PIX and NAT with VPN

2001-02-15 Thread Rick Holden
I have a PIX firewall that is being used for a VPN as well. The problem is all the inside addresses are being translated to public addresses even when the traffic is destine for the VPN tunnel. I tried the following commands but this seems to block all translations. (real IPs have been replaced fo

Telnet to outside interface on PIX

2001-02-21 Thread Rick Holden
I current setup VPNs with PIXs and have the hardest time getting the VPN to come up. Usually because the person on the other end doesn't have a clue. Security is on a concern until the VPN is up. I heard that it is possible to telnet to a PIX (not through the PIX, [i.e. NAT] because nothing exist

pix nat

2001-03-02 Thread Rick Holden
Can someone please tell me what is wrong with this config access-list nonat permit ip 192.168.1.0 255.255.255.0 192.168.2.0 255.255.255.0 nat (inside) 0 access-list nonat global (outside) 1 172.16.10.50 255.255.255.255 I get no translation at all. I have permit ip any any access lists on both in

CA Server

2001-03-17 Thread Rick Holden
Does anyone know where I can download a certificate server that will work with Cisco routers, PIX and Check Point firewall. I am only looking for a shareware or freeware version. _ FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html

Re: Secondary IP add

2001-03-21 Thread Rick Holden
I use secondary IPs when the IP scheme is changing (192.168.x.x to 172.16.x.x) and I don't want to take the network down. This way I can change the IPs on the PCs and have no disruption in service. Otherwise I would have to change them all at once and until I did change them they would work.

2600 Route Processor

2001-01-07 Thread Rick Holden
I find on Cisco's web page that the 2600 series routers are capable of inter-vlan routing. Does this mean that a 2600 can be used as a route processor for an MLS? Or does it just mean that it can route between vlans because it can has to Ethernet ports? _ FAQ, list

Re: Cisco Secure VPN Client

2001-01-11 Thread Rick Holden
The Cisco VPN client doesn't work with win2k; however, the company that wrote the client software for Cisco also puts out a product call safe-net (www.ire.com) that will work with win2k. It is almost identical to the Cisco client. I believe that it costs 75$ per seat. Cisco isn't coming out with a

switch flow control

2001-01-11 Thread Rick Holden
There is one thing that confuses me about switches. If you have a switch with a 100Mb port and 10Mb port and the 100 starts sending data to the 10 how does the sending station keep from overflowing the buffer on the switch since there in now flow control at layer 2? __

WS-F5521 or WS-X5530-E2

2000-09-27 Thread Rick Holden
Could someone please explain to me the difference between these to cards.   WS-F5521 and WS-X5530-E2 I looked on Cisco's web site but still can't get a clear picture of what the difference is. They both seem to be supervisor card with NFFC, but the WS-F5521 card is alot less expensive. Why s

Cisco VPN book

2000-10-01 Thread Rick Holden
Does anyone know any good books for setting up and configuring Cisco VPNs. Or any other resources.

ubr924

2000-11-04 Thread Rick Holden
I have a cable router that I am trying to get working in my house, but with no success. The problem is the service provider is not giving me an IP address and the IOS doesn't let me assign one. I believe that the service provider wants to assign it based on the hostname, because that how my PC get

IPX on cisco support exam [7:2408]

2001-04-28 Thread Rick Holden
Does, anyone know how much IPX is covered on the support exam? /Rick Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=2408&t=2408 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misc

Queuing over P2P frame-relay [7:2839]

2001-05-01 Thread Rick Holden
I would like to implement priority queuing form a spoke and hub frame-relay network. I would like to know the best way to day this. I want all branches to have the same queuing strategy. There seems to be two way of doing this. I could place the priority-group to the interface, but I am not sure t

VPN Diffie-Hellmen [7:6539]

2001-05-30 Thread Rick Holden
I am a little confused why Diffie-Hellmen's key exchange is needed for IKE. When I setup ISAKMP, regardless of the authentication I am using I need to supple a key weather pre-share, public/private, or RSA sig. If this is the case why can't the two VPN peer just use this key for setting up the VPN

PIX 506 [7:6540]

2001-05-30 Thread Rick Holden
I was told today that the PIX 506 can only support 4 VPN tunnels. It this true and does it include remote access users. I just sold a customer a 506 and he wants to connect 10 salesman to it that have laptop computers. Thanks. Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=65

vpdn pptp [7:7211]

2001-06-04 Thread Rick Holden
I am trying to configure a voluntary VPDN tunnel and am having trouble with the example config I got from Cisco's web page. The example is as follows: vpdn-group 1 ! Default PPTP VPDN group accept-dialin protocol pptp virtual-template 1 local name cisco_pns The problem is with the PROTOCOL

what is spare [7:8443]

