IOS 15.x PKI Redundancy (HA CS) setup and router crashed

Hi,
would like to hear if someone have experienced that one of the HA CS pair routers has broken down in pieces and got replaced with a new one?
I'm expecting to fire up new router and perform the following steps in order to restore the HA state:
1. Configure new router with IPs and NTP
2. Stop CA server in active
3. Configure redundancy and verify it works
4. Start CA in active and keep fingers crossed that required files/keys are replicated to standby unit
Like said, would be nice to hear if there's someone out there who have had successful replacement and willing to share some hints.
Already read this one: Configuring PKI HA for Cisco IOS CA Servers and Client-Side PKI
Best regards,
Toni

Hi Sean,
Current configuration:
On the PIX:
crypto isakmp policy 5
      authentication pre-share
      encryption 3des
      hash sha
      group 2
      lifetime 86400
crypto map outside_map 1 match address outside_1_cryptomap
crypto map outside_map 1 set peer X.X.21.29
crypto map outside_map 1 set transform-set ESP-DES-SHA
crypto map outside_map 1 set security-association lifetime seconds 28800
crypto map outside_map 1 set security-association lifetime kilobytes 4608000
crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac
access-list outside_1_cryptomap extended permit ip 10.1.0.0 255.255.0.0 10.20.0.0 255.255.0.0
tunnel-group X.X.21.29 type ipsec-l2l
tunnel-group X.X.21.29 ipsec-attributes
     pre-shared-key SECRET
On the Router:
crypto isakmp policy 1
      authentication pre-share
crypto map la-2800-ipsec-policy 1 ipsec-isakmp
      description vpn ipsec policy    
      set peer X.X.138.132
      set transform-set la-2800-trans-set
      match address 101
access-list 101 permit ip 10.20.0.0 0.0.0.255 10.1.0.0 0.0.255.255
crypto ipsec transform-set la-2800-trans-set esp-des esp-sha-hmac
crypto isakmp key SECRET address X.X.138.132 no-xauth
Portu.
Please rate any helpful posts
Message was edited by: Javier Portuguez

Similar Messages

  • I have an iphone 5 with ios 6. I am trying to setup a new exchange email account. I need the backslash but it is not available. I can find it on other apps but not when trying to set up the mail account. (it is not on the  keyboard)

    I have an iphone 4s with ios 6. I am trying to setup a new exchange email account. I need the back slash but it does not show up on the keyboard. I know it is supposed to be on the +key (and is for other apps) but for some reason it is not available when setting up an email account. Is this on purpose or am I doing something wrong?

    I can tell you that with Sprint their coverage area isn't as good as Verizon or AT&T.
    Are you sending these imessage while on wifi or cellular data?  Also your husband would need to be in a good coverage area.
    Usually when imessage is unavailable it will send it as a text.  Does your husband receive your imessage as a text?

  • Branch office setup with L3 switch and router with IOS security

    Hello,
    I am in the process of putting together a small branch office network and I am in need of some design advise. The network will support about 10-15 workstations/phones, 3-4 printers, and 4-5 servers. In addition we will eventually have up to 25-30 remote users connecting to the servers via remote access VPN, and there will also be 2-3 site-to-site IPSec tunnels to reach other branches.
    I have a 2911 (security bundle) router and 3560 IP Base L3 switch to work with. I have attached a basic diagram of my topology. My initial design plan for the network was to setup separate VLANs for workstation, phone, printer, and server traffic. The 3560 would then be setup with SVIs to perform routing between VLANs. The port between the router and switch would be setup as a routed port, and static routes would be applied on the switch and router as necessary. The thought behind this was that I'd be utilizing the switch backplane for VLAN routing instead instead of doing router-on-a-stick.
    Since there is no firewall between the switch and router my plan was to setup IOS firewalling on the router. From what I am reading ZBF is my best option for this. What I was hoping for was a way to set custom policies for each VLAN, but it seems that zones are applied per interface. Since the interface between the router and switch is a routed interface, not a trunk/subinterface(s), it doesn't seem like there would be a way for me to use ZBF to control traffic on different VLANs. From what I am gathering I would have to group all of my internal network into one zone, or I would have to scrap L3 switching all together and do router-on-a-stick if I want to be able to set separate policies for each VLAN. Am I correct in my thinking here?
    I guess what I am getting at is that I really don't want to do router-on-a-stick if I have a nice switch backplane to do all of the internal routing. At the same time I obviously need some kind of firewalling done on the router, and since different VLANs have different security requirements the firewalling needs to be fairly granular.
    If I am indeed correct in the above thinking what would be the best solution for my scenario? That is, how can I setup this network so that I am utilizing the switch to do L3 routing while also leveraging the firewall capabilities of IOS security?
    Any input would be appreciated.
    Thanks,
    Austin

