1811W Router wi fi config

                   Hi all,
I have 1811w router and i need to config that for home wi fi.
IT has 2 interfaces
Router#sh ip int brief
Interface                  IP-Address      OK? Method Status                Prot
ocol
Async1                     unassigned      YES unset  down                  down
Dot11Radio0                unassigned      YES unset  up                    up
Dot11Radio1                unassigned      YES unset  ad
Need to know what should i config on Do1 radio for wi fi config?
Can i use only 1 interface or i need to use both?
Thanks
MAhesh

Radio 0 is the 2.4GHz, and Radio 1 is the 5GHz.
you can configure only one if you want, or you can have the same SSID on both.  you could even configure one SSID on R0, and a different one on R1 if you want to.
Any of the AP configuration guides, or walk throughs should work well to get you up and running.
http://www.cisco.com/en/US/docs/wireless/access_point/12.3_7_JA/configuration/guide/s37ssid.html
HTH,
Steve
Please remember to rate useful posts, and mark questions as answered

Similar Messages

  • Base wireless config - 1811w router

    Greetings,
    Is there any chance someone could sketch out a basic wireless configuration for a SOHO Cisco 1811W router? I just need the wireless to connect to the base wired LAN - with both WEP and MAC authentication. And - can the MAC auth. parameters be configured via CLI and not have to use either SDM or CP? I can access the router via SDM - but the Wirless Application will not fire up - and CP doesn't work at all.
    Thanks for any assistance you can lend.

    Hi,
    I have been following this discussion and I have exactly the same problem.
    Everything is already set. I followed the configuration above and I'm stock at "Why can't the wireless device or the dot11 radio obtain ip from dhcp server?"
    Any answer is very much appreciated.

  • Fields for Super BOM, Work Center & Super Routing for Variant Config

    hi! gurus,
    Please can you give me mandatory fields & values for Super BOM, Work Center & Super Routing for Variant Config
    thank you

    Hi,
    In the Super BOM you need to maintain the object dependencies.
    Workcenter fields are as usual for other production processes.
    Also you can use search option in the forum to view the threads posted in the past. There are many posts related to variant configuration.
    Regards,
    Senthilkumar

