WRV200 IPSEC VPN to a remote site with 2 different subnets

Hi,
My old WRV54G had no problem with this! I'm trying to connect an IPSEC tunnel back to a router at my main office, there are two Subnets there 192.168.0.0/24 and 10.171.131.0/24. In my old router I would set up two tunnels to the same gateway with different subnets and everything would work fine.
When I do this with the WRV200 both tunnels come up but in the view of the VPN status they both have the remote network listed as 192.168.0.0 /24 and I can't seem to get them both to work. If I delete the 192.168.0.0/24 tunnel (tunnel #A) and just use the tunnel#B I can connect to the 10 network.
Anyone been able to get this working?

Hi,
Ok, so the first thing you will have to think about is the encryption domain of the existing L2L VPN. Since your aim is to publish a Web server from another site through a L2L VPN connections you have to consider what the source addresses for the Web server connections can be?
It might be that you would need to have the source address for the L2L VPN in DC1 as "any" and naturally on DC2 the destination would be "any".
Though in that case it would probably cause problems if the Web server would need to use the DC2 Internet connections for something. This is because we would have now defined that traffic from the Web server to "any" destination IP address should be tunneled to the L2L VPN.
One other option might be that you actually configure DC1 site so that all incoming traffic from the Internet towards the 111.111.111.111 will have their source address translated to a single IP address (to be decided) before entering the L2L VPN. This would eliminate the need to use the "any" in the L2L VPN configurations because the Web server would see all connections come from a single IP address and therefore would not cause problems for the DC2 Web server IF it needs to access or be accessed through the local DC2 Internet connection.
Judging by your examples it would seem that you are using a 8.2 or older software level. Would you be willing to share some current configurations (with masked public IP addresses) or should I just give you some example configurations?
Most important ones would naturally be current NAT configurations and configuration related to the L2L VPN connection.
- Jouni

Similar Messages

  • Remote Site with its own CUCM Sub#2 and Router network failed and the site didnt keep its phones active, need some assistance

    I have a Pub and 2 Sub's.  Sub #1 is with the Pub, at the main site it is our TFTP server, Sub #2 is at a remote site with about 100 users along with a router and 2 PRI's for outbound calls.  We had a network failure between the main site and the remote site and all phone lost their registration with the system until we were able to get the network back up.   Currently the network is up in a crippled state on a 1 T-1 link while we troubleshoot the bigger issue with our 6mb pipe, however Sub #2 and its associated router arent talking with the PUB or other Sub.  I'm still getting alerts every 30 minutes stating they are the server is down.  I'm sure once the network is corrected this will bring everything back on line.  My question is how can I prevent in this in the future.  I need this site to be stand alone if the network goes down again.  I was told by our vendor that if we had a subscriber at each site then we would need SRST licensing. I know something needs to be configured to make it all work, I'm just not sure what.

    I already have a group at the site but it includes both the Pub and Sub from the main site as well as the Sub from the remote site.  I would only have to remove the Sub from the main site, problem is I currently only have 1 TFTP server it runs on SUB #1, should I make SUB#2 a TFTP server as well and the phones are setup for DHCP at the main site, I'm going to need to have a DHCP server setup at the remote site as well. Correct?

  • Register APs at remote site with WLCs at the core via Metro E.

    All,
    I have problem with register APs at the remote site with WLCs at the core.
    All of my WLCs are on main site; and the majority of APs are on same subnet and same site with the WLCs. This works just fine.
    However I have a remote site with connected to the core via metro E. And I am unable to make the APs at this site register to the controllers at the core.
    On remote site APs and PCs are on subnet. And PCs are work just fine. I have the DHCP scope options 43 set for the ip address of the WLCs.
    Metro E interfaces are on 192.168.0.0 /24.
    Clients (PCs and APs) at remote are on 192.168.56.0 /24
    I have the configuration on the Metro E and and remote site on the attachment.
    Thank in advantage.

