Need ASA DHCPD log with client hostname

I recently switched from a Linux DHCP server to using DHCPD configuration on Cisco ASA 8.4 code.  With the Linux DHCP servers, the logs showed the hostname of the requesting DHCP client.  Unfortunately, I'm not seeing the hostname information in the DHCPD logs from the ASA.  How can I get the ASA to log the clients' hostname?
Thanks

I've got the Cisco VPN client 5.x setup with connection profile to Tunnel Group name and pre-shared key.
Client is communicating with the ASA and is getting prompted for user login.  I have the ASA configured for aaa radius authentication to MS IAS on Windows 2003K server.   Experimenting on the IAS side between the IAS config "connection policies" and AD user profile.  I can now assign a static IP address to the remote VPN client which is nice!  This can be done two ways... either in IAS connection profile or in AD user profile.  What I'm working on next is having the IAS server pass back to the ASA (radius client) a acl list # (filter.id = 80.id) where I have an access-list 80 statement defined.  Not finished up with setup.  Any advice/input on this piece would be helpful.
The basic goals of this exercise/project include:
1.  Remote Cisco VPN users authenticating with AD.
2.  Pre-configured .pcf file created and deployed to remote users.
3.  Unique static IP's assigned to all VPN users for audit purposes (or troubleshooting).
4.  Apply ACL's to VPN users based on their assigned static IP so I can control what subnet's/IP's they can reach.
So far so go... We are a month or so away from implementing our first Windows 2008 server, so I'm fine with getting this to work for our 20-30 remote users with IAS in Win2Kserver environment while I get educated on NSP.
Joe

Similar Messages

  • I need timed data logging with continuous graphing

    I am graphing continuous temperature measurements, but I only want to log onto a spreadsheet measurements every hour. How do I do that?

    Hello,
    In order to log the measurements every hour, you will want to implement a "Wait (ms)" function. This function can be added to the block diagram by [right-clicking] and selecting the following:
    [All Functions] >> [Time & Dialog] >> [Wait (ms)]
    You will want to place this wait function inside your code and wire a constant to the wait function with a value of 3,600,000 (60min/hr x 60sec/min x 1000ms/s). To wire a constant to the wait function, [right-click] on the input terminal of the "wait (ms)" icon and select [Create]>>[Constant].
    I hope this helps. Please let me know if I can further assist you.
    Kind Regards,
    Joe Des Rosier
    National Instruments

  • Client Hostname

    Feature request: Client Hostname.
    Our HIS/RIS system launches certain PACS viewer based on which Windows name the PC has. Even if we connect via RDP to a PC which has the "right" name it doesn't matter -- the home computer's Windows name must be set right. Otherwise the wrong default
    viewer is launched via the HIS/RIS - PACS integration
    Some RDP clients like CoRD.app allow to set this "Client Hostname" or "fake" hostname.
    I wish also Microsoft Remote Desktop.app had a setting for the Client Hostname.
    thanks,

    Of course I must enter the "Connection name = whatever" and "PC name = 12.34.56.78" in Microsoft Remote Desktop.app.
    But in addition to that I need an option to set "Client Hostname" i.e. the Windows name the RDP connection uses...
    ...initially I thought that if I launch a RDP terminal services connection from home to a PC named "work", it behaves as if I was using the "work" PC. But some resources DO NOT use the remote PC as is...
    So if I connect from home to work via RDP, I must set the RDP client so that it really behaves as if I'm really using a PC at work:
    If a set up VMware and Windows 7 on OS X, I must set the Windows 7 "Computer name" as "work". Or set the RDP "Client Hostname" as "work".
    So I miss an option to set Microsoft Remote Desktop.app "Client Hostname" as "work".

  • Need to be logged in to get help with logging in? ...