    Thanks for the input.
    1. I agree, since I have only three to four printers, they need not be in a separate VLAN. I simply was compartmentalizing VLANs by function when I initially came up with the design.
    2. Here's a little more info on the phone situation. The phones are VoIP. The IP PBX is on premise, but they are currently on a completely separate ISP/network. The goal in the future is to converge the data and voice networks and setup PBR/route maps to route voice traffic out the voice ISP and data traffic out the other ISP. This leads up to #3. 
    3. The reason a router was purchased over a firewall was that ASA's cannot handle routing and dual ISPs very well. PBR is not supported at all on an ASA, and dual ISPs can only be setup in an active/standby state. Also, an ASA Sec+ does not have near the VPN capabilities that the 2911 security does. The ASA Sec+ would support only 25 concurrent IPSec connections while the 2911 security is capable of doing an upwards of 200 IPSec connections.
    Your point about moving the SVI's to a firewall to perform filtering between VLANs makes sense, however, wouldn't this be the same thing as creating subinterfaces on a router? In both cases you are moving routing from the switch backplane to the firewall/routing device, which is what I am trying to avoid.  

  • What are some of the best iOS apps can remotely played videos, audios, photos and text files from a NAS hdd connected to Airport Extreme USB port? And how to configure this setup?

    I have already set up NAS hdd as connecting it at USB port of Airport Extreme, i also want to remotely access it from iPhone, so what's the next step? What are some of the best iOS apps can remotely played videos, audios, photos and text files from the NAS hdd and how to configure this setup?

    *Edit - I am not able to connect to the NAS when hardwired to the airport extreme.

  • If I backed up with a newer version of iOS than the phone I am trying to backup to.. Is there any way to bypass the setup assistant in order to download the new iOS on the new phone then go back and restore from my old phone?

    if I backed up with a newer version of iOS than the phone I am trying to backup to.. Is there any way to bypass the setup assistant in order to download the new iOS on the new phone then go back and restore from my old phone?

    Try deleting your last backup by turning off iCloud Backup in Settings>iCloud>Storage & Backup, then tap Manage Storage, swipe across your backup and tap Delete, then go back and turn iCloud Backup back on again.  If it still won't back up, you may have an app that is preventing the backup from succeeding.  To locate which one, go to Settings>iCloud>Storage & Backup>Manage Storage, tap the name of your device under Backups, under Backup Options tap Show All Apps, then turn them all to Off (including camera roll) and try backing up again.  If it succeeds, then the camera roll and/or one of your apps is preventing the backup and you'll have to located by process of elimination. Turn the camera roll On and try backing up again.  If it succeeds, turn some of your apps to On and try backing up again.  If it succeeds again, turn some more apps to On then try again; repeat this process until it fails.  Eventually you'll be able to locate the problem app and exclude it from your backup.

  • TS1843 i am using iphone 4 ios 6.1.3, after hotmail imap setup, error showing "CANNOT GET MAIL" tHE CONNECTION TO THE SERVER FAILED. its happening since 14 aug. plz help !

    i am using iphone 4 ios 6.1.3, after hotmail imap setup, error showing "CANNOT GET MAIL" tHE CONNECTION TO THE SERVER FAILED. its happening since 14 aug. plz help !

    I have trouble with sending e-mail and syncing e-mail. Try changing to 1 day sync under settings. It's sluggish but it works for me until they resolve the issue. MS claims all is normal. If you still have a problem you should report it here: https://status.live.com/report/hotmail

  • IOS 5 Hotmail native support vs Exchange setup

    Should I delete the current account setup and re-setup with the included, native option?

    You will need to look in Apple's developer documentation
    http://developer.apple.com/
    or perhaps there is or will be an in depth review at Ars Technica
    http://arstechnica.com/apple/

  • Lightroom workflow - HD setup and file locations

    Has anyone waxed poetic about catalog and image file locations or workflow? How do you go about conceptualizing a drive and file storage strategy for a Lightroom workflow? Of course this will vary depending on the equipment you have, but I'd appreciate and links to stories that run through various configuration setups and the possible workflows and locations for catalog, master files and backup locations. Here's my setup:
    - Mac Pro (3GHz 8 Core) with two 750GB internal drives (one for OS X) the other for Apps and content storage); two empty drive bays for now.
    - PowerBook G4 1.2GHz w/160GB internal drive that I use on location, or as an in-lab Flash card reader if the Addonics external, Firewire card reader attached to the Mac Pro fails to see a camera card (as it sometimes does). This second in-lab scenario adds some complexity to the workflow, although the machines are linked with Cat 6, gigabit Ethernet.
    - OWC Mercury Elite Pro with two 750GB drives configured as a mirrored, software RAID on Firewire 800 for backups.
    Should I set up the Lightroom catalog on the internal "content" drive and store all the actual image files there, reserving the RAID drive strictly for backups? This would mean that the RAID would only be used a redundant backup system (which is fine and what I originally planned) since it's probably slower than the single, internal drive. The problem is this: remembering to back up the files from the main content drive to the software RAID drive.
    Or should I be using the slower, mirrored RAID for main content (master image file and catalog) storage.