    To get APs registered, make sure AP is getting an ip address and can ping WLC
    Once this is verified, run the following debugs on WLC CLI and attach it to the thread:
    - debug mac addr
    - debug capwap OR lwapp events enable
    - debug capwap OR lwapp errors enable
    - debug pm pki enable
    To stop debug
    - debug  disable-all
    In case you have 'console' access to remote site AP, capture AP boot up and then run "debug ip udp" on AP CLI
    To stop this debug
    AP# undebug all

  • Connecting Multiple Remote Sites with VPN Passthrough

    I have several Win2003SBS sites requiring VPN passthrough from remote clients some using the VPN Connectoid supplied with the SBS (on the RWW - "Download Connection Manager". The requirement is for an DSL modem router with at least 10 tunnels which also supports GRE. The device should support ADSL2 as a minimum and SDSL is preferred.
    A more detailed diagram is attached. Access to the Web Server will be required from both the LAN and WAN sides later.
    Any suggestions please?

    3700 Series multiservice access routers supports GRE, SDSL, ADSL.Refer the following URL for more information
    http://cisco.com/en/US/products/hw/routers/ps282/products_data_sheet09186a00800921f0.html

  • Deploying unity connection at remote site with CUCM at central site

    I am planning to deploy Unity connection at remote site while the CUCM is at central site only. Will appreciate of someone can shd some light on this, has anyone already deplyed same scenario , any specific requirements to take care of please ?
    Thanks in advnace,
    AB

    AB,
    Yes, having your Unity Connection server at a different location than your CUCM is supported.  
    I cannot really help you with specifc requirements as it largely depends on exactly how you intend to deploy it and what features you intend to enable.  Clustering, Digital Networking, Unified Inbox, etc.. all have their own additional requirements the whole of which would not fit into a message board post.
    However, specific bandwidth and latency requirements are listed in the "System Requirements for Cisco Unity Connection Release 8.X.   http://www.cisco.com/en/US/partner/docs/voice_ip_comm/connection/8x/requirements/8xcucsysreqs.html
    The SRND and the System Requirements should get you on the  right  track.  I would encourage you to read both documents fully and  then  come back with any specific design questions you may have.
    -Steven

  • Setting up remote sites with a domain controller at each

    Hello, I am setting up offices at 2 locations for the first time and I was wondering where I should go to get the best step by step information. My goal is to have a Windows 2012 (standard) server at each location acting as primary and secondary DC. User
    log in at each location would act as one and file sharing would be seamless. Since this is my first venture, it goes without saying that I have a lot of questions... To name a few; as I will be using DHCP, are the private IP's at each location the same or
    different? Would it be faster and more efficient to keep user-A files at their home location or put all the data to be accessed on one server? The questions could go on but this is not the place for it. I have done extensive searching on the topic but either
    I get bits and pieces or the sites assumes that you already know a step so much is overlooked in assumptions. Help

    Hi,
    For the 2 questions:
    1. Generally we will setup 2 sites for different locations so that computers know which site they are located.
    2. Local file server is much more efficient - users will always access a local server - access a remote server will be very slow unless you have high network connectivity.
    In order to get users accessing local file server, site-cost need to be set (so we need to use different sites for different locations).
    FYI, here is an article for AD design. As you said it may lead more questions so just feel free to discuss with us.
    If you are going to discuss a different topic, it is recommended to post a new thread for avoiding confusion.
    Best Practice Active Directory Design for Managing Windows Networks
    https://msdn.microsoft.com/en-us/library/bb727085.aspx
    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • How can one update text windows on remote site with out DW

    Hi!
    I am new to site design and I don't know if what I have in mind can be achieved.
    I would like to have a website with different news (text) and I would like to update those text by just uploading a file with the new text, can this be done.
    If yes, how?
    Thanks for any clue.
    Edgar

