cancel
Showing results for 
Search instead for 
Did you mean: 

Answer Questions

  • ISE 2.0 Cert Chain Android - ( 12m ago )
  • Policy and Access
  • I recently updated a couple certs on our ISE server. I applied the same cert to the default portal policy as well as EAP Authentication. We went from an OV cert to an EV cert which required an intermediate cert to be installed to the ISE server. I am not having any problems with anything except the Guest Portal on Android.   What is happening is the Certificate chain is not complete on the android devices. All laptops are listing it as valid cert as they are listing the root and intermediate certs. I can manually install the intermediate cert on my android devices and have it show as valid, however that should not be needed as it is installed on the ISE server.   On top of that problem, we are recieving the portal redirect page (connectivitycheck.gstatic.com) and no portal. The only way I have been able to get around this is by clicking "connect as is" and open chrome; I then navigate to "connectivitycheck.gstatic.com". Then I am redirected to the correct Guest Portal.   Any help is appreciated Thank you
    View more
12m ago
Cancel Post

  • IP phone how to communication with other site without voice gateway - ( 40m ago )
  • IP Telephony and Phones
  • Hi guys,    I am a totally beginner of Voice. Our company have Headquarter、Site1 and Site2     Headquarter have call manager(CUCM) , site1 have voice gateway(C2900), and the IP Phone function of them is normally    Now the question is that Site2  is a new site, and it doesn't have voice gateway(C2900). Site2 establish ipsec-vpn between  Headquarter and site1 , so site2 how to use the  IP Phone ? Thanks    
    View more
40m ago
Cancel Post

  • SF300-24P BOOT CODE VERSIONS 1.0.0.4 AND 1.1.0.6 NEEDED - ( 42m ago )
  • Small Business Switches
  • Boot software versions 1.0.0.4 and 1.1.0.6 files urgently needed to downgrade my firmware from 1.3.5.58 to 1.2.7.76.I was told that version 1.2.7.76 is a workaround the POE FAIL error I have on my switches.I cannot downgrade straight from 1.3.5.58 to 1.2.7.76 unless the boot code is downgraded first.All helps to get these files will be appreciated. See attached files.  
    View more
42m ago
Cancel Post

an hour ago
Cancel Post

  • ASR920 Management - ( an hour ago )
  • Metro
  • I'm struggling with how to manage the asr920 remotely. I have a UNI S-port feeding connectivity to the unit. In this s port is a tag that contains a management VLAN. I've tried configuring a c-port, but I kind of figured it wouldn't work connecting that port to the management interface - which it doesn't. I don't have any other boxes I can connect to at this location. Is there a way to create a virtual interface on the unit and have it associated with a uni c port? Or am I going about this in the wrong manner?
    View more
an hour ago
Cancel Post

an hour ago
Cancel Post

  • ISE DHCP - ( an hour ago )
  • Wireless Security and Network Management
  • Hello, I have Cisco 5508 WLC, and also i have Cisco ISE, When i created the radius configuration between the WLC and ISE after the authentication using mobile phone the i can't get ip from dhcp but when i setup the authentication from the WLC to use WAP the dhcp working without any issues 
    View more
an hour ago
Cancel Post

  • 2960X switches support TLS 1.2 ???? - ( 2 hours ago )
  • Switching
  • Hi there We Run a lot of 2960X switches at our one site.  Do they support the TLS 1.2 ??  I have looked over the support device list but do not see them listed.  Just need to make sure. We also use 2960S series at our second site.  Can they use TLS1.2 ? thank you Steve
    View more
2 hours ago
Cancel Post

  • Problem with cat6a cable and cisco ATA 186 and 187 - ( 2 hours ago )
  • IP Telephony and Phones
  • Good afternoon.  Has anybody had issues with faxing using a cisco ATA 186 or 187 when the fax line is using a standard cat6a terminated network jack?  We could not get the fax to work, and wound up putting the ATA next to the printer/copier/fax, where it works find on the standard 4 wire satin ribbon cable direct from the ATA port to the line port on the MFC.  We are well under the 300 foot mark from the patch panel to the device.  We have not had any issues using cat5e or cat6 cable with standard 4-wire phone codes from ATA port to panel, and wall jack to device, but with the Hubble C6ASPDSW wire type, we have not had any luck.   Just curious if other are having issues with ATA 186 and 187 models using cat6a cable.   Thanks.
    View more
2 hours ago
Cancel Post

