RE: Default Gateway and Ip Default Network [7:42099]

2002-04-21 Thread Rick Foster
GOL is the last resort tried by the router to send packets bound for unknown destinations. default network command, specifies the network (e.g. the ISP's network) to which the un-known destination packets will be forwarded to. This is particularly useful when you move frequently, but have a well

Static NAT with HSRP - longish [7:41036]

2002-04-10 Thread Rick Foster
Hi all, We have 6509 with Dual Sup1A and dual MSFC/PFC. Sup1A is running CatOS ver 5.5(6a) and MSFC is running IOS ver 12.0(3)XE2. These dual engines have been configured for "high availability" and "config redundancy". Multiple vlan interfaces have been configured on the MSFC. HSRP configuratio

ISDN problems in IOS 12.1(5)T10 [7:37782]

2002-03-10 Thread Rick Foster
Hi all, Have faced some weird problems when working with 4 port BRI module in 3662 router. The 3662 router has 12.1(5)T10 IP Plus IOS. Some of the problems faced are as under : The "dialer idle-timeout" on dialer interfaces does not work. The connections (ppp multilink bundle) are disconnected

RE: Least cost router to run BGP (partial or Full) [7:32397]

2002-01-21 Thread Rick Foster
I think u are looking for the NM-4T module that will fit into your WIC-1T. However this module is only supported on 36xx series routers. If the 26xx routers have two slots, you could use 2 numbers of WIC2T to get a max of 8Mbps, with a dual Ethernet ports in 2651. HTH... Message Posted at: htt

Protocol based vlan [7:31870]

2002-01-14 Thread Rick Foster
Hi, Can someone help with configuring protocol based vlans on a 6000/6500 switch. Currently we have configured these subnet based vlans using: Created 2 vlan interfaces (vlan1 and vlan2) on the MSFC and assigned different subnets to each vlan interface. Then individually assigned ports 2/1-48 t

exec timeout in dual MSFC config [7:26102]

2001-11-13 Thread Rick Foster
We have a 6500 with dual SUP-1A's with each having MSFC. The MSFC's are configured in redundant mode. Thus the configuration can be changed on only one of the MSFC's. There is a unique problem being faced with such a config. The vty 0 4 configuration is as follows: line vty 0 4 session-timeout 5

MSCEP without anonymous access [7:20235]

2001-09-17 Thread Rick Foster
Hi all, I am sure many of you must have deployed MSCEP for automatic certificate enrollment for PIX/VPN installations. We have a 3015 VPN and are using Win2K-CA for certificate enrollment. MSCEP (cesetup.exe) is installed on the Certificate server and when using Cisco VPN client (3.0.3 or 3.1) a

RE: VPN certificate [7:16759]

2001-09-02 Thread Rick Foster
What version of VPN Concentrator S/W and VPN client software are u using. Are u connecting from behind a NAT device, or is your VPN situated behind the firewall. I am facing a similar problem when connecting using certificates. With similar errors : on client : Remote peer not responding. On VPN c

IPSec-over-NAT [7:18224]

2001-09-02 Thread Rick Foster
Hi all, We are using Cisco VPN 3015 concentrator with 3.0.3.3des software and a 3.0.3B Cisco VPN client. We have a NAT device (1600 router with NAT) between the VPN client and the VPN concentrator. If I use preshared keys and with IPSec-over-NAT enabled, I am able to connect to the VPN concentrato

Re: ip default-network [7:16507]

2001-08-20 Thread Rick Foster
How is this different from configuring two different default routes for the same network e.g. ip route 10.0.0.0 255.0.0.0 202.33.22.11 ip route 10.0.0.0 255.0.0.0 203.44.33.22 ip route 10.0.0.0 255.0.0.0 204.55.44.33 Regards ... Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=1

VPN 3000 using certificates [7:16172]

2001-08-15 Thread Rick Foster
When using Digital certificates for authentication I am facing problems if the vpn3000 internal user database is used for extended authentication. If an internal user is created and if that user does not belong to the VPNC_base_group then the extended authentication fails. i.e. if a new group is

multicast on 8540 BVI interfaces [7:16136]

2001-08-15 Thread Rick Foster
We have 8540 CSR sitting at the core of our network. Three 5500 switches connect to it via gig uplinks. We have three different IP subnets and all the three 5500's have users from all these three subnets. Due to this we had to configure BVI on the 8540 and make the interfaces connecting to each o