    Hi!,
    Finaly I thought Server Side Include would be the easiest way to achieve my goal.
    I took a text and save it as HTML; open it with notepad and erase all HTML tags, leaving just, I think the, the requested tag for tex, heraafter copy of my file:
    I am not sure about what was wrong, but using the DW to write the "include" rather than to do it by hand (to understand better what I was doing ) it works well after I erase the following lines :
       </STYLE>
    < LANG="fr-FR" TEXT="#000000" DIR="LTR">
    <H4 CLASS="western">nserting an image placeholder</H4>
    <P CLASS="western">An image placeholder is a graphic you use until
    final artwork is ready to be added to a web page; it is not a graphic
    image that displays in a browser. Before you publish your site,
    replace any image placeholders you've added with web-friendly graphic
    files such as GIFs or JPEGs. Click the link below to begin the
    simulation</P>
    <P CLASS="western" STYLE="margin-bottom: 0cm"><BR>
    </P>
    And that does not work I get :
    an error occurred while processing this directive]
    Wher is my error
    Thank you
    Message was edited by: edgar4

  • DR Site with different os

    Dear all,
    I have 2 servers,Sun and IBM and oracle 10gr2 .I have a plan to implement DR-site.I know a dataguard cann't using with different os,rigth?
    Do you have any idea for this plan (except using dataguard)?
    Thank you for advance
    chara

    I would be surprised if DataGuard could fulfill this role with the disparate O/S, though the MOS note shows the database needs to be non-RAC, non-TDE and at 11.2.0.2 or above. Both O/S' need to be 64-bit also. I know when I looked at this not so long ago, it wasn't an option, but now they seem to have updated it.
    I would suggest GoldenGate. It's intended for logical replication between heterogeneous systems, which is basically what you're looking at. Though you might find the cost very high - one of the key selling points is to limit downtime between migration and upgrades and a lot of their main customers are banks.

  • Can i use cisco 2951 cme 9 router to connect different branch location ip phones together with different subnet?

    hi all,
    I want to do VoIP , with cisco 2951 router with cme 9.0. I just want to know can i connect differnt branch  ip phone in differnt subnet in single centralized cme router 2951.
    that is for differnt branch ip phone there is differnt dhcp pool and then interVlan routing or as such.
    i have already done it for 1 location ,can i uses that single router to connect there all branch office?
    thank you
    regards,
    vishakha

    Yes that works. The phones get an IP from the local site with the info where to reach the TFTP-Server (which is typically the CME). From there the phones load a config file and learn the IP of the CME. The rest is pure routing from the phone to the CME.
    I don't know where marin and thana is, just make sure that the delay and jitter between the sites is inside an accepted range of < 150ms (latency) and < 30 ms (jitter).
    Don't stop after you've improved your network! Improve the world by lending money to the working poor:
    http://www.kiva.org/invitedby/karsteni

