Getting most benefits of your LAN network

Thanks to take time to read this post.
I'm a *regular Mac user* who work on a small business and we using 8 mac vs 2 PC on our next work, recently i setup a mac (the holdes one in the place, a hold G4), as a "server". In fact, it is just a computer with standard *OS 10.5.X (not the server edition).* We use it *to share files* on a shared folder so avery body connect as guest and they drop files into the folder for other people. I also use it to create a *intranet site* where i can create HTML pages to display paste projets and internet links. I also create a *HTTPS file sharing* over the internet site (using CrushFTP) for transferring big files with clients, i use HTTPS becose i heard that is more secure than a FTP site. And finilly whe put lots of external hardrive on this mac and we *backup files* using Time Machine for people with Macbook, so they can backup wirelesly without aving to connect any hard drive to there Macbook.
So, *avery thing work fine but...* (becose there a but) I would like to get a little more of this setup.
1- I would like to be able to *connect to the LAN network over the internet* so any body at home can connect to there Mac at office. For the momment, with the HTTPS site we can only connect to the server. How can i setup de "Server" or the rooter to be able to connect to any mac in the network.
2- All the mac in the network use manuel IP adresse, i meen that the DHCP is close in the netwook. I did that becose it whase easier to create applescript apps to automate things, but *is that secure to have stable adresse* for all the mac if the LAN is accessible on the internet.
3- *What about security* wath do i have to do to make those new setup secure, so nobody get abuse by hakers or any other abusewares?
4- For the moment, the intranet web site is a standard first generation HTTP site without any interraction possible. If someone wan to add info there, he have to transfert my the stuf and i edit the html files with dreamweaver. I would like to give the possibility to all the workers to *edit html like the next generation of web site*, where i have to look for that, do i nead OS X Server? Is there a software to create site like this, like CrushFTP do, for the FTP site? I try to read on that but it's vary confusing. For exemple there a page on the intranet that show internet links for web site in relation to a projet, i would like to put a button so if you want to add a next like you just press in and copy the web adress and press ok to redefind the web page.
5- That's about it for the moment, i would like the create with this post a : *How to get most of your Mac office network for Dummies*, for people that like mac put dont studing in cumputer networking or things like that.
Hope to have lost of posts, and i hope to help other with that
Message was edited by: rewq

rewq wrote:
1- I would like to be able to *connect to the LAN network over the internet* so any body at home can connect to there Mac at office. For the momment, with the HTTPS site we can only connect to the server. How can i setup de "Server" or the rooter to be able to connect to any mac in the network.
You need to setup routes between ports on the external IP address and addresses/ports on the internal LAN. I haven't done this in about 8 years so I can't tell you how. I would just recommend you get a tool like IPNetRouter to do it for you. Just setup a unique external port/internal address/port for each machine. If your server is directly connected, you can do it there. If you have some sort of router, add your routes on that device.
Also, you haven't specified how you want to connect to the internal machines. You will have to decide that. You can route anything you want, but you need to know and plan for it.
2- All the mac in the network use manuel IP adresse, i meen that the DHCP is close in the netwook. I did that becose it whase easier to create applescript apps to automate things, but *is that secure to have stable adresse* for all the mac if the LAN is accessible on the internet.
That is fine. It will make establishing external connections easier.
3- *What about security* wath do i have to do to make those new setup secure, so nobody get abuse by hakers or any other abusewares?
You have Macs, so that is a good start. Just be sure to limit any routes that are visible to the outside world. Hackers will be able to get it and you will have to stop them on the client side.
Or, if you have more money and/or time, you could setup a VPN.
4- For the moment, the intranet web site is a standard first generation HTTP site without any interraction possible. If someone wan to add info there, he have to transfert my the stuf and i edit the html files with dreamweaver. I would like to give the possibility to all the workers to *edit html like the next generation of web site*, where i have to look for that, do i nead OS X Server? Is there a software to create site like this, like CrushFTP do, for the FTP site? I try to read on that but it's vary confusing. For exemple there a page on the intranet that show internet links for web site in relation to a projet, i would like to put a button so if you want to add a next like you just press in and copy the web adress and press ok to redefind the web page.
That is pretty open-ended. There are lots of ways you could do this: Content Management systems, configuration management systems (CVS), or dozens of other tools.

Similar Messages

  • Keep getting message "none of your preferred networks are available"

    Whenever I start mny iMac running 10.6.3 I keep getting the message ""none of your preferred networks are available" and my wifi won;'t connect. This never happened before yesterday. Help! What do I do?

    OK, well let's start. First thing to try is a SMC Reset Please read the instructions carefully as they cover multiple models of Mac's you want to use the one for Intel iMacs.
    After you done your SMC reset please report what happened.

  • None of your preferred networks available

    We have two MBP that were upgraded to Lion and worked well with our previous router.  Since changing over to the Time Capsule both MBPs get the "none of your preferred networks are available" popup when waking from sleep mode.  After searching for an answer I cannot find a good explanaton.  Not sure if this is just a problem with the router change or Lion since people have posted having the problem with using the same router they had before upgrading to Lion.  Any help would be appreciated.

