Adding Reverse Route causes 50% loss

I am building some IPSEC tunnels where thje remote locations have Dynamic IP addresses. It works fine, but I need to add more sites, right now I just have the one. When I add the reverse route statement, i start getting 50% packet loss based on ping responses "!.!.!.!.!.!.!.!" If I remove the RR it works fine. "!!!!!!!!!!"  Question is, what am I doing wrong or do I really need the reverse route? Right now the ACL is for the one subnet for current location, but I will be adding more sites. How would I adjust the ACL for more remote subnets if the remote sites are doing split tunneling and the ACLs must match?
crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
lifetime 7200
crypto isakmp key (PASSWORD) address 0.0.0.0 0.0.0.0
crypto isakmp invalid-spi-recovery
crypto isakmp keepalive 30 20 periodic
crypto ipsec security-association lifetime seconds 1800
crypto ipsec transform-set NAMECRYPTset esp-3des esp-md5-hmac
crypto dynamic-map NAMECRYPTmap 10
set transform-set NAMECRYPTset
match address 115

I removed the reverse route, and also removed  "
match address 115" as neither is needed in this scenario
I think this will be what I am needing, but still curious as to why the RR appears to drop packets> I don;t need it now because I will not be advertising those routes, but still wondering.

Similar Messages

  • CSCub04965 - TCP Session hung causing Packet loss

    FYI - We have experienced this problem in the 2951 router running 15.1(4) IOS.

    I located the issue of the packet loss. I have a security system that uploads FTP images of the cameras and after the reboot of the network, the only computer that wasn't shut down was the security camera PC.
    So I think what happened was after I brought everything back up, it was saturating the outgoing bandwidth, causing packet loss and high latency. Once I determined what it was and shut off the FTP image upload, the pings stabilized and it is working fine now. Trace routes are still not functioning, but I can live without that for now.

  • Adding a route in solaris

    I added a route in solaris by command-->
    route add 10.224.86.10 -netmask 255.255.255.224 10.224.8.10
    it gave the prompt--add net 10.224.56.0: gateway 10.224.8.10
    I checked the routing table by netstat -r
    10.224.86.10 10.224.8.10 UG 1 0
    which shows that it is added
    but i am not able to ping it from that server
    ping 10.224.86.10
    gives
    no answer from 10.224.86.10
    What is the reason?
    Thanks
    Anmol

    Hi
    You cannot add a route in appliance. You can only setup a default gateway on the appliance.
    All the routing decisions should be taken by default gateway of the appliance.
    ~Rohit

  • Adding a route to a non pingable router

    I want to add a route to a network that is routed by a firewall. This firewall can't be ping.
    My question is 'How can I add this route ?" because when I try to add the route manually
    route add net 172.19.0.0 255.255.0.0 172.18.60.4 1
    The reply is :
    add net 172.19.0.0: gateway 255.255.0.0: Network is unreachable
    With the HP-UX server, there is an option in the /dev/ip module that tells the routing to NOT ping a gateway when adding a route but this variable ip_ire_gw_probe doesn't exist on Solaris.
    Is there somebody who had an idea ?
    Gilles.

    The following should work, just add the -netmask switch.
    route add net 172.19.0.0 -netmask 255.255.0.0 172.18.60.4 1

  • The following files weren't attached because adding them would cause the message to exceed the maximum size limit of 35 MB: MALAWI .pptx.

    The following files weren't attached because adding them would cause the message to exceed the maximum size limit of 35 MB.
    I have had my macbook pro since June and have had no problems sending an email until I have tried to send a presentation today. The above message is what I keep receiving even after using 3 email accounts.

    Email providers often set file size limitations to conserve bandwidth and prevent service overload.  Most common seems to be a limit on the order of 21 MB.  If possible, break your presentation into two parts and send as two messages.

  • The following files weren't attached because adding them would cause the message to exceed the maximum size limit of 10 MB

    Dear sir/madam 
    I installed exchange server 2013 
    my clients want to attache more than 10 MB 
    when they attache more than 10 MB they got this massage "The following files weren't attached because adding them would cause the message to exceed the maximum size limit of 10 MB"
    so how can you help me to increase the attachment size and the way to do that 
    how can I change the default 10 MB  
    Please can you help me as soon as
    Rawa Zangana  

    Hi Rawa,
    You can use EAC or EMS to set the MaxSendSize. The default value of MaxSendSize is 10 MB.
    If you use EAC, here is the steps:
    Logon to EAC -> Mail flow -> Receive connectors -> settings-> type the Maximum send message size you want to set
    If you use EMS, please use the cmdlet Rajith provided.
    Hope it helps.
    Best regards,
    If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Amy Wang
    TechNet Community Support

  • When synching my ipod 80 gig classic, I get this message " iPod cannot be synched.  A duplicate file name was specified"  And yet, any new music in iTunes is added.  What causes this message?

