Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
We have anyconnect configured, with a login banner, but the banner shows up after authentication.
You are required to select "Accept" to continue the connection.
I have seen a login banner as soon as the client connects to the ASA before authenticati...
My company has a 100Mbps Internet circuit with a 10Mbps SIP trunk provisioned with Internet. The person who ordered the circuit no longer is with the company, and no one seems to know a lot about it.
It has been decided to go with a different carrier...
We have a Cisco ASA 5585 HA pair in context mode (Version 9.1(7)4 <context>) being used for VPN tunnels.
We have a customer who wants a primary (Their main site)and backup (their secondary site) VPN tunnel to peer with our ASA. Both tunnels will peer...
We have two ISPs, connected to two ASR routers. Our configuration is set up Primary/Secondary.
We are using Level 3 as our primary ISP. Traffic outbound is controlled via HSRP and L3 has priority outbound.
L3 is also the primary path inbound to our D...
We have two ASR routers, with two different ISPs. Currently there is a Primary router inbound and outbound, the second router is backup to the Primary.
The config is pretty much identical on the two routers. We have a Public address block we are adve...
Perhaps it was not clear when I mentioned "same IP Address"
they have two sites, we have one:
My Site (3.3.3.3)<---> Their Site 1 (1.1.1.1)
My Site (3.3.3.3)<---> Their Site 2 (2.2.2.2)
So, you are saying that if we had the same destination subnets i...
This would be the layer 2 only vlan that connects the ASA and the MPLS router.
There is no other way to route traffic to the ASA from the other site, or route from the other site across the /30 to the ASA without a layer 3 connection in that VLAN.
1. I described the new link as a layer 2 link, because that is what the provider is calling it, but we can do with it whatever we want, according to the provider. In fact, their words are "this is like a layer 1 physical connection between the 2 site...
Would this solution allow for the NATing of just a couple of hosts in the DMZ, and allow all other hosts in the DMZ to accessed via their native IP Address?