Need Help for configuring Floating static route in My ASA.
Hi All,
I need your support for doing a floating static route in My ASA.
I have tried this last time but i was not able to make it. But this time i have to Finish it.
Please find our network Diagram and configuration of ASA
route outside 0.0.0.0 0.0.0.0 6.6.6.6 1 track 1
route outside 0.0.0.0 0.0.0.0 6.6.6.6 1
route rOutside 0.0.0.0 0.0.0.0 3.3.3.3 10
route inside 10.10.4.0 255.255.255.0 10.10.3.1 1
route inside 10.10.8.0 255.255.255.0 10.10.3.1 1
route inside 10.10.9.0 255.255.255.0 10.10.3.1 1
route inside 10.10.15.0 255.255.255.0 10.10.3.1 1
route rOutside x.x.x.x 255.255.255.255 5.5.5.5 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
timeout tcp-proxy-reassembly 0:01:00
dynamic-access-policy-record DfltAccessPolicy
http server enable
http 10.10.3.77 255.255.255.255 inside
http 10.10.8.157 255.255.255.255 inside
http 10.10.3.59 255.255.255.255 inside
no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
sla monitor 123
type echo protocol ipIcmpEcho 8.8.8.8 interface outside
num-packets 3
frequency 10
sla monitor schedule 123 life forever start-time now
crypto ipsec transform-set cpa esp-3des esp-md5-hmac
crypto ipsec security-association lifetime seconds 28800
crypto ipsec security-association lifetime kilobytes 4608000
crypto map vpn_cpa 1 match address acl_cpavpn
crypto map vpn_cpa 1 set peer a.a.a.a
crypto map vpn_cpa 1 set transform-set abc
crypto map vpn_cpa 1 set security-association lifetime seconds 3600
crypto map vpn_cpa interface outside
crypto isakmp identity address
crypto isakmp enable outside
crypto isakmp policy 10
authentication pre-share
encryption 3des
hash md5
group 2
lifetime 86400
crypto isakmp policy 65535
authentication pre-share
encryption 3des
hash sha
group 2
lifetime 86400
track 1 rtr 123 reachability
telnet 10.10.3.77 255.255.255.255 inside
telnet 10.10.8.157 255.255.255.255 inside
telnet 10.10.3.61 255.255.255.255 inside
telnet timeout 500
ssh timeout 5
console timeout 0
threat-detection basic-threat
threat-detection statistics port
threat-detection statistics protocol
threat-detection statistics access-list
no threat-detection statistics tcp-intercept
ntp server 10.10.3.14
webvpn
tunnel-group .a.a.a.a ipsec-attributes
pre-shared-key *
class-map inspection_default
match default-inspection-traffic
policy-map type inspect dns preset_dns_map
parameters
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect netbios
inspect rsh
inspect rtsp
inspect skinny
inspect esmtp
inspect sqlnet
inspect sunrpc
inspect tftp
inspect sip
inspect xdmcp
service-policy global_policy global
smtp-server 10.10.5.11
prompt hostname context
Cryptochecksum:eea6e7b6efe5d1a180439658c3912942
: end
i think half of the configuration stil there in the ASA.
Diagram.
Thanks
Roopesh
You have missed the last command in your configuration, Please check it again
route ISP1 0.0.0.0 0.0.0.0 6.6.6.6 track 1
route ISP2 0.0.0.0 0.0.0.0 3.3.3.3
sla monitor 10
type echo protocol ipIcmpEcho 8.8.8.8 interface ISP1
num-packets 3
frequency 10
sla monitor schedule 123 life forever start-time now
track 1 rtr 123 reachability
You can do NAT in same way, here the logical name of the interface will be different.
Share the result
Please rate any helpful posts.
Similar Messages
-
Need help for configuring integration scenario for AII
Hi,
We are referring to "RFID-Enabled Outbound Processing: Configuration Guide" for transferring materials from ECC to AII through XI.
So far we have been successful sending the IDOC to XI.
When we display the XML message in XI using IDX5, we get the error message "No receiver could be determined".
I request you to help us with the configuration of the integration scenario in XI.
Regards.
GauravHi Yogesh,
Thanks for reply.
