CSS virtual-router master/master problem
Dear all experts,
I have two CSSs 11150 and have configured them as following:
CSS-1#
circuit VLAN100
ip address 172.10.10.101 255.255.255.0
ip virtual-router 1 priority 105 preempt
ip redundant-vip 1 172.10.10.1
ip critical-service 1 up_down_stream
no redirects
CSS-2#
circuit VLAN100
ip address 172.10.10.102 255.255.255.0
ip virtual-router 1 priority 101 preempt
ip redundant-vip 1 172.10.10.1
ip critical-service 1 up_down_stream
no redirects
Here is my connection:
CSS-1 <=> Switch <=> CSS-2
They were working fine before but CSS-2 suddenly change to master few days ago. I have already checked the connection between these two CSSs and it seems ok, so I tried to capture the packet trace both for the ports connected to CSS-1 and CSS-2 from the switch. And finally I found that I can see the vrrp adv. message which send from CSS-2 at the port which is monitoring CSS-1, but there is no vrrp adv. message send from CSS-1. I am not sure the problem is related to the acl as it has configured to permit any any:
clause 254 permit any any destination any
Could anyone can help me in this case? Is the problem related to the keyword "preempt" in CSS-2? Is it a software bugs which hasn't listed in cisco bug list (SW Version: 6.10)?
Thanks!
Hi,
I'm not sure if this you've resolved this problem; however, from what I have read you should never configure the preempt option on the same virtual router on both CSSs.
The issue of both CSSs becoming master when using the preempt option is highlighted in this guide:
http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/css11000series/v5.00/command/reference/CmdCirIP.html#wp1027189
I have used the preempt option to failover to the backup CSS in the past; however, to achieve this the preempt option had to be removed from the existing master.
I hope this helps.
Thanks,
C
Similar Messages
-
Problem with Virtual Credit Card Master Card
(Sorry for my english, i am from Russia)
I bought Virtual Credit Card Master Card and put its number and security code. Then I bought Pages, Keynote,GT Racing and some other apps. They have successfully downloaded and I can use them. But money from the credit card didnt removed (??) !
When I entered iTunes from my PC I saw this letters: "We were unable to authorize your credit card for this purshase. Please update your billing ifo. Amount you owe: 31.93 $" But I entered all true (I checked), but i have only 27 $ on my credit card and I can not fill up it (it's a virtual card) Can you take the money that I have now on my credit card? Then I'll buy another and repay debt. Now i can't buy anything from AppStore (Even free), but I can use all apps (Pages, Keynote,GT Racing) I bought. (but money from the credit card didnt removed!!!)
How to pay this bill and use app store? Please, help me!
Message was edited by: NikdenYou have posted on a user board. You need to contact itunes store support!
http://www.apple.com/support/itunes/contact.html -
Topic : Alesis Master Control Problem (to previous post unanswered fixed)
Topic : Alesis Master Control Problem to the original post user: Garrud
Me:111984cz i have an answer to ur problem.i too had the same problem with cubase 5 ,Nuendo 4 and any of Steinberg softwares with the alesis master-control studio interface. i hope u run into this to learn my fix.
the problem is check ur midi input on your actual track.make sure it says to (master-control midi port) and not (all midi inputs).as for your device manager settings set to (master-control port) don't set your midi to all or master control port as it will interfere .now it will work perfect.this is for all who have the same problem as well.hope this helps many as i spend a lot of hours of trouble shooting.i almost thought there was something wrong with my mixer.have a great day guys!!
Original post:
I've installed the MasterControl driver as instructed and followed the logic set up instructions provided with the MC and all that seems to happen is the Controller acts as a midi keyboard playing different notes rather than the intended function.
e.g if i touch one of the faders it plays a high pitched note and if i move the fader it acts like the note is being pitched, like a pitch bend function on a keyboard.
Very strange...cannot figure out whats going on
PLEASE HELP I'M GOING INSANE
MacBook Pro Mac OS X (10.6.4)I too had the same problem and resolved it.
However, I have had nothing but issues with the Alesis Mastercontrol since it arrived last week. I purchased mine second-hand as a replacement to a Fire-Wire / Analogue mixer made by Mackie (Onyx 1220). A fantastic amp, but not a control surface.
I decided I wanted an all rounder, plus something I could place in-front of my iMac so I could work on the fly.
So...
1) Alesis Mastercontrol
2) 1 x Rode microphone in Ch1
3) 1 x Rode microphone in Ch2
4) Peavey guitar in Ch3
I use Logic Studio Pro 8.
I finally figured out how to get the Alesis to behave and interact with Logic. So far so good!
I then ran into a series of issues that are frustrating me.
I cannot get the microphones to mute properly (I would also complain about the poorly position gain dials at the back of the unit for the microphones. So poor indeed that I have purchased an Art mic preamp to slap into the back (not arrived yet) and by-pass the rear controls).
I also cannot get my semi-acoustic Peavey to record at all. I can hear it through the control desk, but it is much lower than expected and I am getting nothing when I try to record). In record mode the pair of mics record and I can't get the 3rd channel to operate, although it looks like it's functioning on the screen. I try MUTE / SOLO and selecting the correct channel, but nothing!
