L2L VPN connection-type with multiple peers in both sides
Hi tech guys. We have a problem with the connection-type (aka vpn initiator) due to we have two peers (two isp) in both sides of the vpn tunnel...
We need to find a way to can get a one-way initiator vpn. That's easy with only one side with dual isp, dual isp side is answer-only and the single isp side is originate-only, but it become a problem when the single isp side upgrades to dual isp.
It's possible to add a second crypto map setting for the same traffic, the same encryption, but different policy and peer and also as ANSWER-ONLY?
eg.
Cryto map for the first peer...
crypto map outside_map 20 match address outside_20_cryptomap (Same traffic)
crypto map outside_map 20 set connection-type answer-only
crypto map outside_map 20 set peer xxx.xxx.xxx.xxx (Primary ISP for the remote side)
crypto map outside_map 20 set transform-set ESP-3DES-SHA
Cryto map for the second peer...
crypto map outside_map 25 match address outside_20_cryptomap (Same traffic)
crypto map outside_map 25 set connection-type answer-only
crypto map outside_map 25 set peer xxx.xxx.xxx.xxx (Second ISP for the remote side)
crypto map outside_map 25 set transform-set ESP-3DES-SHA
Please help to see if it is possible, thanks.
Crypto map with different Ids is the way to create multiple crypto maps. This is a working configuration
Similar Messages
-
Logical Standby Database with 10g+ASM on both sides??
Hi out there,
is there a known way to establish a logical standby database on 10g, if both
sides are running with an ASM setup?
I've tried to create one out of a physical standby database (which is set up
and running w/o any problems), like a book suggested me to do.
The procedure was:
1. switch on supplemental logging
2. prepare initiation parameters (for archive logging etc.) on both sides for
logical stb.
3. shut down the phyiscal standby
4. alter database create logical standby controlfile as '<path>'; on the
primary, transfer the controlfile to the standby db. Here I had to use RMAN
to copy the controlfile into the ASM System, and modify the initfile/spfile
in order to use the controlfile. No problem so far.
5. mount the standby database, alter database recover managed standby database
disconnect; -> At this point, the alert log complained about non-available
datafiles.
6. alter database activate standby database; --> fails ("needs recovery") due
to last point.
The trouble is, the controlfile created at point 4 cointains wrong paths to
the datafiles. Since I can not have the same disk group name on the standby
system, and since ASM renames the stored datafiles by its own, the complaints
of point 5 are comprehensible, but nevertheless annoying.
I tried to backup a controlfile to trace and change the paths, but at after
mounting the standby with this controlfile and proceeding at point 5, the
system says "<path> is not a standby controlfile"
Is there a different way of creating a "Logical Standby Database with 10g+ASM
on both sides"? Metalink said nothing about LogStby and ASM.
Best regards and thanks in advance,
MartinI'm not sure if this will work but try:
1. create trace control file (you did it)
2. change paths (you did it)
3. recrate control file (you did it)
... there was error occured during mount before
so mount database (not as standby)
4. create standby control file (from recreated control file)
5. shutdown instance, replace control file with new standby control file or replace the control filename in parameter file.
6. mount as standby
What happend?
Update: Tested on my side and it has worked fine... How about you?
Message was edited by:
Ivan Kartik -
Is it/shouldn't it be possible to order postcards with full image on both sides?
Is it/shouldn't it be possible to order postcards with full image on both sides?
Yes, you can create such a card. This example is the folded Holiday Colors theme. Just choose the layout for the inside that includes a full page photo on top and text on the bottom.
OT -
I ordered prints from Apple. They came back with the people on both sides cut off. How do I correct the problem?
crop to the print size before ordering - for example you can not fit a 8x12 iomage onto a 8 x10 sheet of paper
LN -
Cisco vpn connect problem with 3g dongle
Hi,
I am trying to connect cisco vpn but every time i am getting following error while trying to connect from huawei 3g usb dongle in win8. for win7 it works fine with no issue. Also the problem is only form datacard, form lan and wireless interaface i can easily connect to vpn without any issue. Any help/idea/suggestion highly appreciated?
