problem with transformation of 8265 3785?
I am using ORACLE 11 g Release 11.2.0.1.0and Mapviewer Version: Ver11_B091229.
I use the MVGoogleTileLayer to put in Google maps. No problem.
The problem is when I try to superimpose my data.
My data are based on the coordinate system of 8265.
1. I tried to create the map cache as described here:
http://oraclemaps.blogspot.com/2009/03/displaying-MapViewer-tile-layers-over.html
This does not cause my card being superimposed anywhere near what Google maps has. It seems not even to be the right size to fit the area I'm just overlap.
2. I tried to simply superimpose a thematic FAITH on Google maps. It's closer to ad looks like the right size, but there is always a time lag. I tried this with the original data, as well as the data I ran sdo_cs.transform on. The display is the same.
Is there some problem with transformation between 8265 and 3785 I should know about?
(2): you need a rule for 8265 <-->3785. See the thread of three pages on google proj 900913.
Something like (run as a privileged user)
Call sdo_cs.create_pref_concatenated_op (82653785, ' OPERATION 82653785', TFM_PLAN (SDO_TFM_CHAIN (8265 1000000000, 4055, 19847, 3785)), CONCATENATED NULL ");
Re-verification theory myself, but (1) it is a probably a difference between what is in the javascript API tile config for Google tile layer and the def of tile for the layer of tiles MV. The likely fix is to set the def of tile mapviewer as from level 1 of the google def tile. In other words, change
TO
i.e. Delete level 0, rename etc. 1-0, 2-1.
...
...
Tags: Fusion Middleware
Similar Questions
-
Problem with transformation for connector DBAT 11
Hi, this time I'm doing a Transformation for a DBAT 11.1.1.5.0 connector by following the instructions in the official document Oracle for this connector.
The problem is when I run the scheduled task, I get this error:Message
java.lang.NoClassDefFoundError:
Oracle/iam/connectors/common/transformation/processing
The code that I want to implement is identical to the example provided in the documentation:
/ public class TransformAttribute implements {Transformation
public Object transform (hmUserDetails, hmEntitlementDetails, String sField HashMap HashMap) {}
String firstName = (String) hmUserDetails.get ("First Name");
String lastName = (String) hmUserDetails.get ("Last Name");
"String fullName = firstName +". "+ lastName;
Returns the full name;
}
}
I think the problem is with the "Transformation" interface, I don't know what .jar file find this one.
I found an interface of Transformation in a '.jar' for an SAP connector 9 version but I think that is not correct.Any idea where I can get the Transformation dbat 11 connector interface?
Thank you very much! Best regards!
What ia the IOM version you use?
Its mainly a bug. check the Doc ID 1451037.1
-
Problems with transform->; scale
Whenever I have a choice to scale the edges of the selection I didn't budge are left with a border of pixels wide 1 ugly who tries to imitate the colors around it, but is quite noticeable. I've been solving this border remains of manually and it is very annoying. How to avoid this border after the scale effect?
What version of photoshop?
If you just transform the selection itself and not the content in earlier versions cs6 you can go into Photoshop preferences (edit) > General and change of the
Image to the nearest neighbor interpolation. But don't forget to reset one of the bicubic options before turning an image.
In cs6, you should be able to change it in the options toolbar.
If transform you the content inside the selection, and then it depends on what type of layer is.
-
Hello!
I m facing a problem with the help of oraext: query-database.
In my transformation im try the following (Simplified):
How to get the correct value when you use oraext:query - database?<xsl:template match="*"> <xsl:variable sqlQuery="select ....."/> <xsl:variable name="storeSec" select="oraext:query-database($sqlQuery,true(),true(),'jdbc/xref')/> <xsl:choose> <xsl:when test="string-length($storeSec/ROWSET/ROW[1]/STORE_PART_SECTION) > 0"> <xsl:value-of select="$storeSec/ROWSET/ROW[1]/STORE_PART_SECTION"/> </xsl:when> <xsl:otherwise> <xsl:value-of select"some other val"/> </xsl:otherwise> </xsl:choose> </xsl:template> {code} This always results in +some+ +other+ +val+ !! I´v checked the output from oraext:query-database by using getcontentAsString and if I instead test putting the expected output from oraext:queryDatabase in my variable it gives me A100 which is what i expected. {code} <xsl:template match="*"> <xsl:variable sqlQuery=select ....."/> <xsl:variable name="storeSec"> <ROWSET> <ROW num="1"> <STORE_PART_SECTION>A100</STORE_PART_SECTION> </ROW> <ROW num="2"> <STORE_PART_SECTION>XXm</STORE_PART_SECTION> </ROW> </ROWSET> </xsl:variable> <xsl:choose> <xsl:when test="string-length($storeSec/ROWSET/ROW[1]/STORE_PART_SECTION) > 0"> <xsl:value-of select="$storeSec/ROWSET/ROW[1]/STORE_PART_SECTION"/> </xsl:when> <xsl:otherwise> <xsl:value-of select"some other val"/> </xsl:otherwise> </xsl:choose> </xsl:template>
How should you exit? Several item ID with each having a value of the result set?
If Yes, then you can try following: -
Satellite Pro P300 - problem with volume control
Hello
I have a problem with my volume control. He worked for the first two months of use value, but now refuses to lower the sound.
He sort of stutters and actually transforms the sound upward when you turn, he 'left' to drop.I markets DEAMS it is a digital control and therefore is not a point 'end' like other laptops. I also noticed others are experieicing this problem.
Is there a solution to this problem? I don't really like having to manually click on the volume control in the status bar on the window in order to be able to turn the laptop down. Maybe someone can help me?
Thanks in advance.
SamHello
In your case, I recommend reinstalling the audio driver and controls (with Win XP) Toshiba or Toshiba VAP (if Vista is installed).
In addition, you should check if the BIOS can be updated too.Sorry for this suggestion, but in my opinion that the question must be related software and the fact is that driver sound and the VAP multimedia button controls and the sound card.
