Black box able to log traffic passing through...
Hi
I'm looking for a box able to sniff the tcp/ip traffic (source ip address, destination ip address and ports) passing from it's ingress interface to the egress interface and viceversa (useful the bypass option if this box fails) without any change of the traffic passing through, just logging it and sending this log to a syslog server.
We need it as solution to be compliant with the new police law against computer criminals where is written that all the internet traffic has to be logged (we offer sometimes transparent internet access to our customers where we do not put any kind of equipment as firewall, proxy or something else, only the router providing the internet access).
Do you know if Cisco provide something like that ? Other vendors ?
Any other idea how to be compliant with this request ?
Thanks
Pls advise
Ric
Cisco Intrusion Prevention System Sensor can be used to log ip traffic. You can manually configure the sensor to capture all IP traffic associated with a host you specify by IP address. You can specify how long you want the IP traffic to be logged, how many packets you want logged, and how many bytes you want logged. The sensor stops logging IP traffic at the first parameter you specify.You can also have the sensor log IP packets every time a particular signature is fired. You can specify how long you want the sensor to log IP traffic and how many packets and bytes you want logged
Similar Messages
-
Does user traffic pass through Controller and Aironet 1030?
Hi All,
I want to beat out some questions that I cannot find exactly guideline in Cisco. I intend to implement 2 Airespace 2000 controller and some 1010s and one 1030 to my main office and branch office. At present, there is a 512kbps WAN link between this two office. So I don't want to let the traffic within the branch office to pass through the WAN link. Therefore, I intend to use the solution that 1 controller stay in main office to serve the 1010s in main office and 1 controller stay in remote office to serve the 1010s in remote office. But the remote site only needs 1 AP, thus I would like to use one 1030 to stay in branch office and 2 controller stay in main office to perform controller's redundancy. I would like to know Does the clients' traffic pass through the link between 1030 and controller as the same as 1010? I does very confuse whether 1030 has this feature because I found some blur instruction of 1030 in Cisco.
Further, if I place one of the controller in remote office, how can I control the APs in remote office to choose the local controller instead of the controller in main office using Layer 3 discovery method? Does any know? Thanks!
Jason,
best regards,Hi Jason,
Hopefully this info will clear this up for you;
Q. Can I install an access point (AP) at a remote office and install a Cisco WLC at my headquarters? Does the Lightweight AP Protocol (LWAPP) work over a WAN?
A. Yes, you can have the WLCs across the WAN from the APs. LWAPP works over a WAN. Use Remote Edge AP (REAP) mode. REAP allows the control of an AP by a remote controller that is connected via a WAN link. Traffic is bridged onto the LAN link locally, which avoids the need to unnecessarily send local traffic over the WAN link. This is precisely one of the greatest advantages of having WLCs in your wireless network.
Note: Not all lightweight APs support REAP. For example, the 1030 AP supports REAP, but the 1010 and 1020 AP do not support REAP. Before you plan to implement REAP, check to determine if the APs support it. Cisco IOS Software APs that have been converted to LWAPP do not support REAP.
Q. I want to set up the Cisco 1030 Lightweight Access Point (AP) with a Cisco WLC in Remote Edge AP (REAP) mode. In this mode, is all wireless traffic tunneled back to the WLC? Additionally, if the AP cannot contact the WLC, what happens to the wireless clients?
A. The 1030 AP tunnels all WLC traffic (control and management traffic) to the WLC via Lightweight AP Protocol (LWAPP). All data traffic stays local to the AP. The 1030 REAP can only reside on a single subnet because it cannot perform IEEE 802.1Q VLAN tagging. As such, traffic on each service set identifier (SSID) terminates on the same subnet on the wired network. So, while wireless traffic may be segmented over the air between SSIDs, user traffic is not separated on the wired side. Access to local network resources is maintained throughout WAN outages.