    John, Andrew and others:
    Thanks for your thoughts. Do you also use Lightroom to manage all "working" versions of Photoshop files (multiple version - edits - of files in progress)?
    During my first couple of projects, I ended up creating a "Working" folder for each project outside the Nikon folder-oriented hierarchy of the original image files. I did this only out of habit rather than workflow planning, but ended up with a second workflow outside of Lightroom.
    Does anyone think it's better to simply save these files (with or without the "working" folders) into the same folder hierarchy with all the Nikon originals? I'm just trying to figure out how to organize the workflow for the in-progress files.
    Again, before Lightroom, I managed these files in separate folders on the hard drive, and usually moved them to a new location for final storage. Clearly, that won't work for Lightroom, but what does? I'm getting into a bit of trouble trying to manage file (and working folder) locations as I try to transition to a new, database-driven workflow.

  • My new ipod is unable to join my wifi network in the initial setup and I cannot use it. What do I do?

    Please help

    Reset the iPod
    Reset iOS device: Hold down the On/Off button and the Home button at the same time for at
    least ten seconds, until the Apple logo appears.
    then do the following before trying again
    - iOS: Troubleshooting Wi-Fi networks and connections
    - Wi-Fi: Unable to connect to an 802.11n Wi-Fi network
    - iOS: Recommended settings for Wi-Fi routers and access points
    It might be easier to setup via iTunes and then troubleshoot the wifi problem

  • IOS 5 rapid battery drain (including in sleep mode), springboard crashes: FIX!

    OK folks, I resolved all issues in their entirety with the help of a genius bar tech who recognized that I was very technical.  WARNING!  Sync or backup your phone prior to performing these steps!
    First, do a MANUAL download here of the IOS 5 that matches the model of phone you have and save that image to your desktop or some other place on your computer.  PUT THE PHONE IN DFU MODE, not recovery mode (google on how to accomplish if you are not familiar).  The raeson why you are going to put in DFU mode is so that you will be able to not only get a good copy of IOS 5 installed but to ensure that your firmware is not corrupt, which appeared to be the case with my battery drains and springboard crash issues.
    One you are in DFU mode (your screen should be black the whole time, again google), open itunes and it will give you a warning that says that your phone needs to be restored.  If you are on a mac, hold down the option key and press RESTORE in iTunes.  This will open up a box that will allow you to "locate and select" a file, which will be the IOS 5 image that you manually downloaded before.
    Once you do, the iphone will start to restore.  After all of the restore cycles have been completed, you will be prompted in iTunes to either setup as a new phone or restore from backup.  I USED RESTORE FROM BACKUP so that I could preserve all of my settings.  Everything has been working PERFECTLY ever since completing these steps!  I will probably go ahead and make a separate thread related to this fix.
    I hope this helps!  Scott

    Their is another thread in here that mentions turning off reporting of Diagnostics data (Settings --> General --> About --> Scroll to the bottom/Diafnostics --> Select Don't send.
    Another item to check are you E-mail accounts. If you only have one account in this section then you should be good. If you have multiple and have every feature turned on (Contacts, Calendars, Reminders, etc) then your device could be trying to update to all and timing out which would get it to retry over and over again. I have turned off all the other features for my email accounts with the exception of iCloud and my battery life is looking good.

  • I've installed ios 7.0.6 on my iphone 4 and lost voice on outgoing and incoming calls. My simm is ok, i've checked it, I've done a full clean and restore. Still no calls. Please help.

    Hi there,
    I've just installed ios 7.0.6 on my iphone 4 and now lost voice on outgoing and incoming calls.It rings on incoming and I'm told rings on the recipient's 'phone, but then no vocal communication...its just dead. My simm is ok, i've checked it, I've done a full clean and restore of the 'phone. Still no calls.
    I've not caused any physical or water damage to the 'phone. I would welcome any help/suggestions to get my calls back asap.
    Please help.
    Miss liberty

    Have you tried restarting or resetting your iPhone?
    Restart: Press On/Off button until the Slide to Power Off slider appears, select Slide to Power Off and, after It shuts down, press the On/Off button until the Apple logo appears.
    Reset: Press the Home and On/Off buttons at the same time and hold them until the Apple logo appears (about 10 seconds).
    Also consider deleting and reinstalling the Mail Account in question.