Cisco Systems VPN Client Version 5.0.07.0440
Copyright (C) 1998-2010 Cisco Systems, Inc. All Rights Reserved.
Client Type(s): Windows, WinNT
Running on: 6.2.9200
25 08:06:46.846 12/25/13 Sev=Info/4 CM/0x63100002
Begin connection process
26 08:06:46.848 12/25/13 Sev=Info/4 CM/0x63100004
Establish secure connection
27 08:06:46.848 12/25/13 Sev=Info/4 CM/0x63100024
Attempt connection with server "116.68.208.113"
28 08:06:46.849 12/25/13 Sev=Info/6 IKE/0x6300003B
Attempting to establish a connection with 116.68.208.113.
29 08:06:46.855 12/25/13 Sev=Info/4 IKE/0x63000001
Starting IKE Phase 1 Negotiation
30 08:06:46.858 12/25/13 Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Frag), VID(Nat-T), VID(Unity)) to 116.68.208.113
31 08:06:47.145 12/25/13 Sev=Info/4 IPSEC/0x63700008
IPSec driver successfully started
32 08:06:47.145 12/25/13 Sev=Info/4 IPSEC/0x63700014
Deleted all keys
33 08:06:52.144 12/25/13 Sev=Info/4 IKE/0x63000021
Retransmitting last packet!
34 08:06:52.144 12/25/13 Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK AG (Retransmission) to 116.68.208.113
35 08:06:57.144 12/25/13 Sev=Info/4 IKE/0x63000021
Retransmitting last packet!
36 08:06:57.144 12/25/13 Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK AG (Retransmission) to 116.68.208.113
37 08:07:02.145 12/25/13 Sev=Info/4 IKE/0x63000021
Retransmitting last packet!
38 08:07:02.145 12/25/13 Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK AG (Retransmission) to 116.68.208.113
39 08:07:07.145 12/25/13 Sev=Info/4 IKE/0x63000017
Marking IKE SA for deletion (I_Cookie=97205EA6A12866F0 R_Cookie=0000000000000000) reason = DEL_REASON_PEER_NOT_RESPONDING
40 08:07:07.645 12/25/13 Sev=Info/4 IKE/0x6300004B
Discarding IKE SA negotiation (I_Cookie=97205EA6A12866F0 R_Cookie=0000000000000000) reason = DEL_REASON_PEER_NOT_RESPONDING
41 08:07:07.645 12/25/13 Sev=Info/4 CM/0x63100014
Unable to establish Phase 1 SA with server "116.68.208.113" because of "DEL_REASON_PEER_NOT_RESPONDING"
42 08:07:07.645 12/25/13 Sev=Info/5 CM/0x63100025
Initializing CVPNDrv
43 08:07:07.645 12/25/13 Sev=Info/6 CM/0x63100046
Set tunnel established flag in registry to 0.
44 08:07:07.645 12/25/13 Sev=Info/4 IKE/0x63000001
IKE received signal to terminate VPN connection
45 08:07:08.146 12/25/13 Sev=Info/4 IPSEC/0x63700014
Deleted all keys
46 08:07:08.146 12/25/13 Sev=Info/4 IPSEC/0x63700014
Deleted all keys
47 08:07:08.146 12/25/13 Sev=Info/4 IPSEC/0x63700014
Deleted all keys
48 08:07:08.146 12/25/13 Sev=Info/4 IPSEC/0x6370000A
IPSec driver successfully stopped
49 08:19:59.202 12/25/13 Sev=Info/4 CM/0x63100002
Begin connection process
50 08:19:59.202 12/25/13 Sev=Info/4 CM/0x63100004
Establish secure connection
51 08:19:59.202 12/25/13 Sev=Info/4 CM/0x63100024
Attempt connection with server "116.68.208.113"
52 08:19:59.202 12/25/13 Sev=Info/6 IKE/0x6300003B
Attempting to establish a connection with 116.68.208.113.