It of certainly worth a try
-
Satellite A200-1d(a): various problems with Windows Vista Mail
Model: Satellite A200-1d(a)
O/s: Windows Vista editions Home Premium more
Background: Recommended for a parent, now transformed into 'support harassment ".The behavior of Windows Mail is displayed is non-standard and unreliable, for example:
Creating new folders local they are initially displayed in the list of folders (left sidebar), if the mail is restarted they disappear and reappear only if they are selected after clicking on "local folders". Other than the Inbox, local folders and the Microsoft? (used for notes, etc.), all the other default folders are missing, either sent, sent, drafts box, etc.
Another minor issue is that windows mail does not seem to recognize when the status of the internet connection changes from unavailable to available, in order to empty the Outbox and send emails, it is necessary to restart windows Messaging.
A number of occasions, all messages disappear from your Inbox and all other folders are not available, the only solution to this problem seems to be a reboot of the laptop.
This link seems to suggest that there is a problem with the security software which is now Norton Internet Security (configured and bundled with the laptop):
http://forums.techguy.org/all-other-software/551829-Windows-Mail-doesn ' t-display - messages.htmlI tried to disable email inbound/outbound scanning in Norton, but it made no difference.
Next step is to apply:http://support.toshiba-tro.de/KB0/TSB7701X30005R01.htm
and then remove Norton Internet security
Any ideas?
Other than the foregoing the laptop is fine, looks like a problem of s/w for me.concerning
Ball
Hello
I can't provide an exactly the solution to this problem of Vista Mail but to me, it looks like a Microsoft Vista operating system problem and not Toshiba Satellite.
I don t think there could be a problem with the hardware that's why we should look for solutions.Now you will ask where a software solution? In my opinion, you should check the knowledge base Microsoft for some useful tips.
http://support.Microsoft.com/search/
and the solution center in Windows Vista
http://support.Microsoft.com/windowsvistaBut first make sure that your Vista operating system is up-to-date and you have already installed all the updates and patches!
Good bye
-
Problems with playlists on Clip +.
Hello
I am having some problems with the creation of playlists on the Sansa Clip + (4GB). I have some MP3 files on the internal memory and I have no problem with the creation of playlists for these files. But I have also some MP3 on my 8 GB MicroSD card (made by SanDisk, by the way) and I was not able to create playlists for these files.
Let me clarify; I can create playlists for MP3 on the MicroSD card, but no matter where I store these playlists (internal memory or the card itself) I have problems. If I store playlists on the internal memory of the content of these playlists disappears if I unplug the card. Playlists are still there, but they are empty. If I store those playlists on the MicroSD card (where are the MP3 files) and later to unplug the card, the playlists are transformed into something completely different. The file names are replaced by something starting with a whole bunch of numbers and the playlists are not recognizable.
I am also having the same problem when I copy MP3s directly on the MicroSD card - the names are changed and there are a bunch of unnecessary additional files added. The problem gets worse if I put the music in the files on the MicroSD card. At least if they are all in the same folder that I can get rid of unnecessary files.
I should probably mention that I do not use the crazy method they recommend manual synchronization of the user with Windows Media Player. It takes too long and it's too complicated. Instead, I just select the songs I want in any playlist special (I copied on my micro SD my PC card) and make a right click on any of the selected files and a context menu appears and gives you the ability to create a Playlist - (in Windows XP SP3).
It works very well on the internal memory. This is how I did it on my regular Sansa Clip and it worked without any problem at all. But it will not work with any files on my MicroSD card. I did something wrong? Or is my card MicroSD does not work properly?
Any help would be greatly appreciated. Thank you.
Well, I solved the problem I've been create permanent playlists for MP3 stored on my MicroSD card.
What I've discovered, is that the new Clip + doesn't seem to like the playlists created in Windows Explorer (i.e.; Choose the songs / right click / Choose "create Playlists) with the extension of file .pla .»
Which works very well for any MP3 stored on the internal memory, but not for files stored on the card.
I use a free program called Playlist Creator 3.6 to create playlists in .m3u format. This is the format that works for MP3 files on the MicroSD card.
I make selections in the folder my music is stored On MY PC - then I copy this .m3u playlist folder On THE MicroSD CARD where my MP3s are (those of the playlist I just created).
You need to copy the list of reading in the same folder that your music is (on the map). As long as the MP3 in the same folder as the .m3u playlist - the playlist will find them.
Now, the playlist seems to be empty if you try to open them in Windows, but don't worry-there is work. The info is still there. And playlists keep the info and the names you give them even if you remove the card and later put it again. Hope it will be useful to someone else.
-
Anyone who has a problem with net.exe?
Windows 7 Ultimate x 64 with all patches
Open a command window and tried to run net.exe:
C:\>NET
This version of C:\Windows\system32\net.exe is not compatible with the version o
f Windows that you use. Check your computer's system information to see information indicating if
r you need a x 86 (32 bit) or x 64 (64-bit) version of the program, then told the
CT the software publisher.Checked net.exe and found that it was not true. Did a scan using Microsoft Security Essentials and it says that it ASNA 2 files and found no threat.
The original net.exe was renamed appearently net1.exe.
The owner of the file is trustedinstaller. I can't move, rename or delete it even when running as administrator. The system says that I need the permission of the Trusted Installer.
Any idea of what could have caused this and how get rid of?
Hello, saberman
The fact that the Details tab of the property sheet for your net.exe is not filled with the correct information is undoubtedly a problem. This is why suggested Yann Support engineer runs the System File Checker ("SFC"), which is designed to find and replace corrupt or missing system files from backups in your store of components (windows side by side or WinSXS folder; note that the KB929833 article I just linked ("System File Checker") has yet to be re-written to reflect the fact that) Since the advent of Windows Resource Protection in Windows Vista is no longer a dllcache folder in System32 and file system backups are now located @ C:\Windows\winsxs\Backup). Running SFC should have found the problem with net.exe & repaired, without needing to resort to a system restore, which can sometimes cause problems as indicated by the error message you posted, i.e. that net.exe "is invalid for your system. I suggest to read the article from KB929333 on SFC and see if enforcement of that tool is not correct the problem. If not, a good starting point for troubleshooting to solve the problem is the sfcdetail.txt newspaper, which shows the results of each operation of checking files and each transaction attempted repair. instructions for how extract/transform/load this journal of his 'home' in the service area global log (log CBS.log) in a usable format appear under the heading "How to view the details of the System File Checker process" of KB929333, and the instructions on how to repair files that are not SFC are included in the article "How replace manually a file system damaged by a known file correct copy" section (the two sections are available by clicking on the circle '+' sign next to "for more information"). It is to note that it is not uncommon to have to run SFC repeatedly to deal with corruption - 3 times is the recommended minimum, and I personally saw him require more... the error dialog box that you see leads me to believe there is more harm than simply a lack of functionality net.exe and CFS can be just the thing to get things straightened.
