IPSec between Mobile Node - Mobile Router - Foreign Agent - Home Agent ?

At this moment, I will like to know if Cisco Mobile IP solution has the security feature that provides end-2-end VPN IPSec tunnel for Mobile Node -> Mobile Router -> Foreign Agent -> Home Agent ? Now, I know that FA-HA will either have IP- or GRE- tunnel, right ? Does this mean it already have got IPSec tunnel ?

Since there has been no response to your post, it appears to be either too complex or too rare an issue for other forum members to assist you, or there is no public information available at this time. If you don't get a suitable response to your post, you may wish to review our resources online at http://www.cisco.com/go/solutions. You may also contact our product information line at 1-800-553-NETS or a Cisco Systems Engineer at your local Cisco office or reseller. To locate your local Cisco representative, visit http://www.cisco.com/warp/public/687/Directory.shtml
If anyone else in the forum has some advice, please reply to this thread.
Thank you for posting.

Similar Messages

  • Configure IPsec between PIX and ADSL router

    Hi,
    We want to create IPsec between PIX @ Point A and ASA(which is behind ADSL router) @ Point B. 
    Point A PIX ----> Internet -- cloud -- Internet <---- ADSL Router <---ASA Point B    
    Please guide me or share usefull link for same.
    Thanks & Regards,
    Dhaval Dikshit                

    IPSec should only be an option if the WLC has a crypto card installed.  IIRC, only the 4400 supported the crypto card, and it went EoS shortly after the airespace acquisition.
    HTH,
    Steve
    Please remember to rate helpful posts or to mark the question as answered so that it can be found later.

  • Internet Not in IP Mobile Router

    IOS to 15.4(3)M1 on IOS to 15.4(3)M1  with 4GEHWIC  card.  The interface Loopback255 is not in SHOW IP MOBILE ROUTER.
    Looking for advice or ideas?
    oco-na1306rw1#s run | sec ip mobile router
    ip mobile router-service roam
    ip mobile router-service collocated ccoa-only
    ip mobile router
    address 1.2.3.4 255.255.255.255
    collocated single-tunnel
    home-agent 66.174.251.2
    mobile-network Loopback255
    mobile-network Loopback17
    register extend expire 10 retry 3 interval 5
    reverse-tunnel
    tunnel mode gre
    interface Loopback255
    description FOR DMNR SUMMARY GENERATION
    ip vrf forwarding DMNR
    ip address 10.47.176.254 255.255.240.0
    joco-na1306rw1#sho ip int brief
    Loopback17                 172.17.40.254   YES NVRAM  up                    up     
    Loopback255                10.47.176.254   YES manual up                    up 
    joco-na1306rw1#sho ip mobile router
    Mobile Router
        Enabled 03/05/15 14:26:12
        Last redundancy state transition NEVER
    Configuration:
        Home Address 1.2.3.4 Mask 255.255.255.255
        Home Agent 66.174.251.2 Priority 100 (best) (current)
        Registration lifetime 65534 sec
        Retransmit Init 1000, Max 5000 msec, Limit 3
        Extend Expire 10, Retry 3, Interval 5
        Reverse tunnel required
        Request GRE tunnel
        Multi-path denied by HA, Requested metric: bandwidth
        Mobile Networks:                                                           ß Missing Loop255 here
                         Loopback17 (172.17.40.254/255.255.255.255)
    Monitor:
        Status -Registered-
        Using collocated care-of address 172.17.127.2
        On interface Cellular0/0/0
        Tunnel0 mode GRE/IP

    bump :)
    title should say IP Subnet not showing in IP Mobile Router

  • When frequently switching between mobile and desktop view

    When I frequently switching between mobile and desktop view I have to open the layers every time since they get closed/collapsed. Adobe may need to fix it for the next version.

    You can use CTRL+# to switch between Code and Design View.
    By the way, this is the Dreamweaver Application Development forum which deals with questions about using server-side scripting languages like PHP or ColdFusion. General Dreamweaver questions should be posted in the regular Dreamweaver General Discussions forum.
    And while I´m at it: please use descriptive headlines such as "how to switch between Code and Design View" for your posts -- mentioning your screen name "Goula129" is not helpful to other users.