  • ACS 5.0 having issues with different subnet AAA Clients

    Dear All,
    I am getting weird issue. My ACS 5.0 is in subnet 10.1.1.0/24. All the AAA clients which are in the same subnet can communicate with the ACS but different subnet cannot.
    I have checked the firewall between them, Its allow any any with all services.
    One more thing I have faced today is that now from only one switch (10.1.2.10) can access ACS but switches in the same subnet (10.1.2.0/24) cant access ACS as same previous issue.
    Following are the logs of one switch(10.1.2.10) in different subnet can access ACS :
    Working Switch with Same configuration:
    SW-A#test aaa group tacacs+ test cisco legacy
    Attempting authentication test to server-group tacacs+ using tacacs+
    User was successfully authenticated.
    SW-A#
    *Nov 17 00:05:52.041: AAA: parse name=<no string> idb type=-1 tty=-1
    *Nov 17 00:05:52.041: AAA/MEMORY: create_user (0x1B1FD04) user='test' ruser='NULL' ds0=0 port='' rem_addr='NULL' authen_type=ASCII service=LOGIN priv=1 initial_task_id='0', vrf= (id=0)
    *Nov 17 00:05:52.041: TAC+: send AUTHEN/START packet ver=192 id=3237327729
    *Nov 17 00:05:52.041: TAC+: Using default tacacs server-group "tacacs+" list.
    *Nov 17 00:05:52.041: TAC+: Opening TCP/IP to 10.1.1.2/49 timeout=5
    *Nov 17 00:05:52.041: TAC+: Opened TCP/IP handle 0x1B44D48 to 10.1.1.2/49
    *Nov 17 00:05:52.041: TAC+: 10.1.1.2 (3237327729) AUTHEN/START/LOGIN/ASCII queued
    SW-A#
    *Nov 17 00:05:52.243: TAC+: (3237327729) AUTHEN/START/LOGIN/ASCII processed
    *Nov 17 00:05:52.243: TAC+: ver=192 id=3237327729 received AUTHEN status = GETPASS
    *Nov 17 00:05:52.243: TAC+: send AUTHEN/CONT packet id=3237327729
    *Nov 17 00:05:52.243: TAC+: 10.1.1.2 (3237327729) AUTHEN/CONT queued
    *Nov 17 00:05:52.444: TAC+: (3237327729) AUTHEN/CONT processed
    *Nov 17 00:05:52.444: TAC+: ver=192 id=3237327729 received AUTHEN status = PASS
    *Nov 17 00:05:52.444: AAA/MEMORY: free_user (0x1B1FD04) user='test' ruser='NULL' port='' rem_addr='NULL' authen_type=ASCII service=LOGIN priv=1 vrf= (id=0)
    Logs from the same subnet switch (10.1.2.20) which cannot access ACS:
    SW-B#test aaa group tacacs+ test cisco legacy
    Attempting authentication test to server-group tacacs+ using tacacs+
    No authoritative response from any server.
    SW-B#
    *Oct 20 00:54:12.834: AAA: parse name=<no string> idb type=-1 tty=-1
    *Oct 20 00:54:12.842: AAA/MEMORY: create_user (0x1A6F3F0) user='test' ruser='NULL' ds0=0 port='' rem_addr='NULL' authen_type=ASCII service=LOGIN priv=1 initial_task_id='0', vrf= (id=0)
    *Oct 20 00:54:12.842: TAC+: send AUTHEN/START packet ver=192 id=3281146755
    *Oct 20 00:54:12.842: TAC+: Using default tacacs server-group "tacacs+" list.
    *Oct 20 00:54:12.842: TAC+: Opening TCP/IP to 10.1.1.2/49 timeout=5
    *Oct 20 00:54:12.842: TAC+: Opened TCP/IP handle 0x1B1E888 to 10.1.1.2/49
    *Oct 20 00:54:12.842: TAC+: 10.1.1.2 (3281146755) AUTHEN/START/LOGIN/ASCII queued
    SW-B#
    *Oct 20 00:54:12.943: TAC+: (3281146755) AUTHEN/START/LOGIN/ASCII processed
    *Oct 20 00:54:12.943: TAC+: received bad AUTHEN packet: type = 0, expected 1
    *Oct 20 00:54:12.943: TAC+: Invalid AUTHEN/START/LOGIN/ASCII packet (check keys).
    *Oct 20 00:54:12.943: TAC+: Closing TCP/IP 0x1B1E888 connection to 10.1.1.2/49
    *Oct 20 00:54:12.943: TAC+: Using default tacacs server-group "tacacs+" list.
    *Oct 20 00:54:12.943: AAA/MEMORY: free_user (0x1A6F3F0) user='test' ruser='NULL' port='' rem_addr='NULL' authen_type=ASCII service=LOGIN priv=1 vrf= (id=0)
    Waiting for your responses.
    Regards,
    Anser

    Ok, cool,
    So this usually means that the switch is sourcing the requests from a difernet interface that is configured on the ACS.
    I would guess that the ACS is reporting unknown NAS...
    Can you please use the "ip tacacs source-interface" command to make sure the switch will source the Tacacs+ packets from the interface with the IP address for which you have the ACS configured to?
    HTH,
    Tiago
    If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

  • Sonicwall connect with different subnet Mitel VOIP system

    You can add a VLAN sub interface to interface X3, just click the Add Interface button at the button under all the current interfaces you have under Network Interface.Select the Zone you want to assign to this
    Select the VLAN you want to assign to the new interface
    Select the parent Interface (in this case X)Personally I would create a new zone for this(called Mitel VOIP or similar)to allow you to customise your Access rules as they work with zones rather than interfaces. If you setup the interface zone as trusted then the access rules will be automatically setup to allow all traffic in both directions to and from your other trusted zones. If it is setup as an untrusted zone then the traffic should be blocked to all other trusted zones (but I'm not toosure about the other direction - it's been a while since I've setup a sub interface).
    ...