  • Not able to get outside of network on wireless - 1811W Router

    I have configured router to issue ip's on two vlan's. Vlan1 works fine, vlan2 is for the wirless issues the correct ip but not will not
    let me go the internet.
    Any help will be greatly appreciated.
    Current configuration : 9574 bytes
    ! Last configuration change at 17:43:57 PCTime Fri Aug 30 2013
    ! NVRAM config last updated at 15:36:03 PCTime Fri Aug 30 2013 by patrick
    version 12.4
    service timestamps debug datetime msec
    service timestamps log datetime msec
    no service password-encryption
    hostname St.Patricks
    boot-start-marker
    boot-end-marker
    logging message-counter syslog
    no logging buffered
    enable secret 5 $1$lvNA$wGnkzv7kjLmif0RNDxf2g0
    no aaa new-model
    clock timezone PCTime -6
    clock summer-time PCTime date Apr 6 2003 2:00 Oct 26 2003 2:00
    crypto pki trustpoint TP-self-signed-3607837666
    enrollment selfsigned
    subject-name cn=IOS-Self-Signed-Certificate-3607837666
    revocation-check none
    rsakeypair TP-self-signed-3607837666
    crypto pki certificate chain TP-self-signed-3607837666
    certificate self-signed 01
    30820243 308201AC A0030201 02020101 300D0609 2A864886 F70D0101 04050030
    31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
    69666963 6174652D 33363037 38333736 3636301E 170D3133 30383239 30363232
    34395A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
    4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 36303738
    33373636 3630819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
    8100E525 0425ECCD 2F904636 B21AF280 AD7993E4 8F79564C 6203B366 E769FAF5
    62DACE0A 40CFD386 0F5BD78F FE7C6A7C EACC4A3C 3F84A48C AC7D3280 9FF029BE
    D5BA4E83 00F7BD4B 11984721 76F5CCDF D03E6CD7 84195C8F 73D770C8 99734F0D
    4F583941 0BE9FD8D 87F3D876 FFDB0588 2BECA057 79DA62D2 AC47D3ED 6AE5C7F4
    B3AB0203 010001A3 6B306930 0F060355 1D130101 FF040530 030101FF 30160603
    551D1104 0F300D82 0B53742E 50617472 69636B73 301F0603 551D2304 18301680
    146385C7 4B02E815 B28909F2 2A604395 37FB3F60 21301D06 03551D0E 04160414
    6385C74B 02E815B2 8909F22A 60439537 FB3F6021 300D0609 2A864886 F70D0101
    04050003 81810067 7A20CF98 7D7FAC17 A5B73A4A 00BEAE11 3BFFF9BC 1A74E61A
    E7DC833C FDBA0BB8 A0F74011 C3B1F3AA 0CF39238 66A9AF5F EB62E3C3 D92A4289
    E6000537 D253E03F A1B95F7C A545EC84 14724057 E72DAEE2 568A7B40 174FEB03
    1373CFAE 4BEC84B1 794E3E1B D56E2DDC DD2B1162 7B0A782C A4D2391E 83DA63D6
    4CD7029D B9F668
           quit
    dot11 syslog
    dot11 vlan-name Wireless_VLAN vlan 2
    dot11 ssid St.Patricks_WiFi
    vlan 2
    authentication open
    authentication key-management wpa
    guest-mode
    mbssid guest-mode
    infrastructure-ssid optional
    wpa-psk ascii 0 patrick1
    ip source-route
    ip dhcp excluded-address 10.10.10.1 10.10.10.99
    ip dhcp excluded-address 10.10.11.1 10.10.11.99
    ip dhcp pool DHCP_POOL
       import all
       network 10.10.10.0 255.255.255.0
       dns-server 208.67.222.123 208.67.220.123
       default-router 10.10.10.1
       domain-name St.Patricks
    ip dhcp pool WireLess_Pool
       import all
       network 10.10.11.0 255.255.255.0
       domain-name St.Patricks_Wireless
       dns-server 208.67.222.123 208.67.220.123
       default-router 10.10.10.1
    ip cef
    ip name-server 208.67.222.123
    ip name-server 208.67.220.123
    no ipv6 cef
    multilink bundle-name authenticated
    username patrick privilege 15 secret 5 $1$MLJt$jLLnyQkm61ukzlwxHB/7f0
    archive
    log config
    hidekeys
    class-map type inspect match-any SDM_BOOTPC
    match access-group name SDM_BOOTPC
    class-map type inspect match-any SDM_HTTPS
    match access-group name SDM_HTTPS
    class-map type inspect match-any SDM_SSH
    match access-group name SDM_SSH
    class-map type inspect match-any SDM_SHELL
    match access-group name SDM_SHELL
    class-map type inspect match-any sdm-cls-access
    match class-map SDM_HTTPS
    match class-map SDM_SSH
    match class-map SDM_SHELL
    class-map type inspect match-any SDM_DHCP_CLIENT_PT
    match class-map SDM_BOOTPC
    class-map type inspect match-any ccp-skinny-inspect
    match protocol skinny
    class-map type inspect match-any sdm-cls-bootps
    match protocol bootps
    class-map type inspect match-any ccp-cls-insp-traffic
    match protocol cuseeme
    match protocol dns
    match protocol ftp
    match protocol https
    match protocol icmp
    match protocol imap
    match protocol pop3
    match protocol netshow
    match protocol shell
    match protocol realmedia
    match protocol rtsp
    match protocol smtp extended
    match protocol sql-net
    match protocol streamworks
    match protocol tftp
    match protocol vdolive
    match protocol tcp
    match protocol udp
    class-map type inspect match-all ccp-insp-traffic
    match class-map ccp-cls-insp-traffic
    class-map type inspect match-any ccp-h323nxg-inspect
    match protocol h323-nxg
    class-map type inspect match-any ccp-cls-icmp-access
    match protocol icmp
    match protocol tcp
    match protocol udp
    class-map type inspect match-any ccp-h225ras-inspect
    match protocol h225ras
    class-map type inspect match-any ccp-h323annexe-inspect
