Well , it is a simple task like others said , using IOS IPsec features as long as your IOS image has a ***K9** version. Your current ios version support it. You could use IPSEC site-to-site using pre-shared-key method or use digital certificate method. For not disturbing your live traffic you could simulate using Dynampis or GNS3 emulator first and then apply the config to the real router. But don`t forget it will increase a little bit of your router CPU and Memory consumption after apply the ipsec.
rgrds
CSA
mwapetech <mwapetech@...> wrote:
I have two Cisco Routers model C2851 with IOS c2800nm-ipvoicek9-mz.124-3g. These two routers are acting as peer routers between a Fiber WAN link. I would like to encrypt data between my two private networks that are behind these two routers, without using a Certificate Authority (CA). Anyone with configuration or idea of how to go about it.
it is really easy.. chec on cisco.com how to do that..
basically you have to say.. this is my preshared key.. and crypto map,
this is my interesting traffic (ACL)
and this is where my VPN starts and this is what im looking for int the net. (forming Tunnel inrefaces)
then taran you have your super VPN.. haa.. you need to have a "K" on your IOS name to do that VPN.
--- El vie 30-may-08, mwapetech <mwapetech@...> escribió:
De:: mwapetech <mwapetech@...> Asunto: [Cisco_CCIE_Lab] Data Encryption Between Peer Routers. A: Cisco_CCIE_Lab@yahoogroups.com Fecha: viernes, 30 mayo, 2008, 3:22 am
I have two Cisco Routers model C2851 with IOS c2800nm-ipvoicek9- mz.124-3g. These two routers are acting as peer routers between a Fiber WAN link. I would like to encrypt data between my two private networks that are behind these two routers, without using a Certificate Authority (CA). Anyone with configuration or idea of how to go about it.
You can configure IPSec Tunnel between two routers..........
Kashif
mwapetech <mwapetech@...> wrote:
I have two Cisco Routers model C2851 with IOS c2800nm-ipvoicek9-mz.124-3g. These two routers are acting as peer routers between a Fiber WAN link. I would like to encrypt data between my two private networks that are behind these two routers, without using a Certificate Authority (CA). Anyone with configuration or idea of how to go about it.
DM.
I AM NOT THE BEST
BUT I AM NOT LIKE REST
!! KASHIF.....
From Chandigarh to Chennai - find friends all over India. Click here.
I have two Cisco Routers model C2851 with IOS
c2800nm-ipvoicek9-mz.124-3g. These two routers are acting as peer
routers between a Fiber WAN link. I would like to encrypt data between
my two private networks that are behind these two routers, without
using a Certificate Authority (CA). Anyone with configuration or
idea of how to go about it.
DM.
We had the same issue before in our network as well.
After a long struggle , we moved to another solution,
bought a new L4 foundry switches and connected the
cache to redirect the web traffic ..
try with the newer IOS...best of luck.
regards,
sakthi
--- Nasser Heidari <blackhat_hk@...> wrote:
> Hi all,
>
> Recently I configured a 6500 with SUP-720 for
> transparent web caching
> with IP Spoofing. The configuration was quite
> simple.
> The idea behind IP Spoof enabled cache is to
> redirect both send and
> receive traffic to web cache and the box will spoof
> the source ip of
> the original user requesting the page. you have to
> do the following tasks:
>
> 1- Set 2 WCCP general configuration one with "ip
> wccp web-cache" and
> the other with "ip wccp 95"
> 2- On the VLAN/L3 Port facing the Internet you have
> to set "ip wccp
> web-cache redirect out" to redirect outbound
> connections to web cache.
> 3- On the VLAN/L3 Port facing cache interface you
> have to set "ip wccp
> redirect exclude in" to exclude web cache traffic
> itself.
> 4- On the VLAN/L3 Port facing users you have to set
> "ip wccp 95
> redirect out" to redirect incoming traffic (web
> responses to cache).
>
> but when i redirect all users traffic to the web
> cache the
> 6500 with the golden sup720 explode with %100 cpu
> usage and the box
> starts to drop traffic!