That said, it is also true that there is often more than one place that a protected system file is stored, other than the C:\Windows\winsxs\Backup on a Windows 7 computer. Typical areas of other instances of the net.exe include C:\Windows\winsxs\x86_microsoft-windows-net-command-line-tool_31bf3856ad364e35_6.1.7600.16385_none_5208a7a3d3caa54c records, while net1.exe can usually be discovered (on a 64 - bit with an AMD processor machine) and two C:\Windows\winsxs\x86_microsoft-windows-net1-command-line-tool_31bf3856ad364e35_6.1.7600.16385_none_86b24994b5e6bfbf at C:\Windows\winsxs\amd64_microsoft-windows-net1-command-line-tool_31bf3856ad364e35_6.1.7600.16385_none_e2d0e5186e4430f5 (note that the part "31bf3856ad364e35" of these folder names may vary). There may be other places in the store of components according to these things the way that system restore several times has been executed, whether an OEM computer (i.e., a pre-loaded with Windows by an Original Equipment Manufacturer) who has already found "Factory Spec", which updates Windows, service packs and other fixes/patches have been applied, and other factors. The trick is to know what file is correct to use to replace a version corrupted in C:\Windows\System32 - which is not always easy to determine - and by "taking possession" file corrupted in question, so it may be deleted or replaced.
The windows component store peut usually be used as the source of a file replacement for one that SFC cannot fix by using the information in C:\Windows\winsxs\Backup, but a user must make sure that they know what they are doing to avoid the disaster (this is why Microsoft has included the "automatic" option to perform a "repair installation" to correct the corruption of the system)- and if the user has access to another , work computer running the same version of Windows, or for the installation media (if no Service Pack or other update of the kernel has been applied), or "slipstream" self-created media (if Windows 7 Service Pack 1 has been applied) designed specifically for the operating system in use, extraction verified copies of the record of those required are usually an "easier" approach Detailed instructions on the use of all these forms of installation with SFC media are in the Wiki author try * 3of 6 December 2013 post to the thread of community "System File Checker and access files blocked, while detailed instructions on how to create a"slipstreamed"media are in his post from August 25, 2012 to pg 3 of the thread"guide to recovery of Windows 7 Home Premium account user word of. past lost, unable to connect, connection problem"(it is also useful to have a look at this whole thread, which has very useful information about different Windows 7 recovery options, and that includes links to downloadable PDFs (portable document files) on each of the options many.). BTW, these pdf files is hosted on the cloud OneDrive service, which is where we usually place downloaded files (for example the zipped copy of your corrupt net.exe file you mention) and make them accessible to third parties. to learn more on how to do that I recommend community animator Gerry C J Cornellexcellent tutorial 'Forums Community Microsoft"on its site Computer Tips of Gerry .
As you noted, net.exe (and net1.exe - which, as I have, reminder has been around in all NTFS OS since @ least NT4.0 however hardly documented; official documentation only I ever)
seen mention that this is the Windows Embedded article Utility Net.exe : thus, as well as many others
protected system files) is 'held', in terms of security of the file/folder permissions, by service "Trusted Installer". The implementation of the Protection of resources of Windows, Vista, limit property of this service-protected system files in large part to protect themselves against malicious or accidental deletions. However, a user with administrative privileges ('high') can always take ownership over any file and then manipulate it at will. TechNet Library 'ownership of a file or a folder' article provides advice on how to do it, but without expertise in the creation of a file batch, macro, visual basic program, Power Shell command or similar to handle this action based on a large scale, the procedure described is essentially limited to a one-at-a-time approach. In my opinion, a better technique is to add the ability to take ownership of a file or folder from the context menu (right click "") of the operating system. many people have found the information and automated "registry hacks" in the Seven Forums tutorial "Windows 7: take ownership shortcut" very useful in this regard. Even with this capability, users can occasionally run through a file that stubbornly refuses to behave even when the property has been reassigned to the said user. in this case, the stand-alone freeware program ("Portable Executable", requiring no installation runs) UnLocker can be valuable.
I'm hopeful that SFC be enough to take care of this problem for you, but if not, I would also consider
check the integrity of the hard disk / partition with Check Disk. If none of these solves the problem, a repair installation may be in order. Useful information on this procedure can be found in article KB2255099, "How to perform an upgrade in Place on Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2" and the tutorial of the Forum seven "How to do a repair of trouble Windows 7 installation. Good luck!
-
Problem with a SIP Trunk between VCS and CUCM
Hello world
I created a SIP Trunk between control VCS (X7.1) and a CUCM 8.6.
I followed this Cisco_VCS_Cisco_Unified_Communications_Manager_Deployment_Guide_CUCM_6-1_7_8_and_X7 - 0.pdf deployment guide.
The trunk is in place, but I have the following problem: I can ring since an EX90 recorded on the VCS for a registered on the CUCM 9951 but when I take the call, I have a busy signals (audio and video). When I on the EX90 9951 ring, I have the following message on VC: can not reach the contact.
I have a 503 service unavailable status on the call history and "call rejected" on the event log.
My transformation is OK and the call is sent to my neighbor CUCM zone
You have an idea to solve this problem?
Thanks for your help
Best regards
Bruno Z.
Hello
Yes, it's true! It seems at first glance a problem with codec negotiation when I see the reason 47 code.
in any case set the region to G.711 trunk phone in case if you have different device pool and the trunk region and ip-phones.
make G.711 end to end and test again.
