Point-to-point wireless with IPSEC
lan1----e1R1e0-----350bd----wireless-----350bd----e0R2e1-----LAN2
I am running ipsec between r1 and r2 to encrypt the data between lan1 and lan2. What precaution should I implement to secure link between R1e0 and e0R2.
Thx
At a minimum I would run 128 bit static WEP on the bridges with MIC and TKIP. But I really would like at MAC address filtering and maybe even EAP if you already have the infrastructure in your network
Have you seen the safe white paper ?? It will give you a great guide to what each level of security can do.
http://www.cisco.com/en/US/products/hw/wireless/ps430/products_white_paper09186a00800b469f.shtml
Currently all your layer 3 data is protected but your layer 2 wireless network is wide open malicous people could associate to your AP and create excessive broadcasts reduing your throughput or could spoof MAC addresses etc
Currently you have the equivlent of running IPSEC on your clients plugged into a hub but leaving that hub in a busy bar where anyone can plug into.
Similar Messages
-
Problem setting up Wireless with WAP54G
I am having trouble setting up my wireless network with my WAP54G access point. I have used this same router successfully before but now on my new network it gives me trouble.
I did a reset on my Access Point, Then the default setting is with a static IP address. I can just connect with the access point (wireless) with no problem. But when connected to the modem it doesn't give me internet...
Reading the manual of the modem it tells me that any router connected to the modem should be set to DHCP. So when I put the settings on my access point to DHCP (and change them on the network settings of my laptop) I cannot connect with the Accesspoint anymore..
Can anyone help me? am I just doing something stupid here?Hi sdedmer. What is the make and model of your modem? Is it a modem-router-in-one or a gateway? If so, you may need to enable the DHCP of the device so it can provide IP addresses for multiple devices to connect wirelessly. The WAG54G is an access point. It can only provide wireless and Internet access to one device at a time. For this, you may need to purchase a wireless router if you want to connect multiple devices (wired or wireless) and extend the wireless range using the WAG54G.
For more information about access points and routers, check this link out: http://kb.linksys.com/Linksys/ukp.aspx?vw=1&docid=b22772feb0f348f98a9c5d13e8469fca_192.xml&pid=80&re...
Information. Share it to learn.
Help, learn and share -
I need to know if 3502p with outdoor antennas supports Point-to-Point Wireless Bridging??
The 3502p is only used for arenas and or stadiums. These are different units than the 3500's and 3600's. So no they can't be.
You can use Cisco Aironet 1400 Series Wireless Bridge for a wireless link between two buildings (1km) to extend your LAN. For more detail you can go through the below link.
http://www.cisco.com/en/US/prod/collateral/wireless/ps5679/ps5279/ps5285/product_data_sheet09186a008018495c.html -
Do somebody knows what´s the recommended heigh to install an access point 1242 with external antennas 1728 on a flat area?And for example, if i use aps 3602 the heigh to install is the same?? BEST REGARDS
To determine the required height of an antenna tower over a hypothetically flat, spherical Earth, it's necessary to calculate the effect of the Earth's curvature, and then add a distance equal to 60% of the radius of the First Fresnel Zone. The table below shows the result of these calculations. Values have been rounded up to the nearest foot.
Line of Sight Distance Between Antenna Towers
Height of Tower to Avoid Flat Earth Curvature
Tower Height Required Over Tallest Obstacle In Line-of-Sight to Provide
60% Fresnel Zone Clearance
2.4GHz 802.11b/g
5.8 GHz 802.11a
8 Miles
10 feet
33
25
10 Miles
15 feet
38
30
12 Miles
20 feet
43
35
14 Miles
25 feet
48
40
16 Miles
30 feet
53
45
18 Miles
40 feet
63
55
20 Miles
50 feet
73
65
22 Miles
60 feet
83
75
24 Miles
70 feet
93
85
26 Miles
80 feet
103
95
28 Miles
100 feet
123
115
32 Miles
125 feet
148
140
34 Miles
150 feet
173
165
40 Miles
200 feet
223
215
It can be seen in the table above that a wireless link between two points separated by 26 miles would require an antenna tower with a minimum height of 103 feet for an 802.11b/g radio and 95 feet for an 802.11a radio. In practice the heights would typically be 20 feet higher, or more. This is because the Earth is not smooth and flat and the tower height must be raised to compensate for buildings, trees, hills, or other obstacles. For example, in a suburban setting, with houses and small offices, it may be necessary to add 20 to 40 feet to the tower height to get over the homes, offices, and trees that would be in the line-of-sight between the two towers. -
Null pointer Exception with removeRowWithKey operation
Hii experts,,,
I am using JDevelepor 11.1.2.1.0 Version
I Am new in ADF ,
In My sample application i select row in iterator by findIterator() method
then get the specified row by getCurrentRow();
then i get the rowKey By row.getKey() method..