2001-06-13 Thread Rick Holden
I have seen many items on Cisco's web page listed a spare with an = sign in the part number. Can some tell me what this means? Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=8443&t=8443 -- FAQ, list archives, and subscription in

Re: RADIUS solution [7:8640]

2001-06-14 Thread Rick Holden
I have used one called radtac. It works good for me, but I only use it for very simple configs and don't really hit it vary hard, so I can't say much more about it. You can get a full trial version off their web sight that is good for 30 day. (www.radtac.com) /Rick - Original Message - Fro

PIX 506 [7:8799]

2001-06-15 Thread Rick Holden
I have been using the PIX 506 and have had hardware problems. The unit seems to loose power. The fan stays spinning, but all the LEDs go out and it doesn't function. When it is turned off and back it works for anywhere for 10 to 5 hours, then needs to be power cycled again. I have had this problem

IP Phones [7:8898]

2001-06-17 Thread Rick Holden
I am looking to pass the Cisco IP Telephony and the CVOICE exams. I would like to get a hold of some cheap IP Phone for IP Telephony. Does anyone know where I can get them. I am not interested in quality, just something to test and study with. Thanks. /Rick Message Posted at: http://www.groups

1750 with VIC [7:14102]

2001-07-29 Thread Rick Holden
I am having problems telling whether my VIC cards are working in my 1750 router. After the router powers up I see two amber LEDs that never go out. I don't know if they are suppose to stay on or not. I issue the "show voice port" command and I don't see any cards. I also try the global configurati

Cisco Call Manager [7:15402]

2001-08-08 Thread Rick Holden
I am looking to pass the CIPT exam and would like to get a copy of Call Manager. Does anyone know where I can get a copy or maybe a shareware voice or an eval? Thanks. /Rick Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=15402&t=15402 -

ROM Upgrade

2000-07-21 Thread Rick Holden
I have an older 2503 router that I want to upgrade the flash memory for. I order 16 and installed it an the router now states that it is incompatible memory. I put is in an new 2503 router and it worked fine. I want to know if I can upgrade the ROM to a newer level if it would be able to use

Windows 2000 CA

2000-07-26 Thread Rick Holden
Does anyone know if you can use the Certificate Authorities Service that come with Win2k with a Cisco VPN for digital certificates. And if so, what is involved. Thanks. ___ UPDATED Posting Guidelines: http://www.groupstudy.com/list/guide.html FAQ, list archives, an

Catalyst menu and command line

2000-07-28 Thread Rick Holden
I have a Catalyst 3000 and a Catalyst 1900. I want to use these switches to study for the BCMSN exam. However when I connect to the console port I a presented with a menu and I want to get to the command line to practice commands. Is there a command line option for these switches and if not can I

Re: Catalyst menu and command line

2000-07-29 Thread Rick Holden
mode for the 1900. > > JEK > Senior Network/Hardware/Systems Engineer > > "Rick Holden" <[EMAIL PROTECTED]> wrote in message > 000f01bff8f1$c0928da0$[EMAIL PROTECTED]">news:000f01bff8f1$c0928da0$[EMAIL PROTECTED]... > > I have a Catalyst 3000

Re: Catalyst menu and command line

2000-07-29 Thread Rick Holden
mode for the 1900. > > JEK > Senior Network/Hardware/Systems Engineer > > "Rick Holden" <[EMAIL PROTECTED]> wrote in message > 000f01bff8f1$c0928da0$[EMAIL PROTECTED]">news:000f01bff8f1$c0928da0$[EMAIL PROTECTED]... > > I have a Catalyst 3000

STP

2000-08-15 Thread Rick Holden
I have a question on Spanning tree across the core layer. If I have switch stacks that look like the following diagram: 292429242924292429242924292429242924 292429242924292429242924292429242924 29242924292429242924

STP though the core

2000-08-15 Thread Rick Holden
I have a question on Spanning tree across the core layer. If I have switchstacks that look like the following diagram:2924    2924    2924    2924    2924    2924    2924    2924    29242924    2924    2924    2924    2924    2924    2924    2924    29242924    2924    2924    2924    2

Multicast software

2000-09-03 Thread Rick Holden
I am studying for the BCMSN exam and I would like to do some testing with multicasting. Does anyone know were I can download a shareware multicast server and client. Thanks ___ UPDATED Posting Guidelines: http://www.groupstudy.com/list/guide.html FAQ, list archives

LANE between CAT 3k and CAT 5k [7:23722]

2001-10-21 Thread Rick Holden
I was able to dig up 2 switches with ATM modules in them and wanted to practice setting up an ATM network between them; however, I can't find any documentation on directly connecting the two switches. I can only fine docu on connecting two switches together with a lightstream between them. Is it p