At times of WAN link outage, all WLANs except the first is decommissioned. Therefore, use WLAN 1 as the primary WLAN and plan security policies accordingly. Cisco recommends that you use a local authentication/encryption method, such as the Wi-Fi Protected Access (WPA) Pre-Shared Key (WPA-PSK), on this first WLAN.
Note: Wired Equivalent Privacy (WEP) suffices, but this method is not recommended because of known security vulnerabilities.
If you use WPA-PSK (or WEP), properly configured users are still able to gain access to local network resources even when the WAN link is down.
From this doc;
http://www.cisco.com/en/US/products/ps6366/products_qanda_item09186a008064a991.shtml
Hope this helps!
Rob
Please remember to rate helpful posts..... -
Only some of the traffic passing through inline vlan pair
Here is my network setup
firewall<---- >(g1/2)Coreswitch 6500 with IDSM(TG9/1)<-----> (TG9/1) Distrib switch with FWSM---------Accessswitch
configuration in core switch
interface GigabitEthernet1/2.11
description **** ****
encapsulation dot1Q 211
ip vrf forwarding VRF11
ip address 10.2.11.73 255.255.255.248
ip ospf network point-to-point
standby 1 ip 10.2.11.75
standby 1 priority 110
standby 1 preempt
interface GigabitEthernet1/2.37
description **** ****
encapsulation dot1Q 237
ip vrf forwarding VRF37
ip address 10.2.37.73 255.255.255.248
ip ospf network point-to-point
standby 1 ip 10.2.37.75
standby 1 priority 110
standby 1 preempt
interface TenGigabitEthernet9/1.11
description **** ****
encapsulation dot1Q 311
ip vrf forwarding VRF11
ip address 10.2.11.2 255.255.255.252
ip ospf network point-to-point
interface TenGigabitEthernet9/1.12
description **** ****
encapsulation dot1Q 312
ip vrf forwarding VRF12
ip address 10.2.12.2 255.255.255.252
ip ospf network point-to-point
configuration in Distribution switch:
interface TenGigabitEthernet9/1.11
description **** ****
encapsulation dot1Q 311
ip vrf forwarding VRF11
ip address 10.2.11.1 255.255.255.252
no ip route-cache
ip ospf network point-to-point
interface TenGigabitEthernet9/1.37
description ********
encapsulation dot1Q 337
ip vrf forwarding VRF37
ip address 10.2.37.1 255.255.255.252
no ip route-cache
ip ospf network point-to-point
i have seggregated n/w like this. i am using inline vlan pair , to pass all the traffic through the IDSM module ,
i am using the monitoring port gi0/8
config in core switch
intrusion-detection module 8 data-port 2 trunk allowed-vlan 211-260,311-360
IDSM
physical-interfaces GigabitEthernet0/8
subinterface-type inline-vlan-pair
subinterface 11
description
vlan1 211
vlan2 311
exit
subinterface 37
description
vlan1 237
vlan2 337
exit
Problem i am facing is , some of the vlan-pair traffic passing through the IDSM some of the traffic are not passing , here i have given the statistics
MAC statistics from interface GigabitEthernet0/8
Statistics From Subinterface 11
Statistics From Vlan 211
Total Packets Received On This Vlan = 0
Total Bytes Received On This Vlan = 0
Total Packets Transmitted On This Vlan = 0
Total Bytes Transmitted On This Vlan = 0
Statistics From Vlan 311
Total Packets Received On This Vlan = 0
Total Bytes Received On This Vlan = 0
Total Packets Transmitted On This Vlan = 0
Total Bytes Transmitted On This Vlan = 0
Statistics From Subinterface 37
Statistics From Vlan 237
Total Packets Received On This Vlan = 3189658726
Total Bytes Received On This Vlan = 64165872092928
Total Packets Transmitted On This Vlan = 3549575166
Total Bytes Transmitted On This Vlan = 64165872092928
Statistics From Vlan 337
Total Packets Received On This Vlan = 3549575166
Total Bytes Received On This Vlan = 64165872092928
Total Packets Transmitted On This Vlan = 3189658726
Total Bytes Transmitted On This Vlan = 64165872092928
Statistics From Subinterface 38
Statistics From Vlan 238
Total Packets Received On This Vlan = 2215151150
Total Bytes Received On This Vlan = 64165872092928
Total Packets Transmitted On This Vlan = 126546964
Total Bytes Transmitted On This Vlan = 64165866995200
Statistics From Vlan 338
Total Packets Received On This Vlan = 126546964
Total Bytes Received On This Vlan = 64165866995200
Total Packets Transmitted On This Vlan = 2215151150
Total Bytes Transmitted On This Vlan = 64165872092928
Give me idea experts , so that i can resolve this issue.
