Thats the hard part. It is already dual homed and in operation. The other switch port it is homed to looks exactly the same. I did a SPAN and captured 700Mb of traffic and its all SMTP and associated plus management traffic. There are a lot of out of sequence packets and packet fragments if that...
Thanks. here it is.
sh access-lists 115
Extended IP access list 115
10 deny tcp any any eq 4444 (540 matches)
20 deny tcp any eq 4444 any (8069 matches)
30 deny udp any any eq 4444 (126 matches)
40 deny udp any eq 4444 any (739 matches)
50 deny udp any any eq 1434 (136...
Hi
I installed the Secure Remote client on my laptop for work but have had to uninstall it as it stopped me being able to browse by screwing up the DNS. This was without the VPN connected! I am told this is a bug and there is a fix. Does anyone know it?
The client was SC_NGX_R60_HFA2_630000044...
#sh int vlan 150
Vlan150 is up, line protocol is up
Hardware is EtherSVI, address is 0011.bc9c.2800 (bia 0011.bc9c.2800)
Description: Exchange Server LAN
Internet address is x.x.x.x/24
MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec,
reliability 255/255, txload 1/255, rxload 2/255...
I applied the accounting to the VLAN interface:
#sh int mac-accounting
Vlan150 Exchange Server LAN
Output (510 free)
0100.5e00.000d(82 ): 8 packets, 960 bytes, last: 26344ms ago
0100.5e00.0002(93 ): 82 packets, 9348 bytes, last: 924ms ago
Total: 90 packets...
Hi
The output from the switching is below, but it does not support ip accounting. The last line is a bit odd though so I have pasted the interface output again below
sh int fast 4/29 switching
FastEthernet4/29 DTCSMSXB01
Throttle count 0
Drops RP 0...
Hi
There is a single acl to prevent TCP or UDP 4444/4434 but it doesn't seem like there are enough hits to warrant the number of drops. Since I cleared the acl counters yesterday there are roughly 520 matches here but (see below) drops:
Extended IP access list 115
10 deny tcp any any eq...
Here is the show run for that interface:
interface FastEthernet4/29
description *********
no ip address
switchport
switchport access vlan 150
no cdp enable
end
The server is Exchange and it is patched directly in.
Thanks
Hi
I have an issue with a server uplink on a Catalyst 6500. The Output Drops are incrementing yet I have no other interface errors. I have used SPAN and wireshark to look for excess broadcast etc but found nothing but general SMTP traffic etc.
Interface Output is below:
FastEthernet4/29 is...
Thanks for that. It was a stupid mistake that was causing the traffic to the DMZ from outside to fail. The DMZ security level was 0........... I typed part of the config sample and ASSumed I had set the DMZ to 50.
I have a problem with basic access through an ASA 5505 SEC bundle with DMZ enabled. The symptoms are:
ssh to 10.10.10.83 works to 192.168.50.1 inside
1433 from 192.168.50.129 dmz works to 192.168.50.1 inside
ssh and 80 to 10.10.10.82 denied 192.168.50.129 dmz
I cannot see why. Am I missing the...
Hi
I have a request to allow SSH through an ASA to an internal server.
I already have ssh management access configured with;
aaa authentication ssh console LOCAL
and
ssh permit 0.0.0.0 0.0.0.0 outside
Which works.
If I add an access-list and static to allow ssh through the firewall to...
You If you ping from one LAN to the other and debug crypto isa and debug crypto ipsec, what does the output tell us? Could you post it?
Without the VPN configs from each end it is hard to tell but if you cannot ping from LAN IP to LAN IP, the tunnel is not configured correctly.
That's interesting. I have only ever used it as layer three interfaces, but want to extend VLANs via this sort of setup. What is the maximum it can run over ethernet using two wires? I'm looking at using it to extend ethernet over 100 metres.
I have connected two SDSL routers back-to-back to extend an ethernet link in the past successfully. I wondered if anyone has bridged this type of connection in order to preserve VLANs over it?
Hi
I have a watchguard that I cannot get conneected to on the GUI. It has developed a strange problem where the web interface that worked previously does not work any longer either. It is still passing traffic but needs some new services adding. If I connect a console cable will it be possible...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.