All I can do is record myself playing guitar through the mics I cannot switch off.
Strange machine! Almost wishing I'd not sold my Mackie Onyx 1220 so swiftly. -
MOVED: K7D Master Sound Problems
This topic has been moved to Server/workstation.
K7D Master Sound Problems...AC 97 is common hardware so it should be easy to find a driver...maybe here?..
...I'm not familiar with that OS, but have you done all the updates?.. -
Routing through master channel
Hi Guys,
I want to use the master channel to add some final compression to my mix but it appears not to be working e.g. sliding the volume fader on master has no effect on the songs volume.. what's the best way to check that everything's being routed through master properly?
cheers.You can't add compression on the master fader. It is for volume only, no plugs.
To compress your mix: Be sure everything is routed to the same pair of outputs (1/2) and add compression there. -
HT3702 Is there option to use one time virtual card from Master Card?
Is there option to use one time virtual card from Master Card?
Recently my original purchase of app from AppStore failed after successful authentication of 1$ authorization check. Note however the purchased app downloaded successfully.
Also, note this happened as the card usually expires after one time attempt to use it.This Question is not resolved.
-
Is it possible to create a Master-Master-Detail JClient Form?
Hi,
I've been trying to create a Master-Master-Detail JClient Form, where both master-values will be displayed in a seperated drop-down-list.
First I've tested this with a single Master-Detail (is it correct, that a single drop-down-list, working as master will not work with LoV-Binding!?) - However, the combobox-model must be set to Navigation-Binding...
After adding another combobox (the second master), and testing the result, it seems that the detail-table only corresponds to the selection of the first master.
The problem with LoV-Binding was, that the drop-down-list starts with the value at ID '0' (which doesn't exists) instead of '1'...
The Question is, how can I create a Master-Master-Detail JClient Form!?
thanks,
hubiHi,
I've been trying to create a Master-Master-Detail JClient Form, where both master-values will be displayed in a seperated drop-down-list.
First I've tested this with a single Master-Detail (is it correct, that a single drop-down-list, working as master will not work with LoV-Binding!?) - However, the combobox-model must be set to Navigation-Binding...That's true for navigation as you want to use the Combo as the navigator for the Master VO iterator. Lov Binding is used to "update" certain attributes based on selection. You are trying to drive the detail rowset for a selected master and NavigationBinding is the appropriate binding for this purpose.
After adding another combobox (the second master), and testing the result, it seems that the detail-table only corresponds to the selection of the first master.That's the behavior you get from the default data model.
The Question is, how can I create a Master-Master-Detail JClient Form!?First you need to create a ViewUsage structure that implements Master-master-detail. This is not allowed by Bc4j wizards. However you can create such a structure at runtime by using createViewLink method on the ApplicationModule to link the "second" master with the detail (same VO as the first Master's detail).
Assuming both the comboboxes are bound to individual Master VOs using NavigationBinding, you should now be able to traverse the details using both ComboBoxes (which represent the master). -
Master/Master Matrix Report
May I know is it possible to create a Master/Master matrix report? The example given in the Reports Documentation shows Master/Master Tabular reports only and I have been attempting to create a Matrix one but without success. Thank You.
Cheers,
TanI have never come across a two query M:M matrix report. Just out of curiosity, what is your requirement that would make that necessary?
Metalink provides a couple of different ways to do matrix reports (including the 1 query and 3 query methods) but I haven't seen anything to the effect of what you are describing.
Regards,
Steve -
How to set mac mini to virtual router
how to set mac mini to virtual router.
Hi James,
It's Internet Sharing you're looking for in System Preferences>Sharing, which can share your connection, say from Ethernet to other computers/devices using Airport/Wifi. -
Airport Utility cannot find base station. The AirPort Status Icon is showing on my iMac's menu bar, but when I click on it I do not see an AirPort option in the list --- only the various networks that are within range and the options to Create or Join a network. I have a 1st generation Airport Express (Moded A1264) and recently installed a new router, Linksys E1500. Could the router be the problem? Another computer in the house had to be set up on the router using Cisco Connect on my husband's Window's 7 computer. This was also necessary for our Wii console. When I try to use Cisco Connect to see if it needs to recognize the AirPort device, it gives me certain wireless settings necessary to connect the device (Network Name (SSID), Security key and Security Type (WPA2 or WAP). looked on the site but didn't see an option for setting up Airport Express. I also upgraded from Snow Leopard OS to Lion shortly before adding the new router. I use the Airport Express to play our Tune music on powered speakers in our kitchen and did not think to see if it was operating between the time I upgraded the operating system and the time I installed a new router. I have two different versions of AirPort Utility on the computer 6.0 and 5.6. Any suggestions?
Just spoke with Cisco about the router. They said the router is compatible with the E1500. They suggested that I contact Apple to see if their default IP address was that same as the router (192.168.1.1). They told me I would have to change it if that was the case. How would I do that?
-
I need help on Config Master Master Replication
Hi :
I got fail on config Master-Master Replica on Directory Server 5.2sp4
. Can anyone give me some on configuring MMR.