53 08:19:59.202 12/25/13 Sev=Info/4 IKE/0x63000001
Starting IKE Phase 1 Negotiation
54 08:19:59.218 12/25/13 Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK AG (SA, KE, NON, ID, VID(Xauth), VID(dpd), VID(Frag), VID(Nat-T), VID(Unity)) to 116.68.208.113
55 08:19:59.656 12/25/13 Sev=Info/4 IPSEC/0x63700008
IPSec driver successfully started
56 08:19:59.656 12/25/13 Sev=Info/4 IPSEC/0x63700014
Deleted all keys
57 08:20:04.656 12/25/13 Sev=Info/4 IKE/0x63000021
Retransmitting last packet!
58 08:20:04.656 12/25/13 Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK AG (Retransmission) to 116.68.208.113
59 08:20:09.656 12/25/13 Sev=Info/4 IKE/0x63000021
Retransmitting last packet!
60 08:20:09.656 12/25/13 Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK AG (Retransmission) to 116.68.208.113
61 08:20:14.656 12/25/13 Sev=Info/4 IKE/0x63000021
Retransmitting last packet!
62 08:20:14.656 12/25/13 Sev=Info/4 IKE/0x63000013
SENDING >>> ISAKMP OAK AG (Retransmission) to 116.68.208.113
63 08:20:19.656 12/25/13 Sev=Info/4 IKE/0x63000017
Marking IKE SA for deletion (I_Cookie=46B8917FD54C64AC R_Cookie=0000000000000000) reason = DEL_REASON_PEER_NOT_RESPONDING
64 08:20:20.156 12/25/13 Sev=Info/4 IKE/0x6300004B
Discarding IKE SA negotiation (I_Cookie=46B8917FD54C64AC R_Cookie=0000000000000000) reason = DEL_REASON_PEER_NOT_RESPONDING
65 08:20:20.156 12/25/13 Sev=Info/4 CM/0x63100014
Unable to establish Phase 1 SA with server "116.68.208.113" because of "DEL_REASON_PEER_NOT_RESPONDING"
66 08:20:20.156 12/25/13 Sev=Info/5 CM/0x63100025
Initializing CVPNDrv
67 08:20:20.156 12/25/13 Sev=Info/6 CM/0x63100046
Set tunnel established flag in registry to 0.
68 08:20:20.156 12/25/13 Sev=Info/4 IKE/0x63000001
IKE received signal to terminate VPN connection
69 08:20:20.156 12/25/13 Sev=Info/4 IPSEC/0x63700014
Deleted all keys
70 08:20:20.156 12/25/13 Sev=Info/4 IPSEC/0x63700014
Deleted all keys
71 08:20:20.156 12/25/13 Sev=Info/4 IPSEC/0x63700014
Deleted all keys
72 08:20:20.156 12/25/13 Sev=Info/4 IPSEC/0x6370000A
IPSec driver successfully stoppedHi Karsten,
Thank you for the reply !!! & best wishes for the new year 2014.
The problem is like this, if i select datacard connection type to NDIS it works but it doesnt work when i select RAS(modem) connection type for 3G datacard it doesnt. (NDIS and RAS(Modem) connection types are the 2 modes currently supporetd by the datacard.). Is there any case the users are experiencing from the similar problem? and what they have done to solve the issues? And thank you for the workaroung, i have checked the shrew-soft with win7 and it was working fine but not on win8, i will check shrew-soft on win8 very soon. Also we can move to the anyconnect solution but just want to know if this can solve our problem or not? whether there will be any issues with anyconnect solution for win 8 or not? can you please confim.