Help me thanks in advanceI believe the issue is because of the config below:
interface GigabitEthernet1/2.11
description **** ****
encapsulation dot1Q 211
ip vrf forwarding VRF11
ip address 10.2.11.73 255.255.255.248
ip ospf network point-to-point
standby 1 ip 10.2.11.75
standby 1 priority 110
standby 1 preempt
encapsulation dot1Q 311
ip vrf forwarding VRF11
ip address 10.2.11.2 255.255.255.252
ip ospf network point-to-point
interface TenGigabitEthernet9/1.12
description **** ****
encapsulation dot1Q 312
ip vrf forwarding VRF12
ip address 10.2.12.2 255.255.255.252
ip ospf network point-to-point
As you can see we have 2 ip subnets in the VRF 11 .73 & .2 in vlan 211 & 311 respectively.
The switch is doing intervlan routing directly without having to go through the IDSM for VRF 11.
What we need to remember is IDSM does not do routing, and it can only bridge vlans.
Hence we have to force to packet to go through the IDSM.
Here is what we do when we use IDSM to see traffic going between vlans.:
Normally, with vlans, and IDSM inline mode, we have one IP subnet and 2 Vlans.
IDSM2 in inline mode necessitates an additional artificial Vlan on the SAME subnet as the Vlan you wish to sense.
A layer 3 switch interface needs to be configured within this additional artificial Vlan.
In a nutshell, we need to create 2 Vlans that share one same ip subnet and put SVI on only one of the Vlans.
In your case you will need one ip between vlans 211 & 311 in VRF 11 to force the data to go through the IDSM.
I can understand if this is a bit tricky to understand.
Please go through my design document for IDSM inline mode, which explains the basic concepts and packet walk in detail.
It will explain why we need the above and how arp makes the mac-address table populate correct entries, (with one ip subnet for 2 vlans) so that traffic goes through the IDSM.
https://supportforums.cisco.com/docs/DOC-12206
- Sid -
AAA Authentication for Traffic Passing through ASA
I am setting up AAA authentication for traffic that will pass through my ASA. I am having difficulty enabling 'aaa authentication secure-http-client'. Without secure communications enabled access functions as expected. When I enable access, I get prompted for a username/password. The username/password is entered. Authentication passes (show uauth). The requested page (http://www.cisco.com) switches to https://x.x.x.x (a resolved IP address for the site). Eventually (5 seconds), I am asked to accept or deny a certificated. Interestingly, the certificate is for the ASA and not the requested site (http://www.cisco.com).
Am I missing something?
firewall# show run aaa
aaa authentication http console TACACS+ LOCAL
aaa authentication telnet console TACACS+ LOCAL
aaa authentication serial console TACACS+ LOCAL
aaa authentication ssh console TACACS+ LOCAL
aaa authentication enable console TACACS+ LOCAL
aaa authentication match guestnetwork_access guestnetwork RADIUS
aaa authentication secure-http-client
firewall# show access-li guestnetwork_access
access-list guestnetwork_access; 2 elements
access-list guestnetwork_access line 1 extended deny udp 10.255.255.0 255.255.255.0 any eq domain (hitcnt=33)
access-list guestnetwork_access line 2 extended permit ip 10.255.255.0 255.255.255.0 any (hitcnt=412)
firewall# show run aaa-s
aaa-server RADIUS protocol radius
aaa-server RADIUS (inside) host 192.168.250.14
key xxxxx
firewall# show run http
http server enableyour definition for the aaa-server is different to the aaa authentication server-group
try
aaa authentication http console RADIUS LOCAL
aaa authentication telnet console RADIUS LOCAL -
Does IPv6 traffic "pass-through" or "drop" by cisco waas?