    I just got off the phone with Apple support and the fix he walked me thru has worked.
    Go to Airport Utility and click on manual setup at the bottom of the window.  Go to wireless tab and select radio channel selection...change 5GHz to 161 and 2.4GHz to 9.  Click update.
    Open network preferences and click advanced.  Highlight and delete all items that appear in preferred networks (use the minus button).  Click ok (think apply comes up as well).
    Spotlight search for "keychain".  Click on "keychain access".  Delete the instances of your network name by highlighting and using the delete key.  Close and apply if asked.
    Turn Airport off then back on.  Click to join your network and enter password.  Turn Airport off and back on (at this point it auto connected).  Restart computer and make sure it auto connects.  Put to sleep and wake back up to make sure it connects.
    These steps worked for me...not sure if it was a time capsule specific issue, but figured these steps seemed pretty universal since I changed no time capsule setting.

  • How do you know if someone else is attempting access to your wireless network? (WRT54G)

    I searched adn tried the Linksys FAQ to no avail to get an answer to the subject question.
    Is there any way to verify who is actually using or trying to attempt use of your wireless network, if so, where do I locate and view this information?
    I just set up a wireless system so my wife could get access from her wireless equipped laptop, but I really see no area to verify who is actually using the wireless network or if some other outside source/person is attempting to get access.
    Any info on where, how and what to do to view this type of info would be greatly appreciated and if it can't be, shouldn't there be something added to the system that would allow one to view all users accessing their wireless system?
    Thank you,
    Clay Fugitte

    Tracking down who is using your wireless system is usually difficult or impossible.  The router only knows the MAC address of the connecting computer.  MAC addresses can be faked.  Even if you knew the MAC address of the person connecting, what can you do with that info?  Go around the neighborhood asking people "Is this your MAC address?"
    Instead of worrying about who is connecting to your wireless, you should simply set up wireless security.  This will keep intruders off your wireless network.  Then you don't need to worry about who is connecting.
    It sounds like you are running an unsecured wireless router.  When you run an unsecured wireless router, anyone within range can login and use your Internet connection. At a minumum, this means that they will be using your bandwidth. At worst, they could be uploading copyrighted music, sending spam email, distributing viruses, or downloading child pornography --- all from an account with your name on it!   So my advice is --- secure your wireless network.
    To set up wireless security, do the following:
    First of all, to setup wireless security,  you must use a computer that is wired to the router.
    Where to find the router settings: The router's login password is usually on one of the "Administration" pages. The other settings are all found in the "Wireless" section of the router's setup pages, located at 192.168.1.1
    First, give your router a unique SSID. Don't use "linksys".
    Make sure "SSID Broadcast" is set to "enabled".
    Next, leave the router at its default settings (except for the unique SSID), and then use your pc to connect wirelessly to the router. Test your wireless Internet connection and make sure it is working correctly. You must have a properly working wireless connection before setting up wireless security.
    To implement wireless security, you need to do one step at a time, then verify that you can still connect your wireless computer to the router.
    Next, encrypt your wireless system using the highest level of encryption that all of your wireless devices will support. Common encryption methods are:
    WEP - poor (see note below)
    WPA (sometimes called PSK, or WPA with TKIP) - good
    WPA2 (sometimes called PSK2, or WPA with AES) - best
    WPA and WPA2 sometimes come in versions of "personal" and "enterprise". Most home users should use "personal". Also, if you have a choice between AES and TKIP, and your wireless equipment is capable of both, choose AES. With any encryption method, you will need to supply a key (sometimes called a "password" ).
    The wireless devices (computers, printers, etc.) that you have will need to be set up with the SSID, encryption method, and key that matches what you entered in the router.
    Retest your system and verify that your wireless Internet connection is still working correctly.
    And don't forget to give your router a new login password.
    Picking Passwords (keys): You should never use a dictionary word as a password. If you use a dictionary word as a password, even WPA2 can be cracked in a few minutes. When you pick your login password and encryption key (or password or passphrase) you should use a random combination of capital letters, small letters, and numbers, but no spaces. A login password, should be 12 characters or more. WPA and WPA2 passwords should be at least 24 characters. Note: Your key, password, or passphrase must not have any spaces in it.
    Most home users should have their routers set so that "remote management" of the router is disabled. If you must have this option enabled, then your login password must be increased to a minumum of 24 random characters.
    One additional issue is that Windows XP requires a patch to run WPA2. Go to Microsoft Knowledge base, article ID=893357 and it will direct you to the patch.
    Sadly, the patch is not part of the automatic Windows XP updates, so lots of people are missing the patch.
    Note:
    WEP is no longer recommended. The FBI has demonstrated that WEP can be cracked in just a few minutes using software tools that are readily available over the Internet. Even a long random character password will not protect you with WEP. You should be using WPA or preferably WPA2 encryption.

  • Can't get iPad 4 to accept LAN password.

    Just setup new iPad 4, but I can't get it to accept my LAN password. It finds the Wi-Fi network name, but won't recognized the password my Windows 7 says is the network password. Can it be that my Home Group network and the Wi-Fi network are two different things?

    Windows 7 doesn't set your wifi password, your router does.
    The password generated by Windows 7, I believe the one you mean, is for sharing files across the network with other windows machines-it's not for accessing wifi.