    match protocol h323-annexe
    class-map type inspect match-all sdm-access
    match class-map sdm-cls-access
    match access-group 101
    class-map type inspect match-any ccp-h323-inspect
    match protocol h323
    class-map type inspect match-all ccp-icmp-access
    match class-map ccp-cls-icmp-access
    class-map type inspect match-all ccp-invalid-src
    match access-group 100
    class-map type inspect match-any ccp-sip-inspect
    match protocol sip
    class-map type inspect match-all ccp-protocol-http
    match protocol http
    policy-map type inspect ccp-permit-icmpreply
    class type inspect ccp-icmp-access
    inspect
    class class-default
    pass
    policy-map type inspect ccp-inspect
    class type inspect ccp-invalid-src
    drop log
    class type inspect ccp-protocol-http
    inspect
    class type inspect ccp-insp-traffic
    inspect
    class type inspect ccp-sip-inspect
    inspect
    class type inspect ccp-h323-inspect
    inspect
    class type inspect ccp-h323annexe-inspect
    inspect
    class type inspect ccp-h225ras-inspect
    inspect
    class type inspect ccp-h323nxg-inspect
    inspect
    class type inspect ccp-skinny-inspect
    inspect
    policy-map type inspect ccp-permit
    class class-default
    drop
    zone security in-zone
    zone security out-zone
    zone-pair security ccp-zp-self-out source self destination out-zone
    service-policy type inspect ccp-permit-icmpreply
    zone-pair security ccp-zp-in-out source in-zone destination out-zone
    service-policy type inspect ccp-inspect
    zone-pair security ccp-zp-out-self source out-zone destination self
    service-policy type inspect ccp-permit
    bridge irb
    interface FastEthernet0
    description WAN$FW_OUTSIDE$
    ip address dhcp
    ip nat outside
    ip virtual-reassembly
    zone-member security out-zone
    duplex auto
    speed auto
    interface FastEthernet1
    no ip address
    shutdown
    duplex auto
    speed auto
    interface FastEthernet2
    interface FastEthernet3
    interface FastEthernet4
    interface FastEthernet5
    interface FastEthernet6
    interface FastEthernet7
    interface FastEthernet8
    interface FastEthernet9
    interface Dot11Radio0
    no ip address
    no dot11 extension aironet
    encryption vlan 2 mode ciphers tkip
    broadcast-key vlan 2 change 30
    ssid St.Patricks_WiFi
    mbssid
    speed basic-1.0 basic-2.0 basic-5.5 6.0 9.0 basic-11.0 12.0 18.0 24.0 36.0 48.0 54.0
    station-role root
    interface Dot11Radio0.2
    encapsulation dot1Q 2 native
    bridge-group 1
    bridge-group 1 subscriber-loop-control
    bridge-group 1 spanning-disabled
    bridge-group 1 block-unknown-source
    no bridge-group 1 source-learning
    no bridge-group 1 unicast-flooding
    interface Dot11Radio1
    no ip address
    no dot11 extension aironet
    encryption vlan 2 mode ciphers tkip
    broadcast-key vlan 2 change 30
    ssid St.Patricks_WiFi
    speed basic-6.0 9.0 basic-12.0 18.0 basic-24.0 36.0 48.0 54.0
    station-role root
    interface Dot11Radio1.2
    encapsulation dot1Q 2 native
    bridge-group 1
    bridge-group 1 subscriber-loop-control
    bridge-group 1 spanning-disabled
    bridge-group 1 block-unknown-source
    no bridge-group 1 source-learning
    no bridge-group 1 unicast-flooding
    interface Vlan1
    description $FW_INSIDE$
    ip address 10.10.10.1 255.255.255.0
    ip nat inside
    ip virtual-reassembly
    zone-member security in-zone
    interface Vlan2
    ip address 10.10.11.1 255.255.255.0
    bridge-group 1
    interface Async1
    no ip address
    encapsulation slip
    interface BVI1
    ip address 10.10.11.1 255.255.255.0
    ip forward-protocol nd
    ip http server
    ip http authentication local
    ip http secure-server
    ip http timeout-policy idle 60 life 86400 requests 10000
    ip nat inside source list 1 interface FastEthernet0 overload
    ip access-list extended SDM_BOOTPC
    remark CCP_ACL Category=0
    permit udp any any eq bootpc
    ip access-list extended SDM_HTTPS
    remark CCP_ACL Category=1
    permit tcp any any eq 443
    ip access-list extended SDM_SHELL
    remark CCP_ACL Category=1
    permit tcp any any eq cmd
    ip access-list extended SDM_SSH
    remark CCP_ACL Category=1
    permit tcp any any eq 22
    access-list 1 remark CCP_ACL Category=2
    access-list 1 permit 10.10.10.0 0.0.0.255
    access-list 1 remark Wireless
    access-list 1 permit 10.10.11.0 0.0.0.255
    access-list 100 remark CCP_ACL Category=128
    access-list 100 permit ip host 255.255.255.255 any
    access-list 100 permit ip 127.0.0.0 0.255.255.255 any
    access-list 101 remark CCP_ACL Category=128
    access-list 101 permit ip any any
    control-plane
    bridge 1 protocol ieee
    bridge 1 route ip
    banner motd ^C
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    YOU ARE NO AUTHORIZED -------- SEE ADMINISTRATOR
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ^C
    alias exec s show ip int br
    alias exec sr show run
    line con 0
    exec-timeout 0 0
    logging synchronous
    line 1
    modem InOut
    stopbits 1
    speed 115200
    flowcontrol hardware
    line aux 0
    line vty 0 4
    login
    transport input telnet ssh
    end