  • SG550XG stack - after reboot unit 2 - problems with Etherchannel - some IPs only - ( 2 hours ago )
  • Small Business Switches
  • Hi, have here 2*SG550XG as native stack.  Attached are 3* vSphere 6.5 servers, via Etherchannel, redundunt cabeling across the stack members. This works fine. After a FW upgrade the stack unit 2 ran into a boot loop. The good news was that the vSphere was up and running, so the redundancy worked.  I noticed today, that a couple of VM IPs were not pingable (but just combinations). This means, from the switch all IPs were pingable, from some host some IPs were not pingable to from other VMs/Hosts the IPs were pingable, so I think that the Etherchannel IP/MAC hash table was corrupt. I rebooted on host, this fixed some IPs, but some VMs were still not pingable.After rebooting the stack and the hosts, all IPs are now pingable again. How to analyze/avoid this kind of problems?  vSphere NIC teaming: Route based on IP hashLoad Balance Algorithm: IP/MAC Adress Thanks Henri
    View more
2 hours ago
Cancel Post

  • Cisco ASA 5510 replacment - ( 4 hours ago )
  • Firewalls
  • I have Cisco ASA 5510 that we are looking to replace.  We would like to replace it with another Cisco Appliance.  My Question is 2 parts. Part 1 I am not extremely familiar with the Cisco line of products. The main requirements are VPN and we have 2 internet circuits used for failover only not load balancing. What current appliance would be a suitable replacement to fit those requirements? Part 2 Going back to not knowing to much about Cisco firwealls. Can a config file be saved from this ASA 5510 and then be dropped into a new device? Allowing it to apply all the current configuration of the old device. I know this device is really old and I would have a really hard time re-building all the port forwards, routing rules, ect.  Any help that anyone can suggest is appreciatedThanks.. 
    View more
4 hours ago
Cancel Post

  • place a call using the speakerphone not working in cme 11.6 - ( 4 hours ago )
  • IP Telephony and Phones
  • We are unable to place a call using the speakerphone (Cisco 7921 SIP) in cme ,   It working when i dial number and pick the reciever calls are going .   it not working When i press speaker button  to place call    voice register dn 10 number 8238 allow watch name Cisco label Cisco ! voice register pool 100 busy-trigger-per-button 2 id mac 1020.1201.8901 type 7821 number 1 dn 10 cor incoming Local default username user217 password cisco codec g711ulaw
    View more
4 hours ago
Cancel Post

  • Creating a redundant network ring with 2 Cisco 1941 routers and 2 catalyst 2960 switches with1 bridge radio and 1 mikrotik radio router in the middle. Issue with connected routes thru a switch questions for a network guru. - ( 4 hours ago )
  • Routing
  • Hello, Let me first explain what I am configuring here to help explain what I am creating.  You can see my network in the attached diagram.Here is the issue I am having I would like to have a redundant path if one of my RF paths go down between my 2 radio's or a radio itself goes down.  Lets say that Basic Sm bridge MikroTik goes down I need for the redundant path to to be taken but since my cisco routers are connected to a switch they think the radio path is still up even though the radio is down.  Like in the example below. Every thing INSV: Gateway of last resort is c.c.251.251 to network 0.0.0.0O*E1 0.0.0.0/0 [110/2] via c.c.251.251, 00:06:00, Vlan2001.0.0.0/32 is subnetted, 1 subnetsO 1.1.1.1 [110/11] via c.c.251.251, 00:06:00, Vlan20010.0.0.0/8 is variably subnetted, 5 subnets, 3 masksC a.a.80.32/28 is directly connected, GigabitEthernet0/1L a.a.80.34/32 is directly connected, GigabitEthernet0/1C c.c.251.0/24 is directly connected, Vlan200L c.c.251.1/32 is directly connected, Vlan200O b.b.252.0/24 [110/2] via a.a.80.33, 00:01:06, GigabitEthernet0/1 sh ip ospf neighborNeighbor ID Pri State Dead Time Address Interface1.1.1.1 1 FULL/DR 00:00:23 c.c.251.251 Vlan200b.b.252.1 1 FULL/DR 00:00:37 a.a.80.33 GigabitEthernet0/1DIV-HILL-1941#  So if I want to reach anything on c.c.251.0/24 network I can take vlan200 route over and this works.  However if my vlan 200 radio goes down c.c.251.250,RTR 2 still sees this path up VLAN 200 thru my switch 2.  Here taking down Radio #2 ip = c.c.251.250 Gateway of last resort is 10.45.80.33 to network 0.0.0.0O*E1 0.0.0.0/0 [110/3] via 10.45.80.33, 00:01:18, GigabitEthernet0/11.0.0.0/32 is subnetted, 1 subnetsO 1.1.1.1 [110/12] via a.a.80.33, 00:01:18, GigabitEthernet0/110.0.0.0/8 is variably subnetted, 5 subnets, 3 masksC a.a.80.32/28 is directly connected, GigabitEthernet0/1L a.a.80.34/32 is directly connected, GigabitEthernet0/1C c.c.251.0/24 is directly connected, Vlan200L c.c.251.1/32 is directly connected, Vlan200O b.b.252.0/24 [110/2] via a.a.80.33, 00:08:17, GigabitEthernet0/1#sh ip ospf neighborNeighbor ID Pri State Dead Time Address Interfaceb.b.252.1 1 FULL/DR 00:00:32 a.a.80.33 GigabitEthernet0/1 You can see that from RTR #2 that vlan 200 to c.c.251.0/24 is still INSV.  Which from the router's point of view it is but is there any way I can tell the RTR #2 that this path is no longer valid via the switch as the far end radio is down? I can get it to work if I put in static routes shrinking the subnet so that the path picks the more precise path but this is not really scalable as I have to brake up the c.c.251.0 /24 subnet into c.c.251.1/25 and c.c.251.129/25. Just looking for idea's on how to tell a router a connected path is down past the switch so we can use the backup path via RTR2-RTR1-Switch #1-Radio #1? Thanks for any input.   
    View more
4 hours ago
Cancel Post