I put rowKey as parameter to removeRowWithKey operation
I have get null pointer Exception with removeRowWithKey operation
java.lang.NullPointerException
at oracle.jbo.server.ViewRowSetImpl.prepKeyForFind(ViewRowSetImpl.java:5352)
at oracle.jbo.server.ViewRowSetImpl.findByKey(ViewRowSetImpl.java:5394)
at oracle.jbo.server.ViewRowSetImpl.findByKey(ViewRowSetImpl.java:5296)
at oracle.jbo.server.ViewRowSetImpl.findByKey(ViewRowSetImpl.java:5290)
at oracle.jbo.server.ViewObjectImpl.findByKey(ViewObjectImpl.java:11536)
at oracle.adf.model.binding.DCIteratorBinding.removeRowWithKey(DCIteratorBinding.java:3748)
at oracle.jbo.uicli.binding.JUCtrlActionBinding.doIt(JUCtrlActionBinding.java:1598)
how can solve this???thanks Timo
through this URL i get possible deletion methods...
pls give more Information about the concept of removeRowWithKey, setCurrentRowWithKey, setCurrentRowWithKeyValue operation.... Just For Knowledge....
Edited by: NZL on Mar 2, 2012 9:37 AM
Edited by: NZL on Mar 2, 2012 9:42 AM -
GR with backflush not for reporting point logic with autom. GR option
Dear Experts,
While doing backflashing though MFBF we are getting following error
"GR with backflush not for reporting point logic with autom. GR option"
We have maintained 5 production version for this material while calling with first production version we are getting the error.
Rate routing & BOM maintanied for the FERT material
ThanksDid you check the BackFlash option are actuvated in the following places ?
1. In the Rate routing, the backflush indicator is set in the component assignment.-CA22
2. In the material master record, the backflush indicator has the characteristic "Always backflush".-MRP3
3. In the material master record, the backflush indicator has the characteristic "Work center decides", the indicator being set in the work center.-CR21-Basic Data View .
4.Goto-MM02-MRP4 View -Select the PV-Goto Details -Check particularly this production version REM Allowed or not
5.You should use REM-Profile -0004/0003 where RP and Auto GR with RP at last Back Flashing Activated .
6.Check Rate Routing Operation Control Key -Auto GR with indicator Confirmation required
Regards
JH
Edited by: Jiaul Haque on Jun 22, 2010 11:19 AM -
Program related ENHANCEMENT-POINT/SECTION with the name LMEPOF8D_02 exists
Hello
In an upgrade, after finishing with the SPAU task we got the following error in the standard object LMEPOF8D:
A program related ENHANCEMENT-POINT/SECTION with the name "LMEPOF8D_02" already exists.
Anyone knows which cause could be generate this kind of error?
Thanks in advance for your help
Best Regards,
LeonardoHello Sandra,
We have finished with SPAU. Regarding LMEPOF8D include, we kept with the ECC6 standard code. Therefore, from a point of view of code, it should be ok. However, we have this sintax error.
As you said, the include contains the enhancement point LMEPOF8D_02 which generates the sintax error, but we couldn't find if this enhancement is used in another place.
We also found note 1331844 and tried to fix the issue by using the 2nd solution propose in the note. But, it didn't work neither.
Do you have any idea about what cause could generates this error?
Thanks in advance for your support.
Best Regards,
Leonardo -
Create a point to point link with a wlc 4402
Hi to all,
i have a wlc 4402 and i need to configure a point to point link with two air-lap1310g-e-k9, i have found on cisco.com this link:
http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a00808e9c1b.shtml#zero
but on the wlc configuration page i cannot found some configuration step.
Someone have configured this type of behaviour or can give me some hints?!
How can i configure on the wlc the parameter about the bridges configuration?! Or i must configure the bridges overriding the global configuration?!