Thank you -
When my clients connect their CMAK-created VPN, it fails to run the script to set their routing table with the following error:
Custom script (to update your routing table) failed (8000ffff)
My objective is to create a VPN connection with split tunneling - does not use the VPN connection as the client's default gateway.
All my clients are on Windows 8.1 64-bit, and are logged in with Administrative privileges
My VPN Clients are on 10.242.2.0/24, my internal network is on 10.172.16.0/24
I want only traffic for 10.172.16.0 to go via the VPN. Everything else should go via the client's internet connection
My Connection Manager Administration Kit profile, was created on Windows 2012 R2 CMAK with the following settings:
"Make this connection the client's default gateway" is UNticked on the IPv4 tab.
Define a routing table update is specified with a text file containing:
+++ Start of txt file +++
REMOVE_GATEWAY
add 10.172.16.0 mask 255.255.255.0 default metric default if default
+++ End of txt file +++
The txt file is saved in DOS/Windows format (not Unicode or UTF-8 which I've read causes problems)
I've tried everything in lower and upper case in the txt file after reading that the file might be case sensitive
The following appears on the client with logging enabled:
[cmdial32] 10:42:34
03 Pre-Init Event CallingProcess = C:\WINDOWS\system32\rasautou.exe
[cmdial32] 10:42:40
04 Pre-Connect Event ConnectionType = 1
[cmdial32] 10:42:40
06 Pre-Tunnel Event UserName = UserName Domain = DUNSetting = VPN (L2TP x64 NoGW) Tunnel DeviceName = TunnelAddress = vpn.mydomain.tld
[cmdial32] 10:42:43
07 Connect Event
[cmdial32] 10:42:43
09 Custom Action Exe ActionType = Connect Actions Description = (none) ActionPath = CMDL32.EXE. The program was launched successfully.
[cmdial32] 10:42:43
08 Custom Action Dll ActionType = Connect Actions Description = to update your routing table ActionPath = C:\Users\UserName\AppData\Roaming\Microsoft\Network\Connections\Cm\VPN64\CMROUTE.DLL ReturnValue
= 0x8000ffff
[cmdial32] 10:42:43
21 On-Error Event ErrorCode = -2147418113 ErrorSource = to update your routing table
[cmdial32] 10:42:43
13 Disconnect Event CallingProcess = C:\WINDOWS\system32\cmdial32.dll
Where can I find out what error codes 8000ffff or -2147418113 mean?That was it. Thanks, Steven
"By default, the dial-up entry and the VPN entry have Make this connection the default gateway selected.
Leave this default in place, and remove any gateways by using the REMOVE_GATEWAY command in the routing table update file itself."
It seems counter-intuitive to leave
Make this connection the default gateway selected, when I specifically don't want that behaviour, but leaving it selected and using REMOVE_GATEWAY works for me. -
Hi,
I chose the wrong connection type when setting up VPN. I selected PPTP instead of IPSEC. How do I change it?Hi,
Thanks for your reply. When I do that and then add a new one it just adds another configuraion but still using PPTP.
Even in Internet Connect it has VPN(PPTP) as the name of the tab beside Airport and Bluetooth tabs.
How do I start from scratch? i.e. make it give me the choice of IPSEC or PPTP like when I launched VPN first? -
Printer printing with truncating characters on both sides using Style PDF
Hi,
DB:11.1.0.7.0
Oracle Apps: 12.1.1
OS:Linux Red Hat 86x64
We are using Printer name XYZ with Printer Type: HPLJ4SI
Style: PDF Publisher
Driver:PASTA_PDF
Issue: The same printer works fine in DEV env but not in INT env.
What could be the issues here and where could be the fix?
Could anyone please share such an issues faced before?
Thanks for your time!
Regards,Hi,
Yes.Verified.
Printer style: PDF Publisher :
User style: PDF Publisher
Layout: Columns: 132 Rows :55
Report Definition:
Output Format: XML
Columns: 132
Rows: 45
Style: PDF Publisher
Exactly the same setups are there in both the environments but still it's printing with truncated characters at both left and right margins of the page in INT only.