    While this is obviously a vent, I really would welcome suggestions for password help in the future. Here goes...
    We don't use Skype often, but when we want to use it, we want to use it NOW. Because we don't use it often, we forget the Skype name and password between times. Yes, we should have a way to remember it, but this is 2015 and we expect a tool to help us out a little bit in our busy lives.
    The first step is to remember our Skype name. Since we had to pick a unique one, it's not something we use for anything else and we don't remember what we had to come up with on the fly when we signed up for Skype. Fortunately, we did keep the welcome email from when we signed up and it has our Skype name in it. Great!
    Ok, next we need our password. Nothing we type is working. We click to request a password reset and an email is supposed to be sent to us.  One would think it would arrive immediately, but no. We requested it more than 2 hours ago and have not received anything. And no, it is not in the Spam/Junk folder either. We know the code will only be good for 3 hours. Where the heck is the email to tell us what it is?? If this were a one-time circumstance where it didn't arrive right away, that would be forgivable, but this has happened before. No email, or at least not until several hours later.
    Ok, with no reset email, we keep trying different passwords and none work. Now we're notified that we're locked out and need to wait to try again. Did I mention we want to use Skype NOW? We don't want to wait over 2 hours for an email (which still hasn't arrived). We don't want to be locked out for 24 hours. We want to Skype... NOW.
    Ok, we need customer support help. Where is the customer support number? Doesn't seem to be one. Where is the live chat button? Need to pay for that. Well, email takes forever, but at least it gets a message straight to Skype that we need help so we'll go that route. Guess what, you need to be logged in to be able to send an email for support. Are you kidding me?? I need to be logged in to tell you I can't get logged in.
    Ok, the only other option for help is the community. The existing posts aren’t helping me, and I can't post anything new unless I'm... get this... logged in. I cannot believe there is no way to get a message to anyone connected with Skype unless I'm logged in.
    Out of total desperation, I created a new Skype account. And going against all best practices for security, we have written down the odd user name we needed to choose, as well as the new password. Out of the 300 million Skype accounts that exist, I can't help but think some 200 million of them are extra accounts people needed to create because they couldn't get their password reset.
    I'll end my venting there. If anyone has any insights on more I could've/should've tried to get my password reset IN A TIMELY MANNER, please share. I would not be surprised if the reset code email eventually arrives, but if it's going to take 2+ hours to get it to me, don't even bother. 

    In case anyone needs it, this seems to be the thread that MS is following the closest:
    http://answers.microsoft.com/en-us/windows/forum/windows_tp-winipp/build-9879-windows-feedback-app-doesnt-recognize/6fc9b35b-8141-4045-b17a-f53ecd5ca6ae

  • SCCM Client entry in SCCM console for new VM with same hostname

    HI,
    I have Hyper V server with several VM's running with server OS. Recently I have stopped 2 VM's with OS windows server 2008 & 2012 & recreated new VM's with same hostnames & IP addresses. Problem is I am unable to install SCCM client on New VM
    as old enrty lies in SCCM consle with client status Active. I tried to uninstall the client from console, But its showing "can not ping".
    So is it ok to simply delete this entry from console so new entry will come in front?

    Hi,
    You can delete the object in the SCCM Admin Console,you can also install the client manually and then they will register again creating a new object with the same name.
    Regards,
    Jörgen
    -- My System Center blog ccmexec.com -- Twitter
    @ccmexec

  • ORACLE_HOME/log/diag/clients folder with no ADR. What it is for?

    Hi,
    I'm behind a troubleshooting in a 11.2.0.1 DB, and for it I enabled sqlnet trace level 16 for both server and client (since the issue is related with Nagios connections running on the same server). [So, this is my first time testing with traces]
    I'm also familiarized with ADR structure and adrci commands so I wanted to keep it, but no for sqlnet client traces generated by root user.
    This is my configuration. I move adr/traces to a separate volume, so I wont scary if they growth too much:
    parameter diagnostic_dest=/mnt/tracesvol/ADR/
    $ORACLE_HOME/network/admin/sqlnet.ora
    TRACE_LEVEL_CLIENT=16
    TRACE_LEVEL_SERVER=16
    /root/.sqlnet.ora
    DIAG_ADR_ENABLED = off
    TRACE_LEVEL_CLIENT = 16
    LOG_DIRECTORY_CLIENT = /mnt/tracesvol/client/
    TRACE_DIRECTORY_CLIENT = /mnt/tracesvol/client/
    TRACE_TIMESTAMP_CLIENT = on
    This configuration writes all the server traces in the new ADR repository destination, and sqlnet client traces by root user in /mnt/tracesvol/client/ folder without ADR (cli_*.trc trace files). Trace files were generating on them as expected.
    The problem is that our sysadmin found the folder /root/oradiag_root/diag/clients/user_root/host_486939793_76/ with several trace files. In its subdir ./alert/, the log.xml said that $ORACLE_HOME/log/diag does not exist. So, we created that folder (but I dont know why he was looking for this folder. As I see on Parameters for the sqlnet.ora File he only looks for this folder if ADR is enabled and no $ORACLE_BASE variable is defined [but I've disabled ADR in /root/.sqlnet.ora]).
    After that , we found that the folder $ORACLE_HOME/log/diag/clients/user_root/host_486939793_76/ were generating new trace files, with the format ora_*_*.trc, but they dont content the same traces as /mnt/tracesvol/client/cli_*.trc has
    What is this folder and all these traces, and who generate them?
    Regards

