Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hello,From what I understand most of the Data Centers are dealing with 9K MTU size with their Endpoints at the leaf level.For the East-West flows, it won't be rare to have those packets egressed from the ISN Device.I wanted to find out, if I m peerin...
If we're not doing the NAT with those firewalls(at each site), this scenario would be very easy to be implemented, my questions is about the traffic steering that's supposed to be happening to the appropriate compute leaf, how can that be accomplishe...
If my firewall can route to a certain subnet that I haven't included in my split tunnel, any authorized user can add that route by open connect Linux app and get into my network, how can we enforce only the split tunnel ACL subnets to get in? Thanks
Just a disclaimer Cisco AnyConnect Mobility Client binary uses this function CHostConfigMgr::StartInterfaceAndRouteMonitoring() that monitors the routing table for any modifications, so as long as user runs the Cisco client he can't add any new route...
I mean ofc we don't have no such thing as 100% secure, but I mistakenly thought split tunnel is also act as an ACL, or in other word it's not just client side, it's server side.VPN is pretty open though, you usually give vpn to someone you already ha...
Throughput licenses are honored based, so no purchase required as of Now.However you still need to purchase every 10G port you are going to use, e.g. on 1002 HX first 4 ports comes with the device purchase, but anything after that requires a license
https://www.cisco.com/c/en/us/td/docs/routers/asr1000/install/guide/1001-x/asr1hig-book/router_license_verify.html#con_1062130Could you read this sirI couldn't decipher it!