  • "None of your preferred networks are available" But they are!

    This is the one problem that most bugs me with my MBP, i was hoping that 10.5.2 would fix it, but it does not.
    I use my MBP on two wireless networks. They are both airport expresses with different SSIDs.
    The first (work) is one airport express and my MBP will connect to it when ever it is in range happily. The second (home) is an airport express with another airport express extending the first. The only one in range on my laptop is the extension. Every time I wake the laptop it will tell me that "None of your preferred networks are available" and show the name of my network in the list - it has the password stored and has been told to remember the network... and yet it still refuses to connect.
    Clicking the network shows that it knows the password as it displays it. I have rest both airport expresses and made the network from scratch, I have also deleted all references to the network in keychain and airport preferences, and yet it still does it.
    There are a couple of other threads on this topic, but none of them have been resolved (That i have found) and they seem to have a slightly different problem to me, so I have posted my own question.
    Does anyone know what is wrong?
    Thanks.

    I don't have the answer, I have the problem...
    I'm also in one of the other threads about 10.5.2 messing up connection to my Apple Airport Extreme (melted marshmallow), but I also have the "None of your preferred networks are available" problem.
    My network configuration looks like this: http://tijil.org/LAN_06.jpg
    I have: Hard reset Airport, re-loaded firmware, re-done all settings, powered up and down numerous times, changed channels, etc. to no avail.
    For me the Airport Base continues to work just fine with the other two computers connected to it wirelessly, but my 3 week old MacBook with 10.5.2 will no do so automatically, and once it does, even though the signal is strong and the S/N ratio is good, the connection is usually much slower than either of the other machines, has difficulty sustaining a large upload, and frequently drops out - for the MacBook only.
    This did not happen with 10.5.0 or 10.5.1 and does not happen with the machines running 10.4.x.
    The Airport Extreme Base is set to use 802.11b/g as one of the older machines can only handle 'b'...
    I have MAC screening set up and also WAP. Network is NOT 'hidden.'
    Airport Utility on the MacBook also has difficulty finding the base even when the MacBook is actually connected to it and using it to download mail. sigh
    The problem is something that changed in 10.5.2.
    Hope Apple gets this sorted soon!
    Tom

  • How do I stop the None of your preferred networks are available dialogue?

    I'm using my macBook in 2 places - one where I connect to the internet with an ethernet cable and one where I use a wireless network. It works fine, except that when I start up with the ethernet cable, I get a message from airport saying "None of your preferred networks are available".
    I'd like to get rid of that message. Preferably entirely, but at least when I'm already connected via Ethernet (I've already tried putting Ethernet above Airport in the preferred order list which didn't help)

    Eight wrote:
    I am having this problem "None of your preferred networks are available" when only one network is available, ie. my own.
    Still the computer will not join to it automatically whether the box is ticked or not.
    I STILL HAVE TO MANUALLY CHOOSE! I just want it to connect automatically after I wake up!
    Can anybody help.
    I too have been frustrated by this for a month now. Tonight I finally got frustrated enough to find a workaround. Go to network preferences, click on the airport item, then on the advanced button. Under the wireless settings, add a second instance of your network to the 'preferred networks' list. I now have two entries with the exact same network name and password as the first and second 'preferred networks' and my laptop now wakes up connected to my network!
    By the way...one possible outcome when you finally hit the 'Apply' button is that your entire machine will freeze and your only recourse is to restart. This is possibly the most annoying OS X upgrade in the last 5 years.