Maintaining XI Directory configuration
u2022 Generate business scenario using business scenario configurator
u2022 Creating a scenario
It is fine upto these two steps
u2022 assigning business systems
We have assigned "AII" business system
only (receiver)
u2022 creating communication channels
Following parameters are set for comm channel
Adapter type: HTTP
Configured as Receiver
Transport Protocol: HTTP: 1.0
Message Protocol: XI payload in HTTP Body
Adapter engine: Integration server
Addressing type: URL Address
Target host: <name of AII system>
Service number: <service no>
path prefix: /sap/xi/engine?type=entry
u2022 defining receiver determinations
u2022 defining interface determinations
u2022 defining receiver agreements
All these were generated automatically
Are these configurations alright?
Regards,
Gaurav -
if a rip enabled primary interface goes down and is backed up by a dialer 1 Floating static route with an admin distance of e.g 200 can a second Dialer 2 be configured to connect to the same location via a second floating static route e.g admin cost 240. In the event of Dialer 1 not connecting.
Hi Larry,
I've given this a bit of thought and believe that you can possibly get this going using the feature 'Reliable Static Routing Backup Using Object Tracking'. There's some info and examples regarding this here:
http://www.cisco.com/univercd/cc/td/doc/product/software/ios123/123newft/123limit/123x/123xe/dbackupx.htm#wp1071672
Essentially, you would use the 'track' keyword with the 'ip route' statement for the floating static route for your first dialer. The static route would only be installed if you had actual connectivity over this dialer. If your dialer does not come up, the track object will change status to down and bring down that floating static route, enabling your third static default route to kick in.
I have not tried this personally but the approack makes sense...
Hope that helps - pls rate the post if it does.
Regards,
Paresh -
Need help Setting up Multiple Static Ip , 1 for each port of the fios router
Need help Setting up multiple Static Ip on my fios router
I have been trying to figure out how to set up multiple ip in my fios router.
However I kind of managed how to set up multiple static ip However the way I want it is for each port of my router to have an external ip signed to it. ( like 4 different modem in 1 )
Verizon gave me 5 static ip but they can not help me how to set it up.
Have anyone here done more then one static ip on different ports? I assume that the process will be the after the second static ip.You want to set up Static Nat. You will not assign the IP to a port, but rather to a local machine. Figure out what machines you want your IP's to go to. Under the firewall section you will see static nat. Pick the machine you want and enter one of the IP's you were assigned.
-
I´m doing a design for presale, where I will need a router what support PAT for 500 or a little more of users, it not need any more features only static routing and dhcp pool for 500 users, can you help me for know what router recommend?
What is your WAN speed currently and projected WAN speed in the next 3 years?
-
Hi All,
I need help on Configuring the Site to Site VPN from Cisco 2811 to Websense Cloud for web Traffic redirect
2811 having C2800NM-ADVIPSERVICESK9-M
2811 router connects to the Internet SW then connects to the Internet router.
Note- For Authentication am using the Device ID & Pre share key. I am worried as all user traffic goes with PAT and not firing up my tunnel for port 80 traffic. Can you please suggest what can be the issue ?