    Things looks a little weird with the VLAN 2 interface having an IP address. Once you create the BVI interface that is where all of the layer 3 stuff should go.
    I would so try adding IP NAT inside to the BVI interface.
    Elton
    Sent from Cisco Technical Support iPhone App

  • 1811W router unable to get DHCP IP from Speedstream 4100

    I have a Yahoo-ATT DSL installation with 1 dynamic IP address. It uses an ISP supplied speedstream 4100 DSL modem. The 4100 appears to take care of all the PPOE duties and DHCP connections from PCs or low-end routers (I'm temporarily using a NetGear unit) work fine.
    BUT, when I swap the Netgear out for my new 1811W, the cisco unit is unable to obtain a DHCP address from the modem. I can see the request on the modem lights when I do a "no shutdown fastethernet0"...but I never get an IP address.
    The speedstream appears to support 100Mbps and I have tried 100, 10 and Auto on the 1811W. I can look at the log on the modem and it does not show any activity by the modem's dhcp service. However, when I swap back to the netgear unit, I can see appropriate entries in the modem log.
    The 1811 is new and I strongly suspect its working ...I tested it on a different DSL line that had static IP. I see a number of similar issues in this forum; but have not seen any resolution that seems to fit my situation.
    Any help/suggestions would be appreciated...my next step will be log the DHCP packets with a sniffer. I think I know what I"ll see...1811W DHCP broadcast...no response. But, that won't help me resolve the issue.
    Thanks,
    Chuck McP

    Hi, this would a config example once you configure the dsl modem for bridging:
    http://www.cisco.com/en/US/tech/tk175/tk15/technologies_configuration_example09186a0080126dc0.shtml
    look at the 2600 part. you can omit these commands that are for older versions:
    vpdn enable
    no vpdn logging
    vpdn-group 1
    request-dialin
    protocol pppoe
    Hope this helps, please rate post if it does!

  • EA4500 behind NAT Router - would cloud config work?

    This is the topology:  
    Internet +--(coax)--+ Modem/Wired Router Combo +--(cat5e)--+ EA4500
    Would it EVER be possible to configure the EA4500 with CiscoConnectCloud?   How could the cloud reach through to it?  
    I have an EA4500 that I have never been able to associate with a cloud account. 
    With another wireless router, all I did was turn off DHCP service on the wireless router, and plug the upstream ethernet cable into an ethernet port (i.e. the cat5e goes into the blue, not yellow, port.) and let it rip. 
      I wouldn't deliberately choose cloud config for this, but I am here.  Is it even possible?

    Thank you for your careful answer.  These are really good suggestions, and I bet they will help many people.   In fact, at my house I should implement them even though my current best router is a Netgear N600 type.   That sounds bizarre, but it is because this EA4500 isn't mine. 
    It belongs to my parents, a thousand miles away.  Last April when I visited them, I set them up with a Roku XS.  They have necessary activities going on their computers, active trading and such.  Because I'm not there, at my recommendation, they rent their networking stuff from Comcast, so Comcast can help them if there's a problem.  They live in one of those houses that originally was one fourth of its current size, so they have different density walls, many different base electrical circuits: not what is best for wireless networking.  Their established wireless setup couldn't begin to deliver to the TV.
    I knew it was rather insulting to the EA4500, but I bought it and set it up solely to deliver content to the Roku.  I also figured if their wimpy wireless went out and Comcast made them wait, I would just tell them how to connect to the Cisco, as a backup, if necessary.   They didn't use the Roku a whole lot, and for a while they thought they did something wrong.  So it was a while before I even heard about their issues. It was a very early unit, purchased on April 9.  I may also have jumped to a conclusion - they said it stopped working in the week or two before the Fourth of July. , Dad and I did a lot of sleuthing over the phone, on and off for weeks.  Then  I assumed it was the firmware update that broke their connectivity.  So this week when I had them ship me the router so I could work on it at my house.
    Your ideas are great and I am going to set it up here the way you both say and let the Cisco do the heavy lifting.  That will tell me for sure whether the thing is working properly. 
    Because for right now, the only way it works as a router is when it is dumb and connected via LAN not WAN.  It's the only way I can log in to configure it, and it's the only way I can connect to the internet "through" it.  I've been going back and forth between the firmware versions, topology, and wireless versus wired.  And resetting.  Gosh, thanks for getting me out of that rat trap!  