Error message I got as follows:
[25/Jul/2006:17:11:17 +0800] - import userRoot: Processed 489736 entries -- average rate 191.8/sec, recent rate 104.7/sec, hit ratio 97%
[25/Jul/2006:17:11:38 +0800] - import userRoot: Processed 492001 entries -- average rate 191.1/sec, recent rate 105.8/sec, hit ratio 97%
[25/Jul/2006:17:12:00 +0800] - import userRoot: Processed 494072 entries -- average rate 190.3/sec, recent rate 100.8/sec, hit ratio 97%
[25/Jul/2006:17:12:22 +0800] - import userRoot: Processed 496657 entries -- average rate 189.7/sec, recent rate 105.8/sec, hit ratio 97%
[25/Jul/2006:17:12:43 +0800] - import userRoot: Processed 499113 entries -- average rate 189.1/sec, recent rate 114.6/sec, hit ratio 97%
[25/Jul/2006:17:13:05 +0800] - import userRoot: Processed 501254 entries -- average rate 188.4/sec, recent rate 106.9/sec, hit ratio 97%
[25/Jul/2006:17:13:08 +0800] - import userRoot: Workers finished; cleaning up...
[25/Jul/2006:17:13:25 +0800] - import userRoot: Workers cleaned up.
[25/Jul/2006:17:13:25 +0800] - import userRoot: Indexing complete. Post-processing...
[25/Jul/2006:17:13:26 +0800] - import userRoot: Flushing caches...
[25/Jul/2006:17:13:26 +0800] - import userRoot: Closing files...
[25/Jul/2006:17:13:35 +0800] - import userRoot: Import complete. Processed 501537 entries in 2691 seconds. (186.38 entries/sec)
[25/Jul/2006:17:13:35 +0800] - INFORMATION - NSMMReplicationPlugin - conn=-1 op=-1 msgId=-1 - multimaster_be_state_change: replica o=tfn.net.tw is coming online; enabling replication
[25/Jul/2006:17:13:35 +0800] - INFORMATION - NSMMReplicationPlugin - conn=-1 op=-1 msgId=-1 - replica_reload_ruv: Warning: new data for replica o=tfn.net.tw does not match the data in the changelog.
Recreating the changelog file. This could affect replication with replica's consumers in which case the consumers should be reinitialized.
[25/Jul/2006:17:13:36 +0800] - INFORMATION - NSMMReplicationPlugin - conn=-1 op=-1 msgId=-1 - This supplier for replica o=tfn.net.tw will immediately start accepting client updates
[25/Jul/2006:17:13:36 +0800] - INFORMATION - NSMMReplicationPlugin - conn=-1 op=-1 msgId=-1 - Replica (o=tfn.net.tw) has been initialized by total protocol as full replica
[25/Jul/2006:17:13:36 +0800] - WARNING<10276> - Incremental Protocol - conn=-1 op=-1 msgId=-1 - Replication inconsistency Consumer Replica "ldap1.tfn.net.tw:389/o=tfn.net.tw" has a different data version. It may have not been initialized yet.
The procedure I did as follows:
Two LDAP , LDAP1, LDAP2
1. Install LDAP1 and LDAP2
2. Migrate Data from old LDAP Server to New LDAP1
then
On LDAP1:
3. Enable Change Log and some parameter
4. Enable Replication, select "Master"
5. Create Replication Agreement to LDAP2
and then
On LDAP2:
6. Enable Change Log and some parameter
7. Enable Replication, select "Master"
8. Create Replication Agreement to LDAP1
Now Go back LDAP1
9. select replication agreement and start initial LDAP2 now.
10. wait for finished, LDAP1will receive initialiation completed message on startconsole.
but On LDAP2
11. check for error log. I got errors.
[25/Jul/2006:17:13:36 +0800] - WARNING<10276> - Incremental Protocol - conn=-1 op=-1 msgId=-1 - Replication inconsistency Consumer Replica "ldap1.tfn.net.tw:389/o=tfn.net.tw" has a different data version. It may have not been initialized yet.
Can anyone point out what steps I was wrong ?
ps: I can't also find the button on procedure 3 mentioned on admin manual.==>
"To Begin Accepting Updates Through the Console"
Follow these steps to explicitly allow update operations after the initialization of a multi-master replica:
3. Click the button to the right of the message to start accepting update
operations immediately.
Victor1. answer for your last question:
data server -- configuration -- Data -- your suffix -- Replication
In right panel, click on the SIR agreement -- click on "Action" on your right low corner -- choose "Send Updates now ..."
2. answer for your replication question:
Usually I will move step 2 down before step 9. That means setting up replication first, then feeding your master server using your ldif file: to ldap1, then init ldap2 using data from ldap1, either through Console or through command (if using command, have to use db2ldif -r to dump data from ldap1 and use ldif2db to init ldap2).
If anytime in your log, you see "different verison of data", try to init again. -
Hi Everyone,
We have an ASA 5540 at our data center, with ASA 5505's at most remote sites.
At the sites without layer 3 switches behind the ASA 5505's, we can't reach the data center internal network through the ASA for flow-export, etc.
So, what I'm basically saying is, even though the tunnel is up and everything behind the branch ASA can reach the data center networks fine, the ASA itself cannot reach hosts on the data center network.
