Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Search results for query: *

  1. Staticfactory

    Packet loss over IPSEC L2L tunnel

    Thanks for your reply Richard... that would certainly be a good place to look if we were running QoS on either of the ASAs in question. I was also thinking that it could be related to MTU but it's an issue that just started to appear across the entire subnet. Fortunately for me, the issue...
  2. Staticfactory

    Packet loss over IPSEC L2L tunnel

    I have an L2L Tunnel between an ASA5540 and an ASA5505 that has been working correctly for months. No updates have taken place, but I'm now seeing about 50% packet loss between the sites. The isakmp/ipsec tunnels are active and are not displaying any errors/drops/discards. I don't see any...
  3. Staticfactory

    4948s reboot themselves

    We wondered if maybe it was an overflow issue but can't find anything that would lead us to believe it, or indicate the source of the problem. The only thing that these switches have in common besides being 4948s is that they are all server switches, and it's most HP servers behind them (but not...
  4. Staticfactory

    4948s reboot themselves

    Wish I could, but we don't have TAC support on these switches (or I wouldn't be bugging you guys) ;) Wasn't my idea to not have the coverage either...
  5. Staticfactory

    4948s reboot themselves

    No, they reboot at different intervals, usually a few weeks to a few months apart. They are also plugged into different rack power strips on one massive UPS (along with other switch models that have no odd behavior). Just doing some investigating and it appears to create a dump, but I'm not...
  6. Staticfactory

    4948s reboot themselves

    Thanks for the reply brianinms -- definitely a good place to start. We have a group of about 16 switches that are attached to the same UPS and (so far) it's only the 4948-10GEs that reboot themselves at seemingly random intervals. Solarwinds would also report the node as down/up in the case of...
  7. Staticfactory

    4948s reboot themselves

    We're encountering a very strange problem with Catalyst 4948-10GE switches that are rebooting themselves without cause (that we can find). Nothing appears in syslog or any other error logs but Solarwinds does see them reboot and the uptime reflects the reboot as well. Has anyone ever had this...
  8. Staticfactory

    No IKE Phase 2 between ASA 5540 and VPN 3002 device

    It's landing on the DefaultL2LGroup when it establishes IKE phase 1 (and it appears to like the pre-shared keys) so I'm a little confused.
  9. Staticfactory

    No IKE Phase 2 between ASA 5540 and VPN 3002 device

    I should also mention that I'm not even sure if the 3002 is capable of tunneling L2L... we had it connect correctly using an RA configuration.
  10. Staticfactory

    crypto isakmp nat-traversal 120

    The NAT Bindings for the tunnel (should there be a NAT device between the 2 end-points) in order to successfully traverse the NAT.
  11. Staticfactory

    No IKE Phase 2 between ASA 5540 and VPN 3002 device

    We are trying to get an old Cisco 3002 hardware VPN client to connect site-to-site with our central ASA5540 running the latest IOS version. The client and the ASA successfully complete the IKE Phase 1 negotiations using a pre-shared key, but then the VPN device appears to stop responding and...
  12. Staticfactory

    VPN though ASA5505 can not see other computers within the network or w

    I've had issues when my local ip pool subnet overlaps with the inside subnet. Try using 192.168.2.xxx instead.
  13. Staticfactory

    NAT Translation error 305005

    By scrubbed config, he means to put X's in place of the middle 2 octets of any public addresses in your config, thus eliminating any security concerns. Without being able to see the entire configuration it's often very difficult to pin-point configuration issues.
  14. Staticfactory

    OWA

    OWA as in Outlook Web Access? What kind of "performance optimization" are you looking for?
  15. Staticfactory

    Setting up VPN on ASA 5505

    You need to use the tunnel-group name and associated pre-shared key as the "Group Authentication" information in the Cisco VPN client. Once you connect to the host using this information, it should prompt you for the local username and password that you configured.
  16. Staticfactory

    ASA5540 - Deny reverse path check

    The host addresses have started to change dynamically as we set up blocking rules, so we've deduced that a host somewhere has been compromised and is creating the spoofed traffic. Thanks for your help.
  17. Staticfactory

    ASA5540 - Deny reverse path check

    Thanks for your reply unclerico. The problem is that I can't, for the life of me, find the source of this traffic. The core switch does not contain ANY ARP information regarding any of the addresses in question, nor is there anything in the mac address table to trace back. I don't even know...
  18. Staticfactory

    ASA5540 - Deny reverse path check

    I could really use your help as I'm still fairly wet behind the ears when it comes to this sort of thing. Our ASA has been flooded with "Deny reverse path check" drops and I can't figure out for the life of me how to find the culprit. I'll elaborate... first, here is an example from the ASA...
  19. Staticfactory

    ASA 5510 - Basic Config

    http://www.cisco.com/en/US/docs/security/asa/asa80/release/notes/arn804n.html Check out the "New Features" and open/resolved caveats section.
  20. Staticfactory

    ASA5505 dual-ISP (redundancy) question

    I have an ASA5505 to which I would like to add a redundant (backup) ISP link. It is currently a simple inside/outside configuration (no DMZ required). From what I have been able to find so far, it appears that I will need to upgrade from the base license to the security-plus license in...

Part and Inventory Search

Back
Top