Thanks and best regards,
Carlo Sagratella.The correct thing to do would be to downgrade the 1310's to autonomous (or 1242's) and set up a root bridge and non-root bridge.
Alternately however, if you REALLY wanted one of the points to be LWAPP, in theory you could always make one of the Access Points Autonomous and join it as a workgroup bridge to the LWAPP AP. However, there really is no reason to do that since it would be cleaner to convert both to autonomous. -
Two buttons in upper left corner , arrow pointing upwards with a tail & tw
Real simple and quick question in a lot of logic windows in the upper left corner I see these two buttons.
Once is a arrow pointing upwards with a tail that goes to the right, and turns at a right angle.
The other question is what is the button right next to it that looks like two paper clips, or two links in a chain. Often this is shaded meaning that it is enabled correct?cyline wrote:
Real simple and quick question in a lot of logic windows in the upper left corner I see these two buttons.
Once is a arrow pointing upwards with a tail that goes to the right, and turns at a right angle.
That's the hierarchy button, useful for moving up in the display levels - for navigating up and down within folders, for example.
The other question is what is the button right next to it that looks like two paper clips, or two links in a chain. Often this is shaded meaning that it is enabled correct?
That button links windows. Control-clicking sets the way the links are established. Useful for updating (or not) displays of regions - for example, linking a specific region to the piano roll.
There's another useful link button on plug-in windows, which allows you to switch a plug-in display to show another plug-in in the same window, or with it off, display separate windows each time, so you can compare one to another. -
Firefox will not start warning message "The procedure entry point PK11_Derive With Template nss3.dll" after IE update and zeroing cookies.
Do a clean reinstall and download a fresh Firefox copy from http://www.mozilla.com/firefox/all.html and save the file to the desktop.
Uninstall your current Firefox version and remove the Firefox program folder before installing that copy of the Firefox installer.
It is important to delete the Firefox program folder to remove all the files and make sure that there are no problems with files that were leftover after uninstalling.
You can skip the step to create a new profile, that is not necessary for this issue.
See http://kb.mozillazine.org/Standard_diagnostic_-_Firefox#Clean_reinstall -
Problem with IPSec on solaris 9
Hi all
I'm facing a problem with IPSec on solaris 9 that I didn't have with Solaris 8 (With the Security package installed).
I've an application that creates SA's by using the pf-key interface.
What it does is first doing a GETSPI to a specific SPI and a specific Destination IP Address.
This will create an SA and put it in a LARVAL state. After about a minute my application will do an UPDATE to this SPI and that command should change the state of the SA from LARVAL to MATURE but instead I get an error saying that this SPI & IP address already exist (errno = 17).
Well of course it's already exist that's the all point it should just change the state of an existing SA.
This exact scenarion was is working fine on Solaris 8.
Am I doing somthing wrong (maybe there is a package on the solaris 9 that I need to install ?)
or is this a bug in solaris 9.
If anyone has any idea on how to do that (without using a one step ADD for a new SA) I will be very thankfull.Sorry for using reply for querying.
I got a problem in creating a Security Association using the PF_KEY Socket (first used SADB_GETSPI and got SPI,with SPI tried to update SADB_UPDATE).
Getting this problem on Sun Solaris 8.
It returns errno 122 . operation not supported.
Here is my mailId [email protected]
I got few more queries regarding PF_KEY socket.
Not much directions are available also for pf_key socket in internet.
Monitor produces the following error.
# ipseckey monitor
"Base message (version 2) type UPDATE, SA type AH.
Error Operation not supported on transport endpoint from PF_KEY.
Message length 16 bytes, seq=4294967294, pid=450."
Here is my mailId [email protected]
Thanks in Advance.
ssundar. -
How do I get my computer to print wireless with HP6600
I have tried to get my computer to print wireless with the HP6600. I have tried all the trouble shooting things and still does not work. The printer is contected to the wireless network. I can print from my phone and Ipad fine without a problem.
@ minipinny26 - When you downloaded the drivers and attempted to install the software I am guessing the software could not find the printer. Is this correct?
If so, then did you try a power cycle on the circuit?
* Unplug router and wait 30 seconds
* Plug router back in and wait for it to completely repower up
* Restart the PC
* While the PC is restarting: Unplug the printer while the unit is on
* Wait 30 seconds and plug the printer back up for power
Can the software find the printer at this point?
