Greetings..
Looking for some help here. I have the trial of Forefront TMG setup on a server and things are going great. I am having a slight issue with a Web Access Policy which I created. I will start by telling you this is a single adapter template setup. All private IP's are considered...
Burt-
Appreciate you config. I must admit, i am th eone that is blind. I did not issue these two commands..
aaa authorization network groupauthor local
crypto map vpn isakmp authorization list groupauthor
Once I put this in my config, phase 1 and phase 2 complete and establisd a VPN...
Burt-
Thanks for your replay. my vpnlist is on the first line above...
aaa authentication login vpnlist local
This is my list which shold query the local user database.
Frank
I have been staring at this config now for the better part of the night an into this morning. I have ran all the basic debugs and my config is failing on phase 1. I have included the config on the router for the VPN clients. Can some one tell me what I am missing.
Thanks
Frank
aaa new-model...
There is.
We need to see some configs to get the ball rolling, so if you don't mind paste way. Feel free to take out important public IP addresses and things you deem a security risk.
Frank
I have a four farm Citrix Presentation server set up. i am able to shadow using the Administrator account via Access Management Console and the Shadow Taskbar. I have set a group of Non-Admin Shadowers which are in a Active Directory Global Group. I then; using Presentation Server Console...
Have you taken a look at the new ASA 5500 series platform? These are really sweet and IMHO are better that the PIX firewalls because of the many intergartion that can added. The Pix 520 is end of life and is locked in at OS 6.3(4) while the news pix's will do versions 7.
Frank
My ISA 2006 box is a backend FW with a Cisco ASA 5510 as the FrontEnd. After following Thomas's article, I hooked up a PC in the DMZ and tried to access my OWA address and was greeted with the Page Cannot Be Displayed; Error Code: 403 Forbidden (12202). I tried running some diags and looked at...
Binh-
I think I might see what the problem might be. I also agree with FWATER; After looking over this in greater detail and comparing my cnig. If you look at this statement on your second PIX.
nat (inside) 0 0.0.0.0 0.0.0.0 0 0 I believe it should be
nat (inside) 1 0.0.0.0 0.0.0.0 0 0...
Binh-
To the naked eye, your config looks fine.
Try adding this to the end of your command... no-xauth no-config-mode.
isakmp key ******** address 192.168.1.18 netmask 255.255.255.255 no-xauth no-config-mode on both pix's.
Also have you enabled your debugs?
Try debug crypto isakmp first...
Issue the command
sh isakmp sa
This will show you what IP is currently VPNed into your PIX.
Then do a sh ip local pool to see which IP addresses you have assigned out to them. (this is provided that you are using local pools)
Frank
Djess-
Yes you can accomplish this. At least you will be able to have the iSCSI HBA see the iSCSI lun. I can assist you with this. I am using the IBM Bladecenter H with HS21 to SAN boot to a Celerra NS502 with a Clarion Backend.
The problem I am runnng into is the Bladcenter Chassis does...
Has anyone encountered this particualr error when trying to connect to a valid Windows 2003 Terminal Server with licenses?
"the remote computer disconnected the session because of an error in the licensing protocol"
I have ran through several tips and troubleshooting methods from Microsoft and...
Ok I am having a issue that i am trying to get resolved. I am trying to get the Replication manager to work with my Celerra 502 system we have. I have follwed the quick start pamplet that I received. I have installed Solutions Enabler 6.3, I have installed RM/SE 3.1.0 with the patch to get me...
Ok I have configured my FE Exchange 2003 server and configured it to use SSL with FBA(Forms based Authentication). When I type in the URL of https://<server name>/exchange, it prompts me to accept the security certificate and proceeds to bring up the FBA page. I then login, but I do not get my...
I would like to do a semi in-place upgrade to Exchange 2003 from Exchange 2000. What I mean by semi in-place is the following:
I just installed a second exchange 2000 server on a Windows 2K server wSP4 and SP3 for exchange. I have moved one mailbox (mines) to the new server successfully. My...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.