In DEV it's printing fine.
So, now where else could we be looking for the fix.
Thanks, -
SSL VPN Connection error with SA520
Hi there,
I have an SA520 setup and all my users can login to the SSL VPN tunnel except one user. The laptop is running windows 7 64bit and had IE9 installed. When I try to connect her to use an SSL VPN Tunnel, I get the following error: Cisco-SSLVPN-Tunnel Install Failed: Error in getting proxy settings!.
I have made sure the firewall was turned off. Any idea on how to get the ssl tunel connected?
ThanksHihi,
we have the same problem, running on Vista 32 bit, and IE9.
On the same machine, using virtual PC and emulating an XP environment it works, what a paradox!
It works also on Win 7 64 bit, although only with the 64 bit version of IE.
Coming back to our Vista issue, we did not find any way to make it work properly.
Tried to turn off firewall, disinstall a lot of stuff that may interphere, etc. , still same problem.
We are a bit annoyed there seems to be no documentation about this error nor troubleshooting help.
Anyone has any suggestion ??
Tks -
Remote Desktop Connection problem with multiple Lenovo machines
Hello,
I've been running into issues with connecting to some of the latest Lenovos we purchased using RDP. It has happened with a batch of 3 x220s and a batch of 2 Thinkstation C20s (possibly others that I haven't yet had to remote into).
The symptoms are maddening in the paucity of information given for the failure. It basically goes like this -- type in the name of the computer and hit connect. Immediately I get a "this computer can't connect to the remote computer"; it's so sudden that it seems to be getting rejected immediately. I've check every windows log (even the ones under Applications and Services) and the ONLY thing logged (on the destination computer) is that an RDP session was initiated. NO reason is given for the failure. No error event given.
Has anyone else run into this? I'm having to use 3rd party software to log in to computers, which is becomming a nuisance as I am trying to set up computers at a branch office for new users. Is there some way to debug RDP? I ran a packet sniffer and a total of 6 packets are passed for these "sessions" -- mostly TCP handshake packets at that, and only one actual RDP packet. Is there a more verbose log I should be looking at?
Any help would be greatly appreciated!If you can't connect to your new or restored Lenovo with the OEM install of Windows 7, it may very well be that the particular registry key below is not set to the typical default value (I think Lenovo has messed up their OEM install image). The two secrity packages 'tspkg' and 'pku2u' are missing on OEM Lenovo images.
This registry key:
HKLM\system\currentcontrolset\control\lsa\security packages
Should look like this:
kerberos msv1_0 schannel wdigest tspkg pku2u
Fix it and RDC will connect.
(may need a reboot to take effect) -
VPN Concentrator authentication with multiple domains
I have a hub and spoke network where a T1 comes in to the hub site A and there is a frame relay connection going over to the spoke site B. We want to add a VPN concentrator to site A for remote access but site A and site B have their own domains that are independant of one another. Can I set up the VPN Concentrator to authenticate users that belong to site A domain using site A's domain controller and authenticate users the belong to site B domain using site B's domain controller? That way we can use a single VPN concentrator and a single internet connection but keep the authentication seperate.
Thanks in advance for any help.To authenticate users that belong to site A domain using site A's domain controller you should authenticate users the belong to site A domain using site A's domain controller
-
JDBC connection issue with multiple DBs on same instance
I have two databases on one sql server 2012 instance. One called 'demotime' the other called 'demotime_dev'. how ever when I change in my JDBC connection the DB from demotime to demotime_dev. the connection still remains established with
the demotime, is there any known reason to cause this? does both being on the same instance have anything to do with the problem?Do your application may send a "USE [demotime]" command to Switch to the database? Do you may use a config file in your application where the database is still pointing to the other database?