    Hi,
    I think you answered most of your own questions.
    I found your post because I was looking at een exploding /var/tmp/oradiag_<client>/diag/clients.
    It appears that if the unix user who connects via the oracle client does not have a $ORACLE_BASE variable defined, the oracle client write to the $ORACLE_HOME/log/diag/clients.
    But if the $ORACLE_HOME/log/diag does not exist, it uses /var/tmp to put trace and alert logs in.
    regards

  • Need help to log off iTunes - the tab with the current Apple-iD is "greyed" out.

    Need help to log off iTunes -> the tab with the current Apple-iD is "greyed" out. Can anyone help me?

    Do you have Restrictions turned on?

  • Need help with client identifier & DHCP

    I have created static hosts for all of my clients (interim measure until I get DNS servers built and running) on an SG300-20. I defined all of these allocations using MAC addresses.
    However, several of my clients (1 Windows 7 workstation, 2 FreeNAS / FreeBSD storage servers and 1 HP color Laserjet printer) are still being dynamically assigned other addresses based on client identifier.
    In all four cases, the client identifier being used by the switch is the MAC address with a leading "01" octet attached.
    For example, my workstation has a MAC address of 00:10:18:E3:64:2F, which is defined as a static host based on that MAC address. The switch is using a client identifier of 01:00:10:18:E3:64:2F.
    I am sure that I need to be entering a client identifier in the static host instead of the MAC address. From the discussions that I have read on here, that should look something like 0100.1018.e364.2f, but the static hosts GUI will not accept that. It won't allow me to type periods at all, and it won't accept 0100:1018:e364:2f, so I am clearly not entering this correctly.
    Any help on how to resolve this / how the GUI is expecting the client identifier to be formatted?
    Thanks!

    To me that's a bug. You can't know how to enter a host into the static bind table until you know whether it wil provide a client id. Like you said if you enter a MAC and comes up with a client id it doesn't recieve the assigned ip, if you assume the client id based on 01+MAC and it doesn't end up presenting a client id again the host doesn't get the assigned ip.
    For years with dumber switches I could take a list of MACs and enter them on my switches so that when a device came online if their default was dhcp it would obtain the address I wanted and I'd know where to find it. Now with these "smarter" switches I have to work harder so in some regards these switches are dumber than an Best Buy off the shelf switch.
    You should be able to fill in the MAC value and the switch should auto-complete the client id assuming a 01 prefix that cna be changed. Both values should be editable and maintained in their own tables for each host entry.

  • Web service client needs to share data with a SOAP Message Handler

    I have a web service client that is built using WebLogic 10 clientgen. I also have a Soap Message Handler configured that will create the required Soap Headers for the web service call.
    Creating these Soap Headers works great as long as the header data is static but the problem comes up when I need to place some dynamic data in these headers. The web service client has this data and somehow needs to pass it to the Soap Message Handler. It looks like I need to somehow have the client place this data in the MessageContext before the call so the data can be accessed by the Soap Message Handler.
    How do I get access to the MessageContext from the client or is there a better way to do this?
    Thanks in advance for any help you can give.