Since cisco waas is not yet supported IPv6, if i am running IPv4 and IPv6 dual stack mode on the same circuit, does IPv6 traffic get dropped by the waas or does waas put IPv6 traffic in "pass-through" mode and let it goes? I am thinking, waas will treat IPv6 as non-IP traffic and will let it goes. Am i right?
Hi Joe and Kanwai,
One note though - if your running WCCP as the redirection mode, you won't get the IPv6 traffic redirected, as WCCP does NOT support IPv6. Hence you won't see IPv6 traffic at all on the WAAS device.
Best Regards
Finn Poulsen -
Check boxes not checked when value passed through a request
I've a URL which sets default-check box values -
f?p=121:41:&SESSION.::YES::P41_OWNER,P41_AI_TYPE:&BUGDB_USER.,\5,6,7\
where "\5,6,7\" is the value of check-boxes.
On Page 41, I compute P41_AI_TYPE as follows (as a Process - On Load Before Regions) -
begin
if (:P41_AI_TYPE = '5,6,7') then
*:P41_AI_TYPE := '6:7:5';*
end if;
end;
There are 3 conditional reports that are generated on the page 41 based on these values. i.e. 5,6,7. All the three reports are displayed indicating that the reports do indeed see the P41_AI_TYPE variable.
The "Debug" shows
0.03: ...Session State: Saved Item "P41_AI_TYPE" New Value="6:7:5"
prior to displaying the checkbox
The "Session" also shows -
121 41 P41_AI_TYPE Checkbox 6:7:5 U
However none of the check-boxes are checked.
What could be the issue ?
Edited by: ygore on Aug 26, 2009 10:41 AM0.01:
0.02: S H O W: application="121" page="41" workspace="" request="" session="692841112185158"
0.02: Language derived from: FLOW_PRIMARY_LANGUAGE, current browser language: en-us
0.02: alter session set nls_language="AMERICAN"
0.02: alter session set nls_territory="AMERICA"
0.02: NLS: CSV charset=WE8MSWIN1252
0.02: ...NLS: Set Decimal separator="."
0.02: ...NLS: Set NLS Group separator=","
0.02: ...NLS: Set date format="DD-MON-RR"
0.02: ...Setting session time_zone to dbtimezone
0.02: NLS: Language=en-us
0.02: Application 121, Authentication: CUSTOM2, Page Template: 5653628457062181
0.02: ...Session ID 692841112185158 can be used
0.02: ...Application session: 692841112185158, [email protected]
0.03: ...Determine if user "YPGORE" workspace "943324391470666" can develop application "121" in workspace "943324391470666"
0.03: Session: Fetch session header information
0.03: Saving g_arg_names=P41_OWNER and g_arg_values=YGORE
0.03: ...Session State: Saved Item "P41_OWNER" New Value="YGORE"
0.03: Saving g_arg_names=P41_AI_TYPE and g_arg_values=5,6,7
0.03: ...Session State: Saved Item "P41_AI_TYPE" New Value="5,6,7"
0.03: ...Metadata: Fetch page attributes for application 121, page 41
0.03: Fetch session state from database
0.03: Branch point: BEFORE_HEADER
0.03: Fetch application meta data
0.04: Computation point: BEFORE_HEADER
0.04: Processing point: BEFORE_HEADER
0.04: Show page template header
0.04: Computation point: AFTER_HEADER