Below is router config for VPN & NAT
crypto keyring ISR_Keyring
pre-shared-key hostname vpn.websense.net key 2c22524d554556442d222d565f545246
crypto isakmp policy 1
encr 3des
authentication pre-share
group 2
crypto isakmp keepalive 10
crypto isakmp profile isa-profile
keyring ISR_Keyring
self-identity user-fqdn [email protected]
match identity user vpn-proxy.websense.net
crypto ipsec transform-set ESP-NULL-SHA esp-null esp-sha-hmac
crypto map GUEST_WEB_FILTER 10 ipsec-isakmp
set peer vpn.websense.net dynamic
set transform-set ESP-NULL-SHA
set isakmp-profile isa-profile
match address 101
interface FastEthernet0/1
description connected to Internet
ip address 216.222.208.101 255.255.255.128
ip access-group HVAC_Public in
ip nat outside
ip virtual-reassembly
duplex full
speed 100
no cdp enable
crypto map GUEST_WEB_FILTER
access-list 101 permit tcp 192.168.8.0 0.0.3.255 any eq www
access-list 103 deny ip 192.168.8.0 0.0.3.255 host 85.115.41.187 log
access-list 103 deny ip 192.168.8.0 0.0.3.255 host 85.115.41.181 log
access-list 103 deny ip 192.168.8.0 0.0.3.255 host 85.115.41.182 log
access-list 103 deny ip 192.168.8.0 0.0.3.255 86.111.216.0 0.0.1.255
access-list 103 deny ip 192.168.8.0 0.0.3.255 116.50.56.0 0.0.7.255
access-list 103 deny ip 192.168.8.0 0.0.3.255 86.111.220.0 0.0.3.255
access-list 103 deny ip 192.168.8.0 0.0.3.255 103.1.196.0 0.0.3.255
access-list 103 deny ip 192.168.8.0 0.0.3.255 177.39.96.0 0.0.3.255
access-list 103 deny ip 192.168.8.0 0.0.3.255 196.216.238.0 0.0.1.255
access-list 103 permit ip 192.168.8.0 0.0.3.255 any
ip nat pool mypool 216.222.208.101 216.222.208.101 netmask 255.255.255.128
ip nat inside source list 103 interface FastEthernet0/1 overload
ip nat inside source route-map nonat pool mypool overloadHow does Websense expect your source IPs in the tunnel? 192.168.8.0 0.0.3.255 or PAT'ed 216.222.208.101 ?
Check
show crypto isakmp sa
show crypto ipsec sa
show crypto session
You'd better remove the preshared key from your post. -
Need help for access list problem
Cisco 2901 ISR
I need help for my configuration.... although it is working fine but it is not secured cause everybody can access the internet
I want to deny this IP range and permit only TMG server to have internet connection. My DHCP server is the 4500 switch.
Anybody can help?
DENY 10.25.0.1 – 10.25.0.255
10.25.1.1 – 10.25.1.255
Permit only 1 host for Internet
10.25.7.136 255.255.255.192 ------ TMG Server
Using access-list.
( Current configuration )
object-group network IP
description Block_IP
range 10.25.0.2 10.25.0.255
range 10.25.1.2 10.25.1.255
interface GigabitEthernet0/0
ip address 192.168.2.3 255.255.255.0
ip nat inside
ip virtual-reassembly in max-fragments 64 max-reassemblies 256
duplex auto
speed auto
interface GigabitEthernet0/1
description ### ADSL WAN Interface ###
no ip address
pppoe enable group global
pppoe-client dial-pool-number 1
interface ATM0/0/0
no ip address
no atm ilmi-keepalive
interface Dialer1
description ### ADSL WAN Dialer ###
ip address negotiated
ip mtu 1492
ip nat outside
no ip virtual-reassembly in
encapsulation ppp
dialer pool 1
dialer-group 1
ppp authentication pap callin
ppp pap sent-username xxxxxxx password 7 xxxxxxxxx
ip nat inside source list 101 interface Dialer1 overload
ip route 0.0.0.0 0.0.0.0 Dialer1
ip route 10.25.0.0 255.255.0.0 192.168.2.1
access-list 101 permit ip 10.25.0.0 0.0.255.255 any
access-list 105 deny ip object-group IP any
From the 4500 Catalyst switch
( Current Configuration )
interface GigabitEthernet0/48
no switchport
ip address 192.168.2.1 255.255.255.0 interface GigabitEthernet2/42
ip route 0.0.0.0 0.0.0.0 192.168.2.3Hello,
Host will can't get internet connection
I remove this configuration...... access-list 101 permit ip 10.25.0.0 0.0.255.255 any
and change the configuration .... ip access-list extended 101
5 permit ip host 10.25.7.136 any
In this case I will allow only host 10.25.7.136 but it isn't work.
No internet connection from the TMG Server. -
I have a PC and a need help to configure my external hard disk on my network. Thanks
I have a PC and a need help to configure my external hard disk on my network. Thanks
If you mean you wish to plug a USB drive into the Airport Extreme router (or TC not express) that is easy..
The disk must be formatted FAT32.. as if.. stay away from FAT .. or HFS+ ie Mac OS extended Journaled.