If not, then can you ping the printer?
* Open the Command Prompt screen by typing CMD in the Run command box
* Type ping followed by the ip address of the printer.
Also, take a look at the steps in the document found here. Let me know what happens.
-------------How do I give Kudos? | How do I mark a post as Solved? --------------------------------------------------------
I am not an HP employee. -
I need a printer that will work wirelessly with Lion os
Please help me find an all in one printer that will work wirelessly with the new Lion OS.
I'm on my third printer...
ThanksExactly what did you do when trying to set up the printers? Did you follow the mfr's instructions?
I also have an Epson (Artisan 810) and it works flawlessly - both wired and wirelessly. If I remember correctly, the instructions specifically said in order to set it up wirelessly, I had to connect it via USB first and then unplugged the cable at a specific point (following the instructions). And, the instructions included having to copy the printer's MAC address (a series of numbers and letters) from the printer display panel and enter it at my router's (Netgear) online setup site. -
Voice over Wireless with Cisco phones 7921 and 7925
Hello experts,
I made an wireless audit for a company.
They have 2 WLCs 5508 in HA mode, with APs 2602 for indoor and 1552. Version of the WLC : 7.6.120.0
At the end of the day we noticed that the roaming between indoor and outdoor access points is sometimes failing and results to a complete disconnection of the wireless phone (7921 or 7925) from the network. When people go from the indoor to the outdoor area, there is no problem. The problem comes when people are coming from the outdoor to the indoor.
Also, on the WLC, the power lvl of the outdoor APs are set to 1 ... Is it good or not ?
My question is, is there any known issue about Voice over wireless with WLC 5508-7.6.120.0 with APs 2602 and 1552 ?
Maybe it should be better to upgrade to 7.6.130.0 ?
Thanks in advance,
AlexisNormally yes.
Is there a way to troubleshoot what's going on with the phones ? Maybe a "show client detail MAC address* on the WLC ?
Here are some logs when the phones are losing the network :
*Dot1x_NW_MsgTask_4: Apr 09 12:44:21.320: #DOT1X-3-INVALID_WPA_KEY_MSG_STATE: 1x_eapkey.c:957 Received invalid EAPOL-key M2 msg in START state - invalid secure bit; KeyLen 40, Key type 1, client 00:24:d7:83:56:dc
*apfMsConnTask_6: Apr 09 12:28:32.668: #APF-3-VALIDATE_CCKM_REASS_REQ_ELEMENT: apf_utils.c:2506 Could not validate the CCKM Reassociation request element.Received Timestamp deviation > 1sec in CCKM Info Element from mobile. Mobile:4c:00:82:85:6e:e1, AP:1
*Dot1x_NW_MsgTask_1: Apr 09 12:26:53.964: #DOT1X-3-INVALID_REPLAY_CTR: 1x_eapkey.c:445 Invalid replay counter from client 74:26:ac:63:8c:a9 - got 00 00 00 00 00 00 00 03, expected 00 00 00 00 00 00 00 04
*Dot1x_NW_MsgTask_1: Apr 09 12:26:53.929: #DOT1X-3-INVALID_REPLAY_CTR: 1x_eapkey.c:445 Invalid replay counter from client 74:26:ac:63:8c:a9 - got 00 00 00 00 00 00 00 02, expected 00 00 00 00 00 00 00 04
*apfMsConnTask_4: Apr 09 12:24:34.959: #APF-3-VALIDATE_CCKM_REASS_REQ_ELEMENT: apf_utils.c:2506 Could not validate the CCKM Reassociation request element.Received Timestamp deviation > 1sec in CCKM Info Element from mobile. Mobile:78:da:6e:f6:5f:89, AP:5
*Dot1x_NW_MsgTask_0: Apr 09 12:22:30.217: #DOT1X-3-INVALID_REPLAY_CTR: 1x_eapkey.c:445 Invalid replay counter from client 4c:00:82:85:1d:68 - got 00 00 00 00 00 00 00 03, expected 00 00 00 00 00 00 00 04