    In my SonicWALL NSA 2400
    at X0 Parent interface LAN IP is 192.168.3.1/24
    X1 interface WAN IP assigned by ISP.
    X2 interface WLAN IP is 192.168.10.1/24
    our all switches are L2 switch.
    192.168.3.1 Network
    connected to running all our workstation, printer, pretty much everything. I
    have different subnet physically different system Using Mitel VOIP phone system
    using 192.168.2.1/24.
    Is there anyway can I set up the VLAN in SonicWALL’s X3 interface and connect
    the cable in X3 interface to the 192.168.2.1/24
    network switch. And can I manage the Mitel system from
    192.168.3.1/24 network connected workstation.
    Any suggestions would be appreciated.
    This topic first appeared in the Spiceworks Community

  • ASA 5510 and VPN access to remote site over Ext WAN

    ASA 5510
    int client IP 172.0.1.XXX /24
    VPN Client IP 172.0.1.248 /29
    Static routes in the ASA
    1) 0.0.0.0 --- points to router1
    2) 172.29.1.1 --- Points to router2
    3) 172.29.1.2 --- Points to router2
    Router1 Internet connection // VPN access in path
    Router2 Dedicated line to offsite hosting // Dedicated routes in ASA
    ................../---- ROUTER 1
    ..Inside -- ASA --- outside (switch 2 rtrs)
    ..................\---- ROUTER 2
    If a PC from inside the network wants to talk with 172.29.1.2 it will work fine. If I VPN into the router, I can connect to anything onsite. I cannot talk to 172.29.1.1 or .2
    At first I thought it was the same-security-traffic issue and applied same-security-traffic permit inter-interface then i tried same-security-traffic permit intra-interface.
    Both commands failed, Looking at the diagram I think its something with the fact I VPN into this ASA. Now router2 see's our ASA as its external. So it see's our 208.12.*.* as the outgouing address and dest is 172.29.1.1 or .2
    I did a capture on the outside interface and I see the following. Now these caps are from the inside PC's accessing the website.
    3000 packets captured
    1: 15:03:38.176733 208.12.*.*.60404 > 172.29.1.2.443: P 2697372408:2697372444(36) ack 2813073572 win 64360
    2: 15:03:38.179815 208.12.*.*.63637 > 172.29.1.2.443: P 3373326671:3373326705(34) ack 3255654279 win 64512
    3: 15:03:38.179876 208.12.*.*.60404 > 172.29.1.2.443: P 2697372444:2697372480(36) ack 2813073572 win 64360
    4: 15:03:38.180181 172.29.1.2.443 > 208.12.*.*.27133: . ack 838693750 win 65456
    5: 15:03:38.180212 172.29.1.2.443 > 208.12.*.*.26920: P 1652457319:1652457373(54) ack 2226176804 win 65482
    Can someone point me in the right direction on how I would get the VPN working so it too can connect to those websites?

    Hi,
    Did you try to do NONAT for the traffic from 172.0.1.0 going to 172.29.1.0
    Something like this:-
    access-list NONAT permit ip 172.0.1.0 255.255.255.0 172.29.1.0 255.255.255.0
    nat (Inside) 0 access-list NONAT