  • TS1538 my ipad can not continue to download ios 6.1.2 because of connection problem and it is stuck in connect to itunes image, i cant open it anymore..what should i do? help plz

    my ipad can not continue to download ios 6.1.2 because of connection problem and it is stuck in connect to itunes image, i cant open it anymore..what should i do? help plz

    Connect to iTunes on the computer you usually Sync with and “ Restore “...
    http://support.apple.com/kb/HT1414
    If necessary Place the Device into Recovery mode...
    http://support.apple.com/kb/ht4097
    You may need to try this More than Once...
    Be sure to Follow ALL the Steps...
    But... if the Device has been Modified... this will Not necessarily work.

  • Since the latest IOS update, my new iPad Air is freezing and glitching badly. Typing is delayed.

    Since the latest IOS update, my new iPad Air is freezing and glitching badly. Typing is delayed.

    iPad running slow? How to speed up a slow iPad
    http://appletoolbox.com/2012/07/ipad-running-slow-how-to-speed-up-a-slow-ipad/
    If You Think iOS 7 Feels Slow Here’s How to Speed It Up
    http://osxdaily.com/2013/09/23/ios-7-slow-speed-it-up/
    You may have many apps open which can possibly cause the slowdown and possibly the loss of wifi. In iOS 4-6 double tap your Home button & at the bottom of the screen you will see the icons of all open apps. Close those you are not using by pressing on an icon until all icons wiggle - then tap the minus sign. For iOS 7 users, there’s an easy way to see which apps are open in order to close them. By double-tapping the home button on your iPhone or iPad, the new multitasking feature in iOS 7 shows full page previews of all your open apps. Simply scroll horizontally to see all your apps, and close the apps with a simple flick towards the top of the screen.
     Cheers, Tom

  • Hi...lags animations in games and messages and album pic..when disable assistive touch,it's true and fix..please release update to fix this in ios 7.1..i need assistive touch and fast game and animation booth!!

    Hi...lags animations in games and messages and album pic..when disable assistive touch,it's true and fix..please release update to fix this in ios 7.1..i need assistive touch and fast game and animation booth!!

    No Apple here, user to user forum.
    I will not be releasing any version of iOS ever.

  • TS3694 I performed an iOS 7 software update on my iPhone yesterday, and now the phone is not working at all. The iPhone screen shows to connect to iTunes to restore. I've have done this, and still the iPhone is not working. What going on?

    I performed an iOS 7 software update on my iPhone yesterday, and now the phone is not working at all. The iPhone screen shows to connect to iTunes to restore. I've have done this, and still the iPhone is not working. What going on?

    I have no idea what may have caused your MacBook to stop working, but from your description it kind of sounds like it may have started before you ran Software Update and installed the new Apps. Just the general slow feeling and bugginess is what tips me off. You said that you weren't sure if you had closed all open windows, that doesn't matter if the computer restarts itself. It automatically closes all other open applications when restarting.
    As to your data being retrievable, if when you take it in they do a fresh install of the OS, then no, it will not be unless you want to pay several thousand dollars to a software retrieval company.
    I am glad to hear that you have taken into the Apple Store to get it fixed, and that you have all of your purchased music backed up to your iPod. You should be able to just transfer it all back to iTunes once you get your computer back should it be necessary.
    As a side note, the proper place for this topic would probably in the MacBook forums, not iTunes since there is no evidence that iTunes started the issue.

Maybe you are looking for

  • Running a 32 bit app on a 64 bit server issue

    Please help! I have been trying all of the fixes on the internet and nothing seems to work. I am trying to use the Oracle OLE DB Provider to run a 32 bit application on a 64 bit server - tried on a 2008 R2 and a 2003 SP2, both fail. I have tried with

  • Live photo

    Hi everyone Not sure if this is in the right forum or not but my Windows Server 2011 SBS has screensaver set to Windows Live Photo Gallery which should subsequently play some photo's stored on my server, but it doesn't! I've tried changing the locati

  • Photo stream access?

    hi there, i had some trouble with my iPhone 4s and got it replaced (great service, by the way!).but i lost a lot of the pictures that were on that phone. now these pictures are all still visible on my apple tv photostream and my ipad that had photost

  • Problems with download BB world

    Dear, I got problems with Blackberry bold. BB world. This app need upgrade. When I accept it, it send me direct to BB pages for download, but nothing happend. On page is mentioned times run out. Could you help me please? Stepan Solved! Go to Solution

  • Is there any way I can re-edit a finalised DVD?

    I watched a DVD recently that I created on iMovie four years ago and decided that I would like to tweak it in order to improve it- now that i'm more proficient with iMovie. Is this at all possible to do with a finalised disc? There has to be a way in