PIX 501 - Configure Alternative Route Outside on PIX's ATM2
Hello to all
i am trying to add a line to allow the PIX to use an alternative ADSL Line when the first goes down
Is it enought that i put a new line like this?
currentt route outside: route outside 0.0.0.0 0.0.0.0 89.xxx.xxx.33
new line i'll add: route outside 0.0.0.0 0.0.0.0 2.yyy.yyy.102
Obviously i'll plug the new router an the ATM 2 port of the PIX.
Consider that i have ths NAT inside rule
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
As usual thanks in advance for your answers.
Stefano
Hello Stefano,
You are looking for Sla Monitor on the PIX/ASA:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00806e880b.shtml
Let me know if you have any question.
Regards,
Felipe.
Similar Messages
-
All,
I have a friend trying to configure an existing PIX. They needed to change IP addresses due to ISP switch. Config was very basic but whenever he puts in the route outside command the PIX seems to take it but then he is saying it is disappearing when he checks the config. Does anyone have any ideas what this could be? He only changed outside IP address, a static translation
All replies rated. Thanks in advance!Hi Angel,
My assumption is that you have a speed issue between the outside interface of the PIX and the new ISP equipment.
You have statically set the outside interface "interface ethernet0 10baset"
Please post :
show int e0
PS : nice software version 6.2
Regards
Dan -
Configuring Static Route Tracking Using ASDM 7.1(3) ASA 9.1(2)
I have recently updated my ASA5520 to 9.1(2) and I am using ASDM 7.1(3) to configure Static Route Tracking. I have done this previoussy in earlier version of ASDM without a problem. There seems to be a new field in the Tracked Options section. What is the "Target Interface"? Is it the interface I want to use as the standby route when the Monitor fails? Or is it the Interface that is doing the monitoring?
I have looked through Cisco ASA Series General Operations ASDM Configuration Guide Software Version 7.1, as well as older ASDM books and this field is never listed or described.Hi,
The target interface will be the interface through which you will be polling some destination IP address with ICMP Echos to determine if the route through that interface is still valid.
So in your case you would use "Outside"
Heres the link to the ASA Command Reference listing the above "type" command under the "sla monitor 1" configuration
http://www.cisco.com/en/US/docs/security/asa/command-reference/t2.html#wp1568359
- Jouni -
Want to propose Alternative Route in Order
Hi friends,
I would like to know what configuration settings I should be doing for to propose Alternative Route in Order.
Condition is as below.
Rec Zone(X)Shipping Zone(Y)SH Cond(02)+ Trans Grp(0001) = Route( ABC) .Here I want to propose (popup) laternative routes.
Please reply soon.Waiting for your kind reply.hello again.
also look into IMG > SD > Basic Functions > Routes > Route Determination > Maintain Route Determination.
if you are just defining a combination of departure zone and receiving zone, click 'New Entries'. if you are adding alternative routes, select a combination and click Route Determination without weight group. in the next screen, you can make your assignments based on Shipping conditions + Transport group + proposed route.
if weight group is relevant, then click on Route Determination with weight group. in the next screen, the weight group and actual (alternative) route can be assigned together with the transport group and shipping conditions.
regards. -
MFBF and Alternative Routing Sequence
Hi;
We are using REM in PP.We confirm via MFBF. And we create routings via ca01. I want to use alternative routing sequence during confirmation.
What should I do? or Is it possible for REM?
Thanks.Hi;
Thanks for your answers. I dont want to create new production versions. But routing informations are change.
Ex: I have two machines in a production line, lets say it A and B. This line has a work center code in SAP ( lets says Line1)
When I use only machine A I produce 100 pieces in 5 minutes with 2 worker. But when I use A & B at the same time I produce 100 pieces in 3 minutes with 3 worker.
Machine A and B are connected to the same conveyor belt, so I put the pieces in the same palette. And during confirmation I use Line1 as workcenter.
What should I do to post the exact activities ?
Thanks for your information. -
Configuring Cisco Router for use with Syslog Server
Configuring Cisco Router for use with Syslog Server:
Does anyone know of a good doc for this?