  • Easy way to erase a router's config & reload an IOS? Dont know passwords..

    I've been given a couple of 3640 routers, one of them had no config and I was able to work with it. The other 3640 had some config on there and heres what I've done so far.
    *Change config regsiter and booted up to access the startup config.
    *Copied all data
    *Whenever I do the command "copy start run" I get some weird memory dump issues (but that is besides the point) and I cant change any data or do any commands.
    I want to erase the router and put a new IOS on it. I dont know any passwords how do I do this easily? Im guessing a simple config register change from within ROMON mode????
    Anyone have a how to: for me????

    If you do the parts of password recovery that deal with accessing the router, setting the config register to 0x2142, and booting the router you will have wiped the config and kept the IOS. You do not need to do the other parts of password recovery. Once you have wiped the config and booted the router be sure to set the config register back to its normal value (probably 0x2102).
    In looking at the error that you describe, this part (%AAAA-3-INVSTATE) seems to indicate that the error is generated in AAA. We do not know what is in the existing config, but I believe that it is something in the existing config that is causing your problem and not some inherent problem in the router.
    Try just setting the config register to 0x2142 and booting the router and let us know if that worked.
    HTH
    Rick

  • Copy startup-config tftp + %Error opening tftp://192.168.0.12/router-confg (Socket error)

    Please advise me on the below error;; I am using tftpd for tft
    Router#copy startup-config tftp
    Address or name of remote host []? 192.168.0.12
    Destination filename [router-confg]?
    %Error opening tftp://192.168.0.12/router-confg (Socket error)

    This was the right answer.. Solved
    https://learningnetwork.cisco.com/thread/56041
    im surprised you can ping without attaching a crossover cable.
    because if your only using your console port to connect your pc...then you dont have ip connectivity
    i think the cable your using to connect your pc to your router fa port is a straight through ethernet cable....
    you see it attaches to a switch port in the back of your home router(not cisco router)
    not a router port.
    so you need a different cable depending on how you want to connect to your router.
    you can check to see if it is a crossover cable
    just peer down the end of the cable you can see the colours...
    if they are in the same order on each end...then it is a straight through cable
    if they have a different order...then it is a crossover cable
    if your connecting to your pc via your home router.
    then yes.....you need to plug a straight through cable into your cisco router from your home router
    and it will work
    if your connecting your pc directly to your router
    then you need to use  a crossover cable from the back of your pc...to your cisco router.
    and it will work

  • Existing 1811W, need to turn on wireless

    I have an existing Cisco 1811W router, running just fine, but now I need to turn on wireless. All of the web docs that I see seem to involve turning on bridging? shouldn't it be sufficient just to put the Dot11Radio0 and Dot11Radio1 interfaces into the existing Vlan1 that the FastEthernet ports are already in or am I missing something obvious?
    Does anyone have any good pointers to example wireless configs that I can use for templates for the 1811W router?

    if you do not turn on bridging, then the wireless must have a diferent segment
    example:
    ethernet 192.168.10.10
    wireless 192.168.20.10
    and if you turn bridging on that way you can put in the same vlan and same segment