Thank you
Alok
-
Bluetooth mouse problems with windows 7 ultimate
I have two laptops which, without reason, all of a sudden loses connectivity of bluetooth mouse, it just stopped working and then I have to reboot to get it working again. Two of these computers also have a bluetooth keyboard that is not assigned, the mouse. I don't find anything wrong with bluetooth and have tried several different mice with the same results. Windows 7 ultimate on two laptops. a laptop computer used to run vista ultimate with the same mouse windows and it never happened, it started with windows 7.
Hello
These used laptops are relatively very close where they can interfere with each other?
Will there be electrical/electronic or other types of interference in the region?
Check with the bluetooth device to the manufacturer for known issues and possible solutions
Visit the Microsoft Solution Center and antivirus security for resources and tools to keep your PC safe and healthy. If you have problems with the installation of the update itself, visit the Microsoft Update Support for resources and tools to keep your PC updated with the latest updates.
Norton and other security/antivirus/antispyware programs are known to cause problems with
BlueTooth/mouse devices.=================================================================
It is extremely difficult to solve the intermittent problems.
Hardware devices not detected or does not work - a Mr Fixit
http://support.Microsoft.com/GP/hardware_device_problemsThe problems with Bluetooth devices
http://Windows.Microsoft.com/en-us/Windows-Vista/troubleshoot-problems-with-Bluetooth-enabled-devicesSet up a Bluetooth compatible device
http://Windows.Microsoft.com/en-us/Windows-Vista/set-up-a-Bluetooth-enabled-deviceThe problems with Bluetooth devices
http://207.46.197.98/Windows/en-in/help/11a74104-645D-40D4-b933-bde5d15537bb1033.mspxHow to set up a Bluetooth connection
http://www.vista4beginners.com/how-to-setup-a-Bluetooth-connectionThe Bluetooth item in Control Panel on a Windows Vista SP2 computer does not
as expected when you click on the element - for Windows 7 this check manually
http://support.Microsoft.com/kb/960531/en-usIf you need drivers try the support site for the manufacturer of your system and/or the site of the manufacturer of the real device.
BluetoothView is a small utility that runs in the background and monitor the activity of Bluetooth technology
devices around you. For each detected Bluetooth device, it displays the following information:
The device name, address Bluetooth, Major Device Type, minor device Type, first detection time,
Last detection time and more. BluetoothView can also warn when a new Bluetooth device
is detected, by displaying a balloon in your bar tasks or playing a little beep. -FREE
http://www.NirSoft.NET/utils/bluetooth_viewer.htmlBluetoothCL is a small console application that transforms all differential of bluetooth devices detected in
the standard output. For each Bluetooth device, the following information is displayed: MAC
Address, name, Major Device Type, minor device Type and possibly the name of the company of
the device (if the external file of MAC addresses - oui.txt is provided) - FREE
http://www.NirSoft.NET/utils/bluetoothcl.html---------------------------------------------------------------------
Add a Bluetooth device to your computer
http://Windows.Microsoft.com/en-us/Windows7/add-a-Bluetooth-enabled-device-to-your-computerAdd a Bluetooth device or other wireless or network device: frequently asked questions
http://Windows.Microsoft.com/en-us/Windows7/add-a-Bluetooth-or-other-wireless-or-network-device-frequently-asked-questions---------------------------------------------------------------------
More information of possible interest to some: (not directly related to this issue)
What is a Bluetooth personal area network (PAN) network?
http://Windows.Microsoft.com/en-us/Windows-Vista/what-is-a-Bluetooth-personal-area-network-PanConnect to a Bluetooth personal area network (PAN) network
http://Windows.Microsoft.com/en-us/Windows-Vista/connect-to-a-Bluetooth-personal-area-network-PanI hope this helps.
Rob Brown - MS MVP - Windows Desktop Experience: Bike - Mark Twain said it right.
-
Problem with IPSEC tunnel between Cisco PIX and Cisco ASA
Hi all!
Have a strange problem with one of our tunnel ipsec for one of our customers, we can open the tunnel of the customers of the site, but not from our site, don't understand what's wrong, if it would be a configuration problem should can we not all up the tunnel.
On our side as initiator:
Jan 14 13:53:26 172.27.1.254% PIX-7-702208: ISAKMP Phase 1 Exchange started (local 1.1.1.1 (initiator), remote 2.2.2.2)
Jan 14 13:53:26 172.27.1.254% PIX-7-702210: Exchange of ISAKMP Phase 1 is complete (local 1.1.1.1 (initiator), remote 2.2.2.2)
Jan 14 13:53:26 172.27.1.254% 6-PIX-602202: ISAKMP connected session (local 1.1.1.1 (initiator), remote 2.2.2.2)
Jan 14 13:53:26 172.27.1.254% PIX-6-602201: Phase 1 ISAKMP Security Association created (local 1.1.1.1/500 (initiator), 2.2.2.2/500 remotely, authentication = pre-action, encryption = 3DES-CBC, hash = SHA, group = 2, life = 86400 s)
Jan 14 13:53:26 172.27.1.254% PIX-7-702209: ISAKMP Phase 2 Exchange started (local 1.1.1.1 (initiator), remote 2.2.2.2)
Jan 14 13:53:26 172.27.1.254% PIX-7-702201: ISAKMP Phase 1 delete received (local 1.1.1.1 (initiator), remote 2.2.2.2)
Jan 14 13:53:26 172.27.1.254% PIX-6-602203: ISAKMP disconnected session (local 1.1.1.1 (initiator), remote 2.2.2.2)