-AshleyStart with that one: http://security-planet.de/wp-content/uploads/2008/12/logging-ios.pdf
And if you need more informations, just ask what you want to achieve.
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni -
Configuring Transport route in Java system
Hi,
Pls let me know the steps to configuring transport routes in Java System.Hi,
Please look at the following pdf which tells you about CTS+ in portal with only java and non abap objects.
https://www.sdn.sap.com/irj/sdn/go/portal/prtroot/docs/library/uuid/90d3b550-b6fb-2910-0fa5-ece5d61fb9c3
Rakesh -
airport extreme software will not install on vista, how can i still configure the router? Trying to help someone with vista get an airpot extreme configured. 10.0.1.1 does not work, the software will not install correctly on their vista machine. How can I get into the base tation and lock it down?
Hi - Vista can be tricky - I need more info to see if I can be of some help - first, is the Vista machine a desktop or a laptop and is it fully up to date with Windows Update (sp2 or higher)? - next, are you trying to install Airport Utility version 5.5.3 which is the correct one for Vista? - and finally, what do you mean "it will not install" - what kind of error messages or evidence are you getting?
-
How to install and configure SAP Router
Dear SAP Expert !
I want to install SAP Router but i dont know the SAP router package is allocated on DVD ? what is the DVD number ?
If you already configure SAP router please let me know how to configure ?Hello Thao
what is th exact issue that are u facing.
The account must be the administartor of the machine where u are installing SAPROUTER.Make sure you are following the correct steps as follows:
Downloading necessary software components from SAP Service Marketplace
1. Login to the SAP Service Marketplace with the Service Marketplace at using
the USERID/PASSWORD which was assigned for your installation.
2. Change the alias to www.service.sap.com/tcs to downloaded the SAP
cryptographic software. Select the correct SAPcrptographic software
depending on your saprouter operating system as shown below.
3. You must have the sapcar.exe in order to extract the SAP cryptographic
software file.
4. With the command of u201Csapcar -xvf xxxxxxx.saru201D, /ntintel directory would be
created and the following files would be extracted.
(Example C:/saprouter/ntintel)
( when the Microsoft Windows NT Intel version is downloaded)
C:/saprouter/ntintel/sapcrypto.dll
C:/saprouter/ntintel/sapgenpse.exe
C:/saprouter/ticket
Issue of Electronic Certificate
5. It is necessary to define the environment variable for u201CSECUDIRu201D and
u201CSNC_LIBu201D under system account.
Window NT environment variable setup :
Right-clicked the icon of you computer
Property -> details -> environment variable
SECUDIR = < Directory name >
Example. Variable name : SECUDIR
Variable value
: C:/saprouter/SNC_LIB = < Directory name >
Example. Variable name : SNC_LIB
Variable value : C:/saprouter/ntintel/sapcrypto.dll
UNIX
<path_to_libsecude>/<name_of_sapcrypto_library>
Windows
NT,
<drive>:/<path_to_libsecude>/<name_of_sapcrypto_library>
Windows
2000
6. Check if the environment of the user running saprouter contains the
environment variable SNC_LIB.
UNIX
Printenv
Windows NT
System environment Variable
7. You may now apply for a SAProuter certificate from the SAP Trust Center
Service of SAP service marketplace
http://service.sap.com/tcs
> SAP Trust Center Service in Detail
> SAProuter Certificates
SAProuter Certificate "Apply Now"
Click the button.
8. Please take note of your "Distinguished Name"
Please refer to the example above
-SAPRouter Name
: JPL50020586
-Distinguished Name
CN=JPL50020586, OU=0000036946, OU=SAProuter, O=SAP, C=DE
Then, clicked the "Continue" button.
9. Execute the following command in the /saprouter/ntintel
directory in order to generate your certificate to be exchanged with SAP.
sapgenpse get_pse -v -r certreq -p local.pse "Distinguished Name"
Example
sapgenpse get_pse u2013v -r certreq -p local.pse "CN=JPL50020586, OU=0000036946,
OU=SAProuter, O=SAP, C=DE"
Enter the PIN number. (you may enter any PIN Number you wish.)