I'm hoping to configure these ASA 5505's so I can do flow export and SNMP logging from them, but without this routing or nat problem resolved, they just won't do it.
Doing a packet tracer from the ASA 5505 to the data center server I'm most focused on, reveals this:
BRANCH5505f01# packet input inside icmp 10.15.16.1 8 0 10.1.1.15 detailed
Phase: 1
Type: ACCESS-LIST
Subtype:
Result: ALLOW
Config:
Implicit Rule
Additional Information:
Forward Flow based lookup yields rule:
in id=0xcb0b6698, priority=1, domain=permit, deny=false
hits=1004755, user_data=0x0, cs_id=0x0, l3_type=0x8
src mac=0000.0000.0000, mask=0000.0000.0000
dst mac=0000.0000.0000, mask=0100.0000.0000
input_ifc=inside, output_ifc=any
Phase: 2
Type: ROUTE-LOOKUP
Subtype: input
Result: ALLOW
Config:
Additional Information:
in 10.1.1.15 255.255.255.255 outside
Phase: 3
Type: ROUTE-LOOKUP
Subtype: input
Result: ALLOW
Config:
Additional Information:
in 0.0.0.0 0.0.0.0 outside
Result:
input-interface: inside
input-status: up
input-line-status: up
output-interface: outside
output-status: up
output-line-status: up
Action: drop
Drop-reason: (rpf-violated) Reverse-path verify failed
I am thinking the problem is NAT related, but with the new ASA NAT rule format due to v9.1... struggling to get a grip on where it is... any thoughts/help are appreciated.
Ken
Here is the relevant config for the Branch ASA and also the relevant config from the data center ASA:
Branch ASA Config Parts:
: Saved
ASA Version 9.1(2)
hostname BRANCHASA5505
xlate per-session deny tcp any4 any4
xlate per-session deny tcp any4 any6
xlate per-session deny tcp any6 any4
xlate per-session deny tcp any6 any6
xlate per-session deny udp any4 any4 eq domain
xlate per-session deny udp any4 any6 eq domain
xlate per-session deny udp any6 any4 eq domain
xlate per-session deny udp any6 any6 eq domain
names
interface Ethernet0/0
switchport access vlan 2
interface Ethernet0/1
speed 100
duplex full
interface Ethernet0/2
interface Ethernet0/3
interface Ethernet0/4
interface Ethernet0/5
interface Ethernet0/6
interface Ethernet0/7
interface Vlan1
description LAN_NETWORK
nameif inside
security-level 100
ip address 10.15.6.1 255.255.254.0
interface Vlan2
nameif outside
security-level 0
ip address <outside ip> 255.255.255.248
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
object network obj_any
subnet 0.0.0.0 0.0.0.0
object-group network BRANCH_NETWORKS
description BRANCH LOCAL NETWORKS
network-object 10.15.6.0 255.255.254.0
object-group network LAN_NETWORKS
network-object 10.0.0.0 255.0.0.0
network-object 134.200.131.0 255.255.255.0
network-object 134.200.220.0 255.255.255.0
network-object 134.201.2.0 255.255.255.0
network-object 163.243.195.0 255.255.255.0
network-object 172.16.0.0 255.240.0.0
network-object 192.168.0.0 255.255.0.0
network-object 10.1.3.0 255.255.255.0
network-object 10.31.2.0 255.255.255.0
network-object 10.1.1.0 255.255.255.0
network-object 172.26.1.0 255.255.255.0
object-group network NETWORK_MGMT
network-object 10.0.0.0 255.0.0.0
access-list DATACENTER_VPN_ACL remark *******************************************************************
access-list DATACENTER_VPN_ACL remark * FOR VPN CONNECTION TO DATACENTER/VEYANCE NETWORKS *
access-list DATACENTER_VPN_ACL remark *******************************************************************
access-list DATACENTER_VPN_ACL extended permit ip host <outside ip> host <outside ip datacenter asa>
access-list DATACENTER_VPN_ACL extended permit ip object-group BRANCH_NETWORKS object-group LAN_NETWORKS
access-list INSIDE_NONAT extended permit ip object-group BRANCH_NETWORKS object-group LAN_NETWORKS
access-list INSIDE_FILTER extended permit tcp any4 any4 eq www
access-list INSIDE_FILTER extended permit tcp any4 any4 eq 8080
logging host inside 10.1.1.15
flow-export destination inside 10.1.1.15 2055
ip verify reverse-path interface inside
ip verify reverse-path interface outside
nat (inside,outside) source static LAN_NETWORKS LAN_NETWORKS destination static BRANCH_NETWORKS BRANCH_NETWORKS route-lookup
nat (inside,outside) source static BRANCH_NETWORKS BRANCH_NETWORKS destination static NETWORK_MGMT NETWORK_MGMT route-lookup
nat (inside,outside) source dynamic any interface
object network obj_any
nat (inside,outside) dynamic interface
access-group FROM_OUTSIDE in interface outside
route outside 0.0.0.0 0.0.0.0 <outside ip gateway> 1
route outside 10.1.1.15 255.255.255.255 <outside ip datacenter asa> 1
management-access inside
threat-detection basic-threat
threat-detection statistics access-list