  • Problem of routing between inside and outside on ASA5505

    I have a ASA5505 with mostly factory default configuration. Its license allows only two vlan interfaces (vlan 1 and vlan 2). The default config has interface vlan 1 as inside (security level 100), and interface vlan 2 as outside (security level 0 and using DHCP).
    I only changed interface vlan 1 to IP 10.10.10.1/24. After I plugged in a few hosts to vlan 1 ports and connect port Ethernet0/0 (default in vlan 2) to a live network, here are a couple of issues I found:
    a) One host I plugged in is a PC, and another host is a WAAS WAE device. Both are in vlan 1 ports. I hard coded their IP to 10.10.10.250 and 10.10.10.101, /24 subnet mask, and gateway of 10.10.10.1. I can ping from the PC to WAE but not from WAE to the PC, although the WAE has 10.10.10.250 in its ARP table. They are in the same vlan and same subnet, how could it be? Here are the ping and WAE ARP table.
    WAE#ping 10.10.10.250
    PING 10.10.10.250 (10.10.10.250) from 10.10.10.101 : 56(84) bytes of data.
    --- 10.10.10.250 ping statistics ---
    5 packets transmitted, 0 packets received, 100% packet loss
    WAE#sh arp
    Protocol Address Flags Hardware Addr Type Interface
    Internet 10.10.10.250 Adj 00:1E:37:84:C9:CE ARPA GigabitEthernet1/0
    Internet 10.10.10.10 Adj 00:14:5E:85:50:01 ARPA GigabitEthernet1/0
    Internet 10.10.10.1 Adj 00:1E:F7:7F:6E:7E ARPA GigabitEthernet1/0
    b) None of the hosts in vlan 1 in 10.10.10.0/24 can ping interface vlan 2 (address in 172.26.18.0/24 obtained via DHCP). But on ASA routing table, it has both 10.10.10.0/24 and 172.26.18.0/24, and also a default route learned via DHCP. Is ASA able to route between vlan 1 and vlan 2? (inside and outside). Any changes I can try?
    Here are ASA routing table and config of vlan 1 and vlan 2 (mostly its default).
    ASA# sh route
    Codes: C - connected, S - static, I - IGRP, R - RIP, M - mobile, B - BGP
    D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
    N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
    E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
    i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
    * - candidate default, U - per-user static route, o - ODR
    P - periodic downloaded static route
    Gateway of last resort is 172.26.18.1 to network 0.0.0.0
    C 172.26.18.0 255.255.255.0 is directly connected, outside
    C 127.1.0.0 255.255.0.0 is directly connected, _internal_loopback
    C 10.10.10.0 255.255.255.0 is directly connected, inside
    d* 0.0.0.0 0.0.0.0 [1/0] via 172.26.18.1, outside
    interface Vlan1
    nameif inside
    security-level 100
    ip address 10.10.10.1 255.255.255.0
    interface Vlan2
    nameif outside
    security-level 0
    ip address dhcp setroute
    interface Ethernet0/0
    switchport access vlan 2
    All other ports are in vlan 1 by default.

    I should have made the config easier to read. So here is what's on the ASA and the problems I have. The ASA only allows two VLAN interfaces configured (default to Int VLAN 1 - nameif inside, and Int VLAN 2 - nameif outside)
    port 0: in VLAN 2 (outside). DHCP configured. VLAN 2 pulled IP in 172.26.18.0/24, default gateway 172.26.18.1
    port 1-7: in VLAN 1 (inside). VLAN 1 IP is 10.10.10.1. I set all devices IP in VLAN 1 to 10.10.10.0/24, default gateway 10.10.10.1
    I have one PC in port 1 and one WAE device in port 2. PC IP set to 10.10.10.250 and WAE set to 10.10.10.101. PC can ping WAE but WAE can't ping PC. Both can ping default gateway.
    If I can't ping from inside interface to outside interface on ASA, how can I verify inside hosts can get to outside addresses and vise versa? I looked at ASA docs, but didn't find out how to set the routing between inside and outside. They are both connected interfaces, should they route between each other already?
    Thanks a lot

  • Swap Actiontec MI424WR Router

    Verizon needed to swap my Actiontec MI424WR router for performance reasons.  However I had a significant amount of time invested in my configuration so I was reluctant to agree.  Fortunately I had 7 versions of my configuration saved.  It was my understanding from talking with Verizon that I should be able to load saved configurations into the new router.  However when I go to do this I get ...
    The configuration file that you are trying to load does not match this device I could    save a configuration file from the old router and load it into the old router.I can       save a configuration file from the new router and load it into the new router.I cannot  save a configuration file from the old router and load it into the old router. I can save a configuration file from the new router  and load a configuration from the new Has anyone successfully swapped an Actiontec device or solved this issue? There are the specs for the new router ... unfortunately I don't know the specs for the old one as Verizon took it. Firmware Version: 20.10.7.5  Model Name: MI424WR-GEN2  Hardware Version: F Got a response from Verizon and Actiontec and it's not a good one.  Configuration files are specific to device therefore new devices must always be configured manually. Does this make any sense?

