Easiest and best plan in the long run is to change one of the site's Network ranges, or split them in half (site 1 uses 10.1.1.0/25 and site 3 uses 10.1.1.128/25. Otherwise you'd have to set up some sort of bridging rather than routing between the sites, which increases the broadcast domain to travel over the WAN. This is undesirable at best.
... View more
My guess would be that although there's a SESSION limit of 750 users, there's an INTERNAL SERVER config limit of 250 users! Use some external authentication method instead. Especially with that many users, integrating it into AD domain, or something is probably a good idea, and would simplify management.
... View more
How does one add the custom graphics to the VPN Client? I'm using the Install Shield Install, because the .msi one looked too hard to customize with transforms and such. I have an oem.ini file, and I've changed the settings in that OK (like program name, and install path), but I can't figure out how to replace any of the graphics? The Documentation only says: "Table 5-2 lists the GUI image (portable network graphic) files that the VPN Client uses. If you want to replace any of them with your own image files, you must name your image files exactly as shown in the list; otherwise, the VPN Client GUI does not recognize them." But it never says WHERE to put these files. Also it never says if they need to be noted in the oem.ini file, and if they do I don't know the syntax to use! Anybody done this? How?
... View more
Why is your DMVPN tunnel network using the same range of IPs as your Remote-Access users? As for why your pings are being lost; is the default gateway of the 'server being pinged' 'router2'? If not, and it doesn't have a static route for the DMVPN tunnel/remote access network range, the machine has no idea where to send them!
... View more
How does one add the custom graphics to the VPN Client? I'm using the Install Shield Install, because the .msi one looked too hard to customize with transforms and such. I have an oem.ini file, and I've changed the settings in that OK (like program name, and install path), but I can't figure out how to replace any of the graphics? The Documentation only says: "Table 5-2 lists the GUI image (portable network graphic) files that the VPN Client uses. If you want to replace any of them with your own image files, you must name your image files exactly as shown in the list; otherwise, the VPN Client GUI does not recognize them." But it never says WHERE to put these files. Also it never says if they need to be noted in the oem.ini file, and if they do I don't know the syntax to use! Anybody done this? How?
... View more
The document you link that quote to is talking about IOS "12.2(18)SXE DMVPN Support on the Cisco 6500 and Cisco 7600". Apparently it does hold true for other hardware devices, and more recent, feature-rich IOS versions... Unfortionatley I still have little good idea how to configure a very basic-level of QoS into our setup...
... View more
I am a little confused in trying to best configure bandwidth management for our Hub and Spoke DMVPN router network over the WAN. How would one configure a router to best handle traffic flow out a WAN link, where the router 'sees' the network as fast ethernet, but in the 'internet' a much smaller maximum throughput rate is set (like standard T1 or Cable modem speeds)? Or is there really nothing to do? I understand that regular TCP/IP flow controls should scale back data transfer when it detects packet loss; but what about any UDP flows, or the like? The actual setup: We have DMVPN hub with ethernet interfaces, connected to internet via a 6Mbps rate limited ethernet line to ISP. The LAN AND WAN ethernet interfaces on our router itself run at 100Mbps. All the remote spokes have 10Mbps ethernet interfaces connected to T1 terminators or cable/DSL lines. 99.9% of the traffic leaving all the routers is the IPSEC traffic from the DMVPN. We want some sort of QoS policy to give priority to things like interactive intranet web-browsing, odbc database transactions, and voip (3com nbx not cisco) traffic through the DMVPN tunnels, leaving general backup-type file transfers, email, ftp, and other large-data, non-interactive sessions as a lower priority. It seems like this should be setup to rate limit/prioritize the traffic to the ISP's Max line speed before encrypting and tunneling takes place; but how? Right now there is NO form of QoS or queueing or anything. I believe as a result, we do in fact see consistent drops of non-tcp/ip traffic, (like pings) on and off. Also things like the afformentioned web browsing are extremely slow and laggy--but latency across the networks are stable between 50 and 100 ms. Which should be perfectally acceptable for web-browsing. This leads me to believe it's a problem due to basic traffic drops trying to push all this LAN traffic over a WAN. I've tried to research this, and think i understand on a basic level HOW QoS works, and it sounds like a good idea, but I'm a little unsure which type to use, and I have a BIG problem trying to understand specifically how to implement it. Thank you for any help, -Shawn
... View more
Best to contact Cisco sales rep, or Cisco Sales directally, and ask them. They should put you in touch with a Cisco internal engineer, who should be able to provide you with all the specific data you need.
... View more
Ah, no. I don't think there's a supported way to change the administrator login page. I've not seen any options at all. One would think there would at least be a logon banner option. I hadn't thought of it before though. You can try asking cisco, or maybe requesting the ability. They're always recommending setting up a banner on their other products...
... View more
At: "Configuration | Tunneling and Security | WebVPN | Home Page" you can configure the VPN device start Page. Options are limited however, and the amount of 'custom text' is also limited. You can however put in html, which is nice if you want a small custom format, or highlight. It's just a text-box, so the maximum length is something like 256 characters or something, and it all has to be one line (no carrage returns)--but you can use 'p' and 'br' html tags to add lines. The logo image (along the top of pages) can be set at: "Configuration | Tunneling and Security | WebVPN | Home Page". I created a nice small animated GIF that looks nice there.
... View more
I did the same thing, TAC support said they've had like 20 people complain about this. He said "there is no reason to update the boot code on a 3005 model. It is only needed on the 3015 and higher models to support RAM chips larger than 256MB." TAC support said DO NOT UPDATE the boot code on the 3005. I suggested that they make note of this SOMEWHERE in their documentation. He provided me with some hidden low-level commands to erase the boot code, but as he said the 3005 doesn't need v4 of the boot code, and the boot code hasn't been tested for it, it's possible it would just break the concentrator. He then added the only way to 'fix' a damaged boot code is to replace the entire unit. He suggested we not touch it anymore, and leave the boot code running as-shipped.
... View more
I wasn't sure where to ask this, but this seems the most relivent (sort of). Is there a document somewhere which details how IOS licensing works, along with how upgrades, etc work? I've looked around the cisco site, but can't seem to find any information on this other than the basic idea that 'IOS upgrades can be purchased through 2 ways; through a smartnet contract as an upgrade, or without a contract through a new license'. Also there was mention that upgrades through the 'product upgrade paths' are free. I just want alot more detail. What are the 'product upgrade paths', and what are the 'rules'? There's got to be information about how it all works somewhere...If only I could find it! Thanks in advance.
... View more
Do you have any links to documentation on how to set this up? We have a similar setup as this, but I believe we 'control the routers' as well (we just get regular T1 lines into here, and we want to share among them, and have fall-over. What's we will soon have cisco IOS routers all over the place to terminate the T1s and elsewhere. I just don't know where to look, or what it is called that I'm looking for--which makes finding a solution hard. I appreciate any help you can provide.
... View more
Can I ask *why* you'd want to do this? Also, if you can mention what wasn't working in your tests (where it was failing), maybe we can figure it out better...
... View more