Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
We are municipality IT which at this point do most Cisco work in house. However our VPN experience with Cisco is limited. This project involves replacing Linux boxes running OPENVPN with Cisco 2811 routers to a few temporary/small locations were si...
Thanks Ken for the follow up info. My situation is somewhat different, for one example switch - I am running 9 pools on the Cisco, and 4 via forwarding (ip helper), so I'm actively using DHCP.My main concern was/is - am I just seeing the "making of t...
I can confirm the initial report. I first saw this on 3 new 9300's I deployed (Advantage Licensed) this summer starting at 17.15.04 (and later to 17.15.05). These switches are in schools with mostly identical configuration as other switches in othe...
Marcin, thanks again for your help and attention, please bare with me as we've definitely hit my knowledge limit here. > Try removing DF-bit clearing and use tunnel path MTU discovery feature (both tunnel interfaces). I had removed the crypto ipsec d...
So I ping'ed (ping -f -l value) from a client off the site router to the IP of the far tunnel interface and found I was fine starting at 1400 to 1402, then no response from 1403 1420, then responses and not until about 1450 would I actually get the f...
Thanks for the reply Marcin,I'll try removing crypto ipsec df-bit clear and see what we get. This command was part of the tutorial we started with.I did some testing of the MTU path, it was unclear which portions should we test against. Should t...