Format the disk on a Mac is best.. and even use GUID partition scheme not MBR.
The PC has no issue writing and reading files because this is a network drive.. The PC does not write to the drive.. it writes files to the Airport OS which writes and reads the disk and passes the info using standard windows SMB.. To the windows computer it will be a Windows NT server.. FAT32 setup.
If your setup is different.. to my hugely guessed assumptions.. give details.. always helps to have.. make and model.
Make and model of disk.. make and model of router.. how the setup will be done.. what windows OS you run.. etc etc.
As it stands your question could have nothing to do with apple at all.. other than you posted in a forum so I guess there is something apple in there somewhere. -
I have problem with buying in games , I got the massage that the purchased can not be completed , please contact iTunes support.. I need help for my case please
http://www.apple.com/support/itunes/contact/
-
Hi I need Help for Formating HD so Wat Key need hold on start up for format HD I apprciated you Help
Jesus:
Formatting, Partitioning Erasing a Hard Disk Drive
Warning! This procedure will destroy all data on your Hard Disk Drive. Be sure you have an up-to-date, tested backup of at least your Users folder and any third party applications you do not want to re-install before attempting this procedure.
• With computer shut down insert install disk in optical drive.
• Hit Power button and immediately after chime hold down the "C" key.
• Select language
• Go to the Utilities menu (Tiger) Installer menu (Panther & earlier) and launch Disk Utility.
• Select your HDD (manufacturer ID) in left side bar.
• Select Partition tab in main panel. (You are about to create a single partition volume.)
• _Where available_ +Click on Options button+
+• Select Apple Partition Map (PPC Macs) or GUID Partition Table (Intel Macs)+
+• Click OK+
• Select number of partitions in pull-down menu above Volume diagram.
(Note 1: One partition is normally preferable for an internal HDD.)
• Type in name in Name field (usually Macintosh HD)
• Select Volume Format as Mac OS Extended (Journaled)
• Click Partition button at bottom of panel.
• Select Erase tab
• Select the sub-volume (indented) under Manufacturer ID (usually Macintosh HD).
• Check to be sure your Volume Name and Volume Format are correct.
• Click Erase button
• Quit Disk Utility.
cornelius -
Need help for my requirement...
Need help for my requirement...
Hello Experts,
I have report where users can input the company, housebank, account ID and posting date.
Now in one column of my report named 'Cash in Bank', I need to get all postings from cash
accounts with GL code ending in '0'. Now, I know that I can get the amounts in BSIS/BSAS
but how do I link it with the proper bank and account?
For example:
Cash in Bank
Bank A
Account ID 1 1,000,000
Account ID 2 25,000,000
Hope you can help me guys. Thank you and take care!hi Viraylab,
each house bank you can find in table T012, in T012K you'll find the bank accounts to the housebank, the G/L account will be in T012K-HKONT.
hope this helps
ec -
i need help for flash builder 4 and papervison 3d. I need to create a slider with it ranges of value from 10 to 50 to adjust the camera values for the camera.fov and also need to create it for the yaw of the object from 0 to 360. I try to look for any slider event and classes in this program but cant find any, btw, i need to use the AS only project file.
here is my codes:
can you please tell me how i should modify the codes?
package
import flash.display.BitmapData;
import flash.display.Sprite;
import flash.events.Event;
import org.papervision3d.materials.BitmapFileMaterial;
import org.papervision3d.materials.BitmapMaterial;
import org.papervision3d.objects.primitives.Sphere;
import org.papervision3d.view.BasicView;
[SWF (width="800", height="600", backgroundColor="0x000000",frameRate="30")]
public class EarthBitmap extends BasicView
private var sphere:Sphere;
public function EarthBitmap()
super(800 , 600);
var earthmaterial:BitmapFileMaterial = new BitmapFileMaterial("../assets/Earth.jpg");
sphere = new Sphere(earthmaterial,100,20,18);
camera.fov = 25;
scene.addChild(sphere);
addEventListener(Event.ENTER_FRAME,rotateSphere);
public function rotateSphere(evt:Event):void
sphere.yaw(0.2);
singleRender();Turn the click handler into a full on separate function. Then store all the views in an array and use Math.rand() to randomly choose one.
