS app and try there, but same result. So I received a ticket number and ended the chat session.

    Now, I tried to set the internet connection on the router at the bridge. But once I did, I was unable to connect to the router via WiFi. I needed to do a reset to be able to access it again.

    At this point I called my ISP. They told me that if I wanted to add another router like that, they would need to reset my router/modem FiberHome bridged mode. But they are unable to do it remotely and cannot (or don't want to) give me instructions on how to do it myself.  They need to send a technician to my home. They could not tell me when. I have to wait for a call. (I got a ticket number).

    This means that for now, I have a blue and black, sitting bins there, I can't do anything with.

    So I'm waiting, I thought I'd post this in the hope that someone might have some ideas configuration I could try or for the general amusement of peoples.

    Thank you!

    You may have a conflict between the two routers in IP subnet. In this case the WRT1900AC will change it's default subnet to 10.x.x.x instead of 192.168.1.1

    You can find the new IP address of the router by looking at a customers connect ITI information IP address appears as the default gateway.

  • By default static route with recevied BGP default route

    Hi guys;

    I have a problem and I don't know how to find or solve it.

    My chart is attached, please check everything first.

    Secondly, I have a multihomed BGP with two Internet service providers, I received two ISPS via BGP default route.

    Now, I have two types of IP addresses as follows:

    1 - my own prifixes, who has recorded with my ACE

    2 - iPs purchased ISP2.

    I have two networks, the first will contain my own prefixes and second will contain my prifixes ISP2. so I have to go on the internet, static route by default to the ISP2 need and that's fine, now the problem that carry the second defect I received two ISPS in routing however my table if I show ip bgp I see that I received it, but because of favorite and distancing China he disappear the default road statistics.

    so now a network is already online and the second network that contain my own IPs is out of service, of course this second network I need to routed to my isps1 via bgp and when isps1 down, go through ISP2 and I do using weight and as path prefix.

    Thank you

    Hi Nathan,

    With ACB option, you config-route map is your own prefix and set its next hop ISP 1 and 2 PSI when ISP 1 IP is not accessible. Apply the road map to interface with Network1. ACB is processed before routing.

    With option VRF, put the Network1 interface and isps1 VRF1, so it will have separate routing table. Under the vrf1 you static default config with higher AD and the next hop pointing to ISP2 in the global routing table. This will be used when you lose by default isps1. Because separate ridges VRF table routing, so netwoek1 will use the default route in vrf1 to isps1 as primary, the Network2 use ISP2.

    HTH,
    Lei Tian

    Sent by Cisco Support technique iPhone App

  • Problem setting up VPN

    MY problem is that when the vpn is configured, and I try to run a tracert to one of my remote PC across the VPN, the VPN router sends information from the internet and do not attempt to open the tunnel. what I am doing wrong?

    I use a cisco router 1700 and connect to a vpn concentrator 3030 Cisco

    Current configuration: 1522 bytes

    !

    version 12.3

    horodateurs service debug datetime msec

    Log service timestamps datetime msec

    encryption password service

    !

    router host name

    !

    boot-start-marker

    boot-end-marker

    !

    enable secret 5

    !

    MMI-60 polling interval

    No mmi self-configuring

    No pvc mmi

    MMI snmp-timeout 180

    No aaa new-model

    IP subnet zero

    !

    !

    !

    IP cef

    Max-events of po verification IP 100

    !

    !

    crypto ISAKMP policy 9

    BA 3des

    md5 hash

    preshared authentication

    Group 2

    ISAKMP crypto key (shared key) (peer IP address)

    !

    86400 seconds, duration of life crypto ipsec security association

    !

    Crypto ipsec transform-set esp-3des esp-md5-hmac TS1

    !

    crypmap 1 ipsec-isakmp crypto map

    defined peer (IP ADDRESS of the peer)

    game of transformation-TS1

    match address 101

    !

    !