    When synching my ipod 80 gig classic, I get this message " iPod cannot be synched.  A duplicate file name was specified"  And yet, any new music in iTunes is added.  What causes this message?

    Try deleting the iPod Photo Cache from the nominated folder that you have set up to sync photos to the devices.
    See iTunes: Understanding the iPod Photo Cache folder for more info.
    tt2

  • How to find the route cause of the issue in one Z-transaction

    Hi,
    I am analysing one Z-transaction is created by one standard program RHU_HELP and the Z-transaction is  ZHOMO03.
    In that transaction one parameter field is P_BATCH.
    If parameter P_BATCH is blanks then no records showing in the output but if I give the value 0* then it gives the ALV output.
    So Itried to debug the program RHU_HELP, but there is no ALV function module REUSE_ALV_GRID_DISPLAY.
    I tried to find the final internal table where the ALV output getting displayed but not getting.
    Can anyone give the idea to find the route cause of the issue.
    Waiting for quick response.
    Best Regards,
    BDP

    Hi
    What is the output format. It is ALV output you are getting. If not ALV function module is not used.
    There migh be some class function module it might have used. Please check is the below function module
    called
    FM : SET_TABLE_FOR_FIRST_DISPLAY.
    Regards
    Thirupathy

  • HT4356 will router cause a probelm?

    I use hp laser jet p1102w with update firmware. Sometimes my ipad can recoginze the printer but most times doesn't.
    I don't know why this going to happen. I use asus wireless router rt-n10. Is this router causing me this problem.

    Maybe you should try changing:
    1. Security setting WEP, WPA, WPA2
    2. Wireless protocol e.g. a,b,g,n
    3. Channel 1,6 or 11
    4. Update router firmware

  • Adding Static Routes for VLANS

    We have 3 servers each in a different vlan and 1 server is a Bordermanager.
    We added network routes to 2 server and all the vlans can see them, the
    Bordermanager already has a default route that takes it out on the
    internet, when we try to add a private network number of the vlans, it does
    not see the other vlans. What is the correct way to do this or is there?
    Thank you...

    Ok Craig,
    There are only 2 vlans, VLAN1 has all the servers, VLAN2 has all the users,
    a Cisco router supposedly does the routing between both VLANS because the
    router protocol supports ISL. Rip has been removed from the servers. The
    Bordermanager Server is in VLAN1, the problem is that all the servers you
    can change the Static Route to the VLAN2 that has all the users, but the
    Border cannot because it's static route goes out to the internet and it
    doesn't let you make a change, would a 3 card in the Border help? Thanxs...
    > In article <Mfc4e.1881$[email protected]>, wrote:
    > > when we try to add a private network number of the vlans, it does
    > > not see the other vlans. What is the correct way to do this or is there?
    > >
    > Can you give more details?
    >
    > Somewhere there has to be a router that contains all of the VLANS in order
    > to route between them. (Or a pair of routers each with 2 of the VLANS).
    > This could be a server or a routing module in your VLAN box.
    >
    > The BMgr server would need a static route pointing to the router(s)
    > connecting the VLANS.
    >
    > Craig Johnson
    > Novell Support Connection SysOp
    > *** For a current patch list, tips, handy files and books on
    > BorderManager, go to http://www.craigjconsulting.com ***
    >

  • Linksys WRT54GSV4 causing packet loss? Wired or Wireless.

    Hi.  I have been having trouble for months with my connection having packet loss.  Up until yesterday my results from www.pingtest.net were between 2%-6% packet loss.  Generally at 5% packet loss.  A technician came out yesterday and bypassed my DSL modem and ran that test and got 0% packet loss every single time he ran it.  So I bought a new Westell DSL modem off him to replace my Speadstream 4100 and away he went.
    Now, when I hook up my Linksys WRT54GSV4 router to the Westell 6100 DSL modem, I get between 0%-1% packet loss.  It's never higher than 1% but usually is 1%.  This happens on my wireless laptops as well as PC's wired directly into the router.  The main reason this packet loss was affecting me in the first place was Xbox Live gaming.  Gears of War 2 kept thinking I was cheating, and it was host banning me.  Last night I got host and did not get host banned but that doesn't mean it won't ban me in the future for the minimal packet loss.
    Any suggestions on why the router could be causing this packet loss when the Linksys router is invovled?  With a PC directly connected to the DSL modem I get 0% packet loss on that ping test every single time.
    Internet Service: AT&T DSL (6.0 Mbps)
    DSL Modem: Westell 6100
    Router: Linksys WRT54GSV4
    Solved!
    Go to Solution.