Jan 14 13:53:56 172.27.1.254% PIX-7-702303: sa_request, CBC (MSG key in English) = 1.1.1.1, dest = 2.2.2.2, src_proxy = 172.27.1.10/255.255.255.255/0/0 (type = 1), dest_proxy = 192.168.100.18/255.255.255.255/0/0 (type = 1), Protocol is ESP transform = lifedur hmac-sha-esp, esp-3des 28800 = s and 4608000 Ko, spi = 0 x 0 (0), id_conn = 0, keysize = 0, flags = 0 x 4004
The site of the customer like an answering machine:
14 jan 11:58:23 172.27.1.254% PIX-7-702208: ISAKMP Phase 1 Exchange started (local 1.1.1.1 (answering machine), 2.2.2.2 remote)
14 jan 11:58:23 172.27.1.254% PIX-7-702210: Exchange of ISAKMP Phase 1 is complete (local 1.1.1.1 (answering machine), 2.2.2.2 remote)
14 jan 11:58:23 172.27.1.254% 6-PIX-602202: ISAKMP connected session (local 1.1.1.1 (answering machine), 2.2.2.2 remote)
14 jan 11:58:23 172.27.1.254% PIX-6-602201: Phase 1 ISAKMP Security Association created (local 1.1.1.1/500 (answering machine), distance 2.2.2.2/500, authentication = pre-action, encryption = 3DES-CBC, hash = MD5, group = 1, life = 86400 s)
14 jan 11:58:23 172.27.1.254% PIX-7-702209: ISAKMP Phase 2 Exchange started (local 1.1.1.1 (answering machine), 2.2.2.2 remote)
14 jan 11:58:23 172.27.1.254% PIX-6-602301: its created, (his) sa_dest = 2.2.2.2, sa_prot = 50, sa_spi = 0x9de820bd (2649235645) sa_trans = sa_conn_id of hmac-sha-esp, esp-3des = 116
14 jan 11:58:23 172.27.1.254% PIX-7-702211: Exchange of ISAKMP Phase 2 is complete (local 1.1.1.1 (answering machine), 2.2.2.2 remote)
Jan 14 12:28:54 172.27.1.254% PIX-6-602302: SA deletion, (his) sa_dest = 2.2.2.2, sa_prot = 50, sa_spi = 0x9de820bd (2649235645), sa_trans = esp-3desesp-sha-hmac, sa_conn_id = 116
Kind regards
Johan
From my experience when a tunnel is launched on one side, but it is not on the other hand, that the problem is with an inconsistency of the isakmp and ipsec policies, mainly as ipsec policies change sets and corresponding address with ASA platform when a tunnel is not a statically defined encryption card he sometimes use the dynamic tag to allocate this vpn connection. To check if this is the case go ahead and make a "crypto ipsec to show his" when the tunnel is active on both sides, see on the SAA if the corresponding tunnel is the static encryption card set or if it presents the dynamic encryption card.
I advise you to go to the settings on both sides and ensure that they are both in the opposite direction.
-
Problem with ping VPN cisco 877
Hi all!
I have a working VPN between a fortigate and a Cisco.
I have a problem with ping network behind the cisco of the network behind the forti.
When I ping to vlan2 cisco without problem (192.168.252.1) interface, but I can't ping a server in the vlan2 (192.168.252.2) behind the cisco.
However the Cisco I can ping the server. In the forti, I see that ping to the interface vlan2 and server in vlan2 take in the same way, and I can see package.
I post my config could see it it as blocking the ping from 10.41.2.36 to 192.168.252.2 while 192.168.252.1 ping is OK?
IPSEC #show run
Building configuration...Current configuration: 3302 bytes
!
! Last modification of the configuration at 14:42:17 CEDT Friday, June 25, 2010
! NVRAM config update at 14:42:23 CEDT Friday, June 25, 2010
!
version 12.4
no service button
horodateurs service debug datetime msec
Log service timestamps datetime localtime show-time zone
encryption password service
!
IPSEC host name
!
boot-start-marker
boot-end-marker
!
logging buffered 1000000
enable secret 5 abdellah
!
No aaa new-model
clock timezone GMT 1
clock to summer time CEDT recurring last Sun Mar 02:00 last Sun Oct 03:00
!
!
dot11 syslog
IP cef
No dhcp use connected vrf ip
DHCP excluded-address IP 192.168.254.0 192.168.254.99
DHCP excluded-address IP 192.168.254.128 192.168.254.255
!
IP dhcp DHCP pool
network 192.168.254.0 255.255.255.0
router by default - 192.168.254.254
Server DNS A.A.A.A B.B.B.B
!
!
no ip domain search
name of the IP-server A.A.A.A
name of the IP-server B.B.B.B
!
!
!
!
!
crypto ISAKMP policy 1
BA aes 256
preshared authentication
Group 5
ISAKMP crypto key ciscokey address IP_forti
!
!
Crypto ipsec transform-set esp - aes 256 esp-sha-hmac vpntest
!
myvpn 10 ipsec-isakmp crypto map
defined by peer IP_forti
Set transform-set vpntest
match address 101
!
Archives
The config log
hidekeys
!
!
!
!
!
interface Tunnel0
IP 2.2.2.1 255.255.255.252
source of Dialer0 tunnel
destination of IP_forti tunnel
myvpn card crypto
!
ATM0 interface
bandwidth 320
no ip address
load-interval 30
No atm ilmi-keepalive
DSL-automatic operation mode
!
point-to-point interface ATM0.1
MTU 1492
bandwidth 160
PVC 8/35
VBR - nrt 160 160
PPPoE-client dial-pool-number 1
!
!
interface FastEthernet0
switchport access vlan 2
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
switchport access vlan 2
!
interface Vlan1
IP 192.168.20.253 255.255.255.0
IP nat inside
no ip virtual-reassembly
!
interface Vlan2
IP 192.168.252.1 255.255.255.0
IP nat inside
IP virtual-reassembly
!
interface Dialer0
bandwidth 128
the negotiated IP address
NAT outside IP
no ip virtual-reassembly
encapsulation ppp
load-interval 30
Dialer pool 1
Dialer-Group 1
KeepAlive 1 2
Authentication callin PPP chap Protocol
PPP chap hostname [email protected] / * /
PPP chap password 7 abdelkrim
myvpn card crypto
!
IP forward-Protocol ND
IP route 0.0.0.0 0.0.0.0 Dialer0
IP route 10.41.2.32 Tunnel0 255.255.255.240
!
no ip address of the http server
no ip http secure server
The dns server IP
translation of nat IP tcp-timeout 5400
no ip nat service sip 5060 udp port
overload of IP nat inside source list NAT interface Dialer0
!