  • Difference between Mobile sales and Mobile Service

    Hi All
    Can anybody help and explain me what are the major defferences between Mobile Sales and Mobile Service,What are the configuration settings required in Mobile Service,Because we have to start support project for Mobile Service.
    Regards
    Krishna

    Hi Krishna,
    The difference is Mobile Service is used by field technicians who provide a service to customers. Eg: an engineer who goes out to customer site to fix machinery. They can fill out the deatils on the Mobile Service application. Time spent, parts used etc..
    Sales is used by sales reps, who are selling a product.
    The configuration is the same for both. In fact its possible to have bothe sales and service installed on the same machine.
    Regards,
    Gervase

  • Can I share ring tones or alert tones purchased from iTunes between mobile devices?

    Does anyone know if there is a way to share ring tones or alert tones purchased from iTunes between mobile devices?  I purchased them on my iPhone and they come up on my computer but I cannot transfer them to my iPad.  Is it possible to share them between mobile devices like any other song?

    If you just want to select the whole song as your ringtone (without cutting out the best part) go to your computer and check were the file is saved. When found create a copy of it and rename its extension from m4a to m4r. Now drag&drop that file into itunes and there is your ringtone

  • How the communication take place between mobile to Desktop PC & vice-versa

    How the communication take place between mobile to Desktop PC & vice-versa
    Plz explain in flow way

    I am a student of BCS n final year n my final project is remote desktop capture of a pc using its ip from a mobile under nokia 6600 series.... I am new at this expecially java..
    can u guide me because i have searched a lot and could not find any help.
    can u plz plz help me...
    I have done some research work too n the module is divided into
    1. Communication between PC n application server
    2. Communication between application server n wap gateway
    3. Communication between way gateway and mobile
    Can anyone help/give a hint of how to proceed or what techonology to follow
    Waiting for your reply
    Leena Ali GIllani
    Peshawar, Pakistan

  • IPSec ikev2 between ASA and Cisco Router

    Hi,
    i try to do IPSec with ikev2 (SHA2) between ASA and Cisco Router, without success. Any one can help me ?
    - Remote site (Router) with dynamic public IP -> Dynamic crypto map on the ASA
    - Authentication with Certificats
    - integrity sha2
    I try a lot of configurations without success.
    Thanks for your help.
    Mic

    The more secure ike policy should have the higher priority which is a smaller number. So I would configure there the following way (policy 30 only if really needed):
    crypto ikev1 policy 10
    authentication pre-share
    encryption aes-256
    hash sha
    group 5
    lifetime 28800
    crypto ikev1 policy 20
    authentication pre-share
    encryption aes-256
    hash sha
    group 2
    lifetime 28800
    crypto ikev1 policy 30
    authentication pre-share
    encryption aes
    hash sha
    group 2
    lifetime 43200
    The Cisco VPN Client is EOL and not supported any longer. And yes, by default DH group 2 is used. But that can be configured by a parameter in the PCF-file.
    There are two (three) better options:
    Best option with very little needed configuration:
    Move to AnyConnect with TLS. AnyConnect is the actual Cisco client that is also supported with Windows 8.x. The legacy IPsec client isn't.
    Best option with a little stronger crypto but more configuration:
    Move to AnyConnect with IPsec/IKEv2. 
    Move to a third-party client like shrew.net. I didn't use that client since a couple of years any more, but it's quite flexible and also has a config for a better DH-group.
    For option 1) and 2) there is an extra license needed, but thats not very expensive.

  • HT4759 What is the difference between Mobile Me and iCloud?

    What is the difference between Mobile Me and iCloud?

    Mobile Me doesn't exist. It was shut down 2 years ago. iCloud is its replacement.

  • What is the difference between Mobile Engine and MI?

    hi all,
    i want to know the difference between Mobile Engine and MI and also what are the main advantages included in MI instead of ME.

    Hi Anusha,
    ME had MicroITS as UI.
    MI has JSP and AWT as UI programming.
    From the above discussion its clear that JSP is the best option for programming.
    PS: AWT was depricated by SUNMicro.
    I just thought of sharing the history of MI.
    just to share to you a "history" of mobile projects in SAP.
    the current MI was actually a merged project from two mobile
    projects - the old Mobile Engine and the unheard Mobile
    Development Framework (MDF). when these projects were
    restructured, the ME was extended with some functionalities
    such as the SmartSync which was actually the replication
    technology used in MDF. MDF client was based on C++ and
    uses the CEDB as the database. it was not chosen to be
    the client due to its platform-dependency. MDF was already
    a working product when the restructuring happened. and there
    were some client functionalities like xml based GUI and
    metadata/logic definition that the current MI client doesn't
    have.
    Hope this is helpful.
    Close the thread if your done with your clarification.
    Cheers,
    Karthick

  • Do the colored flags/ categories in mail transition between mobile devices?