4 hours ago
Cancel Post

  • voice gateway port reports - ( 4 hours ago )
  • Unified Communications Infrastructure
  • Hi,   I was wondering if anybody has a way of gathering all the gateways configured along with which ports were configured. For example a VG202 with port 0/1 configured with x1234 but port 0/2 is not configured.   Thanks in advance, Ted
    View more
4 hours ago
Cancel Post

4 hours ago
Cancel Post

  • VLAN - Q-IN-Q - ( 5 hours ago )
  • Routing
  • Hi everybody, I would like to create a q in q vlan inside my network architecture but unfortunately i have only to 2941 router to do this functionality. I find several websites which describe q in q vlan cisco commands.Finally I do the below configuration in my two tunneling routers : #R1enableconf tno ip routinginterface GigabitEthernet 0/0no shutinterface GigabitEthernet 0/1no shutinterface GigabitEthernet0/0.100encapsulation dot1q 100 second-dot1q 2,3no shutinterface GigabitEthernet0/1.2encapsulation dot1q 2no shutinterface GigabitEthernet0/1.3encapsulation dot1q 3no shut #R2enableconf tno ip routinginterface GigabitEthernet 0/0no shutinterface GigabitEthernet 0/1no shutinterface GigabitEthernet0/0.100encapsulation dot1q 100 second-dot1q 2,3no shutinterface GigabitEthernet0/1.2encapsulation dot1q 2no shutinterface GigabitEthernet0/1.3encapsulation dot1q 3no shut I want to use my routers as  L2 switchs and I don t want to add ip address in my subinterfaces. I m not sure this configuration works. I would like know others possibilites to use this router like a switch ?Thank you very much regards
    View more
5 hours ago
Cancel Post

  • Updated docs on ISE integration with Microsoft Intune? - ( 6 hours ago )
  • Identity Services Engine (ISE)
  • Hi all,   I have a customer who is interested in the integration between ISE and Microsoft Intune, for MDM purposes. So far, I've been able to find in this community post a presentation related to ISE 2.1, written in 2016. I was wondering if there is any updated documentation that you might know about.   Thank you. Pier
    View more
6 hours ago
Cancel Post