    !

    interface Ethernet0

    IP (IP ADDRESS)

    NAT outside IP

    Half duplex

    crypmap card crypto

    !

    interface FastEthernet0

    IP (IP ADDRESS)

    IP nat inside

    automatic speed

    !

    the IP nat inside source 1 interface Ethernet0 overload list

    IP classless

    IP route 0.0.0.0 0.0.0.0 (default router)

    no ip address of the http server

    no ip http secure server

    !

    !

    access-list 1 permit one

    access-list 101 permit ip host (LOCALHOST using NAT) host (the remote host 1)

    access-list 101 permit ip host (LOCALHOST using NAT) host (remote host 2)

    access-list 101 permit ip host (LOCALHOST using NAT) host (the remote host 3)

    access-list 101 permit ip host (LOCALHOST using NAT) host (the remote host 4)

    !

    !

    Line con 0

    line to 0

    line vty 0 4

    7 PASSWORD password

    opening of session

    !

    end

    Hi Jim

    You must change the access list statement also the declaration of overloaded nat...

    You must deny traffic between 2 vpn networks is natted...

    You can check the below link configuration to the top of the same...

    http://www.Cisco.com/en/us/Tech/tk583/TK372/technologies_configuration_example09186a008009448f.shtml

    regds

  • ASA5505 problem of asymmetric routing? (I think)

    Good evening everyone,

    I'm looking for suggestions for a solutoion I met today... I am installing a new router and firewall into an existing network. The router is an Edgewater VOIP router to a cable connection with static IP. The firewall is an ASA5505 (security more). There is a third-party router in the mixture (Cisco 1841) which has a PTP connection goes to another site. I'll try to verbally explain the architecture of the network:

    Unfortunately, the existing network was flattened on a 19 on which I'm not allowed to change so:

    VLAN 1 = data network (they used a large 19)

    VLAN 40 = voice (for VOIP phones)

    Edgewater Port 4 > UNTAG 1, tag 40 > ASA5505 Port 0

    Edgewater Port WAN > Cable Modem

    Edgewater DHCP Server for VLAN 40

    ASA5505 Port 0 > UNTAG 1, tag 40 > router Edgewater

    1 port ASA5505 > UNTAG 1, tag 40 > Cisco 2950 FE0/4 (set manually vlan the native 1 2950 to work)

    2 port ASA5505 > UNTAG 1, tag 40 > Cisco SG300 Gig1

    Voice of ASA5505 route 0.0.0.0 0.0.0.0 VLAN40_IP_OF_EDGEWATER

    ASA5505 data route 0.0.0.0 0.0.0; 0 VLAN1_IP_OF_EDGEWATER

    ASA5505 DHCPD for VLAN 1 (small subnet, the rest is ready for static with a gateway from the Cisco 1841 (infrastructure))

    Cisco 2950 4 > UNTAG 1, tag 40 > ASA5505 Port 1

    Cisco 2950 GIg1 > UNTAG 1, tag 40 > Cisco 2950 B

    DG of Cisco 2950 a = IP of Cisco 1841

    Cisco 2950 B Gig1 > UNTAG 1, tag 40 > Gig1 Cisco 2950 (rising MM fiber)

    Cisco 2950 B FE11 > UNTAG 1, tag 40 > Cisco 1841 FE0/0

    Cisco 2950B DG = IP of Cisco 1841

    Cisco 1841 FE0/0 0/0.1 dot1q native 0/0.40 dot1q 40 > FE11 Cisco 2950 B

    Road to Cisco 1841 ip 0.0.0.0 0.0.0.0 firewall VLAN 1 Interface IP (Changed to ip route ip VLAN40_NETWORK VLAN40_IP_OF_EDGEWATER and VLAN1_NETWORK VLAN1_IP_TO_ASA5505)

    Cisco also has internal IP routes through the private point of connection to another site...