no threat-detection statistics tcp-intercept
tunnel-group <outside ip datacenter asa> type ipsec-l2l
tunnel-group <outside ip datacenter asa> ipsec-attributes
ikev1 pre-shared-key *****
class-map type regex match-any DomainBlockList
match regex DomainList-Netflix
class-map type inspect http match-all BlockDomainsClass
match request header host regex class DomainBlockList
class-map inspection_default
match default-inspection-traffic
class-map httptraffic
match access-list INSIDE_FILTER
policy-map type inspect dns preset_dns_map
parameters
message-length maximum client auto
message-length maximum 512
policy-map type inspect http http_inspection_policy
parameters
protocol-violation action log
class BlockDomainsClass
reset log
policy-map URL-filter-policy
class httptraffic
inspect http http_inspection_policy
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect ip-options
inspect http
class class-default
flow-export event-type all destination 10.1.1.15
service-policy URL-filter-policy interface inside
prompt hostname context
Datacenter ASA Config Parts:
ASA Version 9.0(1)
hostname DATACENTERASA5540
xlate per-session deny tcp any4 any4
xlate per-session deny tcp any4 any6
xlate per-session deny tcp any6 any4
xlate per-session deny tcp any6 any6
xlate per-session deny udp any4 any4 eq domain
xlate per-session deny udp any4 any6 eq domain
xlate per-session deny udp any6 any4 eq domain
xlate per-session deny udp any6 any6 eq domain
xlate per-session deny tcp any4 any4
xlate per-session deny tcp any4 any6
xlate per-session deny tcp any6 any4
xlate per-session deny tcp any6 any6
xlate per-session deny udp any4 any4 eq domain
xlate per-session deny udp any4 any6 eq domain
xlate per-session deny udp any6 any4 eq domain
xlate per-session deny udp any6 any6 eq domain
names
interface GigabitEthernet0/0
description *** TO OUTSIDE NETWORK AT DATACENTER ***
speed 100
duplex full
nameif OUTSIDE
security-level 0
ip address <outside ip>
interface GigabitEthernet0/1
description *** TO INSIDE NETWORK ***
nameif INSIDE
security-level 100
ip address 10.1.3.2 255.255.255.0
same-security-traffic permit inter-interface
same-security-traffic permit intra-interface
object-group network LAN_NETWORKS
network-object 10.0.0.0 255.0.0.0
network-object 134.200.131.0 255.255.255.0
network-object 134.200.220.0 255.255.255.0
network-object 134.201.2.0 255.255.255.0
network-object 163.243.195.0 255.255.255.0
network-object 172.16.0.0 255.240.0.0
network-object 192.168.0.0 255.255.0.0
network-object 10.1.3.0 255.255.255.0
network-object 10.31.2.0 255.255.255.0
network-object 10.1.1.0 255.255.255.0
network-object 172.26.1.0 255.255.255.0
object-group network DATACENTER_NETWORKS
network-object 10.1.0.0 255.255.0.0
object-group network BRANCH_NETWORKS
network-object 10.15.6.0 255.255.254.0
access-list BRANCH_VPN_ACL remark ****************************************************
access-list BRANCH_VPN_ACL remark * FOR SITE TO SITE VPN TO BRANCH WV USA *
access-list BRANCH_VPN_ACL remark ****************************************************
access-list BRANCH_VPN_ACL extended permit ip host <outside ip> host <outside ip branch asa>
access-list BRANCH_VPN_ACL extended permit ip object-group LAN_NETWORKS object-group BRANCH_NETWORKS
flow-export destination INSIDE 10.1.1.15 2055
flow-export template timeout-rate 1
flow-export delay flow-create 180
ip verify reverse-path interface OUTSIDE
ip verify reverse-path interface INSIDE
no failover
nat (INSIDE,OUTSIDE) source static LAN_NETWORKS LAN_NETWORKS destination static BRANCH_NETWORKS BRANCH_NETWORKS route-lookup
access-group FROM_OUTSIDE in interface OUTSIDE
route OUTSIDE 0.0.0.0 0.0.0.0 <outside ip> 1
route INSIDE 10.0.0.0 255.0.0.0 10.1.3.1 1
route OUTSIDE 10.15.6.0 255.255.254.0 <outside ip branch asa> 1
crypto map OUTSIDE-MAP 156 match address BRANCH_VPN_ACL
crypto map OUTSIDE-MAP 156 set pfs
crypto map OUTSIDE-MAP 156 set peer <outside ip branch asa>
crypto map OUTSIDE-MAP 156 set ikev1 transform-set ESP-3DES-MD5 ESP-3DES-SHA
tunnel-group <outside ip branch asa> type ipsec-l2l
tunnel-group <outside ip branch asa> ipsec-attributes
ikev1 pre-shared-key *****
class-map inspection_default
match default-inspection-traffic
policy-map type inspect dns preset_dns_map
parameters
message-length maximum client auto
message-length maximum 512
policy-map global_policy
class inspection_default
inspect dns preset_dns_map
inspect ftp
inspect h323 h225
inspect h323 ras
inspect rsh
inspect rtsp
inspect esmtp
inspect sqlnet
inspect skinny
