CSS virtual-router master/master problem

Dear all experts,
I have two CSSs 11150 and have configured them as following:
CSS-1#
circuit VLAN100
  ip address 172.10.10.101 255.255.255.0
    ip virtual-router 1 priority 105 preempt
    ip redundant-vip 1 172.10.10.1
    ip critical-service 1 up_down_stream
    no redirects
CSS-2#
circuit VLAN100
  ip address 172.10.10.102 255.255.255.0
    ip virtual-router 1 priority 101 preempt
    ip redundant-vip 1 172.10.10.1
    ip critical-service 1 up_down_stream
    no redirects
Here is my connection:
CSS-1 <=> Switch <=> CSS-2
They were working fine before but CSS-2 suddenly change to master few days ago. I have already checked the connection between these two CSSs and it seems ok, so I tried to capture the packet trace both for the ports connected to CSS-1 and CSS-2 from the switch. And finally I found that I can see the vrrp adv. message which send from CSS-2 at the port which is monitoring CSS-1, but there is no vrrp adv. message send from CSS-1. I am not sure the problem is related to the acl as it has configured to permit any any:
clause 254 permit any any destination any
Could anyone can help me in this case? Is the problem related to the keyword "preempt" in CSS-2? Is it a software bugs which hasn't listed in cisco bug list (SW Version: 6.10)?
Thanks!

Hi,
I'm not sure if this you've resolved this problem; however, from what I have read you should never configure the preempt option on the same virtual router on both CSSs.
The issue of both CSSs becoming master when using the preempt option is highlighted in this guide:
http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/css11000series/v5.00/command/reference/CmdCirIP.html#wp1027189
I have used the preempt option to failover to the backup CSS in the past; however, to achieve this the preempt option had to be removed from the existing master.
I hope this helps.
Thanks,
C

Similar Messages

  • Problem with Virtual Credit Card Master Card

    (Sorry for my english, i am from Russia)
    I bought Virtual Credit Card Master Card and put its number and security code. Then I bought Pages, Keynote,GT Racing and some other apps. They have successfully downloaded and I can use them. But money from the credit card didnt removed (??) !
    When I entered iTunes from my PC I saw this letters: "We were unable to authorize your credit card for this purshase. Please update your billing ifo. Amount you owe: 31.93 $" But I entered all true (I checked), but i have only 27 $ on my credit card and I can not fill up it (it's a virtual card) Can you take the money that I have now on my credit card? Then I'll buy another and repay debt. Now i can't buy anything from AppStore (Even free), but I can use all apps (Pages, Keynote,GT Racing) I bought. (but money from the credit card didnt removed!!!)
    How to pay this bill and use app store? Please, help me!
    Message was edited by: Nikden

    You have posted on a user board. You need to contact itunes store support!
    http://www.apple.com/support/itunes/contact.html

  • Topic : Alesis Master Control Problem (to previous post unanswered fixed)

    Topic : Alesis Master Control Problem to the original post user: Garrud
    Me:111984cz i have an answer to ur problem.i too had the same problem with cubase 5 ,Nuendo 4 and any of Steinberg softwares with the alesis master-control studio interface. i hope u run into this to learn my fix.
    the problem is check ur midi input on your actual track.make sure it says to (master-control midi port) and not (all midi inputs).as for your device manager settings set to (master-control port) don't set your midi to all or master control port as it will interfere .now it will work perfect.this is for all who have the same problem as well.hope this helps many as i spend a lot of hours of trouble shooting.i almost thought there was something wrong with my mixer.have a great day guys!!
    Original post:
    I've installed the MasterControl driver as instructed and followed the logic set up instructions provided with the MC and all that seems to happen is the Controller acts as a midi keyboard playing different notes rather than the intended function.
    e.g if i touch one of the faders it plays a high pitched note and if i move the fader it acts like the note is being pitched, like a pitch bend function on a keyboard.
    Very strange...cannot figure out whats going on
    PLEASE HELP I'M GOING INSANE
    MacBook Pro Mac OS X (10.6.4)

    I too had the same problem and resolved it.
    However, I have had nothing but issues with the Alesis Mastercontrol since it arrived last week. I purchased mine second-hand as a replacement to a Fire-Wire / Analogue mixer made by Mackie (Onyx 1220). A fantastic amp, but not a control surface.
    I decided I wanted an all rounder, plus something I could place in-front of my iMac so I could work on the fly.
    So...
    1) Alesis Mastercontrol
    2) 1 x Rode microphone in Ch1
    3) 1 x Rode microphone in Ch2
    4) Peavey guitar in Ch3
    I use Logic Studio Pro 8.
    I finally figured out how to get the Alesis to behave and interact with Logic. So far so good!
    I then ran into a series of issues that are frustrating me.
    I cannot get the microphones to mute properly (I would also complain about the poorly position gain dials at the back of the unit for the microphones. So poor indeed that I have purchased an Art mic preamp to slap into the back (not arrived yet) and by-pass the rear controls).
    I also cannot get my semi-acoustic Peavey to record at all. I can hear it through the control desk, but it is much lower than expected and I am getting nothing when I try to record). In record mode the pair of mics record and I can't get the 3rd channel to operate, although it looks like it's functioning on the screen. I try MUTE / SOLO and selecting the correct channel, but nothing!
    All I can do is record myself playing guitar through the mics I cannot switch off.
    Strange machine! Almost wishing I'd not sold my Mackie Onyx 1220 so swiftly.

  • MOVED: K7D Master Sound Problems

    This topic has been moved to Server/workstation.
    K7D Master Sound Problems

    ...AC 97 is common hardware so it should be easy to find a driver...maybe here?..
    ...I'm not familiar with that OS, but have you done all the updates?..

  • Routing through master channel

    Hi Guys,
    I want to use the master channel to add some final compression to my mix but it appears not to be working e.g. sliding the volume fader on master has no effect on the songs volume.. what's the best way to check that everything's being routed through master properly?
    cheers.

    You can't add compression on the master fader. It is for volume only, no plugs.
    To compress your mix: Be sure everything is routed to the same pair of outputs (1/2) and add compression there.

  • HT3702 Is there option to use one time virtual card from Master Card?

    Is there option to use one time virtual card from Master Card?
    Recently my original purchase of app from AppStore failed after successful authentication of 1$ authorization check. Note however the purchased app downloaded successfully.
    Also, note this happened as the card usually expires after one time attempt to use it.

    This Question is not resolved.

  • Is it possible to create a Master-Master-Detail JClient Form?

    Hi,
    I've been trying to create a Master-Master-Detail JClient Form, where both master-values will be displayed in a seperated drop-down-list.
    First I've tested this with a single Master-Detail (is it correct, that a single drop-down-list, working as master will not work with LoV-Binding!?) - However, the combobox-model must be set to Navigation-Binding...
    After adding another combobox (the second master), and testing the result, it seems that the detail-table only corresponds to the selection of the first master.
    The problem with LoV-Binding was, that the drop-down-list starts with the value at ID '0' (which doesn't exists) instead of '1'...
    The Question is, how can I create a Master-Master-Detail JClient Form!?
    thanks,
    hubi

    Hi,
    I've been trying to create a Master-Master-Detail JClient Form, where both master-values will be displayed in a seperated drop-down-list.
    First I've tested this with a single Master-Detail (is it correct, that a single drop-down-list, working as master will not work with LoV-Binding!?) - However, the combobox-model must be set to Navigation-Binding...That's true for navigation as you want to use the Combo as the navigator for the Master VO iterator. Lov Binding is used to "update" certain attributes based on selection. You are trying to drive the detail rowset for a selected master and NavigationBinding is the appropriate binding for this purpose.
    After adding another combobox (the second master), and testing the result, it seems that the detail-table only corresponds to the selection of the first master.That's the behavior you get from the default data model.
    The Question is, how can I create a Master-Master-Detail JClient Form!?First you need to create a ViewUsage structure that implements Master-master-detail. This is not allowed by Bc4j wizards. However you can create such a structure at runtime by using createViewLink method on the ApplicationModule to link the "second" master with the detail (same VO as the first Master's detail).
    Assuming both the comboboxes are bound to individual Master VOs using NavigationBinding, you should now be able to traverse the details using both ComboBoxes (which represent the master).

  • Master/Master Matrix Report

    May I know is it possible to create a Master/Master matrix report? The example given in the Reports Documentation shows Master/Master Tabular reports only and I have been attempting to create a Matrix one but without success. Thank You.
    Cheers,
    Tan

    I have never come across a two query M:M matrix report. Just out of curiosity, what is your requirement that would make that necessary?
    Metalink provides a couple of different ways to do matrix reports (including the 1 query and 3 query methods) but I haven't seen anything to the effect of what you are describing.
    Regards,
    Steve

  • How to set mac mini to virtual router

    how to set mac mini to virtual router.

    Hi James,
    It's Internet Sharing you're looking for in System Preferences>Sharing, which can share your connection, say from Ethernet to other computers/devices using Airport/Wifi.

  • Airport Express 1st Generation base station not showing up using new Linksys E1500 router.  Compatibility problem?

    Airport Utility cannot find base station.  The AirPort Status Icon is showing on my iMac's menu bar, but when I click on it I do not see an AirPort option in the list --- only the various networks that are within range and the options to Create or Join a network.  I have a 1st generation Airport Express (Moded A1264) and recently installed a new router, Linksys E1500.  Could the router be the problem?  Another computer in the house had to be set up on the router using Cisco Connect on my husband's Window's 7 computer.  This was also necessary for our Wii console.  When I try to use Cisco Connect to see if it needs to recognize the AirPort device, it gives me certain wireless settings necessary to connect the device (Network Name (SSID), Security key and Security Type (WPA2 or WAP).    looked on the site but didn't see an option for setting up Airport Express.  I also upgraded from Snow Leopard OS to Lion shortly before adding the new router.  I use the Airport Express to play our Tune music on powered speakers in our kitchen and did not think to see if it was operating between the time I upgraded the operating system and the time I installed a new router.  I have two different versions of AirPort Utility on the computer  6.0 and 5.6.  Any suggestions?

    Just spoke with Cisco about the router.  They said the router is compatible with the E1500.  They suggested that I contact Apple to see if their default IP address was that same as the router (192.168.1.1).  They told me I would have to change it if that was the case.  How would I do that?

  • I need help on Config Master Master Replication

    Hi :
    I got fail on config Master-Master Replica on Directory Server 5.2sp4
    . Can anyone give me some on configuring MMR.
    Error message I got as follows:
    [25/Jul/2006:17:11:17 +0800] - import userRoot: Processed 489736 entries -- average rate 191.8/sec, recent rate 104.7/sec, hit ratio 97%
    [25/Jul/2006:17:11:38 +0800] - import userRoot: Processed 492001 entries -- average rate 191.1/sec, recent rate 105.8/sec, hit ratio 97%
    [25/Jul/2006:17:12:00 +0800] - import userRoot: Processed 494072 entries -- average rate 190.3/sec, recent rate 100.8/sec, hit ratio 97%
    [25/Jul/2006:17:12:22 +0800] - import userRoot: Processed 496657 entries -- average rate 189.7/sec, recent rate 105.8/sec, hit ratio 97%
    [25/Jul/2006:17:12:43 +0800] - import userRoot: Processed 499113 entries -- average rate 189.1/sec, recent rate 114.6/sec, hit ratio 97%
    [25/Jul/2006:17:13:05 +0800] - import userRoot: Processed 501254 entries -- average rate 188.4/sec, recent rate 106.9/sec, hit ratio 97%
    [25/Jul/2006:17:13:08 +0800] - import userRoot: Workers finished; cleaning up...
    [25/Jul/2006:17:13:25 +0800] - import userRoot: Workers cleaned up.
    [25/Jul/2006:17:13:25 +0800] - import userRoot: Indexing complete. Post-processing...
    [25/Jul/2006:17:13:26 +0800] - import userRoot: Flushing caches...
    [25/Jul/2006:17:13:26 +0800] - import userRoot: Closing files...
    [25/Jul/2006:17:13:35 +0800] - import userRoot: Import complete. Processed 501537 entries in 2691 seconds. (186.38 entries/sec)
    [25/Jul/2006:17:13:35 +0800] - INFORMATION - NSMMReplicationPlugin - conn=-1 op=-1 msgId=-1 - multimaster_be_state_change: replica o=tfn.net.tw is coming online; enabling replication
    [25/Jul/2006:17:13:35 +0800] - INFORMATION - NSMMReplicationPlugin - conn=-1 op=-1 msgId=-1 - replica_reload_ruv: Warning: new data for replica o=tfn.net.tw does not match the data in the changelog.
    Recreating the changelog file. This could affect replication with replica's consumers in which case the consumers should be reinitialized.
    [25/Jul/2006:17:13:36 +0800] - INFORMATION - NSMMReplicationPlugin - conn=-1 op=-1 msgId=-1 - This supplier for replica o=tfn.net.tw will immediately start accepting client updates
    [25/Jul/2006:17:13:36 +0800] - INFORMATION - NSMMReplicationPlugin - conn=-1 op=-1 msgId=-1 - Replica (o=tfn.net.tw) has been initialized by total protocol as full replica
    [25/Jul/2006:17:13:36 +0800] - WARNING<10276> - Incremental Protocol - conn=-1 op=-1 msgId=-1 - Replication inconsistency Consumer Replica "ldap1.tfn.net.tw:389/o=tfn.net.tw" has a different data version. It may have not been initialized yet.
    The procedure I did as follows:
    Two LDAP , LDAP1, LDAP2
    1. Install LDAP1 and LDAP2
    2. Migrate Data from old LDAP Server to New LDAP1
    then
    On LDAP1:
    3. Enable Change Log and some parameter
    4. Enable Replication, select "Master"
    5. Create Replication Agreement to LDAP2
    and then
    On LDAP2:
    6. Enable Change Log and some parameter
    7. Enable Replication, select "Master"
    8. Create Replication Agreement to LDAP1
    Now Go back LDAP1
    9. select replication agreement and start initial LDAP2 now.
    10. wait for finished, LDAP1will receive initialiation completed message on startconsole.
    but On LDAP2
    11. check for error log. I got errors.
    [25/Jul/2006:17:13:36 +0800] - WARNING<10276> - Incremental Protocol - conn=-1 op=-1 msgId=-1 - Replication inconsistency Consumer Replica "ldap1.tfn.net.tw:389/o=tfn.net.tw" has a different data version. It may have not been initialized yet.
    Can anyone point out what steps I was wrong ?
    ps: I can't also find the button on procedure 3 mentioned on admin manual.==>
    "To Begin Accepting Updates Through the Console"
    Follow these steps to explicitly allow update operations after the initialization of a multi-master replica:
    3. Click the button to the right of the message to start accepting update
    operations immediately.
    Victor

    1. answer for your last question:
    data server -- configuration -- Data -- your suffix -- Replication
    In right panel, click on the SIR agreement -- click on "Action" on your right low corner -- choose "Send Updates now ..."
    2. answer for your replication question:
    Usually I will move step 2 down before step 9. That means setting up replication first, then feeding your master server using your ldif file: to ldap1, then init ldap2 using data from ldap1, either through Console or through command (if using command, have to use db2ldif -r to dump data from ldap1 and use ldif2db to init ldap2).
    If anytime in your log, you see "different verison of data", try to init again.

  • Route or NAT problem?

    Hi Everyone,
    We have an ASA 5540 at our data center, with ASA 5505's at most remote sites.
    At the sites without layer 3 switches behind the ASA 5505's, we can't reach the data center internal network through the ASA for flow-export, etc.
    So, what I'm basically saying is, even though the tunnel is up and everything behind the branch ASA can reach the data center networks fine, the ASA itself cannot reach hosts on the data center network.
    I'm hoping to configure these ASA 5505's so I can do flow export and SNMP logging from them, but without this routing or nat problem resolved, they just won't do it.
    Doing a packet tracer from the ASA 5505 to the data center server I'm most focused on, reveals this:
    BRANCH5505f01# packet input inside icmp 10.15.16.1 8 0 10.1.1.15 detailed
    Phase: 1
    Type: ACCESS-LIST
    Subtype:
    Result: ALLOW
    Config:
    Implicit Rule
    Additional Information:
    Forward Flow based lookup yields rule:
    in  id=0xcb0b6698, priority=1, domain=permit, deny=false
            hits=1004755, user_data=0x0, cs_id=0x0, l3_type=0x8
            src mac=0000.0000.0000, mask=0000.0000.0000
            dst mac=0000.0000.0000, mask=0100.0000.0000
            input_ifc=inside, output_ifc=any
    Phase: 2
    Type: ROUTE-LOOKUP
    Subtype: input
    Result: ALLOW
    Config:
    Additional Information:
    in   10.1.1.15       255.255.255.255 outside
    Phase: 3
    Type: ROUTE-LOOKUP
    Subtype: input
    Result: ALLOW
    Config:
    Additional Information:
    in   0.0.0.0         0.0.0.0         outside
    Result:
    input-interface: inside
    input-status: up
    input-line-status: up
    output-interface: outside
    output-status: up
    output-line-status: up
    Action: drop
    Drop-reason: (rpf-violated) Reverse-path verify failed
    I am thinking the problem is NAT related, but with the new ASA NAT rule format due to v9.1... struggling to get a grip on where it is... any thoughts/help are appreciated.
    Ken
    Here is the relevant config for the Branch ASA and also the relevant config from the data center ASA:
    Branch ASA Config Parts:
    : Saved
    ASA Version 9.1(2)
    hostname BRANCHASA5505
    xlate per-session deny tcp any4 any4
    xlate per-session deny tcp any4 any6
    xlate per-session deny tcp any6 any4
    xlate per-session deny tcp any6 any6
    xlate per-session deny udp any4 any4 eq domain
    xlate per-session deny udp any4 any6 eq domain
    xlate per-session deny udp any6 any4 eq domain
    xlate per-session deny udp any6 any6 eq domain
    names
    interface Ethernet0/0
    switchport access vlan 2
    interface Ethernet0/1
    speed 100
    duplex full
    interface Ethernet0/2
    interface Ethernet0/3
    interface Ethernet0/4
    interface Ethernet0/5
    interface Ethernet0/6
    interface Ethernet0/7
    interface Vlan1
    description LAN_NETWORK
    nameif inside
    security-level 100
    ip address 10.15.6.1 255.255.254.0
    interface Vlan2
    nameif outside
    security-level 0
    ip address <outside ip> 255.255.255.248
    same-security-traffic permit inter-interface
    same-security-traffic permit intra-interface
    object network obj_any
    subnet 0.0.0.0 0.0.0.0
    object-group network BRANCH_NETWORKS
    description BRANCH LOCAL NETWORKS
    network-object 10.15.6.0 255.255.254.0
    object-group network LAN_NETWORKS
    network-object 10.0.0.0 255.0.0.0
    network-object 134.200.131.0 255.255.255.0
    network-object 134.200.220.0 255.255.255.0
    network-object 134.201.2.0 255.255.255.0
    network-object 163.243.195.0 255.255.255.0
    network-object 172.16.0.0 255.240.0.0
    network-object 192.168.0.0 255.255.0.0
    network-object 10.1.3.0 255.255.255.0
    network-object 10.31.2.0 255.255.255.0
    network-object 10.1.1.0 255.255.255.0
    network-object 172.26.1.0 255.255.255.0
    object-group network NETWORK_MGMT
    network-object 10.0.0.0 255.0.0.0
    access-list DATACENTER_VPN_ACL remark *******************************************************************
    access-list DATACENTER_VPN_ACL remark * FOR VPN CONNECTION TO DATACENTER/VEYANCE NETWORKS *
    access-list DATACENTER_VPN_ACL remark *******************************************************************
    access-list DATACENTER_VPN_ACL extended permit ip host <outside ip> host <outside ip datacenter asa>
    access-list DATACENTER_VPN_ACL extended permit ip object-group BRANCH_NETWORKS object-group LAN_NETWORKS
    access-list INSIDE_NONAT extended permit ip object-group BRANCH_NETWORKS object-group LAN_NETWORKS
    access-list INSIDE_FILTER extended permit tcp any4 any4 eq www
    access-list INSIDE_FILTER extended permit tcp any4 any4 eq 8080
    logging host inside 10.1.1.15
    flow-export destination inside 10.1.1.15 2055
    ip verify reverse-path interface inside
    ip verify reverse-path interface outside
    nat (inside,outside) source static LAN_NETWORKS LAN_NETWORKS destination static BRANCH_NETWORKS BRANCH_NETWORKS route-lookup
    nat (inside,outside) source static BRANCH_NETWORKS BRANCH_NETWORKS destination static NETWORK_MGMT NETWORK_MGMT route-lookup
    nat (inside,outside) source dynamic any interface
    object network obj_any
    nat (inside,outside) dynamic interface
    access-group FROM_OUTSIDE in interface outside
    route outside 0.0.0.0 0.0.0.0 <outside ip gateway> 1
    route outside 10.1.1.15 255.255.255.255 <outside ip datacenter asa> 1
    management-access inside
    threat-detection basic-threat
    threat-detection statistics access-list
    no threat-detection statistics tcp-intercept
    tunnel-group <outside ip datacenter asa> type ipsec-l2l
    tunnel-group <outside ip datacenter asa> ipsec-attributes
    ikev1 pre-shared-key *****
    class-map type regex match-any DomainBlockList
    match regex DomainList-Netflix
    class-map type inspect http match-all BlockDomainsClass
    match request header host regex class DomainBlockList
    class-map inspection_default
    match default-inspection-traffic
    class-map httptraffic
    match access-list INSIDE_FILTER
    policy-map type inspect dns preset_dns_map
    parameters
      message-length maximum client auto
      message-length maximum 512
    policy-map type inspect http http_inspection_policy
    parameters
      protocol-violation action log
    class BlockDomainsClass
      reset log
    policy-map URL-filter-policy
    class httptraffic
      inspect http http_inspection_policy
    policy-map global_policy
    class inspection_default
      inspect dns preset_dns_map
      inspect ftp
      inspect h323 h225
      inspect h323 ras
      inspect rsh
      inspect rtsp
      inspect esmtp
      inspect sqlnet
      inspect skinny
      inspect sunrpc
      inspect xdmcp
      inspect sip
      inspect netbios
      inspect tftp
      inspect ip-options
      inspect http
    class class-default
      flow-export event-type all destination 10.1.1.15
    service-policy URL-filter-policy interface inside
    prompt hostname context
    Datacenter ASA Config Parts:
    ASA Version 9.0(1)
    hostname DATACENTERASA5540
    xlate per-session deny tcp any4 any4
    xlate per-session deny tcp any4 any6
    xlate per-session deny tcp any6 any4
    xlate per-session deny tcp any6 any6
    xlate per-session deny udp any4 any4 eq domain
    xlate per-session deny udp any4 any6 eq domain
    xlate per-session deny udp any6 any4 eq domain
    xlate per-session deny udp any6 any6 eq domain
    xlate per-session deny tcp any4 any4
    xlate per-session deny tcp any4 any6
    xlate per-session deny tcp any6 any4
    xlate per-session deny tcp any6 any6
    xlate per-session deny udp any4 any4 eq domain
    xlate per-session deny udp any4 any6 eq domain
    xlate per-session deny udp any6 any4 eq domain
    xlate per-session deny udp any6 any6 eq domain
    names
    interface GigabitEthernet0/0
    description *** TO OUTSIDE NETWORK AT DATACENTER ***
    speed 100
    duplex full
    nameif OUTSIDE
    security-level 0
    ip address <outside ip>
    interface GigabitEthernet0/1
    description *** TO INSIDE NETWORK ***
    nameif INSIDE
    security-level 100
    ip address 10.1.3.2 255.255.255.0
    same-security-traffic permit inter-interface
    same-security-traffic permit intra-interface
    object-group network LAN_NETWORKS
    network-object 10.0.0.0 255.0.0.0
    network-object 134.200.131.0 255.255.255.0
    network-object 134.200.220.0 255.255.255.0
    network-object 134.201.2.0 255.255.255.0
    network-object 163.243.195.0 255.255.255.0
    network-object 172.16.0.0 255.240.0.0
    network-object 192.168.0.0 255.255.0.0
    network-object 10.1.3.0 255.255.255.0
    network-object 10.31.2.0 255.255.255.0
    network-object 10.1.1.0 255.255.255.0
    network-object 172.26.1.0 255.255.255.0
    object-group network DATACENTER_NETWORKS
    network-object 10.1.0.0 255.255.0.0
    object-group network BRANCH_NETWORKS
    network-object 10.15.6.0 255.255.254.0
    access-list BRANCH_VPN_ACL remark ****************************************************
    access-list BRANCH_VPN_ACL remark *  FOR SITE TO SITE VPN TO BRANCH WV USA  *
    access-list BRANCH_VPN_ACL remark ****************************************************
    access-list BRANCH_VPN_ACL extended permit ip host <outside ip> host <outside ip branch asa>
    access-list BRANCH_VPN_ACL extended permit ip object-group LAN_NETWORKS object-group BRANCH_NETWORKS
    flow-export destination INSIDE 10.1.1.15 2055
    flow-export template timeout-rate 1
    flow-export delay flow-create 180
    ip verify reverse-path interface OUTSIDE
    ip verify reverse-path interface INSIDE
    no failover
    nat (INSIDE,OUTSIDE) source static LAN_NETWORKS LAN_NETWORKS destination static BRANCH_NETWORKS BRANCH_NETWORKS route-lookup
    access-group FROM_OUTSIDE in interface OUTSIDE
    route OUTSIDE 0.0.0.0 0.0.0.0 <outside ip> 1
    route INSIDE 10.0.0.0 255.0.0.0 10.1.3.1 1
    route OUTSIDE 10.15.6.0 255.255.254.0 <outside ip branch asa> 1
    crypto map OUTSIDE-MAP 156 match address BRANCH_VPN_ACL
    crypto map OUTSIDE-MAP 156 set pfs
    crypto map OUTSIDE-MAP 156 set peer <outside ip branch asa>
    crypto map OUTSIDE-MAP 156 set ikev1 transform-set ESP-3DES-MD5 ESP-3DES-SHA
    tunnel-group <outside ip branch asa> type ipsec-l2l
    tunnel-group <outside ip branch asa> ipsec-attributes
    ikev1 pre-shared-key *****
    class-map inspection_default
    match default-inspection-traffic
    policy-map type inspect dns preset_dns_map
    parameters
      message-length maximum client auto
      message-length maximum 512
    policy-map global_policy
    class inspection_default
      inspect dns preset_dns_map
      inspect ftp
      inspect h323 h225
      inspect h323 ras
      inspect rsh
      inspect rtsp
      inspect esmtp
      inspect sqlnet
      inspect skinny
      inspect sunrpc
      inspect xdmcp
      inspect sip
      inspect netbios
      inspect tftp
      inspect ip-options
    class class-default
      flow-export event-type all destination 10.1.1.15
      user-statistics accounting
    service-policy global_policy global
    smtp-server 172.19.1.137
    prompt hostname context
    call-home reporting anonymous
    Again, any help you can provide is appreciated... will vote for best...

    I ran it, with the source IP corrected (it is 10.15.6.2):
    BRANCHASA# packet input inside icmp 10.15.6.2 8 0 10.1.1.15 detailed
    Phase: 1
    Type: ACCESS-LIST
    Subtype:
    Result: ALLOW
    Config:
    Implicit Rule
    Additional Information:
    Forward Flow based lookup yields rule:
    in  id=0xcb0b6698, priority=1, domain=permit, deny=false
            hits=1203279, user_data=0x0, cs_id=0x0, l3_type=0x8
            src mac=0000.0000.0000, mask=0000.0000.0000
            dst mac=0000.0000.0000, mask=0100.0000.0000
            input_ifc=inside, output_ifc=any
    Phase: 2
    Type: ROUTE-LOOKUP
    Subtype: input
    Result: ALLOW
    Config:
    Additional Information:
    in   0.0.0.0         0.0.0.0         outside
    Phase: 3
    Type: UN-NAT
    Subtype: static
    Result: ALLOW
    Config:
    nat (inside,outside) source static BRANCH_NETWORKS BRANCH_NETWORKS destination static NETWORK_MGMT NETWORK_MGMT route-lookup
    Additional Information:
    NAT divert to egress interface outside
    Untranslate 10.1.1.15/0 to 10.1.1.15/0
    Phase: 4
    Type: ROUTE-LOOKUP
    Subtype: input
    Result: ALLOW
    Config:
    Additional Information:
    in   10.15.6.0       255.255.254.0   inside
    Phase: 5
    Type: NAT
    Subtype:
    Result: ALLOW
    Config:
    nat (inside,outside) source static BRANCH_NETWORKS BRANCH_NETWORKS destination static NETWORK_MGMT NETWORK_MGMT route-lookup
    Additional Information:
    Static translate 10.15.6.2/0 to 10.15.6.2/0
    Forward Flow based lookup yields rule:
    in  id=0xcb12f2f0, priority=6, domain=nat, deny=false
            hits=15824, user_data=0xcb0fdef8, cs_id=0x0, flags=0x0, protocol=0
            src ip/id=10.15.6.0, mask=255.255.254.0, port=0, tag=0
            dst ip/id=10.0.0.0, mask=255.0.0.0, port=0, tag=0, dscp=0x0
            input_ifc=inside, output_ifc=outside
    Phase: 6
    Type: NAT
    Subtype: per-session
    Result: ALLOW
    Config:
    Additional Information:
    Forward Flow based lookup yields rule:
    in  id=0xcaa712e0, priority=0, domain=nat-per-session, deny=true
            hits=77610, user_data=0x0, cs_id=0x0, reverse, use_real_addr, flags=0x0, protocol=0
            src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0
            dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0, dscp=0x0
            input_ifc=any, output_ifc=any
    Phase: 7
    Type: IP-OPTIONS
    Subtype:
    Result: ALLOW
    Config:
    Additional Information:
    Forward Flow based lookup yields rule:
    in  id=0xcb0bc128, priority=0, domain=inspect-ip-options, deny=true
            hits=91404, user_data=0x0, cs_id=0x0, reverse, flags=0x0, protocol=0
            src ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0
            dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=0, dscp=0x0
            input_ifc=inside, output_ifc=any
    Phase: 8
    Type: INSPECT
    Subtype: np-inspect
    Result: ALLOW
    Config:
    Additional Information:
    Forward Flow based lookup yields rule:
    in  id=0xcb0bbc28, priority=66, domain=inspect-icmp-error, deny=false
            hits=4585, user_data=0xcb0bb238, cs_id=0x0, use_real_addr, flags=0x0, protocol=1
            src ip/id=0.0.0.0, mask=0.0.0.0, icmp-type=0, tag=0
            dst ip/id=0.0.0.0, mask=0.0.0.0, icmp-code=0, tag=0, dscp=0x0
            input_ifc=inside, output_ifc=any
    Phase: 9
    Type: VPN
    Subtype: encrypt
    Result: ALLOW
    Config:
    Additional Information:
    Forward Flow based lookup yields rule:
    out id=0xcb0c1218, priority=70, domain=encrypt, deny=false
            hits=708, user_data=0xbf63c, cs_id=0xcb9ad918, reverse, flags=0x0, protocol=0
            src ip/id=10.15.6.0, mask=255.255.254.0, port=0, tag=0
            dst ip/id=10.0.0.0, mask=255.0.0.0, port=0, tag=0, dscp=0x0
            input_ifc=any, output_ifc=outside
    Phase: 10
    Type: NAT
    Subtype: rpf-check
    Result: ALLOW
    Config:
    nat (inside,outside) source static BRANCH_NETWORKS BRANCH_NETWORKS destination static NETWORK_MGMT NETWORK_MGMT route-lookup
    Additional Information:
    Forward Flow based lookup yields rule:
    out id=0xcb12fb00, priority=6, domain=nat-reverse, deny=false
            hits=15837, user_data=0xcb124438, cs_id=0x0, use_real_addr, flags=0x0, protocol=0
            src ip/id=10.15.6.0, mask=255.255.254.0, port=0, tag=0
            dst ip/id=10.0.0.0, mask=255.0.0.0, port=0, tag=0, dscp=0x0
            input_ifc=inside, output_ifc=outside
    Phase: 11
    Type: FLOW-CREATION
    Subtype:
    Result: ALLOW
    Config:
    Additional Information:
    New flow created with id 143081, packet dispatched to next module
    Module information for forward flow ...
    snp_fp_tracer_drop
    snp_fp_inspect_ip_options
    snp_fp_translate
    snp_fp_adjacency
    snp_fp_encrypt
    snp_fp_fragment
    snp_ifc_stat
    Module information for reverse flow ...
    Result:
    input-interface: inside
    input-status: up
    input-line-status: up
    output-interface: outside
    output-status: up
    output-line-status: up
    Action: allow

  • RG54G2 Wireless Router Internet Connection Problem

    Hi,
    (apologies for the long message - trying to cover all details - summary: wireless router often drops internet connection)
    I recently bought an RG54G2 Wireless Router, a CB54G2 PCMCIA Wireless card and a D-Link GWL-630 PCMCIA Wireless card.  In addition to two laptops connected to the wireless router WLAN, I have two PCs (one Win WP Pro SP 1 and one Win98SE) connected to the router via wired LAN.  I also have a SurfBoard SB3100 Cable Modem connected to the WAN port (this connects to my ISP -  Optusnet (Australia) via DHCP).
    The problem I have is that the internet connection is disconnected many times a day (often every few minutes, sometimes an hour or so).  I am able to reconnect by resetting the wireless router via the wireless router configuration page.  When the internet is disconnected I am still able to access the computers on the LAN/WLAN (via Windows Explorer and Ping), I am also able to ping the router and the Cable Modem, but nothing outside of the cable modem.
    Also, when the internet is disconnected the System Status page indicates that the router is still connected to the internet, and the Diagnostics page passes the Test Connection test, though no external pings work.
    I did not have this problem when the cable modem was connected directly to the Win98SE PC (and other PCs via ICS).
    I have disabled the WLAN and the problem still exists with only the wired LAN.
    I have changed numerous settings in the wireless router config page with no success (eg disabling DHCP and setting each IP address, minimising LAN and WLAN speeds to 10 and 11MBps plus others).
    I have upgraded the wireless router firmware to R1.0.6.0 (no change to the problem).
    Searching on Google I have found several other cases of routers with unstable internet connections (none refering to the MSI routers), but none had solutions that helped my situation (most replies suggested updating the firmware).
    Any suggestions of how to make the router internet connection stable?
    Thanks,
    Mike

    maybe this is the FIX 4 wireles router internet connection problem
    please let me know if any one fix the problem with this tips
    thankz
    M. B.      Feb 6 2004, 8:20 am     hide options
    Newsgroups: comp.os.ms-windows.networking.windows
    From: "M. B." - Find messages by this author
    Date: Fri, 06 Feb 2004 16:20:48 GMT
    Local: Fri, Feb 6 2004 8:20 am
    Subject: SOLUTION to my router loosing connection to Windows XP
    Reply | Reply to Author | Forward | Print | Individual Message | Show original | Report Abuse
    I am happy to report that after 8 days of constant battles, reboots, phone
    calls, cable pulling, router changing, it seems that I finally have found a
    combination that has had me using Verizon DSL account for over 12 hours so
    far without any kind of interruptions.
    Since so many of you tried giving me comments and suggestions, I felt that
    it is necessary for me to post this here so that the next person will not
    (hopefully) need to go through this hell as I did!
    My original problem was that when after I purchased a D-Link Wireless Router
    DI-624, I would get disconnected from Verizon DSL at least once every 2
    hours or so. My internet access would "freeze" and then a little popup box
    at the bottom right system tray would tell me that the "LAN cable has been
    unplugged".   After about a minute or so, my internet connection would be
    back working   This was NEVER happening during the 2+ years I was using my
    Westell modem alone (running in router mode).
    Please keep in mind: The problem I was having was not wireless related as
    it was happening to the desktop computer to which the router/westell was
    connected to!
    During these last 8 days, I tried: one DI-624 wireless router, two Netgear
    614v3 routers and two Linksys WRT54G v.2 routers. In addition, I received a
    brand new Westell 2200 modem from Verizon.   I also tried about four
    different CAT-5 cables. Here is the final outcome:
    I have the Linksys WRT54G (version 2) wireless router connected to the
    Netgear Fast Ethernet FA310TX network card in Auto-Sense mode (using the
    built-in XP drivers, as Netgear told me that there was never a newer
    revision released). I have DISABLED the built-in 3Com Gigabit LOM (3C940)
    network card (via the ASUS P4C800 Deluxe motherboard BIOS), DISABLED the
    Zero Wireless Configuration service, and have put in the IP/Gateway/DNS
    address numbers inside my Windows XP Network Connections | LAN setup. My
    operating system is Windows XP Pro SP1 and the modem is a Westell 2200
    configured as bridge only.
    If my situation continues to be stable, I *might* try to go back to the 3Com
    built-in card (disable any power management) and then re-enabling the Zero
    Wireless Configuration services. But in reality, I am happy with the way
    things are and have already spent enough time trying to get my router to
    work with Verizon DSL without having it drop connections!
    Now, the next step will be setting up the WIRELESS part of this. I don't
    even yet have a laptop with me on the premises, but the 802.11g card that I
    already have is the D-Link DWL-G650. I hope and assume that this will work
    okay with the Linksys...
    One thing I must say is that I never realized that how many problems other
    users are having. I would have thought that since 802.11x has been around
    in the mainstream by now 2+ years, that things would have been much more
    "system friendlier".   And again, my issues were not even WIRELESS related.
    All 3 tech supports were not really helpful, as none of them realized that
    the problem is somehow between the router and Windows XP (Ethernet card?)
    loosing a connection, which of course results in Verizon DSL loosing the
    connection also.
    One other comment about the Netgear 614 v.3 router: A number of people have
    responded to tell me that they have had this random "router resetting"
    happen to them (where the routers behaves as if someone turned the power off
    and then back on, and the lights flash) just as if you first turn it on). I
    was lucky to witness it myself during one of the "disconnects" that I had.
    This was actually the reason why I went back to try the Linksys one more
    time. So, I would definitely recommend staying way from this 614 (version
    3) model.
    Once again - THANK YOU everyone!