Please enter PIN :
Please re-enter PIN :
<- you must use the same PIN Number as the above.
10. The "certreq" file is created in the /saprouter/ntintel directory.
11. Use a notepad to open the "certreq" file and copy the displayed information
(From the -BEGIN .to the END -)
12.You now have to paste the above copy content into the space provided
shown below. After you have pasted the text, click the u201CRequest certificateu201D
button to submit your request.
13. Once you click on the u201CRequest Certificateu201D a new screen will be displaying
your certificate issued by SAP CA (Certification Authority).
14. Using a notepad to copy the content (From u2013Beingu2026 to -END) and save it
as u201Csrcertu201D into /saprouter/ntintel/srcert.
Note :
- Please rename srcert.txt into srcert without any extension.
15. You then need to import this certificate into SAProuter using the following
command.
Please run on /saprouter/ntintel directory.
sapgenpse import_own_cert -c srcert -p local.pse
Please enter PIN : (same as point 9)
16. Execute the following command in the /saprouter/ntintel directory.
sapgenpse seclogin -p local.pse
Please enter PIN : (same as point 9)
This will create a file "cred_v2" in the same directory.
17. Please check whether the certificate has been imported correctly.
Execute this command in /saprouter/ntintel directory.
sapgenpse get_my_name -v -n Issuer
The result should be "CN=SAProuter CA, OU=SAProuter, O=SAP, C=DE".
18. When the above results are not obtained , please delete local.pse and
cred_v2 and work again from steps 9. Please seek the assistance from your
local SAP helpdesk or create an OSS message via component XX-SER-NET-
OSS, if you are not able to obtain the above-mentioned result after you have
repeated the above steps.
Route permission table (saprouttab)
19. The corresponding file ./saprouttab should contain at least the following
entries.
Example : by SNC connection, when connecting to sapserv2
(194.39.131.34) the following entries need to be indicated by saprouttab.,
SNC-connection to SAP
KT "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" 194.39.131.34
SNC-connection from SAP to local R/3-System for Support
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <R/3-Server> <R/3-Instance>
SNC-connection from SAP to local R/3-System for pcANYWHERE, if it is needed
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <R/3-Server> 5631
SNC-connection from SAP to local R/3-System for NetMeeting, if it is needed
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <R/3-Server> 1503
SNC-connection from SAP to local R/3-System for saptelnet, if it is needed
KP "p:CN=sapserv2, OU=SAProuter, O=SAP, C=DE" <R/3-Server> 23
Access from the local Network to SAPNet - R/3 Frontend (OSS)
P <IP-addess of a local PC> 194.39.131.34 3299
deny all other connections
D * * *
Start the SAProuter with the following command.
Saprouter -r -S <port> -K
"p: <Your Distingiushed Name>"
-K tells the saprouter to start with loading the SNC library.
Example: saprouter -r -S 3299 u2013K "p:CN=JPL50020586, OU=0000036946,
OU=SAProuter, O=SAP, C=DE"
Additional Note
-You may refer to SAP note: 30289 in the SAP service marketplace for detail
information with regards to SAProuter
http://www.service.sap.com/note -
Alternative router settings to replace hh4
Hi all
I have recently purchased a Cisco rv220w router to replace my home hub 4. I have tried and tried but can't seem to get the router to receive an internet signal. I have used pppoe and changed the user name to that of my home hub.. I think one issue might be that my new router is asking me for a password and the hh4 doesn't have one?
Any one on here had any luck or can share some advice about using an alternative router? Would a call to bt help?
JamesJust to confirm, are you on Infinity or adsl broadband. If on adsl broadband your new router does not have an adsl modem it is only a router and that would be the reason it won't work.
If you are on Infinity I presume you are connecting through the Openreach modem as your router does not have a VDSL modem built in and would not work with out the Openreach one. -
BAPI For listing alternative routing with sequence details.
Dear all,
I want to use BAPI For listing alternative routing with sequence details.
Pl' tell BAPI function Module for routing .
Thanks.I am not sure ,but check with BAPI_ROUTING_CREATE
-
Please help me in configuring a router!