  • Instructions to add an airport express to your existing network

    Adding your airport express to your existing wireless (none apple) network seems a hard thing to do since the instruction manual doesn’t tell the simple steps to be taken. Changing the network settings once configured causes the same trouble. Many of you will have got the famous 10057 error trying to…
    It took me a while to figure out the solution but I found it and here it is….
    Start with setting your airport to default factory. This is an important step, so don’t skip it.
    1. First of all. Connect your airport express directly to the router of your own wireless network by a normal network cable. Now start your PC and make sure the Airport express utility program is installed (can be found on the installation cd or at the apple website).
    2. Now do a HARD reset of the airport express into factory settings. This will erase every setting you’ve entered and starts with a clean “new” machine.
    a. Push the reset button and keep it pushed. (button is located on the bottom and can be pushed by a paperclip or so)
    b. Now connect your airport to the power outlet so it starts up. Still keep the reset button pushed.
    c. After a few seconds the status led will start flashing orange (amber). Now release the reset button and let the airport completely start up for about 1 minute until it slowly flashes orange (amber). Your factory settings haven been restored and the password is reset to ‘ public ’
    Once your airport has started and flashes amber, proceed with the following steps:
    3. Start on your pc the airport express utility program. If necessary, hit the “look for devices” button.
    4. Your aiport express is shown on the left. Select it by single click and note down the IP address as shown in on the right side in your airport utility program
    5. Under the menu “File”, choose “configure other base station” Don’t bother the strange description, just choose this option. Now enter the IP address of your airport and the password “public” (has been reset to this remember). Hit the OK button.
    6. Now the miracle happens. Your airport is suddenly found and shown. A new screen opens with all settings of your airport express and you can change them.
    a. By default the icon Airport is selected.
    - The first tab is called overview and is not relevant.
    - Go to the second tab, called base station.
    --> Give your airport express a name and add a password
    --> Note: you might want to open the Options Button and unselect the “look for new firmware option”. If you unselect it, you will keep the airport from constantly downloading new firmware forcing you to reboot it almost every week.
    - Now go to the tab wireless
    --> Select in the dropdown “wireless mode” the option “connect with wireless network". Doing so, you instruct the airport not to create a network but to join an existing one (in this case your own network)
    --> Select your own network in the dropdown under “name Wireless network"
    --> Select the security mode (in most cases WPA/2) and enter your network security password. This is the password you have been creating on your network configuration.
    b. Now click the Music Icon
    --> Select the option “activate Airtunes”
    --> Enter a name you want to be shown in Itunes for this airport.
    c. If you want, you can set up your printer on by clicking on the printers icon and fill out the settings.
    d. Now finally hit the button “Update” at the bottom.
    7. A dialog is shown to warn you. Of course you want to proceed, so hit the “next” button.
    8. Now your changes are sent to the airport device.
    LET FOLLOWING STEPS FINISH COMPLETELY:
    First it writes to the device (a dialog screen is shown telling you that).
    Secondly your device is restarted (again a dialog is shown).
    Third step is to try to read the airport express again. A dialog is shown.
    Let it finish and at the end you will get a “error” message telling you it can’t read the airport you just configured. Don’t worry about that. Just close this message.
    9. Close the Airport Utility program on your pc
    10. Disconnect your airport from power and network.
    11. Reboot your airport now anywhere you want in your home and let it start up for about 1 minute until the green led becomes solid.
    Yes, it will work.
    Message was edited by: Carlo Mantels

    Carlos,
    This is an excellent tutorial.  For some Windows users, however, who have not made changes to their network settings and yet still encounter the dreaded 10057 error code, my post below might resolve:
    https://discussions.apple.com/thread/3289924
    My problem was my Windows PC's TCP/IP settings/configuration, which had become corrupt.  I could use Airport Utility without incident on my Macs, but not via my Windows machine.  Refreshing the TCP/IP settings via the instructions above resolved the issue.
    Kind regards,
    Jason Havens
    Destin, FL, USA

  • Trying to connect to a known internet connection but i keep getting the response "unable to join network"

    Trying to connect to a known internet connection but I keep getting the response "Unable to join network" and the internet is connected, please help.

    Okay now this description was pretty vague but it could be a few things. First thing to try. Turn wifi off and then one again and try to connect. If this fails read on.
    The second step is to select that network in the wifi settings so you get an expanded menu of it. Follow these steps from the home menu on your ipad... SETTINGS>Wi-FI>NETWORK NAME (you have to click the little blue arrow)> FORGET THIS NETWORK. Then turn wifi off and then on. Then try to connect again. If this fails... well read on,
    Okay, so now you really know it's most likely not your ipad, so go on down to your wifi router and turn it off, wait ten seconds, turn it on again. WITH YOUR IPAD OFF. Then turn on your ipad on and then try to connect again. If this fails... Then you'll have to do some more complex things. You could try setting up the network again. IF that fails too. Leave some details about your router, brand, year etc... And I'll try to let you know what else it could be.

  • Tecra A10 - Refurbished - unable to get it connected to my home network

    I just got this Tecra A10-104 refurbished Laptop...before I take it back I am asking here just in case theres something I have missed as I am unable to get it connected to my home network.
    I am running a Belkin Wireless Router that has 2 main PC's directly connected (LAN), and another PC wirelessly connected.
    This is my router: http://www.belkin.com/uk/support/article/?lid=enu&pid=F5D8233uk4&aid=9238&scid=0
    All PC's working fine and connected.
    Now I'm trying to setup this laptop to connect.
    I uninstalled the Vista Business and ussed the XP Pro Product Recovery disc that came with the Tecra.
    My WiFi card is: Intel(R) Wireless WiFi Link 5100 (Driver Date: 27/04/2008 - Driver Version: 12.0.0.73)
    It sees the network but no matter what i try just won't connect.
    What I have done so far (read before suggesting stuff I have already tried):
    Reconfigured routers WPS to Shared Key system.
    Made sure the wireless adapter has settings set to 20/40hz (auto)
    Restarted router, cable modem & laptop several times
    Wireless button on side of Laptop is ON.
    FN + F8 to enable WIFI (ON) BLUETOOTH (OFF)
    Added wireless network to Auto Connect settings along with SSID and passcode end encryption method.
    Clicked connect when network appears in network viewer dialogue and retyped passcode.
    Not working.
    I should add the Laptop has no problems connecting via its Gigabit LAN port.
    Anything else I'm missing?
    Thanks in advance.
    EDIT: Dual post removed.

    UPDATE:
    The next thing I tried was to reinstall Vista Business from recovery disc to see if this suffered from the same problem.
    The wireless connection worked fine on Vista and, despite the updates that I was being offered, worked without needing to update any drivers.
    This made me think...so the issue is probably XP DRIVER related.
    What I have done now is backup all the driver updates I was told to download by TEMPRO (BIOS & wireless manager updates included).
    I think part of the problem is that TEMPRO only works in Vista (not XP) so you are not informed of any updates that may be required if you downgrade to XP straight after purchase (which is what I did).