    Do the colored flags/ categories in mail transition between mobile devices? I haven't seen anything that seems like it would allow me to flag different mail items on my iphone to reflect the colored flags in mail that I have categorized on my iMac. I find that I have to go through twice to categorize my flagged mail with the colors I've designated on my iMac if it's flagged from my iPhone.
    Thanks.

    I had the same issue, but with a macbook pro, imac, ipad and iphone 4G.
    everything worked fine until the addition of the iPhone 4G which made disappear mails that had been donwloaded/synced by the iphone and/or ipad.
    However I found a solution:
    In mail right click (ctrl left click) on the specific IMAP account inbox and select rebuilt.

  • Network LOD support for All Paths between 2 nodes

    In the in-memory Network API, there is a method NetworkManager.allPaths. This method returns available paths between 2 nodes with possible constraints. I am looking for a similar method in the LOD NetworkAnalyst class and am not finding it. Is there something similar?
    Or, here is what I want to do, and maybe there is a better way to do it. I am using NDM to data-mine our roadway inventory. Its a big network, whole state of Ohio, all roads--both local and state. One of the things I am trying to identify are what we call co-located routes. These are routes that have multiple names, for example, the ohio turnpike is both Interstate 80 and 90 on the same bed of road. In our line work, where these routes are co-located, we would only have a record for 80. The portion of 90 that we would have would be only in the case where it is NOT co-located with 80; in other words, 90 has a gap where it is co-located with 80. This is true for all our roads. In this case, we call 80 the primary, and 90 the secondary. We can have infinite secondaries (our worst case scenario is 6 routes overlapping). My situation in many cases, is I know that a route becomes secondary, I know how long the secondary section is, but I don't know what the primary is, so I want to discover it.
    Given these assumptions, I should be able to ask for all paths between 2 nodes that exactly match a cost (the overall length of the overlap). This should be simple with NDM. I provide a begin node, an end node, and a target cost, possible some traversal constraints, and it returns me the candidate paths. I thought that NetworkAnalyst.withinCost would do this, but as I discovered from the Stored Procedure docs, it returns the shortest path within the given less than or equal to the given cost--not necessarily the path I am looking for.
    Any advice? FYI, I am using Oracle 11GR2.
    Thanks, Tom

    So what I have come up with so far, is that the NetworkAnalyst trace methods provide this type of functionality. For example, with traceOut, I provide a start node, distance and some traversal constraints, and it returns me all paths less than or equal to the specified distance. What was throwing me a little with this method was the application of the LODGoalNode. I was thinking that the goal node would allow me to specify a particular node to be a requirement for the entire path such that a resulting path would have my start node, and end on a particular goal node with links in between. That IS NOT how it works. The LODGoalNode.isGoal is tested for EACH link that is part of a potential path, and only if this method returns true, is it added to the resulting path list.
    In my case, if I specified a start node and implemented the LODGoalNode.isGoal method such that it tested the provided end node for equality to my target node, the result would be that only links containing that specific goal node in the link. Anyway, so in my implementation, I leave the goalNode of the traceOut method null.
    So I have a new question. Is there a way to test when a path has been found, and then apply some constraints on it (PathConstraint)? This would be useful in cases where you get many paths returned to you, but in addition to a maximum distance constraint, you also want to apply for example a minimum distance on the resulting path, or that this is only a valid path if it ends on a particular node. Maybe there is a way to do this, and I haven't figured it out yet. The old AnalysisInfo class used to have a way to query the current path links and nodes, that would be useful in the LODAnalysisInfo class to help accomplish this perhaps? This feature isn't critical, because I can filter the list of paths returned from traceOut on my own after they are returned, but it would add some efficiency, especially when a large amount of paths are returned.
    Thanks, Tom

  • Difference between Interface node and normal node?

    What is the main difference between  Interface node and normal node?
    Cheers
    Aisurya.

    Hi surya,
    Interface node or methods comes into picture whenever you want to use one component as used component. I mean to say
    Component usages. If you select node as interface node, it will available in another component so you can use that node or methods.
    Normal node means in that component only. Simply we can say for component usages we go for interface nodes.
    Cehck This...
    http://help.sap.com/saphelp_nw70ehp1/helpdata/EN/79/555e3f71e41e26e10000000a114084/content.htm
    Cheers,
    Kris.

