Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hello!I'm now trying to lab Outside NAT with dynamic translation to the pool on the CSR1000V and facing an issue with a static route to Outside Local address via Outside Global address not being added to the routing table on the IOS-XE 16.3.2+ (IOS-X...
Hello!
I have a case in which I need to use some sort of the custom-written client to the Anyconnect SSL VPN Gateway on the multi-context ASA SSL VPN.
As I wrote earlier, ASA's context is configured properly and Windows-based ANyconnect client can c...
Hello!
I have a topology, in which Catalyst 2960L (IOS 15.2(5)E1) is connected to the Catalyst 4500-E (SupV-10GE IOS 15.0(2)SG11, WS-X4506-GB-T) using SFP ports and LACP configured on that link.
There're following cases: - only DHCP Snooping is conf...
Hello!
I'm curious if the Catalyst 4500-E VSS supports WS-X4712-SFP-E and WS-X4724-SFP-E linecards (not for VLS, for regular ports). All the config guides state that WS-X4712-SFP+E is supported, but there's no info about WS-X4712-SFP-E and WS-X4724-...
Hi!
Now facing an issue when a vPC-attached ESXi (not e-vPC, not vPC+) with MS NLB cluster members is not reachable by the clients connected from other vPC-attached ESXi. Interestingly, a vPC-attached client can reache the MS NLB cluster, located on...
you need an ISAKMP profile for the VRF-Aware IKEv1 to work:crypto isakmp profile IKEv1-INET-PROF vrf INET keyring Ipsec-KEY vrf INET match identity address 1.2.3.4 255.255.255.255 INET isakmp authorization list default!crypto ipsec profile Ipsec-PROF...
It's exact the same as with PfR - if you need MC redundancy, make it with HSRP or Anycast Loopback. For Geo-redundant MC you then need a way to make an L2 tunnel between the two for HSRP or regular routing metrics for the Anycast.
Also for a one with a case "Certificate Authority Service disabled on a PAN" it's worth to mention that for the Certificate Authority Service to be enabled on the PAN in the ISE 2.2, PAN for some reason must be enabled with a Policy Services role, ot...
Hello!
After doing some investigations with SPAN, I've figured out following: upon activating ARP Inspection, 2960L takes all the ARP Requests it received from the uplink port and replicates them back to that port for an unknown reason. Seems, that'...
Hello, Aizat!
What Mark says is not 100% correct. For the VSS, the main rule is always "local forwarding".
That means in case you're landing both links from the ISP with LACP and you have like one static default route to the ISP in the config, all t...