Something like this:
<fx:Script>
<![CDATA[
var questionsArray:Array = {question2,question3,question5,questionRed,questionGeography};
function buttonClickHandler(event:MouseEvent){
var randomProblem:int = Math.floor(Math.random()*(questionsArray.length)); //generates a random integer between 0 and the total number of questions in the array (arrays are 0-based)
navigator.pushView(questionsArray[randomProblem]);
]]>
</fx:Script>
<s:Button id="randomProblemButton" label="Next Problem" click="buttonClickHandler(event)" />
Haven't tested that, but something along that line should work -
Need help for importing oracle 10G dump into 9i database
hi, Someone help me to import oracle 10G dump into 9i database. I'm studying oracle . Im using oracle 10G developer suite(downloaded from oracle) and oracle 9i database. I saw some threads tat we can't import the higher version dumps into lower version database. But i'm badly need help for importing the dump...
or
someone please tell me the site to download oracle 9i Developer suite as i can't find it in oracle site...I didnt testet it to import a dump out of a 10g instance into a 9i instance if this export has been done using a 10g environment.
But it is possible to perform an export with a 9i environment against a 10g instance.
I am just testing this with a 9.2.0.8 environment against a 10.2.0.4.0 instance and is working so far.
The system raises an EXP-00008 / ORA-37002 error after exporting the data segments (exporting post-schema procedural objects and actions).
I am not sure if it is possible to perform an import to a 9i instance with this dump but maybe worth to give it a try.
It should potentially be possible to export at least 9i compatible objects/segments with this approach.
However, I have my doubts if this stunt is supported by oracle ...
Message was edited by:
user434854 -
Need Help for Nokia 6500 slide
Hi all I'm A new Guy here ,
But I do really need help for hard reset my phone
I already try *#7073# But It doesn't work ,
If Anybody know to make a hard reset please helprwss wrote:
I'v got te same problem with my 6500 Slide, is there a button combination that we have to press
to hard reset the 6500 Slide?!
How does the 6500 slide hard reset?
That's simple.
All you have to do is:
From MENU goto SETTINGS, When there scroll down and select 'Restore Factory Setting'.
There are two options in there:
"Restore Settings only"
and
"Restore all"
Select "Restore All"
When done the phone will delete every thing on the Phone memory(C:\)(contacts,picture,messages etc)
and also restore phone to its original settings and will restart.
This proceedure is mostly common on S40 phone.
Hope this explain and solve the problem. -
Need help for publishing web intelligence document (universe) into InfoView
Post Author: mirage
CA Forum: Publishing
Hello all,
I need help for publishing web intelligence document (universe) into InfoView.
can't find this information in Business Objects Designer's Guide and in Business Objects Administrator Guide.
Can somebody give short instructions how can I do it?
Regards, SlavaIf the change between the 2 types of data has to happen dynamically during run time them
1. Use 2 dataproviders
a. Current
b. Historic
2. Merge the 2 dimensions
3. Use Webi variable to switch between the measure of the current and historic universe
Ex if [year] < 2010 then historic.[expense] else current.[expense]
Hope this helps,
Divya
Maybe you are looking for
-
How to do Title and Paragraph Side-by-side?
I'd like to switch from Word to Pages, but I need to figure out how to format a title and/or a subtitle such that it sits to the left of a paragraph (horizontally even) rather than above it. In Word, I would put the Headings/subheadings into a text b
-
Hi I have one product table. i am trying to create Alias on Product table. In physical layer i was right clicked on Product table. It shows all options( like New object, Update row count, view data.......etc) when i am moving cursor on New object it
-
Signature Images to be fetched according tocurrent user in Crystal report.
Hi Experts I am creating Report in which client wants the current users Signature picture to be fetched in the report at footer level. I have inserted the image on the report . but i am unable to apply logic that how the current users Signature pictu
-
Can I change my font size on Photosmart D 110
Can I change my font size on my Photosmart D 110 if so How?
-
Appending XML data to a file using file adaptor
Hi, I am trying to append data to a file using file adaptor in XML format. (Objective is to store data as XML message in the file). I understand it is possible to append data to an existing file by making appropriate changes in WSDL manually. However