    This got off topic real quick but I have the same issue as the original poster, A LOT of time invested in configuration especially for VoIP QOS as that is not documented very well nor do the Verizon techs understand anything in that arena much less general networking and always respond with we don't support QOS.  Really?  Better get w/ the rest of the world if you want to keep customers Verizon!!! I was actually told by a tech that if my speeds are in the kb's for a 150/150 plan it can only mean I have some malware or a virus on my system.  His claim was that a higher level tech had told him this is a factual rule.  He stuck tight to this claim even after I told him I atached a single, "flashed-to-factory" tablet with a direct ethernet connection directly to the router with no other devices connected and wireless disabled, had the same exact issue as the other PCs.  Yes, a virus or malware *could* be a problem in some circumstances but this guy was clinging to it like it was always the case which is rediculous.  I went on to prove that if what he was saying was true, why would my mobile devices experience this horrible connection speed when *ONLY* connected to the FiOS router and not other networks???  Idiot. Back to the config file.  I've checked both routers and they are identical in model, version, firmware and both are gen3 I.  The details under System Monitoring > Router Status is identical (except for obvious serial # and MAC of course). So it appears that this actiontec feature was intentionally hacked by Verizon which really gets under my skin.  I am sure they do this so people don't load corrupt or misconfigured configuration files into the new router and still complain about the same issue they were having.  But this is a very shoddy way to NOT have to provide the proper support where a real qualified technician should be able to identify BEFORE changing out the router if the config file is the issue or not. My biggest gripe is the techs that work at Verizon that I have dealt with have a very poor understanding of common networking concepts, troubleshooting methods and how routers actually work and I don't agree with Verizon's blatent decision to remove this capability as if they know better then their cutomers whats good for them. Now I have to go through and screen shot every config page and manually key in everything.  What a PIA especially when I'm absolutely certain the issue is the chewed up fiber strands I can visually see with my eyes in my yard from gophers but the verizon tech still thinks it's the router!!!  Idiot. POOR MOVE VERIZON.

  • ISE version 1.3 and static route not working

    This command works without any issues with ISE version 1.1 and 1.2:
    ip route 192.168.1.1 255.255.255.255 gateway 127.0.0.1
    However, it does NOT work in ISE version 1.3.  See below:
    ciscoisedev/admin(config)# ip route 192.168.1.1 255.255.255.255 gateway 127.0.0.1
    % Warning: Could not find outgoing interface for gateway 127.0.0.1 while trying to add the route.
    % Error: Error adding static route.
    ciscoisedev/admin(config)#
    Any ideas anyone?

    So it appears that there is no option to lock down access to the shell now that the command that you used to use is no longer valid. What is worse is that there isn't an option to create an ACL in the shell that you could attach to the interface. So I would recommend that you create a defect with Cisco TAC and get this re-added or request that ACL functionality is added. 
    For the GUI (in case you were not already aware of this), you can restrict access from Administration > Admin Access > Settings > Access > IP Access

  • H323 static Nat doesn't work fine on 3900 series router with IOS 15.2(3) T

    Hi,
    I have a problem with static nat setting on my 3925 router with IOS15.2(3). The scenario is like this:
    I set a static nat between 172.16.1.2 and x.x.x.x(public IP address) using following command:
    ip nat inside source static 172.16.1.2 x.x.x.x
    The intranet IP address is set on a video conference system from Huawei, after setting all these things, ping works fine to this public IP address, but video conference cannot be built. I tried same setting using another 2811 router with IOS12.4 and it worked fine. Which means the problem should be isolated to this 3925 router. Full config is also attached, sorry that I elimated the public IP address and use other characters instead.
    Additionally, I debugged ip natting and I see following information when making video calls:
    router#debug ip nat h323
    IP NAT H323 debugging is on
    router#                
    *Jul 10 09:11:07.343: NAT[0]: H323: received pak, payload_len=0
    *Jul 10 09:11:07.343: [NAT[0]: H323 ACK packet ? FALSE
    *Jul 10 09:16:15.731: NAT[1]: H323: received pak, payload_len=0
    *Jul 10 09:16:15.731: [NAT[1]: H323 ACK packet ? FALSE
    *Jul 10 09:16:57.215: NAT[1]: H323: received pak, payload_len=0
    *Jul 10 09:16:57.215: [NAT[1]: H323 ACK packet ? FALSE
    *Jul 10 09:17:02.731: NAT[1]: H323: received pak, payload_len=0
    *Jul 10 09:17:02.731: [NAT[1]: H323 ACK packet ? FALSE
    *Jul 10 09:17:14.731: NAT[1]: H323: received pak, payload_len=0
    *Jul 10 09:17:14.731: [NAT[1]: H323 ACK packet ? FALSE
    This problem has been bothering me for weeks. Hope that someone could help me out. Many thanks in advance.
    Regards,
    Angran

    Hi,
    i have the same requirement for a customer, not for video but for audio calls, i have a remote office with h.323 phones and they need to get registered to a gk in central office to send and recieve voice calls, did you make it work? can you share the config please?