IP access-list standard BROADCAST
permit of 0.0.0.0
deny all
!
NAT extended IP access list
IP enable any host IP_cisco
deny ip 192.168.252.0 0.0.0.255 10.41.2.32 0.0.0.31
!
access-list 101 permit ip 192.168.252.0 0.0.0.255 10.41.2.32 0.0.0.31
public RO SNMP-server community
3 RW 99 SNMP-server community
SNMP-server community a RO
SNMP-Server RO community oneCommunityRead
not run cdp
!
!
!
control plan
!
!
Line con 0
password 7 abdelkrim
opening of session
no activation of the modem
line to 0
line vty 0 4
password 7 aaaaa
opening of session
escape character 5
!
max-task-time 5000 Planner
NTP-period clock 17175037
Server NTP B.B.B.B
Server NTP A.A.A.Aend
Alex,
It's your GRE tunnel:
interface Tunnel0
IP 2.2.2.1 255.255.255.252
source of Dialer0 tunnel
destination of IP_forti tunnel
myvpn card cryptoYou also have routing set by it.
You don't need a GRE tunnel, nor do you need the road to tunnel if you want just IPsec tunnel.
-
Problems with VPN tunnels after the upgrade to PIX 7.0
It seems that Cisco has revamped the VPN process on the new Version of PIX 7.0.
After I've upgraded, I noticed that AH (i.e. ah-sha-hmac, ah-md5-hmac) was no longer supported and all my container transformation games OH no were not converted.
Another question, if you have enabled on Versieon 6.3, names when you upgrade, tunnel groups will be created (formerly "identity isakmp crypto, crypto key
isakmp peer ') which will include a hostname (hostname of identity) instead of IP as it was to the point 6.3. Guess what... Nothing works! Having to delete and recreate it using the IP address. See an example...
tunnel-group OTHER_END type ipsec-l2l
IPSec-attributes tunnel-group OTHER_END
pre-shared-key *.
The above does not work... Having to recreate using the IP address mapped to OTHER_END...
tunnel-group 2.2.2.2 type ipsec-l2l
2.2.2.2 tunnel-group ipsec-attributes
pre-shared-key *.
Furthermore, I have problems with my racoon and freeswan extranet... Did someone recently updated with success and other gateways VPN provider (i.e. checkpoint, Freeswan and Racoon) work?
We found the solution for this problem. It appeared that the perfect forward secrecy is enabled at the other side. If a 'card crypto outside_map 10 set pfs' is necessary. With the pix 6.3 version that appears not to make the difference, the vpn works even with pfs disabled on the side of pix.
-
I have two problems with IPSEC VPN, using the cisco client, and a third, which I think could answer here if this isn't strictly associated with VPN.
1. cannot access the internet, while VPN is in place. This can be a problem of client as I * think * I've split tunneling to install correctly.
2. cannot access other networks except the network associated with the inside interface natively.
3. I can not ping to the internet from inside, be it on the VPN or not.
I tend to use the SMDA; Please, if possible, keep the answer to this kindof of entry.
Here is the config:
Output of the command: "sh run".
: Saved
:
ASA Version 8.4 (1)
!
hostname BVGW
domain blueVector.com
activate qWxO.XjLGf3hYkQ1 encrypted password
2KFQnbNIdI.2KYOU encrypted passwd
names of
!
interface Ethernet0/0
nameif outside
security-level 10
IP 5.29.79.10 255.255.255.248
!
interface Ethernet0/1
nameif inside
security-level 100
IP 172.17.1.2 255.255.255.0
!
interface Ethernet0/2
Shutdown
No nameif
no level of security
no ip address
!
interface Ethernet0/3
Shutdown
No nameif
no level of security
no ip address
!
interface Management0/0
nameif management
security-level 100
IP 172.19.1.1 255.255.255.0
management only
!
passive FTP mode
DNS server-group DefaultDNS
domain blueVector.com
permit same-security-traffic inter-interface
permit same-security-traffic intra-interface
the subject of WiFi network
172.17.100.0 subnet 255.255.255.0
WiFi description
the object to the Interior-net network
172.17.1.0 subnet 255.255.255.0
network of the NOSPAM object
Home 172.17.1.60
network of the BH2 object
Home 172.17.1.60
the EX2 object network
Home 172.17.1.61
Description internal Exchange / SMTP outgoing
the Mail2 object network
Home 5.29.79.11
Description Ext EX2
network of the NETWORK_OBJ_172.17.1.240_28 object
subnet 172.17.1.240 255.255.255.240
network of the NETWORK_OBJ_172.17.200.0_24 object
172.17.200.0 subnet 255.255.255.0
DM_INLINE_TCP_1 tcp service object-group
port-object eq www
EQ object of the https port
the DM_INLINE_NETWORK_1 object-group network
network-object BH2
network-object NOSPAM
Outside_access_in list extended access permit tcp any eq smtp DM_INLINE_NETWORK_1 object-group
Outside_access_in list extended access permit tcp any object object-group DM_INLINE_TCP_1 BH2
pager lines 24
Enable logging
asdm of logging of information
Outside 1500 MTU
Within 1500 MTU
management of MTU 1500
mask pool local 172.17.1.240 - 172.17.1.250 VPN IP 255.255.255.0
mask pool local 172.17.200.100 - 172.17.200.200 VPN2 IP 255.255.255.0
no failover
ICMP unreachable rate-limit 1 burst-size 1
don't allow no asdm history
ARP timeout 14400
NAT (inside, outside) static source EX2 Mail2
NAT (inside, outside) static source all all NETWORK_OBJ_172.17.1.240_28 of NETWORK_OBJ_172.17.1.240_28 static destination
NAT (inside, outside) static source all all NETWORK_OBJ_172.17.200.0_24 of NETWORK_OBJ_172.17.200.0_24 static destination
NAT (inside, outside) static source to the Interior-NET Interior-net destination static NETWORK_OBJ_172.17.1.240_28 NETWORK_OBJ_172.17.1.240_28
!