    Try reducing the MTU value to 1365 and uncheck Block Anonymous Internet Requests under Security tab on the router's GUI...and check if it makes any difference.
    If the above steps doesn't work then,try to upgrade/reflash the router's firmware,reset the router and reconfigure it from the scratch...Download  the firmware for your router and save it on the desktop.Now,On the Linksys GUI,click on Administrator tab to upgrade the firmware.  

  • Reverse Routing

    Hi below i am enclosing basic view of my network.
    I configured Nat Exemption in my ASA 5520
    nat (inside) 0 172.20.0.0 255.255.0.0
    route in ASA as
    route outside 0.0.0.0 0.0.0.0 122.x.x.33 1
    route inside 172.0.0.0 255.0.0.0 172.x.x.1 1
    and configured PAT over my 2801 router inside interface where there is a route as follows
    ip route 0.0.0.0 0.0.0.0 122.x.x.50
    ip route 172.16.0.0 255.240.0.0 122.x.x.44
    and my doubt is i want to configure PAT over my ASA 5520 and remove NAT in 2801 router how can i change the ROute commands in both ASA and Router
    Please Help me in this regard

    As far as i see, you do not need to change any route's commands.
    however you may remove
    ip route 172.16.0.0 255.240.0.0 122.x.x.44
    as the firewall outside and router inside are directly connected, which consideration i made after reading the following statement "configured PAT over my 2801 router *inside* interface"
    Keeping the route wouldn't cause any problem anyway.
    Remember to Rate me if helpful.

  • Aaack. Adding a PC to my Happy Mac Family, adding a router?

    Okay, I have 3 Macs connected to a DSL modem via Airport Express, WEP encrypted network. Two Macs run 10.4.8, one runs 10.2.8, all have Airport cards.
    Hubby's new job comes with an IBM Thinkpad running latest version of Windows. New Co. insists he uses "their" router, and sent us a Linksys WRT54G. They say adding this to our network is easy, just plug it in. Huh?
    Any advice or suggestions would be most welcome.....
    Elizabeth

    The Linksys WRT54G is a wireless router and performs basically the same functions that that AirPort Express Base Station (AX) does, except for sharing a USB printer or streaming iTunes.
    You won't need to use both routers, but if you do, you would need to re-setup the AX as a "bridge." Your network configuration with both routers, would be something like the following:
    DSL modem > (Ethernet cable) > [Internet port] Linksys [LAN port] > (Ethernet cable) > [Ethernet port] AX
    If you elect just to use the Linksys, then just remove the AX from the above network configuration. The Linksys router comes with Windows-based setup software, but it administration is also web-based...so you could your Mac to set it up by way of Safari.
    The following is a typical Linksys router setup for DSL:
    Linksys Router Setup - DSL
    - Access the Linksys web-based setup at 192.168.1.1 (or whatever address your router is set at) using a web browser. The default username is blank & password is "admin."
    Setup tab
    - LAN IP Address: 192.168.1.1
    - Subnet Mask: 255.255.255.0
    - WAN Connection Type: PPPoE
    -- User Name: <ISP Account Name>
    -- Password: <ISP Account Password>
    -- Service Name: (optional)
    -- Connect on Demand: Max Idle Time 5 Min. (enabled)
    - Apply (if you make changes)
    Status tab
    - WAN (all the values here should be populated by your ISP)
    DHCP tab
    - DHCP Server: Enable
    - Starting IP Address: 192.168.1.n, where n should be greater than 1
    - Number of DHCP Users: n, where n should reflect the realistic number of concurrent clients that you plan on having connected to the router at any given time.
    - Client Lease Time: 0
    - DNS 1, 2, 3: <leave at default>
    - WINS: <leave at default>
    - Apply (if you make changes)
    Advanced - Filters tab
    - Filtered Private IP Range: <leave at default>
    - Filtered Private Port Range: <leave at default>
    - Block WAN Request: Enable
    - Multicast Pass Through: Enable
    - IPSec Pass Through: Enable
    - PPTP Pass Through: Enable
    - Remote Management: Disable
    - Remote Upgrade: Disable
    - MTU: Disable
    - Filter Internet NAT Redirection: Enable
    - Filter IDENT(port 113): Enable
    - Apply (if you make changes)
    - Leave all the other tabs at their respective default settings.

  • Adding a Router

    Has anyone had success adding a second router to act as an AP with the Actionterc Router?  I am trying to expand wireless coverage in my house and would like to use a linksys router I have and set it up as a wireless Access Point on another floor of my home.  I don't want to add it to my netork with ethernet connection because that would mean running cable through floors and walls.

    tlb68 wrote:
    Has anyone had success adding a second router to act as an AP with the Actionterc Router?  I am trying to expand wireless coverage in my house and would like to use a linksys router I have and set it up as a wireless Access Point on another floor of my home.  I don't want to add it to my netork with ethernet connection because that would mean running cable through floors and walls.
    http://www.dslreports.com/faq/verizonfios/3.0_Networking
    It's pretty common for people to piggy back a 2nd router off of the actiontec for exactly the reason you described.  The above link will give you various configuration setups and solutions and is probably one of the more complete FAQ's out there.