  • Exchange 2013, multiple IIS OWA sites with different authentication

    Hi
    I have an exchange 2013 server with Client Access and Mailbox server installed. The server has an second ip address which I have bound an additional IIS site to. The additional IIS site is named ExchangeExternalFBA.
    The default web site is configured for basic and windows authentication with:
    Set-EcpVirtualDirectory -identity "ecp (default web site)" -FormsAuthentication:$false
    Set-owavirtualdirectory -identity "owa (Default Web Site)" -FormsAuthentication:$false -WindowsAuthentication:$true -BasicAuthentication:$true
    Then a new ECP and OWA are configured with:
    New-ecpVirtualDirectory -WebSiteName "ExchangeExternalFBA"
    New-OwaVirtualDirectory -WebSiteName "ExchangeExternalFBA"
    Set-owavirtualdirectory -identity "owa (ExchangeExternalFBA)" -LogonFormat FullDomain -FormsAuthentication:$true -WindowsAuthentication:$false -BasicAuthentication:$true
    Set-EcpVirtualDirectory -identity "ecp (ExchangeExternalFBA)" -FormsAuthentication:$true
    Then I perform an iisreset.
    My problem is that then when I try to access the ECP or OWA on the default website, it loads forms authentication! The ECP or OWA on the ExchangeExternalFBA web site works correctly and also loads forms authentication.
    If I run...
    get-owavirtualdirectory "owa (ExchangeExternalFBA)"
    then it returns:
    InternalAuthenticationMethods                       : {Basic, Ntlm,
                                                          WindowsIntegrated}
    BasicAuthentication                                 : True
    WindowsAuthentication                               : True
    DigestAuthentication                                : False
    FormsAuthentication                                 : False
    LiveIdAuthentication                                : False
    AdfsAuthentication                                  : False
    OAuthAuthentication                                 : False
    If I then run
    Set-EcpVirtualDirectory -identity "ecp (default web site)" -FormsAuthentication:$false
    Set-owavirtualdirectory -identity "owa (Default Web Site)" -FormsAuthentication:$false -WindowsAuthentication:$true -BasicAuthentication:$true
    and perform another iisreset then when I try to access the ECP or OWA on the default website it loads correctly. But then the forms based authentication on the ExchangeExternalFBA website can no longer log in, it does not accept the user name and password.
    If I then disable and enable FBA on the ExchangeExternalFBA website then it works but forms based authentication takes over the default web site again!
    Whether I perform the above from the gui or from powershell it does not make a difference, the same behaviour is observed. Changing the logontype on the FBA does not make a difference.
    This has been tested on exchange 2013 cu1 and cu2.
    Similar(if not identical until they get sidetracked) issue reported in http://social.technet.microsoft.com/Forums/exchange/en-US/9fcd360f-6658-4940-add7-2f13265cf86b/multiple-owa-sites-on-a-single-server-2012-with-exchange-2013-mailbox-cas.
    This worked fine in outlook 2007 and 2010, why now do my virtual directories break each other?
    I can reproduce the issue on a test exchange 2013 I built in dev.
    Is this a bug or are you no longer meant to host different forms of authentication on a single cas?
    I'm mostly interested to see if this works for other people and why it no longer seems to work in 2013, so please no questions; 'why do you want 2 different forms of authentication'. 
    Much appreciated, Thanks!

    Based off of your feedback I have run the following:
    Remove-OwaVirtualDirectory "owa (ExchangeExternalFBA)"
    Remove-EcpVirtualDirectory "ecp (ExchangeExternalFBA)"
    iisreset
    Set-EcpVirtualDirectory -identity "ecp (default web site)" -FormsAuthentication:$false
    Set-owavirtualdirectory -identity "owa (Default Web Site)" -FormsAuthentication:$false -WindowsAuthentication:$true -BasicAuthentication:$true
    New-ecpVirtualDirectory -WebSiteName "ExchangeExternalFBA" -Role ClientAccess
    New-OwaVirtualDirectory -WebSiteName "ExchangeExternalFBA" -Role ClientAccess
    Set-owavirtualdirectory -identity "owa (ExchangeExternalFBA)" -LogonFormat FullDomain -FormsAuthentication:$true -WindowsAuthentication:$false -BasicAuthentication:$true
    Set-EcpVirtualDirectory -identity "ecp (ExchangeExternalFBA)" -FormsAuthentication:$true
    iisreset
    After this there has been no change in behaviour. After the iisreset, forms have again hijacked the default web site and re-setting the authentication on the default web site removes the forms but breaks the ability to sign in to the forms based page on the
    ExchangeExternalFBA web site again.
    Note. '-Role Frontend' did not work. It showed the error:
    Cannot process argument transformation on parameter 'Role'. Cannot convertvalue "frontend" to type
    "Microsoft.Exchange.Management.SystemConfigurationTasks.VirtualDirectoryRole".
    Error: "Unable to match the identifier name frontend to a valid enumerator name.  Specify one of the following enumerator names and try again:
    ClientAccess, Mailbox"
        + CategoryInfo          : InvalidData: (:) [New-OwaVirtualDirectory], ParameterBindin...mationException
        + FullyQualifiedErrorId : ParameterArgumentTransformationError,New-OwaVirtualDirectory
    Running get-help New-OwaVirtualDirectory -detailed shows the correct usage would be '-Role ClientAccess'?
        -Role <ClientAccess | Mailbox>
            The Role parameter specifies the configuration that should be used
            when the virtual directory is created. The following are the values
            that can be used with this parameter:
            * FrontEnd Configures the virtual directory for use on a Client Access
              server.
            * BackEnd Configures the virtual directory for use on a Mailbox server.