> I've done so many tests with different modular / non
> modular IOS of
> different versions but no success. As i searched the
> command reference
> for the 12.2 IOS I've noticed that using WCCP
> requires full and
> interface-full mls flow configuration I've done it
> as well but again
> no success. Generally something like 250mbps traffic
> passes this 6500
> but I've tested even with 100mbps and still IP INPUT
> process (or
> ios-base process in modular IOS) eat up all the CPU.
> Another point
> that may help is that using WCCP without IP spoof
> (just "ip wccp
> web-cache" command) only takes %15 of CPU handling
> 150mbps traffic.
> Other configuration regarding cache is that it's
> using version 2, GRE
> for Assignment Method and Layer 2 for Forwarding
> Method and no WCCP
> password is in place. There is an "accelerated"
> keyword for wccp but
> it seems it works only with WCCP version 1. I've
> seen some comments
> regarding high CPU utilization on 6500 but all of
> them state that it's
> been fixed before 12.2(18)SXD4
>
(http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/catos/8.x/configurati\
on/guide/msfc_ios.html).
> i've tested the following IOS:
> s72033-adventerprisek9_wan-mz.122-33.SXH.bin
> s72033-adventerprisek9_wan-vz.122-33.SXH.bin
> s72033-advipservicesk9_wan-mz.122-18.SXF12.bin
> which are the latest available.
>
> Does any one has any idea???
>
> ----------
> users ---->| 6500 |-----> Internet
> ----||----
> / \
> / \
> cache1 cache2
>
>
Do Something Usefully,That Something Will Help You To Get Some useful Thing
Atlast.
Regards,
V.Sakthi Vadivel Velumani ,
________________________________________________________________________________\
____
Be a better friend, newshound, and
know-it-all with Yahoo! Mobile. Try it now.
http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ
Man , if you configure Two HSRP group in two router and make failover one-to-another so both links will be active and failover to each other just the diffrence you will have two or more vlan inside.
:)
----- Original Message ---- From: Adrian Lopez <lomadrian@...> To: Cisco_CCIE_Lab@yahoogroups.com Sent: Tuesday, May 6, 2008 4:14:18 PM Subject: Re: [Cisco_CCIE_Lab] ADSL or DSL load balance
Traffic engeenering. noooo!!!
all seems too easy until apears that word in MPLS and BGP.
you can use both if you have two or more VLAN, depend on your network design :) and how you configured your routers
Regards,
----- Original Message ---- From: Adrian Lopez <lomadrian@yahoo. com.mx> To: Cisco_CCIE_Lab@ yahoogroups. com Sent: Monday, May 5, 2008 12:23:26 AM Subject: Re: [Cisco_CCIE_ Lab] ADSL or DSL load balance
thats a good one..
but use Gateway load balancing instead of HSRP. because HSRP will use one of the 2 Internet links..
Hi all,
Recently I configured a 6500 with SUP-720 for transparent web caching
with IP Spoofing. The configuration was quite simple.
The idea behind IP Spoof enabled cache is to redirect both send and
receive traffic to web cache and the box will spoof the source ip of
the original user requesting the page. you have to do the following tasks:
1- Set 2 WCCP general configuration one with "ip wccp web-cache" and
the other with "ip wccp 95"
2- On the VLAN/L3 Port facing the Internet you have to set "ip wccp
web-cache redirect out" to redirect outbound connections to web cache.
3- On the VLAN/L3 Port facing cache interface you have to set "ip wccp
redirect exclude in" to exclude web cache traffic itself.
4- On the VLAN/L3 Port facing users you have to set "ip wccp 95
redirect out" to redirect incoming traffic (web responses to cache).
but when i redirect all users traffic to the web cache the
6500 with the golden sup720 explode with %100 cpu usage and the box
starts to drop traffic!
I've done so many tests with different modular / non modular IOS of
different versions but no success. As i searched the command reference
for the 12.2 IOS I've noticed that using WCCP requires full and
interface-full mls flow configuration I've done it as well but again
no success. Generally something like 250mbps traffic passes this 6500
but I've tested even with 100mbps and still IP INPUT process (or
ios-base process in modular IOS) eat up all the CPU. Another point
that may help is that using WCCP without IP spoof (just "ip wccp
web-cache" command) only takes %15 of CPU handling 150mbps traffic.