  • Network Errors Adding New Router

    Hello,
    I posted this in the iChat forum earlier today but I think this would a better forum to ask this question. We were using a D-Link DI-604 Wired Router for about 5 years until yesterday when we purchased a new D-Link EBR-2310 Wired Router. Ever since connecting the new router, about every 15 to 30 minutes in the console log on my iMac 3.06 GHz Intel Core 2 Duo, I get the following errors now:
    Jun 12 17:31:57 <computer name> kernel[0]: AppleYukon2: 00000001,00000000 sk98nif - deadmanCheck - nothing received, resetting chip
    Jun 12 17:31:57 <computer name> configd[14]: AppleTalk shutdown
    Jun 12 17:31:59 <computer name> configd[14]: AppleTalk shutdown complete
    Jun 12 17:32:01 <computer name> kernel[0]: AppleYukon2: error - Link Partner not Auto-Neg. able
    Jun 12 17:32:01 <computer name> configd[14]: AppleTalk startup
    Jun 12 17:32:01 <computer name> kernel[0]: AppleYukon2: 00000000,00000000 skgehw - cppSkDrvEvent - SKDRV_LIPA_NOT_ANABLE: link partner not auto-negotiate capable, port, phy r6
    Jun 12 17:32:01 <computer name> kernel[0]: Ethernet [AppleYukon2]: Link up on en0, 10-Megabit, Half-duplex, No flow-control, Debug [796d,0c08,0de1,0200,0021,0000]
    Jun 12 17:32:07 <computer name> configd[14]: AppleTalk startup complete
    This never happened with the old router and I can't figure out what is causing this (I keep a close watch on my console log and I know for sure that this problem just started since connecting the new router). The new router is cascaded to an older Farallon 10Mbps ethernet hub (exactly the same way the old router was set up) so at first, I thought the errors may have been due to the fact that I had the WAN Port Speed of the new router set to "Auto 10/100Mbps" causing my iMac to (unsuccessfully) try to negotiate a faster port speed. On the old router, we had the WAN Port Speed set to 10Mbps and I never noticed any of these errors so I changed the WAN Port Speed on the new router to 10Mbps instead of "Auto 10/100Mbps" and we're still getting the same thing happening.
    I've tried connecting my iMac directly to the router and directly to the cascaded Farallon 10Mbps ethernet hub and either way, it makes no difference. Our internet connection works fine but we get the odd error when sending a print job to our networked HP LaserJet with the new router. Does anyone with any networking experience have any idea what can be causing this? Is there a way to change the 10/100Mbps speed on the iMac itself rather than on the router?
    Thanks so much,
    Gerard

    Is there a way to change the 10/100Mbps speed on the iMac itself rather than on the router?
    System Preferences/Network/Advanced/Ethernet - Configure manually
    The book on this router at Newegg is that it works for some people, but others using Vista notice the router can't handle multiple users very well. Disconnects, slow throughput, resets. It's not a very costly router, and hasn't had a firmware update since 2007. Maybe Vista pushes it too hard?
    I'm just guessing that the deadmanCheck reference in the error is some sort of test to see if anybody is there and when the router doesn't respond, the Mac reset's it's ethernet chips.
    Since you've had so many problems with the programs, firewall and port routing, and incomprehensible tech support, you might look at one of the competitors products that can keep up with your equipment.

Maybe you are looking for

  • Cannot deploy EJB from JDev 3.2

    Dear Sirs, When you try to create a deployment profile using JDeveloper 3.2 step #2 of the wizard asks for "select a type of deployment". In Jdeveloper 3.1.1.2 the option "deploy Enterprise Java Bean (EJB) to Oracle8i". But in release 3.2 that option

  • Error while uploading par file

    Hi,         I am trying to  upload par file for the first time. When I try to deploy the par file, I am getting message saying, 'Operation failed: Please make surethe server 'Myportal' (host:port) is running or check the log( sap-plugin.log) for more

  • Mac Pro 3,1 Shuts Down Unexpectedly

    My computer lately shuts down unexpectedly. It's not an overheat problem. When I use skype, as soon as the video conversation starts, it shuts down. When I try to resize a photo on Photoshop CS5, it shuts down. (I modified an OpenGL option, and I don

  • Where are the symbole used in Pages? What a downward arrow in a rectangle mean?

    I found a new symbol located on a Pages document. It was a downward arrow within a box in the upper right-hand corner. It appeared where you show all of your documents. Next, there's no table showing this symbol anywhere's, particularly in the help w

  • Is there a printer/scanner that works with MacBook?

    I would like to able to scan a document and send with an e-mail.