the object to the Interior-net network
NAT (inside, outside) dynamic interface
network of the NOSPAM object
NAT (inside, outside) static 5.29.79.12
Access-group Outside_access_in in interface outside
Route outside 0.0.0.0 0.0.0.0 5.29.79.9 1
Route inside 10.2.0.0 255.255.255.0 172.17.1.1 1
Route inside 10.3.0.0 255.255.255.128 172.17.1.1 1
Route inside 10.10.10.0 255.255.255.0 172.17.1.1 1
Route inside 172.17.100.0 255.255.255.0 172.17.1.3 1
Route inside 172.18.1.0 255.255.255.0 172.17.1.1 1
Route inside 192.168.1.0 255.255.255.0 172.17.1.1 1
Route inside 192.168.11.0 255.255.255.0 172.17.1.1 1
Route inside 192.168.30.0 255.255.255.0 172.17.1.1 1
Timeout xlate 03:00
Timeout conn 01:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
Sunrpc timeout 0:10:00 h323 0:05:00 h225 mgcp from 01:00 0:05:00 mgcp-pat 0:05:00
Sip timeout 0:30:00 sip_media 0:02:00 prompt Protocol sip-0: 03:00 sip - disconnect 0:02:00
Timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
dynamic-access-policy-registration DfltAccessPolicy
AAA-server blueVec protocol ldap
blueVec AAA-server (inside) host 172.17.1.41
LDAP-base-dn DC = adrs1, DC = net
LDAP-group-base-dn DC = EIM, DC = net
LDAP-scope subtree
LDAP-naming-attribute sAMAccountName
LDAP-login-password *.
LDAP-connection-dn CN = Hanna\, Roger, OU = human, or = WPLAdministrator, DC = adrs1, DC = net
microsoft server type
Enable http server
http 192.168.1.0 255.255.255.0 management
http 172.17.1.0 255.255.255.0 inside
http 24.32.208.223 255.255.255.255 outside
No snmp server location
No snmp Server contact
Server enable SNMP traps snmp authentication linkup, linkdown warmstart of cold start
Crypto ipsec transform-set ikev1 ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac
Crypto ipsec transform-set ikev1 ESP-DES-SHA esp - esp-sha-hmac
Crypto ipsec transform-set ikev1 esp ESP-DES-MD5-esp-md5-hmac
Crypto ipsec transform-set ikev1 ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac
Crypto ipsec transform-set ikev1 ESP-3DES-MD5-esp-3des esp-md5-hmac
Crypto ipsec transform-set ikev1 ESP-AES-256-SHA esp-aes-256 esp-sha-hmac
Crypto ipsec transform-set ikev1 ESP-AES-128-SHA aes - esp esp-sha-hmac
Crypto ipsec transform-set ikev1 ESP-AES-192-SHA esp-aes-192 esp-sha-hmac
Crypto ipsec transform-set ikev1 ESP-AES-128-MD5-esp - aes esp-md5-hmac
Crypto ipsec transform-set ikev1 SHA-ESP-3DES esp-3des esp-sha-hmac
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 define ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA MD5-ESP-3DES ESP-DES-SHA ESP-DES-MD5
card crypto Outside_map 65535-isakmp dynamic ipsec SYSTEM_DEFAULT_CRYPTO_MAP
Outside_map interface card crypto outside
Crypto ikev1 allow outside
IKEv1 crypto policy 10
preshared authentication
3des encryption
sha hash
Group 2
life 86400
IKEv1 crypto policy 30
authentication crack
3des encryption
sha hash
Group 2
life 86400
Telnet timeout 5
SSH 172.17.1.0 255.255.255.0 inside
SSH timeout 5
Console timeout 0
dhcpd address 172.17.1.100 - 172.17.1.200 inside
dhcpd 4.2.2.2 dns 8.8.8.8 interface inside
dhcpd lease interface 100000 inside
dhcpd adrs1.net area inside interface
!
a basic threat threat detection
threat detection statistics
a statistical threat detection tcp-interception rate-interval 30 burst-400-rate average rate 200
WebVPN
internal blueV group policy
attributes of the strategy of group blueV
value of server WINS 172.17.1.41
value of 172.17.1.41 DNS server 172.17.1.42
Ikev1 VPN-tunnel-Protocol
value by default-field ADRS1.NET
internal blueV_1 group policy
attributes of the strategy of group blueV_1
value of server WINS 172.17.1.41
value of 172.17.1.41 DNS server 172.17.1.42
Ikev1 VPN-tunnel-Protocol
Split-tunnel-policy tunnelspecified
adrs1.NET value by default-field
username gwhitten encrypted password privilege 0 8fLfC1TTV35zytjA
username gwhitten attributes
VPN-group-policy blueV
rparker encrypted FnbvAdOZxk4r40E5 privilege 15 password username
attributes of username rparker
VPN-group-policy blueV
username mhale encrypted password privilege 0 2reWKpsLC5em3o1P
username mhale attributes
VPN-group-policy blueV
VpnUser2 SlHbkDWqPQLgylxJ encrypted privilege 0 username password
username VpnUser2 attributes
VPN-group-policy blueV
Vpnuser3 R6zHxBM9chjqBPHl encrypted privilege 0 username password
username Vpnuser3 attributes
VPN-group-policy blueV
username VpnUser1 encrypted password privilege 0 mLHXwxsjJEIziFgb
username VpnUser1 attributes
VPN-group-policy blueV
username dcoletto encrypted password privilege 0 g53yRiEqpcYkSyYS
username dcoletto attributes
VPN-group-policy blueV
username, password jmcleod aSV6RHsq7Wn/YJ7X encrypted privilege 0
username jmcleod attributes
VPN-group-policy blueV
rhanna encrypted Pd3E3vqnGmV84Ds2 privilege 15 password username
rhanna attributes username
VPN-group-policy blueV
username rheimann encrypted password privilege 0 tHH5ZYDXJ0qKyxnk
username rheimann attributes
VPN-group-policy blueV
username jwoosley encrypted password privilege 0 yBOc8ubzzbeBXmuo
username jwoosley attributes
VPN-group-policy blueV
2DBQVSUbfTBuxC8u encrypted password privilege 0 kdavis username
kdavis username attributes
VPN-group-policy blueV
username mbell encrypted password privilege 0 adskOOsnVPnw6eJD
username mbell attributes
VPN-group-policy blueV
bmiller dpqK9cKk50J7TuPN encrypted password privilege 0 username
bmiller username attributes
VPN-group-policy blueV
type tunnel-group blueV remote access
tunnel-group blueV General-attributes
address VPN2 pool
authentication-server-group blueVec
Group Policy - by default-blueV_1
blueV group of tunnel ipsec-attributes
IKEv1 pre-shablue-key *.