0.04: Processing point: AFTER_HEADER
Root Cause Analysis
([email protected]) | Logout
Reports
Edit
Classify
Edit
Administration
Edit
EditEditEdit
Summary Report Area Report Custom Reports
0.05: Region: Action Items Report
Action Items Report
0.05: Computation point: BEFORE_BOX_BODY
0.05: ...Evaluate condition "NEVER" for computation of item: P41_AI_TYPE
0.05: Processing point: BEFORE_BOX_BODY
0.05: ...Process "Compute AI Type": PLSQL (BEFORE_BOX_BODY) begin if (:P41_AI_TYPE = '5,6,7') then :P41_AI_TYPE := '6:7:5'; :P41_AI_TYPE_COMMA := '5,6,7'; end if; end;
*0.05: ...Session State: Saved Item "P41_AI_TYPE" New Value="6:7:5"*
0.05: ...Session State: Saved Item "P41_AI_TYPE_COMMA" New Value="5,6,7"
0.05: Region: Enter Bug User Id
0.06: Item: P41_AREA TEXT
Area : Edit
0.06: Item: P41_OWNER TEXT
AI Owner : Edit
0.06: Item: P41_AI_PERCENT_LOW_MARK TEXT
AI %age comp. range Edit
0.06: Item: P41_AI_PERCENT_HI_MARK TEXT
And Edit
0.06: Item: P41_AI_TYPE CHECKBOX
AI Type :
Test-Generic TestCase Development
Edit
0.06: Item: P41_AI_ID TEXT_WITH_ENTER_SUBMIT
AI Id : Edit
0.06: Item: P41_GO BUTTON
Go
Edit
0.06: Item: P41_AI_TYPE_COMMA HIDDEN
Edit
0.06: Region: Test-Generic Action Items Report
Test-Generic Action Items ReportEdit
0.06: show report
0.07: determine column headings
0.07: activate sort
0.07: parse query as: RMTOOLS_QAINIT
0.07: binding: ":P41_AREA"="P41_AREA" value="%"
0.07: binding: ":P41_OWNER"="P41_OWNER" value="YGORE"
0.07: binding: ":P41_AI_PERCENT_LOW_MARK"="P41_AI_PERCENT_LOW_MARK" value="0"
0.07: binding: ":P41_AI_PERCENT_HI_MARK"="P41_AI_PERCENT_HI_MARK" value="100"
0.07: binding: ":P41_AI_ID"="P41_AI_ID" value="%"
0.08: print column headings
0.08: rows loop: 15 row(s)
No action items in this category.
0.08: Region: TestCase Action Items Report
TestCase Action Items ReportEdit
0.08: show report
0.08: determine column headings
0.08: activate sort
0.09: parse query as: RMTOOLS_QAINIT
0.09: binding: ":P41_AREA"="P41_AREA" value="%"
0.09: binding: ":P41_OWNER"="P41_OWNER" value="YGORE"
0.09: binding: ":P41_AI_PERCENT_LOW_MARK"="P41_AI_PERCENT_LOW_MARK" value="0"
0.09: binding: ":P41_AI_PERCENT_HI_MARK"="P41_AI_PERCENT_HI_MARK" value="100"
0.09: binding: ":P41_AI_ID"="P41_AI_ID" value="%"
0.09: print column headings
0.09: rows loop: 15 row(s)
No action items in this category.
0.09: Region: Development Action Items Report
Development Action Items ReportEdit
0.10: show report
0.10: determine column headings
0.10: activate sort
0.10: parse query as: RMTOOLS_QAINIT
0.10: binding: ":P41_AREA"="P41_AREA" value="%"
0.10: binding: ":P41_OWNER"="P41_OWNER" value="YGORE"
0.10: binding: ":P41_AI_PERCENT_LOW_MARK"="P41_AI_PERCENT_LOW_MARK" value="0"
0.10: binding: ":P41_AI_PERCENT_HI_MARK"="P41_AI_PERCENT_HI_MARK" value="100"
0.10: binding: ":P41_AI_ID"="P41_AI_ID" value="%"
0.11: print column headings
0.11: rows loop: 15 row(s)
No action items in this category.