    You may want to check the response to this previous post to see if it yields any ideas for you:
    Not able to Pass header info to Microsoft MapPoint WebService using WLS10

  • Restore Log with Standby Mode on VHDX disk problem - hotfix for SQL 2014 needed

    Restore Log with Standby Mode on Virtual VHDX disk cause a 9004 error in SQL Server 2014 ( test performed on Web edition and Standard version )
    Similar Bug for SQL 2008R2 is already registered with number hotfix
    KB2987585
    Restore operations always fail in Hyper-V R2 Server in situations ( text copied from
    KB2987585 page )
    The primary database has its transaction log file (.ldf) stored on a disk that has "Bytes per Physical Sector" set as 512 bytes.
    You take the transaction log backups of this database, and then you try to restore it by using the standby option on the secondary database.
    The secondary database transaction log file (.ldf) is located on a VHDX disk that has "Bytes per Physical Sector" set as 4,096 bytes.
    In this scenario, the restore operation fails and returns the following error message:
    Error: 9004, Severity: 16, State: 6.
    An error occurred while processing the log for database '<databasename>'. If possible, restore from backup. If a backup is not available, it might be necessary to rebuild the log.
    After this error occurs, the secondary database goes into a suspect state.
    So restore from Generation1 to Generation2 machine ( where only VHDX disk is possible ) always fails and database is not accessible.
    Please create hotfix for SQL 2014 version

    Please create hotfix for SQL 2014 version
    This is a community forum, no one of use can create a hotfix for SQL Server.
    Raise a case at Microsoft Support or create an entry at MS Connect:
    http://connect.microsoft.com/SQLServer
    Olaf Helper
    [ Blog] [ Xing] [ MVP]

  • SSL VPN with client, anyconnect.

    I've set up a simple test on SSL VPN with client on a 3800.
    It didnt work. I assume i have to turn on the IP http server so that the client can hit it.
    but when I turned it on, the client goes to SDM, nothing with ssl vpn happened. it tells me the pay is not available.
    The underlying routing is fine.
    Could you tell me where it is configured wrong?
    Config is copied below.
    thanks,
    Han
    =======
    Current configuration : 3340 bytes
    version 12.4
    service timestamps debug datetime msec
    service timestamps log datetime msec
    no service password-encryption
    hostname Router
    boot-start-marker
    boot-end-marker
    enable password cisco
    aaa new-model
    aaa authentication login default local
    aaa session-id common
    no network-clock-participate slot 1
    crypto pki trustpoint TP-self-signed-3551041125
    enrollment selfsigned
    subject-name cn=IOS-Self-Signed-Certificate-3551041125
    revocation-check none
    rsakeypair TP-self-signed-3551041125
    crypto pki certificate chain TP-self-signed-3551041125
    certificate self-signed 01
    3082024F 308201B8 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
    31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
    69666963 6174652D 33353531 30343131 3235301E 170D3131 31313135 31383238
    30365A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
    4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 35353130
    34313132 3530819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
    8100CFCF CFFAD76A 50DA82C9 8D4E3F90 64AD24EB 5409C5E2 43BC64F3 07F6C0E0
    29FF2D71 0DA0D897 2F814BD2 7F817503 429D4BC6 6AD6EEA4 DFA74BAD 0EAF84D5
    6ED55EC0 6C637178 BEEBCD1D 184BB90C CA84E974 48003885 87B53F2E 36A04661
    23DA2CBB DD8EEE1D 2F25AF9A E21DC288 BF76A17C C1F4BA07 95F09377 A12BE01A
    53750203 010001A3 77307530 0F060355 1D130101 FF040530 030101FF 30220603
    551D1104 1B301982 17526F75 7465722E 776E7362 6E6F632E 696E7465 726E616C
    301F0603 551D2304 18301680 14BE9E8F ED788928 560D7CA1 EED89B0D DE34D772
    5D301D06 03551D0E 04160414 BE9E8FED 78892856 0D7CA1EE D89B0DDE 34D7725D
    300D0609 2A864886 F70D0101 04050003 818100BC 4A2A3C47 7BF809AF 78EE0FD9
    73692913 F280765E BAFAECAB ED32C38D 3030810B C62C7F45 13C8A6EE AE96A891
    CDD4C78B 803299AD EB098B27 383CEF6F 0E2B811F 3ECFADBA 07CD0AC6 BBB8C5FE
    B2FC0FD8 562B7100 BB28036E 4575D1F5 B17687C6 8EACBD66 A9E52FEE A030E69A
    CAAE9F1B 618FA59D 02C25BC8 77D6CAC2 C7E56F
    quit
    dot11 syslog
    ip cef
    multilink bundle-name authenticated
    voice-card 0
    no dspfarm
    username cisco1 privilege 15 secret 5 $1$L2RA$Zqs6FLce5Ns5fny5aRL49/
    archive
    log config
    hidekeys
    interface GigabitEthernet0/0
    ip address dhcp
    duplex auto
    speed auto
    media-type rj45
    end
    interface Loopback1
    ip address 1.1.1.1 255.255.255.0
    interface GigabitEthernet0/0
    ip address dhcp
    duplex auto
    speed auto
    media-type rj45
    ip local pool svc-poll 1.1.1.50 1.1.1.100
    ip forward-protocol nd
    ip route 0.0.0.0 0.0.0.0 192.168.1.254
    ip http server
    no ip http secure-server
    control-plane
    line con 0
    logging synchronous
    line aux 0
    line vty 0 4
    scheduler allocate 20000 1000
    webvpn gateway SSLVPN
    ip interface GigabitEthernet0/0 port 443
    ssl trustpoint local
    inservice
    webvpn install svc flash:/webvpn/svc.pkg
    webvpn context SSLVPN
    ssl authenticate verify all
    policy group default
       functions svc-required
       svc default-domain "test.org"
       svc keep-client-installed
       svc split dns "primary"
    default-group-policy default
    gateway SSLVPN
    inservice
    end