inspect sunrpc
inspect xdmcp
inspect sip
inspect netbios
inspect tftp
inspect ip-options
class class-default
flow-export event-type all destination 10.1.1.15
user-statistics accounting
service-policy global_policy global
smtp-server 172.19.1.137
prompt hostname context
call-home reporting anonymous
Again, any help you can provide is appreciated... will vote for best...I ran it, with the source IP corrected (it is 10.15.6.2):
BRANCHASA# packet input inside icmp 10.15.6.2 8 0 10.1.1.15 detailed
Phase: 1
Type: ACCESS-LIST
Subtype:
Result: ALLOW
Config:
Implicit Rule
Additional Information:
Forward Flow based lookup yields rule:
in id=0xcb0b6698, priority=1, domain=permit, deny=false
hits=1203279, user_data=0x0, cs_id=0x0, l3_type=0x8
src mac=0000.0000.0000, mask=0000.0000.0000
dst mac=0000.0000.0000, mask=0100.0000.0000
input_ifc=inside, output_ifc=any
Phase: 2
Type: ROUTE-LOOKUP
Subtype: input
Result: ALLOW
Config:
Additional Information:
in 0.0.0.0 0.0.0.0 outside
Phase: 3
Type: UN-NAT
Subtype: static
Result: ALLOW
Config:
nat (inside,outside) source static BRANCH_NETWORKS BRANCH_NETWORKS destination static NETWORK_MGMT NETWORK_MGMT route-lookup
Additional Information:
NAT divert to egress interface outside
Untranslate 10.1.1.15/0 to 10.1.1.15/0
Phase: 4
Type: ROUTE-LOOKUP
Subtype: input
Result: ALLOW
Config:
Additional Information:
in 10.15.6.0 255.255.254.0 inside
Phase: 5
Type: NAT
Subtype:
Result: ALLOW
Config:
nat (inside,outside) source static BRANCH_NETWORKS BRANCH_NETWORKS destination static NETWORK_MGMT NETWORK_MGMT route-lookup
Additional Information:
Static translate 10.15.6.2/0 to 10.15.6.2/0
Forward Flow based lookup yields rule:
in id=0xcb12f2f0, priority=6, domain=nat, deny=false
hits=15824, user_data=0xcb0fdef8, cs_id=0x0, flags=0x0, protocol=0
src ip/id=10.15.6.0, mask=255.255.254.0, port=0, tag=0
dst ip/id=10.0.0.0, mask=255.0.0.0, port=0, tag=0, dscp=0x0
input_ifc=inside, output_ifc=outside
Phase: 6
Type: NAT
Subtype: per-session
Result: ALLOW
Config:
Additional Information:
Forward Flow based lookup yields rule:
in id=0xcaa712e0, priority=0, domain=nat-per-session, deny=true
hits=77610, user_data=0x0, cs_id=0x0, reverse, use_real_addr, flags=0x0, protocol=0
src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0
dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0, dscp=0x0
input_ifc=any, output_ifc=any
Phase: 7
Type: IP-OPTIONS
Subtype:
Result: ALLOW
Config:
Additional Information:
Forward Flow based lookup yields rule:
in id=0xcb0bc128, priority=0, domain=inspect-ip-options, deny=true
hits=91404, user_data=0x0, cs_id=0x0, reverse, flags=0x0, protocol=0
src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0
dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0, dscp=0x0
input_ifc=inside, output_ifc=any
Phase: 8
Type: INSPECT
Subtype: np-inspect
Result: ALLOW
Config:
Additional Information:
Forward Flow based lookup yields rule:
in id=0xcb0bbc28, priority=66, domain=inspect-icmp-error, deny=false
hits=4585, user_data=0xcb0bb238, cs_id=0x0, use_real_addr, flags=0x0, protocol=1
src ip/id=0.0.0.0, mask=0.0.0.0, icmp-type=0, tag=0
dst ip/id=0.0.0.0, mask=0.0.0.0, icmp-code=0, tag=0, dscp=0x0
input_ifc=inside, output_ifc=any
Phase: 9
Type: VPN
Subtype: encrypt
Result: ALLOW
Config:
Additional Information:
Forward Flow based lookup yields rule:
out id=0xcb0c1218, priority=70, domain=encrypt, deny=false
hits=708, user_data=0xbf63c, cs_id=0xcb9ad918, reverse, flags=0x0, protocol=0
src ip/id=10.15.6.0, mask=255.255.254.0, port=0, tag=0
dst ip/id=10.0.0.0, mask=255.0.0.0, port=0, tag=0, dscp=0x0
input_ifc=any, output_ifc=outside
Phase: 10
Type: NAT
Subtype: rpf-check
Result: ALLOW
Config:
nat (inside,outside) source static BRANCH_NETWORKS BRANCH_NETWORKS destination static NETWORK_MGMT NETWORK_MGMT route-lookup
Additional Information:
Forward Flow based lookup yields rule:
out id=0xcb12fb00, priority=6, domain=nat-reverse, deny=false
hits=15837, user_data=0xcb124438, cs_id=0x0, use_real_addr, flags=0x0, protocol=0
src ip/id=10.15.6.0, mask=255.255.254.0, port=0, tag=0
dst ip/id=10.0.0.0, mask=255.0.0.0, port=0, tag=0, dscp=0x0
input_ifc=inside, output_ifc=outside
Phase: 11
Type: FLOW-CREATION
Subtype:
Result: ALLOW
Config:
Additional Information:
New flow created with id 143081, packet dispatched to next module
Module information for forward flow ...
snp_fp_tracer_drop
snp_fp_inspect_ip_options
snp_fp_translate
snp_fp_adjacency
snp_fp_encrypt
snp_fp_fragment
snp_ifc_stat
Module information for reverse flow ...