0.11: Region: Print Region
Print Report
Edit
0.11: Computation point: AFTER_BOX_BODY
0.11: Processing point: AFTER_BOX_BODY
0.11: Computation point: BEFORE_FOOTER
0.11: Processing point: BEFORE_FOOTER
0.11: Show page tempate footer
Home Application 121 Edit Page 41 Create Session Activity No Debug Hide Edit Links Show Edit Links
0.11: Computation point: AFTER_FOOTER
0.11: Processing point: AFTER_FOOTER
0.11: Log Activity:
0.11: End Show: -
TUNNEL UP BUT NO TRAFFIC PASSING THROUGH
Hello, we have a customer that has been working with us like 1 month with no problem. We did a connection between a fortigate firewall and a Cisco 2811. Now the tunnel is up but no traffic is going and coming through it. I did remake the whole configuration for this costumer: Key, cryptomap and access-list. The tunnel comes up but again, no traffic is coming or going.
Any hints ?
Thanks.Hi,
Below is an excellent document on Most Common L2L and Remote Access IPSec VPN Troubleshooting Solutions.
http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml
If this doc does not help, do post your configuration along with the Src and Dest IP Addresses that you are trying to ping across the tunnel.
Regards,
Arul
*Pls rate if it helps* -
High delay when traffic passes through the tunnel
Hello,
i have a dmvpn topology, .
When i try to ping the real ip on the hub's outside interface from the spoke, the delay is approximately 100ms, but when i ping the tunnel ip address the delay becomes 4000ms.
Your help is really appreciatedCan you post the configuration?
Did you set the MTU of the tunnel interface correctly?
Also check the switching (CEF/Process Switching) configuration.
Regards
Farrukh -
A new user of Motion, I've just run into the problem of not being able to select the "pass through" blend mode for a group. I've seen elsewhere that this happens when you do something that causes the group to be rasterized. OK, got that. But what next? Is there a way to "unrasterize" your group? Basically I just want to be able to use a blending mode on this group and have it interact with layers outside the group again.
thanks in advance.You have to determine what is causing the rasterization in order to figure out another approach. Look in the Inspector, the offending critter (parameter) will have a blue dot.
-
When trying to log in with my primary Apple ID and password, I am continuously asked for my pass word without being able to log in. How can I solve this issue, without creating a new Apple ID?
Chewning wrote:
I saved some of my music to a Cloud I can't access. Now, they show up as "Purchased" in iTunes, and I'm not given the option of re-downloading OR repurchasing them.
Music purchased from the iTunes store is not stored in your personal iCloud account, and an iCloud account is not required to redownload them. You should be able to redownload them as explained here: http://support.apple.com/kb/ht2519. If you are unable to, contact iTunes store support for assistance by going to https://expresslane.apple.com ; click ‘iTunes', and then 'iTunes Store', then 'Purchases, Billing & Redemption'. -
Configure FRITZ!Box Fon WLAN 7320 for PPPOE PASS-Through
I just switched ISP providers, from ARCOR to 1&1 and received a new FRITZ!Box Fon WLAN 7320 modem. I've been trying to figure our (without success) how to get it to do pppoe pass-through and allow my Airport Extreme router to the authenication with 1&1 versus the Fritzbox. I would greatly appreciate any and all assistance.
I do not want to use the Fritzboz WLAN and/or have it do the PPPOE authenication.
Message was edited by: jmpsohiOne for the Airport forum, I would think:
http://discussions.apple.com/category.jspa?categoryID=140
Regards
TD -
Cisco ASA - Pass Through QoS Traffic
Hi Sirs,
Given the following topology:
Switch - IP Phone (Branch) |----| Router |----| MPLS |----| Router |----| ASA |----| Switch - Voice Network (Head Office)
My question, the ASA can impact the QoS traffic to pass through it?
Thank you!
Rafael TrujilhoHi Andrew,
I want the ASA does NOT take any markings, NOT impacting the quality applied to voice traffic.