  • VXML RINGTONE SERVICE Problem - Call is not routed to agents

    We got below mentioned error in CVP Call Server logs for our calls. Due to this calls are not routed to agents.
    Apart from our call flow, I need to know what is the cause and solution of this error.
    Aborting XFER and disconnecting the caller code 488. RINGTONE SERVICE is not answering within 5000 millisecs, or the caller did not receive or accept the reinvite for ringtone media setup.  
    1646: 172.20.242.103: May 14 2014 11:50:07.701 +0300: %CVP_9_0_ICM-7-CALL: {Thrd=pool-1-thread-69-ICM-561} CALLGUID = 28D1273EDA6511E3999FDDDE4246E36C, DLGID = 112 [IVR_LEG] - Processing ,, [MsgBus:CALL_STATE_EVENT], ssId=SYS_IVR1, eventId=DISCONNECT, causeCode=NORMAL_COMPLETION,, LEGID = , DNIS = 9555210577, ANI = sip:[email protected]:5060
    1647: 172.20.242.103: May 14 2014 11:50:07.701 +0300: %CVP_9_0_ICM-7-CALL: {Thrd=pool-1-thread-69-ICM-561} CALLGUID = 28D1273EDA6511E3999FDDDE4246E36C, DLGID = 112 [IVR_LEG] - Publishing ,, [ICM_EVENT_REPORT], dialogueId=112, sendSeqNo=2, eventId=DISCONNECT, causeCode=NORMAL_COMPLETION,, LEGID = , DNIS = 9555210577, ANI = sip:[email protected]:5060
    1648: 172.20.242.103: May 14 2014 11:50:07.701 +0300: %CVP_9_0_ICM-7-CALL: {Thrd=pool-1-thread-69-ICM-561} CALLGUID = 28D1273EDA6511E3999FDDDE4246E36C, DLGID = 112 [IVR_LEG] - Deleted dialogue. Duration: 0 hrs, 0 mins, 0 secs, 109 msecs
    2017: 172.20.242.103: May 14 2014 11:50:07.717 +0300: %CVP_9_0_SIP-7-CALL: {Thrd=DIALOG_CALLBACK.7} CALLGUID = 28D1273EDA6511E3999FDDDE4246E36C LEGID = 28D25F8E-DA6511E3-99A5DDDE-4246E36C - [INBOUND]: Reinvitation proceeding TRYING.
    2018: 172.20.242.103: May 14 2014 11:50:12.685 +0300: %CVP_9_0_SIP-7-CALL: {Thrd=pool-1-thread-66-SIP-7351} CALLGUID = 28D1273EDA6511E3999FDDDE4246E36C LEGID = 28D25F8E-DA6511E3-99A5DDDE-4246E36C - [INBOUND]: Called ring leg: CALLGUID = 28D1273EDA6511E3999FDDDE4246E36C LEGID = 28D1273EDA6511E3999FDDDE4246E36C-140005740768575 - [RING-OUT]: status code = 0: elapsed msecs = 5000
    2019: 172.20.242.103: May 14 2014 11:50:12.685 +0300: %CVP_9_0_SIP-3-SIP_CALL_ERROR: CALLGUID = 28D1273EDA6511E3999FDDDE4246E36C LEGID = 28D25F8E-DA6511E3-99A5DDDE-4246E36C - [INBOUND]: Aborting XFER and disconnecting the caller code 488. RINGTONE SERVICE is not answering within 5000 millisecs, or the caller did not receive or accept the reinvite for ringtone media setup. (current=1 max=226) [id:5004]
    2020: 172.20.242.103: May 14 2014 11:50:12.685 +0300: %CVP_9_0_SIP-7-CALL: {Thrd=pool-1-thread-74-SIP-7355} CALLGUID = 28D1273EDA6511E3999FDDDE4246E36C LEGID = 28D25F8E-DA6511E3-99A5DDDE-4246E36C - [INBOUND]: Waiting 2000 millisecs before terminating.
    69088: 172.20.242.103: May 14 2014 11:50:12.873 +0300: %CVP_9_0_RPT-7-handleFakeNewCall: {Thrd=Thread-58} create fake New Call for >>HEADERS: (JMSType)=MsgBus:VXML_SCRIPT_DETAIL (JMSDestination)=Topic(CVP.VXMLSERVER.REPORT) (JMSTimestamp)=1400057412857 (ServerID)=cvp9lab2.SYS_VXML1:VXML:VXML1:cvp9lab2.MsgBus001 >>BODY: elementName=start elementid=1001871400057412857 timezone=Asia/Riyadh callguid=2BEF7F5ADA6511E399B0DDDE4246E36C localOffset=180 sessionname=172.20.242.103.1400057412842.21144.outbound ani=sip:172.20.243.187 howEventExited=1 sessionvars= sessionid=1001881400057412857 eventExitState=next uui=NA appName=outbound callStartDatetime=Wed May 14 11:50:12 AST 2014 elementTypeID=0 isNewCall=true vxmldatetime=Wed May 14 11:50:12 AST 2014 version=CVP_9_0 calltypeid=6 category=0 iidigits=NA dnis=sip:[email protected]:5060 >>STATE: isTabular=false isWriteable=false cursor=-1
    69089: 172.20.242.103: May 14 2014 11:50:12.873 +0300: %CVP_9_0_RPT-7-handleFakeNewCall : {Thrd=Thread-58} 2BEF7F5ADA6511E399B0DDDE4246E36C onHold start time: Wed May 14 11:50:12 AST 2014

