Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
An 871 router has been deployed at one of our employees houses, specifically to allow him to use a VoIP phone. It connects via an L2L IPSec tunnel back to a VPN 3005 concentrator.The idea initially was to tag all non-trunked incoming packets with a ...
I was wondering if anyone knew if it was possible to apply the same crypto map (or an identical crypto map at least) to two interfaces on the same ASA?I have two ethernet circuits being handed off by two ISPs at the Core of a hub and spoke IPVPN netw...
We have a branch location connecting to our corporate office through a leased T1 line. Their connection goes from their Foundry switch to a Cisco 2600 router, which then connects to a 2600 router at the corp office. Last week the IT admin at this o...
I have read Cisco's document on NAT-on-a-stick but neither of the examples directly apply to my situation and I can't seem to figure out how to get this to work. This is the scenario: We have an internal server at one of our locations that must hav...
If you want one device specifically to have lower priority, you will have to create a lower precedence crypto map entry matching the same access list with the secondary peer.My personal recommendation would just be to use them both in the same crypto...
There is no way to acheive load balancing with this configuration. Only one of the tunnels will remain active on the PIX at a time, preventing load balancing.To configure the PIX to use one link as a backup. simply configure multiple peers within t...
If you are asking if there is a way for the concentrator to detect an overlapping LAN range with its primary DHCP scope and then shift to a secondary scope the answer is no.The best bet is to just pick a range that is less likely to be used, (e.g. 17...
What I am seeing look fine. What I dont see is the rest of the ISAKMP configuration on either side. A possiblity is that you are using a firewall with an old software version with different default settings.Your hunch about the license is incorrect...
1) The best way to establish a site to site connection is using IPsec capable devices on both sides and creating an IPsec tunnel. PPTP is severely cracked.2)Here is an article for how to configure PPTP in conjunction with an MS server:http://www.cis...