Regards,
Trujilho -
I have followed every step in the various help pages I was directed to when troubleshooting the inability to install Adobe Flash Player on my Mac using either Safari or Chrome. Everything has failed. I always get the black box that says briefly, "Retrieving instal. . . " and then goes blank. When I close that window, I get the message, "Adobe Flash Player could not be installed." Then it gives some links to follow for troubleshooting. I have followed ALL of the links there and on other help pages, to no avail. I've run into problems installing Adobe before, but it's never been this bad. Would someone please develop another format besides Adobe? Trying to get help from Adobe feels a little like trying to find a building in New York City with no map or GPS. The time required is voluminous, the emotional energy a/k/a frustration is overwhelming, and long before I get anything resolved, I wish the earth would open up and swallow all things Adobe@. Absence that miraculous intervention, I have to figure out what to do next. Does anyone know? Anyone?
Same question, same answer: use the offline installer http://fpdownload.macromedia.com/pub/flashplayer/latest/help/install_flash_player_osx.dmg
-
I'm not able to log in as J2EE_ADMIN through the Web Browser.
If I try to log into the server using http://<server>:50000/ I get the SAP Nteweaver SAP Web Application screen. I click on System Information, I get prompted for the username and password. I enter the username J2EE_ADMIN and then the password, but it keep asking for the username and password until I get the 401 unauthorized screen. I can log into Visual Administrator using the J2EE_ADMIN and the same password with no problems.
I activated the sap* account, but the same thing is happenning, I'm not able to log in as sap*!
Any suggestions or tips?In the Security Provider Service choose Runtime --> Policy Configurations -->Authentication tab, please check whether you have the below settings correctly, if not set as below.
Login Modules Flag
EvaluateTicketLoginModule SUFFICIENT
BasicPasswordLoginModule REQUISITE
CreateTicketLoginModule OPTIONAL
Thank you,
Shyam -
Newly created users are not able to log in through WEBGUI in SRM system
Hi All,
I have created new roles in the SRM system with the BP tanscation codes Like( BBPSC01
BBPSC02
BBPSC03
BBPSC04)
after that I have created new users and I have assigned these roles to users. Users are able to login throgh SAP GUI but Users are not able to log in WEB GUI.. Once they providing user id and password in web gui. they are facing issue.
For web login do we need to maintain any special settings in SRM system?
Please suggest me.
Thanks in advance.
Regards,
SivaHi,
Here is the error when user is giving user id and pwd.
Note
The following error text was processed in the system DN0 : Error message occurred.
The error occurred on the application server dm2serv_DN0_01 and in the work process 0 .
The termination type was: RABAX_STATE
The ABAP call stack was:
SYSTEM-EXIT of program SAPMSYST
Regards,
Siva
Maybe you are looking for
-
A problem with return order with free goods
Hello I am working on ECC 6.0 I am facing a problem with the return order the case is I created an order of 1000 pc with inclusive free goods (w/o item generation) condition record that for every 10 pc over the 100 the customer will take 1 free pc 1
-
I have 2 domain controllers running 2003 server, server1 and server2. I ran dcpromo on server1 and removed AD and removed him from the domain and disconnected from network. I then added a 2012 server with the same name and IP address server1 with no
-
Trouble accessing a property of an instance inside a dynamically created MC.
I’m dynamically creating an instance of a movieclip, call it a game piece. This game piece has 4 frames, each with a movieclip called “base” (although one is red, one blue, one green, one yellow). When the game piece is created I set the frame to ind
-
Hello, I am seeing a weird behavior when performing a write operation on a non-blocking socket channel. The write call completes normally for several write invocations, however when the total number of bytes written exceeds 8K the sending of data gri
-
PAYMENT 처리시 PRE-INSERT TRIGGER (VALUE_ERROR)
제품 : FIN_AP 작성날짜 : 2005-05-10 11.0.3 - PAYMENT 처리시 PRE-INSERT TRIGGER (VALUE_ERROR) ============================================== PURPOSE Problem Description Payment 화면에서 특정 Invoice 선택 후 저장 시 아래와 같은 Error Message 가 발생함. Payment 화면에서 Invoice 선택 후 저장