Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi there,Can anyone shed any light on how-to approximate the following IOS QoS configs (from one of our 800 series ISRs) on an SG 300 switch:-class-map match-any VoIP match protocol rtp match protocol sipclass-map match-any RDP match protocol ms-wbt!...
Hi there,Is it possible to forward and QoS traffic destined for other hosts on a Cisco 800 series ISR?For example, all traffic for 203.174.152.32/28 is currently being routed to 203.174.188.56/30.IP addresses 203.174.188.58 and 203.174.152.33 (second...
Hi,I am hoping someone can help with configuring a Cisco 881 which does NAT for the vlan and has a handful of port forwards from the WAN interface to hosts on the vlan.I've created an extended access-list named 'outbound-filter' with the following ru...
Hi there,I am actually hoping Andrew Hickman, author of DOC-16927 and DOC-23028 can help with this.I have established a Site to Site IPSec VPN between our SRP527W-U and CISCO881-K9 (ISR), running IOS 15.0(1)M3.This is the first branch to use an SRP. ...
Hi Marius,I like that solution, looks cleaner than using CBAC. Your example appears to allow any tcp or udp traffic out to the Internet?If I want to lock this down to just ICMP, HTTP/S, HTTP/S alternates, FTP, DNS and mail (IMAP/S and POP3/S) and cat...
Thank you Jon and Marius. You are both correct and I have used both your answers in my solution. CBAC so Skype and other allowed apps can negotiate dynamic ports for file transfers etc. and the addtional permit rules for the port forwards to permit S...
Hi Andy,That's a real shame. As I would imagine an unencrypted GRE tunnel would be an unsuitable deployment for most organisations, and obviously IPSec does not address all VPN needs.Is there any way to bridge the SRP with an IOS device to do routing...
Hi Andy,I am not sure I follow; there is nothing wrong with my config, routes or ACLs? The behaviour I described is expected on the current firmware between SRP and IOS?IPSec is only half the solution here, I wanted to focus on getting this right bef...