01-24-2013 04:23 PM - edited 03-04-2019 06:50 PM
Hi all,
I have an 1801w connected to ATT/Bellsouth FastAccess via its DSL port. The LAN connection is through FastEthernet1 trunked to an Extreme Networks Summit 450e. My 1801w configuration is attached and everything is working great.
My problem: DSL bandwidth is unfortunately limited to 3mbps/384kpbs in my area, so I'm considering adding a second DSL line and aggregating bandwidth (load balancing) between two.
1) Can this be acheived using the 1801w, perhaps by adding an external modem for the second DSL connection feeding the 1801's FastEthernet0 port?
2) If yes, then might anyone have a specific modem recommendation? If no, then what other equipment would I need?
3) Most importantly, would someone please point me in the right direction regarding the 1801 configurations changes required? (I expect my goal would be to equally share the WAN links between all connected VLANs/networks, but if necessary I suppose a workable alternative might be to dedicate a new VLAN/network (e.g., "office") to the new WAN link.
Thanks for your help and suggestions!
Best,
Don
01-31-2013 07:15 PM
Well, after more research, I may have found answers to some of my questions:
BUT the document does suggest additional policy routing rules may be necessary to direct certain types of traffic to a single ISP (e.g., IPSec, VoIP, etc.). This statement has me a little concerned. While I only use SSL VPN now and VoIP remains within the LAN, I will need to add L2TP/IPSec at some point to support remote Android devices (since mobile AnyConnect isn't supported on IOS backends). Further, I will also be placing a 3rd party's 800 series router behind the 1801 over which I will have no control. I assume the 800 will need to tunnel through the 1801 back to the 3rd party's offices. This additional complexity makes me wary of attempting a load-balanced dual WAN/ISP configuration. Somebody needs to talk me into it
Cheers,
Don
01-31-2013 08:52 PM
Why you say you can't connect SSL-VPN for Androids to IOS ?
01-31-2013 10:48 PM
Hi
Support for anyconnect Depends on ios Version in The Router and it is Limited against The Features available on The ASA but it is working.
Sent from Cisco Technical Support iPhone App
02-01-2013 04:57 AM
Yes, AnyConnect on Android works fine with a Cisco ASA device on the backend but not with any Cisco ISR running IOS (There is no mobile device AnyConnect license available to my knowlege). It's a shame really as AnyConnect works well for my Windows and Linux clients; it would be great to extend access to mobiles with no additional setup.
When it comes time to replace the 1801, I may consider an ASA device instead, but then I believe ASA is missing some of the other functionality I'm running (or want to run) on the ISR. If Cisco would add mobile AnyConnect support to IOS, it would be a no brainer (although costly for a SOHO user like me) to jump to the 1921 or the 1941 when the 1801 reaches end of life.
Cheers,
Don
http://www.cisco.com/en/US/products/ps8411/products_qanda_item09186a00809aec31.shtml
Q. Is it possible to connect the iPad, iPod, or iPhone AnyConnect VPN Client to a Cisco IOS router?
A. No. It is not possible to connect the iPad, iPod, or iPhone AnyConnect VPN Client to a Cisco IOS router. AnyConnect on iPad/iPhone can connect only to an ASA that runs version 8.0(3).1 or later. Cisco IOS is not supported by the AnyConnect VPN Cli...Security Appliances and Software Supported section of the Release Notes for Cisco AnyConnect Secure Mobility Client 2.4, Apple iOS 4.2 and 4.3.
02-01-2013 05:07 AM
Hm
strange would have tryed but own only a iPhone and this works well ..
02-01-2013 05:55 AM
Patrick,
My appologies. You are absolutely correct. I had not tried the latest AnyConnect Android client (3.0.09093) since installing IOS 15.1(4) on my 1801. It actually works!!! Why hasn't there been more publicity about this much needed support? Officially Cisco's position has been ASA is needed for Android/IPhone AnyConnect. In any case, thank you! I have now one less issue to solve in not needing to configure LT2P/IPSec.
Now back to my dual-WAN ISP problem
Don
02-01-2013 07:27 AM
That could be the marketing or sales push, for what's worth.
Technically, we know better.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide