DC and ADC Synchronization through ASA 5580

Hi , I have a Windows 2008 server acing as DC connected to one of the interface of ASA 5580, and have couple of ADC in the branches which are connected to different interfaces of ASA.  The routing is happening through the ASA. When trying to do DCPROMO on the ADC it’s giving an error.  Natting is not there in the ASA and I have access-list configured for “Permit IP Any any ” for all interface.  Any clue wht could be the problem ?

1) Please check the syslog to see if it's being blocked by the firewall.
2) Run packet capture on both interfaces with ACL just between the DC and ADC:
access-list cap-test permit ip host host
access-list cap-test permit ip host host
capture cap-DC access-list cap-test interface
capture cap-ADC access-list cap-test interface
Try the "DCPROMO", and check the packet capture to see where it is breaking.

Similar Messages

  • Synchroniz​ation between DAC and ADC on NI 4451

    I need for my DAC and ADC software buffers to line up with each other in analog time.
    I'm using the following code to start the DAC and ADC conversions:
    status = WFM_Group_Control (deviceNumber, group, START);
    if (status==0)
    status = SCAN_Start (deviceNumber, (short *)ADCbinArray, total_samples*SENSOR_CHANNELS, sampTimebase, sampInterval, scanTimebase, scanInterval);
    But I end up with a 70-75 millisecond delay between the DAC start and the ADC start. I need synchronization to at least a few hundred microseconds between the DAC and ADC buffers.

    One clarification point is needed her. Yes, it is true that both the Analog Input and Analog Output of the 4451 use the same clock source. However, the way you currently have the start of these operations is to start each one separately through a software call. This is why you are not about to get better than millisecond resolution.
    You can achieve hardware-timed synchronization of your input and output operations using RTSI to share a hardware start trigger for both the input and output. The idea is that you will route the start trigger of one operation to a RTSI line. Then tell the other operation to use the same RTSI line as its start trigger.
    Even thought the RTSI bus is used to pass this signal from the AI circuitry to the AO trigger, there
    is no need to connect a RTSI cable. In DSA devices, the analog input and output are automatically phase locked. There will be no phase drift between the input and output sample clocks, and minimal phase difference if they are running at the same rate.

  • Hi...i bought the new iphone 4 and would like to ask how can i transfer all my data from my old iphone to the new one?  If I will do "synchronization" through itunes with the old phone and the plug in the new one will that be the case?

    Hi...i bought the new iphone 4 and would like to ask how can i transfer all my data from my old iphone to the new one?  If I will do "synchronization" through itunes with the old phone and the plug in the new one will that be the case?

    Follow the instructions in this article to transfer your info: iPhone: Transferring information from your current iPhone to a new iPhone

  • IP Phone SSL VPN through ASA

    Im in the middle of configuring Ip Phone SSL VPN through ASA, got stuck on authentication.. When I enter username and password on the phone screen, i get "Username and password failed" message on the screen. However, in ASA logs I see the following line
    Feb 16 2011    15:12:57    725002    85.132.43.67    52684            Device completed SSL handshake with client vpn:85.132.*.*/52684
    Feb 16 2011    15:17:26    725007    85.132.43.67    52745            SSL session with client vpn:85.132.*.*/52745 terminated.
    What does it mean?  How can I turn on debugging to see what is going on?
    Thank you in advance!

    Hi,
    If you're not using certificates in client authentication then the SSL handshake will complete before the user is requested to authenticate with username/password.  If this authentication request fails you will see the SSL session terminated immediately following this failure (as in the logs you provided).  Notice the 5 seconds between the SSL session establishment and termination, this is most likely when the user is being authenticated against the aaa server.  If the phone is failing authentication against an external aaa-server you'll want to investigate the logs on that server to determine the root cause of the failure.  The ASA can also provide confirmation of the authentication request/reject with the command 'show aaa-server'.  If you want to see what's going on at an authentication protocol level you can enable several debugs including "debug aaa authentication|common|internal' and protocol specific debugs such as 'debug radius user|session|all' or 'debug ldap'.
    Did this answer your question? If so, please mark it Answered!

  • DfltCustomization File is missing in Cisco ASA 5580

    I wanted to perform the customization of the SSL WebVPN page. But When I tried to create a new Customization object is is not happening as the
    DfltCustomization object is not available.
    We are having so many webvpn configuration and objects that i cant issue "revert webvpn all" command.
    Can I able to import the File from any location or anyone can provide me the default customization object file so the I can export it into the ASA and create new custmixed object accordingly.
    Or what other steps I can take to have customization happening in my Cisco ASA 5580. 8.2 (5) and ASDM 6.4.
    With Regards,
    Faizul

    Hi Faizul,
    I am including the DfltCustomization file, which has been exported from an active ASA.
    Please try to upload it and let me know.
    Portu.
    Please rate any posts you find helpful.

  • Where can I find the CRIO-9102 Calibration and ADC to Voltage Conversion VIs ?

    I am working through the "Developing High Speed Continuous Buffered Data Acquistion Applications with CompactRIO" tutorial located at http://zone.ni.com/devzone/cda/tut/p/is/3268  I am using a CRIO-9201 analog input module instead of the cRIO-9215 shown in the tutorial.
    I would greatly appreciate help with the following:
    Where can I find the cRIO-9102 calibration and ADC to Voltage conversion VIs?
    Thanks

    Thank you for correcting the link to the tutorial. For the sake of clarification here are my questions. I am fairly new to LabVIEW and very new to the cRIO platform:
    1. Are the calibration VIs for specific modules available as part of LabVIEW or do I have to create my own using the property nodes for the module.
    As I worked through the tutorial I modified the calibration VI for the cRIO-9215 as necessary so that it would work with the cRIO-9201 module that I am using.
    2. I am assuming that the "Convert to Voltage (cRIO-9125).vi" shown in the tutorial will work correctly with the cRIO-9201 since I am passing cRIO-9201 calibration data to it.  Is this correct?
    Thanks
    Thanks

  • ASA 5580-20 Security Contexts

    Hi,
       How many Contexts can a Cisco ASA 5580-20 provide. I have seen that ir is upto 250. Can someone confirm that.
    Please do tell me about the licensing part for the same. How many of then come as default with the box and what is the license conditions/specifications for additional contexts. Is it one extra license for every context.
    Rgds
    Rajesh

    Hi Rajesh,
    Please refer to this URl Link:-
    http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/license/license82.html
    Security Contexts
    2
    Optional licenses:
    5
    10
    20
    50
    Let me know if this answers your query.
    Thanks and Regards,
    Vibhor

  • GRE tunnel through asa no pptp, l2tp, ipsec

    Hello!
    can't understand how to configure GRE tunnel through ASA
    i have one router with public ip, connected to internet
    ASA 8.4 with public ip connected to internet
    router with private ip behind ASA.
    have only one public ip on ASA with /30 mask
    have no crypto
    have network behind ASA and PAT for internet users.
    can't nat GRE? cause only TCP/UDP nated(?)
    with packet-tracer i see flow already created but tunnel doesn't work

    A "clean" way would be to use a protocol that can be PATted. That could be GRE over IPSec. With that you have the additional benefit that your communication is protected through the internet.
    Don't stop after you've improved your network! Improve the world by lending money to the working poor:
    http://www.kiva.org/invitedby/karsteni

  • ASA 5580 with EtherChannel 20Gbs, Does the Failover link must match the same Speed?

    Hello,
    I have an ASA 5580, I am plannning on setting two EtherChannels (inside and outside), each channel will include two TenGigabit interfaces.
    My questions is that if the links that I am gonig to use for the failover and link, should also be 20Gbs each, or it is ok to use 10Gbs for each link?
    According to the Configuration guide 8.4
    Use the following failover interface speed guidelines for the ASAs:
    • Cisco ASA 5510
    – Stateful link speed can be 100 Mbps, even though the data interface can operate at 1 Gigabit due
    to the CPU speed limitation.
    • Cisco ASA 5520/5540/5550
    – Stateful link speed should match the fastest data link.
    • Cisco ASA 5580/5585
    – Use only non-management 1 Gigabit ports for the stateful link because management ports have
    lower performance and cannot meet the performance requirement for Stateful Failover.
    Thanks in advance

    Hi,
    I have 2x ASA5580-20 with 8x1GE interfaces and additional 2x 10GE interfaces each. Software version running is v8.4.4.1.
    I am planning to use them in multiple context (active/active) transparent mode. Taking into account the FW performance of 5Gbps real-world traffic per ASA5580-20, which on the following interface configurations would make the most sense?
    Option 1:
    2x10GE = 20GE Etherchannel for Data
    1x1GE LAN Failover
    1x1GE STATE Failover
    Option 2:
    1x 10GE Data
    1x 10GE LAN & STATE Failover
    Option 3:
    2x10GE = 20GE Etherchannel for Data
    4x1GE = 4GE Etherchannel for LAN/STATE Failover (possibly up to 8x1GE)
    (etherchannel for LAN/STATE Failover actually does not make much sense, since only one interface wll be used anyway)
    Option 4:
    1x10GE LAN & STATE Failover
    8x1GE = 8 GE Etherchannel for Data
    I have read several guides (e.g. link1, link2, link3). Some state that 1GE Failover interfaces would suffice for the ASA5580, others recommend a link as fast as the data link. Almost none of them account for higher bandwidth etherchannels.
    What is recommended in this case? Both Firewalls will be connected to one VSS Switch Pair, so it would make sense to cross-connect with at least 2 links on each VSS member.
    The ASA does not support connecting an EtherChannel to a switch stack. If the ASA EtherChannel is connected cross stack, and if the Master switch is powered down, then the EtherChannel connected to the remaining switch will not come up. (http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/interface_start.html)
    Thanks in advance for your feedback!

  • Asa 5580 storage

    Hey all, are the hard drive bays on the front of ASA 5580s usable? I'm not finding any documentation regarding those bays and like the idea of using it for local log storage rather than storing logs on the 1gig of flash. We've been hitting limits on the number of logs our syslog server can process from these firewalls and I was thinking of sending all the logs to local disk (if possible) them moving them off to another server every 8-12 hours. 

    I do not believe that this is possible.  When logging to flash you only have the option to log to the internal flash, disk0 by default. All other disks which you insert into the ASA will be defined as external flash.
    However you can tell the ASA that when the buffer is almost full and about to "wrap around" itself (ie. overwrite existing logs) to send the logs to a syslog server.  Something like this:
    The following commands tells the ASA to save logs to the buffer until it is full and then send it to an FTP server.  The /Syslogs specifies the directory path on the FTP server followed by the username and password for the FTP server.
    logging flash-bufferwrap
    logging ftp-server 10.1.1.1 /Syslogs FTPadminUsername FTPadminPassword
    Please remember to select a correct answer and rate helpful posts

  • Tracing a route passing through ASA

    Hi Everyone,
    Need help on tracing a route IP 192.168.27.0  that is passing through ASA
    i did sh route on ASA
    S    192.168.27.0 255.255.255.0 [1/0] via 192.168.101.14, Xnet
    so this means that this ASA is learning this route statically through int Xnet  right ?
    when i do sh int on ASA  it shows Xnet as interface.
    what should be my next step?
    also i am able to ping this IP from ASA  but whne i do sh arp it does not show this IP 192.168.27.251 and mac address
    Thanks
    Mahesh
    Message was edited by: mahesh parmar

    So I presume you have ASA5550 or you have bought addiotional 4 GigabitEthernet module.
    When you look at the ASA from the side where the physical ports are
    The usual ports (without the module) should be in the Right side
    The modules ports should be on the Left side
    The module should contain 8 ports
    4 Ports are for SFP slots (usually for fiber connections)
    4 Ports are for basic Ethernet connectivity
    The configuration should have some line "media-type" which defines which type is used "rj45" of "sfp"
    rj45 for Ethernet
    sfp for SFP module
    So GigabitEthernet 1/2 port should be to my understanding either the Third Ethernet or Third SFP port of the module depending on the above port configuration mentioned (media-type rj45/sfp)
    The ports GigabitEthernet0/0 - x are the ports that are in every ASA, Ports GigabitEthernet1/0 - x are the expansion modules ports
    Hope this helps. Hopefully I remembered that right.
    - Jouni

  • The difference between VGA, DVI-D and ADC?

    Hi.
    The difference between VGA, DVI-D and ADC and which should be used with a T244 widescreen monitor into a Quicksilver G4 with a GeForce2 MX nVIDIA (0x10de) card. What's a good upgrade card if the above is not good enough?
    Thank you for your input.
    Walter

    Look at this link http://en.wikipedia.org/wiki/DigitalVisualInterface
     Cheers, Tom

  • My apple ID and password, recognized through out the Cloud, is not being recognized in the itunes store. I am signed into itunes.When I want to change something in my account, the sign in prompt comes up and doesn't recognize my PW

    My apple ID and password, recognized through out the Cloud, is not being recognized in the itunes store. I am signed into itunes.When I want to change something in my account, the sign in prompt comes up and doesn't recognize my PW

    Solved the problem. I had to allow cookies for safari and it run - as here: Re: itunes keeps asking for my apple id password. it's NOT entered incorrectly.

  • I have tried loading 3 different cds that I just bought into Itunes and I click the import cd button and it goes through the motions of importing the cds, but when I go to my library none of these cds is there.  Help, please!

    I have tried loading 3 different cds that I recently purchased into Itunes.  I click the import cd button and Itunes goes through the motion of copying and importing the cds, but the songs are not in my music library.  I have searched everywhere to find where these cds might be, but to no avail.  Could really use some help here.  Never used to have this problem.

    Are they in the relevant artist & album folders when you look via Windows Explorer. If so something may have gone wrong with the index of the Music playlist. Download the current iTunes Free Single of the Week. I know it sounds odd, but it should fix the problem.
    If that doesn't work close iTunes and delete the hidden file sentinel from inside the main iTunes folder, then start iTunes again. It should run a consistency check when it starts up.
    tt2

  • Can I use the new Time Capsule to backup my mid 2010 Macbook Pro? Also can I want to free up my hard disk, can I save my photos and files on the time capsule and later access through wifi?

    Can I use the new Time Capsule to backup my mid 2010 Macbook Pro? Also can I want to free up my hard disk, can I save my photos and files on the time capsule and later access through wifi?

    Can I use the new Time Capsule to backup my mid 2010 Macbook Pro?
    Yes, if you are asking about using Time Machine to backup the Mac.
    Also can I want to free up my hard disk, can I save my photos and files on the time capsule and later access through wifi?
    You are not thinking of deleting the photos and files on your Mac, are you?  If you do this, you will have no backups for those files.
    Another concern is that Time Machine backs up the changes on your Mac. At some point, Time Machine will automatically delete the photos and files from the Time Capsule.....you just don't know when this might occur.
    In other words, only delete files from your Mac that you can afford to lose.

Maybe you are looking for

  • Extracting data into two ODS at same time

    Hi experts, I am on BW 3.5, and was wondering if the possible scenario is possible; We are extracting 6.5 million recs from our R/3 system into ODS 1. But the records should split up and either go into ODS 1 or ODS 2 depending on its company code. I

  • Help with a program i'm writing

    I'm trying to write a program for a golf leader board. It currently accepts player names from an input file, and puts them inot an array. it also does the same thing with the hole details. The players are sorted into pairs. I can add scores to each p

  • 911 coming from main number instead of individual user DID

    We are moving all of our numbers to a SIP provider and need to make sure that when someone dials 911 that it comes from the "main" number of the facility instead of the individual users phone number. Is it possible to setup lync to operate this way,

  • How do I return to the previous version of Java?

    After the latest Apple Update I have After the latest Apple-Update, I use Java 6 Update 24 for Mac OS X 10.6. If I try to upload the files in Safari and clicking the button for the upload, the window don't open to select the files. If I try the same

  • Appying a general severity to a server or group of servers

    Hi All, We have recently begun to deploy scom 2012 within our company and we are currently building out our system. Basically, in our organisation, we have servers that are critical to production, and some that are not, depending on which goes down o