thought I had it down pat, but still seem to be missing something when using a different subnet of addresses for my RAS clients ---
Useful info - - - - - - - - - - - - - - - - - - - - - - - - -
Internal network is 10.9.2.0 /23 - the custom mask allows addresses 10.9.2.1 - 10.9.3.255 to be on...
just curious what the industry "best practices" was in regards to using Perfect Forward Secrecy. I notice a lot of other security devices ship with it enabled by default (and I understand that the reissuing of the DH keys everytime a new tunnel is established is more secure), but was just...
client asked me to setup a site to site tunnel between 3 sites (Sites A, B and C)
Site A has a Cisco ASA 5510
Site B has a Cisco ASA 5505
Site C has a Juniper Netscreen 50
I was responsible for Sites A and B and another consultant took care of the Netscreen. The L2L tunnel between my 5510 and...
I've been going through the ISA Server 2004 documentation, but can't seem to find out if this is possible.
What I would like to do is have an external user be able to type a url like http://crm.company.com and have that http request be directed to the ISA server. I would then like the ISA...
my company has been tasked with colocating a couple of other company's servers for a few months.
- We currently have a two separate links to the internet (microwave and cable). The microwave is our company's main line to the internet with cable used for backup.
- We would like to use one...
quick info ---
ASA 5510 running 7.2(2)
internal interface assigned 192.168.72.1
- one lan to lan tunnel connecting to remote address of 172.17.1.x
- the remote access config hands out addresses of 172.16.1.1 through 172.16.1.254
Remote Access VPNs (172.16.1.x) were working fine until I setup...
Hello all,
question - is there an issue with having an exchange server use two separate ip addresses (specifically in regards to OWA)?
the problem is that I can't enable forms based authentication at all. I've done it on about 10 other production servers without any issue, but on this...
My company has two separate broadband lines to different ISPs. I was originally going to use a 5505 for the backup line and a 5510 for the main line. My boss asked if there was a way to connect both lines to one device and have that device keep the two ISP networks separate. This made me think...
hello.
Configured my asa using the Remote Access vpn wizard. Was working fine, but stopped working recently (may have to do with some static tunnels I created using older pix commands.)
I enabled debug crypto isakmp and ipsec -
When I connect using the cisco vpn client, the monitor shows that...
hello.
I have isa server at the perimeter. It's external interface has a block of addresses from 66.x.x.210 through 66.x.x.215
66.x.x.210 is the first address assigned to the external interface so that this is the address used by all internal clients when they are accessing resources on the...
Hello all.
just curious, I have a Windows 2003 Server with two built in nics. I would love to be able to distribute the load between the two nics and thought that that was what the built in load balancing service does. But upon reading some white papers, it looks like this build in load...
just curious, but do you need a mirror image of acl (that permits ip traffic to the local network) on each pix. I have a site to site tunnel between two pixes.
On my side I have a group of developers that need to have rdp access to servers on another company's network. The other company doesn't...
probably a basic question -
lets say you have 3 sites - A,B,C - all using a pix
C serves as the central site
Both A and B connect to C via site to site tunnels.
Is it possible for to configure these tunnels so that A can now access resources at B (and vice versa) via the tunnels that they have...
I am looking to setup about 30 pix site to site vpn tunnels for a client all coming back to his main office's pix 515e. He wants some sort of centralized tool to monitor and manage all of the pixes - stuff like health statistics, reconfigs, fos upgrades etc. all done remotely. He did some...
this is probably more of a basic tcp/ip question, but I have gotten a couple of different answers. Essentially, I just saw a pix 515e, the outside interface has an ip address from the isp, the inside interface has an address of
10.0.10.3/8 The thing that throws me off is that the rest of the...
hello. I am in the process of setting up a bunch of remote sites with pix 501s to create site to site vpn tunnels back to my main office's 515e. Because each site will have about 5 computer users I was thinking of getting the 501 with the 10-user license. My question is, will this be enough to...
Hello all. I have a client and during a brief discussion, I found out that they have multiple remote sites that are connected to the internet via dsl or cable. At these sites, the users are using either Outlook 2k, xp or 2k3. They connect back to their exchange server directly over the internet...
Hello all,
I am working for a group of developers. I have created an OU structure in AD that has all of the developers and their workstations under it. Under the developers OU there is an OU called computers - and underneath computers are two OUs - desktops and servers. I would like to give one...
hello all,
I am in the process of migrating all my groupwise users (ver 6) to exchange 2003. All users will be using Outlook 2003. The migration is going fine, but was wondering if anyone had come up with a solution (script or otherwise)to automate the process of importing the users calendar...
hello all. I am trying to get our windows mobile 5 handheld devices to connect to our exchange 2003 server using imap over ssl. In trying to find which certificate to install on the handheld, i installed about 3, but now realized they may have been the wrong certificates. Is there a way to...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.