  • Remote access VPN client gets connected no access to LAN

    : Saved
    ASA Version 8.6(1)2
    hostname COL-ASA-01
    domain-name dr.test.net
    enable password i/RAo1iZPOnp/BK7 encrypted
    passwd i/RAo1iZPOnp/BK7 encrypted
    names
    interface GigabitEthernet0/0
    nameif outside
    security-level 0
    ip address 172.32.0.11 255.255.255.0
    interface GigabitEthernet0/1
    nameif inside
    security-level 100
    ip address 192.9.200.126 255.255.255.0
    interface GigabitEthernet0/2
    shutdown
    no nameif
    no security-level
    no ip address
    interface GigabitEthernet0/3
    shutdown
    no nameif
    no security-level
    no ip address
    interface GigabitEthernet0/4
    shutdown
    no nameif
    no security-level
    no ip address
    interface GigabitEthernet0/5
    nameif failover
    security-level 0
    ip address 192.168.168.1 255.255.255.0 standby 192.168.168.2
    interface Management0/0
    nameif management
    security-level 0
    ip address 192.168.2.11 255.255.255.0
    ftp mode passive
    dns server-group DefaultDNS
    domain-name dr.test.net
    object network RAVPN
    subnet 192.168.0.0 255.255.255.0
    object network NETWORK_OBJ_192.168.200.0_24
    subnet 192.168.200.0 255.255.255.0
    object network NETWORK_OBJ_192.9.200.0_24
    subnet 192.9.200.0 255.255.255.0
    object-group network inside_network
    network-object 192.9.200.0 255.255.255.0
    object-group network Outside
    network-object host 172.32.0.25
    access-list RAVPN_splitTunnelAcl standard permit 192.9.200.0 255.255.255.0
    access-list test123 extended permit ip host 192.168.200.1 host 192.9.200.190
    access-list test123 extended permit ip host 192.9.200.190 host 192.168.200.1
    access-list test123 extended permit ip object NETWORK_OBJ_192.168.200.0_24 192.9.200.0 255.255.255.0
    access-list test123 extended permit ip 192.9.200.0 255.255.255.0 object NETWORK_OBJ_192.9.200.0_24
    pager lines 24
    mtu management 1500
    mtu outside 1500
    mtu inside 1500
    mtu failover 1500
    ip local pool RAVPN 192.168.200.1-192.168.200.254 mask 255.255.255.0
    no failover
    icmp unreachable rate-limit 1 burst-size 1
    asdm image disk0:/asdm-66114.bin
    no asdm history enable
    arp timeout 14400
    nat (inside,outside) source dynamic any interface
    nat (any,inside) source static NETWORK_OBJ_192.168.200.0_24 NETWORK_OBJ_192.168.200.0_24 destination static NETWORK_OBJ_192.9.200.0_24 NETWORK_OBJ_192.9.200.0_24
    route outside 0.0.0.0 0.0.0.0 172.32.0.2 1
    timeout xlate 3:00:00
    timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
    timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
    timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
    timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
    timeout tcp-proxy-reassembly 0:01:00
    timeout floating-conn 0:00:00
    dynamic-access-policy-record DfltAccessPolicy
    user-identity default-domain LOCAL
    aaa authentication ssh console LOCAL
    http server enable
    http 0.0.0.0 0.0.0.0 outside
    http 0.0.0.0 0.0.0.0 inside
    no snmp-server location
    no snmp-server contact
    snmp-server enable traps snmp authentication linkup linkdown coldstart warmstart
    crypto ipsec ikev1 transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac
    crypto ipsec ikev1 transform-set ESP-DES-SHA esp-des esp-sha-hmac
    crypto ipsec ikev1 transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
    crypto ipsec ikev1 transform-set ESP-DES-MD5 esp-des esp-md5-hmac
    crypto ipsec ikev1 transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac
    crypto ipsec ikev1 transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac
    crypto ipsec ikev1 transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac
    crypto ipsec ikev1 transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac
    crypto ipsec ikev1 transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac
    crypto ipsec ikev1 transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac
    crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs group1
    crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5
    crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
    crypto map outside_map interface outside
    crypto ca trustpoint ASDM_TrustPoint0
    enrollment terminal
    subject-name CN=KWI-COL-ASA-01.dr.test.net,O=KWI,C=US
    crl configure
    crypto ikev1 enable outside
    crypto ikev1 policy 10
    authentication crack
    encryption aes-256
    hash sha
    group 2
    lifetime 86400
    crypto ikev1 policy 20
    authentication rsa-sig
    encryption aes-256
    hash sha
    group 2
    lifetime 86400
    crypto ikev1 policy 30
    authentication pre-share
    encryption aes-256
    hash sha
    group 2
    lifetime 86400
    crypto ikev1 policy 40
    authentication crack
    encryption aes-192
    hash sha
    group 2
    lifetime 86400
    crypto ikev1 policy 50
    authentication rsa-sig
    encryption aes-192
    hash sha
    group 2
    lifetime 86400
    crypto ikev1 policy 60
    authentication pre-share
    encryption aes-192
    hash sha
    group 2
    lifetime 86400