    Using the SDM follow the below config example
    http://www.cisco.com/en/US/products/ps6496/products_configuration_example09186a008071c58b.shtml
    The text "cisco 3800 ssl vpn configuration" in my favorite search engine, identified the above.
    HTH>

  • How do I use Cisco MARS to monitor two ASA (active/stby) with IPS modules?

    Hi
    The two ASA with IPS modules are in active/standby mode. When I try to add both the two IP (active/standby) into the MARS, the MARS will complain duplicated hostnames.
    How to setup MARS to monitor ASA with IPS with active standby topology?
    Thanks!

    Hi,
    The fundamental problem with this scenario is that you have non-failover capable modules in a failover chassis - think of the ASA failover pair as one device and the IPS modules as two completely separate devices.
    Then, as already mentioned, add only the primary ASA. (The secondary will never be passing traffic in standby mode so it's not actually needed in MARS) Then, with the first IPS module you can add it as a module of the ASA or as a standalone device (MARS doesn't care). With the second IPS module the only option is to add it as a separate device anyway.
    In a failover scenario the ASA's swap IP's but the IPS's don't so whereas you'll only ever get messages from the active ASA you'll get messages from both IPS IP's depending on which one happens to be in the active ASA at the time.
    Don't forget that you have to manually replicate all IPS configuration every time you make a change.
    HTH
    Andrew.

  • Question on J2EE agent Property for client.hostname.header

    Hi,
    Anyone know how to use this property com.sun.identity.agents.config.client.hostname.header? In the AMAgent.properties file, it said client.hostname.header is to specifies a HTTP header name that holds the Hostname of the client. See comment extracted from the AMAgent.properties file:
    # CLIENT IDENTIFICATION PROPERTIES
    # - client.ip.header: Specifies a HTTP header name that holds the IP
    # address of the client. May be left blank if not used.
    # - client.hostname.header: Specifies a HTTP header name that holds the
    # Hostname of the client. May be left blank if not used.
    # Hot-Swap Enabled: No
    # Example:
    # com.sun.identity.agents.config.client.ip.header = X-Proxy-Client-IP
    # com.sun.identity.agents.config.client.hostname.header = X-Proxy-Client-Host
    Questions:
    (1) In what conditions that we need to use this property?
    (2) What should be the correct value the above 2 property?
    Many thanks
    ~BHQ

    Hi Paul,
    You want to match inbound or outgoing dial peer on the basis of IP address in from field? voice-class uri command can be used to match a dial peer in Inbound direction only. As per your configuration dial peer 510 will be matched in Inbound direction then on the basis of called number outgoing dial peer will be matched. Here it looks like outbound dial peer is not found by router due to which call failed with 404 not found. Could you provide below mentioned debugs with calling and called number
    debug ccsip message
    debug ccsip error
    debug voip ccapi inout
    Also provide me "show run".
    Regards,
    Mohit Singh

  • HowI get Address Book Server sync with clients?