*Dot1x_NW_MsgTask_4: Apr 09 12:22:30.206: #DOT1X-3-INVALID_REPLAY_CTR: 1x_eapkey.c:445 Invalid replay counter from client 4c:00:82:85:b3:ac - got 00 00 00 00 00 00 00 03, expected 00 00 00 00 00 00 00 04
*Dot1x_NW_MsgTask_4: Apr 09 12:22:30.186: #DOT1X-3-INVALID_REPLAY_CTR: 1x_eapkey.c:445 Invalid replay counter from client 4c:00:82:85:b3:ac - got 00 00 00 00 00 00 00 02, expected 00 00 00 00 00 00 00 04
*Dot1x_NW_MsgTask_0: Apr 09 12:22:30.167: #DOT1X-3-INVALID_REPLAY_CTR: 1x_eapkey.c:445 Invalid replay counter from client 4c:00:82:85:1d:68 - got 00 00 00 00 00 00 00 02, expected 00 00 00 00 00 00 00 04
*Dot1x_NW_MsgTask_6: Apr 09 12:22:29.672: #DOT1X-3-INVALID_REPLAY_CTR: 1x_eapkey.c:445 Invalid replay counter from client 78:da:6e:f6:14:2e - got 00 00 00 00 00 00 00 03, expected 00 00 00 00 00 00 00 04
*Dot1x_NW_MsgTask_6: Apr 09 12:22:29.638: #DOT1X-3-INVALID_REPLAY_CTR: 1x_eapkey.c:445 Invalid replay counter from client 78:da:6e:f6:14:2e - got 00 00 00 00 00 00 00 02, expected 00 00 00 00 00 00 00 04
*apfMsConnTask_3: Apr 09 12:19:22.098: #APF-3-VALIDATE_CCKM_REASS_REQ_ELEMENT: apf_utils.c:2506 Could not validate the CCKM Reassociation request element.Received Timestamp deviation > 1sec in CCKM Info Element from mobile. Mobile:4c:00:82:85:6e:e1, AP:5
*osapiBsnTimer: Apr 09 12:13:36.031: #LOG-3-Q_IND: spam_lrad.c:53542 The system is unable to find WLAN 2 to be deleted -
My computer / iTunes is set up correctly for wireless (account info. all good), and emial is synched wirelessly. BUT not photos / videos or songs. I seem to have to plug my iPhone into my computer for iTunes to recognize my device. Shouldn't iTunes recognize my iphone wirelessly? For example, I have read that "device" should show up in menu bar on iTunes but it doesn't unless I'm cabled in.
Also, when I go to my iPhone to "synch wirelessly with iTunes", the button / tab doesn't light up for me to chose and tells me will synch when "smith - laptop" is available.....
This is my first iPhone, and just got it so may be user error.....
thanksDid you build Elsa with this package from AUR: elsa-svn-arch
The way your elsa.conf looks like indicates to me that you have not.
Please use the package because you are also missing pam-files.
Maybe you are looking for
-
The sound on my Macbook doesn't work.
The sound of my MacBook Pro 15" Retina just works at the startup screen. I can control the volume on startup screen but when I login I can't hear any sound from my MacBook even I plug headphones or speakers in.
-
Hi Guys, While import abap phase 36 jobs got finished, then suddenly my laptop got restarted after i launched sapinst again i got this error INFO 2009-05-25 00:27:23 CJSlibModule::writeInfo_impl() Output of C:\j2sdk1.4.2_17\bin\java.
-
How to get count for missing month
I created a view as follows: CREATE OR REPLACE FORCE VIEW "Vinfection1" ("MONTH", "COUNT") AS select "MONTH","COUNT" from ( select to_char(s.pdate,'Mon-yyyy') as month, count(*) as count from surproc s, diagnosis_surproc d where s.surprocid = d.surpr
-
JHS 1012 with Standalone OC4J 904
Has anyone got this to work? I can deploy JHS 10.1.2 to standalone OC4J 10.1.2 (without ADF runtime installed) but standalone 9.0.4 OC4J gives an HTTP 500 error (without ADF runtime installed, no additional messages appear; with ADF runtime installed
-
ERROR : BBP_PDH_WFL_APPROVAL_SIMULATE after saving SC
Hello, We upgraded to SRM7.0 from SRM5.0 SRM_SERVER 700 0008 SAPKIBKV08 SRM_SERVER we activated workflow in application mode. After saving Shopping cart when display or edit the SC We get the error message: BBP_PDH_WFL_APPROVAL_SIMULATE, PDO Layer. W