    crypto ikev1 policy 70
    authentication crack
    encryption aes
    hash sha
    group 2
    lifetime 86400
    crypto ikev1 policy 80
    authentication rsa-sig
    encryption aes
    hash sha
    group 2
    lifetime 86400
    crypto ikev1 policy 90
    authentication pre-share
    encryption aes
    hash sha
    group 2
    lifetime 86400
    crypto ikev1 policy 100
    authentication crack
    encryption 3des
    hash sha
    group 2
    lifetime 86400
    crypto ikev1 policy 110
    authentication rsa-sig
    encryption 3des
    hash sha
    group 2
    lifetime 86400
    crypto ikev1 policy 120
    authentication pre-share
    encryption 3des
    hash sha
    group 2
    lifetime 86400
    crypto ikev1 policy 130
    authentication crack
    encryption des
    hash sha
    group 2
    lifetime 86400
    crypto ikev1 policy 140
    authentication rsa-sig
    encryption des
    hash sha
    group 2
    lifetime 86400
    crypto ikev1 policy 150
    authentication pre-share
    encryption des
    hash sha
    group 2
    lifetime 86400
    crypto ikev1 policy 65535
    authentication pre-share
    encryption 3des
    hash sha
    group 2
    lifetime 86400
    telnet 192.9.200.0 255.255.255.0 inside
    telnet timeout 30
    ssh 0.0.0.0 0.0.0.0 management
    ssh 0.0.0.0 0.0.0.0 outside
    ssh 66.35.45.128 255.255.255.192 outside
    ssh 0.0.0.0 0.0.0.0 inside
    ssh timeout 30
    ssh version 2
    console timeout 0
    threat-detection basic-threat
    threat-detection statistics access-list
    no threat-detection statistics tcp-intercept
    webvpn
    enable outside
    anyconnect image disk0:/anyconnect-win-2.5.2014-k9.pkg 1
    anyconnect enable
    tunnel-group-list enable
    group-policy DfltGrpPolicy attributes
    group-policy RAVPN internal
    group-policy RAVPN attributes
    wins-server value 192.9.200.164
    dns-server value 66.35.46.84 66.35.47.12
    vpn-filter value test123
    vpn-tunnel-protocol ikev1
    split-tunnel-policy tunnelspecified
    split-tunnel-network-list value test123
    default-domain value dr.kligerweiss.net
    username test password xxxxxxx encrypted
    username admin password aaaaaaaaaaaa encrypted privilege 15
    username vpntest password ddddddddddd encrypted
    tunnel-group RAVPN type remote-access
    tunnel-group RAVPN general-attributes
    address-pool RAVPN
    default-group-policy RAVPN
    tunnel-group RAVPN ipsec-attributes
    ikev1 pre-shared-key *****
    class-map inspection_default
    match default-inspection-traffic
    policy-map type inspect dns preset_dns_map
    parameters
      message-length maximum client auto
      message-length maximum 512
    policy-map global_policy
    class inspection_default
      inspect dns preset_dns_map
      inspect ftp
      inspect h323 h225
      inspect h323 ras
      inspect ip-options
      inspect netbios
      inspect rsh
      inspect rtsp
      inspect skinny
      inspect esmtp
      inspect sqlnet
      inspect sunrpc
      inspect tftp
      inspect sip
      inspect xdmcp
    service-policy global_policy global
    prompt hostname context
    no call-home reporting anonymous
    call-home
    profile CiscoTAC-1
      no active
      destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
      destination address email [email protected]
      destination transport-method http
      subscribe-to-alert-group diagnostic
      subscribe-to-alert-group environment
      subscribe-to-alert-group inventory periodic monthly 2
      subscribe-to-alert-group configuration periodic monthly 2
      subscribe-to-alert-group telemetry periodic daily
    password encryption aes
    Cryptochecksum:b001e526a239af2c73fa56f3ca7667ea
    : end
    COL-ASA-01#
    Here is some capture done on the inside interface which may help too, I tried pointing the gateway to inside interface on the target device but I think this was a switch without ip route available on it I believe that is still sending packet back to Cisco inside interface
    COL-ASA-01# sho cap test | in 192.168.200
    25: 23:45:55.570618 192.168.200.1 > 192.9.200.190: icmp: echo request
      29: 23:45:56.582794 192.168.200.1.137 > 192.9.200.164.137:  udp 68
      38: 23:45:58.081050 192.168.200.1.137 > 192.9.200.164.137:  udp 68
      56: 23:45:59.583176 192.168.200.1.137 > 192.9.200.164.137:  udp 68
      69: 23:46:00.573517 192.168.200.1 > 192.9.200.190: icmp: echo request
      98: 23:46:05.578110 192.168.200.1 > 192.9.200.190: icmp: echo request
      99: 23:46:05.590057 192.168.200.1.137 > 192.9.200.164.137:  udp 68
    108: 23:46:07.092310 192.168.200.1.137 > 192.9.200.164.137:  udp 68
    115: 23:46:08.592468 192.168.200.1.137 > 192.9.200.164.137:  udp 68
    116: 23:46:10.580795 192.168.200.1 > 192.9.200.190: icmp: echo request
    COL-ASA-01#
    Any help or pointers greatly appreciated, I am doing this config after a long gap on Cisco last time I was working it was all PIX so just need some expert eyes to let me know if I am missing something.
    And Yes I do not have a Host in Inside network to test against, all I have is a switch which cannot route and ip default gateway is not helping too...