Hi! I have to configure a new router with a static route. No routing protocol will be used. Since, I'm a budding Network aspirant i do not know much about things. My senior Network Engineer has asked me to configure this router. There's an apartment where our Overseas employees stay, earlier this apartment had a broadband connection which was further divided through the APs(Cisco Wireless Access Points) and made usable to around 20 users. Now, they have bought in their own lease line and I have to configure this router. Please help me doing this as I'm not aware of anything else apart from what I have written here. Thanks a ton in advance!
Hello,
You should provide some info so that people can figure out what do you want to do. For example, what kind of leased-line is it? L2 or L3? Is it like a cable connecting two sites from your company or is there any router in between from your leased-line provider...?
For what you say, the easiest thing would be to configure a default route to the other end of the leased line and voilà.
Otherwise, you can always ask your senior Network Engineer to configure it (him/her)self or ask for help to him/her.
Regards,
Reg. -
Hi All,
My company recently order a new circuit for our VoIP use and we have a Cisco 2911 router.
The new circuit is terminated with a ethernet handoff. I have never configure a router direct connect to ISP circuit before, please help!
Following details is give by the ISP:
WAN IP
IPv4 Network Address: X.X.6.204/30
IPv4 Customer Address: X.X.6.206/30
IPv4 PE Interface Address: X.X.6.205/30
LAN IP
IPv4 Static Routing : X.X.159.0/29
Default GATEWAY: X.X.159.1
Available Addresses: X.X.159.2 - X.X.159.6
Subnetmask: 255.255.255.248
VLAN Tagging :Transparent
DNS Server: 198.6.100.6, 198.6.1.125Hi,
On the circuit (interface) connecting to your provider you need to add this IP
X.X.6.206/30
example:
interface f0/0
ip address X.X.6.206 255.255.255.252
no sh
On the interface connecting to your lan you need to add this IP:
X.X.159.1
example:
interface f0/1
ip address X.X.159.1 255.255.255.248
no sh
below range is used for your LAN side (PC, server, etc..) with default gateway being X.X.159.1 255.255.255.248
X.X.159.2 - X.X.159.6
HTH -
ok so the hh3 is an ok router for standard use BUT not ideal for advanced use, NAT loopback and dyndns being the main issues, so what is a good alternative router to use that does a proper routing job,
guess the main requirements are
it needs to support connection to infinity
needs to support dyndns
needs to allow NAT loop back
802.11nA quick check of the TP Link forum for the TP-Link TL-WR1043ND seems to indicate that it does.
11-15-2012 04:33 #8
Taylor
Junior Member
Join Date
Sep 2012
Posts
4
I'm pretty sure TP-LINK wired routers support NAT Loopback, I have test it with my IP camera, it works.
There are some useful help pages here, for BT Broadband customers only, on my personal website.
BT Broadband customers - help with broadband, WiFi, networking, e-mail and phones. -
Ipx configuration for router 2800
please help me to have ipx configuration for router 2800 work with novel ver4 server.
please help me to have ipx configuration for router 2800 work with novel ver 4 server.
Maybe you are looking for
-
Two different iPods sharing same computer and iTunes
How do I set up a second iPod on the same computer but keep them separate?
-
Just upgraded itunes and now it won't work
ive just upgraded my itunes and whenever i try to load it up i get an agreement mesage that come up for a second then goes and i can't get into itunes. I've since tried to downgrade but that didnt help and i have read about the norton method of fixin
-
Need to stop posting a line item in PR using BADI ME_PROCESS_REQ_CUST
Hi All, I have a requirement to check the combination of the GLaccount and project and if the combination is not allowed i need to show an error message and to stop the user from saving the Purchase Requisition. For this i have coded in BADI ME_PROCE
-
How to logoff a session created by RFC
Hi All, I'm using an RFC to call a funtion in another server and is working right now using a logical destination, but I have a problem with the session, everytime when the user execute this funtion to a come back to R/3, CRM server keep the session
-
Converting xmltype to document/node
I am trying to take XMLType and create a DOMDocument or DOMNode. How can this be done. Thank you, Jim