    I have just set up Lion Server on a macmini and am learning how to set it up.  I cannot get address Book server to sync with client accounts.
    The server is function is active.  The users are properly set up, and the clients have been connected to the server and a Mac OSX Server Address Book created.  I have also set up the address book on the Mac Mini with an OSX Server addresss book.  It should show the same entries as the client and sync wherever changes are made.  Not a sausage....nothing......  The little 'wheel' whizzes round and does......... you have got it........ nothing.
    I thought this was easy to use?
    Any help would be welcome.

    Hi,
    Yes the sync tool is a standalone utility (you don't need the outlook connector installed). I finally got around to installing/configuring the latest version (comm-suite-5 sync tool) against my 2005Q4 test install.
    The addressbook server is the UWC address as I mentioned before but you also need to include the /uwc on the end.
    So for my system I have the following setting:
    local.sso.uwc.verifyurl = http://test-system.sun.com:82/uwc/VerifySSO?
    This maps to a :
    => Address Book Server: test-system.sun.com/uwc
    => Port: 82
    So in your case it would be:
    local.sso.uwc.verifyurl = http://hostname:6788/uwc/VerifySSO?
    => Address Book Server: hostname/uwc
    => Port: 6788
    Regards,
    Shane.

  • Adobe Creative Cloud - How To Share Files With Clients and Colleagues | Creative Suite Podcast: Designers | Adobe TV

    In this episode of the Adobe Creative Suite Podcast, Terry White shows how to share Photoshop, Illustrator and InDesign Files with clients and colleagues and all they'll need is a browser to comment and see your Photoshop Layers.
    http://adobe.ly/10ZjpE4

    Terry,
    I guess I miss something. How can I share a folder of photos? When I return from a shoot, I select 20 of the pictures and need to share them with my client to pick up the favorites. Am I supposed to copy and past an URL for each image separately?
    Sometimes I also work with a colleague, I need to share my favorites with him. Same issue.
    We have tried Adobe Cloud, and then went for Dropbox. There we can share a folder and he can put even his pictures in it as well. That's what I call collaboration. And it is free (unlike Adobe Cloud). If you have some word in Adobe, please tell them to either drop it and make a deal with services like Dropbox, or make it properly.
    Thanks.
    Vaclav

Maybe you are looking for

  • Get millisecond values from timestamp column in v$logmnr_contents

    Hello How do we get millisecond values from timestamp column in v$logmnr_contents. I tried with following query. select scn,To_Char(timestamp,'DD-MON-YYYY HH24:MI:SS:FF') from v$logmnr_contents WHERE OPERATION NOT IN('START') and username ='SCOTT' an

  • Certification marks

    Hi folks, i have writen the XI certification. i got overall score 69% Except mapping is core above 65% in all topics. after compltion of my exam i recived message the " congrtas , u have cleared the test". my query is could you please tell me " iam c

  • WLCS 2.0.1 sp2 commercePool failing with demo apps

    When I start WLCS, I get the message below after various EJBs are deployed: Wed Sep 27 13:41:36 PDT 2000:<I> <JDBC Pool commercePool> A connection from pool commercePool was tested during reserve with a select count(*) from WLCS_IS_ALIVE and failed:

  • Images placed in indd are flat but now showing transparent

    running windows xp cs3 previous pagemaker document converted to indcs3. Image files are flat grayscale tif images. Images are being placed on upper layer over a gradient tint using pantone color why is the gradient knocking out the image?

  • Capture Change in Sales Order Status

    Dear All, I have an issue in which i need to capture all the sales order in which change has taken place in a given day. I have checked CDHDR & CDPOS but they arent helpful as they are not updated when there is change in status of sales order. Could