Other configuration regarding cache is that it's using version 2, GRE
for Assignment Method and Layer 2 for Forwarding Method and no WCCP
password is in place. There is an "accelerated" keyword for wccp but
it seems it works only with WCCP version 1. I've seen some comments
regarding high CPU utilization on 6500 but all of them state that it's
been fixed before 12.2(18)SXD4
(http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/catos/8.x/configurati\
on/guide/msfc_ios.html).
i've tested the following IOS:
s72033-adventerprisek9_wan-mz.122-33.SXH.bin
s72033-adventerprisek9_wan-vz.122-33.SXH.bin
s72033-advipservicesk9_wan-mz.122-18.SXF12.bin
which are the latest available.
Does any one has any idea???
----------
users ---->| 6500 |-----> Internet
----||----
/ \
/ \
cache1 cache2
all seems too easy until apears that word in MPLS and BGP.
mehmood moon <mehmood_sajid@...> escribió:
you can use both if you have two or more VLAN, depend on your network design :) and how you configured your routers
Regards,
----- Original Message ---- From: Adrian Lopez <lomadrian@yahoo.com.mx> To: Cisco_CCIE_Lab@yahoogroups.com Sent: Monday, May 5, 2008 12:23:26 AM Subject: Re: [Cisco_CCIE_Lab] ADSL or DSL load balance
thats a good one..
but use Gateway load balancing instead of HSRP. because HSRP will use one of the 2 Internet links..
you can use both if you have two or more VLAN, depend on your network design :) and how you configured your routers
Regards,
----- Original Message ---- From: Adrian Lopez <lomadrian@...> To: Cisco_CCIE_Lab@yahoogroups.com Sent: Monday, May 5, 2008 12:23:26 AM Subject: Re: [Cisco_CCIE_Lab] ADSL or DSL load balance
thats a good one..
but use Gateway load balancing instead of HSRP. because HSRP will use one of the 2 Internet links..
I was trying to do Layer 2 password recovery on 6509 switch,
1. I power cycled the switch and it rebooted. 2. When it asked for password, i pressed " Enter" 3. When typed enable at console prompt, it asked for password, i pressed " Enter" it keeps asking for password, but i was not able to get int to console(enable) to apply set password and set enablepass
I have also attached password recovery procedure for 6509. Any help is appreciated.
Waiting for your reply,
Shibi
Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now.
Yahoo! Deportes Beta ¡No te pierdas lo último sobre el torneo clausura 2008! Entérate aquí http://deportes. yahoo.com
Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now.
----- Original Message ---- From: Shibi Ali <shibi.alikunju@...> To: Cisco_CCIE_Lab@yahoogroups.com Sent: Friday, May 2, 2008 9:44:21 PM Subject: [Cisco_CCIE_Lab] Layer 2 password recovery on 6509 switch
Hi
I was trying to do Layer 2 password recovery on 6509 switch,
1. I power cycled the switch and it rebooted. 2. When it asked for password, i pressed " Enter" 3. When typed enable at console prompt, it asked for password, i pressed " Enter" it keeps asking for password, but i was not able to get int to console(enable) to apply set password and set enablepass
I have also attached password recovery procedure for 6509. Any help is appreciated.
Waiting for your reply,
Shibi
Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now.
Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now.
----- Original Message ---- From: sneravi <sneravi@...> To: Cisco_CCIE_Lab@yahoogroups.com Sent: Saturday, May 3, 2008 6:04:40 AM Subject: [Cisco_CCIE_Lab] dhcp on ciscco switch
hi all,
is it possible to create dhcp server on cisco 3750 switch?????? if possible tell me the commans!!!!! !!!
thnx Ravi
Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now.
I was trying to do Layer 2 password recovery on 6509 switch,
1. I power cycled the switch and it rebooted. 2. When it asked for password, i pressed " Enter" 3. When typed enable at console prompt, it asked for password, i pressed " Enter" it keeps asking for password, but i was not able to get int to console(enable) to apply set password and set enablepass
I have also attached password recovery procedure for 6509. Any help is appreciated.
Waiting for your reply,
Shibi
Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now.