!
class-map inspection_default
match default-inspection-traffic
!
!
type of policy-card inspect dns preset_dns_map
parameters
maximum message length automatic of customer
message-length maximum 512
Policy-map global_policy
class inspection_default
inspect the preset_dns_map dns
inspect the ftp
inspect h323 h225
inspect the h323 ras
inspect the rsh
inspect the rtsp
inspect esmtp
inspect sqlnet
inspect the skinny
inspect sunrpc
inspect xdmcp
inspect the sip
inspect the netbios
inspect the tftp
Review the ip options
!
global service-policy global_policy
context of prompt hostname
call-home
Profile of CiscoTAC-1
no active account
http https://tools.cisco.com/its/service/oddce/services/DDCEService destination address
email address of destination [email protected] / * /
destination-mode http transport
Subscribe to alert-group diagnosis
Subscribe to alert-group environment
Subscribe to alert-group monthly periodic inventory
monthly periodicals to subscribe to alert-group configuration
daily periodic subscribe to alert-group telemetry
HPM topN enable
Cryptochecksum:2491a825fb8a81439a6c80288f33818e
: end
Any help is appreciated!
-Roger
Hey,.
Unfortunately, I do not use ASDM myself but will always mention things that could be done.
You do not split tunneling. All traffic either tunnel to the ASA, while VPN is active
You have the following line under the "group policy"
Split-tunnel-policy tunnelspecified
You will also need this line
Split-tunnel-network-list value
Defines the destination for the VPN Client networks. If you go in on the side of the ASDM group policy settings, you should see that no ACL is selected. You don't really seem to have an ACL in the configuration above, for the split tunneling?
To activate access Internet via the VPN Client now in the current configuration, I would say the following configuration of NAT
VPN-CLIENT-PAT-SOURCE network object-group
object-network 172.17.200.0 255.255.255.0
NAT (outside, outdoor) automatic interface after dynamic source VPN-CLIENT-PAT-SOURCE
In regards to the traffic does not for other networks, I'm not really sure. I guess they aren't hitting the rule NAT that are configured. I think they should, but I guess they aren't because its does not work
I could myself try the following configuration of NAT
object-group, network LAN-NETWORKS
object-network 10.2.0.0 255.255.255.0
object-network 10.3.0.0 255.255.255.128
object-network 10.10.10.0 255.255.255.0
object-network 172.17.100.0 255.255.255.0
object-network 172.18.1.0 255.255.255.0
object-network 192.168.1.0 255.255.255.0
object-network 192.168.11.0 255.255.255.0
object-network 192.168.30.0 255.255.255.0
object-group, network VPN-POOL
object-network 172.17.200.0 255.255.255.0
NAT (inside, outside) static static source of destination LAN-LAN-NETWORK VPN-VPN-POOL
Add ICMP ICMP Inspection
Policy-map global_policy
class inspection_default
inspect the icmp
or alternatively
fixup protocol icmp
This will allow automatically response to ICMP echo messages pass through the firewall. I assume that they are is blocked by the firewall now since you did not previously enable ICMP Inspection.
-Jouni
-
I had many problems with Adobe Pro CC...
Greetings,
First off I do let's plays on Youtube. I use the saved game, face cam and audio (face cam and audio are recorded separately, web cam, then using Audacity with the microphone of the cam turns off).
Question 1: most of the videos I've done here lately had synchronization problems. Whenever I have 'trim' or cut the timeline to take coins to up the cam audio / face mismatch. I'm always cut 5-14 frames of audio so that it can synchronize to the top. I have to repeat this process several times throughout most of the projects now.
Question 2: Audio during the manual move through the timeline. I rely on this to hear "synchronization of Clap" so I know not if the cam audio / face is well aligned. It stopped randomly a week ago.Question No. 3: the audio stops at random all by listening to the recording in Adobe first CC.
Question 4: The video/audio for all randomly gets choppy when editing. Also, it started about 2 weeks ago.
Issue 5: Stream (seen during your editing) randomly empties in some sections of the sequence. I have to reboot the first CC to be able to see it.Please note, when sync problems are fixed there are virtually no problems with the video once it's over. However, all these problems collectively transform quick projects into nightmares of 2-3 hours.
Help?
Sync sounds like a problem of VFR... the video is VFR, and audio is NOT recorded VFR. Harley posted a few days that you can right-click on a clip and turn on interpolation, which corrects a good part of video problems... but... the audio synchronization could still be wobbly.
Download MediaInfo, drag an item to the program, switch to the view of the tree and see what it says on your video stream... codec, CFR/VFR, that sort of thing.
Media Info: https://mediaarea.net/en/MediaInfo
Neil
Maybe you are looking for
-
The Norton Toolbar is missing again in Firefox 18. How can this be corrected?
-
How can I deactivate heart rate monitor
I want to register my pace heart health App via the data of my cup of BP... I don't want no other heart rate data. How can I turn off the monitor watch heart where it generates no data in the application of health on my iPhone?
-
can I put UPS on Dell Optiplex 3020 box top
can I put UPS on Dell Optiplex 3020 box top? is it ok for the health of my case? wight of the inverter can be a round 10-15 KG?
-
Hi I had lost a receipt for October 17, 2013 that we could recover from Adobe however on the same date the same amount had been caught twice.I got 1 and it is very good but we need a refund on the second.Case 0218208111 of what we worked on.I sent th
-
Can I export files WebM and OGG from adobe media encoder?
Are there 3rd party plugins that are available? That actually work?