  • Router learns MAC address from switch that doesn't have it? - ( 6 hours ago )
  • Switching
  • I need help understanding how a router learns a MAC address from a switch that doesn't appear to have it? The router is C9500-40X, and the directly connected switch is WS-C3850-24XU. From the router: #sh mac add add 0000.00ff.ef52 Mac Address Table ------------------------------------------- Vlan Mac Address Type Ports ---- ----------- -------- ----- 100 0000.00ff.ef52 DYNAMIC Te1/0/9 108 0000.00ff.ef52 DYNAMIC Te1/0/9 110 0000.00ff.ef52 DYNAMIC Te1/0/9 120 0000.00ff.ef52 DYNAMIC Te1/0/9 180 0000.00ff.ef52 DYNAMIC Te1/0/9 181 0000.00ff.ef52 DYNAMIC Te1/0/9 182 0000.00ff.ef52 DYNAMIC Te1/0/9 183 0000.00ff.ef52 DYNAMIC Te1/0/9 184 0000.00ff.ef52 DYNAMIC Te1/0/9 185 0000.00ff.ef52 DYNAMIC Te1/0/9 186 0000.00ff.ef52 DYNAMIC Te1/0/9 187 0000.00ff.ef52 DYNAMIC Te1/0/9 188 0000.00ff.ef52 DYNAMIC Te1/0/9 200 0000.00ff.ef52 DYNAMIC Te1/0/9 300 0000.00ff.ef52 DYNAMIC Te1/0/9 800 0000.00ff.ef52 DYNAMIC Te1/0/9 801 0000.00ff.ef52 DYNAMIC Te1/0/9 875 0000.00ff.ef52 DYNAMIC Te1/0/9 910 0000.00ff.ef52 DYNAMIC Te1/0/9 Total Mac Addresses for this criterion: 19 #sh cdp nei Te1/0/9 Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone, D - Remote, C - CVTA, M - Two-port Mac Relay Device ID Local Intrfce Holdtme Capability Platform Port ID 216-501-cis2 Ten 1/0/9 145 S I WS-C3850- Ten 1/1/4 Total cdp entries displayed : 1 When I connect to that switch though, it's not there: 216-501-cis2#sh mac add add 0000.00ff.ef52 Mac Address Table ------------------------------------------- Vlan Mac Address Type Ports ---- ----------- -------- ----- 216-501-cis2# If I shut down the interface (Ten1/0/9) on the 9500 then the MAC address table entries go away, and when I bring it back up again they come back, so it's not something old and leftover -- it's actively re-learned more or less immediately.   Also interesting is that I see this MAC address across multiple VLANs, but not all existing vlans. I've also verified that this MAC address is not the address of any of the interfaces on these devices. Any suggestions as to how this MAC address table is being learned? Thanks!! -Chris
    View more
6 hours ago
Cancel Post

  • WLC 3504 Will Not Boot - ( 6 hours ago )
  • Other Wireless - Mobility Subjects
  • Bought a new Cisco 3504 WLC. I've connected a USB cable to the console port and accessed the console via the terminal on my Mac:screen /dev/tty.usbmodem1461 9600  I then restart the 3504 and all I get in the terminal is "Cisco bootloader . . ." - I try to hit escape and stop the booting, but nothing happens. I've had the machine on for 24 hours now and booting never finishes. I've also done both versions of reset (hold button for 3 second and hold button for 10 seconds) and I all I get is the same "Cisco bootloader . . ." message. Note: I have also tried using the service port but never get an IP. This led me to believe the machine was not booting.  The System light is slow green flashing and the Alert light is solid amber.
    View more
6 hours ago
Cancel Post

6 hours ago
Cancel Post

6 hours ago
Cancel Post

  • Subject: SIP Lines: Modify Incoming calling number Prefix +91 to 0 - ( 6 hours ago )
  • IP Telephony and Phones
  •  We are doing POC at one of our customer location and configured UC setup for Customer is having SIP Line for PSTN calling. We have configured IP Trade turrets on CUCM for dealing business. We have tested all scenarios and working fine. we have saved contacts list by prefix 0 with contact number on IP trade turrets for dialing out. when incoming call comes on saved contact numbers then customer wants to blink already saved contact number (same as our contact list in mobile phones).but it is not happening due to calls coming with +91 prefix. below are the scenarios Current scenario: Incoming calling number showing on IP Trade turrets: Example:( Country code + Number) +91 9665279125,+91 2262300192 , +91 20456528 etc. Customer requirement :Incoming calling number should show on IP turretes with prefix 0 instead +91. Example: 1) Actual Incoming calling number is +91 9665279125 but it should show on IP Trade turretes as 0 9665279125 as a incoming calling number. 2) Actual Incoming calling number is +91 2262300192 but it should show on IP Trade turretes as 0 2262300192 as a incoming calling number. Could you please help out us to modify incoming calling number.    How to make SIP profile for the same.
    View more
6 hours ago
Cancel Post

  • UDLD Modes - ( 7 hours ago )
  • Switching
  • Cisco docs are a bit confusing on this. So if UDLD normal mode is used, does the port/link remain up even when a unidirectional link failure is detected? 
    View more
7 hours ago
Cancel Post

7 hours ago
Cancel Post