  • How can I use a template in a site with different lang tags?

    My site has pages in six different languages.  For example, the French page is
    <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="fr" lang="fr">
    My template, however, reads:
    <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
    <html xmlns="http://www.w3.org/1999/xhtml">
    Ergo, every time I update my site because I changed the template, my foreign langauge pages lose their language declarations.
    You cannot make an editable region for this.  When I tried, I got error messages.
    Anyone know a good work around?
    At this point, I have to manually edit those foreign language pages every time I do a site-wide update.
    Thanks.

    I have just tested this very quickly, but it seems to work.
    Dreamweaver templates allow you to create editable attributes. You can't do it for the <html> tag through the Dreamweaver interface, but it seems to work without problem if you hand-code it in the template.
    In the main template, change the <html> tag to look like this:
    <html xmlns="http://www.w3.org/1999/xhtml" xml:lang="@@(lang)@@" lang="@@(lang)@@">
    Just before the closing </head> tag, add this:
    <!-- TemplateParam name="lang" type="text" value="fr" -->
    Save the template.
    All child pages will automatically be updated to have xml:lang="fr" lang="fr".
    In pages that use a different language, go to Modify > Template Properties, and change the value of lang to en, or whatever language it uses.
    An alternative approach is to keep your language pages in different folders, and then use Find and Replace on the whole folder to change the values in the <html> tag.

  • WISM Interface Grouping with different subnets

    WISM v7.0 VLAN Select.
    Anyone can confirm if the VLANs subnet to be configured under interface group MUST be having the same subnet.
    Eg. VLAN1 - mask 255.255.255.248
          VLAN2 - mask 255.255.255.120
    Would these two VLANs be able to work together in interface grouping?
    Thanks in advance.
    Cheers,
    Wong

    The subnet mask doesn't matter, but the smaller subnet will ge marked dirty first since it is a smaller subner.
    Sent from Cisco Technical Support iPad App

Maybe you are looking for

  • Previewing on local testing server

    When previewing a file in the Dreamweaver development environment, Dreamweaver loads the file, say testfile.html, in the browser with its file system address, eg file://Applications/MAMP/htdocs/jsMath/test/testfile.html. However, the local website ad

  • Withholding tax -number could not be determined for numbering group ID0017

    While positing the FB60 transaction with withholding tax for country Indonesia, the below error is coming: A number could not be determined for numbering group ID0017 Message no. 7Q630 "The system could not determine a certificate number for the numb

  • Ordering notebook outside of US?

    Hello, I'm from the Netherlands, and I want to order a notebook from Best Buy, is that possible? Or is it U.S. only? Thanks in advance, Paul Solved! Go to Solution.

  • Illustrator CC Version 17.0.1 Crashes immediately

    Hi, Illustrator CC Version 17.0.1 crashes immediately after opening. IS there a solution for this?

  • Repeating frames...simple problem

    I am new to Oracle Reports and have run into a simple issue which I am not able to fix. Suppose that I’ve a table Numbers as shown below: SQL> desc numbers Name Null? Type COL1 NUMBER SQL> select * from numbers; COL1 1 2 3 4 5 Now I want to build a r