Result:
input-interface: inside
input-status: up
input-line-status: up
output-interface: outside
output-status: up
output-line-status: up
Action: allow -
RG54G2 Wireless Router Internet Connection Problem
Hi,
(apologies for the long message - trying to cover all details - summary: wireless router often drops internet connection)
I recently bought an RG54G2 Wireless Router, a CB54G2 PCMCIA Wireless card and a D-Link GWL-630 PCMCIA Wireless card. In addition to two laptops connected to the wireless router WLAN, I have two PCs (one Win WP Pro SP 1 and one Win98SE) connected to the router via wired LAN. I also have a SurfBoard SB3100 Cable Modem connected to the WAN port (this connects to my ISP - Optusnet (Australia) via DHCP).
The problem I have is that the internet connection is disconnected many times a day (often every few minutes, sometimes an hour or so). I am able to reconnect by resetting the wireless router via the wireless router configuration page. When the internet is disconnected I am still able to access the computers on the LAN/WLAN (via Windows Explorer and Ping), I am also able to ping the router and the Cable Modem, but nothing outside of the cable modem.
Also, when the internet is disconnected the System Status page indicates that the router is still connected to the internet, and the Diagnostics page passes the Test Connection test, though no external pings work.
I did not have this problem when the cable modem was connected directly to the Win98SE PC (and other PCs via ICS).
I have disabled the WLAN and the problem still exists with only the wired LAN.
I have changed numerous settings in the wireless router config page with no success (eg disabling DHCP and setting each IP address, minimising LAN and WLAN speeds to 10 and 11MBps plus others).
I have upgraded the wireless router firmware to R1.0.6.0 (no change to the problem).
Searching on Google I have found several other cases of routers with unstable internet connections (none refering to the MSI routers), but none had solutions that helped my situation (most replies suggested updating the firmware).
Any suggestions of how to make the router internet connection stable?
Thanks,
Mikemaybe this is the FIX 4 wireles router internet connection problem
please let me know if any one fix the problem with this tips
thankz
M. B. Feb 6 2004, 8:20 am hide options
Newsgroups: comp.os.ms-windows.networking.windows
From: "M. B." - Find messages by this author
Date: Fri, 06 Feb 2004 16:20:48 GMT
Local: Fri, Feb 6 2004 8:20 am
Subject: SOLUTION to my router loosing connection to Windows XP
Reply | Reply to Author | Forward | Print | Individual Message | Show original | Report Abuse
I am happy to report that after 8 days of constant battles, reboots, phone
calls, cable pulling, router changing, it seems that I finally have found a
combination that has had me using Verizon DSL account for over 12 hours so
far without any kind of interruptions.
Since so many of you tried giving me comments and suggestions, I felt that
it is necessary for me to post this here so that the next person will not
(hopefully) need to go through this hell as I did!
My original problem was that when after I purchased a D-Link Wireless Router
DI-624, I would get disconnected from Verizon DSL at least once every 2
hours or so. My internet access would "freeze" and then a little popup box
at the bottom right system tray would tell me that the "LAN cable has been
unplugged". After about a minute or so, my internet connection would be
back working This was NEVER happening during the 2+ years I was using my
Westell modem alone (running in router mode).
Please keep in mind: The problem I was having was not wireless related as
it was happening to the desktop computer to which the router/westell was
connected to!
During these last 8 days, I tried: one DI-624 wireless router, two Netgear
614v3 routers and two Linksys WRT54G v.2 routers. In addition, I received a
brand new Westell 2200 modem from Verizon. I also tried about four
different CAT-5 cables. Here is the final outcome:
I have the Linksys WRT54G (version 2) wireless router connected to the
Netgear Fast Ethernet FA310TX network card in Auto-Sense mode (using the
built-in XP drivers, as Netgear told me that there was never a newer
revision released). I have DISABLED the built-in 3Com Gigabit LOM (3C940)
network card (via the ASUS P4C800 Deluxe motherboard BIOS), DISABLED the
Zero Wireless Configuration service, and have put in the IP/Gateway/DNS
address numbers inside my Windows XP Network Connections | LAN setup. My
operating system is Windows XP Pro SP1 and the modem is a Westell 2200
configured as bridge only.
If my situation continues to be stable, I *might* try to go back to the 3Com
built-in card (disable any power management) and then re-enabling the Zero
Wireless Configuration services. But in reality, I am happy with the way
things are and have already spent enough time trying to get my router to
work with Verizon DSL without having it drop connections!