  • Import EIGRP default route only with network command

    Hi,
    Does anyone know why I can only import the default route learned by EIGRP (from a CE router) in the VPNV4 table with the command ?network 0.0.0.0? under the address family? Is this the correct behavior?
    router bgp 100
    address-family ipv4 vrf red
    redistribute eigrp 200
    no synchronization
    network 0.0.0.0
    exit-address-family
    PE9(config-router-af)#do show ip route vrf red 0.0.0.0
    Routing entry for 0.0.0.0/0, supernet
    Known via "eigrp 200", distance 90, metric 547840, candidate default path, type internal
    Redistributing via bgp 100, eigrp 200
    Last update from 91.91.91.1 on FastEthernet0/0.91, 00:04:11 ago
    Routing Descriptor Blocks:
    * 91.91.91.1, from 91.91.91.1, 00:04:11 ago, via FastEthernet0/0.91
    Route metric is 547840, traffic share count is 1
    Total delay is 20400 microseconds, minimum bandwidth is 100000 Kbit
    Reliability 255/255, minimum MTU 1500 bytes
    Loading 1/255, Hops 4
    PE9(config-router-af)#do show ip bgp vpnv4 vrf red 0.0.0.0
    % Network not in table
    PE9(config-router-af)#
    PE9(config-router-af)#network 0.0.0.0
    PE9(config-router-af)#
    PE9(config-router-af)#do show ip bgp vpnv4 vrf red 0.0.0.0
    BGP routing table entry for 91:91:0.0.0.0/0, version 1068
    Paths: (1 available, best #1, table red)
    Flag: 0x820
    Advertised to update-groups:
    2
    Local
    91.91.91.1 (via red) from 0.0.0.0 (9.9.9.9)
    Origin IGP, metric 547840, localpref 100, weight 32768, valid, sourced, local, best
    Extended Community: RT:118:118 Cost:pre-bestpath:128:547840
    0x8800:32768:0 0x8801:200:522240 0x8802:65284:25600 0x8803:65281:1500
    mpls labels in/out 28/nolabel
    PE9(config-router-af)#
    Thanks,
    Marcelo

    Hi Marcelo,
    Yes this is normal, a default route unlike any other routes is not redistributed between routing protocols by default, in the case of BGP you have 2 options, either use a network command and make sure that the route is in the routing table (via EIGRP in your case), or use redistribute + default-information originate, you can test this by removing the network command and adding the default-information originate under the address family.
    HTH,
    Mohammed Mahmoud.

  • Route List

    Hello everbody,
    I have a route list which points to 3 route groups. Here's the order:
    First one is a PRI in Boston (Primary), second is a T1 in Boston and the tired one is a PRI in New York. As Configured; when first PRI is not available the T1 has to kick in and when none of the links in Boston are available the PRI in New York has to take the charge. The links are working individually but when I unplug the PRI in Boston, we cannot make any calls. It looks like the switch over is not configured properly. Is there any configuration that I am missing? Where else de I need to look and configure in order to assure the failover?
    Thanks,
    BT

    Also, one thing I noticed in the router config, you have dial-peer 101 pots configured, putting mcgpapp on the the PRI - the interop guide says you should not do this:
    Restrictions for MGCP PRI Backhaul and T1 CAS Support
    ?Voice interfaces on the NM-HDA and the AIM-VOICE-30 are not supported.
    ?Integrated access, in which the channels on a T1 or E1 interface are divided between a group used for voice and another group used for WAN access, is not supported when voice is controlled by Cisco Unified CallManager through MGCP.
    ?T1 and E1 protocols, such as QSIG, E1 R2, T1 FGD, and PRI NFAS, are not supported with MGCP only with H.323.
    ?E1 CAS is not supported.
    ?Do not add the application mgcpapp command to dial peers that support PRI backhaul.
    http://www.cisco.com/en/US/products/ps6441/products_configuration_guide_chapter09186a0080541bf5.html
    That used to be generated when you downloaded the config from CM, and then it went away, and I know we put it back in a few places, but now they specify that you should not. I wonder if you removed that and did a ccm config check reset on the router to redownload config if it would behave better - that is, if you determine that it is really not unregistering.
    Mary Beth

Maybe you are looking for