Yahoo! Deportes Beta ¡No te pierdas lo último sobre el torneo clausura 2008! Entérate aquí http://deportes. yahoo.com
Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now.
I was trying to do Layer 2 password recovery on 6509 switch,
1. I power
cycled the switch and it rebooted. 2. When it asked for password, i pressed " Enter" 3. When typed enable at console prompt, it asked for password, i pressed " Enter" it keeps asking for password, but i was not able to get int to console(enable) to apply set password and set enablepass
I have also attached password recovery procedure for 6509. Any help is appreciated.
Waiting for your reply,
Shibi
Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now.
Yahoo! Deportes Beta ¡No te pierdas lo último sobre el torneo clausura 2008! Entérate aquí http://deportes.yahoo.com
I was trying to do Layer 2 password recovery on 6509 switch,
1. I power cycled the switch and it rebooted. 2. When it asked for password, i pressed " Enter" 3. When typed enable at console prompt, it asked for password, i pressed " Enter" it keeps asking for password, but i was not able to get int to console(enable) to apply set password and set enablepass
I have also attached password recovery procedure for 6509. Any help is appreciated.
Waiting for your reply,
Shibi
Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now.
For Wireless Devices , We should always keep in mind that ,
what exectly we require from the device :
Troughput or Range or both ..
Again we do have Internal & external AP, with Bridge like AP CISCO 1300 Series ,
We also use External Anteena to extends our Coverage area ,i.e
OMNI Directional with different Sizes & DB or YAGI Receiver ,
We also check about POE ,if it is difficult to reach the location .
So choose the device according to your requirment as well as your coverage area.
Cheer
Amit Kumar
ravindra gandhi <r_a_gandhi@...> wrote:
Any Body tell me how to make a Medium SIze HotSpot,and wht is the basic checklist for creating Hotspot,and which minimum device are required for the Same.?
Thanks and Regards
Ravindra A Gandhi
Bollywood, fun, friendship, sports and more. You name it, we have it.
Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now.
Wireless controller (in case of light AP) and Wireless Access Point (go for 802.11 n/b/g) requires that depend on your area which you want to cover.
A Portal Server with Radius/billing if you are going to provide service in a Cafe or public area.
Cisco Systems is the best but other options also there just depend on price
D-Link is having built-in protal server also. Arubanetworks.com is also having very good solution.
Regards,
----- Original Message ---- From: ravindra gandhi <r_a_gandhi@...> To: Cisco_CCIE_Lab@yahoogroups.com Sent: Sunday, April 27, 2008 11:55:55 AM Subject: [Cisco_CCIE_Lab] HotSpot
Any Body tell me how to make a Medium SIze HotSpot,and wht is the basic checklist for creating Hotspot,and which minimum device are required for the Same.?
Thanks and Regards
Ravindra A Gandhi
Bollywood, fun, friendship, sports and more. You name it, we have it.
Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now.
all depends from your site survey. (here the consultatns tell you where you need to place the A.P. and the coverage area of each one.)
and what is the speed an services you want to provide.
ravindra gandhi <r_a_gandhi@...> escribió:
Any Body tell me how to make a Medium SIze HotSpot,and wht is the basic checklist for creating Hotspot,and which minimum device are required for the Same.?
Thanks and
Regards
Ravindra A Gandhi
Bollywood, fun, friendship, sports and more. You name it, we have it.
Yahoo! Deportes Beta ¡No te pierdas lo último sobre el torneo clausura 2008! Entérate aquí http://deportes.yahoo.com
Any Body tell me how to make a Medium SIze HotSpot,and wht is the basic checklist for creating Hotspot,and which minimum device are required for the Same.?
Thanks and Regards
Ravindra A Gandhi
Bollywood, fun, friendship, sports and more. You name it, we have it.
I have call manager 4.0 , internally can make calls. I have 1760 router with 4 FXO ports , 2 Serial ports. Recentally we only change WAN configuration other than any changes.
Now we cant make call Inside to outside PSTN and vis versa.
When i call '9' that hit the router and dial the number cant route to outside. And dial to my PSTN from out some time engage tone with fxo light with green.
Pls guide me , how to trouble shoot this
Be a better friend, newshound, and know-it-all with Yahoo! Mobile. Try it now.