    I'm replacing out of their existing connection is a sonicwall firewall and adding a few new POE switches for VOIP phones, VOIP router and an ASA5505. I can't play nice no matter what I tried. It seems that I am running into problems of asymmetric routing (ASA send me some)

    Deny TCP (no relation) on the VLAN 1 static and given dhcp VLAN40 DHCP handed the Edgewater works fine, I can browse on without any problem)...

    I'm not sure what the best approach is to do this. They need to keep the 1841 for now until a connection VPN of STS can be configured with the ASA5505 to their ASA5510 at the other site (months on the road by their budget). All of their PC is statically allocated and using their default gateway as the C1841.

    If you need output all configs I created so far or havy of suggestions on how to solve my problem, I'd love to hear about them. I tried everything short of re - structuring their entire network or deletion of my VOIP router that manages a large number of configurations for VOIP PBX phones.

    Thank you!

    Jon

    Apologies, but this is a very confusing description of how it is configured.  A diagram would probably help.

    If the new VoIP router's DHCP server for vlan 40 where are the customers compared to this?

    You have two lanes on the SAA pointing the VoIP router, what is the reasoning behind this?

    Why are you the ASA to the router VoIP trunking?

    The VoIP router can hand out DHCP addresses for a network, that it is not directly connected or is it why you extended vlan 40 completely out to the VoIP router?

    The router VoIP must give the vlan 40 IPs.

    I guess maybe it's to do with my lack of understanding as to exactly what does a VoIP router (as opposed to a normal router).

    So maybe you could clarify?

    Jon

    Jon

  • Static region with default router activity

    Hi all
    I have a simple problem,

    What is the right way to do the following:
    I have a tf which has default router activity. I want to use this area as static, but also I want to call this region with dif. parametars of entry. Value of matches will put to rout next activity in static region.
    In addition, in the home page I meni, I want to spend the value by clicking on some of the elements of mani, say meni item A I spend 2 as value to the router in the static region, meni point B crossing value 99 to the router in the static region.


    I use beans, but in this case, it only works if I have some funk, for each meni set matches and bean mus be at the session, right?
    Thank you for you time.

    Published by: newenrba on March 20, 2012 12:30

    Hello
    You can archive this as shown here http://tompeez.wordpress.com/2011/11/27/jdev-11-1-2-1-0-using-router-to-conditionally-set-navigation-target/
    Instead of the button that I use in the blog, you use a menu item to set the variable as you then check in the workflow.

    Timo

  • When you try to set default values, Explorer stops

    trying to set wmp as default. When I click on set as default I get explore stopped

    trying to set wmp as default. When I click on set as default I get explore stopped

    Suggestion:
    Run a file system check... sfc/scannow
    After sfc is done, at the end of the screen, it will say either (and I paraphrase)...
    No violation of the intergrety, or
    Found some files corrupted but unable to trouble.

    First see if you can set default this time.
    If this isn't the case, please post the resullt of the verification of the file system.

    For the benefits of others looking for answers, please mark as answer suggestion if it solves your problem.

  • Cannot set default printer in Windows Vista.

    Hello
    My computer still works fine until lately something's happened to Windows Vista all of a sudden. One day I put on the computer and found that the left side of the menu 'start' all deleted, and the content on the right side of the Panel is still there. But then I found that I cannot print a document PDF and Excel, and the error message reads: "Before you print a document, you must install a printer." I have a HP Color laser printer connected to it since and it still works well. I can always print Word document (unless I have to manually select HP printer each time the dialog box I have ever had to do before), but cannot print PDF or Excel. On the 'control panel', the HP printer icon is still there, but it is not set as default printer, as it has always been. And when I tried to set up as a default printer, the error message reads: "can't set default printer.

    Can anyone help? Thank you very much.

    I would like to begin uninstalling the printer, restart and reinstall the printer to determine if that solves the problem...