  • CS4 Master Collection - Problem occurred while extracting...

    After spending $1,500 and two days of RL time downloading the CS4 Master Collection twice, I am just a tad frustrated.
    Each time I download the CS4 suite file and try to install it, I immediately get the error:
    "A problem occurred while extracting the archive. Please try downloading the Adobe CS4 Master Collection again."
    No. I refuse to spend another full day downloading this file yet again just to receive the same error.
    Anyone have some insight into this problem? (more so than "turn off your anti-virus program"
    Thanks in advance.

    I am having the same problem. I found a forum that suggested this. Apparently it worked for some people, but not for me. Let me know if it does:
    1. Start -> All Programs -> Accessories
    2. Right-click on Command Prompt and select "Run as..."
    3. Run as Administrator (even if you are logged in as Admin. You need to run in the Black Command Prompt, not the White one)
    4. Run: regsvr32 JScript.DLL
    5. Then run: regsvr32 vbscript.DLL
    (dont forget the spaces, or it won't work)
    6. Then try running the set up again
    As i said, it worked for some on the forum, but not others (like me). Try it and see if works for you

  • CS4 Master Collection - Problem Applying Updates

    Hi
    I'm running the CS4 Master Collection on Windows Vista Ultimate 32-bit, SP2.
    Normally I have no problem applying updates to the various Adobe components when they become available, however for a while now I've been unable to instal an update that's reported as being available for Adobe Media Encoder 4.1.0.
    If I run the "check for updates" manually I can download the update (reported as being 63.7MB) and when I attempt to instal it the installation process appears to run. It finishes after a while and the Adobe Updater reports "The Udating Process is Finished" in a single dialog box with a single button entitled "Quit" - which seems odd as "Quit" implies "finish earlier than planned", I'd have expected something more in line with "All done", something like "OK".
    Anyway, when I run the check for updates again I'm told about the same update implying that it wasn't applied successfully.
    I get this behaviour whether I run the update as an Administrator or not (all other updates for other products are applied without problem). I also get it regardless of whether or not I reboot the machine after trying to apply the update.
    Does anyone have any suggestions on what could be causing the problem ? I couldn't find anything obvious or obviously relevant in any of the Windows event logs on the PC.
    Thanks for any ideas
    Steve

    I am having the same problem. I found a forum that suggested this. Apparently it worked for some people, but not for me. Let me know if it does:
    1. Start -> All Programs -> Accessories
    2. Right-click on Command Prompt and select "Run as..."
    3. Run as Administrator (even if you are logged in as Admin. You need to run in the Black Command Prompt, not the White one)
    4. Run: regsvr32 JScript.DLL
    5. Then run: regsvr32 vbscript.DLL
    (dont forget the spaces, or it won't work)
    6. Then try running the set up again
    As i said, it worked for some on the forum, but not others (like me). Try it and see if works for you

Maybe you are looking for

  • Since updating to iOS7 I am unable to send or receive messages on my iPad. What can I do to solve this problem?

    Since updating my iPad mini I have been unable to send or receive messages. My iPad only wants to recognize contacts with apple products but still won't deliver a message to them. What can I do to solve this problem?

  • How to import images in iPhoto?

    I use iPhoto importing images from this same computer and from iPhone with iCloud. A problem I've always suffered also before buying iPhone was that I can't import images in iPhoto. Well, I can drag an image from, for example, the desktop, but if I d

  • Real time queries to know more about live project

    Hi All, I am new to XI, I have some doubts about real time xi project related activities. 1.  Who will be responsible for preparing the minutes of meeting? (XI Developer/Team Lead/senior consultant etc…) 2    In usual Dev->QA->Prod project cycle...  

  • Applying PSU 2 to OMS causes service to be unavailable.

    Repository Database Oracle 11.2.0.3 OMS 12.1.0.2.0 Agent(s) 12.1.0.2.0 Grid Infrastructure 11.2.0.3 Our goal is to patch Enterprise Manager 12C R2 with the latest PSUs and patches so that we can being using it in ernest, tackling one problem at a tim

  • Subtracting numerical fields in form fields

    I am looking for a way to subtract a numerical field in one field from the other.  On the form field, when calculate tab is chosen, there is no drop down for the (-) side of the equation. Is there a way to do a simple Javascript code to do this task?