Now, the next step will be setting up the WIRELESS part of this. I don't
even yet have a laptop with me on the premises, but the 802.11g card that I
already have is the D-Link DWL-G650. I hope and assume that this will work
okay with the Linksys...
One thing I must say is that I never realized that how many problems other
users are having. I would have thought that since 802.11x has been around
in the mainstream by now 2+ years, that things would have been much more
"system friendlier". And again, my issues were not even WIRELESS related.
All 3 tech supports were not really helpful, as none of them realized that
the problem is somehow between the router and Windows XP (Ethernet card?)
loosing a connection, which of course results in Verizon DSL loosing the
connection also.
One other comment about the Netgear 614 v.3 router: A number of people have
responded to tell me that they have had this random "router resetting"
happen to them (where the routers behaves as if someone turned the power off
and then back on, and the lights flash) just as if you first turn it on). I
was lucky to witness it myself during one of the "disconnects" that I had.
This was actually the reason why I went back to try the Linksys one more
time. So, I would definitely recommend staying way from this 614 (version
3) model.
Once again - THANK YOU everyone! -
CS4 Master Collection - Problem occurred while extracting...
After spending $1,500 and two days of RL time downloading the CS4 Master Collection twice, I am just a tad frustrated.
Each time I download the CS4 suite file and try to install it, I immediately get the error:
"A problem occurred while extracting the archive. Please try downloading the Adobe CS4 Master Collection again."
No. I refuse to spend another full day downloading this file yet again just to receive the same error.
Anyone have some insight into this problem? (more so than "turn off your anti-virus program"
Thanks in advance.I am having the same problem. I found a forum that suggested this. Apparently it worked for some people, but not for me. Let me know if it does:
1. Start -> All Programs -> Accessories
2. Right-click on Command Prompt and select "Run as..."
3. Run as Administrator (even if you are logged in as Admin. You need to run in the Black Command Prompt, not the White one)
4. Run: regsvr32 JScript.DLL
5. Then run: regsvr32 vbscript.DLL
(dont forget the spaces, or it won't work)
6. Then try running the set up again
As i said, it worked for some on the forum, but not others (like me). Try it and see if works for you -
CS4 Master Collection - Problem Applying Updates
Hi
I'm running the CS4 Master Collection on Windows Vista Ultimate 32-bit, SP2.
Normally I have no problem applying updates to the various Adobe components when they become available, however for a while now I've been unable to instal an update that's reported as being available for Adobe Media Encoder 4.1.0.
If I run the "check for updates" manually I can download the update (reported as being 63.7MB) and when I attempt to instal it the installation process appears to run. It finishes after a while and the Adobe Updater reports "The Udating Process is Finished" in a single dialog box with a single button entitled "Quit" - which seems odd as "Quit" implies "finish earlier than planned", I'd have expected something more in line with "All done", something like "OK".
Anyway, when I run the check for updates again I'm told about the same update implying that it wasn't applied successfully.
I get this behaviour whether I run the update as an Administrator or not (all other updates for other products are applied without problem). I also get it regardless of whether or not I reboot the machine after trying to apply the update.
Does anyone have any suggestions on what could be causing the problem ? I couldn't find anything obvious or obviously relevant in any of the Windows event logs on the PC.
Thanks for any ideas
SteveI am having the same problem. I found a forum that suggested this. Apparently it worked for some people, but not for me. Let me know if it does:
1. Start -> All Programs -> Accessories
2. Right-click on Command Prompt and select "Run as..."
3. Run as Administrator (even if you are logged in as Admin. You need to run in the Black Command Prompt, not the White one)
4. Run: regsvr32 JScript.DLL
5. Then run: regsvr32 vbscript.DLL
(dont forget the spaces, or it won't work)
6. Then try running the set up again
As i said, it worked for some on the forum, but not others (like me). Try it and see if works for you
Maybe you are looking for
-
Since updating my iPad mini I have been unable to send or receive messages. My iPad only wants to recognize contacts with apple products but still won't deliver a message to them. What can I do to solve this problem?
-
How to import images in iPhoto?
I use iPhoto importing images from this same computer and from iPhone with iCloud. A problem I've always suffered also before buying iPhone was that I can't import images in iPhoto. Well, I can drag an image from, for example, the desktop, but if I d
-
Real time queries to know more about live project
Hi All, I am new to XI, I have some doubts about real time xi project related activities. 1. Who will be responsible for preparing the minutes of meeting? (XI Developer/Team Lead/senior consultant etc ) 2 In usual Dev->QA->Prod project cycle...
-
Applying PSU 2 to OMS causes service to be unavailable.
Repository Database Oracle 11.2.0.3 OMS 12.1.0.2.0 Agent(s) 12.1.0.2.0 Grid Infrastructure 11.2.0.3 Our goal is to patch Enterprise Manager 12C R2 with the latest PSUs and patches so that we can being using it in ernest, tackling one problem at a tim
-
Subtracting numerical fields in form fields
I am looking for a way to subtract a numerical field in one field from the other. On the form field, when calculate tab is chosen, there is no drop down for the (-) side of the equation. Is there a way to do a simple Javascript code to do this task?