  • Cannot set default printer. Error code 0 x 0000709

    Printer Deskjet HP3510 instaled on Hp laptop running windows 7. Cannot set default printer. Error code 0 x 0000709. Removing software and old computer

    tgwright,

    Thanks for the additional info. With the doctor print and scan does not locate a corrupted software/driver problems its time to turn to the operating system itself. Others who have had similar problems with the same error indicate a corrupted registry key, the origin of the problem:
    http://goo.GL/t94JG

    http://goo.GL/uejgi

    Beware these solutions indicate the change of information in registry (very dangerous if you don't know what you're doing). If you are not familiar with the registry or have never been here before that I would suggest seeking additional support in some way (local / Microsoft IT / PC repair service, etc.).

    Good luck!

  • BGP, OSPF with default route

    Hello

    My branch becomes internet through seat & connected through lease line and ospf is running. a static route id 0.0.0.0 set to HO.

    Now an additional link is added to our extensive network of MPLS link redundancy & EBGP is running.

    My question is how to configure ospf route (my internal network) to bgp & default (for internet) route for connectivity?

    Please help with examples.

    Thank you

    For the internet, you need a default route. I am assuming that you will get by default route of MPLS as well so leased will remain DEFAULT road get MPLS BGp inject into LAN by this command that I already added to your config file.

    router ospf xxx

    default information are created

    !

    Also if you connect line Lased and MPLS on the same router then router chooses MPLS as the main path as favorite eBGP and ospf. If you ave to change AD BGP routes to ospf will get better than BGP. Use in config for leased line primary and secondary MLP.

    router bgp xxx

    BGP distance 200 200 200

    !

  • Default route inside the tunnel VPN Site to site

    We want to carry the default traffic within the site to site VPN tunnel, our goal is to route all traffic including default branch road and HO HO help branch for surfing the internet.

    I have due to difficulties

    1. cannot configure dynamic NAT for the router in the branch on the ASA HO, I know configuration for 8.2, but know not about 8.4

    This is the configuration for the 8.2, if someone can translate to 8.4, which would be a great help

    NAT (outside) 1 192.168.230.0

    2. I do not know how to write the default route on the branch office router to send all traffic within the VPN tunnel

    Hello

    As I understand it then you want to route ALL traffic from the Remote Site to the Central Site and manage Internet traffic there.

    I suppose you could define "interesting traffic" in configuring VPN L2L ACL / access-list in the following way

    Branch router

    extended IP access list

    allow an ip

    ASA central

    ip access list allow one

    The idea behind the type of ACL for the VPN L2L above configurations is that, for example, the branch office router has a rule that sets connection coming from the local LAN for 'any' destination address must be sent to the VPN L2L connection. So, it would be in such a way that all the traffic will be sent to the Central Site via VPN L2L.

    I must say however, that the VPN router configurations side are not more familiar to me because I manage especially with ASA Firewall (and to some extent still PIX and FWSMs)

    I guess that on the ASA Central you will PAT translation to "outside" so that the host can access the Internet?

    You would probably do something like this

    object-group network to REMOTE-SITE-PAT-SOURCE

    network-object

    interface of REMOTE-SITE-PAT-SOURCE dynamic NAT (outside, outside) after auto source

    If you don't want to use the 'outside' IP address, then you will have to create a 'network of object' for address IP of PAT and use it in the line of NAT configuration above instead of "interface".

    Alternate configuration might be

    network of the REMOTE-SITE-PAT object

    subnet

    dynamic NAT interface (outdoors, outdoor)

    You also need to enable

    permit same-security-traffic intra-interface

    To allow traffic to enter and exit the same interface on the ASA

    All these answers are naturally suggestion on what you have to do. I don't know what kind of configurations you have right now.

    Hope this helps in some way

    -Jouni

    Post edited by: Jouni Forss

  • Vm cloning: unable to set default gw

    Hi guys,.

    the more time I spend on this troubleshooting problem more I think this is a bug.

    I tried 2 different ways (new-vm and clonevm_task) of cloning a vm and I can not put the default gateway on my virtual machine.