    Hi,
    The first thing you should do to avoid problems is to change the VPN Pool to something else than the current LAN network as they are not really directly connected in the same network segment.
    You could try the following changes
    tunnel-group RAVPN general-attributes
      no address-pool RAVPN
    no ip local pool RAVPN 192.168.200.1-192.168.200.254 mask 255.255.255.0
    ip local pool RAVPN 192.168.201.1-192.168.201.254 mask 255.255.255.0
    tunnel-group RAVPN general-attributes
      address-pool RAVPN
    no nat  (any,inside) source static NETWORK_OBJ_192.168.200.0_24  NETWORK_OBJ_192.168.200.0_24 destination static  NETWORK_OBJ_192.9.200.0_24 NETWORK_OBJ_192.9.200.0_24
    In the above you first remove the VPN Pool from the "tunnel-group" and then remove and recreate the VPN Pool with another network and then insert it back to the same "tunnel-group". Nex you remove the current NAT configuration.
    object network LAN
    subnet 192.168.200.0 255.255.255.0
    object network VPN-POOL
    subnet 192.168.201.0 255.255.255.0
    nat (inside,outside) 1 source static LAN LAN destination static VPN-POOL VPN-POOL
    The above NAT configurations adds the correct NAT0 configuration for the changed VPN Pool. It also inserts the NAT rule to the very top before the Dynamic PAT rule you currently have. It is also one of the problems with the configurations as it will override your current NAT configurations.
    You have your Dynamic PAT rule at the very top of your NAT rules currently which is not a good idea. If you wish to change it to something else that wont override the other NAT configurations in the future you can do the following change.
    no nat (inside,outside) source dynamic any interface
    nat (inside,outside) after-auto source dynamic any interface
    NOTICE! Changing the above Dynamic PAT configuration will temporarily terminate all connections for users from the LAN as you reconfigure the Dynamic PAT rule. So if you do this change make sure that its ok to cause still small cut in the current connections of internal users
    Hope this helps
    Let me know if it works for you
    - Jouni

  • I just sent the following in a drop down box that allowed reporting system problems:I am most unhappy with your Lion 10.7.3 operating system that I installed on this MacBook:  Hardware Overview:    Model Name:     MacBook Pro   Model Identifier:     MacBo

    I am most unhappy with your Lion 10.7.3 operating system that I installed on this MacBook:
    Hardware Overview:
      Model Name:          MacBook Pro
      Model Identifier:          MacBookPro5,4
      Processor Name:          Intel Core 2 Duo
      Processor Speed:          2.53 GHz
      Number of Processors:          1
      Total Number of Cores:          2
      L2 Cache:          3 MB
      Memory:          4 GB
      Bus Speed:          1.07 GHz
      Boot ROM Version:          MBP53.00AC.B03
      SMC Version (system):          1.49f2
      Serial Number (system):          W8******7XJ
      Hardware UUID: ******
      Sudden Motion Sensor:
      State:          Enabled
    1. The scrolling, as far as I've been able to determine, is by using the slide bar to the right of most diplays. There are no up or down arrows that allow slow movement
    2. The top and botton toolbars are not visible. The top one appears when you point the arrow to the top of the screen but the same doesn't work well if at all pointing the cursor to the bottom.
    3. When downloading, something jumps to the upper right of the screen. I could point and click it and get a diplay if my downloads. I was attempting to fix some of the above. Now the little thing jumps off the screen and I can't get to it.
    4I was trying to installMacBook Pro EFI Firmware Update 2.3. I got message it couldn't be installed on my system.
    5. The red yellow and blue bullets that allow shutting down, minimizing and maximizing are missing on most open windows.
    Can you do something about these problems
    It's problematical that one can't communicate directly with Apple to resolve these problems
    <Edited By Host>

    1: I'm scrolling this page right now using the arrow keys.
    2: Press the escape (esc) key to exit full-screen mode. Select Apple menu > Dock > Turn Hiding Off.
    3: ???
    4: That's because you downloaded an update for another model.
    5: See 2.

  • I've tried downloading iOS5 several times and after an hour each time I get a message that says my network connection has timed out.  But I can't find any information about "timing out" or how to correct the situation.  Any help?

    I've tried downloading iOS5 several times and after an hour each time I get a message that says my network connection has timed out.  But I can't find any information about "timing out" or how to correct the situation.  Any help?

    Disable your antivirus and firewall, and try again.

  • Is there a better way to share your music library outside your home network other than using an i-Pod classic?