    Hi,
    //After that the agent goes to Reserved state but the call doesn't come through.//
     I don't have experience on PCCE , but UCCE perspective this looks to me more like ATR(Agent Targeting rule) or Device Target Issue. Ringtone service should not cause Calls to fail.
    Can you please post log from CVP, for Particular call that faced this issue?
    Regards
    Chintan

  • Replication between 130 nodes and 1 Data Center

    Hi everyone.
    I have 130 database nodes (Oracle Standard Edition One) with a big distance of separation, and 1 Data Center with 3 nodes (Oracle Real Application Cluster 10g R2). The connection between nodes and datacenter is through various ISP ( WAN).
    I have exactly the same model design of database in nodes and datacenter.
    DataCenter is a repository of data for reporting to directors and dictate the business rules to guide all nodes.
    Each node have approximately 15 machines connected with desktop application.
    In other words Desktop Application with a Backend Database (node).
    My idea of replication is not instantly, when a transaction commit in a node then replicate to datacenter. Also over nigth replicate images because is heavy, approximately 1 mg per image. Each image correspond to one transaction.
    On the orher hand i have to replicate some data from datacenter to nodes, business rule, for example: new company names, new persons, new prohibitions, etc.
    My problem is to determine th best way to replicate data through nodes to datacenter.
    Please somebody could suggest me the best solution.
    Thanks in advanced.

    Last I checked, Streams and multi-master replication require enterprise edition databases at both ends, which rules them out for the sort of deployment you're envisioning.
    If a given table will only ever be modified on nodes or on the master site, never both, you can build everything as read-only materialized views. This would probably require, though, that the server at the data center have 130 copies of each table, 1 per node. For schemas of any size, this obviously gets complicated very quickly. For asynchronous replcation to work, you'd need to schedule periodic refreshes, which assumes that you have relatively stable internet connections between the nodes and the data center.
    I guess I would tend to question the utility of having so many nodes. Is it really necessary to have so many? Or could you just beef up the master and have everyone connect directly?
    Justin
    Distributed Database Consulting, Inc.
    http://www.ddbcinc.com/askDDBC

Maybe you are looking for

  • BAPI to create sales order

    Hi friends i am facing problem in this code , i tried a lot but still some errors are coming  can you please suggest how to remove the errors, anwers will be rewarded , thanks in advance *& Report  Z_TEST_BAPI REPORT  Z_TEST_BAPI. data : ORDER_HEADER

  • Using the Remote App and playing iTunes from a shared Library

    I have a playlist set up in my main iTunes library on my iMac.  This is a shared library on my local network at home.  I can access and play the library remotely from my MacBook.  I want to move my MacBook outside with external speakers for a party. 

  • Delete from dimension

    Hello All, I need to compare my dimesnion to the fact tables that use this dimension and delete all the rows in the dimension with the Sks that are not being used on the fact tables. I wrote a query to get all the Sks that are not being used. Now how

  • Feathers font size

    Hi everybody, I started a project with feathers ( starling ) for android, but I try to understand some things... why the scale of objects and texts is too much different in devices? I try my demo in "xperia mini pro" ( 320 x 480 ) and in a "xperia s"

  • Safari 3.0.4 crash on startup

    All was working well; don't know what I did, but I did it big. Now Safari crashes when attempting to start up. Here is the Crash Report. I can see the thread it crashed on, but don't know how to interpret the report. Can anyone help? Thanks! Pam B. D