Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Good day to all!I have faced with a problem when I tryed to use route-maps and dynamic PAT (overload) on ASR1002 series.At the moment there are:2x ASR 1002Cisco IOS Software, IOS-XE Software (PPC_LINUX_IOSD-ADVENTERPRISEK9-M), Version 15.3(2)S1, RELE...
Hello to everyone!We have recently got our new IPS 4510 appliance and for now there is a task to develop a connection scheme to our backbone multilayer switch (Catalyst 6500).There are several server's and user's VLANs connected to 6500.6500 performs...
Hi everybody!I am using ASA 5505 with firmware 8.2(2).My ISP uses PPPoE as a WAN connection protocol.There is a problem with getting PPPoE session started on my ASA 5505.The debug output says that after negotiation of PPP-authentication protocol ASA ...
Here is my guess of how to realise my scenario:Config on Cat6k should looks something like this:ip routing!interface Ge1/0 switchport trunk encapsulation dot1q switchport trunk allowed vlan 10-12,110-112 switchport mode trunk switchport nonegotiate s...
UPDATE:I found Cat6k feature: "vlan mapping".I think it is exactly what I need in my scenario. But any advices about common principles of "forcing Cat6k to get traffic out itself" are welcome! Especially if your methods were verified I will post th...
Hello Praveer.Thank you for response!About VLAN-pair mode: this is in fact the only mode, where IPS performs changing of VLAN-ID tag.It is unacceptable for my scenario because this mode is not fault tolerance(hardware-bypass is not supported and usel...
Hello Matt!To be honest I am not fully understand what do you mean under "dedicated solution".In my mind "dedicated solution" is something that stands alone of ASA and is independet from it (like 42xx/43xx/45xx appliances).AIP module is rather "built...
UPDATE: I have figured out with assymetric data flow in the Packet Tracer.My mistake was in creating SVI for VLAN 100. Despite the fact that there was a "no ip address" command entered, it was acting like a router interface.I suppose this is because ...