    APPLE-Here's a complement and a question.  Why has the i-Pod Classic fallen from grace compared to other i-Pods?    Please know that while I can share my music using home sharing within my home network with a different i-Tune account, it seems to me that the best benefit of having an i-Pod Classic is that you can give your dedicated music library and device to a friend or housemate to use outside your wireless network (and not on the internet) to use while traveling.   Am I wrong?   Is there a benefit to sharing the cloud usage with a friend.   Add that to the click wheel and I think I'm going to be a fan of the i-Pod Classic far longer than it is in production.  I hope Apple NEVER stops production of this device.   Are you listening Apple?

    Fightthegoodfightnow wrote:
    I also lend books I read and CDs I own and that isn't stealing either. 
    Yes it is, and it's precisely what the music industry has been fighting about for years.
    Interpreting the law to suit yourself does not render law ineffective. Apple's Terms of Use mention this:
    Keep within the Law
    No material may be submitted that is intended to promote or commit an illegal act.
    Do not submit software or descriptions of processes that break or otherwise 'work around' digital rights management software or hardware. This includes conversations about 'ripping' DVDs or working around FairPlay software used on the iTunes Store.
    ...which is why my original response was framed as it was. Nothing to do with "attack mode". (You're the one with an "attack style" user name.)
    Fightthegoodfightnow wrote:
    Heck, as I understand it, I can legally burn up to five copies of a bought song for noncommercial, personal use....so copying in and of itself is also not illegal.
    As I recall, the music industry has acknowledged that making a copy of a CD (that you own, and still have in your possession) is regarded as "Fair Use" - and is therefore tolerated. But until that point was established just a few years ago, then technically, it was illegal to rip a CD into iTunes and onto an iPod. Slightly different to your interpretation. That same music industry (and the musicians) regard the following as unacceptable:
    keeping a copy of a CD but disposing of that CD to someone else
    lending the CD to friends, so that they can make a copy
    making copies and giving them or selling them to someone else
    But what is okay is:
    Home sharing
    use of the CD by someone in your family, living under the same roof
    At this time, if a couple wish to combine their two iTunes accounts of purchased digital music once they get married, they cannot. Perhaps that's where Home Sharing comes in.

  • Unable to get LaserJet M175nw to print over network

    I have just installed a new LaserJet 100 Pro M175nw printer on my network. However I am unable to get it to print via the network.
    The printer is connected to a ethernet cable and configured with a static IP address on the network
    I am using a Windows 7 computer for printing
    All internal functions of the printer work correctly e.g. copy, reports
    Printing works when connected via USB to a computer
    When using the printer via the network:
    Scanning works correctly
    The embedded web mangement page for the printer works correctly
    The HP Print & Scan Doctor diagnostics give the configuration all green ticks
    Print jobs stay in the print queue until they change to an error status.
    The printer does not seem to recognise the print job at all - no progress message indicating printing document on the console
    If the printer is in sleep mode it does not wake up
    Test print pages from the HP Installer, from the Windows Printer Property dialog, from Acrobat Reader and from MS Word all fail.
    All symptoms remain the same when I turn off the Windows Firewall
    Another HP LaserJet 2605dn printer on the network prints correctly on a different IP address but also using the RAW format on port 9100.
    I have removed all drivers for other HP printers in case there was a conflict - no change after re-installing the software.
    Can anyone suggest what I might have overlooked?  Thanks for your help.
    This question was solved.
    View Solution.

    I am confused by your last statement, a TCP/IP is a network connection, which is why the universal print driver is suggested. 
    From what you have described, there is an issue with the print queue. Try running the Print and Scan Doctor :
    http://h10025.www1.hp.com/ewfrf/wc/document?cc=us&lc=en&dlc=en&docname=c03286146
    Also, I am not sure if you tried the PCL6 driver or not, but I would like you to at least try it so that I know what its behavior is. 
    Let me know how that goes and I will get right back with you! 
    -Spencer

Maybe you are looking for

  • How Can I Sync To Another iTunes Library

    We upgraded my manager's iPhone to iOS5...we had to do it from my PC because his iTunes install, even after a reinstall, doesn't want to sync his phone...it gets stuck on backing up 2 of 8. Suffice to say, he can't sync his music. We took it to my PC

  • Using a caculated field to get data from another table.

    I have a Products Table that I need to add a  field to. This field gains data from a Supplier table by using the supplier code to find the correct supplier type. All Products have a Supplier Code. So for example in SQL this would be a simple where st

  • Excise document for Debit Memo

    Hi, When I am doing excise invoice for debit memo for sales in J1IH in other adjustments system shows the below entry Debit- Excise duty collected (PL Account) Credit-Excise duty payable/E.cess (B/S account) which happens at the time of J1IN excise p

  • Choose Preserve Image Dimensions When Relinking

    Is there a way to change the preference "Choose Preserve Image Dimensions When Relinking" from scripting? This setting is accessible in the user interface ( in the Edit menu / Preferences / File Handling tab ). Andreas

  • Logic 9 keeps crashing in 32 bit!!!!!

    Hi all, logic has been having some real problems lately that i think quite alot of users are experiencing. This started around 3 months ago with logic crashing with a white flash. Roughly since updated to 9.1.7. Reinstalled update and seemed to tame