Olaf Helper
[ Blog] [ Xing] [ MVP] -
Generics: Requiring a generic type with multiple super-interfaces
Is it possible to use generics to require that a type be a composition of two superclasses? For instance, let's say that I have a method that serializes a List. Since the List interface is not itself serializable (but most List implementations are), I cannot have a compile-time guarantee that a method with the following signature will succeed:
public void serializeList(List serializableList);
However, could I use generics to construct a new signature (sorry about bad generics syntax) like this:
public void serializeList(<? extends List, Serializeable> serializableList);
Thanks.It's not exactly generics, you want the object to implement both List and Serializable. Generics would let you declare that the List should contain only Serializable objects (don't ask me to write the declaration though).
However you can't even guarantee that a Serializable object can be serialized reliably, since it could contain (directly or indirectly) a reference to an object that isn't serializable. So I wouldn't work too hard on solving that problem. -
One STO Type with multiple Delivery Types
Hi,
We have a requirement in our company, In the STO line item level we have Shipping Tab in that we will get the delivery type based on the configuration u201CAssign Delivery Type and Checking Ruleu201D here we assign in the combination of STO document type and supplying site and delivery type,
Our client requirement is that can we assign multiple delivery type's for the same STO document type and supplying site, if yes on what bases we need to differentiate the same.
This is because we need the different functionality I.e. for one type deliveries we need the packing mandatory and other type of deliveries we have not require the packing functionality.
Thanks & Regards,
Murali.MHi,
i don't think it's possilbe to have more then one delivery type per sto.
Check if you have the possiblity to set up an dependent layout. E.g. if Material A is a FERT then do packing, if HALB not, etc.
regards, Paul. -
One to Many with multiple tables on One side and one table on Many side
Sorry for the confusion in the title. Here is my question. In my program, I have 2 different tables which store 2 different type of entities. Each one of entities has a list of attachments which I stored in a common attachment table. There is a one-to-many relationship between entity tables and attachment table.
ENTITY_ONE (
ID
NAME
ENTITY_TWO (
ID
NAME
ATTACHMENTS (
ID
ENTITY_ID
ATTACHMENT_NAME
ENTITY_ID in ATTACHMENTS table is used to link attachments to either entity one or entity two. All IDs are generated by one sequence. So they are always unique. My question is how I could map this relationship into EntityOne, EntityTwo and Attachment JAVA class?For EntityOne and EntityTwo you can just define a normal OneToMany mapping using the foreign key.
Are you using JPA, or the TopLink API? JPA requires a mappedBy for the OneToMany, so this may be more difficult. You should be able to just add a JoinColumn on the OneToMany and make the column insertable/updateable=false.
For the attachment, you could either map the foreign key as a Basic (DirectToFieldMapping) and maintain it in your model, or use a VariableOneToOne mapping in TopLink (this will require the entities share a common interface).
James : http://www.eclipselink.org : http://en.wikibooks.org/wiki/Java_Persistence
Maybe you are looking for
-
How to make curved lines in image more smooth and clear
How do i make this clear its and image, i want to make the lines really clear and smooth
-
How to pass the bind variable value to the sql statement of the LOV
Hi, I am using Forms 10g builder. I have a text item which will be populated by a LOV when i press a button, but i have a bind variable in the SQL statement of the LOV. That bind variable should be replaced by a value which is derived from a radio gr
-
The new cover flow style in ios 7 is not as nice as the ios 6??
iOS7, why Apple designed such a lack thing like this?? ****!! it doesn't feel so as comfortable as the iOS6. I really like iOS 6 than iOS7, but there is no way to turn back,, so hopeless!! and the iOS is like a copying of Microsoft's Windows 8, why A
-
how can i have select-options in function module?
-
Iphoto keeps crashing, even when starting with command-option,
does anybody have an idea ???? tried the normal steps, with the disk permission, deleten plist, and tried twice to start with command-option... here is the crash-log.... thanx, magdonnellen Mac OS X Version 10.4.11 (Build 8S165) 2011-01-03 08:12:59 +