    My script was shortened and only shows the central part where I have problems. Default gateway shows the empty, but only on Windows Server 2008 Enterprise Edition x 86 and x 64. I tried to reinstall the operating system, but it makes no difference. Defining works of gateway by default on other Windows operating systems.

    I rewrote the script to create a model of customization and it seems fine. And when I clone manually in the GUI I can make it work!

    I have exactly the same problem when using the clonevm_task and the parameter ip in this way:

    $vmcSpec
    .Customization.NicSettingMap[0].Adapter.Ip.IpAddress = $ip $vmcSpec
    .Customization.NicSettingMap[0].Adapter.SubnetMask = $subnetmask $vmcSpec
    .Customization.NicSettingMap[0].Adapter.Gateway = $gateway $vmcSpec
    .Customization.NicSettingMap[0].Adapter.DnsServerList = $dns
    
    
    
    

    My script:

    $vmname = "server1" $ip = "192.168.1.2" 
    
    $subnetmask = "255.255.255.0" 
    
    $gateway = "192.168.1.1" 
    
    $dns = "192.168.0.1","192.168.0.2" 
    
    $vmtemplate = "w2k8-ent-x86" 
    
    $vmesxhost = "ESX1" 
    
    $datastore = "LUN1" 
    
    $notes = "PowerCLI cloning test" 
    
    
    $CustSpec = New-OSCustomizationSpec -Name $vmname ` 
    
         -FullName 'Something' ` 
         -OrgName 'Something' ` 
         -OSType 'Windows' ` 
         -ChangeSID ` 
         -ProductKey "aaaaa-bbbbb-ccccc-ddddd-eeeee" ` 
         -AutoLogonCount 1 ` 
         -Type 'Persistent' ` 
         -AdminPassword "secret" ` 
         -TimeZone 105 ` 
         -Workgroup 'workgroup' ` 
         -LicenseMode 'PerSeat' 
    
    Get-OSCustomizationSpec $custspec | Get-OSCustomizationNicMapping | Set-OSCustomizationNicMapping -IpMode UseStaticIp -IpAddress $ip -SubnetMask $subnetmask -DefaultGateway $gateway -Dns $dns 
    
    $task = New-VM -Template $vmtemplate -VMHost $vmesxhost -Name $vmname -Datastore $datastore -Description $notes -OSCustomizationSpec $custspec
    
    
    
    


    Can anyone confirm if this is a bug? I put all a time between this question so now I want to know if I am against the impossible here

    Thank you

    Kim

    Take a look at KB1016878.

    The bypass of this Ko road may solve your problem?

  • Problem setting transition duration first pro cs4. Is this a bug?

    Hello world

    I have made a project of first pro cs4 and I'm having problems setting the duration of transitions between clips. I have my default transion set to cross dissolve them and 15 frames in length. When I try to lengthen, it seems that first makes two transitions in instead of a longer one. So, if for example I got a clip with a dip to black when I extend more than 15 default images to say 30 images I get two separate transitions one after the other instead of a long. I know it's difficult to understand so I downloaded the video on youtube. If fast forward you to the minute 01:20, you will see the latest bland given away with a dip to black transition and the you'll be right flash a bit after the last light disappears. I hope someone can help me solve this problem, as I'm completaly lost. Thank you :-)

    Work waaay too hard at this, dude.  Just use the default chained.  It gives you good fade to the top using all 24 images, no adjustment necessary.

  • How to set default COPY for HP Officejet 6500 has more quality DRAFT?

    How can I set default COPY quality to the PROJECT for HP Officejet 6500 has more?

    Hello

    Press on copy on the front panel of the printer, then press the settings button.

    Quality faucet and quick selection / project.

    Press on set as the new default settings, and then click Yes to confirm the changes.

    Later draft quality will be used for the copy unless any other quality is selected.

    Kind regards

    Shlomi

Maybe you are looking for